Computer Science - Cryptography and Security; mobile banking app; android application; vulnerability; code smell; Africa; WAEMU
Abstract :
[en] The West African Economic and Monetary Union (WAEMU) states, characterized by
widespread smartphone usage, have witnessed banks and financial institutions
introducing mobile banking applications (MBAs). These apps empower users to
perform transactions such as money transfers, bill payments, and account
inquiries anytime, anywhere. However, this proliferation of MBAs also raises
significant security concerns. Poorly implemented security measures during app
development can expose users and financial institutions to substantial
financial risks through increased vulnerability to cyberattacks. Our study
evaluated fifty-nine WAEMU MBAs using static analysis techniques. These MBAs
were collected from the 160 banks and financial institutions of the eight WAEMU
countries listed on the Central Bank of West African States (BCEAO) website. We
identified security-related code issues that could be exploited by malicious
actors. We investigated the issues found in the older versions to track their
evolution across updates. Additionally, we identified some banks from regions
such as Europe, the United States, and other developing countries and analyzed
their mobile apps for a security comparison with WAEMU MBAs. Key findings
include: (1) WAEMU apps exhibit security issues introduced during development,
posing significant risks of exploitation; (2) Despite frequent updates,
underlying security issues often persist; (3) Compared to MBAs from developed
and developing countries, WAEMU apps exhibit fewer critical security issues;
and (4) Apps from banks that are branches of other non-WAEMU banks often
inherit security concerns from their parent apps while also introducing
additional issues unique to their context. Our research underscores the need
for robust security practices in WAEMU MBAs development to enhance user safety
and trust in financial services.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > TruX - Trustworthy Software Engineering
Disciplines :
Computer science
Author, co-author :
DIALLO, Alioune ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
WAR, Aicha ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
DIOUF, Moustapha Awwalou; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
SAMHI, Jordan ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
ARZT, Steven; Fraunhofer SIT > Secure Software Engineering
BISSYANDE, Tegawendé F.; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KLEIN, Jacques ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
External co-authors :
yes
Language :
English
Title :
Security Assessment of Mobile Banking Apps in West African Economic and Monetary Union
Publication date :
2024
Number of pages :
14
Event name :
1st Cybersecurity4D conference
Event organizer :
PAICTA
Event place :
Eastern Cape, South Africa
Event date :
from 21 to 23 August 2024
Audience :
International
Peer reviewed :
Editorial reviewed
Focus Area :
Security, Reliability and Trust
Name of the research project :
R-AGR-3790 - LuxWays - part UL - BISSYANDE Tegawendé