USENIX Security2020Top-tier venue
Cardpliance: PCI DSS Compliance of Android Applications
Samin Yaseer Mahmud, Akhil Acharya, Benjamin Andow, William Enck, Bradley Reaves
Abstract
Smartphones and their applications have become a predominant way of computing, and it is only natural that they have become an important part of financial transaction technology. However, applications asking users to enter credit card numbers have been largely overlooked by prior studies, which frequently report pervasive security and privacy concerns in the general mobile application ecosystem. Such applications are particularly security-sensitive, and they are subject to the Payment Card Industry Data Security Standard (PCI DSS). In this paper, we design a tool called Cardpliance, which bridges the semantics of the graphical user interface with static program analysis to capture relevant requirements from PCI DSS. We use Cardpliance to study 358 popular applications from Google Play that ask the user to enter a credit card number. Overall, we found that 1.67% of the 358 applications are not compliant with PCI DSS, with vulnerabilities including improperly storing credit card numbers and card verification codes. These findings paint a largely positive picture of the state of PCI DSS compliance of popular Android applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 06aeba0a-c3d5-4e1b-9b14-7774544f6777Cited by top-tier papers1
Ask how each one uses itBuilds on6
- Finding Clues for Your Secrets: Semantics-Driven, Learning-Based Privacy Discovery in Mobile AppsYuhong Nan, Zhemin Yang, Xiaofeng Wang, Yuan Zhang et al.NDSS 2018 · 79 citations
- Show Me the Money! Finding Flawed Implementations of Third-party In-app Payment in Android AppsWenbo Yang, Yuanyuan Zhang, Juanru Li, Hui Liu et al.NDSS 2017 · 40 citations
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 34 citations
- Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation AnalysisYi Chen, Luyi Xing, Yue Qin, Xiaojing Liao et al.USENIX Security 2019 · 33 citations
- Security Certification in Payment Card Industry: Testbeds, Measurements, and RecommendationsSazzadur Rahaman, Gang Wang, Danfeng Daphne YaoCCS 2019 · 31 citations
Related papers
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel et al.NDSS 2018 · 33 citations
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis et al.USENIX Security 2024 · 13 citations
- Checking conformance of applications against GUI policiesZhen Zhang, Yu Feng, Michael D. Ernst, Sebastian Porst et al.FSE 2021 · 8 citations
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong et al.USENIX Security 2024 · 3 citations
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim et al.CCS 2017 · 126 citations
