Oscar Belmonte

24 papers C 3Misc 5Journal 7Unranked 9
YearRankTypeTitle / Venue / Authors
2019 conf
IPIN (Short Papers/Work-in-Progress Papers)
Raúl Montoliu, Emilio Sansano-Sansano, Arturo Gascó, Oscar Belmonte, Antonio Caballer
2018 C conf
IPIN
Raúl Montoliu, Emilio Sansano-Sansano, Oscar Belmonte, Joaquín Torres-Sospedra
2017 J jnl
J. Ambient Intell. Smart Environ.
Joaquín Torres-Sospedra, Adriano J. C. Moreira, Stefan Knauth, Rafael Berkvens, Raúl Montoliu, Oscar Belmonte, Sergio Trilles, Maria João Nicolau, Filipe Meneses, António Costa, Athanasios Koukofikis, Maarten Weyn, Herbert Peremans
2017 J jnl
Future Gener. Comput. Syst.
Unai Aguilera, Oscar Peña, Oscar Belmonte, Diego López-de-Ipiña
2017 C conf
IPIN
Raúl Montoliu, Emilio Sansano-Sansano, Joaquín Torres-Sospedra, Oscar Belmonte
2017 J jnl
Sensors
Joaquín Torres-Sospedra, Antonio Ramón Jiménez, Stefan Knauth, Adriano J. C. Moreira, Yair Beer, Toni Fetzer, Viet-Cuong Ta, Raúl Montoliu, Fernando Seco, Germán M. Mendoza-Silva, Oscar Belmonte, Athanasios Koukofikis, Maria João Nicolau, António Costa, Filipe Meneses, Frank Ebner, Frank Deinzer, Dominique Vaufreydaz, Trung-Kien Dao, Eric Castelli
2016 C conf
IPIN
Joaquín Torres-Sospedra, Germán M. Mendoza-Silva, Raúl Montoliu, Oscar Belmonte, Fernando Benitez-Paez, Joaquín Huerta
2016 J jnl
Mob. Inf. Syst.
Joaquín Torres-Sospedra, Raúl Montoliu, Germán M. Mendoza-Silva, Oscar Belmonte, David Rambla, Joaquín Huerta
2016 J jnl
IEEE Trans. Signal Process.
Maximo Cobos, Juan José Pérez Solano, Oscar Belmonte, Germán Ramos, Ana M. Torres
2016 conf
LBS
Germán M. Mendoza-Silva, Joaquín Torres-Sospedra, Joaquín Huerta, Raúl Montoliu, Fernando Benitez-Paez, Oscar Belmonte
2011 conf
ICCSA Workshops
Alberto Denia, José Ribelles, Angeles López, Oscar Belmonte
2010 conf
TPCG
José Ribelles, Angeles López, Oscar Belmonte
2010 conf
TPCG
Oscar Belmonte, Sergio Sancho, José Ribelles
2004 conf
WSCG
J. Francisco Ramos, Miguel Chover, Oscar Belmonte, Cristina Rebollo
2004 J jnl
Future Gener. Comput. Syst.
Oscar Belmonte, Inmaculada Remolar, José Ribelles, Miguel Chover, Marcos Fernández
2003 Misc conf
WSCG
Inmaculada Remolar, Miguel Chover, José Ribelles, Oscar Belmonte
2002 Misc conf
International Conference on Computational Science (2)
Oscar Belmonte, Inmaculada Remolar, José Ribelles, Miguel Chover, Marcos Fernández
2002 conf
Eurographics (Short Presentations)
Inmaculada Remolar, Miguel Chover, Oscar Belmonte, José Ribelles, Cristina Rebollo
2002 Misc conf
WSCG
Oscar Belmonte, Inmaculada Remolar, José Ribelles, Miguel Chover, Cristina Rebollo, Marcos Fernández
2002 J jnl
Comput. Graph.
José Ribelles, Angeles López, Oscar Belmonte, Inmaculada Remolar, Miguel Chover
2001 conf
VIIP
Oscar Belmonte, Inmaculada Remolar, José Ribelles, Miguel Chover, Cristina Rebollo, Marcos Fernández
2001 Misc conf
WSCG (Short Papers)
Oscar Belmonte, José Ribelles, Inmaculada Remolar, Miguel Chover
2001 Misc conf
WSCG
José Ribelles, Angeles López, Oscar Belmonte, Inmaculada Remolar, Miguel Chover
2000 conf
DGCI
José Ribelles, Angeles López, Inmaculada Remolar, Oscar Belmonte, Miguel Chover
redb/extractors/js_extractors/js_deobfuscation.py
← Index redb/extractors/js_extractors/js_deobfuscation.py python
import hashlib
import inspect
import re
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor
from redb.extractors.js_extractors.js_patterns import PATTERNS

