Xiang Li

37 papers C 3Journal 25Unranked 8
YearRankTypeTitle / Venue / Authors
2024 J jnl
Trans. GIS
Di Zhang, Huan Meng, Moyang Wang, Xianrui Xu, Jianhai Yan, Xiang Li
2024 conf
SpatialDI
Bao Zhu, Xianrui Xu, Huan Meng, Chen Meng, Xiang Li
2024 J jnl
Geo spatial Inf. Sci.
Ye Zhang, Moyang Wang, Joseph Mango, Liang Xin, Chen Meng, Xiang Li
2024 J jnl
IEEE Trans. Geosci. Remote. Sens.
Moyang Wang, Xiang Li, Kun Tan, Joseph Mango, Chen Pan, Di Zhang
2024 J jnl
CoRR
Shaohua Wang, Xing Xie, Yong Li, Danhuai Guo, Zhi Cai, Yu Liu, Yang Yue, Xiao Pan, Feng Lu, Huayi Wu, Zhipeng Gui, Zhiming Ding, Bolong Zheng, Fuzheng Zhang, Tao Qin, Jingyuan Wang, Chuang Tao, Zhengchao Chen, Hao Lu, Jiayi Li, Hongyang Chen, Peng Yue, Wenhao Yu, Yao Yao, Leilei Sun, Yong Zhang, Longbiao Chen, Xiaoping Du, Xiang Li, Xueying Zhang, Kun Qin, Zhaoya Gong, Weihua Dong, Xiaofeng Meng
2023 J jnl
GeoInformatica
Senlin Mu, Xiao Huang, Moyang Wang, Di Zhang, Dong Xu, Xiang Li
2023 ed.
SpatialDI
Xiaofeng Meng, Xiang Li, Jianqiu Xu, Xueying Zhang, Yuming Fang, Bolong Zheng, Yafei Li
2023 J jnl
Int. J. Geogr. Inf. Sci.
Joseph Mango, Moyang Wang, Senlin Mu, Di Zhang, Jamila Ngondo, Regina Valerian-Peter, Christophe Claramunt, Xiang Li
2022 J jnl
ISPRS Int. J. Geo Inf.
Moyang Wang, Yijun He, Huan Meng, Ye Zhang, Bao Zhu, Joseph Mango, Xiang Li
2022 J jnl
Int. J. Geogr. Inf. Sci.
Joseph Mango, Christophe Claramunt, Jamila Ngondo, Di Zhang, Dong Xu, EbruHusniye Colak, Xiang Li
2021 J jnl
ISPRS Int. J. Geo Inf.
Pengyuan Wang, Xiao Huang, Joseph Mango, Di Zhang, Dong Xu, Xiang Li
2021 J jnl
Trans. GIS
Dong Xu, Xiao Huang, Joseph Mango, Xiang Li, Zhenlong Li
2020 J jnl
CoRR
Yujie Hu, Harvey J. Miller, Xiang Li
2020 J jnl
Trans. GIS
Dong Xu, Xiao Huang, Zhenlong Li, Xiang Li
2020 J jnl
CoRR
Dong Xu, Xiao Huang, Joseph Mango, Xiang Li, Zhenlong Li
2019 C conf
W2GIS
Xiang Li, Qu Chen, Buyang Cao, Christophe Claramunt, Hong Yi
2019 conf
BMSB
Xiang Li, Li Chen, Zhiyong Gao, Xiaoyun Zhang, Chunxian Wang, Hongyang Chen
2018 conf
Geoinformatics
Qu Chen, Hong Yi, Yujie Hu, Xianrui Xu, Xiang Li
2018 J jnl
Trans. GIS
Xiang Li, Qiuping Li, Xianrui Xu, Dong Xu, Xihui Zhang
2018 conf
Geoinformatics
Jin Ye, Yujie Hu, Xianrui Xu, Hong Yi, Xiang Li
2018 J jnl
Comput. Environ. Urban Syst.
Tao Xu, Xihui Zhang, Christophe Claramunt, Xiang Li
2017 J jnl
Entropy
Tao Xu, Xianrui Xu, Yujie Hu, Xiang Li
2017 J jnl
Ann. GIS
Huijun Ren, Peishan Chai, Yanbing Zhang, Dong Xu, Tao Xu, Xiang Li
2017 C ed.
W2GIS
David Brosset, Christophe Claramunt, Xiang Li, Tianzhen Wang
2015 J jnl
Ann. GIS
Tao Xu, Jionghua Wang, Xiang Li
2014 conf
ISA@GIS
Feixiong Luo, Guofeng Cao, Xiang Li
2014 J jnl
Trans. GIS
Yujie Hu, Harvey J. Miller, Xiang Li
2013 J jnl
Ann. GIS
Xiang Li, Yujie Hu, Jun Xie, Jing Sun
2012 J jnl
Int. J. Oper. Res. Inf. Syst.
Xiang Li, Christophe Claramunt, Xihui Zhang, Yingping Huang
2012 J jnl
J. Syst. Sci. Complex.
Xiang Li, Bo Huang, Zhengjun Liu, Xihui Zhang, Jing Sun
2011 J jnl
Comput. Ind. Eng.
Xiang Li, Ningchuan Xiao, Christophe Claramunt, Hui Lin
2010 J jnl
Comput. Environ. Urban Syst.
Xiang Li, Christophe Claramunt, Cyril Ray
2010 conf
ADMA (2)
Yiyu Huang, Wenjing Su, Xiang Li
2010 conf
Geoinformatics
Xiaojie Li, Xiang Li, Daimin Tang, Xianrui Xu
2008 conf
WAIM
Xiang Li, Da Zhou, Xiaofeng Meng
2008 C ed.
W2GIS
Michela Bertolotto, Cyril Ray, Xiang Li
2006 J jnl
Trans. GIS
Xiang Li, Christophe Claramunt
redb/extractors/macho_extractor.py
← Index redb/extractors/macho_extractor.py python
import logging
from abc import ABCMeta, abstractmethod
import inspect
import sys
import os

