Wei Bao

71 papers A* 3B 1C 3Misc 1Journal 41Unranked 22
YearRankTypeTitle / Venue / Authors
2026 J jnl
Appl. Math. Comput.
Huaihe Huang, Ye Ye, Wei Bao, Yue Zhang, Nenggang Xie
2026 J jnl
Appl. Math. Comput.
Huaihe Huang, Ye Ye, Wei Bao, Yue Zhang, Nenggang Xie
2026 J jnl
Pattern Recognit.
Siqi Li, Yongji Zhang, Wei Bao, Yue Gao
2026 J jnl
ACM Trans. Manag. Inf. Syst.
Wei Bao, Ke Lu, Xianwen Fang, Xiwei Zhang
2026 A* conf
AAAI
Hongli Zhou, Hui Huang, Ziqing Zhao, Lvyuan Han, Huicheng Wang, Kehai Chen, Muyun Yang, Wei Bao, Jian Dong, Bing Xu, Conghui Zhu, Hailong Cao, Tiejun Zhao
2026 J jnl
IEICE Trans. Inf. Syst.
Maoke Zhou, Xiaoke Qi, Wei Bao, Xiaobing Zhao
2025 J jnl
J. Supercomput.
Jian Dong, Wei Bao, Xiaoqi Cao, Yang Xu, Yuze Yang, Binbin Li, Qi Zhang, Heng Ye
2025 J jnl
Int. J. Hum. Comput. Interact.
Yuanyuan Yang, Wei Bao
2025 J jnl
J. Oper. Res. Soc.
Minghui Xu, Wei Bao, Dongsheng Yang
2025 J jnl
IEEE Trans. Geosci. Remote. Sens.
Wei Bao, Meiyu Huang, Jingjing Hu, Xueshuang Xiang
2025 J jnl
CoRR
Ziyuan Tao, Chuanzhi Xu, Sandaru Jayawardana, Wei Bao, Kanchana Thilakarathna, Teng Joon Lim
2025 conf
NLPCC (3)
Xinyi Li, Yan Yan, Bo Chen, Wei Bao, Xiaobing Zhao
2025 A* conf
SIGIR
Wei Bao, Hao Chen, Bang Lin, Tao Zhang, Chengfu Huo
2025 J jnl
IEEE Trans. Intell. Transp. Syst.
Jianwei Zhao, Yubo Wu, Wei Bao, Jingxiang Shi, Xingguo Liu
2025 J jnl
CoRR
Hongli Zhou, Hui Huang, Ziqing Zhao, Lvyuan Han, Huicheng Wang, Kehai Chen, Muyun Yang, Wei Bao, Jian Dong, Bing Xu, Conghui Zhu, Hailong Cao, Tiejun Zhao
2025 J jnl
Comput. Medical Imaging Graph.
Xiaoyang Zou, Zhuyuan Zhang, Derong Yu, Wenyuan Sun, Wenyong Liu, Donghua Hang, Wei Bao, Guoyan Zheng
2024 J jnl
IEEE Internet Things J.
Xiang Wu, Jian Dong, Wei Bao, Baowen Zou, Lili Wang, Huanhuan Wang
2024 J jnl
Data Intell.
Wei Bao, Jian Dong, Yang Xu, Yuanyuan Yang, Xiaoke Qi
2024 J jnl
Appl. Math. Lett.
Xuelian Jiang, Ziming Wang, Wei Bao, Yingxiang Xu
2024 conf
VTC Spring
Wei Bao, Jiangtao Wang, Yongchao Wang
2024 J jnl
Knowl. Based Syst.
Jinyao Ma, Jiaojiao Jiang, Wei Bao, Haibin Zhang
2024 J jnl
CoRR
Wei Bao, Mi Zhang, Tao Zhang, Chengfu Huo
2024 J jnl
Knowl. Based Syst.
Yingli Shen, Wei Bao, Ge Gao, Maoke Zhou, Xiaobing Zhao
2023 J jnl
Pattern Recognit.
Jun Guo, Wei Bao, Jiakai Wang, Yuqing Ma, Xinghai Gao, Gang Xiao, Aishan Liu, Jian Dong, Xianglong Liu, Wenjun Wu
2023 J jnl
Frontiers Comput. Neurosci.
Zhen Zhao, Joon Huang Chuah, Khin Wee Lai, Chee-Onn Chow, Munkhjargal Gochoo, Samiappan Dhanalakshmi, Na Wang, Wei Bao, Xiang Wu
2023 conf
PRCV (1)
Wei Bao, Jingjing Hu, Meiyu Huang, Xueshuang Xiang
2023 C conf
iSPEC
Ran Chen, Hua Huang, Wei Bao, Linlin Chu, Haohua Peng, Jianqiao Zhou, Jianwen Zhang, Gang Shi
2023 J jnl
IEEE Access
Fengli Zhang, Yatish Dubasi, Wei Bao, Qinghua Li
2023 J jnl
Entertain. Comput.
Youcheng Wang, Qiuhao Huang, Zun Xie, Meng Wang, Wei Bao
2023 conf
PRCV (10)
Feng Deng, Meiyu Huang, Wei Bao, Nan Ji, Xueshuang Xiang
2023 A* conf
ICCV
Xiaobo Xia, Jiankang Deng, Wei Bao, Yuxuan Du, Bo Han, Shiguang Shan, Tongliang Liu
2023 J jnl
Comput. Biol. Medicine
Wanying Jia, Songjie Li, Shao Qian, Meng Wang, Wei Bao, Jie Zhao, Kang Hao Cheong, Nenggang Xie
2023 C conf
iSPEC
Ran Chen, Hua Huang, Wei Bao, Yong Liu, Jianqiao Zhou, Jianwen Zhang, Gang Shi
2023 J jnl
IEEE Des. Test
Peng Cao, Tai Yang, Kai Wang, Wei Bao, Hao Yan
2022 conf
PRCV (1)
Wei Bao, Meiyu Huang, Jingjing Hu, Xueshuang Xiang
2022 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Wei Bao, Jingjing Hu, Meiyu Huang, Yao Xu, Nan Ji, Xueshuang Xiang
2022 conf
AIPR
Pengjing Guo, Jianjun Zhao, Zizhuan Li, Xianda Ni, Daohuan Tan, Wei Bao
2022 J jnl
Entropy
Zun Xie, Jianwei Pan, Songjie Li, Jing Ren, Shao Qian, Ye Ye, Wei Bao
2021 conf
ASP-DAC
Peng Cao, Wei Bao, Kai Wang, Tai Yang
2021 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Wei Bao, Meiyu Huang, Yaqin Zhang, Yao Xu, Xuejiao Liu, Xueshuang Xiang
2021 J jnl
CoRR
Wei Bao, Meiyu Huang, Yaqin Zhang, Yao Xu, Xuejiao Liu, Xueshuang Xiang
2021 J jnl
IEEE Access
Wei Bao, Meiyu Huang, Xueshuang Xiang
2021 J jnl
CoRR
Meiyu Huang, Yao Xu, Lixin Qian, Weili Shi, Yaqin Zhang, Wei Bao, Nan Wang, Xuejiao Liu, Xueshuang Xiang
2021 conf
CICAI
Meiyu Huang, Yao Xu, Wei Bao, Xueshuang Xiang
2020 conf
ACM Great Lakes Symposium on VLSI
Wei Bao, Peng Cao, Hao Cai, Aiguo Bu
2020 J jnl
CoRR
Wei Bao, Hongshu Che, Jiandong Zhang
2020 J jnl
Sci. China Inf. Sci.
Wei Bao, Wei Wang, Yuhua Xu, Yulan Guo, Siyu Hong, Xiaohu Zhang
2020 J jnl
Concurr. Comput. Pract. Exp.
Wei Bao, Chuang Ye Pan, Lu Wang, Qing Zhang, Nenggang Xie
2020 conf
SemEval@COLING
Wei Bao, Hongshu Che, Jiandong Zhang
2020 conf
SemEval@COLING
Wei Bao, Weilong Chen, Wei Bai, Yan Zhuang, Mingyuan Cheng, Xiangyu Ma
2019 J jnl
Vis. Comput.
Liang Xie, Yuhua Xu, Xiaohu Zhang, Wei Bao, Chenpeng Tong, Boxin Shi
2019 J jnl
CoRR
Shangyuan Li, Li Feng, Deqiang Gan, Zhen Wang, Wei Bao, Hao Xu
2018 conf
IALP
Wei Bao, Wugedele Bao, Jinhua Du, Yuanyuan Yang, Xiaobing Zhao
2018 conf
PAC
Wei Bao, Qinghua Li
2018 Misc conf
ICNC
Wei Bao, Qinghua Li
2018 conf
LoResMT@AMTA
Wen Lai, Xiaobing Zhao, Wei Bao
2017 J jnl
J. Ambient Intell. Humaniz. Comput.
Ya Li, Jianhua Tao, Linlin Chao, Wei Bao, Yazhu Liu
2017 J jnl
KSII Trans. Internet Inf. Syst.
Kai Wang, Wei Bao, Yingjie Wang, Xiangrong Tong
2017 conf
ISGT Asia
Shaohui Zhang, Yuehao Yan, Wei Bao, Mengru Ma, Jiandong Jiang, Shuaiwen Guo
2017 J jnl
Neurocomputing
Ruilin Pan, Xuemin Wang, Changsheng Yi, Zhanchao Zhang, Yanglong Fan, Wei Bao
2017 conf
ISGT Asia
Shaohui Zhang, Yuehao Yan, Wei Bao, Shuaiwen Guo, Jiandong Jiang, Mengru Ma
2016 J jnl
Int. J. Model. Identif. Control.
Huifang Kong, Xiaoxue Zhang, Hai Wang, Wei Bao, Kaiwen Jiang
2015 conf
ISGT Asia
Wei Bao, Yuehao Yan, Yuanhong Chi, Weiyu Bao
2015 B conf
ACII
Ya Li, Linlin Chao, Yazhu Liu, Wei Bao, Jianhua Tao
2014 conf
ISCSLP
Wei Bao, Ya Li, Mingliang Gu, Jianhua Tao, Linlin Chao, Shanfeng Liu
2013 J jnl
IET Commun.
Wei Bao, Jianhua Zhang, Ping Zhang
2013 conf
VTC Spring
Xiaodan He, Jianhua Zhang, Wei Bao
2012 conf
VTC Fall
Jianhua Zhang, Wei Bao, Ping Zhang, Qiang Wang
2012 conf
VTC Fall
Wei Bao, Jianhua Zhang, Ping Zhang
2010 C conf
ISORC
Nan Li, Hong Li, Jian Wu, Xiaofeng Zhong, Zheng Sun, Wei Bao
2008 conf
ICIRA (1)
Yuhua Xu, Chongwei Zhang, Wei Bao, Ling Su, Mulan Wang
redb/extractors/js_extractors/js_patterns.py
← Index redb/extractors/js_extractors/js_patterns.py python
"""Canonical, compiled JavaScript regex patterns shared across JS extractors.

