信息通信技术与政策

信息通信技术与政策

信息通信技术与政策 ›› 2026, Vol. 52 ›› Issue (9): 88-96.doi: 10.12267/j.issn.2096-5931.2026.09.012

技术与标准 上一篇    

基于多特征分析的移动应用恶意热更新安全检测方法

A security detection method for malicious hot updates in mobile applications based on multi-feature analysis

王淞鹤1,2, 王艳红1,2, 李京典1,2, 桑明臣1,2   

  1. 1 中国信息通信研究院泰尔终端实验室, 北京 100191
    2 移动应用创新与治理技术工业和信息化部重点实验室, 北京 100191
  • 收稿日期:2026-01-12 出版日期:2026-09-25 发布日期:2026-09-30
  • 作者简介:
    王淞鹤,中国信息通信研究院泰尔终端实验室信息安全部、移动应用创新与治理技术工业和信息化部重点实验室工程师,主要从事移动应用软件安全、终端安全、个人信息保护等方面的研究工作;
    王艳红,中国信息通信研究院泰尔终端实验室信息安全部副主任、移动应用创新与治理技术工业和信息化部重点实验室高级工程师,主要从事移动互联网领域信息安全、个人信息保护、数据管理等方面的研究工作;
    李京典,中国信息通信研究院泰尔终端实验室信息安全部、移动应用创新与治理技术工业和信息化部重点实验室工程师,主要从事移动安全、个人信息保护等方面的研究工作;
    桑明臣,中国信息通信研究院泰尔终端实验室信息安全部、移动应用创新与治理技术工业和信息化部重点实验室工程师,主要从事移动智能终端及应用软件安全和个人信息保护检测等方面的研究工作

WANG Songhe1,2, WANG Yanhong1,2, LI Jingdian1,2, SANG Mingchen1,2   

  1. 1 CTTL Terminal Labs, China Academy of Information and Communications Technology, Beijing 100191, China
    2 Key Laboratory of Mobile Application Innovation and Governance Technology, Beijing 100191, China
  • Received:2026-01-12 Online:2026-09-25 Published:2026-09-30

摘要:

热更新技术常用于移动应用程序(Application,App)快速修复、轻量级更新等场景中,然而恶意开发者滥用热更新绕过应用商店安全审核,引发潜在安全风险。针对恶意热更新行为监测成本高、检测难度大、技术对抗严重等问题,提出一种多特征分析检测方法,对热更新代码控制流特征、运行时行为特征以及应用指纹特征进行综合分析。收集12 982款App及300款恶意样本进行试验分析,发现11款新增恶意App,共标记29个恶意家族。试验结果表明,该检测方法能够有效识别恶意热更新行为。

关键词: 移动应用安全, 恶意热更新, 一致性分析, 特征识别

Abstract:

Hot update technology is widely utilized in mobile applications for scenarios such as rapid patching and lightweight updates. However, malicious developers abuse this mechanism to bypass App store security audits, posing potential security risks. To address the challenges of high monitoring costs, significant detection difficulties, and intense technical adversarial confrontanion associated with malicious hot updates, this paper proposes a detection method based on multi-feature analysis. This method performs a comprehensive analysis of the control flow features of hot update code, runtime behavioral features, and application fingerprint features. This paper collected a total of 12 982 Apps and 300 malicious samples for experimental analysis, and identified 11 newly detected malicious Apps and 29 malware familes. Experimental results demonstrate that the proposed method can effectively identify malicious hot update behaviors.

Key words: mobile application security, malicious hot update, consistency analysis, feature recognition

中图分类号: