DocumentCode
1616379
Title
Mobile Payment Fraud: A Practical View on the Technical Architecture and Starting Points for Forensic Analysis of New Attack Scenarios
Author
Kier, Christof ; Madlmayr, Gerald ; Nawratil, Alexander ; Schafferer, Michael ; Schanes, Christian ; Grechenig, Thomas
fYear
2015
Firstpage
68
Lastpage
76
Abstract
As payment cards and mobile devices are equipped with Near Field Communication (NFC) technology, electronic payment transactions at physical Point of Sale (POS) environments are changing. Payment transactions do not require the customerto insert their card into a slot of the payment terminal. The customer is able to simply swipe the payment card or mobilephone in front of a dedicated zone of the terminal to initiate a payment transaction. Secure Elements (SEs) in mobile phonesand payment cards with NFC should keep sensitive application data in a save place to protect it from abuse by attackers.Although hardware and the operating system of such a chip has to go through an intensive process of security testing, thecurrent integration of such a chip in mobile phones easily allows attackers to access the information stored. In the followingpaper we present the implementation of two different proof-of-concept attacks. Out of the analysis of the attack scenarios, wepropose various starting points for the forensic analysis in order to detect such fraudulent transactions. The presented conceptshould lead to fewer fraudulent transactions as well as protected evidence in case of fraud.
Keywords
data protection; digital forensics; fraud; mobile computing; near-field communication; smart phones; transaction processing; NFC technology; POS environments; SE; attack scenarios; electronic payment transactions; forensic analysis; fraudulent transaction detection; information access; mobile devices; mobile payment fraud; mobile phone; near field communication technology; payment cards; payment terminal; physical point-of-sale environments; proof-of-concept attacks; secure elements; security testing; sensitive application data protection; Credit cards; Google; ISO Standards; Relays; Security; Smart phones; EMV Payment; Mobile Payment; NFC Transaction; Payment Fraud;
fLanguage
English
Publisher
ieee
Conference_Titel
IT Security Incident Management & IT Forensics (IMF), 2015 Ninth International Conference on
Conference_Location
Magdeburg
Print_ISBN
978-1-4799-9902-6
Type
conf
DOI
10.1109/IMF.2015.14
Filename
7195807
Link To Document