Nell B. Dale

47 papers A 24B 3Journal 13Unranked 6
YearRankTypeTitle / Venue / Authors
2018 J jnl
Inroads
Nell B. Dale
2010 A conf
SIGCSE
David G. Kay, Kim B. Bruce, Michael J. Clancy, Nell B. Dale, Mark Guzdial, Eric Roberts
2009 A conf
SIGCSE
Nell B. Dale, Andrew D. McGettrick, John Impagliazzo, Robert M. Aiken, Elliot B. Koffman, Jim Leisy
2006 J jnl
ACM SIGCSE Bull.
Nell B. Dale
2005 J jnl
ACM SIGCSE Bull.
Vicki L. Almstrum, Lecia Jane Barker, Barbara Boucher Owens, Elizabeth S. Adams, William Aspray, Nell B. Dale, Wanda P. Dann, Andrea Lawrence, Leslie Schwartzman
2005 J jnl
ACM SIGCSE Bull.
Nell B. Dale
2002 B conf
ITiCSE
Nell B. Dale, Judith Bishop, David J. Barnes, Christoph W. Keßler
2002 J jnl
ACM SIGCSE Bull.
Nell B. Dale
2001 J jnl
ACM SIGCSE Bull.
Nell B. Dale
2001 J jnl
Comput. Sci. Educ.
Mike Clancy, John T. Stasko, Mark Guzdial, Sally Fincher, Nell B. Dale
2001 A conf
SIGCSE
John T. Stasko, Mark Guzdial, Michael J. Clancy, Nell B. Dale, Sally Fincher
2001 A conf
SIGCSE
Nell B. Dale, Rick Mercer, Elliot B. Koffman, Walter J. Savitch
2000 A ed.
SIGCSE
Lillian (Boots) Cassel, Nell B. Dale, Henry MacKay Walker, Susan M. Haller
2000 J jnl
ACM SIGCSE Bull.
Nell B. Dale
2000 A conf
SIGCSE
Renée A. McCauley, Nell B. Dale, Thomas B. Hilburn, Susan A. Mengel, Branson W. Murrill
1999 J jnl
ACM SIGCSE Bull.
Nell B. Dale
1999 conf
ITiCSE-WGR
Nell B. Dale
1999 conf
ITiCSE-WGR
Nell B. Dale
1999 conf
ITiCSE-WGR
Deborah Knox, Don Goelman, Sally Fincher, James Hightower, Nell B. Dale, Ken Loose, Elizabeth S. Adams, Frederick N. Springsteel
1998 A conf
SIGCSE
Cheng-Chih Wu, Nell B. Dale, Lowell J. Bethel
1998 A conf
SIGCSE
Daniel D. McCracken, A. Michael Berman, Ursula Wolz, Owen L. Astrachan, Nell B. Dale
1998 J jnl
ACM SIGCSE Bull.
Nell B. Dale
1998 J jnl
ACM SIGCSE Bull.
Nell B. Dale
1997 A conf
SIGCSE
Richard A. Howard, Lisa C. Kaczmarczyk, Frederick N. Springsteel, Nell B. Dale
1996 B conf
ITiCSE
Vicki L. Almstrum, Nell B. Dale, Anders Berglund, Mary J. Granger, Joyce Currie Little, Diane M. Miller, Marian Petre, Paul Schragger, Frederick N. Springsteel
1995 A conf
SIGCSE
Renée A. McCauley, Clark B. Archer, Nell B. Dale, Rym Mili, James Robergé, Harriet G. Taylor
1994 A conf
SIGCSE
James Caristi, Nell B. Dale, Bill Marion, A. Joe Turner
1993 A conf
SIGCSE
Angel Syang, Nell B. Dale
1993 A conf
SIGCSE
Barry L. Kurtz, Nell B. Dale, Jerry Engel, Jim Miller, Keith Barker, Harriet G. Taylor
1992 J jnl
Comput. Sci. Educ.
Nell B. Dale, Henry M. Walker
1992 A ed.
SIGCSE
Nell B. Dale
1992 J jnl
ACM SIGCSE Bull.
Nell B. Dale
1991 A ed.
SIGCSE
Nell B. Dale
1990 A conf
SIGCSE
Nell B. Dale
1990 A conf
SIGCSE
Virginia Eaton, Sharon Bell, Nell B. Dale, Susie Gallagher, Helen M. Gigley, Cindy Hanchey
1986 conf
ACM Conference on Computer Science
Sharon Cogdill, Pamela S. Kirshen, J. Mack Adams, John Beidler, Nell B. Dale, Malcolm G. Lane, Karen A. Lemone, James Quasney, Don Spencer
1984 A conf
SIGCSE
Karen Wieckert, Nell B. Dale
1982 A conf
SIGCSE
Nell B. Dale, David Orshalick
1981 A conf
SIGCSE
Tom E. Bredt, Charles Lobb, Nell B. Dale, Ez Nahouraii
1981 A ed.
SIGCSE
Kenneth I. Magel, Frank Garnet Walters, Nell B. Dale
1980 A conf
SIGCSE
Nell B. Dale
1980 A conf
SIGCSE
Nell B. Dale, Victor Wallace, Clair Maple, Larry Loos, William G. Bulgren
1978 A conf
SIGCSE
Nell B. Dale
1978 ed.
Eugene I. Lowenthal, Nell B. Dale
1977 conf
SIGMOD Conference
Alfred G. Dale, Nell B. Dale
1976 conf
SIGMOD Conference
Alfred G. Dale, Nell B. Dale
1965 B conf
COLING
Eugene D. Pendergraft, Nell B. Dale
redb/extractors/pe_extractors/pe_sections.py
← Index redb/extractors/pe_extractors/pe_sections.py python
import base64
import hashlib
import inspect
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PESection
from datetime import datetime, timezone
from typing import Any


class PESectionExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_sections"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_SECTION.value

    def _extract_sections(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        sections = []
        for section in self.pe.sections:
            try:
                name = self.process_binary_string(section.Name)
            except Exception as e:
                name = "UnableToDecode"
                self.log.warning(
                    f'Unable to store section Name "{section.Name}" for {self.hash.sha256}'
                    f" exception {e}"
                )
            sec_sha256 = section.get_hash_sha256()
            sec_md5 = section.get_hash_md5()
            # sec_entropy = "%.2f" % section.get_entropy()
            sec_entropy = section.get_entropy()
            pe_section = PESection(
                _id=hashlib.sha256(
                    name.encode()
                ).hexdigest(),  # usecase 8e035beb02a411f8a9e92d4cf184ad34f52bbd0a81a50c222cdd4706e4e45104, all section have same sha256
                section_name=name,
                section_name_b64=base64.b64encode(
                    section.Name.rstrip(b'\x00')
                ).decode(),  # base64.b64decode(b64) to decode
                section_v_addr=section.VirtualAddress,
                section_v_addr_hex=hex(section.VirtualAddress),
                section_v_size=section.Misc_VirtualSize,
                section_size=section.SizeOfRawData,
                section_pointer_to_raw_data=hex(section.PointerToRawData),
                section_md5=sec_md5,
                section_sha256=sec_sha256,
                section_entropy=sec_entropy,
            )
            sections.append(pe_section)
        return sections

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            sections = self._extract_sections()
            # self.export_to_elastic(sections)  # Let the exporters handle this
            return sections
        except Exception as e:
            self.log.error(f"Error extracting PE sections: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            sections = self.extract()
            if sections is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for section in sections:
                data.append([
                    self.sha256,                          # sha256
                    self.md5,                             # md5
                    self.sha1,                            # sha1
                    section.section_name,                 # section_name
                    section.section_name_b64,             # section_name_b64
                    section.section_entropy,              # section_entropy
                    section.section_sha256,               # section_sha256
                    section.section_md5,                  # section_md5
                    section.section_size,                 # section_size
                    section.section_v_addr,               # section_v_addr
                    section.section_v_size,               # section_v_size
                    int(section.section_pointer_to_raw_data, 16),  # section_pointer_to_raw_data - convert from hex
                    current_time                          # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'section_name', 'section_name_b64',
                'section_entropy', 'section_sha256', 'section_md5', 'section_size',
                'section_v_addr', 'section_v_size', 'section_pointer_to_raw_data',
                'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(String)', 'LowCardinality(String)',
                'Float64', 'FixedString(64)', 'FixedString(32)', 'UInt64',
                'UInt64', 'UInt64', 'UInt64',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_sections"