A. K. Mandal, Agostino Cortesi, Pietro Ferrara, F. Panarotto, F. Spoto
{"title":"Vulnerability analysis of Android auto infotainment apps","authors":"A. K. Mandal, Agostino Cortesi, Pietro Ferrara, F. Panarotto, F. Spoto","doi":"10.1145/3203217.3203278","DOIUrl":null,"url":null,"abstract":"With over 2 billion active mobile users and a large array of features, Android is the most popular operating system for mobile devices. Android Auto allows such devices to connect with an in-car compatible infotainment system, and it became a popular choice as well. However, as the trend for connecting car dashboard to the Internet or other devices grows, so does the potential for security threats. In this paper, a set of potential security threats are identified, and a static analyzer for the Android Auto infotainment system is presented. All the infotainment apps available in Google Play Store have been checked against that list of possible exposure scenarios. Results show that almost 80% of the apps are potentially vulnerable, out of which 25% poses security threats related to execution of JavaScript.","PeriodicalId":127096,"journal":{"name":"Proceedings of the 15th ACM International Conference on Computing Frontiers","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"27","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 15th ACM International Conference on Computing Frontiers","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3203217.3203278","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 27
Abstract
With over 2 billion active mobile users and a large array of features, Android is the most popular operating system for mobile devices. Android Auto allows such devices to connect with an in-car compatible infotainment system, and it became a popular choice as well. However, as the trend for connecting car dashboard to the Internet or other devices grows, so does the potential for security threats. In this paper, a set of potential security threats are identified, and a static analyzer for the Android Auto infotainment system is presented. All the infotainment apps available in Google Play Store have been checked against that list of possible exposure scenarios. Results show that almost 80% of the apps are potentially vulnerable, out of which 25% poses security threats related to execution of JavaScript.
Android拥有超过20亿的活跃移动用户和大量的功能,是最受欢迎的移动设备操作系统。Android Auto允许这些设备与车内兼容的信息娱乐系统连接,它也成为了一个受欢迎的选择。然而,随着将汽车仪表盘连接到互联网或其他设备的趋势的增长,安全威胁的潜力也在增加。本文针对Android汽车信息娱乐系统中存在的安全隐患,提出了一种静态分析方法。Google Play Store中所有可用的信息娱乐应用程序都已根据可能的暴露场景列表进行了检查。结果显示,近80%的应用程序存在潜在漏洞,其中25%的应用程序存在与JavaScript执行相关的安全威胁。