Abstract
Background. 3-D Secure 2.0 (3DS 2.0) is an identity federation protocol authenticating the payment initiator for credit card transactions on the Web. Aim. We aim to quantify the impact of factors used by 3DS 2.0 in its fraud-detection decision making process. Method. We ran credit card transactions with two Web sites systematically manipulating the nominal IVs machine-data, value, region, and website. We measured whether the user was challenged with an authentication, whether the transaction was declined, and whether the card was blocked as nominal DVs. Results. While website and card largely did not show a significant impact on any outcome, machine-data, value and region did. A change in machine-data, region or value made it 5-7 times as likely to be challenged with password authentication. However, even in a foreign region with another factor being changed, the overall likelihood of being challenged only reached 60%. When in the card's home region, a transaction will be rarely declined (< 5% in control, 40% with one factor changed). However, in a region foreign to the card the system will more likely decline transactions anyway (about 60%) and any change in machine-data or value will lead to a near-certain declined transaction. The region was the only significant predictor for a card being blocked (OR = 3). Conclusions. We found that the decisions to challenge the user with a password authentication, to decline a transaction and to block a card are governed by different weightings. 3DS 2.0 is most likely to decline transactions, especially in a foreign region. It is less likely to challenge users with password authentication, even if machine-data or value are changed.
| Original language | English |
|---|---|
| Title of host publication | Proceedings - 8th Workshop on Socio-Technical Aspects in Security and Trust, STAST 2018 - Co-located with the 2018 Annual Computer Security Applications Conference, ACSAC 2018 |
| Editors | Giampaolo Bella, Gabriele Lenzini |
| Publisher | Association for Computing Machinery |
| Pages | 21-31 |
| Number of pages | 11 |
| ISBN (Electronic) | 9781450372855 |
| DOIs | |
| Publication status | Published - 4 Dec 2018 |
| Event | 8th Workshop on Socio-Technical Aspects in Security and Trust, STAST 2018, co-located with the 2018 Annual Computer Security Applications Conference, ACSAC 2018 - San Juan, United States Duration: 4 Dec 2018 → … |
Publication series
| Name | ACM International Conference Proceeding Series |
|---|
Conference
| Conference | 8th Workshop on Socio-Technical Aspects in Security and Trust, STAST 2018, co-located with the 2018 Annual Computer Security Applications Conference, ACSAC 2018 |
|---|---|
| Country/Territory | United States |
| City | San Juan |
| Period | 4/12/18 → … |
Bibliographical note
Publisher Copyright:© 2018 ACM.
Keywords
- 3-D secure
- authentication
- fraud detection
ASJC Scopus subject areas
- Software
- Human-Computer Interaction
- Computer Vision and Pattern Recognition
- Computer Networks and Communications
Fingerprint
Dive into the research topics of 'Investigation of 3-D secure's model for fraud detection'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver