Publications
Sort:
Open Access Research and Discussion Issue
Anti-packet Capture Technology and Forensic Methods for Android Applications
Forensic Science and Technology 2025, 50(6): 643-649
Published: 06 December 2024
Abstract PDF (2.9 MB) Collect
Downloads:0

In recent years, Android system applications (hereinafter referred to as ‘APPs’) have become one of the primary ‘tools’ used by criminals for fraud. Criminals develop fraudulent apps and distribute their installation packages, known as Android application packages or APK files, to victims. After downloading and installing these apps, victims are deceived through their interactions within the apps. Therefore, the functional analysis of apps on Android devices has become a crucial source of for analyzing the processes of fraudulent activities and identifying the perpetrators of such crimes. With the development of protective technologies in recent years, an increasing number of fraudulent application files now employ various protective measures to prevent virtual machine executing and packet capturing, making dynamic analysis of these APPs increasingly difficult. This paper introduces common anti-packet capture techniques, including APK environment detection, packet capture detection, and certificate verification detection, and starts with reverse code analysis of APKs, dynamic packet capture analysis, and the underlying system code of Android, which explores the feasibility of bypassing dynamic detection and anti-packet capture mechanisms. The study of these methods for evidence collection provides valuable insights for the analysis of various types of fraudulent and malicious APPs.

Total 1