| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Uporaba smishinga v bančništvu : diplomsko delo visokošolskega študijskega programa Informacijska varnost
Authors:ID Zorko, Domen (Author)
ID Markelj, Blaž (Mentor) More about this mentor... New window
Files:.pdf VS_Zorko_Domen_2023.pdf (1,15 MB)
MD5: BC8C9BC8FC61B698B291A83BBCD43B2E
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:Smishing si kot oblika kibernetskega napada deli s phishingom skupne značilnosti, vendar se razlikuje po tem, da se izvaja preko SMS-sporočil. Napadalci, ki se odločijo uporabljati metodo smishinga, uporabljajo strategije napadov socialnega inženiringa, s ciljem, da uporabniku pošljejo sporočilo, ki vzbuja občutek nujnosti in strahu, v upanju, da povzročijo dovolj stresa, da žrtev uboga napadalca takoj in brez pomisleka. Glavni namen napadalcev je večinoma pridobitev osebnih podatkov, poverilnic, finančnih podatkov ter vodenje žrtev na zlonamerne spletne strani. Pri smishing napadih kriminalci pogosto uporabljajo SMS-spoofing, ki je ključni dejavnik pri uspešnosti smishinga še posebej v kontekstu mobilnega bančništva, ki ga dandanes uporablja večina posameznikov, ki ima v lasti mobilno naprava. Zaradi visokega števila uporabnikov in možnosti kraje denarja so mobilne banke privlačna tarča za kibernetski kriminal. Napadalci se zavedajo dejstva, da banka s svojimi tehničnimi sredstvi ni zmožna povsem odpraviti človeških napak. Zaradi tega je preprečitev smishing napadov velik izziv, ki zahteva celovit pristop. Ta pristop mora vključevati več elementov obrambe, kot so izobraževanje uporabnikov o obstoju in nevarnostih smishinga, implementacija tehničnih sredstev za prepoznavanje ter blokiranje smishing sporočil ter sodelovanje med bankami in varnostnimi strokovnjaki. Izobraževanje uporabnikov je najpomembnejše, saj lahko samo uporabnik, ki je bil poučen o odkrivanju smishinga, zanesljivo prepozna neobičajne načine komunikacije. Preprečevanje smishinga je razvijajoč problem, ki bo zahteval neprestano učenje in prilagajanje novih ukrepov.
Keywords:smishing, bančništvo, socialni inženiring, diplomske naloge
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:D. Zorko
Year of publishing:2023
Year of performance:2023
Number of pages:VIII f., [58] str.
PID:20.500.12556/DKUM-86556 New window
UDC:004.056.53(043.2)
COBISS.SI-ID:179687171 New window
Publication date in DKUM:05.01.2024
Views:873
Downloads:171
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:12.12.2023

Secondary language

Language:English
Title:The use of smishing in banking
Abstract:Smishing is a type of cyber attack that shares common characteristics with phishing in terms of attack methods. The main difference is that it is sent from an SMS message. In smishing, attackers use social engineering attack strategies by sending a message to the user that aims to instill a sense of urgency and fear in the user, causing them to obey the attacker immediately and without hesitations due to stress. The goal of attackers is ususally to obtain personal data, credentials, financial data and lead victims to malicious websites. In smishing attacks, criminals ofter use SMS spoofing, which is one of the key factors in the success of smishing, especially in the context of mobile banking, which is used by the majority of people these days. Due to the number of users and the possibility of stealing money, mobile banks are a particularly attractive target for attackers. Attackers are aware of the fact that a bank cannot overcome human error entirely with just technical means, so the prevention of smishing requires a comprehensive approach that includes a combination of user education, technical solutions and cooperation with banks and security experts.
Keywords:Smishing, banking, social engineering


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica