Evaluating Network Security Configuration (NSC) Practices in Vehicle-Related Android Applications

Author:

Zhang Linxi1,Ma Di2

Affiliation:

1. Central Michigan University

2. University of Michigan

Abstract

<div class="section abstract"><div class="htmlview paragraph">Android applications have historically faced vulnerabilities to man-in-the-middle attacks due to insecure custom SSL/TLS certificate validation implementations. In response, Google introduced the Network Security Configuration (NSC) as a configuration-based solution to improve the security of certificate validation practices. NSC was initially developed to enhance the security of Android applications by providing developers with a framework to customize network security settings. However, recent studies have shown that it is often not being leveraged appropriately to enhance security. Motivated by the surge in vehicular connectivity and the corresponding impact on user security and data privacy, our research pivots to the domain of mobile applications for vehicles. As vehicles increasingly become repositories of personal data and integral nodes in the Internet of Things (IoT) ecosystem, ensuring their security moves beyond traditional issues to one of public safety and trust. To provide a view of the current vehicle apps security landscape, we delve into 122 vehicle-related apps, grouping them into three distinct categories: official car apps developed by manufacturers, general car-related apps, and OBD-II diagnostic tool apps. Our findings show that 68.85% of apps utilize NSC with varying degrees of NSC customization and security practices across these categories. Additionally, understanding that frequent updates often correlate with active maintenance and potential security patching, we analyze the update frequencies of the top ten downloaded apps in each category. The results provide valuable insight into app developers’ level of commitment to safety in the evolving automotive ecosystem. This research aims to drive awareness, underline existing security NSC practices, and pave the way for a more secure vehicular app environment.</div></div>

Publisher

SAE International

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3