R. J. Kuo

72 papers B 1C 1Journal 63Unranked 7
YearRankTypeTitle / Venue / Authors
2026 J jnl
Comput. Ind. Eng.
R. J. Kuo, Kai-Wen Zheng, Ferani E. Zulvia, Timothy Kuo
2026 J jnl
Neural Comput. Appl.
R. J. Kuo, Chia-Jung Fan, Thi Phuong Quyen Nguyen, C.-W. Shih
2024 C conf
IEA/AIE
R. J. Kuo, Chia-Jung Fan, Thi Phuong Quyen Nguyen
2024 J jnl
Comput. Ind. Eng.
R. J. Kuo, Cian-Ying Wu, Timothy Kuo
2024 J jnl
Soft Comput.
R. J. Kuo, C. C. Hsu, Thi Phuong Quyen Nguyen, C. Y. Tsai
2024 J jnl
Appl. Soft Comput.
R. J. Kuo, Tzu-Hsuan Chiu
2023 J jnl
Knowl. Based Syst.
Thi-Thuy-Quynh Trinh, Yu-Chi Chung, R. J. Kuo
2023 J jnl
Ann. Oper. Res.
R. J. Kuo, P. F. Song, Thi Phuong Quyen Nguyen, T. J. Yang
2023 J jnl
Expert Syst. Appl.
R. J. Kuo, Muhammad Fernanda Luthfiansyah, Nur Aini Masruroh, Ferani Eva Zulvia
2023 J jnl
Appl. Soft Comput.
R. J. Kuo, Pei-Cheng Ho, Ferani E. Zulvia
2023 J jnl
Expert Syst. Appl.
R. J. Kuo, Evan Edbert, Ferani E. Zulvia, Shih-Hao Lu
2023 J jnl
Appl. Soft Comput.
R. J. Kuo, Shu-Syun Li
2023 J jnl
J. Intell. Manuf.
R. J. Kuo, Faisal Fuad Nursyahid
2022 J jnl
Appl. Soft Comput.
R. J. Kuo, Hong-Ruei Cheng
2022 J jnl
Expert Syst. Appl.
Shih-Hao Lu, R. J. Kuo, Yi-Ting Ho, Anh-Tu Nguyen
2022 J jnl
Neural Comput. Appl.
Nguyen Thi Phuong Quyen, R. J. Kuo, Minh Duc Le, Thi Cuc Nguyen, Thi Huynh Anh Le
2022 J jnl
Soft Comput.
R. J. Kuo, Dennis A. Kunarsito
2022 J jnl
Comput. Ind. Eng.
R. J. Kuo, Muhammad Rakhmat Setiawan, Thi Phuong Quyen Nguyen
2022 J jnl
Expert Syst. Appl.
R. J. Kuo, Shih-Hao Lu, Pei-Yu Lai, Setyo Tri Windras Mara
2021 J jnl
Knowl. Inf. Syst.
R. J. Kuo, C. K. Chang, Nguyen Thi Phuong Quyen, T. Warren Liao
2021 J jnl
Inf. Sci.
R. J. Kuo, Cheng-Kang Chen, Shao-Hong Keng
2021 J jnl
Int. Trans. Oper. Res.
Setyo Tri Windras Mara, R. J. Kuo, Anna Maria Sri Asih
2021 J jnl
Appl. Soft Comput.
R. J. Kuo, Ferani E. Zulvia
2020 conf
MSIE
R. J. Kuo, C. H. Li
2019 J jnl
J. Intell. Fuzzy Syst.
R. J. Kuo, W. C. Cheng
2019 J jnl
J. Intell. Fuzzy Syst.
R. J. Kuo, W. C. Cheng, Wan-Ching Lien, T. J. Yang
2019 J jnl
J. Intell. Manuf.
Zhen-Yao Chen, R. J. Kuo
2018 J jnl
Appl. Soft Comput.
T. Warren Liao, R. J. Kuo
2017 J jnl
Comput. Intell.
Zhen-Yao Chen, R. J. Kuo
2016 J jnl
Int. J. Artif. Intell. Tools
Zhen-Yao Chen, R. J. Kuo, Tung-Lai Hu
2016 J jnl
J. Intell. Manuf.
R. J. Kuo, Y. S. Tseng, Zhen-Yao Chen
2016 J jnl
Comput. Ind. Eng.
R. J. Kuo, P. S. Li
2015 J jnl
Comput. Methods Programs Biomed.
R. J. Kuo, W. C. Cheng, Wan-Ching Lien, T. J. Yang
2015 J jnl
Appl. Artif. Intell.
Zhen-Yao Chen, R. J. Kuo
2015 J jnl
Int. J. Artif. Intell. Tools
