Oddur Benediktsson

16 papers B 2Journal 9Unranked 5
YearRankTypeTitle / Venue / Authors
2007 conf
History of Nordic Computing
Oddur Benediktsson
2007 conf
History of Nordic Computing
Reino Kurki-Suonio, Oddur Benediktsson, Janis A. Bubenko Jr., Ingemar Dahlstrand, Christian Gram, John Impagliazzo
2006 J jnl
IEE Proc. Softw.
Oddur Benediktsson, Darren Dalcher, Helgi Thorbergsson
2005 J jnl
Softw. Qual. J.
Edwin M. Gray, Alberto Sampaio, Oddur Benediktsson
2005 J jnl
Softw. Process. Improv. Pract.
Oddur Benediktsson
2005 conf
ECBS
Darren Dalcher, Oddur Benediktsson, Helgi Thorbergsson
2005 J jnl
IEE Proc. Softw.
Oddur Benediktsson, Darren Dalcher
2004 B conf
EuroSPI
Oddur Benediktsson, Darren Dalcher
2003 J jnl
Softw. Qual. J.
Oddur Benediktsson, Darren Dalcher, Karl Reed, Mark Woodman
2003 conf
History of Nordic Computing
Oddur Benediktsson, Jóhann Gunnarsson, Egill B. Hreinsson, Jakob Jakobsson, Örn Kaldalóns, Óttar Kjartansson, Ólafur Rósmundsson, Helgi Sigvaldason, Gunnar Stefansson, Jón Zophoniasson
2003 conf
History of Nordic Computing
Oddur Benediktsson
2003 J jnl
IEE Proc. Softw.
Oddur Benediktsson, Darren Dalcher
2001 J jnl
Softw. Process. Improv. Pract.
Oddur Benediktsson, Robin B. Hunter, Andrew D. McGettrick
1998 B conf
ITiCSE
Nancy R. Mead, Thomas B. Hilburn, Donald J. Bagert, Michael Ryan, Oddur Benediktsson, Frances L. Van Scoy
1978 J jnl
ACM SIGPLAN Notices
Oddur Benediktsson
1977 J jnl
Softw. Pract. Exp.
Oddur Benediktsson
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"