# Virbox Protector

Documentation

{% hint style="info" %}
**On premise solution,** Right choice to developer to protect/Shield your  desktop and mobile applications: App, Apk, AAB, AAR, .so & iOS apps.

**All in One features:** Shielding & Code hardening, Encryption, Virtualization, To secure your source code and data asset & resource, effective to defend application to against static attack and dynamical analysis.

**Codless effort and easy to use,** GUI and CLI tool available for Developer. support to shield and protect your software project in post protection and Buiild in process.
{% endhint %}

Virbox Protector, is the latest code hardening and app shielding tool for software developer to protect their software copyright and IP which integrated with multi layer of encryption and protection technology: Virtualization, Obfuscation, Smart compression, Code encryption, Data and resource protection, Detecting Hardware breakpoint, Detecting Memory breakpoint, Code and Memory Integrity Check, etc. It is the powerful protection tools for software developer to protect their software and critical code, algorithm without additional coding, with easy to use and effortless feature.

**Virbox Protector support following Operation system environment and program languages with different of license:**

**System Environments:**

Windows: Windows 7 and above version

Linux: CentOS, Ubuntu, Debian-9.4.0

Mac: OX 10.4 and above version

Android System (Protect Unity3D apk, .so library), 4.0 and above version supported

ARM Linux (V7/V8 architecture)

**Program languages:**

C, C++, .NET, .Net Core3, Java, Unity 3D, Unreal Engine 4, Delphi XE7 or above version, PB, BCB, C#, VB6.0, Python, Lua, Perl, R, Ruby, PHP, HTML 5, etc.

**File protected:**&#x20;

exe, dll, elf, .so libs, dylibs, AutoCAD ARX, JAR, WAR, PY, Apk, AAB, AAR etc;

## Download

{% content-ref url="/pages/bIlotaG2W8LAixTAFCxK" %}
[Installation](/download/installation)
{% endcontent-ref %}

{% content-ref url="/pages/KumkU8pZpfHMZmhhIb2Y" %}
[Sign up & Apply trial license](/download/sign-up-and-apply-trial-license)
{% endcontent-ref %}

{% content-ref url="/pages/I1oVtB8N0ohhMCvuDwBo" %}
[Sign in & Sign out](/download/sign-in-and-sign-out)
{% endcontent-ref %}

## Fundamentals:&#x20;

{% content-ref url="/pages/f1HUTLw653zqTkuxE8CH" %}
[Overview](/fundamentals/overview)
{% endcontent-ref %}

{% content-ref url="/pages/CHz4qhBf5C7XSNiaNJui" %}
[GUI tool](/fundamentals/gui-tool)
{% endcontent-ref %}

{% content-ref url="/pages/EwIgfrMOGHA2tEI0v4ie" %}
[Protection Process](/fundamentals/protection-process)
{% endcontent-ref %}

{% content-ref url="/pages/Ka9cxjeNEGXI5q9cSdA9" %}
[CLI Tool: Overview](/fundamentals/cli-tool-overview)
{% endcontent-ref %}

## Use Cases

{% content-ref url="/pages/cdoRl0uFioD84hEaiHta" %}
[Protect Desktop applications](/use-cases/protect-desktop-applications)
{% endcontent-ref %}

{% content-ref url="/pages/EBAdHGl29FIhjpcZ8WsH" %}
[Protect Unity3D/UE4 application](/use-cases/protect-unity3d-ue4-application)
{% endcontent-ref %}

{% content-ref url="/pages/7irgODbsU3nhQfQKE6bs" %}
[Protect Mobile applications](/use-cases/protect-mobile-applications)
{% endcontent-ref %}

{% content-ref url="/pages/15lo93zOPDs0kG4jntwC" %}
[Protect Scripting language](/use-cases/protect-scripting-language)
{% endcontent-ref %}

## Extras

{% content-ref url="/pages/O8hyUGKbcNb7gyjVCLyn" %}
[How to deal with the Virus False Positive when developer protect the application](/use-cases/faq/how-to-deal-with-the-virus-false-positive-when-developer-protect-the-application)
{% endcontent-ref %}

{% content-ref url="/pages/Ka9cxjeNEGXI5q9cSdA9" %}
[CLI Tool: Overview](/fundamentals/cli-tool-overview)
{% endcontent-ref %}

{% content-ref url="/pages/V9Sks6XdFlGcVMkZ8efy" %}
[Set the label to protect the specified Functions/code](/use-cases/faq/set-the-label-to-protect-the-specified-functions-code)
{% endcontent-ref %}


# Introduction

Help developer to use Virbox Protector to protect application quickly and easily

Virbox Protector provides the trial package for developer downloading and testing and evaluation, if developer  satisfied with trial performance after testing and evaluation and want to get the formal installation package and license of Virbox Protector,&#x20;

Pls free contact us with email:

<mark style="color:blue;">`sales@senselock.com`</mark>

or&#x20;

<mark style="color:blue;">`info@senselock.com`</mark>


# Installation

{% hint style="info" %}
**Good to know:** Virbox Protector support to be installed in windows, Linux and macOS environment, Developer may select right installation package to download and install in your desktop. In this chapter, we introduce the download and installation process&#x20;
{% endhint %}

Virbox Protector provides trial package and formal release package for software developer to download, test/evaluation or protect your formal release software applications, with different kind of license: trial license and commercial license.

Trial license and trial package can be applied and download from Virbox Protector website:

{% embed url="<https://appsec.virbox.com/apply.html>" %}

Apply trial license:&#x20;

Developer input email and other necessary information to get the trial license (cloud based license) and then your email will get a temporary password. when download the Virbox Protector Trial package and install in your machine, execute Virbox Protector GUI tools or CLI tool, use your email and the password received to login, then you can start to test.

<figure><img src="/files/IA8lJs7tMxdzB7iYXPKP" alt=""><figcaption></figcaption></figure>

## Trial package

Download the Virbox Protector trial package (installation package):

Virbox Protector provides different trial pacakge for developer to test in multiple system environment:&#x20;

Windows, Linux or macOS system, pls find and select the right installation package to download the trial package accordingly. as shown as below:

<figure><img src="/files/i4JsNHwwSebMKv8HaNLa" alt=""><figcaption></figcaption></figure>

## Virbox Protector Formal release package

Formal release package used for the developer who purchase Virbox Protector commercial pacakge, Virbox Protector provides different installation package to developer to install in multiple system environment: Windows, Linux or mac OS system. Developer can select the right version in line with your system environment before purchase.&#x20;

{% embed url="<https://appsec.virbox.com/down.html>" %}

<figure><img src="/files/rtFuTyy4x72qdJn6WsGk" alt=""><figcaption></figcaption></figure>

for any questions,  contact us directly:&#x20;

**<sales@senselock.com>**

**<support@senselock.com>**

## Install the Virbox Protector in Windows

Download the Virbox Protector and double click the installation package to install the Virbox Protector to your desktop.

## Install the Virbox Protector in Linux System

Start the terminal window in your linux system and use following command to install Virbox Protector in your linux platform:

{% hint style="info" %}
Root access right required
{% endhint %}

Installation Virbox Protector in CentOS system:

`rpm -ivh virboxprotector_trial_2.3.3.14630.rpm`

Installation Virbox Protector in Ubuntu System:

`dpkg -i virboxprotector_trial_2.3.3.14630.deb`

`Login your account after installation completed`

`ssclt -c all -u account`

{% hint style="info" %}
The digital suffix *<mark style="color:blue;">2.3.3.14630</mark>* in above sample of installation command is trial version No. of Linux Trial package, you need to update with latest trial version No. which you download and execute with latest trial version No.
{% endhint %}

## Install the Virbox Protector in macOS

Virbox Protector support to be installed in the macOS with "PKG" installation, download the Virbox Protector and double click the "PKG" to install the Virbox Protector.

{% hint style="info" %}
For the Mac system in M1 chipset, pls contact with our technical support in case some issue happened when you install the Virbox Protector;

email: <mark style="color:blue;"><support@senselock.com></mark>
{% endhint %}


# Sign up & Apply trial license

Virbox Protector (Standalone) provides "Trial edition （installation package）" and for software developer to apply Trial license to test and evaluate the protection performance.

{% hint style="info" %}
**Good to know:**&#x20;

Trial License valid with 30 days, and the protected program by use of Virbox Protector Trial license can be executed within 7 days only and it can not be used for formal software released.

Trial license is "Cloud based License", after install the trial package into your machine, Developer use email and password to login Virbox Protector account, then you can start testing and protection.&#x20;

For Commercial license, Virbox Protector support the  "Soft license" and "License key", which need to bind with developer machine. in some case, Virbox Protector also support to provide the dongle based license if required.
{% endhint %}

## Sign up in Virbox Protector website

Go to Virbox Protector website, fill in the apply form to apply trial license;

{% embed url="<https://appsecurity.virbox.com/apply.html>" %}

<figure><img src="/files/3q9Ai8rAD606wMEZoYA0" alt=""><figcaption></figcaption></figure>

Then your email will received email  contained the temporary password;

Download and install the Virbox Protector's Trial package via Virbox website

> Kindly remind, download Trial package, Do Not Download the formal release pacakge, the trial license doesn't valid for formal release package.

{% embed url="<https://appsec.virbox.com/down.html>" %}

<figure><img src="/files/esuhNG4LoCmg6lNoiSvX" alt=""><figcaption></figcaption></figure>

and you can find the Virbox Protector GUI tools in the \bin, sub directory of the installation path of Virbox Protector: \bin:

<mark style="color:blue;">`virboxprotector.exe`</mark>&#x20;

{% hint style="info" %}
Virbox Protector support developer to protect their projects both in GUI tools and CLI tools.&#x20;

Developer can find Virbox Protector CLI tools in same sub directory of installation path also:

<mark style="color:blue;">`virboxprotector_con.exe`</mark>
{% endhint %}

## Sign up with Cloud License in Virbox GUI tools

Executed the Virbox Protector GUI tools and Use your email and temporary password to sign in Virbox Protector&#x20;

double click:

<mark style="color:blue;">`virboxprotector.exe`</mark>

![](/files/cor5n39MLgXalO4utHOU)

## Sign up with Cloud License in Virbox CLI tools

Executed the Virbox Protector CLI tools and Use  your email and temporary password to sign in Virbox Protector

```
virboxprotector_con.exe -global --username=<> --password=<>
```

Use following command to find help

```
virboxprotector_con.exe --help=global
```

<figure><img src="/files/RWH2PNAwThwOnGKYHFxx" alt=""><figcaption></figcaption></figure>

## Sign up with cloud license in DSProtector GUI/CLI tools

You also can find the DS Protector, a protection tool used to protect Data resource of your software applications in \Bin directory:

DS Protector GUI Tools:

<mark style="color:blue;">`dsprotector.exe`</mark>

DS Protector CLI tools:

<mark style="color:blue;">`dsprotector_con.exe`</mark>


# Sign in & Sign out

{% hint style="info" %}
**Good to know:** Sign in/out in Linux, you can refer the related section to introduce Virbox Protector CLI tool in Linux System
{% endhint %}

## Windows system in VIrbox Protector GUI tools

### Sign in:

Execute Virbox Protector GUI tool in your windows system

Use your email and the temporary password (you need to update this temp password later) received to sign in and start the trial

![](/files/cor5n39MLgXalO4utHOU)

### Sign out

![](/files/BbZIAkeu9HolvfDoptbt)

## Windows system in VIrbox Protector CLI tools

### Could license

{% hint style="info" %}
For most of case to use Cloud license is for trial license and trial user
{% endhint %}

```
virboxprotector_con.exe -global --username=<> --password=<>
```

### Use Soft license to bind with your machine

```
virboxprotector_con.exe -bind
```

<figure><img src="/files/zDXYiljH1RL2ReVveZUP" alt=""><figcaption></figcaption></figure>

## Linux System

### sign in&#x20;

`ssclt -c all -u <your account>`

### Sign out

`ssclt -o <your account>`


# Virbox License

Virbox License type will be introduce in this section, Developer may select right license type to activate your Virbox Protector


# Virbox Protector License (GUI)

We will introduce Virbox License type in this section

Virbox Protector provides 2 kinds of License:&#x20;

Trial License to Trial user;

Commercial license to formal Virbox Protector user;&#x20;

Virbox Protector support developer to login or bind the license in both GUI and CLI tool;

### Get the Virbox Protector installation package

Virbox Protector support to be installed in the windows, Linux (rpm and deb package) and macOS system environment, developer may select the relevant package to download and install to your machine according the license purchased accordingly.

**For Trial license user:**

Pls download Virbox Protector Trial Package to install in your machine.&#x20;

<figure><img src="/files/yOFZsames5KXwkthVAKQ" alt=""><figcaption></figcaption></figure>

**For commercial license user:**

Pls download the **formal release version** package (see screen shot attached below, the blue box marked), use this formal release package to replace trial package installed in your machine previously.

Pls **Do Not** download the **Trial packakge.**

{% embed url="<https://appsec.virbox.com/down.html>" %}

<figure><img src="/files/M9jsUHIdae3mgq6pLLnG" alt=""><figcaption></figcaption></figure>

### Virbox Account & Password

If you have tested Virbox Protector before, use your existed account and password to sign in and use Virbox Protecor.

### Virbox Protector License type

Virbox Protector is on premise solution for software application hardening/shielding solution. which can be used both for online/offline environment and it is not necessary for developer to upload the application to the cloud platform for hardening/shielding. all of code hardening/app shielding work can be completed in customer premise and no potential code leaking risk.

#### License type

Virbox Protector license type support following license container:

**Online Environment: Account based Cloud License:**

Developer use the email (account) to apply Trial, a temporary password will be sent to your email, and then use the mail and password to login and start the trial.

Usually, the trial license use the account based cloud license, it is quite easy to developer to use license for testing and trial the Virbox Protector.

**Online Environment: Account based Soft license:**

For Developer who purchase the formal release license of Virbox Protector, Developer need to download the Formal release package and install to your desktop in advance. and then developer use the same email and password (same as the trial account) to sign in Virbox Protector.

<figure><img src="/files/Hc8kzdv7QrEaWOKRCFQw" alt=""><figcaption></figcaption></figure>

Later a Online Binding message box will pop up, as shown in below screenshot, click "Online binding". then you can start to use the Virbox Protector.

Tips: It is necessary to rebind the license per every 180 days.

<figure><img src="/files/mbNG2YvM1sbUXIUl1L1N" alt=""><figcaption></figcaption></figure>

Developer can unbind present machine and change to bind new machine in 3 times with free. (in case of machine hardware update/change or the person in charge changed).

**Online Environment: License key to activate license**

Virbox also support to use license key (a series characters) to activate the license key and binding the machine in online environment.

<figure><img src="/files/U54BMxYxA1qS2EjZc3OS" alt=""><figcaption></figcaption></figure>

**Dongle based license:**

License stored in Hardware dongle, For some developer prefer to use dongle based license. they need to buy the dongle (Virbox Elite 5 dongle) and pay relate freight fee to ship the dongle (license inside) and bared import duty accordingly.

No specified machine required for dongle based license. developer are freely to shift machine with the dongle.

\*\*Pls clarify and confirm what kind of license types you prefer when you purchase Virbox Protector's formal release license.

### Virbox Documentation and User Manual

<https://documentation.virbox.com/>

### Service Support

#### Version Update/Upgrade:

**Release Version update:**

**Subscription user:**

Free update during subscription period

**Perpetual user:**

Free update within one year, limited in major version.

**Major version upgrade :**

(i.e. upgrade from 3.xxx to 4.xxx)

**Subscription user**

Free upgrade during subscription period

**Perpetual user:**

50% off of purchase price after 1 year

#### Technical Support

**email support,**

Question, bugs report and patch, technical support, troubleshooting, etc.

contact us at：

email: <support@senselock.com>

**Remote support available on request.**

online (skype), video conference, teamviewer etc.

#### Kindly remind

Unlike with SaaS shiledling solution, as a pure on premise code hardening/app shielding solution, Virbox Protector do not set limitation to software developer regarding to the size, times, projects, versions of application being protected/shielding.

**Software developer is not allowed to use Virbox Protector to provide application hardening/shield service to any of third party.**

**Term of condition in details refer the EULA** when you install Virbox Protector.


# Virbox Protector License: Offline Environment

For some developer worked in offline environment, Virbox supports to use license key (a series characters string, numbers) to activate the Virbox Protector license and binding the machine in offline environment.

> Note: this document applied for Virbox Protector 3.3.2.xxx version or above

Basically, to activate the license key in offline environment includes 3 steps:

## Prerequisites:

1. Download and install Virbox Protector installation package into the machine in offline environment;
2. Get the license key in your hand (Trial license key or formal release license key for the developer who purchase the commercial license)

## Steps

1. #### Generate the c2d **file** from the offline machine

   The software developer use the Virbox Protector to generate the c2d file in offline machine (the process to collect the machine hardware fingerprinting information which to use binding license later, c2d means "customer to developer").
2. #### Exchange/Get d2c file in Virbox License User Center

   Developer use the c2d file and license key in online environment to exchange/get correspondence d2c file from Virbox License User Center. and download this unique d2c file into the online machine. (d2c file which means "developer to customer")
3. #### Use d2c file to activate the license.

   Copy this d2c file from online machine and take this d2c file and import it in to the machine in offline environment (intranet). double click d2c file to activate the license.

## Process to activate License key in offline environment

In this part, we introduce the process to activate the license key in offline environment in details. developer may refer and follow up the process to bind the license with the machine in offline and activate the license accordingly.

The process to activate the license key in offline environment includes following steps.

### Step 0

Execute and start up Virbox Protector GUI tool in offline environment, click The button `License Information` in right top corner of Virbox Protector GUI tools：

<figure><img src="/files/J09p2u9jtKhb6rksw5BQ" alt=""><figcaption></figcaption></figure>

Then a box will popup and click the button `License Center` as shown in below:

<figure><img src="/files/nMH3PnAWG11RlS8GvSXt" alt=""><figcaption></figcaption></figure>

> **Note:**
>
> License Center is the local web license verification tools installed in your local machine, it will show all of license available and add or remove the license.
>
> To view access local machine, the on default IP adress is 127.0.0.1; if you want to view and access network license, you can change IP address respectively;

### Step 1 Generate the c2d file

Click `add license`

{% hint style="info" %}
you may change GUI Language by click the "Setting" in the side bar of License Center
{% endhint %}

<figure><img src="/files/qNqH6Vv5pwoqA7XIPJWo" alt=""><figcaption></figcaption></figure>

Then new box popup, as shown as in below, Click:

&#x20; `Offline Upgrade Package` tab,

and follow with 2 step in below to generate c2d files from this machine in offline environment:

Click:

1. `Download Locl C2D file`

<figure><img src="/files/bFD2SDznmxy2VnHw0pDS" alt=""><figcaption></figcaption></figure>

2. Save the C2D file to specified directory and copy this C2D file later.

### Step 2 exchange and get D2C file from Virbox User license center

Copy the C2D file which download and saved in specified directory. and go back to online environment

Open browser, open Virbox User License Center

<https://user.lm.virbox.com/sn/login.html>

Input your license key, click to signin

<figure><img src="/files/iTk3H04QDfmimK5jo4OJ" alt=""><figcaption></figcaption></figure>

Next step to input Captcha image shown, there would be 2 different kind of image popup in random to you to select:

1. Click the Chinese Characters in the image in sequence shown on top of image.

<figure><img src="/files/5vvqcUQHZGzHrSHqUfhY" alt=""><figcaption></figcaption></figure>

2. Drag the slider in the image to complete the puzzle.

<figure><img src="/files/eyiYExc2G4RzW73suX3V" alt=""><figcaption></figcaption></figure>

Then you will login Virbox User License Center to exchange and get d2c file

<figure><img src="/files/FIz7BKmut8NHPAuz5Bz5" alt=""><figcaption></figcaption></figure>

Then you will find a d2c file generated and download in your online machine. Go to download directory and copy this d2c file and go back to offline environment.

### Step 3 Use d2c file to activate license in offline machine

Now, you have copied the d2c file to your machine in offline environment (which install Virbox Protecor)

Action: add d2c file to Virbox User license tool in your offline machine with:

**Double click the d2c file**

In this step, it is required to use `Virbox User license Tool` to add d2c file (the tools to generate the c2d file) again.

you can click Virbox GUI tool to open `License center` as you have done in Step 1:

<figure><img src="/files/zzsR5d9hQXJ57xajIEX7" alt=""><figcaption></figcaption></figure>

A Box shown license information popup

<figure><img src="/files/bSMVGeIdRYE0aPWb5OyM" alt=""><figcaption></figcaption></figure>

Click the button `Add license`

<figure><img src="/files/07hVfDjBFtvAIFEoEWe8" alt=""><figcaption></figcaption></figure>

Follow below steps to add the d2c file save in your offline machine and confirm to import

<figure><img src="/files/tWq24DjmTNceSPSIrURN" alt=""><figcaption></figcaption></figure>

when import d2c file, you can find the license add in your License center, and the Virbox License has been activated. you can use Virbox Protector to protect your project from now.

<figure><img src="/files/PSMFCsXQLznZGqcxKyPj" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/0yrxF15G36W54OvPZQgP" alt=""><figcaption></figcaption></figure>

Now, you can Open Virbox Protector GUI tools, and click `License Information` in right top corner, to view the license added.

<figure><img src="/files/HKMeyJ2Jm0bTMvMWDJIG" alt=""><figcaption></figcaption></figure>

you can find the license information added with below windows, if not find new license, click `refresh` to view the license status.

<figure><img src="/files/I5ftTDEUftf2bufP0IBp" alt=""><figcaption></figcaption></figure>

Now, you have completed the whole process to bind and activate the license in the machine in offline environment.


# Virbox Protector License (CLI)

## 1. Introduction

For Developer use Virbox Protector CLI tool to protect their software project in project build in process, they can use cloud license (Trial period), soft license or use Hardware dongle (Virbox Elite 5) to be the license container, to login license, bind the license or license key or unbind the license or license key before they use Virbox Protector to protect the software project. In this section, we introduce how to login license, bind license and log out, unbind license when developer use Virbox Protector CLI tools.

## ​2. Virbox Command line tools (CLI tool)

When you install Virbox Protector in your machine, You can find Virbox Protector CLI tool : `virboxprotector_con.exe` in below folder/path (on default directory)

```
Windows:
Commercial release：
C:\Program Files\senseshield\Virbox Protector 3\bin\virboxprotector_con.exe
Trial release：
C:\Program Files\senseshield\Virbox Protector 3 Trial\bin\virboxprotector_con.exe

Linux:
Commercial release：
/usr/share/virboxprotector/bin/virboxprotector_con
Trial release：
/usr/share/virboxprotector-trial/bin/virboxprotector_con

macOS:
Commercial release：
/Applications/Virbox Protector 3.app/Contents/MacOS/bin/virboxprotector_con
Trial release：
/Applications/Virbox Protector 3 trial.app/Contents/MacOS/bin/virboxprotector_con
```

Note：

1）Add the path of`virboxprotector_con` into the system environment variable，you can use the Virbox Protector CLI in the command console directly；

2）If Virbox Protector not add in to the environment variable, you need to specify the absolute path of Virbox Protector CLI tool `virboxprotector_con`, or entry the folder which Virbox Protector `virboxprotector_con` located to execute and protect the project.

## 3. Soft license

Virbox Protector supports 2 kinds of soft license to developer to login/bind with machine:

* Account based soft license
* License key

### 3.1 Use the account based soft license to bind with windows machine

1. Use following command to view help information:

```
virboxprotector_con.exe --help
```

<figure><img src="/files/ihiqKBbvVbTLSp0l862F" alt=""><figcaption><p>Use CLI to view Help info</p></figcaption></figure>

2. Execute following Command to select the type of license：

```
virboxprotector_con.exe -bind
```

1）`Bind with account`

`2) Bind with license key`

When you use the soft license (email account based license), select 1) to bind the soft license with your machine;

When you received a series digital code to activate the Virbox Protector, select 2) to bind the license key with your machine

Here, we select 1)

`Note:`

`Virbox Protector support 2 kinds of Soft license to bind with your machine: Account based soft license and license key, Both soft license and license key supports to use in Online environment and use the license key to bind the machine in offline environment.`

<figure><img src="/files/DMq5hH6gXYQr3fEDCYET" alt=""><figcaption></figcaption></figure>

3. Input your email account and relevant password

<figure><img src="/files/r80xrUYhPi1Z9nlTRlMe" alt=""><figcaption></figcaption></figure>

4. Input email account and password, then it will show and list all of soft license in your account, select and input the number to bind with correspondence soft license, as shown in the sample below (in the sample, we select `7` to bind with correspondence .Net License with machine )

<figure><img src="/files/qiHR5GVK2N5EjwWpzQQw" alt=""><figcaption></figcaption></figure>

5. When bind the license with your machine successfully, then you can use the license at present machine, till the license expired or you want to unbind the license. otherwise, it is not necessary to bind license again.

### 3.2 Use License key to bind license with windows machine

1. Use following command to bind the license with machine

```
virboxprotector_con.exe -bind
```

and select:

`2) Bind with license key`

<figure><img src="/files/x2UFJrYWekxpyLqZ1Jt2" alt=""><figcaption></figcaption></figure>

2. Input the license key to bind the license with your machine

<figure><img src="/files/gNXRRh9iOqT0nEjw1erR" alt=""><figcaption></figcaption></figure>

### 3.3 Bind license key in Linux environment

#### Online Environment

**Activate the license key in online environment**

1. Open terminal windows in Linux system, use following command:

```
ssclt --online_bind_license_key --license_key 26W7-4ZTP-38YP-JRX1
```

The script `26W7-4ZTP-38YP-JRX1` in above is the license key in sample, pls replace with your own license key respectively

2. use command to view if the license has been bind and activate:

   ```
    ssclt --slock 
   ```

   Offline Environment

> When you bind the license key in offline machine, another **online** machine required. this online machine will be used to exchange the d2c file in Virbox User center. The online machine with windows system will be fine. (linux machine also will be fine;)

**Pre requisition**

in your offline machine, pls install Virbox User license tools first.&#x20;

1. Open terminal windows to generate the file contained the offline machine hardware fingerprinting information (c2d file):

   ```
    ssclt --offline_bind_c2d --c2d ./
   ```

   then a file with c2d suffix will be generated under present folder accordingly.

   For example:

   `ZHOUZH-EPC_192.168.0.54_bind_20210428.c2d`
2. Copy this c2d file to another machine in online environment which access internet;
3. in this online machine, visit and access following url to exchange d2c file and input the license key

   <https://user.lm.virbox.com/sn/login.html>

   input the license key you received;

{% hint style="info" %}
For detail process to exchange c2d file in Virbox user center, you may refer process:&#x20;

#### [Virbox Protector License: Offline Environment](/download/virbox-license/virbox-protector-license-gui/virbox-protector-license-offline-environment)

Step 2:

Exchange and get d2c file from Virbox User license center
{% endhint %}

1. Use the c2d file generated to exchange d2c file (click input box then you can select the c2d file which saved in your online machine)

   note: d2c file is the file which used to activate Virbox Protector in offline machine.
2. click "exchange d2c file" to download the d2c file to your online machine;

   sample d2c file name is: `ZHOUZH-EPC_192.168.0.54_bind_20210428.D2C`
3. Copy the d2c file and save this file to your offline machine; and execute the command:

   to activate the Virbox Protector license in your offline machine

   View and check the license bind with your offline machine. use the command:

   For more CLI command in Linux system, you can view CLI user manual.

### 3.4 Unbound Soft license

1. Use following command to get and view help information:

```
virboxprotector_con.exe --help
```

<figure><img src="/files/zQRIWGTmarF1Q1W1MtNs" alt=""><figcaption></figcaption></figure>

2. Use following command to view all of soft license bound with your machine, input the correspondence Number to unbind correspondence soft license, input `0` to unbound all of soft license bind with your machine.

   in the sample below, we input `9` to unbind Virbox Protector Java BCE license from the machine

```
virboxprotector_con.exe -unbind
```

<figure><img src="/files/dh8TB7lBZQh9XGLNyuX8" alt=""><figcaption></figcaption></figure>

## 4. Cloud License

1. Use following command to view the help information

```
virboxprotector_con.exe --help=global
```

<figure><img src="/files/QaDeq9bNBMTIYIUrRY9W" alt=""><figcaption></figcaption></figure>

2. Execute following command to login the cloud license:

```
virboxprotector_con.exe -global --username=<> --password=<>
```

<figure><img src="/files/nv3itcjvbxBLl9kguvYP" alt=""><figcaption></figcaption></figure>

3. When you login account successful, then you can use Virbox Protector command line interface tool to protect your project

> Note:
>
> 1. it is mandatory to execute the login license and protect the project in 2 sperate steps. you can not to combine 2 command in one steps;
> 2. When you login the license, and the soft license contained in your account can be bound with local machine.


# Virbox Protector License （Network License)

## 1. Introduction

For Developer worked use Virbox Protector in same site, team or same company, They can purchase Virbox Protector Network License and install the Virbox Protector in multiple machines , then select one of machine to be the License server to provide Network license in remote to other machine, and the rest of developer can access the Network license, verification and use the network license to protect their project in remote site.

The License container for Network license supported includes hardware dongle and soft license, after setting completed in remote machine, then the network license can be used to protect the software project in remote machine accordingly.

In this chapter, we will introduce how to

1. Set up the environment and use license in remote machine;
2. How to configure in the network license server & Client machine;

## 2. Use network License from client machine (Virbox Protector GUI tool)

### Process in Client machine

2.1 Open your Virbox Protector GUI tool, Click `License Information`, Select the `Network License`, click to add the network license, input the IP address of the machine to be the Network license.

see attached screenshot:

<figure><img src="/files/raORyFswTsdOJ2O2kDRO" alt=""><figcaption></figcaption></figure>

Follow up steps shown in the steps in below to add server machine address

<figure><img src="/files/6DQ7UhwNxI6Jy1AkxMnZ" alt=""><figcaption></figcaption></figure>

2.2 When the license dongle (Virbox Elite 5) or Network license contained in the License Server (machine), it will list all of license contained in the server machine.

<figure><img src="/files/A4fk8AHfH7XbDNMWQFff" alt=""><figcaption></figcaption></figure>

2,3 You can start to protect application when the correspondence Virbox Protector license in the license list on the License Server.

```
Note:
1）One license session will be used when the machine set to be the Network license server and client both.
2）If the No. of the client machine which use the Virbox Protector license is out of the maximum Number of license setting, it will popup a message "up to maximum concurrent number of set " when you execute the Virbox protector to protect applications.
```

## 3. Network License setting in license server/client

### 3.1 Server/Client setting in Windows environment

#### 3.1.1 Server setting

1. Install the Virbox Protector in your server machine.
2. Search `Virbox User License tool` : `ssclient.exe`

The on default installation directory would be:

`C:\Program Files (x86)\senseshield\ss\Tools>ssclient.exe`

<figure><img src="/files/I1soaVwy5wuqZlCtsiJE" alt=""><figcaption></figcaption></figure>

Open it. the GUI is attached as shown in below

3. Select the service mode: `Client/Server mode`

Click `Service`->`Service mode`->`Client/Server Mode (Network Concurrent license)`,

Click `Save & Restart`

<figure><img src="/files/CNYuzZM2rDoO0e0UdY6i" alt=""><figcaption></figcaption></figure>

Note

1）If the Server IP address is located at same network section, it will be identified automatically and add it into the server list;

2）If the server IP address doesn't located at the same IP network section, and available by `ping` , you can add server by manually: Click `Add` button in the Client machine to add the server.

#### 3.1.2 Client Setting

1. Add Server in your client machine (applicable to add the server which IP address located at different IP network section, prerequisite is the server is reachable by use of command `ping`)

Follow the action step by step as the screenshot shown in below:

<figure><img src="/files/eJ4I9T3Yv8WLTkXQ5UDx" alt=""><figcaption></figcaption></figure>

Tips:

1）Above setting applied for adding the Server machine in different network section from client machine, The premise is that the server and client can `ping` each other;

2）For Server machine and client machine are located in the same network section, you can skip and ignore above steps.

2. [Find the Server by using Virbox Protector GUI tool](broken://pages/Hwyses55b72IXOjiOr2S), You can follow the steps to add the server IP address when you open and execute the Virbox Protector GUI tool;

### 3.2 Server setting (Windows) and Client setting (Linux/mac)

#### 3.2.1 Server setting

Click \[Windows Server setting]\(3.1.1 Server setting) and view the setting

#### 3.2.2 Client setting

1. For the Linux/mac client, Use following command to add the server in the client machine.

```
sscfg -a -n xx -i 192.168.1.23 -p 10334
Note: usually, the xx follow with -n is the server name, which can be named freely.
```

<figure><img src="/files/79Z5yPWdhiR6iWH411hH" alt=""><figcaption><p>add server</p></figcaption></figure>

2. it will prompt to restart service message when successful to set the `Client/Server` mode, Use the command in below to restart the service.

1）Restart service in Linux system:

```
sudo systemctl status senseshield
```

2）Restart service in mac system:

```
sudo launchctl stop com.sense.scp
sudo launchctl start com.sense.scp
```

Note:

1）Above setting applied for adding the Server machine in different network section in Linux/mac client machine, The prerequisite is that the server and client can `ping` each other;

2）For Server machine and client machine are located in the same network section, you can skip and ignore above steps.

3. \[Add the server ip address in the Virbox Protector GUI too]\(2. Use network License from client machine (Virbox Protector GUI tool))l, you can follow the steps to add the server IP address when you open and execute the Virbox Protector GUI tool;

### 3.3 Server setting (Linux/mac) and Client setting (Windows)

#### 3.3.1 Server Setting

1. Install Virbox Protector in the server machine (Use correspondence installation package)
2. View and check if the system has been set to be: `Client/Server` mode, if not, you need to change to `Client/Server` mode, you may refer following command to view and check the service mode of the system:

```
sscfg -s
```

<figure><img src="/files/PebQeoCU4WFN8khcukx2" alt=""><figcaption><p>Client</p></figcaption></figure>

3. Set the system's service mode to: `Client/Server mode`, you may refer following command to set the service mode:

```
sscfg -e cs
```

4. When successful setting the system's service mode, the system will prompt to restart service, you may refer following command to restart system:

Restart service in Linux System

```
sudo systemctl status senseshield
```

Restart service in mac System

```
sudo launchctl stop com.sense.scp
sudo launchctl start com.sense.scp
```

5. View and check current system service mode setting:

```
sscfg -s
```

<figure><img src="/files/kOc9YGxOHXSsDeEnDraL" alt=""><figcaption><p>server</p></figcaption></figure>

Tips:

1）The command to check and view the system service mode to Linux system and mac system is same, only the command to restart service is different.

2）If the IP address of server and client is locate same network section, the system will automatically identified the address and add it into server list.

3）If Server machine and client are located in different network section from, and be reachable by use the command to `ping` each other. you can add the server IP address manually in the client machine.

#### 3.3.2 Client Setting

1. View the client setting in the \[window system]\(3.1.2 Client Setting)
2. \[Add the server IP address in Virbox Protector GUI tools]\(2. Use network License from client machine (Virbox Protector GUI tool))

### 3.4 Server setting (Linux/mac) and Client setting(Linux/mac)

#### 3.4.1 Server setting

1. View and check the \[server setting]\(#3.3.1 Server Setting) in the Linux/macOS system

#### 3.4.2 Client Setting

1. View the \[client system setting]\(3.2.2 Client setting) in Linux/macOS:
2. \[Add the server IP address in Virbox Protector GUI tools]\(2. Use network License from client machine (Virbox Protector GUI tool))

## 4. Command line operation & process

**Command line**

1. Install Virbox Protector, entry the installation directory, and find `virboxprotector_con.exe` under the subdirectory `\bin`；
2. Use the command:

`virboxprotector_con.exe --help=global`

​ to view network license status

<figure><img src="/files/s9Jvp36fTwlunHLRi6aI" alt=""><figcaption><p>Comand line</p></figcaption></figure>

3. Command Option

| Command Option                    | Description                     |
| --------------------------------- | ------------------------------- |
| --set-servers=\<ip\_or\_hostname> | Add the server's IP address     |
| --list-servers                    | List the IP address of Server   |
| --delete-servers                  | Delete the IP address of Server |
| --username=\<user\_name>          | The License account             |
| --password=\<user\_name>          | The password of license account |

**The command to execute Virbox Protector to protect application**:

After adding the server IP address, if the server has been issued the Network license or hardware dongle plugin, then the client can use the license in server to protect the application in client end:

1. The command to add designated server:

```
virboxprotector_con.exe -global --set-servers=192.168.71.219
```

2. The command to add multiple servers (sample command add 2 servers in 2 IP address:

```
virboxprotector_con.exe -global --set-servers="192.168.71.219;192.168.71.220"
```

3. The command to Delete the designate server

```
virboxprotector_con.exe -global --delete-servers=192.168.71.219
```

4. The command to Delete the multiple server added:

```
virboxprotector_con.exe -global --delete-servers="192.168.71.219;192.168.71.220"
```

5. Use command line to login the licensed account:

```
virboxprotector_con.exe -global --username=testdemo@sense.com.cn --password=123456

Note: when successful login your license account, 
The interface of Virbox Protector will not show the message to license logined successful, The Virbox User license tool on client end will be accept the license login successful on default, and it will verify the license when you use Virbox Protector CLI tool to protect the application.
```


# Purchase Virbox License

We will introduce Virbox commercial license and how to buy Virbox License

Virbox Protector support developer to protect mobile applications (Android and iOS) and traditional desktop/server application/project (C/C++, C#, Java or scripting language)

Virbox Protector License will be available by program language, system environment, Architecture: includes following license:

Native language license: support to protect C/C++, Delphi, Golang, those native language; developer also need to specify the operation system;

.NET platform license: support to protect C#, VB program Language; License supports cross platform;

Java License; Protect Java application and project;

Scripting language License: include Python license, Javascript language; HTML 5 license; etc.

ARM Linux license; Protect the application running in ARM Linux system

Android AAB/APK license; Protect Android DEX package;

Android .so Library license: Protect Android .so library with the most secured "Virtualization"

Android AAR license: Protect Android SDK package

iOS license: Protect iOS applications;

macOS license: Protect mac applications;

Virbox provides both subscription and perpetual license to developer (for some license, only subscription license available;

Any question related to purchase license, contact us:

<support@senselock.com>

or&#x20;

<sales@senselock.com>


# Overview

{% hint style="info" %}
**Good to know:** Virbox Protector provides both GUI tools and CLI tools to developer to protect their application in different systems
{% endhint %}

You can find the Virbox protector in the  sub directory of Virbox Protector installation path: <mark style="color:blue;">`the installation path of virboxprotector\bin`</mark>

Virbox Protector GUI tool:

<mark style="color:blue;">`virboxprotector.exe`</mark>

[Virbox Protector CLI tools](/fundamentals/cli-tool-overview):

<mark style="color:blue;">`virboxprotector_con.exe`</mark>

Besides of Virbox Protector's GUI tool and CLI tool, Virbox Protector also provides **DS Protector** to protect the data resource of your applications, you can find **DS protector** in the same sub directory of Virbox Protector installation path: <mark style="color:blue;">`the installation path of virboxprotector\bin`</mark>

DS Protector GUI tool:

<mark style="color:blue;">`dsprotector.exe`</mark>

DS Protector CLI tool:

<mark style="color:blue;">`dsprotector_con.exe`</mark>


# GUI tool

Go to \bin sub directory of  installation directory of Virbox Protector and find:

<mark style="color:blue;">`virboxprotector.exe`</mark>

and execute it and sign in with your account

![](/files/C0bwxzNwojQck7FXLDql)

Go to \bin sub directory of  installation directory of Virbox Protector and find the DS protector which used to protect the data resource:

<mark style="color:blue;">`dsprotector.exe`</mark>

execute it:

![](/files/QzaLOyPYRV2hSfCQdcCi)

We will introduce the protection process in next chapter.


# Protection Process

{% hint style="info" %}
**Protect your app with simple process**

It is quite easy for developer to use Virbox Protector GUI to protect their applications with very simple process:

Step 1: Drag the application into the Virbox Protector;

Step 2: Select and Set the protection option to specified functions and set the protection to your applications in general: multiple protection options can be set;

Step 3: Click the Button "Protect Selected Project" to complete the protection process;&#x20;

Step 4: Test and evaluate the security of the protected application;

Step 5: Distribute the protected application to your users or Deployed protected application in different system environment.

{% endhint %}

![](/files/Ocy0MrDKFG1agrHYT9jt)

Virbox Protector provides multi-layer protection/encryption technology and help developer to defend third party attacker to use decompilier, debug tool static and dynamics analysis to crack your application to steal your algorithm, IP and digital asset etc.&#x20;

The most important steps to protect your application is STEP 2: <mark style="color:blue;">Function Options</mark> tabs and <mark style="color:blue;">Protection Option</mark> tabs and STEP3: Protect the projects;

In Step 2, Developer select and set the protection option to the functions and application

**In the Function Option tab**, developer will select those critical functions, methods in your applications and set the protection mode to those critical functions in your application and protect it.&#x20;

The protection options to "functions" includes: Virtualization, Obfuscation, Encryption and No protection which can be select and set to those functions.&#x20;

**In the Protection Option tabs**, Developer may select and set the protection option in your application in generals, multiple protection, detection features can be set in this tab: Import Table protection, Compression, Memory Check, Resource section protection, Anti-debugging, VM detection, Memory Protection, Kernel Mode anti debugging etc. and protect data resource etc.&#x20;

The protection features can be set may slight different to protect different kinds of applications, more description and details can be found in the USE CASES in following chapters.

In Step 3, after protection completed, 2 new file will be generated in the output path which you set:

The configuration file contains protection setting: <mark style="color:blue;">samplename.exe.ssp</mark>

{% hint style="info" %} <mark style="color:blue;">For the file suffix with .ssp, is the configuration file, pls keep and save it, and no need to distribute the configuration file to your software user.</mark>
{% endhint %}

and the protected file: samplename.exe which in seperately directory: \\<mark style="color:blue;">protected\samplename.exe</mark>


# CLI Tool: Overview

Virbox Protector provides command line interface tool to developer also, Developer may use the CLI tool to protect application in "Build in" process. Virbox Protector CLI tool includes 2 tools:

Go to `\bin, the sub directory of  installation directory of Virbox Protector and find:`

<mark style="color:blue;">`virboxprotector_con.exe`</mark>

and DS protector CLI tool:

<mark style="color:blue;">`dsprotector_con.exe`</mark>

![](/files/I3B1OGe1xYqSVn1lqeeM)

in Linux Environment:

<figure><img src="/files/1lbw4kvZApkTZ4KFpUfE" alt=""><figcaption></figcaption></figure>

execute Virbox Protector CLI tool, you can view help information:

`virboxprotector_con`

<figure><img src="/files/yo49YtjvGeXATLCGCiHy" alt=""><figcaption></figcaption></figure>

To specify your application type, to get  help information in detail:

`virboxprotector_con --help={}native|dotnet|apk|aar|app|java-bce|java-vme|u3d|u3dres|h5|strip|mulpkg|ilmerge}`

<figure><img src="/files/NIlBAKXiPxgbHlckdlg2" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note: "app" here means iOS app.
{% endhint %}

For example, to get help information to protect native project

`virboxprotector_con --help=native`

<figure><img src="/files/fHfXrD0uaVbmjpxRtKvy" alt=""><figcaption></figcaption></figure>

Execute the DSprotector\_con.exe, you can view the help information:

`dsprotector_con`

<figure><img src="/files/rZYFW6ZGUSdHnQiKjoU5" alt=""><figcaption></figcaption></figure>

#### Use Virbox Protector CLI tool to Bind license

Use following command to bind License before to use Virbox Protector Command line interface tool:

input Command:

```
virboxprotector_con.exe -bind
```

1. Return，input correspondence selection, Virbox Protector support to bind the license with account or license key;

   ```
   Select a binding type:
   1) Bind with account.
   2) Bind with license key.
   ```
2. Use the account to bind license in sample, then input 1 to select account and input password;
3. all license will be listed, input digit to bind related license, and return to bind the license;

<figure><img src="/files/wRvHPucSRrwrNXcOnhw7" alt=""><figcaption></figcaption></figure>

#### Unbind license

Use following command to bind License

```
virboxprotector_con.exe -unbind
```

when all license bound has been listed, input related digit to unbind the license.

<figure><img src="/files/qg9dWdZUd6m8fmO8ht6S" alt=""><figcaption></figcaption></figure>

For how to use the Virbox Protector CLI tool, pls refer the CLI User manual:

{% content-ref url="/pages/eYRCGDooW6rdTrISIQi3" %}
[CLI Tool: User Manual](/fundamentals/cli-tool-user-manual)
{% endcontent-ref %}

Next, We will introduce how to use Virboxprotector GUI tool to protect the:

{% content-ref url="/pages/cdoRl0uFioD84hEaiHta" %}
[Protect Desktop applications](/use-cases/protect-desktop-applications)
{% endcontent-ref %}

{% content-ref url="/pages/EBAdHGl29FIhjpcZ8WsH" %}
[Protect Unity3D/UE4 application](/use-cases/protect-unity3d-ue4-application)
{% endcontent-ref %}

{% content-ref url="/pages/7irgODbsU3nhQfQKE6bs" %}
[Protect Mobile applications](/use-cases/protect-mobile-applications)
{% endcontent-ref %}

{% content-ref url="/pages/15lo93zOPDs0kG4jntwC" %}
[Protect Scripting language](/use-cases/protect-scripting-language)
{% endcontent-ref %}

{% content-ref url="/pages/Q8tU265WTI2rvlr3rkVQ" %}
[FAQ](/use-cases/faq)
{% endcontent-ref %}


# CLI Tool: User Manual


# User Manual\_Virbox Protector Command Line

## User Manual:

## Virbox Protector Command Line Tool

Virbox Protector supports developer to protect applications in both GUI tool and CLI tool.

Here we introduce how to use "Command Line Interface of Virbox Protector to protect applications.

### Prerequisites

Sign-up Virbox Protector, get the trial license and install the Virbox Protector in your machine;

Go to the ***\bin*** sub directory of installation directory of Virbox Protector, besides of the GUI tool of Virbox Protector, you will find 2 command line interface tools in the same of installation directory:

Virbox Protector CLI tool:

```
virboxprotector_con.exe
```

DS Protector CLI tool (DS Protector is the tool for software developer to protect their data resource, more details information, pls refer the relevant document):

```
dsprotector_con.exe
```

(Above prerequisites is for test/evaluation Virbox Protector only.

