PolySec Lab

Security Analysis of Mobile Money Applications on Android

About

Mobile Money Applications are thriving mainly due to the ease and convenience it brings to people, where it offers transferring money between people’s bank accounts/cards with a few taps on a smartphone either in the form of Mobile Banking or Mobile Payment Services.

However, a key challenge with gaining user adoption of mobile banking and payments is the customer’s lack of confidence in security of the services, and that makes a lot of sense because whenever people grant a service access to their debit/credit cards or bank accounts that automatically opens the door for identity thefts, fraudulent transactions and stolen money. Adding to that, the fact that already people and developers are not giving much attention to the security aspect of the applications.

This project consists of two parts, an intensive security analysis on a selection of different mobile banking and mobile payment applications on the Android platform where 80% of the selected applications were found not following the best security measures, and also a thorough step-step Android security testing guide to ease the process of security testing any android application to be used by developers, ethical hackers, and anyone interested in testing the security of any application.

Dr. Mohammad Husain

Project Director
Professor at Cal Poly Pomona

Hesham Darwish

Project Lead
Former Masters Student at Cal Poly Pomona

Project Details

Security Testing Android Application

Project Resources

Step-by-Step Recommended Analysis Process

Publications/Media

Research Papers & Features