Xiaobo Zhou

85 papers A* 2B 6C 1Misc 1Journal 46Unranked 13
YearRankTypeTitle / Venue / Authors
2026 J jnl
BMC Bioinform.
Xiao Han, Xiaochen Cen, Zhijin Li, Xiaobo Zhou, Zhiwei Ji
2026 J jnl
J. Chem. Inf. Model.
Zhen Feng, Gen Li, Xiaoya Guan, Hui Yu, Xiaobo Zhou, Ke Li
2025 J jnl
Neurocomputing
Shilong Zhang, Xiaobo Zhou, Siyuan Chen
2025 J jnl
Inf. Fusion
Hui Yu, Qingyong Wang, Xiaobo Zhou
2025 J jnl
Discret. Math.
Xianhong Xie, Yaxin Zhao, Zhonghua Sun, Xiaobo Zhou
2025 J jnl
CAAI Trans. Intell. Technol.
Zihao Zhao, Yingchun Xia, Wenjun Xu, Hui Yu, Shuai Yang, Cheng Chen, Xiaohui Yuan, Xiaobo Zhou, Qingyong Wang, Lichuan Gu
2025 J jnl
Complex Intell. Syst.
Hui Yu, Qingyong Wang, Xiaobo Zhou, Lichuan Gu, Zihao Zhao
2025 J jnl
J. King Saud Univ. Comput. Inf. Sci.
Chenglong Zhou, Damin Zhang, Qing He, Mingfang Li, Mingrong Li, Xiaobo Zhou
2025 J jnl
Comput. Electron. Agric.
Weihao Pan, Yi Fang, Xiaobo Zhou, Shunpi Yan, Jun Jiao, Guodong Wu, Cheng Zhu
2025 J jnl
Future Gener. Comput. Syst.
Wenjun Xu, Yingchun Xia, Bifan Sun, Zihao Zhao, Lianggui Tang, Xiaobo Zhou, Qingyong Wang, Lichuan Gu
2025 J jnl
Complex Intell. Syst.
Zhen Feng, Hui Yu, Xiaoya Guan, Lichuan Gu, Ke Li, Xiaobo Zhou
2024 J jnl
Briefings Bioinform.
Qing Wang, Yuzhou Feng, Yanfei Wang, Bo Li, Jianguo Wen, Xiaobo Zhou, Qianqian Song
2024 J jnl
CoRR
Xianhong Xie, Yaxin Zhao, Zhonghua Sun, Xiaobo Zhou
2024 J jnl
Sensors
Weihao Pan, Hualong Li, Xiaobo Zhou, Jun Jiao, Cheng Zhu, Qiang Zhang
2024 J jnl
Sensors
Weihao Pan, Jun Jiao, Xiaobo Zhou, Zhengrong Xu, Lichuan Gu, Cheng Zhu
2023 J jnl
Briefings Bioinform.
Sayed-Rzgar Hosseini, Xiaobo Zhou
2023 J jnl
Neural Comput. Appl.
Binbin Pan, Wen-Sheng Chen, Liping Deng, Chen Xu, Xiaobo Zhou
2023 J jnl
Briefings Bioinform.
Pora Kim, Himansu Kumar, Chengyuan Yang, Ruihan Luo, Jiajia Liu, Xiaobo Zhou
2022 conf
WHICEB
Qing Zhu, Xiaobo Zhou, Shan Liu
2022 J jnl
J. Sensors
Wenyuan Liang, Xiaobo Zhou, Qing Lan
2021 J jnl
Pattern Recognit.
Wenping Ma, Xiaobo Zhou, Hao Zhu, Longwei Li, Licheng Jiao
2021 J jnl
CoRR
Shuang Ge, Qiongyu Ye, Wenquan Xie, Desheng Sun, Huabin Zhang, Xiaobo Zhou, Kehong Yuan
2021 J jnl
J. Intell. Fuzzy Syst.
Guo Yu, Weijian Li, Xiaobo Zhou
2021 J jnl
Comput. Biol. Medicine
Zhiwei Ji, Changan Liu, Weiling Zhao, Claudio Soto, Xiaobo Zhou
2021 J jnl
Biomed. Signal Process. Control.
Xiaobo Zhou, Renling Zou, Xiayang Huang
2020 conf
ATCI
Xiaobo Zhou
2020 J jnl
Comput. Math. Methods Medicine
Heng Zuo, Yunfei Ling, Peng Li, Qi An, Xiaobo Zhou
2020 J jnl
Complex.
Boya Liu, Xiaobo Zhou
2019 J jnl
IEEE Access
Yang Deng, Yao Sun, Yongpei Zhu, Yue Xu, Qianxi Yang, Shuo Zhang, Zhanyu Wang, Jirang Sun, Weiling Zhao, Xiaobo Zhou, Kehong Yuan
2019 J jnl
CoRR
Yang Deng, Yao Sun, Yongpei Zhu, Yue Xu, Qianxi Yang, Shuo Zhang, Mingwang Zhu, Jirang Sun, Weiling Zhao, Xiaobo Zhou, Kehong Yuan
2019 J jnl
IEEE Access
Wei Chen, Kun Wei, Weiling Zhao, Xiaobo Zhou
2019 conf
WOCC
Zihui Yan, Ning Wei, Qizhen Jin, Xiaobo Zhou
2019 J jnl
IEEE Access
Guangming Zhang, Min Pu, Yi Gu, Xiaobo Zhou
2018 J jnl
Int. J. Reconfigurable Comput.
Li Luo, Yakun Wu, Fei Qiao, Yi Yang, Qi Wei, Xiaobo Zhou, Yongkai Fan, Shuzheng Xu, Xinjun Liu, Huazhong Yang
2018 C conf
IPCCC
Beaulah A. Navamani, Chuan Yue, Xiaobo Zhou
2018 J jnl
Comput. Syst. Sci. Eng.
Xiulong Liu, Mianxiong Dong, Xiaobo Zhou
2018 conf
CCIS
Xiaobo Zhou, Bin Zhang
2017 B conf
CLOUD
Beaulah A. Navamani, Chuan Yue, Xiaobo Zhou
2017 ch.
Encyclopedia of GIS
Chandana Gangodagamage, Xiaobo Zhou, Henry Lin
2017 J jnl
J. Am. Medical Informatics Assoc.
Griffin M. Weber, William G. Adams, Elmer V. Bernstam, Jonathan P. Bickel, Kathe P. Fox, Keith Marsolo, Vijay A. Raghavan, Alexander Turchin, Xiaobo Zhou, Shawn N. Murphy, Kenneth D. Mandl
