Efforts to Secure Efforts to Secure Electronic Financial - - PowerPoint PPT Presentation

efforts to secure efforts to secure electronic financial
SMART_READER_LITE
LIVE PREVIEW

Efforts to Secure Efforts to Secure Electronic Financial - - PowerPoint PPT Presentation

- Case Study - - Case Study - Efforts to Secure Efforts to Secure Electronic Financial Transactions Electronic Financial Transactions in Korea in Korea 2008. 6. 27 2008. 6. 27 20 th FIRST Annual Conference 20 th FIRST Annual Conference


slide-1
SLIDE 1
  • 2008. 6. 27

20th FIRST Annual Conference

  • 2008. 6. 27

20th FIRST Annual Conference

  • Case Study -

Efforts to Secure Electronic Financial Transactions

in Korea

  • Case Study -

Efforts to Secure Electronic Financial Transactions

in Korea

jwchoi@fsa.or.kr jwchoi@fsa.or.kr

slide-2
SLIDE 2
  • 2-

Contents Contents Contents Contents Contents Contents

Introducing FSA & KFCERT Introducing FSA & KFCERT Electronic transactions in Korea Electronic transactions in Korea Incident cases Incident cases

Ⅱ Ⅲ Ⅰ

New threats New threats

Countermeasures & Conclusion Countermeasures & Conclusion

slide-3
SLIDE 3
  • 3-
  • I. Introducing FSA & KFCERT

I.

  • I. Introducing FSA & KFCERT

Introducing FSA & KFCERT

Government decided to set up a organization dedicated to secure electronic financial transactions after the first internet banking incident in may, 2005 It is also decided to operate an integrated OTP center for the financial companies

  • 1. Background
  • 1. Background

FSA is a non-profit organization initiated by government (Financial Services Commission) Established in December, 2006 Has 129 member financial companies including Banks, Security Companies, Credit Card Companies, Insurance Companies and others.

  • 2. FSA
  • 2. FSA
slide-4
SLIDE 4
  • 4-
  • I. Introducing FSA & KFCERT

I.

  • I. Introducing FSA & KFCERT

Introducing FSA & KFCERT

Korea Financial CERT is a part of FSA Response financial incidents and monitors threat information Is a FIRST full member since December, 2007

  • 3. KFCERT
  • 3. KFCERT
  • 4. Organization
  • 4. Organization
slide-5
SLIDE 5
  • 5-
  • I. Introducing FSA & KFCERT

I.

  • I. Introducing FSA & KFCERT

Introducing FSA & KFCERT

  • 2005. 5 : Internet banking incident occurred using keylogger and backdoor for the

first time in Korea 2006.12.21 : Financial Security Agency started its work 2007.1.17 : Joined Anti-Phishing Working Group 2007.1.19 : New pharming incident occurred using malware 2007.1.29 : KFCERT has created 2007.1.31 : Joined CONCERT (CONsortium of CERT)

  • 2007. 2. 9 : Joined Korea National CERT Council

2007.3.27 : Joined MS SCP (Security Cooperation Program) 2007.12.20 : Joined FIRST

  • 5. History
  • 5. History
slide-6
SLIDE 6
  • 6-
  • I. Introducing FSA & KFCERT

I.

  • I. Introducing FSA & KFCERT

Introducing FSA & KFCERT

Support developing security policy and counter plans Incident Response Vulnerability Analysis Penetration Test Product Conformity Test Operate Integrated OTP Center Coordinate other financial companies Cooperate with other security organization and law enforcement

  • 6. Role and Responsibility of FSA
  • 6. Role and Responsibility of FSA
slide-7
SLIDE 7
  • 7-
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

Internet banking users are 47 Million Mobile banking users are 5.7 Million 12 Million digital certificates issued

  • 1. Internet banking in Korea (Number of Users)
  • 1. Internet banking in Korea (Number of Users)

5 10 15 20 25 30 35 40 45 50 Mar 05' Jun Sep Dec Mar 06' Jun Sep Dec Mar 07' Jun Sep Dec Mar 08' Users (Million) * Source : Bank of Korea

slide-8
SLIDE 8
  • 8-

Daily transfers hit 21 Million (Number of Transfers) Daily transfers reach 22 Billion USD (Approx.)

  • 1. Internet banking in Korea (Amount of Transfers)
  • 1. Internet banking in Korea (Amount of Transfers)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

5 10 15 20 25 1Q 2007 2Q 3Q 4Q 1Q 2008 Am

  • unt of Daily Transfe

(Billion)

* Source : Bank of Korea

slide-9
SLIDE 9
  • 9-

CD/ATM’s are the most popular channel Internet banking transactions (transfers) are increasing(24.4%) * Inquiry only in internet banking reaches 56.8%

  • 2. Transaction portion for each channel
  • 2. Transaction portion for each channel

0.0% 5.0% 10.0% 15.0% 20.0% 25.0% 30.0% 35.0% 40.0% 45.0% 50.0% Mar 06' Jun Sep Dec Mar 07' Jun Sep Dec Mar 08' Percentage Offline CD/ATM Tele banking Internet banking

  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

* Source : Bank of Korea

slide-10
SLIDE 10
  • 10-

Anti-Keylog / AntiVirus / Encryption should be provided

  • 3. Security programs in internet banking(1)
  • 3. Security programs in internet banking(1)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

slide-11
SLIDE 11
  • 11-

Digital certificate

  • 3. Security programs in internet banking(2)
  • 3. Security programs in internet banking(2)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

slide-12
SLIDE 12
  • 12-

Security Card (Random Number)

  • 3. Security programs in internet banking(3)
  • 3. Security programs in internet banking(3)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

slide-13
SLIDE 13
  • 13-

OTP (One Time Password) : Valid only for 1 minute

  • 3. Security programs in internet banking(4)
  • 3. Security programs in internet banking(4)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

slide-14
SLIDE 14
  • 14-

Back grounds of Electronic Financial Transaction Act

  • Absence of regulation on the electronic transactions
  • Need customer safeguards due to the increasing incident

. Hard to prove the responsibility for the incident . Heavy responsibility to the customers

  • Rack of supervise to the companies dealing with electronic transactions which is not

a financial company

  • 4. Related Law & Policy(1)
  • 4. Related Law & Policy(1)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

Supervise more electronic financial services More responsibility to the incidents Protect the Customers

slide-15
SLIDE 15
  • 15-

Electronic Financial Transaction Act (Article 9)

  • Financial Institutions are basically responsible for transaction incidents

except the user’s intention and negligence

  • Financial Institutions must prove user’s negligence

Electronic Financial Transaction Act (Article 22)

  • Financial institutions should store related logs to trace and search the transaction

within 5 years

  • 4. Related Law & Policy(2)
  • 4. Related Law & Policy(2)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

slide-16
SLIDE 16
  • 16-

Transaction limit for each security level (08’ April)

  • 4. Related Law & Policy(3)
  • 4. Related Law & Policy(3)
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

A Day A Day Each Each 500,000 500,000 100,000 100,000 OTP + Certificate OTP + Certificate Level 3 Level 3 Level 2 Level 2 Level 1 Level 1 Security Security Level Level Security Card + Certificate Security Card + Certificate Security Card + Certificate Security Card + Certificate + SMS Notice + SMS Notice Security Card + Certificate Security Card + Certificate + 2 Channel Authentication + 2 Channel Authentication HSM(Certificate HSM(Certificate) + Security Card ) + Security Card Security Measure Security Measure 50,000 50,000 10,000 10,000 250,000 250,000 50,000 50,000 Transfer Limit (USD, approximately) Transfer Limit (USD, approximately)

slide-17
SLIDE 17
  • 17-

FSA operates Integrated OTP Authentication center 24x7 55 Financial institutions joined integrated center (19 Banks, 30 Security Companies, etc) Users can use all financial institutions with only one OTP token

  • 5. Integrated OTP Authentication center
  • 5. Integrated OTP Authentication center
  • II. Electronic Transactions in Korea

II.

  • II. Electronic Transactions in Korea

Electronic Transactions in Korea

slide-18
SLIDE 18
  • 18-

Malware distributed through portal site Unpatched PCs are infected, ‘hosts’ file was modified for pharming Host site was storing 4,000 certificates No economical loss due to quick response

1.

  • 1. Pharming

Pharming with Malware (07 with Malware (07’ ’Jan) Jan)

  • III. Incident Cases

III.

  • III. Incident Cases

Incident Cases

slide-19
SLIDE 19
  • 19-

Internet payment system(V3D-Secure) should check CVC code 111 Credit card number were used for 6 month Had about 100,000 USD loss in a institution that didn’t check the CVC Password for the payment were guessed easily

  • 2. Internet payment incident (07
  • 2. Internet payment incident (07’

’Apr) Apr)

  • III. Incident Cases

III.

  • III. Incident Cases

Incident Cases

slide-20
SLIDE 20
  • 20-

ATM owner installed a duplication reader in the ATM Passwords were recorded with hidden camera Stored card information was used to duplicate for fraudulent withdrawal

  • 3. Card Duplication (07
  • 3. Card Duplication (07’

’Apr) Apr)

  • III. Incident Cases

III.

  • III. Incident Cases

Incident Cases

slide-21
SLIDE 21
  • 21-

Malware is also able to alter memory of IE allocation So that the hacker modifies account number which will be transferred But the HTML screen prompts that the transfer was successful Account Number ‘34113014972’ will be changed to the hacker’s account number ‘60504966677’ on clicking ‘OK’.

  • 1. Memory Forgery
  • 1. Memory Forgery
  • IV. New threats

IV.

  • IV. New threats

New threats

[Memory] 0x00123456 : 061-21-1085-102 0x0012345a : ... ... 0x0012347b : ... 34113014972 60504966677

slide-22
SLIDE 22
  • 22-

Almost every online software use ActiveX based on MS Windows COM(component object model) ActiveX is one of the technology that uses COM IUnKnown interface IUnKnown interface can be monitored so that the hacker can forge account information

  • 2. COM Hooking
  • 2. COM Hooking
  • IV. New threats

IV.

  • IV. New threats

New threats

slide-23
SLIDE 23
  • 23-

Even though anti-keylog software protects many key loggers from logging the passwords, new hacking technology bypasses security technology It is necessary to monitor the technology and trends to develop complementary security measures

  • 3. Keyboard Logging
  • 3. Keyboard Logging
  • IV. New threats

IV.

  • IV. New threats

New threats

slide-24
SLIDE 24
  • 24-

Recommend kernel level end-to-end encryption to prevent COM hooking and Memory forgery

  • 1. Countermeasures(1)
  • 1. Countermeasures(1)
  • V. Countermeasures and Conclusion

V.

  • V. Countermeasures and Conclusion

Countermeasures and Conclusion

User Bank

Anti-Keylog PKI

slide-25
SLIDE 25
  • 25-

Research and recommend security solutions such as

  • Two channel authentication
  • Secure keypad
  • Secure image (Captcha)
  • Virtualization
  • 1. Countermeasures(2)
  • 1. Countermeasures(2)
  • V. Countermeasures and Conclusion

V.

  • V. Countermeasures and Conclusion

Countermeasures and Conclusion

8 20 8 18

slide-26
SLIDE 26
  • 26-

There’s no perfect security Consistent efforts to cover the weakness are necessary Emphasis user the importance of security Financial institutions should do their best to care its customer safe Lead PC users to install security patches automatically (50~60% are patched)

  • Produce Flash animations, Patch site for financial customers
  • 2. Conclusion
  • 2. Conclusion
  • V. Countermeasures and Conclusion

V.

  • V. Countermeasures and Conclusion

Countermeasures and Conclusion

slide-27
SLIDE 27
  • 27-

Thank You