Penetration testing method for Android game

By identifying the type of game engine, building a hook framework and analyzing game behavior in real time, the problem of poor adaptability of traditional penetration testing to multiple engines is solved, efficient and automated penetration testing is achieved, and the security and test coverage of Android games are improved.

CN120381675AActive Publication Date: 2025-07-29BEIJING ZHI YOU WANG AN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510440784.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-29
Estimated Expiration
2045-04-09

AI Technical Summary

Technical Problem

Traditional penetration testing technology has poor adaptability to diversified game engines, low degree of automation, and it is difficult to effectively intercept and analyze Android games' network communication and memory operations, and requires a lot of manual intervention.

Method used

By analyzing game file identification engine types, extracting key components, building hook frameworks, intercepting and analyzing network communication and memory reading and writing during game runtime, dynamically modifying process status to bypass anti-cheating mechanisms, and performing test tasks in combination with automation tools.

Benefits of technology

It realizes automated penetration testing with cross-engine adaptation, improves testing efficiency and concealment, reduces labor costs, and enhances the effectiveness and comprehensiveness of testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120381675A_ABST
    Figure CN120381675A_ABST
Patent Text Reader

Abstract

The invention provides a penetration testing method for an Android game, and relates to the technical field of security testing and penetration testing of games, the method comprises the following steps: analyzing a game file, identifying a game engine type and extracting a key component to obtain an engine identifier, version information and key file list related information; and analyzing the decompiled byte code, the decompiled Stemari code, the decompiled dynamic library file and the decompiled resource script according to the related information, and positioning an anti-debugging mechanism and an encryption algorithm to obtain a hook framework. Through cross-engine adaptation, automatic detection, anti-detection and safety mechanism bypassing functions, the efficiency and concealment of penetration testing are improved, the labor cost is reduced, and the effectiveness and comprehensiveness of penetration testing are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security testing and penetration testing of games, and particularly to a penetration testing method for Android games. Background Art

[0002] Most traditional penetration testing technologies rely on a single engine or a specific environment for testing, which results in poor adaptability when facing diverse game engines.

[0003] For example, a certain Android game is developed using the Unity engine, while traditional penetration testing tools only support testing a single engine. In this case, testers need to spend a lot of time and effort to find or develop testing tools suitable for the Unity engine, which undoubtedly increases the difficulty and cost of testing. Another game uses the IL2CPP (Intermediate Language to C++) technology for compilation, which makes the game's code more difficult to be reverse-analyzed and dynamically debugged. Most traditional penetration testing tools are unable to effectively hook and intercept when facing games compiled with IL2CPP, and cannot obtain key information during the game's operation.

[0004] In addition, traditional penetration testing technologies require testers to have high reverse-analysis capabilities and professional knowledge, and there is a lot of manual intervention and low automation during the testing process. When conducting network communication analysis, traditional technologies may require testers to manually intercept network request packets and analyze key information one by one, which is not only inefficient but also error-prone.

[0005] For example, when a game uses a complex encrypted communication protocol, manual analysis may miss important security vulnerabilities. When conducting memory read / write monitoring, traditional technologies may require testers to manually set breakpoints through a debugger and observe the changes in memory variables. This method is not only time-consuming and laborious but also difficult to cover all memory read / write operations. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide a penetration testing method for Android games, which enhances the cross-engine adaptability and automated testing of Android games, and improves the testing concealment and efficiency.

[0007] To solve the above technical problem, the technical solution of the present invention is as follows:

[0008] In the first aspect, a penetration testing method for Android games, the method includes:

[0009] By analyzing game files, identifying the game engine type and extracting key components to obtain information related to the engine identifier, version information, and key file list;

[0010] Analyze the decompiled bytecode, Smali code, dynamic library files, and resource scripts based on relevant information, locate the anti-debugging mechanism and encryption algorithm, and obtain the hooking framework;

[0011] Through the hooking framework, intercept and analyze the network communication, memory read / write, and logical calls during the game runtime in real time to obtain network request packets and memory variable value data;

[0012] Based on the network request packets and memory variable value data, dynamically modify the process debugging status and memory verification code to bypass the game anti-cheat mechanism and obtain the preset test rules;

[0013] According to the preset test rules, automatically scan the key programming interfaces and modify the game memory variables to enable the simulated player to perform specific tasks in combination with the automated testing tool;

[0014] Execute batch vulnerability scans through the preset test rule library and generate penetration test reports.

[0015] Furthermore, by analyzing the game files, identify the game engine type and extract the key components to obtain information related to the engine identifier, version information, and key file list, including:

[0016] Parse and decompile the Android game files, extract the AndroidManifest.xml file, resource directory, asset directory, and dynamic library directory, and obtain the package name, version information, and permission requirement data from the application metadata in the AndroidManifest.xml file;

[0017] Convert the Android game files into JAR files, use Java decompilation tools to view the Java source code in the JAR files, determine the specific type of the game engine by analyzing the Java source code; check the files in the asset directory and resource directory, identify the configuration files used by the game, and extract the key information related to the game logic to obtain the game engine identifier, version information, and key file list.

[0018] Furthermore, based on the relevant information, analyze the decompiled bytecode, Smali code, dynamic library files, and resource scripts, and locate the anti-debugging mechanism and encryption algorithm to obtain the hooking framework, including:

[0019] Collect relevant information of the target Android game, including the game engine type, APK file, dynamic library file, and resource script;

[0020] Decompile the APK file, extract the AndroidManifest.xml file, So library, Dex code, and resource files;

[0021] Convert Dex code into Java code using dex2jar or jadx, parse Lua scripts, configuration file resource files, and extract key information, including game logic and configuration parameters, to obtain the static structure information of the game and a preliminary analysis of the running logic; perform logic extraction and code analysis on the converted and parsed Java code, identify key logic and function calls, and finally form the static analysis result;

[0022] Search for key functions in the static analysis result to detect game anti-debugging or anti-cheat mechanisms, and use tools such as readelf and IDA Pro to analyze the so file, identify relevant key functions in the dynamic library, and obtain the dynamic library analysis result;

[0023] Mark anti-debugging points in the static analysis and dynamic library analysis results by searching for key API calls and specific keywords, including frida and xposed, determine the key functions and APIs to be hooked, and generate a list of hook targets;

[0024] Write corresponding hook scripts according to the list of hook targets to obtain a hook framework, that is, the HOOK framework.

[0025] Furthermore, through the hook framework, intercept and analyze the network communication, memory reading and writing, and logic calls during the game runtime in real time to obtain network request packets and memory variable value data, including:

[0026] Use the hook framework function to hook key functions in the game process to obtain the network communication, memory reading and writing, and logic calls during the game runtime;

[0027] Through network communication, the hook framework intercepts network request packets in real time and extracts key information. For memory reading and writing operations, the hook framework monitors the reading and writing process of memory variables, obtains variable values, and analyzes the impact on game logic; according to logic calls, the hook framework tracks the call sequence and parameter passing, analyzes the implementation details of game logic, and obtains network request packets and memory variable value data through the interception and analysis functions of the hook framework.

[0028] Furthermore, according to the network request packets and memory variable value data, dynamically modify the process debugging status and memory verification code to bypass the game anti-cheat mechanism and obtain preset test rules, including:

[0029] Analyze the network request packets and memory variable value data, identify network communication and memory variable access data related to the anti-cheat mechanism, and according to the network communication data, check the debugger detection code and process debugging status in the game process;

[0030] Analyze the data access of memory variables, identify the code segments for verifying memory data, and determine the verification logic and key variables through reverse engineering to modify the values of the verification variables in memory;

[0031] Implement an anti-cheat mechanism based on the modified values of the verification variables to perform test operations, and adjust the test strategy according to the test results to obtain preset test rules.

[0032] Furthermore, according to the preset test rules, automatically scan the key programming interfaces and modify the game memory variables so that the simulated player combines with the automated test tool to perform specific tasks, including:

[0033] Use an automated scanning tool to scan the key programming interfaces in the game process to obtain the scanning results;

[0034] According to the preset test rules and the scanning results, identify the game memory variables that need to be modified, including game status, player data, and resource quantity, and simulate the player's behavior to perform specific tasks according to the automated test tool, including automatically killing monsters, automatically leveling up, and automatically completing tasks.

[0035] Furthermore, the key programming interfaces include logic processing functions, network communication functions, and memory access functions.

[0036] Furthermore, through the preset test rule library, perform batch vulnerability scans and generate penetration test reports, including:

[0037] Build a preset test rule library according to the security vulnerability information, and classify the test rule library according to the dimensions of vulnerability type, impact scope, and exploitation difficulty;

[0038] Use the preset test rule library to perform batch vulnerability scans on Android games. The scanning tool automatically performs static analysis on the game code according to the test rules in the rule library, identifies potential vulnerability points, and forms a preliminary vulnerability list, including vulnerability type, trigger conditions, and impact scope information;

[0039] Generate a penetration test report according to the preliminary vulnerability list, including the description of the vulnerability, severity assessment, trigger conditions, and impact scope information.

[0040] In a second aspect, a computing device includes:

[0041] One or more processors;

[0042] A storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the method described above.

[0043] In a third aspect, a computer-readable storage medium stores a program which, when executed by a processor, implements the method described above.

[0044] The above solution of the present invention has at least the following beneficial effects:

[0045] This method integrates attack tools for multiple mainstream game engines, including Unity, Unreal Engine, Cocos, IL2CPP, Mono, and Lua, and can perform penetration testing in a unified and generalized manner. By analyzing the code structures and call processes of different engines, it provides a highly adaptable and wide-coverage test solution, solving the problem that existing test methods require customized tools for different game engines. It provides a variety of automated attack tools, including speed modification, script decryption, and code injection, reducing manual intervention. Through predefined rules, script execution, and automated interaction, it realizes a batch and efficient test process, thereby reducing labor costs and improving test efficiency.

[0046] In the design, full consideration is given to dealing with the anti-debugging and anti-modification mechanisms of games. By using means such as memory tampering, dynamic HOOK, code injection, and memory snapshot comparison, it can successfully bypass the anti-cheat mechanisms of games, improve the effectiveness and concealment of penetration testing, and enhance the practicality of testing. And it provides a standardized interface including an API or a plugin system, supporting seamless access of different test modules and being compatible with existing penetration testing tools including Frida, Ghidra, and IDA Pro. This design enables users to extend new detection functions based on the API, realize customizable attack vectors, and enhance flexibility and scalability. Description of the Drawings

[0047] Figure 1 It is a flowchart showing a penetration testing method for Android games provided by an embodiment of the present invention. Detailed Embodiments

[0048] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0049] As Figure 1 shown, an embodiment of the present invention proposes a penetration testing method for Android games, and the method includes the following steps:

[0050] Step 1, by analyzing the game files, identify the game engine type and extract key components to obtain information related to the engine identifier, version information, and key file list;

[0051] Step 2, according to the relevant information, analyze the decompiled bytecode, Smali code, dynamic library files, and resource scripts, and locate the anti-debugging mechanism and encryption algorithm to obtain the hook framework;

[0052] Step 3, through the hook framework, intercept and analyze the network communication, memory read / write, and logic calls during the game runtime in real-time to obtain network request packets and memory variable value data;

[0053] Step 4, according to the network request packets and memory variable value data, dynamically modify the process debugging status and memory verification code to bypass the game anti-cheat mechanism and obtain the preset test rules;

[0054] Step 5, according to the preset test rules, automatically scan the key programming interfaces and modify the game memory variables so that the simulated player combines with the automated test tool to operate and execute specific tasks;

[0055] Step 6, through the preset test rule library, perform batch vulnerability scans and generate penetration test reports.

[0056] In the embodiment of the present invention, by analyzing the game files to identify the engine type and extract key components, it is ensured that the test method is customized for specific game engines, improving the accuracy and effectiveness of the test. Deeply analyze various decompiled codes and files to locate the anti-debugging mechanism and encryption algorithm, thereby constructing a hook framework, enabling the test to penetrate deep into the game and discover more potential security issues, and using the hook framework to intercept and analyze various behaviors during the game runtime in real-time, including network communication, memory read / write, and logic calls, to obtain detailed runtime data.

[0057] Dynamically modify the process debugging status and memory verification code to effectively bypass the game's anti-cheat mechanism, enabling the test to be carried out under a situation closer to the real game environment and improving the practicality of the test. According to the preset test rules, automatically scan the key programming interfaces and modify the game memory variables, and combine with the automated test tool to simulate the player's operation to execute specific tasks, improving the test efficiency. Perform batch vulnerability scans through the preset test rule library and generate detailed penetration test reports.

[0058] In a preferred embodiment of the present invention, the above Step 1, by analyzing the game files, identify the game engine type and extract key components to obtain information related to the engine identifier, version information, and key file list, may include:

[0059] Step 110: Parse and decompile the Android game file, extract the AndroidManifest.xml file, resource directory, asset directory, and library dynamic directory, and obtain the package name, version information, and permission requirement data from the application metadata in the AndroidManifest.xml file;

[0060] Step 111: Convert the Android game file into a JAR file, view the Java source code in the JAR file using a Java decompilation tool, determine the types unique to the game engine by analyzing the Java source code; check the files in the asset directory and resource directory, identify the configuration files used by the game, and extract the key information related to the game logic to obtain the game engine identifier, version information, and key file list.

[0061] In the embodiment of the present invention, unzip and extract the AndroidManifest.xml (AndroidManifest file), res / directory (resource directory), assets / directory (asset directory), and lib / directory (library dynamic directory), parse the AndroidManifest.xml file, and obtain the package name (package attribute), version information (versionName and versionCode attributes), and permission requirement data of the application ( <uses-permission>Label).

[0062] Step 111, extract the classes.dex file from the APK file, use the d2j-dex2jar tool to convert the classes.dex file into a JAR file, and open the JAR file with Java decompilation tools including Jadx, CFR or JD-GUI to view the Java source code, analyze the Java source code, and find classes, methods or variables unique to the game engine to determine the type of the game engine. Check the files in the assets / directory and res / directory, identify the configuration files used by the game, including files in JSON and XML formats, extract the key information related to the game logic, including game settings, level data, and character attributes, and organize and output the game engine identification, version information, and key file list.

[0063] Suppose there is an Android game APK file developed using the Unity engine. Extract the AndroidManifest.xml, res / , assets / , and lib / directories. Obtain the package name as com.example.unitygame and the version information as 1.0.0 from the AndroidManifest.xml, and list all permission requirements.

[0064] Convert the classes.dex file into a JAR file and open the JAR file with a Java decompilation tool. The UnityPlayerActivity class is found, confirming that the game engine is Unity. Determine the game_settings.json configuration file in the assets / directory and extract the game setting information from it. Determine the game icon and sound effect resource files in the res / directory. Output the game engine identification as Unity, the version information as 1.0.0, and the key file list including game_settings.json, the game icon, and the sound effect resource files.

[0065] By automatically parsing and decompiling the APK file, the type of the game engine can be quickly identified and key components can be extracted, reducing the time and cost of manual analysis. By deeply analyzing the Java source code and configuration files, the type of the game engine, version information, and key information of the game logic are determined, providing important clues and bases for the engine identification, version information, and key file list. Based on this information, security researchers conduct targeted tests and analyses for specific engines and versions, promoting the development of game security research and improving the security awareness and protection capabilities of game developers and security researchers.

[0066] In a preferred embodiment of the present invention, in step 2 above, according to relevant information, analyze the decompiled bytecode, Smali code, dynamic library files, and resource scripts, and locate the anti-debugging mechanism and encryption algorithm to obtain a hook framework, which may include:

[0067] Step 220, collect relevant information of the target Android game, including the game engine type, APK file, dynamic library file, and resource script;

[0068] Step 221, decompile the APK file to extract the AndroidManifest.xml file, So library, Dex code, and resource files;

[0069] Step 222, use dex2jar or jadx to convert the Dex code into Java code, parse the Lua script and configuration file resource files, extract key information, including game logic and configuration parameters, to obtain the static structure information of the game and a preliminary analysis of the running logic; perform logic extraction and code analysis on the converted and parsed Java code, identify key logic and function calls, and finally form a static analysis result;

[0070] Step 223, search for key functions in the static analysis result to detect the game's anti-debugging or anti-cheat mechanism, and use the readelf and IDA Pro tools to analyze the so file to identify relevant key functions in the dynamic library and obtain a dynamic library analysis result;

[0071] Step 224, mark anti-debugging points in the static analysis and dynamic library analysis results by searching for key API calls and specific keywords, including frida and xposed, determine the key functions and APIs to be hooked, and generate a hook target list;

[0072] Step 225, write corresponding hook scripts according to the hook target list to obtain a hook framework, that is, a HOOK framework.

[0073] In an embodiment of the present invention, based on the APK file header information and in-game features, including UI style and physical engine performance, preliminarily judge the game engine type used, including Unity, Unreal Engine, and Cocos2d-x. Download the APK file of the game from the official channel or a trusted source, decompress the APK through the APK analysis tool APKTool to obtain the so file therein, that is, the dynamic library, and extract the game resource files including pictures, sound effects, and Lua scripts to obtain the game engine type, APK file, dynamic library file list, and resource script list.

[0074] Step 221: Use the APKTool tool to decompress the APK file to obtain the decompressed folder, including AndroidManifest.xml, classes.dex (Dex code), lib / (So library directory), and res / (resource file directory). Decompile the binary-format AndroidManifest.xml into a readable XML format to obtain the Dex code for decompiling the So file. Use dex2jar to convert classes.dex into a JAR file, or use jadx to directly generate Java source code to obtain the decompiled AndroidManifest.xml, So library file, Java source code, and resource files.

[0075] Step 222: Use code analysis tools, including SonarQube and PMD, to perform static analysis on the Java code, extract key information such as game logic and configuration parameters, and use Lua parsers, including LuaJIT, to read and parse scripts to extract game logic and configuration. According to the file type, including SON, XML, and INI, use the corresponding parser to read the content of the configuration file to form the static structure information of the game and a preliminary analysis of the running logic.

[0076] Step 223: Search the Java code and Lua scripts for functions related to anti-debugging and anti-cheating, including detecting debuggers and modifying memory values. Use readelf to view the symbol table of the So file to identify functions related to anti-debugging and anti-cheating; use IDA Pro for more in-depth dynamic library analysis, including viewing the function call graph and data flow, to obtain the dynamic analysis results.

[0077] Step 224: Search the static analysis results and dynamic library analysis results for API calls related to the frida and xposed debugging frameworks. Based on the search results, mark the points in the game code used to detect debuggers. Combine the game logic and anti-debugging mechanism to determine the key functions and APIs to be hooked, and organize the determined hook targets into a list.

[0078] Step 225: Determine the hooking framework, including Xposed and Frida, according to the game engine type and anti-debugging mechanism, and write the corresponding hooking script through the hook target list to achieve the interception and modification of key functions and APIs.

[0079] Suppose the target is an RPG game developed using the Unity engine, and the APK file is named MyRPGGame.apk. Decompress the APK using APKTool to obtain AndroidManifest.xml, classes.dex, lib / , res, convert classes.dex to a JAR file using dex2jar, decompile the JAR file into Java source code using jadx, and parse the res / raw / game_config.json configuration file and Java code to extract game logic and configuration parameters.

[0080] Use readelf and IDA Pro to analyze libunity.so, identify key functions related to anti-debugging, and search for API calls of the frida and xposed debugging frameworks in the static analysis results and dynamic library analysis results. Mark the points in the game code used to detect the debugger, and determine the key functions and APIs to be hooked, including android.os.Debug.isDebuggerConnected(). Write a hooking script to intercept and modify the return value of the android.os.Debug.isDebuggerConnected function.

[0081] Through hooking framework technology, bypass the game's regular anti-debugging mechanism, effectively prevent game crackers from debugging and analyzing behaviors, and at the same time intercept and modify game key functions and APIs to enhance the game's security and prevent malicious modification or cheating. Provide game developers with efficient debugging and analysis tools, use hooking framework technology to quickly locate problems in the game and optimize them, and improve the efficiency and quality of game development.

