Zero-Trust Mobile Application Architecture for Financial Transactions and Fraud Prevention

Authors

  • Ruturajsinh Kiritsinh Jadeja

Keywords:

zero-trust architecture; mobile banking security; continuous authentication; behavioral biometrics; fraud detection; machine learning; trusted execution environment; multi-factor authentication; micro-segmentation; financial-grade API; malware detection; risk-adaptive policy engine

Abstract

With a new network perimeter, mobile financial applications are increasingly adopting a “never trust, always verify” approach to provide protection from credential theft, session hijacking and transaction fraud. This paper consolidates results of 21 sources to propose a unified zero-trust mobile application architecture for financial services which merges the topics of zero-trust architecture, continuous behavioral-biometric authentication, mobile malware detection and machine-learning-based fraud detection. Using National Institute of Standards and Technology, Special Publication 800-207, which requires per-session decision on privileges to be granted on authorization based on a dedicated policy engine, and not on static network location trust. Equal error rates of 2.2% - 15.1% have been reported for continuous authentication mechanisms evaluated, such as touchscreen gestures, hand-movement-orientation-grasp (HMOG) sensor fusion, and keystroke dynamics. The surveyed literature indicates that the accuracy of machine-learning fraud-detection techniques for financial-statement and credit-card fraud detection ranges from about 78% to 99.98%. The proposed architecture is layered on trusted execution environments on the device, network-level micro-segmentation, and application-level risk-adaptive policy enforcement, and is compared to perimeter based virtual private network models on a number of quantitative measures such as breach containment capability, implementation complexity, and cost efficiency. The results show that zero-trust mobile deployments lower the risk of lateral movement, and add some computational and onboarding cost, but the results are measurable and manageable. The paper ends by summarizing some of the problems with migration, regulatory issues regarding open-banking requirements, and some suggested future research directions.

Downloads

Download data is not yet available.

References

M. Abuhamad, A. Abusnaina, D. Nyang, and D. Mohaisen, “Sensor-based continuous authentication of smartphones' users using behavioral biometrics: A contemporary survey,” IEEE Internet of Things J., vol. 8, no. 1, pp. 65–84, 2021.

K. G. Al-Hashedi and P. Magalingam, “Financial fraud detection applying data mining techniques: A comprehensive review from 2009 to 2019,” Comput. Sci. Rev., vol. 40, p. 100402, 2021.

M. N. Ashtiani and B. Raahemi, “Intelligent fraud detection in financial statements using machine learning and data mining: A systematic literature review,” IEEE Access, vol. 10, pp. 72504–72525, 2021.

E. Bertino, “Zero trust architecture: Does it help?” IEEE Security & Privacy, vol. 19, no. 5, pp. 95–96, 2021.

C. Buck, C. Olenberger, A. Schweizer, F. Völter, and T. Eymann, “Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust,” Comput. Secur., vol. 110, p. 102436, 2021.

D. Fett, P. Hosseyni, and R. Küsters, “An extensive formal security analysis of the OpenID financial-grade API,” in Proc. 2019 IEEE Symp. Security and Privacy (S&P), 2019, pp. 1054–1072.

M. A. Ferrag, L. Maglaras, A. Derhab, and H. Janicke, “Authentication schemes for smart mobile devices: Threat models, countermeasures, and open research issues,” Telecommun. Syst., vol. 73, pp. 317–348, 2020.

Y. He, D. Huang, L. Chen, Y. Ni, and X. Ma, “A survey on zero trust architecture: Challenges and future trends,” Wireless Commun. Mobile Comput., vol. 2022, Art. no. 6476274, 2022.

E. Ileberi, Y. Sun, and Z. Wang, “A machine learning based credit card fraud detection using the GA algorithm for feature selection,” J. Big Data, vol. 9, Art. no. 24, 2022.

V. Kouliaridis, K. Barmpatsalou, G. Kambourakis, and S. Chen, “A survey on mobile malware detection techniques,” IEICE Trans. Inf. Syst., vol. E103.D, no. 2, pp. 204–211, 2020.

K. Liu, S. Xu, G. Xu, M. Zhang, D. Sun, and H. Liu, “A review of Android malware detection approaches based on machine learning,” IEEE Access, vol. 8, pp. 124579–124607, 2020.

A. Ometov, S. Bezzateev, N. Mäkitalo, S. Andreev, T. Mikkonen, and Y. Koucheryavy, “Multi-factor authentication: A survey,” Cryptography, vol. 2, no. 1, Art. no. 1, 2018.

S. Rose, O. Borchert, S. Mitchell, and S. Connelly, Zero Trust Architecture, NIST Special Publication 800-207, National Institute of Standards and Technology, 2020.

M. Sabt, M. Achemlal, and A. Bouabdallah, “Trusted execution environment: What it is, and what it is not,” in Proc. 2015 IEEE Trustcom/BigDataSE/ISPA, vol. 1, 2015, pp. 57–64.

S. W. Shah, N. F. Syed, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “LCDA: Lightweight continuous device-to-device authentication for a zero-trust architecture (ZTA),” Comput. Secur., vol. 108, p. 102351, 2021.

Z. Sitová, J. Šeděnka, Q. Yang, G. Peng, G. Zhou, P. Gasti, and K. S. Balagani, “HMOG: New behavioral biometric features for continuous authentication of smartphone users,” IEEE Trans. Inf. Forensics Security, vol. 11, no. 5, pp. 877–892, 2016.

I. Stylios, S. Kokolakis, O. Thanou, and S. Chatzis, “Behavioral biometrics and continuous user authentication on mobile devices: A survey,” Inf. Fusion, vol. 66, pp. 76–99, 2021.

N. F. Syed, S. W. Shah, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “Zero trust architecture (ZTA): A comprehensive survey,” IEEE Access, vol. 10, pp. 57143–57179, 2022.

S. Teerakanok, T. Uehara, and A. Inomata, “Migrating to zero trust architecture: Reviews and challenges,” Security Commun. Netw., vol. 2021, Art. no. 9947347, 2021.

C. Thammarat and W. Kurutach, “A lightweight and secure NFC-base mobile payment protocol ensuring fair exchange based on a hybrid encryption algorithm with formal verification,” Int. J. Commun. Syst., vol. 32, no. 12, Art. no. e3991, 2019.

J. Zhang, B. Chen, Y. Zhao, X. Cheng, and F. Hu, “Data security and privacy-preserving in edge computing paradigm: Survey and open issues,” IEEE Access, vol. 6, pp. 18209–18237, 2018.

Downloads

Published

31.05.2023

How to Cite

Ruturajsinh Kiritsinh Jadeja. (2023). Zero-Trust Mobile Application Architecture for Financial Transactions and Fraud Prevention . International Journal of Intelligent Systems and Applications in Engineering, 11(6s), 1031 –. Retrieved from https://ijisae.org/index.php/IJISAE/article/view/8479

Issue

Section

Research Article