본문 바로가기
  • Home

Analysis and Evaluation of a Need of Safeguard in Korean’s Internet Banking Based on PDR Matrix

  • Journal of Knowledge Information Technology and Systems
  • Abbr : JKITS
  • 2016, 11(2), pp.119-154
  • Publisher : Korea Knowledge Information Technology Society
  • Research Area : Interdisciplinary Studies > Interdisciplinary Research
  • Published : April 30, 2016

허건일 1 Chang Min Park 2 Huy-Kang Kim 3

1고려대학교 정보보호대학원
2웹케시 정보보호센터
3고려대학교

Accredited

ABSTRACT

Complaints among users have increased because of insufficient explanation about safeguard and forced use of safeguard. Someone has said that Internet banking safeguard(hereafter safeguard) is unnecessary because large-scale Internet banking fraud has happened continuously although financial companies have taken complaints among users lying down. But this is a misconception that people try to couple inconvenience caused by ActiveX with use of safeguard. We should judge necessity of respectively safeguard based on objective capacity and interrelation, as opposed to safeguard is unnecessary because of inconvenience. Therefore in this paper we analyzed and evaluated existing domestic safeguard’s necessity based on PDR matrix namely, information security lifecycle which is classified Prevention, Detection, Response and six of Internet banking threats(account theft, public certificate snatch, malware infection, input data modification, input data snatch, phishing/pharming). This made us identify four overlapped sections and two empty sections of safeguard and know that all safeguards are certainly necessary except graphic authentication in P section of account theft and phishing/pharming, phishing prevention program in P section of phishing/pharming in case of overlapped section by evaluating their capacity. But we recognized a gap between the findings of our research and user’s thought by surveying Internet banking users. So we proposed three ways to narrow the gap such as giving specific information regarding Internet banking threat and safeguard to user, giving information considered user’s level to user, guaranteeing user’s a choice regarding use of safeguard.

Citation status

* References for papers published after 2023 are currently being built.