A method and system for automatically extracting Android application data
By detecting the automation support rate of Android devices, installing automation applications and enabling auxiliary services, and sending configuration command protocols to support automated backup processes, it solves the problem of automated backup of different brands and versions of devices, realizes efficient automated data extraction, and improves the efficiency of the electronic evidence forensics industry.
Patent Information
- Application Number
- CN202111392349.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-19
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2041-11-19
AI Technical Summary
The existing technology is difficult to automatically backup application data for Android devices of different brands and versions, and it is inefficient, especially in the electronic evidence forensics industry, which requires manual operation and is relatively inefficient.
By initially detecting the automation support rate of Android devices, marking automation or semi-automation tags, installing automation applications, enabling auxiliary services, sending abstract configuration instructions and protocols to support automated backup processes, monitoring backup progress, and realizing automated data extraction.
It realizes the data process of automated backup application for mobile phones of different brands and versions, supports unified automated detection of backup process progress, achieves automated data extraction, and improves the efficiency of the electronic evidence forensics industry.
Smart Images

Figure CN114064364B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer software technology, and in particular to a method and system for automatically extracting Android application data. Background Art
[0002] Android applications are becoming more and more diverse, and the data is becoming more and more massive. However, due to the system's protection of application data and the increasing difficulty of system ROOT, non-ROOT phones cannot directly back up or extract data through commands. In order to provide users with a method to back up application data, each Android manufacturer has built-in backup software. The system application has system permissions and can back up the data of selected applications to the built-in storage for users to export and restore. Currently, in electronic evidence collection or certain mobile phone-related fields, staff often need to extract application data from the required mobile phones for analysis, but often because they do not know how to operate, and there are many brands and types of devices, it is difficult to operate at once.
[0003] Android has two automation tools: uiautomator and auxiliary services. Uiautomator can directly use ADB commands to execute automation scripts, while auxiliary services need to install applications to open the service execution automation environment. Both categories belong to Android accessibility services. Both methods essentially call accessibility services to perform corresponding automation operations by finding interface element nodes. For example, the commonly used WeChat red envelope grabbing uses auxiliary services to automatically grab red envelopes, while software development companies use uiautomator for automated testing.
[0004] However, some mobile phone manufacturers have not opened up the uiautomator permissions. When a large number of mobile phones need to extract data at the same time, it is difficult for the mobile phones to provide automatic support at the same time. If auxiliary services are used, it is necessary to manually install the application and enable the auxiliary function to support barrier-free services.
[0005] Although mobile phone manufacturers provide users with system backup software to manually back up application data, it is undoubtedly necessary to manually perform tedious operations and wait, manually back up the application data that needs to be backed up, and observe the backup progress of the system software before finally extracting the data. For the electronic forensics industry, if all the data needs to be extracted manually, the efficiency will be very low.
[0006] This solution invents a device that supports multi-channel parallel automatic extraction of Android application data. The device performs pre-processing by initially detecting whether the automation support rate is high or not, and then sends an abstract configuration instruction protocol to the auxiliary service process for execution, so as to support the automatic execution of the system's built-in backup application data process for mobile phones of different brands and versions, support unified automatic detection of the backup process progress, and achieve automatic data extraction. Summary of the invention
[0007] The present invention proposes a method and system for automatically extracting Android application data to solve the above-mentioned defects of the prior art.
