Oihana Otaegui

47 papers B 1C 3Journal 22Unranked 21
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Paola Natalia Cañas, Marcos Nieto, Oihana Otaegui, Igor Rodríguez
2024 J jnl
Proc. ACM Comput. Graph. Interact. Tech.
Nerea Aranjuelo, Siyu Huang, Ignacio Arganda-Carreras, Luis Unzueta, Oihana Otaegui, Hanspeter Pfister, Donglai Wei
2024 J jnl
CoRR
Nerea Aranjuelo, Siyu Huang, Ignacio Arganda-Carreras, Luis Unzueta, Oihana Otaegui, Hanspeter Pfister, Donglai Wei
2023 J jnl
SN Comput. Sci.
Nerea Aranjuelo, Jose Luis Apellaniz, Luis Unzueta, Jorge García, Sara García, Unai Elordi, Oihana Otaegui
2022 J jnl
CoRR
Gorka Vélez, Edoardo Bonetto, Daniele Brevi, Ángel Martín, Gianluca Rizzi, Oscar Castañeda, Arslane Hamza Cherif, Marcos Nieto, Oihana Otaegui
2022 conf
IST
Ioannis Kontopodis, Francisco Javier Iriarte, Peter Leskovský, Jorge García, Oihana Otaegui
2022 J jnl
Sensors
Juan Diego Ortega, Paola Cañas, Marcos Nieto, Oihana Otaegui, Luis Salgado
2022 conf
IST
Jingwen Yang, Peter Leskovský, Andoni Cortés, Jorge García, Oihana Otaegui
2022 J jnl
CoRR
Djibrilla Amadou Kountché, Fatma Raissi, Mandimby N. Ranaivo Rakotondravelona, Edoardo Bonetto, Daniele Brevi, Ángel Martín, Oihana Otaegui, Gorka Vélez
2022 J jnl
CoRR
Marcos Nieto, Mikel García, Itziar Urbieta, Oihana Otaegui
2022 J jnl
CoRR
Paola Natalia Cañas, Juan Diego Ortega, Marcos Nieto, Oihana Otaegui
2021 C conf
IJCCI
Nerea Aranjuelo, Guus Engels, David Montero, Marcos Nieto, Ignacio Arganda-Carreras, Luis Unzueta, Oihana Otaegui
2021 J jnl
IEEE Softw.
Unai Elordi, Luis Unzueta, Jon Goenetxea, Sergio Sanchez-Carballido, Ignacio Arganda-Carreras, Oihana Otaegui
2021 conf
VISIGRAPP (5: VISAPP)
Nerea Aranjuelo, Jorge García, Luis Unzueta, Sara García, Unai Elordi, Oihana Otaegui
2021 conf
VISIGRAPP (5: VISAPP)
Paola Cañas, Juan Diego Ortega, Marcos Nieto, Oihana Otaegui
2021 conf
VISIGRAPP (5: VISAPP)
Jon Goenetxea, Luis Unzueta, Unai Elordi, Oihana Otaegui, Fadi Dornaika
2021 J jnl
Comput. Electr. Eng.
Nerea Aranjuelo, Sara García, Estíbaliz Loyo, Luis Unzueta, Oihana Otaegui
2021 B conf
AVSS
Itziar Sagastiberri, Noud van de Gevel, Jorge García, Oihana Otaegui
2021 conf
VISIGRAPP (5: VISAPP)
David Montero, Luis Unzueta, Jon Goenetxea, Nerea Aranjuelo, Estíbaliz Loyo, Oihana Otaegui, Marcos Nieto
2021 conf
VISIGRAPP (4: VISAPP)
Unai Elordi, Luis Unzueta, Jon Goenetxea, Estíbaliz Loyo, Ignacio Arganda-Carreras, Oihana Otaegui
2021 conf
ICCTA
David Eneko Ruiz de Gauna, Eider Irigoyen, Iñaki Cejudo, Harbil Arregui, Peter Leskovský, Oihana Otaegui
2020 J jnl
CoRR
Guus Engels, Nerea Aranjuelo, Ignacio Arganda-Carreras, Marcos Nieto, Oihana Otaegui
2020 C conf
VEHITS
Guus Engels, Nerea Aranjuelo, Ignacio Arganda-Carreras, Marcos Nieto, Oihana Otaegui
2020 conf
ROBOVIS
Luis Unzueta, Sandra Garcia, Jorge García, Valentin Corbin, Nerea Aranjuelo, Unai Elordi, Oihana Otaegui, Maxime Danielli
2020 J jnl
CoRR
Juan Diego Ortega, Neslihan Kose, Paola Cañas, Min-An Chao, Alexander Unnervik, Marcos Nieto, Oihana Otaegui, Luis Salgado
2020 conf
ECCV Workshops (4)
Juan Diego Ortega, Neslihan Kose, Paola Cañas, Min-An Chao, Alexander Unnervik, Marcos Nieto, Oihana Otaegui, Luis Salgado
2020 conf
ICGDA
Harbil Arregui, Oihana Otaegui, Olatz Arbelaitz
2020 J jnl
Multim. Tools Appl.
Jon Goenetxea, Luis Unzueta, Fadi Dornaika, Oihana Otaegui
2020 conf
SOCO
Nerea Aranjuelo, Guus Engels, Luis Unzueta, Ignacio Arganda-Carreras, Marcos Nieto, Oihana Otaegui
2020 C conf
VEHITS
Juan Diego Ortega, Marcos Nieto, Luis Salgado, Oihana Otaegui
2020 J jnl
IEEE Intell. Transp. Syst. Mag.
Benedict Flade, Axel Koppert, Gorka Vélez, Anweshan Das, David Bétaille, Gijs Dubbelman, Oihana Otaegui, Julian Eggert
2019 J jnl
IEEE Access
Harbil Arregui, Andoni Mujika, Estíbaliz Loyo, Gorka Vélez, Michael Taynnan Barros, Oihana Otaegui
2019 conf
Web3D
Andoni Mujika, Ana Dominguez Fanlo, Iñigo Tamayo, Orti Senderos, Javier Barandiarán, Nerea Aranjuelo, Marcos Nieto, Oihana Otaegui
2018 conf
EUSIPCO
Marcos Nieto, Lorena Garcia, Orti Senderos, Oihana Otaegui
2018 conf
AMDO
Unai Elordi, Luis Unzueta, Ignacio Arganda-Carreras, Oihana Otaegui
2018 conf
AMDO
Nerea Aranjuelo, Luis Unzueta, Ignacio Arganda-Carreras, Oihana Otaegui
2016 conf
Nets4Cars/Nets4Trains/Nets4Aircraft
Gorka Vélez, Marco Quartulli, Ángel Martín, Oihana Otaegui, Haytham Assem
2016 J jnl
J. Real Time Image Process.
Marcos Nieto, Andoni Cortés, Oihana Otaegui, Jon Arróspide Laborda, Luis Salgado
2015 J jnl
J. Real Time Image Process.
Gorka Vélez, Ainhoa Cortés, Marcos Nieto, Igone Vélez, Oihana Otaegui
2015 J jnl
J. Real Time Image Process.
Leonardo De-Maeztu, Unai Elordi, Marcos Nieto, Javier Barandiarán, Oihana Otaegui
2015 J jnl
CoRR
Gorka Vélez, Oihana Otaegui
2014 conf
ICCHP (2)
Eduardo Carrasco, Estíbaliz Loyo, Oihana Otaegui, Claudia Fösleitner, Markus Dubielzig, Rafael Olmedo, Wolfgang Wasserburger, John Spiller
2012 J jnl
IEEE Trans. Intell. Transp. Syst.
Luis Unzueta, Marcos Nieto, Andoni Cortés, Javier Barandiarán, Oihana Otaegui, Pedro J. Sánchez
2012 conf
VISAPP (2)
Marcos Nieto, Andoni Cortés, Oihana Otaegui, Iñigo Etxabe
2012 conf
VISIGRAPP (Selected Papers)
Marcos Nieto, Andoni Cortés, Javier Barandiarán, Oihana Otaegui, Iñigo Etxabe
2011 conf
VISAPP
Marcos Nieto, Luis Unzueta, Andoni Cortés, Javier Barandiarán, Oihana Otaegui, Pedro J. Sánchez
2011 J jnl
EURASIP J. Adv. Signal Process.
Marcos Nieto, Luis Unzueta, Javier Barandiarán, Andoni Cortés, Oihana Otaegui, Pedro J. Sánchez
redb/extractors/js_extractor.py
← Index redb/extractors/js_extractor.py python
import logging
import re
from abc import ABCMeta, abstractmethod

from redb.extractors.extractor import Extractor
from redb.extractors.js_extractors.js_context import JSContext, _text_entropy

logger = logging.getLogger(__name__)

# ESM is recognised by line-anchored `import ... from "..."` / bare side-effect
# `import "..."` / top-level `export ...`. Anchored at line start to avoid
# matching the substring inside string literals or comments.
_ESM_PATTERN = re.compile(
    r'(?m)^\s*(?:'
    r'import\s+[^;\n]*?\bfrom\s+[\'"]'
    r'|import\s+[\'"][^\'"]+[\'"]'
    r'|export\s+(?:default\b|\{|\*|const\b|let\b|var\b|function\b|class\b|async\b)'
    r')'
)


@abstractmethod
class JSExtractor(Extractor, metaclass=ABCMeta):
    """Base class for JavaScript file extractors.

    Every JSExtractor reads its raw materials (bytes / decoded source / line
    list / scan_source results / pyjsparser AST / text entropy) from a shared
    `JSContext`. When workers.py drives the JS pipeline it builds one context
    per sample and threads it into every extractor via `context=`. When tests
    or other callers instantiate an extractor directly, the constructor builds
    a fresh context from `(filepath, source=...)`.

    All historical instance attributes (`self.binary`, `self.js_source`,
    `self.lines`) and helpers (`self._decode_source`, `self._parse_ast`,
    `self._calculate_text_entropy`) are preserved as thin delegators so
    existing extractor code keeps working unchanged.
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        known_benign=False,
        known_malicious=False,
        source=None,
        context=None,
    ):
        if context is None:
            context = JSContext.from_path(filepath, log=log, source=source)
        elif source is not None and context.source != source:
            log.warning(
                "JSExtractor received both `source=` and `context=` with "
                "differing source; ignoring source kwarg"
            )
        self._context = context

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            known_benign=known_benign,
            known_malicious=known_malicious,
        )

    @property
    def binary(self):
        return self._context.raw_bytes

    @property
    def js_source(self):
        return self._context.source

    @property
    def lines(self):
        return self._context.lines

    def _decode_source(self):
        """Back-compat shim — the context already decoded once at construction.

        Kept so any external caller using the historical method name keeps
        working without touching the underlying bytes again.
        """
        return self._context.source

    def _parse_ast(self):
        """Return the shared pyjsparser AST (or None if unavailable)."""
        return self._context.ast

    def _calculate_text_entropy(self, text):
        """Shannon text entropy for `text`.

        When `text` is the context's own source we read the cached value;
        otherwise we compute fresh. JSStringsExtractor calls this on arbitrary
        decoded substrings, so the fresh-compute path must remain available.
        """
        if text is self._context.source:
            return self._context.text_entropy
        return _text_entropy(text)

    def _detect_environment(self):
        """Detect the target JS runtime environment."""
        src = self.js_source
        if not src:
            return "unknown"

        # WScript/WSH indicators
        wscript_patterns = [
            'WScript.', 'WSH.', 'ActiveXObject', 'Scripting.FileSystemObject',
            'WScript.Shell', 'ADODB.Stream',
        ]
        for p in wscript_patterns:
            if p in src:
                return "wscript"

        # Browser-extension APIs — checked before generic browser/worker because
        # `chrome.*` and `browser.runtime` are distinctive of MV2/MV3 extensions
        extension_patterns = [
            'chrome.runtime', 'chrome.tabs', 'chrome.storage',
            'chrome.webRequest', 'browser.runtime', 'browser.tabs',
        ]
        for p in extension_patterns:
            if p in src:
                return "browser_extension"

        # Service / Web Workers — worker-only APIs that don't appear in regular
        # browser pages (a generic browser script would use `window.` or
        # `document.`, never `self.importScripts` or `caches.match`)
        worker_patterns = [
            "self.addEventListener('fetch'", 'self.addEventListener("fetch"',
            'self.importScripts', 'self.skipWaiting',
            'caches.match', 'caches.open',
        ]
        for p in worker_patterns:
            if p in src:
                return "service_worker"

        # Deno runtime
        if 'Deno.' in src:
            return "deno"

        # Node.js indicators
        node_patterns = [
            'require(', 'module.exports', 'process.env', '__dirname',
            '__filename', 'Buffer.', 'child_process',
        ]
        for p in node_patterns:
            if p in src:
                return "node"

        # Browser indicators
        browser_patterns = [
            'document.', 'window.', 'navigator.', 'localStorage',
            'sessionStorage', 'XMLHttpRequest', 'addEventListener',
        ]
        for p in browser_patterns:
            if p in src:
                return "browser"

        return "unknown"

    def _detect_script_type(self):
        """Detect the script type/format."""
        src = self.js_source
        if not src:
            return "unknown"

        stripped = src.lstrip()

        # JScript.Encode payload — must be checked first since the encoded
        # body can't be classified any other way
        if stripped.startswith('#@~^'):
            return "jse"

        # WSF / HTA live in the first few KB of an HTML-ish wrapper
        head_lower = stripped[:4096].lower()

        # Windows Script File — XML wrapper around one or more <script> blocks
        if ('<job' in head_lower or '<package' in head_lower) and '<script' in head_lower:
            return "wsf"

        # HTML Application — distinct from generic embedded_html because HTAs
        # run under mshta.exe with full WSH/ActiveX access
        if '<hta:application' in head_lower or 'application/hta' in head_lower:
            return "hta"

        if stripped.startswith('<!') or stripped.startswith('<html') or '<script' in stripped[:2000]:
            return "embedded_html"

        if 'WScript.' in src or 'WSH.' in src:
            return "wscript"

        if _ESM_PATTERN.search(src):
            return "esm"

        if 'require(' in src or 'module.exports' in src:
            return "node_module"

        return "standalone"