Defending Your Android App

Felipe Sierra, Anthony Ramirez · 2015

In recent years, applications in the Google Play Store have been targets for attackers. Hackers have used a slew of techniques to analyze and modify Android developers' apps. Attackers are modifying app content so they can take advantage of unknowing users. They are also analyzing app content so they can create clones of legitimate apps. Using techniques like reverse engineering, debugging attacks, and dynamic library manipulation, attackers are hacking android apps. We chose to test these techniques against certificate pinning, a method used to authenticate SSL/TLS certificates to prevent MiTM attacks. The research we conducted focused on: (1) Finding apps from the Google Play Store that employ certificate pinning as a security measure for its communications. (2) Studying the three different methods (debugging attacks, reverse engineering, and dynamic library manipulation) used for bypassing certificate pinning on Android Devices. (3) Testing the apps with each tool to see if we could bypass the certificate pinning. (4) After determining the effectiveness of the three methods, we decided to research and develop practices that would allow developers to harden their applications. Our objective is to show these deterrents succeed at protecting against these attacks.

Read the paper · More papers on PaperTik