Ramin V. Parsey

22 papers B 1Journal 17Unranked 4
YearRankTypeTitle / Venue / Authors
2023 J jnl
npj Digit. Medicine
Farzana Z. Ali, Ramin V. Parsey, Shan Lin, Joseph Schwartz, Christine DeLorenzo
2020 J jnl
NeuroImage
Rajapillai L. I. Pillai, Elizabeth A. Bartlett, Mala R. Ananth, Chencan Zhu, Jie Yang, Greg Hajcak, Ramin V. Parsey, Christine DeLorenzo
2015 J jnl
NeuroImage
R. Todd Ogden, Francesca Zanderigo, Ramin V. Parsey
2015 J jnl
IEEE J. Biomed. Health Informatics
Arthur Mikhno, Francesca Zanderigo, R. Todd Ogden, J. John Mann, Elsa D. Angelini, Andrew F. Laine, Ramin V. Parsey
2014 conf
BHI
Arthur Mikhno, Francesca Zanderigo, R. Todd Ogden, Michelle Mikhno, Harry Nagendra, J. John Mann, Andrew F. Laine, Ramin V. Parsey
2014 J jnl
NeuroImage
Martin J. Lan, R. Todd Ogden, Yung-yu Huang, Maria A. Oquendo, Gregory M. Sullivan, Jeffrey Miller, Matthew Milak, J. John Mann, Ramin V. Parsey
2012 conf
EMBC
Arthur Mikhno, Francesca Zanderigo, Mika Naganawa, Andrew F. Laine, Ramin V. Parsey
2012 J jnl
Int. J. Biomed. Imaging
Alayar Kangarlu, Ramin V. Parsey, Eric C. Bourekas
2012 conf
ISBI
Arthur Mikhno, Pablo Martínez-Nuevo, Davangere P. Devanand, Ramin V. Parsey, Andrew F. Laine
2010 J jnl
NeuroImage
Francesca Zanderigo, R. Todd Ogden, Chung Chang, Stephen Choy, Andrew Wong, Ramin V. Parsey
2010 J jnl
NeuroImage
Francesca Zanderigo, R. Todd Ogden, J. John Mann, Ramin V. Parsey
2010 J jnl
NeuroImage
Mikael Palner, Mark D. Underwood, Dileep J. S. Kumar, Victoria Arango, Gitte Moos Knudsen, J. John Mann, Ramin V. Parsey
2010 J jnl
NeuroImage
R. Todd Ogden, Thaddeus Tarpey, J. John Mann, Ramin V. Parsey
2010 J jnl
NeuroImage
Christine DeLorenzo, Sarah Lichenstein, Karen E. Schaefer, Judith Dunn, Randall Marshall, Brigitte Robertson, J. John Mann, Ramin V. Parsey
2010 J jnl
NeuroImage
Arno Klein, Satrajit S. Ghosh, Brian B. Avants, B. T. Thomas Yeo, Bruce Fischl, Babak A. Ardekani, James C. Gee, J. John Mann, Ramin V. Parsey
2010 J jnl
NeuroImage
Christine DeLorenzo, Dileep J. S. Kumar, Johannes T. Tauscher, J. John Mann, Ramin V. Parsey
2010 J jnl
NeuroImage
Jeffrey Miller, Matthew Milak, R. Todd Ogden, Dileep J. S. Kumar, Ramin V. Parsey, J. John Mann
2010 J jnl
NeuroImage
Jeih-San Liow, Shuiyu Lu, Sami S. Zoghbi, Robert L. Gladding, Cheryl L. Morse, Jussi Hirvonen, Ramin V. Parsey, Robert B. Innis, Victor W. Pike
2009 B conf
Image Processing
Christine DeLorenzo, Arno Klein, Arthur Mikhno, Neil Gray, Francesca Zanderigo, J. John Mann, Ramin V. Parsey
2009 J jnl
NeuroImage
Arno Klein, Jesper L. R. Andersson, Babak A. Ardekani, John Ashburner, Brian B. Avants, Ming-Chang Chiang, Gary E. Christensen, D. Louis Collins, James C. Gee, Pierre Hellier, Joo Hyun Song, Mark Jenkinson, Claude Lepage, Daniel Rueckert, Paul M. Thompson, Tom Vercauteren, Roger P. Woods, J. John Mann, Ramin V. Parsey
2006 conf
EMBC
Kjell Erlandsson, Yinpeng Jin, Andrew T. Wong, Peter D. Esser, Andrew F. Laine, R. Todd Ogden, Maria A. Oquendo, Ronald L. Van Heertum, J. John Mann, Ramin V. Parsey
2004 J jnl
NeuroImage
Marie-José Bélanger, J. John Mann, Ramin V. Parsey
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));