R. Lynn Kirlin

45 papers B 2Misc 15Journal 22Unranked 6
YearRankTypeTitle / Venue / Authors
2021 J jnl
IEEE Trans. Inf. Theory
Ali M. Reza, R. Lynn Kirlin
2013 Misc conf
ICASSP
R. Lynn Kirlin, Ali M. Reza
2011 J jnl
IEEE Trans. Ind. Electron.
R. Lynn Kirlin, Cristian Lascu, Andrzej M. Trzynadlowski
2003 conf
ICIP (2)
Xiaoli Lu, R. Lynn Kirlin, Jian Wang
2002 J jnl
IEEE Trans. Ind. Electron.
R. Lynn Kirlin, Michael M. Bech, Andrzej M. Trzynadlowski
2002 conf
SSIAI
Miquel Mujal, R. Lynn Kirlin
2002 Misc conf
ICASSP
Jian Wang, R. Lynn Kirlin
2000 J jnl
IEEE Trans. Signal Process.
Rex K. Andrew, R. Lynn Kirlin
2000 J jnl
IEEE Trans. Signal Process.
Rex K. Andrew, R. Lynn Kirlin
1999 J jnl
Digit. Signal Process.
B. Kaufhold, R. Lynn Kirlin, Reza M. Dizaji
1999 B conf
WCNC
Severine Catreux, R. Lynn Kirlin, Peter F. Driessen
1997 J jnl
IEEE Signal Process. Lett.
Gregory Robertson, R. Lynn Kirlin, W.-S. Lu
1997 J jnl
IEEE Trans. Signal Process.
Ana I. Pérez-Neira, Miguel Angel Lagunas, R. Lynn Kirlin
1997 Misc conf
ICASSP
R. Lynn Kirlin
1997 J jnl
IEEE Trans. Ind. Electron.
Andrzej M. Trzynadlowski, R. Lynn Kirlin, Stanislaw F. Legowski
1996 Misc conf
ICASSP
David A. Caughey, R. Lynn Kirlin
1996 J jnl
IEEE Trans. Commun.
Brad A. Hedstrom, R. Lynn Kirlin
1994 B conf
VTC
R. Lynn Kirlin, Peter F. Driessen
1993 conf
ICASSP (1)
R. Lynn Kirlin, Brad A. Hedstrom
1993 conf
ICASSP (4)
Weixiu Du, R. Lynn Kirlin
1993 conf
ICASSP (3)
W.-S. Lu, Y. Cui, R. Lynn Kirlin
1993 J jnl
IEEE Trans. Signal Process.
Jonathan N. Bradley, R. Lynn Kirlin
1992 J jnl
IEEE Trans. Signal Process.
Weixiu Du, R. Lynn Kirlin
1991 Misc conf
ICASSP
R. Lynn Kirlin
1991 Misc conf
ICASSP
R. Lynn Kirlin, Weixiu Du
1991 conf
ICMC
W. Brent Weeks, W. Andrew Schloss, R. Lynn Kirlin
1990 J jnl
Signal Process.
Luis Torres-Urgell, R. Lynn Kirlin
1990 Misc conf
ICASSP
R. Lynn Kirlin, Yiqun Su
1990 J jnl
Pattern Recognit.
Sue Ellen Englert, Zhaoxin Sheng, R. Lynn Kirlin
1989 J jnl
IEEE Trans. Acoust. Speech Signal Process.
Alireza Moghaddamjoo, R. Lynn Kirlin
1988 Misc conf
ICASSP
William J. Done, R. Lynn Kirlin
1987 Misc conf
ICASSP
Luis Torres-Urgell, R. Lynn Kirlin
1986 J jnl
IEEE Trans. Acoust. Speech Signal Process.
R. Lynn Kirlin, Alireza Moghaddamjoo
1985 J jnl
IEEE Trans. Acoust. Speech Signal Process.
R. Lynn Kirlin, Ernest S. Gale
1985 J jnl
IEEE Trans. Acoust. Speech Signal Process.
R. Lynn Kirlin, Lois A. Dewey
1985 Misc conf
ICASSP
R. Lynn Kirlin, Alireza Moghaddamjoo
1985 Misc conf
ICASSP
R. Lynn Kirlin, Becky Cudzilo, Sharon Wilson
1983 Misc conf
ICASSP
R. Lynn Kirlin
1983 Misc conf
ICASSP
R. Lynn Kirlin, Lois A. Dewey
1980 Misc conf
ICASSP
R. Lynn Kirlin
1980 Misc conf
ICASSP
R. Lynn Kirlin
1977 J jnl
IEEE Trans. Inf. Theory
R. Lynn Kirlin
1975 J jnl
IEEE Trans. Commun.
R. Lynn Kirlin, C. C. Hu
1972 J jnl
IEEE Trans. Commun.
R. Lynn Kirlin
1972 J jnl
IEEE Trans. Inf. Theory
R. Lynn Kirlin
redb/extractors/js_extractor.py
← Index redb/extractors/js_extractor.py python
import logging
import re
from abc import ABCMeta, abstractmethod

from redb.extractors.extractor import Extractor
from redb.extractors.js_extractors.js_context import JSContext, _text_entropy

logger = logging.getLogger(__name__)

# ESM is recognised by line-anchored `import ... from "..."` / bare side-effect
# `import "..."` / top-level `export ...`. Anchored at line start to avoid
# matching the substring inside string literals or comments.
_ESM_PATTERN = re.compile(
    r'(?m)^\s*(?:'
    r'import\s+[^;\n]*?\bfrom\s+[\'"]'
    r'|import\s+[\'"][^\'"]+[\'"]'
    r'|export\s+(?:default\b|\{|\*|const\b|let\b|var\b|function\b|class\b|async\b)'
    r')'
)


@abstractmethod
class JSExtractor(Extractor, metaclass=ABCMeta):
    """Base class for JavaScript file extractors.

    Every JSExtractor reads its raw materials (bytes / decoded source / line
    list / scan_source results / pyjsparser AST / text entropy) from a shared
    `JSContext`. When workers.py drives the JS pipeline it builds one context
    per sample and threads it into every extractor via `context=`. When tests
    or other callers instantiate an extractor directly, the constructor builds
    a fresh context from `(filepath, source=...)`.

    All historical instance attributes (`self.binary`, `self.js_source`,
    `self.lines`) and helpers (`self._decode_source`, `self._parse_ast`,
    `self._calculate_text_entropy`) are preserved as thin delegators so
    existing extractor code keeps working unchanged.
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        known_benign=False,
        known_malicious=False,
        source=None,
        context=None,
    ):
        if context is None:
            context = JSContext.from_path(filepath, log=log, source=source)
        elif source is not None and context.source != source:
            log.warning(
                "JSExtractor received both `source=` and `context=` with "
                "differing source; ignoring source kwarg"
            )
        self._context = context

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            known_benign=known_benign,
            known_malicious=known_malicious,
        )

    @property
    def binary(self):
        return self._context.raw_bytes

    @property
    def js_source(self):
        return self._context.source

    @property
    def lines(self):
        return self._context.lines

    def _decode_source(self):
        """Back-compat shim — the context already decoded once at construction.

        Kept so any external caller using the historical method name keeps
        working without touching the underlying bytes again.
        """
        return self._context.source

    def _parse_ast(self):
        """Return the shared pyjsparser AST (or None if unavailable)."""
        return self._context.ast

    def _calculate_text_entropy(self, text):
        """Shannon text entropy for `text`.

        When `text` is the context's own source we read the cached value;
        otherwise we compute fresh. JSStringsExtractor calls this on arbitrary
        decoded substrings, so the fresh-compute path must remain available.
        """
        if text is self._context.source:
            return self._context.text_entropy
        return _text_entropy(text)

    def _detect_environment(self):
        """Detect the target JS runtime environment."""
        src = self.js_source
        if not src:
            return "unknown"

        # WScript/WSH indicators
        wscript_patterns = [
            'WScript.', 'WSH.', 'ActiveXObject', 'Scripting.FileSystemObject',
            'WScript.Shell', 'ADODB.Stream',
        ]
        for p in wscript_patterns:
            if p in src:
                return "wscript"

        # Browser-extension APIs — checked before generic browser/worker because
        # `chrome.*` and `browser.runtime` are distinctive of MV2/MV3 extensions
        extension_patterns = [
            'chrome.runtime', 'chrome.tabs', 'chrome.storage',
            'chrome.webRequest', 'browser.runtime', 'browser.tabs',
        ]
        for p in extension_patterns:
            if p in src:
                return "browser_extension"

        # Service / Web Workers — worker-only APIs that don't appear in regular
        # browser pages (a generic browser script would use `window.` or
        # `document.`, never `self.importScripts` or `caches.match`)
        worker_patterns = [
            "self.addEventListener('fetch'", 'self.addEventListener("fetch"',
            'self.importScripts', 'self.skipWaiting',
            'caches.match', 'caches.open',
        ]
        for p in worker_patterns:
            if p in src:
                return "service_worker"

        # Deno runtime
        if 'Deno.' in src:
            return "deno"

        # Node.js indicators
        node_patterns = [
            'require(', 'module.exports', 'process.env', '__dirname',
            '__filename', 'Buffer.', 'child_process',
        ]
        for p in node_patterns:
            if p in src:
                return "node"

        # Browser indicators
        browser_patterns = [
            'document.', 'window.', 'navigator.', 'localStorage',
            'sessionStorage', 'XMLHttpRequest', 'addEventListener',
        ]
        for p in browser_patterns:
            if p in src:
                return "browser"

        return "unknown"

    def _detect_script_type(self):
        """Detect the script type/format."""
        src = self.js_source
        if not src:
            return "unknown"

        stripped = src.lstrip()

        # JScript.Encode payload — must be checked first since the encoded
        # body can't be classified any other way
        if stripped.startswith('#@~^'):
            return "jse"

        # WSF / HTA live in the first few KB of an HTML-ish wrapper
        head_lower = stripped[:4096].lower()

        # Windows Script File — XML wrapper around one or more <script> blocks
        if ('<job' in head_lower or '<package' in head_lower) and '<script' in head_lower:
            return "wsf"

        # HTML Application — distinct from generic embedded_html because HTAs
        # run under mshta.exe with full WSH/ActiveX access
        if '<hta:application' in head_lower or 'application/hta' in head_lower:
            return "hta"

        if stripped.startswith('<!') or stripped.startswith('<html') or '<script' in stripped[:2000]:
            return "embedded_html"

        if 'WScript.' in src or 'WSH.' in src:
            return "wscript"

        if _ESM_PATTERN.search(src):
            return "esm"

        if 'require(' in src or 'module.exports' in src:
            return "node_module"

        return "standalone"