R. Cameron Craddock

30 papers Journal 30
YearRankTypeTitle / Venue / Authors
2023 J jnl
CoRR
Soichi Hayashi, Bradley Caron, Anibal Sólon Heinsfeld, Sophia Vinci-Booher, Brent C. McPherson, Daniel N. Bullock, Giulia Berto, J. Guiomar Niso, Sandra Hanekamp, Daniel Levitas, Lindsey Kitchell, Josiah Leong, Filipi N. Silva, Serge Koudoro, Hanna Willis, Jasleen Jolly, Derek Pisner, Taylor Zuidema, Jan Kurzwaski, Koulla Mikellidou, Aurore Bussalb, Christopher Rorden, Conner Victory, Dheeraj Bhatia, Dogu Baran Aydogan, Frank C. Yeh, Franco Delogu, Javier Guaje, Jelle Veraart, Jeremy Fischer, Joshua Faskowitz, Maximilien Chaumon, Ricardo Fabrega, David Hunt, Shawn McKee, Shaw T. Brown, Stephanie Heyman, Vittorio Iacovella, Amanda Mejia, Daniele Marinazzo, R. Cameron Craddock, Emanuele Olivetti, Jamie Hanson, Paolo Avesani, Eleftherios Garyfallidis, Daniel Stanzione, James P. Carson, Robert Henschel, David Y. Hancock, Craig A. Stewart, David M. Schnyer, Damian Eke, Russell A. Poldrack, Nathalie George, Holly Bridge, Ilaria Sani, Winrich Freiwald, Aina Puce, Nicholas Port, Franco Pestilli
2022 J jnl
BMC Medical Imaging
Raphael Roger, Melissa A. Hilmes, Jonathan M. Williams, Daniel J. Moore, Alvin C. Powers, R. Cameron Craddock, John Virostko
2021 J jnl
PLoS Comput. Biol.
Eric W. Bridgeford, Shangsi Wang, Zeyi Wang, Ting Xu, R. Cameron Craddock, Jayanta Dey, Gregory Kiar, William R. Gray Roncal, Carlo Colantuoni, Christopher Douville, Stephanie Noble, Carey E. Priebe, Brian Caffo, Michael P. Milham, Xi-Nian Zuo, Joshua T. Vogelstein
2021 J jnl
Frontiers Digit. Health
Congyu Wu, Hagen Fritz, Melissa Miller, R. Cameron Craddock, Kerry A. Kinney, Darla M. Castelli, David M. Schnyer
2021 J jnl
CoRR
Congyu Wu, Hagen Fritz, R. Cameron Craddock, Kerry A. Kinney, Darla M. Castelli, David M. Schnyer
2021 J jnl
NeuroImage
Lei Ai, R. Cameron Craddock, Nim Tottenham, Jonathan P. Dyke, Ryan Lim, Stanley J. Colcombe, Michael P. Milham, Alexandre R. Franco
2021 J jnl
NeuroImage
Amelie Haugg, Fabian M. Renz, Andrew A. Nicholson, Cindy Lor, Sebastian J. Götzendorfer, Ronald Sladky, Stavros Skouras, Amalia McDonald, R. Cameron Craddock, Lydia Hellrung, Matthias Kirschner, Marcus Herdener, Yury Koush, Marina Papoutsi, Nimrod Jakob Keynan, Talma Hendler, Kathrin Cohen Kadosh, Catharina Zich, Simon H. Kohl, Manfred Hallschmid, Jeff MacInnes, R. Alison Adcock, Kathryn C. Dickerson, Nan-kuei Chen, Kymberly D. Young, Jerzy Bodurka, Michael Marxen, Shuxia Yao, Benjamin Becker, Tibor Auer, Renate Schweizer, Gustavo S. P. Pamplona, Ruth A. Lanius, Kirsten Emmert, Sven Haller, Dimitri Van De Ville, Dong-Youl Kim, Jong-Hwan Lee, Theo Marins, Fukuda Megumi, Bettina Sorger, Tabea Kamp, Sook-Lei Liew, Ralf Veit, Maartje S. Spetter, Nikolaus Weiskopf, Frank Scharnowski, David Steyrl
2021 J jnl
NeuroImage
Xindi Wang, Xinhui Li, Jae Wook Cho, Brian E. Russ, Nanditha Rajamani, Alisa Omelchenko, Lei Ai, Annachiara Korchmaros, Stephen J. Sawiak, R. Austin Benn, Pamela Garcia-Saldivar, Zheng Wang, Ned H. Kalin, Charles E. Schroeder, R. Cameron Craddock, Andrew S. Fox, Alan C. Evans, Adam Messinger, Michael P. Milham, Ting Xu
2020 J jnl
CoRR
Congyu Wu, Amanda N. Barczyk, R. Cameron Craddock, Gabriella M. Harari, Edison Thomaz, Jason D. Shumake, Christopher G. Beevers, Samuel D. Gosling, David M. Schnyer
2020 J jnl
CoRR
Congyu Wu, Hagen Fritz, Zoltán Nagy, Juan P. Maestre, Edison Thomaz, Christine Julien, Darla M. Castelli, Kaya de Barbaro, Gabriella M. Harari, R. Cameron Craddock, Kerry A. Kinney, Samuel D. Gosling, David M. Schnyer
2018 J jnl
NeuroImage
Manuel Garcia-Garcia, Aki Nikolaidis, Pierre Bellec, R. Cameron Craddock, Brian Cheung, Francisco X. Castellanos, Michael P. Milham
