Onn Shehory

138 papers A* 5A 19B 4C 3Journal 30Unranked 56
YearRankTypeTitle / Venue / Authors
2023 J jnl
J. Medical Syst.
Orel Babayoff, Onn Shehory, Shamir Geller, Chen Shitrit-Niselbaum, Ahuva Weiss-Meilik, Eli Sprecher
2023 J jnl
Health Informatics J.
Elad Avizohar, Onn Shehory
2023 J jnl
Empir. Softw. Eng.
Andrea Stocco, Onn Shehory, Gunel Jahangirova, Vincenzo Riccio, Guy Barash, Eitan Farchi, Diptikalyan Saha
2022 J jnl
CoRR
Samuel Ackerman, Eitan Farchi, Orna Raz, Onn Shehory
2021 J jnl
CoRR
Guy Barash, Eitan Farchi, Sarit Kraus, Onn Shehory
2021 C conf
VECoS
Youcef Sklab, Samir Aknine, Onn Shehory, Hanane Ariouat
2021 B conf
ICTAI
Douae Ahmadoun, Elise Bonzon, Cédric Buron, Pavlos Moraitis, Pierre Savéant, Onn Shehory
2020 J jnl
Eng. Appl. Artif. Intell.
Youcef Sklab, Samir Aknine, Onn Shehory, Abdelkamel Tari
2020 J jnl
AI Mag.
Grace Bang, Guy Barash, Ryan Beal, Jacques Calì, Mauricio Castillo-Effen, Xin Cynthia Chen, Niyati Chhaya, Rachel Cummings, Rohan Dhoopar, Sebastijan Dumancic, Huáscar Espinoza, Eitan Farchi, Ferdinando Fioretto, Raquel Fuentetaja, Christopher William Geib, Odd Erik Gundersen, José Hernández-Orallo, Xiaowei Huang, Kokil Jaidka, Sarah Keren, Seokhwan Kim, Michel Galley, Xiaomo Liu, Tyler Lu, Zhiqiang Ma, Richard Mallah, John A. McDermid, Martin Michalowski, Reuth Mirsky, Seán Ó hÉigeartaigh, Deepak Ramachandran, Javier Segovia-Aguas, Onn Shehory, Arash Shaban-Nejad, Vered Shwartz, Siddharth Srivastava, Kartik Talamadupula, Jian Tang, Pascal Van Hentenryck, Dell Zhang, Jian Zhang
2019 J jnl
IEEE Trans. Knowl. Data Eng.
Inbal Yahav, Onn Shehory, David G. Schwartz
2019 J jnl
CoRR
Eitan Farchi, Onn Shehory, Guy Barash
2019 J jnl
AI Mag.
Guy Barash, Mauricio Castillo-Effen, Niyati Chhaya, Peter Clark, Huáscar Espinoza, Eitan Farchi, Christopher W. Geib, Odd Erik Gundersen, Seán Ó hÉigeartaigh, José Hernández-Orallo, Chiori Hori, Xiaowei Huang, Kokil Jaidka, Pavan Kapanipathi, Sarah Keren, Seokhwan Kim, Marc Lanctot, Danny Lange, Julian J. McAuley, David R. Martinez, Marwan Mattar, Mausam, Martin Michalowski, Reuth Mirsky, Roozbeh Mottaghi, Joseph C. Osborn, Julien Pérolat, Martin Schmid, Arash Shaban-Nejad, Onn Shehory, Biplav Srivastava, William W. Streilein, Kartik Talamadupula, Julian Togelius, Koichiro Yoshino, Quanshi Zhang, Imed Zitouni
2018 conf
CNIA+RJCIA
Ndeye Arame Diago, Samir Aknine, Onn Shehory, Mbaye Séne
2018 J jnl
AI Mag.
Bruno Bouchard, Kevin Bouchard, Noam Brown, Niyati Chhaya, Eitan Farchi, Sébastien Gaboury, Christopher W. Geib, Amelie Gyrard, Kokil Jaidka, Sarah Keren, Roni Khardon, Parisa Kordjamshidi, David R. Martinez, Nicholas Mattei, Martin Michalowski, Reuth Mirsky, Joseph C. Osborn, Cem Sahin, Onn Shehory, Arash Shaban-Nejad, Amit P. Sheth, Ilan Shimshoni, Howard E. Shrobe, Arunesh Sinha, Atanu R. Sinha, Biplav Srivastava, William W. Streilein, Georgios Theocharous, K. Brent Venable, Neal Wagner, Anna Zamansky
2017 B conf
ICTAI
Ndeye Arame Diago, Samir Aknine, Sarvapali D. Ramchurn, Onn Shehory, Mbaye Sene
2017 conf
HUMANIZE@IUI
Rachel Yahel Halfon, Onn Shehory, David G. Schwartz
2016 B conf
ICTAI
Ndeye Arame Diago, Samir Aknine, Onn Shehory, Souhila Arib, Romain Caillière, Mbaye Sene
2016 ed.
MATES
Matthias Klusch, Rainer Unland, Onn Shehory, Alexander Pokahr, Sebastian Ahrndt
2015 conf
WI-IAT (2)
Pascal Francois Faye, Samir Aknine, Mbaye Sene, Onn Shehory
2015 J jnl
Auton. Agents Multi Agent Syst.
Yinon Nahum, David Sarne, Sanmay Das, Onn Shehory
2014 ch.
Agent-Oriented Software Engineering
Onn Shehory, Arnon Sturm
2014 conf
GDN
Pascal Francois Faye, Samir Aknine, Onn Shehory, Mbaye Sene
2014 ed.
AMEC/TADA
Sofia Ceppi, Esther David, Verdan Podobnik, Valentin Robu, Onn Shehory, Sebastian Stein, Ioannis A. Vetsikas
2014 book
Onn Shehory, Arnon Sturm
2014 ch.
Agent-Oriented Software Engineering
Arnon Sturm, Onn Shehory
2014 conf
CIbSE
Onn Shehory, Daniel Citron, Peter M. Kruse, Nelly Condori-Fernández, Tanja E. J. Vos, Bilha Mendelson
2014 conf
CSMR-WCRE
Tanja E. J. Vos, Paolo Tonella, Wishnu Prasetya, Peter M. Kruse, Alessandra Bagnato, Mark Harman, Onn Shehory
2014 ch.
Agent-Oriented Software Engineering
Onn Shehory, Arnon Sturm
2014 B conf
AINA
Pascal Francois Faye, Samir Aknine, Mbaye Sene, Onn Shehory
2014 ch.
Agent-Oriented Software Engineering
Arnon Sturm, Onn Shehory
2014 ch.
Agent-Oriented Software Engineering
Arnon Sturm, Onn Shehory
2013 ed.
AMEC/TADA
Esther David, Valentin Robu, Onn Shehory, Sebastian Stein, Andreas L. Symeonidis
2013 ed.
AMEC/TADA
Esther David, Christopher Kiekintveld, Valentin Robu, Onn Shehory, Sebastian Stein
2013 A conf
ESEM
Cu D. Nguyen, Bilha Mendelson, Daniel Citron, Onn Shehory, Tanja E. J. Vos, Nelly Condori-Fernández
2013 A ed.
AAMAS
Maria L. Gini, Onn Shehory, Takayuki Ito, Catholijn M. Jonker
2013 J jnl
Softw. Test. Verification Reliab.
Waldemar Hummer, Orna Raz, Onn Shehory, Philipp Leitner, Schahram Dustdar
2013 conf
FITTEST@ICTSS
Tanja E. J. Vos, Paolo Tonella, I. S. Wishnu B. Prasetya, Peter M. Kruse, Onn Shehory, Alessandra Bagnato, Mark Harman
2012 ed.
AMEC/TADA
Esther David, Kate Larson, Alex Rogers, Onn Shehory, Sebastian Stein
2012 A conf
AAMAS
Yinon Nahum, David Sarne, Onn Shehory, Sanmay Das
2012 ed.
Haifa Verification Conference
Kerstin Eder, João Lourenço, Onn Shehory
2012 A* conf
EC
Yinon Nahum, David Sarne, Sanmay Das, Onn Shehory
2011 A* conf
ICSE
Yoram Adler, Noam Behar, Orna Raz, Onn Shehory, Nadav Steindler, Shmuel Ur, Aviad Zlotnick
2011 A conf
ICST
Waldemar Hummer, Orna Raz, Onn Shehory, Philipp Leitner, Schahram Dustdar
2010 ed.
AMEC/TADA
Wolfgang Ketter, Han La Poutré, Norman M. Sadeh, Onn Shehory, William E. Walsh
2010 ed.
AMEC/TADA
Esther David, Enrico H. Gerding, David Sarne, Onn Shehory
2010 J jnl
IEEE Trans. Syst. Man Cybern. Part C
Arnon Sturm, Dov Dori, Onn Shehory
2010 conf
ICSE (2)
Maayan Goldstein, Onn Shehory, Rachel Tzoref-Brill, Shmuel Ur
