This chapter focuses on attack strategies that can be (and have been) used against financial IT infrastructures. The first section presents an overview and a classification of the different kinds of frauds and attacks carried out against financial institutions and their IT infrastructures. We then restrict our focus by analyzing in detail five attack scenarios, selected among the ones presented in the previous section. These attack scenarios are: Man in the Middle (and its variant, Man in the Browser), distributed denial of service (DDoS), distributed portscan, session hijacking, and malware-based attacks against Internet banking customers. These scenarios have been selected because of their distributed nature: all of them involve multiple, geographically distributed financial institutions. Hence their detection will benefit greatly from the deployment of new technologies and best practices for information sharing and cooperative event processing. For each scenario we present a theoretical description of the attack as well as implementation details and consequences of past attacks carried out against real financial institutions.

Cyber Attacks on Financial Critical Infrastructures / Marchetti, Mirco; Colajanni, Michele; Messori, Michele; L., Aniello; Y., Vigfusson. - STAMPA. - (2012), pp. 53-81. [10.1007/978-3-642-20420-3_3]

Cyber Attacks on Financial Critical Infrastructures

MARCHETTI, Mirco;COLAJANNI, Michele;MESSORI, MICHELE;
2012

Abstract

This chapter focuses on attack strategies that can be (and have been) used against financial IT infrastructures. The first section presents an overview and a classification of the different kinds of frauds and attacks carried out against financial institutions and their IT infrastructures. We then restrict our focus by analyzing in detail five attack scenarios, selected among the ones presented in the previous section. These attack scenarios are: Man in the Middle (and its variant, Man in the Browser), distributed denial of service (DDoS), distributed portscan, session hijacking, and malware-based attacks against Internet banking customers. These scenarios have been selected because of their distributed nature: all of them involve multiple, geographically distributed financial institutions. Hence their detection will benefit greatly from the deployment of new technologies and best practices for information sharing and cooperative event processing. For each scenario we present a theoretical description of the attack as well as implementation details and consequences of past attacks carried out against real financial institutions.
2012
Collaborative Financial Infrastructure Protection: Tools, Abstractions, and Middleware
9783642204197
Springer-Verlag New York Inc
STATI UNITI D'AMERICA
Cyber Attacks on Financial Critical Infrastructures / Marchetti, Mirco; Colajanni, Michele; Messori, Michele; L., Aniello; Y., Vigfusson. - STAMPA. - (2012), pp. 53-81. [10.1007/978-3-642-20420-3_3]
Marchetti, Mirco; Colajanni, Michele; Messori, Michele; L., Aniello; Y., Vigfusson
File in questo prodotto:
Non ci sono file associati a questo prodotto.
Pubblicazioni consigliate

Licenza Creative Commons
I metadati presenti in IRIS UNIMORE sono rilasciati con licenza Creative Commons CC0 1.0 Universal, mentre i file delle pubblicazioni sono rilasciati con licenza Attribuzione 4.0 Internazionale (CC BY 4.0), salvo diversa indicazione.
In caso di violazione di copyright, contattare Supporto Iris

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11380/769013
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 4
  • ???jsp.display-item.citation.isi??? ND
social impact