Omar S. Al-Kadi

44 papers B 1C 1Journal 38Unranked 4
YearRankTypeTitle / Venue / Authors
2025 conf
ICIT
Israa Al Badarneh, Bassam H. Hammo, Omar S. Al-Kadi
2025 J jnl
CoRR
Israa Al Badarneh, Bassam Hammo, Omar S. Al-Kadi
2025 J jnl
Comput. Electr. Eng.
Israa Al Badarneh, Bassam H. Hammo, Omar S. Al-Kadi
2025 J jnl
Neural Comput. Appl.
Israa Al Badarneh, Rana Husni Al Mahmoud, Bassam H. Hammo, Omar S. Al-Kadi
2025 J jnl
CoRR
Israa A. Albadarneh, Bassam H. Hammo, Omar S. Al-Kadi
2025 J jnl
Comput. Sci. Rev.
Israa A. Albadarneh, Bassam H. Hammo, Omar S. Al-Kadi
2025 J jnl
CoRR
Fatima Haimour, Rizik M. H. Al-Sayyed, Waleed Mahafza, Omar S. Al-Kadi
2025 J jnl
Multim. Tools Appl.
Mohammad Qawasmi, Omar S. Al-Kadi
2025 J jnl
Pattern Recognit. Lett.
Abdel Rahman Alsabbagh, Tariq Mansour, Mohammad Al-Kharabsheh, Abdel Salam Ebdah, Roa'a Al-Emaryeen, Sara Al-Nahhas, Waleed Mahafza, Omar S. Al-Kadi
2024 J jnl
Comput. Vis. Image Underst.
Fatima Haimour, Rizik M. H. Al-Sayyed, Waleed Mahafza, Omar S. Al-Kadi
2024 J jnl
CoRR
Abdel Rahman Alsabbagh, Omar S. Al-Kadi
2024 J jnl
CoRR
Hani Y. Ayyoub, Omar S. Al-Kadi
2024 J jnl
IEEE Trans. Learn. Technol.
Hani Ayyoub, Omar S. Al-Kadi
2023 J jnl
Comput. Secur.
Abdullah Alzaqebah, Ibrahim Aljarah, Omar S. Al-Kadi
2023 J jnl
Prog. Artif. Intell.
Abdullah Alzaqebah, Omar S. Al-Kadi, Ibrahim Aljarah
2023 J jnl
CoRR
Roa'a Al-Emaryeen, Sara Al-Nahhas, Fatima Himour, Waleed Mahafza, Omar S. Al-Kadi
2022 J jnl
J. King Saud Univ. Comput. Inf. Sci.
Alaa Abu-Srhan, Mohammad A. M. Abushariah, Omar S. Al-Kadi
2021 J jnl
Commun. ACM
Seif Eldawlatly, Mohamed Abouelhoda, Omar S. Al-Kadi, Takashi Gojobori, Boris R. Jankovic, Mohamad Khalil, Ahsan H. Khandoker, Ahmed Morsy
2021 J jnl
Comput. Biol. Medicine
Alaa Abu-Srhan, Israa Almallahi, Mohammad A. M. Abushariah, Waleed Mahafza, Omar S. Al-Kadi
2020 J jnl
CoRR
Bilal Abu-Salih, Kit Yan Chan, Omar S. Al-Kadi, Marwan Al-Tawil, Pornpit Wongthongtham, Tomayess Issa, Heba Saadeh, Malak Al-Hassan, Bushra Bremie, Abdulaziz Albahlal
2020 J jnl
CoRR
Omar S. Al-Kadi
2020 J jnl
IEEE Trans. Biomed. Eng.
Omar S. Al-Kadi
2020 J jnl
J. Big Data
Bilal Abu-Salih, Kit Yan Chan, Omar S. Al-Kadi, Marwan Al-Tawil, Pornpit Wongthongtham, Tomayess Issa, Heba Saadeh, Malak Al-Hassan, Bushra Bremie, Abdulaziz Albahlal
2019 J jnl
CoRR
Omar S. Al-Kadi, Daniel Y. F. Chung, Constantin-C. Coussios, J. Alison Noble
2019 J jnl
CoRR
Omar S. Al-Kadi
2019 J jnl
CoRR
Omar S. Al-Kadi
2018 conf
STACOM@MICCAI
Omar S. Al-Kadi, Allen Lu, Albert J. Sinusas, James S. Duncan
2017 J jnl
CoRR
Omar S. Al-Kadi
2016 J jnl
CoRR
Omar S. Al-Kadi
2016 conf
MICCAI (1)
Omar S. Al-Kadi, Dimitri Van De Ville, Adrien Depeursinge
2016 J jnl
CoRR
Omar S. Al-Kadi, Daniel Y. F. Chung, Robert C. Carlisle, Constantin-C. Coussios, J. Alison Noble
2016 J jnl
CoRR
Omar S. Al-Kadi
2016 J jnl
CoRR
Omar S. Al-Kadi, D. Watson
2015 J jnl
CoRR
Omar S. Al-Kadi
2015 J jnl
Comput. Medical Imaging Graph.
Omar S. Al-Kadi
2015 J jnl
CoRR
Omar S. Al-Kadi
2015 J jnl
Medical Image Anal.
Omar S. Al-Kadi, Daniel Y. F. Chung, Robert C. Carlisle, Constantin-C. Coussios, J. Alison Noble
2015 J jnl
CoRR
Omar S. Al-Kadi
2014 J jnl
Frontiers Comput. Sci.
Omar S. Al-Kadi, Osama Al-Kadi, Rizik M. H. Al-Sayyed, Ja'far Alqatawna
2012 conf
Computer-Aided Diagnosis
Raja' S. Alomari, Subarna Ghosh, Vipin Chaudhary, Omar S. Al-Kadi
2010 J jnl
Pattern Recognit.
Omar S. Al-Kadi
2009 B conf
ICIP
Omar S. Al-Kadi
2008 C conf
BIBE
Omar S. Al-Kadi, D. Watson
2008 J jnl
IEEE Trans. Biomed. Eng.
Omar S. Al-Kadi, D. Watson
redb/extractors/js_extractor.py
← Index redb/extractors/js_extractor.py python
import logging
import re
from abc import ABCMeta, abstractmethod

