Nele Noels

52 papers B 3C 1Journal 25Unranked 22
YearRankTypeTitle / Venue / Authors
2024 J jnl
IEEE Trans. Inf. Forensics Secur.
Stefano Tomasin, Tarek N. M. M. Elwakeel, Anna V. Guglielmi, Robin Maes, Nele Noels, Marc Moeneclaey
2024 J jnl
IEEE Access
Sander Cornelis, Nele Noels, Marc Moeneclaey
2023 J jnl
IEEE Access
Sander Cornelis, Nele Noels, Marc Moeneclaey
2022 J jnl
IEEE Trans. Wirel. Commun.
Taoyong Li, Nele Noels, Kamil Yavuz Kapusuz, Sam Lemey, Hendrik Rogier, Heidi Steendam
2021 J jnl
IEEE Trans. Commun.
Carlos Mosquera, Nele Noels, Tomás Ramírez, Màrius Caus, Adriano Pastore
2020 J jnl
Signal Process.
Taoyong Li, Nele Noels, Heidi Steendam
2020 J jnl
Int. J. Satell. Commun. Netw.
Nele Noels, Marc Moeneclaey
2020 conf
VTC Spring
Nele Noels, Marc Moeneclaey, Tomás Ramírez, Carlos Mosquera, Màrius Caus, Adriano Pastore
2020 conf
VTC Spring
Taoyong Li, Nele Noels, Heidi Steendam
2020 conf
ASMS/SPSC
Tomás Ramírez, Carlos Mosquera, Nele Noels, Màrius Caus, Joan Bas, Luis Blanco, Nader Alagha
2019 J jnl
IEEE Trans. Commun.
Vo-Trung-Dung Huynh, Nele Noels, Heidi Steendam
2019 J jnl
CoRR
Carlos Mosquera, Tomás Ramírez, Màrius Caus, Nele Noels, Adriano Pastore
2019 J jnl
Int. J. Satell. Commun. Netw.
Nele Noels, Ignacio Aguilar Sánchez
2018 conf
ICT
Vo-Trung-Dung Huynh, Nele Noels, Heidi Steendam
2018 conf
ISWCS
Màrius Caus, Adriano Pastore, Monica Navarro, Tomás Ramírez, Carlos Mosquera, Nele Noels, Nader Alagha, Ana I. Pérez-Neira
2018 conf
ASMS/SPSC
Tomás Ramírez, Carlos Mosquera, Màrius Caus, Adriano Pastore, Monica Navarro, Nele Noels
2018 J jnl
IEEE Trans. Signal Process.
Nele Noels, Marc Moeneclaey
2018 conf
GlobalSIP
Nele Noels, Marc Moeneclaey, Tomás Ramírez, Carlos Mosquera, Màrius Caus, Adriano Pastore
2017 C conf
APCC
Vo-Trung-Dung Huynh, Nele Noels, Heidi Steendam
2017 conf
ICT
Vo-Trung-Dung Huynh, Nele Noels, Heidi Steendam
2017 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Vo-Trung-Dung Huynh, Nele Noels, Heidi Steendam
2017 conf
ICC
Nele Noels, Marc Moeneclaey
2015 conf
ISWCS
Nele Noels, Jabran Bhatti, Herwig Bruneel, Marc Moeneclaey
2015 conf
SCVT
Vo-Trung-Dung Huynh, Nele Noels, Heidi Steendam
2015 conf
ISWCS
Nele Noels, Marc Moeneclaey
2014 J jnl
IEEE Trans. Commun.
Nele Noels, Jabran Bhatti, Herwig Bruneel, Marc Moeneclaey
2012 J jnl
IEEE Trans. Signal Process.
Nele Noels, Marc Moeneclaey
2012 B conf
WCNC
Nele Noels, Marc Moeneclaey
2011 J jnl
IEEE Trans. Signal Process.
Nele Noels, Marc Moeneclaey, Frederik Simoens, Daniel Delaruelle
2011 conf
ICT
Nele Noels, Marc Moeneclaey, Frederik Simoens, Daniel Delaruelle
2011 B conf
PIMRC
Jabran Bhatti, Nele Noels, Marc Moeneclaey
2009
Nele Noels
2007 J jnl
Proc. IEEE
Cédric Herzet, Nele Noels, Vincenzo Lottici, Henk Wymeersch, Marco Luise, Marc Moeneclaey, Luc Vandendorpe
2007 J jnl
IEEE Trans. Signal Process.
Nele Noels, Heidi Steendam, Marc Moeneclaey
2006 conf
ICC
Erdal Panayirci, Hakan A. Çirpan, Marc Moeneclaey, Nele Noels
2006 conf
EUSIPCO
Erdal Panayirci, Hakan A. Çirpan, Marc Moeneclaey, Nele Noels
2006 conf
ICC
Nele Noels, Heidi Steendam, Marc Moeneclaey
2006 J jnl
Eur. Trans. Telecommun.
Erdal Panayirci, Hakan A. Çirpan, Marc Moeneclaey, Nele Noels
2005 J jnl
EURASIP J. Wirel. Commun. Netw.
Nele Noels, Vincenzo Lottici, Antoine Dejonghe, Heidi Steendam, Marc Moeneclaey, Marco Luise, Luc Vandendorpe
2005 J jnl
EURASIP J. Adv. Signal Process.
Nele Noels, Heidi Steendam, Marc Moeneclaey
2005 J jnl
IEEE Trans. Signal Process.
Nele Noels, Heidi Steendam, Marc Moeneclaey, Herwig Bruneel
2005 J jnl
IEEE Commun. Lett.
Nele Noels, Heidi Steendam, Marc Moeneclaey
2004 conf
ICC
Nele Noels, Heidi Steendam, Marc Moeneclaey
2004 J jnl
IEEE Trans. Commun.
Nele Noels, Heidi Steendam, Marc Moeneclaey
2004 J jnl
IEEE Trans. Commun.
Nele Noels, Henk Wymeersch, Heidi Steendam, Marc Moeneclaey
2003 conf
ICC
Heidi Steendam, Nele Noels, Marc Moeneclaey
2003 J jnl
IEEE Commun. Lett.
Nele Noels, Heidi Steendam, Marc Moeneclaey
2003 conf
ICC
Nele Noels, Heidi Steendam, Marc Moeneclaey
2003 conf
ICC
Nele Noels, Cédric Herzet, Antoine Dejonghe, Vincenzo Lottici, Heidi Steendam, Marc Moeneclaey, Marco Luise, Luc Vandendorpe
2002 conf
EUSIPCO
Nele Noels, Heidi Steendam, Marc Moeneclaey
2002 conf
ICC
Nele Noels, Heidi Steendam, Marc Moeneclaey
2002 B conf
GLOBECOM
Nele Noels, Heidi Steendam, Marc Moeneclaey
redb/extractors/apk_extractors/apk_native_libs.py
← Index redb/extractors/apk_extractors/apk_native_libs.py python
import fnmatch
import hashlib
import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKNativeLib

# Known packer/protector native library names
KNOWN_PACKER_LIBS = {
    # Jiagu (360/Qihoo)
    "libjiagu.so", "libjiagu_a64.so", "libjiagu_x86.so", "libjiagu_x64.so",
    # Bangcle/SecNeo
    "libsecexe.so", "libsecmain.so", "libSecShell.so",
    # Baidu
    "libbaiduprotect.so",
    # Tencent (Legu)
    "libtxAppProtect.so", "libBugly.so",
    # iJiami
    "libexec.so", "libexecmain.so",
    # Alibaba
    "libmobisec.so", "libaliprotect.so",
    # APKProtect
    "libAPKProtect.so",
    # Pangxie (Pangolin)
    "libdexjni.so",
    # DexProtector
    "libdexprotector.so",
    # AppSolid
    "libAppSolid.so",
    # Kiwisec
    "libkwscmm.so",
    # DingXiang
    "libx3g.so",
    # NQ Shield
    "libnqshield.so",
    # Generic / other
    "libprotectClass.so",
    "libDexHelper.so",
    "libdexloader.so",
    "libfdog.so",
}

# Glob-style patterns for packer libs (e.g. libshella-*.so)
KNOWN_PACKER_PATTERNS = [
    "libshella-*.so",
    "libshell-super.*.so",
]


def is_known_packer_lib(filename):
    """Check if a native library filename matches known packer signatures."""
    if filename in KNOWN_PACKER_LIBS:
        return True
    for pattern in KNOWN_PACKER_PATTERNS:
        if fnmatch.fnmatch(filename, pattern):
            return True
    return False


class APKNativeLibExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.native_libs = []
        self.abis = set()
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_NATIVE_LIBS.value

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        self.native_libs = []
        self.abis = set()

        zf = self._get_zip_file()
        if not zf:
            return None

        with zf:
            for info in zf.infolist():
                if not (info.filename.startswith("lib/") and info.filename.endswith(".so")):
                    continue
                parts = info.filename.split("/")
                if len(parts) < 3:
                    continue

                abi = parts[1]
                filename = parts[-1]
                self.abis.add(abi)

                try:
                    data = zf.read(info.filename)
                    lib_sha256 = hashlib.sha256(data).hexdigest()
                except Exception as e:
                    self.log.warning(f"Error reading native lib {info.filename}: {e}")
                    continue

                self.native_libs.append(APKNativeLib(
                    abi=abi,
                    filename=filename,
                    size=info.file_size,
                    sha256=lib_sha256,
                    is_known_packer=is_known_packer_lib(filename),
                ))

        if not self.native_libs:
            return None

        return {
            "native_lib_count": len(self.native_libs),
            "abis": sorted(self.abis),
            "native_libs": self.native_libs,
            "known_packer_libs": [
                lib for lib in self.native_libs if lib.is_known_packer
            ],
        }

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.native_libs:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for lib in self.native_libs:
                data.append([
                    self.sha256,
                    lib.abi,
                    lib.filename,
                    lib.size,
                    lib.sha256,
                    int(lib.is_known_packer),
                    current_time,
                ])

            column_names = [
                'sha256', 'lib_abi', 'lib_filename', 'lib_size',
                'lib_sha256', 'lib_is_known_packer', 'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)', 'LowCardinality(String)', 'String', 'UInt64',
                'FixedString(64)', 'UInt8', "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_native_libs"