[0082] In a preferred embodiment of the present invention, in step 3 above, monitor game data through a hooking framework, and intercept and analyze network communication, memory reading and writing, and logical calls during game operation in real time to obtain network request packets and memory variable value data, which may include:

[0083] Step 330, use the hooking framework function to hook key functions in the game process to obtain network communication, memory reading and writing, and logical calls during game operation;

[0084] Step 331, through network communication, the hooking framework intercepts network request packets in real time and extracts key information. For memory reading and writing operations, the hooking framework monitors the reading and writing process of memory variables, obtains variable values, and analyzes the impact on game logic; according to logical calls, the hooking framework tracks the call sequence and parameter passing, analyzes the implementation details of game logic, and obtains network request packets and memory variable value data through the interception and analysis functions of the hooking framework.

[0085] In an embodiment of the present invention, the basic parameters of the hook framework are configured, including the target process name and the list of functions to be hooked, and the entry address of the target function is searched in the address space of the game process. The exact location of the function is determined by the pattern matching method, and the entry instruction of the target function is modified to direct to the processing function of the hook framework. The entry instruction of the original function is saved. In the processing function of the hook framework, custom logic is executed to monitor the behavior of the game process. For the original function that continues to execute, the saved original function entry instruction is called or a jump instruction is used to return to the original execution flow.

[0086] Step 331, when the game process receives a network request, the hook framework obtains the request packet and extracts the key information in the network request packet, including the URL, request headers, request body, and response data. The monitoring logic for memory read and write operations is set in the hook framework. When the game process performs read and write operations on memory variables, the hook framework records the address, value, and timestamp of the read and write operations of the memory variables, and analyzes the impact of the read and write process of the memory variables on the game logic. Through the tracking logic of logical calls, the hook framework records the call order and parameter passing, and analyzes the implementation details of the game logic, including function call relationships, parameter passing methods, and return values. The intercepted network request packets, memory variable values, and logical call information are integrated and analyzed, and output to the developer in the form of a report.

[0087] Suppose the hook framework monitors the running data of an online game, and configures the list of functions to be hooked, including network send / receive functions, memory allocation / free functions, and key functions in the game logic. The entry address of the network send function is searched in the address space of the game process by the pattern matching method, the exact location of the function is confirmed, and the entry instruction of the network send function is modified to direct to the hook framework processing function. When the game process attempts to send a network request, the hook framework captures the request packet.

[0088] Extract the URL, request headers, and request body information in the request packet, and monitor the read and write operations of the game process on key memory variables, recording the address, value, and operation timestamp. Track the specific function call order and parameter passing in the game logic, and integrate the intercepted network request packet information, memory variable values, and function call situations into a log file.

[0089] By intercepting and analyzing the data during the game operation in real time, potential malicious behaviors, including cheating and external plugins, can be discovered in a timely manner, and the security and fairness of the game can be improved, protecting the interests and game experience of players, helping to quickly locate problems in the game, reducing the time cost of debugging and analysis, and improving the development efficiency and quality. By hooking the logical calls and memory read and write operations in the game, the expansion and innovation of the game play are realized, providing a rich and diverse game experience, and enhancing the attractiveness and competitiveness of the game.

[0090] In a preferred embodiment of the present invention, step 4, dynamically modifying the process debugging state and memory verification code according to the network request packet and memory variable value data to bypass the game anti-cheat mechanism and obtain a preset test rule, may include:

[0091] Step 440, analyze the network request packet and memory variable value data, identify network communication and memory variable access data related to the anti-cheat mechanism, and check the debugger detection code and process debugging state in the game process according to the network communication data;

[0092] Step 441, analyze the memory variable access data, identify the code segment for verifying memory data, and determine the verification logic and key variables through reverse engineering to modify the verification variable values in the memory;

[0093] Step 442, implement the anti-cheat mechanism according to the modified verification variable values to perform test operations, and adjust the test strategy according to the test results to obtain a preset test rule.

[0094] In the embodiment of the present invention, parse the obtained network request packet to identify requests related to the anti-cheat mechanism, including debugger detection requests and verification requests. Parse the memory variable value data to locate the memory areas related to the anti-cheat mechanism, including the memory address storing the debugging state and the storage location of the verification code. Analyze the network communication data, identify the execution points of the debugger detection code in the game process, and check the process debugging state to confirm whether the current game process is in a debugged state, including by checking specific memory flag bits or calling specific API functions.

[0095] Step 441, set memory breakpoints in the game process, monitor memory variable access operations related to the anti-cheat mechanism, and record the code segments of the read, write, and execution operations of the memory variables. Perform reverse engineering on the recorded memory access code segments, analyze the logic for verifying memory data, determine the verification algorithm, including CRC verification, hash verification, and key variables including verification codes and seed values. According to the results of reverse analysis, locate the storage location of the verification variables, write a memory modification script, including using the Lua script of Cheat Engine, and dynamically modify the verification variable values in the memory to pass the verification.

[0096] Step 442, inject a custom DLL or modify the existing code in the game process to bypass the detection of the anti-cheat mechanism, execute operations to modify game data and trigger specific events to verify the effectiveness of bypassing the anti-cheat mechanism. Collect logs and data during the test process, analyze the effect and stability of bypassing the anti-cheat mechanism. Identify potential factors that may cause the anti-cheat mechanism to be reactivated, including game updates and anti-cheat mechanism upgrades. According to the analysis of the test results, adjust the test strategy, including increasing test scenarios and optimizing the memory modification script, to obtain a preset test rule.

[0097] Suppose there is an online multiplayer game. The anti-cheat mechanism includes debugger detection and memory verification. Use Wireshark to obtain the network communication packets between the game client and the server, identify the debugger detection requests, and read the memory of the game process through x64dbg to locate the memory address storing the debug status. Analyze the network communication data, inject a custom DLL into the game process, intercept the API function calls, and return false results indicating that the game process is not being debugged. Set memory breakpoints in the game process, monitor the variable access operations related to memory verification, and determine the verification algorithm and key variables through reverse engineering, including the storage location of the verification code. Write a Lua script for Cheat Engine to dynamically modify the verification code in memory to pass the verification. Perform test operations, including modifying game character attributes and triggering special events to verify the effectiveness of bypassing the anti-cheat mechanism. Analyze based on the test results and adjust the test strategy, including adding test scenarios, optimizing the memory modification script, and formulating preset test rules.

[0098] By bypassing the anti-cheat mechanism, testers can efficiently perform test operations and simplify the test process according to the use of preset test rules, improving test efficiency. After bypassing the anti-cheat mechanism, testers can access more game functions and scenarios, thereby enhancing test coverage, discovering more potential game problems and vulnerabilities, and improving game quality, freedom, and innovation space. Developers can test new game functions and adjust game balance more freely without worrying about the limitations of the anti-cheat mechanism. By using automated test scripts and preset test rules, the test cost and time cost can be reduced, and it helps game developers launch new versions and update content faster to meet player needs.

[0099] In a preferred embodiment of the present invention, step 5, according to the preset test rules, automatically scan the key programming interfaces and modify the game memory variables so that the simulated player can perform specific tasks in combination with the automated test tool, may include:

[0100] Step 550, use an automated scanning tool to scan the key programming interfaces in the game process to obtain the scan results;

[0101] Step 551, according to the preset test rules and the scan results, identify the game memory variables that need to be modified, including game status, player data, and resource quantity, and simulate the behavior of the player to perform specific tasks according to the automated test tool, including automatically killing monsters, automatically leveling up, and automatically completing tasks.

[0102] In the embodiments of the present invention, the parameters of the scanning tool are configured, including the scanning range, scanning speed, and scanning depth, and the API is used to obtain the ID of the currently running game process to verify whether the game process is the target game, ensuring the accuracy of the scanning. According to the preset interface characteristics, including function signatures and memory address ranges, the game process memory is scanned, and the scanned interface information is recorded, including interface addresses, interface names, and interface parameters. The scanned interface information is organized into a report format.

[0103] Step 551, the rule content includes the game states, player data, resource quantities to be monitored, and the corresponding modification logics. Through the scanning results, the key programming interfaces related to the test rules are identified, the game memory variables to be modified are determined, and a memory modification tool including Cheat Engine or a custom memory operation function is used to modify the identified game memory variables, including game states, player data, and resource quantities.

[0104] According to the test rules, simulate the behavior of players to perform specific tasks, including using an automated test tool or a custom script to control the actions of game characters, including automatically killing monsters, automatically leveling up, and automatically completing tasks, observe the changes in the game process, and check whether the simulated player behavior is executed as expected, and record the test results.

[0105] Suppose a RPG game is being tested, and the goal is to verify whether the game can automatically unlock new skills when the player reaches a specific level. Load Cheat Engine, configure the scanning range as the game process memory, and use the Windows API to obtain the game process ID and verify that the process name is "RPGGame.exe". Scan the game process memory to find functions or variables related to the player level. Suppose a memory address 0x12345678 is scanned, which stores the player's current level. Read the test rule file, which states that when the player level reaches 10, the new skill "Fireball" should be unlocked, and confirm that the memory address 0x12345678 is related to the test rules. Use Cheat Engine to modify the value of the memory address 0x12345678 to 10, and use an automated test script to control the game character to enter the battle and observe whether the new skill "Fireball" is automatically unlocked, and record the test results.

[0106] By simulating the behavior of players to perform specific tasks, game scenarios and boundary conditions that are difficult to reach by manual testing can be covered. The automated test tool precisely controls the game process and memory variables, reduces test errors caused by human factors, and discovers and fixes problems in the game through testing. Integrating the automated test into the continuous integration process can achieve the rapid iteration and release of the game, improving the stability and user experience of the game.

[0107] In another preferred embodiment of the present invention, the key programming interfaces include logic processing functions, network communication functions, and memory access functions, and may include:

[0108] In the embodiments of the present invention, according to the functions and processes of the game, identify the key functions for processing game logic, including game state update, event handling, and AI behavior. Search for functions related to network communication, including functions for sending and receiving data, and functions for processing network protocols including WebSocket, gRPC, TCP / UDP.

[0109] Hook the identified key functions, write Hook scripts to monitor the calls and executions of the key functions, record function parameters and return values, and memory changes during the function execution. Set mitmproxy as a man-in-the-middle proxy to intercept the network communication traffic of the game and observe the changes in the game state to verify the effectiveness of the memory access functions. By hooking the memory access functions, monitor the changes in game memory variables in real time and analyze the roles and influence scopes of the variables.

[0110] Classify and organize the identified logic processing functions, network communication functions, and memory access functions according to their functions and types. Extract the names, parameters, return values, call relationships, and roles and influences in the game of each function. Select document formats including Markdown, Word, and PDF, and write interface documents to describe in detail the functions, usage methods, parameter descriptions, and example codes of each key programming interface to ensure the accuracy and integrity of the documents.

[0111] In a preferred embodiment of the present invention, in step 6 above, through a preset test rule library, perform batch vulnerability scanning and generate a penetration test report, which may include:

[0112] Step 660, construct a preset test rule library according to the security vulnerability information, and classify the test rule library according to the dimensions of vulnerability types, influence scopes, and exploitation difficulties;

[0113] Step 661, use the preset test rule library to perform batch vulnerability scanning on Android games. The scanning tool automatically performs static analysis on the game code according to the test rules in the rule library, identifies potential vulnerability points, and forms a preliminary vulnerability list, including vulnerability types, trigger conditions, and influence scope information;

[0114] Step 662, generate a penetration test report according to the preliminary vulnerability list, including descriptions of the vulnerabilities, severity assessments, trigger conditions, and influence scope information.

[0115] In the embodiments of the present invention, according to the collected vulnerability information, test rules are written, including the identification conditions, triggering methods, and impact assessments of vulnerabilities, and the test rules are organized using a unified format and naming convention. The test rules are classified according to vulnerability types including SQL injection, XSS, and privilege escalation, and the constructed test rule library is stored in a secure database to ensure data integrity and confidentiality, and the test rule library is updated regularly to address new security threats and vulnerabilities.

[0116] Step 661: According to the characteristics and security requirements of Android games, ensure that the scanning tool is compatible with the test rule library, and correctly parse and execute the test rules. Set the target scope of the scan, including the game version, module, or file path to be scanned. Start the scanning tool, and perform a batch vulnerability scan on the Android game according to the preset test rule library. After the scan is completed, collect the scan results, including the initial vulnerability list, vulnerability details, and triggering conditions, to ensure the accuracy and readability of the results.

[0117] Step 662: Conduct a detailed analysis of the initial vulnerability list, confirm the authenticity and severity of the vulnerabilities, evaluate the exploitation difficulty and potential impact of the vulnerabilities, in order to write a penetration test report, including the description of the vulnerabilities, severity assessment, triggering conditions, and impact scope information, and review the content of the report to ensure the accuracy and integrity of the report.

[0118] Suppose there is an Android game application, including user login, in-game purchases, and leaderboards. Collect vulnerability information related to the Android game, including SQL injection vulnerabilities and XSS vulnerabilities. Check whether user input is fully verified and filtered according to the SQL injection vulnerability rules, and classify and store the test rules according to vulnerability types, impact scope, and exploitation difficulty. Determine the static analysis scanning tool, configure the scan parameters to execute the scan, and the tool performs static analysis on the game code according to the test rule library, identifies potential vulnerability points, and collects the scan results to form an initial vulnerability list. Analyze the vulnerability list to confirm the authenticity and severity of the vulnerabilities in order to generate a penetration test report.

[0119] Through batch vulnerability scanning and penetration test reports, security vulnerabilities in Android games can be discovered and fixed in a timely manner, improving the security of the games and reducing the risk of user data leakage and paralysis caused by security vulnerabilities. The penetration test report provides clear vulnerability information and repair suggestions for developers, helping to quickly locate and fix vulnerabilities, reducing the maintenance costs caused by security incidents, and improving the security of the games and user trust in the games.

[0120] An embodiment of the present invention further provides a computing device, including: a processor and a memory storing a computer program. When the computer program is run by the processor, the above-mentioned method is executed. All implementation manners in the above method embodiments are applicable to this embodiment and can also achieve the same technical effects.

[0121] An embodiment of the present invention further provides a computer-readable storage medium storing instructions. When the instructions are run on a computer, the computer is caused to execute the above-mentioned method. All implementation manners in the above method embodiments are applicable to this embodiment and can also achieve the same technical effects.

[0122] The above are the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A penetration testing method for Android games, characterized in that, The method includes: By analyzing game files, identifying the game engine type and extracting key components to obtain information related to the engine identifier, version information, and key file list; According to the relevant information, analyze the decompiled bytecode, Smali code, dynamic library files, and resource scripts, and locate the anti-debugging mechanism and encryption algorithm to obtain the hooking framework; Through the hooking framework, intercept and analyze the network communication, memory reading and writing, and logical calls during game runtime in real time to obtain network request packets and memory variable value data; According to the network request packets and memory variable value data, dynamically modify the process debugging status and memory verification code to bypass the game anti-cheat mechanism and obtain the preset test rules; According to the preset test rules, automatically scan the key programming interfaces and modify the game memory variables to enable the simulated player to perform specific tasks in combination with the automated test tool; Through the preset test rule library, perform batch vulnerability scans and generate penetration test reports.

2. The penetration testing method for Android games according to claim 1, characterized in that, By analyzing game files, identifying the game engine type and extracting key components to obtain information related to the engine identifier, version information, and key file list, including: Parse and decompile the Android game file, extract the AndroidManifest.xml file, resource directory, asset directory, and dynamic library directory, and obtain the package name, version information, and permission requirement data from the metadata of the application in the AndroidManifest.xml file; Convert the Android game file into a JAR file, use a Java decompilation tool to view the Java source code in the JAR file, and determine the specific type of the game engine by analyzing the Java source code; check the files in the asset directory and resource directory, identify the configuration files used by the game, and extract the key information related to the game logic to obtain the game engine identifier, version information, and key file list.

3. The penetration testing method for Android games according to claim 2, characterized in that, According to the relevant information, analyze the decompiled bytecode, Smali code, dynamic library files, and resource scripts, and locate the anti-debugging mechanism and encryption algorithm to obtain the hooking framework, including: Collect relevant information of the target Android game, including the game engine type, APK file, dynamic library file, and resource script; Decompile the APK file to extract the AndroidManifest.xml file, So library, Dex code, and resource files; Use dex2jar or jadx to convert the Dex code into Java code, parse the Lua script, configuration file, and resource file, and extract key information, including game logic and configuration parameters, to obtain the static structure information of the game and a preliminary analysis of the running logic; perform logical extraction and code analysis on the converted and parsed Java code, identify the key logic and function calls, and finally form the static analysis result; Search for key functions in the static analysis result to detect the game anti-debugging or anti-cheat mechanism, and use the readelf and IDA Pro tools to analyze the so file to identify the relevant key functions in the dynamic library and obtain the dynamic library analysis result; By searching for key API calls and specific keywords, including frida and xposed, mark anti-debug points in the results of static analysis and dynamic library analysis, determine the key functions and APIs to be hooked, and generate a list of hook targets; According to the list of hook targets, write the corresponding hook script to obtain the hook framework, that is, the HOOK framework.

4. The penetration testing method for Android games according to claim 3, characterized in that, Monitor game data through the hook framework, intercept and analyze network communication, memory reading and writing, and logical calls during game operation in real time to obtain network request packets and memory variable value data, including: Use the functions of the hook framework to hook the key functions in the game process to obtain network communication, memory reading and writing, and logical calls during game operation; Through network communication, the hook framework intercepts network request packets in real time and extracts key information. For memory reading and writing operations, the hook framework monitors the reading and writing process of memory variables, obtains variable values, and analyzes the impact on game logic; According to logical calls, the hook framework tracks the call sequence and parameter passing, analyzes the implementation details of game logic, and obtains network request packets and memory variable value data through the interception and analysis functions of the hook framework.

5. The penetration testing method for Android games according to claim 4, wherein According to the network request packets and memory variable value data, dynamically modify the process debugging status and memory verification code to bypass the game anti-cheat mechanism and obtain preset test rules, including: Analyze the network request packets and memory variable value data, identify network communication and memory variable access data related to the anti-cheat mechanism, and check the debugger detection code and process debugging status in the game process according to the network communication data; Analyze the memory variable access data, identify the code segment for verifying memory data, and determine the verification logic and key variables through reverse engineering to modify the verification variable values in memory; Implement the anti-cheat mechanism according to the modified verification variable values to execute test operations, and adjust the test strategy according to the test results to obtain preset test rules.

6. The penetration testing method for Android games according to claim 5, wherein According to the preset test rules, automatically scan key programming interfaces and modify game memory variables so that the simulated player combines with the automated test tool to operate and execute specific tasks, including: Use the automated scanning tool to scan the key programming interfaces in the game process to obtain the scanning results; According to the preset test rules and scanning results, identify the game memory variables that need to be modified, including game status, player data, and resource quantity, and simulate the player's behavior to execute specific tasks according to the automated test tool, including automatically killing monsters, automatically leveling up, and automatically completing tasks.

7. The penetration testing method for Android games according to claim 6, wherein The key programming interfaces include logic processing functions, network communication functions, and memory access functions.

8. The penetration testing method for Android games according to claim 7, characterized in that Execute batch vulnerability scans through the preset test rule library and generate a penetration test report, including: Build a preset test rule library according to the security vulnerability information and classify the test rule library according to the dimensions of vulnerability type, impact range, and exploitation difficulty; Use the preset test rule library to perform batch vulnerability scans on Android games. The scanning tool automatically performs static analysis on the game code according to the test rules in the rule library, identifies potential vulnerability points, and forms a preliminary vulnerability list, including vulnerability type, trigger condition, and impact range information; Generate a penetration testing report based on the preliminary vulnerability list, including vulnerability descriptions, severity assessments, triggering conditions, and impact scope information.

9. A computing device, characterized in that, Including: One or more processors; A storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the method according to any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that, A program is stored in the computer-readable storage medium, and when the program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Game data processing method and device, storage medium and electronic equipment

    CN119015713A

  • JavaScript obfuscation by hooking automatically decrypted and how to detect malicious Web sites

    KR1020120070018A