Onkar Singh

22 papers Misc 1Journal 16Unranked 4
YearRankTypeTitle / Venue / Authors
2025 J jnl
SN Comput. Sci.
Onkar Singh
2025 J jnl
Expert Syst. J. Knowl. Eng.
Onkar Singh, Ajay Jaiswal, Nitin Kumar, Naveen Kumar
2025 J jnl
Appl. Intell.
Onkar Singh, Ajay Jaiswal, Naveen Kumar
2025 J jnl
IEEE Access
Stuti Pandey, Onkar Singh, Ashish Pandey, Chandrasen Pandey
2024 conf
IST
Abhinandan Jha, Onkar Singh, Koushlendra Kumar Singh, Akbar Sheikh Akbari, Masahiro Takei
2024 J jnl
SN Comput. Sci.
Onkar Singh, Koushlendra Kumar Singh
2024 J jnl
SN Comput. Sci.
Onkar Singh, Kanchan Lata Kashyap, Koushlendra Kumar Singh
2023 conf
IST
Onkar Singh, Koushlendra Kumar Singh, Saikat Das, Akbar Sheikh Akbari, Nurulfajar Abd Manap
2023 J jnl
Biomed. Signal Process. Control.
Onkar Singh, Kanchan Lata Kashyap, Koushlendra Kumar Singh
2021 J jnl
BMC Bioinform.
Onkar Singh, Wen-Lian Hsu, Emily Chia-Yu Su
2019 Misc conf
AMIA
Grace Gao, Madeleine J. Kerr, Sarah Beman, Candice Bruhjell, Joyce Rudenick, Onkar Singh, Mehrdad Rafiei, Karen A. Monsen
2019 ch.
Encyclopedia of Bioinformatics and Computational Biology (2)
Onkar Singh, Nai-Wen Chang, Hong-Jie Dai, Jitendra Jonnagaddala
2018 J jnl
Database J. Biol. Databases Curation
Hong-Jie Dai, Onkar Singh
2017 conf
DDDSM@IJCNLP
Chen-Kai Wang, Onkar Singh, Zhao-Li Tang, Hong-Jie Dai
2016 J jnl
Database J. Biol. Databases Curation
Sun Kim, Rezarta Islamaj Dogan, Andrew Chatr-aryamontri, Christie S. Chang, Rose Oughtred, Jennifer M. Rust, Riza Batista-Navarro, Jacob Carter, Sophia Ananiadou, Sérgio Matos, André Santos, David Campos, José Luís Oliveira, Onkar Singh, Jitendra Jonnagaddala, Hong-Jie Dai, Emily Chia-Yu Su, Yung-Chun Chang, Yu-Chen Su, Chun-Han Chu, Chien Chin Chen, Wen-Lian Hsu, Yifan Peng, Cecilia N. Arighi, Cathy H. Wu, K. Vijay-Shanker, Ferhat Aydin, Zehra Melce Hüsünbeyi, Arzucan Özgür, Soo-Yong Shin, Dongseop Kwon, Kara Dolinski, Mike Tyers, W. John Wilbur, Donald C. Comeau
2016 conf
EMBC
Suleman Atique, Mowafa S. Househ, Luis Fernández-Luque, Elia Gabarron, Marian Wan, Onkar Singh, Vicente Traver Salcedo, Yu-Chuan (Jack) Li, Syed Abdul Shabbir
2016 J jnl
Database J. Biol. Databases Curation
Hong-Jie Dai, Chu-Hsien Su, Po-Ting Lai, Ming-Siang Huang, Jitendra Jonnagaddala, Toni Rose Jue, Shruti Rao, Hui-Jou Chou, Marija Milacic, Onkar Singh, Syed Abdul Shabbir, Wen-Lian Hsu
2016 J jnl
Database J. Biol. Databases Curation
Hong-Jie Dai, Onkar Singh, Jitendra Jonnagaddala, Emily Chia-Yu Su
2016 J jnl
Database J. Biol. Databases Curation
Qinghua Wang, Shabbir Syed-Abdul, Lara Almeida, Sophia Ananiadou, Yalbi I. Balderas-Martínez, Riza Batista-Navarro, David Campos, Lucy Chilton, Hui-Jou Chou, Gabriela Contreras, Laurel Cooper, Hong-Jie Dai, Barbra Ferrell, Juliane Fluck, Socorro Gama-Castro, Nancy George, Georgios V. Gkoutos, Afroza Khanam Irin, Lars Juhl Jensen, Silvia Jimenez, Toni Rose Jue, Ingrid M. Keseler, Sumit Madan, Sérgio Matos, Peter McQuilton, Marija Milacic, Matthew E. Mort, Jeyakumar Natarajan, Evangelos Pafilis, Emiliano Pereira, Shruti Rao, Fabio Rinaldi, Karen Rothfels, David Salgado, Raquel M. Silva, Onkar Singh, Raymund Stefancsik, Chu-Hsien Su, Suresh Subramani, Hamsa D. Tadepally, Loukia Tsaprouni, Nicole A. Vasilevsky, Xiaodong Wang, Andrew Chatr-aryamontri, Stanley J. F. Laulederkind, Sherri Matis-Mitchell, Johanna R. McEntyre, Sandra E. Orchard, Sangya Pundir, Raul Rodriguez-Esteban, Kimberly Van Auken, Zhiyong Lu, Mary L. Schaeffer, Cathy H. Wu, Lynette Hirschman, Cecilia N. Arighi
2016 J jnl
BMC Bioinform.
Onkar Singh, Emily Chia-Yu Su
2015 J jnl
J. Syst. Control. Eng.
Mohan K. Misra, Bishakh Bhattacharya, Onkar Singh, Arya Chatterjee
2009 J jnl
J. Comput. Chem.
Jagdish Chandra Patra, Onkar Singh
redb/extractors/js_extractor.py
← Index redb/extractors/js_extractor.py python
import logging
import re
from abc import ABCMeta, abstractmethod

from redb.extractors.extractor import Extractor
from redb.extractors.js_extractors.js_context import JSContext, _text_entropy

logger = logging.getLogger(__name__)

# ESM is recognised by line-anchored `import ... from "..."` / bare side-effect
# `import "..."` / top-level `export ...`. Anchored at line start to avoid
# matching the substring inside string literals or comments.
_ESM_PATTERN = re.compile(
    r'(?m)^\s*(?:'
    r'import\s+[^;\n]*?\bfrom\s+[\'"]'
    r'|import\s+[\'"][^\'"]+[\'"]'
    r'|export\s+(?:default\b|\{|\*|const\b|let\b|var\b|function\b|class\b|async\b)'
    r')'
)


@abstractmethod
class JSExtractor(Extractor, metaclass=ABCMeta):
    """Base class for JavaScript file extractors.

    Every JSExtractor reads its raw materials (bytes / decoded source / line
    list / scan_source results / pyjsparser AST / text entropy) from a shared
    `JSContext`. When workers.py drives the JS pipeline it builds one context
    per sample and threads it into every extractor via `context=`. When tests
    or other callers instantiate an extractor directly, the constructor builds
    a fresh context from `(filepath, source=...)`.

    All historical instance attributes (`self.binary`, `self.js_source`,
    `self.lines`) and helpers (`self._decode_source`, `self._parse_ast`,
    `self._calculate_text_entropy`) are preserved as thin delegators so
    existing extractor code keeps working unchanged.
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        known_benign=False,
        known_malicious=False,
        source=None,
        context=None,
    ):
        if context is None:
            context = JSContext.from_path(filepath, log=log, source=source)
        elif source is not None and context.source != source:
            log.warning(
                "JSExtractor received both `source=` and `context=` with "
                "differing source; ignoring source kwarg"
            )
        self._context = context

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            known_benign=known_benign,
            known_malicious=known_malicious,
        )

    @property
    def binary(self):
        return self._context.raw_bytes

    @property
    def js_source(self):
        return self._context.source

    @property
    def lines(self):
        return self._context.lines

    def _decode_source(self):
        """Back-compat shim — the context already decoded once at construction.

        Kept so any external caller using the historical method name keeps
        working without touching the underlying bytes again.
        """
        return self._context.source

    def _parse_ast(self):
        """Return the shared pyjsparser AST (or None if unavailable)."""
        return self._context.ast

    def _calculate_text_entropy(self, text):
        """Shannon text entropy for `text`.

        When `text` is the context's own source we read the cached value;
        otherwise we compute fresh. JSStringsExtractor calls this on arbitrary
        decoded substrings, so the fresh-compute path must remain available.
        """
        if text is self._context.source:
            return self._context.text_entropy
        return _text_entropy(text)

    def _detect_environment(self):
        """Detect the target JS runtime environment."""
        src = self.js_source
        if not src:
            return "unknown"

        # WScript/WSH indicators
        wscript_patterns = [
            'WScript.', 'WSH.', 'ActiveXObject', 'Scripting.FileSystemObject',
            'WScript.Shell', 'ADODB.Stream',
        ]
        for p in wscript_patterns:
            if p in src:
                return "wscript"

        # Browser-extension APIs — checked before generic browser/worker because
        # `chrome.*` and `browser.runtime` are distinctive of MV2/MV3 extensions
        extension_patterns = [
            'chrome.runtime', 'chrome.tabs', 'chrome.storage',
            'chrome.webRequest', 'browser.runtime', 'browser.tabs',
        ]
        for p in extension_patterns:
            if p in src:
                return "browser_extension"

        # Service / Web Workers — worker-only APIs that don't appear in regular
        # browser pages (a generic browser script would use `window.` or
        # `document.`, never `self.importScripts` or `caches.match`)
        worker_patterns = [
            "self.addEventListener('fetch'", 'self.addEventListener("fetch"',
            'self.importScripts', 'self.skipWaiting',
            'caches.match', 'caches.open',
        ]
        for p in worker_patterns:
            if p in src:
                return "service_worker"

        # Deno runtime
        if 'Deno.' in src:
            return "deno"

        # Node.js indicators
        node_patterns = [
            'require(', 'module.exports', 'process.env', '__dirname',
            '__filename', 'Buffer.', 'child_process',
        ]
        for p in node_patterns:
            if p in src:
                return "node"

        # Browser indicators
        browser_patterns = [
            'document.', 'window.', 'navigator.', 'localStorage',
            'sessionStorage', 'XMLHttpRequest', 'addEventListener',
        ]
        for p in browser_patterns:
            if p in src:
                return "browser"

        return "unknown"

    def _detect_script_type(self):
        """Detect the script type/format."""
        src = self.js_source
        if not src:
            return "unknown"

        stripped = src.lstrip()

        # JScript.Encode payload — must be checked first since the encoded
        # body can't be classified any other way
        if stripped.startswith('#@~^'):
            return "jse"

        # WSF / HTA live in the first few KB of an HTML-ish wrapper
        head_lower = stripped[:4096].lower()

        # Windows Script File — XML wrapper around one or more <script> blocks
        if ('<job' in head_lower or '<package' in head_lower) and '<script' in head_lower:
            return "wsf"

        # HTML Application — distinct from generic embedded_html because HTAs
        # run under mshta.exe with full WSH/ActiveX access
        if '<hta:application' in head_lower or 'application/hta' in head_lower:
            return "hta"

        if stripped.startswith('<!') or stripped.startswith('<html') or '<script' in stripped[:2000]:
            return "embedded_html"

        if 'WScript.' in src or 'WSH.' in src:
            return "wscript"

        if _ESM_PATTERN.search(src):
            return "esm"

        if 'require(' in src or 'module.exports' in src:
            return "node_module"

        return "standalone"