Nave Frost

42 papers A* 6A 3B 6Journal 22Unranked 4
YearRankTypeTitle / Venue / Authors
2026 B conf
EDBT
Yael Einy, Guy Dar, Slava Novgorodov, Tova Milo, Nave Frost
2026 B conf
EDBT
Avia Asael, Nave Frost, Amir Gilad, Daniel Deutch
2025 J jnl
CoRR
Omer Abramovich, Daniel Deutch, Nave Frost, Ahmet Kara, Dan Olteanu
2025 J jnl
Proc. VLDB Endow.
Omer Abramovich, Daniel Deutch, Nave Frost, Ahmet Kara, Dan Olteanu
2025 J jnl
CoRR
Matan Ben-Tov, Daniel Deutch, Nave Frost, Mahmood Sharif
2024 J jnl
Proc. ACM Manag. Data
Omer Abramovich, Daniel Deutch, Nave Frost, Ahmet Kara, Dan Olteanu
2024 A* conf
SP
Matan Ben-Tov, Daniel Deutch, Nave Frost, Mahmood Sharif
2024 J jnl
Proc. VLDB Endow.
Roni Copul, Nave Frost, Tova Milo, Kathy Razmadze
2024 B conf
EDBT
Aviv Ben-Arie, Daniel Deutch, Nave Frost, Yair Horesh, Idan Meyuhas
2024 B conf
ALT
Nave Frost, Zachary C. Lipton, Yishay Mansour, Michal Moshkovitz
2024 B conf
EDBT
Dana Arad, Daniel Deutch, Nave Frost
2024 J jnl
Proc. ACM Manag. Data
Roni Copul, Nave Frost, Tova Milo, Kathy Razmadze
2023 J jnl
CoRR
Omer Abramovich, Daniel Deutch, Nave Frost, Ahmet Kara, Dan Olteanu
2022 conf
SIGMOD Conference
Daniel Deutch, Nave Frost, Benny Kimelfeld, Mikaël Monet
2022 A* conf
ICML
Sanjoy Dasgupta, Nave Frost, Michal Moshkovitz
2022 J jnl
CoRR
Sanjoy Dasgupta, Nave Frost, Michal Moshkovitz
2022 A conf
CIKM
Dana Arad, Daniel Deutch, Nave Frost
2022 conf
SIGMOD Conference
Susan B. Davidson, Daniel Deutch, Nave Frost, Benny Kimelfeld, Omer Koren, Mikaël Monet
2022
Nave Frost
2021 J jnl
CoRR
Daniel Deutch, Nave Frost, Benny Kimelfeld, Mikaël Monet
2021 A conf
CIKM
Daniel Deutch, Nave Frost, Amir Gilad, Oren Sheffer
2021 conf
ML4H@NeurIPS
Ilya Valmianski, Nave Frost, Navdeep Sood, Yang Wang, Baodong Liu, James J. Zhu, Sunil Karumuri, Ian M. Finn, Daniel S. Zisook
2020 J jnl
CoRR
Nave Frost, Michal Moshkovitz, Cyrus Rashtchian
2020 A* conf
ICML
Michal Moshkovitz, Sanjoy Dasgupta, Cyrus Rashtchian, Nave Frost
2020 J jnl
CoRR
Sanjoy Dasgupta, Nave Frost, Michal Moshkovitz, Cyrus Rashtchian
2020 B conf
EDBT
Daniel Deutch, Nave Frost, Amir Gilad, Tomer Haimovich
2020 J jnl
CoRR
Daniel Deutch, Nave Frost, Amir Gilad
2020 J jnl
VLDB J.
Daniel Deutch, Nave Frost, Amir Gilad
2020 J jnl
CoRR
Naama Boer, Daniel Deutch, Nave Frost, Tova Milo
2020 J jnl
Proc. VLDB Endow.
Nave Frost, Naama Boer, Daniel Deutch, Tova Milo
2020 J jnl
CoRR
Ilya Valmianski, Ian M. Finn, Nave Frost, Yang Wang, Baodong Liu, James J. Zhu, Sunil Karumuri, Daniel S. Zisook
2020 conf
SIGMOD Conference
Daniel Deutch, Nave Frost, Amir Gilad, Oren Sheffer
2020 J jnl
CoRR
Daniel Deutch, Nave Frost, Amir Gilad, Oren Sheffer
2019 A* conf
ICDE
Daniel Deutch, Nave Frost
2019 A* conf
ICDE
Nave Frost
2019 A* conf
ICDE
Naama Boer, Daniel Deutch, Nave Frost, Tova Milo
2018 A conf
CIKM
Daniel Deutch, Nave Frost
2018 J jnl
Proc. VLDB Endow.
Daniel Deutch, Nave Frost, Amir Gilad, Tomer Haimovich
2018 J jnl
SIGMOD Rec.
Daniel Deutch, Nave Frost, Amir Gilad
2018 J jnl
IEEE Data Eng. Bull.
Daniel Deutch, Nave Frost, Amir Gilad
2017 J jnl
Proc. VLDB Endow.
Daniel Deutch, Nave Frost, Amir Gilad
2016 J jnl
Proc. VLDB Endow.
Daniel Deutch, Nave Frost, Amir Gilad
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));