Rachel Edita Roxas

18 papers C 6Unranked 12
YearRankTypeTitle / Venue / Authors
2024 C conf
PACLIC
Rachel Edita Roxas
2021 C conf
TENCON
Johanna Minglana, Rogelio Ruzcko Tobias, Rachel Edita Roxas
2021 conf
ICICT (2)
Joseph Marvin Imperial, Angelica H. De La Cruz, Emmanuel Malaay, Rachel Edita Roxas
2021 C conf
TENCON
Rogelio Ruzcko Tobias, Rachel Edita Roxas, Mideth B. Abisado
2021 conf
IALP
Rachel Edita Roxas, Rogelio Ruzcko Tobias, Johanna Minglana
2019 conf
IALP
Joseph Marvin Imperial, Rachel Edita Roxas, Erica Mae Campos, Jemelee Oandasan, Reyniel Caraballo, Ferry Winsley Sabdani, Ani Rosa Almaroi
2018 conf
GHTC
Brandie Nonnecke, Shrestha Mohanty, Andrew Lee, Jonathan Lee, Sequoia Beckman, Justin Mi, Thanatcha Panpairoj, Jeffrey Rosario Ancheta, Hilary Martinez, Nathaniel Oco, Rachel Edita Roxas, Camille Crittenden, Ken Goldberg
2017 conf
IALP
Alfred John Tacorda, Marvin John Ignacio, Nathaniel Oco, Rachel Edita Roxas
2017 conf
O-COCOSDA
Emmanuel Malaay, Michael Simora, Ronald John Cabatic, Nathaniel Oco, Rachel Edita Roxas
2017 conf
GHTC
Brandie Nonnecke, Shrestha Mohanty, Andrew Lee, Jonathan Lee, Sequoia Beckman, Justin Mi, Sanjay Krishnan, Rachel Edita Roxas, Nathaniel Oco, Camille Crittenden, Ken Goldberg
2017 C ed.
PACLIC
Rachel Edita Roxas
2017 conf
IALP
Ken Gorro, Jeffrey Rosario Ancheta, Kris Capao, Nathaniel Oco, Rachel Edita Roxas, Mary Jane Sabellano, Brandie Nonnecke, Shrestha Mohanty, Camille Crittenden, Ken Goldberg
2016 C conf
PACLIC
Nathaniel Oco, Leif Romeritch Syliongka, Tod Allman, Rachel Edita Roxas
2016 conf
IALP
Cerino Ligutom, Jay Vincent Orio, Dyannah Alexa Marie Ramacho, Chuchi Montenegro, Rachel Edita Roxas, Nathaniel Oco
2013 conf
O-COCOSDA/CASLRE
Nathaniel Oco, Leif Romeritch Syliongka, Rachel Edita Roxas, Joel P. Ilao
2011 conf
ALR@IJCNLP
Shirley N. Dita, Rachel Edita Roxas
2009 conf
ALR7@IJCNLP
Rachel Edita Roxas, Charibeth Cheng, Nathalie Rose Lim
2006 C conf
PACLIC
Ebony Domingo, Rachel Edita Roxas
redb/extractors/detectiteasy.py
← Index redb/extractors/detectiteasy.py python
import inspect
from pprint import pprint
import subprocess
import json
from typing import Any
from datetime import datetime, timezone
import os
from dotenv import load_dotenv

from redb.extractors.enum import Tag
from redb.models.dataclasses import DIEinfo
from redb.extractors.extractor import Extractor

load_dotenv(override=True)

class DIEExtractor(Extractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        precomputed_hashes=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix, elastic_index, known_benign, known_malicious,
            precomputed_hashes=precomputed_hashes
        )
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.die_info = None
        self.die_info_dict = {}
        self.elastic_index = self.index_prefix + "-die"

