Abstract

Purpose. Due to the use of technology in banks their risks of information security breach are rising significantly. In the context of active introduction of remote banking services (RBS) in banking business of Russia, additional study of issues of assessing the risk of cyberattacks on banking automated systems was required. Methods. The methods of financial management, probability theory, system analysis of scientific literature on fundamental and applied research, and a method of graphical interpretation of analyzed phenomena are used. The paper gives a detailed analysis of the concepts of “cyberspace” and “cybersecurity”. Remote banking is considered from the point of view of financial management. Attention is drawn to the factors of work in cyberspace that increase the levels of banking risks. The relationship of cyberattacks on bankingautomated systems and possible consequences for the bank is analyzed. Novelty. Given the wide spread of social engineering methods when committing fraudulent activities on the Internet the measures to increase the cyber literacy of population are needed. The method for assessing the risk of cyberattacks on RBS for use by risk department specialists and employees of internal control services is developed. As a result, considering innovative systems and technologies that await us in the future, the effectiveness of risk assessment for solving current challenges is increased. Results. Attempts are made to formulate the mathematical model of the probabilistic analysis of information security incidents to optimize the algorithm for responding to incidents. Calculations based on the proposed model made it possible to determine the duration of exploitation of vulnerability of RBS, when the probability of preventing an incident exceeds probability of its realization. The findings may be useful for scientific research on the risks of information security breach in RBS.

Highlights

  • The latest achievements in the field of information and telecommunication technologies have significantly changed the process of conducting the banking business and have become the basis for the active implementation of remote banking services (RBS)1

  • The authors of this paper propose introducing the method of “blind” typing with ten fingers into the education system in Russia, as the development of fine motor skills of the hands contributes to the activation of the frontal lobes of the brain

  • It requires the mastering of measures to increase cyberliteracy and prevent the uncontrolled development of cyberspace; 2

Read more

Summary

Introduction

The latest achievements in the field of information and telecommunication technologies have significantly changed the process of conducting the banking business and have become the basis for the active implementation of remote banking services (RBS). 1. Expanding profiles of typical banking risks due to computer attacks Consider the main types of cyberattacks on BAS noted in the annual reports of FinCERT of the Bank of Russia and the company's Group-IB8: attacks on AWP CBR, AWP SWIFT, AWP RBS9 and attacks on self-service devices (Automated Teller Machines – ATMs). Expanding profiles of typical banking risks due to computer attacks Consider the main types of cyberattacks on BAS noted in the annual reports of FinCERT of the Bank of Russia and the company's Group-IB8: attacks on AWP CBR, AWP SWIFT, AWP RBS9 and attacks on self-service devices (Automated Teller Machines – ATMs) To implement all these attacks, first one needs to download malicious software (malware) into the local area network (LAN) of the credit institution. The main target is to receiving money with the maximum possible “erasure of traces” of a crime

AWP of ATMs software updates
Conclusion
REFERENCES:
Informatsionnaya bezopasnost'

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.