PayScan: Detection and Security Analysis of Payment Libraries in Android Apps


연구 분야: Infrastructure



학회: International Journal of Information Security


초록

Third-party payment libraries (TPLs) are widely used in Android applications to facilitate in-app transactions, yet their security implications remain largely underexplored. In this paper, we present a novel approach for automated detection and security analysis of payment libraries in Android applications. Our tool, PayScan, employs byte-pattern analysis and heuristic scanning techniques to identify TPLs and then it assesses their security posture. Additionally, the tool integrates three independent security scanners. We analyzed a dataset of 10,553 Android applications, detecting 18 payment libraries and evaluating their security and privacy risks. Our findings indicate that 71.7% of applications use outdated payment libraries, with some SDK versions being over four years old. Additionally, we identified 397 private key leaks across 212 applications. The security scanners detected over 20,000 vulnerabilities, including critical issues such as SSL misconfigurations, WebView XSS, and weak cryptographic implementations. We compare our detection approach against LibScout and LibRadar, demonstrating its practical performance in detecting payment libraries, including in obfuscated applications. This study reveals important security risks in mobile payment ecosystems and emphasizes the value of continued monitoring of third-party payment libraries. The proposed tool offers a scalable solution for detection and analysis, providing practical utility for researchers, developers, and auditors focused on financial application security.


Author Profile
Fadi Mohsen

Bernoulli Institute for Mathematics Computer Science and Artificial Intelligence University of Groningen 9747 AG Groningen Netherlands

Andorra
Author Profile
Manar Alohaly

Information Systems Department Princess Nourah Bint Abdulrahman University Riyadh Saudi Arabia

Saudi Arabia
Author Profile
Usman Rauf

Department of Mathematics and Computer Science Mercy University Dobbs Ferry NY USA

Andorra

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Andorra, Saudi Arabia
사이트 Springer
좋아요 수 0

연관 논문 목록 (103건)