A Study Using OWASP On Secure Open Banking Architecture

Ashwini Kumar, Ankita Gandhi · 2023

Consumers have had greater control over their personal financial data since the Data Protection Rule of the European Union was put into effect in 2015. This occurred in 2015. As a direct result of this, "Open Banking" has developed, which provides 3rdparty organizations and software designers with Usage of a banking applications programming interfaces (APIs). This has resulted in an abundance of new approaches to the economic industry. However, a range of cybersecurity vulnerabilities exist when a bank makes its data available to 3rdparty vendors via an application programming interface (API). This paper presents a technology stack that consists of the segments and sub-Flask, the cloud-based system Heroku, and the continuous digital storage layer. These components work together to ensure that there is a proper division of responsibilities and that the procedure of integrating using Nordea's New Financial services APIs (sandbox edition) is as smooth as possible. We investigate the website service vulnerabilities by using the OWASP Top 10, which is a a ranking of the 10 biggest severe cyber risks. Based on our findings, we determine whether the technological framework provides sufficient strong security. Our findings not only helped in the description and creation of Nordea's APIs, but they may also help future developers and businesses that are working on web applications for modern banking improve their level of protection by enabling them to select the appropriate frameworks and considering the most significant threats. This would allow them to improve the level of protection offered by their applications.

Read the paper · More papers on PaperTik