Omer Tsimhoni

43 papers A* 3A 6B 1C 1Misc 10Journal 17Unranked 5
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Xufang Zhao, Omer Tsimhoni
2024 conf
SM
Xu Fang Zhao, Omer Tsimhoni
2023 Misc conf
ICASSP
Ron M. Hecht, Ohad Rahamim, Shaul Oron, Andrea Forgacs, Gershon Celniker, Dan Levi, Omer Tsimhoni
2022 Misc conf
ICASSP
Ron M. Hecht, Ke Liu, Noa Garnett, Ariel Telpaz, Omer Tsimhoni
2020 B conf
CogSci
Ron M. Hecht, Ariel Telpaz, Gila Kamhi, Omer Tsimhoni, Aharon Bar-Hillel, Naftali Tishby
2019 J jnl
IEEE Trans. Hum. Mach. Syst.
Ron M. Hecht, Aharon Bar-Hillel, Ariel Telpaz, Omer Tsimhoni, Naftali Tishby
2017 J jnl
Cogn. Technol. Work.
Asaf Degani, Claudia V. Goldman, Omer Deutsch, Omer Tsimhoni
2017 J jnl
Int. J. Mob. Hum. Comput. Interact.
Ariel Telpaz, Brian Rhindress, Ido Zelman, Omer Tsimhoni
2016 A* conf
AAAI
Avraham Shvartzon, Amos Azaria, Sarit Kraus, Claudia V. Goldman, Joachim Meyer, Omer Tsimhoni
2015 A conf
AAMAS
Avraham Shvartzon, Amos Azaria, Sarit Kraus, Claudia V. Goldman, Omer Tsimhoni, Joachim Meyer
2015 conf
AAAI Workshop: AI for Transportation
Ariel Rosenfeld, Amos Azaria, Sarit Kraus, Claudia V. Goldman, Omer Tsimhoni
2015 A conf
AAMAS
Ariel Rosenfeld, Amos Azaria, Sarit Kraus, Claudia V. Goldman, Omer Tsimhoni
2015 J jnl
AI Mag.
Amos Azaria, Ariel Rosenfeld, Sarit Kraus, Claudia V. Goldman, Omer Tsimhoni
2015 A conf
INTERSPEECH
Ron M. Hecht, Aharon Bar-Hillel, Stas Tiomkin, Hadar Levi, Omer Tsimhoni, Naftali Tishby
2015 conf
AutomotiveUI
Ariel Telpaz, Brian Rhindress, Ido Zelman, Omer Tsimhoni
2015 J jnl
J. Intell. Transp. Syst.
Avi Rosenfeld, Zevi Bareket, Claudia V. Goldman, David J. LeBlanc, Omer Tsimhoni
2014 A* conf
AAAI
Amos Azaria, Sarit Kraus, Claudia V. Goldman, Omer Tsimhoni
2014 A conf
AAMAS
Amos Azaria, Sarit Kraus, Claudia V. Goldman, Omer Tsimhoni
2012 A conf
AAMAS
Amos Azaria, Zinovi Rabinovich, Sarit Kraus, Claudia V. Goldman, Omer Tsimhoni
2012 C conf
IAAI
Avi Rosenfeld, Zevi Bareket, Claudia V. Goldman, Sarit Kraus, David J. LeBlanc, Omer Tsimhoni
2012 J jnl
AI Mag.
Avi Rosenfeld, Zevi Bareket, Claudia V. Goldman, Sarit Kraus, David J. LeBlanc, Omer Tsimhoni
2011 conf
AutomotiveUI
Noam Tractinsky, Ohad Inbar, Omer Tsimhoni, Thomas Seder
2011 J jnl
IEEE Trans. Syst. Man Cybern. Part A
Luzheng Bi, Omer Tsimhoni, Yili Liu
2010 J jnl
IEEE Trans. Intell. Transp. Syst.
Ji Hyoun Lim, Omer Tsimhoni, Yili Liu
2010 J jnl
IEEE Trans. Intell. Transp. Syst.
Ji Hyoun Lim, Yili Liu, Omer Tsimhoni
2010 conf
AutomotiveUI
Ute Winter, Tim J. Grost, Omer Tsimhoni
2010 J jnl
IEEE Trans. Intell. Transp. Syst.
Tulga Ersal, Helen J. A. Fuller, Omer Tsimhoni, Jeffrey L. Stein, Hosam K. Fathy
2009 J jnl
IEEE Trans. Intell. Transp. Syst.
Luzheng Bi, Omer Tsimhoni, Yili Liu
2008 Misc conf
WSC
Marcial Lapp, Shervin AhmadBeygi, Amy Cohn, Omer Tsimhoni
2008 J jnl
IEEE Trans. Intell. Transp. Syst.
Changxu Wu, Omer Tsimhoni, Yili Liu
2008 Misc conf
WSC
Chachrist Srisuwanrat, Photios G. Ioannou, Omer Tsimhoni
2008 J jnl
Hum. Factors
John M. Sullivan, Omer Tsimhoni, Scott Bogard
2008 Misc conf
WSC
Jared Davis, Barbara Fordyce, James Cicala, Matthew Cooper, Omer Tsimhoni
2006 Misc conf
WSC
Rita Awwad, Amir H. Behzadan, Omer Tsimhoni
2006 J jnl
ACM Trans. Comput. Hum. Interact.
Yili Liu, Robert G. Feyen, Omer Tsimhoni
2005 Misc conf
WSC
David B. Roggenkamp, Dave Park, Omer Tsimhoni
2005 Misc conf
WSC
Benjamin Dubiel, Omer Tsimhoni
2005 Misc conf
WSC
Omer Tsimhoni, Changxu Wu
2005 Misc conf
WSC
Sara A. Curin, Jeremy S. Vosko, Eric W. Chan, Omer Tsimhoni
2004 J jnl
Hum. Factors
Omer Tsimhoni, Daniel Smith, Paul A. Green
2001 J jnl
Int. J. Speech Technol.
Omer Tsimhoni, Paul A. Green, Jennifer Lai
2001 A* conf
CHI
Jennifer Lai, Karen Cheng, Paul A. Green, Omer Tsimhoni
2000 A conf
INTERSPEECH
Jennifer Lai, Omer Tsimhoni, Paul A. Green
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));