2017 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2017 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2017 J jnl
Future Gener. Comput. Syst.
Daniel S. Katz, Xiaobo Zhou
2017 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2017 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2017 J jnl
Comput. Syst. Sci. Eng.
Xiaobo Zhou, Kequi Li
2017 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2017 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2017 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2015 conf
IWSPA@CODASPY
Zhentan Feng, Shuguang Xiong, Deqiang Cao, XiaoLu Deng, Xin Wang, Yang Yang, Xiaobo Zhou, Yan Huang, Guangzhu Wu
2014 J jnl
J. Am. Medical Informatics Assoc.
Kenneth D. Mandl, Isaac S. Kohane, Douglas McFadden, Griffin M. Weber, Marc D. Natter, Joshua C. Mandel, Sebastian Schneeweiss, Sarah Weiler, Jeffrey G. Klann, Jonathan P. Bickel, William G. Adams, Yaorong Ge, Xiaobo Zhou, James Perkins, Keith Marsolo, Elmer V. Bernstam, John Showalter, Alexander Quarshie, Elizabeth O. Ofili, George Hripcsak, Shawn N. Murphy
2014 conf
ISER
Xiaobo Zhou, Seung-kook Jun, Venkat Krovi
2014 J jnl
IEEE J. Biomed. Health Informatics
Dongmin Guo, Anne L. van de Ven, Xiaobo Zhou
2014 A* conf
ICRA
Xiaobo Zhou, Seung-kook Jun, Venkat Krovi
2014 J jnl
Robotica
Xiaobo Zhou, Seung-kook Jun, Venkat Krovi
2013 Misc conf
ICASSP
Yao Qian, Frank K. Soong, Xiaobo Zhou, Yundi Qian, Xiaotian Zhang
2013 conf
CASE
Seung-kook Jun, Suren Kumar, Xiaobo Zhou, Daniel K. Ramsey, Venkat N. Krovi
2013 J jnl
BMC Bioinform.
Jiawen Bian, Chenglin Liu, Hongyan Wang, Jing Xing, Priyanka Kachroo, Xiaobo Zhou
2012 A* conf
ICRA
Xiaobo Zhou, Chin Pei Tang, Venkat Krovi
2012 conf
DUBMMSM
Sheng Wang, Xiaobo Zhou, Ziqi Wang, Ming Zhang
2012 J jnl
Secur. Commun. Networks
Taeshik Shon, Costas Lambrinoudakis, Xiaobo Zhou
2011 J jnl
J. Netw. Comput. Appl.
Sireesha Muppala, Xiaobo Zhou
2011 J jnl
Int. J. Comput. Sci. Eng.
Xiaobo Zhou, Ying Tan
2011 J jnl
Int. J. Intell. Mechatronics Robotics
Madusudanan Sathia Narayanan, Srikanth Kannan, Xiaobo Zhou, Frank Mendel, Venkat Krovi
2011 B ed.
ICCCN
Haohong Wang, Jin Li, George N. Rouskas, Xiaobo Zhou
2010 conf
CASoN
Xiaobo Zhou
2010 conf
ISER
Qiushi Fu, Xiaobo Zhou, Venkat Krovi
2009 B conf
ICCCN
Sireesha Muppala, Xiaobo Zhou
2009 J jnl
Pattern Recognit.
Tuan Pham, Xiaobo Zhou
2009 conf
FSKD (3)
Xiaobo Zhou, Chengduan Wang, Hong Lan
2008 ch.
Encyclopedia of GIS
Chandana Gangodagamage, Xiaobo Zhou, Henry Lin
2008 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2008 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2008 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2008 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2008 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2008 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2008 ch.
Encyclopedia of GIS
Xiaobo Zhou, Henry Lin
2008 J jnl
Int. J. Hybrid Intell. Syst.
Tuan Pham, Xiaobo Zhou
2007 B conf
GLOBECOM
Hancheng Lu, Xiaobo Zhou, Peilin Hong
2006 conf
ICON
Mengjuan Liu, Peilin Hong, Jinsheng Li, Xiaobo Zhou
2000 B conf
ICCCN
Xiaobo Zhou, Reinhard Lüling
2000 conf
IPDPS Workshops
Xiaobo Zhou, Reinhard Lüling, Li Xie
2000 B conf
ICPP
Xiaobo Zhou, Reinhard Lüling, Li Xie
1999 J jnl
J. Comput. Sci. Technol.
Sanglu Lu, Xiaobo Zhou, Li Xie
redb/extractors/capa.py
← Index redb/extractors/capa.py python
from dataclasses import asdict
import inspect
import json
import subprocess
import magic
from magika import Magika
from typing import Any, Dict, List, Tuple
from datetime import datetime, timezone

from redb.extractors.enum import Tag
from redb.models.dataclasses import CAPA
from redb.extractors.extractor import Extractor
from dotenv import load_dotenv
import os

load_dotenv(override=True)

class CAPAExtractor(Extractor):

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        elastic_index=None,
        known_benign=False,
        known_malicious=False,
    ):
        super().__init__(
            filepath, 
            log, 
            exporters,
            index_prefix, 
            elastic_index, 
            known_benign, 
            known_malicious
        )
        self.capa = None
        self.elastic_index = self.index_prefix + "-capa"

    def _replace_empty_keys(self, dictionary, replacement="default_empty_key"):
        """
        Replace empty keys in a dictionary with a specified replacement.

        Args:
        dictionary (dict): The input dictionary
        replacement (str): The replacement for empty keys (default: 'empty_key')

        Returns:
        dict: A new dictionary with empty keys replaced
        """
        # tmp_dict = {}
        # for k, v in dictionary.items():
        #     if k == '':
        #         tmp_dict[replacement] = dictionary[k]
        #     else:
        #         tmp_dict[k] = dictionary[k]
        # return tmp_dict
        return {(replacement if k == "" else k): v for k, v in dictionary.items()}

    def _extract_capa(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        TIMEOUT = int(os.getenv("CAPA_TIMEOUT")) # 5 minutes in seconds
        capa_command = [os.getenv("CAPA_PATH"), "-j", self.filepath] # COMMENT FOR TESTING ON MAC

        import signal

        # try:
        #     result = subprocess.run(
        #         capa_command, capture_output=True, text=True, check=True, timeout=TIMEOUT
        #     )
        # except subprocess.TimeoutExpired:
        #     self.log.error(f"The capa command timed out after {TIMEOUT} seconds")
        #     return {}
        # except subprocess.CalledProcessError as e:
        #     self.log.error(f"Error running capa: {e}")
        #     return {}

        # try:
        #     capa_output = json.loads(result.stdout)
        # except json.JSONDecodeError as e:
        #     self.log.error("Error parsing capa output: {e}")
        #     return {}

        # Create a process group for easier termination of all child processes
        try:
            # Start the process in a new process group
            process = subprocess.Popen(
                capa_command,
                stdout=subprocess.PIPE,
                stderr=subprocess.PIPE,
                text=True,
                preexec_fn=os.setsid  # Use os.setsid() to create a new process group
            )
            
            # Implement timeout handling manually
            try:
                stdout, stderr = process.communicate(timeout=TIMEOUT)
                # Process completed within timeout
                if process.returncode != 0:
                    self.log.error(f"Error running capa, return code: {process.returncode}, stderr: {stderr}")
                    return {}
            except subprocess.TimeoutExpired:
                # Kill the entire process group on timeout
                self.log.warning(f"The capa command timed out after {TIMEOUT} seconds, terminating process group")
                
                try:
                    # Send SIGTERM to the entire process group
                    os.killpg(process.pid, signal.SIGTERM)
                    
                    # Give it a moment to terminate gracefully
                    try:
                        process.wait(timeout=3)
                    except subprocess.TimeoutExpired:
                        # If it's still running after 3 seconds, send SIGKILL
                        self.log.warning("Process didn't terminate with SIGTERM, sending SIGKILL")
                        os.killpg(process.pid, signal.SIGKILL)
                        
                    process.wait()  # Make sure process resources are fully cleaned up
                except (ProcessLookupError, OSError) as e:
                    self.log.warning(f"Error while killing process: {e}")
                    
                return {}
                
            try:
                capa_output = json.loads(stdout)
            except json.JSONDecodeError as e:
                self.log.error(f"Error parsing capa output: {e}")
                return {}

            capa_dump = {}  # dictionalry of capabilities
            capabilities = set()  # list of capabilities
            namespaces = set()  # list of namespaces
            attack_dump = {}  # dictionary of tuples [tactic](technique, technique_id)
            tactics = set()  # list of tactics
            techniques = set()  # list of techniques
            techniques_id = set()  # list of techniques_id
            mbc_dump = {}  # dictionary of tuples [objective](behavior, behavior_id)
            mbc_objectives = set()  # list of objectives
            mbc_behaviors = set()  # list of behaviors
            mbc_behaviors_id = set()  # list of behaviors_id

            if isinstance(capa_output, dict) and "rules" in capa_output:
                rules = capa_output["rules"]
                if isinstance(rules, dict):
                    for rule_name, rule_data in rules.items():
                        if isinstance(rule_data, dict) and "meta" in rule_data:
                            meta = rule_data["meta"]
                            if isinstance(meta, dict):
                                # Process capabilities
                                namespace = meta.get("namespace", "").lower()
                                # if namespace != 'lib':
                                if namespace not in capa_dump:
                                    capa_dump[namespace] = []
                                    namespaces.add(namespace)
                                capa_dump[namespace].append(rule_name)
                                capabilities.add(rule_name)

                                # Process ATTACK information
                                if "attack" in meta:
                                    for attack_entry in meta["attack"]:
                                        tactic = attack_entry.get("tactic", "")
                                        technique = attack_entry.get("technique", "")
                                        id = attack_entry.get("id", "")
                                        if tactic and technique:
                                            if tactic in attack_dump:
                                                attack_dump[tactic].append((technique, id))
                                            else:
                                                attack_dump[tactic] = [(technique, id)]
                                            tactics.add(tactic)
                                            techniques.add(technique)
                                            techniques_id.add(id)

                                # Process MBC information
                                if "mbc" in meta:
                                    for mbc_entry in meta["mbc"]:
                                        objective = mbc_entry.get("objective", "")
                                        behavior = mbc_entry.get("behavior", "")
                                        id = mbc_entry.get("id", "")
                                        if objective and behavior:
                                            if objective in mbc_dump:
                                                mbc_dump[objective].append((behavior, id))
                                            else:
                                                mbc_dump[objective] = [(behavior, id)]
                                            mbc_objectives.add(objective)
                                            mbc_behaviors.add(behavior)
                                            mbc_behaviors_id.add(id)

            # return {
            #     'capabilities_all': json.dumps(capabilities_all, indent=2),
            #     'capabilities': list(capabilities),
            #     'namespaces': list(namespaces),
            #     'attack': json.dumps(attack, indent=2),
            #     'tactics': list(tactics),
            #     'techniques': list(techniques),
            #     'techniques_id': list(techniques_id),
            #     'mbc': json.dumps(mbc, indent=2),
            #     'mbc_objectives': list(mbc_objectives),
            #     'mbc_behaviors': list(mbc_behaviors),
            #     'mbc_behaviors_id': list(mbc_behaviors_id)
            # }

            capa_dump = self._replace_empty_keys(capa_dump)
            attack_dump = self._replace_empty_keys(attack_dump)
            mbc_dump = self._replace_empty_keys(mbc_dump)
            self.capa = CAPA(
                json.dumps(capa_dump, indent=2),
                list(capabilities),
                list(namespaces),
                json.dumps(attack_dump, indent=2),
                list(tactics),
                list(techniques),
                list(techniques_id),
                json.dumps(mbc_dump, indent=2),
                list(mbc_objectives),
                list(mbc_behaviors),
                list(mbc_behaviors_id),
            )
            self.log.debug(f"CAPA dump: {self.capa})")
            
        except Exception as e:
            self.log.error(f"Unexpected error in CAPA extraction: {str(e)}")
            # Try to clean up any process if possible
            if 'process' in locals() and process.poll() is None:
                try:
                    os.killpg(process.pid, signal.SIGKILL)
                    process.wait()
                except:
                    pass
            return {}

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ElasticsearchExporter":
            return self.capa
        elif exporter_type == "ClickHouseExporter":
            current_time = datetime.now(timezone.utc)
            
            # Prepare data for multiple tables
            tables_data = {
                'multi_table': True,  # Flag for multi-table export
                
                # Raw data table
                'raw': {
                    'table': 'redb_capa',
                    'data': [[
                        self.sha256,
                        self.md5,
                        self.sha1,
                        current_time,
                        self.capa.capa_dump,  # capa_dump
                        self.capa.attack_dump,            # attack_dump
                        self.capa.mbc_dump                # mbc_dump
                    ]],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'capa_dump', 'attack_dump', 'mbc_dump'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'JSON', 'JSON', 'JSON'
                    ]
                },
                
                # Capabilities table
                'capabilities': {
                    'table': 'redb_capa_capabilities',
                    'data': [
                        [self.sha256, self.md5, self.sha1, current_time, namespace, capability]
                        for namespace, capabilities in json.loads(self.capa.capa_dump).items()
                        for capability in capabilities
                    ],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'namespace', 'capability'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'LowCardinality(String)', 'LowCardinality(String)'
                    ]
                },
                
                # MITRE ATT&CK table
                'attack': {
                    'table': 'redb_capa_attack',
                    'data': [
                        [self.sha256, self.md5, self.sha1, current_time, 
                         tactic, technique[0], technique[1]]  # technique[0] is the name, technique[1] is the ID
                        for tactic, techniques in json.loads(self.capa.attack_dump).items()
                        for technique in techniques
                    ],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'tactic', 'technique', 'technique_id'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'LowCardinality(String)', 'LowCardinality(String)', 
                        'LowCardinality(String)'
                    ]
                },
                
                # MBC table
                'mbc': {
                    'table': 'redb_capa_mbc',
                    'data': [
                        [self.sha256, self.md5, self.sha1, current_time,
                         objective, behavior[0], behavior[1]]  # behavior[0] is the name, behavior[1] is the ID
                        for objective, behaviors in json.loads(self.capa.mbc_dump).items()
                        for behavior in behaviors
                    ],
                    'column_names': [
                        'sha256', 'md5', 'sha1', 'analysis_date',
                        'objective', 'behavior', 'behavior_id'
                    ],
                    'column_type_names': [
                        'FixedString(64)', 'FixedString(32)', 'FixedString(40)',
                        'DateTime64(3, \'UTC\')',
                        'LowCardinality(String)', 'LowCardinality(String)',
                        'LowCardinality(String)'
                    ]
                }
            }
            
            return tables_data

    def get_clickhouse_table(self) -> str:
        return "redb_capa"  # Return the main table name

    def extract(self):
        self.log.debug(inspect.currentframe().f_code.co_name)
        try:
            self._extract_capa()
            return self.capa  # Return the extracted data instead of exporting directly
        except Exception as e:
            self.log.error(f"Error extracting CAPA: {e}")
            return None

    def tag(self):
        return Tag.CAPA.value