from redb.extractors.extractor import Extractor
from redb.extractors.js_extractors.js_context import JSContext, _text_entropy

logger = logging.getLogger(__name__)

# ESM is recognised by line-anchored `import ... from "..."` / bare side-effect
# `import "..."` / top-level `export ...`. Anchored at line start to avoid
# matching the substring inside string literals or comments.
_ESM_PATTERN = re.compile(
    r'(?m)^\s*(?:'
    r'import\s+[^;\n]*?\bfrom\s+[\'"]'
    r'|import\s+[\'"][^\'"]+[\'"]'
    r'|export\s+(?:default\b|\{|\*|const\b|let\b|var\b|function\b|class\b|async\b)'
    r')'
)


@abstractmethod
class JSExtractor(Extractor, metaclass=ABCMeta):
    """Base class for JavaScript file extractors.

    Every JSExtractor reads its raw materials (bytes / decoded source / line
    list / scan_source results / pyjsparser AST / text entropy) from a shared
    `JSContext`. When workers.py drives the JS pipeline it builds one context
    per sample and threads it into every extractor via `context=`. When tests
    or other callers instantiate an extractor directly, the constructor builds
    a fresh context from `(filepath, source=...)`.

    All historical instance attributes (`self.binary`, `self.js_source`,
    `self.lines`) and helpers (`self._decode_source`, `self._parse_ast`,
    `self._calculate_text_entropy`) are preserved as thin delegators so
    existing extractor code keeps working unchanged.
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        known_benign=False,
        known_malicious=False,
        source=None,
        context=None,
    ):
        if context is None:
            context = JSContext.from_path(filepath, log=log, source=source)
        elif source is not None and context.source != source:
            log.warning(
                "JSExtractor received both `source=` and `context=` with "
                "differing source; ignoring source kwarg"
            )
        self._context = context

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            known_benign=known_benign,
            known_malicious=known_malicious,
        )

    @property
    def binary(self):
        return self._context.raw_bytes

    @property
    def js_source(self):
        return self._context.source

    @property
    def lines(self):
        return self._context.lines

    def _decode_source(self):
        """Back-compat shim — the context already decoded once at construction.

