<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Examining Security Risks of Mobile Banking Applications through Blog Mining</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Wu He</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Xin Tian</string-name>
          <email>xtian@odu.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Jiancheng Shen</string-name>
          <email>jshen@odu.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Old Dominion University</institution>
          ,
          <addr-line>Norfolk, VA</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>This paper provides an in-depth review of the security aspect of mobile banking applications. The authors employed blog mining as a research method to analyze blog discussion on security of mobile banking applications. Security risks, protection strategy/best practices and future security trends are summarized to help banks and consumers mitigate the security risks of mobile banking applications.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        Many people are using their mobile devices such as smart
phones to access various online services on a daily basis.
In particular, mobile banking applications are increasingly
becoming popular. Many banks are offering mobile
banking services which allow bank customers to check balance
in their personal account, to transfer funds between
accounts and make online payments anywhere and at anytime
by simply using mobile banking applications installed on
their mobile devices
        <xref ref-type="bibr" rid="ref6">(Elkhodr et al., 2012)</xref>
        . Moreover,
customers can receive alerts from banks such as overdraft
alerts, low balance warnings, recent large transactions, and
so on (Panja et al., 2013).
      </p>
      <p>
        Unfortunately, mobile malware has been increasing in
frequency and sophistication in the past five years and has
caused a variety of damages including leaking of sensitive
financial data, financial loss and identify theft
        <xref ref-type="bibr" rid="ref9">(He, 2013)</xref>
        .
In particular, mobile banking apps have attracted the
attention of many cyber criminals (Panja et al., 2013). There are
a lot of concerns with the security aspect of mobile
banking since mobile devices are vulnerable to threats, attack
and loss
        <xref ref-type="bibr" rid="ref4">(Claessens et al., 2002)</xref>
        .
      </p>
      <p>In an effort to address the increasing threat, researchers
and security vendors have been developing new practices,
techniques and solutions to reduce security risks associated
with mobile banking applications. To help readers
understand the state-of-the-art in this fast-moving area, the
authors synthesize the related discussions in literature and
provide an in-depth review of the security aspect of mobile
banking. Currently, the discussion of security risks of
mobile banking is disparate, fragmented and distributed in
different outlets such as academic articles, white papers,
security threat reports and news articles. The authors
employed blog mining as a research method to analyze blog
discussion on mobile banking applications. Best practices
are summarized to help banks and consumers mitigate the
security risks of mobile banking.</p>
    </sec>
    <sec id="sec-2">
      <title>Literature Review</title>
      <p>
        Mobile banking has been developed as an effective and
convenient channel for financial institutions to distribute
their services to clients
        <xref ref-type="bibr" rid="ref18 ref19 ref6">(Mallat et al., 2004; Nie &amp; Hu,
2008; Lin, 2011; Elkhodr et al., 2012)</xref>
        . Mobile banking
makes financial services easily accessible for customers
through a handheld device
        <xref ref-type="bibr" rid="ref15">(Singh et al., 2010)</xref>
        . However,
the wide use of smartphones is also accompanied with an
equally alarming rise in mobile malware (Seo et al., 2012).
Security is considered as a priority for many mobile
banking customers. A survey found that when it comes to
mobile banking, 31% of customers are willing to pay for
added security features, 63% are willing to switch accounts for
one with better security features, and 71% are willing to
switch accounts to one that guaranteed losses would be
reimbursed
        <xref ref-type="bibr" rid="ref12">(Heggestuen, 2014)</xref>
        .
