Vijay Kumar

88 papers A* 3A 2B 7C 4Misc 5Journal 27Unranked 35
YearRankTypeTitle / Venue / Authors
2016 conf
COMPSAC Workshops
Mahesh Nath Maddumala, Vijay Kumar
2016 J jnl
J. Inf. Secur. Appl.
Chetan Jaiswal, Vijay Kumar
2015 conf
MDM (2)
Mahesh Nath Maddumala, Vijay Kumar
2015 conf
SITIS
Chetan Jaiswal, Vijay Kumar
2015 conf
MDM (2)
Chetan Jaiswal, Vijay Kumar
2015 conf
LCN Workshops
Chetan Jaiswal, Vijay Kumar
2014 J jnl
IEEE Trans. Parallel Distributed Syst.
Vijay Kumar
2014 J jnl
IEEE Cloud Comput.
Chetan Jaiswal, Mahesh Nath Maddumala, Vijay Kumar
2013 J jnl
Int. J. Commun. Networks Distributed Syst.
Cory C. Beard, Zhiqiang Chen, Vijay Kumar, Yugyung Lee, W. Daniel Leon-Salas, Praveen Rao
2012 J jnl
Int. J. Next Gener. Comput.
Vijay Kumar
2012 J jnl
Int. J. Comput. Heal.
Debopam Acharya, Vijay Kumar
2012 B conf
SRDS
Chetan Jaiswal, Vijay Kumar
2012 conf
MobileHealth@MobiHoc
Debopam Acharya, Vijay Kumar, Hyo-Joo Han
2011 conf
CTS
Amol Khekdar, Vijay Kumar
2011 conf
ANT/MobiWIS
Debopam Acharya, Vijay Kumar
2010 conf
PIKM
Debargh Acharya, Vijay Kumar
2010 B ed.
Mobile Data Management
Takahiro Hara, Christian S. Jensen, Vijay Kumar, Sanjay Madria, Demetrios Zeinalipour-Yazti
2010 B conf
Mobile Data Management
Amol Khekdar, Vijay Kumar
2010 Misc conf
IKE
Amol Khekdar, Vijay Kumar
2008 J jnl
Int. J. Intell. Def. Support Syst.
Debopam Acharya, Vijay Kumar, Gary M. Gaddis, Nicholas Garvin
2007 J jnl
Distributed Parallel Databases
Sanjay Kumar Madria, Mohammed Baseer, Vijay Kumar, Sourav S. Bhowmick
2007 Misc conf
SAC
Debopam Acharya, Vijay Kumar, Gi-Chul Yang
2006 ed.
MobiDE
Panos K. Chrysanthis, Christian S. Jensen, Vijay Kumar, Alexandros Labrinidis
2006 conf
DEXA Workshops
Vijay Kumar
2005 B conf
Mobile Data Management
Nitin Prabhu, Vijay Kumar
2005 C conf
AICCSA
Vijay Kumar, Nitin Prabhu, Panos K. Chrysanthis
2005 J jnl
J. Digit. Inf. Manag.
Debopam Acharya, Vijay Kumar
2005 conf
MobiDE
Debopam Acharya, Vijay Kumar
2005 J jnl
Comput. Syst. Sci. Eng.
Vijay Kumar, Margaret H. Dunham, Nitin Prabhu
2005 ed.
MobiDE
Vijay Kumar, Arkady B. Zaslavsky, Ugur Çetintemel, Alexandros Labrinidis
2005 J jnl
SIGMOD Rec.
Sujata Banerjee, Mitch Cherniack, Panos K. Chrysanthis, Vijay Kumar, Alexandros Labrinidis
2005 J jnl
Ingénierie des Systèmes d Inf.
Vijay Kumar, Debopam Acharya
2004 Misc conf
ICDCIT
Pradeep Parvathipuram, Vijay Kumar, Gi-Chul Yang
2004 conf
AINA (2)
Nitin Prabhu, Vijay Kumar, Indrakshi Ray, Gi-Chul Yang
2004 Misc conf
ICDCIT
Vijay Kumar
2004 conf
TES
Debopam Acharya, Nitin Prabhu, Vijay Kumar
2004 J jnl
Mob. Networks Appl.
Arkady B. Zaslavsky, Panos K. Chrysanthis, Vijay Kumar
2004 conf
ISTA
Nitin Prabhu, Vijay Kumar, Indrakshi Ray
2004 conf
BNCOD
Indrakshi Ray, Ross M. McConnell, Monte Lunacek, Vijay Kumar
2003 A* conf
ICDE
Panos K. Chrysanthis, Vijay Kumar, Evaggelia Pitoura
2003 conf
DEXA Workshops
Nimisha Garg, Vijay Kumar, Margaret H. Dunham
2003 J jnl
IEEE Trans. Knowl. Data Eng.
Qun Ren, Margaret H. Dunham, Vijay Kumar
2003 J jnl
SIGMOD Rec.
Vijay Kumar
2002 Misc conf
SAC
Deendayal Dinakarpandian, Vijay Kumar
2002 B conf
Mobile Data Management
Vinod Vulupala, Vijay Kumar
2002 ed.
ER (Workshops)
Hiroshi Arisawa, Yahiko Kambayashi, Vijay Kumar, Heinrich C. Mayr, Ingrid Hunt
2002 conf
DEXA Workshops
Sanjay Kumar Madria, Vijay Kumar, Evaggelia Pitoura
2002 J jnl
IEEE Trans. Computers
Vijay Kumar, Nitin Prabhu, Margaret H. Dunham, Ayse Yasemin Seydim
2001 conf
DEXA Workshop
Ayse Yasemin Seydim, Margaret H. Dunham, Vijay Kumar
2001 conf
WECWIS
Kiran Chelluri, Vijay Kumar
2001 conf
WECWIS
Margaret H. Dunham, Ahmad S. Al-Mogren, Ayse Yasemin Seydim, Vijay Kumar
2001 conf
MobiDE
Ayse Yasemin Seydim, Margaret H. Dunham, Vijay Kumar
2000 conf
ADBIS-DASFAA
Sanjay Kumar Madria, Bharat K. Bhargava, Evaggelia Pitoura, Vijay Kumar
2000 J jnl
IEEE Trans. Computers
Anindya Datta, Sang Hyuk Son, Vijay Kumar
2000 conf
Kyoto International Conference on Digital Libraries
Mukesh K. Mohania, Vijay Kumar, Yahiko Kambayashi, Bharat K. Bhargava
1999 J jnl
ACM Trans. Database Syst.
Anindya Datta, Debra E. VanderMeer, Aslihan Celik, Vijay Kumar
1999 conf
MobiDE
Vijay Kumar
1999 A conf
CIKM
Sunil Samtani, Vijay Kumar, Mukesh K. Mohania
1998 conf
DEXA Workshop
Margaret H. Dunham, Vijay Kumar
1998 conf
DEXA Workshop
Sunil Samtani, Vijay Kumar
1998 conf
ER Workshops
Sunil Samtani, Mukesh K. Mohania, Vijay Kumar, Yahiko Kambayashi
1997 conf
RTDB
Anindya Datta, Igor R. Viguier, Sang Hyuk Son, Vijay Kumar
1997 A* conf
ICDE
Anindya Datta, Aslihan Celik, Jeong Geun Kim, Debra E. VanderMeer, Vijay Kumar
1997 B conf
LCN
Raju V. J. Chintalapati, Vijay Kumar, Anindya Datta
1997 J jnl
Data Knowl. Eng.
Vijay Kumar
1997 J jnl
Inf. Sci.
Albert Burger, Vijay Kumar, Mary Lou Hines
1996 ch.
Performance of Concurrency Control Mechanisms in Centralized Database Systems
Vijay Kumar
1996 book
Vijay Kumar
1996 C conf
DEXA
Vijay Kumar
1995 J jnl
Data Knowl. Eng.
Vijay Kumar, Judy Mullins
1993 B conf
COMPSAC
Vijay Kumar, Judy Mullins
1992 conf
ACM Conference on Computer Science
Judy Mullins, Vijay Kumar
1992 J jnl
IEEE Trans. Knowl. Data Eng.
Vijay Kumar, Albert Burger
1992 conf
ACM Conference on Computer Science
Albert Burger, Vijay Kumar
1991 J jnl
IEEE Trans. Knowl. Data Eng.
Vijay Kumar, Jerry Place, Gi-Chul Yang
1991 conf
VDB
Albert Burger, Vijay Kumar, Patricia Simpson
1991 C conf
DEXA
Vijay Kumar, James Mumper
1991 A* conf
ICDE
Vijay Kumar, Albert Burger
1990 conf
ACM Conference on Computer Science
Albert Burger, Vijay Kumar
1990 J jnl
Commun. ACM
Vijay Kumar
1990 A conf
ACSAC
Elizabeth A. Unger, Lein Harn, Vijay Kumar
1990 conf
SPDP
Vijay Kumar, Albert Burger
1990 J jnl
Inf. Sci.
Vijay Kumar
1990 C conf
ICCI
Jerry Place, Vijay Kumar, Appie van de Liefvoort
1989 conf
ACM Conference on Computer Science
Vijay Kumar
1989 conf
IFIP Congress
Vijay Kumar, Jerry Place, Gi-Chul Yang
1989 J jnl
Inf. Syst.
Vijay Kumar
1989 J jnl
Inf. Process. Lett.
Vijay Kumar
docs/CODE_ANALYSIS_APPROACH.md
← Index docs/CODE_ANALYSIS_APPROACH.md markdown
# Code Analysis Approach

