Victor J. Rayward-Smith

68 papers A* 2A 2B 2C 7Journal 45Unranked 10
YearRankTypeTitle / Venue / Authors
2014 J jnl
Stat. Anal. Data Min.
Khaled Alotaibi, Victor J. Rayward-Smith, Beatriz de la Iglesia
2013 J jnl
Discret. Appl. Math.
George Kettleborough, Victor J. Rayward-Smith
2012 J jnl
J. Math. Model. Algorithms
Victor J. Rayward-Smith
2012 conf
SocialCom/PASSAT
Khaled Alotaibi, Victor J. Rayward-Smith, Wenjia Wang, Beatriz de la Iglesia
2011 C conf
IDEAL
Oliver Kirkland, Victor J. Rayward-Smith, Beatriz de la Iglesia
2011 J jnl
J. Math. Model. Algorithms
Quynh H. Nguyen, Victor J. Rayward-Smith
2011 C ed.
IDEAL
Hujun Yin, Wenjia Wang, Victor J. Rayward-Smith
2011 J jnl
Intell. Data Anal.
Victor J. Rayward-Smith
2011 C conf
IDEAL
Khaled Alotaibi, Victor J. Rayward-Smith, Beatriz de la Iglesia
2009 J jnl
J. Oper. Res. Soc.
Kweku-Muata Osei-Bryson, Victor J. Rayward-Smith
2009 J jnl
J. Math. Model. Algorithms
Victor J. Rayward-Smith
2009 C conf
KEOD
Hongyan Yi, Victor J. Rayward-Smith
2008 J jnl
Comput. Oper. Res.
Victor J. Rayward-Smith, Djamal Rebaine
2008 J jnl
J. Math. Model. Algorithms
Victor J. Rayward-Smith
2008 J jnl
Int. J. Bus. Intell. Data Min.
Quynh H. Nguyen, Victor J. Rayward-Smith
2008 J jnl
J. Math. Model. Algorithms
John A. Keane, Hujun Yin, Victor J. Rayward-Smith
2007 J jnl
Comput. Stat. Data Anal.
Victor J. Rayward-Smith
2006 J jnl
Appl. Intell.
Sami H. Al-Harbi, Victor J. Rayward-Smith
2006 J jnl
J. Math. Model. Algorithms
Alan P. Reynolds, Graeme Richards, Beatriz de la Iglesia, Victor J. Rayward-Smith
2006 J jnl
Eur. J. Oper. Res.
Beatriz de la Iglesia, Graeme Richards, M. S. Philpott, Victor J. Rayward-Smith
2005 C conf
EMO
Beatriz de la Iglesia, Alan P. Reynolds, Victor J. Rayward-Smith
2005 B conf
Congress on Evolutionary Computation
Victor J. Rayward-Smith
2005 J jnl
Intell. Data Anal.
Graeme Richards, Victor J. Rayward-Smith
2005 conf
CIS (2)
Hong Yan Yi, Beatriz de la Iglesia, Victor J. Rayward-Smith
2004 C conf
IDEAL
Alan P. Reynolds, Graeme Richards, Victor J. Rayward-Smith
2003 conf
EvoWorkshops
Alan P. Reynolds, Jo L. Dicks, Ian N. Roberts, Jan-Jaap Wesselink, Beatriz de la Iglesia, Vincent Robert, Teun Boekhout, Victor J. Rayward-Smith
2003 B conf
IEEE Congress on Evolutionary Computation
Beatriz de la Iglesia, M. S. Philpott, Anthony J. Bagnall, Victor J. Rayward-Smith
2003 conf
ICANNGA
Martin Burgess, Gareth J. Janacek, Victor J. Rayward-Smith
2003 C conf
IEA/AIE
Sami H. Al-Harbi, Victor J. Rayward-Smith
2002 J jnl
Bioinform.
Jan-Jaap Wesselink, Beatriz de la Iglesia, Stephen A. James, Jo L. Dicks, Ian N. Roberts, Victor J. Rayward-Smith
2001 J jnl
Artif. Intell. Medicine
Graeme Richards, Victor J. Rayward-Smith, P. H. Sönksen, S. Carey, C. Weng
2001 A* conf
ICDM
Graeme Richards, Victor J. Rayward-Smith
2001 J jnl
J. Oper. Res. Soc.
Victor J. Rayward-Smith
2001 J jnl
Inf. Softw. Technol.
Anthony J. Bagnall, Victor J. Rayward-Smith, Ian M. Whittley
1999 J jnl
Appl. Intell.
Justin C. W. Debuse, Victor J. Rayward-Smith
1999 J jnl
Ann. Oper. Res.
S. A. Harrison, Victor J. Rayward-Smith
1999 A conf
GECCO
G. F. Davenport, M. D. Ryan, Victor J. Rayward-Smith
1998 A conf
PPSN
R. J. Quick, Victor J. Rayward-Smith, G. D. Smith
1998 J jnl
J. Oper. Res. Soc.
Victor J. Rayward-Smith
1998 J jnl
J. Oper. Res. Soc.
Victor J. Rayward-Smith
1997 J jnl
J. Intell. Inf. Syst.
Justin C. W. Debuse, Victor J. Rayward-Smith
1997 conf
ICGA
Anthony J. Bagnall, Geoff P. McKeown, Victor J. Rayward-Smith
1996 A* conf
KDD
Beatriz de la Iglesia, Justin C. W. Debuse, Victor J. Rayward-Smith
1996 conf
Evolutionary Computing, AISB Workshop
R. J. Quick, Victor J. Rayward-Smith, G. D. Smith
1996 J jnl
RAIRO Theor. Informatics Appl.
Victor J. Rayward-Smith, Djamal Rebaine
1995 J jnl
Notre Dame J. Formal Log.
Mike S. Joy, Victor J. Rayward-Smith
1995 conf
Evolutionary Computing, AISB Workshop
A. Kapsalis, Pierre Chardaire, Victor J. Rayward-Smith, G. D. Smith
1995 conf
ICANNGA
A. Kapsalis, Victor J. Rayward-Smith, G. D. Smith
1994 conf
Evolutionary Computing, AISB Workshop
A. Kapsalis, G. D. Smith, Victor J. Rayward-Smith
1994 J jnl
J. Funct. Program.
F. Warren Burton, Victor J. Rayward-Smith
1993 J jnl
Ann. Oper. Res.
Victor J. Rayward-Smith, S. A. Rush, Geoff P. McKeown
1992 J jnl
RAIRO Theor. Informatics Appl.
Victor J. Rayward-Smith, Djamal Rebaine
1991 J jnl
Ann. Oper. Res.
Geoff P. McKeown, Victor J. Rayward-Smith, Heather Jane Turpin
1991 J jnl
Ann. Oper. Res.
J. Luis A. Yebra, Victor J. Rayward-Smith, A. P. Revitt
1990 J jnl
Comput. J.
F. Warren Burton, Geoff P. McKeown, Victor J. Rayward-Smith
1988 J jnl
Inf. Process. Lett.
F. Warren Burton, Geoff P. McKeown, Victor J. Rayward-Smith
1988 J jnl
New Gener. Comput.
Victor J. Rayward-Smith, Geoff P. McKeown, F. Warren Burton
1987 J jnl
Inf. Process. Lett.
Victor J. Rayward-Smith
1987 J jnl
Discret. Appl. Math.
Victor J. Rayward-Smith
1986 J jnl
Networks
Victor J. Rayward-Smith, A. Clare
1985 J jnl
Comput. Lang.
Mike S. Joy, Victor J. Rayward-Smith, F. Warren Burton
1984 J jnl
Comput. Lang.
K. Hammond, Victor J. Rayward-Smith
1984 J jnl
Inf. Process. Lett.
Geoff P. McKeown, Victor J. Rayward-Smith
1983 J jnl
Discret. Appl. Math.
L. B. Wilson, C. S. Edwards, Victor J. Rayward-Smith
1980 J jnl
Inf. Process. Lett.
Victor J. Rayward-Smith, R. N. Rolph
1979 J jnl
ACM Trans. Math. Softw.
Victor J. Rayward-Smith
1977 J jnl
J. Comput. Syst. Sci.
Victor J. Rayward-Smith
1977 conf
Strathclyde ALGOL 68 Conference
Victor J. Rayward-Smith
redb/extractors/elf_extractors/elf_exports.py
← Index redb/extractors/elf_extractors/elf_exports.py python
import inspect
from datetime import datetime, timezone
from typing import Any, List, Set

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFExport


class ELFExportExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_exports = None
        self.elastic_index = self.index_prefix + "-elf_exports"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _get_exported_functions_from_symbols(self, elf) -> Set[str]:
        """Extract exported functions from symbol tables."""
        exported_functions = set()

        try:
            # Check both static (.symtab) and dynamic (.dynsym) symbol tables
            symbol_sections = ['.symtab', '.dynsym']

            for section_name in symbol_sections:
                section = elf.get_section_by_name(section_name)
                if not section or not hasattr(section, 'iter_symbols'):
                    continue

                for symbol in section.iter_symbols():
                    # Check if symbol is exported (defined and globally visible)
                    if (symbol.name and
                        symbol.entry.get('st_shndx', 0) != 'SHN_UNDEF' and  # Not undefined
                        symbol.entry.get('st_info', {}).get('bind') in ['STB_GLOBAL', 'STB_WEAK'] and  # Global or weak binding
                        symbol.entry.get('st_info', {}).get('type') in ['STT_FUNC', 'STT_OBJECT']):  # Function or object

                        # Additional checks for meaningful exports
                        if (symbol.entry.get('st_value', 0) > 0 or  # Has a value
                            symbol.entry.get('st_size', 0) > 0):    # Has a size
                            exported_functions.add(symbol.name)

        except Exception as e:
            self.log.error(f"Error extracting exported functions from symbols: {e}")

        return exported_functions

    def _get_exported_functions_from_dynamic_section(self, elf) -> Set[str]:
        """Extract exported functions information from dynamic section."""
        exported_functions = set()

        try:
            # Get the dynamic section
            dynamic_section = elf.get_section_by_name('.dynamic')
            if not dynamic_section:
                return exported_functions

            # Look for version definition sections that might indicate exports
            # This is complementary to symbol table analysis
            for tag in dynamic_section.iter_tags():
                if tag.entry.d_tag == 'DT_SONAME':
                    # If it has a SONAME, it's likely a shared library with exports
                    # The actual exports are still found in symbol tables
                    pass

        except Exception as e:
            self.log.error(f"Error extracting exports from dynamic section: {e}")

        return exported_functions

    def _filter_meaningful_exports(self, exports: Set[str]) -> Set[str]:
        """Filter out compiler-generated and internal symbols to focus on meaningful exports."""
        filtered_exports = set()

        # Common patterns to exclude (compiler-generated, internal symbols)
        exclude_patterns = [
            '_start',
            '_init',
            '_fini',
            '__libc_',
            '__gmon_start__',
            '_IO_stdin_used',
            '__data_start',
            '__bss_start',
            '_edata',
            '_end',
            '__TMC_END__',
            '_ITM_deregisterTMCloneTable',
            '_ITM_registerTMCloneTable',
            '__cxa_finalize',
            '__gxx_personality_v0',
            '_Jv_RegisterClasses'
        ]

        for export in exports:
            # Skip empty or very short names
            if not export or len(export) < 2:
                continue

            # Skip symbols that match exclude patterns
            skip = False
            for pattern in exclude_patterns:
                if export.startswith(pattern):
                    skip = True
                    break

            # Skip symbols that look like internal mangled names (but keep reasonable C++ names)
            if export.startswith('_Z') and len(export) > 50:  # Very long mangled names
                skip = True

            if not skip:
                filtered_exports.add(export)

        return filtered_exports

    def tag(self):
        return Tag.ELF_EXPORTS.value if hasattr(Tag, 'ELF_EXPORTS') else "elf_exports"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_data(elf):
                # Extract exported functions from multiple sources
                exported_functions = set()

                # From symbol tables (primary source)
                symbol_exports = self._get_exported_functions_from_symbols(elf)
                exported_functions.update(symbol_exports)

                # From dynamic section (supplementary)
                dynamic_exports = self._get_exported_functions_from_dynamic_section(elf)
                exported_functions.update(dynamic_exports)

                # Filter out compiler-generated and internal symbols
                meaningful_exports = self._filter_meaningful_exports(exported_functions)

                # Convert to sorted list for consistent output
                export_functions_list = sorted(list(meaningful_exports))

                # Return ELFExport dataclass
                return ELFExport(
                    elf_exports_total=len(export_functions_list),
                    elf_export_functions=export_functions_list,
                )

            if not self._is_elf_file():
                return None

            result = self._with_elf_file(extract_data)
            if result is None:
                return None

            self.elf_exports = result
            return self.elf_exports

        except Exception as e:
            self.log.error(f"Error extracting ELF exports {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_exports
        elif exporter_type == "ClickHouseExporter":
            try:
                if not self.elf_exports:
                    return None

                # Prepare data array
                data = [[
                    self.sha256,
                    self.md5,
                    self.sha1,
                    self.elf_exports.elf_exports_total,
                    self.elf_exports.elf_export_functions,
                    datetime.now(timezone.utc)
                ]]

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'elf_exports_total',
                    'elf_export_functions',
                    'analysis_date'
                ]

                if not data:
                    return None

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    'UInt32',
                    'Array(LowCardinality(String))',
                    'DateTime64(3, \'UTC\')'
                ]

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_exports"