Xiaojuan Li

51 papers C 16Journal 22Unranked 13
YearRankTypeTitle / Venue / Authors
2024 J jnl
IEEE Trans. Geosci. Remote. Sens.
Wei Chen, Jinyan Tian, Jie Song, Xiaojuan Li, Yinghai Ke, Lin Zhu, Yongxin Yu, Yang Ou, Huili Gong
2024 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Rumei Li, Liyan Zhang, Zun Wang, Xiaojuan Li
2024 J jnl
Remote. Sens.
Mingyuan Lyu, Xiaojuan Li, Yinghai Ke, Jiyi Jiang, Zhenjun Sun, Lin Zhu, Lin Guo, Zhihe Xu, Panke Tang, Huili Gong, Lan Wang
2023 J jnl
Comput. Geosci.
Zijian Wang, Lin Guo, Huili Gong, Xiaojuan Li, Lin Zhu, Ying Sun, Beibei Chen, Xueqi Zhu
2023 J jnl
Remote. Sens.
Xueqi Zhu, Wantian Zhu, Lin Guo, Yinghai Ke, Xiaojuan Li, Lin Zhu, Ying Sun, Yaxuan Liu, Beibei Chen, Jinyan Tian, Huili Gong
2022 J jnl
Remote. Sens.
Xiaotong Guo, Dan Meng, Xuelong Chen, Xiaojuan Li
2021 J jnl
IEEE Trans. Geosci. Remote. Sens.
Zhenxin Zhang, Lan Sun, Ruofei Zhong, Dong Chen, Liqiang Zhang, Xiaojuan Li, Qiang Wang, Siyun Chen
2021 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Beibei Chen, Huili Gong, Yun Chen, Kunchao Lei, Chaofan Zhou, Yuan Si, Xiaojuan Li, Yun Pan, Mingliang Gao
2021 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Jie Zhang, Jinyan Tian, Xiaojuan Li, Le Wang, Beibei Chen, Huili Gong, Rongguang Ni, Bingfeng Zhou, Cankun Yang
2021 J jnl
Remote. Sens.
Lin Guo, Huili Gong, Yinghai Ke, Lin Zhu, Xiaojuan Li, Mingyuan Lyu, Ke Zhang
2020 J jnl
Remote. Sens.
Mingyuan Lyu, Yinghai Ke, Xiaojuan Li, Lin Zhu, Lin Guo, Huili Gong
2020 J jnl
Sensors
Ke Zhang, Cankun Yang, Xiaojuan Li, Chunping Zhou, Ruofei Zhong
2019 J jnl
Remote. Sens.
Jinyan Tian, Le Wang, Xiaojuan Li, Dameng Yin, Huili Gong, Sheng Nie, Chen Shi, Ruofei Zhong, Xiaomeng Liu, Ronglong Xu
2019 J jnl
Remote. Sens.
Mingli Wang, Longjiang Du, Yinghai Ke, Maoyi Huang, Jing Zhang, Yong Zhao, Xiaojuan Li, Huili Gong
2019 J jnl
Remote. Sens.
Mingliang Gao, Huili Gong, Xiaojuan Li, Beibei Chen, Chaofan Zhou, Min Shi, Lin Guo, Zheng Chen, Zhongyun Ni, Guangyao Duan
2018 J jnl
Remote. Sens.
Qin Yang, Yinghai Ke, Dongyi Zhang, Beibei Chen, Huili Gong, Mingyuan Lv, Lin Zhu, Xiaojuan Li
2018 J jnl
Remote. Sens.
Mingliang Gao, Huili Gong, Beibei Chen, Xiaojuan Li, Chaofan Zhou, Min Shi, Yuan Si, Zheng Chen, Guangyao Duan
2017 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Jinyan Tian, Le Wang, Xiaojuan Li, Huili Gong, Chen Shi, Ruofei Zhong, Xiaomeng Liu
2017 J jnl
IEEE J. Sel. Top. Appl. Earth Obs. Remote. Sens.
Jinyan Tian, Le Wang, Xiaojuan Li, Chen Shi, Huili Gong
2016 C conf
IGARSS
Siyao Yang, Dan Meng, Xiaojuan Li
2016 J jnl
Remote. Sens.
Mi Chen, Roberto Tomás, Zhenhong Li, Mahdi Motagh, Tao Li, Leyin Hu, Huili Gong, Xiaojuan Li, Jun Yu, Xulong Gong
2015 J jnl
Remote. Sens.
Dan Li, Yinghai Ke, Huili Gong, Xiaojuan Li
2015 J jnl
Int. J. Appl. Earth Obs. Geoinformation
Jinyan Tian, Le Wang, Xiaojuan Li
2013 C conf
IGARSS
Wenbin Li, Yonghua Sun, Dan Meng, Xiaojuan Li
2013 C conf
IGARSS
Mingyu Wang, Yonghua Sun, Dan Meng, Xiaojuan Li
2012 conf
Geoinformatics
Dan Meng, Huili Gong, Xiaojuan Li, Demin Zhou
2011 C conf
IGARSS
Linrui Song, Jing Zhang, Huili Gong, Xiaojuan Li, Jingyu Zhang
2011 C conf
IGARSS
Wenhui Zhao, Huili Gong, Wenji Zhao, Xiaojuan Li
2010 C conf
IGARSS
Jian Lian, Xiaojuan Li, Huili Gong, Yanbing Wang, Cankun Yang
2010 C conf
IGARSS
Lili Tang, Deyong Hu, Xiaojuan Li, Jian Lian
2010 conf
Geoinformatics
Jing Zhang, Linrui Song, Huili Gong, Qian Li, Xiaojuan Li
2010 C conf
IGARSS
Dan Meng, Huili Gong, Xiaojuan Li, Wenji Zhao, Yanfang Li
2010 conf
Geoinformatics
Xuhua Cai, Huili Gong, Xiaojuan Li, Lin Zhu
2010 conf
Geoinformatics
Jian Lian, Xiaojuan Li, Huili Gong, Yanbing Wang, Yonghua Sun
2009 conf
IGARSS (4)
Zhaoning Gong, Xiaojuan Li, Wenji Zhao
2009 conf
IGARSS (2)
Lin Zhu, Huili Gong, Xiaojuan Li, Yaoming Su, Lingling Jing
2009 conf
IGARSS (3)
Dan Meng, Huili Gong, Xiaojuan Li, Wenji Zhao, Zhaoning Gong, Lin Zhu, Deyong Hu
2008 conf
IGARSS (2)
Youquan Zhang, Huili Gong, Xiaojuan Li, Taiguang Liu, Wen Yang, Beibei Chen, Angsheng Li, Yaoming Su
2008 conf
IGARSS (4)
Huili Gong, Youquan Zhang, Xiaojuan Li, Angsheng Li, Beibei Chen, Huan Zhou, Yonghua Sun
2008 conf
IGARSS (3)
Ou Zhang, Xiaojuan Li, Huili Gong, Weiguang Zhang, Yonghua Sun
2008 conf
IGARSS (2)
Yonghua Sun, Xiaojuan Li, Huili Gong, Chunping Zhou
2008 conf
IGARSS (2)
Deyong Hu, Xiaojuan Li, Wen-Ji Zhao, Huili Gong
2008 conf
IGARSS (4)
Deyong Hu, Wenji Zhao, Huili Gong, Xiaojuan Li, Jiacun Li
2007 C conf
IGARSS
Yonghua Sun, Xiaojuan Li, Huili Gong, Wenji Zhao, Zhaoning Gong
2007 C conf
IGARSS
Zhuowei Hu, Wenji Zhao, Xiaojuan Li, Ying Chen, Living Zhu, Songmei Zhang, Fusheng Wang
2007 C conf
IGARSS
Dan Meng, Zhiqiang Zhang, Tao Yang, Huili Gong, Wenji Zhao, Xiaojuan Li, Zhaoning Gong, Yanhui Wang, Zhuowei Hu, Yonghua Sun
2007 C conf
IGARSS
Wenji Zhao, Zhaoning Gong, Huili Gong, Xiaojuan Li, Zhuowei Hu, Songmei Zhang, Fusheng Wang
2007 C conf
IGARSS
Huili Gong, Zhuowei Hu, Wenji Zhao, Xiaojuan Li, Yanhui Wang, Zhaoning Gong, Songmei Zhang
2007 C conf
IGARSS
Zhaoning Gong, Huili Gong, Wenji Zhao, Xiaojuan Li, Zhuowei Hu
2006 C conf
IGARSS
Adu Gong, Yun-Hao Chen, Jing Li, Huili Gong, Xiaojuan Li
2005 C conf
IGARSS
Lingli Yang, Xiaojuan Li, Huili Gong, Wen-Ji Zhao, Lei Wang, Yong Hua Sun
sql/redb_js_tables.sql
← Index sql/redb_js_tables.sql sql
-- JavaScript malware analysis tables
-- Engine: ReplacingMergeTree(analysis_date) — latest analysis wins on re-processing
--
-- File order:
--   1. redb_js_features
--   2. redb_js_suspicious_apis
--   3. redb_js_deobfuscation
--   4. code_text_content              (generic text-content table; JS today,
--                                      PowerShell / Python / email / extracted
--                                      PDF / Office text in the future)
--   5. redb_iocs source_type ALTER    (extends Enum8 with text_raw/text_normalized
--                                      so JS — and any future text-based pipeline —
--                                      can distinguish IOCs found in the raw vs
--                                      normalised surface)
--   6. redb_iocs ioc_type ALTER       (adds registry_key=42 so HKLM/HKCU/HKEY_*
--                                      keys are extracted alongside file paths)
--
-- Decoded strings from JS still go into the shared code_binja_strings_raw
-- table (same schema used by DecompileBinja and DecompileAPK). JS
-- string_encoding values: hex, unicode, charcode, base64, concat. Plain long
-- literals are not extracted here — they're already in code_text_content and
-- scraped by the IOC pipeline over text_raw/text_normalized.
-- string_offset is the line number in the source file.
--
-- redb_js_features.script_type values (file format / container, first match):
--   jse, wsf, hta, embedded_html, wscript, esm, node_module, standalone, unknown
-- redb_js_features.detected_environment values (runtime by API surface, first
-- match):
--   wscript, browser_extension, service_worker, deno, node, browser, unknown

