Raj Bhatnagar

69 papers A* 5A 8B 3C 8Misc 2Journal 11Unranked 29
YearRankTypeTitle / Venue / Authors
2025 conf
ICDM (Workshops)
Allen Detmer, Raj Bhatnagar, Jillian Aurisano
2024 conf
ICDM (Workshops)
Aniket Bhanderi, Raj Bhatnagar
2024 J jnl
CoRR
Aniket Bhanderi, Raj Bhatnagar
2022 conf
BDA
Siqi Chen, Raj Bhatnagar
2021 conf
PAKDD (1)
Susheela Polepalli, Raj Bhatnagar
2021 ed.
BDA
Satish Narayana Srirama, Jerry Chun-Wei Lin, Raj Bhatnagar, Sonali Agarwal, P. Krishna Reddy
2018 B conf
COLING
Jagadeesh Patchala, Raj Bhatnagar
2018 Misc ed.
ICDCIT
Atul Negi, Raj Bhatnagar, Laxmi Parida
2016 B conf
WI
Divya Sardana, Raj Bhatnagar
2016 conf
HCI (4)
Priya Chawla, Raj Bhatnagar, Chia Han
2015 conf
IEEE BigData
Raj Bhatnagar, Lalit Kumar
2015 conf
MLDM
Jagadeesh Patchala, Raj Bhatnagar, Sridharan Gopalakrishnan
2015 conf
IEEE BigData
Divya Sardana, Raj Bhatnagar, Radu Pavel, Jonathan Iverson
2015 conf
BDA
Raj Bhatnagar
2015 conf
IEEE BigData
Jagadeesh Patchala, Raj Bhatnagar
2014 conf
WI-IAT (3)
Divya Paliwal, Raj Bhatnagar
2014 conf
MLDM
Vineet Joshi, Raj Bhatnagar
2014 conf
AMT
Divya Sardana, Raj Bhatnagar
2014 conf
AMT
Vineet Joshi, Raj Bhatnagar
2014 conf
AMT
Vineet Joshi, Raj Bhatnagar
2013 conf
ICDM Workshops
Chao Wu, Arjun Bakshi, Bruce J. Aronow, Anil G. Jegga, Raj Bhatnagar
2013 J jnl
CoRR
Raj Bhatnagar
2012 J jnl
Stat. Anal. Data Min.
Zhen Hu, Raj Bhatnagar
2012 conf
ICDM Workshops
Arjun Bakshi, Raj Bhatnagar
2012 J jnl
Sci. Program.
Zhen Hu, Raj Bhatnagar
2011 A* conf
KDD
Faris Alqadah, Raj Bhatnagar
2011 conf
BIOKDD
Zhen Hu, Raj Bhatnagar
2011 A* conf
ICDM
Zhen Hu, Raj Bhatnagar
2011 J jnl
Ann. Math. Artif. Intell.
Faris Alqadah, Raj Bhatnagar
2010 J jnl
Stat. Anal. Data Min.
Faris Alqadah, Raj Bhatnagar, Anil G. Jegga
2010 A* conf
ICDM
Zhen Hu, Raj Bhatnagar
2010 conf
ICDM Workshops
Minlu Zhang, Chunsheng Fang, Yan Xu, Raj Bhatnagar, Long J. Lu
2010 A conf
SDM
Faris Alqadah, Raj Bhatnagar, Anil G. Jegga
2010 Misc conf
ISAIM
Faris Alqadah, Raj Bhatnagar
2009 B conf
ICTAI
Aditya Sinha, Raj Bhatnagar
2009 A conf
SDM
Faris Alqadah, Raj Bhatnagar
2009 J jnl
Web Intell. Agent Syst.
Eric T. Matson, Scott A. DeLoach, Raj Bhatnagar
2009 ch.
Computer and Information Science
Haiyun Bian, Raj Bhatnagar
2008 conf
ICTAI (2)
Shriram Narayanaswamy, Raj Bhatnagar
2008 ch.
Data Mining: Foundations and Practice
Haiyun Bian, Raj Bhatnagar
2008 A conf
CIKM
Faris Alqadah, Raj Bhatnagar
2008 A conf
CIKM
Faris Alqadah, Raj Bhatnagar
2007 J jnl
Comput. Informatics
Ahmed Khedr, Raj Bhatnagar
2007 C conf
ICMLA
Haiyun Bian, Raj Bhatnagar, Barrington Young
2007 C conf
ICMLA
Barrington Young, Raj Bhatnagar, Giridhar Tatavarty, Haiyun Bian
2007 C conf
CIDM
Giridhar Tatavarty, Raj Bhatnagar, Barrington Young
2007 C conf
CIBCB
Amit U. Sinha, Raj Bhatnagar
2007 C conf
ICMLA
Amit U. Sinha, Mukta Phatak, Raj Bhatnagar, Anil G. Jegga
2007 conf
COIN
Eric T. Matson, Raj Bhatnagar
2007 C conf
ICMLA
Sasthakumar Ramamurthy, Raj Bhatnagar
2006 conf
ICDM Workshops
Haiyun Bian, Raj Bhatnagar
2006 conf
IAT
Eric T. Matson, Raj Bhatnagar
2006 C conf
PST
Barrington Young, Raj Bhatnagar
2005 A* conf
ICDM
Haiyun Bian, Raj Bhatnagar
2005 A conf
SDM
Haiyun Bian, Raj Bhatnagar
2005 conf
IICAI
Lynne Vettel, Raj Bhatnagar
2003 conf
IWDC
Ahmed Khedr, Raj Bhatnagar
2003 conf
MAICS
Ahmed Khedr, Raj Bhatnagar
2003 A conf
SDM
Wen Niu, Raj Bhatnagar
2003 A* conf
KDD
Raj Bhatnagar, Goutham Kurra, Wen Niu
2003 conf
MAICS
Richard Horvitz, Raj Bhatnagar
2002 C conf
ICMLA
Lynne Vettel, Raj Bhatnagar
2001 conf
BIOKDD
Goutham Kurra, Wen Niu, Raj Bhatnagar
1997 J jnl
Pattern Recognit. Lett.
Raj Bhatnagar, Richard Horvitz, Rob Williams
1997 conf
AAAI/IAAI
Raj Bhatnagar, Sriram Srinivasan
1995 J jnl
Fundam. Informaticae
Raj Bhatnagar
1994 A conf
UAI
Raj Bhatnagar
1993 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
Raj Bhatnagar, Laveen N. Kanal
1985 A conf
UAI
Raj Bhatnagar, Laveen N. Kanal
CLAUDE.md
← Index CLAUDE.md markdown
# CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

## Project Overview

REDB (RationalEdge Samples DB) is a malware analysis framework that extracts features from PE (Portable Executable) files and stores them in ClickHouse database for analysis. It provides a comprehensive set of extractors for analyzing binary samples including PE headers, imports, resources, signatures, and decompiled code.

## Common Commands

### Development Setup
```bash
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

# Run the main application
python start.py --path /path/to/samples --repo sample_repo --index_prefix redb
```

### Analysis Commands
```bash
# Process a single file
python start.py --path /path/to/binary --repo test --index_prefix redb

# Process from S3 storage
python start.py --s3 --repo malpedia --index_prefix redb

# Process from S3 storage but only a subset of a specific repository
python start.py --s3 --repo "vx-itw" --s3-notes "ITW.0138" --index_prefix redb

# Run only decompilation
python start.py --path /path/to/binary --repo test --index_prefix redb --decompile

# Run specific modules
python start.py --path /path/to/binary --repo test --index_prefix redb --modules "BasicPropertiesExtractor,PEFeaturesExtractor"

# Run as Nomad job (for containerized deployment)
python start.py --nomad-job
```

### Testing
There are no formal unit tests. Testing is done by running the extractors on sample files in the `test_files/` directory.

## Architecture Overview

### Core Components

1. **Ingestor (`redb/ingestor.py`)**: Main orchestrator that handles file processing, multiprocessing, and coordinates extractors
2. **Extractors (`redb/extractors/`)**: Modular analysis components that extract specific features
3. **Database Exporters (`redb/extractors/database_exporters.py`)**: Handle data export to ClickHouse
4. **Settings (`redb/settings/`)**: Configuration management for database connections

### Extractor Architecture

All extractors inherit from the base `Extractor` class and implement:
- `extract()`: Main analysis logic
- `prepare_export_data()`: Format data for database export
- `get_clickhouse_table()`: Return target table name

Available extractors:
- **General**: BasicPropertiesExtractor, HashExtractor, DIEExtractor, CAPAExtractor
- **PE-specific**: PEFeaturesExtractor, PEImportExtractor, PEResourceExtractor, PEOverlayExtractor, PESectionExtractor, PESignatureExtractor, PEDotNetExtractor, PEInconstistencyTestsExtractor, PEExtraFindings
- **ELF**: ELFFeaturesExtractor, ELFSegmentExtractor, ELFSectionExtractor, ELFDependencyExtractor, ELFSymbolExtractor, ELFImportExtractor, ELFExportExtractor, ELFRelocationExtractor, ELFNotesExtractor
- **Mach-O**: MachOFeaturesExtractor, MachOSegmentExtractor, MachOImportExtractor, MachOExportExtractor, MachODylibExtractor, MachOSignatureExtractor
- **APK**: APKFeaturesExtractor, APKManifestExtractor, APKPermissionsExtractor, APKSignatureExtractor, APKDexExtractor, APKResourceExtractor, APKNativeLibExtractor, APKInconsistencyTestsExtractor
- **Decompilation**: DecompileBinja, DecompileAPK

### Database Schema

The project uses a comprehensive ClickHouse schema defined in `redb/redb_schema.yml` with tables for:
- Basic properties (`redb_basic_properties`)
- PE features (`redb_pe_features`, `redb_pe_imports`, `redb_pe_sections`, etc.)
- Decompiled code (`code_binja_decompiled_functions_content`, `code_binja_decompiled_functions_references`)
- CAPA analysis (`redb_capa`, `redb_capa_capabilities`)

Full schema documentation is available in `docs/database_schema.md`.

### Processing Modes

1. **Analysis Mode**: Extracts features using selected modules
2. **Decompile Mode**: Uses Binary Ninja for code decompilation
3. **S3 Mode**: Fetches samples from S3 storage based on catalog queries
4. **Nomad Job Mode**: Processes single jobs using environment variables for containerized deployment

### Configuration

Environment variables are used for configuration:
- Database connection: `CLICKHOUSE_HOST`, `CLICKHOUSE_PORT`, `CLICKHOUSE_USER`, `CLICKHOUSE_PASSWORD`
- S3 storage: `S3_ENDPOINT`, `S3_ACCESS_KEY`, `S3_SECRET_KEY`
- Processing: `BATCH_SIZE`, `REDB_TIMEOUT`, `DECOMPILE_WORKER_TIMEOUT`
- Nomad jobs: `JOB_ID`, `S3_KEY`, `S3_BUCKET`, `WORKER_TYPE`, `CALLBACK_URL`, `ANALYSIS_MODULES`

## Important Implementation Details

### Multiprocessing
- Uses `spawn` method for multiprocessing to avoid memory issues
- Worker processes have timeout handlers to prevent hanging
- Supports both batch processing and streaming processing modes

### Memory Management
- Implements aggressive garbage collection between batches
- Monitors swap usage and restarts worker pools when needed
- Kills stuck processes automatically

### Error Handling
- Comprehensive logging with per-file context
- Graceful handling of corrupted or unsupported files
- Automatic retry logic for database operations

### Security Context
This is a defensive security tool for malware analysis. It processes potentially malicious files in a controlled environment to extract features for detection and analysis purposes.

## Development Notes

- The codebase is optimized for processing large batches of malware samples
- Extractors are designed to be modular and can be run individually or in combination
- Database schema supports both normalized and denormalized views for different query patterns
- S3 integration allows for scalable processing of large malware repositories