Towards Secure Open Banking Architecture: An Evaluation with OWASP

被引:4
|
作者
Kellezi, Deina [1 ]
Boegelund, Christian [1 ]
Meng, Weizhi [1 ,2 ]
机构
[1] Tech Univ Denmark, Dept Appl Math & Comp Sci, Lyngby, Denmark
[2] Guangzhou Univ, Dept Comp Sci, Guangzhou, Peoples R China
来源
基金
中国国家自然科学基金;
关键词
Web security; Open Banking API; OWASP; Threat and risk; PSD2; regulation; Secure architecture;
D O I
10.1007/978-3-030-36938-5_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The European Union passed the PSD2 regulation in 2015, which gives ownership of bank accounts to the private person owning it. As a result, the term Open Banking, allowing third party providers and developers access to bank APIs, has emerged, welcoming a myriad of innovative solutions for the financial sector. However, multiple cyber security issues arise from exposing bank data to third party providers through an API. In this work, we propose an architectural model that ensures clear separation of concern and easy integration with Nordea's Open Banking APIs (sandbox version), and a technological stack, consisting of the micro-framework Flask, the cloud application platform Heroku and persistent data storage layer (using Postgres). We analyze the web application's security threats, and determine whether or not the technological frame provides adequate security protection, by leveraging the OWASP Top 10 list of the Ten Most Critical Web Application Security Risks. Our results can support future developers and industries working on web applications for Open Banking towards security improvement by choosing the right frameworks and considering the most important vulnerabilities, as well as contributing to the documentation and development of Nordea's APIs.
引用
收藏
页码:185 / 198
页数:14
相关论文
共 50 条
  • [1] Securing Open Banking with Model-View-Controller Architecture and OWASP
    Kellezi, Deina
    Boegelund, Christian
    Meng, Weizhi
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [2] Towards A Secure SDN Architecture
    Raghunath, Karthik
    Krishnan, Prabhakar
    2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [3] Deploying Secure Web Applications with OWASP Resources
    Cerullo, Fabio E.
    WEB APPLICATION SECURITY, 2010, 72 : 21 - 21
  • [4] An open architecture for secure interworking services
    Hayton, R
    Moody, K
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, 1997, : 315 - 321
  • [5] Towards a New Architecture for European Banking Supervision
    Lamandini, Marco
    EUROPEAN COMPANY LAW, 2009, 6 (01): : 6 - 13
  • [6] TOWARDS AN OPEN ARCHITECTURE FOR LDL
    CHIMENTI, D
    GAMBOA, R
    KRISHNAMURTHY, R
    VERY LARGE DATA BASES - PROCEEDINGS, 1989, : 195 - 203
  • [7] Towards an Open Networking Architecture
    Barguil, Samier
    Lopez, Victor
    Fernandez-Palacios Gimenez, Juan Pedro
    2020 INTERNATIONAL CONFERENCE ON OPTICAL NETWORK DESIGN AND MODELING (ONDM), 2020,
  • [8] Towards Secure Architecture-based Adaptations
    Khakpour, Narges
    Skandylas, Charilaos
    Nariman, Goran Saman
    Weyns, Danny
    2019 IEEE/ACM 14TH INTERNATIONAL SYMPOSIUM ON SOFTWARE ENGINEERING FOR ADAPTIVE AND SELF-MANAGING SYSTEMS (SEAMS 2019), 2019, : 114 - 125
  • [9] OWASP Anleitungen und Tools für Secure SDLC
    Emin İslam Tatlı
    Datenschutz und Datensicherheit - DuD, 2012, 36 (11) : 805 - 809
  • [10] TOWARDS AN OPEN SOFTWARE CONVERSION ARCHITECTURE
    BAILES, PA
    ATKINSON, S
    CHAPMAN, M
    JOHNSTON, D
    PEAKE, I
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 1995, 5 (03) : 423 - 444