{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T03:04:27Z","timestamp":1760238267207,"version":"build-2065373602"},"reference-count":35,"publisher":"MDPI AG","issue":"15","license":[{"start":{"date-parts":[[2020,7,28]],"date-time":"2020-07-28T00:00:00Z","timestamp":1595894400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2018YFB10044"],"award-info":[{"award-number":["2018YFB10044"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["No. U1636213"],"award-info":[{"award-number":["No. U1636213"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Information leaks can occur through many Android applications, including unauthorized access to sensors data. Hooking is an important technique for protecting Android applications and add security features to them even without its source code. Various hooking frameworks are developed to intercept events and process their own specific events. The hooking tools for Java methods are varied, however, the native hook has few methods. Besides, the commonly used Android hook frameworks cannot meet the requirement of hooking the native methods in shared libraries on non-root devices. Even though some approaches are able to hook these methods, they have limitations or are complicated to implement. In the paper, a feasible hooking approach for Android native methods is proposed and implemented, which does not need any modifications to both the Android framework and app\u2019s code. In this approach, the method\u2019s reference address is modified and control flow is redirected. Beyond that, this study combines this approach with VirtualXposed which aims to run it without root privileges. This hooking framework can be used to enforce security policies and monitor sensitive methods in shared objects. The evaluation of the scheme demonstrates its capability to perform hook operation without a significant runtime performance overhead on real devices and it is compatible and functional for the native hook.<\/jats:p>","DOI":"10.3390\/s20154201","type":"journal-article","created":{"date-parts":[[2020,7,29]],"date-time":"2020-07-29T07:31:45Z","timestamp":1596007905000},"page":"4201","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["An Android Inline Hooking Framework for the Securing Transmitted Data"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6404-8853","authenticated-orcid":false,"given":"Yu-an","family":"Tan","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuo","family":"Feng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China"},{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangzhou 510006, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0371-9646","authenticated-orcid":false,"given":"Xiaochun","family":"Cheng","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Middlesex University, London NW4 4BE, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1931-366X","authenticated-orcid":false,"given":"Yuanzhang","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,7,28]]},"reference":[{"key":"ref_1","unstructured":"Gasparis, I., Qian, Z.Y., Song, C.Y., and Krishnamurthy, S.V. (2017, January 16). Detecting Android Root Exploits by Learning from Root Providers. Proceedings of the 26th USENIX Conference on Security Symposium, USENIX Association, Vancouver, BC, Canada."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Yuan, Y.L., Tasik, R., Adhatarao, S.S., Yuan, Y.C., Liu, Z.L., and Fu, X.M. (2020). RACE: Reinforced Cooperative Autonomous Vehicle Collision AvoidancE. IEEE Trans. Veh. Technol.","DOI":"10.1109\/TVT.2020.2974133"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"27629","DOI":"10.1109\/ACCESS.2018.2836898","article-title":"Secure APIT Localization Scheme against Sybil Attacks in Distributed Wireless Sensor Networks","volume":"6","author":"Yuan","year":"2018","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"714","DOI":"10.1109\/TKDE.2019.2891581","article-title":"NewMCOS: Towards a Practical Multi-cloud Oblivious Storage Scheme","volume":"32","author":"Liu","year":"2020","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"284","DOI":"10.1016\/j.ins.2019.09.024","article-title":"BotMark: Automated botnet detection with hybrid analysis of flow-based and graph-based traffic behaviors","volume":"511","author":"Wang","year":"2020","journal-title":"Inf. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1184","DOI":"10.1109\/TMC.2019.2903186","article-title":"Privacy Risk Analysis and Mitigation of Analytics Libraries in the Android Ecosystem","volume":"19","author":"Liu","year":"2020","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1049\/iet-ifs.2013.0095","article-title":"Analysis of Bayesian classification-based approaches for Android malware detection","volume":"8","author":"Yerima","year":"2014","journal-title":"IET Inf. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"987","DOI":"10.1109\/TIFS.2019.2932228","article-title":"Android HIV: A Study of Repackaging Malware for Evading Machine-Learning Detection","volume":"15","author":"Chen","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"10:1","DOI":"10.1147\/JRD.2013.2284403","article-title":"Automatic detection of inter-application permission leaks in Android applications","volume":"57","author":"Sbirlea","year":"2013","journal-title":"IBM J. Res. Dev."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Lu, L., Li, Z.C., Wu, Z.Y., Lee, W., and Jiang, G.F. (2012, January 16). CHEX: Statically vetting Android apps for component hijacking vulnerabilities. Proceedings of the 2012 ACM conference on Computer and communications security, Raleigh North, SC, USA.","DOI":"10.1145\/2382196.2382223"},{"key":"ref_11","unstructured":"Grace, M., Zhou, Y.J., Wang, Z., and Jiang, X.X. (2012, January 5\u20138). Systematic detection of capability leaks in stock android smartphones. Proceedings of the nineteenth annual network and distributed system security symposium ndss\u201912 isoc, San Diego, CA, USA."