Securities Issues in a company, Computer Network Security

'Near Field Communication' (NFC) technologies are expected to become commonplace in the near future. Some relevant features are these:

  • A suitable device (such as a mobile phone) may interact with another device (another phone, or a simple tag, or some other fixed reader), provided the two devices are held in close proximity, or 'tapped' together. In order to communicate, simple tags can derive their power from the nearby device.
  • Moderate amounts of data may be exchanged (one-way or two-way) in such interactions - a few kBytes, typically.
  • Management of data relevant to such interactions might be stored in the ordinary memory of the phone, or might be undertaken by a secure element such as the SIM card. In a payment application, for example, the 'cash balance' might be recorded by the card, that card running a protocol with the remote card, intended to ensure that a rogue application could not corrupt its legitimate operation. Such secure storage is characterized by high qualities of security, and very limited storage capacity.

One topic of debate among security experts is whether the 'near field' property can be subverted - for example, whether special antennae could eavesdrop from a distance: this is likely to be the case, in the right circumstances.

Suppose a supermarket has decided to use NFC to enhance shoppers' experience, and to attempt to induce its customers (or potential customers) to buy more items.

Crucially, this will involve giving the shoppers a special app to run on their smartphones, and will involve placing relevant tags on shelves and/or individual products. Three phases of app roll-out are envisaged:

1. The app allows shoppers to look up information about products - such as their nutritional content - before buying them. The shopper's phone is tapped onto the relevant shelf label to receive such information.

2. the app receives vouchers and special offers, pushed by the supermarket (perhaps on a schedule, perhaps based on the shopper's habits, perhaps when tapped on a shelf to activate a particular offer, or perhaps when the phone's location service indicates proximity to this supermarket or a competitor's shop).

3. The app allows shoppers to scan each item they place in their trollies (much as some supermarkets currently allow with hand-held barcode scanners); 3 stored vouchers are automatically applied; upon leaving the shop, the app automatically triggers an online payment for the full cost of the contents of the cart

Your task is to identify the threats inherent in this scenario (or, these scenarios, regarding each phase separately). Describe each threat, making clear the anticipated motive(s) of the attacker(s). There may be significant high-level design decisions to be made which will impact the security of the solution: explain what these are, and what their implications are.

Which threats would you expect to give rise to the biggest risks? Explain your answer. Your answer will necessarily be incomplete without an assessment of vulnerabilities, which is out of scope. Is there any other information you would need in order to complete a risk assessment?

Posted Date: 2/21/2013 7:36:25 AM | Location : United States







Related Discussions:- Securities Issues in a company, Assignment Help, Ask Question on Securities Issues in a company, Get Answer, Expert's Help, Securities Issues in a company Discussions

Write discussion on Securities Issues in a company
Your posts are moderated
Related Questions
Use the Chinese remainder theorem to evaluate x from the following simultaneous congruences: x ≡ 1 (mod 2); x ≡ 2 (mod 3); x ≡ 3 (mod 5). Calculate gcd(14526, 2568). (

Question : Environmental Accounting is a means for businesses to fulfill their responsibilities for accountability to stakeholders. (a) What do you understand by Environment

LOG FILE MONITORS Log file monitor (LFM) is similar to NIDS. It reviews log files generated by servers, network devices, and even other IDSs for patterns and signatures. Pattern

Question: (a) Your office administrator is being trained to take server backups. Which authorization model could be ideal for this situation: MAC, DAC or RBAC? Justify your a

LOCALITY OF REFERENCE PRINCIPLE:  Principle of "Locality of Reference" use to predict computer interaction patterns. There are two patterns shown as follows: a) Spatial loca

Listing Assets in Order of Importance Weighting should be created for each category based on the answers to questions. The relative importance of each asset is calculated usin

B-Router Hybrid devices that has the features of both routers and bridges . A bridge router or brouter is a network machine that acts as a router and as a bridge. The brout

This project involves the design and development of a simulation environment of many sensors tagging material/ machinery/equipment/etc in a warehouse site to help monitor and manag

Question: (a) Describe fully with example the two access control methods available to implement database security. (b) Discuss why database statistics (meta data) provide es

Digital Certificates Digital Certificates are electronic document having key value and identifying information about entity which controls key. Digital signature which is attach