Wei Li

80 papers B 4C 4Misc 1Journal 51Unranked 17
YearRankTypeTitle / Venue / Authors
2026 J jnl
Expert Syst. Appl.
Ying Huang, Xiaojian Cao, Benben Zhou, Wei Li, Shuling Yang, S. M. Shafi, Zhou Yang
2026 J jnl
Expert Syst. Appl.
Wei Li, Zhiting Liu, Ning Yang, Qing Xu, Ying Huang, Weize Qin
2026 J jnl
Swarm Evol. Comput.
Hui Wang, Jinyu Xu, Jiayao Qian, Xinyu Zhou, Wei Li, Zhihua Cui, Jia Zhao
2025 J jnl
Inf. Sci.
Yuhang Hu, Yuelin Qu, Wei Li, Ying Huang
2025 J jnl
Int. J. Comput. Sci. Math.
Ziqiong Liu, Sanfeng Chen, Xiang Du, Wei Li, Hui Wang
2025 J jnl
Expert Syst. Appl.
Hui Wang, Dong Xiao, Shahryar Rahnamayan, Wei Li, Jia Zhao
2025 J jnl
IEEE Internet Things J.
Yishan Chen, Jie Wu, Shumei Ye, Wei Li, Zhonghui Xu
2025 J jnl
Eng. Appl. Artif. Intell.
Wei Li, Xiaolong Zeng, Ying Huang, Yiu-ming Cheung
2025 J jnl
Swarm Evol. Comput.
Yuelin Qu, Yuhang Hu, Wei Li, Ying Huang
2025 J jnl
Swarm Evol. Comput.
Qing Xu, Shuzheng Xie, Ning Yang, Ying Huang, Shaochang Nie, Wei Li
2024 conf
GECCO Companion
Zhongtian Luo, Jianpeng Xiong, Hu Peng, Gaosheng Zhan, Qingfu Zhang, Hui Wang, Xinyu Zhou, Wei Li, Ying Huang
2024 J jnl
Swarm Evol. Comput.
Wei Li, Yangtao Chen, Yuehua Dong, Ying Huang
2024 J jnl
Expert Syst. Appl.
Peng Liang, Yangtao Chen, Yafeng Sun, Ying Huang, Wei Li
2024 J jnl
IEEE Internet Things J.
Yishan Chen, Bo Li, Wei Li, Bowen Zeng, Jianwei Yin, Shuiguang Deng
2024 J jnl
Inf. Sci.
Yishan Chen, Shumei Ye, Jianqing Wu, Bi Wang, Hui Wang, Wei Li
2024 J jnl
Comput. Networks
Yishan Chen, Shumei Ye, Jie Wu, Wei Li, Jiyuan Wang
2024 J jnl
Inf. Sci.
Qing Xu, Yuhao Chen, Cisong Shi, Junhong Huang, Wei Li
2023 J jnl
Inf. Sci.
Wei Li, Jianghui Jing, Yangtao Chen, Yishan Chen
2023 J jnl
Expert Syst. Appl.
Wei Li, Bo Sun, Yafeng Sun, Ying Huang, Yiu-ming Cheung, Fangqing Gu
2023 J jnl
Concurr. Comput. Pract. Exp.
Ying Huang, Wei Li
2023 J jnl
Complex Syst. Model. Simul.
Wei Li, Jianghui Jing, Yangtao Chen, Xunjun Chen, Ata Jahangir Moshayedi
2023 J jnl
Expert Syst. Appl.
Hu Peng, Zhenzhen Xu, Jiayao Qian, Xiaogang Dong, Wei Li, Zhijian Wu
2023 J jnl
Appl. Soft Comput.
Wei Li, Cancan Wang, Ying Huang, Yiu-ming Cheung
2023 J jnl
Swarm Evol. Comput.
Wei Li, Peng Liang, Bo Sun, Yafeng Sun, Ying Huang
2022 J jnl
Inf. Sci.
Ying Huang, Ling Lai, Wei Li, Hui Wang
2022 J jnl
Complex Syst. Model. Simul.
Wei Li, Xinqiang Ye, Ying Huang, Soroosh Mahmoodi
2022 J jnl
Int. J. Intell. Syst.
Wei Li, Bo Sun, Ying Huang, Soroosh Mahmoodi
2022 J jnl
Connect. Sci.
Wei Li, Yafeng Sun, Ying Huang, Jianbing Yi
2022 J jnl
J. Ambient Intell. Humaniz. Comput.
Wei Li, Le Xia, Ying Huang, Soroosh Mahmoodi
2022 C conf
CIS
Yuhao Chen, Yangtao Chen, Wei Li, Qing Xu
2022 J jnl
Complex Syst. Model. Simul.
Wei Li, Yangtao Chen, Qian Cai, Cancan Wang, Ying Huang, Soroosh Mahmoodi
2022 J jnl
Int. J. Swarm Intell. Res.
Wei Li, Cisong Shi, Qing Xu, Ying Huang
2022 B conf
CEC
Bo Sun, Yafeng Sun, Wei Li
2022 conf
ICCI*CC
Shuhui Ding, Wei Li, Ying Huang
2022 B conf
CEC
Bo Sun, Wei Li, Ying Huang
2021 C conf
CIS
Xiangfang Yan, Wei Li, Ying Huang, Soroosh Mahmoodi
2021 C conf
CIS
Cancan Wang, Wei Li, Ying Huang
2021 J jnl
Int. J. Pattern Recognit. Artif. Intell.
Wei Li, Xiang Meng, Ying Huang, Junhui Yang
2021 J jnl
Neurocomputing
Wei Li, Xiang Meng, Ying Huang
2020 J jnl
Appl. Soft Comput.
Ying Huang, Wei Li, Furong Tian, Xiang Meng
2020 J jnl
Inf. Sci.
Feng Wang, Huiqing Zhu, Wei Li, Kangshun Li
2020 conf
ICKG
Wei Li, Le Xia, Ying Huang
2020 ed.
ISICA
Kangshun Li, Wei Li, Hui Wang, Yong Liu
2020 J jnl
Int. J. Cogn. Informatics Nat. Intell.
Wei Li, Furong Tian, Ke Li
2020 J jnl
Inf. Sci.
Wei Li, Xiang Meng, Ying Huang, Zhang-Hua Fu
2019 J jnl
Int. J. Pattern Recognit. Artif. Intell.
Kangshun Li, Fahui Gu, Wei Li, Ying Huang
2019 J jnl
Int. J. Pattern Recognit. Artif. Intell.
Kangshun Li, Hui Wang, Fei Tang, Wei Li, Yunru Lu
2019 J jnl
Int. J. Intell. Inf. Database Syst.
Jialin Li, Wei Li
2019 C conf
CIS
Wei Li, Xiang Meng, Ying Huang
2019 conf
ISICA
Qing Xu, Sylvie Huet, Wei Li
2019 J jnl
Int. J. Comput. Sci. Eng.
Weigang Zou, Wei Li, Zhaoquan Cai
2019 B conf
CEC
Hui Wang, Wenjun Wang, Songyi Xiao, Zhihua Cui, Wei Li, Huasheng Zhu, Shengqing Zhu
2019 J jnl
Soft Comput.
Wei Li, Shanni Li, Zhangxin Chen, Liang Zhong, Chengtian Ouyang
2019 conf
ICCI*CC
Wei Li, Ke Li, Xiang Meng, Feng Wang, Yan Chen, Kangshun Li
2018 J jnl
Multim. Tools Appl.
Wei Li, Kangshun Li, Luyan Guo, Ying Huang, Yu Xue
2018 J jnl
Soft Comput.
Shuling Yang, Kangshun Li, Zhengping Liang, Wei Li, Yu Xue
2018 J jnl
Soft Comput.
Ying Huang, Wei Li, Chengtian Ouyang, Yan Chen
2018 ed.
ISICA (1)
Kangshun Li, Wei Li, Zhangxing Chen, Yong Liu
2018 ed.
ISICA (2)
Kangshun Li, Wei Li, Zhangxing Chen, Yong Liu
2018 J jnl
Soft Comput.
Ying Huang, Wei Li, Zhengping Liang, Yu Xue, Xiuni Wang
2018 J jnl
Swarm Evol. Comput.
Kangshun Li, Yan Chen, Wei Li, Jun He, Yu Xue
2018 J jnl
Soft Comput.
Dazhi Jiang, Bo Hu, Yifei Chen, Yu Xue, Wei Li, Zhengping Liang
2017 J jnl
Soft Comput.
Wei Li, Kangshun Li, Ying Huang, Shuling Yang, Lei Yang
2017 conf
CSE/EUC (1)
Wei Li, Kangshun Li, Liang Zhong, Ying Huang
2017 conf
CSE/EUC (1)
Jialin Li, Wei Li, Ying Huang
2017 J jnl
Int. J. High Perform. Syst. Archit.
Jialin Li, Wei Li, Ying Huang, Chengtian Ouyang
2017 J jnl
Int. J. Embed. Syst.
Wei Li, Kangshun Li, Ying Huang, Xiaoyang Deng
2017 conf
ISICA (1)
Hui Wang, Zhangxin Chen, Wenjun Wang, Zhijian Wu, Keliu Wu, Wei Li
2016 conf
BIC-TA (2)
Shuling Yang, Kangshun Li, Wei Li, Weiguang Chen, Yan Chen
2015 conf
ISICA
Lei Yang, Kangshun Li, Wensheng Zhang, Yan Chen, Wei Li, Xinghao Bi
2015 conf
ISICA
Wei Li, Kangshun Li, Ying Huang, Xiaoyang Deng
2015 conf
ISICA
Kangshun Li, Lei Zuo, Wei Li, Lei Yang
2015 conf
ISICA
Shuling Yang, Kangshun Li, Wei Li, Weiguang Chen
2015 conf
ISICA
Fahui Gu, Kangshun Li, Lei Yang, Wei Li
2015 B conf
CEC
Kangshun Li, Xiaoyang Deng, Xinyu Zhou, Wei Li
2012 Misc conf
ICNC
Wei Li, Ying Huang
2010 conf
NLPKE
Ying Huang, Wei Li
2008 conf
ICNC (1)
Wei Li, Kangshun Li, Wensheng Zhang, Chao Wang, Ying Huang
2007 J jnl
Int. J. Comput. Math.
Kangshun Li, Wei Li
2006 conf
VECPAR
Kangshun Li, Wei Li, Zhangxin Chen, Feng Wang
redb/extractors/ioc_extractor/ioc_extractor.py
← Index redb/extractors/ioc_extractor/ioc_extractor.py python
"""
IOC Extractor - Extractor class for extracting IOCs from decompilation results.

