Xianyong Li

78 papers B 1Journal 71Unranked 5
YearRankTypeTitle / Venue / Authors
2026 J jnl
Eng. Appl. Artif. Intell.
Maolin Zhang, Xianyong Li, Xiaoliang Chen, Yajun Du, Dong Huang, Shumin Wang, Yongquan Fan
2026 J jnl
Int. J. Mach. Learn. Cybern.
Yongquan Fan, Tao Chen, Yajun Du, Xianyong Li
2026 J jnl
Expert Syst. Appl.
Hongyang Wang, Yajun Du, Jia Liu, Xianyong Li, Xiaoliang Chen, Yan-Li Lee, Qing Qi, Wanjie Zhang
2026 J jnl
Eng. Appl. Artif. Intell.
Yukun Wang, Xianyong Li, Yajun Du, Dong Huang, Xiaoliang Chen, Zhicheng Dong, Yujie Zhang
2026 J jnl
Inf. Process. Manag.
Wei Jiang, Yongquan Fan, Jin Tang, Xianyong Li, Yajun Du, Xiaomin Wang
2026 J jnl
Inf. Sci.
Kaiwei Xu, Yongquan Fan, Jing Tang, Xianyong Li, Yajun Du, Xiaomin Wang
2026 J jnl
Expert Syst. Appl.
Wanjie Zhang, Yajun Du, Hongyang Wang, Jia Liu, Xianyong Li
2026 J jnl
Int. J. Mach. Learn. Cybern.
Yongquan Fan, Yuhang Cheng, Yitong Wang, Xianyong Li
2025 J jnl
Cogn. Comput.
Chen Huang, Xianyong Li, Yajun Du, Zhicheng Dong, Dong Huang, Deepak Kumar Jain, Amir Hussain
2025 J jnl
Int. J. Mach. Learn. Cybern.
Sijia Yang, Xianyong Li, Yajun Du, Dong Huang, Xiaoliang Chen, Yongquan Fan, Shumin Wang
2025 J jnl
Appl. Intell.
Jiaming Huang, Xianyong Li, Yajun Du, Yongquan Fan, Dong Huang, Xiaoliang Chen
2025 J jnl
Int. J. Mach. Learn. Cybern.
Chen Huang, Xianyong Li, Yajun Du, Xin Zheng, Dong Huang, Xiaoliang Chen, Shumin Wang, Yongquan Fan, Zhicheng Dong
2025 J jnl
Int. J. Parallel Emergent Distributed Syst.
Qiang Liu, Hao Li, Chunzhi Xie, Kexin Xu, Yajun Du, Xianyong Li, Yanli Li, Jia Liu
2025 J jnl
Soft Comput.
Kexin Xu, Chunzhi Xie, Qiang Liu, Yajun Du, Xianyong Li, Yan-Li Lee, Jia Liu
2025 J jnl
Inf. Process. Manag.
Kaiwei Xu, Yongquan Fan, Jing Tang, Xianyong Li, Yajun Du, Xiao-Ming Wang
2025 J jnl
J. Supercomput.
Songlin Chen, Weicheng Wang, Xiaoliang Chen, Maolin Zhang, Peng Lu, Xianyong Li, Yajun Du
2025 J jnl
Neurocomputing
Wei Jiang, Yongquan Fan, Yajun Du, Xianyong Li, Xiaomin Wang
2025 J jnl
Neurocomputing
Shun Yang, Yajun Du, Shangyi Du, Xianyong Li, Xiaoliang Chen, Yanli Li, Chunzhi Xie, Jia Liu
2025 J jnl
Inf. Fusion
Zhaoyan Li, Yajun Du, Shun Yang, Xiaoliang Chen, Xianyong Li
2025 J jnl
Appl. Intell.
Haoyu Jiang, Xiaoliang Chen, Duoqian Miao, Hongyun Zhang, Xiaolin Qin, Xu Gu, Peng Lu, Xianyong Li
2025 J jnl
Expert Syst. Appl.
Chen Huang, Xianyong Li, Xin Zheng, Yajun Du, Xiaoliang Chen, Dong Huang, Yongquan Fan
2025 J jnl
Expert Syst. Appl.
Haoyun Wang, Yongquan Fan, Yajun Du, Xianyong Li, Xiaomin Wang
2025 J jnl
Expert Syst. Appl.
Sai Kang, Yajun Du, Xianyong Li, Xiaoliang Chen, Chunzhi Xie, Jia Liu, Yan-Li Lee
2025 J jnl
Neurocomputing
Minjie Fan, Yongquan Fan, Yajun Du, Xianyong Li
2025 J jnl
Knowl. Based Syst.
Chen Huang, Xianyong Li, Xin Zheng, Yajun Du, Dong Huang, Xiaoliang Chen, Jian Zhu
2025 J jnl
Appl. Soft Comput.
Sai Kang, Yajun Du, Xianyong Li, Xiaoliang Chen, Chunzhi Xie, Jia Liu, Yan-Li Lee
2024 J jnl
Expert Syst. Appl.
Jiahui Liao, Yajun Du, Jinrong Hu, Hui Li, Xianyong Li, Xiaoliang Chen
2024 J jnl
Expert Syst. Appl.
Zhiyang Hou, Yajun Du, Qizhi Li, Xianyong Li, Xiaoliang Chen, Hongmei Gao
2024 J jnl
Intell. Data Anal.
Jing Tang, Yongquan Fan, Yajun Du, Xianyong Li, Xiaoliang Chen
2024 J jnl
Expert Syst. Appl.
Yitong Wang, Xianyong Li, Yuhang Cheng, Yajun Du, Dong Huang, Xiaoliang Chen, Yongquan Fan
2024 J jnl
Eng. Appl. Artif. Intell.
Xu Gu, Xiaoliang Chen, Peng Lu, Zonggen Li, Yajun Du, Xianyong Li
2024 J jnl
Expert Syst. Appl.
Yuhang Cheng, Yongquan Fan, Yitong Wang, Xianyong Li
2024 J jnl
Intell. Data Anal.
Zhuo Feng, Yajun Du, Jiaming Huang, Xianyong Li, Xiaoliang Chen, Chunzhi Xie
2024 J jnl
Appl. Soft Comput.
Junsen Fu, Xianyong Li, Yihong Zhu, Yajun Du, Yongquan Fan, Xiaoliang Chen, Dong Huang, Shumin Wang
2024 J jnl
Int. J. Parallel Emergent Distributed Syst.
Zhihao Zhang, Mingwei Tang, Xiaoliang Chen, Yan-Li Lee, Yajun Du, Liansong Zong, Xianyong Li, Zhongyuan Jiang, Haosong Gou
2024 J jnl
Neural Process. Lett.
Qin Deng, Xiaoliang Chen, Zaiyan Yang, Xianyong Li, Yajun Du
2024 J jnl
J. Membr. Comput.
Qin Deng, Zexia Huang, Xiaoliang Chen, Xianyong Li, Yajun Du
2024 J jnl
Appl. Soft Comput.
Shun Yang, Yajun Du, Jiaming Huang, Xianyong Li, Shangyi Du, Jia Liu, Yanli Li
2024 J jnl
Pattern Recognit.
Shun Yang, Yajun Du, Xin Zheng, Xianyong Li, Xiaoliang Chen, Yanli Li, Chunzhi Xie
2024 J jnl
Expert Syst. Appl.
Shun Yang, Yajun Du, Jia Liu, Xianyong Li, Xiaoliang Chen, Hongmei Gao, Chunzhi Xie, Yan-Li Lee
2024 J jnl
Multim. Tools Appl.
Rui Kong, Xianyong Li, Jiankun Wang, Xiaoling Wang
2024 J jnl
Intell. Data Anal.
Jiaming Huang, Xianyong Li, Qizhi Li, Yajun Du, Yongquan Fan, Xiaoliang Chen, Dong Huang, Shumin Wang
2024 J jnl
Expert Syst. Appl.
Yiheng Fu, Xiaoliang Chen, Duoqian Miao, Xiaolin Qin, Peng Lu, Xianyong Li
2024 J jnl
Neurocomputing
Gang Wang, Yajun Du, Yurui Jiang, Jia Liu, Xianyong Li, Xiaoliang Chen, Hongmei Gao, Chunzhi Xie, Yan-Li Lee
2024 J jnl
J. Supercomput.
Xu Gu, Xiaoliang Chen, Peng Lu, Xiang Lan, Xianyong Li, Yajun Du
2024 J jnl
Int. J. Found. Comput. Sci.
Xianyong Li, Jiaming Huang, Yajun Du, Yongquan Fan, Xiaoliang Chen
2023 J jnl
Enterp. Inf. Syst.
Xianyong Li, Jiabo Zhang, Yajun Du, Jian Zhu, Yongquan Fan, Xiaoliang Chen
2023 J jnl
Inf. Technol. Control.
Jianwei Li, Xianyong Li, Yajun Du, Yongquan Fan, Xiaoliang Chen, Dong Huang
2023 J jnl
Expert Syst. Appl.
Xuyang Wang, Yajun Du, Danroujing Chen, Xianyong Li, Xiaoliang Chen, Yan-Li Lee, Jia Liu
2023 conf
BIGCOM
Yuqi Chen, Xianyong Li, Weikai Zhou, Yajun Du, Xiaoliang Chen, Yongquan Fan
2023 J jnl
Appl. Intell.
Jiajian Jiang, Xiaoliang Chen, Zexia Huang, Xianyong Li, Yajun Du
2023 J jnl
J. Supercomput.
Junyuan Ding, Xiaoliang Chen, Peng Lu, Zaiyan Yang, Xianyong Li, Yajun Du
2023 J jnl
Appl. Soft Comput.
Xuyang Wang, Yajun Du, Danroujing Chen, Xianyong Li, Xiaoliang Chen, Yongquan Fan, Chunzhi Xie, Yanli Li, Jia Liu, Hui Li
2023 B conf
SMC
Jiaming Huang, Xianyong Li, Yajun Du, Chunzhi Xie, Xiaoliang Chen, Yongquan Fan
2023 J jnl
Networks Heterog. Media
Yuntian Zhang, Xiaoliang Chen, Zexia Huang, Xianyong Li, Yajun Du
2022 J jnl
Secur. Commun. Networks
Xianyong Li, Qizhi Li, Yajun Du, Yongquan Fan, Xiaoliang Chen, Fashan Shen, Yunxia Xu
2022 J jnl
Eng. Appl. Artif. Intell.
Qian Zhang, Xianyong Li, Yongquan Fan, Yajun Du
2022 J jnl
Inf. Fusion
Yajun Du, Yakun Wang, Jinrong Hu, Xianyong Li, Xiaoliang Chen
2022 J jnl
Appl. Soft Comput.
Zhiyang Hou, Yajun Du, Wei Li, Jinrong Hu, Hui Li, Xianyong Li, Xiaoliang Chen
2022 conf
HPCC/DSS/SmartCity/DependSys
Qizhi Li, Xianyong Li, Yujia Song, Maolin Zhang, Longqi Chen, Gang Wang, Yajun Du
2022 J jnl
Intell. Data Anal.
Zhibin Wang, Xiaoliang Chen, Xianyong Li, Yajun Du, Xiang Lan
2022 J jnl
Eng. Appl. Artif. Intell.
Wei Li, Yajun Du, Xianyong Li, Xiaoliang Chen, Chunzhi Xie, Hui Li, Xiaolei Li
2022 conf
HPCC/DSS/SmartCity/DependSys
Xianyong Li, Qizhi Li
2021 J jnl
Inf. Sci.
Yajun Du, Qiaoyu Zhou, JiaXing Luo, Xianyong Li, Jinrong Hu
2021 conf
NLPCC (2)
Qizhi Li, Xianyong Li, Yajun Du, Xiaoliang Chen
2021 J jnl
Symmetry
Haiping Gao, Jian Zhu, Xianyong Li, Xing Chen
2021 J jnl
Complex.
Xianyong Li, Jian Zhu, Yajun Du, Qian Zhang
2021 J jnl
AI Open
Tiancui Zhang, Xiaoliang Chen, Yajun Du, Xianyong Li
2020 J jnl
IEEE Access
Yajun Du, Fanghong Su, Anzheng Yang, Xianyong Li, Yongquan Fan
2020 J jnl
Eng. Appl. Artif. Intell.
Yajun Du, Yongtao Yi, Xianyong Li, Xiaoliang Chen, Yongquan Fan, Fanghong Su
2020 J jnl
Eng. Appl. Artif. Intell.
Cheng Gong, Yajun Du, Xianyong Li, Xiaoliang Chen, Xiaoying Li, Yakun Wang, Qiaoyu Zhou
2020 conf
EITCE
Qian Zhang, Xianyong Li, Yajun Du
2019 ed.
CCKS
Jun Zhao, Frank van Harmelen, Jie Tang, Xianpei Han, Quan Wang, Xianyong Li
2016 J jnl
Int. J. Comput. Math.
Xianyong Li
2015 J jnl
Int. J. Found. Comput. Sci.
Xianyong Li, Xiaofan Yang, Li He, Cui Yu, Jing Zhang
2015 J jnl
Ars Comb.
Zhengxin Qin, Xianyong Li, Guoping Wang
2014 J jnl
Theor. Comput. Sci.
Xianyong Li, Xiaofan Yang, Li He, Jing Zhang, Cui Yu
2013 J jnl
Int. J. Comput. Math.
Xianyong Li, Xiaofan Yang, Li He
APK_FEATURES_PDD.md
← Index APK_FEATURES_PDD.md markdown
# APK Extractor — Product Design Document

