Wei Feng

67 papers B 3C 22Journal 40Unranked 2
YearRankTypeTitle / Venue / Authors
2026 J jnl
Digit. Signal Process.
Wenkai Xu, Wenxing Bao, Wei Feng, Kewen Qu, Xuan Ma, Xiaowu Zhang, Wenlong Wang
2025 J jnl
Symmetry
Peiting Shan, Wei Feng, Shuntian Lou, Gabriel Dauphin, Wenxing Bao
2025 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Zhizhong Liu, Wenxing Bao, Wei Feng, Kewen Qu, Xuan Ma, Xiaowu Zhang
2025 J jnl
IEEE Trans. Geosci. Remote. Sens.
Yongxu Liu, Zhihao Ma, Wenxiang Zhu, Na Li, Chuang Li, Kai Xiong, Zhenyu Wang, Wei Feng, Junzheng Jiang, Yinghui Quan
2025 J jnl
IEEE Geosci. Remote. Sens. Lett.
Shuxian Dong, Wei Feng, Yijun Long, Wenxing Bao, Ke Li, Gabriel Dauphin, Mengdao Xing, Yinghui Quan
2024 C conf
IGARSS
Yali Zhang, Wei Feng, Yinghui Quan, Fan Bu, Zhiwei Xie, Mengdao Xing
2024 C conf
IGARSS
Wei Feng, Fan Bu, Xinting Gao, Shuo Wang, Yinghui Quan, Gabriel Dauphin, Mengdao Xing, Yan Lv
2024 J jnl
Remote. Sens.
Yan Lv, Wei Feng, Shuo Wang, Shiyu Wang, Liang Guo, Gabriel Dauphin
2024 J jnl
Remote. Sens.
Yali Zhang, Wei Feng, Yinghui Quan, Guangqiang Ye, Gabriel Dauphin
2024 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Wei Feng, Yijun Long, Gabriel Dauphin, Yinghui Quan, Wenjiang Huang, Mengdao Xing
2024 J jnl
Remote. Sens.
Wei Feng, Fan Bu, Puxia Wu, Gabriel Dauphin, Yinghui Quan, Mengdao Xing
2024 C conf
IGARSS
Han Lang, Wenxing Bao, Wei Feng, Shasha Sun, Xuan Ma, Xiaowu Zhang
2024 J jnl
IEEE Signal Process. Lett.
Lihe Yang, Wei Feng, Yaojun Wu, Liang Huang, Yinghui Quan
2023 J jnl
Symmetry
Shiruo Liu, Xiaoguang Yuan, Wei Feng, Aifeng Ren, Zhenyong Hu, Zuheng Ming, Adnan Zahid, Qammer H. Abbasi, Shuo Wang
2023 J jnl
Symmetry
Qiang Li, Wei Feng, Guo-Li Wang
2023 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Yang Cao, Wei Feng, Yinghui Quan, Wenxing Bao, Gabriel Dauphin, Yijia Song, Aifeng Ren, Mengdao Xing
2023 J jnl
Remote. Sens.
Xiaoguang Yuan, Yiduo Liang, Wei Feng, Junhang Li, Hongtao Ren, Shuo Han, Mengqi Liu
2023 J jnl
IEEE Geosci. Remote. Sens. Lett.
Yijia Song, Wei Feng, Gabriel Dauphin, Yijun Long, Yinghui Quan, Mengdao Xing
2023 J jnl
Remote. Sens.
Xiaoguang Yuan, Shiruo Liu, Wei Feng, Gabriel Dauphin
2023 J jnl
Remote. Sens.
Shasha Sun, Wenxing Bao, Kewen Qu, Wei Feng, Xiaowu Zhang, Xuan Ma
2023 C conf
IGARSS
Shasha Sun, Wenxing Bao, Hao Guo, Kewen Qu, Wei Feng
2023 J jnl
IEEE Trans. Geosci. Remote. Sens.
