Attacking of Smart Card-Based Banking Applications with Java']Java Script-Based Rootkits

被引:0
|
作者
Bussmeyer, Daniel [1 ]
Groebert, Felix [1 ]
Schwenk, Joerg [1 ]
Wegener, Christoph [1 ]
机构
[1] Ruhr Univ Bochum, Chair Network & Data Secur, Horst Gortz Inst IT Secur, Bochum, Germany
来源
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to recent attacks on online banking systems and consequent soaring losses through fraud, different methods have been developed to ensure a secure connection between a bank and its customers. One method is the inclusion of smart card readers into these schemes, which come along with different benefits, e.g., convenience and costs, and endangerrnents, especially on the security side. We give a review on a security concept and its implementation deployed as an online banking solution, which consists of a USB smart card reader and a customized browser. We propose a thread model and an attack vector exploiting the limited capabilities of the class one smart card reader. Furthermore a proof of concept malware is presented, which utilizes the primary vulnerability, i.e., class one reader, and otherwise supporting vulnerabilities, to show how transactions may be manipulated.
引用
收藏
页码:320 / 327
页数:8
相关论文
共 50 条
  • [1] Developing smart card-based applications using Java']Java Card
    Vandewalle, JJ
    Vétillard, E
    [J]. SMART CARD RESEARCH AND APPLICATIONS, PROCEEDINGS, 2000, 1820 : 105 - 124
  • [2] Reversing the operating system of a Java']Java based smart card
    Bouffard, Guillaume
    Lanet, Jean-Louis
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2014, 10 (04): : 239 - 253
  • [3] A Java']Java processor suitable for applications of Smart Card
    Zhang, JJ
    Li, FH
    Ge, YQ
    Yue, ZW
    Yang, ZL
    [J]. 2001 4TH INTERNATIONAL CONFERENCE ON ASIC PROCEEDINGS, 2001, : 736 - 739
  • [4] A Java']Java Card Based Approach for Smart Meter Gateway Security
    Piska, Srinivas
    Shetty, Manasa
    [J]. 2013 IEEE INNOVATIVE SMART GRID TECHNOLOGIES - ASIA (ISGT ASIA), 2013,
  • [5] The ultimate control flow transfer in a Java']Java based smart card
    Bouffard, Guillaume
    Lanet, Jean-Louis
    [J]. COMPUTERS & SECURITY, 2015, 50 : 33 - 46
  • [6] An advanced Java']Java Card System architecture for smart card based on large RAM memory
    Yang, Yoon-Sim
    Choi, Won-Ho
    Jin, Min-Sik
    Hwang, Cheul-Jun
    Jung, Min-Soo
    [J]. 2006 INTERNATIONAL CONFERENCE ON HYBRID INFORMATION TECHNOLOGY, VOL 2, PROCEEDINGS, 2006, : 646 - +
  • [7] Type classification against Fault Enabled Mutant in Java']Java based Smart Card
    Dubreuil, Jean
    Bouffard, Guillaume
    Lanet, Jean-Louis
    Cartigny, Julien
    [J]. 2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 551 - 556
  • [8] A multilayered architecture for the development of smart card-based healthcare applications
    Georgoulas, A.
    Giakoumaki, A.
    Koutsouris, D.
    [J]. Proc. Annu. Int. Conf. IEEE Eng. Med. Biol. Soc. EMBS, (1378-1381):
  • [9] A taxonomy of various attacks on smart card-based applications and countermeasures
    Gupta, B. B.
    Quamara, Megha
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2021, 33 (07):
  • [10] Reversing Bytecode of Obfuscated Java']Java Based Smart Card Using Side Chanel Analysis
    Kasmi, Mohammed Amine
    Azizi, Mostafa
    Lanet, Jean-Louis
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (11): : 347 - 356