To protect formal release software, pls purchase and get the related Virbox Protector license)

### 1. Start to use Virbox Protector CLI tool

The on default path for`Virbox Protector` CLI tools: `virboxprotector_con.exe` are:

```
Windows:
C:\Program Files\senseshield\Virbox Protector 3\bin

Linux:
/usr/share/virboxprotector/bin

macOS:
/Applications/Virbox Protector 3.app/Contents/MacOS/bin
```

When you call Virbox Protector Command line tool and execute the Virbox protector,

You may:

Either to specify the full absolutely path, for example:

```shell
"C:\Program Files\senseshield\Virbox Protector 3\bin\virboxprotector_con.exe" <file_path>      <options ..> -o <output_path>
```

Or,

in windows system , you may add the environmental variable and directly input:

`virboxprotector_con`

and no need to specify the full path to execute the Virbox Protector.

For non windows system: you may set the Symbolic Link, like this sample below:

```shell
sudo ln -s /usr/share/virboxprotector/bin/virboxprotector_con /usr/local/bin/virboxprotector_con
```

Then you can directly input: `virboxprotector_con` to protect your applications.

### 2. The main protection function/feature of Virbox Protector CLI tool:

To protect desktop or mobile application, you can call Virbox Protector CLI tool and specify the application path and out path to protect your applications. Virbox Protector will automatically to recognize the application types;

Like with Virbox Protector tool, Developer may use "option" to set and specify the "Protection option" to the application protected, includes “Function Option”, "Protection Option", "Data & Resource Protection" etc.&#x20;

{% hint style="info" %}
On default, if developer doesn't specify output folder, after protection succeed, a new `\protected` folder will be generated, the protected application with same file name located in the new directory.&#x20;
{% endhint %}

```shell
virboxprotector_con <file_path> <options ...> -o <output_path>
```

To get help information, use following command:

`virboxprotector_con`

or

`virboxprotector_con --help=?`

to view help information to each type of application in details:

<figure><img src="/files/yo49YtjvGeXATLCGCiHy" alt=""><figcaption></figcaption></figure>

For dsprotector\_con

`dsprotector_con <filename|directory> <-c ssp>`

To get help information, execute&#x20;

`dsprotector_con`

or

`dsprotector -?`

<figure><img src="/files/v9UsQnq1rUkIeYROHx0b" alt=""><figcaption></figcaption></figure>

Specify application type to view help information in detail:&#x20;

`native|dotnet|apk|aab|aar|app|u3d|java-bce|java-vme|h5|strip|u3dres|mulpkg|ilmerge`

For example, get help information to protect Android AAB package:

`virboxprotector_con --help=aab`

<figure><img src="/files/CpwccVinII1IweQVbw5D" alt=""><figcaption></figcaption></figure>

For some special application type, it is required to specify the argument accordingly.

| Application type and protection option                                    | Argument                   |
| ------------------------------------------------------------------------- | -------------------------- |
| Protect the Java apps with BCE protection mode                            | `-java`                    |
| Protect the Java apps with VME protection mode                            | N/A, on default to use VME |
| Protection Unity3D app and resource encryption (Windows/Linux hot update) | `-u3dres`                  |
| Protection the HTML 5 (.js file)                                          | `-h5`                      |
| To remove the debugging information from ELF file (strip)                 | `-strip`                   |
| Protect and archive with multiple package                                 | `-mulpkg`                  |
| Protect and merge assemblies                                              | `-ilmerge`                 |

Example:

```shell
virboxprotector_con -java <java_dir> <other_options ...>
```

#### **The Syntax of Virbox Protector CLI with long options**

For most of command line options, the syntax is:

`--{opt}=value`

1 means enable/switch on

0 means disable/switch off

**Sample**

`--mem-check=1`, `--jit-enc=0`

#### **How to get the CLI's Help**

For more detail instruction/help to use VBP CLI's options/arguments,

**use**: `--help={type}` to view the CLI helps:

```shell
virboxprotector_con --help=apk
```

<figure><img src="/files/VwQcYTTOszcbroB5szcR" alt=""><figcaption></figcaption></figure>

The application supports to get "help" includes:

```shell
--help={native|dotnet|apk|aab|aar|app|u3d|java-bce|java-vme|h5|strip|u3dres|mulpkg|ilmerge}
```

`native` application means the native types of application to the operation system, and it doesn't need the Virtual machine environment or interpreter when executed. usually, these native application compiled by C/C++/Delphi/VB6 program language, which includes:

​ The PE program in the Windows system(with the suffix of .exe/.dll/.sys );

​ The Elf programs in the Linux/Android system (with the suffix of .so or main program);

​ The MachO application (.dylib or main program) in the macOS/iOS system.

<figure><img src="/files/fHfXrD0uaVbmjpxRtKvy" alt=""><figcaption><p>Help info to protect native application</p></figcaption></figure>

### 3. The way using Virbox Protector CLI to protect applications

Unlike with by using the Virbox Protector GUI tool, developer to set protection option by "select and click", when Developer use the CLI tool to set the protection setting, there are 2 ways for Software developer to set the protection option by use of Virbox Protector CLI tool to protect their project.

#### **Option 1: With protection configuration file**

Configuration file (suffix .ssp) is the file which generated by Virbox Protector GUI tool which save the protection option setting. Developer use **Virbox Protector GUI  tool** to generate the protection configuration file (the configuration file suffix is **.ssp file**, which store the protection setting to functions protection setting, general protection setting etc..) and then save the configuration file together with the project which to be protected in the same folder, then use **Virbox Protector CLI** (no need to specify argument, option, since all of protection setting has been saved in the configuration file) to protect the project accordingly.

#### **Option 2: Without Protection Configuration file**

&#x20;Use CLI tool to protect the software project directly, with specified the argument, option which to define the functions protection option and general protection options.

Developer may use VBP CLI tool to protect different kind of application with multiple arguments and options.

if no specified argument/option has been used in Virbox CLI tool, the protection setting will be used on default.

#### **Option 1 example**

Here we use a native executive file to be a example to show how to use Virbox Protector GUI tool to generate a protection configuration file (.ssp file) and then use the CLI tool and the configuration file to protect the original native executive file.&#x20;

**Step1**, Generate the "Protection Configuration File"

Open the Virbox Protector GUI tool, drag the native file into Virbox Protector GUI tools, set the protection option in the `Function Option` tab and `Protection Option` tab;

Click the button (menu): `Save Selected Configuration` which save the configuration file generated (suffix name is .ssp in the output folder

<figure><img src="/files/zLi6yVLyg1uIL4pZzGhD" alt=""><figcaption></figcaption></figure>

#### Go to output folder

Go to the output folder, find the .ssp file and save the configuration file in the same folder together with native file which to be protected.

#### Step 2 &#x20;

Use Virbox Protector CLI tool to protect the native project file

Virbox Protector standard command to protect applications:

```
virboxprotector_con <file_path> <options ...> -o <output_path>
```

C:\the absolutely path of virbox protector\virboxprotector\_con the absolutely path of protected file\protected filename -o absolutedly path of output file\output file name

sample:

<figure><img src="/files/wbWeKI3cTHyjrw1jxyBQ" alt=""><figcaption></figcaption></figure>

#### if no configuration file generated or  not be found the configuration file in same folder

Virbox Protector CLI tool will use protection option setting on default to protect the project:

The on default protection option setting for:

**Native Project:**

Compression and Memory Check

**.NET Project:**&#x20;

Compression and JIT Encryption;&#x20;

if you want to specify to protect the concrete function with Code encryption or Code Obfuscation, you need to generate the protection configuration file first. and follow the protect step above.

**ELF Project:**

Compression and Memory Check;

**MachO Project:**

Memory Check

**Android APK:**

On default protection setting:&#x20;

On default anti debug

### 4. The Protected Application Type & Protection Options setting

From the section below, we will introduce how to use Virbox CLI tools (or Combine with GUI tools) to protect different kind of project, or different language.

CLI command to protect application:

`virboxprotector_con <apk_path> filename <options ...> [-o <output_path>]`

#### Protect Android APK/AAB

Virbox Protector CLI command to use to protect Android AAB or Apk.

`virboxprotector_con <apk_path> <options ...> [-o <output_path>]`

View help info

<figure><img src="/files/CpwccVinII1IweQVbw5D" alt=""><figcaption><p>Help info to Android AAB</p></figcaption></figure>

<figure><img src="/files/QCqje3QNrE7Q8kHy5SdW" alt=""><figcaption><p>Help info to Android Apk</p></figcaption></figure>

| Protection Options                                | CLI arguments        | On default value: |
| ------------------------------------------------- | -------------------- | ----------------- |
| Dex Encryption                                    | `--dex-enc=`         | `APK:1`, `AAB:0`  |
| File Verification                                 | `--file-check=`      | `1`               |
| Signature Verification                            | `--sign-check=`      | `0`               |
| Anti-Injection                                    | `--anti-inject=`     | `1`               |
| Detect the debug tool                             | `--detect-dbg=`      | `0`               |
| Detect the simulator                              | `--detect-emu=`      | `0`               |
| Root Detection                                    | `--detect-root=`     | `0`               |
| Multi parallel Detection                          | `--detect-multi=`    | `0`               |
| Output apks (Valid when enable the AAB signature) | `--apks=<apks_path>` | N/A               |

1 means enable/switch on

0 means disable/switch off

**Resource Encryption**

Virbox Protector (include GUI tool and CLI tool) support developer to protect the data, image resource attached together with the Android application.

Use the argument: `--res-enc=1` to enable the Resource encryption options,

Use the `;` to separate the resource file list, support the wild card `*`

| Option        | CLI argument           | On default Argument value               |
| ------------- | ---------------------- | --------------------------------------- |
| Enable        | `--res-enc=`           | `0`                                     |
| Resource list | `-res <resource_list>` | On default to protect all resource file |

Sample:

```shell
--res-enc=1 -res "file1;file2;assets/file1;assets2/*"
```

**Function Protection Option**

Besides of General protection option setting to applications, Virbox Protector supports developer to protect the specified function/methods, for APK and AAB's Functions Protection, Virbox Protector provides the feature: "Code of Virtualization" to protect the functions/method. which is most secured Protection options to specified functions to Android APK/AAB applications.

On default setting to "Code of Virtuallization" is to protect the methods of entry class of Application and Main Activity's class.

If you want to protect the specific functions/methods, pls refer:

[Function Option](#5.-function-protection-option)

**Archive application to multiple packages**

To archive the application to multiple package template, pls refer:

[Archive with multiple package](#archive-with-multiple-package)

**Signature**

Virbox Protector support developer to use signature, for Signature Options setting, pls refer:

[Signature option](#4.-signature-option)

**Sample**

```shell
virboxprotector_con app-release.apk 
	--dex-enc=1 --file-check=1 --detect-dbg=0 --sign-check=1
	--res-enc=1 -res "assets/*;res/*"
	--hide-symtab=0 -lib "lib/armeabi-v7a/libhello.so;/lib/arm64-v8a/*"
	--sign=1 --ks="test/android.ks" --ks-pass=mypass --ks-key-alias=CERT --key-pass=mykeypass
	-o app-release-protected.apk
```

#### **Protect AAR package**

Virbox Protector support to protect Android AAR pacakge with Code of Virtualization, and to protect the .so libs of AAR package:

Virbox Protector CLI toolCommand used:

`virboxprotector_con <aar_path> <options ...> [-o <output_dir>]`

<figure><img src="/files/rqVYcP86ejp5W2Kfwk6b" alt=""><figcaption><p>Help info to Android AAR</p></figcaption></figure>

Sample (Sample shows to protect the all of the class method of “test.aar” package and protect all of .so libs, "v" means "virtualization")

```shell
virboxprotector_con test.aar -v "com.example.*" -lib "jni/*" -o protected/test.aar
```

#### Protect the Android .SO lib \*\*

Virbox Protector CLI command to protect Android .so libs

`virboxprotector_con <Android.so lib_path> <options ...> [-o <output_path>]`

<figure><img src="/files/vcDpDRshTrgodQgPP6jm" alt=""><figcaption><p>Help Info to Android .so libs</p></figcaption></figure>

| Option                | CLI argument            | On default Argument value |
| --------------------- | ----------------------- | ------------------------- |
| Hide the symbol table | `--hide-symtab=`        | `0`                       |
| Resource list         | `-lib <nativelib_list>` | N/A                       |

```shell
--hide-symtab=0 -lib "lib/armeabi-v7a/libhello.so;/lib/arm64-v8a/*"
```

#### Protect the PE and native application

`virboxprotector_con <native_path> <options ...> [-o <output_dir>]`

<figure><img src="/files/fHfXrD0uaVbmjpxRtKvy" alt=""><figcaption><p>Help info to Native</p></figcaption></figure>

| Protection Option           | CLI arguments     | On default argument value |
| --------------------------- | ----------------- | ------------------------- |
| Compression                 | `--pack=`         | `1`                       |
| Memory Check                | `--mem-check=`    | `1`                       |
| Import table protection     | `--imp-protect=`  | `1`                       |
| Resource section protection | `--res-sect-enc=` | `1`                       |
| Protect/encrypt PE overlay  | `--overlay-enc=`  | `1`                       |
| Detect the debug tool       | `--detect-dbg=`   | `0`                       |
| VM detection                | `--detect-vm=`    | `0`                       |

here value setting:

1 means enable/switch on

0 means disable/switch off

#### Protect the ELF

| Option                             | CLI arguments      | On default argument value |
| ---------------------------------- | ------------------ | ------------------------- |
| Compression                        | `--pack=`          | `1`                       |
| Memory Check                       | `--mem-check=`     | `1`                       |
| Detect the debug tool              | `--detect-dbg=`    | `0`                       |
| Strip the symbol table of ELF file | `--strip-dbginfo=` | `1`                       |

here value setting:

1 means enable/switch on

0 means disable/switch off

#### Protect the MachO

| Protection Option | CLI argument    | On default Argument value |
| ----------------- | --------------- | ------------------------- |
| Memory Check      | `--mem-check=`  | `1`                       |
| Detect debug tool | `--detect-dbg=` | `0`                       |

For how to sign and use signature, pls refer:

[Signature Options](#4.-signature-option)

Here value setting:

1 means enable/switch on

0 means disable/switch off

#### Protect iOS App

Virbox Protector CLI command to protect iOS App

`virboxprotector_con <input_path> <options ...> [-o <output_path>]`

<figure><img src="/files/oRxrzjLSP79GPMryOGOX" alt=""><figcaption><p>Help Info to protect iOS App</p></figcaption></figure>

| Protection Option                               | CLI Argument       | On default Argument value |
| ----------------------------------------------- | ------------------ | ------------------------- |
| Memory Check                                    | `--mem-check=`     | `1`                       |
| Detect Debug tool                               | `--detect-dbg=`    | `0`                       |
| Objective-C: Name of Obfuscation to Objective C | `--objc-rename=`   | `0`                       |
| Output path                                     | `-o`               | `protected/<file_name>`   |
| IPA path (enable signature required)            | `--ipa=<ipa_path>` | None                      |

Here value setting:

1 means enable/switch on

0 means disable/switch off

**Signature Option**

Pls refer the signature of iOS/macOS in the "[Signature Option](#4.-signature-option)".

#### Protect .NET project

Virbox Protector CLI command to protect dotNET project

`virboxprotector_con <input_path> <options ...> [-o <output_path>]`

<figure><img src="/files/G94usu1x29G15c0x5syp" alt=""><figcaption><p>Help Info to protect dotNET</p></figcaption></figure>

| Protection Option                     | CLI Argument     | On default Argument Value |
| ------------------------------------- | ---------------- | ------------------------- |
| Compression                           | `--pack=`        | `0`                       |
| JIT Encryption                        | `--jit-enc=`     | `1`                       |
| String Encryption                     | `--str-enc=`     | `1`                       |
| Overlay encryption                    | `--overlay-enc=` | `1`                       |
| Detect the debug tool                 | `--detect-dbg=`  | `0`                       |
| Name of Obfuscation                   | `--rename=`      | `0`                       |
| Keep the rules of Name of obfuscation | `--keep-rules=`  | `""`                      |

here value setting:

1 means enable/switch on

0 means disable/switch off

> If No overlay data attachment, then ignore the argument: `--overlay-enc` 。

**Name of Obfuscation Options:**

`--rename=0` Off, disable the feature of Name of obfuscation;

`--rename=1` Set the name of Obfuscation to private member

`--rename=2` Reserve/keep the name of self-defined and not obfuscated.

**Keep the Rule of Name of Obfuscation**

Use the semicolon: `;`to separate the functions/methods, support to use wild card `*`

**Sample**

```shell
virboxprotector_con test.dll --pack=0 --jit-enc=1 --str-enc=1 --rename=2 --keep-rules="MyNamespace.MyInterface.*;MyNamespace.ExportForInvoke.*"
```

**Function Protection Option Setting**

Virbox Protector support developer to set the protection option to "fucntions/methods level (with fine grained level protection), To those critical methods/functions, Developer may select and set the protection mode to specified functions, with "Encryption", "Obfuscation", and "Virtualization".

Pls refer the "[Function Protection Option](#5.-function-protection-option)", on default to encrypt the code of entry functions.

**SDK label**

For some special methods and code, Developer may use the "SDK label to label in project code process. when Developer use the Virbox protector to protect the .net project. Virbox Protector will capapible and recognized these code label and protected.&#x20;

For .NET project, Virbox Protector support developer to label the critical functions/methods with 2 protection options: Code Encryption and Code Obfuscation.&#x20;

set the label to the functions code (start and ending), then project compiled and developer use Virbox protector to protect the project. GUI tools will show these functions with protection mode accordingly.

See [SDK label](broken://pages/kNLcvIY35xSERvEpiiBS) section for detail.

SDK sample for .NET project:

`//Name`

`namespace Virbox{`&#x20;

`//Code obfuscation`

&#x20;    `class Mutate : System.Attribute`&#x20;

&#x20;    `{`

&#x20;    `}`&#x20;

`//Code encryption`

&#x20;     `class Encrypt: System.Attribute`

&#x20;    `{`&#x20;

&#x20;    `}`&#x20;

`}`&#x20;

`public class main`&#x20;

`{`

&#x20;     `[Virbox.Mutate]//code obfuscation`

&#x20;     `public static void test1(string[] args)`

&#x20;`{`&#x20;

&#x20;     `System.Console.WriteLine("hello Virbox.Mutate!");`&#x20;

&#x20;     `}`&#x20;

&#x20;     `[Virbox.Encrypt]//Code Encryption`&#x20;

&#x20;     `public static void test2(string[] args)`&#x20;

&#x20;     `{`&#x20;

&#x20;          `System.Console.WriteLine("hello Virbox.Encrypt!");`

&#x20;     `}`&#x20;

&#x20;     `public static void Main(string[] args)`&#x20;

&#x20;     `{`

&#x20;`test1(args);`&#x20;

&#x20;`test2(args);`&#x20;

&#x20;      `}`

`}`

#### Protect Unity3D project

Virbox Protector CLI tool command to protect Unity3D project

`virboxprotector_con <input_path> <options ...> [-o <output_path>]`

<figure><img src="/files/ZXcuwGP45xbTQijzcroB" alt=""><figcaption></figcaption></figure>

| Protection Option                                            | CLI Argument              | On default Argument value |
| ------------------------------------------------------------ | ------------------------- | ------------------------- |
| Memory Check (Valid for il2cpp)                              | `--mem-check=`            | `1`                       |
| File Check （Valid for Android)                               | `--file-check=`           | `1`                       |
| Signature check (Valid for Android)                          | `--sign-check=`           | `0`                       |
| Anti Injection（Valid for Android）                            | `--anti-inject=`          | `1`                       |
| Protect Unity Engine （Valid for Android il2cpp project only） | `--unity-engine-protect=` | `1`                       |
| MetaData, name of Obfuscation（Valid for il2cpp）              | `--metadata-rename=`      | `0`                       |
| Detect debug tool                                            | `--detect-dbg=`           | `1`                       |
| Detect simulator (Valid for Android Only)                    | `--detect-emu=`           | `0`                       |
| Root Detection (Valid for Android only)                      | `--detect-root=`          | `0`                       |
| Parallel detection                                           | `--detect-multi=`         | `0`                       |

#### **Encrypt the assembly**

Use `-asm` to specify assembly list and use semicolon: `;` to separate each assembly, support wild card `*`，On default to encrypt the .dll which prefix by `Assembly-CSharp` and `Assembly-UnityStrcip` and not necessary to specify these assembly accordingly.

Sample:

```shell
-asm "Data/Managed/Assembly-CSharp.dll;Data/Managed/Assembly-CSharp-first.dll"
```

**Resource Encryption**

Use the option: `--res-enc=1` to enable "Resource encryption" to protect resources, ，use the semicolon `;` to be separator between the resource list , wild card `*` supported.

| Protection Option                                                      | CLI Argument           | On default argument Value           |
| ---------------------------------------------------------------------- | ---------------------- | ----------------------------------- |
| Enable                                                                 | `--res-enc=`           | `1`                                 |
| Protection Priority by resources size (valid for android and iOS only) | `--res-favor-size=`    | `0`                                 |
| Set the Password to Resource encryption (Valid for Windows/Linux only) | `--res-pass=`          | N/A                                 |
| Resource list                                                          | `-res <resource_list>` | On default to protect all resource. |

Sample:

```shell
--res-enc=1 -res "file1;file2;assets/file1;assets2/*"
```

#### Protect Java Project

Virbox Protector support developer to protect Java Project with different kind of protection mode:

**Java BCE mode**

**and**

**Java VME mode**

For the difference between these 2 protection mode, pls refer the related section in the Virbox Protector User Manual.

Note: 2 different license required to use these 2 protection mode.

#### **Protect Java project with Java-BCE Protection mode**

Virbxo Protector CLI command to protect Java project (with BCE protection mode)

```shell
virboxprotector_con -java <project_directory> [--java-pass=<password>] [-o <output_directory>]
```

<figure><img src="/files/HnoFCjuGFITVHOgaLx3p" alt=""><figcaption><p>Help info to Java Project with BCE protection mode</p></figcaption></figure>

| Protection Option        | CLI Argument          | On default Argument value/setting |
| ------------------------ | --------------------- | --------------------------------- |
| Set the password         | `--java-pass=`        | Random password                   |
| Encrypt the JAR embedded | `--include-embedded=` | `0`                               |
| Specify the Output path  | `-o <path>`           | xxxx\_protected                   |

Sample:

```shell
virboxprotector_con -java my_java_dir --java-pass=12345 --include-embedded=1 -o my_java_dir_protected
```

After protection successed, you will find 3 new file has been generated in the specified output folder:

1. the new protected jar file
2. ReadMe.txt (which describe how to deploy when execute the protected jar file;
3. `sjt_agent.jar`

#### How to deploy when execute the protected JAR file (ReadMe.text)

There are 2 ways to deployed Jar file when executed

**Option 1:**

Use command line to specify and add `sjt_agent` to JAR, see sample:

`java -javaagent:"D:\test\sjt\sjt_agent.jar" -jar test.jar`

**Option 2**:&#x20;

For "Tomcat" framework or other special framework which profile  can be used to setup option, for example, `setenv.sh`, developer may edit the profile and add `-javaagent` option, for how to edit the profile, pls refer relevant document.

[JAR deployment](https://documentation.virbox.com/fundamentals/cli-tool-user-manual/pages/WGyUwFqsnpyo4vBdZii6#5.1.-jar-deployment)

[WAR deployment](https://documentation.virbox.com/fundamentals/cli-tool-user-manual/pages/WGyUwFqsnpyo4vBdZii6#5.2.-war-deployment)

pls refer related sections in Protect Java Project with GUI tool.

#### **Protect Java project with Java-VME mode**

{% hint style="info" %}
Java-VME support to protect the Java method with "code of Virtualization" only, which is most of secure way to protect the Java method.

There are 3 ways to protect Java project with VME protection mode:

1. Use Virbox Protector GUI to generate the configuration file, and then use Virbox Protector CLI to protect java project;
2. Use Virbox Protector CLI tools to protect Java project directly (go through this way in below section;
3. SDK lable to those critical method, Virbox Protector support developer to set a SDK label to those critical method, then use CLI tool to protect Java Project.
   {% endhint %}

Virbox Protector CLI command to protect Java Project with VME protection mode

`virboxprotector_con <jar_path> <options ...> [-o <output_dir>]`

<figure><img src="/files/2D7RlLwQf6brYsaM7o7q" alt=""><figcaption><p>Help info to protect Java with VME protection mode</p></figcaption></figure>

Sample 1 ( Protect all of methods of "test1" and "test2" with "Virtualization" ):

```shell
virboxprotector_con my_jar.jar -v "com.example.test1.*;com.example.test2.*" -o protected/my_jar.jar
```

Sample 2(Protect all of methods in the JAR archive)：

```shell
virboxprotector_con my_jar.jar -v "*" -o protected/my_jar.jar
```

**SDK label**

For some critical functions/methods, Virbox Protector also support developer to set SDK label to those functions/methods in project coding process. for more detail how to use/set SDK label to these functions/method in coding process, pls refer next chapter.

[pls refer SDK label section](broken://pages/kNLcvIY35xSERvEpiiBS)

#### Protect HTML 5 Project

```shell
virboxprotector_con -h5 <dir_or_file> -o <output_path>
```

<figure><img src="/files/vpfgVwGPZy39gHsiDgHl" alt=""><figcaption></figcaption></figure>

#### Protect Python Project  (Scripting language project)

To protect Python project, or other similar Scripting language project, the protection process consists 2 parts:

1. Protect “python.exe", in this part, Developer may use Virbox protector GUI tool to generate configuration file or use CLI tools to protect the "Python.exe" directly.
2. Protect "py" or "pyc" file, in this section developer use dsprotector\_con to protect py or pyc file.

Here we introduce how to protect the Python project steps by steps

Step 1: Protect "python.exe"

Option 1: Use Virbox Protector CLI to protect python.exe, The protection process pls refer related native protection section above.

Option 2: Use Virbox Protector GUI tool to generate the configuration file which save the "Protection option" setting.&#x20;

Pls following below 2 steps to generate the configuration file to python.exe. kindly remind, to switch on "DS" button and input the password.

save the the configuration file (.ssp file) with the same folder of "py" or "pyc" file.

the configuration file to python.exe is:  `python.exe.ssp`

<figure><img src="/files/2VsNstCQkZav0L8BUX9X" alt=""><figcaption></figcaption></figure>

Step 2: Use DS Protector CLI to protect py or pyc file/pyc file folder.

dsprotector\_con \<filename|directory> -c ssp -o \<filename|directory>

sample:

`dsprotector_con.exe C:\Users\test\Desktop\cmd\python\py.py -c C:\Users\test\Desktop\cmd\python\python.exe.ssp -o C:\Users\test\Desktop\cmd\python\protected\py.py`

Option Description to DSProtector CLI

| Option setting | Description                                                             |
| -------------- | ----------------------------------------------------------------------- |
| filename       | to protect the specific file                                            |
| directory      | to protect the whole directory                                          |
| -c ssp         | use the configuration file which generated by Virbox Protector GUI tool |
| -o output      | output directory for the protected file                                 |

{% hint style="info" %}
Protect pyc file directory, DSProtector supports to protect multiple py/pyc files in same directory. so, specify the directory, all of py/pyc file in the directory will be protected.
{% endhint %}

#### Protect PHP Project

Protect PHP, Lua, or other scripting language project. the protection process is similar to the protection process to Python.&#x20;

in General, there are 2 steps to protect PHP project:

Step 1 Use Virbox Protector CLI tool to protect PHP executive file

Step 2 Use DSProtector CLI tool tool to protect PHP file.

For the detail info, Pls refer the Python Protection process section above.

### 5. Signature Option

#### APK/AAB Signature

| Option                  | CLI Argument      | On default argument value/setting |
| ----------------------- | ----------------- | --------------------------------- |
| Enable the sign         | `--sign=`         | `0`                               |
| Set Key Store Path      | `--ks=`           | Valid for Global Configuration    |
| Set Key Store Password  | `--ks-pass=`      | Valid for Global Configuration    |
| Set the Key alias       | `--ks-key-alias=` | Valid for Global Configuration    |
| Set the Password of Key | `--key-pass=`     | Valid for Global Configuration    |

**Sample**

```shell
virboxprotector_con <file_path> <other_options ...> 
	--sign=1 --ks="test/android.ks" --ks-pass=mypass --ks-key-alias=CERT --key-pass=mykeypass 
	-o <output_path>
```

#### iOS/macOS Signature

| Option           | CLI Argument  | On default argument value/setting |
| ---------------- | ------------- | --------------------------------- |
| enable signature | `--sign=`     | `0`                               |
| Certificate      | `--identity=` | N/A                               |

### 6. Function Protection Option

Virbox Protector supports developer to protect the functions/method level (fine grained protection) and specify the "rule" to protect the critical functions/methods with different kind of protection options: Code of Encryption, Code of obfuscation (Mutation) and Code of Virtualization.

, use the semicolon: `;` to separate functions, support to use wild card: `*`

| Option                                                 | CLI Argument                   | Wild card          |
| ------------------------------------------------------ | ------------------------------ | ------------------ |
| Ignore/skip the function/method not support to protect | `--ignore-unsupported=<value>` | N/A                |
| Code of Encryption                                     | `-e`                           | support to use: \* |
| Code of Obfuscation (Code of mutation)                 | `-m`                           | Support to use: \* |
| Code of Virtualization                                 | `-v`                           | Support to use: \* |

**Sample**

`-m "function1;function2" -v "function3;function4" -e "test*" --ignore-unsupported=1`

> `--ignore-unsupported=`
>
> This option used to skip/ignore those functions which developer select the protection option doesn't support to protect; This option is enable on default when developer protect the following type of applications: **Jar/aar/war/apk/aab**

[**SDK label to some critical functions/methods**](broken://pages/kNLcvIY35xSERvEpiiBS)

Virbox Protector also support to set SDK label in project coding process. for more detail how to use SDK label to label to functions/methods in coding process,  pls refer next chapter.

### 7. Other Options

#### Archive with multiple package

**Protect and use multiple package template to archive package**

```shell
virboxprotector_con <apk_path> <other_options ...> 
	--mulpkg-template=<template_path> --mulpkg-outdir=<multi_package_outdir>
	[-o <output_main_apk_file>]
```

**Archive with multiple package only (no protect)**

```shell
virboxprotector_con -mulpkg <apk_path> --mulpkg-template=<template_path> -o <output_directory>
```

**To specify the signature (optional)**

For all above CLI command options, developer may specify to enable signature, pls refer the related "[Signature Options](#4.-signature-option)" respectively.

#### Merge the assemblies

Use: `-ilmerge` option to merge the assemblies:

```shell
virboxprotector_con -ilmerge <main_assembly> <other_assemblies ...> -o <output_path>
```

**Sample**

```shell
virboxprotector_con -ilmerge Project.exe MyLibrary1.dll MyLibrary2.dll -o Merged/Project.exe
```

#### Remove "Symbol table"

Use `-strip` option to remove the debugging information (Static symbol table & static string table) from ELF application

```shell
virboxprotector_con -strip <file_path> -o <output_path>
```

**Sample**

```shell
virboxprotector_con -strip libhello.so -o striped/libhello.so
```

### **8. Error code for Virbox Protector CLI tool**

<table><thead><tr><th>Error Code</th><th>Description</th><th data-hidden>Description</th><th data-hidden></th></tr></thead><tbody><tr><td>Error（0x00000000)</td><td>Success</td><td>Success</td><td></td></tr><tr><td>Error（0x00000002）</td><td>Memory in sufficient</td><td></td><td></td></tr><tr><td>Error（0x00000003）</td><td>Configuration file error</td><td></td><td></td></tr><tr><td>Error（0x00000011）</td><td>Project has been encrypted</td><td></td><td></td></tr><tr><td>Error（0x00000012）</td><td>Failed to read file, file or file folder not found </td><td></td><td></td></tr><tr><td>Error（0x00000013）</td><td>Failed to write file, file has been occupied or no access right to write file</td><td></td><td></td></tr><tr><td>Error（0x00000021）</td><td>not found .ssp file (configuration file not found)</td><td></td><td></td></tr><tr><td>Error（0x00000022）</td><td>Configuration file error</td><td></td><td></td></tr><tr><td>Error（0x00000023）</td><td>missing the configuration file to ds plugin in the .ssp file (configuration file) or ds node in the .ssp file has been deleted.</td><td></td><td></td></tr><tr><td>Error（0x00000024）</td><td>ds plug in the .ssp file not activate (which means ds button not been switch on</td><td></td><td></td></tr><tr><td>Error（0x00000025）</td><td>password node for the ds plug in in the .ssp file missing. which means no password input or password node has been deleted.</td><td></td><td></td></tr><tr><td>Error（0x00000031）</td><td>file size too small (less 4 bytes)</td><td></td><td></td></tr></tbody></table>


# Set the SDK label (Annotation) to protect the specified Functions/Code/String

In project coding, SDK label API used to mark the specified functions/code/string before compile, when Developer use Virbox Protector to protect app. Virbox will recognize & protect the label function

## Introduction

The Virbox Protector tool’s SDK Label (annotation) are statically embedded into the Class, functions, Methods/Algorithm  that need to be recognized and protected. After generating the executable program, the Virbox Protector can parse the program and identify the SDK‑marked (annotation) functions in its interface. This helps users quickly locate the core code that requires protection.

SDK Label API, String Encryption

&#x20;Virbox Protector provides SDK label API which can be used by developer to set the label to identify in project coding process, Virbox provides different kind of API (Label) to set the label to protect these critical function, method, algorithm, sensitive code section or string, license key/data, or other critical string with multiple protection option: Obfuscation (Mutation), Virtualization etc.&#x20;

In this section, we introduce how to use Virbox SDK label API to set label in project coding process, sample provided. Developer also can find more sample case, head file in the installation directory in the Virbox Protector.

{% hint style="info" %}
Pls note, For the protection feature which SDK labeled, it will only for developer to set the label  to each critical "Function, algorithm or String" with specified protection option: Obfuscation, Virtualization or other option. The protection to the specified function/method/algorithm/string will be effective/valid only when developer use "Virbox Protector" to protect it.&#x20;
{% endhint %}

## How to use SDK Label in Project coding

## Introduction

Virbox Protector supports developer to protect software application to against static attack and dynamic attack.

Besides to general protection option setting to application, Virbox Protector supports developer to protect software application to functions/methods level (with most fine grained protection) by select function name and set a label to those critical and important function, methods or code section.

Developer will has 2 ways to set the protection option to these critical functions/method/String/code section:

1. Use Virbox Protector GUI tool to set protection option in "Function Option" tab: Click & Select;
2. For those function/methods/string/algorithm or code section which is critical, Developer may also use the Virbox Protector SDK label API to mark it during coding process. then when the project has been compiled into executive or dll libs, or drag the application into the Virbox GUI tool or use Virbox Protector CLI to protect it. Virbox Protector will parse and automatically recognize these label set to these functions/method/critical code section and protect them with the protection option set by SDK label.

In general, Developer may use the Virbox SDK label API (provided by Virbox Protector) to mark to those function/methods or the code section (for example: license key data, critical string etc) which need to be protected, then developer build and compile the code and generate a executive application;&#x20;

When Developer use Virbox Protector to parse the applications with these labels, Virbox Protector will capable to parse the application and recognize those function/method or code section has been marked. it will help developer to find these critical code location. and protect these functions, string with protection option set accordingly.

**Support coding language:**

C\C++\C#\OC\swift\Java

## System Environment & Prerequisites

1. Install Virbox Protector into your machine;
2. After installation, you will find the Head file,  Static API, Dynamic API which SDK label's required in following directory:

Head file:

`C:\Program Files\senseshield\Virbox Protector 3\sdk\inc\virbox.h`

Static API and lib:

`C:\Program Files\senseshield\Virbox Protector 3\sdk\lib`

Dynamic API and lib:

```
The path in windows：C:\Program Files\senseshield\Virbox Protector 3\sdk\windows\x86
The path in Linux：C:\Program Files\senseshield\Virbox Protector 3\sdk\linux，includes armand x86 architecture
The path in macOS：C:\Program Files\senseshield\Virbox Protector 3\sdk\darwin，includes arm and x86 architecture
The path Android：C:\Program Files\senseshield\Virbox Protector 3\sdk\android，includes arm and x86 architecture
```

3. Demo case, developer may find demo case in below directory:

```
The path of demo：C:\Program Files\senseshield\Virbox Protector 3\example\sdk
```

## Application supported by use of SDK Label API

### Use SDK label API to Native application

The Native application means the executive file or dynamic linked library which compiled in Windows, Linux, ARM Linux, Android and macOS environment.

After you installed the Virbox Protector to your machine, you will find the "head file" which contain the SDK label APIs:

`C:\Program Files\senseshield\Virbox Protector 3\sdk\inc\virbox.h`

The sample case to SDL label API can be found:

`C:\Program Files\senseshield\Virbox Protector 3\example\sdk`

```
Note:
If developer set 2 kinds of SDK Label API by sequence in same code section, 
then only last Label API will be valid, and the first Label API will NOT be effective.
Every SDK lable API must be used in pairs, includes "Start" and "End", if used the
"Start" only and not find the "end" API, when Virbox Developer GUI tool parse the 
compiled program, the code section with single SDK label API （no "end" API）will be 
recorded in the log file.
```

#### **Set SDK Label API to mark and protect the "functions"**

Developer may use SDK Label API to set a Label to: obfuscate/virtualize those critical function/methods in the applications, include the entry instruction which generated after compiled. Following SDK Label API can be used:

`VBMutateFunction`

Purpose: To obfuscate present function/method

`VBVirtualizeFunction`

Purpose: To Virtualize present function/method

Sample:

```c
int add(int x, int y)
{
    int ret = 0;
    VBMutateFunction("add#");
    ret = x + y;
    printf("x+y=%d\n", ret);
    return ret;
}

int sub(int x, int y)
{
    int ret = 0;
    VBVirtualizeFunction("sub#");
    ret = x - y;
    printf("x-y=%d\n", ret);
    return ret;
}
```

#### **Set SDK Label API to mark and protect the "Code Section"**

the SDK label can be used to set label for "Code Section" include a pair of label,&#x20;

`Begin&end`, which can be use to set the label to the code section in the function, which means only protect the code in between "Begin" and "End"

**Label to set for "Begin"**

`VBProtectBegin` : Which means the "Code of Virtualization" start here;

`VBVirtualizeBegin` Which means the "Code of Virtualization" start here; (same as:`VBProtectBegin)`

`VBMutateBegin` : Which means "Code of Obfuscation" start here.

`VBSnippetBegin`: Which means "Code of snippet start, this feature only valid for Virbox Protector LM (PRO), not applied for Virbox Protector Standalone.

**Label to set for "End"**

`VBProtectEnd` : means code protection end , which used in pair with "Begin" label

Sample:

```c
int foo(int x)
{
    if (x == 0)
    {
        VBVirtualizeBegin("foo_1#");
        // do something...
        VBProtectEnd();
    }
    else
    {
        VBMutateBegin("foo_2");
        // do something...
        VBProtectEnd();
    }
    return 0;
}
```

#### **Attention & Remark**

1. SDK label API applied for static lib (virbox\_windows.lib) and dynamic lib&#x20;

   （virbox32.dll and virbox64.dll), developer may use both when protect your project.&#x20;

<pre><code><strong>Note
</strong><strong>1. Virbox SDK label Dynamic lib only can be load with static and can not be loaded 
</strong><strong>with dynamic(which means doesn't support with: LoadLibrary). The reason is because of 
</strong><strong>when use SDK label to protect the function, it parse and protect the calling SDK API 
</strong><strong>in static, so, it doesn't support to loadlibrary way to load. 
</strong><strong>2. The static library can be link to your project directly.
</strong></code></pre>

2. When developer call Virbox SDK label (virbox\_windows.lib) with statically,  For the String parameter imported by: `VBProtectBegin`, `VBVirtualizeBegin`, `VBSnippetBegin`, `VBMutateBegin` it can't be shared with other functions.
3. Make sure the imported string parameter to be the ASCII code, then the correct function's name will be shown and displayed correctly when Virbox Protector GUI tool parsing, otherwise it will show messy code and unreadable.
4. Every `begin` must be follow and match with `end`, use the `begin` and `end` in pair used, and only one pair is allowed to mark for one function only.
5. If the protection option set by the label inconsistent with the protection mode saved in the project configuration file (.ssp file), the system will use the protection option saved in the project configuration file.
6. The code in between the `Begin` and `End` is better to more than 3 lines. which to make sure the protected code will be shown in the GUI of Virbox Protector. (it will Not be shown in the GUI of Virbox Protector for the instruction less 15 bytes)
7. SDK Label API provides 32bit and 64bit dll libs, you do need to use these libs accordingly.

#### **Use Virbox SDK label API to protect Critical Strings: String Encryption & Decryption**

Besides of to use Virbox SDK Label to set mark "functions", "method" with specified "protection" modes (Virtualization, Obfuscation) to protect those "functions", Developer may use SDK Label API to set label to encrypt these Critical string or data in the applications, following SDK Label API can be used:

**1. API for String Encryption**

**VBProtectDecrypt**

`void *VB_API_CALL VBProtectDecrypt(void *dst, const void *src, int size);`

Protection Mode Setting:

**String encryption**, it is recommend to use this label only for Virbox Protector LM (Pro), not use in Virbox Protector Standalone. with this Label, AES 256 encryption algorithm used to encrypt data.

When application executed, the encrypted string will be kept in the caller memory and it will Not be released.

Sample：

```c
int test_decrypt()
{
	char buf[1024];
#define ENCRYPTED_DATA  "this is decrypted data,please...testing passing"
	puts(__FUNCTION__);

	VBProtectDecrypt(buf, ENCRYPTED_DATA, sizeof(ENCRYPTED_DATA));
	puts(buf);
	return strcmp(buf, ENCRYPTED_DATA);
}
```

Note: The buffer size of encrypted string must be a multiple of 16;

**2. API For String Encryption**

**VBDecryptData**

`const void* VB_API_CALL VBDecryptData(const void *data, int size);`

Protection mode setting:

String Encryption, usually, Developer may use this API to encrypt the key data (such as private key data), and the data and length must be a constant value, when use this label to protect the data, use random key to encrypt the data, when application executed, the encrypted data kept in the heap memory.

This API can be used together with the API "`VBFreeData`", the purpose to use “`VBFreeData`” is to release the Heap memory which to prevent the debug tool find the string in the heap.

Sample:

```c
int test_encrypt_key()
{
	static const unsigned char g_key[] = { 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10 };
	unsigned char* key = VBDecryptData(g_key, sizeof(g_key));
	for (int i = 0; i != sizeof(g_key); ++i)
	{
		printf("%02x ", key[i]);
	}
	printf("\n");
	return 0;
}
```

**3. API for String Encryption:**

**VBDecryptStringA**

`#define VBDecryptStringA(_X_) ((char*)VBDecryptData(_X_, sizeof(_X_)))`

Protection mode setting:&#x20;

Refers to Standard String encryption, which can be used as long as it is static variable or a global variable, and the encrypted string must be a constant.&#x20;

`VBDecryptStringA` is the encapsulation of `VBDecryptData`, and you only need to use `VBDecryptStringA` when using it.

**Developer may combine use this API with the** `VBFreeString` to release the heap memory, to prevent the debug tool to search the string in the heap memory accordingly.

Sample：

1）To encrypt the string directly

```c
VBDecryptStringA("test_string");
```

2）Local Static variable

```c
static char g_string[] = "test_string";
static const char g_string[] = "test_string";
```

3）Global variable：

```c
char g_test_string[] = "test_string";
const char g_test_string[] = "test_string";
```

4）If the program to be encrypted is too complicated and the data to be encrypted can’t be parsed, it will report error when you use Virbox Protector to protect the software, it is recommended to make the program less complicate. Usually it mostly happened to the Linux program in 32 bits which compiled with –fpic or –fpie with O2.

5）The compiler may merge or combine the multiple and same constant strings to be one string, if only one of these string is encrypted, an error would be reported:

Sample：

```c
const char* a = "test_string"; 
const char* b = VBDecryptStringA("test_string");
printf("a = %s, b = %s\n", a, b);
```

In this sample case, messy code would be shown when you print string “a”.

**4. API to wide string encryption (`wchar_t`)**

**VBDecryptStringW**

`#define VBDecryptStringW(_X_) ((wchar_t*)VBDecryptData(_X_, sizeof(_X_)))`

Protection mode Setting:&#x20;

Refers to wide string (`wchar_t`) encryption, as long as it is a static variable or a global variable can use wide string encryption

it can be used and the encrypted string must be a constant. `VBDecryptStringW` is the encapsulation of `VBDecryptData`, and you only need to use `VBDecryptStringW` when using it.

Sample：

```c
VBDecryptStringW(L"test_string");
```

**Developer may combine use with the API** `VBFreeString` to release the heap memory, to prevent the debug tool to search the string in the heap memory accordingly.

**5. API to release heap memory**

**VBFreeData**

`void VB_API_CALL VBFreeData(const void *data);`

​ `#define VBFreeString(_X_) VBFreeData(_X_)`

Protection mode setting:

`VBFreeData` will release the heap memory only, because, when developer use `VBDecryptData to decrypt data`. If the heap memory is not released in time, the decrypted string can be seen/leaked through dynamic debugging with tools such as OD\ida;

`VBFreeString` is a basic encapsulation to `VBFreeData`. Use the `VBFreeString` macro to pass the string pointer to the `VBFreeData` function to release the corresponding memory space. You only need to use `VBFreeString` when using it.

```c
static char g_string[] = "test_string";
VBFreeString(g_string);
```

#### To convenient Developer calling, Virbox Protector also provides API for data decryption without requied to release. When developer require to use the "string" to decrypt. use these API to decrypt to heap memory and it will released when module uninstalled.

**VBDecryptDataOnce**

Similar use to **VBDecryptData** , without need to release (free);

**VBDecryptStringOnceA**

Similar use to **VBDecryptStringA** , without need to release (free);

**VBDecryptStringOnceW**

Similar use to **VBDecryptStringW** , without need to release (free);

**API to quit execution**

**`VBSafeExit`**

When application detect the malicious behavior, when developer call: `exit`, or `abort` to quit execution, it is easier to be traced by the attacker and bypassed. so, Developer can use this API:

**VBSafeExit**

quit execution, with this label, it will destroy the frame, stack called or address returned, which make difficult to attacker to allocate the calling position.

#### Use Virbox SDK Label API to set "General Protection Option" to application

1. API for Memory integrity

**VBProtectVerifyImage**

`void VB_API_CALL VBProtectVerifyImage();`

Protection mode: **quit execution automatically**

User this API to verify the memory integrity, memory check, to detect if application has been tampered (include static patch and dynamic patch), when tampering has been detected, then the protected application will be **quit execution automatically**;

Sample:

`void timeit(void (*f)()) {`

&#x20;  `VBProtectVerifyImage();//detect & verify memory integrity`

&#x20;  `clock_t start = clock();`&#x20;

&#x20;  `f();`&#x20;

&#x20;  `cout << double(clock() - start) / CLOCKS_PER_SEC <<"second" << endl;`

`}`

2. API for for Memory Integrity (return with non zero value)

`int VB_API_CALL VBVerifyImage(void);`

Protection mode: **return with non zero value**

User this API to verify the memory integrity, memory check, if memory integrity verification failed, then it will **return with non zero value**;

Usage:&#x20;

When the compiled application (contained this API) has been protected by Virbox Protector, if detected memory has been modified,  the protected application will returned with non zero value, and no impact to application execution.&#x20;

if developer use: `VBSafeExit`, then the application will quit.

