- 10
- 0
- 约9.36千字
- 约 23页
- 2017-03-09 发布于上海
- 举报
Why Cryptosystems Fail SNU为什么密码失败首尔
*/23 */28 * Why Cryptosystems Fail Ross Anderson Proceeding of the 1st ACM Conference on Computer and Communications Security, 1993 2010-20784 ??? Introduction Information on how cryptosystems fail hard to getdue to secrecy This paper surveys the failure modes of ATM in order to discover out the information After government, the next biggest application is in banking It turns out that the threat model was wrong Most frauds were not caused by cryptanalysis or other technical attacks But by implementation errors and management failures Alternative models are analyzed which we might usefully import into the security domain Safety critical systems Limitation of Cryptology No public feedback about how cryptographic systems fail Their major user have traditionally been government agencies, which are very secretive about their mistakes Difference with most other engineering The flying community has a strong and institutional learning mechanism If an aircraft crashes .. A typical example – phantom withdrawals Nonetheless customers did not withdraw money from an account, there is the withdrawal record on the account Outline Introduction How ATM fraud takes place Simple attacks Complex attacks Discussion The wider implications Why the threat model was wrong Confirmation of our analysis A new security paradigm Conclusion Simple Attacks (1) From inside (by bank staff) Issuing extra cards Recording customer’s PIN and account number, counterfeited cards Using cards which can withdraw money from any customer accounts From outside Observing customers’ PINs standing in ATM queues It can be done because the full account number is printed on the ATM ticket Recording a ‘pay’ response from the bank and keeping on replaying it until the machine is empty Simple Attacks (2) From outside Postal interception 30% of all UK payment card losses Test transaction Outputting 10 banknotes when a 14 digit sequence is entered False terminal Collecting customer card and PIN data Using
您可能关注的文档
- What is Ecommerce 四川外国语大学精品课程建设网站什么是电子商务四川外国语大学精品课程建设网站.ppt
- What is Economics什么是经济学.ppt
- What is driving and enabling it KnujOn什么是驱动使它knujon.ppt
- What is Astronomy Academic Computer Center什么是天文学学术计算机中心.ppt
- What is Geography UCI Humanities什么是人文地理的UCI.ppt
- What is Geography resource什么是地理资源.sbo.accomack.k12.va.us.ppt
- What is geography Harlan Falcons什么是地理哈伦猎鹰.pptx
- What is God University at Buffalo什么是神大学在水牛城.ppt
- What is Government ALEX什么是政府亚历克斯.ppt
- WHAT IS GOVERNMENT Council Rock School District什么是政府议会岩学区.ppt
- 广东省广州省实验中学教育集团2025-2026学年八年级上学期期中考试物理试题(解析版).docx
- 广东省广州大学附属中学2025-2026学年八年级上学期奥班期中物理试题(解析版).docx
- 广东省广州市第八十六中学2025-2026学年八年级上学期期中物理试题(含答案).docx
- 广东省广州市第八十九中学2025-2026学年八年级上学期期中考试物理试题(解析版).docx
- 广东省广州市第二中学2025-2026学年八年级上学期期中考试物理试题(含答案).docx
- 广东省广州市第八十六中学2025-2026学年八年级上学期期中物理试题(解析版).docx
- 广东省广州市第八十九中学2025-2026学年八年级上学期期中考试物理试题(含答案).docx
- 广东省广州市第二中学2025-2026学年八年级上学期期中考试物理试题(解析版).docx
- 2026《中国人寿上海分公司营销员培训体系优化研究》18000字.docx
- 《生物探究性实验教学》中小学教师资格模拟试题.docx
原创力文档

文档评论(0)