Vincent Pouget

33 papers C 3Journal 24Unranked 6
YearRankTypeTitle / Venue / Authors
2020 conf
LATS
Israel C. Lopes, Vincent Pouget, Frederic Wrobel, Frédéric Saigné, Antoine D. Touboul, Ketil Røed
2020 conf
DTIS
S. Guagliardo, Frederic Wrobel, Ygor Q. Aguiar, Jean-Luc Autran, Paul Leroux, Frédéric Saigné, Vincent Pouget, Antoine D. Touboul
2019 J jnl
J. Electron. Test.
Gennaro Severino Rodrigues, Ádria Barros de Oliveira, Fernanda Lima Kastensmidt, Vincent Pouget, Alberto Bosio
2018 J jnl
Microelectron. Reliab.
Ygor Q. Aguiar, Frederic Wrobel, Jean-Luc Autran, Paul Leroux, Frédéric Saigné, Antoine D. Touboul, Vincent Pouget
2018 conf
SBCCI
Fabio Benevenuti, Fabiano Libano, Vincent Pouget, Fernanda Lima Kastensmidt, Paolo Rech
2018 conf
LATS
Gennaro Severino Rodrigues, Fernanda Lima Kastensmidt, Vincent Pouget, Alberto Bosio
2018 C conf
IOLTS
Gennaro Severino Rodrigues, Fernanda Lima Kastensmidt, Vincent Pouget, Alberto Bosio
2017 J jnl
Microelectron. Reliab.
Frederic Wrobel, Antoine D. Touboul, Vincent Pouget, Luigi Dilillo, Jerome Boch, Frédéric Saigné
2017 J jnl
Microelectron. Reliab.
Vincent Pouget, S. Jonathas, R. Job, J.-R. Vaillé, Frederic Wrobel, Frédéric Saigné
2013 J jnl
Microelectron. Reliab.
Nogaye Mbaye, Vincent Pouget, Frédéric Darracq, Dean Lewis
2013 J jnl
Microelectron. Reliab.
I. El Moukhtari, Vincent Pouget, C. Larue, Frédéric Darracq, Dean Lewis, Philippe Perdu
2012 J jnl
Microelectron. Reliab.
Alexandre Sarafianos, Roxane Llido, Jean-Max Dutertre, Olivier Gagliano, Valerie Serradeil, Mathieu Lisart, Vincent Goubier, Assia Tria, Vincent Pouget, Dean Lewis
2012 J jnl
Microelectron. Reliab.
R. Llido, Pascal Masson, Arnaud Régnier, Vincent Goubier, Gérald Haller, Vincent Pouget, Dean Lewis
2011 J jnl
Microelectron. Reliab.
Roxane Llido, J. Gomez, Vincent Goubier, N. Froidevaux, L. Dufayard, Gérald Haller, Vincent Pouget, Dean Lewis
2009 J jnl
Microelectron. Reliab.
C. Godlewski, Vincent Pouget, Dean Lewis, Mathieu Lisart
2009 J jnl
Microelectron. Reliab.
Gérald Haller, Aziz Machouat, Dean Lewis, Vincent Pouget
2008 C conf
IOLTS
Vincent Pouget, Alexandre Douin, Gilles Foucard, Paul Peronnard, Dean Lewis, Pascal Fouillat, Raoul Velazco
2008 J jnl
Microelectron. Reliab.
Aziz Machouat, Gérald Haller, Vincent Goubier, Dean Lewis, Philippe Perdu, Vincent Pouget, Pascal Fouillat, Fabien Essely
2007 J jnl
Microelectron. Reliab.
V. Maingot, Jean Baptiste Ferron, Régis Leveugle, Vincent Pouget, Alexandre Douin
2006 J jnl
Microelectron. Reliab.
Fabien Essely, Frédéric Darracq, Vincent Pouget, Mustapha Remmach, Felix Beaudoin, Nicolas Guitard, Marise Bafleur, Philippe Perdu, André Touboul, Dean Lewis
2006 J jnl
Microelectron. Reliab.
Alexandre Douin, Vincent Pouget, M. De Matos, Dean Lewis, Philippe Perdu, Pascal Fouillat
2005 J jnl
Microelectron. Reliab.
Nicolas Guitard, Fabien Essely, David Trémouilles, Marise Bafleur, Nicolas Nolhier, Philippe Perdu, André Touboul, Vincent Pouget, Dean Lewis
2005 C conf
IOLTS
Alexandre Douin, Vincent Pouget, Dean Lewis, Pascal Fouillat, Philippe Perdu
2004 J jnl
IEEE Trans. Instrum. Meas.
Angie Tetelin, Vincent Pouget, Jean-Luc Lachaud, Claude Pellet
2004 J jnl
IEEE Trans. Instrum. Meas.
Vincent Pouget, Dean Lewis, Pascal Fouillat
2003 J jnl
Microelectron. Reliab.
Thomas Beauchêne, Dean Lewis, Felix Beaudoin, Vincent Pouget, Philippe Perdu, Pascal Fouillat, Yves Danto
2003 J jnl
Microelectron. Reliab.
G. Andriamonje, Vincent Pouget, Yves Ousten, Dean Lewis, Yves Danto, Jean-Michel Rampnoux, Younès Ezzahri, Stefan Dilhaire, Stéphane Grauby, Wilfrid Claeys
2003 J jnl
Microelectron. Reliab.
Felix Beaudoin, Romain Desplats, Philippe Perdu, Abdellatif Firiti, Gérald Haller, Vincent Pouget, Dean Lewis
2003 J jnl
Microelectron. Reliab.
Thomas Beauchêne, Dean Lewis, Felix Beaudoin, Vincent Pouget, Romain Desplats, Pascal Fouillat, Philippe Perdu, Marise Bafleur, David Trémouilles
2002 conf
LATW
Dean Lewis, Pascal Fouillat, Vincent Pouget
2001 J jnl
Microelectron. Reliab.
Dean Lewis, Vincent Pouget, Thomas Beauchêne, Hervé Lapuyade, Pascal Fouillat, André Touboul, Felix Beaudoin, Philippe Perdu
2001 J jnl
Microelectron. Reliab.
Vincent Pouget, Hervé Lapuyade, Pascal Fouillat, Dean Lewis, S. Buchner
2000 conf
IOLTW
Vincent Pouget, Pascal Fouillat, Dean Lewis, Hervé Lapuyade, L. Sarger, F. M. Roche, S. Duzellier, R. Ecoffet
redb/extractors/js_extractors/js_suspicious_apis.py
← Index redb/extractors/js_extractors/js_suspicious_apis.py python
import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor
from redb.extractors.js_extractors.js_patterns import CATEGORIES, PATTERNS


# Backwards-compatible export: `{category: [(raw_pattern_string, api_name), ...]}`
# in canonical PATTERNS insertion order (code_execution, network, filesystem,
# process, registry, crypto_encoding, dom_manipulation). Kept so external
# callers (notably JSDeobfuscationExtractor pre-cleanup) keep working until
# they are migrated to PATTERNS directly.
SUSPICIOUS_APIS: "dict[str, list[tuple[str, str]]]" = {}
for _name, _compiled in PATTERNS.items():
    SUSPICIOUS_APIS.setdefault(CATEGORIES[_name], []).append((_compiled.pattern, _name))


class JSSuspiciousAPIsExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.api_findings = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_SUSPICIOUS_APIS.value

    def _get_context_snippet(self, line, max_len=200):
        """Get a truncated context snippet around a match."""
        line = line.strip()
        if len(line) > max_len:
            return line[:max_len] + "..."
        return line

    def extract(self):
        src = self.js_source
        if not src:
            return None

        # Pass 1: shared per-sample scan over the raw source. The dict contains
        # entries for both PATTERNS and FEATURE_PATTERNS; the loop below only
        # consults PATTERNS keys, so feature-only entries are ignored.
        raw_scan = self._context.scan or {}
        raw_lines = self.lines

        # Pass 2: same patterns over the deobfuscated text, when the
        # deobfuscator produced something meaningfully different. APIs hidden
        # behind one obfuscation layer (Vjw0rm-style array.join + eval,
        # Dean-Edwards packers, jjencode, ...) only surface here. The scan is
        # cached on JSContext so JSDeobfuscationExtractor (which computes the
        # new_apis_found diff) reuses the same result.
        deobf_scan = self._context.scan_deobfuscated
        if deobf_scan:
            deobf_text, _ = self._context.deobfuscated
            deobf_lines = deobf_text.splitlines()
        else:
            deobf_lines = []

        findings = []
        # Iterate PATTERNS in canonical order so output is deterministic and
        # matches the historical category/pattern ordering. For each api_name,
        # raw findings take precedence; if an API is found only in the
        # deobfuscated text, we surface it as a row tagged revealed_by_deobf=1
        # with line numbers / snippets pulled from the deobfuscated source.
        for api_name in PATTERNS:
            raw_info = raw_scan.get(api_name)
            if raw_info:
                line_numbers = raw_info["lines"]
                lines_for_snippets = raw_lines
                revealed_by_deobf = 0
            else:
                deobf_info = deobf_scan.get(api_name)
                if not deobf_info:
                    continue
                line_numbers = deobf_info["lines"]
                lines_for_snippets = deobf_lines
                revealed_by_deobf = 1

            snippets = [
                self._get_context_snippet(lines_for_snippets[ln - 1])
                for ln in line_numbers[:3]
                if 0 < ln <= len(lines_for_snippets)
            ]
            findings.append({
                "api_name": api_name,
                "api_category": CATEGORIES[api_name],
                # Historical semantics: count = number of unique lines with a
                # match, not total in-source match count.
                "call_count": len(line_numbers),
                "line_numbers": line_numbers,
                "context_snippet": " | ".join(snippets),
                "revealed_by_deobf": revealed_by_deobf,
            })

        if not findings:
            return None

        self.api_findings = findings
        return findings

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.api_findings:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for f in self.api_findings:
                data.append([
                    self.sha256,
                    f['api_name'],
                    f['api_category'],
                    f['call_count'],
                    f['line_numbers'],
                    f['context_snippet'],
                    f['revealed_by_deobf'],
                    current_time,
                ])

            column_names = [
                "sha256", "api_name", "api_category",
                "call_count", "line_numbers", "context_snippet",
                "revealed_by_deobf",
                "analysis_date",
            ]

            column_type_names = [
                "FixedString(64)", "String", "LowCardinality(String)",
                "UInt32", "Array(UInt32)", "String",
                "UInt8",
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_js_suspicious_apis"