4 ms·
I feel like there should be secondary checks for things like this. When I was running a MMORPG, I was terrified of duplication bugs (dupes). In many ways, dupes
by Shenglong 13y ago
I feel like there should be secondary checks for things like this. When I was running a MMORPG, I was terrified of duplication bugs (dupes). In many ways, dupes have the same effect on a game economy as this type of theft has on the real economy: it can go unnoticed for a long time, and the victims are primarily the masses (money supply) until someone finds out.
Since we didn't have any network security professionals on our team, I was especially worried. What we realized though, was that we kept a detailed log of all item/money creations/deletions, where trades were just a creation/deletion pair. Thus, we wrote a script to learn what the most expensive items (and thus most costly, if duplicated) were at any given time, and match creations to deletions with a frequency increasing with item value. Whenever there was a discrepancy, we were alerted.
I suppose banks could do something similar. If they separate the money transfer system from the account creation system, they could add an additional layer of security. I haven't really thought out the details, but it makes sense at first glance. Perhaps they already do something like this?
- umsm 13y agoAdding another system to the mix is just another system that can be vulnerable to an attack. Once someone is in and they understand how everything works, there is no stopping them.
- TikiTDO 13y agoI wouldn't say he's describing "adding another system to the mix," at least not in a traditional sense; it's more along the lines of two distinct systems working towards a similar goal. What he described is an auditing system with some particular policies of interest to a specific use case. Such a system should not have any direct access to the main system, and should ideally live in a fully segregated environment with tightly controlled read-only access to a copy of the data being audited. The whole idea is that this system would not announce its presence on the network in any way so that the attacker is more likely to miss it. Even if the attacker does know that it's present, he should not know all the checks and validations that such a system uses to detect suspicious behaviour. Hell, you could air-gap the entire thing and just copy over data dumps by using USB sticks. Granted, even in that situation you could get something like Stuxnet which may compromise the machines. However, if you have the resources to build another Stuxnet, chances are you don't really need to get into a bank network.