Xiao Lei

32 papers A* 3A 1B 1C 2Journal 12Unranked 13
YearRankTypeTitle / Venue / Authors
2025 J jnl
ISPRS Int. J. Geo Inf.
Yuan Zeng, Dingli Liu, Diping Yuan, Weijun Liu, Guohua Wu, Xiao Lei
2024 J jnl
Sensors
Bang Wu, Weiguang Wu, Rui Ma, Haobing Chen, Yilin Zhao, Yunfan Li, Xiao Lei, Feng Liu
2023 C conf
PST
Gaoning Pan, Tianxiang Luo, Yiming Tao, Xiao Lei, Shuangxi Chen, Hui Liu, Chunming Wu
2023 C conf
IV
Haohao Hu, Hexing Yang, Jian Wu, Xiao Lei, Frank Bieder, Jan-Hendrik Pauls, Christoph Stiller
2022 J jnl
CoRR
Haohao Hu, Hexing Yang, Jian Wu, Xiao Lei, Frank Bieder, Jan-Hendrik Pauls, Christoph Stiller
2022 A* conf
EC
Mingliu Chen, Adam N. Elmachtoub, Xiao Lei
2022 J jnl
Manag. Sci.
Maxime C. Cohen, Adam N. Elmachtoub, Xiao Lei
2022 J jnl
Int. J. Pattern Recognit. Artif. Intell.
Jingjing Niu, Yulai Xie, Yang Zhang, Jinyu Zhang, Yanfei Zhang, Xiao Lei, Fang Ren
2021 J jnl
Manag. Sci.
Ningyuan Chen, Adam N. Elmachtoub, Michael L. Hamilton, Xiao Lei
2021 conf
FAccT
Maxime C. Cohen, Adam N. Elmachtoub, Xiao Lei
2021 J jnl
IEEE Access
Xiao Lei, Tao Cui, Xiaohui Wu, Hong Zeng, Qiang Liu, Linhuan Li
2021 conf
EITCE
Yao'an Luo, Zhengzhong Huang, Jun Pu, Hongfeng Deng, Yongqiang You, Xiao Lei
2020 A conf
EuroS&P
Philip Sperl, Ching-yu Kao, Peng Chen, Xiao Lei, Konstantin Böttinger
2020 A* conf
EC
Ningyuan Chen, Adam N. Elmachtoub, Michael L. Hamilton, Xiao Lei
2020 J jnl
Eur. J. Oper. Res.
Xuan Vinh Doan, Xiao Lei, Siqian Shen
2020 J jnl
Sensors
Xiao Lei, Xutao Fan, Hanwan Jiang, Kunning Zhu, Hanyu Zhan
2019 J jnl
Virtual Real. Intell. Hardw.
Xiao Lei, Tingwei Zhang, Kun Chen, Jue Zhang, Yue Tian, Fang Fang, Lihan Chen
2019 J jnl
J. Intell. Fuzzy Syst.
Huang Xiurong, Xiao Lei, Tou Xiaodong
2018 conf
ICNC-FSKD
Wei Liu, Jing Su, Xiao Lei, Zhen Xu
2018 J jnl
Comput. Oper. Res.
Xiao Lei, Siqian Shen, Yongjia Song
2015 conf
NAS
Feng Lu, Jiao Song, Xiao Lei, Hai Jin, Zaiyang Tang, Xiaofei Liao, Fei Qiu
2015 B conf
ICCCN
Xiao Lei, Zaiyang Tang, Peng Li, Hai Jin, Song Guo, Xiaofei Liao, Feng Lu
2014 conf
ASMS/SPSC
Xiao Lei, Laura Cottatellucci, Samah A. M. Ghanem
2013 conf
CloudCom (1)
Feng Lu, Hao Pan, Xiao Lei, Xiaofei Liao, Hai Jin
2012 conf
VTC Fall
Xiao Lei, Laura Cottatellucci
2011 A* conf
INFOCOM
Xiao Lei, Laura Cottatellucci, Konstantin Avrachenkov
2010 conf
WWIC
Xiao Lei, Konstantin Avrachenkov, Laura Cottatellucci, Andrey Garnaev
2010 conf
ICEE
Hu Song, Xiao Lei
2007 conf
ICNC (3)
Xiao Lei, C. C. Chan, Kaipei Liu, Li Ma
2006 conf
ICNC (1)
Li Ma, Kaipei Liu, Xiao Lei
2000 conf
ICC (3)
Xiao Lei, Qinglin Liang
2000 conf
ICC (2)
Xiao Lei, Qinglin Liang
redb/extractors/pe_extractors/pe_inconsistency_tests.py
← Index redb/extractors/pe_extractors/pe_inconsistency_tests.py python
import inspect
from redb.ext.spoof_check import (
    Result,
    checksum_test,
    duplicate_test,
    import_count_test,
    linker_test,
)
from redb.extractors.enum import Tag
from redb.extractors.pe_extractor import PEExtractor
from redb.models.dataclasses import (
    DotNetInconsistencyTests,
    PEInconsistencyTests,
)
from datetime import datetime, timezone
from typing import Any


class PEInconstistencyTestsExtractor(PEExtractor):
    """Collection of functions to perform features inconsistency tests

    A Test where the result is True means that there is an inconsistency.
    At the moments it runs a series of inconsistency tests on PE metadata from
    - spoof_check
    - pescanner
    - dotnetfile
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
        pe=None,
        dotnet=None,
    ):
        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            elastic_index,
            known_benign,
            known_malicious,
            pe,
        )
        self.dotnet = dotnet if dotnet else None
        self.pe_inconsistency_tests = None
        self.dotnet_inconsistency_tests = None
        self.elastic_index = self.index_prefix + "-pe_inconsistency_tests"

    def tag(self):
        return [Tag.PE_INCONSISTENCY_TESTS.value, Tag.DOTNET_INCONSISTENCY_TESTS.value]

