An exprimental investigation of the usability of transaction authorization in online bank security systems

Mohammed Alzomai, Bander AlFayyadh, Audun Jøsang, Adrian McCullagh · NORA - Norwegian Open Research Archives · 2008

Security for online banking has changed considerably during the relatively short period that online banking has been in use.In particular, authentication and identity management in the early implementations were, and sometimes still are, vulnerable to various attacks such as phishing.Current state-of-the art solutions include methods for re-authenticating users via out-of-band channels for each transaction.This paper describes a security investigation of this type of solution.The investigation concludes that it protects against certain attacks while still being vulnerable to other obvious attacks.In the near future, it is expected that the remaining vulnerabilities will be exploited as the attackers get more sophisticated.Possible ways of protecting against these future attacks are outlined.

Read the paper · More papers on PaperTik