The Experts below are selected from a list of 3990 Experts worldwide ranked by ideXlab platform

Tzicker Chiueh - One of the best experts on this subject based on the ideXlab platform.

  • tracking Payment Card Data flow using virtual machine state introspection
    Annual Computer Security Applications Conference, 2011
    Co-Authors: Jennia Hizver, Tzicker Chiueh
    Abstract:

    Credit and debit Card Payment processing systems are key elements in financial transactions. Negligence in securing these systems makes them vulnerable to hacking attacks, which may lead to significant monetary losses for both merchants and the financial organizations. To reduce this risk, mandatory security compliance regulations, such as the Payment Card Industry Data Security Standard (PCI DSS), were developed and adopted by the industry. A key pre-requisite of the PCI DSS compliance process is the ability to identify the components of the Payment systems directly involved with the Card Data (i.e. process, transmit, or store). However, existing Data flow tracking tools cannot fully automate the process of identifying system components that touch Card Data, because they either can not examine encrypted communications or they use an instrumentation-based approach and thus require a priori detailed knowledge of the Payment Card processing systems. We describe the implementation and evaluation of a novel tool to identify the Card Data flow in commercial Payment Card processing systems running on virtualized servers. The tool performs realtime monitoring of network communications between virtual machines and inspects the memory of the communicating processes for unencrypted Card Data. Our implementation does not require instrumentation of application binaries and can accurately identify the system components involved in Card Data flow even when the communications among system components are encrypted. Effectiveness of this tool is demonstrated through its successful discovery of the Card Data flow of several open- and closed-source Payment Card processing applications.

  • ACSAC - Tracking Payment Card Data flow using virtual machine state introspection
    Proceedings of the 27th Annual Computer Security Applications Conference on - ACSAC '11, 2011
    Co-Authors: Jennia Hizver, Tzicker Chiueh
    Abstract:

    Credit and debit Card Payment processing systems are key elements in financial transactions. Negligence in securing these systems makes them vulnerable to hacking attacks, which may lead to significant monetary losses for both merchants and the financial organizations. To reduce this risk, mandatory security compliance regulations, such as the Payment Card Industry Data Security Standard (PCI DSS), were developed and adopted by the industry. A key pre-requisite of the PCI DSS compliance process is the ability to identify the components of the Payment systems directly involved with the Card Data (i.e. process, transmit, or store). However, existing Data flow tracking tools cannot fully automate the process of identifying system components that touch Card Data, because they either can not examine encrypted communications or they use an instrumentation-based approach and thus require a priori detailed knowledge of the Payment Card processing systems. We describe the implementation and evaluation of a novel tool to identify the Card Data flow in commercial Payment Card processing systems running on virtualized servers. The tool performs realtime monitoring of network communications between virtual machines and inspects the memory of the communicating processes for unencrypted Card Data. Our implementation does not require instrumentation of application binaries and can accurately identify the system components involved in Card Data flow even when the communications among system components are encrypted. Effectiveness of this tool is demonstrated through its successful discovery of the Card Data flow of several open- and closed-source Payment Card processing applications.

Vikas Singh - One of the best experts on this subject based on the ideXlab platform.

  • A survey of Payment Card industry Data security standard
    IEEE Communications Surveys and Tutorials, 2010
    Co-Authors: Jing Liu, Srinivas Dodle, Suat Özdemir, Yang Xiao, Hui Chen, Vikas Singh
    Abstract:

    Usage of Payment Cards such as credit Cards, debit Cards, and prepaid Cards, continues to grow. Security breaches related to Payment Cards have led to billion dollar losses annually. In order to offset this trend, major Payment Card networks have founded the Payment Card Industry (PCI) Security Standards Council (SSC), which has designed and released the PCI Data Security Standard (DSS). This standard guides service providers and merchants to implement stronger security infrastructures that reduce the risks of security breaches. This article mainly discusses the need for the PCI DSS and the Data security requirements defined in the standard to address the ongoing security issues, especially those pertaining to Payment Card Data handling. It also surveys various technical solutions, offered by a few security vendors, for merchant companies and organizations involved in Payment Card transaction processing to comply with the standard. The compliance of merchants or service providers to the PCI DSS are assessed by PCI Qualified Security Assessors (QSAs). This article thus discusses the requirements to become PCI QSAs. In addition, it introduces the PCI security scanning procedures that guide the scanning of security policies of a merchant or service provider and prepare relevant reports. We believe that this survey sheds light on potential technical research problems pertinent to the PCI DSS and its compliance.

Jennia Hizver - One of the best experts on this subject based on the ideXlab platform.

