1 / 27

Meneropong Situs e-Banking

Meneropong Situs e-Banking. Onno W. Purbo onno@indo.net.id. Beberapa Jenis Serangan. Social Engineering Viruse / Trojan / Spyware Denial of Service (DoS) Sniffing IP Spoofing Worm Replay Attack Man In The Middle. Social Engineering. Flooding DDoS Worm. Sniffing Spoofing

mickey
Download Presentation

Meneropong Situs e-Banking

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Meneropong Situs e-Banking Onno W. Purbo onno@indo.net.id

  2. Beberapa Jenis Serangan • Social Engineering • Viruse / Trojan / Spyware • Denial of Service (DoS) • Sniffing • IP Spoofing • Worm • Replay Attack • Man In The Middle

  3. Social Engineering Flooding DDoS Worm Sniffing Spoofing Man-in-the-Middle Virus Trojan Spyware Keylogger Sniffing Spoofing Man-in-the-Middle Replay Attack

  4. Social Engineering Flooding DDoS Worm Virus Trojan Spyware Keylogger

  5. Network & Application Security • Firewall • Intrusion Prevention System • Secure Socket Layer (SSL) 128 bit • Data encryption

  6. Pengamanan Proses • User ID and Password • Tingkat Kewenangan, yaitu : • System administrator, yang melakukan pendaftaran untuk seluruh pengguna yang menggunakan fitur dari Permatae-Business • Maker, yang melakukan proses pembuatan atas transaksi • Verifier, yang melakukan proses pemeriksaan atas transaksi • Approver, yang melakukan proses persetujuan atas transaksi • Persetujuan transaksi dilakukan oleh lebih dari 1 orang dan secara berjenjang • TIN & Token untuk Approver • Limit transaksi dan limit akses per fitur • Audit trail melalui Permatae-Business

  7. Mengatasi SeranganMade Simple • Jangan Pernah Menggunakan WARNET • Jangan Pernah Akses ke Situs Porno & non kerjaan di Internet • Hati-hati dengan USB Flashdisk • Hati-hati dengan “Social Engineering” • Hati-hati situs e-banking palsu • Hati-hati phissing melalui spam e-mail. • Install Antivirus, Antiadware, Antispam & pastikan komputer anda bebas virus, trojan, keylogger, dll. – Paling mudah gunakan Linux.

  8. Evaluasi permatae-banking

  9. Bagus! Secure HTTP

  10. Bagus! Secure HTTP

  11. permatae-business.com Memang milik Bank Permata

  12. Root Server mengenali permatae-business.com Tidak terjadi spoofing

  13. Port Scanning

  14. Port Scanning Hanya Port HTTP & HTTPS yang dibuka. Bagus. Pakai Firewall Appliances Kemungkinan IPCop / Linux / Sun Solaris. Bagus TCP Sequence Cukup Random. Bagus.

  15. Evaluasi Enkripsi / SSL openssl s_client –connect www.peramate-busienss.com:443 openssl s_client –host www.permatae-business.com –port 443

  16. Subject Bank Permata. Bagus. Issuer Verisign Trust Network

  17. Verisign Adalah Certificate Authority Terbesar & Terpercaya di dunia

  18. Subject Bank Permata. Bagus. Issuer Verisign Trust Network Enkripsi RC4 Fungsi Hash MD5 Public Key 1024 bit Selamat Tinggal!!

  19. Brute Force Attack pd. DES

  20. Brute Force Attack pada RC4

More Related