IEEE Access (Jan 2019)

Mobile Session Fixation Attack in Micropayment Systems

  • F. Tommasi,
  • C. Catalano,
  • M. Fornaro,
  • I. Taurino

DOI
https://doi.org/10.1109/ACCESS.2019.2905219
Journal volume & issue
Vol. 7
pp. 41576 – 41583

Abstract

Read online

The rapid spread of micropayment systems, together with some peculiarity of their typical use, have attracted computer criminals and dishonest companies aiming at exploiting the systems’ weaknesses to steal from users both personal data and money. This paper considers and analyzes some security risks associated with a particular form of micropayment, operator centric micropayment (OCM). A new technique of attack, aimed at an OCM system used by millions of users and named mobile session fixation, is described. By its use, a criminal can obtain the payer’s phone number and even arrange the theft of some money. The paper proposes possible countermeasures and further hints for potential threats which might be the subject of analysis.

Keywords