Sample:

```
void timeit(void (*f)()) {
	int ret = 0;
	ret = VBVerifyImage();// detect memory integrity
	cout << "ret value:" << ret << endl;

	if (ret != 0)
		VBSafeExit(ret);//when memoery is being detected modification, then application will quit execution；
    
	clock_t start = clock();
	f();
	cout << double(clock() - start) / CLOCKS_PER_SEC <<"秒" << endl;
}
```

3. API to detect debug tools

**VBDetectDebugger**

`int VB_API_CALL VBDetectDebugger(void);`

Protection mode: **Returned with non zero value**

Use this API to detect if your application whether or not to be debugged by debug tools, when detected, then it will returned with non zero value;

Usage:&#x20;

When the compiled application (contained this API) has been protected by Virbox Protector, if detected memory has been modified,  the protected application will returned with non zero value, and no impact to application execution.  If call `VBSafeExit`  , then application will quit execution,

Sample:

```
void timeit(void (*f)()) {
	int ret = 0;
	ret = VBDetectDebugger();// detect debug tools
	cout << "ret的值:" << ret << endl;

	if (ret != 0)
		VBSafeExit(ret);//when debug tools detected, then quit excution
    
	clock_t start = clock();
	f();
	cout << double(clock() - start) / CLOCKS_PER_SEC <<"秒" << endl;
}
```

4. API to detect the VM

**VBDetectVirtualMachine**

`int VB_API_CALL VBDetectVirtualMachine(void);`

Purpose:

To detect if the application execution environment is VM environment (VMWare, Virtual Box etc.) or not;&#x20;

When VM environment detected, then return with non zero value (Valid for windows only)

Usage:

When the compiled application (contained this API) has been protected by Virbox Protector, if VM environment has been detected ,  the protected application will returned with non zero value, and no impact to application execution.

Sample:

```
int check()
{
    // For those functions to detect VM, it is better to enhance security to 
    // set label with Obfuscation or Virutualization label
    VBMutateFunction("check#");
    int code = 0;
    if (VBVerifyImage() != 0)
    {
        // memory patches found!
        code = 1;
    }
    
    if (VBDetectDebugger() != 0)
    {
        // debugger found!
        code |= 2;
    }
    
    if (VBDetectVirtualMachine() != 0)
    {
        // vm tools found!
        code |= 4;
    }
    
    if (code != 0)
    {
        // crash
        VBSafeEixt(0xdead0000 | code);
    }
    
    return 0;
}
```

5. API to detect Hooking

`int VB_API_CALL VBDetectHook(const void* func);`

To Checks whether the program’s function address has been hooked. If a hook is detected, the interface returns a non‑zero value. This detection can be used in conjunction with the `VBSafeExit` tag to enforce secure termination behavior.

Supported Platforms

| System                           | Language(s)                   | Result    |
| -------------------------------- | ----------------------------- | --------- |
| Windows (x86, x64, arm64)        | C / C++                       | Supported |
| Linux (x86, x64)                 | C / C++                       | Supported |
| Arm Linux (arm32, arm64)         | C / C++                       | Supported |
| Android (x86, x64, arm32, arm64) | C / C++                       | Supported |
| macOS (x64, arm64)               | C / C++ / Objective‑C / Swift | Supported |

5. API to quit application execution and clear current stack frame

`void VB_API_CALL VBSafeExit(int code);`

Protection

Quit application execution&#x20;

Usage:

Call this API and combine use with following API:

`VBVerifyImage`

`VBDetectDebugger`

`VBDetectVirtualMachine`

When use this API directly, then the application protected by Virbox Protector will stop execution directly.&#x20;

### Use SDK Label API in macOS/iOS applications

The SDK Label API used in the macOS environment and the SDK label used in the native is same API.&#x20;

When compile the project, Xcode can call dynamic library (.dylib) or static library (.a or framework), the function to all of above 3 library are same. developer may free select one of library to call.

The only different thing is, it is necessary to make a configuration to Xcode when compiling the project. Here we brief the process for OC and Swift when using the SDK label.

**1. OC Language**

1）Frist step is add `virbox.h` into the project, use the Xcode to open the project, and add the `virbox.h` into the project;

2）Select the `TARGETS->Build Settings->Architectures`, to view and check the project's Architecture: ARM64 or FAT format. see screenshot below:

<figure><img src="/files/DvfYD7QXhQQzAxP8CbER" alt=""><figcaption></figcaption></figure>

3）Add the related and corresponding the `libvirbox64.dylib` from the installation directory of Virbox Protector: `sdk/darwin`, and select the option from: `TARGETS->Build Phases->Link Binary`, to add the `libvirbox64.dylib`

4）Import the `virbox.h` in your code project and add the SDK label API

Code sample as shown as below：

<figure><img src="/files/s4sKTM7CbTpEwdme50KY" alt=""><figcaption></figcaption></figure>

```objective-c
#import "virbox.h"
-(void)readLoad
{
    //you may use to import other SDK label API also
    VBMutateBegin("load_test"); //Code of Obfuscation
    for (int i=0; i<array.count; i++) {
        News * news=[[News alloc]init];
        news.content=array[i];
        [_newsArray addObject:news];
    }
    VBProtectEnd();
    return NO;
}

- (BOOL)isImageSetFolder:(NSString *)folder
{
    //you may use to import other SDK label API also
    VBVirtualizeFunction("reset_test"); //Code of Virtualization
    if ([folder hasSuffix:kSuffixImageSet]
        || [folder hasSuffix:kSuffixAppIcon]
        || [folder hasSuffix:kSuffixLaunchImage]) {
        return YES;
    }
    return NO;
}
```

**2.Swift language**

1）Add `virbox.h` into your project, Use Xcode to open the proejct and add `virbox.h` into the project, and set the `virbox.h` to be bridging file;

TARGETS->Build Settings->Swift Compiler->Object-C Bridging Header->Project name/virbox.h

<figure><img src="/files/cTx5B19DX9eFHqFdZ0QG" alt=""><figcaption></figcaption></figure>

2）Check the Project's Architecture: Select the `TARGETS->Build Settings->Architectures`, to view the project's Architecture: ARM64 or FAT format. see screenshot below:

<figure><img src="/files/ejIK1FowbSBH6TO3Bua1" alt=""><figcaption></figcaption></figure>

3）Find and Add the related and corresponding the `libvirbox64.dylib` from the installation director of Virbox Protector: `sdk/darwin`, and select the option from: `TARGETS->Build Phases->Link Binary`, to add the `libvirbox64.dylib`

<figure><img src="/files/cMx4i69IGgkMJCXINESC" alt=""><figcaption></figcaption></figure>

4）Add the SDK label API in the code directly. and add the variable name to SDK Lael API is also required.

Code Sample：

```swift
struct ContentView: View {
    var body: some View {
        //you may use to import other SDK label API also
        var body_begin = VBMutateBegin("body_test")// Code of Obfuscation
            
        let columns = [
        GridItem(.flexible()),
        GridItem(.flexible()),
        GridItem(.flexible()),
        GridItem(.flexible())]
        var body_end = VBProtectEnd()// code end
    }
}

struct RdioApp: App {
    var body: some Scene {
        //you may use to import other SDK label API also
        var myva = VBVirtualizeFunction("test") //Code of Virtualization
        HStack(spacing: 24) {
                Image(systemName: "backward.fill")
                    .font(.title3)
                Image(systemName: "play.fill")
                    .font(.title)
                Image(systemName: "forward.fill")
                    .font(.title3)
            }
    }
}
```

**3. Execute the application**

1）After compiling completed, the application execution require to dependent to the `libvirbox64.dylib` , means you need to copy the `libvirbox64.dylib` which corresponding to the application architecture to `/usr/local/lib/libvirbox64.dylib`, and then to execute the compiled application.

If not copied the `libvirbox64.dylib` , the following error will be reported

<figure><img src="/files/4H9mT6YVO0ekzXJJH87V" alt=""><figcaption></figcaption></figure>

**Note:**

For the `libvirbox64.dylib`in ARM architecture and FAT format, it is necessary to sign first and then copy `libvirbox64.dylib` later,

2）Drag the compiled application into Virbox Protector GUI tool, then you can find the functions/method which marked by SDK label API in the "Function Option" tab;

Then, Protect your project, the protected application can executed and without dependent on the`libvirbox64.dylib`

<figure><img src="/files/b745G4nlXom9fTiXMreW" alt=""><figcaption></figcaption></figure>

#### Use SDK Label API to .NET applications

To use and add the SDK label API into the .NET application, it is support following protection option to be set and protect the functions/methods:

Code of Encryption,

Code of Obfuscation.

Code of Virtualization.

To add the SDK label API in the project, it is consistent with Microsoft syntax, and when .NET project compiled completed. drag the the .NET application into the Virbox Protector GUI tools, then The protection option marked by SDK label API will be displayed in the "Function Option" tab.

Sample Code：

`C:\Program Files\senseshield\Virbox Protector 3\example\sdk\dotnet_sdk_demo`

Sample syntax：

```c#
// name
[Obfuscation(Feature = "Rename", Exclude = false)]//Code of Obfuscation
public class main
{
    [Obfuscation(Feature = "Mutate", Exclude = false)]//Code of Obfuscation
    public static void test1(string[] args)
    {
        System.Console.WriteLine("hello Virbox.Mutate!");
    }
    [Obfuscation(Feature = "Encrypt", Exclude = false)]//Code of Encryption
    public static void test2(string[] args)
    {
        System.Console.WriteLine("hello Virbox.Encrypt!");
    }
    [Obfuscation(Feature = "Virtualization", Exclude = false)]//Code of Obfuscation
    public static void test3(string[] args)
    {
        System.Console.WriteLine("hello Virbox.Virtualize!");
    }
}
```

**Note：**

1. SDK Label API can be added before the class name, and if SDK label also has been set to methods, then the SDK label set to methods will be displayed first.
2. The SDK label marked to Function and "Name of obfuscation" can Not be added into the code directly, it only can be added in front of class name and method names.

#### Use SDK label API to Java Applications

For Java Project, Virbox Protector support to use SDK label API with "Code of Virtualization", add the annotation `VBVirtualize` in the Java code, and import it in the methods, when Java project compiled completed, drag the compiled Java project into Virbox Protector GUI tools, then Virbox Protector will display the protection option set to function/method by SDK label API.

`Note: the filename must be the VBVirtualize, and the package name must virbox, otherwise the Virbox Protector will not recognized the SDK label marked.`

1. Create `VBVirtualize.java`, the content shown as below

```java
package virbox;

public @interface VBVirtualize
{
}
```

2. How to import

```java
import virbox.VBVirtualize;

@VBVirtualize // Add it before the class, then all of methods will be protected on default.
public class Main {
    public static void main(String[] args) {
        System.out.println("hello");
        test_vir();
    }

	@VBVirtualize // Add it before the methods, protect this method only
	public static void test_vir()
	{
	    System.out.println("test_vir");
	}

}
```

#### Use SDK Label API in Android applications

**Add SDK Label (Annotation) to Class/methods**

Overview

The `@VBVirtualize` annotation can be applied to classes or methods. It serves as a marker to facilitate recognition after compilation and may affect how names are preserved when ProGuard obfuscation is enabled.

Applicable Scenario

When classes and methods are marked/label with the virtualization annotation (SDK label), the compiled Android APK/AAB application can be imported into the Virbox Protector interface for parsing. By default, the labeled classes (with SDK label) and methods will be displayed.

* **With ProGuard obfuscation enabled**: Function/Method names cannot be determined after obfuscation. However, if classes and methods are marked with the virtualization annotation (SDK label), there is no need to manually locate the corresponding class and method names during application protection.
* **Without ProGuard obfuscation**: Annotated classes and methods will still be displayed by default in the Virbox Protector.

SDK Label (Annotation) Interface Location:

`C:\Program Files\senseshield\Virbox Protector 3\example\sdk\APK\com\virbox\VBVirtualize.java`

#### Notes

1. If ProGuard obfuscation is enabled during compilation of the Android APK/AAB application, some functions may be optimized, which can cause annotated functions to not be parsed correctly.
2. The file name must be **VBVirtualize** and the package name must be **com.virbox**; otherwise, the annotation will not be recognized by the protection tool.
3. The compiled program must be protected using the Virbox Protector tool for the annotation functionality to take effect.

**Protection Process**

1. **Open the Android Project and create a new directory, name with "virbox"**

<figure><img src="/files/tq5nEvhZNbSgl2rzpCGn" alt=""><figcaption></figcaption></figure>

2. **Create >Java Class:**

<figure><img src="/files/nUMWLReEzqPJGb1qR8BL" alt=""><figcaption></figcaption></figure>

3. **Select >Interface and name as: VBVirtualize;**

<figure><img src="/files/Cs2MMkgEONzFSBIGkniU" alt=""><figcaption></figcaption></figure>

4. **Copy the** VBVirtualize.java **and Add the following code in the "VBVirtualize.class":**

```java
package virbox;
import androidx.annotation.Keep;
import java.lang.annotation.Retention;
import java.lang.annotation.RetentionPolicy;

@Keep
@Retention(RetentionPolicy.RUNTIME)
public @interface VBVirtualize {
}
```

5. **Invoke `VBVirtualize` on other class:**

When @VBVirtualize is applied to a class:

* If ProGuard obfuscation is enabled, applying @VBVirtualize to a class will mark that class and preserve its name. The names of other classes will not be preserved.
* If ProGuard obfuscation is not used, applying @VBVirtualize to a class will simply mark that class.

```java
import virbox.VBVirtualize;

@VBVirtualize
public class SecondFragment{
    @Override 
    public View onCreateView(LayoutInflater inflater, ViewGroup container, Bundle savedInstanceState) {
        FragmentSecondBinding inflate = FragmentSecondBinding.inflate(inflater, container, false);
        this.binding = inflate;
        return inflate.getRoot();
    }
    public void onDestroyView() {
        super.onDestroyView();
        this.binding = null;
    }
}
```

When @VBVirtualize is applied to a method:

* If ProGuard obfuscation is enabled, applying @VBVirtualize to a method will mark that method and preserve its name. The names of other methods will not be preserved.
* If ProGuard obfuscation is not used, applying @VBVirtualize to a method will simply mark that method.

```java
import virbox.VBVirtualize;

public class SecondFragment{
    @Override 
    public View onCreateView(LayoutInflater inflater, ViewGroup container, Bundle savedInstanceState) {
        FragmentSecondBinding inflate = FragmentSecondBinding.inflate(inflater, container, false);
        this.binding = inflate;
        return inflate.getRoot();
    }
    @VBVirtualize
    public void onDestroyView() {
        super.onDestroyView();
        this.binding = null;
    }
}
```

### Add SDK Label (Annotation) to enable specify protection option

**Applicable Scenarios**

When an Android APK/AAB application invokes the specified interface, the program may trigger certain behaviors at runtime and return a non-zero value. This return value can then be used to determine the subsequent runtime behavior of the application.

For example, when the `VBDetectRoot` interface is called, if the program is running on a rooted device, it will return a non-zero value. By checking this return value, the application can decide whether to crash immediately or display a warning message.

**SDK label (Annotation) Interface Location**

```
 C:\Program Files\senseshield\Virbox Protector 3\example\sdk\APK\com\virbox\Protector.java 
```

### <sup><sub>Notes<sub></sup>

1. <sub>The file name must be</sub> <sub></sub><sub>**Protector**</sub> <sub></sub><sub>and the package name must be</sub> <sub></sub><sub>**com.virbox**</sub><sub>; otherwise, the annotation will not be recognized by the protection tool.</sub>
2. <sub>The compiled program must be protected using the Virbox Protector tool for the annotation functionality to take effect.</sub>

**Operation Procedure**

1. Open the Android project and create a new directory named **virbox**.

<figure><img src="/files/rc8GEzioaX4pc3EyUjv9" alt=""><figcaption></figcaption></figure>

2.Copy the **Protector.java** file into the `com\virbox` directory. The code in **Protector.java** is as follows:

package com.virbox;

```
package com.virbox;

   public class Protector {
       // Debugger detection
       public static int VBDetectDebugger()    { return 0; }

   // Emulator detection
   public static int VBDetectEmulator()    { return 0; }

   // Root detection
   public static int VBDetectRoot()        { return 0; }

   // Anti-injection detection
   public static int VBDetectInject()      { return 0; }

   // Multiple-instance detection
   public static int VBDetectMulti()       { return 0; }

   // Proxy detection
   public static int VBDetectProxy()       { return 0; }

   // VPN detection
   public static int VBDetectVPN()         { return 0; }

   // File integrity and memory integrity check
   public static int VBIntegrityCheck()    { return 0; }

   }
```

3. Call the interfaces inside **Protector.java**. A sample code reference is as follows:

```
import com.virbox.Protector;

public class SecondActivity extends AppCompatActivity {
    @SuppressLint("SetTextI18n")
    @Override
    protected void onCreate(Bundle savedInstanceState) {
        super.onCreate(savedInstanceState);
        setContentView(R.layout.activity_second);

​    // VPN detection
​    int vpn_result = Protector.VBDetectVPN();
​    TextView testView1 = findViewById(R.id.testView1);
​    testView1.setText("Return value of VPN detection: " + vpn_result);

​    // Emulator detection
​    int emulator_result = Protector.VBDetectEmulator();
​    TextView testView2 = findViewById(R.id.testView2);
​    testView2.setText("Return value of emulator detection: " + emulator_result);

​    // Call other annotations, e.g., integrity check
​    int check_result = Protector.VBIntegrityCheck();
​    TextView testView8 = findViewById(R.id.testView8);
​    testView8.setText("Return value of file and signature integrity check: " + check_result);
​	}

}
```

4\. Protect the Compiled Application

After compiling the Android APK/AAB application, use the **Virbox Protector** tool to apply protection. When the program triggers certain behaviors at runtime, the corresponding interface will return a non-zero value

{% hint style="info" %}

#### Notes

* **For APK**:
  * When the file integrity check is triggered, the return value is **1**.
  * When the signature check is triggered, the return value is **2**.
  * When both file integrity and signature checks are triggered simultaneously, the return value is **1**.
* **For AAB**:
  * AAB does not support signature checking, so the return value will always be **0**.
  * When the file integrity check is triggered, the return value is **1**.
    {% endhint %}

#### All sample to call SDK Label API can be found in the Virbox Protector installation directory

```
C:\Program Files\senseshield\Virbox Protector 3\example\sdk\C
```

All Head file for SDK Label API can be found in the Virbox Protector installation directory

```
C:\Program Files\senseshield\Virbox Protector 3\sdk\inc\virbox.h
```

### FAQ

1. Q: For SDK Label API, map and pdb file, which one will be the first priority when Virbox Protector to protect the application?

   A: SDK Label API will be the first priority when Virbox Protector parse and protect the Application in protection process;
2. Q: Will Virbox SDK label also support to be set and used to the ARX file (the compiled file is ARX)

   A: Yes, Virbox SDK label support to set the SDK label to compiled to arx file.
3. Q: Does global variables can be protected by SDK Label?

   A: Yes, Global variable can be set and protected by `VBDecryptStringA`, for PE, elf and machO application.
4. Q: `begin` `end` is the function body that only processes the current function. If function A calls function B, and function B uses the SDK label, then function A can also use the SDK label again. does this case means nested?

   A: No, It is not the nested case;
5. Q: In a c++ program, after protecting the the sdk label by using String Encryption, can it be seen using the OD debugger?

   A: It can be found and seen in the heap memory using OD. You can call `VBFreeString(xxx)` to release it after each use, and it will no longer be found in the heap memory.
6. Q: For C# program, By using String Encryption, does it can prevent strings from being dumped from memory? Can the OllyDbg see it?

   A: It cannot prevent the string from being dumped from the memory. But the OllyDbg cannot scan the memory directly. only If you find the place where the string is actually used and break point, then you can see the sting encrypted.


# Other Useful tool

Virbox Protector provides both GUI and CLI tool to developer to protect application in post protection and build in process. besides of GUI and CLI tools, Virbox Protector also provides several useful tools to developer to use in convinent and easy way. such as DSProtector, Windows Virtual Folder tools. etc.


# User Guide: Windows Virtual Folder

## Overview

**Virbox Protector** integrate several tools for software developer to use in conveniently, besides of the functionality of code protection and hardening and app shielding.

**Windows Virtual Folder** tools is the packing/archiving tools provides to developer to pack/archive a project **with encryption functionality.**

With the **Windows Virtual Folder** tools, developer may pack/archive all type of project file into one windows exe file, includes but not limited the dynamic link library (dll), video file (MP4), text file (txt) or other type of file. and then when software user only require to execute the packed execution file. which is much easier and convenient for both developer and software user.

Except project exe and dll file, all of project file **will be encrypted** when use the **Windows Virtual Folder** packed/archived.

**Note:**

> Developer use Virbox Protector to protect main program (executable file, dll) and then use the **"Windows Virtual Folder"** tool to pack all of file/folder into one exe file.

## Support System

### Packing Project Folder Support

| Type                         | System             | Support or Not |
| ---------------------------- | ------------------ | -------------- |
| PE project folder            | Windows 7 or above | Yes            |
| .NET project folder          | Windows 7 or above | Yes            |
| Other type of project folder | N/A                | No             |

### Feature

1. With **Windows Virtual Folder** tools, it will bring much convenient to developer when developer complete app shielding & code hardening process. Software user only required to execute the packed exe file and then all of function available and active.
2. High **Compatible**: Except project exe and dll file, all of other type of project file **will be encrypted** when use the Windows Virtual Folder packed/archived into one exe file: such as, .ini, .txt, .config, .xml etc.,
3. The execution **performance** of project will not be negative impacted.

**Note:**

> When execute the packed exe file, the exe file will be generate swap folder under temp folder, and all of file under the swap folder are encrypted file, and and all of these file will be cleared when execution closed.

## Packing process

### Add the main program (executable file)

1. Open Virbox Protector GUI tool, Click "`Tools`" in the Main Menu, find `Window Virtual Tool`in the bottom, as shown in the screenshot in below:

<figure><img src="/files/e1vUSwy19WB8jUp54IY8" alt=""><figcaption></figcaption></figure>

2. Click and open the Windows Virtual Folder tools

<figure><img src="/files/vu18irVGHanPaiPRAYcI" alt=""><figcaption></figcaption></figure>

2. Functionality and Feature

`2.1 Executable file path`: which means the path of the executable file of project；

`2.2 Output File`: means the packed exe file output path；

`2.3 Virtual Directory`: developer drag the rest of file which to be packed into the empty space of this `Virtual directory`, this folder is the present folder of the executable file running or execution;

Please refer the screenshot below:

<figure><img src="/files/FW3xotvLGKMuB9twtSLw" alt=""><figcaption></figcaption></figure>

4. Add the executable file (exe file): drag the executable file into the `Input box`, then output file folder will be the folder to create the pack file on default, which used to save the packed exe file.

   **Note: The type of executable file must be the exe file of PE or .NET type of exe file.**

### Add File/File Folder

Developer will have 3 ways to add file/folder: add file, add folder and add all file (Folder) from project folder, Developer may select one of three ways according to project file:

#### Add file

> **Add file**, is applied for the exe file and other file to be packed are under same folder, developer may put all of file together and pack into one exe file.

1. First, drag the main exe file into the input box of `Executable File Path`
2. Right click `Virtual Directory` to select `Add file` or select file and drag the file directly into the GUI tool;

<figure><img src="/files/Qn1NmA1amtVzL9PufphT" alt=""><figcaption></figcaption></figure>

3. Add file, usually be used to add the file only, and the exe file and the rest of relevant file to be called are under same directory, see screenshot below:

<figure><img src="/files/BwanCflmj9BKrD4iRsi2" alt=""><figcaption></figcaption></figure>

#### Add Folder

> **Add folder**, is applied for the exe file and other project file are located in different folder, and pack all of file in to one exe file.

1. First to drag the main exe file into the input box of `Executable file path`
2. Right click `Virtual Directory` to select to `Add Folder` or select the folder and drag the selected folder into the GUI tool directly;

<figure><img src="/files/Xmcos1hnPidVAdOoxPVF" alt=""><figcaption></figcaption></figure>

3. The path of the folder (location) must be under the same of directory as the exe file located, which is equivalent to the exe calling the file in the folder. see the screenshot as below:

<figure><img src="/files/Px7YW735zJyhgX3uUCk7" alt=""><figcaption></figcaption></figure>

#### Add all of file(folder) of project

> **Add all file(folder)** , is applied for the project contains multiple file and multiple folder, to pack the complex project.

1. First of all, to drag the main exe file into the input box of `Executable file path`, and here the `Virtual Directory` represent the upper level directory of exe file;
2. Right click `Virtual Directory` to select to `Add all files (Folder) in the folder` and select the upper level of the folder of main exe file located to " **Add all of file(folder)**".

<figure><img src="/files/ZsaFOKUdPQqyXjDMXTMc" alt=""><figcaption></figcaption></figure>

3. Add all of files and folders which under the selected folder, but except the selected folder itself;

#### Sample

Let's take a example with the project: Tester to go through whole process:&#x20;

**This project includes the main program exe, dll, and config folder, here we take this project as example to show the whole process to add and pack with one encrypted exe file. the whole packing process will be proceed as shown as below:**

1. Drag the main exe: `load_subprocess.exe` into the input box of `Executable file path`;
2. Right click and select `Add all files(folder）` in the folder and select the folder: `pack_demo` which in the upper level directory of the main exe and add;
3. Click the `Virtual Folder` to list all of files, folders under the `Tester` Folder.
4. Click `Pack` Option, then you can generate the packed file (exe file) which under the folder of `pack_demo\pack`;
5. Execute the packed exe file: double click exe file, all functionality will be executed as normal.

<figure><img src="/files/O9K9tSZpOXEKzFC733D9" alt=""><figcaption></figcaption></figure>

### Pack/Archive

1. When developer complete the setting to: Add main program (executable file) and Add file/Folder to the project;
2. Click the Button `Pack` which located at right corner in below (see attached screenshot), to pack/archive your project file.

<figure><img src="/files/JX0j4XkizH5ROLCDQbms" alt=""><figcaption></figcaption></figure>

3. When packing successful, you can find a exe file generated under the output path, all of file contained in this exe file has been encrypted.

<figure><img src="/files/cvSs5s7M0r5jnCuVS6xP" alt=""><figcaption></figcaption></figure>

3. Double click this exe file, all functionality running smoothly.

## FAQ

1. Can we use `virbox protector` to protect the exe file or dll file of project file first, then use the `Windows Virtual Folder` tool to pack and encrypt the whole project?

   Answer: Yes, support
2. Can we use `Windows Virtual Folder` tool to pack and encrypt the whole project file into one executable file and then use `Virbox Protector` to protect this packed exe file?

   Answer: No, it doesn't support to use `Windows Virtual Folder` in this way, when you use Virbox Protector to protect the packed exe file, then it will popup message and shown:

`The exe file has been protected`


# Protect Static libraries and object file

Developer use Virbox Protector to protect object file, static library with the most secure way.

## Overview of Static Libraries and Object Files

Object files are intermediate outputs generated after source code compilation. Object files contain assembly or machine instructions, symbol tables, and other metadata required during the linking stage. On Linux systems, object files typically use the `.o` extension, while on Windows they use `.obj`.

Static library files are collections of precompiled object files packaged together for reuse during the linking process. When a program is compiled and linked, the required object files inside the static library are copied into the final executable. Static libraries usually use the `.a` extension on Linux and `.lib` on Windows.

#### Security Concerns

Although object files are compiled binaries, they still contain assembly instructions and symbol information. With reverse‑engineering tools, attackers can analyze these files and reconstruct C‑style pseudocode.

In scenarios where developers only deliver static libraries or object files to customers, protecting these project becomes critical to prevent reverse engineering and intellectual property theft.

Virbox Protector secure static libraries and object files through **symbol/name obfuscation** and **function‑level protection**, including **code obfuscation** and **code virtualization**.

<figure><img src="/files/zo6fpkDk3h25rNC2mInK" alt=""><figcaption></figcaption></figure>

### Using Virbox Protector to protect Static Libraries and Object Files

#### Advantage

1. Protected programs generally do not affect the runtime loading speed or memory consumption when linking libraries during compilation.
2. Protected programs typically encounter no compatibility issues at compile time.
3. When appropriate protection methods are applied to functions, program startup time and memory usage remain largely unaffected.

#### Performance Impact

The performance impact of protecting static libraries and object files mainly comes from **function-level code obfuscation and virtualization**.

* Virtualization introduces the highest overhead, while obfuscation is lighter.
* The actual performance loss depends on the specific code logic.

Examples:

1. For functions with frequent loop calls, applying virtualization and obfuscation can noticeably affect runtime performance.
2. For functions with simple logical operations, full virtualization may have minimal impact.

**Recommendation:** Protect only core code, focusing on workflows and logical operations. Avoid applying protection to large loops or enabling protection for all functions indiscriminately.

#### Supported Architectures

Static libraries and object files are supported on the following systems:

| System                      | Support Status |
| --------------------------- | -------------- |
| Windows (x86 and x64)       | Supported      |
| Linux (x86 and x64)         | Supported      |
| Arm Linux (arm32 and arm64) | Supported      |
| macOS (x64 and arm64)       | Supported      |

### Protection Process

when you install Virbox Protector trial or commercial installation package, you can find Virbox Protector GUI tools and CLI tools in the sub-directory of `\bin` in your specified installation folder:

#### Virbox Protector GUI tools

`virboxprotector.exe`

#### Virbox Protector CLI tools:

`virboxprotector_con.exe`

We use `Virbox Protector` GUI tools to show you the protection process to protect Static Libraries and Object Files.

Double click `Virbox Protector` GUI tool icon in your windows UI or entry the `\bin` and find the Virbox Protector GUI tool and start it.

1. Import your object file or static library into Virbox Protector GUI tool
2. Select & Set "protection" option to those critical "Functions" in "Function Option" Tab
3. Set "name of obfuscation, Watermark & Merge Object file" in "Protection Option" Tab
4. Click File menu to start "Protection" process.
5. find the protected file in output path.
6. Use the protected file to archiving with .a file or link to generate elf file.

#### Prerequisites

sign up in Virbox Protector and contact Virbox team to get the license

Open Virbox Protector GUI tools,

1. Import your object file or static library into Virbox Protector GUI tool

   Drag the object file or static library which you want to protect into Virbox Protector GUI tools, then Virbox Protector will parse the file:

   For .a file, the parsing info show as in below:

<figure><img src="/files/1P3TJNiv2uZfKgjA0REi" alt=""><figcaption></figcaption></figure>

For Object file, the parsing info show as in below

<figure><img src="/files/5wtSQdLgwl5hfD3jNM2x" alt=""><figcaption></figcaption></figure>

2. Select & Set "protection" option to protect those critical "Functions" in `Function Option` Tab

> Virbox Protector provides multiple fine grained protection option to protect specified function/core algorithm in the .a or object file.

Go to `Function Option` tab, click `add` button to select those critical function which need to protect.

There are two type of "protection" option can be set to protect those functions by click drop down arrow on the `Protection Type` of selected function:

* Obfuscation
* Virtualization

Click `OK` to complete setting.

> Tips: Its recommend to protect only those functions which is critical (to keep execution performance);

<figure><img src="/files/Qytk6hOmCngjoaZn8Vdi" alt=""><figcaption></figcaption></figure>

3. Set `name of obfuscation`, `Watermark` & `Merge Object file` in `Protection Option` Tab

Virbox protector support developer to set:

Name of Obfuscation

Merge Object file

Watermark

in `Protection Option` tab.

Developer also select and set the output path in “Protection Option"

<figure><img src="/files/cJisl60uMzqSU49yUxgC" alt=""><figcaption></figcaption></figure>

4. Click File menu to start "Protection" process

<figure><img src="/files/3ztlm6ftMw9vfLLJvu4E" alt=""><figcaption></figcaption></figure>

5. Go to output path find the protect .a file or .o file.
6. then use the protected file to continue your development process. archiving or link to generate a output file (elf file or HEX file).

   > with protection by use of Virbox Protector, it will not change your workflow.

For better use `Virbox Protector` to protect static library and object file, we introduce protection functionality in next Chapter.

### Protection Functionality Overview

#### Basic Functionality (Set Protection Option)

**Symbol/Name Obfuscation**

You can use `linux` command `nm <your_file>` to inspect program symbols. The printed output includes identifiers with the following meanings:

* **r**: Read‑only data symbol.
* **b**: BSS segment symbol, typically representing uninitialized global variables.
* **t / T**: Text segment symbol, containing executable code.
* **U**: Undefined symbol, which must be resolved during linking.
* **W**: Weak symbol, allowing multiple symbols to share the same name.

**Note:** Undefined symbols (**U**) and weak symbols (**W**) are not obfuscated by default.

**Local Symbol Obfuscation**

Static libraries and object files both contain local symbols. Local symbols typically describe function names and address information, which are used by the linker to resolve symbol references when building the executable.

When applying protection, you can choose to obfuscate only local symbols. This option ensures that local symbols are obfuscated while maintaining overall compatibility and functionality.

<figure><img src="/files/5fYjbAw8stIBvuo28ERP" alt=""><figcaption></figcaption></figure>

**Comparison (After Local Symbol obfuscation & without Obfuscation)** The following illustration demonstrates the impact of local symbol obfuscation:

<figure><img src="/files/4804OhQ7SC7B6OYvtwxu" alt=""><figcaption></figcaption></figure>

> The left diagram shows the result of **local symbol obfuscation**, while the right diagram displays the **original program** without obfuscation.

**Preserving Custom Symbols**

(`Keep Custom Names` in GUI tool)

Static libraries and object files often contain custom symbols, which are defined within a file but accessible from other files. These may include both global and static symbols, typically specified using certain keywords or modifiers to define their attributes and scope.

<figure><img src="/files/3ftalI7m7zwtAEPprH69" alt=""><figcaption></figcaption></figure>

**Notes:**

1. If the option *Preserve Custom Symbols* (`Keep Custom Name`) is selected but the name list is empty, all symbol names will be obfuscated by default.
2. Ensure that exported function names are retained as needed; otherwise, compilation and linking will **fail** with errors indicating unresolved symbols.

**Comparison (Preserve Custom Symbols & without Preserve Custom Symbols)** The following diagram shows the impact of preserving custom symbols:

<figure><img src="/files/VRYYbzHv40p0JTv48fvu" alt=""><figcaption></figcaption></figure>

> The left diagram shows the result of Preserving Custom Symbols, while the right diagram displays the **original program**

**Merging Object Files**

Protect Static libraries, Virbox Protector support the functionality of merging object files.

<figure><img src="/files/j4MEVifVH3YuOR2GWUuh" alt=""><figcaption></figcaption></figure>

**Description:** Since a static library is composed of multiple precompiled object files, enabling the *Merge Object Files* option consolidates all `.o` or `.obj` files inside the library into a single `.o` or `.obj`.

**Purpose:** When a static library contains multiple `.o` or `.obj` files with interdependent symbol references, applying name obfuscation may cause symbol resolution issues during program loading. By merging object files, such problems can be avoided.

**Comparison (After Merging Object file & Before Merging object file)** The following diagram shows the impact of merging object files: (Insert diagram or screenshot here)

<figure><img src="/files/wkVpf994sJxRcLLAiJY3" alt=""><figcaption></figcaption></figure>

> The left diagram shows the result of Merging Object Files, while the right diagram displays the **original program.**

Protect specified "function" (Setting in "Function Option")

Virbox Protector support developer to protect specific functions with "Obfuscation", "Virtualization", to defend static analysis tool to reverse.<br>

<figure><img src="/files/NzTjQPHgtg5UxqAnkT2k" alt=""><figcaption></figcaption></figure>

**Code Obfuscation**

Code obfuscation transforms the original instructions within a function into randomized, unreadable fragments through techniques such as:

* Equivalent instruction substitution
* Immediate value encryption
* Indirect jumps
* Fake branches
* Dummy instructions
* Instruction slicing

These methods convert the original instructions into complex, non‑readable sequences, making reverse engineering significantly more difficult.

**Decompiled original Program:**

<figure><img src="/files/XKLz9pogeul71Y0vtihb" alt=""><figcaption></figcaption></figure>

**Decompiled after Obfuscation:**

<figure><img src="/files/ozXJEvEc5rVXS7Bgc1wh" alt=""><figcaption></figcaption></figure>

**Code Virtualization**

Code virtualization transforms the original assembly instructions within a function into a set of custom virtual instructions. At runtime, these virtual instructions are executed inside a custom **Virtual Machine**, which simulates behaviors such as memory access, conditional branching, and register state transitions.

**Decompiled Original Program (without Virtualization):**

<figure><img src="/files/26e0M4ZxpO26haLR8keW" alt=""><figcaption></figcaption></figure>

**Decompiled after Virtualization:**

<figure><img src="/files/r1DsNDVLy9VIKNsaT7P4" alt=""><figcaption></figcaption></figure>

#### Automated Integration

Automated integration allows you to protect files through command‑line operations. Virbox Protector supports a full set of command‑line options, enabling you to specify both basic protection settings (Function Option Setting) and function‑level configurations (Protection Option setting)—making it suitable for CI/CD pipelines and other automated workflows.

For more details, see [Virbox protector Command line tools](https://documentation.virbox.com/fundamentals/cli-tool-overview)

**Find Virbox Protector Command-Line Tool**

The command-line tool `virboxprotector_con` is installed in the following default paths:

* **Windows:** `C:\Program Files\senseshield\Virbox Protector 3\bin`
* **Linux:** `/usr/share/virboxprotector/bin`
* **macOS:** `/Applications/Virbox Protector 3.app/Contents/MacOS/bin`

**Protecting Object Files**

Run the following command to view all available parameters for object file protection:

`virboxprotector_con --help=obj`

**Protecting Static Libraries**

Run the following command to view all available parameters for static library protection:

`virboxprotector_con --help=archive`

**Merge Only (Without Applying Protection)**

This option performs **object-file merging only**

Run the following command to view all available parameters for object file protection:

`virboxprotector_con --help=objmerge`

Run the following command to merge object-file

```
 virboxprotector_con -objmerge <archive1> <archive2> ... <options ...>  [-o <output_path>] 
​
 virboxprotector_con -objmerge lib1.a lib2.a lib3.a -o libtest.a 
```

#### Protection Options

The following table lists the available protection options, their corresponding command‑line parameters, and wildcard support:

| **Option**                                 | **Command-Line Parameter** | **Wildcard Support** |
| ------------------------------------------ | -------------------------- | -------------------- |
| Name Obfuscation                           | `--rename=<value>`         | 0                    |
| Function Name List                         | `--keep-rules=<rules>`     | 2                    |
| Function Name List File path               | `--keep-file=<file_path>`  | N/A                  |
| Merge Object Files (static libraries only) | `--obj-merge=<value>`      | 0                    |

**Name Obfuscation Options**

The `--rename` parameter controls how symbol names are obfuscated:

* **--rename=0** — Disable name obfuscation.
* **--rename=1** — Obfuscate **only local symbols**.
* **--rename=2** — Preserve custom symbol names (`Keep Custom name` shown in GUI tools) while obfuscating others.

**Example Commands**

1. Protect a static library, enable object-file merging, and obfuscate only local symbols:

```
virboxprotector_con libhello.a --obj-merge=1 --rename=1 -o protected/libhello.a
```

2. Protect a static library, enable object-file merging, and preserve custom symbol (`Keep Custom Name`) names:

```
virboxprotector_con libhello.a --obj-merge=1 --rename=2 --keep-rules="main;array" -o protected/libhello.a 
```

3. Using a File to Preserve Function Names (`Keep Custom Name`)

If the list of function names to preserve is too long, you can store the names in a text file (for example, `symbol.txt`) and specify it using the `--keep-file=symbol.txt` option when running the command-line tool.

Run following command:

{% code overflow="wrap" %}

```
virboxprotector_con libhello.a --obj-merge=1 --rename=2 --keep-file=symbol.txt -o protected/libhello.a
```

{% endcode %}

<figure><img src="/files/a6YKeCBqAIsfu6yn9C58" alt=""><figcaption></figcaption></figure>

#### Function Option

You can specify function names or matching rules to apply protection. Multiple entries are separated using semicolons (`;`), and wildcard `*` is supported.

| **Option**                   | **Command-Line Parameter**     | **Wildcard Support** |
| ---------------------------- | ------------------------------ | -------------------- |
| Ignore Unsupported Functions | `--ignore-unsupported=<value>` | N/A                  |
| Code Obfuscation             | `-m`                           | Supported (`*`)      |
| Code Virtualization          | `-v`                           | Supported (`*`)      |

**Examples**

```
-m "function1;function2" -v "function3;function4" -e "test*" --ignore-unsupported=1
```

`--ignore-unsupported=`

**Ignore Unsupported Functions**

The `--ignore-unsupported` option is used to skip functions that are not supported by the protection engine. If a function cannot be processed, it will simply be ignored rather than causing the protection process to fail.

This option is **enabled by default** for programs in the following formats:

* Jar
* AAR
* WAR
* APK
* AAB

Command line Example: Apply Function Virtualization with Object-File Merging

Protect a static library, apply **function virtualization**, enable **object-file merging**, and obfuscate **only local symbols**:

```
 virboxprotector_con libhello.a -v "main;array" --obj-merge=1 --rename=1 -o protected/libhello.a 
```

### Best Practice to Protect objective file/Static lib

#### Protection Option

**Name Obfuscation**

**Protect a Linux x64 static library and object file:**

1\) Select the **Preserve Custom Symbols** (`Keep Custom Names` in the GUI tools) option while leaving the name list empty, then apply protection to the selected items.

2\) When linking the protected object files with the compiler, an error occurs: **"undefined reference to xxx"**

<figure><img src="/files/f48kZefrqtstoM6yptCV" alt=""><figcaption></figcaption></figure>

3\) Based on the symbol names reported in the linker error, add the required names (for example, `main`) to the custom symbol list, then apply protection again.

4\) After updating the custom symbol list and re‑protecting the selected items, the compiler can successfully link the object files without errors.

<figure><img src="/files/oJMMFBanhJDVvRQdHgG8" alt=""><figcaption></figcaption></figure>

**Protect a Windows x64 static library and object file:**

1\) Select the **Preserve Custom Symbols** option (`Keep Custom Names` in GUI tools setting) while leaving the name list empty, then apply protection to the selected items.

<figure><img src="/files/6tOwYoJppwGdSVFTebjc" alt=""><figcaption></figcaption></figure>

2\) When linking the protected object files with the compiler, an error occurs: **"undefined reference to xxx"**

<figure><img src="/files/vONzlFOTGL1xqTTvOspm" alt=""><figcaption></figcaption></figure>

symbol names reported in the linker error, add the required names to the custom symbol list — for example: `someLibFunc`, `feiboLib`, `arrayLib`. After updating the list, apply protection to the selected items again.

<figure><img src="/files/nE9coeXarkQV5pcceJ8G" alt=""><figcaption></figcaption></figure>

4. After updating the custom symbol list and re‑protecting the selected items, the compiler can successfully link the object files without errors.

<figure><img src="/files/bRiIg70fuise64xlSjGR" alt=""><figcaption></figcaption></figure>

### FAQ

#### Unrecognized OBJ Files

When compiling a Release-version `.lib` using Visual Studio, the protection tool reports **"File format error"** during parsing. How should this be resolved?

1. In the project settings, navigate to **Configuration Properties → C/C++ → Optimization**, and modify the **Whole Program Optimization** setting. The option **"Use Link-Time Code Generation"** is not supported. Change it to another optimization mode, as shown in the example below.

<figure><img src="/files/aikGhH81fues61WnA9Kx" alt=""><figcaption></figcaption></figure>

2. In the project settings, navigate to **Configuration Properties → C/C++ → Optimization**, and set **Whole Program Optimization** to **No**, as shown in the example.

<figure><img src="/files/WH6U41CJ9kNnV5x68l3h" alt=""><figcaption></figcaption></figure>

3. After adjusting the settings, save the configuration and recompile the project. The newly generated `.lib` file can then be correctly recognized by the protection tool.


# Solution Overview-Protection Scheme for ARM Thumb Object Files and Static Libraries

introduce highly secure protection approach to protect ARM Thumb Object file/Static lib

**Summary**

This document presents a customized protection scheme of **Virbox Protector** designed for ARM‑based embedded environments, specifically targeting the [**Thumb instruction set**](https://developer.arm.com/documentation/ddi0210/c/CACBCAAE). and fully supporting static libraries and object files generated by the [**IAR compiler**](https://en.wikipedia.org/wiki/IAR_Systems).

Since many embedded vendors rely on IAR IDE for commercial ARM embedding device development, this compatibility ensures that `.o` and `.a` files produced by IAR can be protected without modifying the customer’s toolchain or build workflow.

[Virbox Protector](https://appsec.virbox.com/) provides a comprehensive workflow for securing [**object files**](https://developer.arm.com/documentation/101655/0961/Cx51-User-s-Guide/Compiling-Programs/Command-Prompt/Output-Files/Object--OBJ--File) (`.o`) and [**static libraries**](https://en.wikipedia.org/wiki/Static_library) (`.a`) commonly used in customer delivery scenarios.

The solution integrates multiple protection techniques—including code virtualization, obfuscation, watermark embedding, function‑symbol optimization, and object‑file merging—to enhance resistance against reverse engineering while maintaining compatibility with ARM toolchains and constrained flash environments.

To address customer feedback regarding file size expansion, especially in systems with strict flash limits (e.g., 128 KB), this document also details several optimization strategies. These include reducing redundant virtual machines, trimming high‑impact obfuscation features, and improving function parsing to minimize unnecessary branches.

All test data, comparisons, and risk assessments included in this document serve as reference points. Actual results may vary depending on the customer’s real application, build environment, and selected protection configuration.

### Thumb Virtual Machine Function Verification Workflow

#### Product Background

`Virbox Protector` supports function‑level protection for object (`.obj`) files, including both code obfuscation and code virtualization:

* **Code obfuscation** transforms original instructions into randomized and unreadable instruction fragments through techniques such as equivalent substitution, immediate value encryption, indirect jumps, fake branches, junk instruction insertion, and instruction slicing. Obfuscation does **not** change the fundamental characteristics of the instruction set: ARM instructions still execute as ARM, and Thumb instructions still execute as Thumb on the system. Since the original execution flow is preserved, obfuscation is **not affected by special hardware environments**.
* **Code virtualization** converts the original assembly instructions within a function into custom virtual instructions. These instructions are executed inside a custom virtual machine at runtime, simulating memory access, conditional branching, register states, and more. This requires precise instruction parsing and handling of different instruction formats. `Virbox Protector` uses the **A32 instruction set** to implement a virtual machine interpreter capable of handling **A32, T16 (Thumb), and T32 (Thumb‑2)** instructions. However, some embedded processors (e.g., Cortex‑M4 based on the ARMv7E‑M architecture) **cannot execute A32 instructions**, which prevents the protected program from being properly virtualized on such devices.

To expand the protection coverage and enhance security on specific processors, `Virbox Protector` introduces a customized virtual machine implementation that supports virtualization of Thumb instructions on these platforms.

#### Mechanism

For object files containing Thumb instructions, the [Virbox Protector](https://appsec.virbox.com/) uses **T16 and T32 instructions** to implement a virtual machine interpreter for the **T16 (Thumb) and T32 (Thumb‑2)** instruction sets. During protection, the **Thumb virtual machine is enabled by default**, allowing protected Thumb‑based object files to run correctly on specific processors (such as Cortex‑M4 processors based on the ARMv7E‑M architecture).

#### Feature Testing

**Test Environment**

**Android NDK Compilation**

When compiling ARM32 programs with the Android NDK, adding the `-mthumb` parameter instructs the compiler to generate Thumb‑instruction binaries. This allows the resulting program to run on Android devices while still producing Thumb‑based object files, enabling us to perform testing even without embedded processor hardware.

Test Procedure:

1. Compile the Thumb‑instruction `.obj` file using the Android NDK.
2. Use the [Virbox Protector](https://appsec.virbox.com/) to protect the `.obj` file, selecting the target functions for code virtualization.
3. Inspect the protection results of the Thumb instruction set in the protected `.obj` file.
4. Verify whether the protected program can be successfully linked and compiled, and confirm that the resulting executable runs correctly.

***

[**IAR Embedded Workbench**](https://www.iar.com/embedded-development-tools/iar-embedded-workbench) **Compilation**

Test Procedure:

1. Compile the Thumb‑instruction `.obj` file using the [**IAR Embedded Workbench**](https://www.iar.com/embedded-development-tools/iar-embedded-workbench) **Compilation**
2. Use the [Virbox Protector](https://appsec.virbox.com/) to protect the `.obj` file, selecting the target functions for code virtualization.
3. Inspect the linking behavior of the protected `.obj` file when generating the final executable.
4. Inspect the protection results of the Thumb instruction set in the protected `.obj` file.

**Project Decompiled Comparison (Before & After Protection)**

**Decompiled View Before Protection**

Locate the function intended for virtualization and directly decompile it to observe the original assembly instructions.

<figure><img src="/files/gzx7VKgJV2B7TbsuEIyy" alt=""><figcaption></figcaption></figure>

View the C–style pseudocode generated after decompiling the function.

<figure><img src="/files/Y8qk3Pl5RfravhcVHe9s" alt=""><figcaption></figcaption></figure>

**Decompiled project After Protection**

1. Invocation Process

* Locate the virtualized function. When the program executes the instruction `BL sub_D8E4`, double‑clicking `BL sub_D8E4` saves the return address and jumps to `B.W loc_13626`.
* As shown in the figure:

<figure><img src="/files/2o9VHOTUKka7oRvmqNTy" alt=""><figcaption></figcaption></figure>

2. Intermediate Jump

* Double‑click `B.W loc_13626` to continue the jump (an unconditional branch that does not affect the LR register) to the new location. The `B.W` instruction is used in Thumb‑2 mode.
* As shown in the figure:

<figure><img src="/files/Abs6hsp2KlMqkEmFsiZ3" alt=""><figcaption></figcaption></figure>

3. Final Execution

* After reaching `loc_13626`, the program begins executing the actual instructions at this location. The resulting instruction sequence (the final target code) consists entirely of virtualized Thumb instructions.
* As shown in the figure:

<figure><img src="/files/mU6nFPBAqn0kC834jypX" alt=""><figcaption></figcaption></figure>

View the C‑style pseudocode generated after decompiling the function.

<figure><img src="/files/skgvsi93gKpyCO9VyQIh" alt=""><figcaption></figcaption></figure>

#### Performance Testing

**File Size Increment Test**

This test evaluates the file size increase before and after protection. Using a sample file (`system_machine.o`), code virtualization is applied to observe the file size changes when virtualizing: All functions **versus** virtualizing: Only selected functions.

See the table below:

| Number of Virtualized Functions | Original File Size | File Size After Protection | Increase |
| ------------------------------- | ------------------ | -------------------------- | -------- |
| Any 10 selected functions       | 101,161            | 157,828                    | 56,667   |
| Any 30 selected functions       | 101,161            | 213,516                    | 112,355  |
| All functions (134 total)       | 101,161            | 443,532                    | 342,371  |

> **Notes:**
>
> 1\) Compare the file size before and after protection, and choose an appropriate protection strategy based on the actual device constraints. 2) The more functions selected for virtualization, the larger the resulting file size and the greater the performance impact. Adjust dynamically according to the program’s actual requirements.

**Startup Time**

**1. Description**

Using the test demo as an example, compare the performance of the original program and the program after virtualizing 11 functions.

**2. Results**

Note: Performance overhead varies depending on the specific code logic.

**Startup time of the original program:**

<figure><img src="/files/8MhSWjhgWL3QAVjmQZSV" alt=""><figcaption></figcaption></figure>

> Note:
>
> 1. The titles of the four columns in the table above are:
>
> Process ID (PID) , Turnaround Time, Waiting Time, Response Time;
>
> 2. For total 5 Process (PID) above:
>
> Average Turnaround Time: 4.80s;
>
> Average Waiting Time: -1.80s;
>
> Average Response Time: 3.80s;
>
> program execution time:0.004531s

**Startup time of the fully virtualized program:**

<figure><img src="/files/FQVODWrWWNmmsnmg4Nc7" alt=""><figcaption></figcaption></figure>

> Note:
>
> For total 5 Process (PID) with all of function virtualization above:
>
> Average Turnaround Time: 4.60s;
>
> Average Waiting Time: -4.40s;
>
> Average Response Time: 3.60s;
>
> program execution time:0.007879s

**Compatibility Testing**

**Runtime Environment:** Android 7 – Android 16

**Test Program:** Android ARM32 (Thumb instructions)

**Description:** The software is tested across Android devices running different system versions to ensure stable operation.

| Device Model      | System     | Result |
| ----------------- | ---------- | ------ |
| Xiaomi MIX        | Android 7  | Pass   |
| Huawei nova youth | Android 8  | Pass   |
| Xiaomi MIX 2      | Android 9  | Pass   |
| Xiaomi 10         | Android 12 | Pass   |
| Google Pixel 6    | Android 16 | Pass   |
| Oppo Find X8      | Android 16 | Pass   |
| OnePlus 13        | Android 16 | Pass   |

### Multi‑VM Virtualization Function Verification

#### Mechanism

During protection, the `Virbox Protector` tool converts each basic block of a function into virtual machine pseudocode, which is then interpreted and executed by the VM interpreter at runtime.

In this enhanced mechanism, multiple virtual machine instances can be created during protection. Each function is randomly assigned to a different VM instance, and each VM uses a distinct pseudocode encoding scheme. This significantly increases the overall security level.

#### Feature Testing

Test Steps:

1. Compile Thumb‑instruction `.obj` files using the IAR and Green Hills toolchains.
2. Use the Virbox Protector (debug version with symbols) to protect the `.obj` file. Select the functions to be virtualized and configure the number of VM instances (e.g., 4 VMs) in the advanced options.
3. Examine the behavior of the linked executable generated from the protected `.obj` files.
4. Inspect the protection effect on the Thumb instruction set within the protected `.obj` files.

#### Verification of Protection

> Note: The debug version of the Virbox Protector (with symbols) is intended **only** for testing the multi‑VM functionality. The protected `.obj` files generated by this version **must not** be distributed externally.

Use the Virbox protector (debug version with symbols) to protect the `.obj` file. After protection, load the resulting `.obj` file into IDA and search for the `vm_init` function. The number of occurrences indicates how many VM instances are being used. For example, the following case shows that 8 VM instances were generated:

<figure><img src="/files/cZTmHbxBbzTJaKvhNSF2" alt=""><figcaption></figcaption></figure>

**Decompiled View After Protection**

1. Locate the protected function. The program execution reaches the instruction

<figure><img src="/files/PI4FrY0gMv1wrthOaL2O" alt=""><figcaption></figcaption></figure>

2. Double‑click to jump to `BL vm_init_0`.

<figure><img src="/files/hFYvckUdrYpcfDk9K3OJ" alt=""><figcaption></figcaption></figure>

3. Click **X** to enter the `vm_init_0` function and observe the differences in its instructions.
4. Following the same steps, you can compare the behavior of the other VM instances.

<figure><img src="/files/eysAEcLetD6vF9c7Zldo" alt=""><figcaption></figcaption></figure>

#### File Size Increment Test

The file `LP_D13_PTG_app_test.a` is protected to evaluate the file size increase before and after applying protection.

| Number of VM Instances | Number of Functions | Merge Option | File Size | Size Increase |
| ---------------------- | ------------------- | ------------ | --------- | ------------- |
| Original Program       | /                   | /            | 366k      | /             |
| 1 VM                   | 37                  | Enabled      | 509k      | 143k          |
| 1 VM                   | 37                  | Disabled     | 554k      | 188k          |
| 4 VMs                  | 37                  | Enabled      | 662k      | 296k          |
| 4 VMs                  | 37                  | Disabled     | 706k      | 340k          |
| 8 VMs                  | 37                  | Enabled      | 866k      | 500k          |
| 8 VMs                  | 37                  | Disabled     | 911k      | 545k          |

### Watermark Function Verification

#### Description

The `Virbox Protector` implements this feature by embedding custom data into the `.obj` file (object file or static library) during the protection process. These data fields can be configured in the tool interface. After the protected `.obj` file is compiled and linked, the embedded data will remain in the final binary as a watermark.

By detecting whether the binary contains this watermark, it is possible to determine whether the static library has been linked, thereby identifying the user of the static library and preventing unauthorized third‑party usage.

#### Waremark Setting

**Virbox Protector Version:** 3.5.1.21416

**Steps to set Watermark:**

1. Drag the `.obj` file into the `Virbox Protector` GUI tool.
2. In the Protection options of the Virbox Protector GUI tool, the watermark configuration panel is displayed. The watermark value can be set using hexadecimal characters.

> **Note:** The watermark value must contain an **even number of hexadecimal characters**. Odd‑length values are not allowed; otherwise, the protection process will fail.

<figure><img src="/files/XAAKCYNgkNJFd04BMMle" alt=""><figcaption></figcaption></figure>

#### Verification of Watermark setting

1. Use the `010 Editor` tool to inspect the watermark configured during protection. After parsing the static library or binary file, directly search for the corresponding Hex Bytes.
2. Enter the configured watermark value in the search field. If the watermark is stored in the `.text` code section after protection, the configured watermark bytes can be located within the code.

<figure><img src="/files/hlb1abYgHY8ZGFCiuVkP" alt=""><figcaption></figcaption></figure>

### Function Symbol Optimization

**Issue Description:**

When an `.obj` file is dragged into the `Virbox Protector` GUI tool, some function names displayed in the function list contain `??`, as shown in the example below:

<figure><img src="/files/gjxWtFKCnrE8NKc4mPbI" alt=""><figcaption></figcaption></figure>

**Optimization Approach:**

The `?? ... [number]` symbols generated by the IAR compiler are no longer treated as individual functions. In practice, this merges all branch functions into a single function, eliminating the appearance of branch‑level entries and preventing function names from being displayed as `??`. As a result, the total number of functions is reduced, and each optimized function contains more instructions compared to the pre‑optimization branch functions.

| Protector Version | Total Functions |
| ----------------- | --------------- |
| 3.5.1.21385       | 506             |
| 3.5.1.21416       | 115             |

**Virbox Protector Version fixed issue:**

In version **3.5.1.21416**, the function parsing result appears as shown below:

<figure><img src="/files/OimqN3TbbTwTgx2ILjfv" alt=""><figcaption></figcaption></figure>

### Excessive File Size Increase After Protection

For some of embedding device flash, the maximum available flash space is 128 KB. When more than 40 functions are selected for code obfuscation, the compiler reports insufficient flash space. Therefore, optimizations have been applied to the standard obfuscation feature and the object‑file merging feature to reduce the final protected program size.

#### Code Obfuscation Optimization Plan

Since the maximum flash capacity is confirmed to be 128 KB, the core objective is to **maximize security** (including future virtualization support) **while ensuring the protected binary does not exceed the 128 KB limit**. The current version adopts the following adjustment strategy:

**Obfuscation Adjustment Strategy**

*Note: The scoring scale is 1–10, where a higher score indicates a greater impact.*

| Obfuscation Method         | Description                                                                                                                | Impact Analysis                                                                                                      | Impact Score                             | Trimmed                |
| -------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | ---------------------------------------- | ---------------------- |
| Equivalent Substitution    | Replaces original instructions with semantically equivalent but structurally different instructions.                       | Increases code complexity and typically increases code size.                                                         | No change                                | No                     |
| Immediate Value Encryption | Encrypts constants (immediate values) and decrypts them at runtime.                                                        | Prevents direct inspection of constants in the binary, increases static analysis difficulty, may increase code size. | No change                                | No                     |
| Indirect Jumps             | Replaces direct control‑flow jumps with indirect jumps (e.g., function pointers or jump tables).                           | Makes disassembly targets inaccurate, increases analysis difficulty, may increase code size.                         | No change                                | No                     |
| Fake Branches              | Inserts non‑executed branches (dead code) to confuse control flow.                                                         | Requires analysts to distinguish real vs. fake branches; significantly increases code size.                          | No change                                | No                     |
| Dummy Instructions         | Inserts meaningless (garbage) instructions to disrupt logical flow.                                                        | Increases code complexity and significantly increases code size.                                                     | Security Impact: 2/10 Space Impact: 8/10 | Yes (reduced quantity) |
| Instruction Slicing        | Splits a single instruction into multiple fragments, possibly placed in different locations.                               | Makes logic more scattered and harder to understand; may increase code size.                                         | No change                                | No                     |
| Anti‑Run‑Trace             | Inserts hidden probes to detect single‑step debugging; triggers incorrect instructions when illegal debugging is detected. | Adds probes that increase code size; mainly counters IDA Pro trace features; unnecessary for bare‑metal systems.     | Security Impact: 0/10 Space Impact: 6/10 | Yes (removed)          |

**Comparison Before and After Optimization**

**Test Procedure:**

Using the pre‑optimization version (3.5.0.21352) and the post‑optimization version (3.5.1.21361), code obfuscation was applied to a sample program (`system_machine.o`). The file size changes were measured when applying obfuscation to all functions and to selected functions.

**Reference Data:**

| Number of Obfuscated Functions | Program Size (3.5.0.21352) | Program Size (3.5.1.21361) | Reduction |
| ------------------------------ | -------------------------- | -------------------------- | --------- |
| Original Program               | 101,161                    | 101,161                    | /         |
| All Functions (134)            | 485,796                    | 360,548                    | 125,248   |
| Any 30 Functions               | 222,820                    | 180,428                    | 42,392    |
| Any 10 Functions               | 131,292                    | 114,068                    | 17,224    |

**Recommendation:**

The above data is for reference only. Version **3.5.1.21361** available, and users should evaluate based on their own program structure and selected functions to determine whether the optimized VBP version meets the **flash space** requirement.

#### Object‑File Merging Optimization Plan

**Optimization Strategy**

Since a static library (`.a`) contains multiple object files (`.o`), it is recommended to use the **object‑file merging** feature. This feature has been optimized as follows:

* **Before Optimization (Version 3.5.1.21385):**

  The merging process protected each `.o` file first and then merged them. As a result, after **virtualization**, each `.o` file contained its own VM instance. This caused a significant increase in file size because multiple identical VMs were embedded across different object files.
* **After Optimization (Version 3.5.1.21416):**

  The merging process now merges all `.o` files **before** applying protection. This means the merged `.o` file is virtualized only once, resulting in **a single VM instance**. Reducing the number of VMs directly decreases the overall file size impact.

**Comparison Before and After Optimization**

**Test Procedure:**

Using the pre‑optimization version (3.5.1.21385) and the post‑optimization version (3.5.1.21416), code virtualization was applied to a sample static library (`test_app.a`) with the **merge object files** option enabled. The file size changes were measured when virtualizing all functions and when virtualizing only selected functions.

**Reference Data:**

<br>

| **Virtualization Count** (3.5.1.21416) | Program Size (Before **Object‑File Merging**) | Program Size (After Merging) | Reduction |
| -------------------------------------- | --------------------------------------------- | ---------------------------- | --------- |
| Original Program                       | 373,982                                       | 373,982                      | /         |
| All Functions (97 functions)           | 1,089,224                                     | 731,644                      | 357,580   |
| Any 30 Functions                       | 541,392                                       | 443,308                      | 98,084    |
| Any 10 Functions                       | 400,248                                       | 302,444                      | 97,804    |

#### Reference Data (Version 3.5.1.21385)

| **Virtualization Count** (3.5.1.21385) | Program Size (Before **Object‑File Merging**) | Program Size (After Merging) | Reduction |
| -------------------------------------- | --------------------------------------------- | ---------------------------- | --------- |
| Original Program                       | 373,982                                       | 373,982                      | /         |
| All Functions (298 functions)          | 1,276,584                                     | 1,229,884                    | 46,700    |
| Any 30 Functions                       | 443,312                                       | 396,612                      | 46,700    |
| Any 10 Functions                       | 391,016                                       | 344,300                      | 46,716    |

Compared with version 3.5.1.21385, version 3.5.1.21416 shows a larger size increase when **object‑file merging is disabled** and **virtualization** is applied. This is because the new version optimizes the previous issue where functions were split into multiple branch entries. Although the total number of functions is reduced, each function body becomes larger. As a result, when merging is not enabled, the size increase is more noticeable than before.

**Recommendation:**

The above data is for reference only. Version **3.5.1.21416** is available, and users should evaluate based on their own program structure and selected functions to determine whether the optimized VBP version meets the **flash space** requirement.

### Comments

Since the test program cannot fully represent the customer’s real application scenarios, the test results may differ from actual usage conditions. The above results are for reference only. It is recommended to rely on the results obtained from real‑world usage and the actual **test environment** to make final assessments.


# Protect Desktop applications

Introduce the protection process to desktop application, included different kind of program language: C, C++, C# etc.


# Protect the Local desktop application

## Protect the Native PE application

**Virbox Protector** supports to protect Native PE Apps in both GUI tool and CLI tool, in Windows, Linux and ARM linux environments.

The protection process here we introduced applied for local native language application which based on C, C++ language: *exe, dll* file etc, the PE program protection and encryption process.

### Protect your Native PE program in 5 steps

1. Import file: import the file which need to be protected (exe or dll) to Virbox Protector;
2. Set the configuration of "Function Option"; (Select and Protect these specified functions which you want to protect.);
3. Set the configuration of "Protection Option"; (Set the protection to protect the PE program in general);
4. Click to "Protect Selected Projects" to start the protection process;
5. Backup the source file, use the protected file for further testing/evaluation and save the "configuration" file;

For asssociated data assets and resource, use the plug in unit: DS Protector to protect it. see **User Manual DS Protector.**

### Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Open Virbox Protector and sign in with your account  and password for trial you received.

![](/files/fa0AkN9mJjbWiqZtzprl)

:bulb:Above pre-requisition is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.

### Protection Process

1. #### Import the PE file which you want to protect (exe or dll) into Virbox protector

   Drag the exe or dll file into the Virbox protector directly, or:

   Open file from Virbox Protector menu--> File-->Open File

   Then Virbox Protector will parse the file to be protected automatically.&#x20;

![](/files/ICApb8Yg4FGsAaIL7GXt)

{% hint style="info" %}
Virbox Protector will load the "map" file automatically if the xxx.map existed in the same directory with the protected file, then relevant function's name will be shown in the Virbox Protector.

Virbox protector support to load and use the .map file which generated by VS, VC, BCD, Delphi compiler currently.
{% endhint %}

**2. Set the configuration of "Function Option"**

Virbox Protector supports to protect the software application to the specified function's level and provides several protection mode for developer selection to protect the critical functions.

Developer may select the functions contained in the PE file and set the protection mode to specified functions here.

Go to "<mark style="color:blue;">Functions Option</mark>" tabs,&#x20;

![](/files/Y9dGCFljX2Zxg8w9KmKa)

Virbox Protector will parse the functions and listed in the GUI,&#x20;

"<mark style="color:blue;">Left click</mark>" to select the functions which you want to protect, "<mark style="background-color:blue;">Right click</mark>" to set the protection mode: Virtualization, Obfuscation, Encryption;

you can click "<mark style="color:blue;">Add Function</mark>" button to add other functions and "<mark style="color:blue;">Drop down</mark>" to set the protection mode to those added functions. then click "<mark style="color:blue;">OK</mark>" to add more "functions"

![](/files/uAGHRCFhJZzrzEx6E93W)

Click <mark style="color:blue;">"Analysis"</mark> button after set the protection mode of these selected "functions", you can test and evaluate if the execution peformance is satisfy or not, if not, suggest you can skip the function which called frequently to improve execution performance.

<mark style="color:blue;">Ctrl+A</mark> to select “All of Functions"

{% hint style="info" %}
it is Not recommend to select "All of Function" to protect, due to execution performance may impacted;

For the PE executive and DLL files which based C, C++, Delphi XE7 and above, PB, BCB language, the security level of Protection mode:&#x20;

Code of Virtualization>Code Obfuscation>Code Encryption;

For the Program developed on C#, The security level of Protection mode:&#x20;

Code Encryption>Code Obfuscation.
{% endhint %}

* #### 3. Set the configuration of "Protection Option"

  Developer may set the protection configuration to the PE executive or DLL file in general here:

Go to the "Protection Option" tab,

![](/files/kiMKVSxTNHP6OGvKNhhG)

3.1 Set the Output path of the protected files, developer may set the output path and new file name of protected file; otherwise a new sub directory will be created with <mark style="color:blue;">\protected</mark>, the protected file will be saved in this new created sub-directory.

{% hint style="info" %}
It is NOT recommend to use same file name with your source file name, if the output path is source file directory, otherwise the protected file may replace your source file.
{% endhint %}

3\. 2. Click to select the Protection Options to protect your application file in general:

3\. 2.1) Import Table Protection:

To protect and encrypt the "Import table" and hide the API list to protect the functions called from external, it is recommend to click and select this option to enhance the security level;

{% hint style="info" %}
Import Table Protection applied for PE file only;
{% endhint %}

3.2.2) Compression:

To compress the file size and prevent the protected file from the static decompiling

{% hint style="info" %}
If the file size is too small, the compressed file size may not smaller or even bigger than the source file size;&#x20;

Compression feature is not applicable for .NET file and arx file type
{% endhint %}

3.2.3) Memory Check (Verify the code Integrity)

When program executed in memory, The loader of Virbox Protector will check each memory block to ensure the code integrity to prevent tampering, repackaging;

With SDK labeling feature, to verify the memory with dynamically to prevent from tampering

3.2.4) Resource Section Encryption

Encrypt the Resource Section in the program, and use the license to decrypt when program executed and preventing the resources information being extracted and tampered illegally.

Resource Section Encryption applied for local PE program only;

3.2.5 Anti-Debugging:

Click to set to this feature, The protected application will quit the execution when debugging of process  has been detected;

3.2.6 Virtual Machine Detection:

Click to set this feature, The protected application will quit the execution when detect the Virtual Machine environment, include VMWare, Virtual Box etc.

3.3 Plugin Switch on/off

Besides of protection set in above feature, Virbox Protector support below plugin switch on/off to enhance the security to protected files:

3.3.1  Switch on/off: Advanced Process Protection: RASP

{% hint style="info" %}
Optional feature and license required to activate this feature
{% endhint %}

**RASP**: Runtime Application Self Protection: this plugin focus to protect the process running in the kernal for the application in windows platform, when this plugin start to execute, it will load the driver integrated to protect process itself to prevent the third party  plugin  to skip the normal anti debugging protection from debugging in memory. It is also effective to defense the "Cheat Engine" to scan the memory which running the process.&#x20;

**RASP** plugin are most effective functions and applied to those scenario which highly security required. additional license from Virbox required.

There are 3 features can be select in the "Advanced Process Protection" plugin:

* Memory Protection:&#x20;

Click to protect the memory information executed for windows application; which to prevent the attacker/hacker to scan  the process memory by use of "Cheat Engine" tools;

* Kernel Mode Anti-debugging

Click to activate the Anti-debugging feature to prevent the debugging tool to debug the kernal;

* Show Error Message

Pop up error message inlcudes error code when program execution error occured, and popup message will be quite after 5 seconds automatically;

3.3.2 Switch on/off the **ds** Plugin

Switch on/off the **DS Protector**, a plug in unit which used to encrypt/protect the data source file of protected program, you need to "switch on" the "ds" button to open "DS Protector"and set the password for protected data source file.

Another way to open the DS Protector is go to the \bin subdirectory of Virbox Protector and double click: deprotector.exe to open DS Protector. but you still need to "Switch on" ds button to enable the ds function in Virbox Protector.

**4. Click to Start the "Protection" Process**

When you complete the setting to "Function Option" and "Protection Option", Click to the button "Protect Selected Projects" in the Menu, to start the "Protection" Process. and click "Run Application" to verify if the execution performance is satisfied, if everything is OK, click "OK" to complete the Protection process.

![](/files/4bbf3tRnEacv4Ig4Pnc5)

#### 5. Backup the source file. Use the protected file for further testing and save the "configuration" file

Go to output directory, you will find one new file: <mark style="color:blue;">pe\_tetris1.exe.ssp</mark> and one sub directory <mark style="color:blue;">\protected</mark> has been generated:

![](/files/KsdH2PWy0nOMjLHSdrs1)

The "PE\_Tetris1.exe" is source file which not be protected. you need to keep the source file to another directory and not distribute this source file to your user.

The "PE\_Tetris1.exe.ssp" is the configuration file which save all of protection option setting, you can reuse this configuration file when your application updated.

The sub directory: \Protected" is the protected file located. you can find the  the protected file (with same name of source file) and use this file for further testing.

### Summary

Above is the protection process to protect native PE executive or DLL file, the relevant resource assets can be protected by use of DS Protector;

For more further information to Virbox Protector and DS Protector, you may refer the User Manual\_Virbox Protector and User Manual\_DS Protector.


# Best Practice--Protect Native applications

The Native application means the software application which developer build for specific hardware platform and operation system, and it is independent with virtual machine or interpretor when execute. The typical native applications includes：

* The PE application of windows system,
* The ELF programs (suffix with .so or main program) in Linux/Android system a
* The MachO programs (.dylibs or main program) in macOS/iOS system.

| Operation System   | Main program | DLL/Shared Library | Driver |
| ------------------ | ------------ | ------------------ | ------ |
| Windows            | .exe         | dll                | .sys   |
| Linux/Android(Elf) |              | .so                | .ko    |
| macOS/iOS(MachO)   |              | .dylib             |        |

Usually, The native program are developed by C/C++/Objective-C/Swift/Delphi/Go language and running in the PC, Server, mobile client end and IoT or embedding devices. The fundmental to native application's execution is machine instructions based on CPU architecture, for instance, X86 instruction set in PC platform, the ARM instruction set in Android platform, Native apps work with the device's OS in ways that enable them to perform faster and more flexibly than alternative/cross platform applications. If the apps executed in various types of device, then developers need to build a separate app version to each type of device.

The security of native applications, althrough the native program doesn't contained the original functions name, variable name. which bring some of difficulty for decompiliation to native programs. but it is also possible to decompile the native application when cracker use the professional debug and reverse engineering tools without so much effort to those professional attackers. so, for those application which require highly security, it is necessary to protect native project to prevent possible leaking risk.

Here is example to decompile the binary code:

**The source code** (in Android ARM architecture) :

<figure><img src="/files/h59Dd63zniWJZEmrRsBK" alt=""><figcaption></figcaption></figure>

when you use the decompiler to decompile the binary code (without protection), the result is like this:

<figure><img src="/files/Sm8CzQiRUlh4Z5V7Nwbt" alt=""><figcaption></figcaption></figure>

Even the vairiable name in the functions missing after decompiled, but it is possible to get the readable code to understand with additional analyzing the symbol table of ELF ( “Executable and Linkable Format), import/export functions, the critical string;

## Virbox Protector supports to protect following type of native programs

### Architecture & Operation System

| Operation System | x86 | x64 | arm32 | arm64 |
| ---------------- | --- | --- | ----- | ----- |
| Windows          | ✔️  | ✔️  | ✖️    | ✖️    |
| Linux            | ✔️  | ✔️  | ✔️    | ✔️    |
| macOS            | ✖️  | ✔️  | ✖️    | ✔️    |
| Android          | ✔️  | ✔️  | ✔️    | ✔️    |
| iOS              | N/A | N/A | ✖️    | ✔️    |

### App/File Type

| Operation System    | Main programs protected | DLL（dll,.so, .dylibs) | Driver |
| ------------------- | ----------------------- | --------------------- | ------ |
| Windows             | ✔️                      | ✔️                    | .sys   |
| Linux/Android (ELF) | ✔️                      | ✔️                    | .ko    |
| macOS/iOS (MachO)   | ✔️                      | ✔️                    | ✖️     |
| ARM linux           | ✔️                      | ✔️                    | ✖️     |

### Feature Matrix

| Protection Option Tab       | Windows | Linux | macOS | Android | iOS |
| --------------------------- | ------- | ----- | ----- | ------- | --- |
| Compression                 | ✔️      | ✔️    | ✖️    | ✔️      | ✖️  |
| Memory Check                | ✔️      | ✔️    | ✔️    | ✔️      | ✔️  |
| Import Table Protection     | ✔️      | ✖️    | ✖️    | ✖️      | ✖️  |
| Resource section Protection | ✔️      | N/A   | N/A   | N/A     | N/A |
| Overlay Data Encryption     | ✔️      | ✔️    | ✔️    | ✔️      | ✔️  |
| Debug Detection             | ✔️      | ✔️    | ✔️    | ✔️      | ✔️  |
| Virtual Machine Detection   | ✔️      | ✖️    | ✖️    | ✖️      | ✖️  |
| Remove debug info           | ✖️      | ✔️    | ✖️    | ✔️      | ✖️  |
|                             |         |       |       |         |     |
| **Function Option Tab**     |         |       |       |         |     |
| \[E] Code of Encryption     | ✔️      | ✔️    | ✔️    | ✔️      | ✔️  |
| \[M] Code of Obfuscation    | ✔️      | ✔️    | ✔️    | ✔️      | ✔️  |
| \[V] Code of Virtualization | ✔️      | ✔️    | ✔️    | ✔️      | ✔️  |

## Best Practice to protect native applications

### Virbox Protector GUI tool

It is quite easy to use Virbox Protector GUI tool to protect the PE programs. Developer just drag the PE application into Virbox Protector GUI tools, then Virbox Protector will parse the PE application automatically. All of information to PE application will be parsed and shown in the "**Basic Info**" tab.

Then, Developer may set the protection feature in "**Protection Option**" and "**Functions Option**" tabs:

<figure><img src="/files/7mBrqaX66muLKhg9es3t" alt=""><figcaption></figcaption></figure>

### Virbox Protector CLI tool

Developer also may use `virboxprotector_con.exe`, the Virbox Protector CLI tool to protect your PE apps.

<figure><img src="/files/BMQw0bLyKfQd4AJmHgcR" alt=""><figcaption></figcaption></figure>

### General protection to Native applications

#### **Setting the configuration in "Protection Option" tab**

General Protection, refers to protect the project/application in overall, which accomplished by setting the configuration in "Protection Option" tab. With the general protection setting to the application, only minimize negative impact to protected application's performance and easy to set, with anti decompiling, anti tampering and anti debug functionality.

#### \*\*Protection Option \*\*

| Feature                          | Setting                                                                                                                                                                                                                                                                                                                                                                                                                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Compression                      | Click ✔️ to select in GUI tool; Enable this option in CLI tool by specify the argument “pack" with value "1" " --pack=1" More detail info refer the user manual: CLI tool                                                                                                                                                                                                                                                    | Compression makes it is possible to pack, compress and encrypt the application's code and related format setting and data (import table, relocation information and part of resource information etc). and then replace the application entry point with packer coding, when the protected application executed, the packer code will decrypt the encrypted code and data, and then jump to original application's entry point (OEP) to execute. With the Compression protection to the applications, it encrypt all of code section and data section (it doesn't encrypt the writable data part for ELF file), to prevent the applications being decompiling and de-assembling. |
| Memory Check                     | Click ✔️ to select in GUI tool; Enable this option in CLI tool by specify argument "mem-check" with value "1", "--mem-check=1"; More detail info refer the user manual: CLI tool                                                                                                                                                                                                                                             | Memory Check, to check the application's integrity when load the applications, to prevent application from being tampering, when tampering has been detected, the program will quit execution. For memory check dynamically in runtime, use the "SDK label" to set and called in coding.                                                                                                                                                                                                                                                                                                                                                                                         |
| Import table protection          | Click ✔️ to select in GUI tool; Enable this option in CLI tool by specify argument "imp-protect" with value "1" " --imp-protect=1" More detail info refer the user manual: CLI tool                                                                                                                                                                                                                                          | Import table describes the dependence libs, functions and IAT (Import address table), Hacker may easily view the code logic from import table, With the Import table protection feature, it encrypts the import table, which to prevent the PE file being unpacked and prevent the hacker to view "API reference". See attached The comparison of Import table Protection: Before/after Protection.                                                                                                                                                                                                                                                                              |
| Resource Section Encryption      | Click ✔️ to select in GUI tool; Enable this option in CLI tool by specify argument "-res-sect-enc"with value "1" " --res-sect-enc=1" More detail info refer the user manual: CLI tool;                                                                                                                                                                                                                                       | The PE application can be embedded with the resources, which store the GUI layout, icon, multilingual string, developer may also embedded some of sensitive data into the application with the type of "resource", The resource located at the "Resource section" of applications (.rsrc section), it is easy to be extracted and tampering. Resource Section Encryption refers the encryption of the PE resource section (.rsrc) to prevent resource data/info being cracked & extracted.                                                                                                                                                                                       |
| Overlay data encryption          | Click ✔️ to select in GUI tool if overlay data existed Enable this option in CLI tool by specify argument "overlay-enc" with value "1" " --overlay-enc=1" More detail info refer the user manual: CLI tool;                                                                                                                                                                                                                  | Some of archive/Packer tool, such as Audio, video or PPT player, will generate the overlay data (audio/video or database, dbf file) attached, so it is necessary to encrypt the overlay data to prevent these resources (data, video) from extracted or leakage                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Debugging detection (Anti Debug) | <p>Select and enable the "Debugging detection" feature to one module for each process only, for example to enable debugging detection to main .exe program only)<br>\*: If the module be used to be the SDK which released to third party program to call. then please DO Not to enable this debugging detection feature. Enable debugging detection feature in CLI tool by specify argument "detect-dbg" with value "1"</p> | To detect the debug tool (such as: x64dbg, OllyDbg, IDA Pro, Windbg etc, the protected PE program will exit execution when debugging being detected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Remove debug information         | <p>Recommend to select and enable this feature (Remove the debug information<br>If developer need to keep and reserve these debug information, pls be awared use the command line option <code>-strip</code> to remove the debug information before publish and formal released </p>                                                                                                                                         | For ELF file, to some cases, it may contains the debug section, static symbol table, which contains function name, function address etc, it will decrease security when version released, Use "strip" option to remove these "debug information" (remove debug section and static symbol table).                                                                                                                                                                                                                                                                                                                                                                                 |
| Virtual Machine Detection        | Detect if application executed in the "VMware", "Virtual Box" environment                                                                                                                                                                                                                                                                                                                                                    | When VM environment has been detected, the protected application will quit execution.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

For those developer use Virbox Protector GUI tool and only need to protect Native applications in general and no special security requirement to protect critical functions/methods, it is quite easy for developer to set and modify "Protection Option" tab (Virbox Protector GUI tool) to accomplish general protection to prevent decompiling and memory dump. and no additional complicate configuration setting required.

For Developer use The Virbox Protector CLI tool, they can specify the argument to complete general protection to native language project also. Following protection option setting can be referred and used when developer use the Virbox Protector GUI tool:

#### **General protection setting in Virbox Protector GUI tool as shown in below**:

Just click to select each options.

* The Features in the "Protection Option" is mainly used to prevent the attacker/cracker dynamic analysis: Memory check, Debugger Detection, VM detection etc.

<figure><img src="/files/JDpaMpEuyqAwx6LzYoeL" alt=""><figcaption></figcaption></figure>

#### General protection setting in Virbox Protector CLI tool as shown in below:

First you can find CLI help in general:

```
virboxprotector_con --help
```

<figure><img src="/files/q54hfe75MrpbLWE5m4vE" alt=""><figcaption></figcaption></figure>

and then you can find help to protect the specific type of application by specify type: "=java" or other types

```
virboxprotector_con --help=java
```

<figure><img src="/files/cCRh0rbQ8nT8b1WaRg8k" alt=""><figcaption></figcaption></figure>

Find CLI help for native application by:

```
virboxprotector_con --help=native
```

you can find argument setting in below:

<figure><img src="/files/xQkaENoczE8vmCdcvj4A" alt=""><figcaption></figcaption></figure>

* Resource Section:

<figure><img src="/files/yrFACFVyQ03pPr0H8OhP" alt=""><figcaption></figcaption></figure>

#### Protection Comparison: Before and After

**Import Table (PE):**

Original Import table:

<figure><img src="/files/Geix3D17WCVNGzHGKpBW" alt=""><figcaption></figcaption></figure>

!\[img]\(Best Practice\_Protect Native.assets/imp.png)

**Decompile the Import Table (Before Protection)**

<figure><img src="/files/FuvFbEQmorV5ILfq0wWQ" alt=""><figcaption></figcaption></figure>

**Decompile the Import Table (After Protection)**

Note: With the protection to the Import Table, the original import table has been deleted, the calling among the modules replace with packer code.

<figure><img src="/files/OX2CURSwjEG2Fv6a7uTZ" alt=""><figcaption></figcaption></figure>

### Protect the native application which require highly security

### -- "Functions Option" Setting

**Protect the critical Functions/method, fragment of code in fine grain level**

Besides of general protection to native applications introduced above, Virbox protector supports developer to specify and protect those critical functions/method, critical code logic with multi level of obfuscation technology. which can be combined & implemented with **general protection**, to enhance security level of protected native project to prevent from de-assembling, decompiling.

In some cases, the developer intent to design a highly security protection scheme to native applications. such as to protect the license (key) for authentication, encrypt those critical/important algorithm, the process of protocal encapsulation, client/server authentication, those critical code logic,

Then it is recommend to set the **Function Option** tab to protect those functions/methods with fine-grained protection and highly security , developer will have multiple options to select and protect to those functions/algorithms:

**Code of Encryption**,

**Code of Obfuscation**,

**Code of Virtualization**,

or **No protection** etc.

Stand from the cracker point of view, the most of critical steps in the decompiling process is locating the the position of sensitive code or string from the thousands of code project. which to get critical code logic, credentials (such as "key", "password") via reverse engineering or modify the code logic to crack the whole project. For example, to analysis protocal, usually, the cracker only require to reverse engineering the communication protocal, encryption/decryption or signing algorithm, and then to crack the protocal and no need to modify the all of programs (which used to create the game cheating program, Unauthorized plugin or fake player and game mod). As to crack or piracy the program functionality, usually, it is necessary to modify/patch/tamper the authentication mechanism (logic) to original program, or edit the authentication data (key)

| Feature                     | Setting                                                     | Description                                  |
| --------------------------- | ----------------------------------------------------------- | -------------------------------------------- |
| \[E] Code of Encryption     | Use "On default" setting (encrypt the entry functions only) | To Encrypt the specified functions.          |
| \[M] Code of Obfuscation    | No need to select to protect the functions                  | To obfuscate the selectd functions/methods   |
| \[V] Code of Virtualization | No need to select to protect the functions                  | To virtualise the selected functions/methods |

Virbox Protector GUI/CLI tool

Developer may free to use GUI/CLI tool to protect the "functions/methods or code logic", ( For CLI tool, which require developer has basic security knownledge accordingly).

#### Function Option introduction

**Code of Encryption**

Code of Encryption implemented via self-modifying code (SMC), which decrypts itself when the function is called, and then jumps to the correct function instruction for execution. It can prevent the code from being encrypted and execute the original instruction at runtime, so there is almost no performance impact, and it can prevent unpacking and static analysis and decompilation.

Functions Protected by Code of Encryption: Before Protection:

<figure><img src="/files/WIbHcgg1drFFsWbfQzEj" alt=""><figcaption></figcaption></figure>

Functions Protected by Code of Encryption: After Protection:

<figure><img src="/files/eWviZwvfH5xQFYvgvoMQ" alt=""><figcaption></figcaption></figure>

**Code of Obfuscation**

Codes of Obfuscation, is the transformation process of making applications difficult or impossible to decompile and reverse. and the retrieved and reversed instruction are more difficult for humans to recognize and parse. Code Obfuscation normally be used to protect the algorithm, functions, methods, which significantly to increase the difficulty of understanding or modifying an assembly code..

Following techniques will be used:

Renaming of class/functions/method/variables, equivalent transformation, immediate encryption, dummy code insertion, instruction pattern transformation, false branch, string encryption, etc.

Code of Obfuscation may bring part of negative impact to the application's performance in execution, and most frequently be used to protect:

* Critical code logic, and relate functions/method called;
* Entrance and characteristic of cryptography library functions (such as AES S-box, ECC curve etc);
* Protocol encapsulation process;
* Critical function's boundaries;

The purpose & applied for

* To prevent the protected function being decompile and readable which to increase the difficulty of parsing/reverse engineering
* It can not be retrieved to original instruction, to prevent static and dynamic analysis and debugging
* Functions is broken down to random instructions blocks and destroy the function boundary;
* Transforms memory accesses and jump instructions, breaking cross-reference analysis by decompiler. Makes functions without instruction traits, preventing them from being targeted by traits.
* Obfuscated instructions contain stubs that detect debugger Run Trace traces.

Functions Protected by Code of Obfuscation: Before Protection:

<figure><img src="/files/hq4WAdYnnekpqYU5WpnV" alt=""><figcaption></figcaption></figure>

Functions Protected by Code of Obfuscation: After Protection:

<figure><img src="/files/SgYLShVDMJ4KKLuJImue" alt=""><figcaption></figcaption></figure>

**Code of Virtualization**

Code of Virtualization is the process to convert the instruction sets in the assembly into the random and unique instruction sets generated which only can executed into the Virtual Machine self-defined. This makes the code of a protected algorithm completely bullet-proof and hidden from others. All you need to conceal your precious logic is to apply a special attribute to your methods or classes, you only require to select those function/method and set the protection attribute as "Virtualization"

<figure><img src="/files/IrpvlShZqJmjhvyTjK9N" alt=""><figcaption></figcaption></figure>

!\[img]\(Best Practice\_Protect Native.assets/convert.png)

It will cause negative impact to execution performance of program, so pls do not select "Code virtualization" in large scale, only use it to protect those most of important and critical functions, methods or variable, such as:

* The critical algorithm need to protect;
* the vairiable/functions which probably be tampered (scuh as authentication logic, etc.)

The functions,method protected by use of "Code of Virtualization"

Before Protection

<figure><img src="/files/LmAGfFnvjASIAOSyLgxe" alt=""><figcaption></figcaption></figure>

After Protection

<figure><img src="/files/rBjdFaFvQZr6WVfBVDuG" alt=""><figcaption></figcaption></figure>

**The Security:**

Virtualization>Obfuscation>Encryption

**The Performance impact to application execution**

Virtualization>Obfuscation>Encryption

so, beware to use the "Code of Virtualization" to protect the function/method, only select those critical and important function to protect with "Virtualization".

#### SDK Label  to Protect critical code section/functions

Virbox Protector also support developer to set and mark a label to the specific code section, which can be precisely to insert the label and protect these code of section. developer also may use the SDK Label function to protect the data or check and verify the memory integrity.

SDK Label support to be integrated and calling by C/C++ program language. you can find the SDK label sample in the `<install_dir>/example/sdk` which under the installation directory of Virbox Protector.

**Use SDK label to Protect Data, String, Credetial**&#x20;

If the project code contains sensitive string, data, credential, key, certificates, etc, it is recommend to protect these sensitive data by use of SDK label. Developer may use SDK label to set a mark to these data, string, when set the mark to these sensitive string or data, Virbox protector will automatically recognize these label, so, every time when developer use Virbox protector to start the protection process, a random encryption key will be generated which makes and guarantee the encryption result is different.

**Memory Check**

The "Memory Check" feature (Protection Option tab), when you click and select this feature, it will execute the check the memory when application start to execute. consider the attacker may crack the protected application with take the way to skip the detection with the way of dynamic memory patch. so it is recommend developer may also check the memory by use of the SDK lable to call `VBProtectVerifyImage`. and mix the memory check with your code logic together which enhance the memory security.

### Plugin: DSProtector

Virbox protector provide plunin, DSProtector, both GUI tool and CLI tool for developer to protect/encrypt the relevant read only file, such as scripting file, audio/video, image, configuration file, database etc. to prevent these sensitive file from being cracked.

More detail please refer the DSProtector, User Manual.

### Tips to publish the release version

* For the application public released in windows system, pls exclude the symbol table files （.pdb/.map
* For the application in Linux/Android environment, It's mandatory to remove the symbol table (click to select to remove the dbg information)

## Automatic Integration

### Use Virbox Protector CLI tool to integrate to build project

The on default path of CLI tool of`Virbox Protector`: `virboxprotector_con` located at:

```
Windows:
C:\Program Files\senseshield\Virbox Protector 3\bin

Linux:
/usr/share/virboxprotector/bin

macOS:
/Applications/Virbox Protector 3.app/Contents/MacOS/bin
```

###

### Use the configuration file to integrate to build project

There are 2 ways to use Virbox Protector CLI tools to build your project:

With the protection configuration file or Without protection configuration file

### Login license

`virboxprotector_con <file_name> -global --username=<user_name> --password= -o <output_filename>`

#### With Configuration file to integrate and build your project\*\*

Use the Virbox Protector GUI tool to generate the configuration file first and then use the CLI tool to protect your project WITH the configuration generated previously.

For how to generate the configuration file by use of Virbox GUI, the process is similar to the process to protect the project. More details, pls refer to relate the section of Quick Start Guide to Virbox Protector GUI tool.

then, you can find the .ssp file in: \protected, the sub directory in the output path. then call the CLI tool:

virboxprotector\_con.exe with following syntax:

```
virboxprotector_con <input_file> -o <output_file>
```

`virboxprotector_con` will automatically to search the \<input\_file>.ssp which to be the configuration file to start the protection.

#### Without Configuration file to integrate and build your project

​ Use Virbox Protector CLI to protect your project without configuration file (.ssp file)

**Use and set the option/argument to Virbox Protector CLI tool to protect your project.**

for those developer has rich experience in Virbox Protector protection process, they can use Virbox Protector CLI tool with specified option/argument to protect their project directly.

**If no additional option/argument pass in the CLI tool: virboxprotector\_con**

then it will use the option/argument on default to protect the project. for on default option/argument setting, pls refer CLI user manual. or refer following protection option setting in below

**Developer also can use a SDK label to mark those critical function/method, then protect the project.**

### Use Command Line Interface to protect Native program projects: Protection Option Setting:

#### **Protection Option**

**PE**

| Protection Option        | CLI Argument      | On default value settng |
| ------------------------ | ----------------- | ----------------------- |
| Compression              | `--pack=`         | `1`                     |
| Memory Check             | `--mem-check=`    | `1`                     |
| Protect Import Table     | `--imp-protect=`  | `1`                     |
| Encrypt Resource Section | `--res-sect-enc=` | `1`                     |
| Overlay data Encryption  | `--overlay-enc=`  | `1`                     |
| Debugging Detection      | `--detect-dbg=`   | `0`                     |
| VM Detection             | `--detect-vm=`    | `0`                     |

**ELF**

| Protection Option   | CLI Argument Setting | On default value |
| ------------------- | -------------------- | ---------------- |
| Compression         | `--pack=`            | `1`              |
| Memory Check        | `--mem-check=`       | `1`              |
| Debugging Detection | `--detect-dbg=`      | `0`              |
| Remove symbol table | `--strip-dbginfo=`   | `1`              |

**MachO**

| Protection Option   | CLI Argument Setting | On default Value |
| ------------------- | -------------------- | ---------------- |
| Memo Check          | `--mem-check=`       | `1`              |
| Debugging Detection | `--detect-dbg=`      | `0`              |

#### Function Option (Protect function/method)

| Protection Option                        | CLI Argument                   |
| ---------------------------------------- | ------------------------------ |
| Ignore the unsupported functions/methods | `--ignore-unsupported=<value>` |
| Code of Encryption                       | `-e`                           |
| Code of Obfuscation                      | `-m`                           |
| Code of Virtualization                   | `-v`                           |

Virbox protector supports developer to specify the function/method name or use "rule" to protect native language projects, which to protect the critical functions/method with different kind of protection options: Code of **E**ncryption, Code of obfuscation (**M**utation) and Code of **V**irtualization.

Use the semicolon: `;` to separate functions, support to use wild card: `*`

Sample:

`-m "function1;function2" -v "function3;function4" -e "test*" --ignore-unsupported=1`

#### **CLI Sample**

Protect the main program in Windows system：

```shell
virboxprotector_con test.exe --pack=1 --imp-protect=1 --mem-check=1 --res-sec-enc=1 --detect-dbg=1 -o protected/test.exe
```

Protect the linux programs：

```shell
virboxprotector_con libhello.so --pack=1 --mem-check=1 --detect-dbg=0 -o protected/libhello.so
```

Protect Linux program (remain the symbol table and generate the release version)：

```shell
#Generate the version release which contains symbol table for futher analysis.
virboxprotector_con libhello.so --pack=1 --mem-check=1 --strip-dbginfo=0 -o protected/libhello_with_sym.so

#Remove (strip) symbol table to release & publish
virboxprotector_con -strip protected/libhello_with_sym.so -o protected/libhello.so
```

Protect macOS application:

```shell
virboxprotector_con libtest.dylib --detect-dbg=1 --mem-check=1 -e "*" -o protected/libtest.dylib
```

## Appendix: The tools to evaluate security performance

### Prerequisation

1. Deassembling/Decompiling) tools ready and developer familiar the basic using and decompiling process. which can be used and evaluated the protection performance.
2. The correspondence symbol file in the source code program:

   Please keep the .pdb/.map file in the source code program before compiling for windows platform;

   For linux platform, when developer compile and build the project, please keep the symbol table: compiling option add: `-g`

   No symbol file required to kept when developer use the SDK label to mark the functions (Fragment of code)need to be protected.

### Recommend Static Analysis tool (decompiler) used:

* IDA Pro (Paid version required): latest version is 8.2 IDA Pro
* <https://hex-rays.com/ida-pro/>

  Ghidra (Free & Open source) \[Releases · NationalSecurityAgency/ghidra (github.com)]\(


# Protect Jar/War Project with Java BCE Protection Mode

## Introduction

**Virbox Protector Standalone** support to protect the Java projects, include Jar, War archives and class file and related data resource.

Virbox Protector supports developer to protect Java projects with 2 kinds of protection mode: **Java VME** and **Java BCE** (2 different kind of Virbox Protector license required), developer may either select the BCE Mode or VME mode or combine using both modes together to protect your Java project, depends on your security requirement:

​​ --With Virbox Java **VME protection mode**, The bytecode of the Java's method will be transformed into self-defined bytecode which executed in Java Virtual Machine environment. With Virtualization  protection, all of bytecode executed in the JVM will be convert into the instructions executed in private VM, and provides most secured environment for Java project's execution and effective to defend the retrieving and cracking by latest decompiler available in the market. Java VME is suitable for the developer who require to protect their IP/code with highly security.

​ When developer use the Virbox Protector **VME mode** to protect your Java Projects, developer may **drag your JAR Archives or WAR Archives** into Virbox Protector GUI tools and click to select those functions which you want to protect/encrypt, select the "Protection Mode" to be the "Virtualization", and then click the "Button" of "Protect Selected Project". then the JAR or WAR archives will be protected by Java VME mode.

​

​ --With Virbox Java **BCE protection mode**, The bytecode of each method of Java class file will be protected and encrypted, the bytecode will be only decrypted in execution; the execution and decryption rely on relevant java agent.

​ When developer use the Virbox Protector BCE Mode to protect your Java Project, developer may drag **the Folder which contain the JAR or WAR archives** into the Virbox Protector GUI tools, click to "Protect Selected Projects" to protect your JAR or WAR projects, after the protection completed, the Encrypted JAR, WAR archives and sjt\_agent.jar will be generated.

​ Java BCE mode Doesn't support following scenario:

1. The JAR or WAR file which protected by Java BCE mode doesn't support the referenced/called by other projects
2. Compile the protected JAR archives into the exe file to execute;

If developer want to protect/encrypt above 2 scenarios JAR or WAR project, you may select the Java VME mode to protect your Java Project.

**The Difference Between Java VME and Java BCE**

1. The Encryption technology is different:

   With VME mode, it supports to protect/encrypt the Java Method with Virtualization mode,

   With the Java BCE Mode, it supports to protect/encrypt the Java bytecode of each method of Java class file, when executed, the encrypted bytecode will be decrypted dynamically in Java agent.
2. The execution is different:

   With VME protection mode, the execution of protected JAR/WAR archive is same as previous unprotected JAR archives;

   With BCE protection mode, the execution of protect JAR/WAR archives need to rely on the sjt\_agent.jar;
3. The Encryption Operation is different:

   With Java VME protection, developer may drag and encrypt the JAR archive directly;

   With Java BCE protection, developer need to put the JAR/WAR into a folder and drag a whole Java folder to protect it.
4. With VME Protection mode, The Encrypted JAR or WAR archives supports the referenced by other projects; and not supported with BCE protection mode;

   With VME Protection modes, The encrypted JAR or WAR archives support to be compiled to be execution file to execute directly. and not for the encrypted JAR or WAR archives by BCE mode

Virbox Protector Standalone supports to protect Java application (Jar, War, or Java SDK both in GUI tool and CLI tool.

## Protection sample & Environment

Here we use Virbox Protector Standalone GUI tools to show the protection process with BCE protection mode, and also introduce the protection process by use of Virbox Protection CLI mode. Developer may freely to select Virbox Protector GUI or CLI tool to protect their Java project with BCE mode.

**A Folder which contained the Jar archive** has been used as a sample to show the whole protection process step by step; and the protection process to **War Archive** is same as Jar Project process. Developer may refer the Jar Protection process to protect War Project for test and evaluation also.

the Operation environment is windows.

The version of Virbox Protector GUI tools is 2.5.0 trial edition.

## Protect your Jar project with BCE mode in 5 steps

1. Import the Jar/War project: Drag the **whole** **jar/war** **folder** into the Virbox Protector GUI tools;
2. Select The Jar file to be protected in the "Java Files" tab; and Set output path in the "Protection Option" tab;
3. Click "Protect Selected Projects" to start Protection process to the Java Project;
4. Backup the source Jar/War project, rename and use the protected project to source file name and save the configuration files etc.
5. Deployment and execution

## Prerequisites

Sign-up Virbox Protector website to apply a trial license and install the Virbox Protector;

execute Virbox Protector (virboxprotector.exe) and sign in your account with your trial license

{% hint style="info" %}
Above pre-requisition is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector BCE license.
{% endhint %}

## Protection Process

### 1. Import the JAR Folder into the Virbox Protector GUI tool:

Open the Virbox protector GUI tool and *login* to your account, drag the whole folder of JAR or WAR Project located into the Virbox Protector, in the sample case, the Jar Folder name is "Jar Folder", the Jar file we used is: demo-0.0.1-Snapshot.jar; as shown as the snapshot below: and show JAR file information in the "Basic info" tabs, shown as snapshot below:

![](/files/gWnrvdOJFgUbqj8hgTDP)

{% hint style="info" %}
The difference to use Virbox Protector BCE mode and VME mode in Operation is:

With BCE mode, **Drag whole folder of Jar Project** into Virbox Protector.

With VME mode, **Drag the Jar project** to Virbox Protector, not drag whole folder.
{% endhint %}

### 2. Select The JAR file to be protected in the "Java Files" tab; and Set output path in the "Protection Option" tab;

Go to "Java Files"tabs, Developer may Select those Jar/War file via *Jar Files tab* for those Java files which need to be protected:

Click "*Select Files* "Button" to select the JAR file which you want to protect;&#x20;

{% hint style="info" %}
use *Ctrl+A* to select all Jar file (execution performance may impact if you select all of Jar file to be protected),
{% endhint %}

Password for Java File: you can set and input the password to protected Java file, suggest to set the password, and keep the password, so, when the Java file update later, you can use consistent password to encrypt the Java file, and it is not require to update the sjt agent file: `sjt_agent.jar`

Then click *OK* button on the bottom to complete selection and protection setting.

![](/files/UL4KiIfrSPBgIyUEXB92)

Now, Go to the Protection Option tabs, and Set output path: the on default output is same directory which Jar file located.

![](/files/FCqVEoWE2mWqLcvEQnR2)

### 3. Click "Protect Selected Projects" to start Protection process to the Java Project;

Click "Protect selected Project" to start protection; as shown as below:

![](/files/YZ2I3Gpk0QfcBHfunKCo)

Then go to the output folder, you will find a news file and new folder has been generated, as the the sample show as below:

![](/files/ve5j8rgG21kTmWtNuPBv)

The new file which name *"Jar Folder.ssp*", is the configuration file which stored the protection option setting.

The new file folder which name "*Jar Folder Protected*", is the protected Jar Folder; you can find following files contained in this folder:

`demo-0.0.1.SNAPSHOT.jar`: Protected Jar project;

`sjt_agent.jar`: the jar agent file which will be used in future deployment;

`readme.txt`: a instruction file to deployment.

![](/files/F3Ocrjwuf9MrdFZMuoVV)

### 4. Backup the source Jar/War project,  use the protected project to further testing and save the configuration files etc.

Then, don't publish the original Jar file. located in "Jar Folder",

Use the protected Jar project located in the "Jar Folder Protected" to further deployment testing. It is not necessary to distribute the configuration file: Jar Folder.ssp, to your enduser. please keep it, if you use Virbox Protector CLI tool to protect your Java projects, it is useful configuration file when you use Virbox Protector CLI tool later.

In General, With Virbox Protector, with this Quick Start Guide, Developer may quickly to go through whole protection process to protect Jar application. for more details instruction, developer may take refer from the User Manual-Virbox Protector Standalone, or contact us directly.

The War Project Protection process with BCE mode is same as Jar Project's protection process.

### 5. Deployment and execution

The deployment of Jar/War Project protected with Java BCE mode is different from the deployment of Jar project with VME protection. the Jar project deployment and execution depends on the Java agent.

#### 5.1. JAR Deployment

Developer need to specify the `sjt_agent.jar` file path and location when execute the JAR Archives;

**Windows Environment**

Specify the sjt file location/path when execute the protected Jar archive

If sjt library and the Jar archive are located in the same directly, you can execute the following command in the current Jar archive's directory.

`java -javaagent:sjt_agent.jar-jar ***`*`.jar`*

If sjt library and jar archive is not in the same directly, you need to assign the *absolute* directory.

`java -javaagent:C:\Users\test\Desktop\sjt\sjt_agent.jar -jar ***`*`.jar`*

**Linux Environment**

Developer need to specify the sjt\_agent.jar file path and location when execute the JAR Archives;

If the sjt library located in the same directory with Jar archive, you can excute the following command in the current directory:

`java -javaagent:sjt_agent.jar -jar ***`*`.jar`*

If the sjt library is not in the same directory with the jar archive, you need to assign the *absolute* directory:

`java -javaagent:/home/sense/Desktop/sjt_so/sjt_agent.jar -jar ***`*`.jar`*

**macOS Environment**

Developer need to specify the sjt\_agent.jar file path and location when execute the JAR Archives;

If the sjt library located in the same directory with Jar archive, you can execute the following command in the current directory:

`java -javaagent:sjt_agent.jar -jar ***`*`.jar`*

If the sjt library is not in the same directory with the jar archive, you need to specify the absolute directory:

`java -javaagent:/Users/sense/sjt/sjt_agent.jar -jar ***`*`.jar`*

#### 5.2. WAR deployment

**Windows Environment**

There will be 3 scenario to configure the system environment, you can select one of them which depends on your WAR project:

1. Set *setenv.bat* under the *tomcat* directory

Create the *setenv.bat* in the *tomcat\bin* directory, for example:

a) Create “*setenv.bat*” in the *tomcat\bin* directory, set the environment variable: (absolutely path):

​ `set CATALINA_OPTS=%CATALINA_OPTS% -javaagent:sjt_agent.jar`

![](/files/tRfODNnNBGBXvVLZWApn)

b) Put the encrypted "WAR archive" into the location: *.\apache-tomcat\webapps* and start the tomcat service.

2\. Start the tomcat when system service started

a) First you need to uninstall the tomcat service, use the console command:&#x20;

`service.bat uninstall`&#x20;

to uninsall tomcat service;

![](/files/LbF6hib1auLxWksMi6v7)

b) Add the *sjt\_agent.jar* in the parameter of *JvmOptions* in the *service.bat*, as shown as snapshot below:

![](/files/aaicpzEAowcGxlJ7oGVD)

​ c) Then use the command: *`service.bat.install`* in the console windows to install:

![](/files/z7ZruMUACSw6INxVUcoT)

​ d) then start "tomcat" service in the system service;

​ e) put the protected "War archive" into the folder of "*.*`**\apache-tomcat\webapps`, then start tomcat service.

*3.* Start service when you using tomcat9.exe

a) First step is to start the tomcat9w\.exe

b) add the *sjt lib* in the Java Options list, as shown in the snapshot below:

![](/files/MkpPDDchhF0IwV8G4MJW)

​ c) Execute tomcat9.exe to start tomcat service and put the protected war archive into the folder *`.\apache-tomcawebapps`*, then start the tomcat service.

**Linux Environment**

***Set Setenv.sh*** in the tomcat directory:

a) Create a new *setenv.sh* in the *tomcat\bin* directory, the absolute path environment variable can be set as follows:

*`CATALINA_OPTS="$CATALINA_OPTS -javaagent:sjt_agent.jar`*

*as shown below:*

![](/files/sVp0A5dqjHC4JvYmJO9k)

b) Start tomcat service, you can view the *`CATALINA_OPTS`* \***parameter\*** be set

![](/files/IzGHs7mv7cNnB43JbCox)

c) Put the encrypted WAR archive in the directory: .*\apache-tomcat\webapps*

If the War archive can be parsed correctly, the webpage can run correctly.

{% hint style="info" %}
If you have configured the environment variable, the default system environment for Java execution will use the environment variable you have set, even you have assigned the \***sjt\*** library location.
{% endhint %}

**macOS Environment**

a) Create a new `setenv.sh` in the tomcat\bin directory, the full path environment variable can be set as follows:

*`CATALINA_OPTS="$CATALINA_OPTS -javaagent:/Users/sense/sjt/sjt_agent.jar`*

b) Start tomcat system service, you can view the parameter of *`CATALINA_OPTS`* set

c) Put the encrypted war archive in the directory: *`.\apache-tomcat\webapps`*

If the War archive can be parsed correctly, the webpage can run correctly.


# Protect Jar/War Project with Java VME Protection Mode

## Introduction

**Virbox Protector Standalone** support to protect the Java applications, include Jar, War archives and class file and related data resource.

Virbox Protector supports developer to protect Java project with 2 kinds of protection mode: **Java VME** and **Java BCE** (2 different kind of Virbox Protector license required)

​

​ --With Virbox Java **VME protection mode**, The bytecode of the Java's method will be transformed into self-defined bytecode which executed in Java Virtual Machine environment, with Virtualization, all of bytecode executed in the JVM will be convert into the instructions executed in private VM, and provides most secured environment for Java project's execution and effective to defend the retrieving and cracking by latest decompiler available in the market. Java VME is suitable for the developer who require to protect their IP/code with highly security.

​ When developer use the Virbox Protector **VME mode** to protect your Java Projects, developer may **drag your JAR Archives or WAR Archives** into Virbox Protector GUI tools and click to select those functions which you want to protect/encrypt, select the "Protection Mode" to be the "Virtualization", and then click the "Button" of "Protect Selected Project". then the JAR or WAR archives will be protected by Java VME mode.

​

​ --With Virbox Java **BCE protection mode**, The bytecode of each method of Java class file will be protected and encrypted, the bytecode will be only decrypted in execution; the execution and decryption rely on relevant java agent.

​ When developer use the Virbox Protector BCE Mode to protect your Java Project, developer may drag **the Folder which contain the JAR or WAR archives** into the Virbox Protector GUI tools, click to "Protect Selected Projects" to protect your JAR or WAR projects, after the protection completed, the Encrypted JAR, WAR archives and sjt\_agent.jar will be generated.

{% hint style="info" %}
Java VME mode doesn't support following scenario:
{% endhint %}

1. Java VME mode doesn't support to protect the embeded JAR or WAR project;
2. For those JAR archive which use the springframeworks, it doesn't support to protect the .class file which located in the `org/springframework/boot/loader`, it support to protect the kernel .class file only (for example, to protect the .class file located in `BOOT-INF/classes`。
3. The method doesn't support to be protected with virtualization includes: Java Constructor, Destructor and and the method which used the Reflection.

if developer want to protect/encrypt above 2 scenarios JAR or WAR project, you may select the Java VME mode to protect your Java Project.

**The Difference Between Java VME and Java BCE**

1. The Encryption technology is different:

   With VME mode, it supports to protect/encrypt the Java Method with Virtualization mode,

   With the Java BCE Mode, it supports to protect/encrypt the Java bytecode of each method of Java class file, when executed, the encrypted bytecode will be decrypted dynamically in Java agent.
2. The execution is different:

   With VME protection mode, the execution of protected JAR/WAR archive is same as previous unprotected JAR archives;

   With BCE protection mode, the execution of protect JAR/WAR archives need to rely on the sjt\_agent.jar;
3. The Encryption Operation is different:

   With Java VME protection, developer may drag and encrypt the JAR archive directly;

   With Java BCE protection, developer need to put the JAR/WAR into a folder and drag a whole Java folder to protect it.
4. With VME Protection mode, The Encrypted JAR or WAR archives supports the referenced by other projects; and not supported with BCE protection mode;

   With VME Protection modes, The encrypted JAR or WAR archives support to be compiled to be execution file to execute directly. and not for the encrypted JAR or WAR archives by BCE mode

Virbox Protector Standalone supports to protect Java application (Jar, War, or Java SDK both in GUI tool and CLI tool.

## Protection Sample & Environment

Here we use Virbox Protector Standalone GUI tools to show the protection process, and also introduce the protection process by use of Virbox Protection CLI tool. Developer may freely to select Virbox Protector GUI or CLI tool to protect their Java project with VME mode.

**A Jar archive** used as a sample to show the whole protection process step by step; and the protection process to **War Archive** is same as Jar Project process. Developer may refer the Jar Protection process to protect War Project for test and evaluation also.

the Operation environment is windows.

The version of Virbox Protector GUI tools is 2.5.0 trial edition.

## Protect your Jar project in 5 steps

1. Import the Jar/War project: drag the JAR/WAR Archives into the Virbox Protector directly;
2. Set the configuration of "Function Options": Protect the Jar/War functions (methods) with "Virtualization";
3. Set the configuration of "Protection Options", Protect the jar/war in general:
4. Click to start "Protection" Process;
5. Backup the source Jar/War project,  and save the configuration files etc.

   Note: Use SDK Label to mark specified functions(method) before protect the method

## Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Open Virbox Protector and [sign in](/download/sign-in-and-sign-out#sign-in-1) with your account;

Above pre-requisition is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.

![](/files/sN7uwyNqERglVOUnmnw1)

## Protection Process

### 1. Import the Jar Project into the Virbox Protector:

Drag the Jar project into Virbox Protector, Then Virbox protector will parse the Jar sample automatically. and show Jar file information in the "Basic info" tabs, shown as snapshot below:

<div align="center"><img src="/files/yoySFoZ8SxVgzcej1YA4" alt=""></div>

### 2. Set the configuration of "Function Options": Protect the Jar/War functions (methods) with "Virtualization";

2,1 Go to "Function option" tab and click "**Add Functions**", click the functions (method) shown in the "Add Function" box, Virbox Protector will show more functions and list;

<div align="center"><img src="/files/QVgbmL1Ivy15EhJVtPny" alt=""></div>

​ 2.2 Select the function which you want to protect: Virbox Protector support to protect the function with "Virtualization";

​ 2.3 Click the "OK" to finalize the "Function Option" Setting, then go to "Protection Option" tab;

{% hint style="info" %}
2.4.1 Ctrl+A to select all functions, and right click, to select the protect mode, then you can quickly select all of functions with same protection mode: Virtualization.

2.4.2 Considering the program execution performance may impact, so we don't suggest to protect all of Java Functions (methods) with "Virutalization", instead of to select those key and important functions(Methods) to protect with "Virtualization" only.
{% endhint %}

### 3. Set the configuration of "Protection Options", Protect the Jar/War in general:

Developer may set and define following factors in the "Protection Option" tabs

Output Info: Set output path and protected Java filename, as shown in the "box " marked with blue frame, the on default output path is same directory of source Jar file located.

the rest of thing will be setting and protecting by Virbox Protector automatically.

![](/files/M2ZXdP8vvopgGOMZD8F9)

**Advanced Protection to Process plugin: RASP plugin**

**RASP**: Runtime Application Self Protection: this plugin focus to protect the process running in the kernal for the application in windows platform, when this plugin start to execute, it will load the driver integrated to protect process itself to prevent the third party  plugin  to skip the normal anti debugging protection from debugging in memory. It is also effective to defense the "Cheat Engine" to scan the memory which running the process.&#x20;

**RASP** plugin are most effective functions and applied to those scenario which highly security required. additional license from Virbox required.

{% hint style="info" %}
Optional feature and license required to activate this feature
{% endhint %}

There are 3 features can be select in the "Advanced Process Protection" plugin:

* Memory Protection:&#x20;

Click to protect the memory information executed for windows application; which to prevent the attacker/hacker to scan  the process memory by use of "Cheat Engine" tools;

* Kernel Mode Anti-debugging

Click to activate the Anti-debugging feature to prevent the debugging tool to debug the kernal;

* Show Error Message

Pop up error message inlcudes error code when program execution error occured, and popup message will be quite after 5 seconds automatically;

### 4. Click to "Protect Selected Projects" to start "Protection" Process;

![](/files/KQBkjYRIYfQa6Bx1OEc8)

Then go to the output folder, you will find a news file has been generated and a new sub directory has been generated, in the sample, the file and sub directory are:

![](/files/vGfzeUopk5pzOEQb0Zev)

The new sub directory which named `\protected` has been generated, go to this new directory, The new file which named `demo-0.0.1-Snapshot.jar`, is the protected Jar project;

&#x20;`demo-0.0.1-Snapshot.jar.ssp`, is the configuration file which stored the protection option setting.

### 5. Backup the source Jar file and use the protected Jar file to test and distribution

It is not necessary to distribute the configuration file: *`demo-0.0.1-Snapshot.jar.ssp`*, to your enduser. please keep it, if you use CLI mode to protect your Jar project, it is useful configuration file when you use Virbox Protector CLI mode later.

In General, With Virbox Protector, with this Quick Guide, Developer may quickly to go through whole protection process to protect Jar/War application. for more details instruction, developer may take refer from the User Manual-Virbox Protector Standalone, or contact us directly.

## Protect the Jar/War Project with Virbox Protector CLI tool

### 1. Generate the configuration file by use of Virbox Protector GUI tool:

Drag the Jar or War project into the Virbox Protector GUI tools, and set the protection mode to the specific Functions (Method) of Jar (or War) project in "Function Option" tabs.

{% hint style="info" %}
For more detail steps how to select/set the protection option to specific "functions", you may refer the Section "[Protect the Local desktop application](/use-cases/protect-desktop-applications/protect-the-local-desktop-application)" or related section in above GUI tools.
{% endhint %}

Click "*Save All Configuration*" Button, as shown in the snapshot below:

![](/files/rzw3frpIcuX4MiueA6We)

{% hint style="info" %}
if you have used label to mark the protection mode to the functions with virtualization when you built the Jar project. then it is no necessary to generate the configuration file, you can skip this step.
{% endhint %}

Go to the "Output" directory, then you will find a "xxx.jar.ssp" file has been generated. in the sample project, the file name in the sample is: demo-0.0.1-SNAPSHOT.jar.ssp, as shown as snapshot below:

![](/files/Ibbci5csnk7uJAwHbfyK)

Save the configuration file into the same directory of the Jar project which will be protected.

### 2. Protect the Jar project with Virbox Protector CLI tool

Open the terminal window, go to the sub directory which " **virboxprotector\_con.exe**" located, and input *virboxprotector\_con*, to view the help information:

![](/files/L469eXx2kM04Akwht6gC)

​ Use following command in the terminal to protect Jar:

​ `virboxprotector_con <*`*`The`*` ``*jar name which need to be protected> -o <*`*`the`* *`jar name which output>`*

​ See attached sample and protection process below

![](/files/UWA5psYx6c3iaNw5iPax)

### &#x20;3. Deployment

We will not describe how to deploy the protected Jar or War projects in this Quick Start Guide, in case you want to have basic knowledge to Deployment in different operation system, pls refer User Manual.

## Appendix:

### Using label to mark the critical functions (method) with Code Virtualization protection in coding process

Virbox Protector supports to protect the critical functions with "Code of Virtualization" protection mode, developer may set **label** to those critical and key functions in your coding, and quoted in functions, so, when the source code compilation completed, drag the program into the Virbox Protector GUI tools, then Virbox Protector will show protection mode to the functions in coding. here is sample:

### Create VBVirtualize.java

`package virbox;`

`public @interface VBVirtualize`

`{`

`}`

### How to call

`import virbox.VBVirtualize;`

`@VBVirtualize //it can be add to the class, then all of methods can be protected on default`

`public class Main {`

`​ public static void main(String[] args) {`

`​ System.out.println("hello");`

`​ test_vir();`

`​ }`

`​ @VBVirtualize //it can be added to specify method, protect this method only`

`​ public static void test_vir()`

`​ {`

`​ System.out.println("test_vir");`

`​ }`

`}`


# Protect the .NET application

### Introduction

**Virbox Protector** support to protect/encrypt the .NET application and .NET Core 3.0 above applications, protect/encrypt the .dll and executive file directly.

Virbox Protector support to protect .NET application both in GUI tool and CLI tool.

Here we use Virbox Protector GUI tool to show the protection process for .NET application step by step. for how to use CLI tool to protect .NET application, pls refer the User Manual or contact us.

### Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Open Virbox Protector GUI tool and sign in with your account;

{% hint style="info" %}
Above pre-requisition is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.
{% endhint %}

![](/files/fcAId83cyx9tibezgWty)

### Protect your .NET application in 5 steps

1. Import .NET file: drag the .NET file which need to be protected to Virbox Protector;
2. Set the configuration in "Function Option" tab; (Protect specified functions)
3. Set the configuration in "Protection Option" tab; (Protect the .NET apps in general)
4. Click to Start the "Protection" Process
5. Backup the source file. Use the protected file to test/evaluate and save the "configuration" file

### Protection Process

#### 1. Import .NET file: Drag .NET file into Virbox Protector

Drag the .NET file into the Virbox Protector, in the sample case, the .NET file we used is DotNetGame.exe;

![](/files/AoQlYWyHr4yHuDcvmenu)

Then Virbox protector will parse the .NET exe sample automatically. and show .NET file information in the "Basic info" tabs:

![](/files/BHgWSFCvyYRFx6B5TCqg)

#### 2. Set the configuration of "Function Option" tab; (Protect specified functions of the .NET file)

Developer may design your protection scheme via setting of Function Options and protection Options tabs.

For those critical functions of .NET files which need to be protected, Developer may select and define protection mode to each function via "Function Option" tabs:

2.1 Go to "Function option" and click "**Add Functions**", click the exe file shown in the box, Virbox Protector will show and list more functions:

![](/files/Vz5X92lvQ1jXajgL2fe6)

2.2 Select the functions which you want to protect: Virbox Protector provides 3 kinds of protection mode for developer selection: *No Protected, Obfuscation, Encryption;* and the security to each protection mode comparison from high to low is: Code encryption>Obfuscation;

2.3 Performance analysis: you can click the button "Analysis" to verify if the execution performance is satisfied.&#x20;

![](/files/BkPJlgVLXkV6adanQcV5)

Click "*OK*" when finalized the setting.

{% hint style="info" %}

1. Ctrl+A to select all of functions, and Right click, to select the protection mode, then you can quickly select the all functions with same protection mode accordingly;

&#x20; 2\. Considering the program execution performance may be impacted, so we don't suggest to protect all of .NET functions, instead of to select those critical and important functions to protect only.

&#x20; 3\. For some functions may not support the protection mode set to "Encryption", pls change the protection option from "Encryption" to "No Protect" or "Obfuscation" mode, if prompt message pop-up;

&#x20; 4\. "Analysis", since protection may impact the .NET application execution performance, Virbox Protector provides "Analysis" Function (The button on the top right corner of Main Menu,) to developer to verify when the protection mode to each function has been selected. Then developer can evaluate/simulate the program execution performance before the protection finalized. if execution performance is not satisfied, developer can change protect option to some function which frequently called. "No Protect" to improve the performance.
{% endhint %}

#### 3. Set the configuration of "Protection Option" tab; (Protect the .NET project in general)

Go to "Protection Option" tabs, Set protection option and Protect the .NET file in General:

Besides to protect the specifies critical functions, Virbox Protector supports to protect .NET application in fundamental, with multiple technology: Compression, Name of Obfuscation, JIT encryption, and also provides with Plug in unit: DS Protector to protect .NET data resource.

Developer may set and define following factors in the "Protection Option" tabs

3.1 Output Info: Set output path and protected .NET filename, as shown in the "box 1" marked with blue frame, on default it will create new sub directory in same directory, the protected file located in this new sub directory, with same name of source .net file, in the same case, the protected file is:

`\protected\DotNetGame.exe`

3.2 Protection Option Setting: Click to Protect the .NET file in fundamental in general, includes:&#x20;

Compression:&#x20;

To compress the file size and prevent the protected file from the static decompiling

JIT Encryption:

.Net JIT encryption means it encrypt all of the IL instructions of method in the .Net Program, and the instructions will be decrypted only when the JIT compiling proceed in the .Net Virtual Machine, This can be used to prevent static decompiling and prevent the IL code being Dumped in memory.

Anti-Debugging:&#x20;

Click to enable the protected .NET file with Anti debugging capability;

Name of Obfuscation:&#x20;

Rename the .Net program method, class, Variety and parameter name with random string, the name that exported for external call will not be changed.&#x20;

3.3 Options can be set for Name of Obfuscation:

Disable:&#x20;

Not obfuscate the name of variety, parameter, method and classes;

Obfuscate private member only (recommend):&#x20;

Obfuscate the Variety and Parameter name, but not obfuscate the class's name and method's name;

Keep Custom Name:

Yes: to obfuscate the name of parameters, not for class and method name;

No: None of name of parameter, class, method will be obfuscated.

3.4 Plug-in Unit Setting: If Developer has data resource need to be protected, switch on "ds" button to open "DS Protector" to protect relevant data resource via "DS Protector" and set the password to protected data resource.

![](/files/P3fkDVSYsyVLupV5hM1W)

3.5 Switch on/off: **DS Protector**, a plug in unit which used to encrypt/protect the data source file of protected program, you need to "switch on" the "ds" button to open "DS Protector"and set the password for protected data source file.

Another way to open the DS Protector is go to the \bin subdirectory of Virbox Protector and double click: deprotector.exe to open DS Protector. but you still need to "Switch on" ds button to enable the ds function in Virbox Protector.

3.6 Switch on/off: Advanced Process Protection: enable "RASP" plugin

{% hint style="info" %}
Optional feature and license required to activate this feature
{% endhint %}

**RASP**: Runtime Application Self Protection: this plugin focus to protect the process running in the kernal for the application in windows platform, when this plugin start to execute, it will load the driver integrated to protect process itself to prevent the third party  plugin  to skip the normal anti debugging protection from debugging in memory. It is also effective to defense the "Cheat Engine" to scan the memory which running the process.&#x20;

**RASP** plugin are most effective functions and applied to those scenario which highly security required. additional license from Virbox required.

There are 3 features can be select in the "RASP" plugin:

* Memory Protection:&#x20;

Click to protect the memory information executed for windows application; which to prevent the attacker/hacker to scan  the process memory by use of "Cheat Engine" tools;

* Anti-debugging (Kernal Mode)

Click to activate the Anti-debugging feature to prevent the debugging tool to debug the kernal;

* Show Error Message

Pop up error message inlcudes error code when program

{% hint style="info" %}
**Remove the "Strong Name" to your .NET project before Protection and add "Strong Name" after protection completed.**&#x20;
{% endhint %}

#### 4. Click to Start the "Protection" Process

​ Click "Protect selected Project" to start protection;

![](/files/e5JfKUXdaKtXuYzqTWmO)

Then go to the output folder, you will find 2 news file has been generated, in the sample, we have set the output path: D:\VBP protection sample\Dotnet

you can one new file: `DotNetGame.exe.ssp` and new sub directory: `\protected` has been created in the output directory:

![](/files/q6VNuBsEqYYd6txXKtF9)

entry to the sub directory: \protected, you will find a new file, which name is same as the original .Net File name has been generated:

![](/files/5mPUdwTpvuOKK0Glhl7p)

The new file which name DotNetGame.exe.ssp, is the configuration file which stored the protection option setting.

The new file which has same name of original .NET file name: DotNetGame.exe, is the protected .net application; pls use this protected .NET file for further testing. and keep the original file and the configuration seperately. the configuration file can be reused when you update the .Net file or when you use Virbox Protector CLI tool to protect your .NET file.

#### 5. Backup the source file, Use the protected file for further testing and save the "configuration" file

Next, you need to use the protected .NET file for furthur testing,  don't publish this original file. and&#x20;

Please Don't distribute the configuration file: DotNetGame.exe.ssp, to your enduser. please keep it, if you use CLI mode to protect your .NET application, it is useful configuration file when you use Virbox Protector CLI mode later.

## Protect .NET Project with Virbox Protector CLI tool

### 1. Generate the configuration file (.ssp file) by use of Virbox Protector GUI tool:

1.1 Drag the .NET project into the Virbox Protector GUI tools, and set the protection mode to the specific Functions (Method) of .NET project in "Function Option" tabs.

1.2 Click to "Save selected configuration" to  generate the protection configuration file (.ssp file) which will be used  when you use Virbox Protector CLI tool to protect your .net project later.

{% hint style="info" %}
If no configuration file has been generated or found, when you use Virbox Protector CLI to protect your .NET project, The entry functions of the .NET project will be protected on default.
{% endhint %}

1.3 Put the confiuguration file (.ssp file) in the same directory of the .NET file which you want to protect.&#x20;

The .NET project which will be protected is: dot\_*NET2*\_bounce.exe in the sample case.

![](/files/ke656Xk5tVpr3v62ZJKT)

### 2. Use Virbox Protector CLI tool to protect the .NET  project

**Windows Environment:**

go to the installation directory of Virbox Protector, you can find 2 CLI tools:

virboxprotector\_con.exe;

dsprotector\_con.exe ( CLI tool of DS protector)

![](/files/ywKQviHwypUTckOx94Yi)

**Linux Environment:**

The on default installation path to Virbox Protector in linux environment:

`/usr/share/virboxprotector/`

go to /bin of installation directory of Virbox Protector, you can find  2 CLI tools:

virboxprotector\_con.exe;

dsprotector\_con.exe ( CLI tool of DS protector)

![](/files/NUw76Waf0WTbFHIUEMFp)

### 3. Use CLI command to protect .NET project/file:

![](/files/UtkgyR4TXQ8HHj1R8boA)

Windows:

`virboxprotector_con <*`*`The`*` ``*.dotNET project name which need to be protected> -o <*`*`the dotNET project name which output`*

Linux:

`virboxprotector_con <*`*`The`*` ``*.dotNET project name which need to be protected> -o <*`*`the dotNET project name which output`*

### Appendix: Using label to mark the key functions in .NET project

Virbox Protector support to protect the key functions with 2 protection modes:

**Code Encryption** and **Code Obfuscation**

Developer may set a label to mark the protection mode to the function will be protected in code building process, and it can be quoted and viewed in the code, so, when the compiling completed, developer drag the apps into the Virbox Protector, the GUI will show the protection mode set in the code accordingly, here is label sample for code:

`//Label`

`namespace Virbox{`

`​ //Code Obfuscation`

`​ class Mutate : System.Attribute`

`​ {`

`​ }`

`​ //Code Encryption`

`​ class Encrypt: System.Attribute`

`​ {`

`​ }`

`}`

`public class main`

`{`

`​ [Virbox.Mutate]//Code Obfuscation`

`​ public static void test1(string[] args)`

​ `{`

`​ System.Console.WriteLine("hello Virbox.Mutate!");`

`​ }`

`​ [Virbox.Encrypt]//Code Encryption`

`​ public static void test2(string[] args)`

`​ {`

`​ System.Console.WriteLine("hello Virbox.Encrypt!");`

`​ }`

`​ public static void Main(string[] args)`

`​ {`

`​ test1(args);`

`​ test2(args);`

`​ }`

`}`


# Best Practice--Protect .NET applications

.NET is an open-source and cross-platform development platform to build many types of applications. and widely used to web, mobile, desktop, IoT applications.

To implement for cross platform execution: Unlikely the traditional high level language compilation process, the C# in .NET project consist of 2 compiling steps:

With C# compiler, to compile C# to MSIL code first, then with JIT compiler in Runtime, to compile into executable file: exe, dll... and executed in target environment.

<figure><img src="/files/EjSoRZt7pbekoXmvCOSd" alt=""><figcaption></figcaption></figure>

so, with latest decompiler or reverse engineering tools, it is extremely easy to the cracker to decompile .NET project, decompile the IL code to get the original C# code, to further analyze, to understand and modify the operation of the application or program.

<figure><img src="/files/0JEqcYMrWhNNNEEz8Jg8" alt=""><figcaption></figcaption></figure>

[**Virbox Protector**](https://appshield.virbox.com/index.html), use multiple layers encryption technology to protect .NET project in highly security level to defend cracker to decompile, reverse engineering .NET project.

In general, Virbox Protector supports developer to protect their .NET project in following aspect:

​ 1. Overall protection and encryption to .NET project: JIT encryption, string encryption, etc.

​ 2. Runtime protection: Debugging detection, Name of Obfuscation;

​ 3. Obfuscation/encryption in function/methods level, which to protect those critical method, code logic with following code protection options: Code encryption, obfuscation and most secured of code of virtualization;

Developer may combine to use those protection technology and balance execution performance, application scenario, integration and build project to design your own protection scheme for your .net project.

With secured and powerful obfuscator and protector, it is still not easy to developer to complete protection process quickly, developer have to spend lot of time to design and finetone in tailor-made protection scheme, based on each .NET project, platform, environment and security requirement. In this article, we introduce and summarize some of protection experience (configuration, option setting etc.) of [Virbox Protector](https://appshield.virbox.com/index.html) which can be referral to developer when they use Virbox Protector to protect their .NET project.

## Virbox Protector support to protect .NET project in following .NET platform

### Support .NET Platform & Operation Environment

| .NET platform & Environment | Support or Not  | Remarks                                                                                                                   |
| --------------------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------- |
| .NET Framework 2.x \~ 4.x   | Yes             | Fully support                                                                                                             |
| .NET Core 2                 | Partial support | end of life of version.                                                                                                   |
| .NET Core 3                 | Yes             | Part of features not available for non windows system                                                                     |
| .NET 5 \~.NET 9             | Yes             | Part of features not available for non windows system                                                                     |
| Mono Runtime                | No              | For Unity Engine project, Developer may use and follow the Virbox Protector's protection process to the Unity3D projects. |

### Protection Options & Technical Matrix to .NET Project

| Option Setting                        | Compatibility                                                                                                                       | Remarks                                                                                                                                          |
| ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| Compression                           | <p>Support Windows system only<br>Not support<code>In Memory Module</code>, such as the dll loaded by<code>Assembly.Load</code></p> |                                                                                                                                                  |
| JIT Encryption                        | Support in Window Environment                                                                                                       |                                                                                                                                                  |
| String of Encryption                  | Fully Support                                                                                                                       |                                                                                                                                                  |
| Overlay data encryption               | Support in Windows Environment                                                                                                      | Some of archive/Packer tool will generate the overlay data attached, so it is necessary to encrypt the overlay data to prevent plain text leaky. |
| Detect Debug tool                     | Fully Support                                                                                                                       |                                                                                                                                                  |
| Name of Obfuscation                   | Fully Support                                                                                                                       |                                                                                                                                                  |
| **Function/Method protection option** |                                                                                                                                     |                                                                                                                                                  |
| \[E] Code of Encryption               | Fully Support                                                                                                                       |                                                                                                                                                  |
| \[M] Code of Obfuscation              | Fully Support                                                                                                                       |                                                                                                                                                  |
| \[V] Code of Virtualization           | Fully Support                                                                                                                       |                                                                                                                                                  |

##

## Best Practice to protect .NET project

With multiple Obfuscation/Encryption technology, Virbox Protector support developer to design a general protection scheme to protect your .NET project.

<figure><img src="/files/6T5xSkzcKDWIQYNdwpQ0" alt=""><figcaption></figcaption></figure>

### General Guide to obfuscate .NET Project

For those developer who only want to protect/obfuscate their .NET project in general and without special security and protection to some of critical functions/methods, you may follow below process which help you to complete the .NET protection process quickly, which provides general protection to your .NET project. with general protection scheme, Virbox Protector support developer to obfuscate .NET project effectively to defend the decompiling and prevent the normal memory dump.

For the developer who require highly secured protection scheme to protect .NET project, then you can follow the second way to protect your .NET project.

Here are some recommendation to those developer who want to protect .NET project in general and quickly.

Protection Scheme:

| Protection Option                | Recommendation Setting                                                                                                                                                                                                                                                                                            | Notes                                                        |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ |
| Compression                      | it is recommend not select this option                                                                                                                                                                                                                                                                            |                                                              |
| JIT Encryption                   | Select this option in Windows system                                                                                                                                                                                                                                                                              |                                                              |
| String of Encryption             | Select this option if you have sensitive string to hide/encrypt.                                                                                                                                                                                                                                                  |                                                              |
| Overlay data encryption          | Select this option if overlay data exist                                                                                                                                                                                                                                                                          | Some of archive/packer tool will generate overlay data file. |
| Debugging detection (Anti Debug) | <p>Select the "Debugging detection" feature to one module to each process only, for example to enable debugging detection to main .exe program only)<br>\*: If the module be used to be the SDK which released to third party program to call. then please DO Not to enable this debugging detection feature.</p> |                                                              |
| Name of Obfuscation              | <p>To "main exe program", Select "Keep the Name of Self defined" to avoid of miss calling functions/methods after name of obfuscation<br>For "dll files", Select "Obfuscate private member only"</p>                                                                                                              |                                                              |
| \[E] Code of encryption          | <p>For Windows project, use on default option (encrypt the entry functions only)<br>For Non Windows project, since it doesn't support JIT encryption, so it is required to select to enable this feature to protect those functions which necessary to protect.</p>                                               |                                                              |
| \[M] Code of Obfuscation         | On default feature, no need to select to enable this feature                                                                                                                                                                                                                                                      |                                                              |
| \[V] Code of Virtualization      | On default feature, no need to select to enable this feature.                                                                                                                                                                                                                                                     |                                                              |

### For those developer who require highly security protection scheme, following protection setting recommended & used in protection process.

Use "**Name of obfuscation**" and use the "**Code of Virtualization**" to protect class name and those critical functions/methods;

**Self-defined the Name of Obfuscation**:

This features used to obfuscate to name of space, class, method, usually it may exist calling among the modules each other, so, if you obfuscate the name of functions which has the public attribute, it may failed to find the function/method when call relate functions and cause the calling error , so it is required the developer to self define the name of obfuscation of function. to avoid failed to find functions/method with public attributes.

"**Assembly merge**"

For Calling among the modules, developer may use "**Assembly merge**" feature to combine/merge multiple of module/assembly to one assembly and then to protect one assembly only. Virbox protector provides the **Assembly merge** function and support developer to merge the assembly together.

**Assembly Merge** functions can be accessed in the GUI menu -> Tools->Assembly Merge in the Virbox Protector GUI tools,

**Assembly Merge** function can be available in Virbox Protector CLI tools (virboxprotector\_con) also, by adding the option: `-ilmerge`， to merge assembly accordingly.

**Sample：**

```shell
# in the sample case, developer will merge the "test.exe" and dependent test.dll together with new assembly: "test.exe"

virboxprotector_con -ilmerge test.exe test.dll -o merged/test.exe
```

**Virtualization**:

For those critical and sensetive functions/methods, such as the critical encryption/dycryption coding logic, it is recommend to use "Code of Virtualization" to protect these fucntions/method.

Note:

For the functions/method which use the "Code of Virtualization", the execution performance may be negative impacted., so it is NOT recommend to use the "code of virtualization" to every functions/method, only select the critical function to implement;

For performance impact, Virbox Protector provides "Performance Analysis" feature to developer to "pre-view" the performance in execution, which can be available in the "Function Option" tabs.

```
->Add Function->Analysis
```

## Automatic Integration

### Use Virbox Protector CLI tool to integrate to build project

The on default path of CLI tool of`Virbox Protector`: `virboxprotector_con`:

```
Windows:
C:\Program Files\senseshield\Virbox Protector 3\bin

Linux:
/usr/share/virboxprotector/bin

macOS:
/Applications/Virbox Protector 3.app/Contents/MacOS/bin
```

### Use the configuration file to integrate to build project

There are 2 ways to use Virbox Protector CLI tools to build your project:

With the protection configuration file or Without protection configuration file

1. **With Configuration file to integrate and build your project**

   Use the Virbox Protector GUI tool to generate the configuration file first and then use the CLI tool to protect your project WITH the configuration generated previously.

   For how to generate the configuration file by use of Virbox GUI, the process is similar to the process to protect the project. More details, pls refer to relate the section of Quick Start Guide to Virbox Protector GUI tool.

   then, you can find the .ssp file in the

   ```
   \protected
   ```

   the sub directory in the output path. then call the CLI tool:

   ```
   virboxprotector_con.exe
   ```

   to protect your project with following command:

```shell
virboxprotector_con <input_file> -o <output_file>
```

`virboxprotector_con` will automatically to search the \<input\_file>.ssp which to be the configuration file to start the protection.

1. **Without configuration file to protect project**

   Use Virbox Protector CLI to protect your project without configuration file (.ssp file)

   2.1 Use and set the option/argument to Virbox Protector CLI tool to protect your project.

   for those developer has rich experience in Virbox Protector protection process, they can use Virbox Protector CLI tool with specified option/argument to protect their project directly.

   2.2 If no additional option/argument pass in the CLI tool: virboxprotector\_con

   then it will use the option/argument on default to protect the project. the on default option/argument setting, pls refer CLI user manual. or refer following protection option setting in below

   2.3 Developer also can use a SDK label to mark those critical function/method, then protect the project.

### Use Command Line Interface to protect .NET apps: Protection Option Setting:

**Protection Option**

| Option                               | CLI Argument     | On default value setting                                                                                    |
| ------------------------------------ | ---------------- | ----------------------------------------------------------------------------------------------------------- |
| Compression                          | `--pack=`        | `0`                                                                                                         |
| JIT encryption                       | `--jit-enc=`     | `1`                                                                                                         |
| String of encryption                 | `--str-enc=`     | `1`                                                                                                         |
| Overlay data encryption              | `--overlay-enc=` | `1`                                                                                                         |
| Debugging detection                  | `--detect-dbg=`  | `0`                                                                                                         |
| Name of Obfuscation                  | `--rename=`      | <p>For exe file, to obfuscate all of name<br>For DLL file, to obfuscate private name only<code>1</code></p> |
| Keep the rule of name of Obfuscation | `--keep-rules=`  | `""`                                                                                                        |

**Function Option Setting**

| Option                                  | CLI Argument setting                                   |
| --------------------------------------- | ------------------------------------------------------ |
| Ignore these function doesn't supported | `--ignore-unsupported=<value>`On default to disable：0） |
| Code of Encryption                      | `-e`                                                   |
| Code of Obfuscation (mutation)          | `-m`                                                   |
| Code of Virtualization                  | `-v`                                                   |

Virbox protector support developer to specify the function/method name or use "rule" to protect .NET projects, which to protect the critical functions/method with different kind of protection options: Code of Encryption, Code of obfuscation (Mutation) and Code of Virtualization.

Use the semicolon: `;` to separate functions, support to use wild card: `*`

`-m "function1;function2" -v "function3;function4" -e "test*" --ignore-unsupported=1`

### The protection sample of using Virbox Protector CLI tool

**Protect main program(Obfuscation all of name and enable the anti-debugging features)**:

```shell
virboxprotector_con test.exe --pack=0 --jit-enc=1 --str-enc=1 --rename=2 --keep-rules="" -detect-dbg=1 -o protected/test.exe
```

**Protect the dll (obfuscate the private method name):**

```shell
virboxprotector_con test.dll --pack=0 --jit-enc=1 --str-enc=1 --rename=1 
```

**Protect dll (Reserve and keep self defined method name and not obfuscate):**

```shell
virboxprotector_con test.dll --pack=0 --jit-enc=1 --str-enc=1 --rename=2 --keep-rules="MyNamespace.MyClass1.*;MyNamespace.MyClass2.*"
```

**Protect dll in Non Windows Platform with following option setting:**

​ Not use JIT encryption;

​ Encryption to all of method;

​ Enable the anti-debugging fucntions;

​ Ignore the functions which not support.

Note: for the option value settings, pls refer the CLI user manual, there are fully description to Option value setting, usually, value setting to "0" means disable, "1" means enable;

```shell
virboxprotector_con test.dll --pack=0 --jit-enc=0 --detect-dbg=1 --str-enc=1 --rename=1 -e "*" --ignore-unsupported=1
```


# Protect Unity3D/UE4 application

{% hint style="info" %}
Virbox Protector support to protect the Unity3D/UE4 based applications in Windows, Linux, macOS, Android and iOS Systems. For Unity3D applications, Virbox Protector support to portect  the Unity3D application both in Mono framework and IL2CPP compiling  mode.
{% endhint %}

Protection Feature support and available in Different system

<table data-header-hidden><thead><tr><th width="184"></th><th width="150"></th><th width="150"></th><th width="150"></th><th></th><th></th></tr></thead><tbody><tr><td>Features Support</td><td>Windows</td><td>Linux</td><td>macOS</td><td>Android</td><td>iOS</td></tr><tr><td>Assembly Encryption (Mono)</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>N/A</td></tr><tr><td>Resource encryption</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Anti Debugging</td><td>No</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Unity3D engine protection (IL2cpp)</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>MetaData Encryption(IL2CPP)</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>MetaData-Name of Obfuscation (IL2CPP)</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Memory Check</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Yes</td></tr><tr><td>Signature Check</td><td>No</td><td>No</td><td>No</td><td>Yes</td><td>No</td></tr><tr><td>File Check</td><td>No</td><td>No</td><td>No</td><td>Yes</td><td>No</td></tr><tr><td>Anti-Injection</td><td>No</td><td>No</td><td>No</td><td>Yes</td><td>No</td></tr><tr><td>Emulator Detection</td><td>N/A</td><td>N/A</td><td>N/A</td><td>Yes</td><td>N/A</td></tr><tr><td>Root Detection</td><td>N/A</td><td>N/A</td><td>N/A</td><td>Yes</td><td>No</td></tr><tr><td>Multi-Parallel Detection</td><td>No</td><td>No</td><td>No</td><td>Yes</td><td>No</td></tr></tbody></table>

<br>


# Protect Unity3D Android APK

​

## Protect Unity3D Android APK

### Introduction

**Virbox Protector** support to protect/encrypt the Unity3D Android APK compiled in Mono framework and IL2CPP mode.

Virbox Protector supports to protect Unity3D Android APK in both GUI tool and CLI tool.

With Virbox Protector, Developer protect/encrypt the whole Unity3D directory and critical libs and data assets for Unity3D android Apk, includes:&#x20;

<mark style="color:blue;">Assembly-CSharp-firstpass.dll,  Assembly-CSharp.dll,   global-metadata.dat, other C# assemblies  ​ and Unity3D data assets （.resS and resource)</mark>

​and also to protect the Unity3D Android APK in general protection with following functions:&#x20;

Anti- debugging, Anti-Injection and other features.&#x20;

Here we use Virbox Protector GUI tool to show the protection process to Unity3D android APK step by step. and introduce the protection process by Virbox Protector CLI tool in second part.

For more detail, you may also refer to the User Manual\_Virbox Protector Standalone or contact us.

### Protect Unity3D Android APK in 6 steps

1. Import Android Unity3D APK: Drag related APK into Virbox Protector;
2. Setting to protect the C# dll, gloabl metadata and protect Unity3D APK in general in "Protection Option" tab;
3. Setting to protect the Unity3D APK Resource in "Resource Encryption";
4. Protect Unity3D External Resource in "Resource Encryption"
5. Click to start "Protection" Process;
6. Back up source APK and use the protected APK for further testing or distribution.

### Prerequisites

[Sign-up](/download/sign-up-and-apply-trial-license) Virbox Protector to apply trial license and install the Virbox Protector;

Open Virbox Protector and [sign in](/download/sign-in-and-sign-out) your account with your trial password

![](/files/OdB9DV2leLnAaUBaX9Zs)

{% hint style="info" %}
Above prerequisites is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.
{% endhint %}

### Protection Process (Virbox Protector GUI tools)

#### 1. Import Android Unity3D APK:

Drag related APK into Virbox Protector; Then Virbox Protector will parse the Unity3D android APK automatically. and show Android APK information in the "Basic info" tabs, Virbox Protector support to portect  the Unity3D application both in Mono framework and IL2CPP mode. As shown as a snapshot below:

![The Unity3D Android APK complied with IL2CPP](/files/DMXbZI9yeh5Ja1plxRD8)

![The Unity3D Android APK in Mono framework](/files/BLI67BZQ0IITiN5WNDNj)

### 2. Protect the C# dll, global metadata and protect Unity3D APK in general in "Protection Option"

Go to "Protection Option" to set:

2.1 Output path and output file name, click the box in right to change output path and name; otherwise  the protectd APK file will saved in the new sub directory will be created in same directory.

2.2 Set the protection option to Android APK in General to prevent debugging and decompiling

2.3 Signature and keystore path setting

**For IL2CPP and Mono frame based APK, the configuration may slightly different:**

For metadata in IL2CPP, Virbox Protector will encrypt metadata on default.

Developer can click to select other protection option to protect APK in general; (the description/function to each protection option setting as shown as below)

Developer can click to enable signing and set the signature, input keystore file and password

For Unity3D Android APK based on Mono framework, the Virbox Protector GUI shown as attached below:

The *Assembly-CSharp-firstpass.dll*, *Assembly-CSharp.dll* will be encrypted on default by Virbox protector, you can add other C# assemblies by click "+" if necessary. and click to select other protection options, as shown attached below:

![The Unity3D Android APK in Mono framework](/files/vz2EDmXMkhxhmo68Gowr)

![The Unity3D Android APK complied with IL2CPP](/files/lzkIeZJ1ieJsgzW7cTki)

&#x20;**Protection Option Setting summary：**

Click and Select the "Memo Check", to verify memo and check memo integrity(effective to IL2CPP project);

Click and Select the "Unity Engine Encryption", to protect the unity engine and enhance security;

"Meta Data encryption", will be selected on default,  to prevent be parsed and dumped in execution;

Click and Select the "Name Obfuscation of Meta " button, to obfuscate the name of method metadata (effective to IL2CPP project);

Click and Select the "Anti-Debugging" button, then when the debugger use the IDA or other third party debug tools to debug the protected Android Apk, the protected APK will exit directly;

Click to enable the "Signature Check" and input "keystore" fileand password to prevent tampering;

{% hint style="info" %}
Click to select "Enable Sign" button to  enable "signature Check" feature.
{% endhint %}

Click and select the Anti-injection, to prevent the other session to add debugging or injection.

Click and select "Emulator Detection", to prevent the App running in the emulator environment'

Click and Select "Root Detection" to prevent the App running in the rooted device;

Click and Select "Multi-Parallel Detection" to prevent app running with multiple account;

Sign Setting

Click and "enable sign" to set/input keystore file, path and password. etc;

{% hint style="info" %}
Sign Setting

For AAB applications,

In case you click and select the "Sign check", then you can **Not** select  the Google to keep, manage your apps and password. So, you can either to select this option. but Not use Google Play store to manage the signature file, or Not select this option and use Google Play Store to manage your signature file when publish your applications;

If you use "Google" to keep and manage your keys, then the keys which used for published in Google playstore  must be consistent with the key which used in Virbox Protector.
{% endhint %}

### 3. Protect Unity3D APK Resource in "Resource Encryption" tab

Go to "Resource Encryption" tab, developer can set and protect the data assets and resource of Unit3D android APK here.

![](/files/aBTEuAPaz5gySTwt3qkR)

1. Click "Enable" to enable the "Resource Encryption", to protect the resource, data asset which attached in the Unity3D projects.
2. Click the "Favor Size", it means to set the prioritize the compression size than security, if you click to select this option, the protected APK size will much compressed, but the APK security will be lower than that of not selection of this option.
3. Click "Select Files", it will list all of resource file contained in the APK, then click to select those file which need to be encrypted.

### 4. Protect Unity3D External Resource in "Resource Encryption"

Since Unity3D projects often contain large size of AssetBundle files or other heavy resource files, developers frequently treat certain large resources (such as videos, images, or maps) as external files to improve project execution performance. Virbox Protector supports protecting both internal Unity3D resource files and related external resource files/folders. It also supports hot updates of these protected resources — meaning that when developers update resource files, they don’t need to republish the entire Unity3D project again. Instead, simply protecting/encrypting the new version of the resource file is sufficient.

**Here are process to introduce how to protect external resource in Unity3D project.**

**Parsing your unity3D project:**

Drag your unity folder into Virbox Protector; Go to `Resource Encryption` Tab;

Enable button & set password to encrypt the resource, as shown in screenshot in blow. and set/input the password:

<figure><img src="/files/PHinntkgYVUJ0N8Shqmg" alt=""><figcaption></figcaption></figure>

> Note, for Unity3D without external password, no need to input/set password. Virbox Protector will use **random key** to encrypt Resource and decrypt resource;

**Save the configuration to protection option**

Click the button in File menu: `Save Selected Configuration`

<figure><img src="/files/Q0XDjGA1ZpuD5LaTbA2Q" alt=""><figcaption></figcaption></figure>

**Encrypt the external resource**

Go to `Resource Encryption` Tab, Click the Button: `Encrypt External` on the top right of `Resource Encryption`;

\--a windows will pop up which list the external file to be protect/encrypt:

Pls refer following steps to:

* Input/Select the external resource file to be encrypted from the folder located;
* Output folder (encrypted external file folder);
* and select these external resource file to be encrypted;

and click the button `Encrypt` to encrypt these external resource file;

<figure><img src="/files/6Ii7fDwGjeuWEqT7Wepk" alt=""><figcaption></figcaption></figure>

Note:

1. When password not changed. protect the Unity folder just need to protect once;
2. When you have saved the protection configuration file (click to `Save selected configuration`), you can open the external resource file folder in `File Menu` to protect external resource file directly:

<figure><img src="/files/K64Rnlrdm5iLUCH6nClA" alt=""><figcaption></figcaption></figure>

### 5. Click to start "Protection" Process

When you finalize all above selection, click the button "Protect Selected Projects" to start the protection process (it will take some times to protect a large size of APK, pls wait)：

![](/files/bZ9WGbHlxaeS9tvT4BCm)

Go to the output folder, you will following new file has been generated

![](/files/P4Y51syO1oAHrPqTeA1s)

The first sub directory new created  :\protected, which save the protected file, entry this sub directroy, you can find the protected apk file

![](/files/LFsyhbmxWk474OQf6p3B)

The second file is source APK, it is your original APK which not protected. pls DON't distribute this APK.

The thrd file: xxxx.apk.ssp is the configuration file to save your protection options, pls keep it.

If the files protected is AAB project, similar file will be generated. but suffix is aab, not apk.

{% hint style="info" %}
pls don't use the trial version of Virbox Protector to protect and harden your APK or AAB project if you want to publish your project in the Google Store, instead to use formal release Virbox Protector to protect and harden the APK which will be published in the Google Store.
{% endhint %}

### 6. Back up source APK and use the protected APK to test etc.

Next, you need to  save the unprotect APK to another folder, keep it. don't distribute the unprotected APK to publish. and also save and keep the configuration file.

Use the protected APK  for further testing or publish or distribute later.

{% hint style="info" %}
Pls do not publish your protected app which protected by Virbox Protector trial version, pls contact our sales to get the formal release version to protect your application and published.
{% endhint %}

### Protection Process (Virbox Protector CLI tool)

#### Use Virbox Protector GUI to Generate the configuration file (Optional)

Virbox Protector support developer to protect/encrypt Unity3D Android APK with 2 ways, GUI and CLI mode. Here we introduce the protection process for how to use Virbox Protector CLI tool to protect a Unity3D Android APK,

#### 1. Generate a "configuration" file

Before to start protection, you need to generate a "configuration" file which store the setting information of "protection option" to the APK which need to protected.

Open Virbox Protector Standalone GUI tool and sign in with your account and password.

Please refer the protection process by use of Virbox Protector GUI tool in above to set the configuration to Function option, Protection option and Resource Encryption. and click "Save All Configuration" to generate the "configuration" file, which suffix is `.ssp.`&#x20;

![](/files/MC8M18VuyrVwZBnX6Xpo)

Go to the output folder, you will find a new `xxxx.apk.ssp` file has been generated in the output folder.

![](/files/hTjLh64PkfDYKIpix9qC)

&#x20;To generate a configuration file is optional, if no configuration generated, then when you use Virbox Protector CLI tool to protect APK/AAB file, the protected APK/AAB will not be signed, on default.

#### 2. Find the Virbox Protector CLI tools installed in your machine

Go to the Virbox protector's installation folder in your machine, and find the *virboxprotector\_con,exe* and open it in command line terminal:

The on default installation directory in windows system is:

`C:\Program Files\senseshield\Virbox Protector 2 Trial\bin`

The on default installation directory in Linux system is:

`/usr/share/virboxprotector/bin`

Input:

​ *`virboxprotector_con.exe`*

to view the help info:

![](/files/x0uE7au6ax0LJvBCK1b2)

#### 3 Use Virbox Protector CLI tool to protect your Unity3D Android APK

Please put the configuration file which generated by Virbox Protector GUI tool in first step into the same directory of the Unity3D Android APK located.

Use following command to execute the protection:

*`path of “VirboxProtector_con\VirboxProtector_con” “the path of the android apk to be protected\apk name” -u3d –o “the directory of the output path of the Android apk\APK name”`*

system will return with "*succeed*" when protection completed

see sample in below.

![](/files/brGHsznKRXupCr3wJTJu)

If the license of Virbox Protector to unity3D program can not be found, it shows as the snapshot below:

*error, can not find the license*

![](/files/h7jIT79W45RzkBcNDHn8)

if so, you need to contact Virbox to purchase the License of Virbox protector which commercial released and use formal license to protect your Unity3D Android APK or AAB projects.


# Protect Unity3D application in Windows/Linux system

## Protect Unity3D Projects in Windows/Linux system

### Introduction

**Virbox Protector** support to protect/encrypt the Unity3D App compiled in Mono framework and IL2CPP compiling mode.

**Virbox Protector** supports to protect Unity3D App in both GUI tool and CLI tool.

With Virbox Protector, Developer protect/encrypt the whole Unity3D directory and critical libs and data assets for Unity3D android Apk, inlcudes:

<mark style="color:blue;">Assembly-CSharp-firstpass.dll,  Assembly-CSharp.dll,   global-metadata.dat, and other C# assemblies,  ​</mark>

​ and Unity3D data assets <mark style="color:blue;">（</mark><mark style="color:blue;">`.resS and resource`</mark><mark style="color:blue;">)</mark>

​ and to Protect the Unity3D App in general protection:&#x20;

<mark style="color:blue;">Anti- debugging, Anti-Injection</mark> and other features.

Here we use Virbox Protector GUI tool to show the protection process for Unity3D app step by step . For more detail, you may also refer to the User Manual\_Virbox Protector Standalone or contact us.

### Protect Unity3D Application in 5 steps

1. Import Unity3D projects: Drag related Unity3D App into Virbox Protector;
2. Setting to protect the C# dll, gloabl metadata and protect Unity3D APK in general in "Protection Option"
3. Setting to protect Unity3D App Resource in "Resource Encryption"
4. Protect Unity3D External Resource in "Resource Encryption"
5. Click to start "Protection" Process
6. Back up source APK and Use the protected APK for further testing or distribution.

### Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Open Virbox Protector and sign in with your account;

![](/files/yjG5JYHsbHTa5dXb4MXv)

{% hint style="info" %}
Above pre-requisition is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.
{% endhint %}

### Protection Process

#### 1. Import Unity3D Project:

Drag the whole Unity3D app **folder** into Virbox Protector; Then Virbox protector will parse the Unity3D application automatically. and show Unity3D App information in the "Basic info" tabs, shown as snapshot below:

![The Unity3D App in Mono framework](/files/yne6sImOgNvOiyZPu7H1)

![The Unity3D App complied with IL2CPP](/files/9SscUOhJWb7m0PT2Bm0K)

#### 2. Setting to protect the C# dll, gloabl metadata and protect Unity3D App in general in "Protection Option"

Go to "Protection Option" to set:

2.1 Output path and output file name, click the button in right to change output path and name; the on default output will create new sub directory in same path; with configuration file: *xxx.app.ssp.*

2.2 Set the protection option to Unity3D project in General to prevent debugging and decompiling

For Mono frame based and IL2CPP compiled App, the configuration may slightly different:

For Unity3D App based on Mono framework, The *Assembly-CSharp-firstpass.dll*, *Assembly-CSharp.dll* will be encrypted on default by Virbox protector;

You can add other C# assemblies under "Managed directory" by click "+".the Virbox Protector GUI shown as attached below:

![The Unity3D App in Mono framework](/files/9p34vO7eMNPdQLDru3lj)

For Unity3D app compiled on IL2CPP, Virbox Protector will protect/encrypt the metadata on default, click to select other protection options:

Memory Check:&#x20;

Verify memo and check memo integrity(effective to IL2CPP project);

Metadata Name obfuscation:&#x20;

Obfuscate the name of method metadata (effective to IL2CPP project);

Anti debugging:

Click to set to this feature, The protected application will quit the execution when debugging of process  has been detected;

Plugin:

Switch on/off RASP Protection (Advanced Process Protection)

{% hint style="info" %}
Enable to RASP feature: additonal license required
{% endhint %}

Runtime application self protection, the advanced Protection feature to protect the process for windows application, which effective to prevent  debuging tool to debug your application and also prevent the "Cheat Engine" tool to scan the memo of process, this protection function is most effective way for the highly security scenario to protect applications

There are 3 features can be select in the "RASP" Protection plugin:

* Memory Protection:&#x20;

Click to protect the memory information executed for windows application; which to prevent the attacker/hacker to scan  the process memory by use of "Cheat Engine" tools;

* Kernel Mode Anti-debugging

Click to activate the Anti-debugging feature to prevent the debugging tool to debug the kernal;

* Show Error Message

Pop up error message inlcudes error code when program execution error occured, and popup message will be quite after 5 seconds automatically;

as shown attached below:

![The Unity3D App complied with IL2CPP](/files/cFlHgD9s0ubsO8hyGFvQ)

#### 3. Setting to protect Unity3D project Resource in "Resource Encryption"

Go to "Resource Encryption" tab, developer can set and protect the data assets and resource of Unit3D project here.

![](/files/I2Z7rXBA1cUQtLdejlM2)

Switch on "Enable" button, then Virbox Protector will load the resource file;

Input password to encrypt Resources (Optional, if no password input, use the random password)

click "Select Files" to add other resource file to encrypt/protect it.

{% hint style="info" %}
&#x20;It is recommend to encrypt the resource file on default.
{% endhint %}

#### 3.Protect Unity3D External Resource in "Resource Encryption"

Since Unity3D projects often contain large size of AssetBundle files or other heavy resource files, developers frequently treat certain large resources (such as videos, images, or maps) as external files to improve project execution performance. Virbox Protector supports protecting both internal Unity3D resource files and related external resource files/folders. It also supports hot updates of these protected resources — meaning that when developers update resource files, they don’t need to republish the entire Unity3D project again. Instead, simply protecting/encrypting the new version of the resource file is sufficient.

**Here are process to introduce how to protect external resource in Unity3D project.**

**Parsing your unity3D project:**

Drag your unity folder into Virbox Protector; Go to `Resource Encryption` Tab;

Enable button & set password to encrypt the resource, as shown in screenshot in blow. and set/input the password:

<figure><img src="/files/QrXiHE5NPF4bcrOxWM1g" alt=""><figcaption></figcaption></figure>

**Save the configuration to protection option**

Click the button in File menu: `Save Selected Configuration`

<figure><img src="/files/ImYj9PXnNXkaH6iVNhdS" alt=""><figcaption></figcaption></figure>

**Encrypt the external resource**

Go to `Resource Encryption` Tab, Click the Button: `Encrypt External` on the top right of `Resource Encryption`;

\--a windows will pop up which list the external file to be protect/encrypt:

Pls refer following steps to:

* Input/Select the external resource file to be encrypted from the folder located;
* Output folder (encrypted external file folder);
* and select these external resource file to be encrypted;

and click the button `Encrypt` to encrypt these external resource file;

<figure><img src="/files/zNSr9a6bO9KqpmXwKDpm" alt=""><figcaption></figcaption></figure>

Note:

1. When password not changed. protect the Unity folder just need to protect once;
2. When you have saved the protection configuration file (click to `Save selected configuration`), you can open the external resource file folder in `File Menu` to protect external resource file directly:

<figure><img src="/files/6PGdZgUUGme0VlJfEqtE" alt=""><figcaption></figcaption></figure>

#### 5. Click to start "Protection" Process

Click to "Protect Selected Projects" to start the protection process.

![](/files/dTqBKKswISwTlZoiZi6C)

Go to the output folder, besides of original project directory, `Ball2018 2.4f1_X64`.

you will find 1 new protected app folder (*Ball2018.4.f1\_X64 protected*) and

1 new file (the configuration file: *`Ball2018.2.4f1_X64.ssp`*) has been generated.&#x20;

Go to the "protected folder", you can find and use the protected application in this folder for further testing and evaluation,&#x20;

![](/files/zCMEGRB6yOsGXhtlewKy)

#### 6. Back up source Apk and use the protected Apk for further testing

You need to back up your source app, configuration file and use debugging tool and decompiler to verify, test the security performance of protected App.

{% hint style="info" %}
The configuration file can be used for:

When you updated your App version and protect your latest version with same "protection option"

Use Virbox protector  CLI tool to protect your app later.
{% endhint %}

## Use Virbox Protector CLI tool to protect the Unity3D Apk

### Set protection options and generate the configuration file&#x20;

Open Virbox Protector GUI tool, Set the protection options to your apk and generated the configuration file, you may refer and follow the steps to the protection setting described in above chapter.&#x20;

and click the button:  `"Save Selected Project`"  in the main menu to generate the "configuration file", a file with the suffix name: <mark style="color:blue;">`.ssp`</mark>

Put this configuration file into the same directory of the apk which you want to protect.

### Use the Virbox Protector CLI tool to protect your App

Find the Virbox Protector CLI tools: `virboxprotector_con.exe`:

windows:

`C:\Program Files\senseshield\Virbox Protector 2\bin`

Linux:

`/usr/share/virboxprotector/bin`

macOS:&#x20;

&#x20;`/Applications/Virbox Protector 2.app/Contents/MacOS/bin`

**Use following command to protect you apk in CLI mode**.

`virboxprotector_con <application_path> -o <output_application_path>`

## Execution Performance and Technical Mechanism

| Protection Feature                    | Performance impact                                                         | Technical mechanics                                                                                                                                                      |
| ------------------------------------- | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Assembly Encryption                   | Execution performance related with the Qty. and size of methods encrypted. | To encrypt the methods which contained in the Assembly and Encrypt the assembly also, and decrypt these methods and assembly  when compiling the IL  during JIT process. |
| Resource Encryption                   | related with the the size and  no. of "resource" encrypted                 | Select the resource to encrypt and decrypt it in the Unity enginer (modefied) when executed.                                                                             |
| Anti Debugging                        | almost no impact to performance                                            | Use the system API or memo status to detect the debug tool                                                                                                               |
| Unity3D Engine Protection (IL2CPP)    | Slightly impact execution performance                                      | Obfuscate the instruction combine with calling detect                                                                                                                    |
| MetaData-Name of Obfuscation (IL2CPP) | No impact                                                                  | Parse gloabl-metadat.dat and modify the name                                                                                                                             |
| Memory Check (IL2CPP)                 | slightly impact when start execution                                       | Vcan and verify if the instruction be tampered.                                                                                                                          |
| Signature Check                       | slightly impact when start execution                                       | Verify the developer signature in the APK or AAB                                                                                                                         |
| File Check                            | Slightly impact when start execution                                       | Verify the hash of each file                                                                                                                                             |
| Anti Injection                        | almost no impact execution performance                                     | Use the system API to prevent debugger and modify the momory                                                                                                             |
| Emulator Detection                    | Slightly impact when start executio                                        | To detect if the runnging device info. is real hardware info generated.                                                                                                  |
| Root Detection                        | Slightly impact when start executio                                        | To detect if the running environment is root environment.                                                                                                                |
| Multi-Parallel Detection              | Slightly impact when start executio                                        | To detect if the running environment is multi-parallel environment                                                                                                       |


# Protect Mobile applications


# Protect Android AAB Projects

## Protect Android AAB Projects

### Introduction

The **A**ndroid **A**pp **Bundle** is latest format for Android application publishing which request by Google Play Store. Valid from August of 2021, All of Android developer who want to go to Google app store to publish Android application will submit their application with AAB format.

Here we introduce how to use Virbox Protector, a Secure and hardening tool, to protect AAB format application quickly.

Using Virbox Protector, developer will quickly complete the encryption/protection process to the AAB application without additional coding on local premise and no need to upload your application to cloud and no any leaky risk for your android application to upload to cloud.

**Virbox Protector** supports to protect/encrypt the AAB project both in GUI tool and CLI tool

​ With Virbox Protector, the Protected AAB will capable to defend the debugging/decompiling and to prevent IDA or other reverse engineering tool parsing to crack and get source code, With Signature verification, to prevent repackaging and protect critical code, IP be stealing or tampering.

### Use Virbox Protector GUI tool to protect AAB project in 7 Steps

1. Import the AAB project into Virbox Protector; Drag the AAB project into the Virbox Protector
2. Set the configuration of "Protection Option"; (Protect the AAB in general)
3. Set the configuration of "Function Option"; (Protect specified functions)
4. Set the configuration of “Resource Encryption" (Protect the AAB resource & assets)
5. Set the configuration of "Native library Protection" (Protect libs )
6. Click to Start the "Protection" Process
7. Backup the source file and use the protected project for further testing and save the "configuration" file which can be reused when you update AAB version later.

### Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Find Virbox Protector GUI tools in the \bin, the sub directory of the Virbox Protection installation directory: `virboxprotector.exe` and execute it.

Sign in with your account as shown as the snapshot bleow:

![](/files/6csXMSMJlGIMFqnPUom8)

{% hint style="info" %}
Above prerequisites is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.
{% endhint %}

### Protection Process

#### 1. Import the AAB project into Virbox Protector;

Open Virbox Protector, Drag the AAB project into the Virbox Protector or:

Click the Menu-->File-->Open File which located in the Main menu of Virbox Protector, to select the project (AAB format) which you plan to protect;

![](/files/ucvu0WVfw4BkRtxSYZfa)

#### 2. Set the configuration of "Protection Option"; (Protect the AAB in general)

Go to "Protection Option" to set:

2.1 Output path and output file name, click box in right to change output path and name;

On default, the output protected AAB file will be located at new created sub director: \protected\same aab name which in same directory; click "..." to change.

The Configuration file will be generated also at same directory of source AAB file;

2.2 Set the protection option to Android APK in General to prevent debugging and decompiling

![](/files/EnoXF8Qd7waNv3V8UA7I)

"**Dex Encryption**": Protect and encrypt the Dex file in general and hide the file to prevent decompiling;

{% hint style="info" %}
&#x20;Not recommend to select "Dex encryption" in case the AAB will be published in Google Play Store to avoid failed to pass Google check. and instead with use *Virtualization* to protect the functions contained in the Dex file.
{% endhint %}

"**Anti-Debugging**": with multiple detective technology to detect debugging, when the debugger use the IDA or other third party debug tools to debug the protected Apk/AAB projects, the protected APK/AAB will exit directly;

"**File Check**": to ensure the File integrity, Use hash to verify each files integrity contained in the AAB package and make sure not be tampered. more security option, recommend to click and select.

"**Anti-Injection**": with dual session `ptrace` technology, prevent the other session from add debugging or injection to APK session;

"**Signature check**" (Optional): Check/verify the developer signature to prevent repackaging and tampering; or you may use Google signature;

"**Emulator Detection**", to prevent the App/AAB running in the emulator environment'

"**Root Detection**" to prevent the App/AAB running in the rooted device;

"**Multi-Parallel Detection**" to prevent App/AAB running with multiple account;

Click and "**Enable sign**" to set/input keystore file, path and password. etc;

2.3 Sign setting and keystore path setting

{% hint style="info" %}
If you want to publish your AAB package in the Google Play Store, do not click and set keystore file here, otherwise Google Play Store will also sign your AAB file later which it will cause your AAB package collapse
{% endhint %}

2.3.1 Click and "**Enable Sign**"  and input keystore file, path and password. etc;

​ keystore file can be regenerated in case no keystore file available:

Use following command to generate new keystore file:

​ `keytool -genkey -alias aliasname -keyalg RSA -validity 36500 -keystore filename`

​ 2. Enable sign:  a signature will be signed automatically after protection,&#x20;

If not enabled sign, a signature need to sign after protection, or use Google signature later;

a signature command can be referred as followed (if you did not click "enable sign" and not use Google Play Store to publish your AAB Project, then refer following signing command:

`jarsigner -digestalg SHA1 -sigalg SHA256withRSA -keystore keystore file -storepass "password" -keypass "aliasname password!" "the AAB package to be signed" "Aliasname"`

#### 3. Set the configuration of "Function Option"; (Protect specified functions)

Virbox Protector supports developer to protect specified "functions (Method)" in the DEX file with "DEX Virtualization" Protection.&#x20;

{% hint style="info" %}
"DEX Virtualization" means converts and transform the bytecode of DEX methods into the self defined Virtual machines instructions, which interpreted and executed by the Self defined Virtual machine. With the "DEX Virtualization", the bytecode of method can not be reversed and decompiled.&#x20;
{% endhint %}

Go to "Function Option" tabs to set protection option to specified "functions"

add the these specified functions (methods) which need to be protected:

Click "Add Functions" to select and add the functions which need to be protected. Its recommend to protect those functions which is critical (to keep execution performance)

Select the protection mode to be the "Virtualization"

Virbox Protector provides “Virtualization" mode to protect the function contained in the DEX file. the mechanism is convert the Bytecode of Dex's Method to self defined VM instruction and executed. with "Virtualization" protection mode, it will enhance the security to protected AAB projects.

&#x20;The on default protection mode for Virbox Protector will be "Virtualization", and select to protect the entry functions. but you need to select those critical functions by yourself.

![](/files/X620bzvo12lvO2N9UpOn)

#### 4. Set the configuration of “Resource Encryption" (Protect the AAB resource and assets)

Virbox Protector support to protect the file, picture, configuration and script file which under \assets;

Before go to "Resource Encryption" to encrypt the resource and asset, please click "Save Selected Configuration" to save the configuration setting; then go to “Resource Encryption" and switch on the "Enable" button and select the assets and resource file to be protected or delete the file.&#x20;

![](/files/GT5lUgfrCSNVtHHzrADv)

#### 5. Set the configuration of "Native library Protection"

Virbox Protector support to encrypt/protect .so libs, include to "Encryption", "Compression" the code section of the .so libs, hide the import/export functions etc.

{% hint style="info" %}
For the Developer who use .so libs to keep critical functions, algorithms, Virbox Protector provides additional license to protect (Virtualization) the functions, algorithm contained in the .so libs. pls refer relevant sections.
{% endhint %}

Go to "Native libs"

Click to select the files (libs) to be protected;

Click to select to hide Symbol Table (Optional)

![](/files/fHByW8mJNi9xZqE4eVV8)

#### 6. Click to Start the "Protection" Process

Click "Save Selected Configurations" to save the configuration files. or Click "Save all configuration" if you have set multiple projects; after saved, you will find a new "ssp" configuration file generated, in below example, the "`app-release.aab.ssp`" has been generated in the output directory.

Click "Protect Selected Project" to start the protection process, a new protected project will be generated. in below example. the protected AAB project located new sub directory:\protected\app-release.aab.

![](/files/oOmK6n2Cjbk9SKVENxWe)

![](/files/M204f45vgdh3cXewJI22)

#### 7. Backup the source project. use the protected AAB file to further testing and save the "configuration" file.

{% hint style="info" %}
**Signature Option: it is not recommend to select this option for AAB project Publish in&#x20;*****Google Play Store*****.**
{% endhint %}

When you finalize all of evaluation and testing to the protected AAB project. next step is publish your AAB project in *Google Play Store.*

When we set the "Protection Option", we have recommend if you want to publish your AAB project in Google Play Store, then use Google's signature and DO NOT to use Virbox Protector signature option to avoid the signature conflict and crash in execution. so, when you set up in your Google account. you need to select "*Let Google manage and protect your app signing key"*

![](/files/20gXLlO1uFKhgDY4mhnm)

{% hint style="info" %}
**Automatic Integrity Protection (Google Play Store): not click to select this option**

The issue:&#x20;

When the protected AAB package launched by Google Play store, if user download the protected AAB, the package hangs long time or black screen happened. but when  the user donwload not via Google play store, it can be install in to user mobile and startup quickly.&#x20;

The solution:

When developer submit the protected AAP to Google Play store, pls DO NOT select this Option (the option in Google Play store, not the option of Virbox Protector):&#x20;

**Automatic Integrity Protection**
{% endhint %}

Rest of setting for publish in Google play store, just follow up Google instruction. for more detail, you may refer Google official instruction

{% embed url="<https://support.google.com/googleplay/android-developer#topic=>" %}

{% hint style="info" %}
Do not publish your AAB package protected by Virbox Protector trial license. pls use formal release license to protect your AAB package and publish in the Google Play Store
{% endhint %}

### Use Virbox Protector CLI tool to protect AAB project

Similar to protect other applications, Developer will have 2 options to protect AAB package.

Option 1:&#x20;

Use Virbox Protector GUI tool to protect and generate the "Configuration" file which to save the "Protection Option" setting. by Click "Save Selected Configuration"

Save the "configuration" file with the same folder of your AAB package, use Virbox Protector CLI tool to protect your AAB package.

`virboxprotector_con <file_path> <options ...> -o <output_path>`

Option 2:&#x20;

Use Virbox Protector CLI to protect AAB package directly, with option and argument which specify the protection options.

developer use "Long command line:" to specified protection options:

Long Command Line syntax

`Virboxprotector_con --{opt}=value`

value =1 means "Switch on", Value=0 means "Switch off"

For example

`--mem-check=1`, `--jit-enc=0`

Long Command Line setting: Protection Option setting

| Protection Option Setting                  | Command line option  | On default value |
| ------------------------------------------ | -------------------- | ---------------- |
| DEX Encryption                             | `--dex-enc=`         | `apk:1, AAB:0`   |
| File Check                                 | `--file-check=`      | `1`              |
| Enable sign                                | `--sign-check=`      | `0`              |
| Anti Injection                             | `--anti-inject=`     | `1`              |
| Debugger detection                         | `--detect-dbg=`      | `0`              |
| Emulator detection                         | `--detect-emu=`      | `0`              |
| Root Detection                             | `--detect-root=`     | `0`              |
| Multi parallel detection                   | `--detect-multi=`    | `0`              |
| Output apk (valid when AAB signing enabled | `--apks=<apks_path>` | N/A              |

Use `--help=apk`  to view help:

<figure><img src="/files/QCqje3QNrE7Q8kHy5SdW" alt=""><figcaption></figcaption></figure>


# Protect Android AAR projects

## Protect Android AAR Library

### Introduction

Android Archive (AAR) is the bundle of the binary distribution of an Android Library Which contains the libs used or reused across multiple apps. The AAR's structure is similar to a Android APK file.

**Virbox Protector** supports to protect/encrypt the Android Archive (AAR) library both in GUI tool and CLI tool

Using Virbox Protector, developer will quickly complete the encryption/protection process to the AAR projects without additional coding on local premise and no need to upload your application to cloud and no any leaky risk for your android application to upload to cloud.

With Virbox Protector, Developer can protect AAR project with multiple protection layer and protect to specified functions/method level with virtualization. The protected AAR can be effectively to defend decompiler to reverse engineering to retrieve the source code/functions.

Here we introduce how to use Virbox Protector, a Secure and hardening tool, to protect AAB format projects quickly.

### Protect AAR project in 5 Steps

1. Import the AAR project into Virbox Protector; Drag the AAR project into the Virbox Protector
2. Set the configuration of "Function Option"; (Protect specified functions)
3. Set the configuration of "Native library Protection" (Protect libs )
4. Click to Start the "Protection" Process
5. Backup the source file and use the protected project for further testing and save the "configuration" file

### Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Open Virbox Protector and sign in with your account;

![Virbox Protector GUI tool](/files/6csXMSMJlGIMFqnPUom8)

### Protection Process

#### 1. Import the AAB project into Virbox Protector;

Open Virbox Protector, Drag the AAR project into the Virbox Protector

or:

Click the Menu-->File-->Open File which located in the Main menu of Virbox Protector, to select the project (AAR) which you plan to protect;

![](/files/bNqizn71zgxmrPmqZ8zx)

#### 2. Set the configuration of "Function Option"; (Protect specified functions)

Go to the "Functions Options" to set the protection option to these specified "functions":

Click "Add Functions" to select and add the functions which need to be protected. Its recommend to protect those functions which is critical (to keep execution performance) and do not select all of function to be protected which will bring negative impact execution performance.

Select the protection mode to be the "Virtualization"

&#x20;click "Analysis" to simulate the execution performance;

![](/files/iA1VhXUPJ048Sgh5sIDX)

#### 3. Set the configuration of "Native library Protection" (Protect libs )

Virbox protector support to protect the libs contains in AAR project, Go to the "Native Library Protection":

Click "Select Files" to select those library which need to be protected;

&#x20;the libs be protected here only be compression, if you want to protect the functions contained in the libs. pls drag the protected libs in to the Virbox Protector and use "Function Option" to set the protection to those functions;

![](/files/ggNp3w2jyyzolMzaooYf)

#### 4. Click to Start the "Protection" Process

Click "Protect Selected Protects" to start the Protection process：

![](/files/5jhz3GG4KEtcBaAcX5Fy)

After protection completed, you will find;

a new "ssp" configuration file, has been generated in the output directory, in below example, the "**autoreplyprint.aar.ssp**" is the configuration file;

and another new sub directory \proteced has been generated and the protected AAR will be located in this new sub directory.

![](/files/VlLh55CfYJsLzU9AzYyW)

#### 5. Backup the source file. use the protected project for further testing and save the "configuration" file;

Now you can use the new protected project for further testing and evaluation the protection performance;

Follow up, we will briefing how to use Virbox Protector CLI tool to protect AAR project in command line mode:

### Protection Process by use of Virbox Protector CLI tool

Virbox Protector provides 2 ways to support developer to protect their projects, Virbox Protector GUI tool and Virbox Protector CLI tool. you can find the CLI tool under the \bin of Virbox Protector installation directory.

*virboxprotector\_con.exe*

![](/files/xutyWvZ4JACj4neprVOE)

1. Generate the configuration file

   Use Virbox Protector GUI tool to generate the .ssp configuration file, you can follow the operation in above steps to generate the configuration file.

   Select the functions which need to be protected in the "Function Options";

   Select the protection option: "Virtualization" to these Functions;

   Click "Save Selected Configuration" to generate a "Configuration" file;

   Put this "Configuration" file into the same directory which the AAR project located.
2. Execute the:*`virboxprotector_con.exe`*

   Open a terminal windows, go to the sub directory which *virboxprotector\_con.exe* locate and execute the command and return to view the help information.

![](/files/FZh8BdiUTeyCMM2xkdkE)

*3.* Protect the AAR projects:

*`virboxprotector_con.exe test.aar -o test.ssp.aar`*

the ***test.ssp.aar*** is the encrypted aar project after protection


# Protect Android APK Projects

#### Quick Start Guide:

## Protect Android APK Projects

### Introduction

Virbox Protector support developer to protect the Android Apk project to prevent the reverse engineering , decompiling, repackaging and tampering by third party attack. Developer may use Virbox Protector to protect/encrypt the apk and relevant elf, functions, resource and .so libs accordingly.

Here we introduce how to use Virbox Protector, a Secure and hardening tool, to protect Apk format application quickly.

Using Virbox Protector, developer will quickly complete the encryption/protection process to the Apk application without additional coding on local premise and no need to upload your application to cloud and no any leaky risk for your android application for uploading.

**Virbox Protector** supports to protect/encrypt the Apk project both in GUI tool and CLI tool

​ With Virbox Protector, the Protected APK will capable to defend debugging/decompiling and to prevent IDA or other reverse engineering tool from parsing to crack your APK project and get source code, With Signature verification, to prevent repackaging and protect critical code, IP be stealing or tampering.

### Protect APK project in 7 Steps

1. Import the Apk project into Virbox Protector; Drag the Apk project into the Virbox Protector
2. Set the configuration of "Protection Option"; (Protect the APK in general)
3. Set the configuration of "Function Option"; (Protect specified functions)
4. Set the configuration of “Resource Encryption" (Protect the APK resource & assets)
5. Set the configuration of "Native library Protection" (Protect .so libs )
6. Click to Start the "Protection" Process
7. Backup the source file. use the protected project for further security testing and save the "configuration" file.

### Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Open Virbox Protector and sign in with your account;

![](/files/RyeXXTmAMTlINu7Vtu4V)

:information\_source:Above prerequisites is for test/evaluation Virbox Protector only.

To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.

### Protection Process (Virbox Protector GUI tool)

#### 1. Import the APK project into Virbox Protector;

Open Virbox Protector, Drag your Android APK project into the Virbox Protector **or**:

Click the Menu-->File-->Open File which located in the Main menu of Virbox Protector, to select the project (APK format) which you plan to protect;

![](/files/qOiOY8IfgnYxZ2iAxd4S)

#### 2. Set the configuration of "Protection Option"; (Protect the APK project in general)

Go to "Protection Option" to set:

![](/files/BvJvucjWWdXzZW2X8MZF)

2.1 Output path and output file name, click box in right to change output path and name;

on default output AAB located：\protected\same name of source apk,  a new sub directory generated  in same directory; click "..." to change the output path.

and a configuration file will be generated in the output path(directory) with .ssp suffix. this configuration file save and stored  all of protection option you set, which can be used for next version updated.

