Show simple item record

dc.contributor.advisorGopinath, K
dc.contributor.advisorGanapathy, Vinod
dc.contributor.authorAgrawal, Nikhil
dc.date.accessioned2022-09-20T10:28:19Z
dc.date.available2022-09-20T10:28:19Z
dc.date.submitted2022
dc.identifier.urihttps://etd.iisc.ac.in/handle/2005/5860
dc.description.abstractThis thesis concerns the robustness of security checks in financial mobile applications (or simply financial apps). The best practices recommended by OWASP for developing such apps demand that developers include several checks in these apps, such as detection of running on a rooted device, certificate checks, and so on. Ideally, these checks must be introduced in a sophisticated way, and must not be locatable through trivial static analysis, so that attackers cannot bypass them trivially. In this thesis, we conduct a large-scale study focused on financial apps on the Android platform and determine the robustness of these checks. Our study shows that among the apps with at least one security check, > 50% of such apps at least one check can be trivially bypassed. Some of such financial apps we considered have installation counts exceeding 100 million from Google Play. We believe that the results of our study can guide developers of these apps in inserting security checks in a more robust fashion.en_US
dc.description.sponsorshipDepartment of Science and Technology, Govt. of India.en_US
dc.language.isoen_USen_US
dc.rightsI grant Indian Institute of Science the right to archive and to make available my thesis or dissertation in whole or in part in all forms of media, now hereafter known. I retain all proprietary rights, such as patent rights. I also retain the right to use in future works (such as articles or books) all or part of this thesis or dissertationen_US
dc.subjectFinancial Appsen_US
dc.subjectAndroiden_US
dc.subjectReverse Engineeringen_US
dc.subjectOWASPen_US
dc.subjectLarge-scale studyen_US
dc.subject.classificationResearch Subject Categories::TECHNOLOGY::Information technology::Computer science::Computer scienceen_US
dc.titleAn Evaluation of Basic Protection Mechanisms in Financial Apps on Mobile Devicesen_US
dc.typeThesisen_US
dc.degree.nameMTech (Res)en_US
dc.degree.levelMastersen_US
dc.degree.grantorIndian Institute of Scienceen_US
dc.degree.disciplineEngineeringen_US


Files in this item

This item appears in the following Collection(s)

Show simple item record