      </p>
      <p>
        Cyber security experts suggested that the cyber-attacks
against financial services institutions are becoming more
frequent and more sophisticated
        <xref ref-type="bibr" rid="ref23">(Cuomo, 2014; Ryan,
2014)</xref>
        . Overall, there are several cyber security concerns
with regard to mobile banking. Security on mobile banking
is complicated because of the variety of mobile devices
and platforms
        <xref ref-type="bibr" rid="ref16 ref8">(He, 2012; Lee et al., 2013)</xref>
        . The security
and privacy of sensitive financial data is one of the main
concerns in acceptance of the mobile banking applications
        <xref ref-type="bibr" rid="ref6">(Elkhodr et al., 2012)</xref>
        . The limited privacy protection
experience and fewer resources of independent developers
decrease the effectiveness of cyber security protection on the
mobile applications
        <xref ref-type="bibr" rid="ref1">(Balebako &amp; Cranor, 2014)</xref>
        . The weak
and rigid authentication provided by signature, PIN,
password and Card Security Code (CSC) in mobile banking
have numerous flaws and loop-holes (Edge &amp; Sampaio,
2009).
      </p>
      <p>
        To prevent the cyber fraud, and facilitate a safe and
robust mobile banking system, many cyber security experts
have provided pertinent frameworks and methods for
mobile banking security solutions. Edge and Sampaio (2009)
provided a comprehensive survey of existing research in
account signatures, an innovative account profiling
technology that can improve the fraud detection mechanisms.
        <xref ref-type="bibr" rid="ref7">Fatima (2011)</xref>
        posited biometric based authentication and
identification systems as new solutions to address the
issues of security and privacy, which imposes restrictions to
prevent individuals from accessing to certain physical
spaces and electronic services.
        <xref ref-type="bibr" rid="ref6">Elkhodr et al. (2012)</xref>
        proposed the Transport Layer Security (TLS) protocol
combined with a proposed trust negotiation method, which
authenticates the client, the mobile device used in
accessing the bank account information, and the server.
        <xref ref-type="bibr" rid="ref23">Ryan
(2014)</xref>
        , as a practitioner from Conference of State Bank
Supervisors, suggested a four-step mobile banking risk
assessment method, including classification of information,
identify threats and vulnerabilities, measure risk and
communicate risk. On the other hand,
        <xref ref-type="bibr" rid="ref21">Pousttchi and Schurig
(2004)</xref>
        suggested the security requirement for mobile
banking: data needs to be encrypted, access to the data must be
authorized and the authorization has to be simple. Ease of
use is a key factor for consumer acceptance of mobile
banking services (Jeong &amp; Yoon, 2013).
      </p>
    </sec>
    <sec id="sec-3">
      <title>Methodology</title>
      <p>
        The authors employed a relative new research method
called blog mining to find blogs that discuss security of
mobile banking applications. This method has been shown
to be very useful in information and internet research
        <xref ref-type="bibr" rid="ref22">(Rubin et al., 2011)</xref>
        . An analysis of active blogs can add
currency and relevancy to research studies
        <xref ref-type="bibr" rid="ref11 ref3">(Chau &amp; Xu, 2012;
He &amp; Zha, 2014)</xref>
        . As mobile banking is a young and
fastmoving area, many relevant discussions were posted by
technology consultants and security experts on blogs.
Thus, those blogs are a very useful data source for learning
about concerns associated with mobile banking. A
limitation with blog mining is that the information on blogs is
not peer reviewed as journal publications and often
represents personal opinions and attitudes. One way to mitigate
this limitation is to combine blog mining with an extensive
literature search for a more comprehensive understanding
of the topics that are under investigation.
      </p>
      <p>Specifically, we used Google blog search engine
(http://www.google.com/blogsearch) to search for blogs
using the keywords including “mobile banking security”
and “mobile apps vulnerability”. Google Blog Search is
specially designed to retrieve content from blogs that are
freely and publicly available on the Internet. As result,
over 200,000 results were found mostly from 2012-2015 in
0.49 seconds. We selected the top 100 records as the data
set. These top 100 blog posts were saved as text files on
the hard drive for text mining and analysis. A well-known
text analytics tool named NVivo 10 was used for text
mining and analytics. We mainly used NVivo 10 software to
conduct various query searches and cluster analysis in
order to find interesting patterns, connections, and key
themes.</p>
    </sec>
    <sec id="sec-4">
      <title>Blog Mining Results</title>
      <p>After reviewing the generated concept themes and clusters,
the authors merged some sub-clusters manually. Finally,
three major clusters associated with the blog discussion
about security of mobile banking apps were identified. The
emergent clusters and main concept terms in the text were
summarized in Table 1. A word cloud can be seen in
Figure 1.
Furthermore, we manually examined the blog posts that
have the most appearance of the keywords to better
understand their discussions and contexts. As we were
particularly interested in the main threats, attacks and
vulnerabilities related to mobile banking applications, we presented a
synthesis of main threats, attacks and vulnerabilities below
based on what we found from the blog mining.</p>
    </sec>
    <sec id="sec-5">
      <title>Mobile Banking App Threats</title>
      <p>
        We identified a variety of mobile banking app threats from
the blog mining results. They are listed below:
 The mobile malware mainly include Trojans, root kits
and viruses. Some common malware affecting mobile
bank apps include Zitmo, Banker, Perkel/Hesperbot,
Wrob, Bankum, ZertSecurity, DroidDream and
Keyloggers. Many of mobile malware are variants of
existing malware that affect computers and traditional
online banking
        <xref ref-type="bibr" rid="ref25 ref27">(Webroot, 2014; Shih et al., 2008)</xref>
        .
Cyber criminals have been refining these malware to
target mobile devices for access to bank accounts and
make them more resilient to security defenses. Below
are some common malware that affect mobile banking
apps.
 Threats from third party applications. Third party
applications on mobile devices could secretly tamper an
existing banking app that is already in the mobile
device and steal account information. Users are advised to
download apps or app updates only from official
sources or trusted app stores.
 Phishing: Fraud Apps / Fake App Update. There are
many fake banking applications that claim to be official
on third party app marketplace. Cybercriminals also
of

ten offer a downloadable update for the banking apps
on third party app websites. These fake apps or fake
app updates contain malicious codes to steal users’
bank account information (Huang, 2015).
      </p>
      <p>Unencrypted Wi-Fi networks. Public Wi-Fi networks in
coffee shops, libraries, airports, hotels, and other public
places are often not secure. When mobile banking app
users use unsecure wireless networks to check account
balance, deposit checks and pay bills, cybercriminals
can eavesdrop and steal their sensitive information
(Legnitto, 2013).</p>
      <p>Vulnerability of mobile banking apps. For example,
many banking apps lack protection against reverse
engineering of code (whiteCryption, 2014).
Cybercriminals can analyze the source code to steal account
information and other sensitive information.</p>
    </sec>
    <sec id="sec-6">
      <title>Protection Strategy and Best Practices</title>
      <p>
        A number of security mechanisms such as second factor
authentication, data encryption, site key with security
questions and images, registered mobile device authentication,
and anti-virus apps can be adopted to enhance the security
of mobile banking applications
        <xref ref-type="bibr" rid="ref14 ref16 ref2">(Cognizant, 2013;
Constantin, 2014; Lee et al., 2013; Chandramohan &amp; Tan,
2012; La Polla et al., 2013; White, 2013)</xref>
        . We listed some
protection strategy/best practices for users and developers
of mobile banking app respectively below.
      </p>
    </sec>
    <sec id="sec-7">
      <title>Protection strategy and best practices for users</title>
      <p>Many people jailbreak
their smart phones in
order to get additional
benefits. However,
jailbreaking smart phones
brings vulnerabilities to
the operating system.</p>
      <p>Many people try to install
applications from third
parties, because they are
free there. However, many
free apps from third
parties contain virus
Mobile anti-virus apps
will provide partial
protection from malware to help
mitigate risks.</p>
      <p>Best Practices
To protect smartphone
from various security
threats, users need to
avoid jailbreaking or
routing their phone.</p>
      <p>Install mobile banking
apps only from official
bank website.</p>
      <p>Install recommended
antivirus products by
leading organizations
such as PC Magazine
who have been testing
those antivirus products</p>
    </sec>
    <sec id="sec-8">
      <title>Protection strategy and best practices for developers of mobile banking apps</title>
    </sec>
    <sec id="sec-9">
      <title>Emerging Security Trends</title>
      <p>
        Some security experts and vendors propose new ways to
mediate security risks associated with mobile banking
apps. Below are some emerging trends we found from the
blog mining results.