import machofile

from redb.extractors.extractor import Extractor

logger = logging.getLogger(__name__)


@abstractmethod
class MachOExtractor(Extractor, metaclass=ABCMeta):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        macho=None,
    ):
        # Read binary and parse machofile BEFORE calling super().__init__
        # This avoids reading the file twice
        with open(filepath, "rb") as f:
            binary_data = f.read()

        # Parse machofile with binary data
        self.macho = macho if macho else self._generate_machofile_object(binary_data)

        # Extract hashes from machofile to pass to parent
        precomputed_hashes = None
        if self.macho:
            try:
                general_info = self.macho.get_general_info()
                if general_info:
                    # For FAT binaries, get_general_info() returns dict with 'fat' key
                    # For single-arch, it returns the info directly
                    if 'fat' in general_info:
                        fat_info = general_info['fat']
                        precomputed_hashes = {
                            'MD5': fat_info.get('MD5'),
                            'SHA1': fat_info.get('SHA1'),
                            'SHA256': fat_info.get('SHA256'),
                        }
                    else:
                        precomputed_hashes = {
                            'MD5': general_info.get('MD5'),
                            'SHA1': general_info.get('SHA1'),
                            'SHA256': general_info.get('SHA256'),
                        }
            except Exception as e:
                logger.debug(f"Could not get hashes from machofile: {e}")

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            precomputed_hashes=precomputed_hashes,
        )

        # Store binary data so base class doesn't re-read
        self._binary_data = binary_data

    @property
    def binary(self):
        """Override to use already-read binary data."""
        return self._binary_data

    def _generate_machofile_object(self, binary_data):
        """Generate and parse a machofile object from binary data."""
        macho = None
        try:
            macho = machofile.UniversalMachO(data=binary_data)
            if not macho:
                raise Exception("Empty file?")

            # Parse the MachO object once during initialization
            macho.parse()

        except Exception as e:
            logger.error(f"Format error parsing MachO: {e}")
        return macho

    # def _is_macho_file(self):
    #     """Check if the file is a valid Mach-O binary."""
    #     try:
    #         if not self.macho:
    #             return False
            
    #         # For Universal/FAT binaries, check if any architecture is valid
    #         if hasattr(self.macho, 'is_fat') and self.macho.is_fat:
    #             return len(self.macho.architectures) > 0
    #         else:
    #             # Single architecture binary
    #             return hasattr(self.macho, 'macho') and self.macho.macho is not None
    #     except Exception as e:
    #         self.log.error(f"Error checking Mach-O file: {e}")
    #         return False

    def _is_signed(self):
        """Check if the Mach-O binary is code signed using new API."""
        try:
            if not self.macho:
                return False

            # Get architectures using new API
            architectures = self.macho.get_architectures()

            # For each architecture, check if signed
            for arch in architectures:
                try:
                    signature_info = self.macho.get_code_signature_info(arch=arch)
                    if signature_info and signature_info.get('signed', False):
                        return True
                except Exception:
                    continue

            return False
        except Exception as e:
            self.log.error(f"Error checking Mach-O signature: {e}")
            return False

    def _get_architectures(self):
        """Get list of architectures in the Mach-O binary using new API."""
        try:
            if not self.macho:
                return []

            # Use new API method
            architectures = self.macho.get_architectures()
            return architectures if architectures else []
        except Exception as e:
            self.log.error(f"Error getting architectures: {e}")
            return []

    # def _get_macho_for_arch(self, arch_name=None):
    #     """Get MachO instance for specific architecture or default."""
    #     try:
    #         if not self.macho:
    #             return None
            
    #         if hasattr(self.macho, 'is_fat') and self.macho.is_fat:
    #             if arch_name:
    #                 return self.macho.architectures.get(arch_name)
    #             else:
    #                 # Return first available architecture
    #                 return next(iter(self.macho.architectures.values())) if self.macho.architectures else None
    #         else:
    #             # Single architecture binary
    #             return self.macho.macho if hasattr(self.macho, 'macho') else None
    #     except Exception as e:
    #         self.log.error(f"Error getting MachO for architecture: {e}")
    #         return None

    # def _get_formatted_header_values(self, header):
    #     """Get both raw and human-readable header values."""
    #     try:
    #         macho_instance = self._get_macho_for_arch()
    #         if not macho_instance:
    #             return None
            
    #         # Parse the MachO if not already parsed
    #         if not hasattr(macho_instance, 'header') or not macho_instance.header:
    #             macho_instance.parse()
            
    #         # Get human-readable values using machofile's formatting methods
    #         magic_str = macho_instance.format_magic_value(header.get('magic', 0))
            
    #         # Simple CPU type mapping since CPU_TYPE_MAP is not exposed
    #         cputype = header.get('cputype', 0)
    #         if cputype == 0x7:
    #             cputype_str = "x86"
    #         elif cputype == 0x1000007:
    #             cputype_str = "x86_64"
    #         elif cputype == 0xC:
    #             cputype_str = "ARM"
    #         elif cputype == 0x100000C:
    #             cputype_str = "ARM 64-bit"
    #         else:
    #             cputype_str = str(cputype)
            
    #         cpusubtype_str = macho_instance.decode_cpusubtype(header.get('cputype', 0), header.get('cpusubtype', 0))
    #         filetype_str = macho_instance.format_file_type(header.get('filetype', 0))
    #         flags_str = macho_instance.decode_flags(header.get('flags', 0))
            
    #         return {
    #             'raw': {
    #                 'magic': header.get('magic', 0),
    #                 'cputype': header.get('cputype', 0),
    #                 'cpusubtype': header.get('cpusubtype', 0),
    #                 'filetype': header.get('filetype', 0),
    #                 'flags': header.get('flags', 0),
    #             },
    #             'formatted': {
    #                 'magic_str': magic_str,
    #                 'cputype_str': cputype_str,
    #                 'cpusubtype_str': cpusubtype_str,
    #                 'filetype_str': filetype_str,
    #                 'flags_str': flags_str,
    #             }
    #         }
    #     except Exception as e:
    #         self.log.error(f"Error formatting header values: {e}")
    #         return None