Weicai Zhong

49 papers A* 5B 12Journal 20Unranked 12
YearRankTypeTitle / Venue / Authors
2023 A* conf
AAAI
Zhiyu Pan, Yinpeng Chen, Jiale Zhang, Hao Lu, Zhiguo Cao, Weicai Zhong
2023 J jnl
CoRR
Zhiyu Pan, Yinpeng Chen, Jiale Zhang, Hao Lu, Zhiguo Cao, Weicai Zhong
2022 conf
ECCV (29)
Yizheng Wu, Min Shi, Shuaiyuan Du, Hao Lu, Zhiguo Cao, Weicai Zhong
2022 J jnl
CoRR
Yizheng Wu, Min Shi, Shuaiyuan Du, Hao Lu, Zhiguo Cao, Weicai Zhong
2022 A* conf
ACM Multimedia
Yinpeng Chen, Zhiyu Pan, Min Shi, Hao Lu, Zhiguo Cao, Weicai Zhong
2022 J jnl
CoRR
Yinpeng Chen, Zhiyu Pan, Min Shi, Hao Lu, Zhiguo Cao, Weicai Zhong
2022 B conf
ICIP
Zhiyu Pan, Zhiguo Cao, Ke Xian, Hao Lu, Weicai Zhong
2022 A* conf
ACM Multimedia
Zijin Wu, Xingyi Li, Juewen Peng, Hao Lu, Zhiguo Cao, Weicai Zhong
2022 J jnl
CoRR
Zijin Wu, Xingyi Li, Juewen Peng, Hao Lu, Zhiguo Cao, Weicai Zhong
2022 B conf
ICIP
Yinpeng Chen, Jiale Zhang, Zhiguo Cao, Hao Lu, Weicai Zhong
2021 A* conf
CVPR
Chaoyi Hong, Shuaiyuan Du, Ke Xian, Hao Lu, Zhiguo Cao, Weicai Zhong
2021 B conf
ICIP
Tianpei Lian, Zhiguo Cao, Ke Xian, Zhiyu Pan, Weicai Zhong
2021 B conf
ICIP
Tianpei Lian, Zhiguo Cao, Hao Lu, Zijin Wu, Weicai Zhong
2021 A* conf
ICCV
Zhiyu Pan, Zhiguo Cao, Kewei Wang, Hao Lu, Weicai Zhong
2020 conf
ACCV (4)
Jiale Zhang, Ke Xian, Chengxin Liu, Yinpeng Chen, Zhiguo Cao, Weicai Zhong
2013 J jnl
Peer-to-Peer Netw. Appl.
Weicai Zhong, Bijan Raahemi, Jing Liu
2013 J jnl
Biosyst.
Weicai Zhong, Jing Liu, Li Zhang
2012 B conf
IEEE Congress on Evolutionary Computation
Jing Liu, Weicai Zhong
2012 J jnl
Biosyst.
Weicai Zhong, Satoshi Kokubo, Jun Tanimoto
2012 J jnl
Evol. Comput.
Jing Liu, Hussein A. Abbass, David G. Green, Weicai Zhong
2011 B conf
IEEE Congress on Evolutionary Computation
Weicai Zhong, Yang Zhang, Jing Liu
2011 J jnl
Artif. Life
Jing Liu, Hussein A. Abbass, Weicai Zhong, David G. Green
2011 J jnl
Int. J. Swarm Intell. Res.
Jing Liu, Jinshu Li, Weicai Zhong, Li Zhang, Ruochen Liu
2011 J jnl
Inf. Syst. Frontiers
Xue Li, Jing Liu, Quan Z. Sheng, Sherali Zeadally, Weicai Zhong
2010 J jnl
IEEE Trans. Syst. Man Cybern. Part B
Jing Liu, Weicai Zhong, Licheng Jiao
2010 B conf
IEEE Congress on Evolutionary Computation
Jing Liu, Weicai Zhong, Hussein A. Abbass, David G. Green
2009 J jnl
Pattern Recognit. Lett.
Jing Liu, Xue Li, Weicai Zhong
2009 J jnl
Peer-to-Peer Netw. Appl.
Bijan Raahemi, Weicai Zhong, Jing Liu
2009 B conf
IJCNN
Weicai Zhong, Bijan Raahemi, Jing Liu
2009 B conf
IEEE Congress on Evolutionary Computation
Jing Liu, Weicai Zhong, Licheng Jiao
2009 B conf
IEEE Congress on Evolutionary Computation
Jing Liu, Wenrong Jiang, Weicai Zhong, Licheng Jiao
2008 conf
SEAL
Jing Liu, Wenlong Fu, Weicai Zhong
2008 J jnl
IEEE Trans. Evol. Comput.
Jing Liu, Weicai Zhong, Licheng Jiao, Xue Li
2008 conf
SEAL
Jing Liu, Weicai Zhong, Jinshu Li
2008 conf
ICTAI (1)
Bijan Raahemi, Weicai Zhong, Jing Liu
2007 J jnl
IEEE Trans. Syst. Man Cybern. Part B
Jing Liu, Weicai Zhong, Licheng Jiao
2006 J jnl
IEEE Trans. Syst. Man Cybern. Part B
Jing Liu, Weicai Zhong, Licheng Jiao
2006 J jnl
IEEE Trans. Evol. Comput.
Licheng Jiao, Jing Liu, Weicai Zhong
2006 J jnl
IEEE Trans. Neural Networks
Jing Liu, Weicai Zhong, Licheng Jiao
2006 conf
SEAL
Jing Liu, Weicai Zhong
2005 B conf
EvoCOP
Weicai Zhong, Jing Liu, Licheng Jiao
2005 conf
ICNC (3)
Weicai Zhong, Jing Liu, Licheng Jiao
2005 conf
ICNC (3)
Weicai Zhong, Jing Liu, Licheng Jiao
2005 conf
CIS (1)
Jing Liu, Weicai Zhong, Licheng Jiao
2004 B conf
PAKDD
Jing Liu, Weicai Zhong, Fang Liu, Licheng Jiao
2004 conf
Intelligent Information Systems
Weicai Zhong, Jing Liu, Licheng Jiao
2004 J jnl
IEEE Trans. Syst. Man Cybern. Part B
Weicai Zhong, Jing Liu, Mingzhi Xue, Licheng Jiao
2004 conf
Rough Sets and Current Trends in Computing
Jing Liu, Weicai Zhong, Licheng Jiao, Fang Liu
2003 conf
WAA
Mingzhi Xue, Weicai Zhong, Licheng Jiao
redb/extractors/js_extractor.py
← Index redb/extractors/js_extractor.py python
import logging
import re
from abc import ABCMeta, abstractmethod

from redb.extractors.extractor import Extractor
from redb.extractors.js_extractors.js_context import JSContext, _text_entropy

logger = logging.getLogger(__name__)

# ESM is recognised by line-anchored `import ... from "..."` / bare side-effect
# `import "..."` / top-level `export ...`. Anchored at line start to avoid
# matching the substring inside string literals or comments.
_ESM_PATTERN = re.compile(
    r'(?m)^\s*(?:'
    r'import\s+[^;\n]*?\bfrom\s+[\'"]'
    r'|import\s+[\'"][^\'"]+[\'"]'
    r'|export\s+(?:default\b|\{|\*|const\b|let\b|var\b|function\b|class\b|async\b)'
    r')'
)


@abstractmethod
class JSExtractor(Extractor, metaclass=ABCMeta):
    """Base class for JavaScript file extractors.

    Every JSExtractor reads its raw materials (bytes / decoded source / line
    list / scan_source results / pyjsparser AST / text entropy) from a shared
    `JSContext`. When workers.py drives the JS pipeline it builds one context
    per sample and threads it into every extractor via `context=`. When tests
    or other callers instantiate an extractor directly, the constructor builds
    a fresh context from `(filepath, source=...)`.

    All historical instance attributes (`self.binary`, `self.js_source`,
    `self.lines`) and helpers (`self._decode_source`, `self._parse_ast`,
    `self._calculate_text_entropy`) are preserved as thin delegators so
    existing extractor code keeps working unchanged.
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        known_benign=False,
        known_malicious=False,
        source=None,
        context=None,
    ):
        if context is None:
            context = JSContext.from_path(filepath, log=log, source=source)
        elif source is not None and context.source != source:
            log.warning(
                "JSExtractor received both `source=` and `context=` with "
                "differing source; ignoring source kwarg"
            )
        self._context = context

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            known_benign=known_benign,
            known_malicious=known_malicious,
        )

    @property
    def binary(self):
        return self._context.raw_bytes

    @property
    def js_source(self):
        return self._context.source

    @property
    def lines(self):
        return self._context.lines

    def _decode_source(self):
        """Back-compat shim — the context already decoded once at construction.

        Kept so any external caller using the historical method name keeps
        working without touching the underlying bytes again.
        """
        return self._context.source

    def _parse_ast(self):
        """Return the shared pyjsparser AST (or None if unavailable)."""
        return self._context.ast

    def _calculate_text_entropy(self, text):
        """Shannon text entropy for `text`.

        When `text` is the context's own source we read the cached value;
        otherwise we compute fresh. JSStringsExtractor calls this on arbitrary
        decoded substrings, so the fresh-compute path must remain available.
        """
        if text is self._context.source:
            return self._context.text_entropy
        return _text_entropy(text)

    def _detect_environment(self):
        """Detect the target JS runtime environment."""
        src = self.js_source
        if not src:
            return "unknown"

        # WScript/WSH indicators
        wscript_patterns = [
            'WScript.', 'WSH.', 'ActiveXObject', 'Scripting.FileSystemObject',
            'WScript.Shell', 'ADODB.Stream',
        ]
        for p in wscript_patterns:
            if p in src:
                return "wscript"

        # Browser-extension APIs — checked before generic browser/worker because
        # `chrome.*` and `browser.runtime` are distinctive of MV2/MV3 extensions
        extension_patterns = [
            'chrome.runtime', 'chrome.tabs', 'chrome.storage',
            'chrome.webRequest', 'browser.runtime', 'browser.tabs',
        ]
        for p in extension_patterns:
            if p in src:
                return "browser_extension"

        # Service / Web Workers — worker-only APIs that don't appear in regular
        # browser pages (a generic browser script would use `window.` or
        # `document.`, never `self.importScripts` or `caches.match`)
        worker_patterns = [
            "self.addEventListener('fetch'", 'self.addEventListener("fetch"',
            'self.importScripts', 'self.skipWaiting',
            'caches.match', 'caches.open',
        ]
        for p in worker_patterns:
            if p in src:
                return "service_worker"

        # Deno runtime
        if 'Deno.' in src:
            return "deno"

        # Node.js indicators
        node_patterns = [
            'require(', 'module.exports', 'process.env', '__dirname',
            '__filename', 'Buffer.', 'child_process',
        ]
        for p in node_patterns:
            if p in src:
                return "node"

        # Browser indicators
        browser_patterns = [
            'document.', 'window.', 'navigator.', 'localStorage',
            'sessionStorage', 'XMLHttpRequest', 'addEventListener',
        ]
        for p in browser_patterns:
            if p in src:
                return "browser"

        return "unknown"

    def _detect_script_type(self):
        """Detect the script type/format."""
        src = self.js_source
        if not src:
            return "unknown"

        stripped = src.lstrip()

        # JScript.Encode payload — must be checked first since the encoded
        # body can't be classified any other way
        if stripped.startswith('#@~^'):
            return "jse"

        # WSF / HTA live in the first few KB of an HTML-ish wrapper
        head_lower = stripped[:4096].lower()

        # Windows Script File — XML wrapper around one or more <script> blocks
        if ('<job' in head_lower or '<package' in head_lower) and '<script' in head_lower:
            return "wsf"

        # HTML Application — distinct from generic embedded_html because HTAs
        # run under mshta.exe with full WSH/ActiveX access
        if '<hta:application' in head_lower or 'application/hta' in head_lower:
            return "hta"

        if stripped.startswith('<!') or stripped.startswith('<html') or '<script' in stripped[:2000]:
            return "embedded_html"

        if 'WScript.' in src or 'WSH.' in src:
            return "wscript"

        if _ESM_PATTERN.search(src):
            return "esm"

        if 'require(' in src or 'module.exports' in src:
            return "node_module"

        return "standalone"