2018 J jnl
NeuroImage
R. Cameron Craddock, Pierre Bellec, Saâd Jbabdi
2018 J jnl
NeuroImage
Hao-Ting Wang, Danilo Bzdok, Daniel S. Margulies, R. Cameron Craddock, Michael P. Milham, Elizabeth Jefferies, Jonathan Smallwood
2018 J jnl
NeuroImage
Adon F. G. Rosen, David R. Roalf, Kosha Ruparel, Jason Blake, Kevin Seelaus, Lakshmi P. Villa, Rastko Ciric, Philip A. Cook, Christos Davatzikos, Mark A. Elliott, Angel Garcia de La Garza, Efstathios D. Gennatas, Megan Quarmley, J. Eric Schmitt, Russell T. Shinohara, M. Dylan Tisdall, R. Cameron Craddock, Raquel E. Gur, Theodore D. Satterthwaite
2017 J jnl
PLoS Comput. Biol.
Krzysztof J. Gorgolewski, Fidel Alfaro-Almagro, Tibor Auer, Pierre Bellec, Mihai Capota, M. Mallar Chakravarty, Nathan William Churchill, Alexander Li Cohen, R. Cameron Craddock, Gabriel A. Devenyi, Anders Eklund, Oscar Esteban, Guillaume Flandin, Satrajit S. Ghosh, J. Swaroop Guntupalli, Mark Jenkinson, Anisha Keshavan, Gregory Kiar, Franziskus Liem, Pradeep Reddy Raamana, David Raffelt, Christopher John Steele, Pierre-Olivier Quirion, Robert E. Smith, Stephen C. Strother, Gaël Varoquaux, Yida Wang, Tal Yarkoni, Russell A. Poldrack
2017 J jnl
NeuroImage
Alexandre Abraham, Michael P. Milham, Adriana Di Martino, R. Cameron Craddock, Dimitris Samaras, Bertrand Thirion, Gaël Varoquaux
2017 J jnl
NeuroImage
Tamara Vanderwal, Jeffrey Eilbott, Emily S. Finn, R. Cameron Craddock, Adam Turnbull, F. Xavier Castellanos
2017 J jnl
NeuroImage
Franziskus Liem, Gaël Varoquaux, Jana Kynast, Frauke Beyer, Shahrzad Kharabian Masouleh, Julia M. Huntenburg, Leonie Lampe, Mehdi Rahim, Alexandre Abraham, R. Cameron Craddock, Steffi Riedel-Heller, Tobias Luck, Markus Loeffler, Matthias L. Schroeter, Anja Veronica Witte, Arno Villringer, Daniel S. Margulies
2017 J jnl
NeuroImage
Pierre Bellec, Carlton Chu, François Chouinard-Decorte, Yassine Benhajali, Daniel S. Margulies, R. Cameron Craddock
2016 J jnl
NeuroImage
Alexander Opitz, Michael D. Fox, R. Cameron Craddock, Stanley J. Colcombe, Michael P. Milham
2015 J jnl
NeuroImage
Pierre Bellec, Yassine Benhajali, Felix Carbonell, Christian Dansereau, Geneviève Albouy, Maxime Pelland, R. Cameron Craddock, Olivier Collignon, Julien Doyon, Emmanuel Stip, Pierre Orban
2014 J jnl
NeuroImage
Zarrar Shehzad, Clare Kelly, Philip T. Reiss, R. Cameron Craddock, John W. Emerson, Katie McMahon, David A. Copland, F. Xavier Castellanos, Michael P. Milham
2014 J jnl
NeuroImage
Zhen Yang, R. Cameron Craddock, Daniel S. Margulies, Chao-Gan Yan, Michael P. Milham
2014 J jnl
CoRR
Pierre Bellec, Yassine Benhajali, Felix Carbonell, Christian Dansereau, Z. Shehzad, Geneviève Albouy, Maxime Pelland, R. Cameron Craddock, Olivier Collignon, Julien Doyon, Emmanuel Stip, Pierre Orban
2013 J jnl
NeuroImage
Chao-Gan Yan, Brian Cheung, Clare Kelly, Stanley J. Colcombe, R. Cameron Craddock, Adriana Di Martino, Qingyang Li, Xi-Nian Zuo, F. Xavier Castellanos, Michael P. Milham
2013 J jnl
NeuroImage
F. Xavier Castellanos, Adriana Di Martino, R. Cameron Craddock, Ashesh D. Mehta, Michael P. Milham
2013 J jnl
NeuroImage
Gaël Varoquaux, R. Cameron Craddock
2013 J jnl
NeuroImage
R. Cameron Craddock, Michael P. Milham, Stephen LaConte
2013 J jnl
NeuroImage
Chao-Gan Yan, R. Cameron Craddock, Xi-Nian Zuo, Yufeng Zang, Michael P. Milham
2009 J jnl
NeuroImage
George Andrew James, Mary E. Kelley, R. Cameron Craddock, Paul E. Holtzheimer, Boadie W. Dunlop, Charles B. Nemeroff, Helen S. Mayberg, Xiaoping Philip Hu
redb/extractors/elf_extractors/elf_notes.py
← Index redb/extractors/elf_extractors/elf_notes.py python
import inspect
import binascii
from datetime import datetime, timezone
from typing import Any, List, Dict

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFNote


class ELFNotesExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_notes = []
        self.elastic_index = self.index_prefix + "-elf_notes"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _get_note_type_string(self, note_type: int, note_name: str) -> str:
        """Convert note type number to human-readable string."""

        # GNU-specific note types
        if note_name == "GNU":
            gnu_types = {
                1: "NT_GNU_ABI_TAG",
                2: "NT_GNU_HWCAP",
                3: "NT_GNU_BUILD_ID",
                4: "NT_GNU_GOLD_VERSION",
                5: "NT_GNU_PROPERTY_TYPE_0"
            }
            return gnu_types.get(note_type, f"NT_GNU_UNKNOWN_{note_type}")

        # Generic note types
        generic_types = {
            1: "NT_PRSTATUS",
            2: "NT_FPREGSET",
            3: "NT_PRPSINFO",
            4: "NT_TASKSTRUCT",
            5: "NT_AUXV",
            6: "NT_PSTATUS",
            7: "NT_FPREGS",
            8: "NT_PSINFO",
            9: "NT_PRCRED",
            10: "NT_UTSNAME",
            11: "NT_LWPSTATUS",
            12: "NT_LWPSINFO",
            13: "NT_PRFPXREG"
        }

        return generic_types.get(note_type, f"NT_UNKNOWN_{note_type}")

    def _format_note_description(self, note_desc, note_type: int, note_name: str) -> str:
        """Format note description based on type for human readability."""
        try:
            if not note_desc:
                return ""

            # Handle build ID specifically (common case)
            if note_name == "GNU" and note_type == 3:  # NT_GNU_BUILD_ID
                if isinstance(note_desc, bytes):
                    return binascii.hexlify(note_desc).decode('ascii')
                return str(note_desc)

            # Handle ABI tag
            if note_name == "GNU" and note_type == 1:  # NT_GNU_ABI_TAG
                if isinstance(note_desc, bytes) and len(note_desc) >= 16:
                    # ABI tag contains OS, major, minor, subminor
                    import struct
                    try:
                        os_val, major, minor, subminor = struct.unpack('<IIII', note_desc[:16])
                        os_names = {0: "Linux", 1: "GNU", 2: "Solaris", 3: "FreeBSD"}
                        os_name = os_names.get(os_val, f"OS_{os_val}")
                        return f"{os_name} {major}.{minor}.{subminor}"
                    except:
                        pass

            # For binary data, convert to hex
            if isinstance(note_desc, bytes):
                # Limit size for very large descriptions
                if len(note_desc) > 256:
                    return binascii.hexlify(note_desc[:256]).decode('ascii') + "..."
                return binascii.hexlify(note_desc).decode('ascii')

            # For string data
            if isinstance(note_desc, str):
                return note_desc

            # Fallback
            return str(note_desc)

        except Exception as e:
            self.log.error(f"Error formatting note description: {e}")
            return str(note_desc) if note_desc else ""

    def _extract_note_data(self, note, section_name: str) -> ELFNote:
        """Extract data from a single note entry."""
        try:
            # Get note properties
            note_name = note.get('n_name', '').rstrip('\x00') if note.get('n_name') else ""
            note_type_raw = note.get('n_type', 0)
            note_desc_raw = note.get('n_desc', b'')

