Are Mobile Banking Apps Secure? What Can Be Improved?

被引:43
|
作者
Chen, Sen [1 ]
Su, Ting [1 ,2 ]
Fan, Lingling [1 ]
Meng, Guozhu [2 ,3 ]
Xue, Minhui [4 ]
Liu, Yang [2 ]
Xu, Lihua [1 ,2 ,5 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
[2] Nanyang Technol Univ, Singapore, Singapore
[3] Chinese Acad Sci, Beijing, Peoples R China
[4] Optus Macquarie Univ Cyber Secur Hub, Melbourne, Vic, Australia
[5] New York Univ Shanghai, Shanghai, Peoples R China
关键词
Mobile Banking Apps; Vulnerability; Empirical Study;
D O I
10.1145/3236024.3275523
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile banking apps, as one of the most contemporary FinTechs, have been widely adopted by banking entities to provide instant financial services. However, our recent work discovered thousands of vulnerabilities in 693 banking apps, which indicates these apps are not as secure as we expected. This motivates us to conduct this study for understanding the current security status of them. First, we take 6 months to track the reporting and patching procedure of these vulnerabilities. Second, we audit 4 state-of-the-art vulnerability detection tools on those patched vulnerabilities. Third, we discuss with 7 banking entities via in-person or online meetings and conduct an online survey to gain more feedback from financial app developers. Through this study, we reveal that (1) people may have inconsistent understandings of the vulnerabilities and different criteria for rating severity; (2) state-of-the-art tools are not effective in detecting vulnerabilities that the banking entities most concern; and (3) more efforts should be endeavored in different aspects to secure banking apps. We believe our study can help bridge the existing gaps, and further motivate different parties, including banking entities, researchers and policy makers, to better tackle security issues altogether.
引用
收藏
页码:797 / 802
页数:6
相关论文
共 50 条
  • [21] Assisting the Development of Secure Mobile Apps with Natural Language Processing
    Liu, Xueqing
    [J]. 2018 IEEE SYMPOSIUM ON VISUAL LANGUAGES AND HUMAN-CENTRIC COMPUTING (VL/HCC), 2018, : 279 - 280
  • [22] Exploring usage of mobile banking apps in the UAE: a categorical regression analysis
    Sudipa Majumdar
    Vijay Pujari
    [J]. Journal of Financial Services Marketing, 2022, 27 : 177 - 189
  • [23] Exploring usage of mobile banking apps in the UAE: a categorical regression analysis
    Majumdar, Sudipa
    Pujari, Vijay
    [J]. JOURNAL OF FINANCIAL SERVICES MARKETING, 2022, 27 (03) : 177 - 189
  • [24] Mobile banking apps in Poland and their accessibility for consumers with disabilities: a case study
    Borowska-Beszta, Anna
    Smieszek, Mateusz
    Borowska-Beszta, Beata
    [J]. DISABILITY & SOCIETY, 2023,
  • [25] Apps for mobile banking and customer satisfaction: a cross-cultural study
    Sampaio, Claudio Hoffmann
    Ladeira, Wagner Junior
    Santini, Fernando De Oliveira
    [J]. INTERNATIONAL JOURNAL OF BANK MARKETING, 2017, 35 (07) : 1131 - 1151
  • [26] HTPD: Secure and Flexible Message-Based Communication for Mobile Apps
    Liu, Yin
    Cruz, Breno Dantas
    Tilevich, Eli
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2021, PT II, 2021, 399 : 273 - 294
  • [27] Expediting the design and development of secure cloud-based mobile apps
    Chimuco, Francisco T.
    Sequeiros, Joao B. F.
    Simoes, Tiago M. C.
    Freire, Mario M.
    Inacio, Pedro R. M.
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (04) : 3043 - 3064
  • [28] Framework of Lightweight Secure Media Transfer for Mobile Law Enforcement Apps
    Deb, Suash
    Fong, Simon
    Thampi, Sabu M.
    [J]. SECURITY IN COMPUTING AND COMMUNICATIONS, 2014, 467 : 211 - 220
  • [29] Can mobile health apps replace GPs? A scoping review of comparisons between mobile apps and GP tasks
    Apichai Wattanapisit
    Chin Hai Teo
    Sanhapan Wattanapisit
    Emylia Teoh
    Wing Jun Woo
    Chirk Jenn Ng
    [J]. BMC Medical Informatics and Decision Making, 20
  • [30] Can mobile health apps replace GPs? A scoping review of comparisons between mobile apps and GP tasks
    Wattanapisit, Apichai
    Teo, Chin Hai
    Wattanapisit, Sanhapan
    Teoh, Emylia
    Woo, Wing Jun
    Ng, Chirk Jenn
    [J]. BMC MEDICAL INFORMATICS AND DECISION MAKING, 2020, 20 (01)