Viet-Man Le

55 papers A* 3A 4B 1Journal 18Unranked 26
YearRankTypeTitle / Venue / Authors
2026 ed.
ConfWS
Chiara Grosso, Enrico Sandrin, Viet-Man Le
2026 A* conf
AAAI
Viet-Man Le, Lukas André Feldgrill, Alexander Felfernig
2025 B conf
ICTAI
Sebastian Lubos, Alexander Felfernig, Damian Garber, Viet-Man Le
2025 conf
VaMoS
Alexander Felfernig, Damian Garber, Viet-Man Le, Sebastian Lubos
2025 conf
IEA/AIE (1)
Damian Garber, Sebastian Lubos, Viet-Man Le, Alexander Felfernig
2025 conf
UMAP (Adjunct Publication)
Sebastian Lubos, Alexander Felfernig, Damian Garber, Viet-Man Le, Manuel Henrich, Reinhard Willfort, Ivan Dukic
2025 J jnl
J. Intell. Inf. Syst.
Mathias Uta, Viet-Man Le, Alexander Felfernig, Denis Helic
2025 conf
ConfWS@ECAI
Alexander Felfernig, Damian Garber, Viet-Man Le, Sebastian Lubos
2025 conf
RecSoGood@RecSys
Alexander Felfernig, Damian Garber, Viet-Man Le, Sebastian Lubos, Thi Ngoc Trang Tran
2025 J jnl
CoRR
Alexander Felfernig, Damian Garber, Viet-Man Le, Sebastian Lubos, Thi Ngoc Trang Tran
2025 conf
UMAP (Adjunct Publication)
Sebastian Lubos, Alexander Felfernig, Damian Garber, Viet-Man Le, Manuel Henrich, Reinhard Willfort, Jeremias Fuchs
2025 J jnl
CoRR
Sebastian Lubos, Alexander Felfernig, Damian Garber, Viet-Man Le, Thi Ngoc Trang Tran
2025 J jnl
CoRR
Sebastian Lubos, Alexander Felfernig, Thi Ngoc Trang Tran, Viet-Man Le, Damian Garber, Manuel Henrich, Reinhard Willfort, Jeremias Fuchs
2025 conf
ConfWS@ECAI
Alexander Felfernig, Damian Garber, Viet-Man Le, Sebastian Lubos, Thi Ngoc Trang Tran
2025 J jnl
CoRR
Alexander Felfernig, Damian Garber, Viet-Man Le, Sebastian Lubos, Thi Ngoc Trang Tran
2024 conf
ConfWS
Damian Garber, Alexander Felfernig, Viet-Man Le, Tamim Burgstaller, Merfat El Mansi
2024 A* conf
AAAI
Viet-Man Le, Alexander Felfernig, Thi Ngoc Trang Tran, Mathias Uta
2024 J jnl
Frontiers Big Data
Mathias Uta, Alexander Felfernig, Viet-Man Le, Thi Ngoc Trang Tran, Damian Garber, Sebastian Lubos, Tamim Burgstaller
2024 conf
UMAP (Adjunct Publication)
Sebastian Lubos, Thi Ngoc Trang Tran, Alexander Felfernig, Seda Polat Erdeniz, Viet-Man Le
2024 A conf
RecSys
Thi Ngoc Trang Tran, Seda Polat Erdeniz, Alexander Felfernig, Sebastian Lubos, Merfat El Mansi, Viet-Man Le
2024 J jnl
CoRR
Thi Ngoc Trang Tran, Seda Polat Erdeniz, Alexander Felfernig, Sebastian Lubos, Merfat El Mansi, Viet-Man Le
2024 A conf
RE
Sebastian Lubos, Alexander Felfernig, Thi Ngoc Trang Tran, Damian Garber, Merfat El Mansi, Seda Polat Erdeniz, Viet-Man Le
2024 J jnl
CoRR
Sebastian Lubos, Alexander Felfernig, Thi Ngoc Trang Tran, Damian Garber, Merfat El Mansi, Seda Polat Erdeniz, Viet-Man Le
2024 conf
SPLC (A)
Tamim Burgstaller, Damian Garber, Viet-Man Le, Alexander Felfernig
2024 J jnl
CoRR
Alexander Felfernig, Manfred Wundara, Thi Ngoc Trang Tran, Seda Polat Erdeniz, Sebastian Lubos, Merfat El Mansi, Damian Garber, Viet-Man Le
2024 J jnl
Frontiers Big Data
Alexander Felfernig, Manfred Wundara, Thi Ngoc Trang Tran, Seda Polat Erdeniz, Sebastian Lubos, Merfat El Mansi, Damian Garber, Viet-Man Le
2024 conf
ConfWS
Sebastian Lubos, Alexander Felfernig, Lothar Hotz, Thi Ngoc Trang Tran, Seda Polat Erdeniz, Viet-Man Le, Damian Garber, Merfat El Mansi
2024 conf
ConfWS
Mathias Uta, Viet-Man Le, Alexander Felfernig, Damian Garber, Gottfried Schenner, Thi Ngoc Trang Tran
2024 J jnl
J. Intell. Inf. Syst.
Alexander Felfernig, Manfred Wundara, Thi Ngoc Trang Tran, Viet-Man Le, Sebastian Lubos, Seda Polat Erdeniz
2023 conf
SPLC (A)
Sebastian Lubos, Alexander Felfernig, Viet-Man Le, Thi Ngoc Trang Tran, David Benavides, José A. Zamudio, Damian Garber
2023 A conf
RecSys
Sebastian Lubos, Viet-Man Le, Alexander Felfernig, Thi Ngoc Trang Tran
2023 conf
ConfWS
Damian Garber, Tamim Burgstaller, Alexander Felfernig, Viet-Man Le, Sebastian Lubos, Trang Tran, Seda Polat Erdeniz
2023 J jnl
CoRR
Alexander Felfernig, Viet-Man Le, Sebastian Lubos
2023 A* conf
AAAI
Viet-Man Le, Cristian Vidal Silva, Alexander Felfernig, David Benavides, José A. Galindo, Thi Ngoc Trang Tran
2023 A conf
ECAI
Viet-Man Le, Thi Ngoc Trang Tran, Alexander Felfernig
2023 J jnl
CoRR
Viet-Man Le, Cristian Vidal Silva, Alexander Felfernig, David Benavides, José A. Galindo, Thi Ngoc Trang Tran
2023 conf
ConfWS
Alexander Felfernig, Viet-Man Le, Albert Haag, Sebastian Lubos
2023 conf
ConfWS
Benjamin Ritz, Alexander Felfernig, Viet-Man Le, Sebastian Lubos
2023 J jnl
CoRR
Benjamin Ritz, Alexander Felfernig, Viet-Man Le, Sebastian Lubos
2023 conf
ConfWS
Sebastian Lubos, Alexander Felfernig, Viet-Man Le
2023 J jnl
CoRR
Alexander Felfernig, Manfred Wundara, Thi Ngoc Trang Tran, Viet-Man Le, Sebastian Lubos, Seda Polat Erdeniz
2022 conf
SPLC (A)
Mathias Uta, Alexander Felfernig, Denis Helic, Viet-Man Le
2022 J jnl
J. Intell. Inf. Syst.
Andrei Popescu, Seda Polat Erdeniz, Alexander Felfernig, Mathias Uta, Müslüm Atas, Viet-Man Le, Klaus Pilsl, Martin Enzelsberger, Thi Ngoc Trang Tran
2022 conf
SPLC (B)
Viet-Man Le, Thi Ngoc Trang Tran, Alexander Felfernig
2022 conf
SPLC (B)
Sebastian Lubos, Markus Tautschnig, Alexander Felfernig, Viet-Man Le
2022 ed.
SPLC (A)
Alexander Felfernig, Lidia Fuentes, Jane Cleland-Huang, Wesley K. G. Assunção, Andreas A. Falkner, Maider Azanza, Miguel Á. Rodríguez Luaces, Megha Bhushan, Laura Semini, Xavier Devroey, Cláudia Maria Lima Werner, Christoph Seidl, Viet-Man Le, José Miguel Horcas
2022 ed.
SPLC (B)
Alexander Felfernig, Lidia Fuentes, Jane Cleland-Huang, Wesley K. G. Assunção, Clément Quinton, Jianmei Guo, Klaus Schmid, Marianne Huchard, Inmaculada Ayala, José Miguel Rojas, Viet-Man Le, José Miguel Horcas
2022 conf
SPLC (B)
Alexander Felfernig, Bettina Ortner, Viet-Man Le
2022 conf
SPLC (B)
Viet-Man Le, Alexander Felfernig, Thi Ngoc Trang Tran
2022 conf
SPLC (A)
Viet-Man Le, Alexander Felfernig, Mathias Uta, Thi Ngoc Trang Tran, Cristian Vidal Silva
2021 conf
ConfWS
Alexander Felfernig, Andrei Popescu, Mathias Uta, Viet-Man Le, Seda Polat Erdeniz, Martin Stettinger, Müslüm Atas, Thi Ngoc Trang Tran
2021 J jnl
CoRR
Alexander Felfernig, Andrei Popescu, Mathias Uta, Viet-Man Le, Seda Polat Erdeniz, Martin Stettinger, Müslüm Atas, Thi Ngoc Trang Tran
2021 conf
ConfWS
Viet-Man Le, Thi Ngoc Trang Tran, Martin Stettinger, Lisa Weißl, Alexander Felfernig, Müslüm Atas, Seda Polat Erdeniz, Andrei Popescu
2021 conf
ICSE (Companion Volume)
Viet-Man Le
2021 J jnl
CoRR
Viet-Man Le
redb/extractors/elf_extractors/elf_notes.py
← Index redb/extractors/elf_extractors/elf_notes.py python
import inspect
import binascii
from datetime import datetime, timezone
from typing import Any, List, Dict

