Are Mobile Banking Apps Secure? What Can Be Improved?

被引:43
|
作者
Chen, Sen [1 ]
Su, Ting [1 ,2 ]
Fan, Lingling [1 ]
Meng, Guozhu [2 ,3 ]
Xue, Minhui [4 ]
Liu, Yang [2 ]
Xu, Lihua [1 ,2 ,5 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
[2] Nanyang Technol Univ, Singapore, Singapore
[3] Chinese Acad Sci, Beijing, Peoples R China
[4] Optus Macquarie Univ Cyber Secur Hub, Melbourne, Vic, Australia
[5] New York Univ Shanghai, Shanghai, Peoples R China
关键词
Mobile Banking Apps; Vulnerability; Empirical Study;
D O I
10.1145/3236024.3275523
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile banking apps, as one of the most contemporary FinTechs, have been widely adopted by banking entities to provide instant financial services. However, our recent work discovered thousands of vulnerabilities in 693 banking apps, which indicates these apps are not as secure as we expected. This motivates us to conduct this study for understanding the current security status of them. First, we take 6 months to track the reporting and patching procedure of these vulnerabilities. Second, we audit 4 state-of-the-art vulnerability detection tools on those patched vulnerabilities. Third, we discuss with 7 banking entities via in-person or online meetings and conduct an online survey to gain more feedback from financial app developers. Through this study, we reveal that (1) people may have inconsistent understandings of the vulnerabilities and different criteria for rating severity; (2) state-of-the-art tools are not effective in detecting vulnerabilities that the banking entities most concern; and (3) more efforts should be endeavored in different aspects to secure banking apps. We believe our study can help bridge the existing gaps, and further motivate different parties, including banking entities, researchers and policy makers, to better tackle security issues altogether.
引用
收藏
页码:797 / 802
页数:6
相关论文
共 50 条
  • [31] An Empirical Study on Developing Secure Mobile Health Apps: The Developers' Perspective
    Aljedaani, Bakheet
    Ahmad, Aakash
    Zahedi, Mansooreh
    Babar, M. Ali
    [J]. 2020 27TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2020), 2020, : 208 - 217
  • [32] What Drives Users' Removal Behavior of Mobile Apps
    Tai, Wei-Chun
    Duong, Nam Tien
    Wei, Chung-Lun
    Wang, Yu-Min
    Yang, Jih-Hua
    Chen, Ko-Ling
    Wang, Yi-Shun
    [J]. JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2024,
  • [33] What keeps mobile banking customers loyal?
    Thakur, Rakhi
    [J]. INTERNATIONAL JOURNAL OF BANK MARKETING, 2014, 32 (07) : 628 - 646
  • [34] Apps are now everywhere: A look at how mobile apps can improve mine safety
    Benedict, Michael
    [J]. Canadian Mining Journal, 2015, 136 (07) : 32 - 35
  • [35] The Impact of Age and Income in Using Mobile Banking Apps: A Study of Association and Classification
    Olaleye, Sunday Adewale
    Balogun, Oluwafemi Samson
    Sanusi, Ismaila Temitayo
    Dada, Oluwaseun Alexander
    [J]. INTERNATIONAL JOURNAL OF E-BUSINESS RESEARCH, 2022, 18 (01)
  • [36] WHAT APPS CAN DO TO SUPPORT CARBS COUNTING?
    Gillon-Keren, M.
    [J]. DIABETES TECHNOLOGY & THERAPEUTICS, 2016, 18 : A8 - A9
  • [37] An empirical study on secure usage of mobile health apps: The attack simulation approach
    Aljedaani, Bakheet
    Ahmad, Aakash
    Zahedi, Mansooreh
    Babar, Muhammad Ali
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2023, 163
  • [38] When Are Apps Worth Paying For? How Marketers Can Analyze The Market Performance of Mobile Apps
    Stocchi, Lara
    Guerini, Carolina
    Michaelidou, Nina
    [J]. JOURNAL OF ADVERTISING RESEARCH, 2017, 57 (03) : 260 - 271
  • [39] A Secure Mobile-Based Authentication System for e-Banking
    Rifa-Pous, Helena
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2009, PT 2, 2009, 5871 : 848 - 860
  • [40] A Multi-Channel Steganographic Protocol for Secure SMS Mobile Banking
    Obinna, Omego
    Pfluegel, Eckhard
    Clarke, Charles A.
    Tunnicliffe, Martin J.
    [J]. 2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 248 - 253