• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Fuzzing of mobile application in the banking domain. A case study
 
  • Details
  • Full
Options
2020
Conference Paper
Title

Fuzzing of mobile application in the banking domain. A case study

Abstract
Mobile applications are today ubiquitous, and everybody uses them on a daily basis. This applies also to security-critical mobile applications such as online banking apps. In today's architectures, these mobile applications are usually fed from the same source as mobile applications on smart phones, i.e. web services. This makes security testing of web services inevitable. Furthermore, regulation increases and requires stronger security mechanisms as with the strong customer authentication from the Revised European Payment Services Directive (PSD2). Automated security testing is a way to cope with the increasing requirements on assuring the security of such web services and their implemented security controls whilst dealing with decreasing resources for such efforts. In this paper, we present our experiences from a case study provided by Kuveyt Türk Bank performed within the ITEA-3 project TESTOMAT where we introduced automated security testing in terms of fuzzing to complement manual security testing.
Author(s)
Schneider, Martin A.
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Wendland, Marc-Florian  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Akin, Abdurrahman
Kuveyt Türk Participation Bank
Sentürk, Serafettin
Tübitak Informatics and Information Security Research Center
Mainwork
Companion of the IEEE 20th International Conference on Software Quality, Reliability and Security, QRS-C 2020. Proceedings  
Project(s)
TESTOMAT
Funder
Bundesministerium für Bildung und Forschung BMBF (Deutschland)  
Conference
International Conference on Software Quality, Reliability, and Security Companion (QRS-C) 2020  
Workshop on System Testing and Validation (STV) 2020  
Open Access
File(s)
Download (947.75 KB)
DOI
10.24406/publica-r-408858
10.1109/QRS-C51114.2020.00087
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Keyword(s)
  • web services

  • security testing

  • automation

  • fuzz testing

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024