Learn To Reverse Engineer Android Tamper Detection

所在平台: Udemy

课程主页: https://www.udemy.com/course/learn-to-reverse-engineer-android-tamper-detection/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:学习逆向工程Android篡改检测 概述:本课程是在2023年1月研讨会期间录制的,旨在帮助学员掌握简单的Android应用程序开发、Android应用程序的逆向工程(包括Java和SMALI代码的反汇编),以及逆向工程中的其他技术(如补丁修复)。课程特别关注理解、利用和破解篡改检测和证明技术,这些技术被银行、在线游戏和流媒体服务使用,以尽量减少其应用程序在被攻击(如root)设备上运行的风险。常见的示例是Google Play的SafetyNet证明API。在课程中,我们将解释什么是证明和篡改检测,它们在Android应用程序中的作用,以及作为逆向工程师我们如何绕过这些技术进行安全测试。 本课程还着重于补丁的概念,即在运行时之前静态地修改Android应用程序,以改变程序的执行。这可以包括修改变量、函数调用和类。在本课程中,我们将利用补丁技术来规避篡改检测和证明技术。 关于讲师:James Stevenson在编程和计算机安全行业工作超过五年,其中大部分时间担任Android软件工程师和漏洞研究员。在此之前,James于2017年获得计算机安全学士学位。他已在个人网站和行业平台(如Infosecurity杂志)上发表过关于安全原则、Android编程与安全及网络恐怖主义等主题的文章。James是一名全职安全研究员,兼职博士生,偶尔作为会议演讲者。除了研究Android内部,James的研究还集中在犯罪嫌疑人画像和网络犯罪检测能力等领域。

课程评论(0条)

课程详情

This course was filmed as part of a workshop ran in January 2023. By the end of this course you'll be able to develop simple Android applications, reverse Android applications to both Java andSMALI, and apply other techniques to your reverse engineering efforts such as patching.This course has a specific focus on understanding, utilising, and subverting tamper detection and attestation techniques. These techniques are used by banks, online games, and streaming services to minimise the potential of their applications running while on compromised (e.g. rooted) devices. A common and mainstream example of this is the Google Play SafetyNet Attestation API. During this course, we explain what attestation and tamper detection is, how it is used inside of Android applications, and how as reverse engineers we can get around these techniques for security testing. This course also focuses on patching. This is the concept of statically altering an Android application before runtime to alter execution of the program. This can include anything from modifying variables, function calls, and classes. In this course we'll use patching to circumvent tamper detection and attestation techniques. About The Author:James Stevenson has been working in the programming and computer security industry for over 5 years, and for most of that has been working as an Android software engineer and vulnerability researcher. Prior to this, James graduated with a BSc in computer security in 2017. James has featured articles on both personal websites and industry platforms such as Infosecurity Magazine - covering topics from security principles to android programming and security to cyber terrorism. James is a full-time security researcher, part-time PhD student, and occasional conference speaker. Outside of Android internals, James' research has also focused on offender profiling and cybercrime detection capabilities.

课程标签

0人关注该课程

主题相关的课程