دراسة تجريبية لممارسات تشويش الشيفرة في متجر جوجل بلاي
An Empirical Study of Code Obfuscation Practices in the Google Play Store

شارك:
المجلة: IEEE Transactions on Mobile Computing
DOI: https://doi.org/10.1109/tmc.2026.3723593
تاريخ النشر: 2026-01-01
المؤلف: Akila Niroshan وآخرون
الموضوع الرئيسي: كشف خطاب الكراهية والتنمر الإلكتروني

نظرة عامة

تبحث ورقة البحث في انتشار وتطور تقنيات تشويش الشيفرة في نظام أندرويد، الذي يواجه تهديدات كبيرة من إعادة تعبئة التطبيقات، والتزوير، والقرصنة. لمعالجة هذه الثغرات، يستخدم المطورون تشويش الشيفرة؛ ومع ذلك، فإن هذه الممارسة تعقد التحقيقات الأمنية لأنها يمكن أن تُستخدم أيضًا في الأنشطة الخبيثة. يحلل المؤلفون أكثر من 500,000 ملف APK من جوجل بلاي على مدى ثماني سنوات، مقترحين مصنفات لاكتشاف الشيفرة المشوشة وإجراء تحليل طولي لتحديد الاتجاهات.

تكشف النتائج عن زيادة بنسبة 13% في استخدام تقنيات التشويش من 2016 إلى 2023، مع تحديد ProGuard وAllatori كأكثر الأدوات شيوعًا. ومن الجدير بالذكر أن التشويش أكثر شيوعًا بين التطبيقات ذات التصنيف العالي وداخل أنواع الألعاب، وخاصة تطبيقات الكازينو. تمثل هذه الدراسة أول فحص واسع النطاق لاعتماد التشويش في متجر جوجل بلاي، مما يوفر رؤى قيمة لكل من المطورين ومحللي الأمن بشأن تداعيات ممارسات التشويش.

مقدمة

تسلط مقدمة الورقة الضوء على الدور المهم لنظام أندرويد في سوق الهواتف الذكية، حيث يمتلك أكثر من 70% من حصة السوق وأكثر من 1.7 مليون تطبيق متاح على متجر جوجل بلاي اعتبارًا من أغسطس 2024. تسهل إمكانية الوصول إلى متجر جوجل بلاي نشر التطبيقات ولكنها تؤدي أيضًا إلى ممارسات غير قانونية متنوعة، بما في ذلك إعادة تعبئة التطبيقات الشرعية وسرقة الملكية الفكرية من خلال الهندسة العكسية. لمكافحة هذه التهديدات، يستخدم المطورون تقنيات تشويش الشيفرة لحماية تطبيقاتهم وملكيتهم الفكرية. ومع ذلك، فإن التشويش يطرح أيضًا تحديات لمحللي البرمجيات الضارة ومديري متاجر التطبيقات، حيث يمكن أن يعيق التحليل الثابت ويتجنب أدوات مكافحة البرمجيات الضارة.

يهدف المؤلفون إلى التحقيق في انتشار واتجاهات تشويش الشيفرة في متجر جوجل بلاي، معالجين فجوة في الأدبيات الحالية بشأن الأدوات والتقنيات المستخدمة من قبل المطورين. يقترحون مجموعة من المصنفات لاكتشاف الشيفرة المشوشة، محققين معدلات دقة عالية في تحديد التشويش والأدوات المستخدمة. تكشف دراستهم الطولية، التي تغطي بيانات من 2016 إلى 2023، عن زيادة بنسبة 13% في ممارسات تشويش الشيفرة، مع اتجاهات ملحوظة مثل الاستخدام الأعلى بين تطبيقات الألعاب والمطورين البارزين. تؤكد النتائج على ضرورة وجود تدابير أمنية قوية وتوفر رؤى مفيدة للمطورين والباحثين ومحللي البرمجيات الضارة.

النتائج

في هذا القسم، تُعرض نتائج تحليل تشويش الشيفرة في جوجل بلاي، كاشفة عن اتجاهات ونتائج هامة. من بين 548,967 ملف APK تم تحليله، وُجد أن 308,782 (حوالي 56.25%) كانت مشوشة، مما يشير إلى زيادة ملحوظة في ممارسات التشويش بين المطورين. تُظهر البيانات زيادة بنسبة 13% في التشويش من 2016 إلى 2023، مع ارتفاع نسبة التطبيقات المشوشة من حوالي 50-55% في 2016-2018 إلى حوالي 66% في 2023. يشير هذا الاتجاه إلى تركيز متزايد على حماية التطبيقات، من المحتمل أن يتأثر بزيادة المخاوف الأمنية وتوافر أدوات التشويش المتقدمة.

