DocumentCode
3100604
Title
Leveraging Cellular Infrastructure to Improve Fraud Prevention
Author
Park, Frank S. ; Gangakhedkar, Chinmay ; Traynor, Patrick
Author_Institution
Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
fYear
2009
fDate
7-11 Dec. 2009
Firstpage
350
Lastpage
359
Abstract
The relationship between physical security and critical infrastructure has traditionally been unidirectional - the former being necessary to sustain the latter. However, certain pieces of critical infrastructure hold the potential to significantly improve the security of individuals and their most sensitive information. In this paper, we develop a pair of mechanisms for cellular networks and mobile devices that augment the physical security of their users´ financial credentials. In particular, we create FrauVent, a multi-modal protocol that provides users with information related to a pending questionable transaction (e.g., transaction value, location, vendor) in a way that improves the available context for approving or rejecting such exchanges. Through protocol design, formal verification and implementation of an application for the Android platform, we develop a robust tool to help reduce the costs of fraud without requiring financial institutions to significantly change their extensively deployed end systems (i.e., card readers). More critically, we provide a general framework that allows cellular infrastructure to actively improve the physical security of sensitive information.
Keywords
cellular radio; financial data processing; formal verification; fraud; mobile handsets; protocols; telecommunication security; transaction processing; Android platform; FrauVent; cellular networks; critical infrastructure; financial institutions; formal implementation; formal verification; fraud prevention; mobile devices; multimodal protocol; pending questionable transaction; user financial credentials; Authentication; Computer security; Credit cards; Defense industry; Information security; Land mobile radio cellular systems; Mobile handsets; Protection; Protocols; Robustness; Cellular Networks; Credit Card Authentication; Infrastructure-Assisted Security; Mobile Phones; Multi-factor Authentication;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Security Applications Conference, 2009. ACSAC '09. Annual
Conference_Location
Honolulu, HI
ISSN
1063-9527
Print_ISBN
978-0-7695-3919-5
Type
conf
DOI
10.1109/ACSAC.2009.40
Filename
5380689
Link To Document