R. J. Kuo, S. H. Lin, Zhen-Yao Chen
2015 J jnl
J. Intell. Manuf.
R. J. Kuo, J. W. Chang
2014 J jnl
Appl. Soft Comput.
T. Warren Liao, Pei-Chann Chang, R. J. Kuo, Ching-Jong Liao
2014 J jnl
Inf. Sci.
R. J. Kuo, S. Y. Hung, W. C. Cheng
2014 J jnl
Appl. Artif. Intell.
R. J. Kuo, N. J. Chiang, Zhen-Yao Chen
2012 J jnl
Expert Syst. Appl.
R. J. Kuo, Kartika Akbaria, Budiarto Subroto
2012 J jnl
Appl. Math. Comput.
T. Warren Liao, R. J. Kuo, J. T. L. Hu
2012 J jnl
Appl. Soft Comput.
R. J. Kuo, C. F. Wang, Zhen-Yao Chen
2012 J jnl
Inf. Sci.
R. J. Kuo, Y. J. Syu, Zhen-Yao Chen, Fang-Chih Tien
2011 J jnl
Soft Comput.
R. J. Kuo, M. J. Wang, T. W. Huang
2011 J jnl
Appl. Soft Comput.
R. J. Kuo, C. M. Chao, Y. T. Chiu
2011 conf
IEEM
R. J. Kuo, C. M. Chen
2011 J jnl
Appl. Soft Comput.
R. J. Kuo, C. Y. Yang
2010 J jnl
Decis. Support Syst.
R. J. Kuo, L. M. Lin
2009 conf
ICEIS (2)
R. J. Kuo, M. J. Wang, T. W. Huang, Tung-Lai Hu
2009 conf
CAR
R. J. Kuo, Tung-Lai Hu, Zhen-Yao Chen
2009 J jnl
Comput. Math. Appl.
R. J. Kuo, C. C. Huang
2009 J jnl
Appl. Soft Comput.
R. J. Kuo, C. M. Chao, C. Y. Liu
2009 conf
UNISCON
R. J. Kuo, Tung-Lai Hu, Zhen-Yao Chen
2008 conf
ICEIS (2)
R. J. Kuo, L. Y. Lee, Tung-Lai Hu
2008 J jnl
Neurocomputing
R. J. Kuo, S. M. Hong, Y. Lin, Y. C. Huang
2007 J jnl
Comput. Math. Appl.
R. J. Kuo, Chih-Wen Shih
2007 J jnl
Expert Syst. Appl.
R. J. Kuo, S. Y. Lin, Chih-Wen Shih
2006 J jnl
Expert Syst. Appl.
R. J. Kuo, Y. L. An, H. S. Wang, W. J. Chung
2006 J jnl
Decis. Support Syst.
R. J. Kuo, Yu-Ting Su, Chui-Yu Chiu, Kai-Ying Chen, Fang-Chih Tien
2005 J jnl
Expert Syst. Appl.
R. J. Kuo, Y. P. Kuo, Kai-Ying Chen
2005 J jnl
Decis. Support Syst.
R. J. Kuo, J. L. Liao, C. Tu
2004 J jnl
J. Organ. Comput. Electron. Commer.
R. J. Kuo, K. Chang, S. Y. Chien
2002 J jnl
Comput. Ind.
R. J. Kuo, S. C. Chi, S. S. Kao
2002 J jnl
Comput. Oper. Res.
R. J. Kuo, L. M. Ho, Clark M. Hu
2001 J jnl
Eur. J. Oper. Res.
R. J. Kuo
1999 B conf
IJCNN
R. J. Kuo, S. C. Chi, B. W. Den
1999 J jnl
Fuzzy Sets Syst.
R. J. Kuo, K. C. Xue
1999 J jnl
Neural Networks
R. J. Kuo, P. H. Cohen
1998 J jnl
Decis. Support Syst.
R. J. Kuo, K. C. Xue
1998 J jnl
Artif. Intell. Eng.
R. J. Kuo, P. H. Cohen
1998 J jnl
Fuzzy Sets Syst.
R. J. Kuo, P. H. Cohen
1997 conf
ICNN
R. J. Kuo, K. C. Xue
redb/extractors/macho_extractors/macho_segments.py
← Index redb/extractors/macho_extractors/macho_segments.py python
import hashlib
import inspect
import base64
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.macho_extractor import MachOExtractor
from redb.models.dataclasses import MachOSegment


