Omar A. Nasr

38 papers B 12C 1Misc 1Journal 11Unranked 13
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Access
Yasser A. Amer, Hassan I. Saleh, Omar A. Nasr
2024 conf
ICM
Abdelrahman Sabry, Abdallah Said, Abdelaziz Mohammad, Abdelrahman Noureldin, Aya Reda, Sohila Akram, Omar A. Nasr, Eman El Mandouh, Mahmoud Abd El Mawgoed, Samer El Saadany, Waleed Aly
2023 conf
NILES
Ahmed Elgohary, Omar A. Nasr
2023 conf
NILES
Mohamed A. Elhewehy, Karim Ossama Abbas, Omar A. Nasr
2023 J jnl
IEEE Access
Tarek Abubakr, Omar A. Nasr
2022 J jnl
IEEE Access
Amel Mohamed Mahmoud, Mohamed Tharwat, Mohamed Magdy, Tarek Abubakr, Omar A. Nasr, Moustafa Youssef
2022 conf
NILES
Mohamed N. Khalifa, Rania O. Hassan, Omar A. Nasr, Hassan Mostafa
2021 J jnl
IEEE Access
Reda Maher, Omar A. Nasr
2019 C conf
ISCAS
Mahmoud Nazmy, Omar A. Nasr, Hossam Ali Hassan Fahmy
2019 B conf
WCNC
Ahmed Elshafiy, Mohammed A. El-Motaz, Mohamed E. Farag, Omar A. Nasr, Hossam A. H. Fahmy
2018 J jnl
Wirel. Networks
Rana D. Hegazy, Omar A. Nasr, Hanan A. Kamal
2018 conf
FMEC
Omar A. Nasr, Yasser Amer, Mohammed AboBakr
2016 B conf
WCNC
Amr M. Shata, Omar A. Nasr, Yasmine A. Fahmy
2016 B conf
WCNC
Mai O. Said, Omar A. Nasr, Tamer A. ElBatt
2015 B conf
WCNC
Mustafa A. Kishk, Omar A. Nasr, Mohamed M. Khairy
2015 conf
ICECS
Mohammed A. El-Motaz, M. Wagih Ismail, Mohsen Raafat, Ali S. Faried, Mohammed A. Raghieb, Nassr M. Ismail, Sherif A. Hafez, Ahmed H. El-Kady, Esmaail A. El-Sayed, Mohamed A. Sharaf, Ibrahim Shazly, Wael E. Abd El-Kawi, Chadi M. Mohamed, Mohamed N. Elhidery, Karim Mohammed, Omar A. Nasr
2015 B conf
WCNC
Rana D. Hegazy, Omar A. Nasr
2015 J jnl
IET Circuits Devices Syst.
M. Abdel All, Hanan M. Hassan, M. Hamdy, Omar A. Nasr, Karim Mohamed, Ahmed F. Shalash
2015 J jnl
Wirel. Pers. Commun.
Ahmed M. Alaa, Omar A. Nasr
2015 conf
ICECS
Mohammed A. El-Motaz, Ahmed M. El-Shafiey, Mohamed E. Farag, Omar A. Nasr, Hossam A. H. Fahmy
2015 conf
ICECS
Ahmed M. El-Shafiey, Mohamed E. Farag, Mohammed A. El-Motaz, Omar A. Nasr, Hossam A. H. Fahmy
2014 B conf
IWCMC
Mohammed A. El-Motaz, Omar A. Nasr, Karim Osama
2014 Misc conf
ICNC
Ahmed M. Alaa, Omar A. Nasr
2014 J jnl
CoRR
Ahmed M. Alaa, Omar A. Nasr
2014 J jnl
Comput. Networks
Alaa Awad, Amr Mohamed, Amr A. El-Sherif, Omar A. Nasr
2013 B conf
PIMRC
Hazem M. Soliman, Omar A. Nasr, Mohamed M. Khairy
2013 conf
AFRICON
Nora A. Ali, Omar A. Nasr
2012 J jnl
EURASIP J. Embed. Syst.
Mahmoud A. Said, Omar A. Nasr, Ahmed F. Shalash
2012 B conf
WCNC
Hazem M. Soliman, Omar A. Nasr, Mohamed M. Khairy
2011 B conf
PIMRC
Mai H. Hassan, Omar A. Nasr
2011 B conf
GLOBECOM
Mohammed A. El-Gendi, Mohamed M. Khairy, Omar A. Nasr
2011 B conf
IWCMC
Alaa Awad, Omar A. Nasr, Mohamed M. Khairy
2011 conf
ISWCS
Hazem M. Soliman, Ahmed A. Naguib, Omar A. Nasr, Mohamed M. Khairy, Khaled M. F. Elsayed
2011 B conf
PIMRC
Alaa Awad, Omar A. Nasr, Mohamed M. Khairy
2010 J jnl
IEEE Commun. Lett.
Omar A. Nasr, Mihaela van der Schaar, Babak Daneshrad
2010 conf
ICC
Omar A. Nasr, Babak Daneshrad
2010 conf
ICC
Omar A. Nasr, Oscar Y. Takeshita, Weijun Zhu, Babak Daneshrad
2006 conf
WiNTECH
Weijun Zhu, Babak Daneshrad, Jatin Bhatia, Jesse Chen, Hun-Seok Kim, Karim Mohammed, Omar A. Nasr, Sandeep Sasi, Anish Shah, Minko Tsai
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"