Man Wu

67 papers A* 4A 1B 3C 6Journal 31Unranked 22
YearRankTypeTitle / Venue / Authors
2026 J jnl
J. Supercomput.
Haoyu Tang, Yirong Kan, Man Wu, Renyuan Zhang, Yasuhiko Nakashima
2026 J jnl
Multim. Syst.
Man Wu, Hengmiao Zhang, Jing Fang, Yang Yang, Xiong Luo
2025 J jnl
Complex Intell. Syst.
Liyun Su, Man Wu, Fenglan Li
2025 conf
HCI (46)
Xuanyue Feng, Guoming Liu, Man Wu
2025 conf
ACM Great Lakes Symposium on VLSI
Man Wu, Shaswot Shresthamali, Xiaoman Liu, Yuan He
2025 J jnl
Neurocomputing
Pei Yu, Gaocai Wang, Man Wu, Lili Wen
2025 J jnl
IEEE Access
Man Wu, Lili Wen, Gaocai Wang, Yu-Ting Lu
2025 J jnl
Int. J. Mach. Learn. Cybern.
Chuxin Cao, Man Wu, Zhizhe Lin, Jianhong Huang
2024 conf
MCSoC
Man Wu, Masaaki Kondo
2024 conf
ADMA (4)
Xinbai Li, Man Wu
2024 J jnl
CoRR
Man Wu, Xin Zheng, Qin Zhang, Xiao Shen, Xiong Luo, Xingquan Zhu, Shirui Pan
2024 J jnl
Appl. Intell.
Yuting Lu, Gaocai Wang, Xianfei Huang, Shuqiang Huang, Man Wu
2024 J jnl
Softw. Qual. J.
Jinli Zhang, Zhenbo Wang, Zongli Jiang, Man Wu, Chen Li, Yoshihiro Yamanishi
2024 J jnl
CoRR
Yunpeng Yao, Man Wu, Zheng Chen, Renyuan Zhang
2023 conf
ICAI (2)
Guilin Xu, Hengtong Qiu, Xiaomin Yan, Man Wu, Jing Guo, Zhaoyong Huang, Wenlong Huang
2023 J jnl
Hum. Factors
Man Wu, Qin Gao, Yang Liu
2023 conf
BIBM
Zongli Jiang, Zhenbo Wang, Jinli Zhang, Man Wu, Chen Li, Yoshihiro Yamanishi
2023 J jnl
AI Commun.
Feng Zhang, Gaocai Wang, Man Wu, Shuqiang Huang
2023 conf
NEWCAS
Yunpeng Yao, Man Wu, Renyuan Zhang
2023 C conf
ACML
Yunpeng Yao, Man Wu, Zheng Chen, Renyuan Zhang
2023 conf
BIC-TA (2)
Lihua Wu, Yu Liu, Zhenhua Shi, Zhenyi Ai, Man Wu, Yuanbao Chen
2022 J jnl
IEEE Trans. Emerg. Top. Comput. Intell.
Man Wu, Shirui Pan, Xingquan Zhu
2022 conf
BIBM
Haohui Jia, Ziwei Yang, Pei Gao, Man Wu, Chen Li, Yirong Kan, Renyuan Zhang
2022 conf
HPCC/DSS/SmartCity/DependSys
Honglin Shu, Pei Gao, Ziwei Yang, Chen Li, Man Wu
2022 conf
SOCC
Man Wu, Yirong Kan, Renyuan Zhang, Yasuhiko Nakashima
2022 B conf
SMC
Lei Yang, Ji Shen, Man Wu, Yanhong Liu
2022 conf
HPCC/DSS/SmartCity/DependSys
Man Wu, Zheng Chen, Yunpeng Yao
2022 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Yirong Kan, Man Wu, Renyuan Zhang, Yasuhiko Nakashima
2022 conf
HPCC/DSS/SmartCity/DependSys
Man Wu, Hiroki Matsutani, Masaaki Kondo
2022 conf
HCI (12)
Yue Chen, Man Wu, Qin Gao
2022 J jnl
Complex.
Dongmei Li, Man Wu, Jinwang Liu, Yiman Gao
2022 A* conf
DAC
Chunhua Li, Man Wu, Yuhan Liu, Ke Zhou, Ji Zhang, Yunqing Sun
2022 J jnl
Entropy
Junhai Luo, Yuxin Tian, Hang Yu, Yu Chen, Man Wu
2022 B conf
IEEE Big Data
Man Wu, Xingquan Zhu
2021 J jnl
IEEE Commun. Surv. Tutorials
Junhai Luo, Yanping Chen, Man Wu, Yang Yang
2021 J jnl
Secur. Commun. Networks
Ruijie Pan, Gaocai Wang, Man Wu
2021 conf
ICRAI
Lei Yang, Yuge Gu, Man Wu, Yanhong Liu
2021 conf
ICRAI
Lei Yang, Ge Gao, Man Wu, Jianyong Li
2021 J jnl
Neurocomputing
Man Wu, Yirong Kan, Tati Erlina, Renyuan Zhang, Yasuhiko Nakashima
2021 B conf
SMC
Shouan Song, Lei Yang, Man Wu, Yanhong Liu, Hongnian Yu
2021 J jnl
CoRR
Man Wu, Shirui Pan, Lan Du, Xingquan Zhu
2021 J jnl
ACM Trans. Knowl. Discov. Data
Man Wu, Shirui Pan, Lan Du, Xingquan Zhu
2021 J jnl
Knowl. Inf. Syst.
Man Wu, Shirui Pan, Xingquan Zhu
2021 J jnl
Neurocomputing
Junhai Luo, Man Wu, Zhiyan Wang, Yanping Chen, Yang Yang
2021 J jnl
New Gener. Comput.
Pei-Pei Li, Man Wu, Junhong He, Xuegang Hu
2021 J jnl
Complex.
Dongmei Li, Yingying Gui, Jinwang Liu, Man Wu
2021 conf
HCI (25)
Man Wu, Qin Gao
2020 J jnl
Sensors
Junhai Luo, Yang Yang, Zhiyan Wang, Yanping Chen, Man Wu
2020 conf
ISVLSI
Yirong Kan, Man Wu, Renyuan Zhang, Yasuhiko Nakashima
2020 conf
NEWCAS
Man Wu, Yan Chen, Yirong Kan, Takeshi Nomura, Renyuan Zhang, Yasuhiko Nakashima
2020 J jnl
Sensors
Junhai Luo, Zhiyan Wang, Yanping Chen, Man Wu, Yang Yang
2020 C conf
FUSION
Junhai Luo, Yanping Chen, Zhiyan Wang, Man Wu, Yang Yang
2020 J jnl
Mob. Inf. Syst.
Bingcheng Wang, Man Wu, Pei-Luen Patrick Rau, Qin Gao
2020 A* conf
ICDM
Man Wu, Shirui Pan, Xingquan Zhu
2020 A* conf
WWW
Man Wu, Shirui Pan, Chuan Zhou, Xiaojun Chang, Xingquan Zhu
2020 J jnl
Int. J. Hum. Comput. Interact.
Man Wu, Qin Gao
2019 C conf
FUSION
Junhai Luo, Xiaoting He, Man Wu, Yanping Chen, Yang Yang
2019 A* conf
ICDM
Man Wu, Shirui Pan, Xingquan Zhu, Chuan Zhou, Lei Pan
2019 A conf
CIKM
Man Wu, Shirui Pan, Lan Du, Ivor W. Tsang, Xingquan Zhu, Bo Du
2019 conf
HCI (11)
Man Wu, Bingcheng Wang, Qin Gao, Pei-Luen Patrick Rau
2018 J jnl
Soft Comput.
Xiao Yu, Man Wu, Yiheng Jian, Kwabena Ebo Bennin, Mandi Fu, Chuanxiang Ma
2018 C conf
SEKE
Man Wu, Sizhe Ye, Chunhua Li, Ziyi Ma, Zhongwang Fu
2018 conf
HCI (6)
Qin Gao, Man Wu, Bin Zhu
2017 C conf
SEKE
Xiao Yu, Man Wu, Xiangyang Jia, Ye Liu
2017 C conf
SEKE
Xiao Yu, Man Wu, Yan Zhang, Mandi Fu
2016 conf
HCI (11)
Ziyang Li, Pei-Luen Patrick Rau, Nan Qie, Man Wu
2015 J jnl
CoRR
Wei Xu, Man Wu, Hua Zhang, Xiaohu You, Chunming Zhao
redb/extractors/elf_extractor.py
← Index redb/extractors/elf_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class ELFExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious
        )
        # Store ELF object if provided, otherwise we'll create it per-operation for security
        self._provided_elf = elf
        self._elf_file_valid = None  # Cache validity check

    def _with_elf_file(self, operation):
        """Safely execute an operation with an ELF file using context manager.

        Args:
            operation: A callable that takes an ELFFile object and returns a result

        Returns:
            The result of the operation, or None if an error occurred
        """
        if self._provided_elf:
            try:
                return operation(self._provided_elf)
            except ELFError as e:
                if "String Table not found" in str(e):
                    self.log.warning(f"String table missing in ELF {self.hash.sha256}: {e}")
                    return None
                else:
                    self.log.error(f"ELF format error {self.hash.sha256} Full error: {e}")
                    return None
            except Exception as e:
                self.log.error(f"Error processing ELF file {self.hash.sha256} Full error: {e}")
                return None

        try:
            with open(self.filepath, 'rb') as f:
                elf = ELFFile(f)
                if not elf:
                    raise ELFError("Empty file?")
                return operation(elf)
        except ELFError as e:
            if "String Table not found" in str(e):
                self.log.warning(f"String table missing in ELF {self.hash.sha256}: {e}")
                return None
            else:
                self.log.error(f"ELF format error {self.hash.sha256} Full error: {e}")
                return None
        except Exception as e:
            self.log.error(f"Error reading ELF file {self.hash.sha256} Full error: {e}")
            return None

    def _is_elf_file(self):
        """Check if the file is a valid ELF binary."""
        if self._elf_file_valid is not None:
            return self._elf_file_valid

        def check_elf_validity(elf):
            # pyelftools ELFFile object existing means it's valid ELF
            # Just check that we can access the header
            header = elf.header
            return header is not None

        try:
            result = self._with_elf_file(check_elf_validity)
            self._elf_file_valid = bool(result)
            return self._elf_file_valid
        except Exception as e:
            self.log.error(f"Error checking ELF file: {e}")
            self._elf_file_valid = False
            return False

    def _is_64bit(self):
        """Check if the ELF binary is 64-bit."""
        def check_64bit(elf):
            return elf.header.get('e_ident', {}).get('EI_CLASS') == 'ELFCLASS64'

        try:
            result = self._with_elf_file(check_64bit)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking ELF bitness: {e}")
            return False

    def _is_stripped(self):
        """Check if the ELF binary is stripped (no symbol table)."""
        def check_stripped(elf):
            # Look for symbol table sections
            for section in elf.iter_sections():
                if section.name in ['.symtab', '.strtab']:
                    return False
            return True

        try:
            result = self._with_elf_file(check_stripped)
            return result if result is not None else True
        except Exception as e:
            self.log.error(f"Error checking if ELF is stripped: {e}")
            return True

    def _has_debug_info(self):
        """Check if the ELF binary contains debug information."""
        def check_debug_info(elf):
            # Look for debug sections
            debug_sections = ['.debug_info', '.debug_line', '.debug_str', '.debug_abbrev']
            for section in elf.iter_sections():
                if section.name in debug_sections:
                    return True
            return False

        try:
            result = self._with_elf_file(check_debug_info)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking debug info: {e}")
            return False

    def _get_architecture(self):
        """Get the architecture of the ELF binary."""
        def get_arch(elf):
            machine = elf.header.get('e_machine', 'EM_NONE')

            # Map common machine types to readable names
            arch_map = {
                'EM_386': 'x86',
                'EM_X86_64': 'x86_64',
                'EM_ARM': 'ARM',
                'EM_AARCH64': 'ARM64',
                'EM_MIPS': 'MIPS',
                'EM_PPC': 'PowerPC',
                'EM_PPC64': 'PowerPC64',
                'EM_SPARC': 'SPARC',
                'EM_RISCV': 'RISC-V'
            }

            return arch_map.get(machine, machine)

        try:
            result = self._with_elf_file(get_arch)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting architecture: {e}")
            return "unknown"

    def _get_endianness(self):
        """Get the endianness of the ELF binary."""
        def get_endian(elf):
            data_encoding = elf.header.get('e_ident', {}).get('EI_DATA')
            if data_encoding == 'ELFDATA2LSB':
                return "little"
            elif data_encoding == 'ELFDATA2MSB':
                return "big"
            return "unknown"

        try:
            result = self._with_elf_file(get_endian)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting endianness: {e}")
            return "unknown"

    def _get_file_type(self):
        """Get the file type of the ELF binary."""
        def get_file_type(elf):
            etype = elf.header.get('e_type', 'ET_NONE')

