On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform

被引:7
|
作者
Eriksson, Benjamin [1 ]
Groth, Jonas [1 ]
Sabelfeld, Andrei [1 ]
机构
[1] Chalmers Univ Technol, Dept Comp Sci & Engn, Gothenburg, Sweden
基金
瑞典研究理事会;
关键词
In-vehicle App Security; API Security; Program Analysis for Security; Infotainment; Information Flow Control; Android Automotive;
D O I
10.5220/0007678200640075
中图分类号
U [交通运输];
学科分类号
08 ; 0823 ;
摘要
Digitalization has revolutionized the automotive industry. Modern cars are equipped with powerful Internet-connected infotainment systems, comparable to tablets and smartphones. Recently, several car manufacturers have announced the upcoming possibility to install third-party apps onto these infotainment systems. The prospect of running third-party code on a device that is integrated into a safety critical in-vehicle system raises serious concerns for safety, security, and user privacy. This paper investigates these concerns of in-vehicle apps. We focus on apps for the Android Automotive operating system which several car manufacturers have opted to use. While the architecture inherits much from regular Android, we scrutinize the adequateness of its security mechanisms with respect to the in-vehicle setting, particularly affecting road safety and user privacy. We investigate the attack surface and vulnerabilities for third-party in-vehicle apps. We analyze and suggest enhancements to such traditional Android mechanisms as app permissions and API control. Further, we investigate operating system support and how static and dynamic analysis can aid automatic vetting of in-vehicle apps. We develop AutoTame, a tool for vehicle-specific code analysis. We report on a case study of the countermeasures with a Spotify app using emulators and physical test beds from Volvo Cars.
引用
收藏
页码:64 / 75
页数:12
相关论文
共 50 条
  • [41] Impact of Platform Owner's Entry on Third-Party Stores
    He, Shu
    Peng, Jing
    Li, Jianbin
    Xu, Liping
    INFORMATION SYSTEMS RESEARCH, 2020, 31 (04) : 1467 - 1484
  • [42] Understanding and Mitigating Privacy Leaks from Third-Party Smart Speaker Apps
    Alrumayh, Abrar S.
    Lehman, Sarah M.
    Tan, Chiu C.
    2021 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2021, : 263 - 271
  • [43] Automated Detection and Classification of Third-Party Libraries in Large Scale Android Apps
    Wang H.-Y.
    Guo Y.
    Ma Z.-A.
    Chen X.-Q.
    Guo, Yao (yaoguo@pku.edu.cn), 1600, Chinese Academy of Sciences (28): : 1373 - 1388
  • [44] The Design of Enterprise Logistics System Based on Third-party Platform
    Wan, Haixia
    INTERNATIONAL SYMPOSIUM ON ENGINEERING TECHNOLOGY, EDUCATION AND MANAGEMENT (ISETEM 2014), 2014, : 486 - 491
  • [45] Optimization on the recommender system of the third-party platform in new retailing
    Zhou, Yuqian
    Wang, Dong
    Li, Qing
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (02) : 1957 - 1975
  • [46] Updating apps for graphics and .NET - Third-party tools save money and time
    Purdum, Jack J.
    DR DOBBS JOURNAL, 2007, 32 (04): : 85 - +
  • [47] A Payment Model of Mobile Phone based on Third-party Security
    Xu, Yong
    Liu, Xueyan
    Yao, Ruiying
    ICMECG: 2009 INTERNATIONAL CONFERENCE ON MANAGEMENT OF E-COMMERCE AND E-GOVERNMENT, PROCEEDINGS, 2009, : 400 - +
  • [48] Optimizing Product Improvement Spending with Third-Party Security Consultants
    Matthews, Bronwen
    IEEE SECURITY & PRIVACY, 2012, 10 (01) : 91 - 93
  • [49] Study on the Security of Collaborative Management Model of the Third-Party Payment
    Meng Tao
    Huang Shiyu
    PROCEEDINGS OF 2012 7TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE & EDUCATION, VOLS I-VI, 2012, : 550 - 553
  • [50] Shipboard ECDIS Cyber Security: Third-Party Component Threats
    Svilicic, Boris
    Rudan, Igor
    Francic, Vlado
    Doricic, Mateo
    POMORSTVO-SCIENTIFIC JOURNAL OF MARITIME RESEARCH, 2019, 33 (02) : 176 - 180