 Integrating biometrics into mobile banking apps to
enhance user authentication. Biometric authentication
such as fingerprint scanning and voice recognition
offers a promising way for identity and access
management
        <xref ref-type="bibr" rid="ref7">(Fatima, 2011)</xref>
        . As personal biometric also has
vulnerability, it is better to combine personal biometric
with other authentication such as one-time password
(OTP) and SiteKey for stronger personal identification
and verification.
 Integrating intelligent behavioral monitoring and
analysis technology with mobile banking apps.
        <xref ref-type="bibr" rid="ref27">Webroot
(2014)</xref>
        recently developed mobile security SDK which
is designed to embed security within a mobile banking
app, run in the background and deliver real-time threat
intelligence to the bank for further data analysis and
action. By employing a behavioral monitoring and
analysis approach, banks can detect abnormal behavior more
accurately and early. Specifically, behavior analysis
can detect the behavior of the person who is using the
mobile app and compare it with previous behavior or
usage patterns. If abnormal behavior is identified, alert
messages will be sent out.

      </p>
      <p>
        Deployment of advanced big data analytics technology
for fraud detection and behavioral analysis. Accurate
and efficient behavioral analysis requires banks to
deploy advanced big data analytics to mine enormous
volumes of security data to better identify trends of
malicious behavior or abnormal behaviors indicative of an
attack at the outset
        <xref ref-type="bibr" rid="ref17">(Khosla, 2015)</xref>
        .
      </p>
    </sec>
    <sec id="sec-10">
      <title>Conclusion and Future Research</title>
      <p>
        Mobile banking offers a lot of benefits to both banks and
consumers. However, security is a significant barrier to the
wide adoption of mobile banking applications
        <xref ref-type="bibr" rid="ref24 ref26">(To &amp; Lai,
2014)</xref>
        . As there are many security risks with the use of
mobile banking applications, it is critical for both banks
and consumers to be aware of these risks and take steps to
mitigate the risks. Currently, there is lack of systematic
discussion in the literature about the security risks with
mobile banking. In this paper, we identified some key
security risks, protection strategy/best practices and future
security trends associated with mobile banking through
mining relevant blog posts.
      </p>
      <p>As for future research, we plan to use the workflow
technology to simulate mobile banking security risks such
as how to simulate the attack on mobile check deposit so
that we can better increase the security awareness of
mobile banking app developers and users. We are also
interested in studying the use of biometric mechanism in
mobile banking applications and the balance between security
and usability for mobile banking applications.</p>
    </sec>
    <sec id="sec-11">
      <title>Acknowledgment</title>
      <p>This work was supported in part by the U.S. National
Science Foundation under Grant SES-1318470 and
SES1318501.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>Balebako</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Cranor</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Improving App Privacy: Nudging App Developers to Protect User Privacy</article-title>
          .
          <source>Security &amp; Privacy</source>
          , IEEE,
          <volume>12</volume>
          (
          <issue>4</issue>
          ),
          <fpage>55</fpage>
          -
          <lpage>58</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Chandramohan</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Tan</surname>
            ,
            <given-names>H. B. K.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>Detection of mobile malware in the wild</article-title>
          .
          <source>Computer, (9)</source>
          ,
          <fpage>65</fpage>
          -
          <lpage>71</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Chau</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Xu</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>Business intelligence in blogs: Understanding consumer interactions and communities</article-title>
          .
          <source>MIS quarterly</source>
          ,
          <volume>36</volume>
          (
          <issue>4</issue>
          ),
          <fpage>1189</fpage>
          -
          <lpage>1216</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <surname>Claessens</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dem</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>De Cock</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Preneel</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Vandewalle</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2002</year>
          ).
          <article-title>On the security of today's online electronic banking systems</article-title>
          .
