Nauman Ullah Gilal

12 papers C 1Journal 4Unranked 7
YearRankTypeTitle / Venue / Authors
2025 J jnl
Vis. Comput.
Nauman Ullah Gilal, Marwa K. Qaraqe, Jens Schneider, Marco Agus
2025 conf
CVPR Workshops
Nauman Ullah Gilal, Khaled A. Al-Thelaya, Fahad Majeed, Zhihe Lu, Sabri Boughorbel, Jens Schneider, Marco Agus
2025 J jnl
Comput. Biol. Medicine
Zahoor Ahmad, Khaled A. Al-Thelaya, Mahmood Alzubaidi, Faaiz Joad, Nauman Ullah Gilal, William Mifsud, Sabri Boughorbel, Giovanni Pintore, Enrico Gobbetti, Jens Schneider, Marco Agus
2025 conf
VISIGRAPP (2): VISAPP
Fahad Majeed, Khaled Ahmed Lutf Al Thelaya, Nauman Ullah Gilal, Kamilla Swart-Arries, Marco Agus, Jens Schneider
2024 J jnl
Multim. Tools Appl.
Nauman Ullah Gilal, Khaled A. Al-Thelaya, Jumana Khalid Al-Saeed, Mohamed Abdallah, Jens Schneider, James She, Jawad Hussain Awan, Marco Agus
2024 conf
CVPR Workshops
Fahad Majeed, Nauman Ullah Gilal, Khaled A. Al-Thelaya, Yin Yang, Marco Agus, Jens Schneider
2023 conf
EFMI-STC
Mahmood Alzubaidi, Nauman Ullah Gilal, Fahad Alshagathrh, Marco Agus, Mowafa S. Househ
2023 C conf
ISNCC
Nauman Ullah Gilal, Fahad Majeed, Khaled A. Al-Thelaya, Mehak Khan, Jens Schneider, Marco Agus
2022 conf
VCBM
Khaled A. Al-Thelaya, Faaiz Joad, Nauman Ullah Gilal, William Mifsud, Giovanni Pintore, Enrico Gobbetti, Marco Agus, Jens Schneider
2021 J jnl
Comput. Graph.
Khaled A. Al-Thelaya, Marco Agus, Nauman Ullah Gilal, Yin Yang, Giovanni Pintore, Enrico Gobbetti, Corrado Calì, Pierre J. Magistretti, William Mifsud, Jens Schneider
2021 conf
CAA SAFEPROCESS
Ar Junejo, Xiang Li, Minglei Li, Nauman Ullah Gilal
2021 conf
STAG
Nauman Ullah Gilal, Khaled A. Al-Thelaya, Jens Schneider, James She, Marco Agus
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"