首页> 外文学位 >Security Design Flaws that Affect Usability in Online Banking.
【24h】

Security Design Flaws that Affect Usability in Online Banking.

机译:影响在线银行可用性的安全设计缺陷。

获取原文
获取原文并翻译 | 示例

摘要

As the popularity of online banking Websites has increased, the security of these sites has become increasingly critical as attacks against these sites are on the rise. However, the design decisions made during construction of the sites could make usability more difficult, where the user has difficulty making good security decisions. This study analyzed 6 design flaws of this nature: (a) a break in the chain of trust, (b) providing a secure login method on an unsecure page, (c) providing bank contact information or security advice on an unsecure page, (d) having policies that are insufficient for userids and passwords, (e) generating e-mails containing sensitive information that are sent in an unsecure manner, and (f) the multi-factor authentication solution consisting of the presentation of an image in combination with the userid and password. Each of these flaws can lead to security and usability issues. Analysis of 80 banking sites was performed to determine the frequency of the flaws. The sampling of banking institutions was determined from banking institution lists available from the Federal Deposit Insurance Corporation (FDIC). Banking institutions were selected from 5 bank charter classes. The banking sites were downloaded for static analysis. The analysis was performed through a combination of automated programs and manual review. The results found instances of all 6 design flaws. The most prevalent issue found was insufficient policies for userids and passwords. The second most prevalent design flaw was the break in the chain of trust. The design flaw with the smallest number of occurrences was emailing sensitive information in an unsecure manner. The banking charter class of the banking institution did not appear to have a relationship to the frequency of the flaws. However, it appears that banking institutions with a smaller asset size have a higher frequency of the flaws than those with a larger asset size. It is recommended that banking institutions address these design flaws to improve usability for their customers while improving security.
机译:随着在线银行网站的普及,这些站点的安全性也变得越来越重要,因为对这些站点的攻击越来越多。但是,在站点建设期间做出的设计决策可能会使可用性更加困难,因为用户很难做出良好的安全决策。这项研究分析了这种性质的6个设计缺陷:(a)信任链断裂,(b)在不安全的页面上提供安全的登录方法,(c)在不安全的页面上提供银行的联系信息或安全建议,( d)具有不足以提供用户名和密码的策略,(e)生成包含以不安全方式发送的敏感信息的电子邮件,以及(f)包含图像呈现与用户名和密码。这些缺陷中的每一个都会导致安全性和可用性问题。对80个银行站点进行了分析,以确定漏洞的发生频率。银行机构的抽样是根据可从联邦存款保险公司(FDIC)获得的银行机构清单确定的。银行机构是从5个银行宪章类别中选出的。下载了银行网站以进行静态分析。通过自动化程序和手动审查的组合进行分析。结果发现了所有6个设计缺陷的实例。发现的最普遍的问题是用户名和密码的策略不足。第二个最普遍的设计缺陷是信任链断裂。出现次数最少的设计缺陷是以不安全的方式通过电子邮件发送敏感信息。银行机构的银行宪章阶层似乎与漏洞发生的频率没有关系。但是,似乎资产规模较小的银行机构比资产规模较大的银行出现漏洞的频率更高。建议银行机构解决这些设计缺陷,以提高其客户的可用性,同时提高安全性。

著录项

  • 作者

    Gurlen, Stephanie.;

  • 作者单位

    Nova Southeastern University.;

  • 授予单位 Nova Southeastern University.;
  • 学科 Engineering Computer.;Information Technology.
  • 学位 Ph.D.
  • 年度 2013
  • 页码 106 p.
  • 总页数 106
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号