Boxer: Preventing fraud by scanning credit cards
Zain ul Abi Din, Hari Venugopalan, Jaime Park, Andy Li, Weisu Yin, Haohui Mai, Yong Jae Lee, Steven Liu, Samuel T. King
摘要
Card-not-present credit card fraud costs businesses billions of dollars a year. In this paper, we present Boxer, a mobile SDK and server that enables apps to combat card-not-present fraud by scanning cards and verifying that they are genuine. Boxer analyzes the images from these scans, looking for telltale signs of attacks, and introduces a novel abstraction on top of modern security hardware for complementary protection. Currently, 323 apps have integrated Boxer, and tens of them have deployed it to production, including some large, popular, and international apps, resulting in Boxer scanning over 10 million real cards already. Our evaluation of Boxer from one of these deployments shows ten cases of real attacks that our novel hardware-based abstraction detects. Additionally, from the same deployment, without letting in any fraud, Boxer's card scanning recovers 89% of the good users whom the app would have blocked. In another evaluation of Boxer, we run our image analysis models against images from real users and show an accuracy of 96% and 100% on the two models that we use.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Aragorn: A Privacy-Enhancing System for Mobile CamerasHari Venugopalan, Zain ul Abi Din, Trevor Carpenter, Jason Lowe-Power 等UbiComp 2024 · 被引用 8 次
- Doing good by fighting fraud: Ethical anti-fraud systems for mobile paymentsZain ul Abi Din, Hari Venugopalan, Henry Lin, Adam Wushensky 等S&P 2021 · 被引用 8 次
它引用的顶会 Paper6
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio 等NDSS 2016 · 被引用 151 次
- rtCaptcha: A Real-Time CAPTCHA Based Liveness Detection SystemErkam Uzun, Simon Pak Ho Chung, Irfan Essa, Wenke LeeNDSS 2018 · 被引用 60 次
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 被引用 34 次
- Please Pay Inside: Evaluating Bluetooth-based Detection of Gas Pump SkimmersNishant Bhaskar, Maxwell Bland, Kirill Levchenko, Aaron SchulmanUSENIX Security 2019 · 被引用 12 次
- The Cards Aren't Alright: Detecting Counterfeit Gift Cards Using Encoding JitterNolen Scaife, Christian Peeters, Camilo Velez, Hanqing Zhao 等S&P 2018 · 被引用 11 次
相关 Paper
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 被引用 69 次
- Cardpliance: PCI DSS Compliance of Android ApplicationsSamin Yaseer Mahmud, Akhil Acharya, Benjamin Andow, William Enck 等USENIX Security 2020
- Dissecting Click Fraud Autonomy in the WildTong Zhu, Yan Meng, Haotian Hu, Xiaokuan Zhang 等CCS 2021 · 被引用 14 次
- PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on AndroidXianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong LauNDSS 2022
- Kiss from a Rogue: Evaluating Detectability of Pay-at-the-Pump Card SkimmersNolen Scaife, Jasmine D. Bowers, Christian Peeters, Grant Hernandez 等S&P 2019 · 被引用 10 次
