Wei-Chung Teng

33 papers B 8C 2Misc 1Journal 10Unranked 12
YearRankTypeTitle / Venue / Authors
2025 conf
IEA/AIE (2)
Wei-Chung Teng, Chun-Yi Tseng
2025 conf
ARTMAN@CCS
Yu-Cheng Lin, Tao Ban, Shin-Ming Cheng, Takeshi Takahashi, Wei-Chung Teng
2025 conf
ARTMAN@CCS
Yi-Shan Cheng, Tao Ban, Shin-Ming Cheng, Takeshi Takahashi, Wei-Chung Teng
2025 J jnl
SN Comput. Sci.
Nyoman Putra Sastra, Komang Oka Saputra, Wei-Chung Teng
2024 Misc conf
ICMLC
Che-Hao Hsu, Wei-Chung Teng
2018 J jnl
Comput. Hum. Behav.
Hadziq Fabroyir, Wei-Chung Teng
2017 J jnl
IEEE Access
Rayi Yanu Tara, Wei-Chung Teng
2017 J jnl
Intell. Serv. Robotics
Rayi Yanu Tara, Wei-Chung Teng
2017 conf
GCCE
Tien-Ming Yen, Chih-Yuan Yao, Hung-Kung Chu, Yu-Chi Lai, Pe-Ying Chiang, Hsiao-Chin Chen, Wei-Chung Teng, Ya-Wen Hsu
2016 J jnl
IEICE Trans. Inf. Syst.
Komang Oka Saputra, Wei-Chung Teng, Takaaki Nara
2015 conf
WI-IAT (3)
Komang Oka Saputra, Wei-Chung Teng, Yi-Hao Chu
2015 J jnl
IEEE Trans. Instrum. Meas.
Komang Oka Saputra, Wei-Chung Teng, Tsung-Han Chen
2015 B conf
SMC
Rayi Yanu Tara, Wei-Chung Teng
2014 conf
ICA3PP (1)
Chyouhwa Chen, Wei-Chung Teng, Yu-Ren Wu
2014 J jnl
J. Netw. Comput. Appl.
Ding-Jie Huang, Wei-Chung Teng
2014 J jnl
IEICE Trans. Inf. Syst.
Hadziq Fabroyir, Wei-Chung Teng, Yen-Chun Lin
2014 conf
CASE
Ding-Jie Huang, Kai-Ting Yang, Wei-Chung Teng, Ge-Ming Chiu
2013 B conf
SMC
Wei-Chung Teng, Yi-Ching Kuo, Rayi Yanu Tara
2013 conf
ISBAST
Chyouhwa Chen, Po-Chung Tung, Wei-Chung Teng
2013 C conf
CW
Hadziq Fabroyir, Wei-Chung Teng, Shu-Ling Wang, Rayi Yanu Tara
2013 J jnl
Int. J. Commun. Syst.
Ding-Jie Huang, Wei-Chung Teng, Kai-Ting Yang
2012 B conf
AINA
Ding-Jie Huang, Kai-Ting Yang, Chien-Chun Ni, Wei-Chung Teng, Tien-Ruey Hsiang, Yuh-Jye Lee
2012 J jnl
Appl. Math. Comput.
Kuo-Liang Chung, Yong-Huai Huang, Wen-Ming Yan, Wei-Chung Teng
2012 B conf
WiMob
Kai-Ting Yang, Ge-Ming Chiu, Huei-Jhih Lyu, Ding-Jie Huang, Wei-Chung Teng
2011 B conf
MASS
Ding-Jie Huang, Kai-Jie You, Wei-Chung Teng
2009 B conf
SMC
Wei-Chung Teng, Hsuan-Yu Huang, Sheng-Luen Chung
2009 conf
ICAR
Chyi-Yeu Lin, Chang-Kuo Tseng, Wei-Chung Teng, Wei-Chen Lee, Chung-Hsien Kuo, Hung-Yan Gu, Kuo-Liang Chung, Chin-Shyurng Fahn
2008 conf
IAT
Wei-Lun Teng, Wei-Chung Teng
2008 B conf
GLOBECOM
Ding-Jie Huang, Wei-Chung Teng, Chih-Yuan Wang, Hsuan-Yu Huang, Joseph M. Hellerstein
2008 C conf
APSCC
Wei-Chung Teng, Yu-Chun Pao, Sheng-Luen Chung
2008 B conf
WCNC
Tanya G. Roosta, Wei-Chieh Liao, Wei-Chung Teng, Shankar Sastry
2007 conf
KES (2)
Ding-Jie Huang, Wei-Chung Teng
2004 conf
VTC Fall (2)
Huei-Wen Ferng, Hsin-Jung Lin, Wei-Chung Teng, Yi-Chou Tsai, Cheng-Ching Peng
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"