Navid Vafamand

45 papers C 3Journal 41Unranked 1
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Trans. Consumer Electron.
Mohammad Hossein Badiei, Saeed Mohammadi Dashtaki, Navid Vafamand, Md. Jalil Piran
2023 J jnl
IEEE Syst. J.
Navid Vafamand, Mohammad Mehdi Arefi, Amjad Anvari-Moghaddam
2023 J jnl
IEEE Trans. Aerosp. Electron. Syst.
Zhaoyang Zuo, Navid Vafamand, Saleh Mobayen, Tomislav Dragicevic
2023 J jnl
Int. J. Control
Fatemeh Sedghi, Shekoufeh Neisarian, Mohammad Mehdi Arefi, Mohammad Hassan Asemani, Navid Vafamand
2022 J jnl
Trans. Inst. Meas. Control
Reza Rouhi Ardeshiri, Meysam Gheisarnejad, Mohammad-Reza Tavana, Navid Vafamand, Mohammad Hassan Khooban
2022 J jnl
IEEE Access
Soroush Azizi, Mohammad Hassan Asemani, Navid Vafamand, Saleh Mobayen, Afef Fekih
2022 J jnl
Neural Comput. Appl.
Mehdi Mohammadi, Mohammad Mehdi Arefi, Navid Vafamand, Okyay Kaynak
2022 J jnl
IEEE Trans. Ind. Electron.
Navid Vafamand, Mohammad Mehdi Arefi, Mohammad Hassan Asemani, Tomislav Dragicevic
2022 J jnl
IEEE Trans. Syst. Man Cybern. Syst.
Sepide Yazdi, Alireza Khayatian, Mohammad Hassan Asemani, Navid Vafamand
2022 J jnl
IEEE Trans. Instrum. Meas.
Arezoo Vafamand, Behzad Moshiri, Navid Vafamand
2022 J jnl
IEEE Trans. Ind. Electron.
Zahra Sadat Khalafi, Maryam Dehghani, Abdullah Khalili, Ashkan Sami, Navid Vafamand, Tomislav Dragicevic
2022 J jnl
Comput. Electr. Eng.
Khashayar Torabi Farsani, Navid Vafamand, Roozbeh Razavi-Far, Mehrdad Saif
2021 J jnl
Complex.
Soroush Azizi, Mohammad Hassan Asemani, Navid Vafamand, Saleh Mobayen, Mohammad Hassan Khooban
2021 C conf
IAS
Navid Vafamand, Mohammad Mehdi Arefi, Mohammad Hassan Asemani, Mohammad Sadegh Javadi, Fei Wang, João P. S. Catalão
2021 C conf
IAS
Khashayar Torabi Farsani, Maryam Dehghani, Rouzbeh Abolpour, Navid Vafamand, Mohammad Sadegh Javadi, Fei Wang, João P. S. Catalão
2021 J jnl
IEEE Trans. Ind. Electron.
Arezoo Vafamand, Navid Vafamand, Jafar Zarei, Roozbeh Razavi-Far, Tomislav Dragicevic
2021 J jnl
Biomed. Signal Process. Control.
Arezoo Vafamand, Navid Vafamand, Jafar Zarei, Roozbeh Razavi-Far, Mehrdad Saif
2021 J jnl
IEEE Access
Mohammad Saeid Akbari, Mohammad Hassan Asemani, Navid Vafamand, Saleh Mobayen, Afef Fekih
2021 J jnl
IEEE Access
Navid Vafamand, Mohammad Hassan Asemani, Saleh Mobayen, Gisela Pujol-Vázquez
2020 J jnl
IEEE Trans. Aerosp. Electron. Syst.
Navid Vafamand
2020 J jnl
IEEE Syst. J.
Navid Vafamand, Mohammad Hassan Asemani, Tomislav Dragicevic, Frede Blaabjerg, Mohammad Hassan Khooban
2020 J jnl
J. Frankl. Inst.
Behrouz Homayoun, Mohammad Mehdi Arefi, Navid Vafamand, Shen Yin
2020 J jnl
J. Frankl. Inst.
Behrouz Homayoun, Mohammad Mehdi Arefi, Navid Vafamand, Shen Yin
2020 J jnl
Soft Comput.
