Android penetration method and device for implementing silent installation based on accessibility services

US11960869B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11960869-B2
Application numberUS-202217568744-A
CountryUS
Kind codeB2
Filing dateJan 5, 2022
Priority dateNov 20, 2019
Publication dateApr 16, 2024
Grant dateApr 16, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An Android penetration method and device for implementing silent installation based on accessibility services. The method includes: acquiring a second target application by adding a load program to a first target application and adding penetration permissions using an Android decompilation technology; and implementing silent installation of the second target application using an accessibility service technology.

First claim

Opening claim text (preview).

What is claimed is: 1. An Android penetration method for implementing silent installation based on accessibility services, comprising: acquiring a second target application by adding a load program to a first target application and adding penetration permissions using an Android decompilation technology; and implementing the silent installation of the second target application using an accessibility service technology; wherein implementing the silent installation of the second target application using the accessibility service technology comprises steps: declaring accessibility service permissions through accessibility management service configuration; acquiring controllable information of an interactive interface by monitoring a package name of the second target application through accessibility service Info configuration; searching for predefined text content in the interactive interface through a User Interface (UI) exploration, and determining whether a control carrying the text content is the control required for the silent installation, and if so, simulating a user click operation for the silent installation; and sending a second application installation request to a smart terminal through transfer in an accessibility manager, so that the smart terminal implements the silent installation based on the required control. 2. The Android penetration method for implementing the silent installation based on the accessibility services according to claim 1 , further comprising a step of overwriting Metasploit's reverse Transmission Control Protocol (TCP) connection session, wherein the step of overwriting the Metasploit's reverse TCP connection session comprises: implementing the silent installation of the second target application periodically by adding a timing manager, and enabling a penetration load in the second target application to enter a destruction operation program; rewriting the destruction operation program in a service class, and realizing an onDestroy self-start function of the silent installation of the second target application through a disconnected and re-established event definition; and restarting the second target application at a set time interval based on a shell script according to the onDestroy self-start function. 3. The Android penetration method for implementing the silent installation based on the accessibility services according to claim 1 , wherein in the step of declaring the accessibility service permissions through the accessibility management service configuration, includes accessibility auxiliary function permissions which are declared by using a BIND method, and a terminal system is capable of binding the accessibility services. 4. The Android penetration method for implementing the silent installation based on the accessibility services according to claim 1 , wherein in the step of acquiring controllable information of an interactive interface by monitoring a package name of the second target application through accessibility service Info configuration, the package name of the second application is monitored, a node object instance of Info is acquired using root node query or a traceability query method, and the node object instance is used as a UI node of an event; an accessibility service class is rewritten to monitor changes in an interface of a mobile smart terminal and then trigger a callback function to acquire controllable information of the UI.

Assignees

Inventors

Classifications

  • G06F8/61Primary

    Installation · CPC title

  • Decompilation; Disassembly · CPC title

  • Execution arrangements for user interfaces · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11960869B2 cover?
An Android penetration method and device for implementing silent installation based on accessibility services. The method includes: acquiring a second target application by adding a load program to a first target application and adding penetration permissions using an Android decompilation technology; and implementing silent installation of the second target application using an accessibility s…
Who is the assignee on this patent?
Univ Guangzhou
What technology area does this patent fall under?
Primary CPC classification G06F8/61. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 16 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).