Olivier L. de Weck

48 papers B 2C 3Journal 30Unranked 13
YearRankTypeTitle / Venue / Authors
2025 conf
SysCon
Heekun Roh, Lilly Etzenbach, Alexia Oltramare, Johannes J. Norheim, Olivier L. de Weck
2023 J jnl
J. Field Robotics
Ethan S. Rolland, Maha N. Haji, Olivier L. de Weck
2023 J jnl
Remote. Sens.
Rashmi Ravishankar, Elaf Almahmoud, Abdulelah H. Habib, Olivier L. de Weck
2023 J jnl
Remote. Sens.
Zeyad Awwad, Abdulaziz Alharbi, Abdulelah H. Habib, Olivier L. de Weck
2022 J jnl
CoRR
Zeyad Awwad, Abdulaziz Alharbi, Abdulelah H. Habib, Olivier L. de Weck
2021 C conf
IGARSS
Afreen Siddiqi, Sheila Baber, Olivier L. de Weck
2020 J jnl
Syst. Eng.
Anne Collin, Afreen Siddiqi, Yuto Imanishi, Eric Rebentisch, Taisetsu Tanimichi, Olivier L. de Weck
2019 C conf
IGARSS
Lisa Yang, Afreen Siddiqi, Olivier L. de Weck
2018 C conf
IGARSS
Olivier L. de Weck
2018 J jnl
IEEE Syst. J.
Paul T. Grogan, Olivier L. de Weck
2018 J jnl
Syst. Eng.
Eun Suk Suh, Olivier L. de Weck
2018 J jnl
IEEE Syst. J.
Paul T. Grogan, Koki Ho, Alessandro Golkar, Olivier L. de Weck
2018 J jnl
Syst. Eng.
Olivier L. de Weck
2017 J jnl
J. Aerosp. Inf. Syst.
Daniel Selva, Alessandro Golkar, Olga Korobova, Ignasi Lluch i Cruz, Paul Collopy, Olivier L. de Weck
2016 conf
CSDM
Abdulaziz Khiyami, Andrew Owens, Abdelkrim Doufene, Adnan Alsaati, Olivier L. de Weck
2016 conf
SysCon
Paul T. Grogan, Alessandro Golkar, Koki Ho, Olivier L. de Weck
2016 J jnl
J. Integr. Des. Process. Sci.
Edoardo F. Colombo, Gaetano Cascini, Olivier L. de Weck
2016 conf
SpringSim (ANSS)
Paul T. Grogan, Olivier L. de Weck
2016 conf
CSDM
Kaushik Sinha, Narek R. Shougarian, Olivier L. de Weck
2016 J jnl
Syst. Eng.
Kaushik Sinha, Olivier L. de Weck
2016 J jnl
CoRR
Kaushik Sinha, Olivier L. de Weck
2016 conf
SysCon
Abdelkrim Doufene, Vivek Sakhrani, Abdullah Alkhenani, Bo-Yang Yu, Stephen Connors, Adnan Alsaati, Olivier L. de Weck
2015 J jnl
IEEE Syst. J.
Paul T. Grogan, Olivier L. de Weck
2014 J jnl
IEEE Trans. Syst. Man Cybern. Syst.
Adedamola Adepetu, Edin Arnautovic, Davor Svetinovic, Olivier L. de Weck
2014 J jnl
Syst. Eng.
Jaemyung Ahn, Olivier L. de Weck, Martin J. Steele
2014 J jnl
Syst. Eng.
