Skip to main navigation Skip to search Skip to main content

Exposed: critical vulnerabilities in USSD banking authentication protocols

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Unstructured Supplementary Service Data (USSD) authentication has been widely adopted as a popular method for verifying user identity and securing transactions in mobile financial banking, particularly in Sub-Saharan African countries. This is due to the convenience, speed, and accessibility since they do not require high-powered computing phones, large storage, or internet connectivity. However, like every technological advancement, this has been widely exploited by malicious actors due to weak authentication requirements. This study critically examines all 19 commercial banks in Nigeria, which has the largest USSD banking usage in Sub-Saharan Africa. We analyse 30 scenarios to conduct an anatomy and build a timeline of USSD banking attacks. Furthermore, we critically but anonymously examine each USSD banking platform against several security factors selected from government guidelines, the National Institute of Standards (NIST) SP800-63B framework and the National Cyber Security Centre (NCSC) recommendations. This led to the revelation that certain services only require a single authentication, such as PIN, while others require no authentication at all. Also, most of the banks failed to comply with governmental and industrial authentication standards. Furthermore, we present a 5-phase timeline of USSD attacks and address present recommendations for different stakeholders at the various stages.
Original languageEnglish
Title of host publication2023 IEEE International Conference on Cyber Security and Resilience (CSR)
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages275-280
Number of pages6
ISBN (Electronic)9798350311709
ISBN (Print)9798350311716
DOIs
Publication statusPublished - 28 Aug 2023
Event3rd IEEE International Conference on Cyber Security and Resilience, CSR 2023 - Hybrid, Venice, Italy
Duration: 31 Jul 20232 Aug 2023

Conference

Conference3rd IEEE International Conference on Cyber Security and Resilience, CSR 2023
Country/TerritoryItaly
CityHybrid, Venice
Period31/07/232/08/23

Keywords

  • authentication
  • mobile banking
  • USSD

Fingerprint

Dive into the research topics of 'Exposed: critical vulnerabilities in USSD banking authentication protocols'. Together they form a unique fingerprint.

Cite this