Xiaohong Ma

61 papers A* 3B 5C 2Misc 1Journal 20Unranked 30
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Huiyu Li, Xiabi Liu, Said Boumaraf, Xiaopeng Gong, Donghai Liao, Xiaohong Ma
2024 A* conf
AAAI
Jinglue Hang, Xiangbo Lin, Tianqiang Zhu, Xuanheng Li, Rina Wu, Xiaohong Ma, Yi Sun
2024 conf
ISBI
Zijun Zhang, Xuanheng Li, Xiaohong Ma, Yi Sun
2023 Misc conf
ICASSP
Xiaohan Zhang, Dong Wang, Xiaohong Ma
2023 conf
ICDIP
Jiaxin Wang, Jianqiao Yu, Xiaohong Ma, Yi Sun, Jia Liu
2023 J jnl
Entertain. Comput.
Baogui Xin, Xiaohong Ma
2023 J jnl
Remote. Sens.
Yingqing Su, Qi Feng, Wei Liu, Meng Zhu, Honghua Xia, Xiaohong Ma, Wenju Cheng, Jutao Zhang, Chengqi Zhang, Linshan Yang, Xinwei Yin
2022 J jnl
Pattern Anal. Appl.
Xinru Guo, Song Xu, Xiangbo Lin, Yi Sun, Xiaohong Ma
2022 J jnl
Signal Image Video Process.
Xiangbo Lin, Yibo Li, Yidan Zhou, Yi Sun, Xiaohong Ma
2021 J jnl
Biomed. Signal Process. Control.
Said Boumaraf, Xiabi Liu, Zhongshu Zheng, Xiaohong Ma, Chokri Ferkous
2021 J jnl
Brain Connect.
Mohammad S. Eslampanah Sendi, Elaheh Zendehrouh, Jing Sui, Zening Fu, Dongmei Zhi, Luxian Lv, Xiaohong Ma, Qing Ke, Xianbin Li, Chuanyue Wang, Christopher C. Abbott, Jessica A. Turner, Robyn L. Miller, Vince D. Calhoun
2021 conf
EMBC
Dongmei Zhi, Vince D. Calhoun, Chuanyue Wang, Xianbin Li, Xiaohong Ma, Luxian Lv, Weizheng Yan, Dongren Yao, Shile Qi, Rongtao Jiang, Jianlong Zhao, Xiao Yang, Zheng Lin, Yujin Zhang, Young Chul Chung, Chuanjun Zhuo, Jing Sui
2021 J jnl
IEEE Access
Huan Huang, Tingting Wang, Qianyong Lv, Xiaohong Ma, Fuzeng Zhang, Huarong Zeng, Jianrong Wu
2021 J jnl
CoRR
Songxiao Yang, Xiabi Liu, Zhongshu Zheng, Wei Wang, Xiaohong Ma
2021 J jnl
Signal Process. Image Commun.
Jian Yang, Xiaohong Ma, Yi Sun, Xiangbo Lin
2021 J jnl
Signal Process. Image Commun.
Xiangbo Lin, Yidan Zhou, Kuo Du, Yi Sun, Xiaohong Ma, Jian Lu
2021 A* conf
ICCV
Zheng Chen, Sihan Wang, Yi Sun, Xiaohong Ma
2021 conf
ICSS
Xinjie Zhou, Guyue Gao, Xinguo Ming, Liya Wang, Dao Yin, Xiaohong Ma
2021 B conf
Image Processing
Zhongshu Zheng, Ling Ma, Songxiao Yang, Said Boumaraf, Xiabi Liu, Xiaohong Ma
2020 J jnl
CoRR
Said Boumaraf, Xiabi Liu, Chokri Ferkous, Xiaohong Ma
2020 B conf
IJCNN
Huiyu Li, Xiabi Liu, Said Boumaraf, Weihua Liu, Xiaopeng Gong, Xiaohong Ma
2020 J jnl
Signal Process. Image Commun.
Xuefeng Li, Yidan Zhou, Yi Sun, Xiangbo Lin, Xiaohong Ma
2020 conf
EMBC
Elaheh Zendehrouh, Mohammad S. Eslampanah Sendi, Jing Sui, Zening Fu, Dongmei Zhi, Luxian Lv, Xiaohong Ma, Qing Ke, Xianbin Li, Chuanyue Wang, Christopher C. Abbott, Jessica A. Turner, Robyn L. Miller, Vince D. Calhoun
2020 conf
MLMI@MICCAI
Huiyu Li, Xiabi Liu, Said Boumaraf, Xiaopeng Gong, Donghai Liao, Xiaohong Ma
2020 J jnl
IEEE Access
Xianglei Yin, Guixi Liu, Xiaohong Ma
2020 J jnl
Signal Process. Image Commun.
Zheng Chen, Kuo Du, Yi Sun, Xiangbo Lin, Xiaohong Ma
2020 J jnl
IEEE Access
Zhijin Zhang, Yang Shenghuan, Jiang Xingliang, Xiaohong Ma, Huang Huan, Pang Guohui, Ji Yaqing, Kai Dong
2020 J jnl
IEEE Access
Xiaohong Ma, Shaowu Li
2020 J jnl
IEEE Access
Shaowu Li, Qin Li, Wenhai Qi, Kunyi Chen, Qing Ai, Xiaohong Ma
2019 J jnl
CoRR
Huiyu Li, Xiabi Liu, Said Boumaraf, Weihua Liu, Xiaopeng Gong, Xiaohong Ma
2019 A* conf
CVPR
Kuo Du, Xiangbo Lin, Yi Sun, Xiaohong Ma
2019 conf
ISNN (1)
Xu Jiang, Xiaohong Ma
2019 conf
ICCV Workshops
Tianqiang Zhu, Yi Sun, Xiaohong Ma, Xiangbo Lin
2018 conf
EMBC
Dongmei Zhi, Xiaohong Ma, Luxian Lv, Qing Ke, Yongfeng Yang, Xiao Yang, Miao Pan, Shile Qi, Rongtao Jiang, Yuhui Du, Qingbao Yu, Vince D. Calhoun, Tianzi Jiang, Jing Sui
2018 conf
ECCV (14)
Yidan Zhou, Jian Lu, Kuo Du, Xiangbo Lin, Yi Sun, Xiaohong Ma
2017 conf
ISNN (2)
Peng Zhang, Xiaohong Ma, Shuxue Ding
2017 J jnl
Comput. Vis. Media
Yuxin Ma, Wei Chen, Xiaohong Ma, Jiayi Xu, Xinxin Huang, Ross Maciejewski, Anthony K. H. Tung
2017 conf
ISNN (2)
Zhuangguo Miao, Xiaohong Ma, Shuxue Ding
2017 conf
ISNN (1)
Linlin Chen, Xiaohong Ma, Shuxue Ding
2016 conf
ICACI
Zheng Zhao, Xiaohong Ma
2016 conf
DSP
Shuangshuang Fang, Xiaohong Ma, Zhongyin Cao
2016 B conf
ICIP
Zheng Zhao, Xiaohong Ma
2015 C conf
ISNN
Yong Zhang, Xiaohong Ma
2015 conf
iCAST
Jifei Song, Xiaohong Ma
2015 C conf
ISNN
Xiaohong Ma, Xizheng Yu
2015 conf
IScIDE (2)
Jingfeng Shao, Jinfu Wang, Xiaobo Bai, Yong Liu, Congying Liu, Xiaohong Ma
2015 conf
iCAST
Xiaohong Ma, Shuxue Ding, Jifei Song, Dongyan Zhu
2013 conf
iCAST/UMEDIA
Linlin Chen, Xiaohong Ma, Jifei Song, Shuxue Ding
2011 conf
iCAST
Qian Shi, Xiaohong Ma
2011 conf
iCAST
Dongyan Zhu, Xiaohong Ma
2009 conf
ISNN (2)
Xiaohong Ma, Lixin Wang, Yi Feng, Hualou Liang
2009 B conf
IJCNN
Xiaohong Ma, Yan Qin, Hualou Liang
2009 conf
ISNN (3)
Xiaohong Ma, Xin Li, Hualou Liang
2008 B conf
ICPR
Zhi Zeng, Xin Li, Xiaohong Ma, Qiang Ji
2007 conf
ISNN (3)
Xiaohong Ma, Xiaohua Liu, Jin Liu, Fuliang Yin
2007 conf
ISNN (2)
Xiaohong Ma, Bo Zhang, Xiaoyan Ding
2006 conf
ISNN (2)
Xiaohong Ma, Xiaoyan Ding, Chong Wang, Fuliang Yin
2006 conf
ISNN (2)
Xiaohong Ma, Jin Liu, Fuliang Yin
2005 conf
ISNN (2)
Xiaohong Ma, Chong Wang, Xiangping Cong, Fuliang Yin
2005 conf
ISNN (2)
Xiaohong Ma, Yu Wang, Wenlong Liu, Fuliang Yin
2005 conf
ISNN (2)
Chong Wang, Xiaohong Ma, Xiangping Cong, Fuliang Yin
redb/extractors/js_extractors/js_suspicious_apis.py
← Index redb/extractors/js_extractors/js_suspicious_apis.py python
import inspect
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.js_extractor import JSExtractor
from redb.extractors.js_extractors.js_patterns import CATEGORIES, PATTERNS


# Backwards-compatible export: `{category: [(raw_pattern_string, api_name), ...]}`
# in canonical PATTERNS insertion order (code_execution, network, filesystem,
# process, registry, crypto_encoding, dom_manipulation). Kept so external
# callers (notably JSDeobfuscationExtractor pre-cleanup) keep working until
# they are migrated to PATTERNS directly.
SUSPICIOUS_APIS: "dict[str, list[tuple[str, str]]]" = {}
for _name, _compiled in PATTERNS.items():
    SUSPICIOUS_APIS.setdefault(CATEGORIES[_name], []).append((_compiled.pattern, _name))


class JSSuspiciousAPIsExtractor(JSExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False, source=None, context=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, source, context=context,
        )
        self.api_findings = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.JS_SUSPICIOUS_APIS.value

    def _get_context_snippet(self, line, max_len=200):
        """Get a truncated context snippet around a match."""
        line = line.strip()
        if len(line) > max_len:
            return line[:max_len] + "..."
        return line

    def extract(self):
        src = self.js_source
        if not src:
            return None

        # Pass 1: shared per-sample scan over the raw source. The dict contains
        # entries for both PATTERNS and FEATURE_PATTERNS; the loop below only
        # consults PATTERNS keys, so feature-only entries are ignored.
        raw_scan = self._context.scan or {}
        raw_lines = self.lines

        # Pass 2: same patterns over the deobfuscated text, when the
        # deobfuscator produced something meaningfully different. APIs hidden
        # behind one obfuscation layer (Vjw0rm-style array.join + eval,
        # Dean-Edwards packers, jjencode, ...) only surface here. The scan is
        # cached on JSContext so JSDeobfuscationExtractor (which computes the
        # new_apis_found diff) reuses the same result.
        deobf_scan = self._context.scan_deobfuscated
        if deobf_scan:
            deobf_text, _ = self._context.deobfuscated
            deobf_lines = deobf_text.splitlines()
        else:
            deobf_lines = []

        findings = []
        # Iterate PATTERNS in canonical order so output is deterministic and
        # matches the historical category/pattern ordering. For each api_name,
        # raw findings take precedence; if an API is found only in the
        # deobfuscated text, we surface it as a row tagged revealed_by_deobf=1
        # with line numbers / snippets pulled from the deobfuscated source.
        for api_name in PATTERNS:
            raw_info = raw_scan.get(api_name)
            if raw_info:
                line_numbers = raw_info["lines"]
                lines_for_snippets = raw_lines
                revealed_by_deobf = 0
            else:
                deobf_info = deobf_scan.get(api_name)
                if not deobf_info:
                    continue
                line_numbers = deobf_info["lines"]
                lines_for_snippets = deobf_lines
                revealed_by_deobf = 1

            snippets = [
                self._get_context_snippet(lines_for_snippets[ln - 1])
                for ln in line_numbers[:3]
                if 0 < ln <= len(lines_for_snippets)
            ]
            findings.append({
                "api_name": api_name,
                "api_category": CATEGORIES[api_name],
                # Historical semantics: count = number of unique lines with a
                # match, not total in-source match count.
                "call_count": len(line_numbers),
                "line_numbers": line_numbers,
                "context_snippet": " | ".join(snippets),
                "revealed_by_deobf": revealed_by_deobf,
            })

        if not findings:
            return None

        self.api_findings = findings
        return findings

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.api_findings:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for f in self.api_findings:
                data.append([
                    self.sha256,
                    f['api_name'],
                    f['api_category'],
                    f['call_count'],
                    f['line_numbers'],
                    f['context_snippet'],
                    f['revealed_by_deobf'],
                    current_time,
                ])

            column_names = [
                "sha256", "api_name", "api_category",
                "call_count", "line_numbers", "context_snippet",
                "revealed_by_deobf",
                "analysis_date",
            ]

            column_type_names = [
                "FixedString(64)", "String", "LowCardinality(String)",
                "UInt32", "Array(UInt32)", "String",
                "UInt8",
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_js_suspicious_apis"