    def _recursive_entry(self, die_dict, master_key):
        self.log.debug(inspect.currentframe().f_code.co_name)
        if master_key:
            self.die_info_dict[master_key] = {}
        else:
            self.die_info_dict = {}
        for value in die_dict:
            if "type" in value:
                type_key = value["type"].lower().replace(" ", "_")
                name = value.get("name", "")
                version = f"({value.get('version')})" if value.get("version") else ""
                info = f"[{value.get('info')}]" if value.get("info") else ""

                if master_key:
                    self.die_info_dict[master_key][type_key] = f"{name}"
                    self.die_info_dict[master_key][f'{type_key}(full)'] = f"{name}{version}{info}"
                else:
                    self.die_info_dict[type_key] = f"{name}"
                    self.die_info_dict[f'{type_key}(full)'] = f"{name}{version}{info}"

            elif "parentfilepart" in value:
                child_key = (
                    value["parentfilepart"].lower().replace(" ", "_")
                    + "."
                    + value["filetype"].lower().replace(" ", "_")
                )
                if master_key:
                    self._recursive_entry(value["values"], f"{master_key}.{child_key}")
                else:
                    self._recursive_entry(value["values"], f"{child_key}")

    def _extract_dieinfo(self):
        """
        Execute a command-line binary with arguments and parse its JSON output.

        :param command: The command or path to the binary to execute
        :param args: Additional arguments to pass to the command
        :return: Parsed JSON output as a Python object
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # Construct the full command
        # command = "nfdc" # UNCOMMENT FOR PROD
        # command = "/Users/p4c0/_tools/NFD.app/Contents/MacOS/nfdc" # COMMENT FOR TESTING ON MAC
        command = os.getenv("DIE_PATH")
        args = ["-durj", self.filepath]
        full_command = [command] + list(args)
        TIMEOUT = int(os.getenv("DIE_TIMEOUT", "180"))

        try:
            # Execute the command and capture its output
            result = subprocess.run(
                full_command,
                capture_output=True,
                text=True,
                check=True,
                timeout=TIMEOUT,
            )

            # Parse the JSON output
            nfdc_output = json.loads(result.stdout)

            # Extract the DIE information from the json output
            for die_entry in nfdc_output["detects"]:
                if die_entry["parentfilepart"] == "Header":
                    master_key = (
                        die_entry["parentfilepart"].lower().replace(" ", "_")
                        + "."
                        + die_entry["filetype"].lower().replace(" ", "_")
                    )
                    self._recursive_entry(die_entry["values"], None)

            # pprint(json.dumps(self.die_info_dict, indent=2)) #debug
            self.die_info = DIEinfo(result.stdout, self.die_info_dict)
            self.log.debug(f"NFDC-DIE JSON dump: todo")
        except subprocess.TimeoutExpired:
            self.log.error(f"The DIE command timed out after {TIMEOUT} seconds")
            return None
        except subprocess.CalledProcessError as e:
            self.log.error(f"Error executing DIE command: {e}")
            self.log.error(f"Command output (stderr): {e.stderr}")
            return None
        except json.JSONDecodeError as e:
            self.log.error(f"Error parsing DIE JSON output: {e}")
            self.log.error(f"Raw output: {result.stdout}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.die_info
        elif exporter_type == "ClickHouseExporter":
            # Convert DIE info to JSON string
            die_info_json = json.dumps(self.die_info_dict)
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                die_info_json,
                datetime.now(timezone.utc)
            ]]
            
            column_names = [
                'sha256', 'md5', 'sha1', 'die_info', 'analysis_date'
            ]
            
            column_type_names = [
                'String', 'String', 'String', 'JSON', 'DateTime64(3, \'UTC\')'
            ]
            
            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_die"

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            self._extract_dieinfo()
            
            # Check if there's a packer in the DIE results
            is_packed = False
            if self.die_info_dict:
                # Check if 'packer' exists in the DIE results
                is_packed = bool(self.die_info_dict.get('packer'))
            
            return self.die_info  # Return the extracted data instead of exporting directly
        except Exception as e:
            self.log.error(f"Error extracting DIE information: {e}")
            return None

    def tag(self):
        return Tag.DIEC.value