[0008] In one aspect, the present invention provides a method for automatically extracting Android application data, the method comprising the following steps:
[0009] S1: Initiate a detection process to an Android device, wherein the detection process is used to detect whether the Android device supports automation;
[0010] If yes, first label the Android device with an automation tag, and then jump to S3;
[0011] If not, first mark the Android device with a semi-automatic tag and send the automated application to the Android device for installation, and then jump to S2;
[0012] S2: after installation, start the automation application, then enable the automation auxiliary service for the Android device to support automation, and execute S3 when the Android device enters the automation environment;
[0013] S3: Convert the data packet name of the configuration information of the application in the Android device to generate an application name list, place the application name list into the device directory of the Android device, and establish a correspondence between the data packet name and the name of the application; wherein the application name list includes options for automatic selection;
[0014] S4: obtaining the value of the data space of the application in the Android device, taking the maximum value of the value of the data space as the detection parameter, and defining the operation action of the accessibility service by configuring the ACTION command and configuring the execution action;
[0015] S5: starting various processes of the accessibility service and instructing the Android device to perform automatic backup by sending an automatic action configuration instruction, the list of application names to be backed up, and required parameters to the Android device;
[0016] S6: During the process of executing the automatic backup, the detection parameter is used to monitor the completion progress of the automatic backup.
[0017] The above method performs pre-processing by initially detecting whether the automation support rate is high or not, and then sends an abstract configuration instruction protocol to the auxiliary service process for execution, so as to support the automatic execution of the system's built-in backup application data flow for mobile phones of different brands and versions, support unified automatic detection of the backup process progress, and achieve automatic data extraction.
[0018] In a specific embodiment, the detection process includes:
[0019] Based on the Android accessibility service, a specific area of the screen is clicked, and the execution result is obtained through user perception to determine whether the Android device supports automation capabilities.
[0020] In a specific embodiment, the operation action of the accessibility service is defined by configuring the ACTION command and configuring the execution action, specifically including:
[0021] The action type of the ACTION command and the execution action type of the accessibility service are configured using a text protocol; wherein the text protocol records the abstraction of automated behaviors required for automated backup of Android devices of different brands;
[0022] The operation action of the barrier-free service is configured as follows: when the automation step is executed, the text protocol is packaged into configuration instructions and sent to the Android device.
[0023] In a specific embodiment, the various processes of the barrier-free service specifically include:
[0024] Parsing the automation action configuration instructions and entering the automation step;
[0025] When the specified page is opened by reading the initial ACTION command and entering the backup page of the Android device, the application name list to be backed up is read to match the LIST entry element of the current page, and the ACTION action is executed according to the matching result;
[0026] Further read ACTION, match ACTION to execute the automatic backup;
[0027] The read end ACTION and the matching ACTION are used to monitor the completion progress of the automated backup.
[0028] In a specific embodiment, the reading of the application name list to be backed up is used to match the LIST entry element of the current page, and the ACTION action is performed according to the matching result. The specific steps include:
[0029] Match the LIST entry elements with the contents of the application name list one by one;
[0030] If the match is successful, an ACTION action is performed on the API of the accessibility service to check the name element node on the page, and the matched application name is removed from the application name list until all application names are removed, indicating that the ACTION action has been completed;
[0031] If the match fails, record the name NODE1 of the node at the bottom of the LIST item element of the current page, obtain the screen position coordinate POS1, use the API of the accessibility service to scroll one screen height distance, and re-obtain the name NODE2 of the node at the bottom of the LIST item element of the current page, obtain the screen position coordinate POS2, determine the relationship between NODE1 and NODE2 and between POS1 and POS2, and execute corresponding ACTION actions based on the relationship.
[0032] In a specific embodiment, the use of the detection parameters to monitor the completion progress of the automated backup includes the following specific steps:
[0033] Obtain the size of the backup directory specified in the automatic backup at the initial moment;
[0034] Specify scanning the backup directory once at a certain interval;
[0035] If the size of the backup directory does not change during the N consecutive scans, it means that the automatic backup is finished;
[0036] Wherein N=(the detection parameter / 1024 / 1024+1)*2.
[0037] In a specific embodiment, the method of obtaining the value of the data space of the application in the Android device includes:
[0038] The system API interface is read according to the configuration information of the application in the Android device, so as to obtain the value of the data space of the corresponding application in the Android device.
[0039] In a specific embodiment, the action type of the ACTION command includes: an execution element unique identifier, an execution action type, and a delay.
[0040] In a specific embodiment, the execution action types of the accessibility service include: opening a specified page, clicking, scrolling, returning to the main desktop, and sliding.