Reza Rouhi Ardeshiri, Mohammad Hassan Khooban, Amin Noshadi, Navid Vafamand, Mohsen Rakhshan
2020 J jnl
IEEE Trans. Syst. Man Cybern. Syst.
Navid Vafamand, Mohammad Hassan Asemani, Alireza Khayatiyan, Mohammad Hassan Khooban, Tomislav Dragicevic
2019 J jnl
IEEE Syst. J.
Navid Vafamand, Shirin Yousefizadeh, Mohammad Hassan Khooban, Jan Dimon Bendtsen, Tomislav Dragicevic
2019 J jnl
IEEE Trans. Ind. Electron.
Mohammad Mehdi Mardani, Navid Vafamand, Mohammad Hassan Khooban, Tomislav Dragicevic, Frede Blaabjerg
2019 J jnl
IEEE Trans. Intell. Veh.
Mohammad Hassan Khooban, Meysam Gheisarnejad, Navid Vafamand, Jalil Boudjadar
2019 J jnl
Biomed. Signal Process. Control.
Bahare Farahmand, Maryam Dehghani, Navid Vafamand
2019 J jnl
Inf. Technol. Control.
Kazem Zare, Mohammad Mehdi Mardani, Navid Vafamand, Mohammad Hassan Khooban, Sajjad Shamsi Sadr, Tomislav Dragicevic
2019 J jnl
IEEE Trans. Ind. Electron.
Navid Vafamand, Mohammad Hassan Khooban, Tomislav Dragicevic, Frede Blaabjerg
2019 J jnl
Trans. Inst. Meas. Control
Mohammad Mehdi Mardani, Navid Vafamand, Mohammad Hassan Khooban, Tomislav Dragicevic, Frede Blaabjerg
2019 J jnl
Trans. Inst. Meas. Control
Mohsen Rakhshan, Navid Vafamand, Mohammad Mehdi Mardani, Mohammad Hassan Khooban, Tomislav Dragicevic
2019 J jnl
IEEE Syst. J.
Mohammad Hassan Khooban, Meysam Gheisarnejad, Navid Vafamand, Mohammad Jafari, Saleh Mobayen, Tomislav Dragicevic, Jalil Boudjadar
2019 J jnl
IEEE Syst. J.
Navid Vafamand, Mohammad Hassan Khooban, Tomislav Dragicevic, Jalil Boudjadar, Mohammad Hassan Asemani
2019 J jnl
Complex.
Mohammad Hassan Khooban, Navid Vafamand, Jalil Boudjadar
2019 J jnl
IEEE Trans. Ind. Electron.
Shirin Yousefizadeh, Jan Dimon Bendtsen, Navid Vafamand, Mohammad Hassan Khooban, Frede Blaabjerg, Tomislav Dragicevic
2018 C conf
IECON
Navid Vafamand, Shirin Yousefizadeh, Mohammad Hassan Khooban, Jan Dimon Bendtsen, Tomislav Dragicevic
2018 conf
EECS
Shirin Yousefizadeh, Navid Vafamand, Jan Dimon Bendtsen, Mohammad Hassan Khooban, Frede Blaabjerg, Tomislav Dragicevic
2018 J jnl
IEEE Trans. Fuzzy Syst.
Navid Vafamand, Mohammad Hassan Asemani, Alireza Khayatian
2018 J jnl
Int. J. Syst. Sci.
Navid Vafamand, S. Vahid Naghavi, Ali Akbar Safavi, Alireza Khayatian, Mohammad Hassan Khooban, Tomislav Dragicevic
2017 J jnl
J. Frankl. Inst.
Navid Vafamand, Mohammad Hassan Asemani, Alireza Khayatian
2016 J jnl
Eng. Appl. Artif. Intell.
Navid Vafamand, Mohammad Hassan Asemani, Alireza Khayatiyan
2016 J jnl
Int. J. Autom. Control.
Mohsen Rakhshan, Navid Vafamand, Mokhtar Shasadeghi, Morteza Dabbaghjamanesh, Amirhossein Moeini
2016 J jnl
J. Frankl. Inst.
Mokhtar Sha Sadeghi, Navid Vafamand, Mohammad Hassan Khooban
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"