Raghu Kacker

82 papers A 10B 2C 2Misc 2Journal 25Unranked 41
YearRankTypeTitle / Venue / Authors
2026 J jnl
SN Comput. Sci.
Krishna Khadka, Jaganmohan Chandrasekaran, Yu Lei, Raghu Kacker, D. Richard Kuhn
2026 conf
KDD (1)
Krishna Khadka, Sunny Shree, Pujan Budhathoki, Yu Lei, Raghu Kacker, D. Richard Kuhn
2026 J jnl
IEEE Secur. Priv.
Dimitris E. Simos, Manuel Leithner, Rick Kuhn, Bernhard Garn, Raghu Kacker, Jeff Yu Lei
2025 J jnl
CoRR
Krishna Khadka, Sunny Shree, Pujan Budhathoki, Yu Lei, Raghu Kacker, D. Richard Kuhn
2025 conf
ICSTW
Klaus Kieseberg, Konstantin Gerner, Bernhard Garn, Wolfgang Czerni, Dimitris E. Simos, D. Richard Kuhn, Raghu Kacker
2025 J jnl
Distributed Ledger Technol. Res. Pract.
Qiping Wei, Fadul Sikder, Huadong Feng, Yu Lei, Raghu Kacker, D. Richard Kuhn
2024 conf
ICSTW
Dimitris E. Simos, Bernhard Garn, Dominik Schreiber, Manuel Leithner, D. Richard Kuhn, Raghu Kacker
2023 A conf
ICST
Huadong Feng, Xiaolei Ren, Qiping Wei, Yu Lei, Raghu Kacker, D. Richard Kuhn, Dimitris E. Simos
2023 conf
BRAINS
Qiping Wei, Fadul Sikder, Huadong Feng, Yu Lei, Raghu Kacker, D. Richard Kuhn
2023 conf
ICSTW
Bernhard Garn, Dominik-Philip Schreiber, Dimitris E. Simos, Rick Kuhn, Jeffrey M. Voas, Raghu Kacker
2022 J jnl
Comput. Secur.
Bernhard Garn, Stefan Zauner, Dimitris E. Simos, Manuel Leithner, D. Richard Kuhn, Raghu Kacker
2022 conf
ISSRE Workshops
Rick Kuhn, M. S. Raunak, Raghu Kacker
2022 J jnl
Softw. Test. Verification Reliab.
Bernhard Garn, Dominik-Philip Schreiber, Dimitris E. Simos, Rick Kuhn, Jeffrey M. Voas, Raghu Kacker
2022 conf
ICST Workshops
Michael Wagner, Manuel Leithner, Dimitris E. Simos, Rick Kuhn, Raghu Kacker
2022 Misc conf
FLAIRS
Jaganmohan Chandrasekaran, Feras A. Batarseh, Laura J. Freeman, Raghu Kacker, M. S. Raunak, Rick Kuhn
2021 conf
ICST Workshops
Jaganmohan Chandrasekaran, Yu Lei, Raghu Kacker, D. Richard Kuhn
2021 conf
ICST Workshops
Jaganmohan Chandrasekaran, Yu Lei, Raghu Kacker, D. Richard Kuhn
2021 conf
ICST Workshops
Bernhard Garn, Daniel Sebastian Lang, Manuel Leithner, D. Richard Kuhn, Raghu Kacker, Dimitris E. Simos
2021 conf
AITest
Jaganmohan Chandrasekaran, Ankita Ramjibhai Patel, Yu Lei, Raghu Kacker, D. Richard Kuhn
2020 J jnl
IEEE Trans. Software Eng.
