Module: HEITT::Scanner

Defined in:
lib/heitt.rb

Class Method Summary collapse

Class Method Details

.get_modes(entry) ⇒ Object



239
240
241
242
# File 'lib/heitt.rb', line 239

def self.get_modes(entry)
  entry[:modes] || entry[:algorithms] || entry[:hashes] || 
  entry[:candidates] || entry[:types] || entry[:hashtypes]
end

.get_regex(entry) ⇒ Object



235
236
237
# File 'lib/heitt.rb', line 235

def self.get_regex(entry)
  entry[:extract_regex] || entry[:regex] || entry[:pattern] || entry[:regexp]
end

.scan(input, database: HEITT::DATABASE, min_entropy: 3.5) ⇒ Object



191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
# File 'lib/heitt.rb', line 191

def self.scan(input, database: HEITT::DATABASE, min_entropy: 3.5)
  text = File.exist?(input) ? File.read(input) : input
  context_scores = HEITT::Analyzer.analyze(text, database: database)
  found = {}#[]
  seen = {}
 

  database.each do |entry|
    regex = get_regex(entry)
    modes = get_modes(entry)
    next unless regex && modes && !modes.empty?
    pattern = regex.is_a?(Regexp) ? regex : Regexp.new(regex)
    scanner = StringScanner.new(text)      
    
    while scanner.scan_until(pattern)
      matched = scanner.matched
      next unless matched.length < 8 || HEITT::Analyzer.high_entropy?(matched, min_entropy)
      offset = scanner.pos - matched.length
      delim_prefix = HEITT::Analyzer.extract_prefix(text, offset)

      candidates = HEITT::Analyzer.score_candidates(modes, delim_prefix, context_scores)
      score = candidates.first[:score]

      found[matched] ||= {hash: matched, candidates: []}
      found[matched][:candidates].concat(candidates)
      end
    end

      found.each_value do |result|
       result[:candidates] = result[:candidates]
        .group_by {|c| c[:name]}
        .map {|name, dupes| dupes.max_by {|c| c[:score]}}
        .sort_by {|c| -c[:score]}

        # Re-assign confidence based on final merged scores
        scores_hash = result[:candidates].map {|c| [c[:name], c[:score]]}.to_h
        confidences = Analyzer.assign_confidence(scores_hash)
        result[:candidates] = result[:candidates].map {|c| c.merge(confidence: confidences[c[:name]])}
  end
  found.values
end