{"title":"侦测和预防网上银行系统中可能的未经授权登入企图,透过窃取凭证进行网路钓鱼攻击","authors":"Shammi Ishara Hewamadduma","doi":"10.1109/ICRIIS.2017.8002440","DOIUrl":null,"url":null,"abstract":"With the current technological expansions customers wish to use online banking facilities due to its convenience and worldwide accessibility. The main challenge of going online for a bank is to provide sufficient security for the online customers and their accounts. The dramatic growth of the number of online banking customers has attracted cyber criminals and identity theft is a severe threat to online banking services. Phishing is a famous and easiest method to steal user credential of online customers where the sole intention is to obtain confidential information for the purpose of monetary gain. In such a situation the main purpose of this research paper is to analysis the usage of phishing attacks and the dangers it poses to customers and the bank, then to find out the available methods to detect and prevent unauthorized login attempts, the technologies and security weaknesses of those methods and finally to propose a solution to detect and prevent unauthorized login attempts using behavioral based analysis, IP and device identification technologies.","PeriodicalId":384130,"journal":{"name":"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)","volume":"75 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Detection and prevention of possible unauthorized login attempts through stolen credentials from a phishing attack in an online banking system\",\"authors\":\"Shammi Ishara Hewamadduma\",\"doi\":\"10.1109/ICRIIS.2017.8002440\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"With the current technological expansions customers wish to use online banking facilities due to its convenience and worldwide accessibility. The main challenge of going online for a bank is to provide sufficient security for the online customers and their accounts. The dramatic growth of the number of online banking customers has attracted cyber criminals and identity theft is a severe threat to online banking services. Phishing is a famous and easiest method to steal user credential of online customers where the sole intention is to obtain confidential information for the purpose of monetary gain. In such a situation the main purpose of this research paper is to analysis the usage of phishing attacks and the dangers it poses to customers and the bank, then to find out the available methods to detect and prevent unauthorized login attempts, the technologies and security weaknesses of those methods and finally to propose a solution to detect and prevent unauthorized login attempts using behavioral based analysis, IP and device identification technologies.\",\"PeriodicalId\":384130,\"journal\":{\"name\":\"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)\",\"volume\":\"75 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-07-16\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICRIIS.2017.8002440\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICRIIS.2017.8002440","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Detection and prevention of possible unauthorized login attempts through stolen credentials from a phishing attack in an online banking system
With the current technological expansions customers wish to use online banking facilities due to its convenience and worldwide accessibility. The main challenge of going online for a bank is to provide sufficient security for the online customers and their accounts. The dramatic growth of the number of online banking customers has attracted cyber criminals and identity theft is a severe threat to online banking services. Phishing is a famous and easiest method to steal user credential of online customers where the sole intention is to obtain confidential information for the purpose of monetary gain. In such a situation the main purpose of this research paper is to analysis the usage of phishing attacks and the dangers it poses to customers and the bank, then to find out the available methods to detect and prevent unauthorized login attempts, the technologies and security weaknesses of those methods and finally to propose a solution to detect and prevent unauthorized login attempts using behavioral based analysis, IP and device identification technologies.