Valentina Tamma

86 papers A* 2A 9B 12C 3Misc 5Journal 21Unranked 23
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Reham Alharbi, Valentina Tamma, Terry R. Payne, Jacopo de Berardinis
2025 conf
ISWC (Industry/Doctoral Consortium/Posters/Demos)
Reham Alharbi, Jacopo de Berardinis, Terry R. Payne, Valentina Tamma
2025 J jnl
CoRR
Samah AlKhuzaey, Floriana Grasso, Terry R. Payne, Valentina Tamma
2025 conf
ESWC-JP
George Hannah, Jacopo de Berardinis, Terry R. Payne, Valentina Tamma, Andrew Mitchell, Ellen Piercy, Ewan Johnson, Andrew Ng, Harry Rostron, Boris Konev
2025 ed.
HGAIS@ISWC
Reham Alharbi, Jacopo de Berardinis, Paul Groth, Albert Meroño-Peñuela, Elena Simperl, Valentina Tamma
2025 J jnl
CoRR
George Hannah, Jacopo de Berardinis, Terry R. Payne, Valentina Tamma, Andrew Mitchell, Ellen Piercy, Ewan Johnson, Andrew Ng, Harry Rostron, Boris Konev
2025 A conf
ECAI
Samah AlKhuzaey, Floriana Grasso, Terry R. Payne, Valentina Tamma
2025 ed.
ESWC Satellite Events (1)
Albert Meroño-Peñuela, Óscar Corcho, Paul Groth, Elena Simperl, Valentina Tamma, Andrea Giovanni Nuzzolese, María Poveda-Villalón, Marta Sabou, Valentina Presutti, Irene Celino, Artem Revenko, Joe Raad, Bruno Sartini, Pasquale Lisena
2025 ed.
ESWC Satellite Events (2)
Albert Meroño-Peñuela, Óscar Corcho, Paul Groth, Elena Simperl, Valentina Tamma, Andrea Giovanni Nuzzolese, María Poveda-Villalón, Marta Sabou, Valentina Presutti, Irene Celino, Artem Revenko, Joe Raad, Bruno Sartini, Pasquale Lisena
2024 J jnl
CoRR
Gianluca Apriceno, Valentina Tamma, Tania Bailoni, Jacopo de Berardinis, Mauro Dragoni
2024 B conf
EKAW
Reham Alharbi, Valentina Tamma, Floriana Grasso, Terry R. Payne
2024 Misc conf
SAC
Reham Alharbi, Valentina Tamma, Floriana Grasso, Terry R. Payne
2024 conf
HGAIS@ISWC
Reham Alharbi, Jacopo de Berardinis, Floriana Grasso, Terry R. Payne, Valentina Tamma
2024 B conf
KES
Samah AlKhuzaey, Floriana Grasso, Terry R. Payne, Valentina Tamma
2024 conf
CAiSE Forum
Reham Alharbi, Valentina Tamma, Floriana Grasso
2024 J jnl
Int. J. Artif. Intell. Educ.
Samah AlKhuzaey, Floriana Grasso, Terry R. Payne, Valentina Tamma
2024 conf
ESWC Satellite Events (1)
Reham Alharbi, Valentina Tamma, Floriana Grasso, Terry R. Payne
2024 conf
EcalLAC@AIED
Samah AlKhuzaey, Floriana Grasso, Terry R. Payne, Valentina Tamma
2023 J jnl
CoRR
Reham Alharbi, Valentina Tamma, Floriana Grasso, Terry R. Payne
2023 J jnl
TGDK
Jean-Paul Calbimonte, Andrei Ciortea, Timotheus Kampik, Simon Mayer, Terry R. Payne, Valentina Tamma, Antoine Zimmermann
2023 J jnl
CoRR
Jiaoyan Chen, Hang Dong, Janna Hastings, Ernesto Jiménez-Ruiz, Vanessa López, Pierre Monnin, Catia Pesquita, Petr Skoda, Valentina Tamma
2023 J jnl
TGDK
Jiaoyan Chen, Hang Dong, Janna Hastings, Ernesto Jiménez-Ruiz, Vanessa López, Pierre Monnin, Catia Pesquita, Petr Skoda, Valentina Tamma
2023 conf
OM@ISWC
George Hannah, Terry R. Payne, Valentina Tamma, Andrew Mitchell, Ellen Piercy, Boris Konev
2022 J jnl
CoRR
Timotheus Kampik, Adnane Mansour, Olivier Boissier, Sabrina Kirrane, Julian A. Padget, Terry R. Payne, Munindar P. Singh, Valentina Tamma, Antoine Zimmermann
2022 J jnl
ACM Trans. Internet Techn.
Timotheus Kampik, Adnane Mansour, Olivier Boissier, Sabrina Kirrane, Julian A. Padget, Terry R. Payne, Munindar P. Singh, Valentina Tamma, Antoine Zimmermann
2022 J jnl
CoRR
David Geleta, Andriy Nikolov, Mark ODonoghue, Benedek Rozemberczki, Anna Gogleva, Valentina Tamma, Terry R. Payne
2021 conf
AIED (1)
Samah AlKhuzaey, Floriana Grasso, Terry R. Payne, Valentina Tamma
2021 B conf
K-CAP
Martin Mansfield, Valentina Tamma, Phil Goddard, Frans Coenen
2021 B conf
K-CAP
Reham Alharbi, Valentina Tamma, Floriana Grasso
2020 ed.
ISWC (1)
Jeff Z. Pan, Valentina Tamma, Claudia d'Amato, Krzysztof Janowicz, Bo Fu, Axel Polleres, Oshani Seneviratne, Lalana Kagal
2020 ed.
ISWC (2)
Jeff Z. Pan, Valentina Tamma, Claudia d'Amato, Krzysztof Janowicz, Bo Fu, Axel Polleres, Oshani Seneviratne, Lalana Kagal
2019 conf
SWH@ISWC
Mauro Dragoni, Valentina Tamma
2018 conf
DH
Yousef Alfaifi, Floriana Grasso, Valentina Tamma
2017 ed.
ISWC (1)
Claudia d'Amato, Miriam Fernández, Valentina Tamma, Freddy Lécué, Philippe Cudré-Mauroux, Juan F. Sequeda, Christoph Lange, Jeff Heflin
2017 ed.
ISWC (2)
Claudia d'Amato, Miriam Fernández, Valentina Tamma, Freddy Lécué, Philippe Cudré-Mauroux, Juan F. Sequeda, Christoph Lange, Jeff Heflin
2017 conf
DH
Yousef Alfaifi, Floriana Grasso, Valentina Tamma
2016 A conf
AAMAS
Gabrielle Santos, Valentina Tamma, Terry R. Payne, Floriana Grasso
2016 B conf
EKAW
David Geleta, Terry R. Payne, Valentina Tamma
2016 B conf
EKAW
Gabrielle Santos, Terry R. Payne, Valentina Tamma, Floriana Grasso
2016 A* conf
KR
Ernesto Jiménez-Ruiz, Terry R. Payne, Alessandro Solimando, Valentina Tamma
2016 conf
OWLED
David Geleta, Terry R. Payne, Valentina Tamma
2016 ed.
OWLED
Valentina Tamma, Mauro Dragoni, Rafael S. Gonçalves, Agnieszka Lawrynowicz
2015 B conf
PRIMA
Terry R. Payne, Valentina Tamma
2014 B conf
EKAW
Terry R. Payne, Valentina Tamma
2014 A conf
AAMAS
Terry R. Payne, Valentina Tamma
2014 ed.
OWLED
C. Maria Keet, Valentina Tamma
2011 J jnl
Appl. Artif. Intell.
Ben Lithgow Smith, Valentina Tamma, Michael J. Wooldridge
2010 conf
ISWC (1)
Paul Doran, Terry R. Payne, Valentina Tamma, Ignazio Palmisano
2010 J jnl
Int. J. Metadata Semant. Ontologies
Ian Blacoe, Valentina Tamma, Michael J. Wooldridge
2010 A conf
AAMAS
Paul Doran, Valentina Tamma, Terry R. Payne, Ignazio Palmisano
2010 J jnl
IEEE Intell. Syst.
Valentina Tamma
2009 B conf
K-CAP
Paul Doran, Valentina Tamma, Terry R. Payne, Ignazio Palmisano
2009 A* conf
IJCAI
Paul Doran, Valentina Tamma, Terry R. Payne, Ignazio Palmisano
2009 conf
AAMAS (2)
Paul Doran, Valentina Tamma, Ignazio Palmisano, Terry R. Payne
2009 Misc conf
ISWC
Ignazio Palmisano, Valentina Tamma, Terry R. Payne, Paul Doran
2009 conf
ArgMAS
Paul Doran, Valentina Tamma, Terry R. Payne, Ignazio Palmisano
2008 C conf
ICEC
Chris van Aart, Valentina Tamma
2008 conf
Web Intelligence
Ignazio Palmisano, Valentina Tamma, Luigi Iannone, Terry R. Payne, Paul Doran
2008 conf
ISWC (Posters & Demos)
Ignazio Palmisano, Valentina Tamma, Luigi Iannone, Terry R. Payne, Paul Doran
2008 conf
Web Intelligence
Paul Doran, Valentina Tamma, Ignazio Palmisano, Terry R. Payne, Luigi Iannone
2008 J jnl
IEEE Intell. Syst.
Valentina Tamma, Terry R. Payne
2008 A conf
ECAI
Ian Blacoe, Ignazio Palmisano, Valentina Tamma, Luigi Iannone
2008 conf
WoMO
Paul Doran, Ignazio Palmisano, Valentina Tamma
2007 J jnl
ACM Trans. Auton. Adapt. Syst.
Shamimabi Paurobally, Valentina Tamma, Michael J. Wooldridge
2007 A conf
AAMAS
Loredana Laera, Ian Blacoe, Valentina Tamma, Terry R. Payne, Jérôme Euzenat, Trevor J. M. Bench-Capon
2007 A conf
CIKM
Paul Doran, Valentina Tamma, Luigi Iannone
2007 conf
WoMO
Mathieu d'Aquin, Paul Doran, Enrico Motta, Valentina Tamma
2007 A conf
AAMAS
Shamimabi Paurobally, Chris van Aart, Valentina Tamma, Michael J. Wooldridge, Peter van Hapert
2006 C conf
EUMAS
Loredana Laera, Valentina Tamma, Jérôme Euzenat, Trevor J. M. Bench-Capon, Terry R. Payne
2006 conf
Ontology Matching
Loredana Laera, Valentina Tamma, Jérôme Euzenat, Trevor J. M. Bench-Capon, Terry R. Payne
2006 Misc conf
ISWC
Loredana Laera, Valentina Tamma, Jérôme Euzenat, Trevor J. M. Bench-Capon, Terry R. Payne
2005 ed.
AAAI Fall Symposium: Agents and the Semantic Web
Terry R. Payne, Valentina Tamma
2005 Misc conf
ISWC
Valentina Tamma, Chris van Aart, Thierry Moyaux, Shamimabi Paurobally, Ben Lithgow Smith, Michael J. Wooldridge
2005 B conf
CCGRID
Line Pouchard, Luc Moreau, Valentina Tamma
2005 Misc conf
ISWC
Valentina Tamma, Ian Blacoe, Ben Lithgow Smith, Michael J. Wooldridge
2005 J jnl
Eng. Appl. Artif. Intell.
Valentina Tamma, Steve Phelps, Ian Dickinson, Michael J. Wooldridge
2005 J jnl
Knowl. Eng. Rev.
Terry R. Payne, Valentina Tamma
2004 B conf
EKAW
Valentina Tamma, Ian Blacoe, Ben Lithgow Smith, Michael J. Wooldridge
2004 A conf
ECAI
Valentina Tamma, Ian Blacoe, Ben Lithgow Smith, Michael J. Wooldridge
2004 conf
RuleML
Loredana Laera, Valentina Tamma, Trevor J. M. Bench-Capon, Giovanni Semeraro
2004 J jnl
IEEE Internet Comput.
Steve Phelps, Valentina Tamma, Michael J. Wooldridge, Ian Dickinson
2003 ed.
OAS
Stephen Cranefield, Timothy W. Finin, Valentina Tamma, Steven Willmott
2002 conf
AMEC
Valentina Tamma, Michael J. Wooldridge, Ian Blacoe, Ian Dickinson
2002 J jnl
Knowl. Eng. Rev.
Valentina Tamma, Trevor J. M. Bench-Capon
2002 B conf
EKAW
Valentina Tamma, Trevor J. M. Bench-Capon
2001 C conf
ECSQARU
Valentina Tamma, Simon Parsons
redb/extractors/apk_extractors/apk_resources.py
← Index redb/extractors/apk_extractors/apk_resources.py python
import hashlib
import inspect
import os
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKResource


# ─── Suspicious file types ──────────────────────────────────────────────
# File types that are suspicious when found inside res/ or assets/.
# Excludes javascript/html (extremely common in legitimate hybrid apps)
# and common media/font types that are normal APK content.
SUSPICIOUS_TYPES = {
    # Executables — no legitimate reason in assets/res
    "elf", "pebin", "macho", "dex", "apk",
    # Java containers — DexClassLoader target
    "jar",
    # Archives — rare in legitimate assets (~135:1 malware-to-benign ratio)
    "zip", "gzip", "7z", "xz", "tar", "bzip2", "rar", "7zip", "lzma",
    # Scripts with system execution capability
    "shell", "python", "powershell", "batch",
}

# ─── Entropy thresholds ─────────────────────────────────────────────────
# For unrecognized/unknown types: encrypted payloads typically land > 7.0
ENTROPY_HIGH_UNKNOWN = 7.0
# For recognized-but-non-image types: stricter threshold
ENTROPY_EXTREME = 7.85

# ─── Android-specific binary format magic bytes ─────────────────────────
# These formats are common in legitimate APKs but unknown to Magika,
# causing misclassification (e.g., AXML → "gzip", profm → "unknown").
AXML_MAGIC = b'\x03\x00\x08\x00'       # Android Binary XML (compiled res/*.xml)
ARSC_MAGIC = b'\x02\x00\x0c\x00'       # Android compiled resource table
ART_PROF_MAGIC = b'pro\x00'            # ART baseline profile
ART_PROFM_MAGIC = b'prm\x00'           # ART baseline profile metadata

# ─── Allowlisted paths ──────────────────────────────────────────────────
# Fixed, hardcoded paths in the Android build system that are always benign.
# ART profiles at these exact paths are shipped by Jetpack ProfileInstaller.
ALLOWLISTED_PATHS = {
    "assets/dexopt/baseline.prof",
    "assets/dexopt/baseline.profm",
}

# ─── Image handling ─────────────────────────────────────────────────────
# Magika-confirmed image types: high entropy is expected (lossy codecs
# like VP8/JPEG arithmetic-code toward entropy ~7.95-8.0 by design).
IMAGE_MAGIKA_TYPES = {"png", "webp", "jpeg", "gif", "bmp", "tiff", "ico"}
IMAGE_EXTENSIONS = {".png", ".webp", ".jpg", ".jpeg", ".gif", ".bmp", ".tiff", ".ico"}

# ─── Types Magika assigns when it can't identify the content ────────────
UNRECOGNIZED_MAGIKA_TYPES = {"unknown", "empty"}

# ─── Resource scan limits ───────────────────────────────────────────────
MAX_RESOURCE_FILES = 5000


class APKResourceExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.resources = []
        self.suspicious_files = []
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_RESOURCES.value

    # ─── Core classification logic ──────────────────────────────────────

    def _identify_android_format(self, header: bytes) -> str | None:
        """
        Identify Android-specific binary formats that Magika doesn't know.
        Returns a corrected type label, or None to fall through to Magika.
        """
        if len(header) < 4:
            return None

        magic4 = header[:4]

        # Android Binary XML — all res/*.xml in a compiled APK.
        # Magika often misclassifies this as "gzip".
        if magic4 == AXML_MAGIC:
            return "android_binary_xml"

        # Android compiled resource table (resources.arsc chunks)
        if magic4 == ARSC_MAGIC:
            return "android_resource_table"

        # ART baseline profiles — high entropy (zlib inside) but benign.
        # The format is inert (method reference bitmaps/metadata, not
        # executable code) and some build configs place them at varying paths.
        if magic4 == ART_PROF_MAGIC:
            return "android_art_profile"
        if magic4 == ART_PROFM_MAGIC:
            return "android_art_profile_metadata"

        return None

    def _is_suspicious_resource(
        self, path: str, magika_type: str, entropy: float,
        android_type: str | None,
    ) -> bool:
        """
        Determine if a resource file is suspicious.

        Detection layers:
        1. Allowlisted paths → always benign
        2. Android-specific format override → reclassify Magika mislabels
        3. Image extension vs Magika type mismatch → encrypted blob detection
        4. Magika-confirmed images → benign regardless of entropy
        5. Suspicious type match → flag known-dangerous types
        6. High-entropy unknown blobs → likely encrypted payloads
        """

        # ── Layer 1: Allowlisted paths (hardcoded Android build artifacts) ──
        if path in ALLOWLISTED_PATHS:
            return False

        # ── Layer 2: Android-specific format detection ──────────────────────
        # Override Magika's label for formats it doesn't recognize.
        # All Android-specific formats (AXML, ARSC, ART profiles) are
        # legitimate build artifacts — never suspicious.
        if android_type is not None:
            return False

        # ── Layer 3: Image extension / Magika type mismatch ─────────────────
        # If the file extension claims "image" but Magika's content analysis
        # disagrees, this is a strong signal for an encrypted payload with
        # a fake image extension (e.g., ErrorFather's "rbyypivsnw.png").
        ext = os.path.splitext(path)[1].lower()
        if ext in IMAGE_EXTENSIONS and magika_type not in IMAGE_MAGIKA_TYPES:
            # Exception: Magika might label a valid image as "unknown" if
            # the file is very small (< ~16 bytes). Don't flag tiny files.
            if entropy > 5.0:
                return True

        # ── Layer 4: Magika-confirmed images → benign ───────────────────────
        # Lossy codecs (VP8, JPEG) produce entropy up to ~8.0 by design.
        # If Magika confirms image structure, high entropy is expected.
        if magika_type in IMAGE_MAGIKA_TYPES:
            return False

        # ── Layer 5: Known suspicious file types ────────────────────────────
        if magika_type in SUSPICIOUS_TYPES:
            return True

        # ── Layer 6: High-entropy unrecognized blobs ────────────────────────
        # Files Magika can't identify with high entropy are likely encrypted
        # payloads. Most Android malware packers store encrypted DEX/SO
        # payloads as opaque blobs with random names and no valid magic.
        if magika_type in UNRECOGNIZED_MAGIKA_TYPES and entropy > ENTROPY_HIGH_UNKNOWN:
            return True

        # ── Layer 7: Extreme entropy on any non-image recognized type ───────
        # Catches edge cases where Magika assigns a benign label (e.g.,
        # "xml", "txt") but the entropy is impossibly high for that format.
        if magika_type not in IMAGE_MAGIKA_TYPES and entropy > ENTROPY_EXTREME:
            return True

        return False

    # ─── Extraction pipeline ────────────────────────────────────────────

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        try:
            from magika import Magika
            magika = Magika()
        except Exception as e:
            self.log.error(f"Failed to initialize Magika for {self.hash.sha256}: {e}")
            magika = None

        self.resources = []
        self.suspicious_files = []
        scanned = 0

        zf = self._get_zip_file()
        if not zf:
            return None

        with zf:
            for info in zf.infolist():
                if info.is_dir():
                    continue
                if not (info.filename.startswith("res/") or
                        info.filename.startswith("assets/")):
                    continue

                if scanned >= MAX_RESOURCE_FILES:
                    self.log.warning(
                        f"Resource scan limit reached ({MAX_RESOURCE_FILES}), "
                        f"stopping resource enumeration"
                    )
                    break
                scanned += 1

                try:
                    data = zf.read(info.filename)
                except Exception as e:
                    self.log.warning(
                        f"Error reading resource {info.filename}: {e}"
                    )
                    continue

                try:
                    file_sha256 = hashlib.sha256(data).hexdigest()
                    file_entropy = round(self.calculate_entropy(data), 3)

                    # Read first bytes for Android-specific format detection
                    header = data[:16] if len(data) >= 16 else data

                    if magika:
                        try:
                            filetype = magika.identify_bytes(data).output.label
                        except Exception:
                            filetype = "unknown"
                    else:
                        filetype = "unknown"

                    # Identify Android-specific formats once, reuse for
                    # both stored type and suspicion classification
                    android_type = self._identify_android_format(header)
                    stored_type = android_type if android_type else filetype

                    suspicious = self._is_suspicious_resource(
                        path=info.filename,
                        magika_type=filetype,
                        entropy=file_entropy,
                        android_type=android_type,
                    )

                    resource = APKResource(
                        path=info.filename,
                        size=info.file_size,
                        sha256=file_sha256,
                        filetype_magika=stored_type,
                        entropy=file_entropy,
                    )

                    if suspicious:
                        resource.is_suspicious = True
                        self.suspicious_files.append(resource)

                    self.resources.append(resource)
                except Exception as e:
                    self.log.warning(
                        f"Error processing resource {info.filename}: {e}"
                    )
                    continue

        if not self.resources:
            return None

        return {
            "total_resource_count": len(self.resources),
            "total_resource_size": sum(r.size for r in self.resources),
            "suspicious_file_count": len(self.suspicious_files),
            "resources": self.resources,
            "suspicious_files": self.suspicious_files,
        }

    # ─── Export ──────────────────────────────────────────────────────────

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.resources:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for res in self.resources:
                data.append([
                    self.sha256,
                    res.path,
                    res.size,
                    res.sha256,
                    res.filetype_magika,
                    res.entropy,
                    int(res.is_suspicious),
                    current_time,
                ])

            column_names = [
                'sha256', 'resource_path', 'resource_size',
                'resource_sha256', 'resource_magika', 'resource_entropy',
                'is_suspicious', 'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)', 'String', 'UInt64',
                'FixedString(64)', 'LowCardinality(String)', 'Float32',
                'UInt8', "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_resources"