            # Map file types to readable names
            type_map = {
                'ET_NONE': 'none',
                'ET_REL': 'relocatable',
                'ET_EXEC': 'executable',
                'ET_DYN': 'shared_object',
                'ET_CORE': 'core_dump'
            }

            return type_map.get(etype, etype)

        try:
            result = self._with_elf_file(get_file_type)
            return result if result is not None else "unknown"
        except Exception as e:
            self.log.error(f"Error getting file type: {e}")
            return "unknown"

    def _is_pie(self):
        """Check if the ELF binary is position-independent executable."""
        def check_pie(elf):
            # PIE binaries are typically ET_DYN type
            etype = elf.header.get('e_type', 'ET_NONE')
            if etype == 'ET_DYN':
                # Check if it has an entry point (executable) vs library
                entry_point = elf.header.get('e_entry', 0)
                return entry_point > 0
            return False

        try:
            result = self._with_elf_file(check_pie)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking PIE: {e}")
            return False

    def _has_stack_protection(self):
        """Check if the binary has stack protection (canaries)."""
        def check_stack_protection(elf):
            # Look for stack protection symbols
            stack_symbols = ['__stack_chk_fail', '__stack_chk_guard']

            for section in elf.iter_sections():
                if hasattr(section, 'iter_symbols'):
                    for symbol in section.iter_symbols():
                        if symbol.name in stack_symbols:
                            return True
            return False

        try:
            result = self._with_elf_file(check_stack_protection)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking stack protection: {e}")
            return False

    def _has_nx_bit(self):
        """Check if the binary has NX bit (non-executable stack)."""
        def check_nx_bit(elf):
            # Look for GNU_STACK segment
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_GNU_STACK':
                    flags = segment.header.get('p_flags', 0)
                    # Check if execute flag is NOT set (NX enabled)
                    return not (flags & 0x1)  # PF_X = 0x1
            return False

        try:
            result = self._with_elf_file(check_nx_bit)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking NX bit: {e}")
            return False

    def _has_relro(self):
        """Check if the binary has RELRO (Relocation Read-Only)."""
        def check_relro(elf):
            # Look for GNU_RELRO segment
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_GNU_RELRO':
                    return True
            return False

        try:
            result = self._with_elf_file(check_relro)
            return bool(result)
        except Exception as e:
            self.log.error(f"Error checking RELRO: {e}")
            return False

    def _get_build_id(self):
        """Extract build ID from notes section."""
        def get_build_id(elf):
            # Look for build ID in notes sections
            for section in elf.iter_sections():
                if section.name == '.note.gnu.build-id':
                    for note in section.iter_notes():
                        if note['n_type'] == 'NT_GNU_BUILD_ID':
                            # Convert bytes to hex string
                            build_id = note['n_desc']
                            if isinstance(build_id, bytes):
                                return build_id.hex()
                            return str(build_id)
            return None

        try:
            result = self._with_elf_file(get_build_id)
            return result
        except Exception as e:
            self.log.error(f"Error getting build ID: {e}")
            return None

    def _count_sections(self):
        """Count the number of sections in the ELF file."""
        def count_sections(elf):
            return elf.header.get('e_shnum', 0)

        try:
            result = self._with_elf_file(count_sections)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting sections: {e}")
            return 0

    def _count_segments(self):
        """Count the number of segments (program headers) in the ELF file."""
        def count_segments(elf):
            return elf.header.get('e_phnum', 0)

        try:
            result = self._with_elf_file(count_segments)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting segments: {e}")
            return 0

    def _count_symbols(self):
        """Count the total number of symbols in symbol tables."""
        def count_symbols(elf):
            symbol_count = 0
            for section in elf.iter_sections():
                if hasattr(section, 'iter_symbols'):
                    symbol_count += section.num_symbols()
            return symbol_count

        try:
            result = self._with_elf_file(count_symbols)
            return result if result is not None else 0
        except Exception as e:
            self.log.error(f"Error counting symbols: {e}")
            return 0

    def _get_dependencies(self):
        """Get list of dynamic dependencies."""
        def get_dependencies(elf):
            dependencies = []
            dynamic_section = elf.get_section_by_name('.dynamic')
            if dynamic_section:
                for tag in dynamic_section.iter_tags():
                    if tag.entry.d_tag == 'DT_NEEDED':
                        dependencies.append(tag.needed)
            return dependencies

        try:
            result = self._with_elf_file(get_dependencies)
            return result if result is not None else []
        except Exception as e:
            self.log.error(f"Error getting dependencies: {e}")
            return []