一种恶意安卓虚拟化应用程序检测方法
By combining static and dynamic analysis methods, the APK file is reverse-compiled and control flow graphs and data flow graphs are constructed to detect sensitive permissions and API calls. This solves the problem of inaccurate detection of malicious Android virtualization programs in existing technologies and achieves higher detection accuracy and comprehensiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHONGQING UNIV OF POSTS & TELECOMM
- Filing Date
- 2023-12-22
- Publication Date
- 2026-07-17
AI Technical Summary
Existing methods for detecting malicious Android virtualization programs are ineffective at accurately identifying malicious features and the detection results are unsatisfactory, especially for detecting various types of virtualization programs.
By combining static and dynamic analysis methods, the application decompiles APK files, extracts plugin paths, constructs control flow graphs and data flow graphs, analyzes the user interface, detects sensitive permissions and API calls, and comprehensively judges the malicious attributes of the application.
It improves the accuracy and comprehensiveness of detecting malicious Android virtualization applications, enabling it to detect malicious behavior at runtime, capture easily overlooked malicious features, and enhance the comprehensiveness and accuracy of detection.
Smart Images

Figure CN117763548B_ABST