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        tests_performed = False

        # Handle PE rich header tests
        try:
            rich_header = self.pe.parse_rich_header()
            if rich_header:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=checksum_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_duplicate=duplicate_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_linker=linker_test(self.pe, rich_header) == Result.INVALID,
                    test_rich_header_import_count=import_count_test(self.pe, rich_header) == Result.INVALID,
                )
                tests_performed = True
            else:
                self.pe_inconsistency_tests = PEInconsistencyTests(
                    test_rich_header_checksum=None,
                    test_rich_header_duplicate=None,
                    test_rich_header_linker=None,
                    test_rich_header_import_count=None,
                )
        except Exception as e:
            self.log.error(f"Error processing rich header tests for {self.hash.sha256}: {e}")
            self.pe_inconsistency_tests = None

            # self.export_to_elastic([self.pe_inconsistency_tests])

        # Handle .NET tests
        try:
            if self._check_dotnet():
                if not self.dotnet:
                    self.dotnet, self.error = self._generate_dotnetfile_object()
                if self.error:
                    self.log.error(f"Error generating .NET object {self.hash.sha256}: {self.error}")
                self.dotnet_inconsistency_tests = DotNetInconsistencyTests(
                    test_dotnet_data_dir_hidden=self.dotnet.AntiMetadataAnalysis.is_dotnet_data_directory_hidden,
                    test_dotnet_extra_data=self.dotnet.AntiMetadataAnalysis.has_metadata_table_extra_data,
                    test_dotnet_fake_types=self.dotnet.AntiMetadataAnalysis.has_self_referenced_typeref_entries,
                    test_dotnet_invalid_type_ref=self.dotnet.AntiMetadataAnalysis.has_invalid_typeref_entries,
                    test_dotnet_fake_datastreams=self.dotnet.AntiMetadataAnalysis.has_fake_data_streams,
                    test_dotnet_extra_module_table=self.dotnet.AntiMetadataAnalysis.module_table_has_multiple_rows,
                    test_dotnet_extra_assembly_table=self.dotnet.AntiMetadataAnalysis.assembly_table_has_multiple_rows,
                    test_dotnet_invalid_strings_stream=self.dotnet.AntiMetadataAnalysis.has_invalid_strings_stream_entries,
                    test_dotnet_streams_mixed_case=self.dotnet.AntiMetadataAnalysis.has_mixed_case_stream_names,
                    test_dotnet_method_def_invalid_table=self.dotnet.AntiMetadataAnalysis.has_invalid_methoddef_entries,
                    test_dotnet_max_len_exceeding_strings=self.dotnet.AntiMetadataAnalysis.has_max_len_exceeding_strings,
                )
                tests_performed = True
        except Exception as e:
            self.log.error(f"Error processing .NET tests for {self.hash.sha256}: {e}")
            self.dotnet_inconsistency_tests = None

        # self.export_to_elastic([self.dotnet_inconsistency_tests])

        # If no tests were performed, return False to skip database insertion
        if not tests_performed:
            self.log.info("No inconsistency tests were performed.")
            return False

        return True

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return [self.pe_inconsistency_tests, self.dotnet_inconsistency_tests]
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)

            # For PE tests: if no rich header (all True), store NULL instead
            has_rich_header = any([
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_checksum'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_duplicate'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_linker'),
                hasattr(self.pe_inconsistency_tests, 'test_rich_header_import_count')
            ])
            
            pe_tests = [
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_checksum,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_duplicate,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_linker,
                None if not has_rich_header else self.pe_inconsistency_tests.test_rich_header_import_count,
            ]
            
            # For .NET tests: if not a .NET file, store NULL instead of False
            dotnet_tests = [
                self.dotnet_inconsistency_tests.test_dotnet_data_dir_hidden if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_data if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_types if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_type_ref if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_fake_datastreams if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_module_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_extra_assembly_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_invalid_strings_stream if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_streams_mixed_case if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_method_def_invalid_table if self.dotnet_inconsistency_tests else None,
                self.dotnet_inconsistency_tests.test_dotnet_max_len_exceeding_strings if self.dotnet_inconsistency_tests else None,
            ]
            
            data = [[
                self.sha256,
                self.md5,
                self.sha1,
                *pe_tests,
                *dotnet_tests,
                current_time
            ]]

            column_names = [
                'sha256', 'md5', 'sha1',
                'test_rich_header_checksum', 'test_rich_header_duplicate', 'test_rich_header_linker', 'test_rich_header_import_count',
                'test_dotnet_data_dir_hidden', 'test_dotnet_extra_data',
                'test_dotnet_fake_types', 'test_dotnet_invalid_type_ref',
                'test_dotnet_fake_datastreams', 'test_dotnet_extra_module_table',
                'test_dotnet_extra_assembly_table', 'test_dotnet_invalid_strings_stream',
                'test_dotnet_streams_mixed_case', 'test_dotnet_method_def_invalid_table',
                'test_dotnet_max_len_exceeding_strings', 'analysis_date'
            ]
            
            column_type_names = [
                'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'Nullable(Boolean)', 'Nullable(Boolean)', 'Nullable(Boolean)',
                'DateTime64(3, \'UTC\')'
            ]

            if not data:
                return None

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_pe_inconsistency_tests"