Rahul Telang

91 papers A 2C 14Journal 53Unranked 22
YearRankTypeTitle / Venue / Authors
2025 J jnl
Commun. ACM
Rahul Telang, Muhammad Zia Hydari
2025 J jnl
Commun. ACM
Brett Danaher, Jonathan Hersh, Michael D. Smith, Rahul Telang
2025 J jnl
Manuf. Serv. Oper. Manag.
Siddhartha Sharma, Rahul Telang, Alejandro Zentner
2024 J jnl
CoRR
Esther Gal-Or, Muhammad Zia Hydari, Rahul Telang
2024 J jnl
CoRR
Muhammad Zia Hydari, Yangfan Liang, Rahul Telang
2023 J jnl
Manag. Sci.
Thomas W. Frick, Rodrigo Belo, Rahul Telang
2023 J jnl
Inf. Syst. Res.
Arslan Aziz, Hui Li, Rahul Telang
2023 J jnl
Manuf. Serv. Oper. Manag.
Saharsh Agarwal, Deepa Mani, Rahul Telang
2022 J jnl
Mark. Sci.
Jaeung Sim, Daegon Cho, Youngdeok Hwang, Rahul Telang
2020 J jnl
MIS Q.
Brett Danaher, Jonathan Hersh, Michael D. Smith, Rahul Telang
2019 J jnl
MIS Q.
Liron Sivan, Michael D. Smith, Rahul Telang
2019 J jnl
J. Manag. Inf. Syst.
Pedro Ferreira, Rahul Telang, Miguel Godinho de Matos
2019 J jnl
Electron. Commer. Res.
Haijing Hao, Rema Padman, Baohong Sun, Rahul Telang
2019 J jnl
Manag. Sci.
Muhammad Zia Hydari, Rahul Telang, William M. Marella
2018 J jnl
Inf. Econ. Policy
Rahul Telang, Joel Waldfogel
2018 J jnl
Inf. Syst. Res.
Haijing Hao, Rema Padman, Baohong Sun, Rahul Telang
2018 J jnl
Manag. Sci.
Rajiv Garg, Rahul Telang
2017 J jnl
Inf. Econ. Policy
Daegon Cho, Michael D. Smith, Rahul Telang
2017 conf
IEEE BigData
Abhinav Maurya, Rahul Telang
2017 J jnl
Commun. ACM
Brett Danaher, Michael D. Smith, Rahul Telang
2016 J jnl
Manag. Sci.
Miguel Godinho de Matos, Pedro A. Ferreira, Michael D. Smith, Rahul Telang
2016 A conf
SOUPS
Alain Forget, Sarah Pearman, Jeremy Thomas, Alessandro Acquisti, Nicolas Christin, Lorrie Faith Cranor, Serge Egelman, Marian Harbach, Rahul Telang
2016 C conf
ICIS
Sriram Somanchi, Rahul Telang
2016 J jnl
Manag. Sci.
Rodrigo Belo, Pedro A. Ferreira, Rahul Telang
2016 J jnl
Manag. Sci.
Idris Adjerid, Alessandro Acquisti, Rahul Telang, Rema Padman, Julia Adler-Milstein
2016 C conf
ICIS
Uttara M. Ananthakrishnan, Michael D. Smith, Rahul Telang
2015 J jnl
Commun. ACM
Muhammad Zia Hydari, Rahul Telang, William M. Marella
2015 J jnl
IEEE Secur. Priv.
Rahul Telang
2015 conf
WEIS
Arslan Aziz, Rahul Telang
2014 J jnl
Manag. Sci.
Brett Danaher, Yan Huang, Michael D. Smith, Rahul Telang
2014 J jnl
Manag. Sci.
Rodrigo Belo, Pedro A. Ferreira, Rahul Telang
2014 conf
HotSoS
Alain Forget, Saranga Komanduri, Alessandro Acquisti, Nicolas Christin, Lorrie Faith Cranor, Rahul Telang
2014 conf
HICSS
Haijing Hao, Rema Padman, Baohong Sun, Rahul Telang
2014 J jnl
MIS Q.
Anuj Kumar, Michael D. Smith, Rahul Telang
2013 J jnl
MIS Q.
Rajiv Garg, Rahul Telang
2013 conf
UKAIS
Haijing Hao, Rema Padman, Rahul Telang
2012 J jnl
Inf. Syst. Res.
Anuj Kumar, Rahul Telang
2012 C conf
ICIS
Muhammad Zia Hydari, Martin S. Gaynor, Rahul Telang
2012 conf
WEIS
Martin S. Gaynor, Muhammad Zia Hydari, Rahul Telang
2012 conf
HICSS
Daegon Cho, Rahul Telang, Michael D. Smith
2012 C conf
ICIS
Rajiv Garg, Rahul Telang
2012 C conf
ICIS
Anuj Kumar, Rahul Telang, Michael D. Smith
2012 J jnl
Inf. Syst. Res.
Sunil Wattal, Rahul Telang, Tridas Mukhopadhyay, Peter Boatwright
2011 conf
HICSS
Rajiv Garg, Michael D. Smith, Rahul Telang
2011 conf
WEIS
Idris Adjerid, Alessandro Acquisti, Rema Padman, Rahul Telang, Julia Adler-Milstein
2011 J jnl
J. Manag. Inf. Syst.