2009 conf
Self-Healing and Self-Adaptive Systems
Artur Andrzejak, Kurt Geihs, Onn Shehory, John Wilkes
2009 conf
Self-Healing and Self-Adaptive Systems
Artur Andrzejak, Kurt Geihs, Onn Shehory, John Wilkes
2009 ed.
AMEC/TADA
John Collins, Peyman Faratin, Simon Parsons, Juan A. Rodríguez-Aguilar, Norman M. Sadeh, Onn Shehory, Elizabeth Sklar
2009 conf
Integrated Network Management
David Breitgand, Maayan Goldstein, Ealan Henis, Onn Shehory
2009 ed.
ICAC
Simon A. Dobson, John Strassner, Manish Parashar, Onn Shehory
2009 conf
Self-Healing and Self-Adaptive Systems
Onn Shehory, Josu Martinez, Artur Andrzejak, Cinzia Cappiello, Wlodzimierz Funika, Derrick Kondo, Leonardo Mariani, Benjamin Satzger, Markus Schmid
2009 ed.
Self-Healing and Self-Adaptive Systems
Artur Andrzejak, Kurt Geihs, Onn Shehory, John Wilkes
2008 J jnl
Artif. Intell.
Avi Rosenfeld, Gal A. Kaminka, Sarit Kraus, Onn Shehory
2008 A* conf
ASE
Mauro Caporuscio, Antinisca Di Marco, Leonardo Mariani, Henry Muccini, Andrea Polini, Onn Shehory
2008 conf
CIA
Shay Raz, Raz Lin, Onn Shehory
2008 conf
ICEIS (4)
Arnon Sturm, Dov Dori, Onn Shehory
2008 conf
ASE Workshops
Onn Shehory
2008 J jnl
Int. J. Softw. Eng. Knowl. Eng.
Arnon Sturm, Dov Dori, Onn Shehory
2007 A ed.
AAMAS
Edmund H. Durfee, Makoto Yokoo, Michael N. Huhns, Onn Shehory
2007 ed.
TADA/AMEC
Maria Fasli, Onn Shehory
2007 conf
SOQUA
Maayan Goldstein, Onn Shehory, Yaron Weinsberg
2007 conf
BDIM
David Breitgand, Ealan A. Henis, Onn Shehory, John M. Lake
2007 conf
Integrated Network Management
David Breitgand, Maayan Goldstein, Ealan Henis, Onn Shehory, Yaron Weinsberg
2007 conf
ESEC/SIGSOFT FSE
Giovanni Denaro, Mauro Pezzè, Onn Shehory
2007 conf
AMEC/TADA
Jonathan Rabin, Onn Shehory
2006 conf
IAT
Samir Aknine, Onn Shehory
2006 conf
PROMAS
Onn Shehory
2006 A conf
AAMAS
Onn Shehory, Eran Dror
2006 conf
ICEIS (3)
Arnon Sturm, Dov Dori, Onn Shehory
2006 conf
IAT
José Ghislain Quenum, Samir Aknine, Onn Shehory, Shinichi Honiden
2006 A conf
ECAI
Samir Aknine, Onn Shehory
2006 A conf
AAMAS
Onn Shehory
2005 A conf
AAMAS
David Ben-Ami, Onn Shehory
2005 J jnl
CoRR
Samir Aknine, Onn Shehory
2005 conf
JFSMA
Samir Aknine, Onn Shehory
2005 conf
ISCIS
Onn Shehory
2005 C conf
EUMAS
Onn Shehory, Eran Dror
2005 A conf
AAMAS
Onn Shehory, Eran Dror
2005 conf
Integrated Network Management
David Breitgand, Ealan Henis, Edya Ladan-Mozes, Onn Shehory, Elena Yerushalmi
2004 J jnl
Fundam. Informaticae
Onn Shehory
2004 A conf
AAMAS
Onn Shehory, Gal A. Kaminka, Eran Shoham
2004 conf
SMC (2)
Gabi Koifman, Onn Shehory, Avigdor Gal
2004 A conf
AAMAS
Gabi Koifman, Onn Shehory, Avigdor Gal
2004 J jnl
Decis. Support Syst.
Claudia V. Goldman, Sarit Kraus, Onn Shehory
2004 A conf
AAMAS
Sarit Kraus, Onn Shehory, Gilad Taase
2003 conf
AOIS
Arnon Sturm, Onn Shehory
2003 J jnl
Auton. Agents Multi Agent Syst.
Onn Shehory
2003 conf
CEEMAS
Onn Shehory
2003 A conf
AAMAS
Sarit Kraus, Onn Shehory, Gilad Taase
2003 A conf
