{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T03:40:19Z","timestamp":1760240419286,"version":"build-2065373602"},"reference-count":38,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2019,6,10]],"date-time":"2019-06-10T00:00:00Z","timestamp":1560124800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100010418","name":"Institute for Information and communications Technology Promotion","doi-asserted-by":"publisher","award":["2017-0-00168"],"award-info":[{"award-number":["2017-0-00168"]}],"id":[{"id":"10.13039\/501100010418","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"publisher","award":["2014K1A1A2043029"],"award-info":[{"award-number":["2014K1A1A2043029"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>As interest in Internet of Things environments rapidly increases throughout the IT convergence field, compatibility with mobile devices must be provided to enable personalized services. The security of mobile platforms and applications is critical because security vulnerabilities of mobile devices can be spread to all things in these environments. Android, the leading open mobile platform, has long used the Dalvik virtual machine as its runtime system. However, it has recently been completely replaced by a new runtime system, namely Android Runtime (ART). The change from Android\u2019s Dalvik to ART means that the existing Dalvik bytecode-based application execution structure has been changed to a machine code-based application execution structure. Consequently, a detailed understanding of ART, such as new file formats and execution switching methods between codes, is required from the viewpoint of application security. In this paper, we demonstrate that an existing Dalvik-based application vulnerability can be exploited as-is in ART. This is because existing Dalvik executable files coexist in the ART executable file, and these Dalvik bytecodes and compiled machine codes have one-to-one mapping relationships. We then propose an ART-based application protection scheme to secure this by dynamically eliminating the one-to-one mapping. In addition, the proposed scheme is implemented to evaluate its reverse engineering resistance and performance through experiments.<\/jats:p>","DOI":"10.3390\/s19112625","type":"journal-article","created":{"date-parts":[[2019,6,10]],"date-time":"2019-06-10T03:16:51Z","timestamp":1560136611000},"page":"2625","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Mobile Code Anti-Reversing Scheme Based on Bytecode Trapping in ART"],"prefix":"10.3390","volume":"19","author":[{"given":"Geonbae","family":"Na","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Soongsil University, Seoul 06978, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jongsu","family":"Lim","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Soongsil University, Seoul 06978, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sunjun","family":"Lee","sequence":"additional","affiliation":[{"name":"School of Software, Soongsil University, Seoul 06978, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2720-0593","authenticated-orcid":false,"given":"Jeong Hyun","family":"Yi","sequence":"additional","affiliation":[{"name":"School of Software, Soongsil University, Seoul 06978, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,6,10]]},"reference":[{"key":"ref_1","first-page":"10","article-title":"Industrial IoT in 5G Environment Towards Smart Manufacturing","volume":"10","author":"Cheng","year":"2018","journal-title":"J. Ind. Inf. Integr."},{"key":"ref_2","unstructured":"Jones, N. (2019, March 22). Top Strategic IoT Trends and Technologies Through 2023. Gartner Report G00370381. Available online: https:\/\/www.gartner.com\/doc\/3890506\/top-strategic-iot-trends-technologies."},{"key":"ref_3","unstructured":"Brahler, S. (2019, March 20). Analysis of the Android Architecture. Available online: os.itec.kit.edu."},{"key":"ref_4","unstructured":"(2019, March 11). Apktool. Available online: https:\/\/ibotpeaches.github.io\/Apktool\/."},{"key":"ref_5","unstructured":"(2019, March 19). Dex2jar. Available online: https:\/\/sourceforge.net\/projects\/dex2jar\/."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"457","DOI":"10.1002\/sec.936","article-title":"Server-Based Code Obfuscation Scheme for APK Tamper Detection","volume":"9","author":"Piao","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"1421","DOI":"10.1007\/s11277-013-1258-x","article-title":"Repackaging Attack on Android Banking Applications and Its Countermeasures","volume":"73","author":"Jung","year":"2013","journal-title":"Wirel. Pers. Commun."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Banescu, S., Collberg, C., Ganesh, V., Newsham, Z., and Pretschner, A. (2016, January 5\u20138). Code Obfuscation Against Symbolic Execution Attacks. Proceedings of the 32nd Annual Conference on Computer Security Applications, Los Angeles, CA, USA.","DOI":"10.1145\/2991079.2991114"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"72","DOI":"10.1016\/j.cose.2016.05.003","article-title":"Control Flow Obfuscation for Android Applications","volume":"61","author":"Balachandran","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"4261","DOI":"10.1007\/s11227-016-1848-y","article-title":"Anti-reversible Dynamic Tamper Detection Scheme using Distributed Image Steganography for IoT Applications","volume":"74","author":"Kim","year":"2018","journal-title":"J. Supercomput."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Aucsmith, D. (1996). Tamper Resistant Software: An Implementation. International Workshop on Information Hiding, Springer.","DOI":"10.1007\/3-540-61996-8_49"},{"key":"ref_12","unstructured":"(2019, February 19). Bangcle. Available online: https:\/\/www.bangcle.com\/."},{"key":"ref_13","unstructured":"(2019, February 07). Ijiami. Available online: http:\/\/www.ijiami.cn\/."},{"key":"ref_14","unstructured":"(2019, May 06). DexGuard. Available online: https:\/\/www.guardsquare.com\/en\/products\/dexguard."},{"key":"ref_15","unstructured":"(2019, May 06). Proguard. Available online: https:\/\/www.guardsquare.com\/en\/products\/proguard."},{"key":"ref_16","unstructured":"(2019, May 09). DexProtector. Available online: https:\/\/dexprotector.com\/."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Bartel, A., Klein, J., Traon, Y.L., and Monperrus, M. (2012, January 14). Dexpier: Converting Android Dalvik Bytecode to Jimple for Static Analysis with Soot. Proceedings of the Association for Computing Machinery SiGPLAN International Workshop on State of the Art in Java Program Analysis, Beijing, China.","DOI":"10.1145\/2259051.2259056"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1192","DOI":"10.1016\/j.infsof.2012.05.003","article-title":"Static Analysis of Android Programs","volume":"54","author":"Payet","year":"2012","journal-title":"Inf. Softw. Technol."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Ning, Z., and Zhang, F. (2018, January 25\u201328). DexLego: Reassembleable Bytecode Extraction for Aiding Static Analysis. Proceedings of the 48th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, Luxembourg.","DOI":"10.1109\/DSN.2018.00075"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"230","DOI":"10.1016\/j.cose.2016.11.011","article-title":"DroidNative: Automating and Optimizing Detection of Android Native Code Malware Variants","volume":"65","author":"Alam","year":"2017","journal-title":"Comput. Secur."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"71229","DOI":"10.1109\/ACCESS.2018.2881699","article-title":"DexMonitor: Dynamically Analyzing and Monitoring Obfuscated Android Applications","volume":"6","author":"Cho","year":"2018","journal-title":"IEEE Access"},{"key":"ref_22","unstructured":"(2019, March 25). Android Runtime. Available online: https:\/\/en.wikipedia.org\/wiki\/AndroidRuntime."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Yadav, R., and Bhadoria, R.S. (2015, January 4\u20136). Performance Analysis for Android Runtime Environment. Proceedings of the Fifth International Conference on Communication Systems and Network Technologies, Gwalior, India.","DOI":"10.1109\/CSNT.2015.52"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Backes, M., Schranz, O., and von Styp-Rekowsky, P. (2015, January 12\u201316). POSTER: Towards Compiler-Assisted Taint Tracking on Android Runtime. Proceedings of the 22nd Association for Computing Machinery SIGSAC Conference on Computer and Communications Security, Denver, CO, USA.","DOI":"10.1145\/2810103.2810129"},{"key":"ref_25","unstructured":"Sabanal, P. (2014, January 13\u201316). State of the ART Exploring the New Android KitKat Runtime. Proceedings of the Hack In The Box Security Conference, K. Lumpur, Malaysia."},{"key":"ref_26","unstructured":"Sabanal, P. (2019, June 09). Hiding Behind ART. Available online: https:\/\/www.blackhat.com\/docs\/asia-15\/materials\/asia-15-Sabanal-Hiding-Behind-ART-wp.pdf."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"12382","DOI":"10.1109\/ACCESS.2018.2808340","article-title":"A Comparison of Android Reverse Engineering Tools via Program Behaviors Validation Based on Intermediate Languages Transformation","volume":"6","author":"Arnatovich","year":"2018","journal-title":"IEEE Access"},{"key":"ref_28","unstructured":"(2019, March 21). Ahead-Of-Time Compilation. Available online: https:\/\/en.wikipedia.org\/wiki\/Ahead-of-timecompilation."},{"key":"ref_29","first-page":"2486","article-title":"Review Paper on Android Operating System","volume":"2","author":"Sharma","year":"2015","journal-title":"Int. J. Emerg. Trends Sci. Technol."},{"key":"ref_30","unstructured":"(2019, March 25). ART and Dalvik. Available online: https:\/\/source.android.com\/."},{"key":"ref_31","unstructured":"(2019, March 21). Just-In-Time Compilation. Available online: https:\/\/en.wikipedia.org\/wiki\/Just-in-timecompilation."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Collberg, C., Martin, S., Myers, J., and Nagra, J. (2012, January 3\u20137). Distributed Application Tamper Detection via Continuous Software Updates. Proceedings of the 28th Annual Computer Security Applications Conference, Orlando, FL, USA.","DOI":"10.1145\/2420950.2420997"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Falcarin, P., Di Carlo, S., Cabutto, A., Garazzino, N., and Barberis, D. (2011, January 21\u201323). Exploiting Code Mobility for Dynamic Binary Obfuscation. Proceedings of the World Congress on Internet Security, London, UK.","DOI":"10.1109\/WorldCIS17046.2011.5749894"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Cabutto, A., Falcarin, P., Abrath, B., Coppens, B., and De Sutter, B. (2015, January 12). Software Protection with Code Mobility. Proceedings of the Second Association for Computing Machinery Workshop on Moving Target Defense, Denver, CO, USA.","DOI":"10.1145\/2808475.2808481"},{"key":"ref_35","unstructured":"(2019, May 27). Android Version Market Share. Available online: https:\/\/developer.android.com\/about\/dashboards."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Geethanjali, D., Ying, T.L., Melissa, C.W.J., and Balachandran, V. (2018, January 19\u201321). AEON: Android Encryption Based Obfuscation. Proceedings of the Eighth Association for Computing Machinery Conference on Data and Application Security and Privacy, Tempe, AZ, USA.","DOI":"10.1145\/3176258.3176943"},{"key":"ref_37","first-page":"1199","article-title":"Multi-Partitioned Bytecode Wrapping Scheme For Minimizing Code Exposure on Android","volume":"19","author":"Park","year":"2018","journal-title":"J. Int. Technol."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"46731","DOI":"10.1109\/ACCESS.2018.2866626","article-title":"Code-Based Authentication Scheme for Lightweight Integrity Checking of Smart Vehicles","volume":"6","author":"Yoo","year":"2018","journal-title":"IEEE Access"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/11\/2625\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T12:57:11Z","timestamp":1760187431000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/11\/2625"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6,10]]},"references-count":38,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2019,6]]}},"alternative-id":["s19112625"],"URL":"https:\/\/doi.org\/10.3390\/s19112625","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2019,6,10]]}}}