  • tracking Payment Card Data flow using virtual machine state introspection
    Annual Computer Security Applications Conference, 2011
    Co-Authors: Jennia Hizver, Tzicker Chiueh
    Abstract:

    Credit and debit Card Payment processing systems are key elements in financial transactions. Negligence in securing these systems makes them vulnerable to hacking attacks, which may lead to significant monetary losses for both merchants and the financial organizations. To reduce this risk, mandatory security compliance regulations, such as the Payment Card Industry Data Security Standard (PCI DSS), were developed and adopted by the industry. A key pre-requisite of the PCI DSS compliance process is the ability to identify the components of the Payment systems directly involved with the Card Data (i.e. process, transmit, or store). However, existing Data flow tracking tools cannot fully automate the process of identifying system components that touch Card Data, because they either can not examine encrypted communications or they use an instrumentation-based approach and thus require a priori detailed knowledge of the Payment Card processing systems. We describe the implementation and evaluation of a novel tool to identify the Card Data flow in commercial Payment Card processing systems running on virtualized servers. The tool performs realtime monitoring of network communications between virtual machines and inspects the memory of the communicating processes for unencrypted Card Data. Our implementation does not require instrumentation of application binaries and can accurately identify the system components involved in Card Data flow even when the communications among system components are encrypted. Effectiveness of this tool is demonstrated through its successful discovery of the Card Data flow of several open- and closed-source Payment Card processing applications.

  • ACSAC - Tracking Payment Card Data flow using virtual machine state introspection
    Proceedings of the 27th Annual Computer Security Applications Conference on - ACSAC '11, 2011
    Co-Authors: Jennia Hizver, Tzicker Chiueh
    Abstract:

    Credit and debit Card Payment processing systems are key elements in financial transactions. Negligence in securing these systems makes them vulnerable to hacking attacks, which may lead to significant monetary losses for both merchants and the financial organizations. To reduce this risk, mandatory security compliance regulations, such as the Payment Card Industry Data Security Standard (PCI DSS), were developed and adopted by the industry. A key pre-requisite of the PCI DSS compliance process is the ability to identify the components of the Payment systems directly involved with the Card Data (i.e. process, transmit, or store). However, existing Data flow tracking tools cannot fully automate the process of identifying system components that touch Card Data, because they either can not examine encrypted communications or they use an instrumentation-based approach and thus require a priori detailed knowledge of the Payment Card processing systems. We describe the implementation and evaluation of a novel tool to identify the Card Data flow in commercial Payment Card processing systems running on virtualized servers. The tool performs realtime monitoring of network communications between virtual machines and inspects the memory of the communicating processes for unencrypted Card Data. Our implementation does not require instrumentation of application binaries and can accurately identify the system components involved in Card Data flow even when the communications among system components are encrypted. Effectiveness of this tool is demonstrated through its successful discovery of the Card Data flow of several open- and closed-source Payment Card processing applications.

Jing Liu - One of the best experts on this subject based on the ideXlab platform.

  • A survey of Payment Card industry Data security standard
    IEEE Communications Surveys and Tutorials, 2010
    Co-Authors: Jing Liu, Srinivas Dodle, Suat Özdemir, Yang Xiao, Hui Chen, Vikas Singh
    Abstract:

    Usage of Payment Cards such as credit Cards, debit Cards, and prepaid Cards, continues to grow. Security breaches related to Payment Cards have led to billion dollar losses annually. In order to offset this trend, major Payment Card networks have founded the Payment Card Industry (PCI) Security Standards Council (SSC), which has designed and released the PCI Data Security Standard (DSS). This standard guides service providers and merchants to implement stronger security infrastructures that reduce the risks of security breaches. This article mainly discusses the need for the PCI DSS and the Data security requirements defined in the standard to address the ongoing security issues, especially those pertaining to Payment Card Data handling. It also surveys various technical solutions, offered by a few security vendors, for merchant companies and organizations involved in Payment Card transaction processing to comply with the standard. The compliance of merchants or service providers to the PCI DSS are assessed by PCI Qualified Security Assessors (QSAs). This article thus discusses the requirements to become PCI QSAs. In addition, it introduces the PCI security scanning procedures that guide the scanning of security policies of a merchant or service provider and prepare relevant reports. We believe that this survey sheds light on potential technical research problems pertinent to the PCI DSS and its compliance.

Suat Özdemir - One of the best experts on this subject based on the ideXlab platform.

  • A survey of Payment Card industry Data security standard
    IEEE Communications Surveys and Tutorials, 2010
    Co-Authors: Jing Liu, Srinivas Dodle, Suat Özdemir, Yang Xiao, Hui Chen, Vikas Singh
    Abstract:

    Usage of Payment Cards such as credit Cards, debit Cards, and prepaid Cards, continues to grow. Security breaches related to Payment Cards have led to billion dollar losses annually. In order to offset this trend, major Payment Card networks have founded the Payment Card Industry (PCI) Security Standards Council (SSC), which has designed and released the PCI Data Security Standard (DSS). This standard guides service providers and merchants to implement stronger security infrastructures that reduce the risks of security breaches. This article mainly discusses the need for the PCI DSS and the Data security requirements defined in the standard to address the ongoing security issues, especially those pertaining to Payment Card Data handling. It also surveys various technical solutions, offered by a few security vendors, for merchant companies and organizations involved in Payment Card transaction processing to comply with the standard. The compliance of merchants or service providers to the PCI DSS are assessed by PCI Qualified Security Assessors (QSAs). This article thus discusses the requirements to become PCI QSAs. In addition, it introduces the PCI security scanning procedures that guide the scanning of security policies of a merchant or service provider and prepare relevant reports. We believe that this survey sheds light on potential technical research problems pertinent to the PCI DSS and its compliance.