from elftools.elf.elffile import ELFFile
from elftools.common.exceptions import ELFError

from redb.extractors.enum import Tag
from redb.extractors.elf_extractor import ELFExtractor
from redb.models.dataclasses import ELFNote


class ELFNotesExtractor(ELFExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        elf=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            elf,
        )
        self.elf_notes = []
        self.elastic_index = self.index_prefix + "-elf_notes"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def _get_note_type_string(self, note_type: int, note_name: str) -> str:
        """Convert note type number to human-readable string."""

        # GNU-specific note types
        if note_name == "GNU":
            gnu_types = {
                1: "NT_GNU_ABI_TAG",
                2: "NT_GNU_HWCAP",
                3: "NT_GNU_BUILD_ID",
                4: "NT_GNU_GOLD_VERSION",
                5: "NT_GNU_PROPERTY_TYPE_0"
            }
            return gnu_types.get(note_type, f"NT_GNU_UNKNOWN_{note_type}")

        # Generic note types
        generic_types = {
            1: "NT_PRSTATUS",
            2: "NT_FPREGSET",
            3: "NT_PRPSINFO",
            4: "NT_TASKSTRUCT",
            5: "NT_AUXV",
            6: "NT_PSTATUS",
            7: "NT_FPREGS",
            8: "NT_PSINFO",
            9: "NT_PRCRED",
            10: "NT_UTSNAME",
            11: "NT_LWPSTATUS",
            12: "NT_LWPSINFO",
            13: "NT_PRFPXREG"
        }

        return generic_types.get(note_type, f"NT_UNKNOWN_{note_type}")

    def _format_note_description(self, note_desc, note_type: int, note_name: str) -> str:
        """Format note description based on type for human readability."""
        try:
            if not note_desc:
                return ""

            # Handle build ID specifically (common case)
            if note_name == "GNU" and note_type == 3:  # NT_GNU_BUILD_ID
                if isinstance(note_desc, bytes):
                    return binascii.hexlify(note_desc).decode('ascii')
                return str(note_desc)

            # Handle ABI tag
            if note_name == "GNU" and note_type == 1:  # NT_GNU_ABI_TAG
                if isinstance(note_desc, bytes) and len(note_desc) >= 16:
                    # ABI tag contains OS, major, minor, subminor
                    import struct
                    try:
                        os_val, major, minor, subminor = struct.unpack('<IIII', note_desc[:16])
                        os_names = {0: "Linux", 1: "GNU", 2: "Solaris", 3: "FreeBSD"}
                        os_name = os_names.get(os_val, f"OS_{os_val}")
                        return f"{os_name} {major}.{minor}.{subminor}"
                    except:
                        pass

            # For binary data, convert to hex
            if isinstance(note_desc, bytes):
                # Limit size for very large descriptions
                if len(note_desc) > 256:
                    return binascii.hexlify(note_desc[:256]).decode('ascii') + "..."
                return binascii.hexlify(note_desc).decode('ascii')

            # For string data
            if isinstance(note_desc, str):
                return note_desc

            # Fallback
            return str(note_desc)

        except Exception as e:
            self.log.error(f"Error formatting note description: {e}")
            return str(note_desc) if note_desc else ""

    def _extract_note_data(self, note, section_name: str) -> ELFNote:
        """Extract data from a single note entry."""
        try:
            # Get note properties
            note_name = note.get('n_name', '').rstrip('\x00') if note.get('n_name') else ""
            note_type_raw = note.get('n_type', 0)
            note_desc_raw = note.get('n_desc', b'')

            # Handle note_type - pyelftools may return string or int
            if isinstance(note_type_raw, str):
                # pyelftools returned the type as a string like 'NT_GNU_BUILD_ID'
                note_type_str = note_type_raw
                # Map known string types to integers
                note_type_map = {
                    'NT_GNU_ABI_TAG': 1,
                    'NT_GNU_HWCAP': 2,
                    'NT_GNU_BUILD_ID': 3,
                    'NT_GNU_GOLD_VERSION': 4,
                    'NT_GNU_PROPERTY_TYPE_0': 5,
                    'NT_PRSTATUS': 1,
                    'NT_FPREGSET': 2,
                    'NT_PRPSINFO': 3,
                    'NT_TASKSTRUCT': 4,
                    'NT_AUXV': 5,
                    'NT_PSTATUS': 6,
                    'NT_FPREGS': 7,
                    'NT_PSINFO': 8,
                    'NT_PRCRED': 9,
                    'NT_UTSNAME': 10,
                    'NT_LWPSTATUS': 11,
                    'NT_LWPSINFO': 12,
                    'NT_PRFPXREG': 13,
                }
                note_type = note_type_map.get(note_type_raw, 0)
            else:
                note_type = note_type_raw
                # Get human-readable type string
                note_type_str = self._get_note_type_string(note_type, note_name)

