DocumentCode :
1616379
Title :
Mobile Payment Fraud: A Practical View on the Technical Architecture and Starting Points for Forensic Analysis of New Attack Scenarios
Author :
Kier, Christof ; Madlmayr, Gerald ; Nawratil, Alexander ; Schafferer, Michael ; Schanes, Christian ; Grechenig, Thomas
fYear :
2015
Firstpage :
68
Lastpage :
76
Abstract :
As payment cards and mobile devices are equipped with Near Field Communication (NFC) technology, electronic payment transactions at physical Point of Sale (POS) environments are changing. Payment transactions do not require the customerto insert their card into a slot of the payment terminal. The customer is able to simply swipe the payment card or mobilephone in front of a dedicated zone of the terminal to initiate a payment transaction. Secure Elements (SEs) in mobile phonesand payment cards with NFC should keep sensitive application data in a save place to protect it from abuse by attackers.Although hardware and the operating system of such a chip has to go through an intensive process of security testing, thecurrent integration of such a chip in mobile phones easily allows attackers to access the information stored. In the followingpaper we present the implementation of two different proof-of-concept attacks. Out of the analysis of the attack scenarios, wepropose various starting points for the forensic analysis in order to detect such fraudulent transactions. The presented conceptshould lead to fewer fraudulent transactions as well as protected evidence in case of fraud.
Keywords :
data protection; digital forensics; fraud; mobile computing; near-field communication; smart phones; transaction processing; NFC technology; POS environments; SE; attack scenarios; electronic payment transactions; forensic analysis; fraudulent transaction detection; information access; mobile devices; mobile payment fraud; mobile phone; near field communication technology; payment cards; payment terminal; physical point-of-sale environments; proof-of-concept attacks; secure elements; security testing; sensitive application data protection; Credit cards; Google; ISO Standards; Relays; Security; Smart phones; EMV Payment; Mobile Payment; NFC Transaction; Payment Fraud;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
IT Security Incident Management & IT Forensics (IMF), 2015 Ninth International Conference on
Conference_Location :
Magdeburg
Print_ISBN :
978-1-4799-9902-6
Type :
conf
DOI :
10.1109/IMF.2015.14
Filename :
7195807
Link To Document :
بازگشت