[0041] In a specific embodiment, during the automatic backup process, if the application name list does not exist or the LIST entry element is zero, the automatic backup is terminated.
[0042] According to a second aspect of the present invention, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a computer processor, the above method is implemented.
[0043] According to a third aspect of the present invention, a system for automatically extracting Android application data is provided, the system comprising:
[0044] Automation function detection module: configured to initiate a detection process to an Android device, wherein the detection process is used to detect whether the Android device supports automation;
[0045] If yes, first label the Android device with an automation tag, and then jump to S3;
[0046] If not, first mark the Android device with a semi-automatic tag and send the automated application to the Android device for installation, and then jump to the automated auxiliary module;
[0047] Automation auxiliary module: configured to start the automation application after installation, and then enable the automation auxiliary service for the Android device to support automation, and execute the application configuration information conversion module when the Android device enters the automation environment;
[0048] An application configuration information conversion module: configured to convert the data packet name of the configuration information of the application in the Android device to generate an application name list, place the application name list into the device directory of the Android device, and establish a correspondence between the data packet name and the name of the application; wherein the application name list includes options for automatic selection;
[0049] Accessibility service configuration module: configured to obtain the value of the data space of the application in the Android device, taking the maximum value of the value of the data space as the detection parameter, and defining the operation action of the accessibility service by configuring the ACTION command and configuring the execution action;
[0050] Accessibility service running module: configured to start various processes of the accessibility service and enable the Android device to perform automatic backup by sending an automated action configuration instruction, the list of application names to be backed up, and required parameters to the Android device;
[0051] An automated progress detection module is configured to monitor the completion progress of the automated backup using the detection parameters during the execution of the automated backup.
[0052] The present invention performs pre-processing by initially detecting whether the automation support rate is high or not, and then sends an abstract configuration instruction protocol to the auxiliary service process for execution, so as to support the automatic execution of the system's built-in backup application data flow for mobile phones of different brands and versions, support unified automatic detection of the backup process progress, and achieve automatic data extraction. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated into and constitute a part of this specification. The accompanying drawings illustrate the embodiments and together with the description are used to explain the principles of the present invention. Other embodiments and many expected advantages of the embodiments will be readily appreciated as they become better understood by reference to the following detailed description. Other features, objects and advantages of the present application will become more apparent by reading the detailed description of the non-limiting embodiments made with reference to the following drawings:
[0054] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;
[0055] Figure 2 is a flow chart of a method for automatically extracting Android application data according to an embodiment of the present invention;
[0056] Figure 3 It is a framework diagram of a system for automatically extracting Android application data according to an embodiment of the present invention;
[0057] Figure 4 It is a structural diagram of a computer system suitable for implementing an electronic device of an embodiment of the present application. DETAILED DESCRIPTION
[0058] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It should also be noted that, for ease of description, only the parts related to the relevant invention are shown in the accompanying drawings.
[0059] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0060] Figure 1 An exemplary system architecture 100 is shown to which an automatic method for extracting Android application data according to an embodiment of the present application can be applied.
[0061] like Figure 1As shown, the system architecture 100 may include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0062] Users can use terminal devices 101, 102, 103 to interact with server 105 through network 104 to receive or send messages, etc. Various applications can be installed on terminal devices 101, 102, 103, such as data processing applications, data visualization applications, web browser applications, etc.
[0063] Terminal devices 101, 102, 103 can be hardware or software. When terminal devices 101, 102, 103 are hardware, they can be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, etc. When terminal devices 101, 102, 103 are software, they can be installed in the electronic devices listed above. They can be implemented as multiple software or software modules (for example, software or software modules used to provide distributed services), or they can be implemented as a single software or software module. No specific limitation is made here.
[0064] The server 105 may be a server that provides various services, such as a background information processing server that provides support for the automation tags displayed on the terminal devices 101, 102, and 103. The background information processing server may process the acquired configuration information and generate a processing result (such as an application name list).
[0065] It should be noted that the method provided in the embodiment of the present application can be executed by the server 105, and can also be executed by the terminal devices 101, 102, 103. The corresponding device is generally set in the server 105, and can also be set in the terminal devices 101, 102, 103.
[0066] It should be noted that the server can be hardware or software. When the server is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or it can be implemented as a single server. When the server is software, it can be implemented as multiple software or software modules (for example, software or software modules used to provide distributed services), or it can be implemented as a single software or software module. No specific limitation is made here.
[0067] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.
[0068] According to an embodiment of the present invention, a method for automatically extracting Android application data is provided. Figure 2 FIG. 1 is a flow chart showing a method for automatically extracting Android application data according to an embodiment of the present invention. Figure 2 As shown, the method comprises the following steps:
[0069] S1: Initiate a detection process to an Android device, wherein the detection process is used to detect whether the Android device supports automation;
[0070] If yes, first label the Android device with an automation tag, and then jump to S3;
[0071] If not, first mark the Android device with a semi-automatic tag and send the automated application to the Android device for installation, and then jump to S2.
[0072] In a specific embodiment, the detection process includes:
[0073] Based on the Android accessibility service, a specific area of the screen is clicked, and the execution result is obtained through user perception to determine whether the Android device supports automation capabilities.
[0074] S2: After installation, the automation application is started, and then the automation auxiliary service is enabled for the Android device to support automation. When the Android device enters the automation environment, S3 is executed.
[0075] S3: Convert the data packet name of the configuration information of the application in the Android device to generate an application name list, place the application name list into the device directory of the Android device, and establish a correspondence between the data packet name and the name of the application; wherein the application name list includes options used for automatic checking.
[0076] S4: Obtain the value of the data space of the application in the Android device, use the maximum value of the value of the data space as a detection parameter, and define the operation action of the accessibility service by configuring an ACTION command and configuring an execution action.
[0077] In a specific embodiment, the operation action of the accessibility service is defined by configuring the ACTION command and configuring the execution action, specifically including:
[0078] The action type of the ACTION command and the execution action type of the accessibility service are configured using a text protocol; wherein the text protocol records the abstraction of automated behaviors required for automated backup of Android devices of different brands;
[0079] The operation action of the barrier-free service is configured as follows: when the automation step is executed, the text protocol is packaged into configuration instructions and sent to the Android device.
[0080] In a specific embodiment, the action type of the ACTION command includes: an execution element unique identifier, an execution action type, and a delay.
[0081] In a specific embodiment, the execution action types of the accessibility service include: opening a specified page, clicking, scrolling, returning to the main desktop, and sliding.
[0082] In a specific embodiment, the method of obtaining the value of the data space of the application in the Android device includes:
[0083] The system API interface is read according to the configuration information of the application in the Android device, so as to obtain the value of the data space of the corresponding application in the Android device.
[0084] S5: By sending an automatic action configuration instruction, the application name list that needs to be backed up, and required parameters to the Android device, various processes of the accessibility service are started and the Android device is instructed to perform automatic backup.
[0085] In a specific embodiment, the various processes of the barrier-free service specifically include:
[0086] Parsing the automation action configuration instructions and entering the automation step;
[0087] When the specified page is opened by reading the initial ACTION command and entering the backup page of the Android device, the application name list to be backed up is read to match the LIST entry element of the current page, and the ACTION action is executed according to the matching result;
[0088] Further read ACTION, match ACTION to execute the automatic backup;
[0089] The read end ACTION and the matching ACTION are used to monitor the completion progress of the automated backup.
[0090] In a specific embodiment, the reading of the application name list to be backed up is used to match the LIST entry element of the current page, and the ACTION action is performed according to the matching result. The specific steps include:
[0091] Match the LIST entry elements with the contents of the application name list one by one;
[0092] If the match is successful, an ACTION action is performed on the API of the accessibility service to check the name element node on the page, and the matched application name is removed from the application name list until all application names are removed, indicating that the ACTION action has been completed;
[0093] If the match fails, record the name NODE1 of the node at the bottom of the LIST item element of the current page, obtain the screen position coordinate POS1, use the API of the accessibility service to scroll one screen height distance, and re-obtain the name NODE2 of the node at the bottom of the LIST item element of the current page, obtain the screen position coordinate POS2, determine the relationship between NODE1 and NODE2 and between POS1 and POS2, and execute corresponding ACTION actions based on the relationship.
[0094] In a specific embodiment, the specific example of executing the corresponding ACTION action according to the above relationship is as follows:
[0095] If NODE1 is not equal to NODE2 or POS1 is not equal to POS2, it means that the LIST page has not reached the bottom, and the step of matching the application name list with the LIST entry elements is repeated. If NODE1 is equal to NODE2 and POS1 is equal to POS2, it means that the LIST page has reached the bottom, and the number of repetitions is recorded. If the number of scrolling exceeds the preset number, it means that the ACTION action has been completed.
[0096] In a specific embodiment, during the automatic backup process, if the application name list does not exist or the LIST entry element is zero, the automatic backup is terminated.
[0097] S6: During the process of executing the automatic backup, the detection parameter is used to monitor the completion progress of the automatic backup.
[0098] In a specific embodiment, the use of the detection parameters to monitor the completion progress of the automated backup includes the following specific steps:
[0099] Obtain the size of the backup directory specified in the automatic backup at the initial moment;
[0100] Specify scanning the backup directory once at a certain interval;
[0101] If the size of the backup directory does not change during the N consecutive scans, it means that the automatic backup is finished;
[0102] Wherein N=(the detection parameter / 1024 / 1024+1)*2.
[0103] In a specific embodiment, the automatic extraction of Android application data of the present invention includes the following operations:
[0104] 1. The device is connected to the Android device. The first step is to detect the automation capability. The detection process is initiated to the Android device. For devices that support automation capabilities, the device is labeled "automated". For devices that do not support automation capabilities, the device is labeled "semi-automated". The automation application is sent to the device for installation. After the application is started, the barrier-free service is enabled to enter the automation environment.
[0105] 2. For devices that do not support automation capabilities, the Android device will perform a second automation capability test after enabling the accessibility service and entering the automation environment. When it detects that the accessibility service process is enabled, it will send "automation" back to the device, and the device will be labeled "automation";
[0106] 3. This solution uses Android accessibility services to click on specific areas of the screen and obtain execution results without user perception to determine whether full automation is supported;
[0107] 4. In order to support the selection of the system's own backup application, the application configuration information needs to be converted into a program name configuration table and placed in the device directory, and a one-to-one correspondence between the package name and the application name needs to be established;
[0108] 5. In order to automatically detect the backup directory space size scanning interval, it is necessary to read the system API interface according to the application configuration information to obtain the corresponding application data space size on the device, and take the maximum value MaxSize as the parameter for subsequent detection of backup completion progress;
[0109] 6. The device forms a list of application names that need to be automatically checked based on the application configuration information. If it is invalid, the automatic backup ends;
[0110] 7. Define configurable commands for accessibility service operation actions. The commands consist of a string of text protocols. The text records the abstract behaviors that need to be automated for different brands of mobile phones. The device packages the configuration instructions and sends them to the Android device to guide the execution of the automation steps:
[0111] Table 1
[0112] Initial Action ACTION ACTION ACTION … End ACTION
[0113] The ACTION action type definition is shown in Table 2:
[0114] Table 2
[0115] Execution element unique identifier Execution action type Delay S
[0116] The execution action types include some main automated behavior actions as shown in Table 3:
[0117] Table 3
[0118] Open the specified page Click scroll Back to the main desktop slide …
