You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

安卓政府保密应用防逆向工程:ProGuard规则最佳实现方案

政府保密应用的ProGuard规则最佳实现方式

当前配置现状

你当前的build.gradle发布版配置:

buildTypes {
    release {
        minifyEnabled true
        proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro'
    }
}

proguard-rules.pro文件内容:

# Add project specific ProGuard rules here.
# You can control the set of applied configuration files using the
# proguardFiles setting in build.gradle.
#
# For more details, see
#   http://developer.android.com/guide/developing/tools/proguard.html

# If your project uses WebView with JS, uncomment the following
# and specify the fully qualified class name to the JavaScript interface
# class:
#-keepclassmembers class fqcn.of.javascript.interface.for.webview {
#   public *;
#}

# Uncomment this to preserve the line number information for
# debugging stack traces.
#-keepattributes SourceFile,LineNumberTable

# If you keep the line number information, uncomment this to
# hide the original source file name.
#-renamesourcefileattribute SourceFile
-keep class com.bsn.buildingaudit.Model.*{*;}

最佳实践优化建议

针对政府保密应用的高安全需求,按以下方式调整ProGuard规则:

1. 强化基础混淆与资源压缩

在build.gradle的release块中添加资源压缩,配合代码混淆进一步缩小攻击面:

buildTypes {
    release {
        minifyEnabled true
        shrinkResources true // 开启资源压缩,移除未使用的资源文件
        proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro'
    }
}

2. 调试信息的安全处理

保留崩溃栈的行号便于问题排查,但隐藏真实源文件名,避免泄露代码结构:

# 保留行号信息用于调试
-keepattributes SourceFile,LineNumberTable
# 将源文件名替换为通用名称,隐藏真实文件路径
-renamesourcefileattribute SourceFile

3. 模型类的精准保护

你当前对模型类的规则过于宽泛,根据模型的实际用途(如序列化、Parcelable)调整为精准规则,减少不必要的代码暴露:

# 如果你用Parcelable传递模型数据,保留CREATOR和必要结构
-keep class com.bsn.buildingaudit.Model.* implements android.os.Parcelable {
    public static final android.os.Parcelable$Creator CREATOR;
}

# 如果用Gson等序列化框架,保留无参构造和字段(根据实际访问权限调整)
-keepclassmembers class com.bsn.buildingaudit.Model.* {
    <init>(); // 保留无参构造
    private <fields>; // 保留私有字段(如果序列化需要)
    public <fields>; // 保留公有字段
}

4. 提升混淆强度

通过自定义字典和包重打包,大幅增加逆向工程的难度:

# 将所有混淆后的类合并到根包,打乱原有包结构
-repackageclasses ''
# 允许修改类的访问权限,让ProGuard可以做更深度的优化
-allowaccessmodification

# 使用自定义字典替换默认混淆命名(需自行创建proguard-dictionary.txt,写入随机字符串)
-obfuscationdictionary proguard-dictionary.txt
-classobfuscationdictionary proguard-dictionary.txt
-packageobfuscationdictionary proguard-dictionary.txt

5. 移除敏感调试信息

彻底移除日志调用和无用代码,避免泄露敏感数据:

# 移除所有Log类的调用,编译时直接删除这些代码
-assumenosideeffects class android.util.Log {
    public static boolean isLoggable(java.lang.String, int);
    public static int v(...);
    public static int i(...);
    public static int w(...);
    public static int d(...);
    public static int e(...);
}

# 忽略不必要的警告和提示,减少逆向者可利用的信息
-dontnote
-dontwarn
-ignorewarnings

6. 适配第三方依赖

针对项目中使用的第三方库(如OkHttp、Retrofit等),添加官方推荐的ProGuard规则,避免混淆导致功能异常。例如OkHttp的规则示例:

-keepattributes Signature
-keepattributes *Annotation*
-keep class okhttp3.** { *; }
-keep interface okhttp3.** { *; }
-dontwarn okhttp3.**

额外安全补充

ProGuard仅能实现代码混淆,对于政府保密应用,还需配合以下防护手段:

  • 使用商业级混淆工具(如DexGuard),提供更强大的代码加密和反逆向能力
  • 接入专业的应用加固服务,对APK进行多层加密保护
  • 对敏感字符串(如接口地址、密钥)进行加密存储,避免静态分析泄露
  • 实现运行时完整性校验,防止APK被篡改

内容的提问来源于stack exchange,提问作者Shiv Shrivas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 13:30:53