AAMAS
Bastian Blankenburg, Matthias Klusch, Onn Shehory
2003 C ed.
ICEC
Norman M. Sadeh, Mary Jo Dively, Robert J. Kauffman, Yannis Labrou, Onn Shehory, Rahul Telang, Lorrie Faith Cranor
2003 conf
AP2PC
Onn Shehory
2003 A conf
AAMAS
Arnon Sturm, Dov Dori, Onn Shehory
2002 ed.
AMEC
Julian A. Padget, Onn Shehory, David C. Parkes, Norman M. Sadeh, William E. Walsh
2002 A conf
AAMAS
Onn Shehory, Maria Goldstein, Adi Shulman, Arnon Sturm, Boris Yurovitsky
2002 J jnl
Auton. Agents Multi Agent Syst.
Onn Shehory
2002 ed.
CIA
Matthias Klusch, Sascha Ossowski, Onn Shehory
2002 conf
CIA
David Ben-Ami, Onn Shehory
2002 J jnl
Int. J. Cooperative Inf. Syst.
Onn Shehory
2002 A conf
AAMAS
Arnon Sturm, Onn Shehory
2001 J jnl
Auton. Agents Multi Agent Syst.
Onn Shehory
2001 conf
CIA
Claudia V. Goldman, Sarit Kraus, Onn Shehory
2001 conf
Agents
Onn Shehory, Arnon Sturm
2001 conf
CIA
Onn Shehory
2001 conf
WOA
Onn Shehory
2000 conf
ICMAS
Kristina Lerman, Onn Shehory
2000 conf
Trust in Cyber-societies
Yosi Mass, Onn Shehory
2000 J jnl
Electron. Trans. Artif. Intell.
Massimo Paolucci, Onn Shehory, Katia P. Sycara
2000 conf
AOSE
Onn Shehory
2000 conf
Agents
Onn Shehory, Katia P. Sycara
1999 conf
ATAL
Massimo Paolucci, Onn Shehory, Katia P. Sycara, Dirk Kalp, Anandeep Pannu
1999 conf
ATAL
Onn Shehory
1999 conf
Agents
Onn Shehory, Katia P. Sycara, Gita Sukthankar, Vick Mukherjee
1999 J jnl
Artif. Intell.
Tuomas Sandholm, Kate Larson, Martin Andersson, Onn Shehory, Fernando Tohmé
1999 ed.
CIA
Matthias Klusch, Onn Shehory, Gerhard Weiß
1999 J jnl
Artif. Intell.
Onn Shehory, Sarit Kraus, Osher Yadgar
1999 J jnl
Comput. Intell.
Onn Shehory, Sarit Kraus
1998 conf
Agents
Somesh Jha, Prasad Chalasani, Onn Shehory, Katia P. Sycara
1998 conf
ICMAS
Onn Shehory, Katia P. Sycara, Prasad Chalasani, Somesh Jha
1998 J jnl
IEEE Commun. Mag.
Onn Shehory, Katia P. Sycara, Prasad Chalasani, Somesh Jha
1998 J jnl
CoRR
Tuomas Sandholm, Kate Larson, Martin Andersson, Onn Shehory, Fernando Tohmé
1998 conf
AAAI/IAAI
Tuomas Sandholm, Kate Larson, Martin Andersson, Onn Shehory, Fernando Tohmé
1998 conf
ATAL
Onn Shehory, Sarit Kraus, Osher Yadgar
1998 conf
ATAL
Onn Shehory, Katia P. Sycara, Prasad Chalasani, Somesh Jha
1998 J jnl
Artif. Intell.
Onn Shehory, Sarit Kraus
1998 conf
Agents
Prasad Chalasani, Somesh Jha, Onn Shehory, Katia P. Sycara
1998 conf
CIA
Prasad Chalasani, Somesh Jha, Onn Shehory, Katia P. Sycara
1997 conf
PAAM
Javier Contreras, Felix F. Wu, Matthias Klusch, Onn Shehory
1997 conf
ATAL
Onn Shehory, Katia P. Sycara, Somesh Jha
1996 conf
AAAI/IAAI, Vol. 1
Onn Shehory, Sarit Kraus
1996 conf
MAAMAW
Matthias Klusch, Onn Shehory
1996 A conf
ECAI
Onn Shehory, Sarit Kraus
1995 conf
DAI
Onn Shehory, Sarit Kraus
1995 A* conf
IJCAI (1)
Onn Shehory, Sarit Kraus
1994 A* conf
AAAI
Onn Shehory
1993 conf
MAAMAW
Onn Shehory, Sarit Kraus
APK_FEATURES_PDD.md
← Index APK_FEATURES_PDD.md markdown
# APK Extractor — Product Design Document

