Information and Communications Technology and Policy

Information and Communications Technology and Policy

Information and Communications Technology and Policy ›› 2026, Vol. 52 ›› Issue (9): 88-96.doi: 10.12267/j.issn.2096-5931.2026.09.012

Previous Articles    

A security detection method for malicious hot updates in mobile applications based on multi-feature analysis

WANG Songhe1,2, WANG Yanhong1,2, LI Jingdian1,2, SANG Mingchen1,2   

  1. 1 CTTL Terminal Labs, China Academy of Information and Communications Technology, Beijing 100191, China
    2 Key Laboratory of Mobile Application Innovation and Governance Technology, Beijing 100191, China
  • Received:2026-01-12 Online:2026-09-25 Published:2026-09-30

Abstract:

Hot update technology is widely utilized in mobile applications for scenarios such as rapid patching and lightweight updates. However, malicious developers abuse this mechanism to bypass App store security audits, posing potential security risks. To address the challenges of high monitoring costs, significant detection difficulties, and intense technical adversarial confrontanion associated with malicious hot updates, this paper proposes a detection method based on multi-feature analysis. This method performs a comprehensive analysis of the control flow features of hot update code, runtime behavioral features, and application fingerprint features. This paper collected a total of 12 982 Apps and 300 malicious samples for experimental analysis, and identified 11 newly detected malicious Apps and 29 malware familes. Experimental results demonstrate that the proposed method can effectively identify malicious hot update behaviors.

Key words: mobile application security, malicious hot update, consistency analysis, feature recognition

CLC Number: