| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Prevare, povezane z zamenjavo SIM kartic : diplomsko delo visokošolskega študijskega programa Informacijska varnost
Authors:ID Pogačar, Aljoša (Author)
ID Markelj, Blaž (Mentor) More about this mentor... New window
ID Zgaga Markelj, Sabina (Comentor)
Files:.pdf VS_Pogacar_Aljosa_2022.pdf (1,43 MB)
MD5: B011F76676CCBD0E5D9075BB94D4D271
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:SIM swapping je prevara v kibernetskem prostoru, ko storilec dejanja izrabi sicer legitimne procese menjave SIM kartice pri ponudniku mobilnih storitev, da dobi dostop do SIM kartice žrtve in s tem dostop do storitev, katerih delovanje je odvisno od aktivne SIM kartice. Glavna izmed storitev na katero napadalci ciljajo, je prejemanje SMS sporočil, predvsem SMS sporočil, prek katerih uporabnik pridobi enkratna gesla za prijavo v račune, ki so zaščiteni z dvofaktorsko avtentikacijo. Zaradi vse večje uporabe dvofaktorske avtentikacije za prijavo v račune, so ti napadi v porastu. Sama izvedba SIM swappinga pa napadalcu ne pomaga bistveno, če pred tem, s pomočjo metod socialnega inženiringa in uporabo škodljivih programskih kod, ne pridobi prijavnih podatkov o računih, ki so zaščiteni z dvofaktorsko avtentikacijo. Kljub temu, da s pomočjo SIM swappinga in vnaprej pridobiljenih prijavnih podatkov napadalec lahko vdre v vsak račun zaščiten z dvofaktorsko avtentikacijo, pa ima navadno glavna cilja; mobilne banke in kriptodenarnice, saj ima z vdorom in zlorabo teh storitev napadalec največji izkupiček. Sama izvedba napada je sestavljena iz več delov. Največjo vlogo igra žrtev (uporabnik mobilne številke), saj je od njega odvisno, kje objavlja in komu posreduje svoje osebne podatke, s pomočjo katerih se napadalec izdaja za žrtev, da mu izdajo novo SIM kartico. Veliko vlogo pri samem procesu SIM swappinga pa igrajo tudi ponudniki mobilnih storitev. In sicer kot orodje napadalcu za izdajo SIM kartice ter kot obrambni mehanizem pred napadi, saj morajo imeti procese menjav SIM kartic zastavljene na način, da je zloraba teh procesov, pa naj bo menjava v živo, prek telefona ali pa prek self-care portala, praktično nemogoča.
Keywords:SIM kartice, socialni inženiring, diplomske naloge
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:[A. Pogačar]
Year of publishing:2022
Year of performance:2022
Number of pages:IX f., 58 str.
PID:20.500.12556/DKUM-82312 New window
UDC:343.72:621.395.721.5(043.2)
COBISS.SI-ID:122154499 New window
Publication date in DKUM:20.09.2022
Views:886
Downloads:95
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:12.08.2022

Secondary language

Language:English
Title:SIM swapping scams
Abstract:SIM swapping is a scam in cyberspace where an attacker exploits the otherwise legitimate process of SIM card replacement by mobile network operators (MNOs) to gain access to a variety of services requiring an active SIM card. The attackers’ most common target is the reception of short message services (SMS), especially SMS containing one-time passwords (OTPs) for logging into accounts that are protected by two-factor authentication (2FA). Concurrent with the increase in usage of two-factor authentication for logging into accounts, SIM swapping attacks are also on the rise. While SIM swapping by itself does not give the attacker enough information to do any real damage, it is often supplemented with other login data for 2FA-protected accounts, obtained through social engineering and malicious software programs. Even though a successfully completed SIM swapping attack supplemented with pre-obtained login information allows the attacker access to any account protected by two-factor authentication, the main targets of these attacks remain mobile banking apps and crypto wallets, as the hijacking of these types of accounts has proven to be the most profitable. The execution of the attack itself consists of multiple steps. The victim, in this case the user of the mobile number, is the factor that determines the difficulty of the attack, depending on their level of discretion with their personal information and how readily they share it either publicly or privately. Once this information has been obtained by the attacker, it is used to impersonate the victim with the goal of convincing MNOs to issue them a new SIM card. In SIM swapping scams, MNOs also play a crucial role, as they act both as a tool used by the attacker to obtain the victim’s new SIM card, as well as a defence mechanism preventing such scams from succeeding. The MNOs achieve this by setting up the processes of issuing new SIM cards or changing existing SIM cards in a way that makes abuse practically impossible in any form, be it in an exchange in the shop, via phone call or via self-care portal.
Keywords:SIM swapping, two-factor authentication, social engineering


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica