Vincent F. Taylor

12 papers A* 1A 2Journal 4Unranked 4
YearRankTypeTitle / Venue / Authors
2018 J jnl
IEEE Trans. Inf. Forensics Secur.
Vincent F. Taylor, Riccardo Spolaor, Mauro Conti, Ivan Martinovic
2017 J jnl
CoRR
Vincent F. Taylor, Alastair R. Beresford, Ivan Martinovic
2017 J jnl
CoRR
Vincent F. Taylor, Riccardo Spolaor, Mauro Conti, Ivan Martinovic
2017
Vincent F. Taylor
2017 conf
Financial Cryptography
Vincent F. Taylor, Ivan Martinovic
2017 conf
WISEC
Vincent F. Taylor, Alastair R. Beresford, Ivan Martinovic
2017 A conf
AsiaCCS
Vincent F. Taylor, Ivan Martinovic
2016 J jnl
CoRR
Vincent F. Taylor, Ivan Martinovic
2016 A conf
EuroS&P
Vincent F. Taylor, Riccardo Spolaor, Mauro Conti, Ivan Martinovic
2016 A* conf
CCS
Vincent F. Taylor, Ivan Martinovic
2016 conf
SPSM@CCS
Vincent F. Taylor, Ivan Martinovic
2014 conf
WTS
Vincent F. Taylor, Daniel Fokum
redb/extractors/decompiler/bninja/analysis/strings.py
← Index redb/extractors/decompiler/bninja/analysis/strings.py python
from collections import Counter
import math

class StringAnalysis:
    def __init__(self, bv, functions):
        self.bv = bv
        self.functions = functions

    def entropy(self, s: str) -> float:
        """Compute Shannon entropy of a string."""
        if not s:
            return 0.0
        freq = Counter(s)
        length = len(s)
        return -sum((count / length) * math.log2(count / length) for count in freq.values())

    def analyze(self):
        """
        Extract unique strings from the binary.

        Deduplicates by (string, encoding) within the same binary, keeping the
        first occurrence (lowest offset). Cross-binary deduplication and
        aggregation is handled by ClickHouse materialized views.
        """
        strings = {}

        # Sort strings by their starting address
        sorted_entries = sorted(self.bv.strings, key=lambda e: e.start)

        for entry in sorted_entries:
            # Key is the string and its encoding
            key = (entry.value, entry.type.name)

            # Skip if this string (value + encoding) was already added.
            # Because entries are sorted by address, the first one is always kept.
            if key in strings:
                continue

            # Store only the first occurrence with schema-matching field names
            # entry.length is the raw byte length, len(entry.value) is decoded string length
            string_entry = {
                "string": entry.value,
                "string_raw": entry.raw,
                "string_encoding": entry.type.name,
                "string_offset": entry.start,
                "string_length": len(entry.value),
                "string_raw_length": entry.length,
                "string_entropy": self.entropy(entry.value),
            }

            strings[key] = string_entry

        # Return as list for export compatibility
        return list(strings.values())