On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform

被引:7
|
作者
Eriksson, Benjamin [1 ]
Groth, Jonas [1 ]
Sabelfeld, Andrei [1 ]
机构
[1] Chalmers Univ Technol, Dept Comp Sci & Engn, Gothenburg, Sweden
基金
瑞典研究理事会;
关键词
In-vehicle App Security; API Security; Program Analysis for Security; Infotainment; Information Flow Control; Android Automotive;
D O I
10.5220/0007678200640075
中图分类号
U [交通运输];
学科分类号
08 ; 0823 ;
摘要
Digitalization has revolutionized the automotive industry. Modern cars are equipped with powerful Internet-connected infotainment systems, comparable to tablets and smartphones. Recently, several car manufacturers have announced the upcoming possibility to install third-party apps onto these infotainment systems. The prospect of running third-party code on a device that is integrated into a safety critical in-vehicle system raises serious concerns for safety, security, and user privacy. This paper investigates these concerns of in-vehicle apps. We focus on apps for the Android Automotive operating system which several car manufacturers have opted to use. While the architecture inherits much from regular Android, we scrutinize the adequateness of its security mechanisms with respect to the in-vehicle setting, particularly affecting road safety and user privacy. We investigate the attack surface and vulnerabilities for third-party in-vehicle apps. We analyze and suggest enhancements to such traditional Android mechanisms as app permissions and API control. Further, we investigate operating system support and how static and dynamic analysis can aid automatic vetting of in-vehicle apps. We develop AutoTame, a tool for vehicle-specific code analysis. We report on a case study of the countermeasures with a Spotify app using emulators and physical test beds from Volvo Cars.
引用
收藏
页码:64 / 75
页数:12
相关论文
共 50 条
  • [1] Security analysis of third-party in-app payment in mobile applications
    Yang, Wenbo
    Li, Juanru
    Zhang, Yuanyuan
    Gu, Dawu
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 48
  • [2] Brahmastra: Driving Apps to Test the Security of Third-Party Components
    Bhoraskar, Ravi
    Han, Seungyeop
    Jeon, Jinseong
    Azim, Tanzirul
    Chen, Shuo
    Jung, Jaeyeon
    Nath, Suman
    Wang, Rui
    Wetherall, David
    PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 1021 - 1036
  • [3] USER'S ADOPTION OF FREE THIRD-PARTY SECURITY APPS
    Han, Bo
    Wu, Yu
    Windsor, John
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2014, 54 (03) : 77 - 86
  • [4] Analysis the Development and Security Policy of Third-Party Online Payment Platform
    Zhen, Chenggang
    Cheng, Peng
    ICCSIT 2010 - 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, VOL 3, 2010, : 43 - 47
  • [5] Categorization of Third-Party Apps in Electronic Health Record App Marketplaces: Systematic Search and Analysis
    Ritchie, Jordon
    Welch, Brandon
    JMIR MEDICAL INFORMATICS, 2020, 8 (05)
  • [6] Business Model Analysis of the Third-Party Platform of Electric Vehicle Charging Pile
    Tong, Yu
    PROCEEDINGS OF THE 5TH ANNUAL INTERNATIONAL CONFERENCE ON SOCIAL SCIENCE AND CONTEMPORARY HUMANITY DEVELOPMENT (SSCHD 2019), 2019, 376 : 110 - 113
  • [7] Understanding Third-party Libraries in Mobile App Analysis
    Wang, Haoyu
    Guo, Yao
    PROCEEDINGS OF THE 2017 IEEE/ACM 39TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING COMPANION (ICSE-C 2017), 2017, : 515 - 516
  • [8] Third-party apps (TPAs) and software platform performance: The moderating role of competitive entry
    Zhou, Geng
    Song, Peijian
    INFORMATION & MANAGEMENT, 2018, 55 (07) : 901 - 911
  • [9] Security Implications of Third-Party Accelerators
    Olson, Lena E.
    Sethumadhavan, Simha
    Hill, Mark D.
    IEEE COMPUTER ARCHITECTURE LETTERS, 2016, 15 (01) : 50 - 53
  • [10] Third-Party Apps on Facebook: Privacy and the Illusion of Control
    Wang, Na
    Xu, Heng
    Grossklags, Jens
    PROCEEDINGS OF THE 5TH ACM SYMPOSIUM ON COMPUTER HUMAN INTERACTION FOR MANAGEMENT OF INFORMATION TECHNOLOGY (CHIMIT 2011), 2011,