Omar Cherkaoui

81 papers A* 2B 18C 5Journal 20Unranked 36
YearRankTypeTitle / Venue / Authors
2024 J jnl
Sensors
Abdelkrim Boumegnane, Said Douhi, Assia Batine, Thibault Dormois, Cédric Cochrane, Ayoub Nadi, Omar Cherkaoui, Mohamed Tahiri
2021 J jnl
Sensors
Ahmed Abed, Zineb Samouh, Cédric Cochrane, François Boussu, Omar Cherkaoui, Reddad El Moznine, Julien Vieillard
2017 J jnl
J. Netw. Syst. Manag.
Eric Lunaud Ngoupe, Clément Parisot, Sylvain Stoesel, Petko Valtchev, Roger Villemaire, Omar Cherkaoui, Pierre Boucher, Sylvain Hallé
2017 J jnl
Comput. Networks
Thibaut Stimpfling, Normand Bélanger, Omar Cherkaoui, André Béliveau, Ludovic Béliveau, Yvon Savaria
2017 C conf
ADMA
Manxing Du, Redouane Sassioui, Georgios Varisteas, Radu State, Mats Brorsson, Omar Cherkaoui
2017 B conf
NCA
Stefan Hommes, Petko Valtchev, Khalil Blaiech, Salaheddine Hamadi, Omar Cherkaoui, Radu State
2017 conf
ANCS
Khalil Blaiech, Salaheddine Hamadi, Stefan Hommes, Petko Valtchev, Omar Cherkaoui, Radu State
2016 A* conf
INFOCOM
Salaheddine Hamadi, Khalil Blaiech, Petko Valtchev, Omar Cherkaoui, Radu State
2015 B conf
IM
Eric Lunaud Ngoupe, Sylvain Stoesel, Clément Parisot, Sylvain Hallé, Petko Valtchev, Omar Cherkaoui, Pierre Boucher
2015 C conf
KSEM
Petko Valtchev, Omar Mounaouar, Omar Cherkaoui, Alexandar Dimitrov
2015 conf
CFIP/NOTERE
Salaheddine Hamadi, Khalil Blaiech, Omar Cherkaoui
2015 B conf
NetSoft
Khalil Blaiech, Salaheddine Hamadi, Petko Valtchev, Omar Cherkaoui, André Béliveau
2015 conf
BigSystem@HPDC
Khalil Blaiech, Omar Cherkaoui
2014 B conf
ICECCS
Eric Lunaud Ngoupe, Sylvain Stoesel, Clément Parisot, Sylvain Hallé, Petko Valtchev, Omar Cherkaoui, Pierre Boucher
2014 conf
GIIS
Rudy Deca, Omar Cherkaoui, Yvon Savaria
2014 conf
CloudNet
Khalil Blaiech, Salaheddine Hamadi, Amina Mseddi, Omar Cherkaoui
2014 conf
GIIS
Salaheddine Hamadi, Ilyas Snaiki, Omar Cherkaoui
2014 conf
WWIC
Nihed Bahria El Asghar, Omar Cherkaoui, Mounir Frikha, Sami Tabbane
2014 B conf
IC2E
Khalil Blaiech, Omar Mounaouar, Omar Cherkaoui, Ludovic Béliveau
2014 conf
OTM Conferences
Nihed Bahria El Asghar, Omar Cherkaoui, Mounir Frikha, Sami Tabbane
2013 B conf
IM
Sylvain Hallé, Eric Lunaud Ngoupe, Roger Villemaire, Omar Cherkaoui
2013 conf
Med-Hoc-Net
Omar Cherkaoui, Catherine Rosenberg
2013 conf
HPPN@HPDC
Thibaut Stimpfling, Yvon Savaria, André Béliveau, Normand Bélanger, Omar Cherkaoui
2013 conf
Med-Hoc-Net
Imen Limam Bedhiaf, Richard Burguin, Omar Cherkaoui, Mikaël Salaün
2012 J jnl
Trans. Comput. Sci.
Sylvain Hallé, Roger Villemaire, Omar Cherkaoui, Rudy Deca
2012 J jnl
J. Internet Serv. Appl.
Hakim Mellah, Omar Cherkaoui, Yves Lemieux
2012 J jnl
CoRR
Petko Valtchev, Omar Mounaouar, Omar Cherkaoui, Alexandar Dimitrov, Laurent Marchand
2012 B conf
GLOBECOM
Imen Limam Bedhiaf, Racha Ben Ali, Omar Cherkaoui
2012 conf
ICC
Omar El Ferkouss, Racha Ben Ali, Yves Lemieux, Omar Cherkaoui
2012 J jnl
J. Networks
Rudy Deca, Omar Cherkaoui, Yvon Savaria
2012 B conf
NOMS
Sylvain Hallé, Omar Cherkaoui, Petko Valtchev
2012 B conf
NOMS
Sylvain Hallé, Eric Lunaud Ngoupe, Gaetan Nijdam, Omar Cherkaoui, Petko Valtchev, Roger Villemaire
2011 B conf
CNSM
Omar El Ferkouss, Ilyas Snaiki, Omar Mounaouar, Hamza Dahmouni, Racha Ben Ali, Yves Lemieux, Omar Cherkaoui
2011 J jnl
IEEE Commun. Mag.
Charles L. Despins, Fabrice Labeau, Tho Le-Ngoc, Richard Labelle, Mohamed Cheriet, Claude Thibeault, François Gagnon, Alberto Leon-Garcia, Omar Cherkaoui, Bill St. Arnaud, Jacques Mcneill, Yves Lemieux, Mathieu Lemay
2011 B conf
WCNC
Sergio Luis O. B. Correia, Joaquim Celestino Jr., Omar Cherkaoui
2011 B conf
GLOBECOM
Omar El Ferkouss, Sergio Luis O. B. Correia, Racha Ben Ali, Yves Lemieux, Martin Julien, Mallik Tatipamula, Omar Cherkaoui
2011 conf
WOCN
Bochra Boughzala, Racha Ben Ali, Mathieu Lemay, Yves Lemieux, Omar Cherkaoui
2011 conf
NCCA
Mohammed El-azzab, Imen Limam Bedhiaf, Yves Lemieux, Omar Cherkaoui
2010 J jnl
Telecommun. Syst.
Halima Elbiaze, Mohamed Faten Zhani, Omar Cherkaoui, Farouk Kamoun
2010 conf
NGI
Kamal Bouyoucef, Imen Limam Bedhiaf, Omar Cherkaoui
2010 conf
ICC
Imen Limam Bedhiaf, Omar Cherkaoui
2010 J jnl
Int. J. Netw. Manag.
Omar Cherkaoui, Olivier Festor, Lisandro Zambenedetti Granville
2009 J jnl
Ann. des Télécommunications
Omar Cherkaoui, Masum Z. Hasan, Guy Pujolle
2009 J jnl
IEEE Trans. Software Eng.
Sylvain Hallé, Roger Villemaire, Omar Cherkaoui
2009 J jnl
Ann. des Télécommunications
Imen Limam Bedhiaf, Omar Cherkaoui, Guy Pujolle
2008 J jnl
Int. J. Netw. Manag.
Omar Cherkaoui, Halima Elbiaze
2007 conf
Software Engineering Research and Practice
Martin Lesage, Omar Cherkaoui, Faysal Abouzaid, Martin Poirier, Gilles Raîche
2007 B conf
SMC
Martin Lesage, Omar Cherkaoui, Faysal Abouzaid, Martin Poirier, Gilles Raîche, Martin Riopel
2007 J jnl
Ann. des Télécommunications
Rudy Deca, Omar Cherkaoui, Yvon Savaria, Doug Slone
2007 conf
WS-FM
Sylvain Hallé, Roger Villemaire, Omar Cherkaoui, Jérôme Tremblay, Boubker Ghandour
2007 B conf
EDOC
Sylvain Hallé, Roger Villemaire, Omar Cherkaoui, Boubker Ghandour
2007 J jnl
Opt. Switch. Netw.
Halima Elbiaze, Omar Cherkaoui
2006 C conf
TIME
Sylvain Hallé, Roger Villemaire, Omar Cherkaoui
2006 conf
Autonomic Networking
Sylvain Hallé, Eric P. Wenaas, Roger Villemaire, Omar Cherkaoui
2005 B conf
MASCOTS
Halima Elbiaze, Omar Cherkaoui, B. McGibbon, M. Blais
2005 C conf
TIME
Roger Villemaire, Sylvain Hallé, Omar Cherkaoui
2005 conf
ICAS/ICNS
Halima Elbiaze, Omar Cherkaoui
2005 conf
Net-Con
Sylvain Hallé, Rudy Deca, Omar Cherkaoui, Roger Villemaire, Daniel Puche
2004 conf
DSOM
Sylvain Hallé, Rudy Deca, Omar Cherkaoui, Roger Villemaire, Daniel Puche
2004 conf
CNSR
Rudy Deca, Omar Cherkaoui, Daniel Puche
2004 conf
NOMS (1)
T. Dieu Linh Truong, Omar Cherkaoui, Halima Elbiaze, Nathalie Rico, El Mostapha Aboulhamid
2004 conf
Computer Supported Acitivity Coordination
Sabri Boutemedjet, Faysal Abouzaid, Omar Cherkaoui, Gilles Gauthier
2004 conf
MMNS
Sylvain Hallé, Rudy Deca, Omar Cherkaoui, Roger Villemaire
2004 conf
Net-Con
Rudy Deca, Omar Cherkaoui, Daniel Puche
2004 J jnl
IEEE Commun. Mag.
Christian Allegre, Omar Cherkaoui
2004 conf
RIVF
Viet Minh Nhat Vo, Omar Cherkaoui
2004 J jnl
Proc. IEEE
Bill St. Arnaud, Andrew K. Bjerring, Omar Cherkaoui, Raouf Boutaba, Martin Pott, Wade Hong
2003 conf
Net-Con
Nathalie Rico, Omar Cherkaoui, Halima Elbiaze
2003 conf
DSOM
Omar Cherkaoui, Nathalie Rico, T. Dieu Linh Truong, Halima Elbiaze, Viet Minh Nhat Vo
2002 conf
DSOM
Yijun Zeng, Omar Cherkaoui
1999 J jnl
Inf. Softw. Technol.
Rachida Dssouli, Kamel Karoui, Kassem Saleh, Omar Cherkaoui
1999 conf
DSOM
Salima Omari, Raouf Boutaba, Omar Cherkaoui
1999 conf
Integrated Network Management
Salima Omari, Raouf Boutaba, Omar Cherkaoui
1999 conf
Integrated Network Management
Omar Cherkaoui, Nathalie Rico, Ahmed Serhrouchni
1999 conf
TOOLS (30)
Hafedh Mili, Joumana Dargham, Omar Cherkaoui, Robert Godin, Ali Mili
1998 B conf
NOMS
Omar Cherkaoui, Abdellatif Obaid, Ahmed Serhrouchni, Noëmie Simoni
1998 C conf
ISCC
Omar Cherkaoui, Ylian Saint Hillaire, Hafedh Mili, Abdellatif Obaid, Ahmed Serhrouchni
1998 B conf
NOMS
Omar Cherkaoui, Ylian Saint-Hilaire, Hafedh Mili, Ahmed Serhrouchni
1994 B conf
NOMS
A. Bemardi, Nathalie Rico, Omar Cherkaoui, J. Banfield
1994 conf
FME
Omar Cherkaoui
1992 A* conf
CAV
Nathalie Rico, Gregor von Bochmann, Omar Cherkaoui
redb/extractors/ioc_extractor/ioc_extractor.py
← Index redb/extractors/ioc_extractor/ioc_extractor.py python
"""
IOC Extractor - Extractor class for extracting IOCs from decompilation results.

