Walid Ibrahim

45 papers B 1C 8Misc 1Journal 18Unranked 15
YearRankTypeTitle / Venue / Authors
2022 J jnl
Educ. Inf. Technol.
Walid Ibrahim, Wissam Ibrahim, Taoufik Zoubeidi, Sayed Marzouk, Amr Sweedan, Hoda H. Amer
2019 C conf
ECMS
Walid Ibrahim, Hoda H. Amer
2019 J jnl
IEEE Trans. Reliab.
Walid Ibrahim, Hazem Ibrahim
2018 conf
IIT
Asma Al Khaili, Aisha Al Mamari, Hoda H. Amer, Walid Ibrahim
2017 J jnl
Educ. Inf. Technol.
Zouheir Trabelsi, Mohammed Al Matrooshi, Saeed Al Bairaq, Walid Ibrahim, Mohammad M. Masud
2016 conf
SummerSim
Walid Ibrahim, Hoda H. Amer
2016 J jnl
IEEE Trans. Computers
Walid Ibrahim
2015 J jnl
J. Educ. Technol. Soc.
Walid Ibrahim, Yacine Atif, Khaled Shuaib, Demetrios G. Sampson
2015 J jnl
IEEE Trans. Computers
Walid Ibrahim, Marwa Shousha, John W. Chinneck
2015 J jnl
Microprocess. Microsystems
Azam Beg, Falah Awwad, Walid Ibrahim, Faheem Ahmed
2014 J jnl
J. Low Power Electron.
Mihai Tache, Valeriu Beiu, Walid Ibrahim, Fekri Kharbash, Massimo Alioto
2014
Walid Ibrahim
2014 conf
CSEDU (1)
Walid Ibrahim, Yacine Atif
2014 C conf
EDUCON
Hoda H. Amer, Walid Ibrahim
2013 J jnl
J. Inf. Technol. Educ. Innov. Pract.
Zouheir Trabelsi, Walid Ibrahim
2013 conf
SpringSim (ANSS)
Walid Ibrahim
2013 conf
ISQED
Valeriu Beiu, Azam Beg, Walid Ibrahim, Fekri Kharbash, Massimo Alioto
2013 conf
ICECS
Walid Ibrahim, Valeriu Beiu, Mihai Tache, Fekri Kharbash
2013 C conf
EDUCON
Zouheir Trabelsi, Walid Ibrahim
2013 conf
ICECS
Fekri Kharbash, Valeriu Beiu, Mihai Tache, Walid Ibrahim
2012 C conf
EDUCON
Yacine Atif, Walid Ibrahim, Khaled Shuaib
2012 J jnl
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.
Walid Ibrahim, Valeriu Beiu, Azam Beg
2012 J jnl
IEEE Trans. Reliab.
Walid Ibrahim, Valeriu Beiu, Azam Beg
2011 conf
ECCTD
Valeriu Beiu, Walid Ibrahim, Azam Beg, Liren Zhang, Mihai Tache
2011 J jnl
IEEE Trans. Reliab.
Walid Ibrahim, Valeriu Beiu
2010 conf
IDT
Walid Ibrahim, Valeriu Beiu, Azam Beg
2009 conf
NanoNet
Walid Ibrahim, Valeriu Beiu
2009 J jnl
Eur. J. Oper. Res.
Walid Ibrahim, Hesham El-Sayed, Amr El-Chouemi, Hoda H. Amer
2009 conf
ICIAR
Walid Ibrahim, Mahmoud R. El-Sakka
2009 ch.
Encyclopedia of Artificial Intelligence
Valeriu Beiu, Walid Ibrahim, Sanja Lazarova-Molnar
2009 conf
IMAGAPP
Walid Ibrahim, Mahmoud R. El-Sakka
2009 conf
NanoNet
Valeriu Beiu, Walid Ibrahim, Rafic Z. Makki
2009 J jnl
Comput. Appl. Eng. Educ.
Azam Beg, Walid Ibrahim
2008 C conf
ISCAS
Valeriu Beiu, Walid Ibrahim
2008 C conf
AICCSA
Mohammad Hayajneh, Chaouki T. Abdallah, Walid Ibrahim
2008 J jnl
Comput. Oper. Res.
Walid Ibrahim, John W. Chinneck
2008 C conf
ISCAS
Azam Beg, P. W. Chandana Prasad, Walid Ibrahim, Emad Abu Shama
2007 J jnl
J. Electron. Test.
Walid Ibrahim
2007 conf
ASAP
Walid Ibrahim, Valeriu Beiu
2007 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Valeriu Beiu, Snorre Aunet, Jabulani Nyathi, Ray Robert Rydberg III, Walid Ibrahim
2007 Misc conf
IWANN
Valeriu Beiu, Walid Ibrahim, Sanja Lazarova-Molnar
2006 B conf
IEEE Congress on Evolutionary Computation
Walid Ibrahim, Amr El-Chouemi, Hoda H. Amer
2006 conf
DFT
Valeriu Beiu, Walid Ibrahim, Y. A. Alkhawwar, Mawahib H. Sulieman
2006 C conf
AICCSA
Walid Ibrahim, Amr El-Chouemi, Hesham El-Sayed
2003 J jnl
Wirel. Commun. Mob. Comput.
Walid Ibrahim, John W. Chinneck, Shalini S. Periyalwar
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));