Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer's Point of View

被引:0
作者
Levshun, Dmitry [1 ]
Chechulin, Andrey [1 ]
Kotenko, Igor [1 ]
机构
[1] Russian Acad Sci SPC RAS, St Petersburg Fed Res Ctr, St Petersburg 199178, Russia
关键词
information security; intelligent transportation systems; security analysis; privacy analysis; white-box testing; driver monitoring systems; smartphone sensors; RISK-ASSESSMENT; IOT DEVICES; DESIGN; VULNERABILITIES; INTERNET;
D O I
10.3390/s22135063
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Nowadays, the whole driver monitoring system can be placed inside the vehicle driver's smartphone, which introduces new security and privacy risks to the system. Because of the nature of the modern transportation systems, the consequences of the security issues in such systems can be crucial, leading to threat to human life and health. Moreover, despite the large number of security and privacy issues discovered in smartphone applications on a daily basis, there is no general approach for their automated analysis that can work in conditions that lack data and take into account specifics of the application area. Thus, this paper describes an original approach for a security and privacy analysis of driver monitoring systems based on smartphone sensors. This analysis uses white-box testing principles and aims to help developers evaluate and improve their products. The novelty of the proposed approach lies in combining various security and privacy analysis algorithms into a single automated approach for a specific area of application. Moreover, the suggested approach is modular and extensible, takes into account specific features of smartphone-based driver monitoring systems and works in conditions of lack or inaccessibility of data. The practical significance of the approach lies in the suggestions that are provided based on the conducted analysis. Those suggestions contain detected security and privacy issues and ways of their mitigation, together with limitations of the analysis due to the absence of data. It is assumed that such an approach would help developers take into account important aspects of security and privacy, thus reducing related issues in the developed products. An experimental evaluation of the approach is conducted on a car driver monitoring use case. In addition, the advantages and disadvantages of the proposed approach as well as future work directions are indicated.
引用
收藏
页数:34
相关论文
共 95 条
[1]  
Adomnicai A, 2018, IEEE CONF COMM NETW
[2]  
Al-Hadadi Mubarak, 2013, International Journal of Computer and Electrical Engineering, V5, P576, DOI 10.7763/IJCEE.2013.V5.776
[3]   Security Analysis and Exploitation of Arduino devices in the Internet of Things [J].
Alberca, Carlos ;
Pastrana, Sergio ;
Suarez-Tangil, Guillermo ;
Palmieri, Paolo .
PROCEEDINGS OF THE ACM INTERNATIONAL CONFERENCE ON COMPUTING FRONTIERS (CF'16), 2016, :437-442
[4]  
Ali A., 2021, P IEEE MADRAS SECTIO, P1
[5]   Android data storage security: A review [J].
Altuwaijri, Haya ;
Ghouzali, Sanaa .
JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2020, 32 (05) :543-552
[6]  
Angelini M., 2018, P 19 INT C DISTRIBUT, P1
[7]  
[Anonymous], 2010, P INT C PERV COMP TE
[8]  
ASSmuth A., 2021, PROC 2 INT C CLOUD C, P8
[9]   Mobile application security: Role of perceived privacy as the predictor of security perceptions [J].
Balapour, Ali ;
Nikkhah, Hamid Reza ;
Sabherwal, Rajiv .
INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2020, 52
[10]  
Beaulaton D, 2018, 2018 13TH ANNUAL CONFERENCE ON SYSTEM OF SYSTEMS ENGINEERING (SOSE), P37, DOI 10.1109/SYSOSE.2018.8428704