• DocumentCode
    3100604
  • Title

    Leveraging Cellular Infrastructure to Improve Fraud Prevention

  • Author

    Park, Frank S. ; Gangakhedkar, Chinmay ; Traynor, Patrick

  • Author_Institution
    Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    350
  • Lastpage
    359
  • Abstract
    The relationship between physical security and critical infrastructure has traditionally been unidirectional - the former being necessary to sustain the latter. However, certain pieces of critical infrastructure hold the potential to significantly improve the security of individuals and their most sensitive information. In this paper, we develop a pair of mechanisms for cellular networks and mobile devices that augment the physical security of their users´ financial credentials. In particular, we create FrauVent, a multi-modal protocol that provides users with information related to a pending questionable transaction (e.g., transaction value, location, vendor) in a way that improves the available context for approving or rejecting such exchanges. Through protocol design, formal verification and implementation of an application for the Android platform, we develop a robust tool to help reduce the costs of fraud without requiring financial institutions to significantly change their extensively deployed end systems (i.e., card readers). More critically, we provide a general framework that allows cellular infrastructure to actively improve the physical security of sensitive information.
  • Keywords
    cellular radio; financial data processing; formal verification; fraud; mobile handsets; protocols; telecommunication security; transaction processing; Android platform; FrauVent; cellular networks; critical infrastructure; financial institutions; formal implementation; formal verification; fraud prevention; mobile devices; multimodal protocol; pending questionable transaction; user financial credentials; Authentication; Computer security; Credit cards; Defense industry; Information security; Land mobile radio cellular systems; Mobile handsets; Protection; Protocols; Robustness; Cellular Networks; Credit Card Authentication; Infrastructure-Assisted Security; Mobile Phones; Multi-factor Authentication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2009. ACSAC '09. Annual
  • Conference_Location
    Honolulu, HI
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3919-5
  • Type

    conf

  • DOI
    10.1109/ACSAC.2009.40
  • Filename
    5380689