          <source>Computers &amp; Security</source>
          ,
          <volume>21</volume>
          (
          <issue>3</issue>
          ),
          <fpage>253</fpage>
          -
          <lpage>265</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <surname>Cognizant</surname>
          </string-name>
          (
          <year>2014</year>
          ). Mobile Banking Security: Challenges, Solutions.
          <source>Retrieved on Feb 22</source>
          ,
          <year>2015</year>
          at http://www.cognizant.com/InsightsWhitepapers/Mobile-BankingSecurity
          <string-name>
            <surname>-Challenges-</surname>
          </string-name>
          Solutions-codex898.pdf
          <string-name>
            <surname>Constantin</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Security analysis of mobile banking apps reveals significant weaknesses</article-title>
          .
          <source>Retrieved on Feb 21</source>
          ,
          <year>2015</year>
          at http://www.pcworld.com/article/2086320/security
          <article-title>-analysis-ofmobile-banking-apps-reveals-significant-weaknesses</article-title>
          .html
          <string-name>
            <surname>Cuomo</surname>
            <given-names>A. M.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Report on Cyber Security in the Banking Sector</article-title>
          . New York State Department of Financial Services.
          <source>Retrieved on Feb 22</source>
          ,
          <year>2015</year>
          at http://www.dfs.ny.gov/about/press2014/pr140505_cyber_security .pdf Edge,
          <string-name>
            <given-names>M. E.</given-names>
            , &amp;
            <surname>Sampaio</surname>
          </string-name>
          ,
          <string-name>
            <surname>P. R. F.</surname>
          </string-name>
          (
          <year>2009</year>
          ).
          <article-title>A survey of signature based methods for financial fraud detection</article-title>
          .
          <source>Computers &amp; security</source>
          ,
          <volume>28</volume>
          (
          <issue>6</issue>
          ),
          <fpage>381</fpage>
          -
          <lpage>394</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>Elkhodr</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shahrestani</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Kourouche</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>A proposal to improve the security of mobile banking applications</article-title>
          .
          <source>In ICT and Knowledge Engineering (ICT &amp; Knowledge Engineering)</source>
          ,
          <year>2012</year>
          10th International Conference on (pp.
          <fpage>260</fpage>
          -
          <lpage>265</lpage>
          ). IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <surname>Fatima</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>E-banking security issues-Is there a solution in biometrics</article-title>
          .
          <source>Journal of Internet Banking and Commerce</source>
          ,
          <volume>16</volume>
          (
          <issue>2</issue>
          ):
          <fpage>2011</fpage>
          -
          <lpage>08</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <surname>He</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>A Review of Social Media Security Risks and Mitigation Techniques</article-title>
          .
          <source>Journal of Systems and Information Technology</source>
          ,
          <volume>14</volume>
          (
          <issue>2</issue>
          ),
          <fpage>171</fpage>
          -
          <lpage>180</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <surname>He</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>A Survey of Security Risks of Mobile Social Media through Blog Mining and an Extensive Literature Search</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <given-names>Information</given-names>
            <surname>Management</surname>
          </string-name>
          and Computer Security,
          <volume>21</volume>
          (
          <issue>5</issue>
          ), pp.
          <fpage>381</fpage>
          -
          <lpage>400</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <surname>He</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Zha</surname>
            ,
            <given-names>S.H.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Insights into the Adoption of Social Media Mashups</article-title>
          .
          <source>Internet Research</source>
          .
          <volume>24</volume>
          (
          <issue>2</issue>
          ), pp.
          <fpage>160</fpage>
          -
          <lpage>180</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          <string-name>
            <surname>Heggestuen</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <source>The Future Of Mobile And Online Banking: 2014. Retrieved on Feb 02</source>
          ,
          <year>2015</year>
          at http://www.businessinsider.
