首页|基于网易云信IM框架的APK加解密取证方法

基于网易云信IM框架的APK加解密取证方法

扫码查看
在电信网络诈骗案件侦办过程中,尤其是在刷单、虚假投资理财、裸聊类案件中,APP及URL取证分析是网络侧勘查取证的重点.因需要在涉案APP中实现聊天、图片上传、语音等功能,基于IM框架二次开发的APP成了主流,其中网易云信IM是目前刷单诈骗案件中最为常见的第三方IM框架.但是随着犯罪分子不断隐匿作案手段,比如通过对APP的加密或对聊天内容的端对端加密,使得直接分析无法获取IM接口key值,或仅获取到加密后的乱码,无法查看聊天内容.基于此类案件,本文介绍了IM框架原理、APP及聊天内容加密技术与解密方法,通过对此类APP进行深入逆向分析和加密算法分析,可以充分提升刷单类诈骗案件的线索挖掘和勘查取证效率,为相关案件的侦破提供有力支撑.
Forensics Analysis of APK Encryption/Decryption Methods Based on NetEase Yunxing IM Framework
In the process of investigating telecommunication network fraud cases,especially in cases such as click farming,investment and financial management fraud and naked chat,APP and URL forensics analysis are the focus of network-side investigation.Because of the need to realize functions such as chatting,picture uploading and voice calling in the APP involved,the APP developed based on IM framework has become the mainstream,among which NetEase Yunxin IM is the most common third-party IM framework in the current fraud cases.However,as criminals continue to hide their means of committing crimes,for example,encrypting APPs or encrypting chat content end-to-end,direct analysis cannot obtain the key value of IM interface,or only the encrypted garbled code can be obtained,and chat content cannot be viewed.Based on this kind of cases,this paper introduces the principle of IM framework,the encryption technology and decryption method of APPs and chat content.Through in-depth reverse analysis and encryption algorithm analysis of this kind of APPs,the efficiency of clue mining and investigation and evidence collection of single fraud cases can be fully improved,which provides strong support for the detection of related cases.

digital forensicsAPK reverseAES decryptionclick farming fraudNetEase Yunxin IM

漏燕娣、郑青庚、计超豪、宋瑞坤

展开 >

浙江省公安厅刑侦总队,杭州 310000

温州市公安局刑事科学技术研究所,浙江 温州 325000

杭州平航科技有限公司,杭州 310051

数字取证 APK逆向 AES解密 刷单诈骗 网易云信IM

2024

刑事技术
公安部物证鉴定中心

刑事技术

CSTPCD
影响因子:0.315
ISSN:1008-3650
年,卷(期):2024.49(4)