On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform

被引:7
|
作者
Eriksson, Benjamin [1 ]
Groth, Jonas [1 ]
Sabelfeld, Andrei [1 ]
机构
[1] Chalmers Univ Technol, Dept Comp Sci & Engn, Gothenburg, Sweden
基金
瑞典研究理事会;
关键词
In-vehicle App Security; API Security; Program Analysis for Security; Infotainment; Information Flow Control; Android Automotive;
D O I
10.5220/0007678200640075
中图分类号
U [交通运输];
学科分类号
08 ; 0823 ;
摘要
Digitalization has revolutionized the automotive industry. Modern cars are equipped with powerful Internet-connected infotainment systems, comparable to tablets and smartphones. Recently, several car manufacturers have announced the upcoming possibility to install third-party apps onto these infotainment systems. The prospect of running third-party code on a device that is integrated into a safety critical in-vehicle system raises serious concerns for safety, security, and user privacy. This paper investigates these concerns of in-vehicle apps. We focus on apps for the Android Automotive operating system which several car manufacturers have opted to use. While the architecture inherits much from regular Android, we scrutinize the adequateness of its security mechanisms with respect to the in-vehicle setting, particularly affecting road safety and user privacy. We investigate the attack surface and vulnerabilities for third-party in-vehicle apps. We analyze and suggest enhancements to such traditional Android mechanisms as app permissions and API control. Further, we investigate operating system support and how static and dynamic analysis can aid automatic vetting of in-vehicle apps. We develop AutoTame, a tool for vehicle-specific code analysis. We report on a case study of the countermeasures with a Spotify app using emulators and physical test beds from Volvo Cars.
引用
收藏
页码:64 / 75
页数:12
相关论文
共 50 条
  • [31] Ammunition Security Studies Based on Third-party logistics
    Wang Jia
    Li Liangchun
    Li Wensheng
    Song Guifei
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON LOGISTICS, ENGINEERING, MANAGEMENT AND COMPUTER SCIENCE, 2014, 101 : 246 - 249
  • [32] Evolutionary Game Analysis of Supervisory Decision Behavior of Third-party Trading Platform
    Yang, Yanbing
    Zhang, Qin
    2020 3RD INTERNATIONAL CONFERENCE ON APPLIED MATHEMATICS, MODELING AND SIMULATION, 2020, 1670
  • [33] The Game Analysis Based on the Third-party Platform Supervision in E-commerce
    Zhou, Jingzhi
    PROCEEDINGS OF 2016 5TH INTERNATIONAL CONFERENCE ON SOCIAL SCIENCE, EDUCATION AND HUMANITIES RESEARCH, 2016, 69 : 913 - 917
  • [34] Diversified Third-Party Library Prediction for Mobile App Development
    He, Qiang
    Li, Bo
    Chen, Feifei
    Grundy, John
    Xia, Xin
    Yang, Yun
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (01) : 150 - 165
  • [35] Third-Party Vehicle Data Collection for Advanced Driver Assistance Systems Analysis
    Berman, Kathleen
    Campbell, Keith
    Gawron, Valerie
    Long, Jeffrey
    Yuha, Samir
    TRANSPORTATION RESEARCH RECORD, 2022, 2676 (02) : 227 - 234
  • [36] An analysis of a third-party food delivery app during the COVID-19 pandemic
    Mccain, Shiang-Lih Chen
    Lolli, Jeffrey
    Liu, Emma
    Lin, Li-Chun
    BRITISH FOOD JOURNAL, 2022, 124 (10): : 3032 - 3052
  • [37] fMRI analysis of third-party punishment
    不详
    NEUROSCIENTIST, 2009, 15 (03): : 214 - 214
  • [38] The Adoption and Openness of Livestreaming on the Retail Platform with Third-Party Sellers
    Liu, Shukun
    Li, Wenli
    Wang, Peng
    JOURNAL OF THEORETICAL AND APPLIED ELECTRONIC COMMERCE RESEARCH, 2023, 18 (02): : 867 - 888
  • [39] Design and Development of the Third-party E-Commerce Platform
    Wang, Tao
    Zhu, Xianyue
    MATERIALS ENGINEERING FOR ADVANCED TECHNOLOGIES (ICMEAT 2013), 2014, 510 : 288 - 292
  • [40] Research on Third-Party Libraries in Android Apps: A Taxonomy and Systematic Literature Review
    Zhan, Xian
    Liu, Tianming
    Fan, Lingling
    Li, Li
    Chen, Sen
    Luo, Xiapu
    Liu, Yang
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (10) : 4181 - 4213