Nancy J. Cooke

68 papers B 2Misc 6Journal 41Unranked 17
YearRankTypeTitle / Venue / Authors
2025 conf
AAAI Spring Symposia
Elmira Zahmat Doost, Xiaoyun Yin, Shiwen Zhou, David A. Grimm, Nancy J. Cooke, Jamie C. Gorman
2025 J jnl
Top. Cogn. Sci.
Lixiao Huang, Jared Freeman, Nancy J. Cooke, Myke C. Cohen, Xiaoyun Yin, Jeska Clark, Matthew D. Wood, Verica Buchanan, Christopher C. Corral, Federico Scholcover, Anagha Mudigonda, Lovein Thomas, Aaron Teo, John Colonna-romano
2024 J jnl
Hum. Factors
Julie L. Harrison, Shiwen Zhou, Matthew J. Scalia, David A. Grimm, Mustafa Demir, Nathan J. McNeese, Nancy J. Cooke, Jamie C. Gorman
2024 J jnl
Hum. Factors
Nancy J. Cooke, Myke C. Cohen, Walter C. Fazio, Laura H. Inderberg, Craig J. Johnson, Glenn J. Lematta, Matthew Peel, Aaron Teo
2024 J jnl
Top. Cogn. Sci.
Christopher W. Myers, Nancy J. Cooke, Jamie C. Gorman, Nathan J. McNeese
2024 B conf
RO-MAN
Mason O. Smith, Sunny Amatya, Ashish Amresh, Jamie C. Gorman, Matthew Johnson, Nancy J. Cooke, Wenlong Zhang
2023 B conf
IVA
Ashish Amresh, Nancy J. Cooke, Adam Fouse
2023 J jnl
CoRR
Yutian Pang, Jueming Hu, Christopher S. Lieber, Nancy J. Cooke, Yongming Liu
2023 J jnl
Adv. Eng. Informatics
Yutian Pang, Jueming Hu, Christopher S. Lieber, Nancy J. Cooke, Yongming Liu
2023 J jnl
Int. J. Hum. Comput. Interact.
Mustafa Demir, Myke C. Cohen, Craig J. Johnson, Erin K. Chiou, Nancy J. Cooke
2023 J jnl
Adv. Eng. Informatics
Ruoxin Xiong, Yanyu Wang, Pingbo Tang, Nancy J. Cooke, Sarah V. Ligda, Christopher S. Lieber, Yongming Liu
2023 conf
HHAI Workshops
Myke C. Cohen, Mickey V. Mancenido, Erin K. Chiou, Nancy J. Cooke
2023 J jnl
Hum. Factors
Craig J. Johnson, Mustafa Demir, Nathan J. McNeese, Jamie C. Gorman, Alexandra T. Wolff, Nancy J. Cooke
2022 J jnl
Int. J. Soc. Robotics
Erin K. Chiou, Mustafa Demir, Verica Buchanan, Christopher C. Corral, Mica R. Endsley, Glenn J. Lematta, Nancy J. Cooke, Nathan J. McNeese
2022 J jnl
Int. J. Soc. Robotics
Erin K. Chiou, Mustafa Demir, Verica Buchanan, Christopher C. Corral, Mica R. Endsley, Glenn J. Lematta, Nancy J. Cooke, Nathan J. McNeese
2021 conf
ICHMS
Shawaiz Bhatti, Mustafa Demir, Nancy J. Cooke, Craig J. Johnson
2021 J jnl
IEEE Trans. Hum. Mach. Syst.
Mustafa Demir, Nathan J. McNeese, Jamie C. Gorman, Nancy J. Cooke, Christopher W. Myers, David A. Grimm
2021 conf
ICHMS
Myke C. Cohen, Mustafa Demir, Erin K. Chiou, Nancy J. Cooke
2021 J jnl
Int. J. Electron. Commer.
Nathan J. McNeese, Mustafa Demir, Erin K. Chiou, Nancy J. Cooke
2020 conf
HCI (7)
Nancy J. Cooke, Mustafa Demir, Lixiao Huang
2020 conf
AHFE (10)
Craig J. Johnson, Glenn J. Lematta, Lixiao Huang, Eric Holder, Shawaiz Bhatti, Nancy J. Cooke
2020 J jnl
CoRR
Ufuk Topcu, Nadya Bliss, Nancy J. Cooke, Missy L. Cummings, Ashley J. Llorens, Howard E. Shrobe, Lenore D. Zuck
2020 Misc conf
WSC
Yanyu Wang, Pingbo Tang, Ying Shi, Yongming Liu, Nancy J. Cooke
2020 Misc conf
CogSIMA
Craig J. Johnson, Mustafa Demir, Garrett M. Zabala, Hongbei He, David A. Grimm, Cody Radigan, Alexandra T. Wolff, Nancy J. Cooke, Nathan J. McNeese, Jamie C. Gorman
2020 J jnl
Int. J. Hum. Comput. Stud.
Mustafa Demir, Nathan J. McNeese, Nancy J. Cooke
2019 J jnl
IEEE Intell. Syst.
Christopher W. Myers, Jerry T. Ball, Nancy J. Cooke, Mary D. Freiman, Michelle Caisse, Stuart M. Rodgers, Mustafa Demir, Nathan J. McNeese
2019 Misc conf
CogSIMA
Mustafa Demir, Nathan J. McNeese, Craig J. Johnson, Jamie C. Gorman, David A. Grimm, Nancy J. Cooke
2019 J jnl
IEEE Trans. Hum. Mach. Syst.
Mustafa Demir, Aaron D. Likens, Nancy J. Cooke, Polemnia G. Amazeen, Nathan J. McNeese
2019 conf
HICSS
Nathan J. McNeese, Mustafa Demir, Erin K. Chiou, Nancy J. Cooke, Giovanni Yanikian
2018 J jnl