This extractor works with in-memory data from DecompileBinja, following the
standard Extractor pattern to support both ClickHouse and PrintExporter (dry-run).

Usage:
    # After DecompileBinja completes:
    ioc_extractor = IOCExtractorFromResults(
        analysis_results=decompiler.analysis_results,
        sha256=sha256,
        log=logger,
        exporters=exporters,
        index_prefix=index_prefix
    )
    ioc_extractor.export_data()
"""

import inspect
from datetime import datetime, timezone
from pathlib import Path
from typing import Any, List, Dict, Optional

from redb.extractors.enum import Tag
from redb.extractors.database_exporters import DatabaseExporter

# Import the IOCScraper and related classes from standalone module
from redb.extractors.ioc_extractor.standalone_ioc_extractor import (
    IOCScraper,
    IOCType,
    SourceType,
    ExtractedIOC,
)
from typing import Set


class IOCExtractorFromResults:
    """
    Extracts IOCs from in-memory decompilation results.

    This follows a simplified Extractor pattern but doesn't inherit from Extractor
    since it doesn't read from a binary file - instead it takes already-processed
    analysis results from DecompileBinja.
    """

    def __init__(
        self,
        analysis_results: Dict[str, Any],
        sha256: str,
        log: Any,
        exporters: Optional[List[DatabaseExporter]] = None,
        index_prefix: Optional[str] = None,
        tld_file: Optional[Path] = None,
        suppress_types: Optional[Set[IOCType]] = None,
        js_context: bool = False,
    ):
        """
        Initialize IOC Extractor with analysis results.

        Args:
            analysis_results: Dict containing 'strings' and 'decompiled' lists from DecompileBinja
            sha256: Sample SHA256 hash
            log: Logger instance
            exporters: List of database exporters (ClickHouse, Print, etc.)
            index_prefix: Index prefix for database
            tld_file: Optional path to TLD list file
            js_context: When True, the underlying IOCScraper rejects FQDN
                candidates that match JS object-access syntax (see
                JS_FP_TLDS / JS_FP_SLDS). Set this for the JS pipeline only;
                APK suppresses FQDN entirely via suppress_types and binary
                callers leave it disabled.
        """
        self.log = log
        self.log.debug(f"Creating {self.__class__.__name__}")
        self.analysis_results = analysis_results
        self.sha256 = sha256
        self.exporters = exporters or []
        self.index_prefix = index_prefix
        self.scraper = IOCScraper(
            tld_file, suppress_types=suppress_types, js_context=js_context,
        )
        self.extracted_iocs: List[ExtractedIOC] = []

    def extract(self) -> List[ExtractedIOC]:
        """
        Extract IOCs from strings and decompiled functions in analysis_results.

        Returns:
            List of ExtractedIOC objects
        """
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.extracted_iocs = []

        # Extract from strings
        strings_count = self._extract_from_strings()

        # Extract from decompiled functions
        functions_count = self._extract_from_decompiled()

        # Extract from text-based artefact surfaces (JS, PowerShell, etc.)
        text_count = self._extract_from_text()

        self.log.info(
            f"Extracted {len(self.extracted_iocs)} IOCs for {self.sha256[:16]}... "
            f"(strings: {strings_count}, functions: {functions_count}, "
            f"text: {text_count})"
        )

        return self.extracted_iocs

    def _extract_from_strings(self) -> int:
        """Extract IOCs from sample's strings."""
        count = 0
        strings = self.analysis_results.get("strings", [])

        for s in strings:
            string_value = s.get("string", "")
            string_offset = s.get("string_offset", 0)

            if isinstance(string_value, bytes):
                string_value = string_value.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(string_value, SourceType.STRING, str(string_offset)):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_decompiled(self) -> int:
        """Extract IOCs from sample's decompiled functions.

        Supports both Binja format (key: "decompiled", fields: "decompiled_function",
        "decompiled_function_hash", "function_type") and APK format (key:
        "decompiled_content", fields: "decompiled_method", "decompiled_method_hash",
        "method_type").
        """
        count = 0

        # Binja format
        decompiled = self.analysis_results.get("decompiled", [])
        for func in decompiled:
            func_type = func.get("function_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_function", "")
            func_hash = func.get("decompiled_function_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        # APK format (decompiled_content with method-level fields)
        decompiled_content = self.analysis_results.get("decompiled_content", [])
        for func in decompiled_content:
            func_type = func.get("method_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_method", "")
            func_hash = func.get("decompiled_method_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_text(self) -> int:
        """Extract IOCs from text-based artefact surfaces.

