A Framework for Evaluating the Security of Mobile Banking Applications in Nigeria

📖 ABSTRACT/OVERVIEW

The proliferation of mobile banking applications among Nigeria's estimated 103 million bank account holders creates an expanding attack surface that demands rigorous security evaluation frameworks adapted to local deployment conditions. This study develops and validates a security evaluation framework for mobile banking applications in Nigeria, addressing the absence of a standardised, locally contextualised assessment methodology. The framework is constructed through a systematic literature review of 45 studies published between 2020 and 2025, combined with primary analysis of the top 12 Nigerian bank mobile applications using static and dynamic analysis tools including MobSF and Frida. The framework covers seven security domains: authentication strength, data transmission security, local data storage protection, session management, code obfuscation, certificate pinning, and API security. Empirical application of the framework reveals that 7 of 12 applications have medium-to-high severity vulnerabilities, most commonly in local data storage and session management. Multiple applications store sensitive data in plaintext shared preferences, contradicting OWASP Mobile Top 10 requirements. The study validates the framework with three independent security researchers to establish inter-rater reliability. Findings fill a critical gap in Nigerian banking security literature and provide regulators with an evaluation instrument for digital banking supervision. Keywords: mobile banking security, OWASP, Nigeria, security evaluation, vulnerability analysis

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