2.2 Set the protection option to Android APK in General to prevent debugging and decompiling

"Dex Encryption": Protect and encrypt the Dex file in general and hide the file to prevent decompiling;

{% hint style="info" %}
Not recommend to select "Dex encryption" in case the APK project will be published in Google Play Store to avoid failed to pass Google check. and instead with use *Virtualization* to protect the functions contained in the Dex file (Setting in the "Function Option")
{% endhint %}

"Anti-Debugging": with multiple detective technology, when the debugger use the IDA or other third party debug tools to debug the protected Apk/AAB projects, the protected APK/AAB will exit directly;

"Signature check" (Optional): Check/verify the developer signature to prevent repackaging and tampering; or use Google signature.

"File Check": to ensure the File integrity, Use hash to verify each files integrity contained in the AAB package and make sure not be tampered. more security option, recommend to click and select.

"Anti-Injection": with dual session ptrace technology, prevent the other session to add debugging or injection to APK session;

"Emulator Detection", to prevent the App/AAB running in the emulator environment'

"Root Detection" to prevent the App/AAB running in the rooted device;

"Multi-Parallel Detection" to prevent App/AAB running with multiple account;

Click and "Enable sign" to set/input keystore file, path and password. etc;

2.3 Sign setting and keystore path setting

Click and "Enable Sign" to set/input keystore file, path and password. etc;

if you didn't click "Enable sign" the protected apk need to be signed manually.

2.3.1 keystore file can be generated in case no keystore file available:

​ Use following command to generate new keystore file:

​ `keytool -genkey -alias aliasname -keyalg RSA -validity 36500 -keystore filename`.

​ 2.3.2. Enable sign:&#x20;

Select to sign a signature after protection, or:

not select and use Google signature to instead later.

#### 3. Set the configuration of "Function Option"; (Protect specified function)

Virbox Protector supports Developer to protect to specified functions （methods） in dex file with "DEX Virtualization" Protection.&#x20;

{% hint style="info" %}
"DEX Virtualization" means converts and transform the bytecode of DEX methods into the self defined Virtual machines instructions, which interpreted and executed by the Self defined Virtual machine. With the "DEX Virtualization", the bytecode of method can not be reversed and decompiled.&#x20;
{% endhint %}

Go to "Function Option" to set protection option to the critical and specified "functions" which need to be protected.

Add the the functions which need to be protected:

Click "Add Functions" to select and add the functions which need to be protected. Its recommend to protect those functions which is critical only and not select all of functions to protect (to keep execution performance).

Select the protection mode to be the "Virtualization"

Virbox Protector provides “Virtualization" mode to protect the functions contained in the DEX file. the mechanism is convert the Bytecode of Dex's Method to self-defined VM instruction and executed. with "Virtualization" protection mode, it will enhance the security dramatically to protected APK projects.

The on-default protection mode for Virbox Protector will be "Virtualization", and to protect the entry functions on default. for other functions, you need to select those critical functions by yourself.

Save your configuration: Before to set the "Resource Encryption", pls save your “configuration" by click the button "Save Selected Configuration" which on the GUI menu.

![](/files/mMK4xvL1JTd5TQOFYPjd)

#### 4. Set the configuration of “Resource Encryption" (Protect the APK resource and assets)

Virbox Protector support to protect the file, picture, configuration and script file which under `\assets`;

Before goto "Resource Encryption" to encrypt the resource and asset, please click "Save Selected Configuration" to save the configuration setting; then go to “Resource Encryption" and switch on the "Enable" button and select the assets and resource file to be protected or delete the file.

![](/files/GHVuQZ7Co8TYMfFkdWMY)

#### 5. Set the configuration of "Native library Protection"

Virbox Protector support to encrypt/protect .so libs, include to encrypt, compression the code section of the .so libs, hide the import/export functions etc.

{% hint style="info" %}
For the Developer who use .so libs to keep critical functions, algorithms, Virbox Protector provides additional license to protect (Virtualization) the functions, algorithm contained in the .so libs. pls refer relevant sections.
{% endhint %}

Go to "Native libs"

Click the "Select Files" (libs) to select the files to be protected;

Click to select the "Hide Symbol Table" (Optional)

![](/files/4iLZ1wUDqKnwkBOHztwX)

#### 6. Click to Start the "Protection" Process

Click "Save Selected Configurations" to save the configuration files. or Click "Save all configuration" if you have set multiple projects; after saved, you will find a new "ssp" configuration file, in below example, the "01.adobe.reader.apk\*\*.ssp\*\*" has been generated in the output directory.

Click "Protect Selected Project" to start the protection process, a new protected project will be generated.&#x20;

![](/files/nA9bCYeQgAXvHYufg72W)

In below example.&#x20;

the protected Apk project in this sample is located in the new sub directory generated:&#x20;

`\protected`

the configuration file which stored the protection option setting information also be generated which can be used for next version update.

`01.adobe.reader.ssp.apk.`

![](/files/cmEH9oV8fbbUc8oLDxue)

#### 7. Backup the source project. use the protected file for further security testing and save the "configuration" file.

{% hint style="info" %}
**Signature Option: it is not recommend to select this option for AAB project Publish in&#x20;*****Google Play Store*****.**
{% endhint %}

When you finalize all of evaluation and testing to the protected APK project. next step is publish your APK project in *Google Play Store.*

When we set the "Protection Option", we have recommend if you want to publish your APK project in Google Play Store, then use Google's signature and no need to use Virbox Protector signature option to avoid the signature conflict and crash in execution. so, when you set up in your Google account. you need to select "*Let Google manage and protect your app signing key"*

![](/files/Q6TDEAxpP0yLwI4jLPap)

{% hint style="info" %}
**Aumatic Integrity Protection (Google Play Store): not click to select this option**

The issue:&#x20;

When the protected AAB package launched by Google Play store, if user download the protected AAB, the package hangs long time or black screen happened. but when  the user donwload not via Google play store, it can be install in to user mobile and startup quickly.&#x20;

The solution:

When developer submit the protected AAP to Google Play store, pls DO NOT select this Option (the option in Google Play store, not the option of Virbox Protector):&#x20;

**Aumatic Integrity Protection**
{% endhint %}

Rest of setting for publish in Google play store, just follow up Google instruction. for more detail, you may refer Google official instruction

`https://support.google.com/googleplay/android-developer#topic=`

### Protection Process by Virbox Protector CLI tool

#### Similar to protect other applications, Developer will have 2 options to protect AAB package.

Option 1:&#x20;

Use Virbox Protector GUI tool to protect and generate the "Configuration" file which to save the "Protection Option" setting. by Click "Save Selected Configuration"

Save the "configuration" file with the same folder of your AAB package, use Virbox Protector CLI tool to protect your Apk package.

Option 2:&#x20;

Use Virbox Protector CLI to protect Apk package directly, with option and argument which specify the protection options.

Here we introduce the option 1 and option step by step as following:

Option 1

1\. Generate the .ssp， the configuration file which save the "Protection Option"

Before to use Virbox Protector CLI tool to start protection, you need to generate a "configuration" file which store the setting information of "protection option" to the APK which need to protected.

Open Virbox Protector Standalone GUI tool and sign in with your account and password.

Please refer the protection process by use of Virbox Protector GUI tool above to set the configuration in: Function option tabs, Protection option tabs, Resource Encryption tabs and Native library tabs, and click "Save All Configuration"

![](/files/y5H1gE32sctKOhNXg3b2)

then go to the output directory. you will find the .ssp file has been generated. see sample file attached.

![](/files/UwdbJzE8PSA8KISRSZ9t)

Put the configuration file which generated by Virbox Protector GUI tool in first step into the same directory of the  Android APK located.

`virboxprotector_con <file_path> <options ...> -o <output_path>`

{% hint style="info" %}
To generate a configuration file is optional, if no configuration generated, then when you use Virbox Protector CLI tool to protect APK/AAB file, the protected APK/AAB will not be signed, on default.
{% endhint %}

Option 2

#### Run the Virbox Protector CLI tool: virboxprotector\_con

Open a console terminal, Go to the Virbox protector's installation folder in your machine, and find the *virboxprotector\_con,exe* and open it in command line terminal:

The on default installation directory in windows system is:

`C:\Program Files\senseshield\Virbox Protector 3 Trial\bin`

The on default installation directory in Linux system is:

/`usr/share/virboxprotector/bin`

Input:

`​`` `*`virboxprotector_con.exe`*

to view the help info

![](/files/clC1Okd8ezunkkgp8IeV)

#### Use Virbox Protector CLI tool to protect to protect the APK directly

`virboxprotector_con <file_path> <options ...> -o <output_path>`

{% hint style="info" %}
For most of application types, Virbox Protector CLI tool will recognized application types and protect the application with protection option on default.
{% endhint %}

Another ways is developer use "Long command line:" to specified protection options:

Long Command Line syntax

`Virboxprotector_con --{opt}=value`

value =1 means "Switch on", Value=0 means "Switch off"

For example

`--mem-check=1`, `--jit-enc=0`

Long Command Line setting: Protection Option setting

| Protection Option Setting                  | Command line option  | On default value |
| ------------------------------------------ | -------------------- | ---------------- |
| DEX Encryption                             | `--dex-enc=`         | `apk:1, AAB:0`   |
| File Check                                 | `--file-check=`      | `1`              |
| Enable sign                                | `--sign-check=`      | `0`              |
| Anti Injection                             | `--anti-inject=`     | `1`              |
| Debugger detection                         | `--detect-dbg=`      | `0`              |
| Emulator detection                         | `--detect-emu=`      | `0`              |
| Root Detection                             | `--detect-root=`     | `0`              |
| Multi parallel detection                   | `--detect-multi=`    | `0`              |
| Output apk (valid when AAB signing enabled | `--apks=<apks_path>` | N/A              |

Use `--help=apk`  to view help:

<figure><img src="/files/QCqje3QNrE7Q8kHy5SdW" alt=""><figcaption></figcaption></figure>

After protection completed, the system will return message protection succeed.


# Protect Android shared library (.so libs)

## Protect Android shared library (.so libs)

Similar to the traditional Linux model, shared libraries in Android are relocatable ELF files that map to the address space of the process when loaded. To save memory and avoid code duplication, all shared objects shipped with Android are dynamically linked.&#x20;

**Virbox Protector** supports to protect Android shared library in both GUI tool and CLI tool with multiple encryption technology. Developer can protect and encrypt the .so lib to specified functional level, with obfuscation, virtualization, code of encryption etc. The protected .so libs can be effectively to defend the debug and dump in memory.

### Protect .so library in 5 steps

1. Import file: import .so library which need to be protected by Virbox Protector;
2. Set the configuration of "Function Option"; (Protect specified functions);
3. Set the configuration of "Protection Option"; (Protect .so library in general);
4. Click to Start the "Protection" Process;
5. Backup the source file. rename the protected file to source file name and save the "Configuration" file;

### Prerequisites

Sign-up Virbox Protector and install the Virbox Protector;

Open Virbox Protector and sign in with your account;

![](/files/RyeXXTmAMTlINu7Vtu4V)

{% hint style="info" %}
Above pre-requisition is for test/evaluation Virbox Protector only, To protect formal and commercial release .so library, pls purchase and get the related Virbox Protector license.
{% endhint %}

### Protection Process

#### 1. Import the .so library which you want to protect into Virbox protector

Drag the .so library into the Virbox protector directly, or:

Open file from Virbox Protector menu--> File-->Open File

Then Virbox Protector will parse the file to be protected automatically:

![](/files/i3jZQkrHfkmLFuwFwiet)

#### 2. Set the configuration of "Function Option"

Virbox Protector supports to protect the .so library to the specified function's level and provides several protection mode for developer selection to protect the critical functions.

Developer may select the functions contained in the so library and set the protection mode to specified functions here.

Click "Add Functions" button, left click to select the functions which you want to protect, right click to set the protection mode: Virtualization, Obfuscation, Encryption,

Ctrl+A to select “all of Function"

Not recommend to select and protect "all of functions" due to negative impact to execution performance.

Comparison of Security of Protection mode: Virtualization>Obfuscation>Encryption

![](/files/WxBsPKY0zxdlUaPdw813)

#### 3. Set the configuration of "Protection Option"; (Protect .so library in general);

Developer may set the protection configuration to the so library in general here:

![](/files/JoT9vrGmTQJ2bH6WT5fw)

3.1 Set the output path and new protected project name

3.2 Click to set the general protection to .so library;

Compression: To compress the file size and prevent the static decompiling

If the file size is too small, the compressed file size may not smaller or even bigger than the source file size;

Memory Check(Verify the code Integrity): When program executed in memory, The loader of Virbox Protector will check each memory block to ensure the code integrity to prevent tampering, repackaging;

Anti-Debugging: select to defend the debug tools to debug the project to prevent reverse engineering;

It is recommend to click above options in "Protection Options";

#### 4. Click to Start the "Protection" Process

When you complete the setting to "Function Option" and "Protection Option", Click to the button "Protect Selected Projects" in the Menu, to start the "Protection" Process. and click "OK" to complete the Protection process.

![](/files/7kskrV2JAW5EKP4h1ouk)

#### 5. Backup the source file. rename the protected file to source file name and save the "configuration" file

Go to output directory, you will find 2 new file has been generated:

![](/files/KxbrYAp38OlId9mtKu70)

The "libwebpbackport.so" is source file which not be protected. you need to keep the source file to another directory and not distribute this source file to your user.

The "libwebpbackport.so.ssp" is the configuration file which save all of protection option setting

The "libwebpbackport.ssp.so" is the protected file. you need to rename this file to source file for further testing or distribution later.


# Best Practice to Protect Android Apps

Share some experience to protect Android Apps

## The Challenge and security issue of Android apps (apk, aab & other types of Android apps)

### The security issue of Android Apps:

Like with the cracking and hacking behavior to other applications, usually, the third party threat actor use decompiler, reverse engineering tool to crack the Android apps in 2 aspects:

#### Static analysis:

Use the decompiler and reverse engineering tool to analysis Android apps, to get those sensitive information, strings of class, fields, functions/methods, and finally to get your source code, code logic, sensitive data, resource, etc.

#### Dynamic analysis:

The third party threat actor to analysis the runtime environment when application executed, for further memory dump, inject part of malicious code and repackaging your Android apps for reusing. In practically, those static and dynamical analysis and tool will help the third party threat actors to:

### Reverse engineering

Usually developer use Java/Kotlin to build the native Android Apps., and compile and packed with dex file in the Apk package. The dex file contains the critical information, such as, the class, methods, members and even contains the source file name, via dex file, the third party cracker may easily to decompile and get source code which developer invest lot of effort to build it.

<figure><img src="/files/Ok5jDTD1iOk9BFl6zFrI" alt=""><figcaption><p>Example: Decompiling The Dex file</p></figcaption></figure>

### Crack/Steal the Code logic

Without hardening and protection to Android Projects, it is easier to get the critical code logic by decompiling which makes lost revenue, investment and effort to project to developer.

### Repackaging/Tampering Android Apps.

Cracker may use the "apk tool" to decompile the dex file in the Apk file to be the "smali" code, by modify/edit the "smali" code, it may easy to edit/modify the code logic and insert malicious code and repackage to new Apk. which cause revenue lost or other negative impact to your business.

Here is snapshoot of java code by using the jadx tools decompiling:

<figure><img src="/files/9LoLNYbBe02KbeDsBPkR" alt=""><figcaption></figcaption></figure>

smali code

<figure><img src="/files/7Elj460BXsZbMnGMw2oV" alt=""><figcaption></figcaption></figure>

### Crack/Steal resource and data assets

For some Android apps: Games, GIS apps, developer also invest lots to create the resource assets, pictures, audio, video files attached in the apps. and for Android Apk file, it is the typical zip format file, and the third party may get apk resource, audio, video, profile easily.

## Protect/hardening the Android apps:

### The Total Solution from Virbox Protector

Integrated with multi layer encryption/protection technology, Virbox Protector supports Android developer:

​ Design tailor-made protection scheme to their Android apps and complete protection and hardening their Android apps easily and quickly, even for those developers without the hardening experience.

​ Effectively to defend static analysis to apps and dynamic analysis in runtime to prevent android apps from decompiling, reverse engineering, tampering and repackaging.

Here is overview to Virbox Protector solution to protect/hardening Android Apps: Apk, AAR, AAB, .so, Android Unity3D, etc.

<figure><img src="/files/31N7iy6dprwJN2rXRhtI" alt=""><figcaption></figcaption></figure>

### Runtime application self protection

With Virbox Protector hardening solution, Developer has capable to implement Runtime application self protection to the Android apps. RASP, which means when application start to execution in Runtime environment, the apps protect itself to prevent from the possible debugging and analyzing, memory dump behavior by third party. and also to defend injection, or other tampering action. and also detect if the apps running in the simulator or root environment which to prevent further debugging, cracking actions.

| Protection option               | Description                                                                                                                                                                 |
| ------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Anti debugging(Debug detection) | To prevent android apps being debugged by third party debugger, suchas IDA Pro, gdb, jeb etc. in case the debugging has been detected, the apps will be stopped and exited. |
| Anti Injection                  | To prevent apps being attached by "ptrace", inject to .so libs, and detect the hook etc;                                                                                    |
| Emulator Detection              | When the apps running in the emulator environment has been detected, then exit execution; to prevent possible debugging or analysis                                         |
| Root Detection                  | When the apps running in the "Root" environment has been detected, then exit execution; to prevent possible debugging or analysis                                           |
| Multi Parallel Detection        | when multi parallel environment has been detected, the apps will exit execution;                                                                                            |

As shown as above Runtime application self protection in below snapshot, developer just click and select those function to accomplish protection setting, no additional coding required.

<figure><img src="/files/S4qsgrVxAnO24SMfTAKT" alt=""><figcaption></figcaption></figure>

### Anti Reverse Engineering

Developer also may click and select following protection options to prevent the dex file, .so libs, scripting language and function/methods being decompiled, stolen, reverse engineering. etc.

| Protection Option                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Dex Encryption                           | To encrypt and hide all of the dex file contained in the apk, to prevent the third party to use "jadx", "jeb" , the decompiler tool to decompile the dex file;                                                                                                                                                                                                                                                                                                                                                           |
| Dex Virtualization                       | Developer may select those critical/important function/methods in the dex file and use "Virtualization" protection option to protect those methods. and convert/transform the code and execute in the self define Virtual machine environment. which effectively to prevent the memory dump to reverse the source code. The critical functions/methods can be: the license code check algorithm implementation, an innovative optimization method, or any of code/algorithm which value worth important need to protect. |
| Encryption to resource and data assets   | Encrypt the resource file, data assets, profiles in the apk, to prevent those resource file being stolen and used.                                                                                                                                                                                                                                                                                                                                                                                                       |
| Protect .so libs                         | Protect to specified .so libs in the Apk file, to encrypt the code section, which to prevent the IDA Pro tools to de-assembling, decompiling.                                                                                                                                                                                                                                                                                                                                                                            |
| Protect .so libs (hide the symbol table) | Hide the export functions in the .so libs, to encrypt the ELF relocatable which to prevent the .so libs unpacked.                                                                                                                                                                                                                                                                                                                                                                                                        |

**Developer may select those "Anti Reverse Engineering" Protection option in following tabs as shown as below:**

Dex Encryption, Encryption to Resource and data assets, Protect so libs, Encryption to the scripting language (if any)

<figure><img src="/files/vihMl3XXOuB4c12PfBv5" alt=""><figcaption></figcaption></figure>

For Dex Virtualization (Function/method Virtulization) Setting, Developer may select and enable protection option in the "**Function Option**" tab, Select those critical & Important methods to protect:

<figure><img src="/files/mXbMPLDHbYLEbVNvwyUU" alt=""><figcaption></figcaption></figure>

**The Result by using Dex Virtualization**

**Before Dex Virtualization**

<figure><img src="/files/VkIqMuXKl6ZPK2xMxMf2" alt=""><figcaption></figcaption></figure>

**After Dex Virtualization**

<figure><img src="/files/7QTsLj7MTazw8qnQKmmQ" alt=""><figcaption></figcaption></figure>

After selection "Virtualization" protection option, the program will jump into self defined interpreter to execute the method (see the method "vm\_void" above)

### Anti-Tampering

Select these anti tampering protection options, the protected program will check code integrity and file integrity which to prevent the application being tampered and repackaging.

| Protection Option | Description                                                                                                                  |
| ----------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| Sign Check        | To check/verify the developer signature in the Apk file to prevent the re signed after repackaging by third party illegally. |
| File Check        | To check/verify the resource file, scripting, .so libs, to prevent those file in the Apk being tampered for repackaging.     |

Developer set these 2 Anti Tampering protection options here:

<figure><img src="/files/d0pPidhrtzFWBiOx1AF3" alt=""><figcaption></figcaption></figure>

### Enable to sign the protected Apk files

also, one thing remind, when you design and complete every function/protection option setting, before you start the protection process, you need to click to enable sign setting for protected apk also and input: Keystore path,

​ Password,

​ Key alias,

​ Key Alias Password etc.

<figure><img src="/files/gmh1WnJtrf1Ye6nHFaJH" alt=""><figcaption></figcaption></figure>

### Click to start & complete the protection process.

<figure><img src="/files/H6SMiDUX8xPzcMVOxx1O" alt=""><figcaption></figcaption></figure>

#### Enjoy & Cheers:)

For technical issue/support for [`Virbox Protector`](https://appsec.virbox.com/)

please contact us at:&#x20;

<support@senselock.com>

### Support Environment

#### Operation System

Android 4.0 and above

#### CPU Architecture:

ARM V7, V8, X86, X64

#### Device type:

Android tablet, Android mobile, Emulator, etc.

### For more information & Trial, welcome to visit:

<https://appsec.virbox.com/apply.html>

[Virbox Protector](https://appsec.virbox.com/): Protect & Hardening your android apps on your premise, offline, no restriction apps version, size, volumes of subscriber activated. etc.


# Protect iOS Project

## Overview

Virbox Protector supports to protect/encrypt the iOS project with GUI tool and CLI tool both.

The format of executive iOS application is MachO format.

Here we use the project "**CoupletLabel**" as a example to introduce how to use Virbox Protector to protect and distribute the project to Apple store.

Tips

> It is suggested to protect iOS projects in Mac environment, which is easier and convenient to sign the iOS application;

### The security of iOS application

Although the iOS application download from **App Store** has been protected, but with the more powerful crack tool available in the market (for example, Clutch) , with these tools, it will not make too big challenge to professional cracker to decrypt the protected iOS application. further more, the cracker may:

use the tools:

`class-dump` to dump and export all of head file of MachO fille;

use hopper or IDA tools to analysis the code MachO file to reverse the source code;

So, for those machO file which require highly security, it is mandatory and necessary to protect with code hardening and app shielding tools.

### Functionality

`Virbox Protector` supports developer to protect iOS application, IPA package, developer may use Virbox Protector GUI tool or CLI tool, to protect specified critical functions with fine grained and general protection to  iOS application or IPA package. which effectively to prevent reverse engineering, dumping, debugging tampering and repackaging to iOS application and IPA package.

#### **General Protection to iOS app, IPA package**&#x20;

> Set general protection in "Protection Option" tab

**Memory Check**

with `Memory Check`, it will check and verify integrity of iOS package when **load** the apps, when tampering has been detected, then quit the execution;

when developer need to check memory in app execution, you can use and set the `SDK label` to check memory in source code accordingly;

**Objective C Name obfuscation**

OC name of obfuscation, means to obfuscate class name into a meaningless string name, and cracker can not identify the calling relationship by use of class name.

> **Tips**
>
> 1. OC name of obfuscation, supports to obfuscate the class name only,
>
> doesn't support to obfuscate the name of method, for the class name which calling other resources, it doesn't support also;
>
> 2. If the obfuscate code involves the reflection calls cross-module , OC name obfuscation may cause the GUI interface functions doesn't work properly.

**Sample**

Not using OC name of obfuscation, use decompiler to decompile the class name of original iOS package, the decompiled result as shown in below:

<figure><img src="/files/tNrcdZOmilXS3y8tLD6h" alt=""><figcaption></figcaption></figure>

When using the OC name of Obfuscation, the decompiled result to the class name of iOS application as shown in below:

<figure><img src="/files/egRg3VczsVex9KJ68uxh" alt=""><figcaption></figcaption></figure>

Comparison: all class name has be obfuscated and meaningless. no useful by cracker

**Debugger Detect**

Debugging is important way in reverse engineering process, it will be quickly tracing & positioning to relevant logic in massive binary instruction when debugging used.

Debugger Detect feature, when this feature enabled, it will detect/monitor if current module process being debugged by IDA Pro/ lldb tools, when debugging has been detected, the protected application will be quit execution.

**Strip Debugging information**

the execution program in IPA package may contained `debug` information and `static symbol table`, which contained the information to functions name, address, etc. if such kind of information has been included when launched and released. it will have potential threaten to your apps;

Use and enable the feature: `Strip Debugging information`, it will remove/strip the .debug info and `static symbol table`

**Sample**

The symbol contained in the original program: as shown in below:

<figure><img src="/files/F5nvBMTk2l4GdaAlBig5" alt=""><figcaption></figcaption></figure>

The symbol when click to enable `Strip debugging information`, as shown in below:

<figure><img src="/files/0P4hW6J6t6xdGQiwiR1e" alt=""><figcaption></figcaption></figure>

**Signature Verification**

To verify developer signature certificate (Team ID), to prevent the IPA package being repackaged and signed again by third party;

> Tips:
>
> 1\) To enable the sign verification, it is mandatory to enable sign option;
>
> 2\) To enable sign, Sign verification can be optional;

**Sign setting**

When sign enabled, it must select the sign certificate consistent with the certificate when use xCode to compile the xCarchive, then protected app has been signed on default;

When sign disabled, then protected app will not signed on default, developer need to manual sign the protected app (for example, developer may use `codesign`, iOS app Signer to sign the app);

#### **Protect  Function (Function Option tab)**

> Developer may select and set the protection option to specified functions in "Function Option" tabs when you use Virbox GUI tool;

**Code of Obfuscation**

Code obfuscation means the process of the converting the original instructions in a function into random instruction fragments that are difficult to read with the method of equivalent transformation, immediate number encryption, indirect jump, false branch, junk instruction scrambling, and instruction slicing.

**Sample**

Use decompiler to decompile the original applications (without code of obfuscation), as shown in below:

<figure><img src="/files/CyJjqywldt1AB56rfjAY" alt=""><figcaption></figcaption></figure>

Use decompiler to decompile the  app with the Code of obfuscation, as shown in below:

<figure><img src="/files/vKA9POxn4OJ1ZolozA6P" alt=""><figcaption></figcaption></figure>

**Code of Virtualization**

Code of Virtualization, means with the "Virtualization" process, the original assembly instructions in the function are converted into customized virtual instructions, which are executed in a customized virtual machine at runtime, simulating the memory access, conditional judgment, register status, etc. in the assembly instructions.

**Sample**

Use decompiler to decompile the "Virtualized" app, as shown in below:

<figure><img src="/files/HP3gBdie6c0FEvPFcC88" alt=""><figcaption></figcaption></figure>

## Protection Process: (Using Virbox Protector GUI tool)

> Developer may select either the Virbox Protector GUI tool or CLI tool to protect iOS applications.

### Compile application with Xcode

1. Compile and build `xcarchive` file which contained the dSYM file

Modify the compile option, the `xcarchive` package compiled contained the dSYM file

Operation:

```
 Xcode->TARGETS->Build Setting->Build Options->Debug Information Format
```

**to select to enable Option:**

**`DWARF with dYSM option`**

Tips:

> The purpose to select and enable this option is to make the xcarchive file being built contained the dSYM file, which to show the function's names when Virbox Protector parse the iOS project. otherwise the functions will only show the relevant address respectively.

<figure><img src="/files/tAVGon0faFbUoYIuxwJC" alt=""><figcaption></figcaption></figure>

2. Diable the Bitcode option

Virbox Protector doesn't support the bitcode, and also, the Xcode editor disable the `bitcode` option start from V 15., so, for developer who use the xCode editor higher than 15. you can ignore below operation;

For developer still use the xCode version under 15, it is necessary to disable the option of `bitcode` when compiling project, as shown in below:

`Xcode->TARGETS->Build Setting->Build Options->Enable Bitcode->no；`

<figure><img src="/files/7qgP5WyPqkDEQILPTjqE" alt=""><figcaption></figcaption></figure>

3. Build and archive the project

Build/Archive the project:&#x20;

`Xcode->Product->Archive`

<figure><img src="/files/QPl5rbu3gjukQ79K1Ji4" alt=""><figcaption></figcaption></figure>

4. Next, Go to the Archive page

<figure><img src="/files/M0DfinmUILsLgVKh9v4g" alt=""><figcaption></figcaption></figure>

5. Select the project archived and right click in "Finder" to open the archive

<figure><img src="/files/fTaGOmeoDIzhsQ3Lep9H" alt=""><figcaption></figcaption></figure>

6. Find the the xcarchive being built, and right click `Show Package Content`

<figure><img src="/files/smyvGPeUzRw8m82sebzb" alt=""><figcaption></figcaption></figure>

7. Go to the archive, find the un-protected application located at:

`Products\Applications`

<figure><img src="/files/rtcjQ5YVbjSpvS1ogjr0" alt=""><figcaption></figcaption></figure>

### Protect iOS Project

#### Open Virbox Protector GUI tools and Sign-in with your account

Find the sub directory which "application" located, Drag the "applications" into the Virbox Protector GUI tools

#### Protect the critical functions (in Function option tab)

Go to:

`Function Option` tab and click "`Add Functions`" button in upper right corner of the page

<figure><img src="/files/tHQKNrXTjVsofz73kYo5" alt=""><figcaption></figcaption></figure>

Click the "`Add Function`" button in Upper right corner to select the functions which need to be protected, and right click to select the "Protection mode" to each functions: `Virtualization`, `Obfuscation`, or `No protect`

Tips

> The Functions selection and protection process to iOS project is similar process to Android and native application process. more information you may refer Android protection process or Native project protection process.

<figure><img src="/files/cBu40aQoBexySawxXD2C" alt=""><figcaption></figcaption></figure>

Tips

> For those iOS application which compiled with Objective C or Swift language, the symbole contained by themself, so Virbox Protector will parse and identify the name of function whether or not contained dSYM file;
>
> For those iOS application called library which compiled by C/C++, then the library doesn't include symbol after compiled, so dSYM file required to identify the name of functions;
>
> Save the dYSM file into the same directory of app files located. then Virbox Protector may parse and shown the function's name. Otherwise, the functions parsed will be shown the address only;
>
> For xcarchive package, it is no need to save the dYSM file into the same directory. Virbox Protector will reading relevant information automatically.
>
> The dYSM file location: as shown in below:

<figure><img src="/files/LEqdvczSRCxJXy2mlSE2" alt=""><figcaption></figcaption></figure>

#### General Protection Setting (Setting in Protection Option tab)

Go to "`Protection Option`" tab

Set the `Output` path and `output` file name, click box in right to change output path and output name;

<figure><img src="/files/z4gYIOh1w8KDChUNfB9I" alt=""><figcaption></figcaption></figure>

Set the protection option to iOS apps in General to prevent debugging and decompiling

**Memory Check**: To prevent apps being tampered.

**Objective-C, Name Obfuscation**: To prevent the Objective-C class dumping, to get the name of method.

**Debugger Detection**: to detect the debugger, to prevent dynamic analysis and debug apps

**Strip Debugging Info**: To remove the debugging information

**Sign Setting**

Click to enable the Signature option, then please keep the signature certificate in consistent with the certificate signed when Xcode compile and build the xcarchive, and then the protected apps has been signed on default.

If you doesn't click to enable the signature, then the protected apps will be Not signed on default. so, it is necessary for developer to sign the protected applications manually (for example, use the "codesign " command line to sign, or use the iOS App Signer tool to sign the apps), and keep the certificated signed consistent with the certificate signed when use Xcode to built project.

Tips

> If the protected apps will be installed in the mobile which non jailbreak. make sure the account specified in Xcode compiling: signing>Team, is consistent with the account used to sign in Virbox Protector.

#### Click "Protect Selected Project" to start protection

<figure><img src="/files/tEA1xxHI58H6Qwv2aZxR" alt=""><figcaption></figcaption></figure>

When protection completed, following "file" will be generated:

\*\*\*.app.ssp: this is the configuration file which saved the setting of `Function Option` and `Protection Option` Tabs. this configuration file location is same as the original file. so it is no need to re set the configuration when you use the Virbox Protector to re protect the file. use the previous configuration file will be fine.

/protected/\*\*\*.ipa: the new IPA package which protected and new generated;

/protected/\*\*\*.app: the new application after protection/shielding.

<figure><img src="/files/qdBZKHtIDMHp4NPMTcLv" alt=""><figcaption></figcaption></figure>

### Distribute the Protected Application to App store

Before distribute the application to App store, it is necessary to back up and move the original applications to another folder. and:

Move the protected application to the folder which the original application located. please don't save it in the xcarchive package.

after above update completed, back to Archived page and click "`Distribute App`" to launch applications

<figure><img src="/files/kpxpZYI5kg9ZYP8rAmec" alt=""><figcaption></figcaption></figure>

## Protection Process: By Virbox Protector CLI tool

Virbox Protector provides CLI to developer to protect iOS application;

The CLI tools: `virboxprotector_con` ,

located at (on default installation path):

```
Windows:C:\Program Files\senseshield\Virbox Protector 3\bin 
​
Linux:/usr/share/virboxprotector/bin 
​
macOS:/Applications/Virbox Protector 3.app/Contents/MacOS/bin 
```

### **With the Configuration file to protect iOS application**

(Protection option configuration file) will be generated: `.ssp` file, then developer can use the same setting (protection configuration file) and use Virbox Protector CLI to protect iOS applications, the CLI command:

```
 virboxprotector_con <input_file> -o <output_file> 
```

then, `virboxprotector_con` , the CLI tools will automatically to search the \<input\_file.ssp, as a configuration file and use protection option setting defined in the configuration to start the protection.

#### Generate the configuration file

In this step, Use Virbox Protector GUI to set the protection option in "`Function Option`" and "`Protection Option`" Tabs to generate .SSP file.

The setting process is similar with the process by use of Virbox Protector GUI tool to protect the apps. only difference is in last step, after you complete the all setting options, click the button:

`Save all Configuration`

as shown in below snapshot.

This configuration file generated will be used by CLI tool in second steps.

<figure><img src="/files/wReifGGqH2LASHRq2wdI" alt=""><figcaption></figcaption></figure>

### Use Virbox Protector CLI to protect iOS apps

Go to the sub directory which Virbox Protector CLI tool located and find the CLI tools

find the Virbox Protector app, open the app folder, you can find the

```
virboxprotector_con
```

under the `/contents/MacOS/bin` directory

#### View "Help" information:

Open the terminal windows, go to the folder: "`virboxprotector_con`", input:

`virboxprotector_con`

to view the help information

#### Execute the protection command

```
 virboxprotector_con helloworld.app -o ssp.helloworld.app 
```

### **Without the Configuration file to protect iOS application**

in case the Configuration file doesn't generated, when developer use the Virbox Protector CLI to protect applications,

The CLI tool `virboxprotector_con` will use the on default protection option setting to protect iOS applications;

Developer also may set the protection option by pass the options, you may refer CLI Option in below:

#### **Protection Option setting to CLI tool**

**Protection Option Setting**

| Protection setting           | Option             | on default value |
| ---------------------------- | ------------------ | ---------------- |
| Memory Check                 | `--mem-check=`     | `0`              |
| Debugger detection           | `--detect-dbg=`    | `0`              |
| Objective C Name Obfuscation | `--objc-rename=`   | `0`              |
| Sign setting: enable sign    | `--sign-check=`    | `0`              |
| Strip Debugging info         | `--strip-dbginfo=` | `1`              |

**Sample**

To protect IPA package, select and enable the option:

`Memory Check`

`Debugger Detection`

`Strip Debugging info`,

and disable

`Sign`

Use following command:

```
virboxprotector_con test.ipa --mem-check=1 --detect-dbg=1 --strip-dbginfo=1 -o protector/test.ipa 
```

#### **Sign Option setting**

| Setting            | Option        |
| ------------------ | ------------- |
| Sign enable        | `--sign=`     |
| Certificate        | `--identity=` |
| ipa package output | `--ipa=`      |

**Sample**

1. Use Command line to view system certificate

   ```
    security find-identity -v -p codesigning 
   ```
2. To protect IPA package, click to select the option:

   Memory Check

   Debugger Detection

   Sign enable & Verification

   Use following command:

   ```
   virboxprotector_con test.ipa --mem-check=1 --detect-dbg=1 --sign-check=1 --sign=1 --identity="certficate id" -o protector/test.ipa 
   ```

#### **Function Protection option setting**

| Function Protection setting     | Option                  |
| ------------------------------- | ----------------------- |
| Code of Virtualization          | `-v`                    |
| Code of Obfuscation (Mutation)  | `-m`                    |
| Code of Encryption              | `-e`                    |
| Ignore the function not support | `--ignore-unsupported=` |

Support to protect functions with specified function name or set a rule to protect functions, to split each setting with semicolon,

support with wildcard `*`

Example

```
-m "function1;function2" -v "function3;function4" -e "test*" --ignore-unsupported=1 
```

### Upload the protected application

Developer use Xcode, or Transpoter to upload the protected application to App Store, developer may also use other tools to upload the application to App Store.

Here we introduce how to use Xcode and Transporter to upload/distribute the protected application into App Store.

#### Upload with Xcode

1. Before distribute the application to App store, it is necessary to back up and move the original applications to another folder;
2. Then move the protected application to the folder which the original application located. Please delete the related .ssp file.
3. after step above, return with Archive page, click `Distribute App` to upload the protected applications

#### Upload with Transporter

1. drag the protected application into the Transporter directly;
2. click `Verification` and wait to complete the verification process;
3. when verification completed, click `upload`

## Appendix

#### 1. How to Get crash information (find the Virbox log file) when the protected application crashed

The issue:&#x20;

if the protected iOS application crashed when running in the mobile terminal, it is necessary to submit the crash information (log file which contained the crash information) to Virbox support teams, so developer need to find the log file and submit to Virbox team.

Step1

Please connect the mobile with the mac machine, and make sure the IP address of mobile keep the same IP network segment with the mac Machine's.

Step2

Open the Xcode, select the `Windows>Devices and Simulator` Option

<figure><img src="/files/yIccWCdY85DZcMnCtCXw" alt=""><figcaption></figcaption></figure>

`Click View Device Log`s Option

<figure><img src="/files/WSp3MUwIUC8DRKotPqq9" alt=""><figcaption></figcaption></figure>

If the IP address of mobile is in the same network segment with mac machine, if the application running in the mobile terminal crashed, then the log file will be automatically synchronized to following page:

Click the Type to be the "Crash", right click "Export Log" and save the log to local machine.

<figure><img src="/files/Jn2Q6Xolh3MDIrnayfJR" alt=""><figcaption></figcaption></figure>

#### 2. How to use the Command line to sign (Code signing)

**2.1 Use the command to query the digital certificate in the machine**

```
 security find-identity -v -p codesigning 
```

**2.2 Use the command codesign the application**

```
  codesign -fs <certificate info>  ***.app 
```

**3. How to pack the application into IPA package**

3.1 Create a folder, folder name is payload

3.2 Save the protected application into the folder created in above steps

3.3 Compress the payload folder (on default compress in zip file)

3.4 Rename the suffix from .zip to .ipa


# Protect Scripting language


# Protect PHP project

### Introduction

PHP, as one of high level, interpreted scripting program language, which widely and popular be used to develop different kind of projects and application by software developers.

As a interpreted language, the PHP application contains 2 kinds of PHP file: php-cgi.exe, the interpreter and php file: \*\*\*.php file, which is source code, which will be called/interpreted by php-cgi.exe when php application executed.

The **Mechanism** to protect the PHP application:

* ​ Using Virbox Protector, to encrypt the php-cgi.exe, the PHP interpreter;
* ​ Use the DS Protector, a plug in unit to protect relevant PHP source code: \*\*\*.php file;

​ **Depoyment:** use the protected (encrypted) php-cgi.exe and encrypted php file to replace original php-cgi.exe and .php when executed.

### Protect the PHP code in 3 steps

Protect the `php-cgi.exe` by use of Virbox Protector

Protect the `.php` file by use of DS protector;

Deployment in different environment

### Prerequisites

Apply trial license & download/install Virbox Protector;

PHP application for test/evaluation is ready;

### Protection Process

### 1. Protect the php-cgi.exe by use of Virbox Protector

**Open Virbox Protector GUI and import (drag) php-cgi.exe into Virbox Protector.**

Go to Virbox Protection directory. find the virboxprotector.exe which located in the \bin sub directory and open it. then drag the php-cgi.exe into the virbox protector.

![](/files/1gT3JQbUSAv2MHPKk1wx)

**Set the configuration to "Function Options" and protect the specified functions.**

Virbox Protector supports to protect the software application to the specified function's level and provides several protection mode for developer selection to protect the critical functions.

Developer may select the functions contained in the PE file and set the protection mode to specified functions here.

Click "Add Function" button, left click to select the functions which you want to protect, right click to set the protection mode: Virtualization, Obfuscation, Encryption,

Ctrl+A to select “all of Function"

it is not recommend to select "all of Function" to protect, due to execution performance may impacted;

![](/files/8l3V6zucCrjexjlbPm3p)

**Set the configuration to "Protection Option"**

1. set the Output path, developer may set the output path and file name of protected file;

It is NOT recommend to use same file name with your source file name, otherwise the protected file may replace your source file.

2\. Click to select the Protection Options

2.1) Import Table Protection:

To protect and encrypt the "Import table" and hide the API list to protect the functions called from external, it is recommend to click and select this option to enhance the security level;

:information\_source:Applied for PE file only;

2.2) Compression:

To compress the file size and prevent the static decompiling

:information\_source:If the file size is too small, the compressed file size may not smaller or even bigger than the source file size; and not applicable for .NET file and arx file type

2.3) Memory Check (Verify the code Integrity)

when program executed in memory, The loader of Virbox Protector will check each memory block to ensure the code integrity to prevent tampering, repackaging;

2.4) Resource Section Encryption

Encrypt the Resource Section in the program, and use the license to decrypt when program executed and preventing the resources information being extracted and tampered illegally.

:information\_source:Resource Section Encryption applied for local PE program only;

3\. **ds Plugin** Switch on/off

Switch on/off the **DS Protector**, a plug in unit which used to encrypt/protect the .php file, you need to "switch on" the "ds" button to open "DS Protector"and **set the password** for protected php file here.

:information\_source:Another way to open the DS Protector is go to the \bin subdirectory of Virbox Protector and double click: deprotector.exe to open DS Protector. but you still need to "Switch on" ds button to enable the ds function in Virbox Protector and set the password here.

![](/files/WY69b4R4Tix0cjL5eVWh)

**Click "Protect Selected Project" to start protection process**

When you complete the setting to "Function Option" and "Protection Option", Click to the button "`Protect Selected Projects`" in the Menu, to start the "**Protection**" Process. and click "OK" to complete the Protection process.

![](/files/2ud16Ph4JwNkms5Ir7mu)

then you will find 2 new file has been generated in the output path:

*php-cgi.exe.ssp*, this is the configuration file which save the protection setting; and this file will be used when you use the ds protector to encrypt the .php file later.

*php-cgi.ssp.exe*, this is the protected php interpreter file.

![](/files/d3HtWzh8Dtwl1X8GRdZj)

### 2. Protect the .php by use of DS Protector

&#x20;:information\_source:Backup your PHP file in advance

Open DS Protector and add the .php file to protect.

![](/files/qhHkHU2PZc4QbnImuNou)

Then DS Protector will load the configuration file which generated automatically.

Add file into DS protector, click to "`Protect`"

If you open DS Protector later, then you need to add the configuration file manually, and add the .php file also. see following steps attached:

![](/files/wAnIrHJqHo9tOOxQ8bH6)

:information\_source: Rename the protected php-cgi.exe to original project name before deployment

### 3 Deployment in different environment

#### phpstudy2018 and phpstudy-pro

Rename the protected php-cgi.exe to original file name

Restart the Apache service and start the php-cgi.exe;

#### XAMPP

For the PHP projects executed in the XAMPP environment, the service use httpd.exe. so the developer who use the XAMPP environment, pls follow the same way in above to protect:

User Virbox Protector to protect the httpd.exe

Use DS Protector to encrypt the php file.

Back up the source project code before protection.

Use the protected htppd.exe and protected php file and restart apache service to execution

#### wampserver service

The protection process in wampserver is same as other environment.

Developer need to find the location of httpd.exe, using the procmon, the monitoring tool to find the location

![](/files/fXdfQsXltRm2dntxe36f)

Find the httpd.exe location

![](/files/J99ccnsbqfrGTl95KksZ)

Then next step will be same as normal protection process

Use Virbox Protector to protect httpd.exe

Use DS Protector to encrypt the php file.

Use protected httpd.exe and encrypted php to replace original PHP project.

Restart service to execution;

#### IIS service

Start up PHP application via IIS service;

Check and find the PHP process is php-cgi.exe via Control panel--administrator--IIS:

![](/files/9SazelQgIFNCoNR3J0qa)

Find the php-cgi.exe in taskmanager.

![](/files/jSMWgxjwHz4eh2rEOVzu)

Then next step will be same as normal protection process

*Use Virbox Protector to protect httpd.exe*

*Use DS Protector to encrypt the php file.*

*Use protected httpd.exe and encrypted php to replace original PHP project.*

*Restart service to execution;*

### Protection process & Deployment in Linux Environment

#### Apache Service

In this case, we introduce how to protect the PHP project in Linux/Apache environment:

**Ubuntu :**

Start up Apache service, view service status, find the apache2 service process and PID

![](/files/98YRuQzKyKeJWGeXtvmZ)

Then next step will be same as normal protection process

*Use Virbox Protector to protect httpd.exe*

*Use DS Protector to encrypt the php file.*

*Use protected httpd.exe and encrypted php to replace original PHP project.*

*Restart service to execution;*

**CentOS:**

Start Apache service and view service status, to find the httpd service process and PID

![](/files/k0ufrPG3HLN9ZXYMFFHs)

Then next step will be same as normal protection process

*Use Virbox Protector to protect httpd process;*

*Use DS Protector to encrypt the php file.*

*Use protected httpd.exe and encrypted php to replace original PHP project.*

*Restart service to execution;*

&#x20;:information\_source:If you start the DS protector with normal user right, it may failed to encrypt file, use system administrator to encrypt the php resource file.

**php-fpm service**

PHP project use the nginx service and php-fpm service to execute php project.

Start php-fpm service and view the service status, find the service process and PID

![](/files/j3TgT3OwgLJiEfA2Fv7A)

Then next step will be same as normal protection process

*Use Virbox Protector to protect php-fpm process;*

*Use DS Protector to encrypt the php file.*

*Use protected php-fpm process and encrypted php to replace original PHP project.*

*Restart service to execution;*

:information\_source:If you start the DS protector with normal user right, it may failed to encrypt file, use system administrator to encrypt the php resource file.


# Protect the Python application with Virbox Protector

Python, as one of high level, interpreted script program language, are widely and popular be used to develop different kind of  application  and projects by software developers.

As a interpreted language, the python application contains 2 kinds of python file: python.exe, the interpreter and py file: py, pyc, or pyd file, which is source code, bytecode file which will be called/interpreted by pyhton.exe when python application executed.

## 1. The Mechanism to protect the python application

1\). Using Virbox Protector, to encrypt the python.exe, the python interpreter;

2\). Use the DS Protector, a plug in unit, to protect relevant python source code: py/pyc file;

3\). **Deployment:** Use the protected (encrypted) python.exe and encrypted py/pyc file to replace original python.exe and py/pyc when executed.

Virbox Supports to protect the python application in following scenarios:

| **Scenario**                                         | **Support or Not** |
| ---------------------------------------------------- | ------------------ |
| Anconda2/Anconda3                                    | yes                |
| Call python module from C++/C Projects               | Yes                |
| Call C++/C from py file                              | Yes                |
| Using pyinstall/py2exe to pack a py file to exe file | Yes                |
| Convert to pyd/so/executable file by py file         | yes                |

Tips: For the pyd/so or executable file which converted by use of pyinstall/py2exe to pack the py file, pls refer the protection process for Native projects.

## 2. Prerequisites

1. Apply trial license & download and install Virbox Protector;
2. Python application for test/evaluation is ready;
3. Above pre-requisition is for test/evaluation Virbox Protector only. To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.

## 3. Protection Process

### 3.1. Protect the python.exe

3.1.1 Open Virbox Protector GUI tool: `virboxprotector.exe`, login Virbox Protector with your account and password;

3.1.2 Find the Python.exe location: Execute python application, and use the windows's task manager to find the python.exe location.

3.1.3 Drag the python.exe into the Virbox Protector GUI tool, Virbox Protector will parse the python.exe automatically. see snapshot attached below:

![](/files/dnZrTgYGfkDeskHXSejy)

3.1.4 Protect the function's via "Function Option" tab

Protect the selected functions in "Function Option" tab, in this section, you may select the functions which you want to protect in the "Function Option" tab to protect the specified functions, with several encryption option to encrypt the functions: "*Encryption*", "*No protect*", "*Obfuscation*", "*Virtualization*" etc.

3.1.5 Protect python.exe in general, via "Protection Option" tab

In "Protection Option" you may:

1. Set output path for protected file (python.exe);
2. select and set protection option to the protected file (python.exe) in general level: Click and select the options listed:

   `Import table:`

   `Compression:`

   `Memory Check:`

   `Resource Section Encryption:`
3. Switch on (Enable) DS Protector button and set password for the py/pyc file (if you don't set the password for py/pyc which DS protector used, Virbox Protector will use a password random generated

![](/files/FP8PsCpiz4cHqkNYIFDy)

3\. 1.6 Protect the python.exe

Click "`Protect Selected Projects`" in the menu, it will generated 2 new files as shown below:

**python.ssp.exe:** This file is python.exe after protection (we will rename the file name and use it later)

**python.exe.ssp**: this file is configuration file for protected python file;

![](/files/F9jvTfD7NYNHcXBZ1W3E)

{% hint style="info" %}
Pls backup and save the original python.exe file to another sub directory, and change the file name: python.ssp.exe to original file name: python.exe.
{% endhint %}

### 3.2 Protect the py/pyc file

#### 3.2.1 Open DS Protector

Open DS protector via Virbox Protector GUI: switch on ds Button (green)

![](/files/m7gKfFKdXl2jNZNiMC5n)

or, Open DS Protector from the virbox protector directory:

you can find the dsprotector.exe in \virboxprotector\bin, and open it.

#### 3.2.2 Protect the py/pyc file by DS Protector

Add the py/pyc which you want to protect by DS Protector GUI and click the "Protect" button on the right bottom corner, as shown in below:

![](/files/1m8HOskx48CZWFzyoex5)

when protection success, the DS Protector will show following information:

![](/files/v4jCy5pfMOWgMDn9p6qy)

2 files can be found in the output directory:

py.py, this is new py file which protected successful by DS Protector; this new py file will be used together with protected python.exe later.

py.py.bak, this is your original py file, pls backup and save it.

![](/files/l7NemV8EQxEv3P1kDC5j)

Till now, you have complete all protection process to protect python application;

Use the new and protected python.exe (don't forget to change name) and protected py.py to execute your python application.

Any questions for testing, implementation to protect python applications,

pls contact Virbox support team at:

**email:**

<support@senselock.com>

<info@senselock.com>

**Skype**: <virbox_help@outlook.com>


# Protect Python Project by PyProtector

\--With PyProtector, a Python extension package, Developer has capability to protect python project to bytecode level, which effective to prevent attacker to decompile python project.

### Introduction to Python

Python is a very popular general-purpose interpreted, interactive, object-oriented, and high-level programming language, easy to read and cross platform support with rich library available, Python is very highly in demand and it has been widely used in various areas of applications such as Machine Learning, Artificial Intelligence, web development, IoT, and more area. Many of major companies select and use Python to develop websites, software components, and applications or to work with Data Science, AI, and ML technologies.

#### **Python file extension name**

| Python file extension | Description                                 |
| --------------------- | ------------------------------------------- |
| py                    | Python script source code                   |
| pyc                   | Python byte code (compiled script)          |
| pyd etc.              | dll in windows,                             |
| pyz                   | Python script archive file                  |
| pyx                   | Cython source code to be converted to C/C++ |

### Python Security:

#### **How to protect the Python script (py) before distribute or deploy to customer premise**

As Python is an interpreted language; When user execute the python project, The Python Interpreter require to compiles the python source code (`py`file) to bytecode (`pyc`) and executed in the python VM. Even the developer may deploy the bytecode (`pyc` file) in the user premise only without use python script file (`py` ) file, but it is not difficult to third party attacker to decompile and reverse the bytecode (`pyc` file) to the original py file, with the Python decompile tool (for example, [uncompyle6](https://github.com/rocky/python-uncompyle6) . so, it is not good idea to deploy the bytecode file to customer premise without additional protection/encryption. It is always the challenge to Python developer when they distribute their Python project to users, especially when deployed python project in customer premise.

<figure><img src="/files/LDFVVKT1X36JgayYMMOk" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/xWOAs2piCAI8B591qvoZ" alt=""><figcaption></figcaption></figure>

The Python interpreter execution consisted 2 phase when execute the python source file:

1. Python source code (`py` file) is compiled into byte code (`pyc` file)
2. Python byte codes (`pyc` file) executed in the Python Virtual Machine (PYM)

When a Python project executed, Python interpreter will check if valid `pyc` file available,

if the `pyc` file is valid, execute the `pyc` file;

If the `pyc` file doesn't existed, or the python script `py` file has been update, the python interpreter will recompile the `py` file to new `pyc` file and execute it.

Bytecode generation saves repeated compilation time; In case python version on the machine changed, the Bytecode will be regenerated (pyc file is much dependent with python version on the machine execution).

#### Typical protection method to Python Project

1. Obfuscate the python script file:

   Obfuscate and change the functions name, variable names; (usually obfuscation is not effective way to prevent the third party to decompile your python script, it just makes reverse process harder and spend longer time.)
2. Archive and pack the python script file into exe file;

   use `py2exe`, `pyinstaller` or other similar packer tool to archive/pack to the `exe` file, only for windows environment;

   (the challenge would be, it is easier to be decompiled by use of python reverse tool, such as `pyinstxtractor` to reverse to the `pyc` file, and use the decompiler to decompile the pyc file and get original source py source code )
3. Compile the python script file to be `.C` file and compile to dynamic link library (.so in linux and .pyd in windows). for example, use the `cython` to implement (compile) the process above;

For the python web project deployed and implemented in customer premise, usually, the developer select the 3rd way to protect python source code being used illegally;

### Virbox Protector: Python extension package (PyProtector)

With Virbox Protector, Developer may have 2 way to protect Python project:

1. For normal python project, no special security requirement, Developer may use DS Protector, a plug in unit, with Virbox Protector **native license** to protect Python project;
2. For those Python project which require highly security to protect py file, Virbox provides "Python extension package (PYProtector)" and support developer to protect python file to "Bytecode" level. Compare with other Python protection solution in the market, Virbox Python protection solution provides the most secured performance to the python project. with Virbox Python extension package (PY Protector), developer may protect python project to bytecode level to prevent the Python file from being decompiled and being tampered. Python extension package (PyProtector) are much suitable and best choice to those Python project deployed in user premise.
3. It is require developer to download the "Python extension package (PY Protector) and install "PYProtector" with Virbox Protector. in this document, we focus to introduce the whole protect process with Virbox Python extension package. ( **Python license required**)

#### Version release (PyProtector)

Start from Release version 3.2.xxxx, Virbox Protector introduce the enhanced Python protection solution, with new extension package: `pyprotector` , with `pyprotector`, it increase the security to protect the Python script. Compare with using DS Protector tool previously, the `pyprotector`, protect the python project to bytecode level, which guaranty the python script can not being decompiled and reversed directly. and make sure your python project security when deployed in customer premise.

**pyprotector** use dynamic encryption/decryption technology to protect Python script file, that means **pyprotector** encrypt original python script file `py` file and decrypt these script file only when execution, and re encrypt the script file when execution completed. and `pyprotector` also use multiple mechanism to verify script, code object etc.

#### Solution advantage

**1. Protect/encrypt the python script in bytecode level**

When Python application executed, no python script (source code) can be exposure, when the third party use python decompiler to decompile in running environment. it can not get correct bytecode and decompiled to source code accordingly.

**2. Python bytecode has been encrypted and only being decrypted before execute**, and it will be re encrypted the bytecode after executed. to prevent being dump to get the script file from the memory.

**3. Compatibility:** In most of cases, the encrypted python file (.py file) is compatible with original .py file and can be replaced seamlessly;

**4. Compatible with multiple version of Python execution environment:** the protected python project can be executed in the 3.6\~3.11 version released.

5.**The condition of Seamless replacement:** The Python interpreter can load the C extension library of `virbox_pyruntime` correctly, with condition of writable right to `virbox_pyruntime` library;

**6. Comparison between DSProtector & PYProtector：**

previously, when developer use the Virbox Protector to protect python project, the plugin tool used is DSProtector, here we compare and list the difference between DSProtector and PYProtector:

<table data-header-hidden><thead><tr><th width="174"></th><th width="307"></th><th></th></tr></thead><tbody><tr><td></td><td><strong>DsProtector</strong></td><td><strong>PyProtector</strong></td></tr><tr><td>Mechanism</td><td>when developer use dsprotector to protect Python script file, it is mandatory to encrypt/protect the python.exe, enable dsprotector and replace the python.exe with encrypted Python.exe when execution.</td><td>No need to encrypt python.exe</td></tr><tr><td>Security</td><td>Possibility to dump the python script code in memory;</td><td>code object (binary) in memory when execution. impossible to dump.</td></tr></tbody></table>

#### Supported Python environment

**1. Applicable Python project version to be protected：**

Python version: 3.6-3.12

> Support to protect/encrypt the `py` file only, it doesn't support to protect `pyc`bytecode file.

**2. The workable Python Environment (version) to protected python project ：**

Python 3.6-3.12

Note: If the operation system doesn't support python 3.8, then it will failed to encrypt the python `py` file

#### Operation System Supported

| Operation System | x86 | x64 | arm32 | arm64            |
| ---------------- | --- | --- | ----- | ---------------- |
| Windows          | ✔️  | ✔️  | N/A   | not support yet  |
| Linux            | ✔️  | ✔️  | ✔️    | ✔️               |
| macOS            | N/A | ✔️  | N/A   | not support yet, |

#### How does it works (Mechanism)

**The execution process of protected python project**

1. Load the module: `virbox_pyruntime`
2. Call the `virbox functions` in the `virbox_pyruntime` module,

   To verify whether the python script file has been modified or not;

   Fix the bytecode encryption/decryption functions, bytecode string/attribute decryption functions, verify functions, etc.
3. Execute the code objective;
4. Decrypt the bytecode body at the beginning of function;
5. Encrypt the bytecode body at the ending of function;

#### Basic Feature to protect Python project (Python Options Tab)

1. Drag Python folder into Virbox Protector, and then Developer select those `py` file which developer want to protect/encrypt in the `Python` tab;
2. Developer click to select those protection options to your python script in `Pyhon Options` tab:

<figure><img src="/files/gm7bC3m8nhF7mwNZ77CW" alt=""><figcaption></figcaption></figure>

**Functions Verification (Check)**

Verify the functions when execution to prevent the functions being replaced in memory dynamically;

**Python Module Verification (Check)**

Verify the Python module imported when execution to prevent being replaced; and prevent the unprotected python module being imported;

**String Encryption**

Encrypt the those critical plaintext string contained in the Python script, to increase the barrier for reverse engineering;

**Attribute Encryption**

To encrypt the class attribute of the Python code (object);

**Local Variable Obfuscation**

Obfuscate the local variable in the Python functions and rename it to meaningless string; to prevent to track python code logic by variable name;

**Bytecode Dynamic Encryption**

With Bytecode dynamic encryption feature, the encrypted bytecode will be decrypted when execute the functions only;

**Tampering Proof**

Block the protected Python script to add additional code (allow to add "code comments")

**Code Object Name Obfuscation**

Rename the code object, to prevent the attacker to trace code logic;

### Getting Started (Protection process)

To protect Python script (py file), when you installed the Virbox Protector in your machine, it is necessary to install additional **Python extension package** and install in your machine.

#### Installation & Setup

**Prerequisite:**

1. Virbox Protector release version or Trial version >3.2.2.xxxx;
2. contact Virbox support team or download by yourself to get Python extension zip package;

Note:

If the Virbox protector installed in your machine is lower than 3.2.2, please download the latest version Virbox Protector installation package（for trial user, download the latest version of Virbox Protector Trial Package) and install Virbox Protector to your machine.

Open Virbox Protector GUI tools, and drag the **whole Python folder** (not only python file) into Virbox Protector GUI tools, then, additional "Python Files" tab will be added in the Virbox Protector GUI tools,

<figure><img src="/files/r8v9yZV6TDGzkgyvDeDP" alt=""><figcaption></figcaption></figure>

click:

`Install extension package`

to install `python extension package`,

Another way to download Virbox Protector Python extension package

Please go to Virbox Protector website and install it via Virbox Protector GUI tools;

<figure><img src="/files/lDNoPtPET4QMpx4w5ypZ" alt=""><figcaption></figcaption></figure>

After complete the installation the python extension package, you can use Virbox Protector to protect your Python Script in bytecode level:

#### Use Virbox Protector GUI tool to protect Python

Go to the installation directory of the Virbox Protector, entry the sub directory \bin\\

Execute `virboxprotector.exe`, login with email and password;

Drag the \*\*whole Python folder(\*\*which folder contained the `python.exe` and correspondent `py` file) into `Virbox Protector` GUI tools:

<figure><img src="/files/P5TI0JZ9vvrJo0g8SltK" alt=""><figcaption></figcaption></figure>

then, after parsing your Python project, Virbox Protector GUI will prompt message and new Python tab will added:

Developer can select and set protection option in following tabs.

1. `Python Options`

   select the py file need to be protected in this tab;
2. `Protection Option` tabs

   Select the protection option to those selected `py` files, all protection feature can be selected here.
3. Click “Protect Selected Project" in the menu, to start python project protection process, then

   a new protected python project will be generated under specified folder:

   `Python simple_protected`

   a new package has been generated in this folder: `virbox_pyruntime`

Note:

1. When you execute the protected python project, it will dependence with c extension library contained in this `virbox_pyruntime` package generated.
2. Python file Password:

<figure><img src="/files/I18mOP1zIAsd4DCmG35j" alt=""><figcaption></figcaption></figure>

​ 1) When there are dependencies between encrypted py files, if the password settings of the two protection/encryption are different, the protected py files cannot be used compatible, if the password settings are the same, the encrypted PY file can be used;

​ 2) When there is no dependency between encrypted py files, no matter for the password settings of the two protections are the same or not, the protected py file can be used normally.

```
Note：
1.In case the `\protected` folder missing in the python file located folder, then the python project execution will be failed.
2.It is recommend to put the `virbox_pyruntime` folder under the folder of python environmenet. then it is not necessary to copy the folder `virbox_pyruntime` under the protected python folder.
```

#### Use Virbox Protector CLI tool to protect Python

Virbox Protector supports developer to protect python project with CLI also, the on default `pyprotector` CLI tools:

`pyprotector_con`

**PYProtector CLI location**, develop find the PYProtector CLI tool at:

```
Windows:
Commercial release：C:\Program Files\senseshield\Virbox Protector 3\bin\pyprotector_con.exe
Trial package：C:\Program Files\senseshield\Virbox Protector 3 Trial\bin\pyprotector_con.exe

Linux:
Commercial release：/usr/share/virboxprotector/bin/pyprotector_con
Trial package：/usr/share/virboxprotector-trial/bin/pyprotector_con

macOS:
Commercial release：/Applications/Virbox Protector 3.app/Contents/MacOS/bin/pyprotector_con
Trial package：/Applications/Virbox Protector 3 trial.app/Contents/MacOS/bin/pyprotector_con
```

**The CLI options:**

1. The options

| Options                                                               | Command                      | On default value |
| --------------------------------------------------------------------- | ---------------------------- | ---------------- |
| Install py extension package                                          | `--install=<zip_path>`       | `0`              |
| Specify the python execution version for the protected py script file | `--target-python-version=`   | `0`              |
| Function check                                                        | `--function-check=<value>`   | `0`              |
| Module Check                                                          | `--module-check=<value>`     | `0`              |
| String Encryption                                                     | `--str-enc=<value>`          | `0`              |
| Attribute Encryption                                                  | `--attr-enc=<value>`         | `0`              |
| Local Variable Obfuscation                                            | `--local-var-rename=<value>` | `0`              |
| Bytecode Dynamic Encryption                                           | `--bc-dyn-enc=<value>`       | `0`              |
| exclude the files by filter to protect                                | `--excludes=`                | `0`              |
| Output path                                                           | `-o=<output_path>`           | `0`              |
| View and list the version Python CLI tool                             | `-V`                         |                  |

2. Command line Sample

1）Use the CLI tool to install the `Python extension pacakge`

```
"C:\Program Files\senseshield\Virbox Protector 3\bin\pyprotector_con.exe" --install=D:\Desktop\python_extension.zip
```

2）To exclude the py file which located at the nested folder

```
"C:\Program Files\senseshield\Virbox Protector 3\bin\pyprotector_con.exe" <py-demo> --excludes=<py-demo>/<dirs> -o <py-demo_protected>
```

3）To exclude the specified nested py file,

```
"C:\Program Files\senseshield\Virbox Protector 3\bin\pyprotector_con.exe" <py-demo> --excludes=*/demo.py -o <py-demo_protected>
```

or, to specify the absolute path of `py` file specified:

\--excludes=specify the absolute path of `py`file.

4）To protect the python project (enable `function check`/`string encryption`/`Bytecode dynamic encryption`):

```
"C:\Program Files\senseshield\Virbox Protector 3\bin\pyprotector_con.exe" <py-demo> --function-check=1 --str-enc=1 --bc-dyn-enc=1 -o <py-demo_protected>
```

5）To specify Python system version to the protected python execution environment(for example to specify the python execution version is 3.9, then the protected python project will be executed under the python version 3.9 only:

```
"C:\Program Files\senseshield\Virbox Protector 3\bin\pyprotector_con.exe" <py-demo> --target-python-version=3.9 -o <py-demo_protected>
```

#### Comparison the py file

**Before protection (original py file)**

<figure><img src="/files/Qax0xjByZAfzG9OU6Uni" alt=""><figcaption></figcaption></figure>

**After protection (encrypted py file)**

<figure><img src="/files/6TwybNLJOJiqIEs5vgqM" alt=""><figcaption></figcaption></figure>

### Comparison to execution performance

No matter we use what kind of code hardening solution to protect Python script, it is always to consider and balance the python code security and python project execution performance, Here we execute the original py script (not protected) and execute the Python project which select different kind of `Protection Option` to protect.

see attached project execution performance comparison (in seconds)

<figure><img src="/files/B2DbnJORcJtwOB69spbg" alt=""><figcaption></figcaption></figure>

#### **Conclusion：**

The **String encryption** and **Attribute encryption** these 2 options selected to protect and encrypt, is the most protection option which bring negative impact to execution performance. compare with other option selected. it almost no performance impact when you select the other options.

```
Why String encryption may bring negative impact to project execution performance: the reason is because when you select these 2 protection options, there will be many of string and attribute encryption and decryption happened to the protected python project. 
```

Let's take the protection of algorithm to support vector in the python as a example, we use the tools `cProfile` to record the time to call the function in several millions, see attached chart.


# Protect the JavaScript code in HTML 5 applications

## -Quick Start Guide

Virbox Protector support developer to protect the JavaScript Code in the [HTML 5](https://en.wikipedia.org/wiki/HTML5) application, with multiple security technology: Obfuscation to Control flow, String encryption etc., which to prevent your HTML 5 project from being decompiled and debugged dynamically. and effectively to enhance HTML5 project security deployed in website and client side.

## 1. Overview

### 1.1 HTML 5 Application mades of 3 kinds of web language Javascript, HTML and css web language

1. HTML file, used for the contents of website project usually;
2. CSS file, cascade style sheets, which describe the website font, size, colors, the layout. store the website layout information. suffix with .css;
3. JavaScript , .js file, is scripting language using in millions of WEb pages and client side application, which describe the functions, algorithm logic of website or light application. .js file is most key file in the HTML 5 project which need to protect the code for most of developers.

### 1.2 Virbox Protector support to protect following HTML 5 Project

Web based HTML5 project

[Electron application](http://www.electronjs.org/);

UNIAPP;

Mini program or other HTML 5 application in client side etc.

.js source code/file which contain the `import` will be support soon;

### 1.3 Protect HTML project within 5 steps

1. Save your HTML 5 project into the specified folder,

   for example, save your HTML project into `\Hello-H5,`
2. Import your HTML project: Drag the whole folder `\Hello-H5,`into Virbox Protector GUI tool; then Virbox Protector will parse and show all of .js file contained in your HTML5 project;
3. Select the .js file to be protected and set the protection option to the .js files, click to "Protect Selected Project" to protect the HTML 5 project;
4. A new, protected folder will be generated: `\Hello_H5_Protected.`
5. Entry this new folder and use HTML 5 project for following test/distribution. keep the source HTML 5 project and do not distribute source project.

## 2. Prerequisites

1. Apply trial license & download and install Virbox Protector from Virbox website;
2. HTML 5 application for test/evaluation is ready;

   *The HTML 5 sample folder in this case below is*: `\Hello-H5`
3. Above pre-requisition is for test/evaluation Virbox Protector only. To protect formal and commercial release software, pls purchase and get the related Virbox Protector license.

## 3. Protection Process

1. Open Virbox Protector GUI tool and drag the folder of your HTML 5 project into the GUI tool;
2. Virbox Protector will parse and show all `.js` file of your HTML project in the **HTML 5 Protection** tab;
3. Go to `H5 protection` tab (HTML 5 protection) to set the protection option, Click to select the Anti debugging to enable the "`Anti-debug`" functions;

![](/files/uqFcqCtPQBWhuHUhjSAY)

`Obfuscation of control flow` and `String of Encryption` will be selected on default;

Click "`Select File`" button in right above to select the .js file which you want to protect.

4\. Click "Protect Selected Project" to start protection, when GUI prompt "Protection Successful", you will find a new folder: `\hello_H5_Protected`, has been generated;

![](/files/zAcNEy1kMcAVs2Xbbz89)

![](/files/Y72w7UQbzSs9GSnJx8k1)

5\. Use the protected HTML 5 project in the new folder generated for further testing;

## 4. Protect HTML 5 project with Virbox Protector CLI tool

### Generate the Configuration file

Use the Virbox Protector GUI tool to generate the configuration file, which will be used to be protection configuration when use CLI tools to protect in second steps

the process you may refer protection process by use of Virbox Protector GUI tools above, when you complete the setting, click "Save Selected Configuration", you will find a new file which suffix is .ssp has been generated.

### Virbox Protector CLI tool

Open a terminal console, go to the sub directory which Virbox Protector CLI tools located, you can view the help info by execute:

`virboxprotector_con.exe`

On default installation directory will be:

`Windows: C:\Program Files\senseshield\Virbox Protector 2\bin`

`Linux: /usr/share/virboxprotector/bin`

`macOS: /Applications/Virbox Protector 2.app/Contents/MacOS/bin`

### Protect HTML 5 project by use of Virbox Protector CLI tool

Use following command to protect your HTML project with CLI tool:

*The HTML 5 sample folder in this case below is*: `\h5-demo`

1. The configuration file has been copied to the same directory which HTML 5 file located.

\[^copy the configuration file to the same directory of the HTML project ]:

`virboxprotector_con -h5 <h5-demo> -o <h5-demo-protected>`

![](/files/aOQxjm357aTPuN0JQ0mE)

2\. No configuration file (.ssp file) available in the HTML 5 folder, use same command to protect HTML 5 folder, all of .js file in the HTML project will be protected on default;

`virboxprotector_con -h5 <h5-demo> -o <h5-demo-protected>`

3\. The configuration file (.ssp file) stay in other folder, and you want to specify and use existed configuration files to protect the HTML 5 folder, then you need to specify the absolute path of .ssp file by use the parameter "X", see sample command:

`virboxprotector_con -h5 h5-demo -x D:\Desktop\demo\h5-demo.ssp -o h5-demo-protected`


# FAQ

In this chapter, We introduce some of experience in practical proejcts

{% content-ref url="/pages/O8hyUGKbcNb7gyjVCLyn" %}
[How to deal with the Virus False Positive when developer protect the application](/use-cases/faq/how-to-deal-with-the-virus-false-positive-when-developer-protect-the-application)
{% endcontent-ref %}

{% content-ref url="/pages/Lan6YMccgJl4DSaNmpLX" %}
[Broken mention](broken://pages/Lan6YMccgJl4DSaNmpLX)
{% endcontent-ref %}

{% content-ref url="/pages/V9Sks6XdFlGcVMkZ8efy" %}
[Set the label to protect the specified Functions/code](/use-cases/faq/set-the-label-to-protect-the-specified-functions-code)
{% endcontent-ref %}


# How to deal with the Virus False Positive when developer protect the application

To protect software source code, Intelligent property, Developer may select and use the different protection tools (Packer, Encryptor, Protector) to protect their software application, with multiple encryption technologies: compression, obfuscation, encryption, virtualization, to defend the reverse engineering and prevent the application from decompiling and debugging. In some cases, these encryption/protection technologies may trigger the false positive: the anti virus installed **in** the user's machine may scan and flag the protected application as Malware, suspicious or virus infected. this is called "false positive" or False alarm, it may bring some negative impact to developer when they promote their application to potential users.

### The reasons:

The reasons which the anti virus flag the protected application to be infected or suspicious malware **are as follows** (**due to several reasons)**:

1. The mechanism and detection criteria of Anti virus to scan and identify the virus and malware.

Anti virus uses several ways to scan, detect and identify the potential malware or virus infected application, includes:

Signature-based (signature here means the string of code of typical malware code which both could be included in legitimate application and in malicious, and these string of code stored in the anti-virus database), anti virus uses these "signature" to scan and cross check the file in your machine and compare with their database.

Heuristics-based anti virus spot suspicious characteristics in new threats and modified versions of existing threats. If a certain percentage of any program’s source code matches anything that is labeled as a threat in the anti virus vendor’s heuristics database, it will be flagged as a possible threat or suspicious. This allows antivirus to catch new malware variants, but it can also result in false positives.

Behavior analysis. more and more Antivirus uses machine learning to identify malware based on behavior rather than signature (what the file’s code looks like). This is especially helpful for detecting newer malware threats that aren’t in a database yet, but sometimes programs are flagged for behavior that is completely legitimate. Networking applications, product key finders, and other similar software are often flagged as malware because they act similarly to popular malware files.

PUP (potential unwanted program) blockers, Many adware and spyware blockers flag ad-supported software and bundleware. If the software you’re trying to download runs ads, offers to install other third-party programs (for Virbox Protector, it may check the license or download license update), or tries to install a toolbar in your browser, there are high chances it’ll be flagged as a potentially unwanted program (PUP), even if it is safe and legitimate.

Due to multiple encryption technology be used in software protection and encryption, which to make harder to analysis, reverse and decompile the protected application and prevent application be cracked , anti-virus failed to identify the characteristic of the protected application, in some cases, the anti virus fail to detect the signature of application, so the anti virus will treat the protected application to be suspicious and flag to be malware, and cause false positive.

you may also refer the article of Microsoft for: How Microsoft identifies malware and potentially unwanted applications [here](https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/criteria):

1. The virus or malware maker also use the same encryption technologies (Compression, obfuscation, encryption or virtualization) which packer, encryptor used to protect software to hide their virus characteristic or malicious code prevent from being detected by anti virus. In some cases, the virus or malware maker use the packer tool available in the market to protect their malware directly. You also can find the article which introduce which protectors are popular be used to protect the malware, etc. The protection mechanism and technology are same, the "signature" of protected legitimate program and protected malware are similar, only the objective is different: the software developer uses the encryption/protection technology to protect the Intellectual property of legitimate file, the malware maker uses same technologies and protector to mask/hide their malware, and the anti virus may be confused, so your application will be mis-identified to be malware.
2. The anti-virus installed in your machine may not update their malicious characteristic database frequently and confused and failed to distinguish the legitimate application and malware, even you have joined the whitelisting team of the anti virus.

### The Solutions:

#### False Positive Submission and Digital signing to your application

For developer who use Virbox Protector or other protection tools to protect their project, in case the anti-virus software give a false-positives (false alarm) to your protected application, here are the options to solve this issue:

**1. Submit the false Positive to Anti Virus software**

submit the application sample to service support of anti-virus company and ask them to support to solve the open issue (flag false positive), usually it will take few days for them to identify the sample, if it is actually a legit application, they will remove the detection and update in their database. Here we list the contact information or the web link to submit file sample to some of most popular anti virus companies. you also can search the website of anti virus which your machine installed and found relevant submission form or email by searching "false positive".

Part of popular anti-virus web link to submit false positive or email submission:

**Avast:**

Avast provides a service named "Avast file whitelisting" to software developer to reduce the risk of "false positive", visit [here](https://support.avast.com/en-us/article/Threat-Lab-file-whitelist/) for detail:

​ for [Joining & Registration](https://www.avast.com/whitelist-program-registration) the whitelisting Program:

​or visit [Avast forum](https://forum.avast.com/index.php?board=4.0) (Virus and worms) at:

​ there are some discussion in practical case to how to solve the false positive in different systems in the Avast forum.

**Avira:**

Avira has described how to deal with false positive in below [website](https://support.avira.com/hc/en-us/articles/360002183358-What-is-a-false-positive-Avira-Antivirus-detection-):

Developer can submit the false positive file [here](https://www.avira.com/en/analysis/submit?utm_source=CS\&utm_medium=KB):

Note: click to select "Suspected False Positive (Not malware) option.

**BitDefender**

Developer can submit the wrong detected file sample [here](https://www.bitdefender.com/consumer/support/answer/29358/):

**Comodo**

Comodo provides following web link to their user to [submit false positive](http://www.comodo.com/home/internet-security/submit.php) file, website and malicious file or suspicious website.

**ESET**

Read ESET description for how to submit the false positive to ESET analysis, then you can [submit the wrong flag file sample here](https://support.eset.com/en/kb141-submit-a-virus-website-or-potential-false-positive-sample-to-the-eset-lab):

**Kaspersky**

Kaspersky provides a "[Threat Intelligence portal" to user/developer to submit file to identify](https://opentip.kaspersky.com/)

**For how to submit a file to analysis in above weblink, pls find the**[ **instruction** ](https://support.kaspersky.com/viruses/answers/1870)**in below link:**

**McAfee:**

McAfee describes how to submit your company software to be considered for whitelisting in below and developer need to read the description and you need to have FTP account and notify submission to Mcafee at this email: <datasubmission@mcafee.com>

`https://service.mcafee.com/?locale=en-IN&articleId=TS102751&fromSearch=true&page=shell&shell=article-view`

or, find a description for how to submit false positive in below weblink

`https://service.mcafee.com/?locale=en-US&articleId=TS103032&page=shell&shell=article-view`

**Symantec:**

Developer can [submit their file sample for False positive here](https://symsubmit.symantec.com/false_positive):

Symantec has been acquired by Broadcom several years ago. for other service request, you can visit their [support website](https://support.broadcom.com/security) here:

**Norton**:

Respond to incorrect Norton alerts that a file is infected or a program or website is suspicious, you can find the[ instruction and entry to submit](https://support.norton.com/sp/en/us/home/current/solutions/kb20100222230832EN) in below:

​ and you can [submit false positive](https://submit.norton.com/) sample file in below:

**Windows Defender** [**submission**](https://www.microsoft.com/en-us/wdsi/filesubmission)**:**

​ Specify attached is a False Positive flagged.

**2. Digital signing.**

Secure your executable and sign it with a valid certificate. For instance, the signature by Verisign or other similar level of digital certificate are well accepted by anti-virus company.

Use the Digital Signing, the most of easiest way to identify your file is legitimate and good file, and to let the Anti-Virus to know where it came from and who created it. So, To build trustee in a file is to check its digital signature. The executable file without digital signature will have high possibility of being identified as suspicious or low trusted file by anti virus.

For software developer who select a protector to test and evaluate the security performance, they may also want to test with different anti virus to check if false positive may happen. Here are some places that consolidate many anti virus and provide online scan service to the protected application and let you know which Anti virus companies will flag a False Positives to your application:

`http://virustotal.com/ http://virusscan.jotti.org/`

`https://www.virscan.org/`

The Benefit to developer using above website is to have false positive result quickly and save time, no need to install many anti virus in your machine to scan. In fact, developer may also submit the application during software testing to avoid the false positive to your application.

And, we have to remind you be careful to use above website to scan your protected application online. because some developer still concern to data, personal info, and source code leaky and security risk to submit application to *Virus total*, and developer need to be careful to think about potential security risk before submission. Especially for the developer in corporate network. And do not violate enterprise security regulation.

For what we recommend is either to join the whitelisting program of anti virus company or use the digital signature which to show your application is "good" application with good "reputation" to the anti virus.

During false positive testing, if the anti virus flag your application to be malware or virus infected. you may temporary to add your application to be "whitelist" or "exception" or "allowed list" to continue to evaluate the security performance. and submit your file sample to the anti virus website later.


# Set the label to protect the specified Functions/code

#### Using the SDK label to mark the critical functions in project coding process

Virbox Protector provides a series SDK label to help developer to mark to those critical functions or code which need to be encrypted in the project coding process. these SDK label will help developer to find and locate these functions easily when developer use the Virbox Protector to encrypt and protect these functions later.

SDK Label , includes head file, static libs and dynamic libs, Developer may load the these SDK label statically into the functions which need to be protected. Then the Virbox Protector can recognize & locate the critical code/functions and protect those functions which use SDK labeled.

## Using SDK Label to Protect your functions

Following SDK label support to be used and added in project coding process.

\***VBProtectBegin\***: Normal & conventional protection

\***VBVirtualizeBegin\***: Virtualization protection

\***VBMutateBegin\*:** Obfuscation protection

\***VBSnippetBegin\***: Code snippet protection (Code fragmentation)

\***VBProtectDecrypt\***: License encryption and decryption

### Note:

The SDK label can only be loaded statically and not supported to be loaded with dynamic link lib (i.e. LoadLibrary);

The String parameter imported by *VBProtectBegin, VBVirtualizeBegin, VBSnippetBegin, VBMutateBegin* can't be shared with other functions.

Make sure the imported parameter to be ASCII code, then the right function's name will be shown, otherwise it will show messy code and unreadable.

Every ***begin*** will follow and match with ***end***, use the \*\*“*begin*”\*\*and ***"end"*** in pair, and only one pair is allowed to mark for one function.

If the protection mode marked in the label inconsistent with the protection mode saved in the project file, the system will use the protection mode saved in your project file.

The code in between the ***"Begin"*** and ***"End"*** is better to more than 3 lines. which to make sure the protected code will be shown in the GUI of Virbox Protector. (it will not be shown in the GUI of Virbox Protector for the instruction less 15 bytes)

SDK provides 32bit and 64bit dll, you do need to use these libs accordingly.

SDK Label doesn't support in Java, Unity3D.

***Begin/end*** do not support nesting use.

***VBProtectDecrypt***, the length of the encrypted string or buffer should be multi times of 16,

*char g\_test\_string\[16] = {"test\_decrypt"}*;

***VBProtectDecrypt*****,** the import buffer and export buffer can’t be the same buffer.

***VBProtectDecrypt***, the buffer import need to be put outside of the function, which means is a global variable. For detail how to use, please refer demo.

.Net program, does not supported by ***VBProtectDecrypt*** currently.

## Encryption of String: How to encrypt and decrypt the Critical strings

Virbox Protector support to encrypt the specified String which developer would like to hide the strings.

The encrypted string must be a constant value.

*VBDecryptData* can be used to encrypt and decrypt the data also, The length and the data should be constant value.

The following type of string Decryption supported:

* String Decryption:

*VBDecryptStringA("test\_string");*

* Local static variable:

*static const char g\_string\[] = "test\_string";*

Global variable:

*char g\_test\_string\[] = "test\_string";*

*const char g\_test\_string\[] = "test\_string";*

*static const char g\_test\_string\[] = "test\_string";*

If the program to be encrypted is too complicated and the data to be encrypted can’t be parsed, it will report error when you use Virbox Protector to protect the software, we recommend you make the program less complicate. Usually it mostly happened to the Linux program which compiled with –fpic or –fpie with O2.

The compiler may merge the same constant string to be one string, if only one of these string is encrypted, an error would be reported:

For example:

*const char\* a = "test\_string"; const char\* b = VBDecryptStringA("test\_string"); printf("a = %s, b = %s\n", a, b);*

For this sample case, messy code would be shown when you print string “a”.


# How to evaluate Virbox Protector protection performance

\--Use decompiler to evaluate shielding performance when you completed your Mobile Apps shielding/hardening

With Virbox Protector shielding/hardening features, developer has capability to safeguard their application, project to defend the third party attacker to use decompiler in reverse engineering and tampering their project.

Usually, when developer complete protection/shielding configuration and process (By GUI or CLI tool). developer need to check and evaluate the protection result and see if the App is safety enough to detect/defend the potential attack behaviors.

in this article, we will briefing the process and steps by use of decompiler to check if your protection configuration is strong enough to defend the decompiling and reverse engineering. if not, you can back and update your configuration (to select more functions, protection option) to enhance and improve your protection scheme.

**Potential threaten**

Usually, crack/attacker will take following way to attack your mobile project:

**Static analysis,** use decompiler to analysis and get the source code, the critical algorithm, data resource by searching key word, method/class name, to identify the critical code position in the project. With those way to crack and get source code of algorithm. etc. analyze it, modify it, debug it, etc. or for further tampering/repackaging your project later.

**Dynamic Analysis**, At runtime, cracker use variety of techniques, such as debug tools, to analyze trace and modify your application when execution, Today, it is easier than ever before for a malicious user to deploy various techniques like jailbreaking, rooting, hooking, and more in order to steal decryption keys, intercept communication to servers and more.

Next, we will take a android apk as a example to show

1. How easily to decompile and analysis original sample apk by use of: `Jadx` GUI tool (you may use other decompiler you familiar or frequently used) and `IDA pro`
2. The protection process to the method, resource, .so libs contained in the sample apk above by use of Virbox Protector.
3. Use same decompiler and reverse engineering tool analysis and check if the protected "Component" in the sample apk can be decompiled and reverse to source code.

### Decompile the original sample projects

The sample apk here we used `demo.apk` is normal Apk package (you also can use AAB or other types of mobile or native language apps to verify the shielding performance if you want) which consists of `Dex` file, soruce code, resource, `.so` libs. everything in one package.

The original `demo.apk`, without any of code obfuscation, resource and libs encryption of protection. so when we use the decompiler `Jadx`GUI tool, a open source decompiler to analysis this apk. all source code, resource, libs will be clearly be decompiled.

First, Open the `Jadx` GUI tool and drag the `demo.apk` into the `Jadx` GUI tool, then `Jadx` will parse all of functions, dex file, resource into source code. for example, the method name "messengerUtils", all of source code has been parsed, as shown as below snapshot:

<figure><img src="/files/fidfOVGHjEUZyMHBXMC8" alt=""><figcaption></figcaption></figure>

For resource file, we use the `test.txt` a resource file, as a sample and use the `Jadx` to decompile. the parsing result like this:

<figure><img src="/files/sZWwEKUFQzAg3uPvMEY5" alt=""><figcaption></figcaption></figure>

For the native library contained in the demo.apk. we use the `IDA pro` (you may use other decompiler if you want) to analysis the native library. It shown clearly structure of source code and function's name.

<figure><img src="/files/247y2Qbjjb433Lku56nb" alt=""><figcaption></figcaption></figure>

From the decompiling above, Without the shielding/protection to original sample applications (Apk, or AAB, AAR, or iOS project), by use of decompiler or reverse engineering tool, it is quite easy to third party attacker to get all of source code, methodology of functions, code logic, data resource for further tampering, repackaging.

### Protection process by use of Virbox Protector

We use the same sample apk to show how to protect the same functions, resource, libs which source code has been decompiled by `Jadx GUI` tool and `IDA pro`.

First drag the `demo.apk` into Virbox Protector GUI tool, after parsing the `demo.apk`, Virbox Protector GUI tool will show as below. then next we will protect the functions, resources, native library respectively in relevant tabs.

<figure><img src="/files/n85AVRiyQJslcl4fdhw9" alt=""><figcaption></figcaption></figure>

Step 1. Protect the functions in "Function Option" tabs with "virtualization"

First, Go to the "Function Option" tabs find `messengerUtils` functions, and select and use the "Virtualization" (Code of Virtualization) to obfuscate this functions, as shown as snapshot in below:

<figure><img src="/files/1qbSTxhFVpE8f4mJHbTE" alt=""><figcaption></figcaption></figure>

Step 2. Protect the resource (`asset/test.txt`) in "Resource Encryption" tabs:

With Virbox Protector, developer may select and encrypt the resource file under the sub directory: `\assets` and `\res`. In the sample case, we encrypt the resource file `test.txt` which under the su directory: \a`ssst`.

<figure><img src="/files/jGv8d2U20sipWuORFV9S" alt=""><figcaption></figcaption></figure>

Step 3. Protect the native lib in "Native Library Protection" tabs

Virbox Protector support developer to protect the native lib, with compression and encryption technology.

Tips: For the developer who develop .so lib and it will be integrate to other android developers, you may select the Virbox Protector .so license to protect/shielding your .so libs. then you can obfuscate/virtualize the functions contained in the .so libs. with most secured shielding performance than the compression/encryption to .so libs.

<figure><img src="/files/IDlqLkCErKvYa7XbsBCe" alt=""><figcaption></figcaption></figure>

Step 4. General protection setting in "Protection option" tabs:

Besides of selecting the protection feature to defend dynamic analysis and tampering, please refer the relevant setting in the "Protection option" tabs. such as "Debugger Detection", "Anti Injection", "Sign setting" etc..

You also need to select `Dex Encryption` to encrypt all dex file in "Protection Option" tabs. which for general protection to dex file.

<figure><img src="/files/VgUacUrzYvSNpeB9PLy1" alt=""><figcaption></figcaption></figure>

With above setting, then you can click the button "**Protected Selected Projects**" to start Protection.

### Decompile process to verify shielding performance

Then we go to output path on default: `\protected\` and use the `Jadx` and `IDA Pro` to decompile the protected `demo.apk` and to verify if above function`messengerUtils`, resource file `test.txt` and .so lib (Native library) can be decompile to original or not.

Drag the protected `demo.apk` into `Jadx` and first to find the protected functions, as shown as below (you can compare with the decompiling result in above snapshot), it is clearly shown above function has been well obfuscated and failed to decompiled to source code by same decompiler.

<figure><img src="/files/3vt3ychAtXVXjxBZtCMA" alt=""><figcaption></figcaption></figure>

Use `Jadx` to decompile the protected resource: `test.txt`, compared with the decompiling result before protection. you can not find any useful information, text content can not be recognized after decompiled:

<figure><img src="/files/toHidKn8SPbKaDxe2R8B" alt=""><figcaption></figcaption></figure>

Last we use the IDA pro to decompile .so lib which protected previously, with the encryption and compression to the .so lib protection, with IDA pro, the functions name, the code of structure are totally different compared with the decompiling before protection.

<figure><img src="/files/DcmDNzLraJzOC8P2MRZu" alt=""><figcaption></figcaption></figure>

### in Summary

Virbox Protector supports developer to shield and protect their mobile project quickly, and it is also necessary to verify the security/Shielding performance by use of third party open source decompiler and reverse engineering tool before launch and release the project. Here we just take example to go through the evaluation process by use of open source tool. Developer also may the other similar tool to verify the shielding performance. Similar verification process can be used to verify your mobile project Apk, AAB, AAR (SDK) and .so libs or to your iOS projects.

Note: Here we just go through the evaluation process to verify the protection performance. in practical case, it is necessary for developer to design their own dedicate scheme to shield/protect their project, according to the specific project requirement. also, the potential risk/attack from third party attacker included but no limited listed above behaviors. Developer should be use the the other tool/methods to check/audit the soft project before project release to make sure code security and vulnerability.

One thing remind, For critical string in your applications, such as password, user name, Virbox Protector also support to use `SDK lable` to mark these critical string to encrypt it which to protect and no leaking happened to third party attacker.

### Appendix

The most popular and frequently used decompiler and reverse engineering tool which developer used to verify the shielding performance.

Open source tools for Android Apps

[Jadx](https://github.com/skylot/jadx)

[IDA pro](https://hex-rays.com/ida-free/)

[Apk tool](https://github.com/iBotPeaches/Apktool)

**For Native Project decompiler**

[Ghidra](https://ghidra-sre.org/)

**For Java Project decompiler**

[Jadx](https://github.com/skylot/jadx)

**For .NET Decompiler**

[Il Spy](https://github.com/icsharpcode/ILSpy/releases)

[DnSpy](https://github.com/dnSpy/dnSpy)

and also, these tools also can be use to verify your shielding performance

Il Dasm

Reflector

debugger,

windbg, etc.


