Xiao Han

59 papers A* 7B 6C 1Journal 38Unranked 6
YearRankTypeTitle / Venue / Authors
2026 J jnl
MIS Q.
Xiao Han, Leye Wang, Junjie Wu, Xiao Fang
2026 J jnl
IEEE Trans. Dependable Secur. Comput.
Qingwen Li, Xiao Han, Ruiyan Wang, Junjie Wu, Lanjuan Liu
2025 J jnl
IEEE Trans. Inf. Forensics Secur.
Yucheng Wu, Yuncong Yang, Xiao Han, Leye Wang, Junjie Wu
2025 J jnl
CoRR
Yucheng Wu, Yuncong Yang, Xiao Han, Leye Wang, Junjie Wu
2025 J jnl
CoRR
Chung-ju Huang, Yuanpeng He, Xiao Han, Wenpin Jiao, Zhi Jin, Leye Wang
2025 J jnl
IEEE Trans. Mob. Comput.
Chung-ju Huang, Yuanpeng He, Xiao Han, Wenpin Jiao, Zhi Jin, Leye Wang
2024 A* conf
WWW
Yucheng Wu, Leye Wang, Xiao Han, Han-Jia Ye
2024 J jnl
CoRR
Yucheng Wu, Leye Wang, Xiao Han, Han-Jia Ye
2024 J jnl
IEEE Trans. Knowl. Data Eng.
Xiao Han, Yuncong Yang, Junjie Wu, Hui Xiong
2024 J jnl
IEEE Trans. Dependable Secur. Comput.
Xiao Han, Yuncong Yang, Leye Wang, Junjie Wu
2024 J jnl
IEEE Trans. Software Eng.
Jie Zhu, Leye Wang, Xiao Han, Anmin Liu, Tao Xie
2024 J jnl
CoRR
Jie Zhu, Leye Wang, Xiao Han, Anmin Liu, Tao Xie
2023 conf
ACL (Findings)
Ruiqing Ding, Xiao Han, Leye Wang
2023 J jnl
INFORMS J. Comput.
Xiao Han, Leye Wang, Weiguo Fan
2023 A* conf
WWW
Ruiqing Ding, Fangjie Rong, Xiao Han, Leye Wang
2023 J jnl
CoRR
Ruiqing Ding, Fangjie Rong, Xiao Han, Leye Wang
2023 J jnl
IEEE Data Eng. Bull.
Leye Wang, Guanghong Fan, Xiao Han
2023 A* conf
WWW
Chung-ju Huang, Leye Wang, Xiao Han
2023 J jnl
CoRR
Chung-ju Huang, Leye Wang, Xiao Han
2023 J jnl
Neural Networks
Qingwen Li, Jianni Chen, Qiqin Xie, Xiao Han
2022 J jnl
CoRR
Ruiqing Ding, Xiao Han, Leye Wang
2022 J jnl
CoRR
Xiao Han, Leye Wang, Junjie Wu, Yuncong Yang
2022 A* conf
ASE
Jie Zhu, Leye Wang, Xiao Han
2022 J jnl
CoRR
Jie Zhu, Leye Wang, Xiao Han
2021 J jnl
CoRR
Xiao Han, Leye Wang, Junjie Wu
2021 J jnl
CoRR
Xiao Han, Yuncong Yang, Junjie Wu
2021 J jnl
MIS Q.
Xiao Han, Leye Wang, Weiguo Fan
2021 A* conf
AAAI
Biyang Guo, Songqiao Han, Xiao Han, Hailiang Huang, Ting Lu
2021 J jnl
IEEE Trans. Dependable Secur. Comput.
Leye Wang, Dingqi Yang, Xiao Han, Daqing Zhang, Xiaojuan Ma
2020 J jnl
CoRR
Leye Wang, Han Yu, Xiao Han
2020 J jnl
CoRR
Biyang Guo, Songqiao Han, Xiao Han, Hailiang Huang, Ting Lu
2020 J jnl
IEEE Trans. Inf. Forensics Secur.
Leye Wang, Daqing Zhang, Dingqi Yang, Brian Y. Lim, Xiao Han, Xiaojuan Ma
2019 J jnl
CoRR
Xiao Han, Ruiqing Ding, Leye Wang, Hailiang Huang
2019 J jnl
IEEE Trans. Dependable Secur. Comput.
Xiao Han, Hailiang Huang, Leye Wang
2018 A* conf
AAAI
Leye Wang, Gehua Qin, Dingqi Yang, Xiao Han, Xiaojuan Ma
2018 J jnl
ACM Trans. Intell. Syst. Technol.
Leye Wang, Daqing Zhang, Dingqi Yang, Animesh Pathak, Chao Chen, Xiao Han, Haoyi Xiong, Yasha Wang
2017 J jnl
CoRR
Reza Farahbakhsh, Xiao Han, Ángel Cuevas, Noël Crespi
2017 C conf
ICIS
Xiao Han, Leye Wang, Hailiang Huang
2017 conf
TrustCom/BigDataSE/ICESS
Reza Farahbakhsh, Samin Mohammadi, Xiao Han, Ángel Cuevas, Noël Crespi
2017 J jnl
CoRR
Leye Wang, Gehua Qin, Dingqi Yang, Xiao Han, Xiaojuan Ma
2017 J jnl
CoRR
Reza Farahbakhsh, Ángel Cuevas, Antonio Manuel Ortiz, Xiao Han, Noël Crespi
2017 A* conf
WWW
Leye Wang, Dingqi Yang, Xiao Han, Tianben Wang, Daqing Zhang, Xiaojuan Ma
2016 conf
UIC/ATC/ScalCom/CBDCom/IoP/SmartWorld
Leye Wang, Xiao Han, Longbiao Chen
2016 conf
PACIS
Xiao Han, Leye Wang
2016 J jnl
Expert Syst. Appl.
Xiao Han, Leye Wang, Reza Farahbakhsh, Ángel Cuevas, Rubén Cuevas, Noël Crespi, Lina He
2016 J jnl
IEEE Commun. Mag.
Leye Wang, Daqing Zhang, Yasha Wang, Chao Chen, Xiao Han, Abdallah M'hamed
2015 J jnl
Decis. Support Syst.
Xiao Han, Leye Wang, Noël Crespi, Soochang Park, Ángel Cuevas
2015 J jnl
CoRR
Xiao Han, Leye Wang, Jiangtao Wen, Ángel Cuevas, Chao Chen, Noël Crespi
2015 J jnl
IEEE Commun. Mag.
Reza Farahbakhsh, Ángel Cuevas, Antonio Manuel Ortiz, Xiao Han, Noël Crespi
2015 conf
ICC
Xiao Han, Leye Wang, Son N. Han, Chao Chen, Noël Crespi, Reza Farahbakhsh
2015
Xiao Han
2014 B conf
ASONAM
Xiao Han, Leye Wang, Soochang Park, Ángel Cuevas, Noël Crespi
2014 J jnl
Future Gener. Comput. Syst.
Xiao Han, Ángel Cuevas, Noël Crespi, Rubén Cuevas, Xiaodi Huang
2014 conf
UIC/ATC/ScalCom
Chao Chen, Daqing Zhang, Leye Wang, Xiaojuan Ma, Xiao Han, Edwin Hsing-Mean Sha
2013 B conf
GLOBECOM
Wipada Chanthaweethip, Xiao Han, Noël Crespi, Yuanfang Chen, Reza Farahbakhsh, Ángel Cuevas
2013 B conf
DCOSS
Dina Hussein, Son N. Han, Xiao Han, Gyu Myoung Lee, Noël Crespi
2013 B conf
ASONAM
Reza Farahbakhsh, Xiao Han, Ángel Cuevas, Noël Crespi
2013 B conf
MASS
Yuanfang Chen, Lei Shu, Xiao Han, Lin Lv, Xuemin Cheng
2013 B conf
MASS
Xiao Han, Lei Shu, Yuanfang Chen, Hairui Zhou
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"