Countering Replay Attacks

967 Words2 Pages

INDEX

1. Introduction

2. Type of Attack in ATM

3. Replay Attack in ATM

4. Counter Measures for Replay Attack :-RIPSEC Protocol[3]

5. References

Introduction

In present era, with rapid growth of banking and financial system throughout

the world.Currently there are more than 730 million Debit/Card circulating

throughout the world. Evesdroppers or Cyber-thief comes with new

measures/attack to perform fraudulent transactions. It has been very

necessary to come up with the proper security measures in ATM transactions

so that people and banks do not suffer the monetary effect of fraudulent

transactions.

Type of Security Attack in Security transactions

These are the common security threats to online/ATm transactions in the

current scenario :-

1.Denial of Service Attack (DoS) [1] is an attempt to make a machine or

network resource unavailable to its intended users. It generally consists of

efforts to temporarily or indefinitely interrupt or suspend services of

a host connected to the Internet.

2.Man in the middle (MITM)attack in network security is kind of active

eavesdropping in which attacker makes independent connections with the

victims and hence transfers relays messages between them, making them

believe they are talking directly to each other.

Fig 2: Man in the middle attack[2]

3.Pre-Play Attack :- It is a cryptographic attack in which an attacker prepares

for the attack in advance by carrying out a simulated transaction while

pretending to be the device to be attacked, and then repeats the attack a

second time with the real device at a time when it is likely to carry out the

same series of operations as in the simulation. The technique relies on being

able to guess the content of the transaction in advance, something usually

made possible by a poor choice of unpredictability within the system

Replay Attack

A replay attack[3] is when an adversary sends copies of a specific packet or

packets to a host for some malicious purpose. In the case of the ATM and

Bank, this malicious purpose could be to drain the ATM of money, debit an

account to zero dollars, or fraudulently transfer money between accounts.

A replay attack is a form of network attack in which a valid data transmission is

maliciously or fraudulently repeated or delayed. This is carried out either by

Open Document