Rajiv Garg, Michael D. Smith, Rahul Telang
2011 J jnl
Manuf. Serv. Oper. Manag.
Anuj Kumar, Rahul Telang
2010 J jnl
Manag. Sci.
Youngsoo Kim, Rahul Telang, William B. Vogt, Ramayya Krishnan
2010 J jnl
Inf. Syst. Res.
Ashish Arora, Ramayya Krishnan, Rahul Telang, Yubao Yang
2010 C conf
ICIS
Rodrigo Belo, Pedro A. Ferreira, Rahul Telang
2010 J jnl
Inf. Econ. Policy
Ashish Arora, Chris Forman, Anand Nandkumar, Rahul Telang
2010 J jnl
Mark. Sci.
Brett Danaher, Samita Dhanasobhon, Michael D. Smith, Rahul Telang
2010 J jnl
Inf. Econ. Policy
Michael D. Smith, Rahul Telang
2009 J jnl
MIS Q.
Michael D. Smith, Rahul Telang
2009 conf
HICSS
Sunil Wattal, Rahul Telang, Tridas Mukhopadhyay
2009 J jnl
J. Manag. Inf. Syst.
Sunil Wattal, Rahul Telang, Tridas Mukhopadhyay
2009 J jnl
Decis. Support Syst.
Sudip Bhattacharjee, Ram D. Gopal, James R. Marsden, Ramesh Sankaranarayanan, Rahul Telang
2008 conf
WEIS
Sasha Romanosky, Rahul Telang, Alessandro Acquisti
2008 J jnl
Manag. Sci.
Ashish Arora, Rahul Telang, Hao Xu
2007 J jnl
IEEE Trans. Software Eng.
Rahul Telang, Sunil Wattal
2007 C conf
ICIS
Michael D. Smith, Rahul Telang
2007 C conf
ICIS
Youngsoo Kim, William B. Vogt, Ramayya Krishnan, Rahul Telang
2007 conf
WEIS
Vineet Kumar, Rahul Telang, Tridas Mukhopadhyay
2007 J jnl
Manag. Sci.
Sudip Bhattacharjee, Ram D. Gopal, Kaveepan Lertwachara, James R. Marsden, Rahul Telang
2006 C conf
ICIS
Ashish Arora, Ramayya Krishnan, Rahul Telang, Yubao Yang
2006 conf
WEIS
Ashish Arora, Chris Forman, Anand Nandkumar, Rahul Telang
2006 J jnl
Inf. Syst. Frontiers
Ashish Arora, Anand Nandkumar, Rahul Telang
2006 conf
WEIS
Vineet Kumar, Rahul Telang, Tridas Mukhopadhyay
2006 J jnl
Inf. Syst. Res.
Anindya Ghose, Michael D. Smith, Rahul Telang
2006 C conf
ICIS
Alessandro Acquisti, Allan Friedman, Rahul Telang
2006 conf
WEIS
Alessandro Acquisti, Allan Friedman, Rahul Telang
2006 J jnl
Manag. Sci.
Ashish Arora, Jonathan P. Caulkins, Rahul Telang
2005 conf
WEIS
Ashish Arora, Ramayya Krishnan, Rahul Telang, Yubao Yang
2005 conf
AMCIS
Rahul Telang, Sunil Wattal
2005 J jnl
Electron. Commer. Res. Appl.
Rahul Telang, Tridas Mukhopadhyay
2005 J jnl
IEEE Secur. Priv.
Ashish Arora, Rahul Telang
2005 J jnl
J. Manag. Inf. Syst.
Anindya Ghose, Rahul Telang, Ramayya Krishnan
2005 conf
WEIS
Rahul Telang, Sunil Wattal
2005 J jnl
Manag. Sci.
Karthik N. Kannan, Rahul Telang
2005 J jnl
Hum. Comput. Interact.
Robert E. Kraut, Shyam Sunder, Rahul Telang, James Morris
2005 conf
HICSS
Anindya Ghose, Rahul Telang, Ramayya Krishnan
2004 conf
HICSS
Tridas Mukhopadhyay, Uday Rajan, Rahul Telang
2004 conf
HICSS
Karthik N. Kannan, Rahul Telang, Hao Xu
2004 J jnl
IT Prof.
Ashish Arora, Dennis Hall, C. Ariel Pinto, Dwayne Ramsey, Rahul Telang
2004 C conf
ICIS
Anindya Ghose, Michael D. Smith, Rahul Telang
2004 conf
HICSS
Ramayya Krishnan, Michael D. Smith, Zhulei Tang, Rahul Telang
2004 J jnl
J. Manag. Inf. Syst.
Rahul Telang, Uday Rajan, Tridas Mukhopadhyay
2003 C conf
ICIS
Anindya Ghose, Rahul Telang, Ramayya Krishnan
2003 C ed.
ICEC
Norman M. Sadeh, Mary Jo Dively, Robert J. Kauffman, Yannis Labrou, Onn Shehory, Rahul Telang, Lorrie Faith Cranor
2002 A conf
CSCW
Robert E. Kraut, James Morris, Rahul Telang, Darrin Filer, Matt Cronin, Shyam Sunder
2002 C conf
ICIS
Ramayya Krishnan, Michael D. Smith, Zhulei Tang, Rahul Telang
yara/README.md
← Index yara/README.md markdown
# YARA Rules Directory

This folder contains YARA rules for scanning binary samples.

## Setting Up YARA-Forge Rules

To use the YARA-Forge rules from [https://github.com/YARAHQ/yara-forge](https://github.com/YARAHQ/yara-forge):

```bash
# Download the latest release
cd /path/to/redb/yara
# wget https://github.com/YARAHQ/yara-forge/releases/latest/download/yara-forge-rules-core.zip
wget https://github.com/YARAHQ/yara-forge/releases/latest/download/yara-forge-rules-extended.zip

# Extract rules
# unzip yara-forge-rules-core.zip
unzip yara-forge-rules-extended.zip
```

Available packages:
- `yara-forge-rules-core.zip` - Core rules (~5,000 rules)
- `yara-forge-rules-extended.zip` - Extended rules (~10,000 rules)
- `yara-forge-rules-full.zip` - Full rules (~11,000+ rules)

## Pre-compiling Rules (Recommended for Production)

For large rulesets like YARA-Forge, pre-compiling rules significantly improves startup time:

```bash
# Pre-compile all rules into a single .yarac file
python -m redb.extractors.yara --compile

# Or specify custom paths
python -m redb.extractors.yara --compile --rules-path /path/to/rules --output /path/to/output.yarac
```

This creates `yara/compiled_rules.yarac` which is loaded automatically on subsequent runs.

### Performance Comparison

| Method | First Scan Startup | Subsequent Scans |
|--------|-------------------|------------------|
| Source files (.yar) | ~10-30 seconds (11k rules) | Instant (cached) |
| Pre-compiled (.yarac) | ~1-2 seconds | Instant (cached) |

## Directory Structure

```
yara/
├── README.md
├── .gitkeep
├── compiled_rules.yarac    # (optional) Pre-compiled rules
├── packages/               # YARA-Forge packages
│   └── core/
│       └── *.yar
└── custom/                 # Your custom rules
    └── my_rules.yar
```

Rules are loaded in this priority:
1. `compiled_rules.yarac` (if exists) - fastest
2. All `.yar` and `.yara` files recursively - compiles on first run

## Usage

### Scan with YARA only

```bash
# Scan local files
python start.py --path /path/to/samples -y --repo my_repo --index_prefix redb

# Scan S3 samples
python start.py --s3 --repo bazaar -y --index_prefix redb

# Dry-run (print results instead of storing in ClickHouse)
python start.py --path /path/to/samples -y --dry-run --repo test --index_prefix redb
```

### Scan already-analyzed samples

Run YARA on samples that were previously analyzed (already in `basic_properties`).
Deduplication is handled by the `yara_matches` table — samples already scanned are
automatically excluded before processing begins:

```bash
# Scan all analyzed macho samples with YARA
python start.py --analyzed --magika macho -y --index_prefix redb

# Scan all analyzed PE samples with YARA
python start.py --analyzed --magika pe -y --index_prefix redb

# Scan all analyzed samples (no filetype filter)
python start.py --analyzed -y --index_prefix redb
```

### Partition large YARA runs by date

Combine `--analyzed` with `--range` to partition millions of samples into
manageable batches. Only samples in `basic_properties` AND within the date
range (by `first_seen` in `catalog_samples`) are processed:

```bash
# Scan analyzed PE samples from Feb 2025
python start.py --range 2025-02-01 2025-02-28 --analyzed --magika pebin -y --index_prefix redb

# Scan analyzed PE samples from first week of March 2025
python start.py --range 2025-03-01 2025-03-08 --analyzed --magika pebin -y --index_prefix redb
```

YARA dedup still applies — re-running a range safely skips already-scanned samples.

### Combined Features + YARA

Run feature extraction and YARA scanning together on the same samples:

```bash
# Local files with features + YARA
python start.py --path /path/to/samples --with-yara --repo my_repo --index_prefix redb

# S3 samples with features + YARA
python start.py --s3 --repo bazaar --with-yara --index_prefix redb
```

### Pre-compile Rules

```bash
# Compile and save to default location (yara/compiled_rules.yarac)
python -m redb.extractors.yara --compile

# Compile with custom paths
python -m redb.extractors.yara --compile --rules-path ./my_rules --output ./compiled.yarac
```

### Sync Rules to Database

Before batch scanning, sync rules to ensure all rule metadata is stored:

```bash
# Sync rules to database
python -m redb.extractors.yara --sync-rules

# Sync with custom source collection name
python -m redb.extractors.yara --sync-rules --source-collection yara-forge-core

# Compile and sync in one command
python -m redb.extractors.yara --compile --sync-rules
```

## ClickHouse Table Schema

YARA data uses a **normalized schema** with two tables for efficient storage.

### Matches Table: `yara_matches`

Stores one row per sample-rule match (optimized with binary sha256 and rule_id):

| Column | Type | Description |
|--------|------|-------------|
| sha256 | FixedString(32) | Binary SHA256 (32 bytes, use `hex(sha256)` to display) |
| rule_id | UInt64 | Unique rule identifier (xxHash64 of canonical rule content) |
| rule_name | LowCardinality(String) | YARA rule name (denormalized for convenience) |
| scan_date | DateTime64(3, 'UTC') | Scan timestamp |
| match_strings | Array(String) | Matched string identifiers |

### Rules Table: `yara_rules`

Stores rule metadata once per unique rule (deduplicated by rule_id):

| Column | Type | Description |
|--------|------|-------------|
| rule_id | UInt64 | Unique rule identifier (xxHash64 of canonical rule content) |
| rule_name | String | YARA rule name |
| source_collection | LowCardinality(String) | Source collection (e.g., 'yara-forge-core', 'malpedia') |
| ingested_at | DateTime64(3, 'UTC') | When this rule was ingested |
| rule_text | String | Full rule source code |
| rule_meta | JSON | Rule metadata (author, description, reference, etc.) |
| rule_tags | Array(LowCardinality(String)) | Rule tags |

### Schema Benefits

- **Binary SHA256**: 32 bytes vs 64 bytes (50% storage savings on hash columns)
- **UInt64 rule_id**: Fast joins and lookups via integer key
- **Content-based rule_id**: xxHash64 of canonical rule content (excluding metadata) for deduplication
- **Denormalized rule_name**: Allows queries without joins for common use cases

### Example Queries

```sql
-- Get matches with hex sha256
SELECT
    hex(m.sha256) as sha256,
    m.rule_name,
    m.match_strings
FROM yara_matches m
WHERE m.sha256 = unhex('abc123...')

-- Join with rules for full metadata
SELECT
    hex(m.sha256) as sha256,
    m.rule_name,
    m.match_strings,
    r.rule_meta,
    r.source_collection
FROM yara_matches m
JOIN yara_rules r ON m.rule_id = r.rule_id
WHERE m.sha256 = unhex('abc123...')

-- Find all samples matching a specific rule
SELECT hex(sha256), scan_date
FROM yara_matches
WHERE rule_name = 'APT_Lazarus_Loader'
ORDER BY scan_date DESC
```

## Environment Variables

| Variable | Description | Default |
|----------|-------------|---------|
| `YARA_RULES_PATH` | Override the YARA rules directory | `yara/` |
| `YARA_COMPILED_RULES` | Compiled rules filename | `compiled_rules.yarac` |
| `YARA_SOURCE_COLLECTION` | Default source collection name | `default` |