Weidong Shao

30 papers A* 1B 3C 2Journal 18Unranked 6
YearRankTypeTitle / Venue / Authors
2025 J jnl
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.
Yujie Zhang, Huiying Lan, Ehsan Aghapour, Zhiyuan Ning, Peng Zan, Weidong Shao, Anuj Pathania, Tulika Mitra
2025 conf
ANTS
Xue Hu, Hong Chen, Weidong Shao, Vimal Bhatia, Suman Palrecha, Bowen Chen
2024 J jnl
J. Opt. Commun. Netw.
Bowen Chen, Ling Liu, Yuexuan Fan, Weidong Shao, Mingyi Gao, Hong Chen, Weiguo Ju, Pin-Han Ho, Jason P. Jue, Gangxiang Shen
2024 B conf
GLOBECOM
Bin He, Nianying Zheng, Yuxuan Lu, Hong Chen, Mingyi Gao, Weidong Shao, Limei Peng, Pin-Han Ho, Bowen Chen
2023 J jnl
IEEE Trans. Commun.
Bowen Chen, Yu Lei, Jingwen Hu, Ling Liu, Weike Ma, Jinbing Wu, Mingyi Gao, Weidong Shao, Pin-Han Ho
2022 J jnl
IEEE Internet Things J.
Weike Ma, Bowen Chen, Ling Liu, Hong Chen, Weidong Shao, Mingyi Gao, Jinbing Wu, Pin-Han Ho
2022 conf
ICAIT
Weidong Shao, Mengfan Cheng, Lei Deng, Qi Yang, Xiaoxiao Dai, Deming Liu
2022 J jnl
IEEE Internet Things J.
Bowen Chen, Yu Lei, Yunfei Jiang, Qi Chen, Jinbing Wu, Weidong Shao, Mingyi Gao, Pin-Han Ho
2020 J jnl
IEEE Commun. Lett.
Yuanyuan Ma, Mingyi Gao, Lei Wang, Yanping Sha, Weidong Shao, Gangxiang Shen
2020 C conf
ICCC
Weidong Shao, Shun Zhang, Caijun Zhong, Xianfu Lei, Pingzhi Fan
2020 J jnl
IEEE Trans. Commun.
Weidong Shao, Shun Zhang, Hongyan Li, Nan Zhao, Octavia A. Dobre
2019 J jnl
IEEE Access
Weidong Shao, Mengfan Cheng, Chenkun Luo, Lei Deng, Minming Zhang, Songnian Fu, Ming Tang, Deming Liu
2019 B conf
PIMRC
Weidong Shao, Shun Zhang, Hongyan Li, Jianpeng Ma
2019 J jnl
IEEE Commun. Lett.
Weidong Shao, Shun Zhang, Xiushe Zhang, Jianpeng Ma, Nan Zhao, Victor C. M. Leung
2019 J jnl
IEEE Commun. Lett.
Weidong Shao, Shun Zhang, Xiushe Zhang, Jianpeng Ma, Nan Zhao
2019 J jnl
IEEE Access
Ning Wang, Gangxiang Shen, Sanjay Kumar Bose, Weidong Shao
2018 conf
OFC
Ning Wang, Weidong Shao, Sanjay K. Bose, Gangxiang Shen
2018 B conf
GLOBECOM
Weidong Shao, Shun Zhang, Hongyan Li, Jianpeng Ma, Guangzhe Zhao, Xiushe Zhang
2018 J jnl
Comput. Math. Appl.
Weidong Shao, Jun Li
2017 conf
WCSP
Weidong Shao, Shun Zhang, Hongyan Li, Jianpeng Ma
2017 J jnl
IEEE Commun. Lett.
Momiao Zhou, Hongyan Li, Jiandong Li, Long Suo, Weidong Shao
2016 J jnl
JOCN
Hao Chen, Yongcheng Li, Sanjay K. Bose, Weidong Shao, Lian Xiang, Yiran Ma, Gangxiang Shen
2016 J jnl
Sci. China Inf. Sci.
Yongcheng Li, Li Gao, Sanjay K. Bose, Weidong Shao, Xiaoling Wang, Gangxiang Shen
2016 conf
ChinaCom (1)
Jianpeng Ma, Shun Zhang, Hongyan Li, Weidong Shao
2015 J jnl
IEEE J. Sel. Areas Commun.
Xuejiao Zhao, Gangxiang Shen, Weidong Shao, Limei Peng
2013 J jnl
JOCN
Yunlei Lui, Gangxiang Shen, Weidong Shao
2012 C conf
ICCC
Yunlei Lui, Gangxiang Shen, Weidong Shao
2009 J jnl
ACM Trans. Web
Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, Dan Boneh
2008 conf
EUSIPCO
Enqing Dong, Wenji Xu, Weidong Shao
2007 A* conf
CCS
Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, Dan Boneh
redb/extractors/js_extractors/scripts/js-xray-runner.js
← Index redb/extractors/js_extractors/scripts/js-xray-runner.js javascript
#!/usr/bin/env node
// Bridge between the Python JS pipeline and @nodesecure/js-x-ray.
//
// Usage: node js-xray-runner.js <path-to-js-file>
//   stdout  one JSON object: {"obfuscator": <name|null>, "warnings": [...]}
//   stderr  human-readable error on failure
//   exit 0  analysis ran (the file may still be benign — see "obfuscator")
//   exit 1  the file could not be read or analysed
//
// Each warning is emitted as {kind, value} so the Python side can tag
// supporting signals (encoded-literal, short-identifiers, suspicious-literal,
// unsafe-stmt) without having to mirror js-x-ray's whole schema.
//
// js-x-ray ≥7 ships as an ES module, which CommonJS `require()` cannot load
// from a `.js` script — the dynamic `import()` below is what makes the
// bridge work without renaming the file to `.mjs` or adding `"type":
// "module"` to package.json (which would break tools that still
// `require()` from this directory).

const fs = require("fs");
const path = require("path");

function fail(msg) {
  process.stderr.write(msg + "\n");
  process.exit(1);
}

async function main() {
  const target = process.argv[2];
  if (!target) fail("usage: js-xray-runner.js <file>");

  let source;
  try {
    source = fs.readFileSync(target, "utf8");
  } catch (e) {
    fail(`read failed: ${e.message}`);
  }

  // The legacy `runASTAnalysis` function is deprecated (removed in v8); the
  // current API is the `AstAnalyser` class. Both produce a result with the
  // same `warnings` shape, so the rest of the bridge is unchanged.
  let AstAnalyser;
  try {
    ({ AstAnalyser } = await import("@nodesecure/js-x-ray"));
  } catch (e) {
    fail(`@nodesecure/js-x-ray not installed (run \`npm install\` in ${path.dirname(__filename)}): ${e.message}`);
  }

  // js-x-ray defaults to module-mode parsing, which rejects scripts that
  // (legally) use reserved words as identifiers, top-level `return`, etc.
  // A lot of real-world JS malware is script-style (WScript/HTA bodies,
  // pasted snippets) — retrying in script mode catches those without
  // pulling in a more lenient parser. Both attempts share the same
  // analyser; only the parse mode flips. If both fail, the original error
  // (module-mode) is reported because that's the more informative one for
  // genuinely broken sources.
  let result;
  const analyser = new AstAnalyser();
  let firstErr;
  try {
    result = await analyser.analyse(source, { module: true });
  } catch (e) {
    firstErr = e;
    try {
      result = await analyser.analyse(source, { module: false });
    } catch (e2) {
      fail(`js-x-ray analysis failed: ${firstErr.message}`);
    }
  }

  const warnings = (result.warnings || []).map((w) => ({
    kind: w.kind,
    value: w.value !== undefined ? w.value : null,
  }));

  // js-x-ray flags the obfuscator family in a warning whose kind is
  // "obfuscated-code" and whose value names the family (jsfuck, obfuscator.io,
  // freejsobfuscator, morse, jjencode, ...). Absent => not detected.
  const obfWarning = warnings.find((w) => w.kind === "obfuscated-code");
  const obfuscator = obfWarning ? obfWarning.value : null;

  // js-x-ray runs its own AST internally with a modern parser, so its
  // identifier-length average is the only path the Python pipeline has to
  // that signal on ES2015+ sources — pyjsparser is ES5.1-only and silently
  // drops to 0 the moment it hits destructuring, classes, optional chaining,
  // etc. Surfacing this lets the heuristic's `avg_identifier_length<2`
  // strong signal fire on real obfuscator.io output. `null` when the value
  // is missing or non-numeric (defensive — older js-x-ray builds may differ).
  const idsLengthAvg =
    typeof result.idsLengthAvg === "number" && !Number.isNaN(result.idsLengthAvg)
      ? result.idsLengthAvg
      : null;

  process.stdout.write(JSON.stringify({ obfuscator, warnings, idsLengthAvg }));
}

main().catch((e) => fail(e.message || String(e)));