        Kept so any external caller using the historical method name keeps
        working without touching the underlying bytes again.
        """
        return self._context.source

    def _parse_ast(self):
        """Return the shared pyjsparser AST (or None if unavailable)."""
        return self._context.ast

    def _calculate_text_entropy(self, text):
        """Shannon text entropy for `text`.

        When `text` is the context's own source we read the cached value;
        otherwise we compute fresh. JSStringsExtractor calls this on arbitrary
        decoded substrings, so the fresh-compute path must remain available.
        """
        if text is self._context.source:
            return self._context.text_entropy
        return _text_entropy(text)

    def _detect_environment(self):
        """Detect the target JS runtime environment."""
        src = self.js_source
        if not src:
            return "unknown"

        # WScript/WSH indicators
        wscript_patterns = [
            'WScript.', 'WSH.', 'ActiveXObject', 'Scripting.FileSystemObject',
            'WScript.Shell', 'ADODB.Stream',
        ]
        for p in wscript_patterns:
            if p in src:
                return "wscript"

        # Browser-extension APIs — checked before generic browser/worker because
        # `chrome.*` and `browser.runtime` are distinctive of MV2/MV3 extensions
        extension_patterns = [
            'chrome.runtime', 'chrome.tabs', 'chrome.storage',
            'chrome.webRequest', 'browser.runtime', 'browser.tabs',
        ]
        for p in extension_patterns:
            if p in src:
                return "browser_extension"

        # Service / Web Workers — worker-only APIs that don't appear in regular
        # browser pages (a generic browser script would use `window.` or
        # `document.`, never `self.importScripts` or `caches.match`)
        worker_patterns = [
            "self.addEventListener('fetch'", 'self.addEventListener("fetch"',
            'self.importScripts', 'self.skipWaiting',
            'caches.match', 'caches.open',
        ]
        for p in worker_patterns:
            if p in src:
                return "service_worker"

        # Deno runtime
        if 'Deno.' in src:
            return "deno"

        # Node.js indicators
        node_patterns = [
            'require(', 'module.exports', 'process.env', '__dirname',
            '__filename', 'Buffer.', 'child_process',
        ]
        for p in node_patterns:
            if p in src:
                return "node"

        # Browser indicators
        browser_patterns = [
            'document.', 'window.', 'navigator.', 'localStorage',
            'sessionStorage', 'XMLHttpRequest', 'addEventListener',
        ]
        for p in browser_patterns:
            if p in src:
                return "browser"

        return "unknown"

    def _detect_script_type(self):
        """Detect the script type/format."""
        src = self.js_source
        if not src:
            return "unknown"

        stripped = src.lstrip()

        # JScript.Encode payload — must be checked first since the encoded
        # body can't be classified any other way
        if stripped.startswith('#@~^'):
            return "jse"

        # WSF / HTA live in the first few KB of an HTML-ish wrapper
        head_lower = stripped[:4096].lower()

        # Windows Script File — XML wrapper around one or more <script> blocks
        if ('<job' in head_lower or '<package' in head_lower) and '<script' in head_lower:
            return "wsf"

        # HTML Application — distinct from generic embedded_html because HTAs
        # run under mshta.exe with full WSH/ActiveX access
        if '<hta:application' in head_lower or 'application/hta' in head_lower:
            return "hta"

        if stripped.startswith('<!') or stripped.startswith('<html') or '<script' in stripped[:2000]:
            return "embedded_html"

        if 'WScript.' in src or 'WSH.' in src:
            return "wscript"

        if _ESM_PATTERN.search(src):
            return "esm"

        if 'require(' in src or 'module.exports' in src:
            return "node_module"

        return "standalone"