class MachOSegmentExtractor(MachOExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        macho=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            macho,
        )
        self.elastic_index = self.index_prefix + "-macho_segments"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _is_empty_result(self, extracted_data) -> bool:
        """
        Override: Empty segments is an ERROR, not a valid empty case.
        A valid MachO file must have segments (at minimum __PAGEZERO, __TEXT).
        """
        # Always return False - empty segments should be treated as an error
        return False

    def tag(self):
        return Tag.MACHO_SEGMENT.value

    def _extract_segments_for_arch(self, arch_name):
        """Extract segment information for a specific architecture."""
        self.log.debug(f"Extracting segments for architecture: {arch_name}")
        segments = []

        try:
            # Get segments using new API with architecture parameter
            segments_data = self.macho.get_segments(arch=arch_name)
            if not segments_data:
                return segments

            # Extract segments for this architecture
            for segment in segments_data:
                try:
                    segment_name = segment.get('segname', 'Unknown')

                    # Calculate segment hash
                    segment_data = self._get_segment_data(segment)
                    if segment_data:
                        seg_sha256 = hashlib.sha256(segment_data).hexdigest()
                    else:
                        seg_sha256 = ""

                    # Use entropy already calculated by machofile module, rounded to 3 decimal places
                    seg_entropy = round(segment.get('entropy', 0.0), 3)

                    # Create segment dataclass with architecture info
                    macho_segment = MachOSegment(
                        segment_name=segment_name,
                        segment_vaddr=segment.get('vaddr', 0),
                        segment_vsize=segment.get('vsize', 0),
                        segment_offset=segment.get('offset', 0),
                        segment_size=segment.get('size', 0),
                        segment_max_vm_protection=segment.get('max_vm_protection', 0),
                        segment_initial_vm_protection=segment.get('initial_vm_protection', 0),
                        segment_nsects=segment.get('nsects', 0),
                        segment_flags=segment.get('flags', 0),
                        segment_entropy=seg_entropy,
                        segment_sha256=seg_sha256,
                    )
                    # Add architecture info to the segment
                    macho_segment.architecture = arch_name
                    segments.append(macho_segment)

                except Exception as e:
                    self.log.warning(
                        f'Unable to process segment "{segment.get("segname", "Unknown")}" for architecture {arch_name} in {self.hash.sha256}: {e}'
                    )
                    continue

            return segments

        except Exception as e:
            self.log.error(f"Error extracting MachO segments for architecture {arch_name}: {e}")
            return segments

    def _extract_segments(self):
        """Extract segment information from all architectures in the MachO binary."""
        self.log.debug(inspect.currentframe().f_code.co_name)
        segments = []

        if not self.macho:
            return segments

        try:
            # Get architectures using new API (already parsed in base class)
            architectures = self.macho.get_architectures()
            if not architectures:
                return segments

            # Process each architecture
            for arch_name in architectures:
                arch_segments = self._extract_segments_for_arch(arch_name)
                segments.extend(arch_segments)

            return segments

        except Exception as e:
            self.log.error(f"Error extracting MachO segments: {e}")
            return segments

    def _get_segment_data(self, segment):
        """Get the raw data for a segment."""
        try:
            offset = segment.get('offset', 0)
            size = segment.get('size', 0)
            
            if size == 0:
                return None
            
            # Read segment data from file
            with open(self.filepath, 'rb') as f:
                f.seek(offset)
                return f.read(size)
                
        except Exception as e:
            self.log.warning(f"Error reading segment data: {e}")
            return None

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            segments = self._extract_segments()
            return segments
        except Exception as e:
            self.log.error(f"Error extracting MachO segments: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            if not self.macho:
                return None

            # Get architectures (macho is already parsed in base class)
            try:
                architectures = self.macho.get_architectures()
                is_fat = len(architectures) > 1
            except Exception as e:
                self.log.error(f"Could not get architectures: {e}")
                return None

            data = []
            current_time = datetime.now(timezone.utc)

            # Loop through each architecture (1 for single, multiple for FAT)
            for arch_name in architectures:
                # Extract segments for this specific architecture
                segments = self._extract_segments_for_arch(arch_name)
                if not segments:
                    continue

                # Get architecture-specific sha256 and header info
                try:
                    arch_general_info = self.macho.get_general_info(arch=arch_name)
                    arch_sha256 = arch_general_info.get('SHA256', self.sha256)

                    # Get raw architecture value
                    arch_header_raw = self.macho.get_macho_header(arch=arch_name)
                    arch_cputype_raw = arch_header_raw.get('cputype', 0) if arch_header_raw else 0
                except Exception as e:
                    self.log.warning(f"Could not get arch-specific data for {arch_name}: {e}")
                    arch_sha256 = self.sha256
                    arch_cputype_raw = 0

                for segment in segments:
                    data.append([
                        arch_sha256,                          # sha256 (architecture-specific)
                        segment.segment_name,                 # segment_name
                        segment.segment_vaddr,                # segment_vaddr
                        segment.segment_vsize,                # segment_vsize
                        segment.segment_offset,               # segment_offset
                        segment.segment_size,                 # segment_size
                        segment.segment_max_vm_protection,    # segment_max_vm_protection
                        segment.segment_initial_vm_protection, # segment_initial_vm_protection
                        segment.segment_nsects,               # segment_nsects
                        segment.segment_flags,                # segment_flags
                        segment.segment_entropy,              # segment_entropy
                        segment.segment_sha256,               # segment_sha256
                        current_time,                         # analysis_date
                    ])

            column_names = [
                'sha256',
                'segment_name', 'segment_vaddr', 'segment_vsize', 'segment_offset',
                'segment_size', 'segment_max_vm_protection', 'segment_initial_vm_protection',
                'segment_nsects', 'segment_flags', 'segment_entropy', 'segment_sha256',
                'analysis_date'
            ]

            if not data:
                return None

            column_type_names = [
                'FixedString(64)',
                'String', 'UInt64', 'UInt64', 'UInt64',
                'UInt64', 'UInt32', 'UInt32',
                'UInt32', 'UInt32', 'Float64', 'FixedString(64)',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

        return None

    def get_clickhouse_table(self) -> str:
        return "redb_macho_segments"