Wei Feng, Xinting Gao, Samia Boukir, Zhiwei Xie, Yinghui Quan, Wenjiang Huang, Mengdao Xing
2023 J jnl
CoRR
Bo Zhang, Zuheng Ming, Wei Feng, Yaqian Liu, Liang He, Kaixing Zhao
2023 C conf
IGARSS
Hao Guo, Wenxing Bao, Wei Feng, Shasha Sun, Lei Yang, Kewen Qu, Xuan Ma, Xiaowu Zhang
2023 J jnl
Remote. Sens.
Hao Guo, Wenxing Bao, Wei Feng, Shasha Sun, Chunhui Mo, Kewen Qu
2023 B conf
ICIP
Wei Feng, Xinting Gao, Gabriel Dauphin, Yinghui Quan
2023 conf
CICAI (1)
Bo Zhang, Zuheng Ming, Yaqian Liu, Wei Feng, Liang He, Kaixing Zhao
2023 conf
WHISPERS
Jiming Tang, Wenxing Bao, Bingbing Lei, Kewen Qu, Wei Feng
2023 J jnl
Symmetry
Yan Lv, Wei Feng, Shuo Wang, Gabriel Dauphin, Yali Zhang, Mengdao Xing
2022 C conf
IGARSS
Xinshan Zou, Wei Feng, Yinghui Quan, Qiang Li, Gabriel Dauphin, Mengdao Xing
2022 J jnl
Remote. Sens.
Daying Quan, Wei Feng, Gabriel Dauphin, Xiaofeng Wang, Wenjiang Huang, Mengdao Xing
2022 C conf
IGARSS
Yali Zhang, Wei Feng, Yinghui Quan, Xian Zhong, Yijia Song, Qiang Li, Gabriel Dauphin, Yong Wang, Mengdao Xing
2022 J jnl
Comput. Electron. Agric.
Shuo Wang, Wei Feng, Yinghui Quan, Qiang Li, Gabriel Dauphin, Wenjiang Huang, Jing Li, Mengdao Xing
2022 J jnl
IEEE Trans. Geosci. Remote. Sens.
Shuxian Dong, Wei Feng, Yinghui Quan, Gabriel Dauphin, Lianru Gao, Mengdao Xing
2022 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Qinzhe Lv, Yinghui Quan, Minghui Sha, Wei Feng, Mengdao Xing
2022 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Yang Cao, Wei Feng, Yinghui Quan, Wenxing Bao, Gabriel Dauphin, Aifeng Ren, Xiaoguang Yuan, Mengdao Xing
2022 J jnl
IEEE Trans. Geosci. Remote. Sens.
Qinzhe Lv, Yinghui Quan, Wei Feng, Minghui Sha, Shuxian Dong, Mengdao Xing
2022 C conf
IGARSS
Yijia Song, Wei Feng, Yinghui Quan, Yue Liu, Qiang Li, Gabriel Dauphin, Yong Wang, Mengdao Xing
2022 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Shuo Wang, Wei Feng, Yinghui Quan, Wenxing Bao, Gabriel Dauphin, Lianru Gao, Xian Zhong, Mengdao Xing
2021 C conf
IGARSS
Yang Cao, Wei Feng, Yinghui Quan, Aifeng Ren, Mengdao Xing
2021 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Shuxian Dong, Yinghui Quan, Wei Feng, Gabriel Dauphin, Lianru Gao, Mengdao Xing
2021 C conf
IGARSS
Bowen Bie, Yinghui Quan, Guang-Cai Sun, Wei Feng, Mengdao Xing
2021 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Qinzhe Lv, Wei Feng, Yinghui Quan, Gabriel Dauphin, Lianru Gao, Mengdao Xing
2021 C conf
IGARSS
Shuxian Dong, Yinghui Quan, Wei Feng, Qiang Li, Gabriel Dauphin, Mengdao Xing
2021 C conf
IGARSS
Qinzhe Lv, Wei Feng, Yinghui Quan, Qiang Li, Gabriel Dauphin, Lianru Gao, Guoping Zhao, Mengdao Xing
2021 C conf
IGARSS
Xian Zhong, Yinghui Quan, Wei Feng, Qiang Li, Gabriel Dauphin, Mengdao Xing
2021 C conf
IGARSS
Yingping Tong, Yinghui Quan, Wei Feng, Gabriel Dauphin, Yong Wang, Puxia Wu, Mengdao Xing
2021 J jnl
Remote. Sens.
Yinghui Quan, Yingping Tong, Wei Feng, Gabriel Dauphin, Wenjiang Huang, Wentao Zhu, Mengdao Xing
2021 J jnl
Remote. Sens.
Yinghui Quan, Xian Zhong, Wei Feng, Jonathan Cheung-Wai Chan, Qiang Li, Mengdao Xing
2021 J jnl
Inf. Sci.
Wei Feng, Yinghui Quan, Gabriel Dauphin, Qiang Li, Lianru Gao, Wenjiang Huang, Junshi Xia, Wentao Zhu, Mengdao Xing
2020 J jnl
Remote. Sens.
Yinghui Quan, Xian Zhong, Wei Feng, Gabriel Dauphin, Lianru Gao, Mengdao Xing
2020 J jnl
Remote. Sens.
Yinghui Quan, Yingping Tong, Wei Feng, Gabriel Dauphin, Wenjiang Huang, Mengdao Xing
2020 B conf
ICPR
Samia Boukir, Wei Feng
2020 C conf
IGARSS
Wei Feng, Yinghui Quan, Gabriel Dauphin, Puxia Wu, Bowen Bie, Yingping Tong, Xiaoguang Yuan, Jing Li, Mengdao Xing
2020 J jnl
Sensors
Wei Feng, Yinghui Quan, Gabriel Dauphin
2020 C conf
IGARSS
Yinghui Quan, Shuxian Dong, Wei Feng, Gabriel Dauphin, Guoping Zhao, Yong Wang, Mengdao Xing
2020 C conf
IGARSS
Wei Feng, Yinghui Quan, Gabriel Dauphin, Xian Zhong, Qiang Li, Mengdao Xing, Wenjiang Huang
2019 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Wei Feng, Gabriel Dauphin, Wenjiang Huang, Yinghui Quan, Wenxing Bao, Mingquan Wu, Qiang Li
2019 C conf
IGARSS
Wei Feng, Wenjiang Huang, Gabriel Dauphin, Junshi Xia, Yinghui Quan, Huichun Ye, Yingying Dong
2019 C conf
IGARSS
Samia Boukir, Wei Feng
2019 J jnl
IEEE Geosci. Remote. Sens. Lett.
Wei Feng, Wenjiang Huang, Wenxing Bao
2019 C conf
IGARSS
Wei Feng, Samia Boukir, W. Huang
2019 J jnl
Knowl. Based Syst.
Wei Feng, Gabriel Dauphin, Wenjiang Huang, Yinghui Quan, Wenzhi Liao
2018 C conf
IGARSS
Wei Feng, Wenjiang Huang, Huichun Ye, Longlong Zhao
2017 J jnl
IEEE Geosci. Remote. Sens. Lett.
Wei Feng, Wenxing Bao
2015 B conf
ICIP
Wei Feng, Samia Boukir
2015 C conf
IGARSS
Wei Feng, Samia Boukir, Li Guo
redb/extractors/js_extractors/js_patterns.py
← Index redb/extractors/js_extractors/js_patterns.py python
"""Canonical, compiled JavaScript regex patterns shared across JS extractors.

All suspicious-API patterns and the few feature-only patterns live here so each
expression is compiled exactly once per Python process and so any pattern that
was previously duplicated across `js_features.py` and `js_suspicious_apis.py`
now resolves to a single shared compiled object.

JavaScript is case-sensitive at runtime, but every suspicious-API pattern matches
either a literal-case identifier (`\\beval\\s*\\(`, `String\\.fromCharCode`, etc.)
or a string-quoted token (`"powershell"`). Compiling them with `re.IGNORECASE`
matches the historical behaviour of `JSSuspiciousAPIsExtractor` and is safe for
the patterns that historically came from `JSFeaturesExtractor` — those literals
are spelled in real-world JS exactly as written.

`scan_source()` is the entry point used by extractors: it walks the source once
per pattern using the pre-compiled regexes and returns a flat
`{name: {"count": N, "lines": [unique_line_numbers_sorted]}}` dict. Both
`JSFeaturesExtractor` and `JSSuspiciousAPIsExtractor` consume the same dict so
the per-pattern × per-line loops they used to run independently collapse to a
single shared scan.
"""

import bisect
import re
from typing import Dict, Iterable, List, Mapping

_FLAGS = re.IGNORECASE

# Canonical compiled patterns, keyed by their human-readable name. The name is
# also the value emitted into `redb_js_suspicious_apis.api_name`.
PATTERNS = {
    # ---- code execution ----
    "eval": re.compile(r"\beval\s*\(", _FLAGS),
    "Function constructor": re.compile(r"\bnew\s+Function\s*\(", _FLAGS),
    "execScript": re.compile(r"\bexecScript\s*\(", _FLAGS),
    "document.write": re.compile(r"\bdocument\.write(?:ln)?\s*\(", _FLAGS),
    "innerHTML assignment": re.compile(r"\.innerHTML\s*=", _FLAGS),
    "outerHTML assignment": re.compile(r"\.outerHTML\s*=", _FLAGS),
    "insertAdjacentHTML": re.compile(r"\.insertAdjacentHTML\s*\(", _FLAGS),
    # ---- network ----
    "XMLHttpRequest": re.compile(r"\bnew\s+XMLHttpRequest\b", _FLAGS),
    "fetch": re.compile(r"\bfetch\s*\(", _FLAGS),
    "WebSocket": re.compile(r"\bnew\s+WebSocket\s*\(", _FLAGS),
    "navigator.sendBeacon": re.compile(r"\bnavigator\.sendBeacon\s*\(", _FLAGS),
    "ActiveXObject XMLHTTP": re.compile(
        r"ActiveXObject\s*\(\s*[\"\'](?:MSXML2\.XMLHTTP|Microsoft\.XMLHTTP)", _FLAGS
    ),
    "require network module": re.compile(
        r"require\s*\(\s*[\"\'](?:http|https|net|dgram)[\"\']", _FLAGS
    ),
    "axios": re.compile(r"\baxios\b", _FLAGS),
    # ---- filesystem ----
    "require fs": re.compile(r"require\s*\(\s*[\"\']fs[\"\']", _FLAGS),
    "require path": re.compile(r"require\s*\(\s*[\"\']path[\"\']", _FLAGS),
    "FileSystemObject": re.compile(r"Scripting\.FileSystemObject", _FLAGS),
    "ADODB.Stream": re.compile(r"ADODB\.Stream", _FLAGS),
    "Shell.Application": re.compile(r"Shell\.Application", _FLAGS),
    "WScript.CreateObject": re.compile(r"WScript\.CreateObject", _FLAGS),
    # ---- process ----
    "require child_process": re.compile(r"require\s*\(\s*[\"\']child_process[\"\']", _FLAGS),
    "child_process exec": re.compile(r"child_process\.(?:exec|spawn|execFile|fork)\s*\(", _FLAGS),
    "WScript.Shell": re.compile(r"WScript\.Shell", _FLAGS),
    "WScript.Shell.Run": re.compile(r"\.Run\s*\(", _FLAGS),
    "WScript.Shell.Exec": re.compile(r"\.Exec\s*\(", _FLAGS),
    "ShellExecute": re.compile(r"\bShellExecute\b", _FLAGS),
    "PowerShell reference": re.compile(r"[\"\']powershell[\"\']", _FLAGS),
    "cmd.exe reference": re.compile(r"[\"\']cmd\.exe[\"\']", _FLAGS),
    "require os": re.compile(r"require\s*\(\s*[\"\']os[\"\']", _FLAGS),
    # ---- registry ----
    "RegRead": re.compile(r"\.RegRead\s*\(", _FLAGS),
    "RegWrite": re.compile(r"\.RegWrite\s*\(", _FLAGS),
    "RegDelete": re.compile(r"\.RegDelete\s*\(", _FLAGS),
    "StdRegProv": re.compile(r"StdRegProv", _FLAGS),
    # ---- crypto / encoding ----
    "atob": re.compile(r"\batob\s*\(", _FLAGS),
    "btoa": re.compile(r"\bbtoa\s*\(", _FLAGS),
    "String.fromCharCode": re.compile(r"String\.fromCharCode\s*\(", _FLAGS),
    "unescape": re.compile(r"\bunescape\s*\(", _FLAGS),
    "decodeURIComponent": re.compile(r"\bdecodeURIComponent\s*\(", _FLAGS),
    "Buffer.from": re.compile(r"Buffer\.from\s*\(", _FLAGS),
    "crypto module": re.compile(r"crypto\.create(?:Cipher|Decipher|Hash|Hmac)", _FLAGS),
    # ---- DOM manipulation ----
    "document.forms": re.compile(r"document\.forms", _FLAGS),
    "document.cookie": re.compile(r"document\.cookie", _FLAGS),
    "querySelector sensitive input": re.compile(
        r"document\.querySelector\s*\([^)]*(?:password|credit|card|cvv|ssn)", _FLAGS
    ),
    "submit event listener": re.compile(r"addEventListener\s*\(\s*[\"\']submit", _FLAGS),
    "createElement script/iframe": re.compile(
        r"\.createElement\s*\(\s*[\"\'](?:script|iframe)", _FLAGS
    ),
    "dynamic script src": re.compile(r"\.src\s*=\s*[\"\'](?:https?://|//)", _FLAGS),
}

# Pattern name -> category (one of code_execution / network / filesystem /
# process / registry / crypto_encoding / dom_manipulation).
CATEGORIES = {
    "eval": "code_execution",
    "Function constructor": "code_execution",
    "execScript": "code_execution",
    "document.write": "code_execution",
    "innerHTML assignment": "code_execution",
    "outerHTML assignment": "code_execution",
    "insertAdjacentHTML": "code_execution",
    "XMLHttpRequest": "network",
    "fetch": "network",
    "WebSocket": "network",
    "navigator.sendBeacon": "network",
    "ActiveXObject XMLHTTP": "network",
    "require network module": "network",
    "axios": "network",
    "require fs": "filesystem",
    "require path": "filesystem",
    "FileSystemObject": "filesystem",
    "ADODB.Stream": "filesystem",
    "Shell.Application": "filesystem",
    "WScript.CreateObject": "filesystem",
    "require child_process": "process",
    "child_process exec": "process",
    "WScript.Shell": "process",
    "WScript.Shell.Run": "process",
    "WScript.Shell.Exec": "process",
    "ShellExecute": "process",
    "PowerShell reference": "process",
    "cmd.exe reference": "process",
    "require os": "process",
    "RegRead": "registry",
    "RegWrite": "registry",
    "RegDelete": "registry",
    "StdRegProv": "registry",
    "atob": "crypto_encoding",
    "btoa": "crypto_encoding",
    "String.fromCharCode": "crypto_encoding",
    "unescape": "crypto_encoding",
    "decodeURIComponent": "crypto_encoding",
    "Buffer.from": "crypto_encoding",
    "crypto module": "crypto_encoding",
    "document.forms": "dom_manipulation",
    "document.cookie": "dom_manipulation",
    "querySelector sensitive input": "dom_manipulation",
    "submit event listener": "dom_manipulation",
    "createElement script/iframe": "dom_manipulation",
    "dynamic script src": "dom_manipulation",
}

# Patterns consumed only by JSFeaturesExtractor (no category, never surfaced as
# a suspicious-API row). Kept here so every JS regex is compiled in one place.
FEATURE_PATTERNS = {
    "hex_escape": re.compile(r"\\x[0-9a-fA-F]{2}"),
    "unicode_escape": re.compile(r"\\u[0-9a-fA-F]{4}"),
    "base64_string": re.compile(r"[A-Za-z0-9+/]{40,}={0,2}"),
    # decodeURI matches BOTH decodeURI and decodeURIComponent. The latter is also
    # a suspicious-API pattern in PATTERNS; this broader form is what the
    # `decodeuri_count` feature column has historically counted.
    "decodeURI": re.compile(r"\b(?:decodeURI|decodeURIComponent)\s*\(", _FLAGS),
    "settimeout_setinterval": re.compile(r"\b(?:setTimeout|setInterval)\s*\(", _FLAGS),
    "function_decl": re.compile(r"\bfunction\s+\w+\s*\(|\bfunction\s*\("),
    "var_decl": re.compile(r"\b(?:var|let|const)\s+"),
    "string_concat": re.compile(r"[\"\'][\s]*\+[\s]*[\"\']"),
    "comment": re.compile(r"//.*?$|/\*[\s\S]*?\*/", re.MULTILINE),
    "long_string": re.compile(r"[\"\']([^\"\']{256,})[\"\']"),
    "array_function_call": re.compile(r"\[(?:0x[0-9a-f]+|[\d]+)\]\s*\(", _FLAGS),
}

# Patterns consumed only by JSStringsExtractor for encoded-string discovery.
# Scoped to *hidden* strings only — patterns whose decoded form is not visible
# to a substring search over the raw text. Plain long literals are not
# extracted here because they're already preserved in code_text_content and
# scraped by the IOC pipeline over text_raw / text_normalized.
#
# Distinct from FEATURE_PATTERNS even where the names rhyme:
#   FEATURE_PATTERNS["hex_escape"] / ["unicode_escape"]   -> single escape
#   STRING_PATTERNS["hex_escape_seq"] / ["unicode_escape_seq"] -> 4+ / 3+ in a row
#   FEATURE_PATTERNS["base64_string"]                     -> bare base64 token
#   STRING_PATTERNS["base64_quoted"]                      -> base64 inside JS quotes
# These do not share match objects with the suspicious-API or feature scans, so
# they are not folded into JSContext.scan; the strings extractor walks them
# itself (one finditer per pattern, with shared line-offset bisect in #4b).
STRING_PATTERNS = {
    "hex_escape_seq": re.compile(r"(?:\\x[0-9a-fA-F]{2}){4,}"),
    "unicode_escape_seq": re.compile(r"(?:\\u[0-9a-fA-F]{4}){3,}"),
    "charcode_call": re.compile(r"String\.fromCharCode\s*\(\s*([\d,\s]+)\s*\)"),
    "base64_quoted": re.compile(r"[\"\']([A-Za-z0-9+/]{40,}={0,2})[\"\']"),
    "concat_chain": re.compile(r"(?:[\"\'][^\"\']+[\"\']\s*\+\s*){3,}[\"\'][^\"\']+[\"\']"),
}


def line_offsets(source: str) -> List[int]:
    """Sorted list of byte offsets for every newline in `source`, plus a final
    sentinel of len(source). Used to translate match offsets into 1-indexed
    line numbers via bisect.
    """
    offsets = [-1]  # so that bisect_right of offset 0 returns line 1
    push = offsets.append
    idx = source.find("\n")
    while idx != -1:
        push(idx)
        idx = source.find("\n", idx + 1)
    return offsets


def _scan_one(
    pattern: "re.Pattern[str]", source: str, offsets: List[int]
) -> Dict[str, object]:
    """Run a single compiled pattern over `source` and return count + unique lines."""
    count = 0
    seen_lines: "set[int]" = set()
    for m in pattern.finditer(source):
        count += 1
        seen_lines.add(bisect.bisect_right(offsets, m.start()))
    if not count:
        return None  # type: ignore[return-value]
    return {"count": count, "lines": sorted(seen_lines)}


def scan_source(
    source: str,
    patterns: Iterable[Mapping[str, "re.Pattern[str]"]] = (PATTERNS, FEATURE_PATTERNS),
) -> Dict[str, Dict[str, object]]:
    """Scan `source` against every compiled pattern in `patterns`.

    Returns a dict keyed by pattern name. Each entry has:
        "count": total number of matches in the source
        "lines": sorted list of unique 1-indexed line numbers where the pattern
                 matched (deduplicated — multiple matches on the same line
                 collapse to one entry, preserving the historical
                 line-set semantics of JSSuspiciousAPIsExtractor)
    Patterns with zero matches are absent from the dict; callers should default
    to {"count": 0, "lines": []}.
    """
    if not source:
        return {}
    offsets = line_offsets(source)
    results: Dict[str, Dict[str, object]] = {}
    for table in patterns:
        for name, pat in table.items():
            entry = _scan_one(pat, source, offsets)
            if entry is not None:
                results[name] = entry
    return results