A Proactive Measure for Confronting ATM Threats using FingerEye

Abiodun Esther Omolara, Aman Jantan, Abiodun Esther Omolara, Nachaat AbdElatif Mohamed · Indonesian Journal of Electrical Engineering and Computer Science · 2019

The rapid surge of customers using A utomated T eller M achine (ATM) for carrying out their da y-to-day banking transaction has created an avenue for criminals to perpetrate numerous crimes. The tumultuous increase in bank security breaches using eavesdropping attack, man-in-the-middle attack, shoulder-surfing has risen great concerns. A predominant point often exploited for an attack is during the authentication stage where a customer may be entering his login information on the ATM and an attacker may use direct observation techniques, such as looking over the customer 's shoulder to steal his passwords, PINs or other sensitive individual details. Existing authentication mechanism employs the tradi tional password-based authentication system which fails to curb such attacks. To address this problem, this paper proposes the FingerEye approach. In the FingerEye approach, a software is designed which is integrated with iris - scan authentication. A customer’s profile is created at the registration phase where the picture of his eyes is taken and the pattern in the iris is analyzed and convert ed into binary codes. The binary codes are then stored in the bank database and are required in the next phase for verification prior to any transaction. A customer that needs to perform any ATM transaction needs to authenticate using his iris . He looks at the camera in front of the ATM. A picture of his eye is taken and the details of his iris are extracted and converted to a binary code which is then compared with the one in the bank database. Once a match is detected, he is authenticated automatically otherwise his authentication is rejected. We leverage on the iris because every user has unique eyes which do not change until death and even a blind person with iris can be authenticated too. We implemented and tested this system using CIMB bank, Malaysia as a case study. We integrated the FingerEye with the current infrastructure employed by the bank and as such, no extra cost was incurred. Our result demonstrates that transactions were executed faster and eavesdropping attack, shoulder-surfing attack by a malicious observer becomes impractical.

Read the paper · More papers on PaperTik