Ovidiu Bagdasar

47 papers Misc 2Journal 36Unranked 8
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Access
Arthit Hongsri, Ovidiu Bagdasar, Narongsak Yotha
2025 J jnl
Axioms
Dorin Andrica, Ovidiu Bagdasar, Catalin Barbu, Laurian Ioan Piscoran
2024 J jnl
Axioms
Dorin Andrica, Ovidiu Bagdasar
2023 J jnl
IEEE Trans. Syst. Man Cybern. Syst.
Wangyang Yu, Lu Liu, Xiaoming Wang, Ovidiu Bagdasar, John Panneerselvam
2022 J jnl
Math. Comput. Simul.
Sam O'Neill, Paul Wrigley, Ovidiu Bagdasar
2022 J jnl
Math. Comput. Simul.
Joseph Dianavinnarasi, Ramachandran Raja, Jehad O. Alzabut, Jinde Cao, Michal Niezabitowski, Ovidiu Bagdasar
2022 J jnl
Neural Process. Lett.
Stephen Arockia Samy, Ramachandran Raja, Jehad O. Alzabut, Quanxin Zhu, Michal Niezabitowski, Ovidiu Bagdasar
2022 J jnl
Math. Comput. Simul.
Sam O'Neill, Ovidiu Bagdasar, Stuart Berry, Nicolae Popovici, Ramachandran Raja
2022 J jnl
Math. Comput. Simul.
Dorin Andrica, Ovidiu Bagdasar
2021 J jnl
Symmetry
Joseph Dianavinnarasi, Ramachandran Raja, Jehad O. Alzabut, Michal Niezabitowski, Ovidiu Bagdasar
2021 J jnl
CoRR
Annamaria Ficara, Lucia Cavallaro, Francesco Curreri, Giacomo Fiumara, Pasquale De Meo, Ovidiu Bagdasar, Wei Song, Antonio Liotta
2021 Misc conf
IDC
Laura Erhan, Mario Di Mauro, Ovidiu Bagdasar, Antonio Liotta
2021 J jnl
Sensors
Laura Erhan, Mario Di Mauro, Ashiq Anjum, Ovidiu Bagdasar, Wei Song, Antonio Liotta
2021 J jnl
CoRR
Lucia Cavallaro, Ovidiu Bagdasar, Pasquale De Meo, Giacomo Fiumara, Antonio Liotta
2021 J jnl
IT Prof.
Byung-Seok Kang, Francis Malute, Ovidiu Bagdasar, Choongseon Hong
2021 conf
COMPLEX NETWORKS
Lucia Cavallaro, Marco Grassia, Giacomo Fiumara, Giuseppe Mangioni, Pasquale De Meo, Vincenza Carchiolo, Ovidiu Bagdasar, Antonio Liotta
2021 J jnl
Inf. Fusion
Laura Erhan, Maryleen U. Ndubuaku, Mario Di Mauro, Wei Song, Min Chen, Giancarlo Fortino, Ovidiu Bagdasar, Antonio Liotta
2020 J jnl
Soft Comput.
Lucia Cavallaro, Ovidiu Bagdasar, Pasquale De Meo, Giacomo Fiumara, Antonio Liotta
2020 J jnl
CoRR
Lucia Cavallaro, Annamaria Ficara, Pasquale De Meo, Giacomo Fiumara, Salvatore Catanese, Ovidiu Bagdasar, Antonio Liotta
2020 Misc conf
UCC
Petr Mrozek, John Panneerselvam, Ovidiu Bagdasar
2020 J jnl
Soft Comput.
Xiaolong Xu, Hao Yuan, Peter Matthew, Jeffrey Ray, Ovidiu Bagdasar, Marcello Trovati
2020 conf
COMPLEX NETWORKS (2)
Lucia Cavallaro, Annamaria Ficara, Francesco Curreri, Giacomo Fiumara, Pasquale De Meo, Ovidiu Bagdasar, Antonio Liotta
2020 J jnl
Neural Process. Lett.
A. Pratap, Ramachandran Raja, Ravi P. Agarwal, Jinde Cao, Ovidiu Bagdasar
2020 J jnl
CoRR
Laura Erhan, Maryleen U. Ndubuaku, Mario Di Mauro, Wei Song, Min Chen, Giancarlo Fortino, Ovidiu Bagdasar, Antonio Liotta
2020 conf
CAMAD
Marco Uras, Raimondo Cossu, Enrico Ferrara, Ovidiu Bagdasar, Antonio Liotta, Luigi Atzori
2019 conf
NUMTA (2)
Sam O'Neill, Ovidiu Bagdasar, Antonio Liotta
2019 conf
NUMTA (2)
Lucia Cavallaro, Ovidiu Bagdasar, Pasquale De Meo, Giacomo Fiumara, Antonio Liotta
2019 J jnl
Electron. Notes Discret. Math.
Nicholas Korpelainen, Ovidiu Bagdasar, Peter J. Larcombe
2019 conf
COMPLEX NETWORKS (2)
Annamaria Ficara, Lucia Cavallaro, Pasquale De Meo, Giacomo Fiumara, Salvatore Catanese, Ovidiu Bagdasar, Antonio Liotta
2019 J jnl
Appl. Math. Comput.
A. Pratap, Ramachandran Raja, Jinde Cao, Chee Peng Lim, Ovidiu Bagdasar
2019 J jnl
Math. Comput. Simul.
Ovidiu Bagdasar, Stuart Berry, Sam O'Neill, Nicolae Popovici, Ramachandran Raja
2018 J jnl
Electron. Notes Discret. Math.
Armen G. Bagdasaryan, Ovidiu Bagdasar
2018 J jnl
Electron. Notes Discret. Math.
Ovidiu Bagdasar, Ralph Tatt
2018 J jnl
Electron. Notes Discret. Math.
Armen Bagdasaryan, Ovidiu Bagdasar
2018 J jnl
Electron. Notes Discret. Math.
Ovidiu Bagdasar, Eve Hedderwick, Ioan-Lucian Popa
2018 J jnl
Electron. Notes Discret. Math.
Ovidiu Bagdasar, Ioan-Lucian Popa
2018 J jnl
Neural Networks
A. Pratap, Ramachandran Raja, Chandran Sowmiya, Ovidiu Bagdasar, Jinde Cao, Grienggrai Rajchakit
2018 J jnl
Electron. Notes Discret. Math.
Dorin Andrica, Ovidiu Bagdasar
2018 J jnl
J. Glob. Optim.
Ovidiu Bagdasar, Nicolae Popovici
2016 J jnl
Electron. Notes Discret. Math.
Ioan-Lucian Popa, Traian Ceausu, Ovidiu Bagdasar
2016 J jnl
Electron. Notes Discret. Math.
Ovidiu Bagdasar, Ioan-Lucian Popa
2015 J jnl
Optim. Lett.
Ovidiu Bagdasar, Nicolae Popovici
2014 conf
UKSim
Ovidiu Bagdasar, Minsi Chen
2014 conf
UKSim
Marcello Trovati, Ovidiu Bagdasar
2013 book
Ovidiu Bagdasar
2008 J jnl
Am. Math. Mon.
Ovidiu Bagdasar, Marian Tetiva
2006 J jnl
Am. Math. Mon.
Ovidiu Bagdasar
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"