A Comprehensive Study of Vulnerability Assessment Techniques of Existing Banking Apps

Kiran Prakash Joshi · International Journal for Research in Applied Science and Engineering Technology · 2018

Online banking solutions have existed for two decades already, and the industry now has a relatively good understanding of security threats and risks against traditional online banking.When dealing with security aspects for mobile banking in the context of mobile devices and applications, a few common themes emerge.If these themes are not addressed properly, through security controls and measures, the underlying threats could compromise the confidentiality, integrity and availability of mobile security assets.Mobile security assets that need protection are mobile devices, the mobile application and private information.Eight threats were identified in this research.These threats can be categorized in the following manner: users, devices, applications and data, and governance.Based on this categorization and testing with professional tool in the field of banking and IT security, the Mobile Banking Security Model was created which can be used to define security controls and measures, perform risk assessments for mobile banking in the context of mobile devices and mobile applications.This paper focus on mobile banking app and its network traffic monitoring for security audit.The network traffic monitor best matching specified criteria is chosen.A network traffic analysis method is implemented for the chosen network traffic monitor.The analysis method is used to show the differing behaviour of two distinct network traffic monitoring approaches (deep packet inspection and flow monitoring).Properties of the chosen network traffic monitor, along with performance measurements, are discussed.

Read the paper · More papers on PaperTik