This document explains the code analysis methodologies used in the REDB malware analysis framework.

## Disassembly Normalization

The framework implements a sophisticated three-level normalization strategy for disassembled code that provides different levels of abstraction for similarity detection and feature extraction.

### Overall Normalization Strategy

The framework implements a **hierarchical abstraction approach** where each instruction is normalized at three different levels simultaneously:

1. **Level 0 (fully_normalized)**: Maximum abstraction - reduces operands to broad categories
2. **Level 1 (api_normalized)**: Medium abstraction - preserves semantic meaning while normalizing details  
3. **Level 2 (category_normalized)**: Minimum abstraction - maintains architectural specificity

This multi-level approach allows analysts to perform similarity analysis at different granularities depending on their specific detection goals.

### Implementation Architecture

The normalization process follows this workflow:

1. **Token Parsing**: Each instruction is parsed from Binary Ninja's instruction tokens to extract the mnemonic and operands
2. **Multi-Level Processing**: Each operand is processed through all three normalization functions
3. **Instruction Reconstruction**: Normalized instructions are rebuilt with the mnemonic plus normalized operands
4. **Control Flow Tagging**: Control flow instructions get a `<TARGET>` suffix for easier pattern matching

### Level 0: Fully Normalized (Maximum Abstraction)

**Purpose**: Creates the most abstract representation for broad pattern detection across different malware families.

**Transformations**:
- **Registers**: All registers normalized to semantic categories via `normalize_register()`:
  - General purpose registers (EAX, EBX, R8, etc.) → `GPR`
  - Stack/Base pointers (ESP, EBP, RSP) → `PTR` 
  - SIMD registers (XMM0, XMM1) → `XMM`
  - FPU registers (ST0, ST1) → `FPU`
- **Memory Operations**: All memory references → `MEM`
- **Constants**: All immediate values → `CONST`  
- **Data References**: All symbols/data references → `DATA_REF`

**Example**:
```
mov eax, [ebp+8]     → MOV GPR MEM
call CreateFileW     → CALL DATA_REF <TARGET>
add ecx, 0x10        → ADD GPR CONST
```

### Level 1: API Normalized (Medium Abstraction)

**Purpose**: Preserves semantic distinctions while normalizing architectural details. Focuses on behavioral patterns and API usage.

**Transformations**:
- **Registers**: Categorized by functional role:
  - Data registers → `GPR_DATA`
  - Index registers (ESI, EDI) → `GPR_INDEX`  
  - Stack registers (ESP, EBP) → `GPR_STACK`
  - SIMD registers → `XMM_REG`
- **Memory Operations**: Classified by access pattern:
  - Stack access → `MEM_STACK`
  - String operations → `MEM_STRING` 
  - General access → `MEM_GENERAL`
- **Constants**: Categorized by range:
  - Small constants (-16 to 16) → `CONST_{value}`
  - Large constants → `CONST_LARGE`
- **API Calls**: Resolved to specific API names:
  - `CreateFileW` → `API_CreateFileW`
  - Other symbols → `DATA_SYM`

**Example**:
```
mov eax, [ebp+8]     → MOV GPR_DATA MEM_STACK
call CreateFileW     → CALL API_CreateFileW <TARGET>
add ecx, 0x10        → ADD GPR_DATA CONST_LARGE
```

### Level 2: Category Normalized (Minimum Abstraction)

**Purpose**: Maintains architectural specificity while normalizing specific values. Best for detecting variants with similar implementation details.

**Transformations**:
- **Registers**: Architecture-specific categories:
  - 64-bit registers → `REG_64`, with special cases for `REG_64_SP`, `REG_64_BP`
  - 32-bit registers → `REG_32`
  - 16/8-bit registers → `REG_16_8`
- **Memory Operations**: Detailed addressing mode classification:
  - Complex addressing → `MEM_SCALED_INDEX`
  - Base + offset → `MEM_BASE_OFFSET`
  - Direct addressing → `MEM_DIRECT`
- **Constants**: Type-specific classification:
  - Hexadecimal → `CONST_HEX`
  - Decimal → `CONST_DEC`
- **API Calls**: Categorized by functional group:
  - File operations → `API_FILE_OP`
  - Memory operations → `API_MEMORY_OP`
  - Network operations → `API_NETWORK_OP`

**Example**:
```
mov eax, [ebp+8]     → MOV REG_32 MEM_BASE_OFFSET
call CreateFileW     → CALL API_FILE_OP <TARGET>
add ecx, 0x10        → ADD REG_32 CONST_HEX
```

### Key Features and Benefits

#### 1. Multi-Granularity Similarity Detection
- **Level 0**: Detects broad behavioral patterns across malware families
- **Level 1**: Identifies API usage patterns and semantic similarities
- **Level 2**: Finds variants with similar implementation approaches

#### 2. Robust Pattern Matching
- Control flow instructions tagged with `<TARGET>` for easier CFG analysis
- Handles edge cases with fallback mechanisms
- Consistent uppercase normalization prevents case sensitivity issues

#### 3. API-Aware Analysis
The framework includes sophisticated API recognition through the `ApiCategory` enum and resolution methods:
- **File Operations**: CreateFile, ReadFile, WriteFile, etc.
- **Memory Operations**: VirtualAlloc, HeapAlloc, VirtualProtect, etc.  
- **Registry Operations**: RegOpenKey, RegSetValue, etc.
- **Network Operations**: WSASocket, send, recv, etc.
- **Process Operations**: CreateProcess, OpenProcess, etc.

#### 4. Scalable Feature Extraction
Each level produces different hash values for the same function:
- `fully_normalized_disassembly_hash`
- `api_normalized_disassembly_hash`  
- `category_normalized_disassembly_hash`

This enables efficient similarity searches at different abstraction levels in the ClickHouse database.

### Practical Applications for Malware Analysis

#### Threat Hunting Scenarios:

1. **Family Detection** (Level 0): Find samples using similar algorithmic approaches regardless of specific implementation
2. **Variant Analysis** (Level 1): Identify samples with similar API usage patterns and behavioral semantics
3. **Code Reuse Detection** (Level 2): Discover samples sharing specific implementation techniques or code fragments

#### Similarity Metrics Integration:
- Each normalization level can be used with different fuzzy hashing algorithms (ssdeep, TLSH, etc.)
- Level 0 works well with structural similarity metrics
- Level 1 optimal for behavioral similarity analysis  
- Level 2 suitable for implementation-specific pattern matching

This three-tiered approach provides malware analysts with flexible tools for detecting similarities across the threat landscape while maintaining the precision needed for detailed variant analysis.



---

*More code analysis approaches will be documented in additional sections as they are implemented.*