• DocumentCode
    2162223
  • Title

    Averting man in the browser attack using user-specific personal images

  • Author

    Goyal, Puneet ; Bansal, N. ; Gupta, Neeraj

  • Author_Institution
    Dept. of CSE, Graphic Era Univ., Dehradun, India
  • fYear
    2013
  • fDate
    22-23 Feb. 2013
  • Firstpage
    1283
  • Lastpage
    1286
  • Abstract
    In the recent years, there has been a tremendous rise in online banking transactions. Some of the major factors contributing to this growth are - easy availability of higher bandwidth internet connections at low cost and ease of online transactions compared to the traditional banking methods. Also, this field has attracted the cybercriminals to take advantage of the loopholes in the process of online transaction. One of the most advanced threats today is the Man In The Browser (MitB) attack. MitB attack deploys a Trojan in the browser of the user and then steals the credentials of the user to initiate a transaction for transferring the money in a mule account. All this happens without any notice to bank or the user. MitB attack defeats the traditional two factor authentication currently used by the banks to authenticate the identity of the user performing the transaction. This paper presents a new framework for enhancing authentication during an online transaction to tackle the problem of MitB attack.
  • Keywords
    Internet; authorisation; bank data processing; computer crime; image processing; invasive software; message authentication; MitB attack; Trojan; bandwidth Internet connection; cybercriminal; identity authentication; image processing; man in the browser attack; money transfer; mule account; online banking transaction; online transaction loophole; security; threat; two factor authentication; user credential; user-specific personal image; Authentication; Browsers; Mobile communication; Online banking; Servers; Trojan horses; Image processing; Internet Banking; MitB; MitM; One Time Passcodes(OTP); Out-of-Band(OOB) Authentication; Security; Zeus Trojan;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advance Computing Conference (IACC), 2013 IEEE 3rd International
  • Conference_Location
    Ghaziabad
  • Print_ISBN
    978-1-4673-4527-9
  • Type

    conf

  • DOI
    10.1109/IAdCC.2013.6514413
  • Filename
    6514413