Ralf Carbon

21 papers A 1B 6Misc 2Journal 4Unranked 7
YearRankTypeTitle / Venue / Authors
2016 J jnl
IEEE Softw.
Susanne Braun, Ralf Carbon, Matthias Naab
2015 conf
WICSA
Matthias Naab, Susanne Braun, Torsten Lenhart, Steffen Hess, Andreas Eitel, Dominik Magin, Ralf Carbon, Felix Kiefer
2012
Ralf Carbon
2012 Misc conf
QUATIC
Silvia Abrahão, Ralf Carbon
2012 Misc conf
QUATIC
Steffen Hess, Felix Kiefer, Ralf Carbon
2012 conf
MobiCASE
Steffen Hess, Felix Kiefer, Ralf Carbon, Andreas Maier
2010 B conf
SPLC
Ina Schaefer, Martin Becker, Ralf Carbon, Sven Apel
2010 J jnl
Softwaretechnik-Trends
Ralf Carbon, Matthias Naab
2010 conf
SPLC Workshops
Ina Schaefer, Ralf Carbon
2010 B conf
SPLC
Ralf Carbon, Dirk Muthig
2009 B conf
SPLC
Ralf Carbon, Sebastian Adam, Takayuki Uchida
2009 B conf
SPLC
Daniel Pech, Jens Knodel, Ralf Carbon, Clemens Schitter, Dirk Hein
2008 B conf
EDOC
Ralf Carbon, Gregor Johann, Dirk Muthig, Matthias Naab
2008 conf
SPLC (2)
Ralf Carbon
2008 conf
SAM@ICSE
Ralf Carbon, Gregor Johann, Thorsten Keuler, Dirk Muthig, Matthias Naab, Stefan Zilch
2008 B conf
SPLC
Ralf Carbon, Jens Knodel, Dirk Muthig, Gerald Meier
2007 A conf
ESEM
Christopher Ackermann, Forrest Shull, Ralf Carbon, Christian Denger, Mikael Lindvall
2007 J jnl
IEEE Trans. Educ.
Eric Ras, Ralf Carbon, Björn Decker, Jörg Rech
2004 conf
GI Jahrestagung (2)
Ralf Carbon, Jörg Dörr, Marcus Trapp
2003 conf
Wissensmanagement
Ralf Carbon, Raimund L. Feldmann
2003 J jnl
J. Univers. Comput. Sci.
Raimund L. Feldmann, Ralf Carbon
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"