        Walks `analysis_results["text_raw"]` and `analysis_results["text_normalized"]`,
        each a list of `{"content": str, "content_hash": str}` dicts. Each
        list is routed through its own SourceType (`TEXT_RAW` /
        `TEXT_NORMALIZED`) so analysts can distinguish IOCs that were already
        present in the raw source from those exposed only after normalisation
        (deobfuscation/beautification). Generic across text-based formats —
        used by JS today, intended for PowerShell, Python, email body,
        extracted PDF/Office text in the future.
        """
        count = 0

        for key, source_type in (
            ("text_raw", SourceType.TEXT_RAW),
            ("text_normalized", SourceType.TEXT_NORMALIZED),
        ):
            for entry in self.analysis_results.get(key, []):
                content = entry.get("content", "")
                content_hash = entry.get("content_hash", "unknown")

                if isinstance(content, bytes):
                    content = content.decode('utf-8', errors='replace')

                for ioc in self.scraper.scrape(content, source_type, content_hash):
                    self.extracted_iocs.append(ioc)
                    count += 1

        return count

    def prepare_export_data(self, exporter_type: str) -> Any:
        """
        Prepare data for specific export type.

        Returns tuple for ClickHouse or list of dicts for Print/Elasticsearch.
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        if not self.extracted_iocs:
            return None

        now = datetime.now(timezone.utc)

        if exporter_type == "ClickHouseExporter":
            data = [
                [
                    self.sha256,
                    ioc.ioc_type.value,
                    ioc.ioc_value,
                    ioc.source_type.value,
                    ioc.source_identifier,
                    now,
                ]
                for ioc in self.extracted_iocs
            ]

            column_names = [
                "sha256",
                "ioc_type",
                "ioc_value",
                "source_type",
                "source_identifier",
                "extracted_at",
            ]

            column_type_names = [
                "FixedString(64)",
                "Enum8('ipv4'=1, 'ipv6'=2, 'fqdn'=3, 'url'=4, 'email'=5, 'server'=6, "
                "'hash_md5'=10, 'hash_sha1'=11, 'hash_sha256'=12, 'cve'=20, 'cwe'=21, 'cpe'=22, "
                "'crypto_btc'=30, 'crypto_eth'=31, 'crypto_xrp'=32, 'crypto_bch'=33, "
                "'crypto_ada'=34, 'crypto_substrate'=35, 'path_linux'=40, 'path_windows'=41, "
                "'registry_key'=42, 'onion'=50)",
                "String",
                "Enum8('decompiled_function'=1, 'disassembled_function'=2, 'string'=3, "
                "'text_raw'=4, 'text_normalized'=5)",
                "String",
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

        else:
            # For PrintExporter and others - return list of dicts
            return [
                {
                    "sha256": self.sha256,
                    "ioc_type": ioc.ioc_type.value,
                    "ioc_value": ioc.ioc_value,
                    "source_type": ioc.source_type.value,
                    "source_identifier": ioc.source_identifier,
                    "extracted_at": now.isoformat(),
                }
                for ioc in self.extracted_iocs
            ]

    def get_clickhouse_table(self) -> str:
        """Return the ClickHouse table name for IOCs."""
        return "redb_iocs"

    def tag(self) -> str:
        """Return the tag for this extractor."""
        return Tag.IOC.value if hasattr(Tag, 'IOC') else "ioc"

    def export_data(self) -> bool:
        """
        Export extracted IOCs to all configured exporters.

        Returns:
            True if export succeeded, False if failed, None if no data
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # First extract the IOCs
        extracted = self.extract()

        if not extracted:
            self.log.debug("No IOCs extracted, skipping export")
            return None

        success = True

        from redb.extractors.database_exporters import PrintExporter, ClickHouseExporter

        for exporter in self.exporters:
            try:
                if isinstance(exporter, PrintExporter):
                    # For PrintExporter, pass the list of dicts
                    export_data = self.prepare_export_data("PrintExporter")
                    success &= exporter.export(export_data)

                elif isinstance(exporter, ClickHouseExporter):
                    # For ClickHouse, pass tuple with table info
                    export_data = self.prepare_export_data("ClickHouseExporter")
                    if export_data:
                        success &= exporter.export(
                            export_data,
                            table=self.get_clickhouse_table(),
                            column_names=export_data[1],
                            column_type_names=export_data[2]
                        )

            except Exception as e:
                self.log.error(f"Error exporting IOCs to {exporter.__class__.__name__}: {e}")
                success = False

        return success