**Author:** Engineering Team
**Date:** 2026-02-21
**Status:** Draft
**Target:** redb ingestor pipeline

---

## 1. Overview

This document describes the design for adding APK (Android Package) static analysis to the redb ingestor pipeline. The APK extractor will follow the same architecture used by the existing PE, ELF, and Mach-O extractors: a format-specific base class (`APKExtractor`) with specialized sub-extractors for each analysis dimension.

### 1.1 Goals

- Extract comprehensive static metadata from Android APK files, comparable in depth to our PE/ELF/Mach-O analysis
- Follow the established extractor architecture (base class, sub-extractors, dataclasses, dual-export to Elasticsearch and ClickHouse)
- Enable clustering, hunting, and pivoting on APK-specific fields (permissions, certificates, DEX API usage, package names)
- Integrate with the existing format-agnostic extractors (BasicProperties, Hashes, DIE, CAPA, YARA, Strings, IOC)

### 1.2 Non-Goals

- Dynamic analysis / sandbox execution (out of scope)
- Full DEX decompilation to Java/smali (out of scope; may be a future extension)
- Deep analysis of embedded native `.so` libraries (inventory only; full ELF pipeline deferred)
- Recursive ingestion of APKs embedded inside other APKs (flag only; full recursive ingestion deferred)

---

## 2. Background

### 2.1 What Is an APK

An APK is a ZIP archive containing an Android application. Its internal structure:

| Path | Contents |
|------|----------|
| `AndroidManifest.xml` | Binary Android XML — package name, permissions, components, SDK versions, intent filters |
| `classes.dex` (+ `classes2.dex`, ...) | Dalvik bytecode — compiled Java/Kotlin code |
| `resources.arsc` | Compiled resource table (strings, dimensions, styles) |
| `res/` | Layouts, drawables, raw resources |
| `lib/<abi>/` | Native shared libraries (`.so`) per CPU architecture |
| `META-INF/` | JAR signing (v1 scheme), CERT.RSA/DSA certificates |
| `assets/` | Arbitrary files bundled by the developer |

### 2.2 Current State

The ingestor already detects APK files via Magika (`ingestor.py:1668`), but the handler is a no-op — it logs `"APK file detected"` and returns without running any extractors. All infrastructure for registration, dispatch, and export is already in place.

### 2.3 Industry Reference

This design was informed by analysis of existing platforms:

- **VirusTotal** — Extracts: hashes (MD5, SHA-1, SHA-256, SSDEEP, TLSH, Permhash), Android metadata (package name, SDK versions, main activity), certificate attributes, permissions with danger flags, full component lists (activities, services, receivers, providers), intent filters, and capability indicators ("performs reflection calls", "makes use of telephony related APIs")
- **Koodous** (https://docs.koodous.com/) — Powered by Androguard for static analysis. Extracts: package name, app name, activities, services, receivers, providers, permissions, intent filters, certificate (SHA-1, issuer, subject), hardcoded URLs, SDK versions. Supports YARA rules with an Androguard module for matching on all these fields
- **APKiD** (https://github.com/rednaga/APKiD) — "PEiD for Android". Signature-based identification of compilers, packers, obfuscators, protectors, anti-VM/debug/root techniques. Uses YARA rules on DEX/APK/ELF. Available under GPL or commercial perpetual license (https://github.com/rednaga/APKiD/blob/master/LICENSE.COMMERCIAL)
- **APKDetect** (https://www.apkdetect.com/) — Malware family identification (30+ families), configuration extraction, loader recognition, shared code detection

---

## 3. Architecture

### 3.1 Existing Extractor Pattern

All extractors in redb follow this hierarchy:

```
Extractor (abstract base — redb/extractors/extractor.py)
├── PEExtractor (redb/extractors/pe_extractor.py)
│   ├── PEFeaturesExtractor
│   ├── PEImportExtractor
│   ├── PESectionExtractor
│   └── ...
├── ELFExtractor (redb/extractors/elf_extractor.py)
│   ├── ELFFeaturesExtractor
│   ├── ELFImportExtractor
│   └── ...
├── MachOExtractor (redb/extractors/macho_extractor.py)
│   ├── MachOFeaturesExtractor
│   ├── MachOImportExtractor
│   └── ...
└── [Format-agnostic extractors]
    ├── BasicPropertiesExtractor
    ├── HashExtractor
    ├── DIEExtractor
    ├── CAPAExtractor
    ├── YaraExtractor
    └── StringsExtractor
```

Each concrete extractor implements:
- `tag()` — returns a `Tag` enum value identifying the extraction category
- `extract()` — performs the analysis, returns a dataclass instance or `None`
- `prepare_export_data(exporter_type)` — formats data for Elasticsearch or ClickHouse
- `get_clickhouse_table()` — returns the target ClickHouse table name

The format-specific base class (e.g., `PEExtractor`) handles:
- Accepting a pre-parsed object (e.g., `pe=`) to avoid redundant parsing
- Providing shared helper methods used by multiple sub-extractors
- Passing `precomputed_hashes` to the parent `Extractor.__init__()` when available

The ingestor dispatches extractors by filetype detected via Magika, running format-agnostic extractors (BasicProperties, Hashes, DIE, CAPA, YARA) followed by the format-specific list.

### 3.2 APK Extractor Architecture

```
Extractor
└── APKExtractor (NEW — redb/extractors/apk_extractor.py)
    ├── APKFeaturesExtractor      (redb/extractors/apk_extractors/apk_features.py)
    ├── APKManifestExtractor      (redb/extractors/apk_extractors/apk_manifest.py)
    ├── APKPermissionsExtractor   (redb/extractors/apk_extractors/apk_permissions.py)
    ├── APKSignatureExtractor     (redb/extractors/apk_extractors/apk_signature.py)
    ├── APKDexExtractor           (redb/extractors/apk_extractors/apk_dex.py)
    ├── APKResourceExtractor      (redb/extractors/apk_extractors/apk_resources.py)
    ├── APKNativeLibExtractor     (redb/extractors/apk_extractors/apk_native_libs.py)
    └── APKInconsistencyTestsExtractor (redb/extractors/apk_extractors/apk_inconsistency_tests.py)
```

The `APKExtractor` base class will:
- Accept an optional pre-parsed `androguard.core.apk.APK` object (`apk=`) to share across sub-extractors
- Parse the APK once in `__init__` if not provided
- Provide shared helpers: `_get_manifest()`, `_get_certificates()`, `_list_files()`, `_is_valid_apk()`

### 3.3 Ingestor Integration

In `ingestor.py:process_binary_file()`, the `elif filetype == "apk"` branch will be expanded to:

1. Parse the APK once using Androguard (`APK(filepath)`)
2. Run format-agnostic extractors (BasicProperties, Hashes, DIE, YARA) — same as PE/ELF/Mach-O
3. Run APK-specific extractors with the shared `apk` object
4. Run Strings + IOC extractors if applicable

---

## 4. Extractor Specifications

### 4.1 APKFeaturesExtractor

**Purpose:** Core APK metadata — the equivalent of `PEFeaturesExtractor` or `ELFFeaturesExtractor`.

**Extracted fields:**
- `package_name` — Android package identifier (e.g., `com.example.app`)
- `app_name` — Human-readable application name
- `version_code` — Internal integer version
- `version_name` — Display version string (e.g., `"1.2.3"`)
- `min_sdk_version` — Minimum Android API level
- `target_sdk_version` — Target Android API level
- `compile_sdk_version` — Compile SDK (if available)
- `main_activity` — Launcher activity class name
- `is_debuggable` — Whether `android:debuggable="true"`
- `allow_backup` — Whether `android:allowBackup="true"`
- `uses_cleartext_traffic` — Whether `android:usesCleartextTraffic="true"`
- `supported_abis` — List of ABIs from `lib/` directory (e.g., `["arm64-v8a", "armeabi-v7a"]`)
- `dex_count` — Number of DEX files
- `total_dex_size` — Combined DEX file size in bytes
- `total_file_count` — Total number of files in the APK archive
- `has_native_code` — Whether `lib/` contains `.so` files
- `has_assets` — Whether `assets/` directory is non-empty
- `uses_libraries` — Declared `<uses-library>` entries
- `earliest_content_modification` — Earliest timestamp from ZIP entry metadata
- `latest_content_modification` — Latest timestamp from ZIP entry metadata
- `contains_embedded_apk` — Whether the archive contains nested APK files (flag only)

**Tag:** `APK_FEATURES`
**ClickHouse table:** `redb_apk_features`

### 4.2 APKManifestExtractor

**Purpose:** Full AndroidManifest.xml component enumeration, mirroring what VirusTotal and Koodous display.

**Extracted fields:**
- `activities` — List of Activity class names with `exported` flag
- `services` — List of Service class names with `exported` flag
- `receivers` — List of BroadcastReceiver class names with `exported` flag
- `providers` — List of ContentProvider class names with `exported` flag
- `intent_filters_by_action` — Aggregated list of all intent filter actions
- `intent_filters_by_category` — Aggregated list of all intent filter categories
- `uses_features` — Declared hardware/software features (e.g., `android.hardware.camera`)
- `meta_data` — Key-value pairs from `<meta-data>` elements
- `manifest_xml` — Full decompiled AndroidManifest.xml as plain text

**Tag:** `APK_MANIFEST`
**ClickHouse table:** `redb_apk_manifest` (one row per APK for aggregated data), `redb_apk_components` (one row per component)

### 4.3 APKPermissionsExtractor

**Purpose:** Dedicated permission analysis with protection-level classification and permhash computation.

**Extracted fields:**
- `permissions` — List of requested permissions with protection level (`normal`, `dangerous`, `signature`, `signatureOrSystem`)
- `dangerous_permissions` — Filtered list of dangerous permissions only
- `dangerous_permission_count` — Count of dangerous permissions
- `custom_permissions` — Permissions defined by the app itself (`<permission>` declarations)
- `total_permission_count` — Total number of requested permissions
- `permhash` — SHA-256 of sorted permission list (Mandiant/Google permhash — https://github.com/google/permhash)

The `permhash` value will also be added to the `Hashes` dataclass in `redb/models/dataclasses.py` so it appears alongside `imphash`, `symhash`, etc. in the unified hash record.

**Tag:** `APK_PERMISSIONS`
**ClickHouse table:** `redb_apk_permissions` (one row per permission per APK)

### 4.4 APKSignatureExtractor

**Purpose:** Certificate and signing scheme analysis, analogous to `PESignatureExtractor` and `MachOSignatureExtractor`.

**Extracted fields:**
- `signature_scheme_versions` — Which signing schemes are present (v1 JAR, v2, v3, v4)
- `is_signed` — Whether the APK has a valid signature
- `number_of_certificates` — Certificate count in the chain
- `x509_certificates` — List of certificate details:
  - `subject` (Distinguished Name)
  - `issuer` (Distinguished Name)
  - `serial_number`
  - `valid_from` / `valid_to`
  - `thumbprint_sha1`
  - `thumbprint_sha256`
  - `algorithm`
  - `key_size`
  - `is_self_signed`
- `signer_subject` — Primary signer's subject DN (convenience field)
- `signer_issuer` — Primary signer's issuer DN

**Tag:** `APK_SIGNATURE`
**ClickHouse table:** `redb_apk_signature`

### 4.5 APKDexExtractor

**Purpose:** DEX file analysis — summarized with categorized API usage (not full method enumeration).

**Output structure (per DEX file):**

- `filename` — DEX filename (e.g., `classes.dex`)
- `sha256` — SHA-256 of the DEX file
- `class_count` — Total number of classes
- `method_count` — Total number of methods
- `string_count` — Total number of string constants
- `top_packages` — List of `{package, class_count}` for top-level Java packages
- `api_usage` — Categorized sensitive API calls:
  - `reflection` — `java.lang.reflect.*`, `Class.forName`, etc.
  - `crypto` — `javax.crypto.*`, `java.security.*`
  - `dynamic_loading` — `DexClassLoader`, `PathClassLoader`, `InMemoryDexClassLoader`
  - `telephony` — `TelephonyManager` methods
  - `sms` — `SmsManager`, `SmsReceiver`
  - `network` — `HttpURLConnection`, `OkHttp`, `Volley`, `Retrofit`
  - `native` — `System.loadLibrary`, `Runtime.exec`
  - `device_info` — `Build.*`, `Settings.Secure.ANDROID_ID`, IMEI/IMSI access
  - `file_io` — `FileOutputStream`, `SharedPreferences`, `SQLiteDatabase`
  - `ipc` — `ContentResolver`, `BroadcastReceiver`, `Binder`
- `obfuscation_indicators`:
  - `short_class_names_pct` — Percentage of classes with names <= 2 chars
  - `short_method_names_pct` — Percentage of methods with names <= 2 chars
  - `non_ascii_identifiers` — Count of identifiers with non-ASCII characters
  - `avg_class_name_length` — Average class name length

**Tag:** `APK_DEX`
**ClickHouse table:** `redb_apk_dex` (one row per DEX file), `redb_apk_dex_api_usage` (one row per API category per DEX)

### 4.6 APKResourceExtractor

**Purpose:** Inventory of embedded resources with filetype detection for suspicious content.

**Extracted fields:**
- `total_resource_count` — Total files in `res/` and `assets/`
- `total_resource_size` — Combined size
- `resource_inventory` — List of `{path, size, sha256, filetype_magika}` for each file
- `suspicious_files` — Files detected as ELF, PE, DEX, APK, ZIP, script, or other executable types
- `suspicious_file_count` — Count of suspicious files

**Tag:** `APK_RESOURCES`
**ClickHouse table:** `redb_apk_resources`

### 4.7 APKNativeLibExtractor

**Purpose:** Inventory of native `.so` libraries per ABI. No deep ELF analysis (inventory only).

**Extracted fields:**
- `native_lib_count` — Total `.so` file count
- `abis` — List of ABI directories present (e.g., `["arm64-v8a", "x86"]`)
- `native_libs` — List of `{abi, filename, size, sha256}` per `.so` file
- `known_packer_libs` — Any `.so` files matching known packer/protector library names (e.g., `libjiagu.so`, `libsecexe.so`, `libDexHelper.so`, `libprotectClass.so`)

**Tag:** `APK_NATIVE_LIBS`
**ClickHouse table:** `redb_apk_native_libs`

### 4.8 APKInconsistencyTestsExtractor

**Purpose:** Anomaly and anti-analysis detection, analogous to `PEInconsistencyTestsExtractor`.

**Extracted fields:**
- `test_zip_bomb` — Compression ratio exceeds threshold
- `test_zip_duplicate_entries` — ZIP contains duplicate filenames
- `test_zip_path_traversal` — ZIP entries with `../` path traversal
- `test_zip_suspicious_timestamps` — Timestamps in the future or at epoch (1980-01-01)
- `test_hidden_dex_files` — DEX files outside standard `classes*.dex` naming or in unexpected locations
- `test_manifest_component_mismatch` — Declared components that don't exist in DEX, or undeclared code
- `test_debuggable_release` — `android:debuggable="true"` combined with a release signature
- `test_emulator_detection_strings` — Presence of Build.FINGERPRINT/MANUFACTURER emulator check strings in DEX
- `test_debugger_detection` — Presence of `Debug.isDebuggerConnected()` calls
- `test_root_detection` — Presence of root detection patterns (su binary checks, Superuser.apk)

**Tag:** `APK_INCONSISTENCY_TESTS`
**ClickHouse table:** `redb_apk_inconsistency_tests`

---

## 5. New Dependencies

### 5.1 Required

| Library | Version | License | Purpose |
|---------|---------|---------|---------|
| **androguard** | >=4.1 | Apache 2.0 | Core APK parsing: binary XML manifest, DEX analysis, certificate extraction, permissions |
| **permhash** | latest | Apache 2.0 | Compute permhash (SHA-256 of sorted permissions) for APK clustering |

### 5.2 Already Available (no changes)

| Library | Current Version | Usage |
|---------|----------------|-------|
| `zipfile` (stdlib) | — | APK archive traversal, ZIP anomaly detection |
| `pyelftools` | 0.32 | Could be used for native .so analysis if scope expands |
| `lief` | 0.17.3 | Has `lief.DEX` module; complement to androguard for DEX class/method enumeration |
| `cryptography` | 43.0.3 | Certificate chain validation (used by PE/Mach-O signature extractors) |
| `Pillow` | 10.4.0 | Icon extraction if needed |
| `magika` | 1.0.1 | Filetype detection for embedded resources |

### 5.3 Future Consideration

| Library | License | Purpose | Notes |
|---------|---------|---------|-------|
| **APKiD** | GPL-3.0 or Commercial (perpetual, royalty-free) | Packer/protector/obfuscator identification | "PEiD for Android". Detects compilers (dx, dexlib, r8), packers (AppGuard, DingXiang, JiaguK), obfuscators (DexGuard, BlackObfuscator), protectors (DexProtector, DxShield), anti-VM/debug/root. Commercial license is perpetual and allows binary redistribution: https://github.com/rednaga/APKiD/blob/master/LICENSE.COMMERCIAL |
| **apksigtool** | MIT | APK Signature Scheme v2/v3/v4 verification | androguard handles v1 well; apksigtool provides more thorough v2+ support |
| **quark-engine** | GPL-3.0 | Behavioral analysis scoring | Similar to CAPA but for Android. Stretch goal |

---

## 6. Data Model Changes

### 6.1 New Dataclasses

Add to `redb/models/dataclasses.py`:
- `APKFeatures`
- `APKManifestComponent`
- `APKPermission`
- `APKCertificate`
- `APKCodeSigningInfo`
- `APKDexFile`
- `APKDexApiUsage`
- `APKResource`
- `APKNativeLib`
- `APKInconsistencyTests`

See Tech Annex for full field definitions.

### 6.2 Existing Dataclass Changes

**`Hashes` dataclass** — add:
```python
permhash: Optional[str] = None  # APK: SHA-256 of sorted permissions (Mandiant/Google)
```

### 6.3 Tag Enum Additions

Add to `redb/extractors/enum.py`:
```python
# APK
APK_FEATURES = "apk_features"
APK_MANIFEST = "apk_manifest"
APK_PERMISSIONS = "apk_permissions"
APK_SIGNATURE = "apk_signature"
APK_DEX = "apk_dex"
APK_RESOURCES = "apk_resources"
APK_NATIVE_LIBS = "apk_native_libs"
APK_INCONSISTENCY_TESTS = "apk_inconsistency_tests"
```

---

## 7. Implementation Phases

### Phase 1 — Core Extractors

1. `APKExtractor` base class + `APKFeaturesExtractor`
2. `APKManifestExtractor`
3. `APKPermissionsExtractor` (including permhash)
4. `APKSignatureExtractor`
5. `APKDexExtractor`
6. `APKResourceExtractor`
7. `APKNativeLibExtractor`
8. Ingestor integration (wire up dispatch in `process_binary_file()`)
9. Hashes dataclass update (add `permhash`)

### Phase 2 — Detection and Anomalies

10. `APKInconsistencyTestsExtractor`
11. Wire up existing format-agnostic extractors for APK (YARA, Strings, IOC)

### Phase 3 — Future (out of scope for this PDD)

- APKiD integration for packer/protector detection
- Deep native library analysis (run ELF pipeline on extracted `.so` files)
- Recursive APK ingestion
- androguard-yara module integration for YARA rules matching on APK metadata

---

## 8. Testing Strategy

- Unit tests per extractor using known APK samples (benign + malicious)
- Validate output against VirusTotal reports for the same samples (cross-reference fields)
- Edge cases: split APKs, obfuscated APKs, packed APKs, APKs with no native code, APKs with no DEX, corrupted APKs
- Integration test: full pipeline run (ingest APK, verify all extractors produce output, verify ClickHouse/ES export)