[0119] 8. The device sends the automation operation abstract action configuration command and the application name list to be backed up and other parameters to the Android device, and starts the Android accessibility service process;
[0120] 9. The Android accessibility service process parses the automation action configuration command and performs the automation execution steps;
[0121] 10. When the Android accessibility service process reads the initial ACTION command to open the specified page and enter the built-in backup page of the Android device, it reads the application name list that needs to be backed up and matches the LIST entry elements of the current page, and matches the entry elements to the application name list one by one. If a match is found, the Android accessibility service API executes the ACTION action to check the name element node on the page and remove the matching name from the application name list until all application names are removed, completing the ACTION action;
[0122] 11. The current page element cannot match the application name list, record the bottom node name NODE1 of the page element, obtain the screen position coordinate POS1 of NODE1, use the barrier-free service API to scroll 1 screen height distance, and re-obtain the bottom node name NODE2 of the page element, obtain the screen position coordinate POS2 of NODE2, if NODE1 is not equal to NODE2 or POS1 is not equal to POS2, it means that the LIST page has not reached the bottom, repeat the application name list matching LIST entry element step in 10 (at this time, the LIST entry has changed because the screen has been scrolled); if they are the same, it means that the LIST page has reached the bottom, record the number of repetitions, and when the number of repetitions exceeds the preset number MAX, complete the ACTION action;
[0123] 12. The Android accessibility service process further reads the ACTION and matches the ACTION to perform the backup execution task;
[0124] 13. The Android accessibility service process reads the end ACTION and matches the ACTION to monitor the progress of the backup task;
[0125] 14. Further start the built-in backup progress detection service, and its progress completion feature is to determine that the size of the backup directory space has not changed for multiple consecutive times. The specific steps are to initially obtain the specified backup directory size, scan it once every 5 seconds, and if there is no change after N consecutive scans, it means the backup is complete. Where N = (MaxSize / 1024 / 1024+1)*2;
[0126] Figure 3 The framework diagram of an automatic Android application data extraction system according to an embodiment of the present invention is shown. The system includes an automatic function detection module 301, an automatic auxiliary module 302, an application configuration information conversion module 303, an accessibility service configuration module 304, an accessibility service operation module 305 and an automatic progress detection module 306.
[0127] In a specific embodiment, the automation function detection module 301 is configured to initiate a detection process to the Android device, wherein the detection process is used to detect whether the Android device supports automation;
[0128] If yes, first label the Android device with an automation tag, and then jump to S3;
[0129] If not, first mark the Android device with a semi-automatic tag and send the automated application to the Android device for installation, and then jump to the automated auxiliary module;
[0130] The automation assistance module 302 is configured to start the automation application after installation, and then enable the automation assistance service for the Android device to support automation, and execute the application configuration information conversion module when the Android device enters the automation environment;
[0131] The application configuration information conversion module 303 is configured to convert the data packet name of the configuration information of the application in the Android device to generate an application name list, place the application name list into the device directory of the Android device, and establish a correspondence between the data packet name and the name of the application; wherein the application name list includes options for automatic selection;
[0132] The barrier-free service configuration module 304 is configured to obtain the value of the data space of the application in the Android device, take the maximum value of the value of the data space as the detection parameter, and define the operation action of the barrier-free service by configuring the ACTION command and configuring the execution action;
[0133] The barrier-free service running module 305 is configured to start various processes of the barrier-free service and enable the Android device to perform automatic backup by sending an automatic action configuration instruction, the application name list to be backed up, and required parameters to the Android device;
[0134] The automatic progress detection module 306 is configured to monitor the completion progress of the automatic backup using the detection parameters during the execution of the automatic backup.
[0135] This system performs pre-processing by initially detecting whether the automation support rate is high or not, and then sends an abstract configuration instruction protocol to the auxiliary service process for execution, so as to support the automatic execution of the system's built-in backup application data flow for mobile phones of different brands and versions, support unified automatic detection of the backup process progress, and achieve automated data extraction.
[0136] Reference below Figure 4 , which shows a schematic diagram of the structure of a computer system 400 suitable for implementing an electronic device of an embodiment of the present application. Figure 4 The electronic device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0137] like Figure 4 As shown, the computer system 400 includes a central processing unit (CPU) 401, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage part 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the system 400 are also stored. The CPU 401, the ROM 402, and the RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0138] The following components are connected to the I / O interface 405: an input section 406 including a keyboard, a mouse, etc.; an output section 407 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN card, a modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the I / O interface 405 as needed. A removable medium 411, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 410 as needed, so that a computer program read therefrom is installed into the storage section 408 as needed.
[0139] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 409, and / or installed from the removable medium 411. When the computer program is executed by the central processing unit (CPU) 401, the above functions defined in the method of the present application are executed. It should be noted that the computer-readable storage medium described in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection with one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable storage medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wireless, wireline, optical cable, RF, etc., or any suitable combination of the foregoing.
[0140] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0141] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0142] The modules involved in the embodiments described in the present application may be implemented by software or hardware. The units described may also be arranged in a processor, and the names of these units do not constitute limitations on the units themselves in certain circumstances.
[0143] An embodiment of the present invention further relates to a computer-readable storage medium having a computer program stored thereon, which implements the method described above when the computer program is executed by a computer processor. The computer program includes program code for executing the method shown in the flowchart. It should be noted that the computer-readable medium of the present application may be a computer-readable signal medium or a computer-readable medium or any combination of the above two.
[0144] The present invention performs pre-processing by initially detecting whether the automation support rate is high or not, and then sends an abstract configuration instruction protocol to the auxiliary service process for execution, so as to support the automatic execution of the system's own backup application data flow for mobile phones of different brands and versions, and supports unified automatic detection of the backup process progress to achieve automatic data extraction. The present invention can more conveniently get rid of manual intervention to automatically extract application data, supports multi-channel parallel extraction, and can realize one-click electronic evidence collection for the electronic evidence collection industry, or even dozens of channels of automatic parallel evidence collection at the same time, which greatly facilitates the electronic evidence collection steps and improves efficiency.
[0145] The above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above invention concept. For example, the above features are replaced with the technical features with similar functions disclosed in this application (but not limited to) by each other to form a technical solution.
Claims
1. A method for automatically extracting Android application data, characterized in that: The following steps are involved: S1: Initiate a detection process to an Android device, wherein the detection process is used to detect whether the Android device supports automation; If yes, first label the Android device with an automation tag, and then jump to S3; If not, first mark the Android device with a semi-automatic tag and send the automated application to the Android device for installation, and then jump to S2; S2: after installation, start the automation application, then enable the accessibility service for the Android device to support automation, and execute S3 after the Android device enters the automation environment; S3: converting the data packet name of the configuration information of the application in the Android device to generate an application name list, placing the application name list into the device directory of the Android device, and establishing a corresponding relationship between the data packet name and the name of the application; wherein the application name list includes options for automatic checking; S4: obtaining the value of the data space of the application in the Android device, taking the maximum value of the value of the data space as the detection parameter, and defining the operation action of the accessibility service by configuring the ACTION command and configuring the execution action; S5: starting various processes of the accessibility service and instructing the Android device to perform automatic backup by sending an automatic action configuration instruction, the list of application names to be backed up, and required parameters to the Android device; S6: During the process of executing the automatic backup, the detection parameter is used to monitor the completion progress of the automatic backup.
2. The method according to claim 1, characterized in that The detection process includes: Based on the Android accessibility service, a specific area of the screen is clicked, and the execution result is obtained through user perception to determine whether the Android device supports automation capabilities.
3. The method according to claim 1, characterized in that The operation actions of the accessibility service are defined by configuring the ACTION command and configuring the execution action, specifically including: The action type of the ACTION command and the execution action type of the accessibility service are configured using a text protocol; wherein the text protocol records the abstraction of automated behaviors required for automated backup of Android devices of different brands; The operation action of the barrier-free service is configured as follows: when the automation step is executed, the text protocol is packaged into configuration instructions and sent to the Android device.