# String literals of 4+ characters; only used by the deobfuscation diff to count
# strings revealed after deobfuscation. Compiled once at module load.
_STRING_LITERAL_4PLUS_RE = re.compile(r"[\"\']([^\"\']{4,})[\"\']")


class JSDeobfuscationExtractor(JSExtractor):
    """Compute pre/post-deobfuscation metrics for a JS sample.

    The actual deobfuscation pass (external tool with jsbeautifier fallback)
    lives on `JSContext.deobfuscated` and is cached per sample, so any other
    extractor that needs the deobfuscated text reads the same value without
    re-running the subprocess. Configure the external tool via env vars:
        JS_DEOBFUSCATOR_PATH    Path or name (default: webcrack)
        JS_DEOBFUSCATE_TIMEOUT  Seconds (default: 60)
    """

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.deobfuscation_result = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_DEOBFUSCATION.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, deobfuscator_used = self._context.deobfuscated
        if deobfuscated is None:
            return None

        original_size = len(src)
        original_entropy = self._context.text_entropy
        deobfuscated_size = len(deobfuscated)
        deobfuscated_entropy = self._calculate_text_entropy(deobfuscated)
        size_change_ratio = round(deobfuscated_size / original_size, 4) if original_size else 0.0

        # Strings revealed by deobfuscation: matched literals are extracted from
        # both versions and the set difference is the count of "new" strings.
        original_strings = set(_STRING_LITERAL_4PLUS_RE.findall(src))
        deobfuscated_strings = set(_STRING_LITERAL_4PLUS_RE.findall(deobfuscated))
        new_strings = deobfuscated_strings - original_strings

        # Suspicious APIs revealed by deobfuscation. Both sides of the diff
        # come from JSContext caches: the raw scan is computed once for the
        # whole pipeline; the deobfuscated scan is computed once and reused
        # by JSSuspiciousAPIsExtractor's revealed_by_deobf rows.
        original_apis = {n for n in self._context.scan if n in PATTERNS}
        deobfuscated_apis = set(self._context.scan_deobfuscated)
        new_apis = deobfuscated_apis - original_apis

        deobfuscated_sha256 = hashlib.sha256(deobfuscated.encode('utf-8')).hexdigest()

        self.deobfuscation_result = {
            'deobfuscator_used': deobfuscator_used,
            'deobfuscation_successful': True,
            'original_size': original_size,
            'deobfuscated_size': deobfuscated_size,
            'size_change_ratio': size_change_ratio,
            'original_entropy': original_entropy,
            'deobfuscated_entropy': deobfuscated_entropy,
            'new_strings_found': len(new_strings),
            'new_apis_found': len(new_apis),
            'deobfuscated_sha256': deobfuscated_sha256,
        }
        return self.deobfuscation_result

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.deobfuscation_result:
                return None

            r = self.deobfuscation_result
            current_time = datetime.now(timezone.utc)
            data = [[
                self.sha256,
                r['deobfuscator_used'],
                int(r['deobfuscation_successful']),
                r['original_size'],
                r['deobfuscated_size'],
                r['size_change_ratio'],
                r['original_entropy'],
                r['deobfuscated_entropy'],
                r['new_strings_found'],
                r['new_apis_found'],
                r['deobfuscated_sha256'],
                current_time,
            ]]

            column_names = [
                "sha256", "deobfuscator_used", "deobfuscation_successful",
                "original_size", "deobfuscated_size", "size_change_ratio",
                "original_entropy", "deobfuscated_entropy",
                "new_strings_found", "new_apis_found",
                "deobfuscated_sha256", "analysis_date",
            ]

            column_type_names = [
                "FixedString(64)", "LowCardinality(String)", "UInt8",
                "UInt64", "UInt64", "Float64",
                "Float64", "Float64",
                "UInt32", "UInt32",
                "FixedString(64)", "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_js_deobfuscation"