All suspicious-API patterns and the few feature-only patterns live here so each
expression is compiled exactly once per Python process and so any pattern that
was previously duplicated across `js_features.py` and `js_suspicious_apis.py`
now resolves to a single shared compiled object.

JavaScript is case-sensitive at runtime, but every suspicious-API pattern matches
either a literal-case identifier (`\\beval\\s*\\(`, `String\\.fromCharCode`, etc.)
or a string-quoted token (`"powershell"`). Compiling them with `re.IGNORECASE`
matches the historical behaviour of `JSSuspiciousAPIsExtractor` and is safe for
the patterns that historically came from `JSFeaturesExtractor` — those literals
are spelled in real-world JS exactly as written.

`scan_source()` is the entry point used by extractors: it walks the source once
per pattern using the pre-compiled regexes and returns a flat
`{name: {"count": N, "lines": [unique_line_numbers_sorted]}}` dict. Both
`JSFeaturesExtractor` and `JSSuspiciousAPIsExtractor` consume the same dict so
the per-pattern × per-line loops they used to run independently collapse to a
single shared scan.
"""

import bisect
import re
from typing import Dict, Iterable, List, Mapping

_FLAGS = re.IGNORECASE

# Canonical compiled patterns, keyed by their human-readable name. The name is
# also the value emitted into `redb_js_suspicious_apis.api_name`.
PATTERNS = {
    # ---- code execution ----
    "eval": re.compile(r"\beval\s*\(", _FLAGS),
    "Function constructor": re.compile(r"\bnew\s+Function\s*\(", _FLAGS),
    "execScript": re.compile(r"\bexecScript\s*\(", _FLAGS),
    "document.write": re.compile(r"\bdocument\.write(?:ln)?\s*\(", _FLAGS),
    "innerHTML assignment": re.compile(r"\.innerHTML\s*=", _FLAGS),
    "outerHTML assignment": re.compile(r"\.outerHTML\s*=", _FLAGS),
    "insertAdjacentHTML": re.compile(r"\.insertAdjacentHTML\s*\(", _FLAGS),
    # ---- network ----
    "XMLHttpRequest": re.compile(r"\bnew\s+XMLHttpRequest\b", _FLAGS),
    "fetch": re.compile(r"\bfetch\s*\(", _FLAGS),
    "WebSocket": re.compile(r"\bnew\s+WebSocket\s*\(", _FLAGS),
    "navigator.sendBeacon": re.compile(r"\bnavigator\.sendBeacon\s*\(", _FLAGS),
    "ActiveXObject XMLHTTP": re.compile(
        r"ActiveXObject\s*\(\s*[\"\'](?:MSXML2\.XMLHTTP|Microsoft\.XMLHTTP)", _FLAGS
    ),
    "require network module": re.compile(
        r"require\s*\(\s*[\"\'](?:http|https|net|dgram)[\"\']", _FLAGS
    ),
    "axios": re.compile(r"\baxios\b", _FLAGS),
    # ---- filesystem ----
    "require fs": re.compile(r"require\s*\(\s*[\"\']fs[\"\']", _FLAGS),
    "require path": re.compile(r"require\s*\(\s*[\"\']path[\"\']", _FLAGS),
    "FileSystemObject": re.compile(r"Scripting\.FileSystemObject", _FLAGS),
    "ADODB.Stream": re.compile(r"ADODB\.Stream", _FLAGS),
    "Shell.Application": re.compile(r"Shell\.Application", _FLAGS),
    "WScript.CreateObject": re.compile(r"WScript\.CreateObject", _FLAGS),
    # ---- process ----
    "require child_process": re.compile(r"require\s*\(\s*[\"\']child_process[\"\']", _FLAGS),
    "child_process exec": re.compile(r"child_process\.(?:exec|spawn|execFile|fork)\s*\(", _FLAGS),
    "WScript.Shell": re.compile(r"WScript\.Shell", _FLAGS),
    "WScript.Shell.Run": re.compile(r"\.Run\s*\(", _FLAGS),
    "WScript.Shell.Exec": re.compile(r"\.Exec\s*\(", _FLAGS),
    "ShellExecute": re.compile(r"\bShellExecute\b", _FLAGS),
    "PowerShell reference": re.compile(r"[\"\']powershell[\"\']", _FLAGS),
    "cmd.exe reference": re.compile(r"[\"\']cmd\.exe[\"\']", _FLAGS),
    "require os": re.compile(r"require\s*\(\s*[\"\']os[\"\']", _FLAGS),
    # ---- registry ----
    "RegRead": re.compile(r"\.RegRead\s*\(", _FLAGS),
    "RegWrite": re.compile(r"\.RegWrite\s*\(", _FLAGS),
    "RegDelete": re.compile(r"\.RegDelete\s*\(", _FLAGS),
    "StdRegProv": re.compile(r"StdRegProv", _FLAGS),
    # ---- crypto / encoding ----
    "atob": re.compile(r"\batob\s*\(", _FLAGS),
    "btoa": re.compile(r"\bbtoa\s*\(", _FLAGS),
    "String.fromCharCode": re.compile(r"String\.fromCharCode\s*\(", _FLAGS),
    "unescape": re.compile(r"\bunescape\s*\(", _FLAGS),
    "decodeURIComponent": re.compile(r"\bdecodeURIComponent\s*\(", _FLAGS),
    "Buffer.from": re.compile(r"Buffer\.from\s*\(", _FLAGS),
    "crypto module": re.compile(r"crypto\.create(?:Cipher|Decipher|Hash|Hmac)", _FLAGS),
    # ---- DOM manipulation ----
    "document.forms": re.compile(r"document\.forms", _FLAGS),
    "document.cookie": re.compile(r"document\.cookie", _FLAGS),
    "querySelector sensitive input": re.compile(
        r"document\.querySelector\s*\([^)]*(?:password|credit|card|cvv|ssn)", _FLAGS
    ),
    "submit event listener": re.compile(r"addEventListener\s*\(\s*[\"\']submit", _FLAGS),
    "createElement script/iframe": re.compile(
        r"\.createElement\s*\(\s*[\"\'](?:script|iframe)", _FLAGS
    ),
    "dynamic script src": re.compile(r"\.src\s*=\s*[\"\'](?:https?://|//)", _FLAGS),
}

# Pattern name -> category (one of code_execution / network / filesystem /
# process / registry / crypto_encoding / dom_manipulation).
CATEGORIES = {
    "eval": "code_execution",
    "Function constructor": "code_execution",
    "execScript": "code_execution",
    "document.write": "code_execution",
    "innerHTML assignment": "code_execution",
    "outerHTML assignment": "code_execution",
    "insertAdjacentHTML": "code_execution",
    "XMLHttpRequest": "network",
    "fetch": "network",
    "WebSocket": "network",
    "navigator.sendBeacon": "network",
    "ActiveXObject XMLHTTP": "network",
    "require network module": "network",
    "axios": "network",
    "require fs": "filesystem",
    "require path": "filesystem",
    "FileSystemObject": "filesystem",
    "ADODB.Stream": "filesystem",
    "Shell.Application": "filesystem",
    "WScript.CreateObject": "filesystem",
    "require child_process": "process",
    "child_process exec": "process",
    "WScript.Shell": "process",
    "WScript.Shell.Run": "process",
    "WScript.Shell.Exec": "process",
    "ShellExecute": "process",
    "PowerShell reference": "process",
    "cmd.exe reference": "process",
    "require os": "process",
    "RegRead": "registry",
    "RegWrite": "registry",
    "RegDelete": "registry",
    "StdRegProv": "registry",
    "atob": "crypto_encoding",
    "btoa": "crypto_encoding",
    "String.fromCharCode": "crypto_encoding",
    "unescape": "crypto_encoding",
    "decodeURIComponent": "crypto_encoding",
    "Buffer.from": "crypto_encoding",
    "crypto module": "crypto_encoding",
    "document.forms": "dom_manipulation",
    "document.cookie": "dom_manipulation",
    "querySelector sensitive input": "dom_manipulation",
    "submit event listener": "dom_manipulation",
    "createElement script/iframe": "dom_manipulation",
    "dynamic script src": "dom_manipulation",
}

# Patterns consumed only by JSFeaturesExtractor (no category, never surfaced as
# a suspicious-API row). Kept here so every JS regex is compiled in one place.
FEATURE_PATTERNS = {
    "hex_escape": re.compile(r"\\x[0-9a-fA-F]{2}"),
    "unicode_escape": re.compile(r"\\u[0-9a-fA-F]{4}"),
    "base64_string": re.compile(r"[A-Za-z0-9+/]{40,}={0,2}"),
    # decodeURI matches BOTH decodeURI and decodeURIComponent. The latter is also
    # a suspicious-API pattern in PATTERNS; this broader form is what the
    # `decodeuri_count` feature column has historically counted.
    "decodeURI": re.compile(r"\b(?:decodeURI|decodeURIComponent)\s*\(", _FLAGS),
    "settimeout_setinterval": re.compile(r"\b(?:setTimeout|setInterval)\s*\(", _FLAGS),
    "function_decl": re.compile(r"\bfunction\s+\w+\s*\(|\bfunction\s*\("),
    "var_decl": re.compile(r"\b(?:var|let|const)\s+"),
    "string_concat": re.compile(r"[\"\'][\s]*\+[\s]*[\"\']"),
    "comment": re.compile(r"//.*?$|/\*[\s\S]*?\*/", re.MULTILINE),
    "long_string": re.compile(r"[\"\']([^\"\']{256,})[\"\']"),
    "array_function_call": re.compile(r"\[(?:0x[0-9a-f]+|[\d]+)\]\s*\(", _FLAGS),
}

# Patterns consumed only by JSStringsExtractor for encoded-string discovery.
# Scoped to *hidden* strings only — patterns whose decoded form is not visible
# to a substring search over the raw text. Plain long literals are not
# extracted here because they're already preserved in code_text_content and
# scraped by the IOC pipeline over text_raw / text_normalized.
#
# Distinct from FEATURE_PATTERNS even where the names rhyme:
#   FEATURE_PATTERNS["hex_escape"] / ["unicode_escape"]   -> single escape
#   STRING_PATTERNS["hex_escape_seq"] / ["unicode_escape_seq"] -> 4+ / 3+ in a row
#   FEATURE_PATTERNS["base64_string"]                     -> bare base64 token
#   STRING_PATTERNS["base64_quoted"]                      -> base64 inside JS quotes
# These do not share match objects with the suspicious-API or feature scans, so
# they are not folded into JSContext.scan; the strings extractor walks them
# itself (one finditer per pattern, with shared line-offset bisect in #4b).
STRING_PATTERNS = {
    "hex_escape_seq": re.compile(r"(?:\\x[0-9a-fA-F]{2}){4,}"),
    "unicode_escape_seq": re.compile(r"(?:\\u[0-9a-fA-F]{4}){3,}"),
    "charcode_call": re.compile(r"String\.fromCharCode\s*\(\s*([\d,\s]+)\s*\)"),
    "base64_quoted": re.compile(r"[\"\']([A-Za-z0-9+/]{40,}={0,2})[\"\']"),
    "concat_chain": re.compile(r"(?:[\"\'][^\"\']+[\"\']\s*\+\s*){3,}[\"\'][^\"\']+[\"\']"),
}


def line_offsets(source: str) -> List[int]:
    """Sorted list of byte offsets for every newline in `source`, plus a final
    sentinel of len(source). Used to translate match offsets into 1-indexed
    line numbers via bisect.
    """
    offsets = [-1]  # so that bisect_right of offset 0 returns line 1
    push = offsets.append
    idx = source.find("\n")
    while idx != -1:
        push(idx)
        idx = source.find("\n", idx + 1)
    return offsets


def _scan_one(
    pattern: "re.Pattern[str]", source: str, offsets: List[int]
) -> Dict[str, object]:
    """Run a single compiled pattern over `source` and return count + unique lines."""
    count = 0
    seen_lines: "set[int]" = set()
    for m in pattern.finditer(source):
        count += 1
        seen_lines.add(bisect.bisect_right(offsets, m.start()))
    if not count:
        return None  # type: ignore[return-value]
    return {"count": count, "lines": sorted(seen_lines)}


def scan_source(
    source: str,
    patterns: Iterable[Mapping[str, "re.Pattern[str]"]] = (PATTERNS, FEATURE_PATTERNS),
) -> Dict[str, Dict[str, object]]:
    """Scan `source` against every compiled pattern in `patterns`.

    Returns a dict keyed by pattern name. Each entry has:
        "count": total number of matches in the source
        "lines": sorted list of unique 1-indexed line numbers where the pattern
                 matched (deduplicated — multiple matches on the same line
                 collapse to one entry, preserving the historical
                 line-set semantics of JSSuspiciousAPIsExtractor)
    Patterns with zero matches are absent from the dict; callers should default
    to {"count": 0, "lines": []}.
    """
    if not source:
        return {}
    offsets = line_offsets(source)
    results: Dict[str, Dict[str, object]] = {}
    for table in patterns:
        for name, pat in table.items():
            entry = _scan_one(pat, source, offsets)
            if entry is not None:
                results[name] = entry
    return results