首页> 外文会议>Information security solutions Europe conference >Hardened Client Platforms for Secure Internet Banking
【24h】

Hardened Client Platforms for Secure Internet Banking

机译:安全网上银行的硬化客户平台

获取原文
获取外文期刊封面目录资料

摘要

We review the security of e-banking platforms with particular attention to the exploitable attack vectors of three main attack categories: Man-in-the-Middle, Man-in-the-PC and Man-in-the-Browser. It will be shown that the most serious threats come from combination attacks capable of hacking any transaction without the need to control the authentication process. Using this approach, the security of any authentication system can be bypassed, including those using SecureID Tokens, OTP Tokens, Biometric Sensors and Smart Cards. We will describe and compare two recently proposed e-banking platforms, the ZTIC and the USPD, both of which are based on the use of dedicated client devices, but with diverging approaches with respect to the need of hardening the Web client application. It will be shown that the use of a Hardened Browser (or H-Browser) component is critical to force attackers to employ complex and expensive techniques and to reduce the strength and variety of social engineering attacks down to physiological fraud levels.
机译:我们审查了电子银行平台的安全性,特别注意了三个主要攻击类别的可利用攻击载体:中间人,人体,电脑和浏览器。结果表明,最严重的威胁来自能够在任何交易中攻击任何交易的组合攻击,而无需控制身份验证过程。使用这种方法,可以绕过任何认证系统的安全性,包括使用SecureID令牌,OTP令牌,生物识别传感器和智能卡的那些。我们将描述并比较最近提出的两个建议的电子银行平台,ZTIC和USPD,这两者都是基于使用专用客户端设备的使用,但是对于强化Web客户端应用程序的需要,具有发散方法。结果表明,使用硬化的浏览器(或H浏览器)组件对于强迫攻击者采用复杂和昂贵的技术并降低社会工程攻击的强度和各种攻击,以强制攻击者至关重要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号