On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform

被引:7
|
作者
Eriksson, Benjamin [1 ]
Groth, Jonas [1 ]
Sabelfeld, Andrei [1 ]
机构
[1] Chalmers Univ Technol, Dept Comp Sci & Engn, Gothenburg, Sweden
基金
瑞典研究理事会;
关键词
In-vehicle App Security; API Security; Program Analysis for Security; Infotainment; Information Flow Control; Android Automotive;
D O I
10.5220/0007678200640075
中图分类号
U [交通运输];
学科分类号
08 ; 0823 ;
摘要
Digitalization has revolutionized the automotive industry. Modern cars are equipped with powerful Internet-connected infotainment systems, comparable to tablets and smartphones. Recently, several car manufacturers have announced the upcoming possibility to install third-party apps onto these infotainment systems. The prospect of running third-party code on a device that is integrated into a safety critical in-vehicle system raises serious concerns for safety, security, and user privacy. This paper investigates these concerns of in-vehicle apps. We focus on apps for the Android Automotive operating system which several car manufacturers have opted to use. While the architecture inherits much from regular Android, we scrutinize the adequateness of its security mechanisms with respect to the in-vehicle setting, particularly affecting road safety and user privacy. We investigate the attack surface and vulnerabilities for third-party in-vehicle apps. We analyze and suggest enhancements to such traditional Android mechanisms as app permissions and API control. Further, we investigate operating system support and how static and dynamic analysis can aid automatic vetting of in-vehicle apps. We develop AutoTame, a tool for vehicle-specific code analysis. We report on a case study of the countermeasures with a Spotify app using emulators and physical test beds from Volvo Cars.
引用
收藏
页码:64 / 75
页数:12
相关论文
共 50 条
  • [21] IDPFilter: Mitigating interdependent privacy issues in third-party apps
    Liu, Shuaishuai
    Biczok, Gergely
    COMPUTERS & SECURITY, 2025, 151
  • [22] Do Developers Update Third-Party Libraries in Mobile Apps?
    Salza, Pasquale
    Palomba, Fabio
    Di Nucci, Dario
    D'Uva, Cosmo
    De Lucia, Andrea
    Ferrucci, Filomena
    2018 IEEE/ACM 26TH INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION (ICPC 2018), 2018, : 255 - 265
  • [23] Splitting Third-Party Libraries' Privileges from Android Apps
    Zhan, Jiawei
    Zhou, Quan
    Gu, Xiaozhuo
    Wang, Yuewu
    Niu, Yingjiao
    INFORMATION SECURITY AND PRIVACY, ACISP 2017, PT II, 2017, 10343 : 80 - 94
  • [24] Breaking and Fixing Third-Party Payment Service for Mobile Apps
    Shi, Shangcheng
    Wang, Xianbo
    Lau, Wing Cheong
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, ACNS 2021, PT II, 2021, 12727 : 3 - 26
  • [25] Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps
    Zhao, Kaifa
    Zhan, Xian
    Yu, Le
    Zhou, Shiyao
    Zhou, Hao
    Luo, Xiapu
    Wang, Haoyu
    Liu, Yepang
    Proceedings - International Conference on Software Engineering, 2023, : 1583 - 1595
  • [26] Analysis of an evolutionary game of pallet pooling with participation of third-party platform
    Liu, Cuiping
    Li, Xinchun
    Liu, Quanlong
    PLOS ONE, 2021, 16 (10):
  • [27] The Road to Hell? Third-Party Intervention to Prevent Atrocities
    Kydd, Andrew H.
    Straus, Scott
    AMERICAN JOURNAL OF POLITICAL SCIENCE, 2013, 57 (03) : 673 - 684
  • [28] How to Organize the Third-party Platform for a Property Management
    Xu, Yan-wen
    2016 INTERNATIONAL CONFERENCE ON MANAGEMENT, ECONOMICS AND SOCIAL DEVELOPMENT (ICMESD 2016), 2016, : 963 - 967
  • [29] An Analysis Platform for the Information Security of In-Vehicle Networks Connected with External Networks
    Ezaki, Takaya
    Date, Tomohiro
    Inoue, Hiroyuki
    ADVANCES IN INFORMATION AND COMPUTER SECURITY (IWSEC 2015), 2015, 9241 : 301 - 315
  • [30] LibRadar: Fast and Accurate Detection of Third-party Libraries in Android Apps
    Ma, Ziang
    Wang, Haoyu
    Guo, Yao
    Chen, Xiangqun
    2016 IEEE/ACM 38TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING COMPANION (ICSE-C), 2016, : 653 - 656