Walter Guttmann

73 papers B 3C 13Journal 43Unranked 12
YearRankTypeTitle / Venue / Authors
2026 J jnl
J. Log. Algebraic Methods Program.
Hitoshi Furusawa, Walter Guttmann, Georg Struth
2025 J jnl
J. Log. Comput.
Hitoshi Furusawa, Walter Guttmann, Georg Struth
2025 J jnl
Arch. Formal Proofs
Walter Guttmann
2024 J jnl
J. Funct. Program.
Roland Carl Backhouse, Walter Guttmann, Michael Winter
2024 J jnl
Fundam. Informaticae
Hitoshi Furusawa, Walter Guttmann
2024 J jnl
J. Log. Algebraic Methods Program.
Hitoshi Furusawa, Walter Guttmann, Georg Struth
2024 J jnl
Fundam. Informaticae
Walter Guttmann
2023 J jnl
CoRR
Roland Carl Backhouse, Walter Guttmann, Michael Winter
2023 J jnl
Arch. Formal Proofs
Walter Guttmann
2023 J jnl
CoRR
Hitoshi Furusawa, Walter Guttmann
2023 C conf
RAMiCS
Walter Guttmann
2023 J jnl
CoRR
Hitoshi Furusawa, Walter Guttmann, Georg Struth
2023 J jnl
Arch. Formal Proofs
Walter Guttmann, Georg Struth
2023 J jnl
CoRR
Hitoshi Furusawa, Walter Guttmann, Georg Struth
2023 J jnl
CoRR
Hitoshi Furusawa, Walter Guttmann, Georg Struth
2023 J jnl
CoRR
Walter Guttmann
2021 J jnl
Arch. Formal Proofs
Walter Guttmann
2021 C conf
RAMiCS
Walter Guttmann, Nicolas Robinson-O'Brien
2021 J jnl
Arch. Formal Proofs
Walter Guttmann
2021 C conf
RAMiCS
Walter Guttmann
2020 C conf
RAMiCS
Walter Guttmann, Bernhard Möller
2020 J jnl
Arch. Formal Proofs
Walter Guttmann, Bernhard Möller
2020 conf
IJCAR (2)
Walter Guttmann
2020 J jnl
Arch. Formal Proofs
Walter Guttmann, Peter Höfner
2020 J jnl
Arch. Formal Proofs
Walter Guttmann
2020 J jnl
Arch. Formal Proofs
Walter Guttmann, Nicolas Robinson-O'Brien
2020 J jnl
J. Log. Algebraic Methods Program.
Rudolf Berghammer, Hitoshi Furusawa, Walter Guttmann, Peter Höfner
2020 C conf
RAMiCS
Walter Guttmann
2019 conf
UTP
Walter Guttmann
2018 J jnl
Arch. Formal Proofs
Walter Guttmann
2018 J jnl
Theor. Comput. Sci.
Walter Guttmann
2018 J jnl
CoRR
Rudolf Berghammer, Hitoshi Furusawa, Walter Guttmann, Peter Höfner
2018 C ed.
RAMiCS
Jules Desharnais, Walter Guttmann, Stef Joosten
2018 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann
2017 J jnl
J. Netw. Comput. Appl.
Mengmeng Ge, Jin B. Hong, Walter Guttmann, Dong Seong Kim
2017 J jnl
J. Log. Algebraic Methods Program.
Rudolf Berghammer, Walter Guttmann
2017 C conf
RAMiCS
Walter Guttmann
2017 J jnl
Arch. Formal Proofs
Walter Guttmann
2017 J jnl
Arch. Formal Proofs
Walter Guttmann
2016 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann
2016 J jnl
Arch. Formal Proofs
Victor B. F. Gomes, Walter Guttmann, Peter Höfner, Georg Struth, Tjark Weber
2016 C conf
ICTAC
Walter Guttmann
2016 J jnl
Arch. Formal Proofs
Walter Guttmann
2015 B conf
MPC
Rudolf Berghammer, Walter Guttmann
2015 C conf
RAMiCS
Rudolf Berghammer, Walter Guttmann
2015 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann
2014 J jnl
Sci. Comput. Program.
Walter Guttmann
2014 C conf
RAMiCS
Walter Guttmann
2014 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann
2013 J jnl
Sci. Comput. Program.
Walter Guttmann
2012 J jnl
Acta Informatica
Walter Guttmann
2012 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann
2012 B conf
MPC
Walter Guttmann
2012 C conf
RAMiCS
Walter Guttmann
2011 conf
ATE
Walter Guttmann, Georg Struth, Tjark Weber
2011 C conf
ICFEM
Walter Guttmann, Georg Struth, Tjark Weber
2011 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann
2011 C conf
RAMiCS
Walter Guttmann
2010 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann
2010 J jnl
J. Log. Algebraic Methods Program.
Walter Guttmann, Bernhard Möller
2010 B conf
MPC
Walter Guttmann
2010 conf
UTP
Walter Guttmann
2009 conf
RelMiCS
Walter Guttmann
2009 conf
Ershov Memorial Conference
Jens Kohlmeyer, Walter Guttmann
2008 conf
RelMiCS
Walter Guttmann
2008 conf
UTP
Walter Guttmann
2007 ch.
Ausgezeichnete Informatikdissertationen
Walter Guttmann
2007
Walter Guttmann
2006 conf
Ershov Memorial Conference
Stefan Sarstedt, Walter Guttmann
2006 conf
UTP
Walter Guttmann, Bernhard Möller
2006 conf
IFIP TCS
Walter Guttmann, Markus Maucher
2005 conf
RelMiCS
Walter Guttmann
2003 J jnl
J. Univers. Comput. Sci.
Walter Guttmann, Helmuth Partsch, Wolfram Schulte, Ton Vullinghs
redb/extractors/pe_extractors/pe_sections.py
← Index redb/extractors/pe_extractors/pe_sections.py python
import base64
import hashlib
import inspect
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PESection
from datetime import datetime, timezone
from typing import Any


class PESectionExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_sections"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_SECTION.value

    def _extract_sections(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        sections = []
        for section in self.pe.sections:
            try:
                name = self.process_binary_string(section.Name)
            except Exception as e:
                name = "UnableToDecode"
                self.log.warning(
                    f'Unable to store section Name "{section.Name}" for {self.hash.sha256}'
                    f" exception {e}"
                )
            sec_sha256 = section.get_hash_sha256()
            sec_md5 = section.get_hash_md5()
            # sec_entropy = "%.2f" % section.get_entropy()
            sec_entropy = section.get_entropy()
            pe_section = PESection(
                _id=hashlib.sha256(
                    name.encode()
                ).hexdigest(),  # usecase 8e035beb02a411f8a9e92d4cf184ad34f52bbd0a81a50c222cdd4706e4e45104, all section have same sha256
                section_name=name,
                section_name_b64=base64.b64encode(
                    section.Name.rstrip(b'\x00')
                ).decode(),  # base64.b64decode(b64) to decode
                section_v_addr=section.VirtualAddress,
                section_v_addr_hex=hex(section.VirtualAddress),
                section_v_size=section.Misc_VirtualSize,
                section_size=section.SizeOfRawData,
                section_pointer_to_raw_data=hex(section.PointerToRawData),
                section_md5=sec_md5,
                section_sha256=sec_sha256,
                section_entropy=sec_entropy,
            )
            sections.append(pe_section)
        return sections

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            sections = self._extract_sections()
            # self.export_to_elastic(sections)  # Let the exporters handle this
            return sections
        except Exception as e:
            self.log.error(f"Error extracting PE sections: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            sections = self.extract()
            if sections is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for section in sections:
                data.append([
                    self.sha256,                          # sha256
                    self.md5,                             # md5
                    self.sha1,                            # sha1
                    section.section_name,                 # section_name
                    section.section_name_b64,             # section_name_b64
                    section.section_entropy,              # section_entropy
                    section.section_sha256,               # section_sha256
                    section.section_md5,                  # section_md5
                    section.section_size,                 # section_size
                    section.section_v_addr,               # section_v_addr
                    section.section_v_size,               # section_v_size
                    int(section.section_pointer_to_raw_data, 16),  # section_pointer_to_raw_data - convert from hex
                    current_time                          # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'section_name', 'section_name_b64',
                'section_entropy', 'section_sha256', 'section_md5', 'section_size',
                'section_v_addr', 'section_v_size', 'section_pointer_to_raw_data',
                'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(String)', 'LowCardinality(String)',
                'Float64', 'FixedString(64)', 'FixedString(32)', 'UInt64',
                'UInt64', 'UInt64', 'UInt64',
                'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_sections"