Model Driven Security in a Mobile Banking Application Context

被引:1
|
作者
Senturk, Serafettin [1 ]
Yasar, Hasan [2 ]
Sogukpinar, Ibrahim [3 ]
机构
[1] Kuveyt Turk, R&D Ctr, Kocaeli, Turkey
[2] Carnegie Mellon Univ, Software Engn Inst, Pittsburgh, PA 15213 USA
[3] Gebze Tech Univ, Comp Engn, Kocaeli, Turkey
来源
14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019) | 2019年
关键词
security by design; authentication; authorization; secure UML; UMLSec; Graphwalker; METHODOLOGY;
D O I
10.1145/3339252.3340529
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As there are growing number of mobile devices worldwide, the applications running on the mobile hand-helds have great impact on the human life. One of the biggest factors for the usage of mobile applications is security and privacy since there are lots of personal and sensitive information for the individuals which are stored in these mobile devices. Because the mobile devices interact with many other devices and run on different kinds of communication protocols, the complexity and integration of mobile applications with the other digital entities increases much more ever than before. That is the reason the security and privacy issues for the mobile clients should be considered in very early steps of their application development phase which is exactly the analysis and design steps. In this study some of the security and privacy by design methodologies and toolsets have been explored. In the phase of UML modelling and workflow definition parts of the application development life cycle, some appropriate techniques have been used. From early stages of designing to test case generation and test execution steps have been covered, so that end to end secure mobile application development life cycle has been realized.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] The Challenges of Mobile Banking Application on Novice Users
    Hussain, Azham
    Thamer, Aysar
    Matcharan, Adilah
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON APPLIED SCIENCE AND TECHNOLOGY (ICAST'18), 2018, 2016
  • [42] Classify and Analyze the Security Issues and Challenges in Mobile banking in Uzbekistan
    Abdullaev, Azamjon
    Al-Absi, Mohammed Abdulhakim
    Al-Absi, Ahmed Abdulhakim
    Sain, Mangal
    Lee, Hoon Jae
    2020 22ND INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): DIGITAL SECURITY GLOBAL AGENDA FOR SAFE SOCIETY!, 2020, : 1211 - 1217
  • [43] Model-Based Testing for Network Security Protocol for E-Banking Application
    Alaba, Fadele Ayotunde
    Hakak, Saqib
    Khan, Fawad Ali
    Adewale, Sulaimon Hakeem
    Rahmawati, Sri
    Patma, Tundung Subali
    Ritonga, Rajab
    Herawan, Tutut
    INFORMATION SYSTEMS DESIGN AND INTELLIGENT APPLICATIONS, INDIA 2017, 2018, 672 : 740 - 751
  • [44] UPI Based Mobile Banking Applications - Security Analysis and Enhancements
    Lakshmi, K. Krithiga
    Gupta, Himanshu
    Ranjan, Jayanthi
    PROCEEDINGS 2019 AMITY INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE (AICAI), 2019, : 903 - 908
  • [45] A Novel Protocol For the Security of SMS-Based Mobile Banking
    Abolghasemi, Meer Soheil
    Rezapour, Taha Yasin
    Atani, Reza Ebrahimi
    2013 5TH CONFERENCE ON INFORMATION AND KNOWLEDGE TECHNOLOGY (IKT), 2013, : 97 - 101
  • [46] Mobile Banking Continuance Intention: The Moderating Role of Security and Customization
    Albashrawi, Mousa Ahmed
    JOURNAL OF INFORMATION TECHNOLOGY RESEARCH, 2021, 14 (01) : 55 - 69
  • [47] Context Aware Mobile Application for Mobile Devices
    Masango, Mfundo
    Mouton, Francois
    Nottingham, Alastair
    Mtsweni, Jabu
    2016 INFORMATION SECURITY FOR SOUTH AFRICA - PROCEEDINGS OF THE 2016 ISSA CONFERENCE, 2016, : 85 - 90
  • [48] Mobile password system for enhancing usability-guaranteed security in mobile phone banking
    Lee, SJ
    Park, SB
    WEB AND COMMUNICATION TECHNOLOGIES AND INTERNET -RELATED SOCIAL ISSUES - HSI 2005, 2005, 3597 : 66 - 74
  • [49] A Threat Model-Driven Security Testing Approach for Web Application
    Yan, Bobo
    Li, Xiaohong
    Du, Zhijie
    CONTEMPORARY RESEARCH ON E-BUSINESS TECHNOLOGY AND STRATEGY, 2012, 332 : 158 - 168
  • [50] Standards Driven Security Assurance for Mobile Networks
    Lachmund, Sven
    Journal of ICT Standardization, 2015, 3 (02): : 105 - 132