Oliverio J. Santana

63 papers A* 2B 8C 7Misc 2Journal 24Unranked 18
YearRankTypeTitle / Venue / Authors
2026 ed.
CAIP (1)
Modesto Castrillón Santana, Carlos M. Travieso-González, Oscar Déniz-Suárez, David Freire-Obregón, Daniel Hernández-Sosa, Javier Lorenzo-Navarro, Oliverio J. Santana
2026 ed.
CAIP (2)
Modesto Castrillón Santana, Carlos M. Travieso-González, Oscar Déniz-Suárez, David Freire-Obregón, Daniel Hernández-Sosa, Javier Lorenzo-Navarro, Oliverio J. Santana
2026 J jnl
Pattern Recognit.
David Freire-Obregón, Oliverio J. Santana, Javier Lorenzo-Navarro, Daniel Hernández-Sosa, Modesto Castrillón Santana
2025 C conf
VCIP
José Salas-Cáceres, Modesto Castrillón Santana, David Freire-Obregón, Oliverio J. Santana, Daniel Hernández-Sosa, Javier Lorenzo-Navarro
2025 J jnl
CoRR
Modesto Castrillón Santana, Oliverio J. Santana, David Freire-Obregón, Daniel Hernández-Sosa, Javier Lorenzo-Navarro
2025 conf
icSPORTS
David Freire-Obregón, Oliverio J. Santana, Javier Lorenzo-Navarro, Daniel Hernández-Sosa, Modesto Castrillón Santana
2025 conf
FLLM
David Freire-Obregón, José Salas-Cáceres, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2025 J jnl
CoRR
David Freire-Obregón, José Salas-Cáceres, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2025 Misc conf
ICIAP
David Freire-Obregón, Oliverio J. Santana, Javier Lorenzo-Navarro, Daniel Hernández-Sosa, Modesto Castrillón Santana
2025 J jnl
CoRR
David Freire-Obregón, Oliverio J. Santana, Javier Lorenzo-Navarro, Daniel Hernández-Sosa, Modesto Castrillón Santana
2024 J jnl
CoRR
David Freire-Obregón, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2024 C conf
ICPRAM
Modesto Castrillón Santana, David Freire-Obregón, Daniel Hernández-Sosa, Oliverio J. Santana, Francisco Ortega-Zamorano, José Isern González, Javier Lorenzo-Navarro
2024 J jnl
Neurocomputing
Oliverio J. Santana, Javier Lorenzo-Navarro, David Freire-Obregón, Daniel Hernández-Sosa, Modesto Castrillón Santana
2024 C conf
ICPRAM
Javier Torón-Artiles, Daniel Hernández-Sosa, Oliverio J. Santana, Javier Lorenzo-Navarro, David Freire-Obregón
2024 C conf
ICPRAM
Javier Torón-Artiles, Daniel Hernández-Sosa, Oliverio J. Santana, Javier Lorenzo-Navarro, David Freire-Obregón
2024 B conf
FG
David Freire-Obregón, Daniel Hernández-Sosa, Oliverio J. Santana, Javier Lorenzo-Navarro, Modesto Castrillón Santana
2024 J jnl
CoRR
David Freire-Obregón, Daniel Hernández-Sosa, Oliverio J. Santana, Javier Lorenzo-Navarro, Modesto Castrillón Santana
2024 J jnl
SN Comput. Sci.
Modesto Castrillón Santana, Elena Sánchez-Nielsen, David Freire-Obregón, Oliverio J. Santana, Daniel Hernández-Sosa, Javier Lorenzo-Navarro
2023 B conf
IJCB
David Freire-Obregón, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2023 conf
ICIAP (1)
David Freire-Obregón, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2023 Misc conf
MVA
David Freire-Obregón, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2023 J jnl
CoRR
David Freire-Obregón, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2023 J jnl
CoRR
Javier Torón-Artiles, Daniel Hernández-Sosa, Oliverio J. Santana, Javier Lorenzo-Navarro, David Freire-Obregón
2023 C conf
ICPRAM
Sara L. Almonacid-Uribe, Oliverio J. Santana, Daniel Hernández-Sosa, David Freire-Obregón
2023 C conf
ICPRAM
Oliverio J. Santana, Javier Lorenzo-Navarro, David Freire-Obregón, Daniel Hernández-Sosa, Modesto Castrillón Santana
2023 conf
CAIP (1)
Modesto Castrillón Santana, Elena Sánchez-Nielsen, David Freire-Obregón, Oliverio J. Santana, Daniel Hernández-Sosa, Javier Lorenzo-Navarro
2023 conf
ICPRAM (Revised Selected Papers)
Sara L. Almonacid-Uribe, Oliverio J. Santana, Daniel Hernández-Sosa, David Freire-Obregón
2023 J jnl
Multim. Tools Appl.
Oliverio J. Santana, David Freire-Obregón, Daniel Hernández-Sosa, Javier Lorenzo-Navarro, Elena Sánchez-Nielsen, Modesto Castrillón Santana
2023 conf
ICPRAM (Revised Selected Papers)
Oliverio J. Santana, Javier Lorenzo-Navarro, David Freire-Obregón, Daniel Hernández-Sosa, Modesto Castrillón Santana
2023 conf
ICIAP (1)
David Freire-Obregón, Daniel Hernández-Sosa, Oliverio J. Santana, Javier Lorenzo-Navarro, Modesto Castrillón Santana
2022 C conf
ICPRAM
Miguel Angel Medina, Javier Lorenzo-Navarro, David Freire-Obregón, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2022 J jnl
CoRR
Sara L. Almonacid-Uribe, Oliverio J. Santana, Daniel Hernández-Sosa, David Freire-Obregón
2022 conf
ICPRAM (Revised Selected Papers)
Oliverio J. Santana, Javier Lorenzo-Navarro, David Freire-Obregón, Daniel Hernández-Sosa, José Isern González, Modesto Castrillón Santana
2022 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Oliverio J. Santana, Daniel Hernández-Sosa, Ryan N. Smith
2022 B conf
ICPR
David Freire-Obregón, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2022 J jnl
CoRR
David Freire-Obregón, Javier Lorenzo-Navarro, Oliverio J. Santana, Daniel Hernández-Sosa, Modesto Castrillón Santana
2020 J jnl
Remote. Sens.
Oliverio J. Santana, Daniel Hernández-Sosa, Jeffrey Martz, Ryan N. Smith
2014 conf
ICS 25th Anniversary
Alex Ramírez, Ayose Falcón, Oliverio J. Santana, Mateo Valero
2010 B conf
PACT
Tanausú Ramírez, Alex Pajuelo, Oliverio J. Santana, Onur Mutlu, Mateo Valero
2010 J jnl
IEEE Trans. Computers
Francisco J. Cazorla, Alex Pajuelo, Oliverio J. Santana, Enrique Fernández, Mateo Valero
2009 B conf
ICPP
Tanausú Ramírez, Alex Pajuelo, Oliverio J. Santana, Mateo Valero
2009 J jnl
IEEE Trans. Computers
Oliverio J. Santana, Ayose Falcón, Alex Ramírez, Mateo Valero
2008 conf
HiPEAC
Alejandro García, Oliverio J. Santana, Enrique Fernández, Pedro Medina, Mateo Valero
2008 A* conf
HPCA
Tanausú Ramírez, Alex Pajuelo, Oliverio J. Santana, Mateo Valero
2007 J jnl
SIGARCH Comput. Archit. News
Tanausú Ramírez, Alex Pajuelo, Oliverio J. Santana, Mateo Valero
2007 J jnl
IEEE Trans. Computers
Oliverio J. Santana, Alex Ramírez, Mateo Valero
2007 B conf
PACT
Javier Vera, Francisco J. Cazorla, Alex Pajuelo, Oliverio J. Santana, Enrique Fernández, Mateo Valero
2007 B conf
PACT
Tanausú Ramírez, Alex Pajuelo, Oliverio J. Santana, Mateo Valero
2006 conf
MEDEA@PACT
Tanausú Ramírez, Alex Pajuelo, Oliverio J. Santana, Mateo Valero
2006 B conf
PACT
Oliverio J. Santana, Ayose Falcón, Alex Ramírez, Mateo Valero
2006 conf
Conf. Computing Frontiers
Tanausú Ramírez, Alex Pajuelo, Oliverio J. Santana, Mateo Valero
2005 J jnl
IEEE Micro
Adrián Cristal, Oliverio J. Santana, Francisco J. Cazorla, Marco Galluzzi, Tanausú Ramírez, Miquel Pericàs, Mateo Valero
2005 conf
ISHPC
Oliverio J. Santana, Alex Ramírez, Mateo Valero
2004 J jnl
Res. Comput. Sci.
Adrián Cristal, Mateo Valero, Oliverio J. Santana
2004 J jnl
Int. J. High Perform. Comput. Netw.
Ayose Falcón, Oliverio J. Santana, Alex Ramírez, Mateo Valero
2004 J jnl
ACM Trans. Archit. Code Optim.
Oliverio J. Santana, Alex Ramírez, Josep Lluís Larriba-Pey, Mateo Valero
2004 conf
Euro-Par
Adrián Cristal, Oliverio J. Santana, Mateo Valero
2004 conf
Interaction between Compilers and Computer Architectures
Oliverio J. Santana, Alex Ramírez, Mateo Valero
2004 J jnl
ACM Trans. Archit. Code Optim.
Adrián Cristal, Oliverio J. Santana, Mateo Valero, José F. Martínez
2003 conf
ISHPC
Ayose Falcón, Oliverio J. Santana, Alex Ramírez, Mateo Valero
2002 conf
ISHPC
Oliverio J. Santana, Ayose Falcón, Enrique Fernández, Pedro Medina, Alex Ramírez, Mateo Valero
2002 A* conf
MICRO
Alex Ramírez, Oliverio J. Santana, Josep Lluís Larriba-Pey, Mateo Valero
2002 conf
ISHPC
Ayose Falcón, Oliverio J. Santana, Pedro Medina, Enrique Fernández, Alex Ramírez, Mateo Valero
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |