Skip to content

Behavioral Protection

Emirhan Uçan edited this page Jul 15, 2026 · 6 revisions

Behavioral Protection

HydraDragonAV Mobile includes a comprehensive suite of runtime behavioral detectors that protect against UI-based attacks, automated abuse, and configuration tampering — all without root or accessibility-service overreach.

1. UI Hijacking / Clickjacking Protection

Detects and blocks automated UI manipulation attacks:

Attack Type Detection Method
Automated rapid clicks Detects inhumanly fast permission-granting click sequences
Notification spam floods Monitors notification frequency from individual apps
Repeated overlay/dialog abuse Flags apps that repeatedly draw overlays or system dialogs
StrandHogg (Task Hijacking) Monitors activity stack for task-hijacking patterns

When detected, the offending app's background process is killed and a system uninstall prompt is displayed.

2. Notification Spam Detection

Monitors notification frequency and patterns to identify adware and spam apps:

  • Tracks notification volume per app over time
  • Flags apps that exhibit adware-style notification behavior
  • Each detector is individually toggleable from Settings

3. Settings Self-Protection

HydraDragonAV Mobile hardens its own Settings UI against automated tampering:

  • Tapjacking prevention: Every toggle/button checks FLAG_WINDOW_IS_OBSCURED — if an overlay is detected, the tap is rejected.
  • Burst detection: An inhumanly fast burst of setting changes (the signature of a malicious accessibility service driving the UI) is detected, reverted, and blocked.
  • Result: Only the actual device owner can change protection settings.
  • FLAG_SECURE guard: Detects unauthorized removal of FLAG_SECURE (screen recording protection). An optional "Allow screen recording" Settings toggle lets the user intentionally disable FLAG_SECURE — when enabled, the guard stops polling and does NOT treat the removal as tampering.
┌──────────────────┐
│  User taps       │
│  a setting       │
└────────┬─────────┘
         │
    ┌────▼────┐
    │ Overlay │      Yes
    │ present?│─────────► REJECT
    └────┬────┘
         │ No
    ┌────▼────┐
    │ Burst   │      Yes
    │ pattern?│─────────► REVERT + BLOCK
    └────┬────┘
         │ No
    ┌────▼────┐
    │  ALLOW  │
    │  change │
    └─────────┘

4. Screen Capture Protection

  • Screen recording guard: Detects unauthorized screen recording attempts.
  • FLAG_SECURE enforcement: Opt-in toggle to force FLAG_SECURE on the app's own windows, preventing screen capture by other apps.

5. Behavioral Detection Suite (Runtime)

A dedicated set of runtime detectors, each individually toggleable from Settings:

Detector Function
UI/Notification Spam Identifies adware-style apps with aggressive notification behavior
Device Rooted Mid-Session Monitors for root access appearing after app installation
Permission+DNS Risk Score Combines permission analysis with DNS query patterns for risk scoring
Ransomware Behavior Active file I/O + screen interaction pattern analysis

Every hit immediately:

  1. Kills the offending app's background process (where possible)
  2. Pops the system uninstall prompt

6. Bloatware Cleaner

Background cleanup tool for removing pre-installed bloatware and suspicious apps, integrated into the Settings UI.

7. Self-Protection & Root Detection

  • Device Admin tamper resistance: Prevents unauthorized deactivation of Device Admin
  • Rooted device detection: Refuses to run on rooted devices (RootCheck)
  • Debug mode warning: Alerts when USB/wireless debugging is left on (DebugModeCheck)

See Also

Clone this wiki locally