Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/3588001.3609367acmconferencesArticle/Chapter ViewAbstractPublication PagescompassConference Proceedingsconference-collections
research-article
Open access

Evaluating Mobile Banking Application Security Posture Using the OWASP’s MASVS Framework

Published: 16 August 2023 Publication History

Abstract

In the context of financial gain, hackers are motivated to exploit vulnerabilities that could result in financial or data loss. Therefore, it is crucial for financial applications to undergo thorough testing to identify and address such vulnerabilities. Regrettably, many financial institutions neglect proper testing procedures and sometimes even fail to establish a suitable security release baseline. This report presents an analysis of 18 mobile applications, each belonging to a different financial institution in Africa. The selection of these applications was carefully executed, considering institutions of varying sizes, to enable a comparative assessment of security practices across different organizational scales. The assessment was conducted by evaluating the sampled applications against the Mobile Application Security Verification Standard v2.0. This is a set of checklists and guidelines by the Open Web Application Security Project (OWASP) used as a baseline for mobile application security. Due to the extensive nature of the project, the testing scope was limited to the application itself, as experienced by the end user. This included examining the application’s interaction with the back-end server and observing its behavior on the user’s mobile device. It is important to note that this report does not provide a comprehensive analysis, as it excludes the assessment of the server-side API and testing of business logic that requires elevated privileges within the application. Furthermore, a survey was conducted to gain insights into why developers may neglect baseline security thereby introducing potential vulnerabilities in mobile applications. The findings of this survey are also included in a short summary at the end of this document.

References

[1]
[1] https://www.worldbank.org/en/topic/financialinclusion/overview
[2]
[2] Mobile Privacy: What Do Your Apps Know About You?", Symantec-enterprise-blogs.security.com https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mobile-privacy-apps
[3]
[3] Application sandbox Android Open Source Project. https://source.android.com/docs/security/app-sandbox
[4]
[4] OWASP MASVS (Mobile Application Security Verification Standard) https://mas.owasp.org/MASVS/
[5]
[5] Android API Levels https://apilevels.com/
[6]
[6] Android ABIs https://developer.android.com/ndk/guides/abis
[7]
[7] android:debuggable https://developer.android.com/topic/security/risks/android-debuggable
[8]
[8] Binary Protection Mechanisms https://mas.owasp.org/MASTG/General/0x04h-Testing-Code-Quality/#dynamic-analysis-security-testing-considerations_1
[9]
[9] Financial Inclusion https://www.worldbank.org/en/topic/financialinclusion/overview#2
[10]
[10] Fintech in Africa: The end of the beginning August 2022 McKinsey & Company

Cited By

View all

Index Terms

  1. Evaluating Mobile Banking Application Security Posture Using the OWASP’s MASVS Framework

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Conferences
    COMPASS '23: Proceedings of the 6th ACM SIGCAS/SIGCHI Conference on Computing and Sustainable Societies
    August 2023
    170 pages
    ISBN:9798400701498
    DOI:10.1145/3588001
    This work is licensed under a Creative Commons Attribution International 4.0 License.

    Sponsors

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 16 August 2023

    Check for updates

    Author Tags

    1. Android Applications
    2. Financial Inclusion
    3. OWASP MASVS v2.0
    4. VAPT

    Qualifiers

    • Research-article
    • Research
    • Refereed limited

    Conference

    COMPASS '23
    Sponsor:

    Acceptance Rates

    Overall Acceptance Rate 25 of 50 submissions, 50%

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • 0
      Total Citations
    • 555
      Total Downloads
    • Downloads (Last 12 months)555
    • Downloads (Last 6 weeks)115
    Reflects downloads up to 30 Aug 2024

    Other Metrics

    Citations

    Cited By

    View all

    View Options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    HTML Format

    View this article in HTML Format.

    HTML Format

    Get Access

    Login options

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media