Nantiwat Pholdee

37 papers Journal 33Unranked 4
YearRankTypeTitle / Venue / Authors
2024 J jnl
Expert Syst. Appl.
Yodsadej Kanokmedhakul, Sujin Bureerat, Natee Panagant, Thana Radpukdee, Nantiwat Pholdee, Ali Riza Yildiz
2023 J jnl
Knowl. Based Syst.
Betül Sultan Yildiz, Sumit Kumar, Natee Panagant, Pranav Mehta, Sadiq M. Sait, Ali Riza Yildiz, Nantiwat Pholdee, Sujin Bureerat, Seyedali Mirjalili
2023 J jnl
Knowl. Based Syst.
Sumit Kumar, Natee Panagant, Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat, Nikunj Mashru, Pinank Patel
2023 J jnl
IEEE Trans. Control. Syst. Technol.
Felix Biertümpfel, Nantiwat Pholdee, Samir Bennani, Harald Pfifer
2023 J jnl
Eng. Appl. Artif. Intell.
Pakin Champasak, Natee Panagant, Nantiwat Pholdee, Sujin Bureerat, Parvathy Rajendran, Ali Riza Yildiz
2022 J jnl
Expert Syst. J. Knowl. Eng.
Betül Sultan Yildiz, Sumit Kumar, Nantiwat Pholdee, Sujin Bureerat, Sadiq M. Sait, Ali Riza Yildiz
2022 J jnl
Eng. Comput.
Betül Sultan Yildiz, Nantiwat Pholdee, Sujin Bureerat, Ali Riza Yildiz, Sadiq M. Sait
2022 J jnl
Knowl. Based Syst.
Kittinan Wansasueb, Sorasak Panmanee, Natee Panagant, Nantiwat Pholdee, Sujin Bureerat, Ali Riza Yildiz
2022 J jnl
Int. J. Online Biomed. Eng.
Kriengkrai Nabudda, Jarupol Suriyawanakul, Kiatfa Tangchaichit, Nantiwat Pholdee, Weerachai Kosuwon, Taweechok Wisanuyotin, Kamolsak Sukhonthamarn
2022 J jnl
Eng. Comput.
Kittinan Wansasueb, Nantiwat Pholdee, Natee Panagant, Sujin Bureerat
2022 J jnl
Soft Comput.
Sumit Kumar, Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat
2022 J jnl
Knowl. Based Syst.
Siwakorn Anosri, Natee Panagant, Sujin Bureerat, Nantiwat Pholdee
2021 J jnl
Soft Comput.
Sujin Bureerat, Nantiwat Pholdee
2021 J jnl
Appl. Soft Comput.
Felix Biertümpfel, Nantiwat Pholdee, Sujin Bureerat, Harald Pfifer
2021 J jnl
Comput. Intell. Neurosci.
Yodsadej Kanokmedhakul, Natee Panagant, Sujin Bureerat, Nantiwat Pholdee, Ali Riza Yildiz
2021 J jnl
CoRR
Felix Biertümpfel, Nantiwat Pholdee, Samir Bennani, Harald Pfifer
2021 J jnl
Knowl. Based Syst.
Sumit Kumar, Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat, Pranav Mehta
2021 J jnl
Expert Syst. Appl.
Sumit Kumar, Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat
2021 J jnl
Eng. Comput.
Sumit Kumar, Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat
2021 J jnl
Knowl. Based Syst.
Sumit Kumar, Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat
2021 J jnl
Expert Syst. J. Knowl. Eng.
Betül Sultan Yildiz, Nantiwat Pholdee, Sujin Bureerat, Ali Riza Yildiz, Sadiq M. Sait
2020 J jnl
Comput. Intell.
Wonsiri Punurai, Md Samdani Azad, Nantiwat Pholdee, Sujin Bureerat, Chana Sinsabvarodom
2019 J jnl
Expert Syst. Appl.
Sujin Bureerat, Nantiwat Pholdee, Thana Radpukdee, Papot Jaroenapibal
2019 J jnl
Eng. Comput.
Teerapol Techasen, Kittinan Wansasueb, Natee Panagant, Nantiwat Pholdee, Sujin Bureerat
2019 J jnl
Expert Syst. Appl.
Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat, Doddy Prayogo, Amir H. Gandomi
2018 J jnl
Appl. Soft Comput.
Sujin Bureerat, Nantiwat Pholdee
2018 conf
ICNCC
Nantiwat Pholdee, Sujin Bureerat
2018 J jnl
Knowl. Based Syst.
Ghanshyam G. Tejani, Nantiwat Pholdee, Sujin Bureerat, Doddy Prayogo
2017 conf
ICCSA (1)
Sujin Bureerat, Nantiwat Pholdee
2017 conf
ISNN (1)
Nantiwat Pholdee, Sujin Bureerat, Papot Jaroenapibal, Thana Radpukdee
2017 J jnl
Expert Syst. Appl.
Kasem Nuaekaew, Pramin Artrit, Nantiwat Pholdee, Sujin Bureerat
2016 conf
MIWAI
Sujin Bureerat, Nantiwat Pholdee, Won-Woong Park, Dong-Kyu Kim
2016 J jnl
Int. J. Syst. Sci.
Nantiwat Pholdee, Sujin Bureerat
2016 J jnl
J. Comput. Civ. Eng.
Sujin Bureerat, Nantiwat Pholdee
2015 J jnl
Int. J. Syst. Sci.
Nantiwat Pholdee, Sujin Bureerat
2014 J jnl
Adv. Eng. Softw.
Nantiwat Pholdee, Sujin Bureerat
2013 J jnl
Inf. Sci.
Nantiwat Pholdee, Sujin Bureerat
redb/extractors/decompiler/_archive/DecompileGhidra-old.py
← Index redb/extractors/decompiler/_archive/DecompileGhidra-old.py python
from hashlib import sha256
import inspect
from pathlib import Path
import subprocess
import json
import subprocess
import json
import os
import tempfile
import uuid
import shutil
import time

from dotenv import load_dotenv

from redb.extractors.enum import Tag
from redb.models.dataclasses import Decompiled
from redb.extractors.extractor import Extractor


class DecompileGhidra(Extractor):
    def __init__(
        self,
        filepath,
        log,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
    ):
        super().__init__(
            filepath, log, index_prefix, elastic_index, known_benign, known_malicious
        )
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.elastic_index = self.index_prefix + "-ghidra"
        self.ghidra_path = "/opt/ghidra"
        self.java_script_path = (
            self.ghidra_path
            + "/Ghidra/Features/Base/ghidra_scripts/GhidraDecompilerScript.java"
        )
        self.decompiled = None
        load_dotenv()
        self.decompiled_folder = os.getenv("DECOMPILED_FOLDER", "/opt/decompiled")
        self.log.debug(f"Decompiled folder: {self.decompiled_folder}")

    def run_command(self, cmd, env=None):
        try:
            self.log.info(f"Starting command: {' '.join(cmd)}")
            start_time = time.time()
            TIMEOUT = 1200  # 20 minutes in seconds
            process = subprocess.Popen(
                cmd, env=env, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True
            )

            while True:
                output = process.stdout.readline()
                if output:
                    print(output.strip())
                if process.poll() is not None:
                    break
            try:
                stdout, stderr = process.communicate(timeout=TIMEOUT)
            except subprocess.TimeoutExpired:
                process.kill()
                self.log.error(f"Ghidra timed out after {TIMEOUT} seconds")
                # raise subprocess.TimeoutExpired(process.args, TIMEOUT)
                return None
            end_time = time.time()

            self.log.debug(
                f"Command finished. Execution time: {end_time - start_time:.2f} seconds"
            )
            self.log.debug(f"Return code: {process.returncode}")

            if process.returncode != 0:
                self.log.error(f"Error output:\n{stderr}")
                return None
            return stdout
        except Exception as e:
            self.log.error(f"Error running command {' '.join(cmd)}: {e}")
            return None

    def analyze_binary(self):
        self.log.debug(f"Ghidra path: {self.ghidra_path}")
        self.log.debug(f"Binary path: {self.filepath}")
        self.log.debug(f"Java script path: {self.java_script_path}")

        # Check if Java script exists
        if not os.path.exists(self.java_script_path):
            self.log.error(f"Error: Java script not found at {self.java_script_path}")
            return None

        # Set up environment variables
        env = os.environ.copy()
        java_home = "/usr/lib/jvm/java-17-openjdk-amd64"  # Adjust this path if needed
        env["JAVA_HOME"] = java_home
        env["PATH"] = f"{java_home}/bin:{env['PATH']}"
        env["LD_LIBRARY_PATH"] = f"{java_home}/lib:{env.get('LD_LIBRARY_PATH', '')}"
        env["DECOMPILED_FOLDER"] = self.decompiled_folder

        # Print environment variables for debugging
        self.log.debug(f"JAVA_HOME: {env['JAVA_HOME']}")
        self.log.debug(f"PATH: {env['PATH']}")
        self.log.debug(f"LD_LIBRARY_PATH: {env['LD_LIBRARY_PATH']}")

        # Check Ghidra installation
        analyzeHeadless_path = f"{self.ghidra_path}/support/analyzeHeadless"
        self.log.debug(
            f"analyzeHeadless exists: {os.path.exists(analyzeHeadless_path)}"
        )

        # Create a temporary project directory
        project_path = tempfile.gettempdir() + "/ghidra_" + str(uuid.uuid4())
        os.makedirs(project_path, exist_ok=True)
        self.log.debug(f"Created temporary project path: {project_path}")
        output_file = ""

        try:
            # Run Ghidra's headless analyzer
            analyze_cmd = [
                analyzeHeadless_path,
                project_path,
                "TempProject",
                "-import",
                self.filepath,
                "-postScript",
                self.java_script_path,
                self.sha256,
                "-deleteProject",
            ]

            result = self.run_command(analyze_cmd, env=env)
            if result is None:
                return None

            # Read the output JSON file
            output_file = os.path.join(
                self.decompiled_folder, self.sha256 + "-decompiled.json"
            )
            if os.path.exists(output_file):
                with open(output_file, "r") as f:
                    functions = json.load(f)
                return functions
            else:
                self.log.error(
                    f"Output file {output_file} not found. Ghidra analysis may have failed."
                )
                return None
        finally:
            # Clean up
            if os.path.exists(project_path):
                shutil.rmtree(project_path)
                self.log.debug(f"Deleted temporary project path: {project_path}")

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            functions = self.analyze_binary()

            if functions:
                self.log.info(f"Extracted functions from {self.filepath}:")
                for func in functions:
                    id = sha256(func["address"].encode()).hexdigest()
                    self.decompiled = Decompiled(
                        _id=id,
                        decompiled_function_name=func["name"],
                        decompiled_function_address=func["address"],
                        decompiled_function=func["decompiled"],
                    )
                    self.export_to_elastic([self.decompiled])
            else:
                self.log.error("No decompiled functions extracted.")
            return True
        except Exception as e:
            self.log.error(f"Error extracting decompiled information: {e}")
            return None

    def tag(self):
        return Tag.DECOMPILED.value