Android APK Hardening: Defense in Depth

加固提高客户端分析成本;平台证明提供外部可信度;设备注册和业务后端决定一次动作能否被接受

Android APK hardening defense in depth architecture Five security layers connect build-time transformations, runtime shell and RASP, Android platform trust, device registration, and backend risk decisions. ONE REQUEST CROSSES FIVE DIFFERENT TRUST LAYERS deny, step-up, limit or allow with monitored risk threat telemetry and outcomes refresh device and account history 1 / BUILD-TIME COST Code Hardening R8 / names / control flow / strings class encryption / selective VMP / DEX2C goal: delay understanding and reuse 2 / LOCAL EXECUTION COST Shell and RASP loader / decrypt / integrity / anti-hook root / emulator / debugger / overlay signals goal: detect or disturb live analysis 3 / PLATFORM EVIDENCE Signing and Attestation APK v2/v3/v4 / Play App Signing appIntegrity / deviceIntegrity / requestHash goal: add evidence outside app control 4 / IDENTITY CONTINUITY Device Registration install handle / device profile / account link activation / event history / lifecycle rotation goal: preserve explainable continuity 5 / SERVER AUTHORITY Bound Business Request action + amount + object + account + nonce the only useful unit of authorization Evidence Normalizer freshness / app / device / account / network missing is not automatically safe or hostile Risk and Policy Engine graph / velocity / abuse history / entitlement tiered policy replaces one-bit trust Decision and Feedback allow / challenge / limit / deny / observe outcomes age and correct prior confidence WHAT EACH LAYER CAN AND CANNOT PROVE HARDENINGraises cost; cannot attest itself as genuine ATTESTATIONdescribes app/device state; not user intent DEVICE REGISTRATIONlinks history; not physical uniqueness SERVER DECISIONowns authorization and business consequence Design rule: never let a local anti-debug result, device ID, or one integrity verdict become a permanent allow/deny decision by itself.

加固保护的是成本

  • 混淆、加密、抽取与 VMP 延缓代码理解
  • 壳和 RASP 压缩稳定的动态观测窗口
  • 客户端最终仍在攻击者控制的机器上执行

可信度必须来自外部

  • APK 签名保证安装与升级身份连续
  • Attestation 为具体请求提供平台证据
  • 证据必须绑定业务摘要并验证新鲜度

后端保留最终权力

  • 设备句柄只连接历史,不代表真人或真机
  • 授权依赖账号、对象、金额和行为上下文
  • 处置结果持续修正画像与策略