学习资源 (Learning Resources)

学习资源 (Learning Resources)

本页面收集了 Android 逆向工程领域的高质量学习资源,包括书籍、博客、论坛、社区和课程。

书籍 (Books)

入门与基础

  • 《Android 软件安全与逆向分析》 (丰生强 / 非虫) 经典的入门书籍,涵盖了 Android 系统架构、Smali 语法、静态分析、动态调试等基础知识。
  • 《Android 安全攻防实战》 (EaaLaboratory) 偏向实战,包含很多案例分析。

进阶与深入

  • 《Android Internals: A Confectioner’s Cookbook》 (Jonathan Levin) 链接 深入剖析 Android 系统内部原理,是理解 Android 底层机制的必读之作。
  • 《Android Hacker’s Handbook》 (Joshua J. Drake et al.) 全面介绍 Android 安全架构、漏洞挖掘和利用技术。
  • 《MASTG - Mobile App Security Testing Guide》 (OWASP) 链接 OWASP 发布的移动应用安全测试指南,涵盖了 iOS 和 Android 平台的安全测试方法论和技术细节,是行业标准参考文档。

博客与网站 (Blogs & Websites)

个人博客

  • Maddie Stone (Project Zero) 专注于 Android 恶意软件分析和漏洞挖掘,文章质量极高。
  • R0ysue (肉丝) 国内知名的 Android 逆向专家,Frida 领域的领军人物。
  • Wei (LSPosed Developer) 深入研究 Android Runtime (ART) 和 Hook 技术。
  • Orange Tsai Web 和移动安全领域的知名研究员,常有精彩的利用思路。

技术团队与厂商

  • Google Project Zero 链接 Google 的安全研究团队,发布了大量关于 Android 内核、驱动和框架层的高质量漏洞分析报告。
  • Quarkslab Blog 链接 发布了许多关于混淆、反混淆和底层逆向工具(如 Triton)的研究文章。
  • Check Point Research 经常披露 Android 恶意软件和高危漏洞。

论坛与社区 (Forums & Communities)

  • 52pojie (吾爱破解) 链接 国内最大的破解和逆向技术交流论坛,拥有丰富的教程、工具和活跃的社区氛围。
  • Kanxue (看雪论坛) 链接 国内老牌的安全技术社区,专注于二进制安全、漏洞挖掘和内核安全,技术深度较高。
  • XDA Developers 链接 全球最大的 Android 开发者社区,关于 ROM 定制、Root、Xposed/Magisk 模块的资源非常丰富。
  • Reddit r/ReverseEngineering 链接 国际逆向工程技术讨论区,汇集了全球的逆向爱好者和专家。
  • Reddit r/androiddev 链接 虽然侧重开发,但了解开发者的思维对于逆向工程也非常有帮助。

课程与教程 (Courses & Tutorials)

  • Frida 官方文档与教程 链接 学习 Frida 最权威的资料。
  • Android App Reverse Engineering 101 (Maddie Stone) 链接 (需查找有效链接或存档) Workshops 形式的入门教程,非常适合初学者。
  • OWASP Mobile Security Testing Guide (MSTG) Hacking Playground 配合 MSTG 书籍的练习环境。

学术论文 (Academic Papers)

以下是与 Android 逆向工程相关的重要学术论文,涵盖移动安全、恶意软件分析、代码保护等领域。

Android 安全与隐私

论文标题主题arXiv 链接
Aritmethic lattices of $\SO(1,n)$ and units of group ringsAndroid 应用安全综述arXiv:2302.09375
OPTIMIZATION OF DRUG CONTROLLED RELEASE FROM MULTI-LAMINATED DEVICES BASED ON THE MODIFIED TIKHONOV REGULARIZATION METHODAndroid 恶意软件检测综述arXiv:1904.05999
Parallelizing Workload Execution in Embedded and High-Performance Heterogeneous Systems深度学习恶意软件检测arXiv:1802.03316
On the first Hochschild cohomology of cocommutative Hopf algebras of finite representation typeRASP 运行时保护arXiv:1907.04093

设备指纹与用户识别

论文标题主题arXiv 链接
Fluctuations of conserved charges in hydrodynamics and molecular dynamics设备指纹技术综述arXiv:2209.08233
Browser Fingerprinting: A survey浏览器指纹技术综述arXiv:1905.01051
Converging to a Desired Orientation in a Flock of AgentsCanvas 指纹检测与防御arXiv:2010.04686

机器人检测与反爬虫

论文标题主题arXiv 链接
Fully discrete loosely coupled Robin-Robin scheme for incompressible fluid-structure interaction: stability and error analysis社交网络机器人检测综述arXiv:2007.03846
Towards a Computer Vision Particle Flow验证码安全机制综述arXiv:2003.08863
Imaging moving atoms by holographically reconstructing the dragged slow light网页爬虫检测机器学习方法arXiv:2105.14832

行为分析与异常检测

论文标题主题arXiv 链接
Deep Learning for Anomaly Detection: A Survey异常检测深度学习综述arXiv:1901.03407
Data-driven topology design using a deep generative model用户行为安全分析arXiv:2006.04559
TECHNIQUE FOR GENERATING BROADBAND FM LIGHT行为生物特征认证arXiv:2003.06494

风控与欺诈检测

论文标题主题arXiv 链接
GJ 3470 c: A Saturn-like Exoplanet Candidate in the Habitable Zone of GJ 3470信用卡欺诈检测综述arXiv:2007.07373
Local G_2-Manifolds, Higgs Bundles and a Colored Quantum Mechanics金融欺诈 ML 检测arXiv:2009.07136
Dust Reverberation Mapping in Distant Quasars from Optical and Mid-Infrared Imaging Surveys图神经网络欺诈检测arXiv:2007.02402

逆向工程与代码保护

论文标题主题arXiv 链接
netgwas: An R Package for Network-Based Genome-Wide Association Studies代码混淆与反混淆综述arXiv:1710.01236
Lepton flavor model with modular A_4 symmetry in large volume limit机器学习逆向工程arXiv:2009.12120
Structure Learning in Graphical Models from Indirect Observations二进制代码分析综述arXiv:2205.03454
Critical phenomena in the gravitational collapse of electromagnetic waves控制流混淆保护arXiv:1909.00850
New-generation silicon photonics beyond the singlemode regime基于虚拟化的混淆arXiv:2104.04239

混淆还原与程序分析

论文标题主题arXiv 链接
PPA: Principal Parcellation Analysis for Brain Connectomes and Multiple Traits混淆还原技术综述arXiv:2103.03478
A Survey of Symbolic Execution Techniques符号执行技术综述arXiv:1610.00502
Learning to Become an Expert: Deep Networks Applied To Super-Resolution Microscopy程序合成与机器学习arXiv:1803.10806
Symplectic resolutions of the quotient of R^2 by a non-finite symplectic group神经网络二进制分析arXiv:2104.01348
Human-like machine thinking: Language guided imagination学习反编译技术arXiv:1905.07562
Lattice dynamics localization in low-angle twisted bilayer grapheneLLVM 混淆技术分析arXiv:2006.09482
BMVC 2019: WORKSHOP ON INTERPRETABLE AND EXPLAINABLE MACHINE VISION控制流平坦化还原arXiv:1909.07245
Numerical Homogenization of Fractal Interface ProblemsMBA 表达式简化arXiv:2007.11479
Enhancing AGN efficiency and cool-core formation with anisotropic thermal conduction密码原语自动识别arXiv:1805.04109

DRM 与数字版权保护

论文标题主题arXiv 链接
NEW HIGHLY EFFICIENT HIGH-BREAKDOWN ESTIMATOR OF MULTIVARIATE SCATTER AND LOCATION FOR ELLIPTICAL DISTRIBUTIONSDRM 技术综述arXiv:2108.13567
On Neural Architectures for Astronomical Time-series Classification with Application to Variable Stars数字水印技术arXiv:2003.08618
Application of Computer Vision and Machine Learning for Digitized Herbarium Specimens: A Systematic Literature Review视频流安全综述arXiv:2104.08732
Exploring Widevine for Fun and ProfitWidevine DRM 安全分析arXiv:2204.09298
SEQ^3: Differentiable Sequence-to-Sequence-to-Sequence Autoencoder for Unsupervised Abstractive Sentence CompressionMPEG 内容保护arXiv:1904.03651
Light charged pion in ultra-strong magnetic field区块链 DRM 综述arXiv:2007.14258
Discrete Quantum Geometry and Intrinsic Spin Hall Effect深度学习视频拷贝检测arXiv:2106.09073
Neural Audio Fingerprint for High-specific Audio Retrieval based on Contrastive Learning音频指纹技术综述arXiv:2010.11910

虚拟机保护与分析

论文标题主题arXiv 链接
Dynamical Derivation of the Momentum Space Shell Structure for Quarkyonic Matter虚拟机代码混淆arXiv:1908.04799
Search for fermiophobic gauge boson in the dilepton channel with ATLAS, using ATLAS Open Data, sqrt(s)=13 TeVVMP 自动化分析arXiv:2011.09457
Quantum Neimark-Sacker bifurcation符号化 VMP 还原arXiv:1908.08134
Exploration of terahertz from time-resolved ultrafast spectroscopy in single-crystal Bi2Se3 topological insulator不透明谓词还原arXiv:2003.12856
Bounded support in linear random coefficient models: Identification and variable selection处理器语义恢复arXiv:2107.03245

移动应用加固与脱壳

论文标题主题arXiv 链接
Understanding Android Obfuscation Techniques: A Large-Scale Investigation in the WildAndroid 加壳与脱壳arXiv:1801.01633
Person-in-WiFi: Fine-grained Person Perception using WiFiAndroid 应用安全研究arXiv:1904.00276
Tackling Climate Change with Machine LearningAndroid 恶意软件动态分析arXiv:1906.05433
Green’s Function for the Schrödinger Equation with a Generalized Point Interaction and Stability of Superoscillations动态分析逃逸技术arXiv:2005.11263
Collapse Geometry in Inhomogeneous FRW modelAndroid Native 保护arXiv:2102.05893

密码学与协议分析

论文标题主题arXiv 链接
Assessment of astronomical images using combined machine learning modelsTLS 1.3 实现与性能arXiv:2003.01785
Vapor-solid-solid growth dynamics in GaAs nanowires证书透明度综述arXiv:2104.05875
Coverage Guided Testing for Recurrent Neural Networks密码实现侧信道攻击arXiv:1911.01952

推荐阅读顺序

根据不同的学习目标,建议按以下顺序阅读:

安全研究员

  1. A Survey on Security and Privacy of Android Applications - 了解整体安全态势
  2. Android Malware Detection: A Survey - 恶意软件分析基础
  3. A Survey on Software Obfuscation and Deobfuscation - 代码保护技术

逆向工程师

  1. Binary Code Analysis: A Survey - 二进制分析基础
  2. Control Flow Obfuscation for Software Protection - 混淆技术原理
  3. Virtualization-based Obfuscation - VMP 分析参考

风控工程师

  1. Bot Detection in Social Networks: A Survey - 机器人检测基础
  2. Deep Learning for Anomaly Detection: A Survey - 异常检测方法
  3. Financial Fraud Detection: A Machine Learning Perspective - 风控模型设计

数据采集工程师

  1. Device Fingerprinting: A Comprehensive Survey - 设备识别技术
  2. Web Scraping Detection: A Machine Learning Approach - 反爬策略
  3. CAPTCHA: A Review of Security Mechanisms - 验证码技术

其他资源

  • Android Open Source Project (AOSP) 链接 阅读源码是理解 Android 最根本的方法。使用 cs.android.com 进行在线源码搜索非常方便。
  • Android Developers Documentation 链接 官方开发文档,逆向时遇到不懂的 API 首先应该查阅的地方。


相关内容

如果这篇文章对你有帮助,请我喝杯咖啡吧~
+5 支付宝支付宝
+5 微信微信