Xavier Le Roux

22 papers C 1Journal 2Unranked 19
YearRankTypeTitle / Venue / Authors
2024 C conf
QRS
Afef Awadid, Xavier Le Roux, Boris Robert, Morayo Adedjouma, Eric Jenn
2023 conf
ICTON
Paula Nuño Ruano, Jianhao Zhang, Xavier Le Roux, Daniele Melati, David González-Andrade, Eric Cassan, Delphine Marris-Morini, Laurent Vivien, Norberto Daniel Lanzillotti-Kimura, Carlos Alonso-Ramos
2021 conf
ICECS
Dimitri Galayko, Jose-Francisco Ambia-Campos, Xavier Le Roux, Armine Karami, Elie Lefeuvre
2021 J jnl
Sensors
Natnicha Koompai, Papichaya Chaisakul, Pichet Limsuwan, Xavier Le Roux, Laurent Vivien, Delphine Marris-Morini
2019 conf
ICTON
D. Oser, Xavier Le Roux, F. Mazeas, Diego Pérez-Galacho, Daniel Benedikovic, Elena Durán-Valdeiglesias, V. Vakarin, Olivier Alibart, Pavel Cheben, Sebastien Tanzilli, Laurent Labonté, Delphine Marris-Morini, Eric Cassan, Laurent Vivien, Carlos Alonso-Ramos
2018 conf
ICTON
Joan Manel Ramirez, Qiankun Liu, V. Vakarin, Jacopo Frigerio, A. Ballabio, Daniel Chrastina, Xavier Le Roux, Carlos Alonso-Ramos, Giovanni Isella, Laurent Vivien, Delphine Marris-Morini
2017 conf
ICTON
Quynh Le-Van, Hongyue Wang, Xavier Le Roux, Abdelhanin Aassime, Aloyse Degiron
2017 conf
ICTON
Natalia Dubrovina, Yulong Fan, Xavier Le Roux, Andre de Lustrac, Anatole Lupu
2017 conf
ICTON
Weiwei Zhang, Elena Durán-Valdeiglesias, Thi Hong Cam Hoang, Matteo Balestrieri, Samuel Serna, Carlos Alonso-Ramos, Xavier Le Roux, Arianna Filoramo, Laurent Vivien, M. Gurioli, Eric Cassan
2017 conf
ICTON
Weiwei Zhang, Samuel Serna, Xavier Le Roux, Laurent Vivien, Eric Cassan
2017 conf
ICTON
Carlos Alonso-Ramos, Diego Pérez-Galacho, D. Oser, Xavier Le Roux, Daniel Benedikovic, F. Mazeas, W. Zhang, Samuel Serna, V. Vakarin, Elena Durán-Valdeiglesias, Laurent Labonté, Sebastien Tanzilli, Pavel Cheben, Eric Cassan, Delphine Marris-Morini, Laurent Vivien
2016 conf
ICTON
Léopold Virot, Delphine Marris-Morini, Daniel Benedikovic, Carlos Alonso-Ramos, Jean-Michel Hartmann, Eric Cassan, Paul Crozat, Xavier Le Roux, Charles Baudot, Frédéric Boeuf, Jean-Marc Fedeli, Laurent Vivien
2016 conf
ICTON
Delphine Marris-Morini, V. Vakarin, Papichaya Chaisakul, Jacopo Frigerio, M. Rahman, Joan Manel Ramirez, M.-S. Rouifed, Daniel Chrastina, Xavier Le Roux, Giovanni Isella, Laurent Vivien
2016 conf
ICTON
Weiwei Zhang, Samuel Serna, Thi Hong Cam Hoang, Xavier Le Roux, Laurent Vivien, Eric Cassan
2016 conf
ICTON
Pedro Damas, Xavier Le Roux, Mathias Berciano, G. Marcaud, Carlos Alonso-Ramos, Daniel Benedikovic, Delphine Marris-Morini, Eric Cassan, Laurent Vivien
2016 conf
ICTON
Pavel Cheben, Jens H. Schmid, Dan-Xia Xu, Siegfried Janz, Jean Lapointe, M. Rahim, Shurui Wang, Martin Vachon, Robert Halir, Alejandro Ortega-Moñux, Jose Darío Sarmiento-Merenguel, J. Gonzalo Wangüemert-Pérez, Íñigo Molina-Fernández, James Pond, Daniel Benedikovic, Carlos Alonso-Ramos, Xavier Le Roux, Laurent Vivien, Delphine Marris-Morini, Jordi Soler Penadés, Milos Nedeljkovic, Goran Z. Mashanovich, Aitor V. Velasco, Maria Luisa Calvo, Milan Dado, Jarmila Müllerová, Weimin Ye, Martin Papes, Vladimir Vasinek
2015 conf
ICTON
Thi Hong Cam Hoang, Weiwei Zhang, Samuel Serna, Charles Caer, Xavier Le Roux, Laurent Vivien, Eric Cassan
2015 conf
ICTON
Weiwei Zhang, Samuel Serna, Xavier Le Roux, Laurent Vivien, Eric Cassan
2015 conf
ICTON
Pedro Damas, Xavier Le Roux, Delphine Marris-Morini, Eric Cassan, Laurent Vivien
2014 conf
ECOC
Nicolas Dubreuil, Jérémy Oden, Samuel Serna, M. Hanna, Charles Caer, Xavier Le Roux, C. Sauvan, Stéphane Trebaol, P. Delaye, Eric Cassan
2014 conf
ICTON
Aloyse Degiron, Tatiana V. Teperik, Quynh Le-Van, Xavier Le Roux
2009 J jnl
Proc. IEEE
Delphine Marris-Morini, Laurent Vivien, Gilles Rasigade, Jean-Marc Fedeli, Eric Cassan, Xavier Le Roux, Paul Crozat, Sylvain Maine, Anatole Lupu, Philippe Lyan, Pierrette Rivallin, Mathieu Halbwax, Suzanne Laval
redb/extractors/pe_extractors/pe_resources.py
← Index redb/extractors/pe_extractors/pe_resources.py python
from hashlib import sha256
import inspect
from datetime import datetime, timezone
from typing import Any

import magic
from magika import Magika
import pefile
from pefile import UnicodeStringWrapperPostProcessor

from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import PEResource


class PEResourceExtractor(PEExtractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.elastic_index = self.index_prefix + "-pe_resources"
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.PE_RESOURCE.value

    def _extract_resources(self):
        """
        Returns:
        resources: a list of dictionaries, one per each resources type found.
                    each dictionary the key represents the name of the content,
                    which is the value itself.
                    Empty list if no resources present.
        """
        self.log.debug(inspect.currentframe().f_code.co_name)
        resources_list = []
        try:
            if hasattr(self.pe, "DIRECTORY_ENTRY_RESOURCE"):
                for resource_type in self.pe.DIRECTORY_ENTRY_RESOURCE.entries:
                    # if resource_type.name is not None:
                    #     name = resource_type.name
                    # else:
                    #     name = pefile.RESOURCE_TYPE.get(resource_type.struct.Id)
                    # if not name:
                    #     name = resource_type.struct.Id
                    name = (
                        resource_type.name
                        if resource_type.name is not None
                        else pefile.RESOURCE_TYPE.get(resource_type.struct.Id)
                    )
                    if isinstance(name, UnicodeStringWrapperPostProcessor):
                        name = name.decode()
                    try:
                        if hasattr(resource_type, "directory"):
                            for resource_id in resource_type.directory.entries:
                                if hasattr(resource_id, "directory"):
                                    for resource_lang in resource_id.directory.entries:
                                        rsrc_data = self.pe.get_data(
                                            resource_lang.data.struct.OffsetToData,
                                            resource_lang.data.struct.Size,
                                        )
                                        file_type = magic.from_buffer(rsrc_data)
                                        magik = Magika().identify_bytes(rsrc_data).output.label

                                        rsrc_entropy = (
                                            "%.2f"
                                            % pefile.SectionStructure.entropy_H(
                                                self.pe, rsrc_data
                                            )
                                        )
                                        rsrc_sha256 = sha256(rsrc_data).hexdigest()
                                        lang = pefile.LANG.get(
                                            resource_lang.data.lang, "*unknown*"
                                        )
                                        sublang = pefile.get_sublang_name_for_lang(
                                            resource_lang.data.lang,
                                            resource_lang.data.sublang,
                                        )
                                        pe_resource = PEResource(
                                            _id=rsrc_sha256,
                                            resource_type=name,
                                            resource_entropy=rsrc_entropy,
                                            resource_sha256=rsrc_sha256,
                                            resource_filetype=file_type,
                                            resource_magika=magik,
                                            resource_language=lang,
                                            resource_rva=resource_lang.data.struct.OffsetToData,
                                            resource_size=resource_lang.data.struct.Size,
                                            resource_sub_lang=sublang,
                                        )
                                        resources_list.append(pe_resource)
                    except Exception as e:
                        self.log.warning(
                            f"Continue after Error in {self.hash.sha256}: {resource_type.name} "
                            f"Exception: {e}",
                            stack_info=True,
                        )
                        # resources_list.append({f"{e} - {resource_type.name}"})
                        continue
        except Exception as e:
            self.log.exception(
                f"Extract exports error {self.hash.sha256} Exception: {e}"
            )
        self.log.debug(f"Resource list {resources_list}")
        return resources_list

    def extract(self):
        try:
            self.log.debug(inspect.currentframe().f_code.co_name)
            resources = self._extract_resources()
            # self.export_to_elastic(resources)  # Let the exporters handle this
            return resources
        except Exception as e:
            self.log.error(f"Extract resources error {self.hash.sha256} Exception: {e}")
            return None

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.extract()
        elif exporter_type == "ClickHouseExporter":
            resources = self.extract()
            if resources is None:
                return None
            
            data = []
            current_time = datetime.now(timezone.utc)
            
            for resource in resources:
                data.append([
                    self.sha256,                    # sha256
                    self.md5,                       # md5
                    self.sha1,                      # sha1
                    resource.resource_type,         # resource_type
                    resource.resource_entropy,      # resource_entropy
                    resource.resource_sha256,       # resource_sha256
                    resource.resource_filetype,     # resource_filetype
                    resource.resource_magika,       # resource_magika
                    resource.resource_language,     # resource_language
                    resource.resource_sub_lang,     # resource_sub_lang
                    resource.resource_size,         # resource_size
                    resource.resource_rva,          # resource_rva
                    current_time                    # analysis_date
                ])
            
            column_names = [
                'sha256', 'md5', 'sha1', 'resource_type', 'resource_entropy',
                'resource_sha256', 'resource_filetype', 'resource_magika',
                'resource_language', 'resource_sub_lang', 'resource_size',
                'resource_rva', 'analysis_date'
            ]
            
            if not data:
                return None

            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'LowCardinality(Nullable(String))', 'Float64',
                'FixedString(64)', 'LowCardinality(Nullable(String))', 'LowCardinality(Nullable(String))',
                'LowCardinality(Nullable(String))', 'LowCardinality(Nullable(String))', 'UInt64',
                'UInt64', 'DateTime64(3, \'UTC\')'
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_resources"