首页    期刊浏览 2024年10月06日 星期日
登录注册

文章基本信息

  • 标题:A FORENSIC FIRST LOOK AT A POS DEVICE: SEARCHING FOR PCI DSS DATA STORAGE VIOLATIONS
  • 本地全文:下载
  • 作者:Larson, Stephen ; Jones, James ; Swauger, Jim
  • 期刊名称:Journal of Digital Forensics, Security and Law
  • 印刷版ISSN:1558-7215
  • 电子版ISSN:1558-7223
  • 出版年度:2020
  • 卷号:15
  • 期号:2
  • 页码:4-20
  • DOI:10.15394/jdfsl.2020.1614
  • 出版社:Association of Digital Forensics, Security and Law
  • 摘要:According to the Verizon 2018 Data Breach Investigations Report, 321 POS terminals (user devices) were involved in about 14% of the 2,216 data breaches in 2017 (Verizon, 2018). These data breaches involved standalone POS terminals as well as associated controller systems. This paper examines a standalone Point-of-Sale (POS) system which is ubiquitous in smaller retail stores and restaurants. An attempt to extract unencrypted data and identify possible violations of the Payment Card Industry Data Security Standard (PCI DSS) requirement to protect stored cardholder data were be made. Persistent storage (flash memory chips) were removed from the devices and their contents were successfully acquired. Information about the device and the code running on it was successfully extracted, although no PCI DSS data storage violations were identified. The confirmation that the POS systems examined keep our payment card information encrypted is welcome news as payment cards are still very much in use in our daily activities.
  • 关键词:POS device; PCI DSS; compliance; data extraction; chip-off
国家哲学社会科学文献中心版权所有