An exprimental investigation of the usability of transaction authorization in online bank security systems

  • Authors:
  • Mohammed AlZomai;Bander AlFayyadh;Audun Jøsang;Adrian McCullagh

  • Affiliations:
  • Queensland University of Technology, Brisbane, Australia;Queensland University of Technology, Brisbane, Australia;Queensland University of Technology, Brisbane, Australia;Queensland University of Technology, Brisbane, Australia

  • Venue:
  • AISC '08 Proceedings of the sixth Australasian conference on Information security - Volume 81
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security for online banking has changed considerably during the relatively short period that online banking has been in use. In particular, authentication and identity management in the early implementations were, and sometimes still are, vulnerable to various attacks such as phishing. Current state-of-the art solutions include methods for re-authenticating users via out-of-band channels for each transaction. This paper describes a security investigation of this type of solution. The investigation concludes that it protects against certain attacks while still being vulnerable to other obvious attacks. In the near future, it is expected that the remaining vulnerabilities will be exploited as the attackers get more sophisticated. Possible ways of protecting against these future attacks are outlined.