Apkfile

Android app analysis and feature extraction library

Cybersecurity & Ethical HackingJavaApache-2.0

Abstract

Apkfile is an open-source Cybersecurity & Ethical Hacking project. Android app analysis and feature extraction library. ApkFile is a library which creates a representation of an APK composed of Java objects which can be easily inspected for analysis or serialized into JSON. The goal of the library is to provide a robust way to inspect hostile malware samples, but it's general purpose enough to be used for other stuff too. It is built using Java, Android, Machine Learning. The complete source code is publicly available on GitHub under the Apache License 2.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

ApkFile is a library which creates a representation of an APK composed of Java objects which can be easily inspected for analysis or serialized into JSON. The goal of the library is to provide a robust way to inspect hostile malware samples, but it's general purpose enough to be used for other stuff too.

This library and APKiD provide the machine learning feature extraction for Judge, an Android malware detection engine.

Below is the highly abbreviated output from the code above. A full version can be found here.

2. Objective

Android app analysis and feature extraction library

This project demonstrates how Java, Android, Machine Learning can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

JavaAndroidMachine Learning

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • JDK 11 or later
  • Maven / Gradle
  • IntelliJ IDEA, Eclipse or Android Studio
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/CalebFenton/apkfile.git
cd apkfile
  1. Android manifest
  2. Resources via modified & hardened ArscBlamer
  3. Signing certificate
  4. DEX files via dexlib2
  5. Classes, methods, etc.
  6. APK entries
ApkFile apkFile = new ApkFileFactory().build('ApiDemos.apk');
AndroidManifest androidManifest = apkFile.getAndroidManifest();
String packageName = androidManifest.getPackageName(); // com.example.android.apis

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by CalebFenton and published on GitHub under the Apache License 2.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship