Xiangde Zhang

47 papers Journal 37Unranked 10
YearRankTypeTitle / Venue / Authors
2025 J jnl
Image Vis. Comput.
Qi Wang, Sheng Shi, Jiahui Li, Wuming Jiang, Xiangde Zhang
2023 J jnl
Neural Process. Lett.
Hegui Zhu, Ziwei Zhang, Luyang Wang, Tian Geng, Xiangde Zhang
2022 J jnl
Vis. Comput.
Qi Wang, Xiangyue Meng, Ting Sun, Xiangde Zhang
2022 J jnl
Multim. Tools Appl.
Qingsong Tang, Xiaoxu Feng, Xiangde Zhang
2022 J jnl
J. Electronic Imaging
Lianping Yang, Hao Sun, Jian Zhang, Sijia Mo, Wuming Jiang, Xiangde Zhang
2022 J jnl
Math. Comput. Simul.
Hegui Zhu, Jiangxia Ge, Wentao Qi, Xiangde Zhang, Xiaoxiong Lu
2022 J jnl
J. Glob. Optim.
Qingsong Tang, Xiangde Zhang, Cheng Zhao, Peng Zhao
2022 J jnl
Neural Comput. Appl.
Qi Wang, Yuanshuai Wang, Yuan Zhou, Jing Wang, Wuming Jiang, Xiangde Zhang
2022 J jnl
CoRR
Qi Wang, Sheng Shi, Jiahui Li, Wuming Jiang, Xiangde Zhang
2021 J jnl
Appl. Intell.
Lianping Yang, Hongliang Zhang, Panpan Wei, Yubo Sun, Xiangde Zhang
2021 J jnl
Neural Process. Lett.
Hegui Zhu, Ru Wang, Xiangde Zhang
2021 J jnl
J. Real Time Image Process.
Lianping Yang, Yu Qin, Xiangde Zhang
2021 J jnl
Neurocomputing
Hegui Zhu, Huimin Zeng, Jinhai Liu, Xiangde Zhang
2021 J jnl
Entropy
Xiangde Zhang, Yuan Zhou, Jianping Wang, Xiaojun Lu
2021 J jnl
Entropy
Xiangde Zhang, Jian Zhang
2021 J jnl
Neural Comput. Appl.
Hegui Zhu, Min Zhang, Xiangde Zhang, Libo Zhang
2020 J jnl
Neural Process. Lett.
Hegui Zhu, Yan Miao, Xiangde Zhang
2020 J jnl
Appl. Intell.
Hegui Zhu, Baoyu Wang, Xiangde Zhang, Jinhai Liu
2020 conf
ECCV (12)
Ben Niu, Weilei Wen, Wenqi Ren, Xiangde Zhang, Lianping Yang, Shuzhen Wang, Kaihao Zhang, Xiaochun Cao, Haifeng Shen
2020 J jnl
CoRR
Ben Niu, Weilei Wen, Wenqi Ren, Xiangde Zhang, Lianping Yang, Shuzhen Wang, Kaihao Zhang, Xiaochun Cao, Haifeng Shen
2019 conf
CCBR
Xiangde Zhang, Bin Zheng, Yuanjie Li, Lianping Yang
2019 conf
CCBR
Xiangde Zhang, Runan Zhou, Xiangyue Meng, Qi Wang
2018 J jnl
J. Comb. Optim.
Qingsong Tang, Xiangde Zhang, Guoren Wang, Cheng Zhao
2018 J jnl
Entropy
Xiaojun Lu, Jiaojuan Wang, Xiang Li, Mei Yang, Xiangde Zhang
2018 conf
CSAE
Yang Guo, Xiang Li, Jiaojuan Wang, Xiangde Zhang
2018 conf
CCBR
Qi Wang, Ying Lian, Ting Sun, Yuna Chu, Xiangde Zhang
2018 J jnl
CoRR
Lianping Yang, Bin Shao, Ting Sun, Song Ding, Xiangde Zhang
2017 J jnl
Int. J. Distributed Sens. Networks
Qi Wang, Rui Sun, Xiangde Zhang, Yanrui Sun, Xiaojun Lu
2017 conf
CCBR
Lianping Yang, YuanYuan Li, Xu Duan, Xiangde Zhang
2017 conf
CCBR
Qi Wang, Xia Su, Zhenlin Cai, Xiangde Zhang
2017 J jnl
J. Comb. Optim.
Qingsong Tang, Yuejian Peng, Xiangde Zhang, Cheng Zhao
2016 J jnl
Entropy
Hegui Zhu, Xiangde Zhang, Hai Yu, Cheng Zhao, Zhiliang Zhu
2016 J jnl
Optim. Lett.
Qingsong Tang, Yuejian Peng, Xiangde Zhang, Cheng Zhao
2016 J jnl
Mob. Inf. Syst.
Qi Wang, Yingying Feng, Xiangde Zhang, Yan-Rui Su, Xiaojun Lu
2015 conf
CCBR
Qingsong Tang, Qinqin Zhang, Xiaomeng Zhang, Zhenlin Cai, Xiangde Zhang
2015 J jnl
Ars Comb.
Xiaojun Lu, Xiangde Zhang
2015 conf
CCBR
Hegui Zhu, Yang Wang, Xiuping Mao, Xiangde Zhang
2015 conf
CCBR
Xiaojun Lu, Lingmei Kong, Mengzhu Liu, Xiangde Zhang
2015 J jnl
J. Electronic Imaging
Qi Wang, Tie Zhang, Zhenlin Cai, Nan Jiang, Jiamei Wu, Xiangde Zhang
2014 J jnl
J. Optim. Theory Appl.
Qingsong Tang, Yuejian Peng, Xiangde Zhang, Cheng Zhao
2014 J jnl
Discret. Appl. Math.
Qingsong Tang, Yuejian Peng, Xiangde Zhang, Cheng Zhao
2013 J jnl
Signal Process. Image Commun.
Hegui Zhu, Cheng Zhao, Xiangde Zhang
2013 J jnl
Comput. Secur.
Hegui Zhu, Cheng Zhao, Xiangde Zhang, Lianping Yang
2013 J jnl
J. Comput. Biol.
Lianping Yang, Xiangde Zhang, Tianming Wang, Hegui Zhu
2012 J jnl
Pattern Recognit. Lett.
Qi Wang, Xiangde Zhang, Mingqi Li, Xiaopeng Dong, Qunhua Zhou, Yu Yin
2012 J jnl
J. Softw.
Xiangde Zhang, Qingsong Tang, Hua Jin, Yue Qiu, Yang Guo
1999 J jnl
J. Comput. Sci. Technol.
Fanjia Kong, Guangxing Wang, Xiangde Zhang
CLAUDE.md
← Index CLAUDE.md markdown
# CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

## Project Overview

REDB (RationalEdge Samples DB) is a malware analysis framework that extracts features from PE (Portable Executable) files and stores them in ClickHouse database for analysis. It provides a comprehensive set of extractors for analyzing binary samples including PE headers, imports, resources, signatures, and decompiled code.

## Common Commands

### Development Setup
```bash
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

# Run the main application
python start.py --path /path/to/samples --repo sample_repo --index_prefix redb
```

### Analysis Commands
```bash
# Process a single file
python start.py --path /path/to/binary --repo test --index_prefix redb

# Process from S3 storage
python start.py --s3 --repo malpedia --index_prefix redb

# Process from S3 storage but only a subset of a specific repository
python start.py --s3 --repo "vx-itw" --s3-notes "ITW.0138" --index_prefix redb

# Run only decompilation
python start.py --path /path/to/binary --repo test --index_prefix redb --decompile

# Run specific modules
python start.py --path /path/to/binary --repo test --index_prefix redb --modules "BasicPropertiesExtractor,PEFeaturesExtractor"

# Run as Nomad job (for containerized deployment)
python start.py --nomad-job
```

### Testing
There are no formal unit tests. Testing is done by running the extractors on sample files in the `test_files/` directory.

## Architecture Overview

### Core Components

1. **Ingestor (`redb/ingestor.py`)**: Main orchestrator that handles file processing, multiprocessing, and coordinates extractors
2. **Extractors (`redb/extractors/`)**: Modular analysis components that extract specific features
3. **Database Exporters (`redb/extractors/database_exporters.py`)**: Handle data export to ClickHouse
4. **Settings (`redb/settings/`)**: Configuration management for database connections

### Extractor Architecture

All extractors inherit from the base `Extractor` class and implement:
- `extract()`: Main analysis logic
- `prepare_export_data()`: Format data for database export
- `get_clickhouse_table()`: Return target table name

Available extractors:
- **General**: BasicPropertiesExtractor, HashExtractor, DIEExtractor, CAPAExtractor
- **PE-specific**: PEFeaturesExtractor, PEImportExtractor, PEResourceExtractor, PEOverlayExtractor, PESectionExtractor, PESignatureExtractor, PEDotNetExtractor, PEInconstistencyTestsExtractor, PEExtraFindings
- **ELF**: ELFFeaturesExtractor, ELFSegmentExtractor, ELFSectionExtractor, ELFDependencyExtractor, ELFSymbolExtractor, ELFImportExtractor, ELFExportExtractor, ELFRelocationExtractor, ELFNotesExtractor
- **Mach-O**: MachOFeaturesExtractor, MachOSegmentExtractor, MachOImportExtractor, MachOExportExtractor, MachODylibExtractor, MachOSignatureExtractor
- **APK**: APKFeaturesExtractor, APKManifestExtractor, APKPermissionsExtractor, APKSignatureExtractor, APKDexExtractor, APKResourceExtractor, APKNativeLibExtractor, APKInconsistencyTestsExtractor
- **Decompilation**: DecompileBinja, DecompileAPK

### Database Schema

The project uses a comprehensive ClickHouse schema defined in `redb/redb_schema.yml` with tables for:
- Basic properties (`redb_basic_properties`)
- PE features (`redb_pe_features`, `redb_pe_imports`, `redb_pe_sections`, etc.)
- Decompiled code (`code_binja_decompiled_functions_content`, `code_binja_decompiled_functions_references`)
- CAPA analysis (`redb_capa`, `redb_capa_capabilities`)

Full schema documentation is available in `docs/database_schema.md`.

### Processing Modes

1. **Analysis Mode**: Extracts features using selected modules
2. **Decompile Mode**: Uses Binary Ninja for code decompilation
3. **S3 Mode**: Fetches samples from S3 storage based on catalog queries
4. **Nomad Job Mode**: Processes single jobs using environment variables for containerized deployment

### Configuration

Environment variables are used for configuration:
- Database connection: `CLICKHOUSE_HOST`, `CLICKHOUSE_PORT`, `CLICKHOUSE_USER`, `CLICKHOUSE_PASSWORD`
- S3 storage: `S3_ENDPOINT`, `S3_ACCESS_KEY`, `S3_SECRET_KEY`
- Processing: `BATCH_SIZE`, `REDB_TIMEOUT`, `DECOMPILE_WORKER_TIMEOUT`
- Nomad jobs: `JOB_ID`, `S3_KEY`, `S3_BUCKET`, `WORKER_TYPE`, `CALLBACK_URL`, `ANALYSIS_MODULES`

## Important Implementation Details

### Multiprocessing
- Uses `spawn` method for multiprocessing to avoid memory issues
- Worker processes have timeout handlers to prevent hanging
- Supports both batch processing and streaming processing modes

### Memory Management
- Implements aggressive garbage collection between batches
- Monitors swap usage and restarts worker pools when needed
- Kills stuck processes automatically

### Error Handling
- Comprehensive logging with per-file context
- Graceful handling of corrupted or unsupported files
- Automatic retry logic for database operations

### Security Context
This is a defensive security tool for malware analysis. It processes potentially malicious files in a controlled environment to extract features for detection and analysis purposes.

## Development Notes

- The codebase is optimized for processing large batches of malware samples
- Extractors are designed to be modular and can be run individually or in combination
- Database schema supports both normalized and denormalized views for different query patterns
- S3 integration allows for scalable processing of large malware repositories