Abstract
Automotive companion apps are mobile apps designed to remotely connect with cars to provide features such as diagnostics, logging, navigation, and safety alerts. Specifically, onboard diagnostics (OBD) based mobile applications directly communicate with the in-vehicle network through the OBD device. This can lead to several security issues, for instance, onboard information of vehicles can be tracked or altered through a malicious or vulnerable app. We conduct a comprehensive measurement study including static, runtime, and network traffic analysis of OBD companion apps. Our analysis has been applied to 125 Android mobile applications available on the Google Play Store. We identify a set of vulnerabilities and further validate these vulnerabilities with real-world vehicles. We show that 70% of the apps have vulnerabilities that can lead to private information leakage, property theft, and direct risk while driving. For instance, 18 apps could connect to open OBD dongles without requiring any authentication, accept arbitrary CAN commands as inputs from the (potentially malicious) user, and deliver the commands to the CAN bus without any validation. We discuss the possible countermeasures and also make responsible disclosures to app developers.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Similar content being viewed by others
References
A complete guide to hacking your vehicle bus on the cheap and easy. https://theksmith.com/software/hack-vehicle-bus-cheap-easy-part-1/
A remote attack on the bosch drive log connector Dongle. https://argus-sec.com/blog/cyber-security-blog/remote-attack-bosch-drivelog-connector-dongle/
Auto cyberattacks becoming more widespread. https://semiengineering.com/auto-cyberattacks-becoming-more-widespread
Controlling vehicle features of Nissan LEAFs across the globe via vulnerable APIs. https://www.troyhunt.com/controlling-vehicle-features-of-nissan/
ELM 327 detailed info. https://www.sparkfun.com/datasheets/Widgets/ELM327_AT_Commands.pdf
Hacking cars remotely with just their VIN. https://www.bitdefender.com/blog/hotforsecurity/hacking-cars-remotely-with-just-their-vin
How to hack a car - a quick crash-course. https://www.freecodecamp.org/news/hacking-cars-a-guide-tutorial-on-how-to-hack-a-car-5eafcfbbb7ec
Hyundai ‘Blue Link’ vulnerability allows thieves to start cars remotely (update: Hyundai’s statement). https://www.tomshardware.com/news/hyundai-blue-link-vulnerability-thieves,34248.html
OBD2 Explained - A Simple Intro. https://www.csselectronics.com/pages/obd2-explained-simple-intro
There’s a new form of keyless car theft that works in under 2 minutes (2023)
Abraham, A., et al.: Mobile Security Framework (MobSF). https://github.com/ajinabraham/Mobile-Security-Framework-MobSF. Accessed January 2024
Ai, M., et al.: Blacktooth: breaking through the defense of Bluetooth in silence. In: ACM CCS (2022)
Alrawi, O., Zuo, C., Duan, R., Kasturi, R.P., Lin, Z., Saltaformaggio, B.: The betrayal at cloud city: an empirical analysis of cloud-based mobile backends. In: USENIX Security Symposium, pp. 551–566 (2019)
Antonioli, D., Payer, M.: On the insecurity of vehicles against protocol-level Bluetooth threats. In: IEEE Security and Privacy Workshops (2022)
Antonioli, D., Tippenhauer, N.O., Rasmussen, K.B.: The \(\{\)KNOB\(\}\) is broken: exploiting low entropy in the encryption key negotiation of Bluetooth \(\{\)BR/EDR\(\}\). In: USENIX Security Symposium (2019)
Avatefipour, O., Malik, H.: State-of-the-art survey on in-vehicle network communication (CAN-Bus) security and vulnerabilities. arXiv:1802.01725 (2018)
Bernardini, C., Asghar, M.R., Crispo, B.: Security and privacy in vehicular communications: challenges and opportunities. Veh. Commun. 10, 13–28 (2017)
Bloom, G.: WeepingCAN: a stealthy can bus-off attack. In: Workshop on Automotive and Autonomous Vehicle Security (2021)
Bolshev, A., Yushkevich, I.: Scada and Mobile Security in the Internet of Things Era. EMBEDI, IOActive, Whitepaper (2017)
Bozdal, M., Samie, M., Aslam, S., Jennions, I.: Evaluation of can bus security challenges. Sensors 20(8), 2364 (2020)
Bruton, J.A.: Securing can bus communication: An analysis of cryptographic approaches, pp. 1–5. Nat. Univ. Ireland, Galway (2014)
De La Torre, G., Rad, P., Choo, K.K.R.: Driverless vehicle security: challenges and future research opportunities. Futur. Gener. Comput. Syst. 108, 1092–1111 (2020)
Demba, A., Möller, D.P.: Vehicle-to-vehicle communication technology. In: IEEE International Conference on Electro/Information Technology (EIT) (2018)
Faruki, P., et al.: Android security: a survey of issues, malware penetration, and defenses. IEEE Commun. Surv. Tutorials 17(2), 998–1022 (2014)
He, D., Naveed, M., Gunter, C.A., Nahrstedt, K.: Security concerns in android mHealth apps. In: AMIA annual symposium proceedings, vol. 2014, p. 645. American Medical Informatics Association (2014)
Humayed, A.: An overview of vehicle OBD-II port countermeasures. In: International Conference on Interactive Collaborative Robotics (2023)
Humayed, A., Li, F., Lin, J., Luo, B.: CANSentry: Securing CAN-based cyber-physical systems against denial and spoofing attacks. In: Chen, L., Li, N., Liang, K., Schneider, S. (eds.) ESORICS 2020. LNCS, vol. 12308, pp. 153–173. Springer, Cham (2020). https://doi.org/10.1007/978-3-030-58951-6_8
Humayed, A., Luo, B.: Poster: cyber-physical security for smart cars: taxonomy of vulnerabilities, threats, and attacks. In: ACM/IEEE ICCPS (2015)
Humayed, A., Luo, B.: Using id-hopping to defend against targeted dos on can. In: International Workshop on Safe Control of Connected and Autonomous Vehicles (2017)
Iehira, K., Inoue, H., Ishida, K.: Spoofing attack using bus-off attacks against a specific ECU of the CAN bus. In: IEEE CCNC (2018)
Jedh, M., Othmane, L.B., Ahmed, N., Bhargava, B.: Detection of message injection attacks onto the can bus using similarities of successive messages-sequence graphs. IEEE Trans. Inf. Forensics Secur. 16, 4133–4146 (2021)
Jo, H.J., Choi, W.: A survey of attacks on controller area networks and corresponding countermeasures. IEEE Trans. Intell. Transp. Syst. 23(7), 6123–6141 (2021)
Krishna, A.M., Tyagi, A.K., Prasad, S.: Preserving privacy in future vehicles of tomorrow. JCR 7(19), 6675–6684 (2020)
Li, L., et al.: Static analysis of android apps: a systematic literature review. Inf. Softw. Technol. 88, 67–95 (2017)
LinkedIn: QARK (2018). https://github.com/linkedin/qark
Mandal, A.K., Panarotto, F., Cortesi, A., Ferrara, P., Spoto, F.: Static analysis of android auto infotainment and on-board diagnostics II apps. Softw. Pract. Experience 49(7), 1131–1161 (2019)
Nowdehi, N., Lautenbach, A., Olovsson, T.: In-vehicle can message authentication: an evaluation based on industrial criteria. In: IEEE VTC (2017)
Serag, K., et al.: \(\{\)ZBCAN\(\}\): A \(\{\)Zero-Byte\(\}\)\(\{\)CAN\(\}\) defense system. In: USENIX Security (2023)
Serag, K., Bhatia, R., Kumar, V., Celik, Z.B., Xu, D.: Exposing new vulnerabilities of error handling mechanism in \(\{\)CAN\(\}\). In: USENIX Security Symposium (2021)
Sharma, S., Kaushik, B.: A survey on internet of vehicles: applications, security issues & solutions. Veh. Commun. 20, 100182 (2019)
skylot: Jadx - Dex to Java decompiler (2020)
skylot: On-board diagnostic II (OBD II) systems fact sheet (2019). https://ww2.arb.ca.gov/resources/fact-sheets/board-diagnostic-ii-obd-ii-systems-fact-sheet
Tian, D.J., et al.: Attention spanned: comprehensive vulnerability analysis of \(\{\)AT\(\}\) commands within the android ecosystem. In: USENIX Security (2018)
Tian, Y., et al.: SmartAuth: user-centered authorization for the internet of things. In: USENIX Security Symposium, vol. 5, pp. 8–2 (2017)
Van Herrewege, A., Singelee, D., Verbauwhede, I.: CANAuth-a simple, backward compatible broadcast authentication protocol for can bus. In: ECRYPT workshop on Lightweight Cryptography, vol. 2011, p. 20. ECRYPT (2011)
Wen, H., Chen, Q.A., Lin, Z.: Plug-N-Pwned: Comprehensive vulnerability analysis of OBD-II dongles as a new over-the-air attack surface in automotive IoT. In: USENIX Security Symposium (2020)
Wen, H., Zhao, Q., Chen, Q.A., Lin, Z.: Automated cross-platform reverse engineering of can bus commands from mobile apps. In: NDSS (2020)
Yu, L., et al.: Towards automatically reverse engineering vehicle diagnostic protocols. In: USENIX Security Symposium (2022)
Zhang, Y., Ge, B., Li, X., Shi, B., Li, B.: Controlling a car through OBD injection. In: IEEE International Conference on Cyber Security and Cloud Computing (2016)
Zhang, Y., et al.: Detecting third-party libraries in android applications with high precision and recall. In: IEEE International Conference on Software Analysis, Evolution and Reengineering (2018)
Zhao, J., Chen, Y., Gong, Y.: Study of connectivity probability of vehicle-to-vehicle and vehicle-to-infrastructure communication systems. In: IEEE VTC (2016)
Zuo, C., Lin, Z., Zhang, Y.: Why does your data leak? Uncovering the data leakage in cloud from mobile apps. In: IEEE Symposium on Security & Privacy (2019)
Acknowledgement
This paper was supported in part by United States National Science Foundation (NSF) under grants IIS-2014552, DGE-1565570, DGE-1922649, CNS-2204785, and CNS-2205868, and the Ripple University Blockchain Research Initiative. The authors would like to thank the anonymous reviewers for their valuable comments and suggestions
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
A Summary of Vulnerabilities in Top Apps
A Summary of Vulnerabilities in Top Apps
In Table 5, we summarize the vulnerabilities in the top most downloaded apps.

Rights and permissions
Copyright information
© 2024 The Author(s), under exclusive license to Springer Nature Switzerland AG
About this paper
Cite this paper
Mallojula, P., Li, F., Du, X., Luo, B. (2024). Companion Apps or Backdoors? On the Security of Automotive Companion Apps. In: Garcia-Alfaro, J., Kozik, R., Choraś, M., Katsikas, S. (eds) Computer Security – ESORICS 2024. ESORICS 2024. Lecture Notes in Computer Science, vol 14984. Springer, Cham. https://doi.org/10.1007/978-3-031-70896-1_2
Download citation
DOI: https://doi.org/10.1007/978-3-031-70896-1_2
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-031-70895-4
Online ISBN: 978-3-031-70896-1
eBook Packages: Computer ScienceComputer Science (R0)Springer Nature Proceedings Computer Science