4. The method according to claim 1, characterized in that: The various processes of the accessibility service specifically include: Parsing the automation action configuration instructions and entering the automation step; When the specified page is opened by reading the initial ACTION command and entering the backup page of the Android device, the list of application names to be backed up is read to match the LIST entry element of the current page, and the ACTION action is executed according to the matching result; Further read ACTION, match ACTION to execute the automatic backup; The read end ACTION and the matching ACTION are used to monitor the completion progress of the automated backup.
5. The method according to claim 4, characterized in that The reading of the application name list to be backed up is used to match the LIST entry element of the current page, and the execution of the ACTION action according to the matching result, specifically comprising the following steps: Match the LIST entry elements with the contents of the application name list one by one; If the match is successful, an ACTION action is performed on the API of the accessibility service to check the name element node on the page, and the matched application name is removed from the application name list until all application names are removed, indicating that the ACTION action has been completed; If the match fails, record the name NODE1 of the node at the bottom of the LIST item element of the current page, obtain the screen position coordinate POS1 of NODE1, use the API of the accessibility service to scroll one screen height distance, and re-obtain the name NODE2 of the node at the bottom of the LIST item element of the current page, obtain the screen position coordinate POS2 of NODE2, determine the relationship between NODE1 and NODE2 and between POS1 and POS2, and execute corresponding ACTION actions according to the relationship.
6. The method according to claim 1, characterized in that The step of monitoring the completion progress of the automatic backup by using the detection parameters specifically includes: Obtain the size of the backup directory specified in the automatic backup at the initial moment; Specify scanning the backup directory once at a certain interval; If the size of the backup directory does not change during the N consecutive scans, it means that the automatic backup is finished; Wherein N=(the detection parameter / 1024 / 1024+1)*2.
7. The method according to claim 1, characterized in that The method of obtaining the value of the data space of the application in the Android device includes: The system API interface is read according to the configuration information of the application in the Android device, so as to obtain the value of the data space of the corresponding application in the Android device.
8. The method according to claim 3, characterized in that The action type of the ACTION command includes: a unique identifier of an execution element, an execution action type, and a delay.
9. The method according to claim 3, characterized in that: The execution action types of the accessibility service include: opening a specified page, clicking, scrolling, returning to the main desktop, and sliding.
10. The method according to claim 4, characterized in that During the automatic backup process, if the application name list does not exist or the LIST entry element is zero, the automatic backup is terminated.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a computer processor, the method according to any one of claims 1 to 10 is implemented.
12. A system for automatically extracting Android application data, characterized in that: include: Automation function detection module: configured to initiate a detection process to an Android device, wherein the detection process is used to detect whether the Android device supports automation; If yes, first label the Android device with an automation tag, and then jump to S3; If not, first mark the Android device with a semi-automatic tag and send the automated application to the Android device for installation, and then jump to the automated auxiliary module; Automation auxiliary module: configured to start the automation application after installation, and then enable barrier-free service for the Android device to support automation, and execute the application configuration information conversion module when the Android device enters the automation environment; An application configuration information conversion module: configured to convert the data packet name of the configuration information of the application in the Android device to generate an application name list, place the application name list into the device directory of the Android device, and establish a correspondence between the data packet name and the name of the application; wherein the application name list includes options for automatic selection; Accessibility service configuration module: configured to obtain the value of the data space of the application in the Android device, taking the maximum value of the value of the data space as the detection parameter, and defining the operation action of the accessibility service by configuring the ACTION command and configuring the execution action; Accessibility service running module: configured to start various processes of the accessibility service and enable the Android device to perform automatic backup by sending an automated action configuration instruction, the list of application names to be backed up, and required parameters to the Android device; An automated progress detection module is configured to monitor the completion progress of the automated backup using the detection parameters during the execution of the automated backup.
Citation Information
Patent Citations
Automatic test method and device, storage medium and electronic equipment
CN107704398A
A memory data forensics method based on Android platform automated test tool
CN109542788A