**Author:** Engineering Team
**Date:** 2026-02-21
**Status:** Draft
**Target:** redb ingestor pipeline

---

## 1. Overview

This document describes the design for adding APK (Android Package) static analysis to the redb ingestor pipeline. The APK extractor will follow the same architecture used by the existing PE, ELF, and Mach-O extractors: a format-specific base class (`APKExtractor`) with specialized sub-extractors for each analysis dimension.

### 1.1 Goals

- Extract comprehensive static metadata from Android APK files, comparable in depth to our PE/ELF/Mach-O analysis
- Follow the established extractor architecture (base class, sub-extractors, dataclasses, dual-export to Elasticsearch and ClickHouse)
- Enable clustering, hunting, and pivoting on APK-specific fields (permissions, certificates, DEX API usage, package names)
- Integrate with the existing format-agnostic extractors (BasicProperties, Hashes, DIE, CAPA, YARA, Strings, IOC)

### 1.2 Non-Goals

- Dynamic analysis / sandbox execution (out of scope)
- Full DEX decompilation to Java/smali (out of scope; may be a future extension)
- Deep analysis of embedded native `.so` libraries (inventory only; full ELF pipeline deferred)
- Recursive ingestion of APKs embedded inside other APKs (flag only; full recursive ingestion deferred)

---

## 2. Background

### 2.1 What Is an APK

An APK is a ZIP archive containing an Android application. Its internal structure:

| Path | Contents |
|------|----------|
| `AndroidManifest.xml` | Binary Android XML — package name, permissions, components, SDK versions, intent filters |
| `classes.dex` (+ `classes2.dex`, ...) | Dalvik bytecode — compiled Java/Kotlin code |
| `resources.arsc` | Compiled resource table (strings, dimensions, styles) |
| `res/` | Layouts, drawables, raw resources |
| `lib/<abi>/` | Native shared libraries (`.so`) per CPU architecture |
| `META-INF/` | JAR signing (v1 scheme), CERT.RSA/DSA certificates |
| `assets/` | Arbitrary files bundled by the developer |

### 2.2 Current State

The ingestor already detects APK files via Magika (`ingestor.py:1668`), but the handler is a no-op — it logs `"APK file detected"` and returns without running any extractors. All infrastructure for registration, dispatch, and export is already in place.

### 2.3 Industry Reference

This design was informed by analysis of existing platforms:

- **VirusTotal** — Extracts: hashes (MD5, SHA-1, SHA-256, SSDEEP, TLSH, Permhash), Android metadata (package name, SDK versions, main activity), certificate attributes, permissions with danger flags, full component lists (activities, services, receivers, providers), intent filters, and capability indicators ("performs reflection calls", "makes use of telephony related APIs")
- **Koodous** (https://docs.koodous.com/) — Powered by Androguard for static analysis. Extracts: package name, app name, activities, services, receivers, providers, permissions, intent filters, certificate (SHA-1, issuer, subject), hardcoded URLs, SDK versions. Supports YARA rules with an Androguard module for matching on all these fields
- **APKiD** (https://github.com/rednaga/APKiD) — "PEiD for Android". Signature-based identification of compilers, packers, obfuscators, protectors, anti-VM/debug/root techniques. Uses YARA rules on DEX/APK/ELF. Available under GPL or commercial perpetual license (https://github.com/rednaga/APKiD/blob/master/LICENSE.COMMERCIAL)
- **APKDetect** (https://www.apkdetect.com/) — Malware family identification (30+ families), configuration extraction, loader recognition, shared code detection

---

## 3. Architecture

### 3.1 Existing Extractor Pattern

All extractors in redb follow this hierarchy:

```
Extractor (abstract base — redb/extractors/extractor.py)
├── PEExtractor (redb/extractors/pe_extractor.py)
│   ├── PEFeaturesExtractor
│   ├── PEImportExtractor
│   ├── PESectionExtractor
│   └── ...
├── ELFExtractor (redb/extractors/elf_extractor.py)
│   ├── ELFFeaturesExtractor
│   ├── ELFImportExtractor
│   └── ...
├── MachOExtractor (redb/extractors/macho_extractor.py)
│   ├── MachOFeaturesExtractor
│   ├── MachOImportExtractor
│   └── ...
└── [Format-agnostic extractors]
    ├── BasicPropertiesExtractor
    ├── HashExtractor
    ├── DIEExtractor
    ├── CAPAExtractor
    ├── YaraExtractor
    └── StringsExtractor
```

Each concrete extractor implements:
- `tag()` — returns a `Tag` enum value identifying the extraction category
- `extract()` — performs the analysis, returns a dataclass instance or `None`
- `prepare_export_data(exporter_type)` — formats data for Elasticsearch or ClickHouse
- `get_clickhouse_table()` — returns the target ClickHouse table name

The format-specific base class (e.g., `PEExtractor`) handles:
- Accepting a pre-parsed object (e.g., `pe=`) to avoid redundant parsing
- Providing shared helper methods used by multiple sub-extractors
- Passing `precomputed_hashes` to the parent `Extractor.__init__()` when available

The ingestor dispatches extractors by filetype detected via Magika, running format-agnostic extractors (BasicProperties, Hashes, DIE, CAPA, YARA) followed by the format-specific list.

### 3.2 APK Extractor Architecture

```
Extractor
└── APKExtractor (NEW — redb/extractors/apk_extractor.py)
    ├── APKFeaturesExtractor      (redb/extractors/apk_extractors/apk_features.py)
    ├── APKManifestExtractor      (redb/extractors/apk_extractors/apk_manifest.py)
    ├── APKPermissionsExtractor   (redb/extractors/apk_extractors/apk_permissions.py)
    ├── APKSignatureExtractor     (redb/extractors/apk_extractors/apk_signature.py)
    ├── APKDexExtractor           (redb/extractors/apk_extractors/apk_dex.py)
    ├── APKResourceExtractor      (redb/extractors/apk_extractors/apk_resources.py)
    ├── APKNativeLibExtractor     (redb/extractors/apk_extractors/apk_native_libs.py)
    └── APKInconsistencyTestsExtractor (redb/extractors/apk_extractors/apk_inconsistency_tests.py)
```

The `APKExtractor` base class will:
- Accept an optional pre-parsed `androguard.core.apk.APK` object (`apk=`) to share across sub-extractors
- Parse the APK once in `__init__` if not provided
- Provide shared helpers: `_get_manifest()`, `_get_certificates()`, `_list_files()`, `_is_valid_apk()`

### 3.3 Ingestor Integration

In `ingestor.py:process_binary_file()`, the `elif filetype == "apk"` branch will be expanded to:

1. Parse the APK once using Androguard (`APK(filepath)`)
2. Run format-agnostic extractors (BasicProperties, Hashes, DIE, YARA) — same as PE/ELF/Mach-O
3. Run APK-specific extractors with the shared `apk` object
4. Run Strings + IOC extractors if applicable

---

## 4. Extractor Specifications

### 4.1 APKFeaturesExtractor

**Purpose:** Core APK metadata — the equivalent of `PEFeaturesExtractor` or `ELFFeaturesExtractor`.

**Extracted fields:**
- `package_name` — Android package identifier (e.g., `com.example.app`)
- `app_name` — Human-readable application name
- `version_code` — Internal integer version
- `version_name` — Display version string (e.g., `"1.2.3"`)
- `min_sdk_version` — Minimum Android API level
- `target_sdk_version` — Target Android API level
- `compile_sdk_version` — Compile SDK (if available)
- `main_activity` — Launcher activity class name
- `is_debuggable` — Whether `android:debuggable="true"`
- `allow_backup` — Whether `android:allowBackup="true"`
- `uses_cleartext_traffic` — Whether `android:usesCleartextTraffic="true"`
- `supported_abis` — List of ABIs from `lib/` directory (e.g., `["arm64-v8a", "armeabi-v7a"]`)
- `dex_count` — Number of DEX files
- `total_dex_size` — Combined DEX file size in bytes
- `total_file_count` — Total number of files in the APK archive
- `has_native_code` — Whether `lib/` contains `.so` files
- `has_assets` — Whether `assets/` directory is non-empty
- `uses_libraries` — Declared `<uses-library>` entries
- `earliest_content_modification` — Earliest timestamp from ZIP entry metadata
- `latest_content_modification` — Latest timestamp from ZIP entry metadata
- `contains_embedded_apk` — Whether the archive contains nested APK files (flag only)

**Tag:** `APK_FEATURES`
**ClickHouse table:** `redb_apk_features`

### 4.2 APKManifestExtractor

**Purpose:** Full AndroidManifest.xml component enumeration, mirroring what VirusTotal and Koodous display.

**Extracted fields:**
- `activities` — List of Activity class names with `exported` flag
- `services` — List of Service class names with `exported` flag
- `receivers` — List of BroadcastReceiver class names with `exported` flag
- `providers` — List of ContentProvider class names with `exported` flag
- `intent_filters_by_action` — Aggregated list of all intent filter actions
- `intent_filters_by_category` — Aggregated list of all intent filter categories
- `uses_features` — Declared hardware/software features (e.g., `android.hardware.camera`)
- `meta_data` — Key-value pairs from `<meta-data>` elements
- `manifest_xml` — Full decompiled AndroidManifest.xml as plain text

**Tag:** `APK_MANIFEST`
**ClickHouse table:** `redb_apk_manifest` (one row per APK for aggregated data), `redb_apk_components` (one row per component)

### 4.3 APKPermissionsExtractor

**Purpose:** Dedicated permission analysis with protection-level classification and permhash computation.

**Extracted fields:**
- `permissions` — List of requested permissions with protection level (`normal`, `dangerous`, `signature`, `signatureOrSystem`)
- `dangerous_permissions` — Filtered list of dangerous permissions only
- `dangerous_permission_count` — Count of dangerous permissions
- `custom_permissions` — Permissions defined by the app itself (`<permission>` declarations)
- `total_permission_count` — Total number of requested permissions
- `permhash` — SHA-256 of sorted permission list (Mandiant/Google permhash — https://github.com/google/permhash)

The `permhash` value will also be added to the `Hashes` dataclass in `redb/models/dataclasses.py` so it appears alongside `imphash`, `symhash`, etc. in the unified hash record.

**Tag:** `APK_PERMISSIONS`
**ClickHouse table:** `redb_apk_permissions` (one row per permission per APK)

### 4.4 APKSignatureExtractor

**Purpose:** Certificate and signing scheme analysis, analogous to `PESignatureExtractor` and `MachOSignatureExtractor`.

**Extracted fields:**
- `signature_scheme_versions` — Which signing schemes are present (v1 JAR, v2, v3, v4)
- `is_signed` — Whether the APK has a valid signature
- `number_of_certificates` — Certificate count in the chain
- `x509_certificates` — List of certificate details:
  - `subject` (Distinguished Name)
  - `issuer` (Distinguished Name)
  - `serial_number`
  - `valid_from` / `valid_to`
  - `thumbprint_sha1`
  - `thumbprint_sha256`
  - `algorithm`
  - `key_size`
  - `is_self_signed`
- `signer_subject` — Primary signer's subject DN (convenience field)
- `signer_issuer` — Primary signer's issuer DN

**Tag:** `APK_SIGNATURE`
**ClickHouse table:** `redb_apk_signature`

### 4.5 APKDexExtractor

**Purpose:** DEX file analysis — summarized with categorized API usage (not full method enumeration).

**Output structure (per DEX file):**

- `filename` — DEX filename (e.g., `classes.dex`)
- `sha256` — SHA-256 of the DEX file
- `class_count` — Total number of classes
- `method_count` — Total number of methods
- `string_count` — Total number of string constants
- `top_packages` — List of `{package, class_count}` for top-level Java packages
- `api_usage` — Categorized sensitive API calls:
  - `reflection` — `java.lang.reflect.*`, `Class.forName`, etc.
  - `crypto` — `javax.crypto.*`, `java.security.*`
  - `dynamic_loading` — `DexClassLoader`, `PathClassLoader`, `InMemoryDexClassLoader`
  - `telephony` — `TelephonyManager` methods
  - `sms` — `SmsManager`, `SmsReceiver`
  - `network` — `HttpURLConnection`, `OkHttp`, `Volley`, `Retrofit`
  - `native` — `System.loadLibrary`, `Runtime.exec`
  - `device_info` — `Build.*`, `Settings.Secure.ANDROID_ID`, IMEI/IMSI access
  - `file_io` — `FileOutputStream`, `SharedPreferences`, `SQLiteDatabase`
  - `ipc` — `ContentResolver`, `BroadcastReceiver`, `Binder`
- `obfuscation_indicators`:
  - `short_class_names_pct` — Percentage of classes with names <= 2 chars
  - `short_method_names_pct` — Percentage of methods with names <= 2 chars
  - `non_ascii_identifiers` — Count of identifiers with non-ASCII characters
  - `avg_class_name_length` — Average class name length

**Tag:** `APK_DEX`
**ClickHouse table:** `redb_apk_dex` (one row per DEX file), `redb_apk_dex_api_usage` (one row per API category per DEX)

### 4.6 APKResourceExtractor

**Purpose:** Inventory of embedded resources with filetype detection for suspicious content.

**Extracted fields:**
- `total_resource_count` — Total files in `res/` and `assets/`
- `total_resource_size` — Combined size
- `resource_inventory` — List of `{path, size, sha256, filetype_magika}` for each file
- `suspicious_files` — Files detected as ELF, PE, DEX, APK, ZIP, script, or other executable types
- `suspicious_file_count` — Count of suspicious files

**Tag:** `APK_RESOURCES`
**ClickHouse table:** `redb_apk_resources`

### 4.7 APKNativeLibExtractor

**Purpose:** Inventory of native `.so` libraries per ABI. No deep ELF analysis (inventory only).

**Extracted fields:**
- `native_lib_count` — Total `.so` file count
- `abis` — List of ABI directories present (e.g., `["arm64-v8a", "x86"]`)
- `native_libs` — List of `{abi, filename, size, sha256}` per `.so` file
- `known_packer_libs` — Any `.so` files matching known packer/protector library names (e.g., `libjiagu.so`, `libsecexe.so`, `libDexHelper.so`, `libprotectClass.so`)

**Tag:** `APK_NATIVE_LIBS`
**ClickHouse table:** `redb_apk_native_libs`

### 4.8 APKInconsistencyTestsExtractor

**Purpose:** Anomaly and anti-analysis detection, analogous to `PEInconsistencyTestsExtractor`.

**Extracted fields:**
- `test_zip_bomb` — Compression ratio exceeds threshold
- `test_zip_duplicate_entries` — ZIP contains duplicate filenames
- `test_zip_path_traversal` — ZIP entries with `../` path traversal
- `test_zip_suspicious_timestamps` — Timestamps in the future or at epoch (1980-01-01)
- `test_hidden_dex_files` — DEX files outside standard `classes*.dex` naming or in unexpected locations
- `test_manifest_component_mismatch` — Declared components that don't exist in DEX, or undeclared code
- `test_debuggable_release` — `android:debuggable="true"` combined with a release signature
- `test_emulator_detection_strings` — Presence of Build.FINGERPRINT/MANUFACTURER emulator check strings in DEX
- `test_debugger_detection` — Presence of `Debug.isDebuggerConnected()` calls
- `test_root_detection` — Presence of root detection patterns (su binary checks, Superuser.apk)

**Tag:** `APK_INCONSISTENCY_TESTS`
**ClickHouse table:** `redb_apk_inconsistency_tests`

---

## 5. New Dependencies

### 5.1 Required

| Library | Version | License | Purpose |
|---------|---------|---------|---------|
| **androguard** | >=4.1 | Apache 2.0 | Core APK parsing: binary XML manifest, DEX analysis, certificate extraction, permissions |
| **permhash** | latest | Apache 2.0 | Compute permhash (SHA-256 of sorted permissions) for APK clustering |

### 5.2 Already Available (no changes)

| Library | Current Version | Usage |
|---------|----------------|-------|
| `zipfile` (stdlib) | — | APK archive traversal, ZIP anomaly detection |
| `pyelftools` | 0.32 | Could be used for native .so analysis if scope expands |
| `lief` | 0.17.3 | Has `lief.DEX` module; complement to androguard for DEX class/method enumeration |
| `cryptography` | 43.0.3 | Certificate chain validation (used by PE/Mach-O signature extractors) |
| `Pillow` | 10.4.0 | Icon extraction if needed |
| `magika` | 1.0.1 | Filetype detection for embedded resources |

### 5.3 Future Consideration

| Library | License | Purpose | Notes |
|---------|---------|---------|-------|
| **APKiD** | GPL-3.0 or Commercial (perpetual, royalty-free) | Packer/protector/obfuscator identification | "PEiD for Android". Detects compilers (dx, dexlib, r8), packers (AppGuard, DingXiang, JiaguK), obfuscators (DexGuard, BlackObfuscator), protectors (DexProtector, DxShield), anti-VM/debug/root. Commercial license is perpetual and allows binary redistribution: https://github.com/rednaga/APKiD/blob/master/LICENSE.COMMERCIAL |
| **apksigtool** | MIT | APK Signature Scheme v2/v3/v4 verification | androguard handles v1 well; apksigtool provides more thorough v2+ support |
| **quark-engine** | GPL-3.0 | Behavioral analysis scoring | Similar to CAPA but for Android. Stretch goal |

---

## 6. Data Model Changes

### 6.1 New Dataclasses

Add to `redb/models/dataclasses.py`:
- `APKFeatures`
- `APKManifestComponent`
- `APKPermission`
- `APKCertificate`
- `APKCodeSigningInfo`
- `APKDexFile`
- `APKDexApiUsage`
- `APKResource`
- `APKNativeLib`
- `APKInconsistencyTests`

See Tech Annex for full field definitions.

### 6.2 Existing Dataclass Changes

**`Hashes` dataclass** — add:
```python
permhash: Optional[str] = None  # APK: SHA-256 of sorted permissions (Mandiant/Google)
```

### 6.3 Tag Enum Additions

Add to `redb/extractors/enum.py`:
```python
# APK
APK_FEATURES = "apk_features"
APK_MANIFEST = "apk_manifest"
APK_PERMISSIONS = "apk_permissions"
APK_SIGNATURE = "apk_signature"
APK_DEX = "apk_dex"
APK_RESOURCES = "apk_resources"
APK_NATIVE_LIBS = "apk_native_libs"
APK_INCONSISTENCY_TESTS = "apk_inconsistency_tests"
```

---

## 7. Implementation Phases

### Phase 1 — Core Extractors

1. `APKExtractor` base class + `APKFeaturesExtractor`
2. `APKManifestExtractor`
3. `APKPermissionsExtractor` (including permhash)
4. `APKSignatureExtractor`
5. `APKDexExtractor`
6. `APKResourceExtractor`
7. `APKNativeLibExtractor`
8. Ingestor integration (wire up dispatch in `process_binary_file()`)
9. Hashes dataclass update (add `permhash`)

### Phase 2 — Detection and Anomalies

10. `APKInconsistencyTestsExtractor`
11. Wire up existing format-agnostic extractors for APK (YARA, Strings, IOC)

### Phase 3 — Future (out of scope for this PDD)

- APKiD integration for packer/protector detection
- Deep native library analysis (run ELF pipeline on extracted `.so` files)
- Recursive APK ingestion
- androguard-yara module integration for YARA rules matching on APK metadata

---

## 8. Testing Strategy

- Unit tests per extractor using known APK samples (benign + malicious)
- Validate output against VirusTotal reports for the same samples (cross-reference fields)
- Edge cases: split APKs, obfuscated APKs, packed APKs, APKs with no native code, APKs with no DEX, corrupted APKs
- Integration test: full pipeline run (ingest APK, verify all extractors produce output, verify ClickHouse/ES export)