Olga Volkoff

18 papers C 1Journal 12Unranked 5
YearRankTypeTitle / Venue / Authors
2017 J jnl
Inf. Syst. Res.
Andrew Burton-Jones, Olga Volkoff
2016 J jnl
J. Inf. Technol.
Bendik Bygstad, Bjørn Erik Munkvold, Olga Volkoff
2014 J jnl
J. Assoc. Inf. Syst.
Diane M. Strong, Olga Volkoff, Sharon A. Johnson, Lori Pelletier, Bengisu Tulu, Isa Bar-On, John Trudel, Lawrence Garber
2013 J jnl
MIS Q.
Olga Volkoff, Diane M. Strong
2013 conf
AMCIS
Donald E. Wynn Jr., Olga Volkoff, Clay K. Williams, Diane M. Strong
2011 conf
AMCIS
Olga Volkoff, Stephanie Bertels, Daniel Papania
2010 J jnl
MIS Q.
Diane M. Strong, Olga Volkoff
2009 conf
AMCIS
Diane M. Strong, Olga Volkoff, Sharon A. Johnson, Isa Bar-On, Lori Pelletier
2007 J jnl
Organ. Sci.
Olga Volkoff, Diane M. Strong, Michael B. Elmes
2005 conf
ICIQ
Diane M. Strong, Olga Volkoff
2005 J jnl
Inf. Organ.
Michael B. Elmes, Diane M. Strong, Olga Volkoff
2005 J jnl
Eur. J. Inf. Syst.
Olga Volkoff, Diane M. Strong, Michael B. Elmes
2004 J jnl
Computer
Diane M. Strong, Olga Volkoff
2004 J jnl
J. Strateg. Inf. Syst.
Olga Volkoff, Michael B. Elmes, Diane M. Strong
2003 conf
AMCIS
Diane M. Strong, Olga Volkoff, Michael B. Elmes
1999 J jnl
Inf. Manag.
Olga Volkoff, Yolande E. Chan, E. F. Peter Newson
1999 J jnl
J. Inf. Technol.
Olga Volkoff, E. F. Peter Newson
1998 C conf
ICIS
Olga Volkoff, E. F. Peter Newson
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"