AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (2.9 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Research and Discussion | Publishing Language: Chinese | Open Access

Anti-packet Capture Technology and Forensic Methods for Android Applications

Jiabin LI1Haomiao YU1Jiahao MAO1Hongqing PEI2Jiajun CEN2( )
Xihu Branch of Hangzhou Public Security Bureau, Hangzhou 310012, China
Hangzhou Pinghang Technology, Hangzhou 310051, China
Show Author Information

Abstract

In recent years, Android system applications (hereinafter referred to as ‘APPs’) have become one of the primary ‘tools’ used by criminals for fraud. Criminals develop fraudulent apps and distribute their installation packages, known as Android application packages or APK files, to victims. After downloading and installing these apps, victims are deceived through their interactions within the apps. Therefore, the functional analysis of apps on Android devices has become a crucial source of for analyzing the processes of fraudulent activities and identifying the perpetrators of such crimes. With the development of protective technologies in recent years, an increasing number of fraudulent application files now employ various protective measures to prevent virtual machine executing and packet capturing, making dynamic analysis of these APPs increasingly difficult. This paper introduces common anti-packet capture techniques, including APK environment detection, packet capture detection, and certificate verification detection, and starts with reverse code analysis of APKs, dynamic packet capture analysis, and the underlying system code of Android, which explores the feasibility of bypassing dynamic detection and anti-packet capture mechanisms. The study of these methods for evidence collection provides valuable insights for the analysis of various types of fraudulent and malicious APPs.

CLC number: DF793.2 Document code: A Article ID: 1008-3650(2025)06-0643-07

References

【1】
【1】
 
 
Forensic Science and Technology
Pages 643-649

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
LI J, YU H, MAO J, et al. Anti-packet Capture Technology and Forensic Methods for Android Applications. Forensic Science and Technology, 2025, 50(6): 643-649. https://doi.org/10.16467/j.1008-3650.2024.0082

0

Views

0

Downloads

0

Crossref

0

Scopus

Received: 11 June 2024
Revised: 29 October 2024
Published: 06 December 2024
© 2025 The Editorial Office of Forensic Science and Technology

This is an open access article under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0, http://creativecommons.org/licenses/by/4.0/).