Raffaele Crapolicchio

21 papers C 11Journal 9Unranked 1
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Aina García-Espriu, Estrella Olmedo, Verónica González-Gambau, Cristina González-Haro, Antonio Turiel, Yoann Rey-Ricord, Eric Jeansou, Roberto Sabia, Raffaele Crapolicchio, Roger Oliva
2022 J jnl
IEEE Trans. Geosci. Remote. Sens.
Raúl Díez-García, Roger Oliva, Raffaele Crapolicchio, Manuel Martín-Neira
2021 C conf
IGARSS
Manuel Martín-Neira, Roger Oliva, Raul Onrubia, Ignasi Corbella, Nuria Duffo, Roselena Rubino, Juha Kainulainen, Josep Closa, Alberto Zurita, Javier Del Castillo, François Cabot, Ali Khazaal, Eric Anterrieu, José Barbosa, Gonçalo Lopes, Daniel Barros, Joe Tenerelli, Raul Diez-Garcia, Verena Rodriguezi, Jorge Fauste, Jose Maria Castro Ceron, Antonio Turiel, Verónica González-Gambau, Raffaele Crapolicchio, Lorenzo Di Ciolo, Giovanni Macelloni, Marco Brogioni, Francesco Montomoli, Pierre Vogel, Berta Hoyos-Ortega, Elena Checa Cortes, Martin Suess
2020 J jnl
Remote. Sens.
Roger Oliva, Manuel Martín-Neira, Ignasi Corbella, Josep Closa, Alberto Zurita, François Cabot, Ali Khazaal, Philippe Richaume, Juha Kainulainen, José Barbosa, Goncalo Lopes, Joseph Tenerelli, Raúl Díez-García, Verónica González-Gambau, Raffaele Crapolicchio
2019 C conf
IGARSS
Manuel Martín-Neira, François Cabot, Ali Khazaal, Eric Anterrieu, Philippe Richaume, José Barbosa, Goncalo Lopes, Joe Tenerelli, Raúl Díez-García, Jorge Fauste, Antonio Turiel, Roger Oliva, Verónica González-Gambau, Raffaele Crapolicchio, Giovanni Macelloni, Marco Brogioni, Pierre Vogel, Martin Suess, Ignasi Corbella, Francesc Torres, Nuria Duffo, Israel Durán, Juha Kainulainen, Josep Closa, Alberto Zurita
2018 C conf
IGARSS
Manuel Martín-Neira, Martin Suess, Roger Oliva, Jorge Fauste, Ignasi Corbella, Francesc Torres, Nuria Duffo, Israel Durán, Juha Kainulainen, Josep Closa, Alberto Zurita, François Cabot, Ali Khazaal, Eric Anterrieu, José Barbosa, Goncalo Lopes, Joe Tenerelli, Raul Diez-Garcia, Antonio Turiel, Verónica González-Gambau, Raffaele Crapolicchio
2018 C conf
IGARSS
Raffaele Crapolicchio, Daniele Casella, Christophe Marque
2017 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Nazzareno Pierdicca, Fabio Fascetti, Luca Pulvirenti, Raffaele Crapolicchio
2017 C conf
IGARSS
Fabio Fascetti, Nazzareno Pierdicca, Luca Pulvirenti, Raffaele Crapolicchio
2017 C conf
IGARSS
Manuel Martín-Neira, Roger Oliva, Ignasi Corbella, Francesc Torres, Nuria Duffo, Israel Durán, Juha Kainulainen, Josep Closa, Alberto Zurita, François Cabot, Ali Khazaal, Eric Anterrieu, José Barbosa, Goncalo Lopes, Joe Tenerelli, Raul Diez-Garcia, Jorge Fauste, Verónica González-Gambau, Antonio Turiel, Steven Delwart, Raffaele Crapolicchio, Martin Suess, Susanne Mecklenburg, Matthias Drusch, Roberto Sabia, Elena Daganzo-Eusebio, Yann Kerr, Nicolas Reul
2016 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Fabio Fascetti, Nazzareno Pierdicca, Luca Pulvirenti, Raffaele Crapolicchio, Joaquín Muñoz Sabater
2016 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Paola Laiolo, Simone Gabellani, Lorenzo Campo, Francesco Silvestro, Fabio Delogu, Roberto Rudari, Luca Pulvirenti, Giorgio Boni, Fabio Fascetti, Nazzareno Pierdicca, Raffaele Crapolicchio, Stefan Hasenauer, Silvia Puca
2016 C conf
IGARSS
Manuel Martín-Neira, Roger Oliva, Ignasi Corbella, Francesc Torres, Nuria Duffo, Israel Durán, Juha Kainulainen, Josep Closa, Alberto Zurita, François Cabot, Ali Khazaal, Eric Anterrieu, José Barbosa, Goncalo Lopes, Joe Tenerelli, Raul Diez-Garcia, Jorge Fauste, Verónica González-Gambau, Antonio Turiel, Steven Delwart, Raffaele Crapolicchio, Martin Suess
2016 conf
SAR
Fabio Fascetti, Nazzareno Pierdicca, Luca Pulvirenti, Raffaele Crapolicchio
2015 J jnl
IEEE Geosci. Remote. Sens. Lett.
Nazzareno Pierdicca, Fabio Fascetti, Luca Pulvirenti, Raffaele Crapolicchio, Joaquín Muñoz Sabater
2014 C conf
IGARSS
Fabio Fascetti, Nazzareno Pierdicca, Luca Pulvirenti, Raffaele Crapolicchio, Joaquín Muñoz Sabater
2014 C conf
IGARSS
Paola Laiolo, Simone Gabellani, Luca Pulvirenti, Giorgio Boni, Roberto Rudari, Fabio Delogu, Francesco Silvestro, Lorenzo Campo, Fabio Fascetti, Nazzareno Pierdicca, Raffaele Crapolicchio, Stefan Hasenauer, Silvia Puca
2012 C conf
IGARSS
Nazzareno Pierdicca, Luca Pulvirenti, Andrea Santarelli, Raffaele Crapolicchio, Marco Talone, Silvia Puca
2012 C conf
IGARSS
Marco Talone, Raffaele Crapolicchio, Giovanna De Chiara, Xavier Neyt, Anis Elyouncha, Lidia Saavedra De Miguel, Gareth Davies, Bojan Bojkov
2012 J jnl
IEEE Trans. Geosci. Remote. Sens.
Raffaele Crapolicchio, Giovanna De Chiara, Anis Elyouncha, Pascal Lecomte, Xavier Neyt, Alessandra Paciucci, Marco Talone
2012 J jnl
IEEE Trans. Geosci. Remote. Sens.
Susanne Mecklenburg, Matthias Drusch, Yann H. Kerr, Jordi Font, Manuel Martín-Neira, Steven Delwart, Guillermo Buenadicha, Nicolas Reul, Elena Daganzo-Eusebio, Roger Oliva, Raffaele Crapolicchio
redb/extractors/js_extractor.py
← Index redb/extractors/js_extractor.py python
import logging
import re
from abc import ABCMeta, abstractmethod

from redb.extractors.extractor import Extractor
from redb.extractors.js_extractors.js_context import JSContext, _text_entropy

logger = logging.getLogger(__name__)

# ESM is recognised by line-anchored `import ... from "..."` / bare side-effect
# `import "..."` / top-level `export ...`. Anchored at line start to avoid
# matching the substring inside string literals or comments.
_ESM_PATTERN = re.compile(
    r'(?m)^\s*(?:'
    r'import\s+[^;\n]*?\bfrom\s+[\'"]'
    r'|import\s+[\'"][^\'"]+[\'"]'
    r'|export\s+(?:default\b|\{|\*|const\b|let\b|var\b|function\b|class\b|async\b)'
    r')'
)


@abstractmethod
class JSExtractor(Extractor, metaclass=ABCMeta):
    """Base class for JavaScript file extractors.

    Every JSExtractor reads its raw materials (bytes / decoded source / line
    list / scan_source results / pyjsparser AST / text entropy) from a shared
    `JSContext`. When workers.py drives the JS pipeline it builds one context
    per sample and threads it into every extractor via `context=`. When tests
    or other callers instantiate an extractor directly, the constructor builds
    a fresh context from `(filepath, source=...)`.

    All historical instance attributes (`self.binary`, `self.js_source`,
    `self.lines`) and helpers (`self._decode_source`, `self._parse_ast`,
    `self._calculate_text_entropy`) are preserved as thin delegators so
    existing extractor code keeps working unchanged.
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        known_benign=False,
        known_malicious=False,
        source=None,
        context=None,
    ):
        if context is None:
            context = JSContext.from_path(filepath, log=log, source=source)
        elif source is not None and context.source != source:
            log.warning(
                "JSExtractor received both `source=` and `context=` with "
                "differing source; ignoring source kwarg"
            )
        self._context = context

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            known_benign=known_benign,
            known_malicious=known_malicious,
        )

    @property
    def binary(self):
        return self._context.raw_bytes

    @property
    def js_source(self):
        return self._context.source

    @property
    def lines(self):
        return self._context.lines

    def _decode_source(self):
        """Back-compat shim — the context already decoded once at construction.

        Kept so any external caller using the historical method name keeps
        working without touching the underlying bytes again.
        """
        return self._context.source

    def _parse_ast(self):
        """Return the shared pyjsparser AST (or None if unavailable)."""
        return self._context.ast

    def _calculate_text_entropy(self, text):
        """Shannon text entropy for `text`.

        When `text` is the context's own source we read the cached value;
        otherwise we compute fresh. JSStringsExtractor calls this on arbitrary
        decoded substrings, so the fresh-compute path must remain available.
        """
        if text is self._context.source:
            return self._context.text_entropy
        return _text_entropy(text)

    def _detect_environment(self):
        """Detect the target JS runtime environment."""
        src = self.js_source
        if not src:
            return "unknown"

        # WScript/WSH indicators
        wscript_patterns = [
            'WScript.', 'WSH.', 'ActiveXObject', 'Scripting.FileSystemObject',
            'WScript.Shell', 'ADODB.Stream',
        ]
        for p in wscript_patterns:
            if p in src:
                return "wscript"

        # Browser-extension APIs — checked before generic browser/worker because
        # `chrome.*` and `browser.runtime` are distinctive of MV2/MV3 extensions
        extension_patterns = [
            'chrome.runtime', 'chrome.tabs', 'chrome.storage',
            'chrome.webRequest', 'browser.runtime', 'browser.tabs',
        ]
        for p in extension_patterns:
            if p in src:
                return "browser_extension"

        # Service / Web Workers — worker-only APIs that don't appear in regular
        # browser pages (a generic browser script would use `window.` or
        # `document.`, never `self.importScripts` or `caches.match`)
        worker_patterns = [
            "self.addEventListener('fetch'", 'self.addEventListener("fetch"',
            'self.importScripts', 'self.skipWaiting',
            'caches.match', 'caches.open',
        ]
        for p in worker_patterns:
            if p in src:
                return "service_worker"

        # Deno runtime
        if 'Deno.' in src:
            return "deno"

        # Node.js indicators
        node_patterns = [
            'require(', 'module.exports', 'process.env', '__dirname',
            '__filename', 'Buffer.', 'child_process',
        ]
        for p in node_patterns:
            if p in src:
                return "node"

        # Browser indicators
        browser_patterns = [
            'document.', 'window.', 'navigator.', 'localStorage',
            'sessionStorage', 'XMLHttpRequest', 'addEventListener',
        ]
        for p in browser_patterns:
            if p in src:
                return "browser"

        return "unknown"

    def _detect_script_type(self):
        """Detect the script type/format."""
        src = self.js_source
        if not src:
            return "unknown"

        stripped = src.lstrip()

        # JScript.Encode payload — must be checked first since the encoded
        # body can't be classified any other way
        if stripped.startswith('#@~^'):
            return "jse"

        # WSF / HTA live in the first few KB of an HTML-ish wrapper
        head_lower = stripped[:4096].lower()

        # Windows Script File — XML wrapper around one or more <script> blocks
        if ('<job' in head_lower or '<package' in head_lower) and '<script' in head_lower:
            return "wsf"

        # HTML Application — distinct from generic embedded_html because HTAs
        # run under mshta.exe with full WSH/ActiveX access
        if '<hta:application' in head_lower or 'application/hta' in head_lower:
            return "hta"

        if stripped.startswith('<!') or stripped.startswith('<html') or '<script' in stripped[:2000]:
            return "embedded_html"

        if 'WScript.' in src or 'WSH.' in src:
            return "wscript"

        if _ESM_PATTERN.search(src):
            return "esm"

        if 'require(' in src or 'module.exports' in src:
            return "node_module"

        return "standalone"