Cogn. Syst. Res.
Mustafa Demir, Nancy J. Cooke, Polemnia G. Amazeen
2018 J jnl
Hum. Factors
Prashanth Rajivan, Nancy J. Cooke
2018 J jnl
Hum. Factors
Nathan J. McNeese, Mustafa Demir, Nancy J. Cooke, Christopher W. Myers
2018 Misc conf
CogSIMA
David A. Grimm, Mustafa Demir, Jamie C. Gorman, Nancy J. Cooke
2018 J jnl
IEEE Trans. Emerg. Top. Comput. Intell.
Mustafa Demir, Nathan J. McNeese, Nancy J. Cooke
2017 ch.
Theory and Models for Cyber Situation Awareness
Massimiliano Albanese, Nancy J. Cooke, González Coty, David Hall, Christopher G. Healey, Sushil Jajodia, Peng Liu, Michael D. McNeese, Peng Ning, Douglas S. Reeves, V. S. Subrahmanian, Cliff Wang, John Yen
2017 ch.
Theory and Models for Cyber Situation Awareness
Prashanth Rajivan, Nancy J. Cooke
2017 J jnl
Cogn. Syst. Res.
Mustafa Demir, Nathan J. McNeese, Nancy J. Cooke
2017 J jnl
Big Data
Verica Buchanan, Yafeng Lu, Nathan J. McNeese, Michael Steptoe, Ross Maciejewski, Nancy J. Cooke
2016 conf
HCI (15)
Pingbo Tang, Cheng Zhang, Alper Yilmaz, Nancy J. Cooke, Ronald Laurids Boring, Allan Chasey, Timothy Vaughn, Samuel Jones, Ashish Gupta, Verica Buchanan
2016 conf
HCI (14)
Nathan J. McNeese, Nancy J. Cooke
2016 Misc conf
CogSIMA
Mustafa Demir, Nathan J. McNeese, Nancy J. Cooke
2013 J jnl
EAI Endorsed Trans. Security Safety
Nancy J. Cooke, Michael Champion, Prashanth Rajivan, Shree Jariwala
2013 conf
HCI (24)
Prashanth Rajivan, Michael Champion, Nancy J. Cooke, Shree Jariwala, Genevieve Dube, Verica Buchanan
2013 J jnl
Cogn. Sci.
Nancy J. Cooke, Jamie C. Gorman, Christopher W. Myers, Jasmine L. Duran
2013 J jnl
EAI Endorsed Trans. Security Safety
Nancy J. Cooke, Michael D. McNeese
2013 J jnl
Hum. Factors
William S. Marras, Nancy J. Cooke
2012 J jnl
Hum. Factors
Jamie C. Gorman, Nancy J. Cooke, Polemnia G. Amazeen, Shannon Fouse
2012 J jnl
Hum. Factors
Nancy J. Cooke, Andrew Duchon, Jamie C. Gorman, Joann Keyton, Anne Miller
2012 Misc conf
CogSIMA
Michael A. Champion, Prashanth Rajivan, Nancy J. Cooke, Shree Jariwala
2010 J jnl
Hum. Factors
Jamie C. Gorman, Nancy J. Cooke
2010 J jnl
Comput. Math. Organ. Theory
Jerry T. Ball, Christopher W. Myers, Andrea Heiberg, Nancy J. Cooke, Michael Matessa, Mary D. Freiman, Stuart M. Rodgers
2010 J jnl
Hum. Factors
Jamie C. Gorman, Nancy J. Cooke, Polemnia G. Amazeen
2008 J jnl
Hum. Factors
Eduardo Salas, Nancy J. Cooke, Michael A. Rosen
2008 J jnl
Hum. Factors
Nancy J. Cooke
2000 J jnl
Hum. Factors
Nancy J. Cooke, Eduardo Salas, Janis A. Cannon-Bowers, Renée J. Stout
1996 J jnl
Hum. Comput. Interact.
Nancy J. Cooke, Kelly Neville, Anna L. Rowe
1996 conf
CHI Conference Companion
Krisela Rivera, Nancy J. Cooke, Jeff A. Bauhs
1995 conf
CHI 95 Conference Companion
Douglas J. Gillan, Nancy J. Cooke
1994 conf
CHI Conference Companion
Anna L. Rowe, Tammy Lowry, Shannon L. Halgren, Nancy J. Cooke
1994 conf
CHI Conference Companion
Krisela Rivera, Nancy J. Cooke, Anna L. Rowe, Jeff A. Bauhs
1994 conf
CHI Conference Companion
Jeff A. Bauhs, Nancy J. Cooke
1994 conf
CHI Conference Companion
Douglas J. Gillan, Nancy J. Cooke
1994 J jnl
Int. J. Hum. Comput. Stud.
Nancy J. Cooke
1993 J jnl
Int. J. Man Mach. Stud.
Shannon L. Halgren, Nancy J. Cooke
1992 J jnl
Int. J. Man Mach. Stud.
Nancy J. Cooke
1992 conf
CHI Posters and Short Talks
Kay A. Flowers, Nancy J. Cooke
1992 J jnl
Int. J. Man Mach. Stud.
Douglas J. Gillan, Sarah D. Breedin, Nancy J. Cooke
1988 J jnl
Int. J. Man Mach. Stud.
Nancy J. Cooke, Roger W. Schvaneveldt
redb/extractors/apk_extractors/apk_dex.py
← Index redb/extractors/apk_extractors/apk_dex.py python
import hashlib
import inspect
import json
from collections import Counter
from datetime import datetime, timezone
from typing import Any

import tlsh

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKDexFile

# Sensitive API patterns categorized for malware analysis
SENSITIVE_API_CATEGORIES = {
    "reflection": [
        "Ljava/lang/reflect/Method;->invoke",
        "Ljava/lang/reflect/Field;->get",
        "Ljava/lang/reflect/Field;->set",
        "Ljava/lang/reflect/Constructor;->newInstance",
        "Ljava/lang/Class;->forName",
        "Ljava/lang/Class;->getMethod",
        "Ljava/lang/Class;->getDeclaredMethod",
        "Ljava/lang/Class;->getDeclaredField",
        "Ljava/lang/ClassLoader;->loadClass",
    ],
    "crypto": [
        "Ljavax/crypto/Cipher;->getInstance",
        "Ljavax/crypto/Cipher;->init",
        "Ljavax/crypto/spec/SecretKeySpec;-><init>",
        "Ljavax/crypto/spec/IvParameterSpec;-><init>",
        "Ljava/security/MessageDigest;->getInstance",
        "Ljava/security/KeyStore;->getInstance",
        "Ljavax/crypto/Mac;->getInstance",
    ],
    "dynamic_loading": [
        "Ldalvik/system/DexClassLoader;-><init>",
        "Ldalvik/system/PathClassLoader;-><init>",
        "Ldalvik/system/InMemoryDexClassLoader;-><init>",
        "Ldalvik/system/BaseDexClassLoader;-><init>",
        "Ljava/lang/Runtime;->exec",
        "Ljava/lang/ProcessBuilder;->start",
    ],
    "telephony": [
        "Landroid/telephony/TelephonyManager;->getDeviceId",
        "Landroid/telephony/TelephonyManager;->getSubscriberId",
        "Landroid/telephony/TelephonyManager;->getLine1Number",
        "Landroid/telephony/TelephonyManager;->getSimSerialNumber",
        "Landroid/telephony/TelephonyManager;->getNetworkOperator",
        "Landroid/telephony/TelephonyManager;->getSimOperator",
    ],
    "sms": [
        "Landroid/telephony/SmsManager;->sendTextMessage",
        "Landroid/telephony/SmsManager;->sendMultipartTextMessage",
        "Landroid/telephony/SmsManager;->sendDataMessage",
    ],
    "network": [
        "Ljava/net/HttpURLConnection;->connect",
        "Ljava/net/URL;->openConnection",
        "Lokhttp3/OkHttpClient;-><init>",
        "Lokhttp3/Request$Builder;->build",
        "Lorg/apache/http/client/HttpClient;->execute",
        "Landroid/webkit/WebView;->loadUrl",
        "Landroid/webkit/WebView;->setWebViewClient",
    ],
    "native": [
        "Ljava/lang/System;->loadLibrary",
        "Ljava/lang/System;->load",
        "Ljava/lang/Runtime;->loadLibrary",
    ],
    "device_info": [
        "Landroid/os/Build;->FINGERPRINT",
        "Landroid/os/Build;->MODEL",
        "Landroid/os/Build;->MANUFACTURER",
        "Landroid/os/Build;->PRODUCT",
        "Landroid/os/Build;->BRAND",
        "Landroid/os/Build;->DEVICE",
        "Landroid/os/Build;->HARDWARE",
        "Landroid/os/Build;->SERIAL",
        "Landroid/os/Build$VERSION;->SDK_INT",
        "Landroid/provider/Settings$Secure;->getString",
    ],
    "file_io": [
        "Ljava/io/FileOutputStream;-><init>",
        "Ljava/io/FileInputStream;-><init>",
        "Landroid/content/SharedPreferences;->edit",
        "Landroid/database/sqlite/SQLiteDatabase;->execSQL",
        "Landroid/database/sqlite/SQLiteDatabase;->rawQuery",
    ],
    "ipc": [
        "Landroid/content/ContentResolver;->query",
        "Landroid/content/ContentResolver;->insert",
        "Landroid/content/ContentResolver;->delete",
        "Landroid/content/Intent;-><init>",
        "Landroid/content/Context;->sendBroadcast",
        "Landroid/content/Context;->startService",
        "Landroid/content/Context;->bindService",
    ],
}


class APKDexExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.dex_files = []
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_DEX.value

    def _analyze_api_usage(self, dex):
        """Categorize sensitive API calls found in DEX bytecode."""
        api_usage = {cat: set() for cat in SENSITIVE_API_CATEGORIES}

        try:
            for method in dex.get_encoded_methods():
                code = method.get_code()
                if not code:
                    continue
                try:
                    bytecode = code.get_bc()
                    if not bytecode:
                        continue
                    for instruction in bytecode.get_instructions():
                        op_name = instruction.get_name()
                        if not op_name or not op_name.startswith("invoke"):
                            continue
                        output = instruction.get_output()
                        if not output:
                            continue
                        for category, patterns in SENSITIVE_API_CATEGORIES.items():
                            for pattern in patterns:
                                if pattern in output:
                                    api_usage[category].add(output.strip())
                                    break
                except Exception:
                    continue
        except Exception as e:
            self.log.warning(f"Error analyzing API usage: {e}")

        # Convert sets to sorted lists
        return {cat: sorted(calls) for cat, calls in api_usage.items() if calls}

    def _compute_obfuscation_indicators(self, classes, methods):
        """Compute obfuscation indicators from class/method names."""
        class_names = []
        for cls in classes:
            try:
                name = cls.get_name()
                if name:
                    class_names.append(name)
            except Exception:
                continue

        method_names = []
        for m in methods:
            try:
                name = m.get_name()
                if name and name not in ("<init>", "<clinit>"):
                    method_names.append(name)
            except Exception:
                continue

        if not class_names:
            return None

        # Short class names: extract just the class part from Dalvik notation
        short_class = 0
        for n in class_names:
            simple = n.split("/")[-1].rstrip(";")
            if len(simple) <= 2:
                short_class += 1

        short_method = sum(1 for n in method_names if len(n) <= 2)

        return {
            "short_class_names_pct": round(short_class / max(len(class_names), 1), 4),
            "short_method_names_pct": round(short_method / max(len(method_names), 1), 4),
            "non_ascii_identifiers": sum(1 for n in class_names if not n.isascii()),
            "avg_class_name_length": round(
                sum(len(n) for n in class_names) / max(len(class_names), 1), 2
            ),
        }

    def _compute_top_packages(self, classes):
        """Compute top packages by class count."""
        package_counter = Counter()
        for cls in classes:
            try:
                name = cls.get_name()  # "Lcom/example/foo/Bar;"
                if not name:
                    continue
                parts = name[1:].replace("/", ".").rsplit(".", 1)
                if len(parts) > 1:
                    package = parts[0]
                else:
                    package = "(default)"
                package_counter[package] += 1
            except Exception:
                continue

        return [
            {"package": pkg, "class_count": count}
            for pkg, count in package_counter.most_common(20)
        ]

