Treffer: A large-scale study on the adoption of anti-debugging and anti-tampering protections in android apps

Title:
A large-scale study on the adoption of anti-debugging and anti-tampering protections in android apps
Contributors:
Berlato, Stefano, Ceccato, Mariano
Publication Year:
2020
Collection:
Università degli Studi di Verona: Catalogo dei Prodotti della Ricerca (IRIS)
Document Type:
Fachzeitschrift article in journal/newspaper
File Description:
STAMPA
Language:
English
Relation:
info:eu-repo/semantics/altIdentifier/wos/WOS:000536940000004; volume:52; firstpage:1; lastpage:28; numberofpages:28; journal:JOURNAL OF INFORMATION SECURITY AND APPLICATIONS; https://hdl.handle.net/11562/1017268
DOI:
10.1016/j.jisa.2020.102463
Rights:
info:eu-repo/semantics/restrictedAccess
Accession Number:
edsbas.CF85B853
Database:
BASE

Weitere Informationen

Android apps are subject to malicious reverse engineering and code tampering for many reasons, like premium features unlocking and malware piggybacking. Scientific literature and practitioners proposed several Anti-Debugging and Anti-Tampering protections, readily implementable by app developers, to em- power Android apps to react against malicious reverse engineering actively. However, the extent to which Android app developers deploy these protections is not known. In this paper, we describe a large-scale study on Android apps to quantify the practical adoption of Anti-Debugging and Anti-Tampering protections. We analyzed 14,173 apps from 2015 and 23,610 apps from 2019 from the Google Play Store. Our analysis shows that 59% of these apps implement neither Anti-Debugging nor Anti-Tampering protections. Moreover, half of the remaining apps deploy only one protection, not exploiting the variety of available protections. We also observe that app developers prefer Java to Native protections by a ratio of 99 to 1. Finally, we note that apps in 2019 employ more protections against reverse engineering than apps in 2015.