The Vulnerability Analysis of CA Arcot VPS

Sangho Lee, Sung‐Ho Kim, Dea-Hun Nyang, Kyung-Hee Lee · 정보보호학회논문지 · 2013

미국의 Arcot사는 가상 세션을 이용하여 트랜잭션 변경 사항을 표시하는 안전한 온라인 금융 거래 서비스 솔루션을 판매 중이며, 해당 기술의 특허를 출원 중이다. 하지만 VPS(Virtual Private Session)가 제공하는 캡챠의 구성 방식에 의해 취약점을 갖는다. VPS가 제공하는 캡챠는 색상정보를 이용한 공격이 가능함을 보였고, 이는 VPS 또한 안전성을 확신할 수 없음을 시사한다. 이 논문에서는 VPS의 공격 방법을 제시하고 유사 VPS를 만들어 앞서 제시한 방법으로 모의 공격을 통한 취약점을 알아본다. CA Arcot corporation in U.S.A has secure on-line financial trade solution and patent that verify whether transaction had change using virtual session. But, VPS(Virtual Private Session) has another vulnerability by way to construct CAPTCHA. We can't fully trust safety of VPS, Cause it could be attacked by using color information of CAPTCHA. In this paper, We suggest the method of attack VPS, and also point out the vulnerability of VPS though simulation.

Read the paper · More papers on PaperTik