首页> 外文会议>International Conference on Vehicle Technology and Intelligent Transport Systems >On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform
【24h】

On the Road with Third-party Apps: Security Analysis of an In-vehicle App Platform

机译:在第三方应用程序的道路上:车载应用程序平台的安全分析

获取原文

摘要

Digitalization has revolutionized the automotive industry. Modern cars are equipped with powerful Internet-connected infotainment systems, comparable to tablets and smartphones. Recently, several car manufacturers have announced the upcoming possibility to install third-party apps onto these infotainment systems. The prospect of running third-party code on a device that is integrated into a safety critical in-vehicle system raises serious concerns for safety, security, and user privacy. This paper investigates these concerns of in-vehicle apps. We focus on apps for the Android Automotive operating system which several car manufacturers have opted to use. While the architecture inherits much from regular Android, we scrutinize the adequateness of its security mechanisms with respect to the in-vehicle setting, particularly affecting road safety and user privacy. We investigate the attack surface and vulnerabilities for third-party in-vehicle apps. We analyze and suggest enhancements to such traditional Android mechanisms as app permissions and API control. Further, we investigate operating system support and how static and dynamic analysis can aid automatic vetting of in-vehicle apps. We develop AutoTame, a tool for vehicle-specific code analysis. We report on a case study of the countermeasures with a Spotify app using emulators and physical test beds from Volvo Cars.
机译:数字化彻底改变了汽车行业。现代汽车都配备了强大的互联网连接的信息娱乐系统,媲美平板电脑和智能手机。最近,一些汽车制造商已经宣布即将可能性安装第三方应用到这些信息娱乐系统。集成到安全设备上运行的第三方代码的前景至关重要的车载系统提高了安全性,安全性和用户隐私的严重关切。本文研究的车载应用的这些问题。我们专注于应用程序为Android汽车的操作系统,它的几个汽车制造商已经选择使用。虽然从架构一般Android多继承,我们仔细审查其安全机制adequateness相对于车内环境,特别是影响道路安全和用户隐私。我们探讨第三方车载应用程序的攻击面和漏洞。我们分析并提出改进这种传统的Android操作机制的应用权限和API控制。此外,我们研究了操作系统的支持,以及如何静态和动态分析,可以帮助车载应用的自动审批。我们开发AutoTame,车辆特有的代码分析工具。我们在使用仿真器和物理试验台沃尔沃汽车一Spotify应用对策的情况研究报告。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号