Xiaohui Han

47 papers A* 1B 5C 7Misc 2Journal 22Unranked 10
YearRankTypeTitle / Venue / Authors
2025 J jnl
CoRR
Xiaohui Han, Yunlong Zhang, Yuxi Guo
2025 J jnl
J. Informetrics
Linlin Ren, Lei Guo, Hui Yu, Feng Guo, Xinhua Wang, Xiaohui Han
2025 B conf
IJCNN
Xiaotong Li, Xiaohui Han, Hui Cui, Lei Guo, Hua Ding, Chaoran Cui
2025 J jnl
CoRR
Ziang Lu, Lei Guo, Xu Yu, Zhiyong Cheng, Xiaohui Han, Lei Zhu
2025 J jnl
ACM Trans. Inf. Syst.
Ziang Lu, Lei Guo, Xu Yu, Zhiyong Cheng, Xiaohui Han, Lei Zhu
2025 Misc conf
ICASSP
Lin Chen, Peipei Wang, Xiaohui Han, Lijuan Xu
2025 J jnl
CoRR
Lei Guo, Chenlong Song, Feng Guo, Xiaohui Han, Xiaojun Chang, Lei Zhu
2025 J jnl
ACM Trans. Inf. Syst.
Lei Guo, Chenlong Song, Feng Guo, Xiaohui Han, Xiaojun Chang, Lei Zhu
2025 Misc conf
ICASSP
Jinghui Ni, Hui Cui, Lihai Zhao, Fengling Li, Xiaohui Han, Lijuan Xu
2025 J jnl
IEEE Internet Things J.
Lijuan Xu, Baolong An, Xin Li, Dawei Zhao, Haipeng Peng, Weizhao Song, Fenghua Tong, Xiaohui Han
2025 J jnl
Inf. Process. Manag.
Xinhua Wang, Houping Yue, Lei Guo, Feng Guo, Chen He, Xiaohui Han
2024 B conf
IJCNN
Yuecheng Wen, Xiaohui Han, Wenbo Zuo, Weihua Liu
2024 C conf
CSCWD
Yang Liu, Xiaohui Han, Wenbo Zuo, Haiqing Lv, Jing Guo
2024 J jnl
J. Informetrics
Qiuling Liu, Lei Guo, Yiping Sun, Linlin Ren, Xinhua Wang, Xiaohui Han
2024 A* conf
AAAI
Hui Cui, Lihai Zhao, Fengling Li, Lei Zhu, Xiaohui Han, Jingjing Li
2024 C conf
CSCWD
Weihua Liu, Xiaohui Han, Wenbo Zuo, Yu Sun
2024 C conf
ISPA
Haiqing Lv, Xiaohui Han, Peipei Wang, Wenbo Zuo, Jing Guo, Lijuan Xu
2024 B conf
IJCNN
Haiqing Lv, Xiaohui Han, Hui Cui, Peipei Wang, Wenbo Zuo, Yang Zhou
2024 J jnl
IEEE Trans. Inf. Forensics Secur.
Xuejiao Luo, Xiaohui Han, Wenbo Zuo, Xiaoming Wu, Wenyin Liu
2024 B conf
SMC
Menglu Wang, Xiaohui Han, Peipei Wang, Wenbo Zuo
2023 conf
DSIT
Xiaohui Han, Yanran Li, Shuyu Li
2023 J jnl
Eng. Appl. Artif. Intell.
Xiaohui Han, Song Huang, Xu Zhang, Yingkuo Zhu, Guoqing An, Zhenbin Du
2023 conf
ICONIP (13)
Meng Liu, Xiaohui Han, Wenbo Zuo, Xuejiao Luo, Lei Guo
2023 J jnl
Appl. Math. Comput.
Xiaohui Han, Jianping Dong
2023 conf
MSN
Xiao Cui, Xiaohui Han, Guangqi Liu, Wenbo Zuo, Zhiwen Wang
2023 conf
HPCC/DSS/SmartCity/DependSys
Yu Sun, Guangqi Liu, Xiaohui Han, Wenbo Zuo, Weihua Liu
2022 B conf
TrustCom
Xuejiao Luo, Xiaohui Han, Wenbo Zuo, Zhengyuan Xu, Zhiwen Wang, Xiaoming Wu
2022 J jnl
CoRR
Lianxin Song, Xiaohui Han, Guangqi Liu, Wentong Wang, Chaoran Cui, Yilong Yin
2020 J jnl
IEEE Trans. Circuits Syst.
Dawei Zhao, Shumian Yang, Xiaohui Han, Shuhui Zhang, Zhen Wang
2020 J jnl
Comput. Secur.
Lijuan Xu, Bailing Wang, Lianhai Wang, Dawei Zhao, Xiaohui Han, Shumian Yang
2019 J jnl
Comput. Secur.
Xiaohui Han, Lianhai Wang, Shujiang Xu, Dawei Zhao, Guangqi Liu
2019 conf
NaNA
Shuhui Zhang, Lianhai Wang, Lijuan Xu, Shujiang Xu, Xiaohui Han, Shumian Yang
2019 conf
MMM (2)
Yongchao Xu, Qizheng Yang, Chaoran Cui, Cheng Shi, Guangle Song, Xiaohui Han, Yilong Yin
2018 J jnl
Sensors
Ben Guan, Yong Zang, Xiaohui Han, Kailun Zheng
2018 C conf
ICICS
Xiaohui Han, Lianhai Wang, Shujiang Xu, Dawei Zhao, Guangqi Liu
2018 J jnl
Secur. Commun. Networks
Shuhui Zhang, Xiangxu Meng, Lianhai Wang, Lijuan Xu, Xiaohui Han
2018 J jnl
计算机科学
Zhenwu Wang, Xiaohua Lv, Xiaohui Han
2017 J jnl
IEEE Trans. Inf. Forensics Secur.
Xiaohui Han, Lianhai Wang, Chaoran Cui, Jun Ma, Shuhui Zhang
2017 C conf
ISI
Xiaohui Han, Lianhai Wang, Shujiang Xu, Guangqi Liu, Dawei Zhao
2017 conf
ICCCS (1)
Shujiang Xu, Lianhai Wang, Guangqi Liu, Xiaohui Han, Dawei Zhao, Lijuan Xu
2016 J jnl
Sensors
Jin Zhang, Wei Li, Hong-Liang Cui, Changcheng Shi, Xiaohui Han, Yuting Ma, Jiandong Chen, Tianying Chang, Dongshan Wei, Yumin Zhang, Yufeng Zhou
2016 C conf
ISI
Xiaohui Han, Lianhai Wang, Lijuan Xu, Shuihui Zhang
2014 C conf
CIS
Shuhui Zhang, Lianhai Wang, Xiaohui Han
2014 J jnl
Soft Comput.
Xiaohui Han, Jun Ma, Yun Wu, Chaoran Cui
2011 conf
Web Intelligence
Zhaochun Ren, Jun Ma, Gang Wang, Chaoran Cui, Xiaohui Han
2008 conf
AIRS
Zhumin Chen, Jun Ma, Xiaohui Han, Dongmei Zhang
2008 conf
FSKD (2)
Cuiling Zhu, Jun Ma, Dongmei Zhang, Xiaohui Han, Xiaofei Niu
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |