首页> 外文期刊>Multimedia Tools and Applications >Case study of the vulnerability of OTP implemented in internet banking systems of South Korea
【24h】

Case study of the vulnerability of OTP implemented in internet banking systems of South Korea

机译:在韩国的网上银行系统中实施OTP漏洞的案例研究

获取原文
获取原文并翻译 | 示例
           

摘要

The security risk of internet banking has increased rapidly as internet banking services have become commonly used by the public. Among the various security methods, OTP (one time password) is known as one of the strongest methods for enforcing security, and it is now widely used in internet banking services. However, attack methods which can detour OTP have been developed that additional security for OTP is now needed. In this study, we discovered that a new kind of attack through OTP is theoretically possible through an analysis of the currently implemented OTP system and known attack methods. Based on our theory, we tested the new attack method on Korean internet banking services, and empirically proved that it could effectively detour around all of the currently implemented OTP security systems in Korea. To prevent this, we also suggested solutions based on the root cause analysis of the OTP vulnerabilities.
机译:随着互联网银行服务已被公众广泛使用,互联网银行的安全风险迅速增加。在各种安全方法中,OTP(一次性密码)被认为是实施安全性最强的方法之一,现在已广泛用于网上银行服务。但是,已经开发出可以绕过OTP的攻击方法,现在需要针对OTP的附加安全性。在这项研究中,我们发现通过分析当前实施的OTP系统和已知的攻击方法,理论上可以通过OTP进行新型攻击。根据我们的理论,我们测试了针对韩国互联网银行服务的新攻击方法,并通过经验证明了该方法可以有效绕开韩国目前所有已实施的OTP安全系统。为防止这种情况,我们还建议根据OTP漏洞的根本原因分析提出解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号