Wang Gao

64 papers A* 3A 2C 1Misc 1Journal 52Unranked 5
YearRankTypeTitle / Venue / Authors
2026 J jnl
IEEE Trans. Veh. Technol.
Hong Liu, Wang Gao, Heng Zhao, Shuguo Pan, Keck Voon Ling, Feixuan Huang
2026 J jnl
Pattern Recognit. Lett.
Huali Yang, Junjie Hu, Tao Huang, Shengze Hu, Wang Gao, Zhuoran Xu, Jing Geng
2025 J jnl
IEEE Internet Things J.
Xianlu Tao, Haotian Wang, Shuguo Pan, Xiaoguo Zhang, Wang Gao, Qiang Wang
2025 J jnl
CoRR
Xu He, Xiaolin Meng, Wenxuan Yin, Youdong Zhang, Lingfei Mo, Xiangdong An, Fangwen Yu, Shuguo Pan, Yufeng Liu, Jingnan Liu, Yujia Zhang, Wang Gao
2025 C conf
SEKE
Wenya Wang, Wang Gao, Zhenghe Wang, Sicong Cao, Xingwei Lin, Dawu Gu
2025 J jnl
IEEE Internet Things J.
Chun Ma, Shuguo Pan, Wang Gao, Liwei Liu
2025 J jnl
IEEE Trans. Instrum. Meas.
Guoliang Liu, Shuguo Pan, Wang Gao, Baoguo Yu, Jinle Xu
2025 J jnl
Neurocomputing
Yun Liang, Wang Gao, Qimin Liang, Cankun Zhong, Feiping Nie
2025 A* conf
CHI
Xinyue Gui, Ding Xia, Wang Gao, Mustafa Doga Dogan, Maria Larsson, Takeo Igarashi
2025 J jnl
CoRR
Xinyue Gui, Ding Xia, Wang Gao, Mustafa Doga Dogan, Maria Larsson, Takeo Igarashi
2025 J jnl
IEEE Trans. Veh. Technol.
Zongliang Chen, Shuguo Pan, Kegen Yu, Xinhua Tang, Wang Gao, Zhengyang Zhou
2025 A conf
IROS
Zongliang Chen, Shuguo Pan, Xinhua Tang, Wang Gao, Shaobo Liang, Xiaocong Li
2025 J jnl
IEEE Trans. Intell. Transp. Syst.
Zongliang Chen, Shuguo Pan, Kegen Yu, Yuting Wu, Wang Gao, Zhuoxuan Wang, Xiaolin Meng
2025 J jnl
IEEE Trans. Instrum. Meas.
Hong Liu, Shuguo Pan, Xiang Wang, Wang Gao, Baoguo Yu, Heng Zhao
2025 J jnl
IEEE Robotics Autom. Lett.
Wang Gao, Feixuan Huang, Hong Liu, Shuguo Pan, Heng Zhao
2025 A conf
IROS
Feixuan Huang, Hong Liu, Wang Gao, Shuguo Pan, Heng Zhao
2025 J jnl
Pattern Anal. Appl.
Zhuo Chen, Shuguo Pan, Peng Guo, Wang Gao
2025 J jnl
IEEE Robotics Autom. Lett.
Yuting Wu, Shuguo Pan, Zongliang Chen, Zhuoxuan Wang, Wang Gao, Xianlu Tao
2025 J jnl
IEEE Robotics Autom. Lett.
Feixuan Huang, Wang Gao, Shuguo Pan, Hong Liu, Heng Zhao
2025 J jnl
Mach. Vis. Appl.
Peng Guo, Shuguo Pan, Wang Gao, Kourosh Khoshelham
2025 J jnl
IEEE Robotics Autom. Lett.
Zhuoxuan Wang, Shuguo Pan, Jinle Xu, Xianlu Tao, Wang Gao, Qiang Wang
2024 J jnl
IEEE Trans. Netw. Sci. Eng.
Wang Gao, Zhongyuan Zhao, Mengli Wei, Ju Yang, Xiaogang Zhang, Jinsong Li
2024 J jnl
Neurocomputing
Zhongyuan Zhao, Ju Yang, Wang Gao, Yan Wang, Mengli Wei
2024 J jnl
Remote. Sens.
Hao Liu, Ziteng Zhang, Chuanzhen Sheng, Baoguo Yu, Wang Gao, Xiaolin Meng
2024 J jnl
IEEE Trans. Instrum. Meas.
Qi Liu, Chengfa Gao, Rui Shang, Wang Gao, José A. Lopez-Salcedo, Gonzalo Seco-Granados
2024 J jnl
IEEE Trans. Intell. Transp. Syst.
Jiansheng Wei, Shuguo Pan, Wang Gao, Peng Guo
2024 J jnl
IEEE Trans. Instrum. Meas.
Qi Liu, Chengfa Gao, Alda Xhafa, Wang Gao, José A. Lopez-Salcedo, Gonzalo Seco-Granados
2024 J jnl
IEEE Trans. Aerosp. Electron. Syst.
Liwei Liu, Shuguo Pan, Wang Gao, Chun Ma
2024 J jnl
Remote. Sens.
Zhihan Sun, Wang Gao, Xianlu Tao, Shuguo Pan, Pengbo Wu, Hong Huang
2024 J jnl
Remote. Sens.
Zhenhao Xu, Rui Shang, Chengfa Gao, Wang Gao, Qi Liu, Fengyang Long, Dawei Xu
2023 conf
DSIT
Wang Gao, Linlin Zhang, Qian Cao
2023 A* conf
CCS
Wenya Wang, Xingwei Lin, Jingyi Wang, Wang Gao, Dawu Gu, Wei Lv, Jiashui Wang
2023 J jnl
CoRR
Wenya Wang, Xingwei Lin, Jingyi Wang, Wang Gao, Dawu Gu, Wei Lv, Jiashui Wang
2023 J jnl
Remote. Sens.
Rui Shang, Chengfa Gao, Lu Gan, Ruicheng Zhang, Wang Gao, Xiaolin Meng
2023 J jnl
IEEE Trans. Instrum. Meas.
Qi Liu, Chengfa Gao, Rui Shang, Wang Gao, Ruicheng Zhang
2023 conf
DSIT
Wang Gao, Linlin Zhang, Qian Cao
2023 J jnl
Remote. Sens.
Hao Liu, Wang Gao, Weiwei Miao, Shuguo Pan, Xiaolin Meng, Longlei Qiao
2023 J jnl
Remote. Sens.
Qing Zhao, Shuguo Pan, Ji Liu, Yin Lu, Peng Zhang, Wang Gao
2023 J jnl
IEEE Trans. Instrum. Meas.
Qi Liu, Chengfa Gao, Rui Shang, Wang Gao, Ruicheng Zhang
2023 conf
DSIT
Wang Gao, Linlin Zhang, Qian Cao
2022 J jnl
IET Image Process.
Jiansheng Wei, Shuguo Pan, Wang Gao, Tao Zhao
2022 J jnl
Expert Syst. Appl.
Futian Weng, Jianping Zhu, Cai Yang, Wang Gao, Hongwei Zhang
2022 A* conf
SP
Xuancheng Jin, Xuangan Xiao, Songlin Jia, Wang Gao, Dawu Gu, Hang Zhang, Siqi Ma, Zhiyun Qian, Juanru Li
2022 J jnl
Vis. Comput.
Tao Zhao, Shuguo Pan, Wang Gao, Chao Sheng, Yingchun Sun, Jiansheng Wei
2022 J jnl
Sensors
Jie Ren, Yusu Pan, Pantao Yao, Yicheng Hu, Wang Gao, Zhenfeng Xue
2022 J jnl
Remote. Sens.
Chun Ma, Shuguo Pan, Wang Gao, Fei Ye, Liwei Liu, Hao Wang
2022 conf
ICL-GNSS (Work in Progress)
Liwei Liu, Shuguo Pan, Wang Gao, Chun Ma
2022 J jnl
Remote. Sens.
Hong Liu, Shuguo Pan, Wang Gao, Chun Ma, Fengshuo Jia, Xinyu Lu
2022 J jnl
Remote. Sens.
Xuan He, Shuguo Pan, Wang Gao, Xinyu Lu
2022 J jnl
Remote. Sens.
Xuan He, Wang Gao, Chuanzhen Sheng, Ziteng Zhang, Shuguo Pan, Lijin Duan, Hui Zhang, Xinyu Lu
2022 J jnl
Neural Process. Lett.
Jiansheng Wei, Shuguo Pan, Wang Gao, Tao Zhao
2021 J jnl
Remote. Sens.
Liwei Liu, Shuguo Pan, Wang Gao, Chun Ma, Ju Tao, Qing Zhao
2021 J jnl
IEEE Trans. Consumer Electron.
Tao Zhao, Shuguo Pan, Wang Gao, Yingchun Sun
2021 J jnl
Remote. Sens.
Wang Gao, Qing Zhao, Xiaolin Meng, Shuguo Pan
2021 Misc conf
Inscrypt
Yunlong Lyu, Wang Gao, Siqi Ma, Qibin Sun, Juanru Li
2021 J jnl
Int. J. Distributed Sens. Networks
Wang Gao, Shuguo Pan, Liwei Liu, He Wen
2020 J jnl
IEEE Access
Fei Ye, Shuguo Pan, Wang Gao, Hao Wang, Guoliang Liu, Chun Ma, Yunfeng Wang
2020 J jnl
Remote. Sens.
Yan Xia, Shuguo Pan, Xiaolin Meng, Wang Gao, Fei Ye, Qing Zhao, Xingwang Zhao
2020 J jnl
Remote. Sens.
Yan Xia, Shuguo Pan, Xiaolin Meng, Wang Gao, He Wen
2019 J jnl
Sensors
Zhengxie Zhang, Shuguo Pan, Chengfa Gao, Tao Zhao, Wang Gao
2018 conf
CSAE
Lei Gao, Wang Gao, Haitao Gu
2017 J jnl
Remote. Sens.
Wang Gao, Chengfa Gao, Shuguo Pan, Xiaolin Meng, Yan Xia
2017 J jnl
Adv. Eng. Softw.
Yabing Cheng, Xiao-Feng Wang, Huan Liu, Wang Gao, Junyue Zhang
2015 J jnl
Sensors
Wang Gao, Chengfa Gao, Shuguo Pan, Denghui Wang, Jiadong Deng
redb/extractors/ioc_extractor/ioc_extractor.py
← Index redb/extractors/ioc_extractor/ioc_extractor.py python
"""
IOC Extractor - Extractor class for extracting IOCs from decompilation results.

This extractor works with in-memory data from DecompileBinja, following the
standard Extractor pattern to support both ClickHouse and PrintExporter (dry-run).

Usage:
    # After DecompileBinja completes:
    ioc_extractor = IOCExtractorFromResults(
        analysis_results=decompiler.analysis_results,
        sha256=sha256,
        log=logger,
        exporters=exporters,
        index_prefix=index_prefix
    )
    ioc_extractor.export_data()
"""

import inspect
from datetime import datetime, timezone
from pathlib import Path
from typing import Any, List, Dict, Optional

from redb.extractors.enum import Tag
from redb.extractors.database_exporters import DatabaseExporter

# Import the IOCScraper and related classes from standalone module
from redb.extractors.ioc_extractor.standalone_ioc_extractor import (
    IOCScraper,
    IOCType,
    SourceType,
    ExtractedIOC,
)
from typing import Set


class IOCExtractorFromResults:
    """
    Extracts IOCs from in-memory decompilation results.

    This follows a simplified Extractor pattern but doesn't inherit from Extractor
    since it doesn't read from a binary file - instead it takes already-processed
    analysis results from DecompileBinja.
    """

    def __init__(
        self,
        analysis_results: Dict[str, Any],
        sha256: str,
        log: Any,
        exporters: Optional[List[DatabaseExporter]] = None,
        index_prefix: Optional[str] = None,
        tld_file: Optional[Path] = None,
        suppress_types: Optional[Set[IOCType]] = None,
        js_context: bool = False,
    ):
        """
        Initialize IOC Extractor with analysis results.

        Args:
            analysis_results: Dict containing 'strings' and 'decompiled' lists from DecompileBinja
            sha256: Sample SHA256 hash
            log: Logger instance
            exporters: List of database exporters (ClickHouse, Print, etc.)
            index_prefix: Index prefix for database
            tld_file: Optional path to TLD list file
            js_context: When True, the underlying IOCScraper rejects FQDN
                candidates that match JS object-access syntax (see
                JS_FP_TLDS / JS_FP_SLDS). Set this for the JS pipeline only;
                APK suppresses FQDN entirely via suppress_types and binary
                callers leave it disabled.
        """
        self.log = log
        self.log.debug(f"Creating {self.__class__.__name__}")
        self.analysis_results = analysis_results
        self.sha256 = sha256
        self.exporters = exporters or []
        self.index_prefix = index_prefix
        self.scraper = IOCScraper(
            tld_file, suppress_types=suppress_types, js_context=js_context,
        )
        self.extracted_iocs: List[ExtractedIOC] = []

    def extract(self) -> List[ExtractedIOC]:
        """
        Extract IOCs from strings and decompiled functions in analysis_results.

        Returns:
            List of ExtractedIOC objects
        """
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.extracted_iocs = []

        # Extract from strings
        strings_count = self._extract_from_strings()

        # Extract from decompiled functions
        functions_count = self._extract_from_decompiled()

        # Extract from text-based artefact surfaces (JS, PowerShell, etc.)
        text_count = self._extract_from_text()

        self.log.info(
            f"Extracted {len(self.extracted_iocs)} IOCs for {self.sha256[:16]}... "
            f"(strings: {strings_count}, functions: {functions_count}, "
            f"text: {text_count})"
        )

        return self.extracted_iocs

    def _extract_from_strings(self) -> int:
        """Extract IOCs from sample's strings."""
        count = 0
        strings = self.analysis_results.get("strings", [])

        for s in strings:
            string_value = s.get("string", "")
            string_offset = s.get("string_offset", 0)

            if isinstance(string_value, bytes):
                string_value = string_value.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(string_value, SourceType.STRING, str(string_offset)):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_decompiled(self) -> int:
        """Extract IOCs from sample's decompiled functions.

        Supports both Binja format (key: "decompiled", fields: "decompiled_function",
        "decompiled_function_hash", "function_type") and APK format (key:
        "decompiled_content", fields: "decompiled_method", "decompiled_method_hash",
        "method_type").
        """
        count = 0

        # Binja format
        decompiled = self.analysis_results.get("decompiled", [])
        for func in decompiled:
            func_type = func.get("function_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_function", "")
            func_hash = func.get("decompiled_function_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        # APK format (decompiled_content with method-level fields)
        decompiled_content = self.analysis_results.get("decompiled_content", [])
        for func in decompiled_content:
            func_type = func.get("method_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_method", "")
            func_hash = func.get("decompiled_method_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_text(self) -> int:
        """Extract IOCs from text-based artefact surfaces.

        Walks `analysis_results["text_raw"]` and `analysis_results["text_normalized"]`,
        each a list of `{"content": str, "content_hash": str}` dicts. Each
        list is routed through its own SourceType (`TEXT_RAW` /
        `TEXT_NORMALIZED`) so analysts can distinguish IOCs that were already
        present in the raw source from those exposed only after normalisation
        (deobfuscation/beautification). Generic across text-based formats —
        used by JS today, intended for PowerShell, Python, email body,
        extracted PDF/Office text in the future.
        """
        count = 0

        for key, source_type in (
            ("text_raw", SourceType.TEXT_RAW),
            ("text_normalized", SourceType.TEXT_NORMALIZED),
        ):
            for entry in self.analysis_results.get(key, []):
                content = entry.get("content", "")
                content_hash = entry.get("content_hash", "unknown")

                if isinstance(content, bytes):
                    content = content.decode('utf-8', errors='replace')

                for ioc in self.scraper.scrape(content, source_type, content_hash):
                    self.extracted_iocs.append(ioc)
                    count += 1

        return count

    def prepare_export_data(self, exporter_type: str) -> Any:
        """
        Prepare data for specific export type.

        Returns tuple for ClickHouse or list of dicts for Print/Elasticsearch.
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        if not self.extracted_iocs:
            return None

        now = datetime.now(timezone.utc)

        if exporter_type == "ClickHouseExporter":
            data = [
                [
                    self.sha256,
                    ioc.ioc_type.value,
                    ioc.ioc_value,
                    ioc.source_type.value,
                    ioc.source_identifier,
                    now,
                ]
                for ioc in self.extracted_iocs
            ]

            column_names = [
                "sha256",
                "ioc_type",
                "ioc_value",
                "source_type",
                "source_identifier",
                "extracted_at",
            ]

            column_type_names = [
                "FixedString(64)",
                "Enum8('ipv4'=1, 'ipv6'=2, 'fqdn'=3, 'url'=4, 'email'=5, 'server'=6, "
                "'hash_md5'=10, 'hash_sha1'=11, 'hash_sha256'=12, 'cve'=20, 'cwe'=21, 'cpe'=22, "
                "'crypto_btc'=30, 'crypto_eth'=31, 'crypto_xrp'=32, 'crypto_bch'=33, "
                "'crypto_ada'=34, 'crypto_substrate'=35, 'path_linux'=40, 'path_windows'=41, "
                "'registry_key'=42, 'onion'=50)",
                "String",
                "Enum8('decompiled_function'=1, 'disassembled_function'=2, 'string'=3, "
                "'text_raw'=4, 'text_normalized'=5)",
                "String",
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

        else:
            # For PrintExporter and others - return list of dicts
            return [
                {
                    "sha256": self.sha256,
                    "ioc_type": ioc.ioc_type.value,
                    "ioc_value": ioc.ioc_value,
                    "source_type": ioc.source_type.value,
                    "source_identifier": ioc.source_identifier,
                    "extracted_at": now.isoformat(),
                }
                for ioc in self.extracted_iocs
            ]

    def get_clickhouse_table(self) -> str:
        """Return the ClickHouse table name for IOCs."""
        return "redb_iocs"

    def tag(self) -> str:
        """Return the tag for this extractor."""
        return Tag.IOC.value if hasattr(Tag, 'IOC') else "ioc"

    def export_data(self) -> bool:
        """
        Export extracted IOCs to all configured exporters.

        Returns:
            True if export succeeded, False if failed, None if no data
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # First extract the IOCs
        extracted = self.extract()

        if not extracted:
            self.log.debug("No IOCs extracted, skipping export")
            return None

        success = True

        from redb.extractors.database_exporters import PrintExporter, ClickHouseExporter

        for exporter in self.exporters:
            try:
                if isinstance(exporter, PrintExporter):
                    # For PrintExporter, pass the list of dicts
                    export_data = self.prepare_export_data("PrintExporter")
                    success &= exporter.export(export_data)

                elif isinstance(exporter, ClickHouseExporter):
                    # For ClickHouse, pass tuple with table info
                    export_data = self.prepare_export_data("ClickHouseExporter")
                    if export_data:
                        success &= exporter.export(
                            export_data,
                            table=self.get_clickhouse_table(),
                            column_names=export_data[1],
                            column_type_names=export_data[2]
                        )

            except Exception as e:
                self.log.error(f"Error exporting IOCs to {exporter.__class__.__name__}: {e}")
                success = False

        return success