Oliver Gasser

91 papers A 17B 8Misc 1Journal 49Unranked 15
YearRankTypeTitle / Venue / Authors
2026 B conf
PAM
Fahad Hilal, Taha Albakour, Oliver Gasser, Kevin Vermeulen
2026 J jnl
CoRR
Robert Beverly, Amreesh Phokeer, Oliver Gasser
2025 J jnl
Proc. ACM Netw.
Patrick Sattler, Johannes Zirngibl, Fahad Hilal, Oliver Gasser, Kevin Vermeulen, Georg Carle, Mattijs Jonker
2025 J jnl
CoRR
Ali Rasaii, Ha Dao, Anja Feldmann, Mohammadmadi Javid, Oliver Gasser, Devashish Gosain
2025 J jnl
Proc. Priv. Enhancing Technol.
Ali Rasaii, Ha Dao, Anja Feldmann, Mohammadmahdi Javid, Oliver Gasser, Devashish Gosain
2025 J jnl
CoRR
Lucianna Kiffer, Lioba Heimbach, Dennis Trautwein, Yann Vonlanthen, Oliver Gasser
2025 J jnl
Proc. ACM Meas. Anal. Comput. Syst.
Lucianna Kiffer, Lioba Heimbach, Dennis Trautwein, Yann Vonlanthen, Oliver Gasser
2025 A conf
IMC
Fariba Osali, Khwaja Zubair Sediqi, Oliver Gasser
2025 J jnl
CoRR
Fariba Osali, Khwaja Zubair Sediqi, Oliver Gasser
2025 J jnl
CoRR
Hammas Bin Tanveer, Wai Sun Chan, Ricky K. P. Mok, Sebastian Kappes, Philipp Richter, Oliver Gasser, John Ronan, Arthur W. Berger, K. C. Claffy
2025 J jnl
Proc. ACM Netw.
Hammas Bin Tanveer, Echo Chan, Ricky K. P. Mok, Sebastian Kappes, Philipp Richter, Oliver Gasser, John Ronan, Arthur W. Berger, K. C. Claffy
2024 J jnl
Proc. ACM Netw.
Fahad Hilal, Patrick Sattler, Kevin Vermeulen, Oliver Gasser
2024 conf
PAM (1)
Amanda Hsu, Frank Li, Paul Pearce, Oliver Gasser
2024 J jnl
CoRR
Patrick Sattler, Johannes Zirngibl, Fahad Hilal, Oliver Gasser, Kevin Vermeulen, Georg Carle, Mattijs Jonker
2024 A conf
AsiaCCS
Lars Prehn, Pawel Foremski, Oliver Gasser
2023 J jnl
CoRR
Amanda Hsu, Frank Li, Paul Pearce, Oliver Gasser
2023 J jnl
CoRR
Peter Jose, Said Jawad Saidi, Oliver Gasser
2023 B conf
PAM
Aniss Maghsoudlou, Lukas Vermeulen, Ingmar Poese, Oliver Gasser
2023 J jnl
CoRR
Aniss Maghsoudlou, Lukas Vermeulen, Ingmar Poese, Oliver Gasser
2023 conf
ANRW
Cristian Munteanu, Oliver Gasser, Ingmar Poese, Georgios Smaragdakis, Anja Feldmann
2023 B conf
PAM
Ali Rasaii, Shivani Singh, Devashish Gosain, Oliver Gasser
2023 J jnl
CoRR
Ali Rasaii, Shivani Singh, Devashish Gosain, Oliver Gasser
2023 A conf
IMC
Cristian Munteanu, Said Jawad Saidi, Oliver Gasser, Georgios Smaragdakis, Anja Feldmann
2023 J jnl
CoRR
Florian Streibelt, Patrick Sattler, Franziska Lichtblau, Carlos Hernandez Gañán, Anja Feldmann, Oliver Gasser, Tobias Fiebig
2023 B conf
PAM
Florian Streibelt, Patrick Sattler, Franziska Lichtblau, Carlos Hernandez Gañán, Anja Feldmann, Oliver Gasser, Tobias Fiebig
2023 A conf
IMC
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
2023 J jnl
CoRR
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
2023 conf
TMA
Khwaja Zubair Sediqi, Anja Feldmann, Oliver Gasser
2023 J jnl
CoRR
Khwaja Zubair Sediqi, Anja Feldmann, Oliver Gasser
2023 J jnl
CoRR
Patrick Sattler, Johannes Zirngibl, Mattijs Jonker, Oliver Gasser, Georg Carle, Ralph Holz
2023 J jnl
PACMNET
Patrick Sattler, Johannes Zirngibl, Mattijs Jonker, Oliver Gasser, Georg Carle, Ralph Holz
2023 A conf
IMC
Taha Albakour, Oliver Gasser, Georgios Smaragdakis
2023 J jnl
CoRR
Taha Albakour, Oliver Gasser, Georgios Smaragdakis
2023 conf
TMA
Lion Steger, Liming Kuang, Johannes Zirngibl, Georg Carle, Oliver Gasser
2023 J jnl
CoRR
Lion Steger, Liming Kuang, Johannes Zirngibl, Georg Carle, Oliver Gasser
2023 A conf
IMC
Ali Rasaii, Devashish Gosain, Oliver Gasser
2023 J jnl
CoRR
Ali Rasaii, Devashish Gosain, Oliver Gasser
2023 J jnl
PACMNET
Fahad Hilal, Oliver Gasser
2022 J jnl
CoRR
Tanya Shreedhar, Danesh Zeynali, Oliver Gasser, Nitinder Mohan, Jörg Ott
2022 J jnl
CoRR
Said Jawad Saidi, Srdjan Matic, Oliver Gasser, Georgios Smaragdakis, Anja Feldmann
2022 A conf
IMC
Said Jawad Saidi, Srdjan Matic, Georgios Smaragdakis, Oliver Gasser, Anja Feldmann
2022 J jnl
CoRR
Aniss Maghsoudlou, Oliver Gasser, Ingmar Poese, Anja Feldmann
2022 A conf
CoNEXT
Aniss Maghsoudlou, Oliver Gasser, Ingmar Poese, Anja Feldmann
2022 J jnl
CoRR
Khwaja Zubair Sediqi, Lars Prehn, Oliver Gasser
2022 J jnl
Comput. Commun. Rev.
Khwaja Zubair Sediqi, Lars Prehn, Oliver Gasser
2022 J jnl
CoRR
Philipp Richter, Oliver Gasser, Arthur W. Berger
2022 A conf
IMC
Philipp Richter, Oliver Gasser, Arthur W. Berger
2022 J jnl
CoRR
Lars Prehn, Pawel Foremski, Oliver Gasser
2022 J jnl
CoRR
Said Jawad Saidi, Oliver Gasser, Georgios Smaragdakis
2022 J jnl
Comput. Commun. Rev.
Said Jawad Saidi, Oliver Gasser, Georgios Smaragdakis
2022 J jnl
CoRR
Johannes Zirngibl, Lion Steger, Patrick Sattler, Oliver Gasser, Georg Carle
2022 A conf
IMC
Johannes Zirngibl, Lion Steger, Patrick Sattler, Oliver Gasser, Georg Carle
2022 conf
EuroS&P Workshops
Victor-Alexandru Padurean, Oliver Gasser, Randy Bush, Anja Feldmann
2022 J jnl
CoRR
Victor-Alexandru Padurean, Oliver Gasser, Randy Bush, Anja Feldmann
2021 J jnl
Commun. ACM
Anja Feldmann, Oliver Gasser, Franziska Lichtblau, Enric Pujol, Ingmar Poese, Christoph Dietzel, Daniel Wagner, Matthias Wichtlhuber, Juan Tapiador, Narseo Vallina-Rodriguez, Oliver Hohlfeld, Georgios Smaragdakis
2021 B conf
Networking
Florian Aschenbrenner, Tanya Shreedhar, Oliver Gasser, Nitinder Mohan, Jörg Ott
2021 J jnl
CoRR
Florian Aschenbrenner, Tanya Shreedhar, Oliver Gasser, Nitinder Mohan, Jörg Ott
2021 J jnl
CoRR
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
2021 A conf
Internet Measurement Conference
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
2021 B conf
PAM
Aniss Maghsoudlou, Oliver Gasser, Anja Feldmann
2021 J jnl
CoRR
Aniss Maghsoudlou, Oliver Gasser, Anja Feldmann
2020 J jnl
CoRR
Aniss Maghsoudlou, Oliver Gasser, Anja Feldmann
2020 A conf
Internet Measurement Conference
Anja Feldmann, Oliver Gasser, Franziska Lichtblau, Enric Pujol, Ingmar Poese, Christoph Dietzel, Daniel Wagner, Matthias Wichtlhuber, Juan Tapiador, Narseo Vallina-Rodriguez, Oliver Hohlfeld, Georgios Smaragdakis
2020 J jnl
CoRR
Anja Feldmann, Oliver Gasser, Franziska Lichtblau, Enric Pujol, Ingmar Poese, Christoph Dietzel, Daniel Wagner, Matthias Wichtlhuber, Juan Tapiador, Narseo Vallina-Rodriguez, Oliver Hohlfeld, Georgios Smaragdakis
2019 A conf
Internet Measurement Conference
Pawel Foremski, Oliver Gasser, Giovane C. M. Moura
2019
Oliver Gasser
2019 A conf
Internet Measurement Conference
Johannes Naab, Patrick Sattler, Jonas Jelten, Oliver Gasser, Georg Carle
2018 J jnl
Comput. Commun. Rev.
Quirin Scheitle, Taejoong Chung, Jens Hiller, Oliver Gasser, Johannes Naab, Roland van Rijswijk-Deij, Oliver Hohlfeld, Ralph Holz, David R. Choffnes, Alan Mislove, Georg Carle
2018 A conf
Internet Measurement Conference
Oliver Gasser, Quirin Scheitle, Pawel Foremski, Qasim Lone, Maciej Korczynski, Stephen D. Strowes, Luuk Hendriks, Georg Carle
2018 J jnl
CoRR
Oliver Gasser, Quirin Scheitle, Pawel Foremski, Qasim Lone, Maciej Korczynski, Stephen D. Strowes, Luuk Hendriks, Georg Carle
2018 B conf
PAM
Oliver Gasser, Benjamin Hof, Max Helm, Maciej Korczynski, Ralph Holz, Georg Carle
2018 conf
ANRW
Quirin Scheitle, Taejoong Chung, Johanna Amann, Oliver Gasser, Lexi Brent, Georg Carle, Ralph Holz, Jens Hiller, Johannes Naab, Roland van Rijswijk-Deij, Oliver Hohlfeld, David R. Choffnes, Alan Mislove
2018 A conf
Internet Measurement Conference
Quirin Scheitle, Oliver Gasser, Theodor Nolte, Johanna Amann, Lexi Brent, Georg Carle, Ralph Holz, Thomas C. Schmidt, Matthias Wählisch
2018 J jnl
CoRR
Quirin Scheitle, Oliver Gasser, Theodor Nolte, Johanna Amann, Lexi Brent, Georg Carle, Ralph Holz, Thomas C. Schmidt, Matthias Wählisch
2017 J jnl
CoRR
Quirin Scheitle, Oliver Gasser, Patrick Sattler, Georg Carle
2017 conf
TMA
Quirin Scheitle, Oliver Gasser, Patrick Sattler, Georg Carle
2017 conf
TMA
Quirin Scheitle, Oliver Gasser, Minoo Rouhi, Georg Carle
2017 A conf
Internet Measurement Conference
Johanna Amann, Oliver Gasser, Quirin Scheitle, Lexi Brent, Georg Carle, Ralph Holz
2017 Misc conf
HotNets
Patricia Callejo, Conor Kelton, Narseo Vallina-Rodriguez, Rubén Cuevas, Oliver Gasser, Christian Kreibich, Florian Wohlfart, Ángel Cuevas
2017 conf
IEEE Symposium on Security and Privacy Workshops
Oliver Gasser, Quirin Scheitle, Carl Denis, Nadja Schricker, Georg Carle
2017 J jnl
J. Cyber Secur. Mobil.
Oliver Gasser, Quirin Scheitle, Benedikt Rudolph, Carl Denis, Nadja Schricker, Georg Carle
2017 conf
Reproducibility@SIGCOMM
Quirin Scheitle, Matthias Wählisch, Oliver Gasser, Thomas C. Schmidt, Georg Carle
2016 J jnl
CoRR
Quirin Scheitle, Oliver Gasser, Paul Emmerich, Georg Carle
2016 conf
TMA
Oliver Gasser, Felix Emmert, Georg Carle
2016 J jnl
CoRR
Quirin Scheitle, Oliver Gasser, Minoo Rouhi, Georg Carle
2016 conf
TMA
Oliver Gasser, Quirin Scheitle, Sebastian Gebhard, Georg Carle
2016 J jnl
CoRR
Oliver Gasser, Quirin Scheitle, Sebastian Gebhard, Georg Carle
2015 conf
TMA
Timm Böttger, Lothar Braun, Oliver Gasser, Felix von Eye, Helmut Reiser, Georg Carle
2015 conf
TMA
Johann Schlamp, Ralph Holz, Oliver Gasser, Andreas Korsten, Quentin Jacquemart, Georg Carle, Ernst W. Biersack
2014 B conf
NOMS
Oliver Gasser, Ralph Holz, Georg Carle
2011 conf
Informatiktage
Oliver Gasser
redb/extractors/extractor.py
← Index redb/extractors/extractor.py python
import hashlib
import inspect
from abc import ABCMeta, abstractmethod
from dataclasses import asdict
from functools import cached_property
from datetime import datetime, timezone
import math
from typing import Counter, List, Optional, Dict, Any, Tuple
from redb import settings
from redb.models.dataclasses import Hash
from .database_exporters import DatabaseExporter, ElasticsearchExporter, ClickHouseExporter, PrintExporter

class Extractor(metaclass=ABCMeta):
    def __init__(
        self,
        filepath: str,
        log: Any,
        exporters: Optional[List[DatabaseExporter]] = None,
        index_prefix: Optional[str] = None,
        source: Optional[str] = None,
        elastic_index: Optional[str] = None,
        known_benign: bool = False,
        known_malicious: bool = False,
        precomputed_hashes: Optional[Dict[str, str]] = None,
    ):
        self.log = log
        self.log.debug(f"Creating {self.__class__.__name__}")
        self.filepath = filepath
        self.source = source
        self.exporters = exporters or []
        self.index_prefix = index_prefix if index_prefix else settings.ELASTIC_BINARIES_COLLECTION
        self.elastic_index = self.index_prefix + (elastic_index if elastic_index else "")
        self.known_benign = known_benign
        self.known_malicious = known_malicious

        # Use precomputed hashes if provided (e.g., from machofile, pefile)
        # Otherwise compute them from binary
        if precomputed_hashes:
            self.md5 = precomputed_hashes.get('md5') or precomputed_hashes.get('MD5')
            self.sha1 = precomputed_hashes.get('sha1') or precomputed_hashes.get('SHA1')
            self.sha256 = precomputed_hashes.get('sha256') or precomputed_hashes.get('SHA256')
        else:
            self.md5 = hashlib.md5(self.binary).hexdigest()
            self.sha1 = hashlib.sha1(self.binary).hexdigest()
            self.sha256 = hashlib.sha256(self.binary).hexdigest()
        self.hash = Hash(self.md5, self.sha1, self.sha256)

    @cached_property
    def binary(self):
        with open(self.filepath, "rb") as f:
            data = f.read()
        return data

    @property
    @abstractmethod
    def tag(self):
        pass

    @abstractmethod
    def extract(self):
        """
        this method defines the extracted data
        """

    @staticmethod
    def process_binary_string(s):
        # Remove \x00 padding
        s = s.rstrip(b"\x00")

        # Check if there are any non-printable characters
        has_non_printable = any(byte < 32 or byte > 126 for byte in s)

        if not has_non_printable:
            # If all characters are printable, decode the string
            return s.decode()
        else:
            # If there are non-printable characters, represent them as \xDD
            return "".join(
                [
                    f"\\x{byte:02x}" if byte < 32 or byte > 126 else chr(byte)
                    for byte in s
                ]
            )

    @staticmethod
    def remove_non_utf8(binary_string):
        decoded = b""
        for i in range(len(binary_string)):
            try:
                # Try to decode each byte
                char = binary_string[i : i + 1].decode("utf-8")
                decoded += char.encode("utf-8")
            except UnicodeDecodeError:
                # Skip this byte if it can't be decoded
                continue
        return decoded

    def calculate_entropy(self, data):
        """Calculate the entropy of a chunk of data.
        Based on pefile.SectionStructure.entropy_H.
        """
        # self.log.debug(inspect.currentframe().f_code.co_name)
        if not data:
            return 0.0

        if type(data) == str:
            counts = Counter(data)
            frequencies = ((i / len(data)) for i in counts.values())
            return - sum(f * math.log(f, 2) for f in frequencies)
        else:
            occurences = Counter(bytearray(data))
            entropy = 0
            for x in occurences.values():
                p_x = float(x) / len(data)
                entropy -= p_x * math.log(p_x, 2)
            return entropy

    @abstractmethod
    def prepare_export_data(self, exporter_type: str) -> Tuple[List[Any], List[str], List[str]]:
        """
        Prepare data for specific export type
        Returns:
            Tuple containing:
            - data: List of values to insert
            - column_names: List of column names
            - column_type_names: List of column types
        """
        pass

    def export_data(self):
        """Export data to all configured exporters

        Returns:
            True: Export succeeded
            False: Export failed (actual error)
            None: No data to export (not an error, e.g., no overlay, no signature)
        """
        self.log.debug(inspect.currentframe().f_code.co_name)
        success = True
        extracted_data = self.extract()

        if extracted_data is None:
            self.log.debug("extract() returned None, skipping export")
            return None  # No data to export, not a failure
            
        for exporter in self.exporters:
            if isinstance(exporter, PrintExporter):
                # For PrintExporter, we pass the extracted data directly
                success &= exporter.export(extracted_data)
            else:
                # Get the data prepared for this specific exporter type
                export_data = self.prepare_export_data(exporter.__class__.__name__)
                
                if export_data is None:
                    self.log.debug(f"prepare_export_data returned None for {exporter.__class__.__name__}")
                    return False
                
                if isinstance(exporter, ElasticsearchExporter):
                    success &= exporter.export(
                        export_data,
                        index=self.elastic_index,
                        tag=self.tag(),
                        hashes=asdict(self.hash),
                        known_benign=self.known_benign,
                        known_malicious=self.known_malicious
                    )
                elif isinstance(exporter, ClickHouseExporter):
                    # For ClickHouse, we need to pass the table name and the prepared data
                    success &= exporter.export(
                        export_data,
                        table=self.get_clickhouse_table(),
                        # Add these parameters explicitly
                        column_names=export_data[1] if isinstance(export_data, tuple) else None,
                        column_type_names=export_data[2] if isinstance(export_data, tuple) else None
                    )
                
        return success

    @abstractmethod
    def get_clickhouse_table(self) -> str:
        """Return the appropriate ClickHouse table name"""
        pass
    # def export_to_elastic(self, list_of_dataclasses, tag=None):
    #     self.log.debug(inspect.currentframe().f_code.co_name)

    #     if not isinstance(list_of_dataclasses, list):
    #         self.log.error("Called export_to_elastic wrongly")

    #     now_t = datetime.now(timezone.utc).strftime("%Y-%m-%d %H:%M:%S")
    #     for dataclass_ in list_of_dataclasses:
    #         if not settings.ELASTIC_CLIENT.ping():
    #             self.log.error("[CONNECTION ERROR] ping to elastic failed")
            
    #         # Convert dataclass to dict and filter out None values
    #         document = {k: v for k, v in asdict(dataclass_).items() if v is not None}
            
    #         if tag:
    #             document["tag"] = [tag, self.tag()]
    #         else:
    #             document["tag"] = self.tag()
    #         hashes = asdict(self.hash)
    #         document |= hashes
    #         document["timestamp_utc"] = now_t
    #         # document["source"] = self.source
    #         document["known_benign"] = self.known_benign
    #         document["known_malicious"] = self.known_malicious

    #         if "_id" in document:
    #             tmp_id = document.pop("_id") + document["sha256"]
    #             _id = hashlib.sha256(tmp_id.encode()).hexdigest()
    #         else:
    #             _id = document["sha256"]

    #         # self.log.debug(f"[DEBUG] about to export {type(document)} {document}")
    #         try:
    #             doc_dump = json.dumps(document)
    #         except TypeError as e:
    #             self.log.error(
    #                 f"Failed export of document. " f"full document: {document}"
    #             )
    #             raise e

    #         # body={"doc": doc_dump,
    #         #       "doc_as_upsert": True  # Create the document if it doesn't exist
    #         # }

    #         # Check if the index exists, and create it if it doesn't
    #         # if not settings.ELASTIC_CLIENT.indices.exists(index=self.elastic_index):
    #         #     settings.ELASTIC_CLIENT.indices.create(index=self.elastic_index)
    #         # pprint(doc_dump) #DEBUG
    #         # print("[DEBUG] _id: " + _id)
    #         # print("[DEBUG] index: " + self.elastic_index)
    #         settings.ELASTIC_CLIENT.index(
    #             index=self.elastic_index, id=_id, document=doc_dump
    #         )