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        from androguard.core.dex import DEX

        try:
            dex_names = list(self.apk.get_dex_names() or [])
        except Exception as e:
            self.log.warning(f"Error getting DEX names for {self.hash.sha256}: {e}")
            dex_names = []

        try:
            dex_buffers = list(self.apk.get_all_dex() or [])
        except Exception as e:
            self.log.error(f"Error getting DEX buffers for {self.hash.sha256}: {e}")
            return None

        if not dex_buffers:
            self.log.debug("No DEX files found in APK")
            return None

        self.dex_files = []
        for i, dex_data in enumerate(dex_buffers):
            dex_name = dex_names[i] if i < len(dex_names) else f"classes{i}.dex"

            dex_sha256 = hashlib.sha256(dex_data).hexdigest()
            dex_tlsh = None
            if len(dex_data) >= 50:
                try:
                    dex_tlsh = tlsh.hash(dex_data) or None
                except Exception:
                    pass

            try:
                d = DEX(dex_data)
            except Exception as e:
                self.log.warning(f"Failed to parse DEX {dex_name}: {e}")
                continue

            try:
                classes = list(d.get_classes() or [])
            except Exception as e:
                self.log.warning(f"Error getting classes from {dex_name}: {e}")
                classes = []
            try:
                methods = list(d.get_methods() or [])
            except Exception as e:
                self.log.warning(f"Error getting methods from {dex_name}: {e}")
                methods = []
            try:
                strings = list(d.get_strings() or [])
            except Exception as e:
                self.log.warning(f"Error getting strings from {dex_name}: {e}")
                strings = []

            try:
                top_packages = self._compute_top_packages(classes)
            except Exception as e:
                self.log.warning(f"Error computing top packages for {dex_name}: {e}")
                top_packages = []
            try:
                api_usage = self._analyze_api_usage(d)
            except Exception as e:
                self.log.warning(f"Error analyzing API usage for {dex_name}: {e}")
                api_usage = {}
            try:
                obfuscation_indicators = self._compute_obfuscation_indicators(classes, methods)
            except Exception as e:
                self.log.warning(f"Error computing obfuscation indicators for {dex_name}: {e}")
                obfuscation_indicators = None

            self.dex_files.append(APKDexFile(
                filename=dex_name,
                sha256=dex_sha256,
                class_count=len(classes),
                method_count=len(methods),
                string_count=len(strings),
                tlsh=dex_tlsh,
                top_packages=top_packages,
                api_usage=api_usage if api_usage else None,
                obfuscation_indicators=obfuscation_indicators,
            ))

        return self.dex_files if self.dex_files else None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.dex_files:
                return None

            current_time = datetime.now(timezone.utc)

            # DEX table: one row per DEX file
            dex_data = []
            for dex in self.dex_files:
                dex_data.append([
                    self.sha256,
                    dex.sha256,
                    dex.filename,
                    dex.tlsh,
                    dex.class_count,
                    dex.method_count,
                    dex.string_count,
                    json.dumps(dex.top_packages) if dex.top_packages else None,
                    json.dumps(dex.obfuscation_indicators) if dex.obfuscation_indicators else None,
                    current_time,
                ])

            # API usage table: one row per category per DEX
            api_data = []
            for dex in self.dex_files:
                if dex.api_usage:
                    for category, api_calls in dex.api_usage.items():
                        api_data.append([
                            self.sha256,
                            dex.sha256,
                            category,
                            api_calls,
                            current_time,
                        ])

            return {
                'multi_table': True,
                'dex': {
                    'table': 'redb_apk_dex',
                    'data': dex_data,
                    'column_names': [
                        'sha256', 'dex_sha256', 'dex_filename', 'dex_tlsh',
                        'dex_class_count', 'dex_method_count', 'dex_string_count',
                        'dex_top_packages', 'dex_obfuscation_indicators',
                        'analysis_date',
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(64)', 'String', 'Nullable(String)',
                        'UInt32', 'UInt32', 'UInt32',
                        'Nullable(String)', 'Nullable(String)',
                        "DateTime64(3, 'UTC')",
                    ],
                },
                'api_usage': {
                    'table': 'redb_apk_dex_api_usage',
                    'data': api_data,
                    'column_names': [
                        'sha256', 'dex_sha256', 'api_category',
                        'api_calls', 'analysis_date',
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(64)', 'LowCardinality(String)',
                        'Array(String)', "DateTime64(3, 'UTC')",
                    ],
                },
            }

    def get_clickhouse_table(self) -> str:
        return "redb_apk_dex"