Discover the SciOpen Platform and Achieve Your Research Goals with Ease.
Search articles, authors, keywords, DOl and etc.
In recent years, Android system applications (hereinafter referred to as ‘APPs’) have become one of the primary ‘tools’ used by criminals for fraud. Criminals develop fraudulent apps and distribute their installation packages, known as Android application packages or APK files, to victims. After downloading and installing these apps, victims are deceived through their interactions within the apps. Therefore, the functional analysis of apps on Android devices has become a crucial source of for analyzing the processes of fraudulent activities and identifying the perpetrators of such crimes. With the development of protective technologies in recent years, an increasing number of fraudulent application files now employ various protective measures to prevent virtual machine executing and packet capturing, making dynamic analysis of these APPs increasingly difficult. This paper introduces common anti-packet capture techniques, including APK environment detection, packet capture detection, and certificate verification detection, and starts with reverse code analysis of APKs, dynamic packet capture analysis, and the underlying system code of Android, which explores the feasibility of bypassing dynamic detection and anti-packet capture mechanisms. The study of these methods for evidence collection provides valuable insights for the analysis of various types of fraudulent and malicious APPs.
This is an open access article under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0, http://creativecommons.org/licenses/by/4.0/).
Comments on this article