<p>The FinTech sector in India is seeing a surge, especially post the pandemic. Usage of apps for finance and banking purposes is becoming more prevalent due to the convenience factors. This paper mainly focuses on the vulnerabilities that are present in the Android apps that deal with banking and financial services in the Indian market. As the financial apps contain a lot of security-sensitive information, any attack or leakage of information will result in a great loss to the end user. Our dataset contains banking, payment, and crypto applications. To analyse the applications, Static Analysis, Dynamic Analysis and Permissions Analysis were done. Machine Learning algorithms were applied on the output to analyse the results. We discovered 16 vulnerabilities in the applications using static analysis. Certain vulnerabilities exist due to non-compliance with coding standards. Few vulnerabilities were discovered during Dynamic Analysis as well. The permissions utilised by the applications were examined, with a focus on Dangerous Permissions. Random Forest algorithm was able to classify the apps as High, Medium and Low risk based on the permissions accessed with an accuracy of 98.74%. Our findings show that, despite Fintech being a crucial sector, the necessary measures in application security are not taken and renewed attention has to be paid to secure the apps.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Vulnerability analysis of android based FinTech apps in India

  • Akshara Alex,
  • K V Pradeepthi

摘要

The FinTech sector in India is seeing a surge, especially post the pandemic. Usage of apps for finance and banking purposes is becoming more prevalent due to the convenience factors. This paper mainly focuses on the vulnerabilities that are present in the Android apps that deal with banking and financial services in the Indian market. As the financial apps contain a lot of security-sensitive information, any attack or leakage of information will result in a great loss to the end user. Our dataset contains banking, payment, and crypto applications. To analyse the applications, Static Analysis, Dynamic Analysis and Permissions Analysis were done. Machine Learning algorithms were applied on the output to analyse the results. We discovered 16 vulnerabilities in the applications using static analysis. Certain vulnerabilities exist due to non-compliance with coding standards. Few vulnerabilities were discovered during Dynamic Analysis as well. The permissions utilised by the applications were examined, with a focus on Dangerous Permissions. Random Forest algorithm was able to classify the apps as High, Medium and Low risk based on the permissions accessed with an accuracy of 98.74%. Our findings show that, despite Fintech being a crucial sector, the necessary measures in application security are not taken and renewed attention has to be paid to secure the apps.