            # Handle note_type - pyelftools may return string or int
            if isinstance(note_type_raw, str):
                # pyelftools returned the type as a string like 'NT_GNU_BUILD_ID'
                note_type_str = note_type_raw
                # Map known string types to integers
                note_type_map = {
                    'NT_GNU_ABI_TAG': 1,
                    'NT_GNU_HWCAP': 2,
                    'NT_GNU_BUILD_ID': 3,
                    'NT_GNU_GOLD_VERSION': 4,
                    'NT_GNU_PROPERTY_TYPE_0': 5,
                    'NT_PRSTATUS': 1,
                    'NT_FPREGSET': 2,
                    'NT_PRPSINFO': 3,
                    'NT_TASKSTRUCT': 4,
                    'NT_AUXV': 5,
                    'NT_PSTATUS': 6,
                    'NT_FPREGS': 7,
                    'NT_PSINFO': 8,
                    'NT_PRCRED': 9,
                    'NT_UTSNAME': 10,
                    'NT_LWPSTATUS': 11,
                    'NT_LWPSINFO': 12,
                    'NT_PRFPXREG': 13,
                }
                note_type = note_type_map.get(note_type_raw, 0)
            else:
                note_type = note_type_raw
                # Get human-readable type string
                note_type_str = self._get_note_type_string(note_type, note_name)

            # Format description
            note_desc = self._format_note_description(note_desc_raw, note_type, note_name)

            return ELFNote(
                note_name=note_name,
                note_type=note_type,
                note_type_str=note_type_str,
                note_desc=note_desc,
                note_section=section_name
            )

        except Exception as e:
            self.log.error(f"Error extracting note data: {e}")
            return None

    def _extract_notes_from_sections(self, elf) -> List[Dict]:
        """Extract notes from note sections."""
        notes = []

        try:
            # Look for note sections
            for section in elf.iter_sections():
                if (section.name and
                    section.name.startswith('.note') and
                    hasattr(section, 'iter_notes')):

                    section_name = section.name
                    try:
                        for note in section.iter_notes():
                            note_data = self._extract_note_data(note, section_name)
                            if note_data:
                                notes.append(note_data)
                    except Exception as e:
                        self.log.debug(f"Could not process notes in section {section_name}: {e}")

        except Exception as e:
            self.log.error(f"Error extracting notes from sections: {e}")

        return notes

    def _extract_notes_from_segments(self, elf) -> List[Dict]:
        """Extract notes from PT_NOTE segments."""
        notes = []

        try:
            # Look for PT_NOTE segments
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_NOTE':
                    segment_name = f"PT_NOTE_segment_{segment.header.get('p_offset', 0)}"

                    try:
                        if hasattr(segment, 'iter_notes'):
                            for note in segment.iter_notes():
                                note_data = self._extract_note_data(note, segment_name)
                                if note_data:
                                    notes.append(note_data)
                    except Exception as e:
                        self.log.debug(f"Could not process notes in segment: {e}")

        except Exception as e:
            self.log.error(f"Error extracting notes from segments: {e}")

        return notes

    def tag(self):
        return Tag.ELF_NOTES.value if hasattr(Tag, 'ELF_NOTES') else "elf_notes"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_data(elf):
                all_notes = []

                # Extract notes from note sections
                section_notes = self._extract_notes_from_sections(elf)
                all_notes.extend(section_notes)

                # Extract notes from PT_NOTE segments
                segment_notes = self._extract_notes_from_segments(elf)
                all_notes.extend(segment_notes)

                # Remove duplicates (same note might appear in section and segment)
                unique_notes = []
                seen_notes = set()
                for note in all_notes:
                    note_key = (note.note_name, note.note_type, note.note_desc)
                    if note_key not in seen_notes:
                        seen_notes.add(note_key)
                        unique_notes.append(note)

                return unique_notes

            if not self._is_elf_file():
                return None

            result = self._with_elf_file(extract_data)
            if result is None:
                return None

            self.elf_notes = result
            return self.elf_notes

        except Exception as e:
            self.log.error(f"Error extracting ELF notes {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_notes
        elif exporter_type == "ClickHouseExporter":
            try:
                # Return valid empty structure if no notes found
                # None is reserved for actual errors

                # Prepare data arrays for all notes
                data = []
                current_time = datetime.now(timezone.utc)
                for note in self.elf_notes:
                    row = [
                        self.sha256,
                        self.md5,
                        self.sha1,
                        note.note_name,
                        note.note_type,
                        note.note_type_str,
                        note.note_desc,
                        note.note_section,
                        current_time
                    ]
                    data.append(row)

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'note_name', 'note_type', 'note_type_str',
                    'note_desc', 'note_section',
                    'analysis_date'
                ]

                if not data:
                    return None

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    'LowCardinality(String)', 'UInt32', 'LowCardinality(String)',
                    'String CODEC(ZSTD(3))', 'LowCardinality(String)',
                    'DateTime64(3, \'UTC\')'
                ]

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_notes"