Comparative Vulnerability Analysis of Thai and Non-Thai Mobile Banking Applications

Author:

Titiakarawongse Chatphat1,Taksin Sasiyaporn1,Ruangsawat Jidapa1,Deeduangpan Kunthida1,Boonkrong Sirapat1

Affiliation:

1. Institute of Digital Arts and Science, Suranaree University of Technology, Nakhon Ratchasima 30000, Thailand

Abstract

The rapid adoption of mobile banking applications has raised significant concerns about their security vulnerabilities. This study presents a comparative vulnerability analysis of mobile banking applications from Thai and non-Thai banks, utilising the OWASP Mobile Top 10 framework. Nine mobile banking applications (five Thai and four non-Thai) were assessed using three vulnerability detection tools: AndroBugs, MobSF, and QARK. The results showed that both Thai and non-Thai mobile banking applications had vulnerabilities across multiple OWASP Mobile Top 10 categories, with reverse engineering, code tampering, and insufficient cryptography being the most common. Statistical analysis revealed that Thai banking applications exhibited significantly more vulnerabilities compared to non-Thai banking applications. In the context of vulnerability detection tools, AndroBugs and QARK proved more effective in detecting vulnerabilities compared to MobSF. Additionally, the study highlights critical security challenges in mobile banking applications, particularly for Thai banks, and emphasises the need for enhanced security measures. The findings also show the importance of using multiple assessment tools for comprehensive security evaluation and suggest potential areas for improvement in mobile banking applications.

Publisher

MDPI AG

Reference17 articles.

1. (2024, July 20). Bank of Thailand Use of Mobile Banking and Internet Banking. Available online: https://app.bot.or.th/BTWS_STAT/statistics/BOTWEBSTAT.aspx?reportID=949&language=ENG.

2. (2024, July 20). StatCounter Global Stats Mobile Operating System Market Share Thailand. Available online: https://gs.statcounter.com/os-market-share/mobile/thailand.

3. Traore, I., Woungang, I., Ahmed, S.S., and Malik, Y. (2018, January 28–30). Analysing Data Security Requirements of Android Mobile Banking Application. Proceedings of the Intelligent, Secure, and Dependable Systems in Distributed and Cloud Environments, Vancouver, BC, Canada.

4. Chen, S., Fan, L., Meng, G., Su, T., Xue, M., Xue, Y., Liu, Y., and Xu, L. (July, January 27). An Empirical Assessment of Security Risks of Global Android Banking Apps. Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering, Seoul, Republic of Korea.

5. Security Model on Mobile Banking Application: Attack Simulation and Countermeasures;Kouraogo;Int. J. Intell. Enterp.,2017

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3