            # Format description
            note_desc = self._format_note_description(note_desc_raw, note_type, note_name)

            return ELFNote(
                note_name=note_name,
                note_type=note_type,
                note_type_str=note_type_str,
                note_desc=note_desc,
                note_section=section_name
            )

        except Exception as e:
            self.log.error(f"Error extracting note data: {e}")
            return None

    def _extract_notes_from_sections(self, elf) -> List[Dict]:
        """Extract notes from note sections."""
        notes = []

        try:
            # Look for note sections
            for section in elf.iter_sections():
                if (section.name and
                    section.name.startswith('.note') and
                    hasattr(section, 'iter_notes')):

                    section_name = section.name
                    try:
                        for note in section.iter_notes():
                            note_data = self._extract_note_data(note, section_name)
                            if note_data:
                                notes.append(note_data)
                    except Exception as e:
                        self.log.debug(f"Could not process notes in section {section_name}: {e}")

        except Exception as e:
            self.log.error(f"Error extracting notes from sections: {e}")

        return notes

    def _extract_notes_from_segments(self, elf) -> List[Dict]:
        """Extract notes from PT_NOTE segments."""
        notes = []

        try:
            # Look for PT_NOTE segments
            for segment in elf.iter_segments():
                if segment.header.get('p_type') == 'PT_NOTE':
                    segment_name = f"PT_NOTE_segment_{segment.header.get('p_offset', 0)}"

                    try:
                        if hasattr(segment, 'iter_notes'):
                            for note in segment.iter_notes():
                                note_data = self._extract_note_data(note, segment_name)
                                if note_data:
                                    notes.append(note_data)
                    except Exception as e:
                        self.log.debug(f"Could not process notes in segment: {e}")

        except Exception as e:
            self.log.error(f"Error extracting notes from segments: {e}")

        return notes

    def tag(self):
        return Tag.ELF_NOTES.value if hasattr(Tag, 'ELF_NOTES') else "elf_notes"

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)

            def extract_data(elf):
                all_notes = []

                # Extract notes from note sections
                section_notes = self._extract_notes_from_sections(elf)
                all_notes.extend(section_notes)

                # Extract notes from PT_NOTE segments
                segment_notes = self._extract_notes_from_segments(elf)
                all_notes.extend(segment_notes)

                # Remove duplicates (same note might appear in section and segment)
                unique_notes = []
                seen_notes = set()
                for note in all_notes:
                    note_key = (note.note_name, note.note_type, note.note_desc)
                    if note_key not in seen_notes:
                        seen_notes.add(note_key)
                        unique_notes.append(note)

                return unique_notes

            if not self._is_elf_file():
                return None

            result = self._with_elf_file(extract_data)
            if result is None:
                return None

            self.elf_notes = result
            return self.elf_notes

        except Exception as e:
            self.log.error(f"Error extracting ELF notes {self.hash.sha256}: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        self.log.debug(inspect.currentframe().f_code.co_name)

        if exporter_type == "ElasticsearchExporter":
            return self.elf_notes
        elif exporter_type == "ClickHouseExporter":
            try:
                # Return valid empty structure if no notes found
                # None is reserved for actual errors

                # Prepare data arrays for all notes
                data = []
                current_time = datetime.now(timezone.utc)
                for note in self.elf_notes:
                    row = [
                        self.sha256,
                        self.md5,
                        self.sha1,
                        note.note_name,
                        note.note_type,
                        note.note_type_str,
                        note.note_desc,
                        note.note_section,
                        current_time
                    ]
                    data.append(row)

                column_names = [
                    'sha256', 'md5', 'sha1',
                    'note_name', 'note_type', 'note_type_str',
                    'note_desc', 'note_section',
                    'analysis_date'
                ]

                if not data:
                    return None

                column_type_names = [
                    'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                    'LowCardinality(String)', 'UInt32', 'LowCardinality(String)',
                    'String CODEC(ZSTD(3))', 'LowCardinality(String)',
                    'DateTime64(3, \'UTC\')'
                ]

                return (data, column_names, column_type_names)

            except Exception as e:
                self.log.error(f"Error preparing export data: {e}")
                raise

    def get_clickhouse_table(self) -> str:
        return "redb_elf_notes"