Rahul Joshi

15 papers A 1Misc 1Journal 10Unranked 3
YearRankTypeTitle / Venue / Authors
2024 J jnl
Multim. Tools Appl.
Pramod Pandurang Jadhav, Sandeep Dwarkanath Pande, Rahul Joshi, Sudhanshu Suhas Gonge, Maya P. Shelke, Pravin R. Futane, Shaik Hasane Ahammad
2024 J jnl
Multim. Tools Appl.
Shaik Hasane Ahammad, Sandeep Dwarkanath Pande, Rahul Joshi, Boddapati Taraka Phani Madhav, P. Poorna Priya, Osama S. Faragallah, Mahmoud M. A. Eid, Ahmed Nabih Zaki Rashed
2023 conf
COMS2
Sudhanshu Suhas Gonge, Rahul Joshi, Ketan Kotecha, Milind Gayakwad, Rupali Gangarde, Gagandeep Kaur, Kalyani Kadam
2023 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Ajay Kumar Patel, Eun-Sung Park, Hongseok Lee, G. G. Lakshmi Priya, Hangi Kim, Rahul Joshi, Muhammad Akbar Andi Arief, Moon S. Kim, In-Suck Baek, Byoung-Kwan Cho
2023 J jnl
Sensors
Rahul Joshi, Lakshmi Priya GG, Mohammad Akbar Faqeerzada, Tanima Bhattacharya, Moon Sung Kim, In-Suck Baek, Byoung-Kwan Cho
2023 conf
CCWC
Karan Salunkhe, Sudhanshu Suhas Gonge, Rahul Joshi, Ketan Kotecha, Vinod Basalalli, Pankaj Shah
2022 J jnl
CoRR
Ishaan Kale, Rahul Joshi, Kalyani Kadam
2022 J jnl
Comput. Electron. Agric.
Perez Mukasa, Collins Wakholi, Mohammad Akbar Faqeerzada, Hanim Z. Amanah, Hangi Kim, Rahul Joshi, Hyun-Kwon Suh, Geonwoo Kim, Hoonsoo Lee, Moon S. Kim, In-Suck Baek, Byoung-Kwan Cho
2021 J jnl
Sensors
Sharnil Pandya, Aanchal Thakur, Santosh Saxena, Nandita Jassal, Chirag I. Patel, Kirit Modi, Pooja Shah, Rahul Joshi, Sudhanshu Suhas Gonge, Kalyani Kadam, Prachi Kadam
2021 J jnl
CoRR
Yuanzhong Xu, HyoukJoong Lee, Dehao Chen, Blake A. Hechtman, Yanping Huang, Rahul Joshi, Maxim Krikun, Dmitry Lepikhin, Andy Ly, Marcello Maggioni, Ruoming Pang, Noam Shazeer, Shibo Wang, Tao Wang, Yonghui Wu, Zhifeng Chen
2020 J jnl
Sensors
Mohammad Akbar Faqeerzada, Santosh Lohumi, Geonwoo Kim, Rahul Joshi, Hoonsoo Lee, Moon Sung Kim, Byoung-Kwan Cho
2011 conf
PReMI
Maunendra Sankar Desarkar, Rahul Joshi, Sudeshna Sarkar
2008 J jnl
Microelectron. Reliab.
S. B. Park, Rahul Joshi
2006 Misc conf
IRI
Rahul Joshi, Y. Alp Aslandogan
2004 A conf
CGO
Rahul Joshi, Michael D. Bond, Craig B. Zilles
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));