Adedamola Adepetu, Paul T. Grogan, Anas Alfaris, Davor Svetinovic, Olivier L. de Weck
2013 J jnl
Syst. Eng.
Olivier L. de Weck
2013 conf
SysCon
Kaushik Sinha, Olivier L. de Weck
2013 J jnl
Int. J. Syst. Syst. Eng.
Shinichiro Haruyama, Sun K. Kim, Kurt A. Beiter, Gerard P. J. Dijkema, Olivier L. de Weck
2013 conf
SysCon
Paul T. Grogan, Olivier L. de Weck
2013 conf
HCI (8)
Chaiwoo Lee, Lisa A. D'Ambrosio, Richard Myrick, Joseph F. Coughlin, Olivier L. de Weck
2013 J jnl
Syst. Eng.
Amira Sharon, Olivier L. de Weck, Dov Dori
2013 conf
HCI (28)
Chaiwoo Lee, Richard Myrick, Lisa A. D'Ambrosio, Joseph F. Coughlin, Olivier L. de Weck
2013 conf
CSDM
Ahmad Alabdulkareem, Anas Alfaris, Vivek Sakhrani, Adnan Alsaati, Olivier L. de Weck
2013 conf
CSCW Companion
Daisuke Asai, Jarrod Orszulak, Chaiwoo Lee, Richard Myrick, Lisa A. D'Ambrosio, Joseph F. Coughlin, Olivier L. de Weck
2012 J jnl
Eur. J. Oper. Res.
Jaemyung Ahn, Olivier L. de Weck, Yue Geng, Diego Klabjan
2012 J jnl
Inf. Media Technol.
Daisuke Asai, Jarrod Orszulak, Richard Myrick, Chaiwoo Lee, Lisa A. D'Ambrosio, Kathryn M. Godfrey, Joseph F. Coughlin, Olivier L. de Weck
2012 J jnl
J. Inf. Process.
Daisuke Asai, Jarrod Orszulak, Richard Myrick, Chaiwoo Lee, Lisa A. D'Ambrosio, Kathryn M. Godfrey, Joseph F. Coughlin, Olivier L. de Weck
2012 J jnl
IEEE Trans. Smart Grid
Husam Suleiman, Khaja Altaf Ahmed, Nauman Zafar, Emine Phillips, Davor Svetinovic, Olivier L. de Weck
2012 B conf
SMC
Chaiwoo Lee, Paul T. Grogan, Olivier L. de Weck
2011 B conf
SMC
Daisuke Asai, Jarrod Orszulak, Richard Myrick, Chaiwoo Lee, Joseph F. Coughlin, Olivier L. de Weck
2011 J jnl
Syst. Eng.
Amira Sharon, Olivier L. de Weck, Dov Dori
2007 J jnl
J. Intell. Manuf.
Dominic P. Hauser, Olivier L. de Weck
2007 J jnl
Syst. Eng.
Matthew R. Silver, Olivier L. de Weck
2006 J jnl
Syst. Eng.
Olivier L. de Weck, Marshall B. Jones
2005 J jnl
Int. J. Satell. Commun. Netw.
Darren D. Chang, Olivier L. de Weck
2004 J jnl
J. Aerosp. Comput. Inf. Commun.
Olivier L. de Weck, Richard de Neufville, Mathieu Chaize
2003 conf
Modelling, Identification and Control
Kin Cheong Sou, Olivier L. de Weck
CLAUDE.md
← Index CLAUDE.md markdown
# CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

