Wei Song

89 papers A* 6A 13C 2Journal 40Unranked 28
YearRankTypeTitle / Venue / Authors
2026 J jnl
IEEE Trans. Serv. Comput.
Chao Zheng, Jian Wang, Maodong Li, Bing Li, Wei Song
2025 J jnl
IEEE Trans. Software Eng.
Yuyong Liu, Zhifei Chen, Lin Chen, Yanhui Li, Xuansong Li, Wei Song
2025 J jnl
Proc. ACM Program. Lang.
Chenyang Ma, Wei Song, Jeff Huang
2025 J jnl
CoRR
Qiong Feng, Xiaotian Ma, Ziyuan Feng, Marat Akhin, Wei Song, Peng Liang
2025 J jnl
Proc. ACM Program. Lang.
Qiong Feng, Xiaotian Ma, Ziyuan Feng, Marat Akhin, Wei Song, Peng Liang
2025 conf
ISSTA Companion
Xiaofan Xu, Wei Song, Jeff Huang
2025 J jnl
Proc. ACM Softw. Eng.
Wei Song, Xiaofan Xu, Jeff Huang
2024 A* conf
ASE
Qiong Feng, Xiaotian Ma, Huan Ji, Wei Song, Peng Liang
2024 A conf
ISSTA
Yunqi Liu, Wei Song
2024 A conf
ISSTA
Yunqi Liu, Wei Song
2024 J jnl
CoRR
Qiong Feng, Xiaotian Ma, Jiayi Sheng, Ziyuan Feng, Wei Song, Peng Liang
2024 J jnl
ACM Trans. Softw. Eng. Methodol.
Zhifei Chen, Lin Chen, Yibiao Yang, Qiong Feng, Xuansong Li, Wei Song
2024 J jnl
Proc. ACM Program. Lang.
Yichuan Li, Wei Song, Jeff Huang
2023 A conf
ISSTA
Yuhao Zhou, Wei Song
2023 A conf
ISSTA
Yuhao Zhou, Wei Song
2023 A* conf
ICDE
Wei Song, Zhen Chang, Hans-Arno Jacobsen, Pengcheng Zhang
2023 A* conf
ICSE
Zeya Tan, Wei Song
2023 conf
ESEC/SIGSOFT FSE
Chenyang Ma, Wei Song, Jeff Huang
2022 J jnl
IEEE Trans. Software Eng.
Binfa Gui, Wei Song, Hailong Xiong, Jeff Huang
2022 J jnl
Inf. Softw. Technol.
Zhifei Chen, Wanwangying Ma, Lin Chen, Wei Song
2022 J jnl
IEEE Trans. Serv. Comput.
Qi Mo, Wei Song, Fei Dai, Leilei Lin, Tong Li
2022 J jnl
IEEE Trans. Knowl. Data Eng.
Wei Song, Zhen Chang, Hans-Arno Jacobsen, Pengcheng Zhang
2022 J jnl
IEEE Trans. Serv. Comput.
Wei Song, Fangfei Chen, Hans-Arno Jacobsen, Chengzhen Zhang
2022 J jnl
IEEE Trans. Serv. Comput.
Pengcheng Zhang, Huiying Jin, Hai Dong, Wei Song
2022 A conf
ISSTA
Shuaihao Yang, Zigang Zeng, Wei Song
2022 J jnl
IEEE Trans. Serv. Comput.
Pengcheng Zhang, Huiying Jin, Hai Dong, Wei Song, Athman Bouguettaya
2021 J jnl
IEEE Trans. Cloud Comput.
Wei Song, Chengzhen Zhang, Hans-Arno Jacobsen
2021 J jnl
IEEE Trans. Serv. Comput.
Wei Song, Hans-Arno Jacobsen, Chengzhen Zhang, Xiaoxing Ma
2021 J jnl
IEEE Trans. Emerg. Top. Comput.
Pengcheng Zhang, Fang Xiong, Hareton Leung, Wei Song
2021 conf
ICSE (Companion Volume)
Wei Song, Mengqi Han, Jeff Huang
2021 A* conf
ICSE
Wei Song, Mengqi Han, Jeff Huang
2021 J jnl
IEEE Trans. Serv. Comput.
Pengcheng Zhang, Huiying Jin, Hai Dong, Wei Song, Liyan Wang
2021 J jnl
IEEE Trans. Knowl. Data Eng.
Wei Song, Hans-Arno Jacobsen, Pengcheng Zhang
2021 A conf
ISSTA
Binfa Gui, Wei Song, Jeff Huang
2021 J jnl
IEEE Trans. Serv. Comput.
Wei Song, Hans-Arno Jacobsen, Shing-Chi Cheung, Hongyu Liu, Xiaoxing Ma
2020 conf
MSN
Yu Liang, Jidong Ge, Sheng Zhang, Changan Niu, Wei Song, Bin Luo
2020 J jnl
IEEE Trans. Knowl. Data Eng.
Wei Song, Hans-Arno Jacobsen, Fangfei Chen
2020 J jnl
IEEE Trans. Big Data
Pengcheng Zhang, Yangyang Jia, Jerry Gao, Wei Song, Hareton Leung
2020 A* conf
ASE
Xuansong Li, Wei Song, Xiangyu Zhang
2020 J jnl
IEEE Trans. Dependable Secur. Comput.
Wei Song, Qingqing Huang, Jeff Huang
2019 J jnl
Inf. Syst.
Pnina Soffer, Annika Hinze, Agnes Koschmider, Holger Ziekow, Claudio Di Ciccio, Boris Koldehofe, Oliver Kopp, Hans-Arno Jacobsen, Jan Sürmeli, Wei Song
2019 J jnl
IEEE Trans. Software Eng.
Wei Song, Xiaoxing Ma, Hans-Arno Jacobsen
2019 J jnl
IEEE Trans. Netw. Serv. Manag.
Xuewei Zhang, Wei Song, Jiacun Wang, Jianchun Xing, Qizhen Zhou
2019 conf
ESEC/SIGSOFT FSE
Wei Song, Jing Zhang, Jeff Huang
2018 J jnl
J. Comput. Sci. Technol.
Xuansong Li, XianPing Tao, Wei Song, Kai Dong
2018 J jnl
IEEE Trans. Serv. Comput.
Zhongjin Li, Jidong Ge, Haiyang Hu, Wei Song, Hao Hu, Bin Luo
2018 J jnl
Inf. Softw. Technol.
Pengcheng Zhang, Huiying Jin, Zhipeng He, Hareton Leung, Wei Song, Yan Jiang
2018 J jnl
IEEE Access
Xuewei Zhang, Jiacun Wang, Jianchun Xing, Wei Song, Qiliang Yang
2018 A conf
ICSOC
Xinchen Cai, Hongyu Kuang, Hao Hu, Wei Song, Jian Lü
2018 J jnl
IEEE Trans. Serv. Comput.
Wei Song, Hans-Arno Jacobsen
2018 J jnl
Int. J. Softw. Eng. Knowl. Eng.
Pengcheng Zhang, Huiying Jin, Yuan Zhuang, Hareton Leung, Wei Song, Yu Zhou
2017 A conf
ICWS
Pengcheng Zhang, Liyan Wang, Wenrui Li, Hareton Leung, Wei Song
2017 conf
APSEC Workshops
Fangfei Chen, Wei Song, Chengzhen Zhang, Xuansong Li, Pengcheng Zhang
2017 A* conf
ASE
Wei Song, Xiangxing Qian, Jeff Huang
2017 J jnl
IEEE Trans. Serv. Comput.
Wei Song, Xiaoxu Xia, Hans-Arno Jacobsen, Pengcheng Zhang, Hao Hu
2017 A conf
ICWS
Yuhao Gong, Hongyu Kuang, Xinchen Cai, Hao Hu, Wei Song, Jian Lu
2017 J jnl
IEEE Trans. Parallel Distributed Syst.
Wei Song, Fangfei Chen, Hans-Arno Jacobsen, Xiaoxu Xia, Chunyang Ye, Xiaoxing Ma
2017 conf
SETSS
Xiaoxing Ma, Tianxiao Gu, Wei Song
2016 conf
SCC
Pengcheng Zhang, Yingtao Sun, Wenrui Li, Wei Song, Hareton Leung
2016 conf
IEEE MS
Pengcheng Zhang, Qing Han, Wenrui Li, Hareton Leung, Wei Song
2016 conf
Internetware
Xiaoxu Xia, Wei Song, Fangfei Chen, Xuansong Li, Pengcheng Zhang
2016 J jnl
Softw. Test. Verification Reliab.
Hongda Wang, Jianchun Xing, Qiliang Yang, Wei Song, Xuewei Zhang
2016 J jnl
IEEE Trans. Serv. Comput.
Wei Song, Hans-Arno Jacobsen, Chunyang Ye, Xiaoxing Ma
2015 A conf
ICWS
Pengcheng Zhang, Yuan Zhuang, Hareton Leung, Wei Song, Yu Zhou
2015 conf
SCC
Yu Du, Hao Hu, Wei Song, Junhua Ding, Jian Lu
2015 A conf
ICWS
Wei Song, Xiaoxu Xia, Hans-Arno Jacobsen, Pengcheng Zhang, Hao Hu
2015 conf
SCC
Kesheng Qi, Hao Hu, Wei Song, Jidong Ge, Jian Lu
2015 conf
Internetware
Yang Liang, Hao Hu, Wei Song, Jidong Ge
2015 J jnl
计算机科学
Xuewei Zhang, Jianchun Xing, Qiliang Yang, Wei Song, Hongda Wang
2014 conf
IEEE SCC
Junhua Ding, Wei Song, Dongmei Zhang
2014 conf
Internetware
Qiliang Yang, XianPing Tao, Hongwei Xie, Jianchun Xing, Wei Song
2013 conf
AP-BPM
Jianchun Xing, Xuewei Zhang, Wei Song, Qiliang Yang, Jidong Ge, Hongda Wang
2013 conf
WAIM
Xuewei Zhang, Wei Song, Jianchun Xing, Qiliang Yang, Hongda Wang, Wenjia Zhang
2013 conf
Internetware
Wenjia Zhang, Wei Song, Xiaoxing Ma, Qiliang Yang, Xuewei Zhang
2013 J jnl
J. Comput. Sci. Technol.
Qiliang Yang, Jian Lu, XianPing Tao, Xiaoxing Ma, Jianchun Xing, Wei Song
2013 conf
CSE
Wei Song, Xiaoxing Ma, Hao Hu, Yang Zou, Gongxuan Zhang
2013 conf
IEEE SCC
Wei Song, Wenjia Zhang, Gongxuan Zhang, Junhua Ding, Xuewei Zhang
2012 conf
Internetware
Wei Song, Zheng Gao, Jing Cai, Xiaoxing Ma
2012 conf
COMPSAC Workshops
Jianchun Xing, Hongda Wang, Wei Song, Qiliang Yang
2012 C conf
APSCC
Wei Song, Gongxuan Zhang, Yang Zou, Qiliang Yang, Xiaoxing Ma
2011 C conf
APSCC
Hongda Wang, Wei Song, Jianchun Xing, Qiliang Yang
2011 A conf
ICWS
Wei Song, Xiaoxing Ma, Shing-Chi Cheung, Hao Hu, Qiliang Yang, Jian Lü
2010 conf
IEEE SCC
Wei Song, Xiaoxing Ma, Shing-Chi Cheung, Hao Hu, Jian Lu
2010 conf
Internetware
Qiliang Yang, Jian Lü, Juelong Li, Xiaoxing Ma, Wei Song, Yang Zou
2009 conf
IEEE SCC
Wei Song, Xiaoxing Ma, Shing-Chi Cheung, Wanchun Dou, Jian Lu
2009 conf
GPC Workshops
Xudong Song, Wanchun Dou, Wei Song
2009 conf
QSIC
Wei Song, Xiaoxing Ma, Chunyang Ye, Wanchun Dou, Jian Lu
2008 A conf
ICWS
Wei Song, Xiaoxing Ma, Wanchun Dou, Jian Lü
2007 conf
APWeb/WAIM Workshops
Wei Song, Wan-Chun Dou, Jinjun Chen, Shaokun Fan
Docker-README.md
← Index Docker-README.md markdown
# REDB Docker Setup

This document describes the Docker containerization for the REDB malware analysis framework.

## Overview

REDB has been containerized as a single unified image that supports both feature extraction and decompilation analysis. The container is stateless, processes files from S3 or local mounts, and exports results to ClickHouse database or via API callbacks.

## Architecture

- **Single Unified Container**: One image handles both feature extraction and decompilation
- **Runtime Tool Installation**: Tools (CAPA, DIE, Binary Ninja) installed at runtime from host snapshots
- **Stateless Processing**: No persistent storage required between runs
- **Multiple Invocation Modes**: Supports `--nomad-job`, `--s3`, `--s3-solo`, and `--path` modes
- **External Dependencies**: Connects to external ClickHouse and S3 services

## Files Structure

```
├── Dockerfile                 # Single unified container definition
├── docker-build.sh            # Build script with Docker Desktop bug workaround
├── docker-push.sh             # Push script to registry
├── test-docker.sh             # Container testing script
├── test-nomad.sh              # Nomad job mode testing
├── .dockerignore              # Build context exclusions
└── scripts/
    └── setup-and-run.sh       # Runtime tool setup entrypoint
```

## Tool Installation Strategy

The container uses a **runtime installation** approach:

1. **Base Image**: Contains Python dependencies and REDB code
2. **Runtime Setup**: `scripts/setup-and-run.sh` configures tools at container start
3. **Host Snapshots**: Binary Ninja installed from `/opt/binaryninja` if available
4. **System Tools**: CAPA and DIE expected at `/usr/bin/capa` and `/usr/bin/nfdc`

## Build and Run

### 1. Build Container

```bash
# Build unified image
./docker-build.sh

# Manual build
docker build --platform linux/amd64 -f Dockerfile -t redb:latest .
```

### 2. Run Modes

#### Nomad Job Mode (Primary)
```bash
# Feature extraction
docker run --rm \
  -e JOB_ID="analysis_001" \
  -e S3_KEY="samples/malware.exe" \
  -e S3_BUCKET="malware-bucket" \
  -e WORKER_TYPE="feature_extraction" \
  -e CALLBACK_URL="https://api.example.com/callbacks" \
  -e ANALYSIS_MODULES="BasicPropertiesExtractor,PEFeaturesExtractor" \
  -e CLICKHOUSE_HOST="clickhouse.example.com" \
  -e S3_ENDPOINT="s3.example.com" \
  -e S3_ACCESS_KEY="your-key" \
  -e S3_SECRET_KEY="your-secret" \
  redb:latest python3 start.py --nomad-job

# Decompilation (same container, different flags)
docker run --rm \
  -e JOB_ID="analysis_002" \
  -e S3_KEY="samples/malware.exe" \
  -e S3_BUCKET="malware-bucket" \
  -e WORKER_TYPE="decompilation" \
  -e CALLBACK_URL="https://api.example.com/callbacks" \
  -e ANALYSIS_MODULES="all" \
  -v /opt/binaryninja:/opt/binaryninja:ro \
  redb:latest python3 start.py --nomad-job --decompile
```

#### S3 Solo Mode
```bash
# Process single sample by S3 key (standard sharded path)
docker run --rm \
  -e S3_BUCKET="samples-bucket" \
  -e CLICKHOUSE_HOST="clickhouse.example.com" \
  -e S3_ENDPOINT="s3.example.com" \
  -e INDEX_PREFIX="redb" \
  -e REPO="test-analysis" \
  redb:latest python3 start.py --s3-solo "09/f7/09f7d02a3c2382199458c98a62b045145ee54ab6aba86166aecf3d10c3c1444c.zip"

# Process private sample (with prepath)
docker run --rm \
  -e S3_BUCKET="samples-bucket" \
  -e CLICKHOUSE_HOST="clickhouse.example.com" \
  -e S3_ENDPOINT="s3.example.com" \
  -e INDEX_PREFIX="redb" \
  -e REPO="test-analysis" \
  redb:latest python3 start.py --s3-solo "private/ab/cd/abcd1234567890abcdef1234567890abcdef1234567890abcdef123456.zip"
```

#### Local Files Mode
```bash
# Mount local samples
docker run --rm \
  -v /path/to/samples:/samples:ro \
  -v ./logs:/app/logs \
  -e CLICKHOUSE_HOST="clickhouse.example.com" \
  redb:latest python3 start.py --path /samples --repo local_test --index_prefix redb
```

## Environment Variables

### Required for Nomad Job Mode
- `JOB_ID` - Unique job identifier
- `S3_KEY` - S3 object key for sample
- `S3_BUCKET` - S3 bucket name
- `WORKER_TYPE` - "feature_extraction" or "decompilation"
- `CALLBACK_URL` - API endpoint for results
- `ANALYSIS_MODULES` - Comma-separated extractor list or "all"

### Database Configuration
- `CLICKHOUSE_HOST` - ClickHouse server hostname
- `CLICKHOUSE_PORT` - Port (default: 8123)
- `CLICKHOUSE_USER` - Database user (default: default)
- `CLICKHOUSE_PASSWORD` - Database password
- `CLICKHOUSE_DATABASE` - Database name (default: default)

### S3 Configuration
- `S3_ENDPOINT` - S3 endpoint URL
- `S3_ACCESS_KEY` - S3 access key
- `S3_SECRET_KEY` - S3 secret key
- `S3_SECURE` - "true" or "false" for HTTPS

### Processing Configuration
- `INDEX_PREFIX` - Database table prefix (default: redb)
- `REPO` - Repository identifier for this analysis batch
- `BATCH_SIZE` - Processing batch size (default: 10)
- `REDB_TIMEOUT` - Analysis timeout in seconds (default: 300)

### Tool Timeouts
- `CAPA_TIMEOUT` - CAPA analysis timeout (default: 300)
- `DIE_TIMEOUT` - DIE analysis timeout (default: 180)
- `BINJA_TIMEOUT` - Binary Ninja timeout (default: 1200)
- `DECOMPILE_EXTRACTOR_TIMEOUT` - Decompilation timeout (default: 2580)

## Binary Ninja Setup

For decompilation capabilities, mount Binary Ninja from host:

```bash
# Mount Binary Ninja installation
-v /opt/binaryninja:/opt/binaryninja:ro

# Mount license file
-v /path/to/license.dat:/home/analyzer/.binaryninja/license.dat:ro
```

The container will automatically detect and configure Binary Ninja at runtime.

## Registry Deployment

### Push to Registry
```bash
# Tag and push
./docker-push.sh

# Or manually
docker tag redb:latest your-registry/redb:latest
docker push your-registry/redb:latest
```

### Pull and Run
```bash
docker pull your-registry/redb:latest
docker run your-registry/redb:latest python3 start.py --nomad-job
```

## Testing

### Container Functionality Test
```bash
# Test with S3 key (standard sharded path)
./test-docker.sh "09/f7/09f7d02a3c2382199458c98a62b045145ee54ab6aba86166aecf3d10c3c1444c.zip"

# Test with private sample S3 key
./test-docker.sh "private/ab/cd/abcd1234567890abcdef1234567890abcdef1234567890abcdef123456.zip"
```

### Nomad Job Architecture Test
```bash
# Test Nomad job mode
./test-nomad.sh
```

## Development

### Interactive Container
```bash
# Debug container interactively
docker run -it --entrypoint /bin/bash redb:latest

# Check tool availability
docker run --rm redb:latest which python3
docker run --rm redb:latest ls -la /usr/bin/capa
```

### Build Troubleshooting

The build script includes workarounds for Docker Desktop bugs:

```bash
# If build hangs at "exporting to image", press Ctrl+C
# The image will still be created and tagged automatically
./docker-build.sh
```

### Container Logs
```bash
# View logs from mounted directory
docker run -v ./logs:/app/logs redb:latest python3 start.py --path /samples
tail -f logs/*.txt
```

## Production Notes

### Resource Requirements
- **Memory**: 2-4GB recommended (8GB for decompilation)
- **CPU**: 2+ cores recommended
- **Disk**: Minimal (stateless container)
- **Network**: Access to ClickHouse and S3 services

### Security
- Container runs as non-root user `analyzer` (UID 1000)
- Sample files should be mounted read-only
- No persistent state between container runs
- Isolated processing environment for malware analysis

### Deployment Architecture

This container is designed for:
- **Nomad job dispatch**: Single-use containers processing one sample each
- **Kubernetes jobs**: Batch processing with external orchestration
- **CI/CD pipelines**: Automated analysis in build systems
- **Development**: Local testing and debugging

The unified container approach means the same image handles both feature extraction and decompilation - the difference is only in the command-line flags used when starting the container.