Walt Truszkowski

48 papers B 3Misc 5Journal 6Unranked 27
YearRankTypeTitle / Venue / Authors
2010 book
Walt Truszkowski, Harold L. Hallock, Christopher A. Rouff, Jay Karlin, James L. Rash, Michael G. Hinchey, Roy Sterritt
2009 J jnl
J. Aerosp. Comput. Inf. Commun.
Kelly Cohen, Fernando Figueroa, Ella M. Atkins, Michel D. Ingham, Richard J. Doyle, Sanjay Garg, Irene Gregory, Shigeru Obayashi, Nhan Ngyuen, Lars Blackmore, Walt Truszkowski
2008 J jnl
AI Mag.
Jerry T. Ball, Chris Arney, Samuel G. Collins, Mitchell Marcus, Sergei Nirenburg, Antonio Chella, Kai Goebel, Jason H. Li, Margaret Lyell, Brian Magerko, Riccardo Manzotti, Clayton T. Morrison, Tim Oates, Mark O. Riedl, Goran Trajkovski, Walt Truszkowski, N. Serdar Uckun
2007 Misc conf
SAC
Michael G. Hinchey, Yuan-Shun Dai, James L. Rash, Walt Truszkowski, Manish Madhusoodan
2007 conf
AAAI Fall Symposium: Regarding the Intelligence in Distributed Intelligent Systems
Tim Finin, Lalana Kagal, Elisa F. Kendall, Jason H. Li, Margaret Lyell, Walt Truszkowski
2007 ed.
AAAI Fall Symposium: Regarding the Intelligence in Distributed Intelligent Systems
Tim Finin, Lalana Kagal, Elisa F. Kendall, Jason H. Li, Margaret Lyell, Walt Truszkowski
2006 ed.
WRAC
Michael G. Hinchey, Patricia Rago, James L. Rash, Christopher A. Rouff, Roy Sterritt, Walt Truszkowski
2005 conf
WRAC
Charles Sebens, Walt Truszkowski
2005 conf
WRAC
Karin K. Breitman, Walt Truszkowski
2005 conf
ECBS
James D. Baldassari, Christopher L. Kopec, Eric S. Leshay, Walt Truszkowski, David Finkel
2005 conf
ICPADS (2)
Michael G. Hinchey, James L. Rash, Walt Truszkowski, Christopher A. Rouff, Roy Sterritt
2005 ed.
FAABS
Michael G. Hinchey, James L. Rash, Walt Truszkowski, Christopher A. Rouff
2005 conf
Software Engineering Research and Practice
Walt Truszkowski, Christopher A. Rouff, Sidney C. Bailin, Mike Rilee
2005 J jnl
Innov. Syst. Softw. Eng.
Walt Truszkowski, Christopher A. Rouff, Sidney C. Bailin, Mike Rilee
2005 conf
ICPADS (2)
Christopher A. Rouff, Michael G. Hinchey, James L. Rash, Walt Truszkowski, Roy Sterritt
2005 conf
EUC Workshops
Roy Sterritt, Michael G. Hinchey, James L. Rash, Walt Truszkowski, Christopher A. Rouff, Denis Gracanin
2005 conf
ICPADS (2)
Walt Truszkowski, Michael G. Hinchey, Roy Sterritt
2005 conf
ICPADS (1)
Christopher A. Rouff, Michael G. Hinchey, Walt Truszkowski, James L. Rash
2004 conf
ECBS
Walt Truszkowski, James L. Rash, Christopher A. Rouff, Michael G. Hinchey
2004 conf
FAABS
Jan Smid, Marek Obitko, David Fisher, Walt Truszkowski
2004 J jnl
IT Prof.
Walt Truszkowski, Mike Hinchey, James L. Rash, Christopher A. Rouff
2004 B conf
SEFM
Christopher A. Rouff, Amy Vanderbilt, Michael G. Hinchey, Walt Truszkowski, James L. Rash
2004 conf
ECBS
Walt Truszkowski, James L. Rash, Christopher A. Rouff, Michael G. Hinchey
2004 conf
ECBS
Christopher A. Rouff, Amy Vanderbilt, Michael G. Hinchey, Walt Truszkowski, James L. Rash
2004 B conf
ICECCS
Christopher A. Rouff, Amy Vanderbilt, Walt Truszkowski, James L. Rash, Michael G. Hinchey
2004 Misc conf
AIAI
Christopher A. Rouff, Amy Vanderbilt, Walt Truszkowski, James L. Rash, Michael G. Hinchey
2003 Misc conf
FLAIRS
Walt Truszkowski, Sidney C. Bailin
2003 ed.
FAABS
Michael G. Hinchey, James L. Rash, Walt Truszkowski, Christopher A. Rouff, Diana F. Gordon-Spears
2003 ed.
WRAC
Walt Truszkowski, Christopher A. Rouff, Michael G. Hinchey
2003 conf
AMKM
Sidney C. Bailin, Walt Truszkowski
2003 conf
Communications in Computing
Jan Smid, Walt Truszkowski
2002 Misc conf
FLAIRS
Walt Truszkowski
2002 conf
WRAC
Jan Smid, Marek Obitko, Walt Truszkowski
2002 conf
FAABS
Walt Truszkowski
2002 conf
WRAC
Sidney C. Bailin, Walt Truszkowski
2002 J jnl
Knowl. Eng. Rev.
Sidney C. Bailin, Walt Truszkowski
2001 Misc conf
FLAIRS
Walt Truszkowski, Nick Netreba, Don Ginn, Sanda Mandutianu
2001 ed.
FAABS
James L. Rash, Christopher A. Rouff, Walt Truszkowski, Diana F. Gordon, Michael G. Hinchey
2001 conf
ICEIS (1)
Sidney C. Bailin, Walt Truszkowski
2001 conf
CIA
Sidney C. Bailin, Walt Truszkowski
2001 B conf
SSDBM
Sidney C. Bailin, Walt Truszkowski
2000 conf
CIA
Walt Truszkowski, Jay Karlin
2000 conf
FAABS
Michael G. Hinchey, James A. Hendler, Charles Pecheur, Constance L. Heitmeyer, Diana F. Gordon, Michael Luck, Walt Truszkowski
1999 conf
CIA
Walt Truszkowski, Harold L. Hallock, James Kurien
1999 conf
Agents
Subrata Kumar Das, Raffi Krikorian, Walt Truszkowski
1995 conf
ICMAS
Walt Truszkowski, Jidé B. Odubiyi, Ed Ruberton
1991 J jnl
Int. J. Softw. Eng. Knowl. Eng.
Sidney C. Bailin, Robert H. Gattis, Walt Truszkowski
1991 conf
KBSE
Sidney C. Bailin, Robert H. Gattis, Walt Truszkowski
redb/extractors/pe_extractors/pe_sections.py
← Index redb/extractors/pe_extractors/pe_sections.py python
import base64
import hashlib
import inspect
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PESection
from datetime import datetime, timezone
from typing import Any


class PESectionExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_sections"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_SECTION.value

    def _extract_sections(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        sections = []
        for section in self.pe.sections:
            try:
                name = self.process_binary_string(section.Name)
            except Exception as e:
                name = "UnableToDecode"
                self.log.warning(
                    f'Unable to store section Name "{section.Name}" for {self.hash.sha256}'
                    f" exception {e}"
                )
            sec_sha256 = section.get_hash_sha256()
            sec_md5 = section.get_hash_md5()
            # sec_entropy = "%.2f" % section.get_entropy()
            sec_entropy = section.get_entropy()
            pe_section = PESection(
                _id=hashlib.sha256(
                    name.encode()
                ).hexdigest(),  # usecase 8e035beb02a411f8a9e92d4cf184ad34f52bbd0a81a50c222cdd4706e4e45104, all section have same sha256
                section_name=name,
                section_name_b64=base64.b64encode(
                    section.Name.rstrip(b'\x00')
                ).decode(),  # base64.b64decode(b64) to decode
                section_v_addr=section.VirtualAddress,
                section_v_addr_hex=hex(section.VirtualAddress),
                section_v_size=section.Misc_VirtualSize,
                section_size=section.SizeOfRawData,
                section_pointer_to_raw_data=hex(section.PointerToRawData),
                section_md5=sec_md5,
                section_sha256=sec_sha256,
                section_entropy=sec_entropy,
            )
            sections.append(pe_section)
        return sections

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            sections = self._extract_sections()
            # self.export_to_elastic(sections)  # Let the exporters handle this
            return sections
        except Exception as e:
            self.log.error(f"Error extracting PE sections: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            sections = self.extract()
            if sections is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for section in sections:
                data.append([
                    self.sha256,                          # sha256
                    self.md5,                             # md5
                    self.sha1,                            # sha1
                    section.section_name,                 # section_name
                    section.section_name_b64,             # section_name_b64
                    section.section_entropy,              # section_entropy
                    section.section_sha256,               # section_sha256
                    section.section_md5,                  # section_md5
                    section.section_size,                 # section_size
                    section.section_v_addr,               # section_v_addr
                    section.section_v_size,               # section_v_size
                    int(section.section_pointer_to_raw_data, 16),  # section_pointer_to_raw_data - convert from hex
                    current_time                          # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'section_name', 'section_name_b64',
                'section_entropy', 'section_sha256', 'section_md5', 'section_size',
                'section_v_addr', 'section_v_size', 'section_pointer_to_raw_data',
                'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(String)', 'LowCardinality(String)',
                'Float64', 'FixedString(64)', 'FixedString(32)', 'UInt64',
                'UInt64', 'UInt64', 'UInt64',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_sections"