论文标题

卡塔尔移动银行申请的安全分析

Security Analysis of Mobile Banking Application in Qatar

论文作者

Al-Delayel, Shaymaa Abdulla

论文摘要

本文讨论了卡塔尔的Android M银行应用程序的安全姿势。由于技术多年来发展并提供了更多的安全方法,因此银行业务现在非常依赖于移动应用程序,以迅速向客户提供服务,从而实现了无缝和远程交易。但是,此类移动银行应用程序可以访问每个银行客户的敏感数据,这为客户和银行提供了潜在的攻击向量。因此,银行有责任通过为其移动应用程序提供高安全层来保护客户的信息。这项研究讨论了Android OS的M银行应用程序,其安全性,脆弱性,威胁和解决方案。使用两个移动测试框架的组合,分析了两个M银行应用程序,并针对标准化最佳实践进行了基准测试。实验评估期间观察到的安全弱点表明,需要对卡塔尔州的移动银行应用程序进行更强大的安全评估。这种方法将进一步确保最终用户的信心。因此,了解安全姿势将为Mbank的安全性和用户意识提供真正的措施。

This paper discusses the security posture of Android m-banking applications in Qatar. Since technology has developed over the years and more security methods are provided, banking is now heavily reliant on mobile applications for prompt service delivery to clients, thus enabling a seamless and remote transaction. However, such mobile banking applications have access to sensitive data for each bank customer which presents a potential attack vector for clients, and the banks. The banks, therefore, have the responsibility to protect the information of the client by providing a high-security layer to their mobile application. This research discusses m-banking applications for Android OS, its security, vulnerability, threats, and solutions. Two m-banking applications were analyzed and benchmarked against standardized best practices, using the combination of two mobile testing frameworks. The security weaknesses observed during the experimental evaluation suggest the need for a more robust security evaluation of a mobile banking application in the state of Qatar. Such an approach would further ensure the confidence of the end-users. Consequently, understanding the security posture would provide a veritable measure towards mbanking security and user awareness.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源