          <article-title>com/the-future-of-mobile-and-</article-title>
          <string-name>
            <surname>onlinebanking-</surname>
          </string-name>
          2014
          <string-name>
            <surname>-</surname>
            slide-deck-2014-10?op=1 Huang,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>The South Korean Fake Banking App Scam</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          <source>Retrieved on Feb 02</source>
          ,
          <year>2015</year>
          at http://www.trendmicro.com/cloud-content/us/pdfs/securityintelligence/white
          <article-title>-papers/wp-the-south-korean-fake-banking-appscam</article-title>
          .pdf
          <string-name>
            <surname>Jeong</surname>
            ,
            <given-names>B. K.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Yoon</surname>
            ,
            <given-names>T. E.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>An Empirical Investigation on Consumer Acceptance of Mobile Banking Services</article-title>
          .
          <source>Business and Management Research</source>
          ,
          <volume>2</volume>
          (
          <issue>1</issue>
          ),
          <fpage>31</fpage>
          -
          <lpage>40</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          <string-name>
            <given-names>La</given-names>
            <surname>Polla</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Martinelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            , &amp;
            <surname>Sgandurra</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>A survey on security for mobile devices</article-title>
          .
          <source>Communications Surveys &amp; Tutorials</source>
          , IEEE,
          <volume>15</volume>
          (
          <issue>1</issue>
          ),
          <fpage>446</fpage>
          -
          <lpage>471</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          <string-name>
            <surname>Singh</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Srivastava</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Srivastava</surname>
            ,
            <given-names>R. K.</given-names>
          </string-name>
          (
          <year>2010</year>
          ).
          <article-title>Customer acceptance of mobile banking: A conceptual framework</article-title>
          .
          <source>Sies journal of management</source>
          ,
          <volume>7</volume>
          (
          <issue>1</issue>
          ),
          <fpage>55</fpage>
          -
          <lpage>64</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          , Zhang,
          <string-name>
            <given-names>Y.</given-names>
            , &amp;
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <surname>K. L.</surname>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>An Investigation of Features and Security in Mobile Banking Strategy</article-title>
          .
          <source>Journal of International Technology and Information Management</source>
          ,
          <volume>22</volume>
          (
          <issue>4</issue>
          ), Article 2.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          <string-name>
            <surname>Khosla</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Behavioral Analysis Could Have Prevented The Anthem Breach</article-title>
          .
          <source>Retrieved on Feb. 22</source>
          , 2015 at http://www.forbes.com/sites/frontline/2015/02/24/behavioralanalysis-could
          <article-title>-have-prevented-the-anthem-breach/</article-title>
          <string-name>
            <surname>Legnitto</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <source>Mobile Banking On Unsecure Wireless Networks Is Risky Business. Retrieved on Feb 22</source>
          ,
          <year>2015</year>
          at http://www.privatewifi.
          <article-title>com/title-mobile-banking-on-unsecurewireless-networks-is-risky-business/</article-title>
          <string-name>
            <surname>Lin</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>An empirical investigation of mobile banking adoption: The effect of innovation attributes and knowledgebased trust</article-title>
          .
          <source>International journal of information management</source>
          ,
          <volume>31</volume>
          (
          <issue>3</issue>
          ):
          <fpage>252</fpage>
          -
          <lpage>260</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          <string-name>
            <surname>Mallat</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rossi</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Tuunainen</surname>
            ,
            <given-names>V. K.</given-names>
          </string-name>
          (
          <year>2004</year>
          ).
          <article-title>Mobile banking services</article-title>
          .
          <source>Communications of the ACM</source>
          ,
          <volume>47</volume>
          (
          <issue>5</issue>
          ),
          <fpage>42</fpage>
          -
          <lpage>46</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          <string-name>
            <surname>Nie</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          (
          <year>2008</year>
          ).
          <article-title>Mobile banking information security and protection methods</article-title>
          .
          <source>In Computer Science and Software Engineering</source>
          , 2008 International Conference on (Vol.
          <volume>3</volume>
          , pp.
          <fpage>587</fpage>
          -
          <lpage>590</lpage>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          (
          <year>2013</year>
          ).
          <article-title>Cybersecurity in banking and financial sector: Security analysis of a mobile banking application</article-title>
          .
          <source>In Collaboration Technologies and Systems (CTS)</source>
          , 2013 International Conference on (pp.
