Aspects of Modeling Fraud Prevention of Online Financial Services
نویسنده
چکیده
Banking and online financial services are part of our critical infrastructure. As such, they comprise an Achilles heel in society and need to be protected accordingly. The last ten years have seen a steady shift from traditional show-off hacking towards cybercrime with great economic consequences for society. The different threats against online services are getting worse, and risk management with respect to denial-of-service attacks, phishing, and banking Trojans is now part of the agenda of most financial institutions. This trend is overseen by responsible authorities who step up their minimum requirements for risk management of financial services and, among other things, require regular risk assessment of current and emerging threats. For the financial institution, this situation creates a need to understand all parts of the incident response process of the online services, including the technology, sub-processes, and the resources working with online fraud prevention. The effectiveness of each countermeasure has traditionally been measured for one technology at a time, for example, leaving the fraud prevention manager with separate values for the effectiveness of authentication, intrusion detection, and fraud prevention. In this thesis, we address two problems with this situation. Firstly, there is a need for a tool which is able to model current countermeasures in light of emerging threats. Secondly, the development process of fraud detection is hampered by the lack of accessible data. In the main part of this thesis, we highlight the importance of looking at the “big risk picture” of the incident response process, and not just focusing on one technology at a time. In the first article, we present a tool which makes it possible to measure the effectiveness of the incident response process. We call this an incident response tree (IRT). In the second article, we present additional scenarios relevant for risk management of online financial services using IRTs. Furthermore, we introduce a complementary model which is inspired by existing models used for measuring credit risks. This enables us to compare different online services, using two measures, which we call Expected Fraud and Conditional Fraud Value at Risk. Finally, in the third article, we create a simulation tool which enables us to use scenario-specific results together with models like return of security investment, to support decisions about future security investments. In the second part of the thesis, we develop a method for producing realistic-looking data for testing fraud detection. In the fourth article, we introduce multi-agent based simulations together with social network analysis to create data which can be used to fine-tune fraud prevention, and in the fifth article, we continue this effort by adding a platform for testing fraud detection.
منابع مشابه
Internet Banking Law: An Iranian Perspective Problems and Prospects of Introducing Islamic Microfinance in Azerbaijan Republic
Bank supervision and monetary policy are strategic concepts in the economy of countries. Development of electronic communications, especially in online and international spheres, has largely threatened financial services in view of security and illegal access to banking networks. Anonymity and identity theft has endangered electronic commerce by crimes like phishing, fraud and different types...
متن کاملProviding a Model for Detecting Tax Fraud Based on the Personality Types of Corporate Financial Managers using the Neural Network Approach
One of the management measures to reduce tax liabilities is non-payment of taxes through tax fraud. Because personality factors may play a role in explaining tax ethics, examining personality traits and aspects of tax fraud can help to better understand the factors that influence tax decisions. The main purpose of this study is to provide a model for detecting tax fraud based on the personality...
متن کاملFraudulent Internet Banking Payments Prevention using Dynamic Key
As the Internet becoming popular, many sectors such as banking and other financial institutions are adopting e-services and improving their Internet services. However, the e-service requirements are also opening up new opportunity to commit financial fraud. Internet banking fraud is one of the most serious electronic crimes (e-crimes) and mostly committed by unauthorised users. This paper prese...
متن کاملCombatting Online Fraud in Saudi Arabia Using General Deterrence Theory (GDT)
Online fraud, described as dubious business transactions and deceit carried out electronically, has reached an alarming rate worldwide and has become a major challenge to organizations and governments. In the Gulf region, particularly Saudi Arabia, where there is high Internet penetration and many online financial transactions, the need to put effective measures to deter, prevent and detect onl...
متن کاملStudy of the effect of internal control weaknesses on fraudulent financial reporting risk with considering the moderating role of CEO characteristics
Internal controls play a vital role in prevention of fraud. Internal controls reduce the opportunities for committing fraud. According to information symmetry theory, internal control disclosure the solution is to examine the role of management accountability. To investigate the subject, based on the probit regression model the data related to the variables is analyzed the period from 2013 to ...
متن کامل