Vali Derhami

27 papers Misc 1Journal 22Unranked 4
YearRankTypeTitle / Venue / Authors
2021 J jnl
J. Electronic Imaging
Masoumeh Rezaei, Mehdi Rezaeian, Vali Derhami, Hossein Khorshidi
2020 J jnl
Robotica
Farinaz Alamiyan Harandi, Vali Derhami, Fatemeh Jamshidi
2020 J jnl
Soft Comput.
Farzaneh Ghorbani, Mohsen Afsharchi, Vali Derhami
2019 J jnl
J. Intell. Fuzzy Syst.
Farzaneh Ghorbani, Mohsen Afsharchi, Vali Derhami
2019 J jnl
Appl. Soft Comput.
Farinaz Alamiyan Harandi, Vali Derhami, Fatemeh Jamshidi
2019 J jnl
Comput. Aided Geom. Des.
Masoumeh Rezaei, Mehdi Rezaeian, Vali Derhami, Ferdous Sohel, Mohammed Bennamoun
2018 J jnl
Informatics
Mohammad Bagher Dowlatshahi, Vali Derhami, Hossein Nezamabadi-pour
2018 J jnl
J. Intell. Fuzzy Syst.
Farinaz Alamiyan Harandi, Vali Derhami, Fatemeh Jamshidi
2018 J jnl
World Wide Web
Tahere Shakiba, Sajjad Zarifzadeh, Vali Derhami
2017 J jnl
Int. J. Data Min. Bioinform.
Nima Shayanfar, Vali Derhami, Mehdi Rezaeian
2017 J jnl
Inf.
Mohammad Bagher Dowlatshahi, Vali Derhami, Hossein Nezamabadi-pour
2017 J jnl
Int. J. Fuzzy Syst.
Farzaneh Ghorbani, Vali Derhami, Mohsen Afsharchi
2016 J jnl
J. Intell. Fuzzy Syst.
Farinaz Alamiyan Harandi, Vali Derhami
2016 J jnl
J. Intell. Fuzzy Syst.
Atefeh Khazaei, Mohammad Ghasemzadeh, Vali Derhami
2016 J jnl
Appl. Soft Comput.
Fatemeh Fathinezhad, Vali Derhami, Mehdi Rezaeian
2015 Misc conf
IDC
Vali Derhami, Yusef Momeni
2013 J jnl
Int. J. Comput. Commun. Control
Hamideh Zare, Fazlollah Adibnia, Vali Derhami
2013 J jnl
Appl. Soft Comput.
Vali Derhami, Elahe Khodadadian, Mohammad Ghasemzadeh, Ali Mohammad Zareh Bidoki
2013 J jnl
J. Intell. Fuzzy Syst.
Vali Derhami
2013 J jnl
J. Web Eng.
Mohammad Amin Golshani, Ali Mohammad Zareh Bidoki, Vali Derhami
2012 conf
IST
Shahrzad Sedaghat, Fazlollah Adibniya, Vali Derhami
2011 conf
AIRS
Mohammad Amin Golshani, Vali Derhami, Ali Mohammad Zareh Bidoki
2011 conf
WCIT
Farideh Hakimiyan, Vali Derhami
2011 J jnl
KSII Trans. Internet Inf. Syst.
Peyman Pahlavani, Vali Derhami, Ali Mohammad Zareh Bidoki
2010 conf
ICT
Vali Derhami, Mohammad Ali Saadatjoo, Fatemeh Saadatjoo
2010 J jnl
Fuzzy Sets Syst.
Vali Derhami, Vahid Johari Majd, Majid Nili Ahmadabadi
2009 J jnl
Comput. Math. Appl.
Fatemeh Saadatjoo, Vali Derhami, Seyed-Mehdi Karbassi
redb/extractors/decompiler/_archive/GhidraDecompilerScript-latest.java
← Index redb/extractors/decompiler/_archive/GhidraDecompilerScript-latest.java java
import ghidra.app.script.GhidraScript;
import ghidra.program.model.listing.*;
import ghidra.app.decompiler.*;
import ghidra.program.model.block.*;
import ghidra.program.model.symbol.*;
import ghidra.program.model.pcode.*;
import ghidra.program.model.address.*;
import org.json.JSONObject;
import org.json.JSONArray;
import java.security.MessageDigest;
import java.nio.charset.StandardCharsets;

public class GhidraDecompilerScript extends GhidraScript {
    private DecompInterface decompInterface;
    private BasicBlockModel basicBlockModel;
    
    @Override
    public void run() throws Exception {
        // Get binary hash and filepath from arguments
        String[] args = getScriptArgs();
        if (args.length < 2) {
            System.err.println("{\"error\": \"Both SHA256 and filepath arguments are required\"}");
            return;
        }
        String sha256 = args[0];
        String filepath = args[1];

        // Initialize analysis components
        setupDecompiler();
        basicBlockModel = new BasicBlockModel(currentProgram);

        // Create the main JSON object for output
        JSONObject output = new JSONObject();
        output.put("sha256", sha256);
        output.put("decompiled", new JSONArray());
        output.put("disassembled", new JSONArray());
        output.put("cfg", new JSONArray());

        // Process all functions
        FunctionIterator functions = currentProgram.getFunctionManager().getFunctions(true);
        for (Function function : functions) {
            processFunction(function, output);
        }

        // Output the final JSON to stdout
        System.out.println(output.toString());
    }

    private void setupDecompiler() {
        decompInterface = new DecompInterface();
        DecompileOptions options = new DecompileOptions();
        decompInterface.setOptions(options);
        decompInterface.openProgram(currentProgram);
    }

    private void processFunction(Function function, JSONObject output) {
        Address entry = function.getEntryPoint();
        String functionName = function.getName();
        String functionAddress = entry.toString();

        // Process decompiled code
        processDecompiledCode(function, output.getJSONArray("decompiled"), 
                            functionName, functionAddress);

        // Process disassembled code
        processDisassembledCode(function, output.getJSONArray("disassembled"), 
                              functionName, functionAddress);

        // Process CFG
        processCFG(function, output.getJSONArray("cfg"), functionAddress);
    }

    private void processDecompiledCode(Function function, JSONArray decompArray, 
                                     String functionName, String functionAddress) {
        DecompileResults results = decompInterface.decompileFunction(function, 30, monitor);
        if (results.decompileCompleted()) {
            String decompiledCode = results.getDecompiledFunction().getC();
            String contentHash = calculateHash(decompiledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("decompiled_content_hash", contentHash);
            functionObj.put("decompiled_function_name", functionName);
            functionObj.put("decompiled_function_address", functionAddress);
            functionObj.put("decompiled_function", decompiledCode);
            
            decompArray.put(functionObj);
        }
    }

    private void processDisassembledCode(Function function, JSONArray disasmArray, 
                                       String functionName, String functionAddress) {
        try {
            StringBuilder disassembly = new StringBuilder();
            StringBuilder normalized = new StringBuilder();
            int instructionCount = 0;

            Listing listing = currentProgram.getListing();
            AddressSetView functionBody = function.getBody();
            InstructionIterator instructions = listing.getInstructions(functionBody, true);

            while (instructions.hasNext()) {
                try {
                    Instruction instr = instructions.next();
                    String disasmLine = instr.toString();
                    disassembly.append(disasmLine).append("\n");
                    normalized.append(normalizeInstruction(disasmLine)).append("\n");
                    instructionCount++;
                } catch (Exception e) {
                    System.err.println("Error processing instruction in " + functionName + ": " + e.getMessage());
                }
            }

            String disassembledCode = disassembly.toString();
            String contentHash = calculateHash(disassembledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("disassembled_content_hash", contentHash);
            functionObj.put("disassembled_function_name", functionName);
            functionObj.put("disassembled_function_address", functionAddress);
            functionObj.put("disassembled_function", disassembledCode);
            functionObj.put("normalized_disassembly", normalized.toString());
            functionObj.put("instruction_count", instructionCount);

            // Set similarity-related fields to null for now
            functionObj.put("minhash_signature", JSONObject.NULL);
            functionObj.put("opcode_frequency_vector", JSONObject.NULL);
            functionObj.put("api_calls_vector", JSONObject.NULL);
            functionObj.put("instruction_embedding", JSONObject.NULL);

            disasmArray.put(functionObj);
        } catch (Exception e) {
            System.err.println("Error processing disassembly for " + functionName + ": " + e.getMessage());
        }
    }

    private void processCFG(Function function, JSONArray cfgArray, String functionAddress) {
        try {
            CodeBlockIterator blocks = basicBlockModel.getCodeBlocksContaining(
                function.getBody(), monitor);

            while (blocks.hasNext()) {
                CodeBlock block = blocks.next();
                String blockInstructions = getBlockInstructions(block);
                String blockId = calculateHash(blockInstructions);

                JSONObject blockObj = new JSONObject();
                blockObj.put("block_id", blockId);
                blockObj.put("function_address", functionAddress);
                blockObj.put("block_instructions", blockInstructions);

                // Get successor blocks
                CodeBlockReferenceIterator successors = block.getDestinations(monitor);
                JSONArray successorAddresses = new JSONArray();
                while (successors.hasNext()) {
                    CodeBlockReference ref = successors.next();
                    successorAddresses.put(ref.getDestinationAddress().toString());
                }
                blockObj.put("successor_blocks", successorAddresses);

                cfgArray.put(blockObj);
            }
        } catch (Exception e) {
            System.err.println("{\"error\": \"Error processing CFG: " + 
                             e.getMessage().replace("\"", "'") + "\"}");
        }
    }

    private String normalizeInstruction(String instruction) {
        return instruction.replaceAll("0x[0-9a-fA-F]+", "IMM")
                        .replaceAll("\\b\\d+\\b", "NUM");
    }

    private String getBlockInstructions(CodeBlock block) {
        StringBuilder instructions = new StringBuilder();
        AddressIterator addresses = block.getAddresses(true);
        while (addresses.hasNext()) {
            Address addr = addresses.next();
            Instruction instr = currentProgram.getListing().getInstructionAt(addr);
            if (instr != null) {
                instructions.append(instr.toString()).append("\n");
            }
        }
        return instructions.toString();
    }

    private String calculateHash(String content) {
        try {
            MessageDigest digest = MessageDigest.getInstance("SHA-256");
            byte[] hash = digest.digest(content.getBytes(StandardCharsets.UTF_8));
            StringBuilder hexString = new StringBuilder();
            for (byte b : hash) {
                hexString.append(String.format("%02x", b));
            }
            return hexString.toString();
        } catch (Exception e) {
            System.err.println("{\"error\": \"Error calculating hash\"}");
            return "";
        }
    }
}