This extractor works with in-memory data from DecompileBinja, following the
standard Extractor pattern to support both ClickHouse and PrintExporter (dry-run).

Usage:
    # After DecompileBinja completes:
    ioc_extractor = IOCExtractorFromResults(
        analysis_results=decompiler.analysis_results,
        sha256=sha256,
        log=logger,
        exporters=exporters,
        index_prefix=index_prefix
    )
    ioc_extractor.export_data()
"""

import inspect
from datetime import datetime, timezone
from pathlib import Path
from typing import Any, List, Dict, Optional

from redb.extractors.enum import Tag
from redb.extractors.database_exporters import DatabaseExporter

# Import the IOCScraper and related classes from standalone module
from redb.extractors.ioc_extractor.standalone_ioc_extractor import (
    IOCScraper,
    IOCType,
    SourceType,
    ExtractedIOC,
)
from typing import Set


class IOCExtractorFromResults:
    """
    Extracts IOCs from in-memory decompilation results.

    This follows a simplified Extractor pattern but doesn't inherit from Extractor
    since it doesn't read from a binary file - instead it takes already-processed
    analysis results from DecompileBinja.
    """

    def __init__(
        self,
        analysis_results: Dict[str, Any],
        sha256: str,
        log: Any,
        exporters: Optional[List[DatabaseExporter]] = None,
        index_prefix: Optional[str] = None,
        tld_file: Optional[Path] = None,
        suppress_types: Optional[Set[IOCType]] = None,
        js_context: bool = False,
    ):
        """
        Initialize IOC Extractor with analysis results.

        Args:
            analysis_results: Dict containing 'strings' and 'decompiled' lists from DecompileBinja
            sha256: Sample SHA256 hash
            log: Logger instance
            exporters: List of database exporters (ClickHouse, Print, etc.)
            index_prefix: Index prefix for database
            tld_file: Optional path to TLD list file
            js_context: When True, the underlying IOCScraper rejects FQDN
                candidates that match JS object-access syntax (see
                JS_FP_TLDS / JS_FP_SLDS). Set this for the JS pipeline only;
                APK suppresses FQDN entirely via suppress_types and binary
                callers leave it disabled.
        """
        self.log = log
        self.log.debug(f"Creating {self.__class__.__name__}")
        self.analysis_results = analysis_results
        self.sha256 = sha256
        self.exporters = exporters or []
        self.index_prefix = index_prefix
        self.scraper = IOCScraper(
            tld_file, suppress_types=suppress_types, js_context=js_context,
        )
        self.extracted_iocs: List[ExtractedIOC] = []

    def extract(self) -> List[ExtractedIOC]:
        """
        Extract IOCs from strings and decompiled functions in analysis_results.

        Returns:
            List of ExtractedIOC objects
        """
        self.log.debug(inspect.currentframe().f_code.co_name)
        self.extracted_iocs = []

        # Extract from strings
        strings_count = self._extract_from_strings()

        # Extract from decompiled functions
        functions_count = self._extract_from_decompiled()

        # Extract from text-based artefact surfaces (JS, PowerShell, etc.)
        text_count = self._extract_from_text()

        self.log.info(
            f"Extracted {len(self.extracted_iocs)} IOCs for {self.sha256[:16]}... "
            f"(strings: {strings_count}, functions: {functions_count}, "
            f"text: {text_count})"
        )

        return self.extracted_iocs

    def _extract_from_strings(self) -> int:
        """Extract IOCs from sample's strings."""
        count = 0
        strings = self.analysis_results.get("strings", [])

        for s in strings:
            string_value = s.get("string", "")
            string_offset = s.get("string_offset", 0)

            if isinstance(string_value, bytes):
                string_value = string_value.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(string_value, SourceType.STRING, str(string_offset)):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_decompiled(self) -> int:
        """Extract IOCs from sample's decompiled functions.

        Supports both Binja format (key: "decompiled", fields: "decompiled_function",
        "decompiled_function_hash", "function_type") and APK format (key:
        "decompiled_content", fields: "decompiled_method", "decompiled_method_hash",
        "method_type").
        """
        count = 0

        # Binja format
        decompiled = self.analysis_results.get("decompiled", [])
        for func in decompiled:
            func_type = func.get("function_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_function", "")
            func_hash = func.get("decompiled_function_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        # APK format (decompiled_content with method-level fields)
        decompiled_content = self.analysis_results.get("decompiled_content", [])
        for func in decompiled_content:
            func_type = func.get("method_type", "UNKNOWN")
            if func_type in ("LIBRARY", "THUNK"):
                continue

            func_content = func.get("decompiled_method", "")
            func_hash = func.get("decompiled_method_hash", "unknown")

            if isinstance(func_content, bytes):
                func_content = func_content.decode('utf-8', errors='replace')

            for ioc in self.scraper.scrape(func_content, SourceType.DECOMPILED_FUNCTION, func_hash):
                self.extracted_iocs.append(ioc)
                count += 1

        return count

    def _extract_from_text(self) -> int:
        """Extract IOCs from text-based artefact surfaces.

        Walks `analysis_results["text_raw"]` and `analysis_results["text_normalized"]`,
        each a list of `{"content": str, "content_hash": str}` dicts. Each
        list is routed through its own SourceType (`TEXT_RAW` /
        `TEXT_NORMALIZED`) so analysts can distinguish IOCs that were already
        present in the raw source from those exposed only after normalisation
        (deobfuscation/beautification). Generic across text-based formats —
        used by JS today, intended for PowerShell, Python, email body,
        extracted PDF/Office text in the future.
        """
        count = 0

        for key, source_type in (
            ("text_raw", SourceType.TEXT_RAW),
            ("text_normalized", SourceType.TEXT_NORMALIZED),
        ):
            for entry in self.analysis_results.get(key, []):
                content = entry.get("content", "")
                content_hash = entry.get("content_hash", "unknown")

                if isinstance(content, bytes):
                    content = content.decode('utf-8', errors='replace')

                for ioc in self.scraper.scrape(content, source_type, content_hash):
                    self.extracted_iocs.append(ioc)
                    count += 1

        return count

    def prepare_export_data(self, exporter_type: str) -> Any:
        """
        Prepare data for specific export type.

        Returns tuple for ClickHouse or list of dicts for Print/Elasticsearch.
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        if not self.extracted_iocs:
            return None

        now = datetime.now(timezone.utc)

        if exporter_type == "ClickHouseExporter":
            data = [
                [
                    self.sha256,
                    ioc.ioc_type.value,
                    ioc.ioc_value,
                    ioc.source_type.value,
                    ioc.source_identifier,
                    now,
                ]
                for ioc in self.extracted_iocs
            ]

            column_names = [
                "sha256",
                "ioc_type",
                "ioc_value",
                "source_type",
                "source_identifier",
                "extracted_at",
            ]

            column_type_names = [
                "FixedString(64)",
                "Enum8('ipv4'=1, 'ipv6'=2, 'fqdn'=3, 'url'=4, 'email'=5, 'server'=6, "
                "'hash_md5'=10, 'hash_sha1'=11, 'hash_sha256'=12, 'cve'=20, 'cwe'=21, 'cpe'=22, "
                "'crypto_btc'=30, 'crypto_eth'=31, 'crypto_xrp'=32, 'crypto_bch'=33, "
                "'crypto_ada'=34, 'crypto_substrate'=35, 'path_linux'=40, 'path_windows'=41, "
                "'registry_key'=42, 'onion'=50)",
                "String",
                "Enum8('decompiled_function'=1, 'disassembled_function'=2, 'string'=3, "
                "'text_raw'=4, 'text_normalized'=5)",
                "String",
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

        else:
            # For PrintExporter and others - return list of dicts
            return [
                {
                    "sha256": self.sha256,
                    "ioc_type": ioc.ioc_type.value,
                    "ioc_value": ioc.ioc_value,
                    "source_type": ioc.source_type.value,
                    "source_identifier": ioc.source_identifier,
                    "extracted_at": now.isoformat(),
                }
                for ioc in self.extracted_iocs
            ]

    def get_clickhouse_table(self) -> str:
        """Return the ClickHouse table name for IOCs."""
        return "redb_iocs"

    def tag(self) -> str:
        """Return the tag for this extractor."""
        return Tag.IOC.value if hasattr(Tag, 'IOC') else "ioc"

    def export_data(self) -> bool:
        """
        Export extracted IOCs to all configured exporters.

        Returns:
            True if export succeeded, False if failed, None if no data
        """
        self.log.debug(inspect.currentframe().f_code.co_name)

        # First extract the IOCs
        extracted = self.extract()

        if not extracted:
            self.log.debug("No IOCs extracted, skipping export")
            return None

        success = True

        from redb.extractors.database_exporters import PrintExporter, ClickHouseExporter

        for exporter in self.exporters:
            try:
                if isinstance(exporter, PrintExporter):
                    # For PrintExporter, pass the list of dicts
                    export_data = self.prepare_export_data("PrintExporter")
                    success &= exporter.export(export_data)

                elif isinstance(exporter, ClickHouseExporter):
                    # For ClickHouse, pass tuple with table info
                    export_data = self.prepare_export_data("ClickHouseExporter")
                    if export_data:
                        success &= exporter.export(
                            export_data,
                            table=self.get_clickhouse_table(),
                            column_names=export_data[1],
                            column_type_names=export_data[2]
                        )

            except Exception as e:
                self.log.error(f"Error exporting IOCs to {exporter.__class__.__name__}: {e}")
                success = False

        return success