DocumentCode
2295182
Title
A Model for Securing E-Banking Authentication Process: Antiphishing Approach
Author
Martino, Antonio San ; Perramon, Xavier
fYear
2008
fDate
6-11 July 2008
Firstpage
251
Lastpage
254
Abstract
This paper presents the authentication environment defined for securing e-banking applications. The proposed method is part of a Phd Doctoral thesis aimed at defining a model for secure operation of an Internet banking environment, even in the presence of malware on the client side. The authentication model has been designed to be easily applicable with minimum impact to the current Internet banking systems. Its goal is to be resistant to the nowadays too frequent phishing and pharming attacks, and also to more classical ones like social engineering or man-in-the-middle attacks. The key point of this model is the need for multi factor mutual authentication, instead of simply basing the security on the digital certificate of the financial entity, since in many cases users are not able to discern the validity of a certificate, and may not even pay attention to it. By following the rules defined in this proposal, the security level of the Web banking environment will increase and customerspsila trust will be enhanced, thus allowing a more beneficial use of this service.
Keywords
banking; security of data; Internet banking environment; Web banking environment; antiphishing approach; e-banking authentication process; e-banking security; malware; man-in-the-middle attacks; pharming attacks; Authentication; Banking; Data security; Guidelines; IEC standards; ISO standards; Information security; Internet; Proposals; Protection; E_Banking; antiphishing; authentication; phishing;
fLanguage
English
Publisher
ieee
Conference_Titel
Services - Part I, 2008. IEEE Congress on
Conference_Location
Honolulu, HI
Print_ISBN
978-0-7695-3286-8
Type
conf
DOI
10.1109/SERVICES-1.2008.32
Filename
4578332
Link To Document