Ran Zhang

41 papers B 9C 2Journal 27Unranked 3
YearRankTypeTitle / Venue / Authors
2026 J jnl
IEEE Trans. Wirel. Commun.
Yuchen Yang, Ran Zhang, Jiang Liu, Shiran Sun, Xinyue Lu, Qinqin Tang, Tao Huang
2026 J jnl
IEEE Trans. Green Commun. Netw.
Wen Wen, Renchao Xie, Qinqin Tang, Zehui Xiong, Ran Zhang, Gaochang Xie, Siqi Sun, Tao Huang
2026 J jnl
IEEE Trans. Mob. Comput.
Yepeng Liu, Ran Zhang, Jiang Liu, Ninghan Sun, Xinyuan Zhang
2025 J jnl
IEEE Netw.
Li Feng, Renchao Xie, Qinqin Tang, Tao Huang, Zehui Xiong, Tianjiao Chen, Ran Zhang, Sha Tan, Zeru Fang
2025 conf
INFOCOM WKSHPS
Xinyue Liao, Jiang Liu, Man Ouyang, Jinyan Du, Yutong Zhao, Ran Zhang
2025 B conf
WCNC
Zeru Fang, Qinqin Tang, Renchao Xie, Tao Huang, Tianjiao Chen, Ran Zhang, Sha Tan, Li Feng
2025 B conf
WCNC
Shiran Sun, Ran Zhang, Kai Liu, Zekun Sun, Qinqin Tang, Tao Huang
2025 J jnl
IEEE Trans. Netw. Sci. Eng.
Renchao Xie, Li Feng, Qinqin Tang, Han Zhu, Tao Huang, Ran Zhang, F. Richard Yu, Zehui Xiong
2025 J jnl
IEEE J. Sel. Areas Commun.
Qinqin Tang, Yutian Yang, Jiayi Cui, Renchao Xie, Tao Huang, Tianjiao Chen, Ran Zhang, Zehui Xiong
2024 J jnl
IEEE Trans. Mob. Comput.
Ran Zhang, Fangqi Liu, Jiang Liu, Mingzhe Chen, Qinqin Tang, Tao Huang, F. Richard Yu
2024 J jnl
IEEE Trans. Intell. Transp. Syst.
Yuzheng Ren, Renchao Xie, Fei Richard Yu, Ran Zhang, Yuhang Wang, Ying He, Tao Huang
2024 J jnl
IEEE Internet Things J.
Xinyuan Zhang, Jiang Liu, Zehui Xiong, Yudong Huang, Ran Zhang, Shiwen Mao, Zhu Han
2024 J jnl
IEEE Trans. Serv. Comput.
Renchao Xie, Li Feng, Qinqin Tang, Tao Huang, Zehui Xiong, Tianjiao Chen, Ran Zhang
2024 B conf
WCNC
Xinyuan Zhang, Jiang Liu, Zehui Xiong, Yudong Huang, Gaochang Xie, Ran Zhang
2024 J jnl
CoRR
Xinyuan Zhang, Jiang Liu, Zehui Xiong, Yudong Huang, Gaochang Xie, Ran Zhang
2024 J jnl
IEEE Trans. Mob. Comput.
Xinyuan Zhang, Jiang Liu, Ran Zhang, Yudong Huang, Jincheng Tong, Ning Xin, Liang Liu, Zehui Xiong
2024 J jnl
IEEE Wirel. Commun.
Tao Huang, Zeru Fang, Qinqin Tang, Renchao Xie, Tianjiao Chen, Ran Zhang, F. Richard Yu
2024 J jnl
IEEE J. Sel. Areas Commun.
Qinqin Tang, Renchao Xie, Zeru Fang, Tao Huang, Tianjiao Chen, Ran Zhang, F. Richard Yu
2024 J jnl
IEEE Internet Things J.
Man Ouyang, Ran Zhang, Bingqing Wang, Jiang Liu, Tao Huang, Liang Liu, Jincheng Tong, Ning Xin, F. Richard Yu
2024 J jnl
IEEE Netw.
Qinqin Tang, Renchao Xie, Li Feng, Fei Richard Yu, Tianjiao Chen, Ran Zhang, Tao Huang
2024 B conf
GLOBECOM
Man Ouyang, Ran Zhang, Bingqing Wang, Jiang Liu, Weihua Zhuang
2023 J jnl
IEEE Commun. Mag.
Yuke Zhou, Ran Zhang, Jiang Liu, Tao Huang, Qinqin Tang, F. Richard Yu
2023 J jnl
Sensors
Yuke Zhou, Jiang Liu, Ran Zhang, Man Ouyang, Tao Huang
2023 B conf
GLOBECOM
Ting Xiong, Ran Zhang, Changqing Luo, Jiang Liu, Geyong Min, Tao Huang
2023 J jnl
IEEE Trans. Mob. Comput.
Qinqin Tang, Renchao Xie, Fei Richard Yu, Tianjiao Chen, Ran Zhang, Tao Huang, Yunjie Liu
2023 B conf
WCNC
Man Ouyang, Jiang Liu, Ran Zhang, Bingqing Wang, Liang Liu, Ning Xin, Jincheng Tong
2022 C conf
ICCC
Yuke Zhou, Jiang Liu, Ran Zhang, Fangqi Liu, Tao Huang, Tianjiao Chen
2022 J jnl
Comput. Networks
Ting Xiong, Ran Zhang, Jiang Liu, Tao Huang, Yunjie Liu, F. Richard Yu
2022 J jnl
IEEE J. Sel. Areas Commun.
Ran Zhang, Jiang Liu, Fangqi Liu, Tao Huang, Qinqin Tang, Shangguang Wang, F. Richard Yu
2022 conf
ICC
Ting Xiong, Jiang Liu, Ran Zhang, Xinyuan Zhang, Changqing Luo, Tao Huang, Yunjie Liu
2022 J jnl
IEEE Internet Things J.
Qinqin Tang, Renchao Xie, Fei Richard Yu, Tianjiao Chen, Ran Zhang, Tao Huang, Yun-Jie Liu
2022 J jnl
IEEE Internet Things J.
Jiang Liu, Xinyuan Zhang, Ran Zhang, Tao Huang, F. Richard Yu
2021 C conf
HPSR
Man Ouyang, Xuefei Duan, Jiang Liu, Ran Zhang, Tao Huang, Lu Hua
2020 J jnl
IEEE Netw.
Ran Zhang, F. Richard Yu, Jiang Liu, Renchao Xie, Tao Huang
2020 J jnl
IEEE Trans. Wirel. Commun.
Ran Zhang, F. Richard Yu, Jiang Liu, Tao Huang, Yunjie Liu
2020 B conf
GLOBECOM
Dan Yang, Jiang Liu, Ran Zhang, Tao Huang
2020 B conf
GLOBECOM
Ran Zhang, Jiang Liu, Tao Huang, Renchao Xie, F. Richard Yu, Yunjie Liu
2020 J jnl
Comput. Networks
Ran Zhang, Jiang Liu, Renchao Xie, Tao Huang, F. Richard Yu, Yunjie Liu
2019 B conf
GLOBECOM
Ran Zhang, Jiang Liu, Renchao Xie, Tao Huang, F. Richard Yu
2017 J jnl
IEEE Access
Ran Zhang, Jiang Liu, Tao Huang, Tian Pan, Lixuan Wu
2017 conf
INFOCOM Workshops
Ran Zhang, Jiang Liu, Tao Huang, Renchao Xie
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"