A Multi-Tier Security Analysis of Official Car Management Apps for Android

被引:7
作者
Chatzoglou, Efstratios [1 ]
Kambourakis, Georgios [2 ]
Kouliaridis, Vasileios [1 ]
机构
[1] Univ Aegean, Dept Informat & Commun Syst Engn, Samos 81300, Greece
[2] European Union, Joint Res Ctr, I-21027 Ispra, Italy
来源
FUTURE INTERNET | 2021年 / 13卷 / 03期
关键词
smart cars; digital automotive services; security; privacy; Android; vulnerability assessment; dynamic analysis; static analysis;
D O I
10.3390/fi13030058
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Using automotive smartphone applications (apps) provided by car manufacturers may offer numerous advantages to the vehicle owner, including improved safety, fuel efficiency, anytime monitoring of vehicle data, and timely over-the-air delivery of software updates. On the other hand, the continuous tracking of the vehicle data by such apps may also pose a risk to the car owner, if, say, sensitive pieces of information are leaked to third parties or the app is vulnerable to attacks. This work contributes the first to our knowledge full-fledged security assessment of all the official single-vehicle management apps offered by major car manufacturers who operate in Europe. The apps are scrutinised statically with the purpose of not only identifying surfeits, say, in terms of the permissions requested, but also from a vulnerability assessment viewpoint. On top of that, we run each app to identify possible weak security practices in the owner-to-app registration process. The results reveal a multitude of issues, ranging from an over-claim of sensitive permissions and the use of possibly privacy-invasive API calls, to numerous potentially exploitable CWE and CVE-identified weaknesses and vulnerabilities, the, in some cases, excessive employment of third-party trackers, and a number of other flaws related to the use of third-party software libraries, unsanitised input, and weak user password policies, to mention just a few.
引用
收藏
页码:1 / 35
页数:35
相关论文
共 23 条
  • [21] Security Testing of Android Apps Using Malware Analysis and XGboost Optimized by Adaptive Particle Swarm Optimization
    Kumar P.
    Singh S.
    SN Computer Science, 5 (1)
  • [22] Amandroid: A Precise and General Inter-component Data Flow Analysis Framework for Security Vetting of Android Apps
    Wei, Fengguo
    Roy, Sankardas
    Ou, Xinming
    Robby
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2018, 21 (03)
  • [23] A Reliable Ring Analysis Engine for Establishment of Multi-Level Security Management in Clouds
    Moghaddam, Faraz Fatemi
    Wieder, Philipp
    Yahyapour, Ramin
    Khodadadix, Touraj
    2018 41ST INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2018, : 505 - 510