Valentin Radu

45 papers A* 1A 2B 3C 8Misc 1Journal 17Unranked 12
YearRankTypeTitle / Venue / Authors
2025 A conf
ICDCS
Hongrui Shi, Valentin Radu, Po Yang
2025 J jnl
CoRR
Hongrui Shi, Valentin Radu, Po Yang
2025 J jnl
Syst.
Alina Iuliana Tabirca, Valentin Radu, Angela-Nicoleta Cozorici, Loredana-Cristina Tanase, Florin Radu
2024 J jnl
Syst.
Valentin Radu, Diana Dranga, Catalin Marian Dumitrescu, Alina Iuliana Tabirca, Maria Cristina Stefan
2023 J jnl
Syst.
Rima H. Binsaeed, Zahid Yousaf, Adriana Grigorescu, Valentin Radu, Abdelmohsen A. Nassani
2023 conf
EuroMLSys@EuroSys
Hongrui Shi, Valentin Radu, Po Yang
2023 conf
GeoIndstry@SIGSPATIAL
Anselmo Talotta, Valentin Radu, Lorenzo Sorgi
2023 conf
DistributedML@CoNEXT
Hongrui Shi, Valentin Radu, Po Yang
2022 J jnl
CoRR
Hongrui Shi, Valentin Radu, Po Yang
2022 conf
EuroMLSys@EuroSys
Hongrui Shi, Valentin Radu
2022 C conf
IPIN
Xijia Wei, Valentin Radu
2022 B conf
CC
Naums Mogers, Lu Li, Valentin Radu, Christophe Dubach
2021 C conf
IPIN
Josh Barrows, Valentin Radu, Matthew Hill, Fabio Ciravegna
2021 conf
BIBM
Mattias Cross, Valentin Radu
2021 J jnl
CoRR
Hongrui Shi, Valentin Radu
2021 conf
EuroMLSys@EuroSys
Rik Mulder, Valentin Radu, Christophe Dubach
2021 C conf
IPIN
Xijia Wei, Zhiqiang Wei, Valentin Radu
2021 J jnl
Sensors
Xijia Wei, Zhiqiang Wei, Valentin Radu
2021 conf
EdgeSys@EuroSys
Hongrui Shi, Valentin Radu
2020 conf
GPGPU@PPoPP
Naums Mogers, Valentin Radu, Lu Li, Jack Turner, Michael F. P. O'Boyle, Christophe Dubach
2020 J jnl
Int. J. Comput. Commun. Control
Valentin Radu, Florin Radu, Alina Iuliana Tabirca, Silviu Ilie Saplacan, Ramona Lile
2020 J jnl
Proc. ACM Interact. Mob. Wearable Ubiquitous Technol.
David Strömbäck, Sangxia Huang, Valentin Radu
2020 J jnl
CoRR
Rik Mulder, Valentin Radu, Christophe Dubach
2020 J jnl
CoRR
Valentin Radu, Kuba Kaszyk, Yuan Wen, Jack Turner, José Cano, Elliot J. Crowley, Björn Franke, Amos Storkey, Michael F. P. O'Boyle
2020 C conf
SBAC-PAD
Yuan Wen, Andrew Anderson, Valentin Radu, Michael F. P. O'Boyle, David Gregg
2020 J jnl
CoRR
Yuan Wen, Andrew Anderson, Valentin Radu, Michael F. P. O'Boyle, David Gregg
2019 C conf
IPIN
Xijia Wei, Valentin Radu
2019 C conf
IPIN
Adrian Cosma, Ion Emilian Radoi, Valentin Radu
2019 C conf
IPIN
Ion Emilian Radoi, Dumitru Cirimpei, Valentin Radu
2019 B conf
PACT
Yuan Wen, Andrew Anderson, Valentin Radu, Michael F. P. O'Boyle, David Gregg
2019 conf
IISWC
Valentin Radu, Kuba Kaszyk, Yuan Wen, Jack Turner, José Cano, Elliot J. Crowley, Björn Franke, Amos Storkey, Michael F. P. O'Boyle
2019 J jnl
Proc. ACM Interact. Mob. Wearable Ubiquitous Technol.
Valentin Radu, Maximilian Henne
2018 J jnl
CoRR
Adrian Cosma, Ion Emilian Radoi, Valentin Radu
2018 conf
IISWC
Jack Turner, José Cano, Valentin Radu, Elliot J. Crowley, Michael F. P. O'Boyle, Amos Storkey
2018 J jnl
CoRR
Jack Turner, José Cano, Valentin Radu, Elliot J. Crowley, Michael F. P. O'Boyle, Amos Storkey
2018 J jnl
CoRR
Jack Turner, Elliot J. Crowley, Valentin Radu, José Cano, Amos Storkey, Michael F. P. O'Boyle
2017 J jnl
Proc. ACM Interact. Mob. Wearable Ubiquitous Technol.
Valentin Radu, Catherine Tong, Sourav Bhattacharya, Nicholas D. Lane, Cecilia Mascolo, Mahesh K. Marina, Fahim Kawsar
2017
Valentin Radu
2016 conf
UbiComp Adjunct
Valentin Radu, Nicholas D. Lane, Sourav Bhattacharya, Cecilia Mascolo, Mahesh K. Marina, Fahim Kawsar
2015 conf
AllThingsCellular@SIGCOMM
Mahesh K. Marina, Valentin Radu, Konstantinos Balampekos
2014 Misc conf
SenSys
Valentin Radu, Panagiota Katsikouli, Rik Sarkar, Mahesh K. Marina
2014 A* conf
MobiCom
Valentin Radu, Panagiota Katsikouli, Rik Sarkar, Mahesh K. Marina
2013 C conf
IPIN
Valentin Radu, Mahesh K. Marina
2013 B conf
CNSM
Valentin Radu, Lito Kriara, Mahesh K. Marina
2012 A conf
MobiSys
Valentin Radu, Jiwei Li, Lito Kriara, Mahesh K. Marina, Richard Mortier
redb/extractors/js_extractors/js_deobfuscation.py
← Index redb/extractors/js_extractors/js_deobfuscation.py python
import hashlib
import inspect
import re
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor
from redb.extractors.js_extractors.js_patterns import PATTERNS

# String literals of 4+ characters; only used by the deobfuscation diff to count
# strings revealed after deobfuscation. Compiled once at module load.
_STRING_LITERAL_4PLUS_RE = re.compile(r"[\"\']([^\"\']{4,})[\"\']")


class JSDeobfuscationExtractor(JSExtractor):
    """Compute pre/post-deobfuscation metrics for a JS sample.

    The actual deobfuscation pass (external tool with jsbeautifier fallback)
    lives on `JSContext.deobfuscated` and is cached per sample, so any other
    extractor that needs the deobfuscated text reads the same value without
    re-running the subprocess. Configure the external tool via env vars:
        JS_DEOBFUSCATOR_PATH    Path or name (default: webcrack)
        JS_DEOBFUSCATE_TIMEOUT  Seconds (default: 60)
    """

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.deobfuscation_result = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_DEOBFUSCATION.value

    def extract(self):
        src = self.js_source
        if not src:
            return None

        deobfuscated, deobfuscator_used = self._context.deobfuscated
        if deobfuscated is None:
            return None

        original_size = len(src)
        original_entropy = self._context.text_entropy
        deobfuscated_size = len(deobfuscated)
        deobfuscated_entropy = self._calculate_text_entropy(deobfuscated)
        size_change_ratio = round(deobfuscated_size / original_size, 4) if original_size else 0.0

        # Strings revealed by deobfuscation: matched literals are extracted from
        # both versions and the set difference is the count of "new" strings.
        original_strings = set(_STRING_LITERAL_4PLUS_RE.findall(src))
        deobfuscated_strings = set(_STRING_LITERAL_4PLUS_RE.findall(deobfuscated))
        new_strings = deobfuscated_strings - original_strings

        # Suspicious APIs revealed by deobfuscation. Both sides of the diff
        # come from JSContext caches: the raw scan is computed once for the
        # whole pipeline; the deobfuscated scan is computed once and reused
        # by JSSuspiciousAPIsExtractor's revealed_by_deobf rows.
        original_apis = {n for n in self._context.scan if n in PATTERNS}
        deobfuscated_apis = set(self._context.scan_deobfuscated)
        new_apis = deobfuscated_apis - original_apis

        deobfuscated_sha256 = hashlib.sha256(deobfuscated.encode('utf-8')).hexdigest()

        self.deobfuscation_result = {
            'deobfuscator_used': deobfuscator_used,
            'deobfuscation_successful': True,
            'original_size': original_size,
            'deobfuscated_size': deobfuscated_size,
            'size_change_ratio': size_change_ratio,
            'original_entropy': original_entropy,
            'deobfuscated_entropy': deobfuscated_entropy,
            'new_strings_found': len(new_strings),
            'new_apis_found': len(new_apis),
            'deobfuscated_sha256': deobfuscated_sha256,
        }
        return self.deobfuscation_result

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.deobfuscation_result:
                return None

            r = self.deobfuscation_result
            current_time = datetime.now(timezone.utc)
            data = [[
                self.sha256,
                r['deobfuscator_used'],
                int(r['deobfuscation_successful']),
                r['original_size'],
                r['deobfuscated_size'],
                r['size_change_ratio'],
                r['original_entropy'],
                r['deobfuscated_entropy'],
                r['new_strings_found'],
                r['new_apis_found'],
                r['deobfuscated_sha256'],
                current_time,
            ]]

            column_names = [
                "sha256", "deobfuscator_used", "deobfuscation_successful",
                "original_size", "deobfuscated_size", "size_change_ratio",
                "original_entropy", "deobfuscated_entropy",
                "new_strings_found", "new_apis_found",
                "deobfuscated_sha256", "analysis_date",
            ]

            column_type_names = [
                "FixedString(64)", "LowCardinality(String)", "UInt8",
                "UInt64", "UInt64", "Float64",
                "Float64", "Float64",
                "UInt32", "UInt32",
                "FixedString(64)", "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_js_deobfuscation"