Ralf Behr

31 papers Journal 31
YearRankTypeTitle / Venue / Authors
2024 J jnl
IEEE Trans. Instrum. Meas.
Nikolai Beev, Miguel Cerqueira Bastos, Michele Martino, Daniel Valuch, Luis Palafox, Ralf Behr
2019 J jnl
IEEE Trans. Instrum. Meas.
Martin Sira, Oliver F. Kieler, Ralf Behr
2019 J jnl
IEEE Trans. Instrum. Meas.
Jane Ireland, Jonathan M. Williams, Oliver F. Kieler, Ralf Behr, Ernest Houtzager, Ralph Hornecker, Helko E. van den Brom
2019 J jnl
IEEE Trans. Instrum. Meas.
Isaac Fan, Ralf Behr, Dietmar Drung, Christian Krause, Martin Götz, Eckart Pesel, Hansjörg Scherer
2017 J jnl
IEEE Trans. Instrum. Meas.
Thomas Hagen, Luis Palafox, Ralf Behr
2017 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Oliver F. Kieler, Bernd Schumacher
2015 J jnl
IEEE Trans. Instrum. Meas.
Marco Schubert, Michael Starkloff, Jinnie Lee, Ralf Behr, Luis Palafox, Alexander Wintermeier, Andreas C. Boeck, Philip M. Fleischmann, Torsten May
2013 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Oliver F. Kieler, Detlef Schleubner, Luis Palafox, Franz-Josef Ahlers
2012 J jnl
IEEE Trans. Instrum. Meas.
Olivier Seron, Sophie Djordjevic, Ilya F. Budovsky, Thomas Hagen, Ralf Behr, Luis Palafox
2011 J jnl
IEEE Trans. Instrum. Meas.
Jinnie Lee, Jürgen Schurr, Jaani Nissilä, Luis Palafox, Ralf Behr, Bryan P. Kibble
2009 J jnl
IEEE Trans. Instrum. Meas.
Johannes Kohlmann, Oliver F. Kieler, R. Iuzzolino, Jinnie Lee, Ralf Behr, B. Egeling, Franz Müller
2009 J jnl
IEEE Trans. Instrum. Meas.
Jinnie Lee, Ralf Behr, Alexander S. Katkov, Luis Palafox
2009 J jnl
IEEE Trans. Instrum. Meas.
Luis Palafox, Ralf Behr, Waldemar G. Kürten Ihlenfeld, Franz Müller, Enrico Mohns, Michael Seckelmann, Franz-Josef Ahlers
2007 J jnl
IEEE Trans. Instrum. Meas.
Jonathan M. Williams, Dale Henderson, Pravin Patel, Ralf Behr, Luis Palafox
2007 J jnl
IEEE Trans. Instrum. Meas.
Charles J. Burroughs Jr., Samuel P. Benz, Paul D. Dresselhaus, Bryan C. Waltrip, Thomas L. Nelson, Yonuk Chong, Jonathan M. Williams, Dale Henderson, Pravin Patel, Luis Palafox, Ralf Behr
2007 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Luis Palafox, Günther Ramm, Harald Moser, J. Melcher
2007 J jnl
IEEE Trans. Instrum. Meas.
Johannes Kohlmann, Franz Müller, Oliver F. Kieler, Ralf Behr, Luis Palafox, M. Kahmann, Jürgen Niemeyer
2007 J jnl
IEEE Trans. Instrum. Meas.
Luis Palafox, Günther Ramm, Ralf Behr, Waldemar G. Kürten Ihlenfeld, Harald Moser
2005 J jnl
IEEE Trans. Instrum. Meas.
Waldemar G. Kürten, Enrico Mohns, Ralf Behr, Jonathan M. Williams, Pravin Patel, Günther Ramm, Hans Bachmair
2005 J jnl
IEEE Trans. Instrum. Meas.
Oleg A. Chevtchenko, Helko E. van den Brom, Ernest Houtzager, Ralf Behr, Johannes Kohlmann, Jonathan M. Williams, Theodoor J. B. M. Janssen, Luis Palafox, David A. Humphreys, François P. M. Piquemal, Sophie Djordjevic, O. Monnoye, André Poletaeff, Rado Lapuh, Karl-Erik Rydler, Gunnar Eklund
2005 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Jonathan M. Williams, Pravin Patel, Theodoor J. B. M. Janssen, Torsten Funck, Manfred Klonz
2004 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Marco Schubert, Torsten May
2003 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Johannes Kohlmann, Theodoor J. B. M. Janssen, Peter Kleinschmidt, Jonathan M. Williams, Sophie Djordjevic, Jean-Pierre Lo-Hive, François P. M. Piquemal, Per-Otto Hetland, Dominique Reymann, Gunnar Eklund, Christian Hof, Blaise Jeanneret, Oleg A. Chevtchenko, Ernest Houtzager, Helko E. van den Brom, Andrea Sosso, Domenico Andreone, Jaani Nissilä, Panu Helistö
2003 J jnl
IEEE Trans. Instrum. Meas.
Jean-Pierre Lo-Hive, Sophie Djordjevic, Phillippe Cancela, François P. M. Piquemal, Ralf Behr, Charles J. Burroughs Jr., Heikki Seppä
2003 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Torsten Funck, Bernd Schumacher, Peter Warnecke
2001 J jnl
IEEE Trans. Instrum. Meas.
Johannes Kohlmann, Holger Schulze, Ralf Behr, Franz Müller, Jürgen Niemeyer
2001 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, L. Grimm, Torsten Funck, Johannes Kohlmann, Holger Schulze, Franz Müller, Bernd Schumacher, Peter Warnecke, Jürgen Niemeyer
2001 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Jürgen Niemeyer, Alexander S. Katkov
2001 J jnl
IEEE Trans. Instrum. Meas.
Torsten Funck, Ralf Behr, Manfred Klonz
1999 J jnl
IEEE Trans. Instrum. Meas.
Dominique Reymann, Thomas J. Witt, Gunnar Eklund, Hannu Pajander, Håkan Nilsson, Ralf Behr, Torsten Funck, Franz Müller
1999 J jnl
IEEE Trans. Instrum. Meas.
Ralf Behr, Holger Schulze, Franz Müller, Johannes Kohlmann, Jürgen Niemeyer
CLAUDE.md
← Index CLAUDE.md markdown
# CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

## Project Overview

REDB (RationalEdge Samples DB) is a malware analysis framework that extracts features from PE (Portable Executable) files and stores them in ClickHouse database for analysis. It provides a comprehensive set of extractors for analyzing binary samples including PE headers, imports, resources, signatures, and decompiled code.

## Common Commands

### Development Setup
```bash
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

# Run the main application
python start.py --path /path/to/samples --repo sample_repo --index_prefix redb
```

### Analysis Commands
```bash
# Process a single file
python start.py --path /path/to/binary --repo test --index_prefix redb

# Process from S3 storage
python start.py --s3 --repo malpedia --index_prefix redb

# Process from S3 storage but only a subset of a specific repository
python start.py --s3 --repo "vx-itw" --s3-notes "ITW.0138" --index_prefix redb

# Run only decompilation
python start.py --path /path/to/binary --repo test --index_prefix redb --decompile

# Run specific modules
python start.py --path /path/to/binary --repo test --index_prefix redb --modules "BasicPropertiesExtractor,PEFeaturesExtractor"

# Run as Nomad job (for containerized deployment)
python start.py --nomad-job
```

### Testing
There are no formal unit tests. Testing is done by running the extractors on sample files in the `test_files/` directory.

## Architecture Overview

### Core Components

1. **Ingestor (`redb/ingestor.py`)**: Main orchestrator that handles file processing, multiprocessing, and coordinates extractors
2. **Extractors (`redb/extractors/`)**: Modular analysis components that extract specific features
3. **Database Exporters (`redb/extractors/database_exporters.py`)**: Handle data export to ClickHouse
4. **Settings (`redb/settings/`)**: Configuration management for database connections

### Extractor Architecture

All extractors inherit from the base `Extractor` class and implement:
- `extract()`: Main analysis logic
- `prepare_export_data()`: Format data for database export
- `get_clickhouse_table()`: Return target table name

Available extractors:
- **General**: BasicPropertiesExtractor, HashExtractor, DIEExtractor, CAPAExtractor
- **PE-specific**: PEFeaturesExtractor, PEImportExtractor, PEResourceExtractor, PEOverlayExtractor, PESectionExtractor, PESignatureExtractor, PEDotNetExtractor, PEInconstistencyTestsExtractor, PEExtraFindings
- **ELF**: ELFFeaturesExtractor, ELFSegmentExtractor, ELFSectionExtractor, ELFDependencyExtractor, ELFSymbolExtractor, ELFImportExtractor, ELFExportExtractor, ELFRelocationExtractor, ELFNotesExtractor
- **Mach-O**: MachOFeaturesExtractor, MachOSegmentExtractor, MachOImportExtractor, MachOExportExtractor, MachODylibExtractor, MachOSignatureExtractor
- **APK**: APKFeaturesExtractor, APKManifestExtractor, APKPermissionsExtractor, APKSignatureExtractor, APKDexExtractor, APKResourceExtractor, APKNativeLibExtractor, APKInconsistencyTestsExtractor
- **Decompilation**: DecompileBinja, DecompileAPK

### Database Schema

The project uses a comprehensive ClickHouse schema defined in `redb/redb_schema.yml` with tables for:
- Basic properties (`redb_basic_properties`)
- PE features (`redb_pe_features`, `redb_pe_imports`, `redb_pe_sections`, etc.)
- Decompiled code (`code_binja_decompiled_functions_content`, `code_binja_decompiled_functions_references`)
- CAPA analysis (`redb_capa`, `redb_capa_capabilities`)

Full schema documentation is available in `docs/database_schema.md`.

### Processing Modes

1. **Analysis Mode**: Extracts features using selected modules
2. **Decompile Mode**: Uses Binary Ninja for code decompilation
3. **S3 Mode**: Fetches samples from S3 storage based on catalog queries
4. **Nomad Job Mode**: Processes single jobs using environment variables for containerized deployment

### Configuration

Environment variables are used for configuration:
- Database connection: `CLICKHOUSE_HOST`, `CLICKHOUSE_PORT`, `CLICKHOUSE_USER`, `CLICKHOUSE_PASSWORD`
- S3 storage: `S3_ENDPOINT`, `S3_ACCESS_KEY`, `S3_SECRET_KEY`
- Processing: `BATCH_SIZE`, `REDB_TIMEOUT`, `DECOMPILE_WORKER_TIMEOUT`
- Nomad jobs: `JOB_ID`, `S3_KEY`, `S3_BUCKET`, `WORKER_TYPE`, `CALLBACK_URL`, `ANALYSIS_MODULES`

## Important Implementation Details

### Multiprocessing
- Uses `spawn` method for multiprocessing to avoid memory issues
- Worker processes have timeout handlers to prevent hanging
- Supports both batch processing and streaming processing modes

### Memory Management
- Implements aggressive garbage collection between batches
- Monitors swap usage and restarts worker pools when needed
- Kills stuck processes automatically

### Error Handling
- Comprehensive logging with per-file context
- Graceful handling of corrupted or unsupported files
- Automatic retry logic for database operations

### Security Context
This is a defensive security tool for malware analysis. It processes potentially malicious files in a controlled environment to extract features for detection and analysis purposes.

## Development Notes

- The codebase is optimized for processing large batches of malware samples
- Extractors are designed to be modular and can be run individually or in combination
- Database schema supports both normalized and denormalized views for different query patterns
- S3 integration allows for scalable processing of large malware repositories