Towards Secure Open Banking Architecture: An Evaluation with OWASP

被引:4
|
作者
Kellezi, Deina [1 ]
Boegelund, Christian [1 ]
Meng, Weizhi [1 ,2 ]
机构
[1] Tech Univ Denmark, Dept Appl Math & Comp Sci, Lyngby, Denmark
[2] Guangzhou Univ, Dept Comp Sci, Guangzhou, Peoples R China
来源
基金
中国国家自然科学基金;
关键词
Web security; Open Banking API; OWASP; Threat and risk; PSD2; regulation; Secure architecture;
D O I
10.1007/978-3-030-36938-5_11
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The European Union passed the PSD2 regulation in 2015, which gives ownership of bank accounts to the private person owning it. As a result, the term Open Banking, allowing third party providers and developers access to bank APIs, has emerged, welcoming a myriad of innovative solutions for the financial sector. However, multiple cyber security issues arise from exposing bank data to third party providers through an API. In this work, we propose an architectural model that ensures clear separation of concern and easy integration with Nordea's Open Banking APIs (sandbox version), and a technological stack, consisting of the micro-framework Flask, the cloud application platform Heroku and persistent data storage layer (using Postgres). We analyze the web application's security threats, and determine whether or not the technological frame provides adequate security protection, by leveraging the OWASP Top 10 list of the Ten Most Critical Web Application Security Risks. Our results can support future developers and industries working on web applications for Open Banking towards security improvement by choosing the right frameworks and considering the most important vulnerabilities, as well as contributing to the documentation and development of Nordea's APIs.
引用
收藏
页码:185 / 198
页数:14
相关论文
共 50 条
  • [21] Teaching Secure Programming to Information Systems Students via OWASP Techniques and Libraries
    Cole, Carey
    Mitri, Michel
    AMCIS 2012 PROCEEDINGS, 2012,
  • [22] An Open Architecture Approach: Towards Common Design Principles for an IoT Architecture
    Vogel, Bahtijar
    Gkouskos, Dimitrios
    11TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE (ECSA 2017) - COMPANION VOLUME, 2017, : 90 - 93
  • [23] TOWARDS GOOD ARCHITECTURE AND THE OPEN CITY: THE 2021 PUBLIC ARCHITECTURE CONFERENCE
    Jaehee, Kim
    SPACE, 2021, (649): : 14 - 14
  • [24] Towards Secure FinTech: A Survey, Taxonomy, and Open Research Challenges
    Mehrban, Sobia
    Nadeem, Muhammad Waqas
    Hussain, Muzammil
    Ahmed, Mohammad Masroor
    Hakeem, Owais
    Saqib, Shazia
    Kiah, M. L. Mat
    Abbas, Fakhar
    Hassan, Mujtaba
    Khan, Muhammad Adnan
    IEEE ACCESS, 2020, 8 : 23391 - 23406
  • [25] Towards Designing Open and Secure IoT Systems: Insights for Practitioners
    Vogel, Bahtijar
    Varshney, Rimpu
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS (IOT'18), 2018,
  • [26] An evaluation space for open architecture controllers
    Chi Yonglin
    The International Journal of Advanced Manufacturing Technology, 2005, 26 : 351 - 358
  • [27] An evaluation space for open architecture controllers
    Chi, YL
    INTERNATIONAL JOURNAL OF ADVANCED MANUFACTURING TECHNOLOGY, 2005, 26 (04): : 351 - 358
  • [28] Evaluation of the generic open architecture framework
    Parrish, Donald L.
    James, Jim A.
    AIAA/IEEE Digital Avionics Systems Conference - Proceedings, 2 : 1 - 1
  • [29] Evaluating Mobile Banking Application Security Posture Using the OWASP's MASVS Framework
    Chiboora, Trevor Henry
    Chacha, Lenah
    Byagutangaza, Theoneste
    Gueye, Assane
    PROCEEDINGS OF THE ACM SIGCAS/SIGCHI CONFERENCE ON COMPUTING AND SUSTAINABLE SOCIETIES 2023,COMPASS 2023, 2023, : 99 - 106
  • [30] Secure Function Evaluation Using an FPGA Overlay Architecture
    Fang, Xin
    Ioannidis, Stratis
    Leeser, Miriam
    FPGA'17: PROCEEDINGS OF THE 2017 ACM/SIGDA INTERNATIONAL SYMPOSIUM ON FIELD-PROGRAMMABLE GATE ARRAYS, 2017, : 257 - 266