},{"key":"ref_12","unstructured":"Zhou, Y.J., and Jiang, X.X. (2013, January 24\u201327). Detecting Passive Content Leaks and Pollution in Android Applications. Proceedings of the 20th Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1869","DOI":"10.1109\/TIFS.2014.2353996","article-title":"Exploring Permission-Induced Risk in Android Applications for Malicious Application Detection","volume":"9","author":"Wang","year":"2014","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"107024","DOI":"10.1016\/j.comnet.2019.107024","article-title":"MSYM: A multichannel communication system for android devices","volume":"168","author":"Wang","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Poeplau, S., Fratantonio, Y., Bianchi, A., Kruegel, C., and Vigna, G. (2014, January 23\u201326). Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications. Proceedings of the network and distributed system security symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2014.23328"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Rastogi, V., Chen, Y., and Jiang, X.X. (2013). DroidChameleon: Evaluating Android anti-malware against transformation attacks. Proceedings of the 8th ACM SIGSAC Symposium on Information, Computer and Communications Security, Association for Computing Machinery.","DOI":"10.1145\/2484313.2484355"},{"key":"ref_17","unstructured":"Li, J., Huang, Y.Y., Wei, Y., Lv, S.Y., Liu, Z.L., Dong, C.Y., and Lou, W.J. (2019). Searchable Symmetric Encryption with Forward Search Privacy. IEEE Trans. Dependable Secure Comput."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"523","DOI":"10.1016\/j.ins.2019.11.013","article-title":"Cross-Lingual Multi-Keyword Rank Search with Semantic Extension over Encrypted Data","volume":"514","author":"Guan","year":"2019","journal-title":"Inf. Sci."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1016\/j.cose.2014.02.006","article-title":"EFM: Enhancing the performance of signature-based network intrusion detection systems using enhanced filter mechanism","volume":"43","author":"Meng","year":"2014","journal-title":"Comput. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1016\/j.jnca.2018.12.002","article-title":"Design of multi-view based email classification for IoT systems via semi-supervised learning","volume":"128","author":"Li","year":"2019","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Spreitzenbarth, M., Freiling, F., Echtler, F., Schreck, T., and Hoffmann, J. (2013). Mobile-sandbox: Having a deeper look into Android applications. Proceedings of the 28th Annual ACM Symposium on Applied Computing, Association for Computing Machinery. SAC \u201913.","DOI":"10.1145\/2480362.2480701"},{"key":"ref_22","unstructured":"Backes, M., Bugiel, S., Hammer, C., Schranz, O., and Styp-Rekowsky, P. (2015). Boxify: Full-fledged App Sandboxing for Stock Android. Proceedings of 24th USENIX Security Symposium, USENIX Association."},{"key":"ref_23","unstructured":"Xu, R., Saidi, H., and Anderson, R. (2012). Aurasium: Practical Policy Enforcement for Android Applications. Proceedings of the 21st USENIX Security Symposium, USENIX Association."},{"key":"ref_24","unstructured":"(2020, July 23). Cydia Substrate for Android. Available online: http:\/\/www.cydiasubstrate.com."},{"key":"ref_25","unstructured":"(2020, July 23). VirtualXposed. Available online: https:\/\/github.com\/android-hacker\/VirtualXposed."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Lee, B., Lu, L., Wang, T.L., Kim, T., and Lee, W. (2014, January 18\u201321). From Zygote to Morula: Fortifying Weakened ASLR on Android. Proceedings of the 2014 IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2014.34"},{"key":"ref_27","unstructured":"Goldberg, I., Wagner, D., Thomas, R., and Brewer, E. (1996). A secure environment for untrusted helper applications (confining the wily hacker). Proceedings of the 6th Conference on USENIX Security Symposium, Focusing on Applications of Cryptography\u2014Volume 6, USENIX Association."},{"key":"ref_28","unstructured":"(2020, July 23). Frida.re. Available online: https:\/\/frida.re."},{"key":"ref_29","unstructured":"Mulliner, C., Oberheide, J., Robertson, W., and Kirda, E. PatchDroid: Scalable third-party security patches for Android devices. Proceedings of the 29th Annual Computer Security Applications Conference;."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"209","DOI":"10.1109\/TDSC.2017.2740169","article-title":"TaintMan: An ART-Compatible Dynamic Taint Analysis Framework on Unmodified and Non-Rooted Android Devices","volume":"17","author":"You","year":"2020","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"ref_31","unstructured":"Costamagna, V., and Zheng, C. (2016, January 6). ARTDroid: A Virtual-Method Hooking Framework on Android ART Runtime. Proceedings of the 2016 Innovations in Mobile Privacy and Security (IMPS), London, UK."},{"key":"ref_32","unstructured":"Wi\u00dffeld, M. (2015). ArtHook: Callee-side method hook injection on the new Android runtime ART. [Ph.D. Thesis, Saarland University]."},{"key":"ref_33","unstructured":"(2020, July 23). Epic. Available online: https:\/\/github.com\/tiann\/epic."},{"key":"ref_34","unstructured":"Sun, M.S., Wei, T., and Lui, J. TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTime. Proceedings of the 23rd ACM Conference on Computer and Communications Security, Association for Computing Machinery."},{"key":"ref_35","unstructured":"Bianchi, A., Fratantonio, Y., Kruegel, C., and Vigna, G. NJAS: Sandboxing Unmodified Applications in non-rooted Devices Running stock Android. Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, Association for Computing Machinery."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/15\/4201\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:52:25Z","timestamp":1760176345000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/15\/4201"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,28]]},"references-count":35,"journal-issue":{"issue":"15","published-online":{"date-parts":[[2020,8]]}},"alternative-id":["s20154201"],"URL":"https:\/\/doi.org\/10.3390\/s20154201","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2020,7,28]]}}}