-- 1. Core features & obfuscation metrics (1 row per sample)
CREATE TABLE IF NOT EXISTS redb_js_features (
    sha256 FixedString(64),
    line_count UInt32,
    char_count UInt64,
    text_entropy Float64,
    max_line_length UInt32,
    avg_line_length Float64,
    is_minified UInt8,
    is_likely_obfuscated UInt8,
    obfuscator_name LowCardinality(String),
    obfuscation_score UInt8,
    obfuscation_techniques Array(String),
    eval_count UInt32,
    function_constructor_count UInt32,
    settimeout_setinterval_count UInt32,
    document_write_count UInt32,
    innerhtml_count UInt32,
    unescape_count UInt32,
    fromcharcode_count UInt32,
    atob_count UInt32,
    decodeuri_count UInt32,
    total_function_count UInt32,
    total_variable_count UInt32,
    max_nesting_depth UInt16,
    avg_identifier_length Float64,
    hex_string_count UInt32,
    unicode_escape_count UInt32,
    long_string_count UInt32,
    base64_string_count UInt32,
    comment_ratio Float64,
    script_type LowCardinality(String),
    detected_environment LowCardinality(String),
    analysis_date DateTime64(3, 'UTC')
) ENGINE = ReplacingMergeTree(analysis_date)
ORDER BY sha256;

-- 2. Suspicious API calls (multi-row per sample)
--
-- `revealed_by_deobf` is 1 when the API only appears after the deobfuscation
-- pass (i.e. the call site is hidden in the raw artefact and surfaces only in
-- text_normalized). Useful for filtering "what did normalisation actually
-- buy us" without re-running the diff.
CREATE TABLE IF NOT EXISTS redb_js_suspicious_apis (
    sha256 FixedString(64),
    api_name String,
    api_category LowCardinality(String),
    call_count UInt32,
    line_numbers Array(UInt32),
    context_snippet String,
    revealed_by_deobf UInt8,
    analysis_date DateTime64(3, 'UTC')
) ENGINE = ReplacingMergeTree(analysis_date)
ORDER BY (sha256, api_name);

-- 3. Deobfuscation results (1 row per sample)
CREATE TABLE IF NOT EXISTS redb_js_deobfuscation (
    sha256 FixedString(64),
    deobfuscator_used LowCardinality(String),
    deobfuscation_successful UInt8,
    original_size UInt64,
    deobfuscated_size UInt64,
    size_change_ratio Float64,
    original_entropy Float64,
    deobfuscated_entropy Float64,
    new_strings_found UInt32,
    new_apis_found UInt32,
    deobfuscated_sha256 FixedString(64),
    analysis_date DateTime64(3, 'UTC')
) ENGINE = ReplacingMergeTree(analysis_date)
ORDER BY sha256;

-- 4. Generic text-content table for any text-based artefact (JS today;
--    PowerShell, Python, plain text, email bodies, extracted PDF/Office text
--    in the future). One row per sha256. content_type carries the magika
--    label so callers can filter without joining other tables.
CREATE TABLE IF NOT EXISTS code_text_content (
    sha256 FixedString(64),
    content_type LowCardinality(String),
    text_raw String CODEC(ZSTD(3)),
    text_normalized Nullable(String) CODEC(ZSTD(3)),
    normalizer_used Nullable(String),
    analysis_date DateTime64(3, 'UTC')
) ENGINE = ReplacingMergeTree(analysis_date)
ORDER BY sha256;

-- 5. Extend redb_iocs.source_type Enum8 with two universal text-content
--    surfaces: text_raw (the artefact's original text) and text_normalized
--    (a deobfuscated/canonicalised form). Used by the JS IOC extraction
--    pipeline today; any future text-based pipeline (PowerShell, PDF, etc.)
--    plugs into the same two values.
--
-- Existing rows keep their stored integer values; only newly-inserted rows
-- can use 4/5. The MODIFY COLUMN must list the full final enum, including
-- the existing values (1/2/3) — ClickHouse rejects partial alters.
ALTER TABLE redb_iocs
    MODIFY COLUMN source_type
    Enum8('decompiled_function'=1, 'disassembled_function'=2, 'string'=3,
          'text_raw'=4, 'text_normalized'=5);

-- 6. Extend redb_iocs.ioc_type Enum8 with registry_key=42. Windows registry
--    paths (HKLM\..., HKCU\..., HKEY_LOCAL_MACHINE\...) are a distinct class
--    of IOC from filesystem paths and were previously extracted by nothing.
--    Same MODIFY COLUMN constraint as the source_type alter — the full final
--    enum must be listed.
ALTER TABLE redb_iocs
    MODIFY COLUMN ioc_type
    Enum8('ipv4'=1, 'ipv6'=2, 'fqdn'=3, 'url'=4, 'email'=5, 'server'=6,
          'hash_md5'=10, 'hash_sha1'=11, 'hash_sha256'=12,
          'cve'=20, 'cwe'=21, 'cpe'=22,
          'crypto_btc'=30, 'crypto_eth'=31, 'crypto_xrp'=32, 'crypto_bch'=33,
          'crypto_ada'=34, 'crypto_substrate'=35,
          'path_linux'=40, 'path_windows'=41, 'registry_key'=42,
          'onion'=50);

-- 7. Migrate redb_js_features to the two-tier obfuscation verdict.
--    `is_obfuscated` (binary heuristic at score >=40) is renamed to
--    `is_likely_obfuscated` (heuristic at >=60 + ≥1 strong signal, OR
--    js-x-ray flagged the obfuscator family). `obfuscator_name` is the
--    family name reported by @nodesecure/js-x-ray (jsfuck, obfuscator.io,
--    morse, jjencode, freejsobfuscator, ...) or empty when not detected.
--
--    Run once against an existing deployment. The CREATE TABLE above
--    already reflects the post-migration shape, so fresh installs skip this.
ALTER TABLE redb_js_features
    RENAME COLUMN is_obfuscated TO is_likely_obfuscated;
ALTER TABLE redb_js_features
    ADD COLUMN IF NOT EXISTS obfuscator_name LowCardinality(String) AFTER is_likely_obfuscated;

-- 8. Harmonise code_text_content column names with redb_iocs.source_type
--    enum values. The enum already uses `text_raw` / `text_normalized` for
--    the surface labels; the table previously stored the same data under
--    `content_raw` / `content_normalized`, forcing every join across the two
--    to translate names. Renaming the columns produces a self-documenting
--    schema where `redb_iocs.source_type='text_raw'` points directly at
--    `code_text_content.text_raw`.
--
--    Run once against an existing deployment. The CREATE TABLE above
--    already reflects the post-migration shape, so fresh installs skip this.
ALTER TABLE code_text_content
    RENAME COLUMN content_raw TO text_raw;
ALTER TABLE code_text_content
    RENAME COLUMN content_normalized TO text_normalized;

-- 9. Add revealed_by_deobf flag to redb_js_suspicious_apis. The strings/APIs
--    extractors now scan both the raw source and the deobfuscated text so APIs
--    hidden behind one obfuscation layer (Vjw0rm-style array.join + eval,
--    Dean-Edwards packers, ...) surface in the table. The flag is 1 only when
--    the API was *not* found in the raw source — querying for it isolates
--    "deobf-only" findings without joining redb_js_deobfuscation.
--
--    Run once against an existing deployment. The CREATE TABLE above
--    already reflects the post-migration shape, so fresh installs skip this.
ALTER TABLE redb_js_suspicious_apis
    ADD COLUMN IF NOT EXISTS revealed_by_deobf UInt8 AFTER context_snippet;