Manuel Casanova

24 papers B 8Journal 4Unranked 12
YearRankTypeTitle / Venue / Authors
2021 J jnl
IEEE Access
Reem Haweel, Ahmed Shalaby, Ali H. Mahmoud, Mohammed Ghazal, Noha A. Seada, Said Ghoniemy, Manuel Casanova, Gregory N. Barnes, Ayman El-Baz
2017 B conf
ICIP
Marwa Ismail, Gregory Barnes, Matthew Nitzken, Andrew E. Switala, Ahmed Shalaby, Ehsan Hosseini-Asl, Manuel Casanova, Robert Keynton, Ashraf Khalil, Ayman El-Baz
2015 B conf
ICIP
Marwa Ismail, Mahmoud Mostapha, Ahmed Soliman, Matthew Nitzken, Fahmi Khalifa, Ahmed Elnakib, Georgy L. Gimel'farb, Manuel Casanova, Ayman El-Baz
2015 conf
MICCAI (2)
Mahmoud Mostapha, Manuel Casanova, Georgy L. Gimel'farb, Ayman El-Baz
2012 J jnl
IEEE Trans. Inf. Technol. Biomed.
Ahmed Elnakib, Manuel Casanova, Georgy L. Gimel'farb, Andrew E. Switala, Ayman El-Baz
2012 conf
CRV
Mostafa Abdelrahman, Asem M. Ali, Ahmed A. Farag, Manuel Casanova, Aly A. Farag
2012 B conf
ICPR
Ahmed Elnakib, Matthew Nitzken, Manuel Casanova, H.-Y. Park, Georgy L. Gimel'farb, Ayman El-Baz
2011 conf
ISBI
Matthew Nitzken, Manuel Casanova, Georgy L. Gimel'farb, Fahmi Khalifa, Ahmed Elnakib, Andrew E. Switala, Ayman El-Baz
2011 B conf
ICIP
Matthew Nitzken, Manuel Casanova, Georgy L. Gimel'farb, Ahmed Elnakib, Fahmi Khalifa, Andrew E. Switala, Ayman El-Baz
2011 J jnl
J. Medical Syst.
Ayman El-Baz, Ahmed Elnakib, Manuel Casanova, Georgy L. Gimel'farb, Andrew E. Switala, Desha Jordan, Sabrina Rainey
2011 conf
ISBI
Ahmed Elnakib, Manuel Casanova, Georgy L. Gimel'farb, Andrew E. Switala, Ayman El-Baz
2010 B conf
ICPR
Ahmed Elnakib, Ayman El-Baz, Manuel Casanova, Andrew E. Switala
2010 B conf
ICIP
Ahmed Elnakib, Ayman El-Baz, Manuel Casanova, Georgy L. Gimel'farb, Andrew E. Switala
2010 conf
ISBI
Ahmed Elnakib, Ayman El-Baz, Manuel Casanova, Georgy L. Gimel'farb, Andrew E. Switala
2010 conf
ISVC (3)
Ahmed A. Farag, Shireen Y. Elhabian, Mostafa Abdelrahman, James H. Graham, Aly A. Farag, Dongqing Chen, Manuel Casanova
2008 B conf
ICIP
Ayman El-Baz, Manuel Casanova, Georgy L. Gimel'farb, Meghan Mott, Andrew E. Switala, Eric Vanbogaert, Russ McCracken
2008 J jnl
Int. J. Comput. Assist. Radiol. Surg.
Ayman El-Baz, Manuel Casanova, Georgy L. Gimel'farb, Meghan Mott, Andrew E. Switala
2008 B conf
ICPR
Ayman El-Baz, Manuel Casanova, Georgy L. Gimel'farb, Meghan Mott, Andrew E. Switala, Eric Vanbogaert, Russ McCracken
2008 conf
ISBI
Noha Youssry El-Zehiry, Manuel Casanova, Adel Elmaghraby
2007 conf
ISBI
Ayman El-Baz, Manuel Casanova, Georgy L. Gimel'farb, Meghan Mott, Andrew E. Switala
2007 conf
MICCAI (2)
Ayman El-Baz, Manuel Casanova, Georgy L. Gimel'farb, Meghan Mott, Andrew E. Switala
2007 conf
ISBI
Rachid Fahmi, Ayman El-Baz, Hossam El Din Hassan Abd El Munim, Aly A. Farag, Manuel Casanova
2006 conf
CVAMIA
Ayman El-Baz, Aly A. Farag, Asem M. Ali, Georgy L. Gimel'farb, Manuel Casanova
2006 conf
ISBI
Noha Youssry El-Zehiry, Manuel Casanova, Hossam S. Hassan, Aly A. Farag
redb/extractors/detectiteasy.py
← Index redb/extractors/detectiteasy.py python
import inspect
from pprint import pprint
import subprocess
import json
from typing import Any
from datetime import datetime, timezone
import os
from dotenv import load_dotenv

from redb.extractors.enum import Tag
from redb.models.dataclasses import DIEinfo
from redb.extractors.extractor import Extractor

load_dotenv(override=True)

class DIEExtractor(Extractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        precomputed_hashes=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix, elastic_index, known_benign, known_malicious,
            precomputed_hashes=precomputed_hashes
        )
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.die_info = None
        self.die_info_dict = {}
        self.elastic_index = self.index_prefix + "-die"

    def _recursive_entry(self, die_dict, master_key):
        self.log.debug(inspect.currentframe().f_code.co_name)
        if master_key:
            self.die_info_dict[master_key] = {}
        else:
            self.die_info_dict = {}
        for value in die_dict:
            if "type" in value:
                type_key = value["type"].lower().replace(" ", "_")
                name = value.get("name", "")
                version = f"({value.get('version')})" if value.get("version") else ""
                info = f"[{value.get('info')}]" if value.get("info") else ""

                if master_key:
                    self.die_info_dict[master_key][type_key] = f"{name}"
                    self.die_info_dict[master_key][f'{type_key}(full)'] = f"{name}{version}{info}"
                else:
                    self.die_info_dict[type_key] = f"{name}"
                    self.die_info_dict[f'{type_key}(full)'] = f"{name}{version}{info}"

            elif "parentfilepart" in value:
                child_key = (
                    value["parentfilepart"].lower().replace(" ", "_")
                    + "."
                    + value["filetype"].lower().replace(" ", "_")
                )
                if master_key:
                    self._recursive_entry(value["values"], f"{master_key}.{child_key}")
                else:
                    self._recursive_entry(value["values"], f"{child_key}")

    def _extract_dieinfo(self):
        """
        Execute a command-line binary with arguments and parse its JSON output.

        :param command: The command or path to the binary to execute
        :param args: Additional arguments to pass to the command
        :return: Parsed JSON output as a Python object
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # Construct the full command
        # command = "nfdc" # UNCOMMENT FOR PROD
        # command = "/Users/p4c0/_tools/NFD.app/Contents/MacOS/nfdc" # COMMENT FOR TESTING ON MAC
        command = os.getenv("DIE_PATH")
        args = ["-durj", self.filepath]
        full_command = [command] + list(args)
        TIMEOUT = int(os.getenv("DIE_TIMEOUT", "180"))

        try:
            # Execute the command and capture its output
            result = subprocess.run(
                full_command,
                capture_output=True,
                text=True,
                check=True,
                timeout=TIMEOUT,
            )

            # Parse the JSON output
            nfdc_output = json.loads(result.stdout)

            # Extract the DIE information from the json output
            for die_entry in nfdc_output["detects"]:
                if die_entry["parentfilepart"] == "Header":
                    master_key = (
                        die_entry["parentfilepart"].lower().replace(" ", "_")
                        + "."
                        + die_entry["filetype"].lower().replace(" ", "_")
                    )
                    self._recursive_entry(die_entry["values"], None)

            # pprint(json.dumps(self.die_info_dict, indent=2)) #debug
            self.die_info = DIEinfo(result.stdout, self.die_info_dict)
            self.log.debug(f"NFDC-DIE JSON dump: todo")
        except subprocess.TimeoutExpired:
            self.log.error(f"The DIE command timed out after {TIMEOUT} seconds")
            return None
        except subprocess.CalledProcessError as e:
            self.log.error(f"Error executing DIE command: {e}")
            self.log.error(f"Command output (stderr): {e.stderr}")
            return None
        except json.JSONDecodeError as e:
            self.log.error(f"Error parsing DIE JSON output: {e}")
            self.log.error(f"Raw output: {result.stdout}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.die_info
        elif exporter_type == "ClickHouseExporter":
            # Convert DIE info to JSON string
            die_info_json = json.dumps(self.die_info_dict)
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                die_info_json,
                datetime.now(timezone.utc)
            ]]
            
            column_names = [
                'sha256', 'md5', 'sha1', 'die_info', 'analysis_date'
            ]
            
            column_type_names = [
                'String', 'String', 'String', 'JSON', 'DateTime64(3, \'UTC\')'
            ]
            
            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_die"

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            self._extract_dieinfo()
            
            # Check if there's a packer in the DIE results
            is_packed = False
            if self.die_info_dict:
                # Check if 'packer' exists in the DIE results
                is_packed = bool(self.die_info_dict.get('packer'))
            
            return self.die_info  # Return the extracted data instead of exporting directly
        except Exception as e:
            self.log.error(f"Error extracting DIE information: {e}")
            return None

    def tag(self):
        return Tag.DIEC.value