Ralf Hartmann

16 papers Journal 15
YearRankTypeTitle / Venue / Authors
2016 J jnl
Comput. Hum. Behav.
Cade McCall, Lea K. Hildebrandt, Ralf Hartmann, Blazej M. Baczkowski, Tania Singer
2015 J jnl
J. Comput. Phys.
Ralf Hartmann, Tobias Leicht
2014 J jnl
J. Comput. Phys.
Stefan Schoenawa, Ralf Hartmann
2011 J jnl
J. Comput. Phys.
Ralf Hartmann, Joachim Held, Tobias Leicht
2010 J jnl
J. Comput. Phys.
Tobias Leicht, Ralf Hartmann
2009 J jnl
J. Comput. Phys.
Francesco Bassi, Carmine De Bartolo, Ralf Hartmann, Alessandra Nigro
2009 J jnl
SIAM J. Sci. Comput.
F. Prill, Mária Lukácová-Medvid'ová, Ralf Hartmann
2008 J jnl
J. Comput. Phys.
Ralf Hartmann, Paul Houston
2008 J jnl
SIAM J. Sci. Comput.
Ralf Hartmann
2007 J jnl
SIAM J. Numer. Anal.
Ralf Hartmann
2007 J jnl
Int. J. Comput. Sci. Math.
Ralf Hartmann
2007 J jnl
ACM Trans. Math. Softw.
Wolfgang Bangerth, Ralf Hartmann, Guido Kanschat
2003 J jnl
SIAM J. Sci. Comput.
Ralf Hartmann, Paul Houston
1993
Ralf Hartmann
1990 J jnl
Eur. Trans. Telecommun.
Wolfgang Böhm, Ralf Hartmann, Günther Ruske
1974 J jnl
Z. Oper. Research
Ralf Hartmann, P. Reiser
redb/extractors/js_extractors/js_content.py
← Index redb/extractors/js_extractors/js_content.py python
"""Persists raw + normalised text into the generic `code_text_content` table.

Reads the raw source and the deobfuscation result directly from the shared
JSContext so no extra compute happens here — both values are computed once
per sample (the source at JSContext construction, the deobfuscation lazily
on first access) and reused by any extractor that needs them.

`text_normalized` is left NULL when the deobfuscation pass produced no
output, so analysts can distinguish "we tried and got nothing" from
"normalisation succeeded".
"""

import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor


class JSContentExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.content_row = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_CONTENT.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, normalizer_used = self._context.deobfuscated

        self.content_row = {
            "content_type": self._context.content_type,
            "text_raw": src,
            "text_normalized": deobfuscated,  # may be None
            "normalizer_used": normalizer_used,  # may be None
        }
        return self.content_row

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type != "ClickHouseExporter":
            return None
        if not self.content_row:
            return None

        r = self.content_row
        data = [[
            self.sha256,
            r["content_type"],
            r["text_raw"],
            r["text_normalized"],
            r["normalizer_used"],
            datetime.now(timezone.utc),
        ]]

        column_names = [
            "sha256",
            "content_type",
            "text_raw",
            "text_normalized",
            "normalizer_used",
            "analysis_date",
        ]

        column_type_names = [
            "FixedString(64)",
            "LowCardinality(String)",
            "String",
            "Nullable(String)",
            "Nullable(String)",
            "DateTime64(3, 'UTC')",
        ]

        return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "code_text_content"