Details

Tehnike obhoda zaznave skrbniškega dostopa v aplikacijah Android
ID Thuma, Tim (Author), ID Medved, Tilen (Author), ID Pesek, Matevž (Author)

.pdfPDF - Presentation file, Download (183,43 KB)
MD5: 2274618DD55DE1CF40FCC203CA084406
URLURL - Source URL, Visit https://ev.fe.uni-lj.si/1-2-2026/Thuma.pdf This link opens in a new window

Abstract
Skrbniški način uporabe operacijskega sistema Android lahko pinaša varnostno tveganje za aplikacije, saj omogoča izvajanje zlonamerne programske opreme s povečanimi pravicami, zaradi česar proizvajalci v svoje aplikacije vgrajujejo mehanizme za zaznavo in preprečevanje izvajanja na napravah s skrbniškim dostopom. V tem članku predstavimo štiri načine za obhod tovrstnih zaščit, vključno z dinamično in statično naalizo ter dvema konfiguracijsama modulov Magisk. Najprej demonstriramo uporabo teh pristopov na testni aplikaciji, nato pa na naboru 23 slovenskih aplikacij analiziramo pogostost zaznave skrbniškega dostopa, vrste implementiranih zaščit ter učinkovitost predstavljenih metod za obhod zaščite. Zaznava skrbniškega dosotpa, vrste implementiranih zaščit ter učinkovitost predstavvljenih metod za obhod zaščite. Zaznava skrbniškega dostopa je prisotna v 10 analiziranih aplikacijah, kjer je najpogosteje vključena v bančnih aplikacijah. V petih primerih je obhod zaščite uspešen z vsemi opisanimi metodami, v enem pa le z ročno analizo. A aplikacijah, ki uporabljajo šifriranje kode, je obhod zaščite neuspešen, pri štirih od petih preostalih pa trivialen.

Language:Slovenian
Keywords:Android, skrbniški dostop, obhod zaščite mobilnih aplikacij, dinamična analiza, statična analiza, Magisk, Zygisk, Frida, Play Integrity API
Work type:Article
Typology:1.04 - Professional Article
Organization:FE - Faculty of Electrical Engineering
Year:2026
Number of pages:Str. 69-78
Numbering:Letn. 93, št. 1/2
PID:20.500.12556/RUL-183222 This link opens in a new window
UDC:004.056:004.451
ISSN on article:0013-5852
COBISS.SI-ID:279776515 This link opens in a new window
Publication date in RUL:08.06.2026
Views:135
Downloads:92
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Record is a part of a journal

Title:Elektrotehniški vestnik
Publisher:Strokovna zadruga koncesijoniranih elektrotehnikov, Elektrotehniška zveza Slovenije
ISSN:0013-5852
COBISS.SI-ID:742916 This link opens in a new window

Licences

License:CC BY 4.0, Creative Commons Attribution 4.0 International
Link:http://creativecommons.org/licenses/by/4.0/
Description:This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.

Secondary language

Language:English
Title:Methods to bypass the root detection mechanism in Android applications
Abstract:
The root access on the Android operating system can pose a security risk to applications as it allows the execution of malicious software with elevated privileges. For this reason, manufacturers incorporate mechanisms into their applications to detect and prevent execution on devices with root privileges. The paper presents four methods to bypass such protections, including dynamic and static analysis and two configurations of the Magisk modules. First, it demonstrates their use on a test application, and then it analyzes a set of 23 Slovenian applications to determine the frequency of the root detection, the types of the implemented protection methods, and the effectiveness of the presented protection bypassing methods. The root detection is present in ten of the analyzed applications, where it is most often included in mobile banking applications. In five cases, the protection bypass is successful with each of the described methods, and in one case the protection is bypassed only with a manual analysis. In the applications that encrypt parts of their code, bypassing the protection is unsuccessful, while in four of the five remaining cases, it is trivial to prevent root detection

Keywords:Android, administrative access, bypassing mobile application protections, dynamic analysis, static analysis, Magisk, Zygisk, Frida, Play Integrity API

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back