A novel security scheme for online banking based on virtual machine

Bei Guan, Yanjun Wu, Yongji Wang

Research output: Chapter in Book/Report/Conference proceedingConference contribution

1 Citation (Scopus)

Abstract

Current online banking scheme built on ordinary software stack, which comprises of the operating system and its applications running on it, is facing attacks including Phishing, Pharming, Malicious Software Attacks (MSW), Man in the Middle Attacks (MITM) and Keylogger. Today's countermeasures either prevent only part of these attacks or have high cost on performance and usability. In this paper, we introduce the Domain Online Banking (DOBank), a novel security scheme for online banking that combines the virtual machine (VM) technology with web services. Firstly, DOBank encapsulates the banking service into a lightweight domain and protects it from any attacks caused by virus from the user's host. Secondly, the domain can access certain hardware devices exclusively against Keylogger and gains nearly native performance using the passthrough technology. Finally, we use the virtual Trusted Platform Module (vTPM) for the online banking domain's integrity verification as well as the SSL/TLS (Security Sockets Layer/Transport Layer Security) protocol for the confidentiality of data transaction over the internet. We show that this scheme is secure enough to prevent typical viruses that threaten the online banking. The experiments on the network throughput and the time consumed of integrity measurement show it adds little overhead to the overall system.

Original languageEnglish
Title of host publicationProceedings of the 2012 IEEE 6th International Conference on Software Security and Reliability Companion, SERE-C 2012
Pages12-17
Number of pages6
DOIs
Publication statusPublished - 5 Oct 2012
Event2012 IEEE 6th International Conference on Software Security and Reliability Companion, SERE-C 2012 - Gaithersburg, MD, United States
Duration: 20 Jun 201222 Jun 2012

Publication series

NameProceedings of the 2012 IEEE 6th International Conference on Software Security and Reliability Companion, SERE-C 2012

Other

Other2012 IEEE 6th International Conference on Software Security and Reliability Companion, SERE-C 2012
CountryUnited States
CityGaithersburg, MD
Period20/6/1222/6/12

    Fingerprint

Keywords

  • Online banking
  • Security
  • Virtual machine
  • Virtualization
  • Web service
  • Xen

ASJC Scopus subject areas

  • Software
  • Safety, Risk, Reliability and Quality

Cite this

Guan, B., Wu, Y., & Wang, Y. (2012). A novel security scheme for online banking based on virtual machine. In Proceedings of the 2012 IEEE 6th International Conference on Software Security and Reliability Companion, SERE-C 2012 (pp. 12-17). [6258439] (Proceedings of the 2012 IEEE 6th International Conference on Software Security and Reliability Companion, SERE-C 2012). https://doi.org/10.1109/SERE-C.2012.28