Mobile money platforms have revolutionized financial inclusion across developing economies, yet they remain
highly vulnerable to sophisticated, automated credential-stuffing and unauthorized access attacks. Traditional static PIN
authentication mechanisms often fail to balance robust security with user experience, leaving systems exposed to distributed
brute-force attempts. This paper presents the design and implementation of an adaptive Security Risks Model powered by
a PIN Attempt Monitoring Algorithm (PAMA) to mitigate fraudulent access in real-time mobile money transactions. The
proposed system utilizes a state-machine architecture that continuously ingests transaction metadata, device telemetry, and
temporal patterns to calculate an instantaneous risk score. Unlike rigid, standard threshold-based lockouts, the PAMA
system introduces dynamic, exponential back-off delays and contextual step-up authentication triggers based on the
calculated risk profile. Experimental simulation data demonstrates that the algorithm successfully mitigates up to 94% of
automated brute-force vectors while maintaining zero friction for legitimate users under normal operating parameters. The
architecture proves that pairing deterministic algorithmic monitoring with risk-scoring structures can significantly harden
mobile financial systems against emerging fraud vectors without sacrificing system performance.
Kazeem O. N., Umar Yahaya, Abdul Kareem Jimoh Mayaki et al.· International Journal of Inn...· 0 citations
Ransomware threats continue to evade traditional signature-based security strategies, particularly when
exploiting zero-day attacks, polymorphic methods, and code obfuscation. Rather than relying on static file analysis, the
system continuously manages runtime process behavior by analyzing key indicators of ransomware operation, including file
encryption rates, mass file renaming, entropy fluctuations, registry modifications, and network connections. This dynamic
behavioral analysis enables the timely identification of malicious activities, consequently enhancing the system's capability
to recognize ransomware threats in real time. The identification engine was implemented using React and TypeScript and
uses a configurable, weighted rule-based scoring strategy to classify running processes as either malicious. During simulated
assessments involving well-known ransomware families, including WannaCry, LockBit3, and Ryuk, the application
efficiently differentiated malicious processes from legitimate ones, delivering a identification accuracy of 88.9% while
maintaining a low false-positive rate. In addition, the proposed solution indicated real-time responsiveness, with an average
event update latency of approximately 360 milliseconds. The experimental results show that the behavior-based
identification methods generates more effective coverage against novel, polymorphic, and fileless ransomware threats than
conventional signature-based identification approaches. Based on these results, it is suggested that the behavioral
identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat
containment, increase incident response, and reduce the danger of data loss.
Kazeem O. N., Abdul Kareem Olaitan Mummen, Shamsudeen Sani Saleh· International Journal of Inn...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.