Laleh Shikh Gholamhossein Ghandehari, Yu Lei, Raghu Kacker, D. Richard Kuhn, Tao Xie, David Chenho Kung
2020 conf
ICST Workshops
Michael Wagner, Kristoffer Kleine, Dimitris E. Simos, Rick Kuhn, Raghu Kacker
2020 conf
AITest
Jaganmohan Chandrasekaran, Huadong Feng, Yu Lei, Raghu Kacker, D. Richard Kuhn
2020 conf
ISSRE Workshops
Athira Varma Jayakumar, Smitha Gautham, D. Richard Kuhn, Brandon J. Simon, Aidan G. Collins, Thomas Dirsch, Raghu Kacker, Carl R. Elks
2019 conf
ICST Workshops
Riley Smith, Darryl C. Jarman, Raghu Kacker, D. Richard Kuhn, Dimitris E. Simos, Ludwig Kampel, Manuel Leithner, Gabe Gosney
2019 conf
HotSoS
Bernhard Garn, Dimitris E. Simos, Stefan Zauner, Rick Kuhn, Raghu Kacker
2019 conf
ICST Workshops
Riley Smith, Darryl C. Jarman, Jared Bellows, D. Richard Kuhn, Raghu Kacker, Dimitris E. Simos
2019 conf
MET@ICSE
Sydney Pugh, M. S. Raunak, D. Richard Kuhn, Raghu Kacker
2018 conf
IEEE BigData
Huadong Feng, Jaganmohan Chandrasekaran, Yu Lei, Raghu Kacker, D. Richard Kuhn
2018 J jnl
Computer
Rick Kuhn, M. S. Raunak, Raghu Kacker
2018 conf
HotSoS
Dimitris E. Simos, Rick Kuhn, Yu Lei, Raghu Kacker
2018 J jnl
IEEE Trans. Reliab.
Nicky Mouha, M. S. Raunak, D. Richard Kuhn, Raghu Kacker
2018 conf
DSA
Linghuan Hu, W. Eric Wong, D. Richard Kuhn, Raghu Kacker
2018 C conf
SEKE
Rick Kuhn, Dylan Yaga, Raghu Kacker, Jeff Yu Lei, Vincent C. Hu
2018 conf
HotSoS
Rick Kuhn, M. S. Raunak, Raghu Kacker
2017 conf
QRS Companion
D. Richard Kuhn, M. S. Raunak, Raghu Kacker
2017 conf
ICST Workshops
Jaganmohan Chandrasekaran, Huadong Feng, Yu Lei, D. Richard Kuhn, Raghu Kacker
2017 conf
QRS Companion
M. S. Raunak, D. Richard Kuhn, Raghu Kacker
2017 J jnl
IACR Cryptol. ePrint Arch.
Nicky Mouha, M. S. Raunak, D. Richard Kuhn, Raghu Kacker
2017 J jnl
IT Prof.
Rick Kuhn, M. S. Raunak, Raghu Kacker
2016 J jnl
Computer
Dimitris E. Simos, Rick Kuhn, Artemios G. Voyiatzis, Raghu Kacker
2016 conf
ICST Workshops
Jaganmohan Chandrasekaran, Laleh S. Ghandehari, Yu Lei, Raghu Kacker, D. Richard Kuhn
2016 C conf
QRS
Dimitris E. Simos, Kristoffer Kleine, Artemios G. Voyiatzis, Rick Kuhn, Raghu Kacker
2016 J jnl
Softw. Test. Verification Reliab.
Wenhua Wang, Sreedevi Sampath, Yu Lei, Raghu Kacker, D. Richard Kuhn, James Lawrence
2015 J jnl
Inf. Sci.
Jose Torres-Jimenez, Idelfonso Izquierdo-Marquez, Alberto Garcia-Robledo, Aldo Gonzalez-Gomez, Javier Bernal, Raghu Kacker
2015 conf
ICST Workshops
Laleh Shikh Gholamhossein Ghandehari, Jaganmohan Chandrasekaran, Yu Lei, Raghu Kacker, D. Richard Kuhn
2015 J jnl
Computer
Jon D. Hagar, Thomas L. Wissink, D. Richard Kuhn, Raghu Kacker
2014 conf
ICST Workshops
Laleh S. Ghandehari, Jacek Czerwonka, Yu Lei, Soheil Shafiee, Raghu Kacker, D. Richard Kuhn
2014 J jnl
Commun. Stat. Simul. Comput.
Jin Chu Wu, Alvin F. Martin, Raghu Kacker
2014 conf
HASE
Linbin Yu, Feng Duan, Yu Lei, Raghu Kacker, D. Richard Kuhn
2014 conf
ICST Workshops
Rick Kuhn, Raghu Kacker, Yu Lei
2014 conf
ICST Workshops
Jon D. Hagar, Rick Kuhn, Raghu Kacker, Tom Wissink
2013 conf
PETRA
Linbin Yu, Yu Lei, Raghu Kacker, D. Richard Kuhn, Ram D. Sriram, Kevin Brady
2013 A conf
ICST
Linbin Yu, Yu Lei, Raghu Kacker, D. Richard Kuhn
2013 A conf
ICST
Linbin Yu, Yu Lei, Mehra Nouroz Borazjany, Raghu Kacker, D. Richard Kuhn
2013 conf
ICST Workshops
Mehra N. Borazjany, Laleh Shikh Gholamhossein Ghandehari, Yu Lei, Raghu Kacker, Rick Kuhn
2013 conf
ICST Workshops
Laleh Shikh Gholamhossein Ghandehari, Mehra N. Borazjany, Yu Lei, Raghu Kacker, D. Richard Kuhn
2013 A conf
ESEM
Itzel Dominguez Mendoza, D. Richard Kuhn, Raghu Kacker, Yu Lei
2013 conf
ICST Workshops
D. Richard Kuhn, Itzel Dominguez Mendoza, Raghu Kacker, Yu Lei
2013 A conf
ISSRE
Laleh Shikh Gholamhossein Ghandehari, Yu Lei, David Chenho Kung, Raghu Kacker, D. Richard Kuhn
2013 Misc conf
INDOCRYPT
Subhadeep Banik, Santanu Sarkar, Raghu Kacker
2012 A conf
ICST
D. Richard Kuhn, James M. Higdon, James Lawrence, Raghu Kacker, Yu Lei
2012 A conf
ICST
Mehra N. Borazjany, Linbin Yu, Yu Lei, Raghu Kacker, Rick Kuhn
2012 B conf
ICECCS
Linbin Yu, Yu Lei, Raghu Kacker, D. Richard Kuhn, James Lawrence
2012 A conf
ICST
Laleh Shikh Gholamhossein Ghandehari, Yu Lei, Tao Xie, D. Richard Kuhn, Raghu Kacker
2012 A conf
ICST
Kiran Shakya, Tao Xie, Nuo Li, Yu Lei, Raghu Kacker, D. Richard Kuhn
2011 J jnl
Electron. J. Comb.
Jim Lawrence, Raghu Kacker, Yu Lei, D. Richard Kuhn, Michael A. Forbes
2011 A conf
DSN
Wenhua Wang, Yu Lei, Donggang Liu, David Chenho Kung, Christoph Csallner, Dazhi Zhang, Raghu Kacker, Rick Kuhn
2011 conf
ICSM
Rick Kuhn, Raghu Kacker
2009 conf
ICSM
Wenhua Wang, Yu Lei, Sreedevi Sampath, Raghu Kacker, Rick Kuhn, James Lawrence
2009 J jnl
Computer
Rick Kuhn, Raghu Kacker, Yu Lei, Justin Hunter
2008 conf
HASE
Wenhua Wang, Sreedevi Sampath, Yu Lei, Raghu Kacker
2008 J jnl
Softw. Test. Verification Reliab.
Yu Lei, Raghu Kacker, D. Richard Kuhn, Vadim Okun, James Lawrence
2008 J jnl
IT Prof.
Rick Kuhn, Yu Lei, Raghu Kacker
2007 J jnl
Softw. Test. Verification Reliab.
Yu Lei, Richard H. Carver, Raghu Kacker, David Chenho Kung
2007 conf
ECBS
Yu Lei, Raghu Kacker, D. Richard Kuhn, Vadim Okun, James Lawrence
1998 B conf
COMPSAC
Charles Hagwood, Raghu Kacker, James Yen, David Banks, Lynne Rosenthal, Leonard Gallagher, Paul E. Black
1995 J jnl
Softw. Pract. Exp.
Gordon Lyon, Raghu Kacker, Arnaud Linz
1995 J jnl
Inf. Process. Lett.
Robert Snelick, Joseph F. JáJá, Raghu Kacker, Gordon Lyon
1994 conf
IEEE METRICS
Gordon Lyon, Raghu Kacker
1994 J jnl
Softw. Pract. Exp.
Robert Snelick, Joseph F. JáJá, Raghu Kacker, Gordon Lyon
1994 J jnl
J. Supercomput.
Gordon Lyon, Robert Snelick, Raghu Kacker
1993 conf
ICPP (2)
Robert Snelick, Joseph F. JáJá, Raghu Kacker, Gordon Lyon
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"