Paršovs, Arnis, juhendajaIlja, KärtTartu Ülikool. Loodus- ja täppisteaduste valdkondTartu Ülikool. Arvutiteaduse instituut2023-10-272023-10-272020https://hdl.handle.net/10062/93811This thesis analyzes the technical means on how to monitor network communication between the Smart-ID Android application and the server. It gives an overview of the Smart-ID solution and then introduces the concept of man-in-the-middle attack used to intercept the traffic. To implement successful traffic interception attack, the certificate pinning mechanism had to be disabled in the Smart-ID application. This thesis provides step-by-step instructions on how to modify the Smart-ID application’s network security configuration and implement traffic interception using mitmproxy tool. Using the proposed methods network requests can be monitored to verify that no obvious personal data is being sent out from the user’s Android mobile device.engopenAccessAttribution-NonCommercial-NoDerivatives 4.0 InternationalSmart-IDnetwork interceptionman-in-the-middle attackbakalaureusetöödinformaatikainfotehnoloogiainformaticsinfotechnologyIntercepting Network Traffic of the Smart-ID Android ApplicationThesis