Nahid Shahmehri

115 papers A* 7A 4B 18C 15Misc 5Journal 21Unranked 38
YearRankTypeTitle / Venue / Authors
2023 J jnl
Empir. Softw. Eng.
Ulf Kargén, Noah Mauthe, Nahid Shahmehri
2023 B conf
ARES
Ulf Kargén, Noah Mauthe, Nahid Shahmehri
2023 J jnl
Sci. Comput. Program.
Ulf Kargén, Ivar Härnqvist, Johannes Wilson, Gustav Eriksson, Evelina Holmgren, Nahid Shahmehri
2022 A conf
SANER
Ulf Kargén, Ivar Härnqvist, Johannes Wilson, Gustav Eriksson, Evelina Holmgren, Nahid Shahmehri
2021 A conf
SANER
Noah Mauthe, Ulf Kargén, Nahid Shahmehri
2019 J jnl
CoRR
Alireza Mohammadinodooshan, Ulf Kargén, Nahid Shahmehri
2019 conf
AISec@CCS
Alireza Mohammadinodooshan, Ulf Kargén, Nahid Shahmehri
2018 B conf
ARES
Ulf Kargén, Nahid Shahmehri
2017 J jnl
Comput. Networks
Rahul Hiran, Niklas Carlsson, Nahid Shahmehri
2017 A* conf
ASE
Ulf Kargén, Nahid Shahmehri
2016 J jnl
IEEE Internet Comput.
Anna Vapen, Niklas Carlsson, Anirban Mahanti, Nahid Shahmehri
2016 B conf
Networking
Rahul Hiran, Niklas Carlsson, Nahid Shahmehri
2016 A conf
ICSME
Ulf Kargén, Nahid Shahmehri
2015 A* conf
ACM Multimedia
Vengatanathan Krishnamoorthi, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri
2015 conf
CNS
Rahul Hiran, Niklas Carlsson, Nahid Shahmehri
2015 Misc conf
SEC
Anna Vapen, Niklas Carlsson, Anirban Mahanti, Nahid Shahmehri
2015 conf
CODASPY
Anna Vapen, Niklas Carlsson, Anirban Mahanti, Nahid Shahmehri
2015 conf
ESEC/SIGSOFT FSE
Ulf Kargén, Nahid Shahmehri
2014 C conf
SCAM
Ulf Kargén, Nahid Shahmehri
2014 conf
WISCS@CCS
Rahul Hiran, Niklas Carlsson, Nahid Shahmehri
2014 A* conf
ACM Multimedia
Vengatanathan Krishnamoorthi, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri
2014 B conf
PAM
Anna Vapen, Niklas Carlsson, Anirban Mahanti, Nahid Shahmehri
2013 conf
FhMN@SIGCOMM
Vengatanathan Krishnamoorthi, Patrik Bergström, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri
2013 J jnl
Comput. Commun. Rev.
Vengatanathan Krishnamoorthi, Patrik Bergström, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri
2013 B conf
MASCOTS
Vengatanathan Krishnamoorthi, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri
2012 J jnl
Inf. Softw. Technol.
Nahid Shahmehri, Amel Mammar, Edgardo Montes de Oca, David Byers, Ana R. Cavalli, Shanai Ardi, Willy Jimenez
2012 C conf
SCAM
Ulf Kargén, Nahid Shahmehri
2012 conf
UIC/ATC
Leonardo A. Martucci, Albin Zuccato, Ben J. M. Smeets, Sheikh Mahbub Habib, Thomas Johansson, Nahid Shahmehri
2011 J jnl
Int. J. Mob. Comput. Multim. Commun.
Anna Vapen, Nahid Shahmehri
2011 B conf
TrustBus
Nahid Shahmehri, David Byers, Rahul Hiran
2010 B conf
ARES
Anna Vapen, David Byers, Nahid Shahmehri
2010 conf
PrimeLife
Anna Vapen, Nahid Shahmehri
2010 conf
SESS@ICSE
David Byers, Nahid Shahmehri
2009 B conf
ARES
Shanai Ardi, Nahid Shahmehri
2009 J jnl
Digit. Investig.
David Byers, Nahid Shahmehri
2009 B conf
ARES
Per Håkon Meland, Shanai Ardi, Jostein Jensen, Erkuden Rios, Txus Sanchez, Nahid Shahmehri, Inger Anne Tøndel
2009 C conf
ICSEA
Shanai Ardi, Nahid Shahmehri
2009 B conf
ARES
David Byers, Nahid Shahmehri
2008 B conf
ARES
David Byers, Nahid Shahmehri
2008 J jnl
Digit. Investig.
David Byers, Nahid Shahmehri
2008 B conf
ARES
Shanai Ardi, Nahid Shahmehri
2007 J jnl
Int. J. Inf. Secur. Priv.
Almut Herzog, Nahid Shahmehri, Claudiu Duma
2007 B conf
ARES
David Byers, Nahid Shahmehri
2007 B conf
ARES
Shanai Ardi, David Byers, Per Håkon Meland, Inger Anne Tøndel, Nahid Shahmehri
2007 J jnl
IEEE Trans. Syst. Man Cybern. Part A
Ioan Chisalita, Nahid Shahmehri
2007 conf
POLICY
Claudiu Duma, Almut Herzog, Nahid Shahmehri
2007 ed.
Peer-to-Peer Computing
Manfred Hauswirth, Adam Wierzbicki, Klaus Wehrle, Alberto Montresor, Nahid Shahmehri
2007 Misc conf
SEC
Almut Herzog, Nahid Shahmehri
2007 J jnl
Inf. Manag. Comput. Secur.
Almut Herzog, Nahid Shahmehri
2007 conf
CHIMIT
Almut Herzog, Nahid Shahmehri
2006 A* conf
AAAI
Cécile Aberg, Johan Aberg, Patrick Lambrix, Nahid Shahmehri
2006 conf
DEXA Workshops
Claudiu Duma, Martin Karresand, Nahid Shahmehri, Germano Caronni
2006 Misc conf
SEC
Almut Herzog, Nahid Shahmehri
2006 B conf
PIMRC
Ioan Chisalita, Nahid Shahmehri
2006 conf
KDLL
He Tan, Vaida Jakoniene, Patrick Lambrix, Johan Aberg, Nahid Shahmehri
2006 conf
WINSYS
Ioan Chisalita, Nahid Shahmehri
2006 conf
ICSM
David Byers, Shanai Ardi, Nahid Shahmehri, Claudiu Duma
2006 Misc conf
SEC
Martin Karresand, Nahid Shahmehri
2006 conf
ISWCS
Ioan Chisalita, Nahid Shahmehri
2006 B conf
ESWC
Piero A. Bonatti, Claudiu Duma, Norbert E. Fuchs, Wolfgang Nejdl, Daniel Olmedilla, Joachim Peer, Nahid Shahmehri
2006 ed.
Peer-to-Peer Computing
Alberto Montresor, Adam Wierzbicki, Nahid Shahmehri
2006 conf
SESS@ICSE
Shanai Ardi, David Byers, Nahid Shahmehri
2005 C conf
WETICE
Cécile Aberg, Patrick Lambrix, Nahid Shahmehri
2005 C conf
WETICE
Almut Herzog, Nahid Shahmehri
2005 conf
DEXA Workshops
Claudiu Duma, Nahid Shahmehri, Germano Caronni
2005 ed.
Peer-to-Peer Computing
Germano Caronni, Nathalie Weiler, Marcel Waldvogel, Nahid Shahmehri
2005 J jnl
Comput. Secur.
Almut Herzog, Nahid Shahmehri
2005 A conf
ASSETS
Dennis Maciuszek, Johan Aberg, Nahid Shahmehri
2004 ed.
Peer-to-Peer Computing
Germano Caronni, Nathalie Weiler, Nahid Shahmehri
2004 B conf
PIMRC
Ioan Chisalita, Nahid Shahmehri
2004 J jnl
IEEE Pervasive Comput.
Paul Cuddihy, Roderick T. Hinman, Al-Thaddeus Avestruz, Elmer C. Lupton, Gary Livshin, John I. Rodriguez, Steven B. Leeb, Corinne M. Clark, Kathy J. Horvath, Ladislav Volicer, Björn Landfeldt, Judy Kay, Robert Kummerfeld, Aaron J. Quigley, David West, Trent Apted, Gavin Sinclair, David J. Haniff, Roy Kalawsky, David Atkins, Martin Lewin, Steve J. Brown, Nahid Shahmehri, Johan Aberg, Dennis Maciuszek, Ioan Chisalita
2004 conf
SMC (4)
Ioan Chisalita, Nahid Shahmehri
2003 ed.
Peer-to-Peer Computing
Nahid Shahmehri, Ross Lee Graham, Germano Caronni
2003 Misc conf
SEC
Claudiu Duma, Nahid Shahmehri, Patrick Lambrix
2003 C conf
WETICE
Claudiu Duma, Nahid Shahmehri, Patrick Lambrix
2003 conf
WWW (Posters)
Nahid Shahmehri, Juha Takkinen, Cécile Aberg
2002 ed.
Peer-to-Peer Computing
Ross Lee Graham, Nahid Shahmehri
2002 C conf
ISMIS
Cécile Aberg, Nahid Shahmehri
2002 conf
SMC (2)
Ioan Chisalita, Nahid Shahmehri
2002 conf
Peer-to-Peer Computing
Eduard Turcan, Nahid Shahmehri, Ross Lee Graham
2001 ed.
Peer-to-Peer Computing
Ross Lee Graham, Nahid Shahmehri
2001 A* conf
CHI
Johan Aberg, Nahid Shahmehri
2001 conf
HICSS
Johan Aberg, Nahid Shahmehri
2001 C conf
WETICE
Ioan Chisalita, Nahid Shahmehri
2001 conf
User Modeling
Johan Aberg, Nahid Shahmehri
2001 conf
WELCOM
Johan Aberg, Nahid Shahmehri, Dennis Maciuszek
2001 A* conf
EC
Johan Aberg, Nahid Shahmehri, Dennis Maciuszek
2000 J jnl
J. Intell. Inf. Syst.
Patrick Lambrix, Nahid Shahmehri
2000 C conf
WETICE
Lin Han, Nahid Shahmehri
2000 C conf
ISMIS
Cécile Boisson, Nahid Shahmehri
2000 J jnl
Internet Res.
Johan Åberg, Nahid Shahmehri
2000 C conf
WETICE
Claudiu Duma, Almut Herzog, Nahid Shahmehri
1999 C conf
WETICE
Lin Han, Nahid Shahmehri
1999 C conf
WETICE
Yahya Y. Al-Salqan, Nahid Shahmehri, Wu Wen, Mourad Debbabi
1999 C conf
ISMIS
Patrick Lambrix, Nahid Shahmehri, Svend Jacobsen
1999 conf
HICSS
Juha Takkinen, Nahid Shahmehri
1998 conf
HICSS (5)
Patrick Lambrix, Nahid Shahmehri, Niclas Wahllöf
1998 conf
HICSS (5)
Juha Takkinen, Nahid Shahmehri
1998 conf
DEXA Workshop
Juha Takkinen, Nahid Shahmehri
1998 conf
HICSS (4)
Patrick Lambrix, Nahid Shahmehri
1997 conf
Description Logics
Patrick Lambrix, Nahid Shahmehri, Niclas Wahllöf
1997 C conf
WETICE
Mats Gustafsson, Benoit Deligny, Nahid Shahmehri
1996 conf
PAAM
T. Hall, Nahid Shahmehri
1995 J jnl
J. Syst. Softw.
Nahid Shahmehri, Mariam Kamkar, Peter Fritzson
1994 J jnl
J. Syst. Softw.
Peter Fritzson, Mikhail Auguston, Nahid Shahmehri
1993 conf
ICSM
Mariam Kamkar, Peter Fritzson, Nahid Shahmehri
1993 J jnl
Microprocess. Microprogramming
Mariam Kamkar, Peter Fritzson, Nahid Shahmehri
1993 conf
AADEBUG
Nahid Shahmehri, Mariam Kamkar, Peter Fritzson
1992 J jnl
LOPLAS
Peter Fritzson, Nahid Shahmehri, Mariam Kamkar, Tibor Gyimóthy
1992 conf
PLILP
Mariam Kamkar, Nahid Shahmehri, Peter Fritzson
1991 A* conf
PLDI
Peter Fritzson, Tibor Gyimóthy, Mariam Kamkar, Nahid Shahmehri
1990 B conf
CC
Nahid Shahmehri, Peter Fritzson
1990 conf
PLILP
Mariam Kamkar, Nahid Shahmehri, Peter Fritzson
1990 conf
ICSM
Nahid Shahmehri, Mariam Kamkar, Peter Fritzson
1988 conf
SIGSMALL/PC
Mariam Kamkar, Nahid Shahmehri, Peter Fritzson
redb/extractors/macho_extractors/macho_universal.py
← Index redb/extractors/macho_extractors/macho_universal.py python
import hashlib
import inspect
import json
from datetime import datetime, timezone
from typing import Any, List

from redb.extractors.enum import Tag
from redb.extractors.macho_extractor import MachOExtractor
from redb.models.dataclasses import MachOUniversal


class MachOUniversalExtractor(MachOExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        macho=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            macho,
        )
        self.elastic_index = self.index_prefix + "-macho_universal"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.MACHO_UNIVERSAL.value

    def _extract_universal_info(self):
        """Extract Universal/FAT binary architecture information using new API."""
        self.log.debug(inspect.currentframe().f_code.co_name)

        if not self.macho:
            return None

        try:
            # Parse at Universal level first (new API requirement)
            self.macho.parse()

            # Get architectures using new API
            architectures = self.macho.get_architectures()
            if not architectures:
                return None

            # Check if this is a FAT binary
            is_fat = len(architectures) > 1

            architecture_info = []

            # Extract info for each architecture
            for arch_name in architectures:
                try:
                    # Get general info for this architecture
                    general_info = self.macho.get_general_info(arch=arch_name)

                    # Get header info for this architecture
                    header_info = self.macho.get_macho_header(arch=arch_name)

                    # Get architecture-specific MachO instance for detailed analysis
                    arch_macho = self.macho.get_macho_for_arch(arch_name)

                    # Calculate architecture slice hash (if we can access the raw data)
                    arch_sha256 = None
                    arch_md5 = None
                    arch_sha1 = None

                    # For FAT binaries, try to get slice-specific info
                    if is_fat and arch_macho:
                        try:
                            # This would require access to the slice data
                            # For now, we'll use the general file info
                            arch_sha256 = general_info.get('SHA256', '') if general_info else ''
                            arch_md5 = general_info.get('MD5', '') if general_info else ''
                            arch_sha1 = general_info.get('SHA1', '') if general_info else ''
                        except Exception as e:
                            self.log.debug(f"Could not extract slice hash for {arch_name}: {e}")

                    architecture_info.append({
                        'architecture': arch_name,
                        'arch_sha256': arch_sha256,
                        'arch_md5': arch_md5,
                        'arch_sha1': arch_sha1,
                        'cputype': header_info.get('cputype') if header_info else None,
                        'cpusubtype': header_info.get('cpusubtype') if header_info else None,
                        'filetype': header_info.get('filetype') if header_info else None
                    })

                except Exception as e:
                    self.log.warning(f"Error extracting info for architecture {arch_name}: {e}")
                    continue

            # Create Universal dataclass
            macho_universal = MachOUniversal(
                is_fat=is_fat,
                architecture_count=len(architectures),
                architectures=architectures,
                architecture_info=architecture_info,
                fat_hash=self.sha256,
                fat_md5=self.md5,
                fat_sha1=self.sha1
            )

            return macho_universal

        except Exception as e:
            self.log.error(f"Error extracting MachO Universal info: {e}")
            return None

    def _extract_fat_architecture_mappings(self):
        """Extract detailed FAT binary architecture mappings for database relationships."""
        self.log.debug(inspect.currentframe().f_code.co_name)

        if not self.macho:
            return []

        try:
            # Parse at Universal level first
            self.macho.parse()

            # Get architectures using new API
            architectures = self.macho.get_architectures()
            if not architectures or len(architectures) <= 1:
                return []  # Not a FAT binary

            mappings = []
            current_time = datetime.now(timezone.utc)

            # For each architecture, create a mapping record
            for arch_name in architectures:
                try:
                    # Get general info
                    general_info = self.macho.get_general_info()

                    # Create mapping record for FAT binary architecture table
                    mapping = {
                        'fat_hash': self.sha256,  # SHA256 of the FAT binary
                        'architecture': arch_name,
                        'arch_sha256': general_info.get('SHA256', '') if general_info else '',  # Will need proper slice extraction
                        'arch_md5': general_info.get('MD5', '') if general_info else '',
                        'arch_sha1': general_info.get('SHA1', '') if general_info else '',
                        'arch_filename': f"{general_info.get('Filename', '')}.{arch_name}" if general_info else '',
                        'analysis_date': current_time
                    }
                    mappings.append(mapping)

                except Exception as e:
                    self.log.warning(f"Error creating mapping for architecture {arch_name}: {e}")
                    continue

            return mappings

        except Exception as e:
            self.log.error(f"Error extracting FAT architecture mappings: {e}")
            return []

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            universal_info = self._extract_universal_info()
            return universal_info
        except Exception as e:
            self.log.error(f"Error extracting MachO Universal info: {e}")
            return None

    def extract_fat_binary_basic_properties_data(self):
        """Extract data needed for creating multiple BasicProperties records for FAT binaries.

        Returns:
            Tuple: (is_fat, fat_sha256, architectures_info) where:
                - is_fat: bool indicating if this is a FAT binary
                - fat_sha256: SHA256 of the FAT wrapper
                - architectures_info: dict with arch names and their hashes
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        if not self.macho:
            return False, None, {}

        try:
            # Parse at Universal level first
            self.macho.parse()

            # Get architectures using new API
            architectures = self.macho.get_architectures()
            if not architectures or len(architectures) <= 1:
                return False, None, {}  # Not a FAT binary

            # This is a FAT binary
            architectures_info = {}

            for arch_name in architectures:
                try:
                    # Get general info for this architecture
                    general_info = self.macho.get_general_info(arch=arch_name)

                    if general_info:
                        architectures_info[arch_name] = {
                            'sha256': general_info.get('SHA256', ''),
                            'md5': general_info.get('MD5', ''),
                            'sha1': general_info.get('SHA1', ''),
                            'filename': general_info.get('Filename', ''),
                            'filesize': general_info.get('Filesize', 0)
                        }
                except Exception as e:
                    self.log.warning(f"Error extracting info for architecture {arch_name}: {e}")
                    continue

            return True, self.sha256, architectures_info

        except Exception as e:
            self.log.error(f"Error extracting FAT binary data: {e}")
            return False, None, {}

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            universal_info = self.extract()
            if universal_info is None:
                return None

            data = []
            current_time = datetime.now(timezone.utc)

            # Get architecture info for the binary
            try:
                if universal_info.is_fat:
                    # For FAT binaries, architecture fields should be NULL since it contains multiple
                    architecture_raw = None
                    architecture_str = None
                else:
                    # For single-arch binaries, get the actual architecture info
                    header_info = self.macho.get_macho_header()
                    architecture_raw = header_info.get('cputype', 0) if header_info else 0
                    architecture_str = universal_info.architectures[0] if universal_info.architectures else None
            except Exception as e:
                self.log.warning(f"Could not get architecture info for binary: {e}")
                architecture_raw = None
                architecture_str = None

            # Main Universal binary record
            data.append([
                self.sha256,                              # sha256
                self.md5,                                 # md5
                self.sha1,                                # sha1
                None,                                     # parent_sha256 (always None for main FAT binary)
                architecture_raw,                         # architecture (raw CPU type)
                architecture_str,                         # architecture_str (human-readable)
                universal_info.is_fat,                    # is_fat
                universal_info.architecture_count,       # architecture_count
                universal_info.architectures,            # architectures (array)
                json.dumps(universal_info.architecture_info[0] if len(universal_info.architecture_info) == 1 else {"architectures": universal_info.architecture_info}) if universal_info.architecture_info else None,  # architecture_info (JSON)
                current_time,                             # analysis_date
            ])

            column_names = [
                'sha256', 'md5', 'sha1', 'parent_sha256', 'architecture', 'architecture_str',
                'is_fat', 'architecture_count', 'architectures', 'architecture_info',
                'analysis_date'
            ]

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(FixedString(64))', 'Nullable(UInt32)', 'LowCardinality(Nullable(String))',
                'UInt8', 'UInt32', 'Array(LowCardinality(String))', 'JSON',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

        return None

    def prepare_fat_architecture_export_data(self) -> Any:
        """Prepare export data for the FAT binary architecture mapping table."""
        mappings = self._extract_fat_architecture_mappings()
        if not mappings:
            return None

        data = []
        for mapping in mappings:
            data.append([
                mapping['fat_hash'],
                mapping['architecture'],
                mapping['arch_sha256'],
                mapping['arch_md5'],
                mapping['arch_sha1'],
                mapping['arch_filename'],
                mapping['analysis_date'],
            ])

        column_names = [
            'fat_hash', 'architecture', 'arch_sha256', 'arch_md5', 'arch_sha1',
            'arch_filename', 'analysis_date'
        ]

        column_type_names = [
            'FixedString(64)', 'LowCardinality(String)', 'FixedString(64)',
            'FixedString(32)', 'FixedString(40)', 'String',
            'DateTime64(3, \'UTC\')'
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_macho_universal"

    # def get_fat_architecture_table(self) -> str:
    #     """Return table name for FAT binary architecture mappings."""
    #     return "redb_fat_binary_architectures"