Benjamin Eriksson, J. Groth, A. Sabelfeld
{"title":"On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform","authors":"Benjamin Eriksson, J. Groth, A. Sabelfeld","doi":"10.5220/0007678200640075","DOIUrl":null,"url":null,"abstract":"© 2019 by SCITEPRESS - Science and Technology Publications, Lda. Digitalization has revolutionized the automotive industry. Modern cars are equipped with powerful Internetconnected infotainment systems, comparable to tablets and smartphones. Recently, several car manufacturers have announced the upcoming possibility to install third-party apps onto these infotainment systems. The prospect of running third-party code on a device that is integrated into a safety critical in-vehicle system raises serious concerns for safety, security, and user privacy. This paper investigates these concerns of in-vehicle apps. We focus on apps for the Android Automotive operating system which several car manufacturers have opted to use. While the architecture inherits much from regular Android, we scrutinize the adequateness of its security mechanisms with respect to the in-vehicle setting, particularly affecting road safety and user privacy. We investigate the attack surface and vulnerabilities for third-party in-vehicle apps. We analyze and suggest enhancements to such traditional Android mechanisms as app permissions and API control. Further, we investigate operating system support and how static and dynamic analysis can aid automatic vetting of in-vehicle apps. We develop AutoTame, a tool for vehicle-specific code analysis. We report on a case study of the countermeasures with a Spotify app using emulators and physical test beds from Volvo Cars.","PeriodicalId":218840,"journal":{"name":"International Conference on Vehicle Technology and Intelligent Transport Systems","volume":"125 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-05-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Conference on Vehicle Technology and Intelligent Transport Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5220/0007678200640075","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8
在有第三方应用的路上:一个车载应用平台的安全性分析
©2019 by sciitepress - Science and Technology Publications, Lda。数字化已经彻底改变了汽车行业。现代汽车配备了强大的联网信息娱乐系统,堪比平板电脑和智能手机。最近,几家汽车制造商宣布,即将有可能在这些信息娱乐系统上安装第三方应用程序。在集成到安全关键车载系统中的设备上运行第三方代码的前景引发了对安全性、安全性和用户隐私的严重担忧。本文对车载应用程序的这些问题进行了调查。我们专注于Android汽车操作系统的应用程序,一些汽车制造商已经选择使用该系统。虽然该系统的架构继承了常规Android系统的许多优点,但我们仔细检查了其安全机制在车载设置方面的适当性,尤其是在道路安全和用户隐私方面。我们调查了第三方车载应用的攻击面和漏洞。我们分析并建议增强传统的Android机制,如应用程序权限和API控制。此外,我们还研究了操作系统的支持,以及静态和动态分析如何帮助自动审查车载应用程序。我们开发了AutoTame,一个用于车辆特定代码分析的工具。我们报告了一个针对Spotify应用程序的对策案例研究,该应用程序使用了沃尔沃汽车的模拟器和物理测试平台。
本文章由计算机程序翻译,如有差异,请以英文原文为准。