Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of View

Nowadays, the whole driver monitoring system can be placed inside the vehicle driver’s smartphone, which introduces new security and privacy risks to the system. Because of the nature of the modern transportation systems, the consequences of the security issues in such systems can be crucial, leadin...

Full description

Bibliographic Details
Main Authors: Dmitry Levshun, Andrey Chechulin, Igor Kotenko
Format: Article
Language:English
Published: MDPI AG 2022-07-01
Series:Sensors
Subjects:
Online Access:https://www.mdpi.com/1424-8220/22/13/5063
_version_ 1827619329130102784
author Dmitry Levshun
Andrey Chechulin
Igor Kotenko
author_facet Dmitry Levshun
Andrey Chechulin
Igor Kotenko
author_sort Dmitry Levshun
collection DOAJ
description Nowadays, the whole driver monitoring system can be placed inside the vehicle driver’s smartphone, which introduces new security and privacy risks to the system. Because of the nature of the modern transportation systems, the consequences of the security issues in such systems can be crucial, leading to threat to human life and health. Moreover, despite the large number of security and privacy issues discovered in smartphone applications on a daily basis, there is no general approach for their automated analysis that can work in conditions that lack data and take into account specifics of the application area. Thus, this paper describes an original approach for a security and privacy analysis of driver monitoring systems based on smartphone sensors. This analysis uses white-box testing principles and aims to help developers evaluate and improve their products. The novelty of the proposed approach lies in combining various security and privacy analysis algorithms into a single automated approach for a specific area of application. Moreover, the suggested approach is modular and extensible, takes into account specific features of smartphone-based driver monitoring systems and works in conditions of lack or inaccessibility of data. The practical significance of the approach lies in the suggestions that are provided based on the conducted analysis. Those suggestions contain detected security and privacy issues and ways of their mitigation, together with limitations of the analysis due to the absence of data. It is assumed that such an approach would help developers take into account important aspects of security and privacy, thus reducing related issues in the developed products. An experimental evaluation of the approach is conducted on a car driver monitoring use case. In addition, the advantages and disadvantages of the proposed approach as well as future work directions are indicated.
first_indexed 2024-03-09T10:25:42Z
format Article
id doaj.art-de41a0ab9dec405e94dd2d9196551e0c
institution Directory Open Access Journal
issn 1424-8220
language English
last_indexed 2024-03-09T10:25:42Z
publishDate 2022-07-01
publisher MDPI AG
record_format Article
series Sensors
spelling doaj.art-de41a0ab9dec405e94dd2d9196551e0c2023-12-01T21:42:24ZengMDPI AGSensors1424-82202022-07-012213506310.3390/s22135063Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of ViewDmitry Levshun0Andrey Chechulin1Igor Kotenko2St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 199178 St. Petersburg, RussiaSt. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 199178 St. Petersburg, RussiaSt. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 199178 St. Petersburg, RussiaNowadays, the whole driver monitoring system can be placed inside the vehicle driver’s smartphone, which introduces new security and privacy risks to the system. Because of the nature of the modern transportation systems, the consequences of the security issues in such systems can be crucial, leading to threat to human life and health. Moreover, despite the large number of security and privacy issues discovered in smartphone applications on a daily basis, there is no general approach for their automated analysis that can work in conditions that lack data and take into account specifics of the application area. Thus, this paper describes an original approach for a security and privacy analysis of driver monitoring systems based on smartphone sensors. This analysis uses white-box testing principles and aims to help developers evaluate and improve their products. The novelty of the proposed approach lies in combining various security and privacy analysis algorithms into a single automated approach for a specific area of application. Moreover, the suggested approach is modular and extensible, takes into account specific features of smartphone-based driver monitoring systems and works in conditions of lack or inaccessibility of data. The practical significance of the approach lies in the suggestions that are provided based on the conducted analysis. Those suggestions contain detected security and privacy issues and ways of their mitigation, together with limitations of the analysis due to the absence of data. It is assumed that such an approach would help developers take into account important aspects of security and privacy, thus reducing related issues in the developed products. An experimental evaluation of the approach is conducted on a car driver monitoring use case. In addition, the advantages and disadvantages of the proposed approach as well as future work directions are indicated.https://www.mdpi.com/1424-8220/22/13/5063information securityintelligent transportation systemssecurity analysisprivacy analysiswhite-box testingdriver monitoring systems
spellingShingle Dmitry Levshun
Andrey Chechulin
Igor Kotenko
Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of View
Sensors
information security
intelligent transportation systems
security analysis
privacy analysis
white-box testing
driver monitoring systems
title Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of View
title_full Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of View
title_fullStr Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of View
title_full_unstemmed Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of View
title_short Security and Privacy Analysis of Smartphone-Based Driver Monitoring Systems from the Developer’s Point of View
title_sort security and privacy analysis of smartphone based driver monitoring systems from the developer s point of view
topic information security
intelligent transportation systems
security analysis
privacy analysis
white-box testing
driver monitoring systems
url https://www.mdpi.com/1424-8220/22/13/5063
work_keys_str_mv AT dmitrylevshun securityandprivacyanalysisofsmartphonebaseddrivermonitoringsystemsfromthedeveloperspointofview
AT andreychechulin securityandprivacyanalysisofsmartphonebaseddrivermonitoringsystemsfromthedeveloperspointofview
AT igorkotenko securityandprivacyanalysisofsmartphonebaseddrivermonitoringsystemsfromthedeveloperspointofview