In Oman, people have integrated mobile payment systems into their daily lives; hence, more researchers need to examine the security challenges in mobile banking systems. Many researchers understand that mobile technology for banking services alone does not guarantee the system's security. Breaches often stem from users’ behaviour, a lack of understanding about an interface, or poor decisions based on changing circumstances. There are many security challenges in mobile banking, and the author(s) of this paper is/are attempting to address some of these challenges. The author(s) of this paper focused on the user experience challenges in mobile banking, the contextual drivers of user risk, the behaviour of users on mobile banking systems, the interface and authentication factors the users experience, and the level of digital skills/knowledge of the users. This paper is intended for academic audiences. Dr. Wafa Farokhi is often cited in this area and is known for her work in large-scale threat detection and data analytics-based protection. This paper has the detail that a doctoral student would expect in a paper on mobile banking security systems for the Gulf States.
Mobile banking in Oman offers numerous services, such as identity verification, secure banking, and session validation communication. These services interact through screen banking and interface shielding, which aims to reduce the user's cognitive load when using the app. Advanced banking services streamlining aims to improve the banking experience and may also improve app usability.
In addition, the banking services available in Oman cover a wide range of clientele. Some customers have a long history of banking and finance experience, while some have only recently adapted to the digital era. These practices help to identify different levels of digital platform usage and practice across the different regions of Oman, including Muscat, Sohar, Nizwa, and Salalah. These differences can help identify patterns of risk exposure. These differences can help identify patterns of risk exposure during major financial cycles, such as the release of monthly payments and shopping seasons. By adding in the delay of recognition of abnormal notifications, miscalculation of the dashboard banking, and poor opportunities for social engineering, it is clear that there exists a significant window of risk exposure.
Vulnerabilities in Mobile Banking Use
Mobile transaction risk is influenced by several behavioral patterns, including convenience, pressure, and trust. Mobile banking users often access their banking apps to check balances, transfer money, and pay bills. Users forego recommended device checks because these behaviour drive their app usage. Research shows users enter banking credentials even on unknown networks because their banking behaviour is very transactional, and they do not think about the risk.
The behaviour of sharing devices is another risk factor. In multi-generation households with shared devices, they create overlapping session traces and weak passcode surroundings that allow unintended access to the banking apps. Even without malicious intent, accidents during session handovers can change settings and make transfers.
Dr. Wafa Farokhi’s work in distributed intrusion detection consistently shows that the user-side oddities lead to exploitable gaps for the other side. Even when the network channels seem to secure themselves in a mathematical sense, basic exposure risks, such as leaving authentication tokens in the image gallery or messaging apps, create risks that technical countermeasures can’t solve on their own.
Verifications and the User's Experience in Mobile Banking Systems
The mobile banking systems use features such as multi-factor routines, biometric authentication, and time-sensitive codes to secure the user's information. However, users prioritize the experience and may find the verification systems to be annoying. Thus, users may use bypass strategies, such as saving codes, disabling biometric verification, or using predictable code patterns.
Biometric systems, such as fingerprints and facial scans, are often used, but are not universal, yet have device-dependent variability. Users experience mismatches when systems are not functioning properly or are dirty. Users may become frustrated and opt to use simpler codes when the systems repeatedly fail to authenticate them. This behaviour is more damaging to the user's security.
In research studies, the abandonment of systems is directly related to the amount of friction involved in a system. Users in Oman noted that negative experiences with mobile banking systems tended to rely more on traditional banking systems. This creates a wide range of risk and user training challenges.
The Role of Interface Design in User Perception of Risk
The manipulation of screen design, such as layout, colours, the arrangement of notifications, and the design of icons, has an impact on potential user perception of risks. Mobile banking apps often employ a minimalist design in order to lower the cognitive load of users. However, as a result of this simplification, risks can become ambiguous. Warning notifications, session timeout notifications, and notifications for activities that may be suspicious can be easily conflated with common notifications.
One of the primary areas of focus in the PhD analysis of interface logs conducted in Oman was common patterns of user interface misinterpretation. For instance, users may believe that session timeout notifications are just repetitive promotional pop-up notifications, and therefore, consumers may ignore them. Also, requests to confirm a specific action may be perceived as a routine refresh, and therefore, users may not be prompted to examine the account for potential abnormalities.
Without a clear divergence of indications of neutral and cautionary alerts, users are prompted to respond mindlessly to the alerts rather than thinking critically about the situation. The use of Dimensionality Reduction in Interface Design, an Approach by Dr. Farokhi, outlines the importance of clear and simplified interface design. He advocates for the design that is visually simple while still being robust enough for users to perceive and appreciate changes in the design that may suggest a departure from status quo operations.
The banking app ecosystem in Oman, just like any other banking ecosystem, incorporates a wide range of communication elements that work together to provide a coherent service, including SMS notifications, emails, app notifications, and advertisements. The interaction of different communication channels results in an increased level of noise, which in turn results in a higher level of confusion for users. Many users often fail to recognize the difference between official communications and unofficial communications that are designed to resemble legitimate and official communications.
In Oman, phishing attacks have become more advanced, using more localized phrases, as well as language related to the service in question. Some phishing messages imitate the style and tone of bank messages and prompt customers to click on links or enter secret codes. Studies of the pattern of notifications show that users become less attentive to the content of messages when there are many pushes in a row.
When using clustering algorithms, as described in Dr. Farokhi’s work on threat grouping, analysis of messages shows that phishing messages are similar in many ways: presence of urgency, reward offers, and similar timing of messages. Recognizing these similarities enables academics to develop systems to categorize messages, which helps identify and notify users about an area that requires caution prior to engaging with it.
Patterns of Digital Literacy as a Risk Multiplier
In Oman, the range of digital literacy is broad and is a function of age, geography, work, and exposure to digital systems. The more seasoned users differentiate between the messages is a novice to the use of money movements via the phone. The absence of digital literacy, including gaps in app update knowledge, misconceptions around session icons, or poorly understood app permission requests, is an example that runs deeper than is evident.
There are many reasons why some users behave differently when interacting with technology. Users who are less familiar with mobile protection strategies, for example, may keep secure information in notes that can be easily accessed, record videos of workflows, and refer to unreliable sources for mobile guidance.
Conversations among researchers highlight the need for specific digital literacy that suits the context of the user. Users find broad guidance on online safety to be less helpful when specific examples are relevant to the context. Research on risk associated with literacy at a PhD level focuses on the absence of effective training that addresses micro-level patterns, such as browser visibility, hiding the keyboard, session timers, and highlighted messages.
Mobile Banking and the Environment
Mobile banking is susceptible to several risks that the user may be unaware of. Additionally, public hotspots in malls, airports, and cafés in Oman are susceptible to session interception. While the risks are decreased with the use of communication channels, secure communication can be disrupted by misuse of systems or malicious access points.
These risks can be exacerbated by the operating system of the mobile phone being used, as well as deactivated security and downloaded apps. Researchers who log systems have found that a portion of mobile risk comes from the environment, rather than the systems. Users often mistake repetitive slow behaviour, such as slow loading, as normal when, in fact, these are routine risk events.
The Role of Researchers in Highlighting Systemic Deficiencies
Large-scale threat models by Dr. Wafa Farokhi are the basis of mobile banking behaviour analysis. Attack pathways and user mistakes are documented through clustering algorithms. With the aid of dimensionality reduction, threat analysts can consider key factors without overwhelming stakeholders with excessive data.
In Oman’s mobile banking case, these research principles add considerable value. Patterns of user behaviour, as shown in user logs, should include device data interpretation, as it is behaviorally biased. System stress is highlighted through the data field in combination with transaction time, patterns of gestures, app-switching behaviour, and responses to notifications.
Such research contributes to the development of enhanced strategies for public safety. Through the analysis of mobile workflows, interface instructions, and authentication mechanisms, the alignment of user expectations with security needs is also achieved.
Ongoing User-Centric Research Gaps
Even with significant progress, there are still some gaps present that are relevant to doctoral-level research. The first involves context-dependent decision-making: there is little research on situational factors such as heightened environmental stress, time pressure, or new surroundings that influence user decisions when dealing with finances. Another important gap is interpretive dissonance, when users perceive a legitimate warning as a piece of optional noise, and some people seem to ignore it, while others do not. This phenomenon calls for both qualitative and quantitative analysis.
The remaining gap is on the influence of cultural communication patterns on the interpretation of virtual cues. Researchers specializing in the financial behaviour of Oman point out that warning communication is affected by the predominant culture of politeness, indirect reference, and situational trust. Such cultural and linguistic determinants need to be incorporated more thoroughly into mobile security design models.