Are Mobile Banking Apps Secure? What Can Be Improved?

被引:43
|
作者
Chen, Sen [1 ]
Su, Ting [1 ,2 ]
Fan, Lingling [1 ]
Meng, Guozhu [2 ,3 ]
Xue, Minhui [4 ]
Liu, Yang [2 ]
Xu, Lihua [1 ,2 ,5 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
[2] Nanyang Technol Univ, Singapore, Singapore
[3] Chinese Acad Sci, Beijing, Peoples R China
[4] Optus Macquarie Univ Cyber Secur Hub, Melbourne, Vic, Australia
[5] New York Univ Shanghai, Shanghai, Peoples R China
关键词
Mobile Banking Apps; Vulnerability; Empirical Study;
D O I
10.1145/3236024.3275523
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile banking apps, as one of the most contemporary FinTechs, have been widely adopted by banking entities to provide instant financial services. However, our recent work discovered thousands of vulnerabilities in 693 banking apps, which indicates these apps are not as secure as we expected. This motivates us to conduct this study for understanding the current security status of them. First, we take 6 months to track the reporting and patching procedure of these vulnerabilities. Second, we audit 4 state-of-the-art vulnerability detection tools on those patched vulnerabilities. Third, we discuss with 7 banking entities via in-person or online meetings and conduct an online survey to gain more feedback from financial app developers. Through this study, we reveal that (1) people may have inconsistent understandings of the vulnerabilities and different criteria for rating severity; (2) state-of-the-art tools are not effective in detecting vulnerabilities that the banking entities most concern; and (3) more efforts should be endeavored in different aspects to secure banking apps. We believe our study can help bridge the existing gaps, and further motivate different parties, including banking entities, researchers and policy makers, to better tackle security issues altogether.
引用
收藏
页码:797 / 802
页数:6
相关论文
共 50 条
  • [1] I can't pay! Accessibility analysis of mobile banking apps
    Lopes, Renan
    Facanha, Agebson Rocha
    Viana, Windson
    [J]. PROCEEDINGS OF THE 28TH BRAZILIAN SYMPOSIUM ON MULTIMEDIA AND THE WEB, WEBMEDIA 2022, 2022, : 253 - 257
  • [2] Forensic Analysis of Mobile Banking Apps
    Osho, Oluwafemi
    Mohammed, Uthman L.
    Nimzing, Nanfa N.
    Uduimoh, Andrew A.
    Misra, Sanjay
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2019, PT V: 19TH INTERNATIONAL CONFERENCE, SAINT PETERSBURG, RUSSIA, JULY 14, 2019, PROCEEDINGS, PART V, 2019, 11623 : 613 - 626
  • [3] An analysis of native apps for mobile banking
    Fenu, Gianni
    Pau, Pier Luigi
    [J]. 2015 12TH ANNUAL IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, 2015, : 168 - 169
  • [4] Can mobile banking apps usage contribute towards the environmental sustainability: a mediation analysis
    Katini, K.
    Amalanathan, S.
    [J]. INTERNATIONAL JOURNAL OF ENVIRONMENT AND POLLUTION, 2022, 71 (1-2) : 1 - 24
  • [5] Drivers of continuance intention with mobile banking apps
    Poromatikul, Chayawan
    De Maeyer, Peter
    Leelapanyalert, Kannika
    Zaby, Simon
    [J]. INTERNATIONAL JOURNAL OF BANK MARKETING, 2020, 38 (01) : 242 - 262
  • [6] Mobile nudging: Youth engagement with banking apps
    Wijland R.
    Hansen P.
    Gardezi F.
    [J]. Journal of Financial Services Marketing, 2016, 21 (1) : 51 - 63
  • [7] An Analysis of Features and Tendencies in Mobile Banking Apps
    Fenu, Gianni
    Pau, Pier Luigi
    [J]. 10TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC 2015) / THE 12TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2015) AFFILIATED WORKSHOPS, 2015, 56 : 26 - 33
  • [8] An Empirical Segmentation of Users of Mobile Banking Apps
    Alavi, Shirin
    Ahuja, Vandana
    [J]. JOURNAL OF INTERNET COMMERCE, 2016, 15 (04) : 390 - 407
  • [9] Variability Handling for Mobile Banking Apps on iOS and Android
    Jorgensen, Jens Baek
    Knudsen, Name
    Sloth, Lennert
    Vase, Johan Rugager
    Christensen, Henrik Baerbak
    [J]. 2016 13TH WORKING IEEE/IFIP CONFERENCE ON SOFTWARE ARCHITECTURE (WICSA), 2016, : 283 - 286
  • [10] Mobile Banking Apps as an Indicator of the Industry's Strategy
    Ali, Radwan
    Gallivan, Mike
    [J]. AMCIS 2017 PROCEEDINGS, 2017,