Static analysis of Android Auto infotainment and on-board diagnostics II apps

被引:21
|
作者
Mandal, Amit Kr [1 ,2 ]
Panarotto, Federica [3 ]
Cortesi, Agostino [1 ]
Ferrara, Pietro [4 ]
Spoto, Fausto [3 ]
机构
[1] Ca Foscari Univ Venice, Venice, Italy
[2] BML Munjal Univ, Gurugram, India
[3] Univ Verona, Verona, Italy
[4] JuliaSoft Srl, Verona, Italy
来源
SOFTWARE-PRACTICE & EXPERIENCE | 2019年 / 49卷 / 07期
关键词
abstract interpretation; Android auto security; in-vehicle infotainment system; ODB-II app security; static analysis;
D O I
10.1002/spe.2698
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Smartphone and automotive technologies are rapidly converging, letting drivers enjoy communication and infotainment facilities and monitor in-vehicle functionalities, via on-board diagnostics (OBD) technology. Among the various automotive apps available in playstores, Android Auto infotainment and OBD-II apps are widely used and are the most popular choice for smartphone to car interaction. Automotive apps have the potential of turning cars into smartphones on wheels but can be also the gateway of attacks. This paper defines a static analysis that identifies potential security risks in Android infotainment and OBD-II apps. It identifies a set of potential security threats and presents an actual static analyzer for such apps. It has been applied to most of the highly rated infotainment apps available in the Google Play store, as well as on the available open-source OBD-II apps, against a set of possible exposure scenarios. Results show that almost 60% of such apps are potentially vulnerable and that 25% pose security threats related to the execution of JavaScript. The analysis of the OBD-II apps shows possibilities of severe controller area network injections and privacy violations, because of leaks of sensitive information.
引用
收藏
页码:1131 / 1161
页数:31
相关论文
共 33 条
  • [31] Ammonia Slip Estimation Based on Ammonia Slip Catalyst Control-Oriented Modeling and On-Board Diagnostics NOX Sensor Cross-Sensitivity Analysis
    Piqueras, Pedro
    Pla, Benjamin
    Sanchis, Enrique Jose
    Aronis, Andre
    JOURNAL OF ENGINEERING FOR GAS TURBINES AND POWER-TRANSACTIONS OF THE ASME, 2023, 145 (04):
  • [32] Integration of Second-generation On-board Diagnostics Data via Deep Learning to Develop Eco-driving Analysis System Applicable to Large and Small Cars
    Chen, Chi-Chun
    Tian, Shang-Lin
    Teng, Chung-Chen
    Yang, Cheng-Wei
    Yen, Meng-Hua
    SENSORS AND MATERIALS, 2022, 34 (06) : 2467 - 2478
  • [33] Status of the EPIC thin and medium filters on-board XMM-Newton after more than 10 years of operation: II - analysis of in-flight data
    Gastaldello, Fabio
    Barbera, Marco
    Collura, Alfonso
    La Palombara, Nicola
    Lo Cicerro, Ugo
    Sartore, Nicola
    Tiengo, Andrea
    Varisco, Salvatore
    UV, X-RAY, AND GAMMA-RAY SPACE INSTRUMENTATION FOR ASTRONOMY XVIII, 2013, 8859