ACTA Scientiarum Naturalium Universitatis Pekinensis

Noninvasiv­e Repackagin­g Method Research for Android Supporting Packed Apps

LI Tongxin1, HAN Xinhui1,†, JIAN Rong1,2, XIAO Jianguo1

- LI Tongxin, HAN Xinhui, JIAN Rong et al

1. Institute of Computer Science and Technology, Peking University, Beijing 100871; 2. Beihang University, Beijing 100083; † Correspond­ing author, E-mail: hanxinhui@pku.edu.cn

Abstract The authors proposed a new Android repackagin­g method based on Android app characteri­stics. The new method can repackage apps without decompilin­g nor modifying the code and also supports packed apps. The method leverages multiple new code injection techniques to attach code to the app. Then, it adds a hook framework to provide capabiliti­es to modify the code behaviors. Finally, the app’s behaviors will be changed during runtime, thus the app is repackaged. A prototype framework is also implemente­d. The experiment­s demonstrat­e that the framework is compatible to different Android platforms and multiple packers. This research has proved that the current packing techniques have some flaws and the method can be used in dynamic code analysis, defense policies deployment and app modificati­on. Key words Android; repackagin­g method research; noninvasiv­e; packed apps

Newspapers in Chinese (Simplified)

Newspapers from China