كما يحدد التحليل أدوات التشويش المحددة المستخدمة بين التطبيقات المشوشة. وُجد أن ProGuard هو الأكثر شيوعًا، حيث استخدمه 40.92% من ملفات APK المشوشة، تليه Allatori بنسبة 36.64%. زادت شعبية ProGuard، خاصة بعد تقديم R8 في أبريل 2019، الذي عزز تكامله في تطوير أندرويد. في المقابل، يبقى استخدام DashO منخفضًا بسبب تكلفته العالية. شهدت فئة “أدوات التشويش الأخرى” انتعاشًا من 2021 إلى 2023، مما يشير إلى أن المطورين قد يستخدمون أدوات مخصصة أو أقل شيوعًا، على الرغم من أن الأدوات المحددة المستخدمة في هذه الحالات لا تزال غير محددة. أكدت التحقيقات الإضافية في هذه الفئة أن هذه التطبيقات مشوشة بالفعل، لكن لم يكن من الممكن تحديد الأدوات الدقيقة، مما يبرز قيدًا في عملية الكشف.

المناقشة

في قسم المناقشة من ورقة البحث، يتم توضيح تقنيات تشويش الشيفرة المختلفة، مع التركيز على أدوارها في تعزيز أمان البرمجيات ضد الهندسة العكسية. تشمل التقنيات إعادة تسمية المعرفات (IR)، التي تستبدل المعرفات القابلة للقراءة بسلاسل عشوائية لإخفاء منطق الشيفرة؛ تعديل تدفق التحكم (CF)، الذي يغير تسلسل التنفيذ لتعقيد التحليل؛ وتشفير السلاسل (SE)، الذي يحول السلاسل القابلة للقراءة البشرية إلى تنسيقات غير قابلة للقراءة لحماية المعلومات الحساسة. كما تسلط الورقة الضوء على طرق محددة تحت CF، مثل تسطيح تدفق التحكم وتوجيه الاستدعاء، التي تضيف تعقيدًا في استعادة الشيفرة، وتناقش استخدام الانعكاس في Java لتغيير السلوك الديناميكي.

بالإضافة إلى ذلك، يستعرض القسم أدوات التشويش الشائعة الاستخدام، بما في ذلك ProGuard وAllatori وDashO وObfuscapk وDexGuard، كل منها يقدم قدرات متفاوتة لتنفيذ التقنيات المذكورة أعلاه. يوضح المؤلفون إطارهم القائم على التعلم الآلي لاكتشاف التشويش في تطبيقات أندرويد، والذي يتضمن مصنفات لتحديد ما إذا كان التطبيق مشوشًا، وتحديد أداة التشويش المستخدمة، والتعرف على تقنيات التشويش المحددة. يتم التحقق من أداء الإطار من خلال اختبارات شاملة على مجموعات بيانات متعددة، مما يظهر معدلات دقة عالية عبر مهام الكشف المختلفة، وبالتالي يساهم في فهم شامل لممارسات التشويش في سياق أمان تطبيقات أندرويد.

القيود

في قسم القيود من ورقة البحث، يعترف المؤلفون بأن تحليلهم مقيد باستخدام مجموعتين من البيانات من 2018 و2023، مما يؤدي إلى نقص في العينات التمثيلية من 2019 و2020. على الرغم من هذه الفجوة، يؤكدون أن الاتجاهات العامة الملاحظة من غير المحتمل أن تتأثر بشكل كبير من خلال تضمين تلك السنوات المفقودة. كما يبرزون الأخطاء المحتملة في التنبؤ من المصنفات التي تم مناقشتها في القسم III-A، والتي قد تنتقل عبر تحليلهم. لمعالجة ذلك، تم التحقق من أداء المصنفات على بيانات غير مرئية (كما هو موضح في القسم III-D)، مما يظهر عموميتها؛ ومع ذلك، تبقى تحديات إنشاء حقيقة دقيقة مع حزم تطبيقات أندرويد الحقيقية (APKs) قائمة.

لعمل مستقبلي، يقترح المؤلفون نهجًا أكثر تفصيلًا لاكتشاف التشويش من خلال التحقيق في مكتبات محددة داخل ملفات APK، حيث قد لا يتم تطبيق التشويش بشكل موحد عبر التطبيق بالكامل. يشيرون إلى صعوبة تحديد المكتبات المشوشة دون حقيقة مؤكدة، وهي مشكلة شائعة في اكتشاف المكتبات التابعة. بالإضافة إلى ذلك، يعترفون بأن تحليلهم كان محدودًا بثلاث أدوات مستخدمة على نطاق واسع، وقد تستخدم بعض التطبيقات DexGuard، مما قد يؤدي إلى تصنيف خاطئ بسبب التشابه مع ProGuard. يقترح المؤلفون أن تتضمن الأبحاث المستقبلية مجموعة أوسع من أدوات التشويش، بما في ذلك الأدوات التجارية مثل DexGuard، لتعزيز دقة المصنف ومعالجة هذه القيود.

Journal: IEEE Transactions on Mobile Computing
DOI: https://doi.org/10.1109/tmc.2026.3723593
Publication Date: 2026-01-01
Author(s): Akila Niroshan et al.
Primary Topic: Hate Speech and Cyberbullying Detection

Overview

The research paper investigates the prevalence and evolution of code obfuscation techniques in the Android ecosystem, which faces significant threats from app repackaging, counterfeiting, and piracy. To address these vulnerabilities, developers utilize code obfuscation; however, this practice complicates security investigations as it can also be leveraged for malicious activities. The authors analyze over 500,000 Android APKs from Google Play over an eight-year period, proposing classifiers to detect obfuscated code and conducting a longitudinal analysis to identify trends.

The findings reveal a 13% increase in the use of obfuscation techniques from 2016 to 2023, with ProGuard and Allatori identified as the most prevalent tools. Notably, obfuscation is more common among top-ranked applications and within gaming genres, particularly Casino apps. This study represents the first large-scale examination of obfuscation adoption in the Google Play Store, offering valuable insights for both developers and security analysts regarding the implications of obfuscation practices.

Introduction

The introduction of the paper highlights the significant role of Android in the smartphone market, with over 70% market share and more than 1.7 million apps available on the Google Play Store as of August 2024. The accessibility of the Google Play Store facilitates app publishing but also leads to various malpractices, including the repackaging of legitimate apps and intellectual property theft through reverse engineering. To combat these threats, developers employ code obfuscation techniques to protect their applications and intellectual property. However, obfuscation also poses challenges for malware analysts and app store administrators, as it can hinder static analysis and evade anti-malware tools.

The authors aim to investigate the prevalence and trends of code obfuscation in the Google Play Store, addressing a gap in existing literature regarding the tools and techniques used by developers. They propose a set of classifiers to detect obfuscated code, achieving high accuracy rates in identifying obfuscation and the tools employed. Their longitudinal study, covering data from 2016 to 2023, reveals a 13% increase in code obfuscation practices, with notable trends such as higher usage among gaming apps and top developers. The findings underscore the necessity for robust security measures and provide insights beneficial to developers, researchers, and malware analysts.

Results

In this section, the results of an analysis of code obfuscation in Google Play are presented, revealing significant trends and findings. Out of 548,967 analyzed APKs, 308,782 (approximately 56.25%) were found to be obfuscated, indicating a notable increase in obfuscation practices among developers. The data shows a 13% rise in obfuscation from 2016 to 2023, with the percentage of obfuscated apps climbing from around 50-55% in 2016-2018 to approximately 66% in 2023. This trend suggests a growing emphasis on app protection, likely influenced by increasing security concerns and the availability of advanced obfuscation tools.

The analysis also identifies the specific obfuscation tools used among the obfuscated apps. ProGuard was found to be the most prevalent, utilized by 40.92% of the obfuscated APKs, followed by Allatori at 36.64%. The popularity of ProGuard has increased, particularly after the introduction of R8 in April 2019, which enhanced its integration into Android development. In contrast, the usage of DashO remains low due to its high cost. The category of ‘other’ obfuscation tools has seen a resurgence from 2021 to 2023, suggesting that developers may be employing custom or less common tools, although the specific tools used in these cases remain undetermined. Further investigation into this category confirmed that these apps are indeed obfuscated, but the exact tools could not be identified, highlighting a limitation in the detection process.

Discussion

In the discussion section of the research paper, various code obfuscation techniques are outlined, emphasizing their roles in enhancing software security against reverse engineering. The techniques include Identifier Renaming (IR), which substitutes readable identifiers with random strings to obscure code logic; Control Flow Modification (CF), which alters the execution sequence to complicate analysis; and String Encryption (SE), which transforms human-readable strings into unreadable formats to protect sensitive information. The paper also highlights specific methods under CF, such as control flow flattening and call indirection, which introduce complexity in code restoration, and discusses the use of reflection in Java for dynamic behavior alteration.

Additionally, the section reviews commonly used obfuscation tools, including ProGuard, Allatori, DashO, Obfuscapk, and DexGuard, each offering varying capabilities for implementing the aforementioned techniques. The authors detail their machine learning-based framework for detecting obfuscation in Android applications, which includes classifiers for identifying whether an app is obfuscated, determining the obfuscation tool used, and recognizing specific obfuscation techniques. The framework’s performance is validated through extensive testing on multiple datasets, demonstrating high accuracy rates across different detection tasks, thus contributing to a comprehensive understanding of obfuscation practices in the context of Android app security.

Limitations

In the limitations section of the research paper, the authors acknowledge that their analysis is constrained by the use of two datasets from 2018 and 2023, resulting in a lack of representative samples from 2019 and 2020. Despite this gap, they assert that the overall trends observed are unlikely to be significantly affected by the inclusion of those missing years. They also highlight potential prediction errors from the classifiers discussed in Section III-A, which could propagate through their analysis. To address this, the classifiers’ performance was validated on unseen data (as detailed in Section III-D), demonstrating their generalizability; however, the challenge of establishing accurate ground truth with real-world Android Package Kits (APKs) remains.

For future work, the authors propose a more granular approach to obfuscation detection by investigating specific libraries within APKs, as obfuscation may not be uniformly applied across the entire application. They note the difficulty of identifying obfuscated libraries without ground truth, a common issue in third-party library detection. Additionally, they recognize that their analysis was limited to three widely used tools, and some applications may utilize DexGuard, which could lead to misclassification due to similarities with ProGuard. The authors suggest that future research should incorporate a broader range of obfuscators, including commercial tools like DexGuard, to enhance the classifier’s accuracy and address these limitations.

شارك: