Rajiv Singh

48 papers C 2Journal 27Unranked 17
YearRankTypeTitle / Venue / Authors
2026 J jnl
Neural Comput. Appl.
Gunjan Pareek, Rajiv Singh, Swati Nigam
2026 J jnl
Signal Image Video Process.
Aishvarya Garg, Swati Nigam, Rajiv Singh
2025 J jnl
IEEE Trans. Circuits Syst. II Express Briefs
Faraz Adin, Hanyu Wang, Lukang Shi, Rajiv Singh, Erhan Hancioglu, Gabor C. Temes
2025 J jnl
SN Comput. Sci.
Nidhi Srivastav, Rajiv Singh
2025 conf
CDC
E. Javier Olucha, Rajiv Singh, Amritam Das, Roland Tóth
2025 J jnl
CoRR
E. Javier Olucha, Rajiv Singh, Amritam Das, Roland Tóth
2025 conf
CDC
Rajiv Singh, Mario Sznaier, Lennart Ljung
2024 J jnl
Vis. Comput.
Sakshi Indolia, Swati Nigam, Rajiv Singh
2024 conf
IHCI (1)
Sanjeev Kumar, Saurabh Bharti, Rajiv Singh, Kapil Kumar, Manju Khari
2024 J jnl
SN Comput. Sci.
Aishvarya Garg, Swati Nigam, Rajiv Singh
2024 J jnl
Computación y Sistemas (CyS)
Pooja Gupta, Swati Nigam, Rajiv Singh
2024 J jnl
Multim. Tools Appl.
Shimpy Goyal, Rajiv Singh
2024 J jnl
CoRR
Tianyu Dai, Khaled Aljanaideh, Rong Chen, Rajiv Singh, Alec Stothert, Lennart Ljung
2024 J jnl
Neural Comput. Appl.
Gunjan Pareek, Swati Nigam, Rajiv Singh
2024 conf
MWSCAS
Faraz Adin, Hanyu Wang, Lukang Shi, Rajiv Singh, Erhan Hancioglu, Gabor C. Temes
2024 J jnl
Neural Comput. Appl.
Bhawana Tyagi, Swati Nigam, Rajiv Singh
2023 J jnl
SN Comput. Sci.
Pooja Gupta, Swati Nigam, Rajiv Singh
2023 J jnl
J. Ambient Intell. Humaniz. Comput.
Sakshi Indolia, Swati Nigam, Rajiv Singh
2023 J jnl
IEEE Control. Syst. Lett.
Rajiv Singh, Mario Sznaier
2023 conf
IHCI (1)
Abha Jain, Swati Nigam, Rajiv Singh
2023 conf
IHCI (2)
Surbhi Jain, Aishvarya Garg, Swati Nigam, Rajiv Singh, Anshuman Shastri, Irish Singh
2023 J jnl
SN Comput. Sci.
Pooja Gupta, Swati Nigam, Rajiv Singh
2023 J jnl
J. Ambient Intell. Humaniz. Comput.
Shimpy Goyal, Rajiv Singh
2023 conf
IHCI (2)
Gunjan Pareek, Swati Nigam, Anshuman Shastri, Rajiv Singh
2023 J jnl
IEEE Access
Sakshi Indolia, Swati Nigam, Rajiv Singh, Vivek Kumar Singh, Manoj Kumar Singh
2023 J jnl
J. Ambient Intell. Humaniz. Comput.
Swati Nigam, Rajiv Singh, Manoj Kumar Singh, Vivek Kumar Singh
2023 conf
IHCI (2)
Aishvarya Garg, Swati Nigam, Rajiv Singh, Anshuman Shastri, Madhusudan Singh
2022 conf
ICACDS (1)
Bhawana Tyagi, Swati Nigam, Rajiv Singh
2022 conf
CDC
Rajiv Singh, Mario Sznaier
2022 J jnl
Wirel. Pers. Commun.
Ankit Agarwal, Manju Khari, Rajiv Singh
2021 conf
NEWCAS
Alexander Pierce, Eashwar Thaigarajan, Rajiv Singh, Erhan Hancioglu, Un-Ku Moon, Gabor C. Temes
2021 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Lukang Shi, Eashwar Thiagarajan, Rajiv Singh, Erhan Hancioglu, Un-Ku Moon, Gabor C. Temes
2020 C conf
ACC
Rajiv Singh, Mario Sznaier
2020 J jnl
CoRR
Suat Gumussoy, Ahmet Arda Ozdemir, Tomas McKelvey, Lennart Ljung, Mladen Gibanica, Rajiv Singh
2020 book
Rajiv Singh, Swati Nigam, Amit Kumar Singh, Mohamed Elhoseny
2020 conf
CDC
Jared Miller, Rajiv Singh, Mario Sznaier
2020 conf
MWSCAS
Lukang Shi, Eashwar Thaigarajan, Rajiv Singh, Erhan Hancioglu, Un-Ku Moon, Gabor C. Temes
2020 J jnl
Concurr. Comput. Pract. Exp.
Chandan Kumar, Amit Kumar Singh, Pardeep Kumar, Rajiv Singh, Siddharth Singh
2019 ch.
Handbook of Multimedia Information Security
Rajiv Singh, Swati Nigam
2018 J jnl
Multim. Tools Appl.
Swati Nigam, Rajiv Singh, A. K. Misra
2017 J jnl
Multim. Tools Appl.
Siddharth Singh, Vivek Singh Rathore, Rajiv Singh
2017 J jnl
Multim. Tools Appl.
Siddharth Singh, Vivek Singh Rathore, Rajiv Singh, Manoj Kumar Singh
2015 conf
SIRS
Siddharth Singh, Rajiv Singh, Tanveer J. Siddiqui
2014 J jnl
Inf. Fusion
Rajiv Singh, Ashish Khare
2014 conf
SIRS
Rajiv Singh, Ashish Khare
2013 conf
IC3
Richa Srivastava, Rajiv Singh, Ashish Khare
2012 C conf
ICISP
Ashish Khare, Richa Srivastava, Rajiv Singh
2012 conf
ICVGIP
Rajiv Singh, Ashish Khare
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"