ST&E Is the Most Cost Effective Measure for Comply with Payment Card Industry (PCI) Data Security Standard

ST&E Is the Most Cost Effective Measure for Comply with Payment Card Industry (PCI) Data Security Standard
复制标题

英石

DOI:
--
复制
发表时间:
2008
期刊:
Financial Cryptography
影响因子:
--
通讯作者:
P. Douthit
P. Douthit
中科院分区:
--
文献类型:
--
作者:
Ken L. Huang;P. Douthit

文献摘要

被引文献

相似文献

2006年9月,五家领先的支付品牌成立了一个独立的委员会来管理支付卡行业(PCI)数据安全标准(DSS)。美国运通、Discover Financial Services、JCB、万事达卡全球和Visa International认为有必要以全球一致的方式保护支付账户数据。因此,存储、处理和处理信用卡的金融机构必须遵守PCI/DSS。每个事件的违规罚款最高可达500,000美元,包括公开披露违规行为。金融机构可以实施非常广泛的安全控制,以符合PCI/DSS标准。成本可能会高得令人望而却步。这张海报认为,最具成本效益的安全措施是在由PCIDSS合格安全评估员(QSA)公司执行昂贵的审计之前进行安全测试和评估(ST&E)项目。我们提出了五个不同的ST&E阶段,以及它对金融机构的CIO/CTO意味着什么。 ST&E的五个阶段是1)计划,2)开发评估方法和工具选择,3)测试执行和报告,4)纠正措施建议和5)重新测试。 在规划阶段,定义了参与的范围和规则,并签署了ST&E的要求。范围取决于确定托管或处理信用卡数据的任务关键型应用程序。例如,Web服务器、应用服务器和数据库都可以用于处理或存储信用卡信息。并且该应用程序可能具有对其他应用程序的依赖性。因此,不同应用程序之间的通信通道可能是关键组件,并在范围内。参与规则确定了ST&E项目的所有利益相关者,并定义了涉及的每个部分的责任。对于ST&E项目来说,一条定义不明确的参与规则将是致命的。 在第二阶段,测试和评估方法由参与ST&E的所有利益相关者定义和同意。测试方法可以是黑盒测试,这意味着测试人员对系统一无所知,并尝试不同的方法来发现安全漏洞。另一种测试方法是白盒测试。在白盒测试过程中,测试人员检查代码和不同的配置文件,然后构建可以入侵系统的攻击方法。这种方法更具成本效益,应该用来发现系统中的大多数证券漏洞。 第三阶段是测试执行和报告,测试人员可以使用手动民族黑客方法或自动化工具来发现系统中的安全漏洞。请记住,自动化工具只能找到很小一部分漏洞。因此,先进的手工种族黑客技能对ST&E项目的成功至关重要。在测试执行后,测试人员需要分析结果以识别假阳性,然后生成报告,该报告将作为ST&E下一阶段的输入。 第四阶段是纠正措施建议。如果受影响的应用程序是在内部开发的,则可以通过与内部开发人员合作来应用纠正措施。否则,测试人员可以与ST&E项目的利益相关者合作,从供应商那里找到合适的补丁,或者在补丁不可用时向供应商报告错误。 最后一个阶段是复试阶段。我们强调,安全测试不是一劳永逸的评估。为了保持可接受的安全级别,必须定期重新测试系统,并在开发人员对系统进行任何更改时进行重新测试。通过制定重复出现的重新测试阶段,阶段5依赖于系统通过其第一次ST&E评估。一旦系统在最初的ST&E后被认为是安全的,结果的总和就可以提交给利益相关者。在这一点上,可以确定系统将被重新测试的频率。 在这张海报演示中,我们将演示金融应用程序中的一些常见漏洞,如跨站脚本攻击、SQL注入、弱会话管理、改进器异常处理和弱加密。演示结束后,我们将详细介绍ST&E方法,CTO/CIO如何通过在内部实施ST&E而受益,以及ST&E如何使组织受益于实现PCI/DSS合规性。
In September of 2006, the five leading payment brands formed an independent council to manage the Payment Card Industry (PCI) Data Security Standard (DSS). American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International saw the need to secure payment account data in a globally consistent manner. As such, the financial institutions which store, process and transact the credit card must comply with the PCI/DSS. The Non-compliance fines can reach up to US $500,000 per incident including the public disclosure of breaches. Financial Institution can implement very broad security controls to comply with the PCI/DSS standard. The cost can be prohibitive. This poster argues that the most cost effective security measure is to conduct a Security Testing and Evaluation (ST&E) project before the expensive auditing performed by a PCI DSS Qualified Security Assessor (QSA) Company. We have proposed 5 distinct phases of ST&E, and what it means to the CIO/CTO of the financial institutions. The five phases of ST&E are 1) Planning, 2) Develop Evaluation Methods and Tool Selection, 3) Test Execution and Reporting, 4) Corrective Measures Recommendation and 5) Re-Testing. During the Planning Phase, the scope and rule of engagement is defined, and the requirement of the ST&E is signed off. The scope depends on identifying the mission critical applications which host or process the credit card data. For example, the web server, the application server and database can all be used for processing or storing the credit card information. And the application may have dependency on other applications. So the communication channels between different applications could be the crucial components and are in scope. The rule of engagement identity all stakeholders of the ST&E project, and define the responsibilities of each part involved. A poorly defined rule of engagement would be fatal for the ST&E project. During the second phase, the testing and evaluation method is defined and agreed upon by all stakeholder involved in the ST&E. The testing method could be black box testing, meaning that the tester has no knowledge of the systems and try different ways to find the security vulnerabilities. Another testing method is the white box testing. During the white box testing, the tester reviews the code and different configuration files, and then constructs the attack methods which could hack into the system. This method is more cost effective and should be used to find the majority of the securities holes in the system. The third phase is the Testing Execution and Reporting, the testers could use both manual ethnic hacking methods or automated tool to find the security vulnerabilities in the system. Keep in mind that the automated tool can only find very small portion of the vulnerabilities. Thus, the advanced manual ethnic hacking skills are crucial to the success of the ST&E project. After the testing execution, the tester needs to analyze the results to identity the false positives and then produce the report which will be the input to the next phase of the ST&E. The forth phase is the Corrective Measures Recommendation. If the application impacted is developed in house, the corrective measure could be applied by working with the developers in house. Otherwise, the tester can work with stakeholders of ST&E project to find the appropriate patches from the vendor or report the bug with the vendor if the patch is not available. The final phase is the Re-testing phase. We emphasize that security testing is not a once and done evaluation. In order to maintain an acceptable level of security, the system must be retested periodically, as well as when the developers make any changes to the system. By developing a reoccurring phase of retesting, Phase Five depends upon the system passing its first ST&E evaluation. Once the system is deemed secure after the initial ST&E, a summation of the results can then be presented to the stakeholders. At that point, the frequency for which the system will be retested can be established. In this poster presentation, we will demo some common vulnerabilities in the financial applications, such as cross site script attack, SQL injection, weak session management, improver exception handling, and weak encryption. After the demo, we will present in detail the ST&E methodology and how the CTO/CIO can benefit by implementing the ST&E in house, and how ST&E can benefit organizations to achieve the PCI/DSS compliance.