首页> 外文会议>National Cyber Summit >Taming the Digital Bandits: An Analysis of Digital Bank Heists and a System for Detecting Fake Messages in Electronic Funds Transfer
【24h】

Taming the Digital Bandits: An Analysis of Digital Bank Heists and a System for Detecting Fake Messages in Electronic Funds Transfer

机译:驯服数字匪徒:数字银行鹤的分析和用于检测电子资金转移中的假信息的系统

获取原文

摘要

In recent years, financial crimes and large scale heists involving the banking sector have significantly increased. Banks and Financial Institutions form the economic and commercial backbone of a country. An essential function of banks is the transfer of funds domestically or internationally. Most banks today transfer money by using electronic fund transfer systems such as the Automated Clearing House (ACH) or messaging systems such as SWIFT, FedWire, Ripple, etc. However, vulnerabilities in the use of such systems expose banks to digital heists. For example, the 2016 heist in the central bank of Bangladesh used the SWIFT network to send fake messages. It almost resulted in the theft of nearly $1 billion, which is one-sixth of the total foreign currency reserve of Bangladesh. Similar attacks have happened in many other countries as well. In this paper, we discussed multiple such incidents. From those incidents, we systematically analyze two such events - the Bangladesh Bank heist and the DNS takeover of Brazilian banks - to understand the nature and characteristics of such attacks. Through our analysis, we identify common and critical security flaws in the current banking and messaging infrastructures and develop the desired security properties of an electronic funds transfer system.
机译:近年来,金融犯罪和涉及银行业的大规模哈斯特大幅增加。银行和金融机构构成了一个国家的经济和商业骨干。银行的基本职能是在国内或国际上转移资金。今天大多数银行通过使用自动化结算房屋(ACH)或消息传递系统(如SWIFT,FEDWIRE,RIPPLE等)的电子基金转移系统来转移资金,但是,在使用此类系统时漏洞将银行暴露给数字哈及者。例如,2016年孟加拉国央行的2016年赫斯特使用SWIFT网络发送假消息。它几乎导致了近10亿美元的盗窃,这是孟加拉国外币总额的六分之一。许多其他国家也发生了类似的攻击。在本文中,我们讨论了多个这样的事件。从那些事件中,我们系统地分析了两项这样的事件 - 孟加拉国银行赫斯特和巴西银行的DNS接管 - 了解此类攻击的性质和特征。通过我们的分析,我们确定当前银行业务和消息传递基础设施中的共同和严重的安全漏洞,并开发了电子资金转移系统的所需安全性质。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号