          <fpage>397</fpage>
          -
          <lpage>403</lpage>
          ). IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          <string-name>
            <surname>Pousttchi</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Schurig</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          (
          <year>2004</year>
          ).
          <article-title>Assessment of today's mobile banking applications from the view of customer requirements</article-title>
          .
          <source>In System Sciences</source>
          ,
          <year>2004</year>
          .
          <source>Proceedings of the 37th Annual Hawaii International Conference on</source>
          (pp.
          <fpage>10</fpage>
          -pp).
          <source>IEEE.</source>
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          <string-name>
            <surname>Rubin</surname>
            ,
            <given-names>V. L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Burkell</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Quan-Haase</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>Facets of serendipity in everyday chance encounters: a grounded theory approach to blog analysis</article-title>
          .
          <source>Information Research</source>
          ,
          <volume>16</volume>
          (
          <issue>3</issue>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          <string-name>
            <surname>Ryan W. J.</surname>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>A Resource Guide for Bank Executives: Executive Leadership of Cybersecurity</article-title>
          .” Conference of State Bank Supervisors.
          <source>Retrieved on Feb 22</source>
          ,
          <year>2015</year>
          at http://www.csbs.org/CyberSecurity/Documents/CSBS%20Cybers
          <source>ecurity%20101%20Resource%20Guide%20FINAL.pdf Seo</source>
          ,
          <string-name>
            <given-names>S. H.</given-names>
            ,
            <surname>Gupta</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Sallam</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. M.</given-names>
            ,
            <surname>Bertino</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            , &amp;
            <surname>Yim</surname>
          </string-name>
          ,
          <string-name>
            <surname>K.</surname>
          </string-name>
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          (
          <year>2014</year>
          ).
          <article-title>Detecting mobile malware threats to homeland security through static analysis</article-title>
          .
          <source>Journal of Network and Computer Applications</source>
          ,
          <volume>38</volume>
          ,
          <fpage>43</fpage>
          -
          <lpage>53</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          <string-name>
            <surname>Shih</surname>
            ,
            <given-names>D. H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lin</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chiang</surname>
            ,
            <given-names>H. S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Shih</surname>
            ,
            <given-names>M. H.</given-names>
          </string-name>
          (
          <year>2008</year>
          ).
          <article-title>Security aspects of mobile phone virus: a critical survey</article-title>
          .
          <source>Industrial Management &amp; Data Systems</source>
          ,
          <volume>108</volume>
          (
          <issue>4</issue>
          ),
          <fpage>478</fpage>
          -
          <lpage>494</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          <string-name>
            <surname>To</surname>
            ,
            <given-names>W. M.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Lai</surname>
            ,
            <given-names>L. S.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>Mobile Banking and Payment in China</article-title>
          .
          <source>IT Professional</source>
          ,
          <volume>16</volume>
          (
          <issue>3</issue>
          ),
          <fpage>22</fpage>
          -
          <lpage>27</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          <string-name>
            <surname>Webroot</surname>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>The risks &amp; rewards of mobile banking apps</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          <source>Retrieved on Feb 22</source>
          ,
          <year>2015</year>
          at http://www.brightcloud.com/pdf/RisksRewardsofMobileBanking AppsWhitepaper_
          <volume>20140619115948</volume>
          _
          <fpage>311111</fpage>
          .pdf whiteCryption (
          <year>2014</year>
          ).
          <article-title>whiteCryption Introduces New Level of Security for Mobile Payment Applications</article-title>
          .
          <source>Retrieved on Feb 22</source>
          ,
          <year>2015</year>
          at http://www.prweb.com/releases/2014/01/prweb11531529.htm
          <string-name>
            <surname>White</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2013</year>
          ).
          <article-title>Six Main Rules Of Safe Mobile Banking</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          <string-name>
            <surname>Where</surname>
          </string-name>
          ,
          <source>When And How? Retrieved on Feb 22</source>
          ,
          <year>2015</year>
          at http://blog.jammer-store.com/
          <year>2013</year>
          /05/six-main
          <article-title>-rules-of-safemobile-banking-where-when-and-how/</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>