Manar AbuTalib

37 papers B 1C 4Journal 19Unranked 13
YearRankTypeTitle / Venue / Authors
2021 J jnl
J. Supercomput.
Manar AbuTalib, Sohaib Majzoub, Qassim Nasir, Dina J. Hejji
2021 J jnl
Neural Comput. Appl.
Sohail Abbas, Qassim Nasir, Douae Nouichi, Mohamed Abdelsalam, Manar AbuTalib, Omnia Abu Waraga, Atta ur Rehman Khan
2021 J jnl
IEEE Access
Ali Bou Nassif, Manar AbuTalib, Qassim Nasir, Halah Albadani, Fatima Mohamad Dakalbab
2020 conf
DAPPS
Ilham Ahmed Qasse, Josef Spillner, Manar AbuTalib, Qassim Nasir
2020 conf
IIT
Mariam Hassan AlThabahi, Manar AbuTalib, Sohail Abbas, Essa Basaeed
2020 J jnl
J. Cases Inf. Technol.
Manar AbuTalib, Areej Alsaafin, Selma Manel Medjden
2020 J jnl
Int. J. Electron. Secur. Digit. Forensics
Manar AbuTalib, Reem Alnanih, Adel Khelifi
2020 conf
IIT
Sara Ali Ghunaim, Qassim Nasir, Manar AbuTalib
2020 J jnl
Comput. Secur.
Omnia Abu Waraga, Meriem Bettayeb, Qassim Nasir, Manar AbuTalib
2020 conf
CCCI
Yaman Afadar, Ali Bou Nassif, Maha Alaa Eddin, Manar AbuTalib, Qassim Nasir
2020 conf
IIT
Rawhi Alrae, Manar AbuTalib, Qassim Nasir
2020 conf
CCECE
Ali Bou Nassif, Manar AbuTalib, Luiz Fernando Capretz
2020 J jnl
CoRR
Ali Bou Nassif, Manar AbuTalib, Luiz Fernando Capretz
2020 conf
CCCI
Dina Jamal Hejji, Ali Bou Nassif, Qassim Nasir, Manar AbuTalib
2019 conf
UCC Companion
Josef Spillner, Manar AbuTalib, Qassim Nasir, Farhad Khalilnia
2019 conf
ArabWIC
Manar AbuTalib, Nafisa Ahmed, Balsam Alkouz, Abdullah Abdulkarim
2019 conf
ArabWIC
Meriem Bettayeb, Qassim Nasir, Manar AbuTalib
2019 conf
ArabWIC
Ilham A. Qasse, Manar AbuTalib, Qassim Nasir
2018 J jnl
CoRR
Ali Bou Nassif, Omar Mahdi, Qassim Nasir, Manar AbuTalib, Mohammad Azzeh
2018 J jnl
Secur. Commun. Networks
Qassim Nasir, Ilham A. Qasse, Manar AbuTalib, Ali Bou Nassif
2018 J jnl
Int. J. Distributed Sens. Networks
Manar AbuTalib, Sohail Abbas, Qassim Nasir, Mohamad Fouzi Mowakeh
2018 J jnl
J. Comput. Virol. Hacking Tech.
Manar AbuTalib
2017 J jnl
J. Comput. Sci.
Manar AbuTalib
2016 J jnl
Int. J. Open Source Softw. Process.
Manar AbuTalib
2016 J jnl
Int. J. Open Source Softw. Process.
Manar AbuTalib
2015 J jnl
J. Comput. Sci.
Manar AbuTalib, Ashraf Elnagar
2015 J jnl
J. Comput. Sci.
Manar AbuTalib
2015 J jnl
J. Comput. Sci.
Manar AbuTalib, Muhammed AbuOdeh, Adhraa Almansoori, Arwa AlNauimi
2015 conf
ISSPIT
Manar AbuTalib
2013 C conf
SNPD
Adel Khelifi, Maher Aburrous, Manar AbuTalib, P. V. S. Shastry
2012 B conf
COMPSAC
Emilia Mendes, Manar AbuTalib, Steve Counsell
2012 C conf
IECON
Manar AbuTalib, Emilia Mendes, Adel Khelifi
2012 C conf
IECON
Manar AbuTalib, Adel Khelifi, Tahsin Ugurlu
2010 C conf
SERA
Manar AbuTalib, Adel Khelifi, Alain Abran, Olga Ormandjieva
2009 J jnl
IEEE Trans. Learn. Technol.
Adel Khelifi, Manar AbuTalib, Mohamed Farouk, Habib Hamam
2008 J jnl
Int. J. Softw. Eng. Knowl. Eng.
Olga Ormandjieva, Manar AbuTalib, Alain Abran
2007 conf
IWSM/Mensura
Manar AbuTalib, Adel Khelifi, Alain Abran, Olga Ormandjieva
redb/extractors/elf_extractors/elf_relocations.py
← Index redb/extractors/elf_extractors/elf_relocations.py python
import inspect
from datetime import datetime, timezone
from typing import Any, List, Dict

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFRelocation


class ELFRelocationExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_relocations = []
        self.elastic_index = self.index_prefix + "-elf_relocations"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _get_relocation_type_string(self, reloc_type: int, machine_arch: str) -> str:
        """Convert relocation type number to human-readable string based on architecture."""
        # This is a simplified mapping - real implementation would need comprehensive
        # architecture-specific relocation type mappings

        common_types = {
            0: "R_NONE",
            1: "R_DIRECT",
            2: "R_PC_RELATIVE",
            3: "R_GOT",
            4: "R_PLT",
            5: "R_COPY",
            6: "R_GLOB_DAT",
            7: "R_JMP_SLOT",
            8: "R_RELATIVE"
        }

        # Architecture-specific mappings could be added here
        if machine_arch == "x86_64":
            x86_64_types = {
                1: "R_X86_64_64",
                2: "R_X86_64_PC32",
                3: "R_X86_64_GOT32",
                4: "R_X86_64_PLT32",
                5: "R_X86_64_COPY",
                6: "R_X86_64_GLOB_DAT",
                7: "R_X86_64_JUMP_SLOT",
                8: "R_X86_64_RELATIVE"
            }
            return x86_64_types.get(reloc_type, f"R_X86_64_{reloc_type}")
        elif machine_arch == "x86":
            i386_types = {
                1: "R_386_32",
                2: "R_386_PC32",
                3: "R_386_GOT32",
                4: "R_386_PLT32",
                5: "R_386_COPY",
                6: "R_386_GLOB_DAT",
                7: "R_386_JMP_SLOT",
                8: "R_386_RELATIVE"
            }
            return i386_types.get(reloc_type, f"R_386_{reloc_type}")

        return common_types.get(reloc_type, f"R_UNKNOWN_{reloc_type}")

    def _extract_relocation_data(self, relocation, section_name: str, machine_arch: str) -> Dict:
        """Extract data from a single relocation entry."""
        try:
            # Get relocation offset
            relocation_offset = relocation.entry.get('r_offset', 0)

            # Get relocation type
            relocation_type = relocation.entry.get('r_info_type', 0)

            # Get symbol index
            relocation_symbol_index = relocation.entry.get('r_info_sym', 0)

            # Get addend (only present in RELA sections)
            relocation_addend = None
            if hasattr(relocation.entry, 'r_addend'):
                relocation_addend = relocation.entry.get('r_addend', 0)

            # Get symbol name if available
            relocation_symbol_name = ""
            if hasattr(relocation, 'symbol') and relocation.symbol:
                relocation_symbol_name = relocation.symbol.name or f"<symbol_{relocation_symbol_index}>"
            else:
                relocation_symbol_name = f"<symbol_{relocation_symbol_index}>"

            # Get type string mapping
            relocation_type_str = self._get_relocation_type_string(relocation_type, machine_arch)

            return ELFRelocation(
                relocation_offset=relocation_offset,
                relocation_type=relocation_type,
                relocation_type_str=relocation_type_str,
                relocation_symbol_index=relocation_symbol_index,
                relocation_symbol_name=relocation_symbol_name,
                relocation_section=section_name,
                relocation_addend=relocation_addend
            )

        except Exception as e:
            self.log.error(f"Error extracting relocation data: {e}")
            return None

    def _extract_relocations_from_section(self, section, machine_arch: str) -> List[Dict]:
        """Extract all relocations from a relocation section."""
        relocations = []

        try:
            if not hasattr(section, 'iter_relocations'):
                return relocations

            section_name = section.name or f"<unnamed_section>"

            for relocation in section.iter_relocations():
                reloc_data = self._extract_relocation_data(relocation, section_name, machine_arch)
                if reloc_data:
                    relocations.append(reloc_data)

        except Exception as e:
            self.log.error(f"Error extracting relocations from section {section.name}: {e}")

        return relocations

    def tag(self):
        return Tag.ELF_RELOCATIONS.value if hasattr(Tag, 'ELF_RELOCATIONS') else "elf_relocations"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_data(elf):
                # Get architecture for relocation type mapping
                machine_arch = self._get_architecture()
                all_relocations = []

                # Iterate through all sections looking for relocation sections with per-section error handling
                for section_index, section in enumerate(elf.iter_sections()):
                    try:
                        # Check if this is a relocation section (.rel or .rela)
                        if (section.name and
                            (section.name.startswith('.rel') or section.name.startswith('.rela')) and
                            hasattr(section, 'iter_relocations')):

                            section_relocations = self._extract_relocations_from_section(section, machine_arch)
                            all_relocations.extend(section_relocations)
                            self.log.debug(f"Extracted {len(section_relocations)} relocations from section {section.name}")
                    except Exception as e:
                        section_name = getattr(section, 'name', f'section_{section_index}')
                        self.log.warning(f"Error processing relocation section {section_name}: {e}")
                        # Continue processing other sections

                return all_relocations

            if not self._is_elf_file():
                return None

            result = self._with_elf_file(extract_data)
            if result is None:
                return None

            self.elf_relocations = result
            return self.elf_relocations

        except Exception as e:
            self.log.error(f"Error extracting ELF relocations {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_relocations
        elif exporter_type == "ClickHouseExporter":
            try:
                # Return valid empty structure if no relocations (e.g., statically linked binary)
                # None is reserved for actual errors

                # Prepare data arrays for all relocations
                data = []
                current_time = datetime.now(timezone.utc)
                for reloc in self.elf_relocations:
                    row = [
                        self.sha256,
                        self.md5,
                        self.sha1,
                        reloc.relocation_offset,
                        reloc.relocation_type,
                        reloc.relocation_type_str,
                        reloc.relocation_symbol_index,
                        reloc.relocation_symbol_name,
                        reloc.relocation_addend,
                        reloc.relocation_section,
                        current_time
                    ]
                    data.append(row)

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'relocation_offset', 'relocation_type', 'relocation_type_str',
                    'relocation_symbol_index', 'relocation_symbol_name',
                    'relocation_addend', 'relocation_section',
                    'analysis_date'
                ]

                if not data:
                    return None

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    'UInt64', 'UInt32', 'LowCardinality(String)',
                    'UInt32', 'LowCardinality(String)',
                    'Nullable(Int64)', 'LowCardinality(String)',
                    'DateTime64(3, \'UTC\')'
                ]

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_relocations"