## Project Overview

REDB (RationalEdge Samples DB) is a malware analysis framework that extracts features from PE (Portable Executable) files and stores them in ClickHouse database for analysis. It provides a comprehensive set of extractors for analyzing binary samples including PE headers, imports, resources, signatures, and decompiled code.

## Common Commands

### Development Setup
```bash
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

# Run the main application
python start.py --path /path/to/samples --repo sample_repo --index_prefix redb
```

### Analysis Commands
```bash
# Process a single file
python start.py --path /path/to/binary --repo test --index_prefix redb

# Process from S3 storage
python start.py --s3 --repo malpedia --index_prefix redb

# Process from S3 storage but only a subset of a specific repository
python start.py --s3 --repo "vx-itw" --s3-notes "ITW.0138" --index_prefix redb

# Run only decompilation
python start.py --path /path/to/binary --repo test --index_prefix redb --decompile

# Run specific modules
python start.py --path /path/to/binary --repo test --index_prefix redb --modules "BasicPropertiesExtractor,PEFeaturesExtractor"

# Run as Nomad job (for containerized deployment)
python start.py --nomad-job
```

### Testing
There are no formal unit tests. Testing is done by running the extractors on sample files in the `test_files/` directory.

## Architecture Overview

### Core Components

1. **Ingestor (`redb/ingestor.py`)**: Main orchestrator that handles file processing, multiprocessing, and coordinates extractors
2. **Extractors (`redb/extractors/`)**: Modular analysis components that extract specific features
3. **Database Exporters (`redb/extractors/database_exporters.py`)**: Handle data export to ClickHouse
4. **Settings (`redb/settings/`)**: Configuration management for database connections

### Extractor Architecture

All extractors inherit from the base `Extractor` class and implement:
- `extract()`: Main analysis logic
- `prepare_export_data()`: Format data for database export
- `get_clickhouse_table()`: Return target table name

Available extractors:
- **General**: BasicPropertiesExtractor, HashExtractor, DIEExtractor, CAPAExtractor
- **PE-specific**: PEFeaturesExtractor, PEImportExtractor, PEResourceExtractor, PEOverlayExtractor, PESectionExtractor, PESignatureExtractor, PEDotNetExtractor, PEInconstistencyTestsExtractor, PEExtraFindings
- **ELF**: ELFFeaturesExtractor, ELFSegmentExtractor, ELFSectionExtractor, ELFDependencyExtractor, ELFSymbolExtractor, ELFImportExtractor, ELFExportExtractor, ELFRelocationExtractor, ELFNotesExtractor
- **Mach-O**: MachOFeaturesExtractor, MachOSegmentExtractor, MachOImportExtractor, MachOExportExtractor, MachODylibExtractor, MachOSignatureExtractor
- **APK**: APKFeaturesExtractor, APKManifestExtractor, APKPermissionsExtractor, APKSignatureExtractor, APKDexExtractor, APKResourceExtractor, APKNativeLibExtractor, APKInconsistencyTestsExtractor
- **Decompilation**: DecompileBinja, DecompileAPK

### Database Schema

The project uses a comprehensive ClickHouse schema defined in `redb/redb_schema.yml` with tables for:
- Basic properties (`redb_basic_properties`)
- PE features (`redb_pe_features`, `redb_pe_imports`, `redb_pe_sections`, etc.)
- Decompiled code (`code_binja_decompiled_functions_content`, `code_binja_decompiled_functions_references`)
- CAPA analysis (`redb_capa`, `redb_capa_capabilities`)

Full schema documentation is available in `docs/database_schema.md`.

### Processing Modes

1. **Analysis Mode**: Extracts features using selected modules
2. **Decompile Mode**: Uses Binary Ninja for code decompilation
3. **S3 Mode**: Fetches samples from S3 storage based on catalog queries
4. **Nomad Job Mode**: Processes single jobs using environment variables for containerized deployment

### Configuration

Environment variables are used for configuration:
- Database connection: `CLICKHOUSE_HOST`, `CLICKHOUSE_PORT`, `CLICKHOUSE_USER`, `CLICKHOUSE_PASSWORD`
- S3 storage: `S3_ENDPOINT`, `S3_ACCESS_KEY`, `S3_SECRET_KEY`
- Processing: `BATCH_SIZE`, `REDB_TIMEOUT`, `DECOMPILE_WORKER_TIMEOUT`
- Nomad jobs: `JOB_ID`, `S3_KEY`, `S3_BUCKET`, `WORKER_TYPE`, `CALLBACK_URL`, `ANALYSIS_MODULES`

## Important Implementation Details

### Multiprocessing
- Uses `spawn` method for multiprocessing to avoid memory issues
- Worker processes have timeout handlers to prevent hanging
- Supports both batch processing and streaming processing modes

### Memory Management
- Implements aggressive garbage collection between batches
- Monitors swap usage and restarts worker pools when needed
- Kills stuck processes automatically

### Error Handling
- Comprehensive logging with per-file context
- Graceful handling of corrupted or unsupported files
- Automatic retry logic for database operations

### Security Context
This is a defensive security tool for malware analysis. It processes potentially malicious files in a controlled environment to extract features for detection and analysis purposes.

## Development Notes

- The codebase is optimized for processing large batches of malware samples
- Extractors are designed to be modular and can be run individually or in combination
- Database schema supports both normalized and denormalized views for different query patterns
- S3 integration allows for scalable processing of large malware repositories