Fear the Reaper: Characterization and Fast Detection of Card Skimmers

Authors: 

Nolen Scaife, Christian Peeters, and Patrick Traynor, University of Florida
Distinguished Paper Award Winner

Abstract: 

Payment card fraud results in billions of dollars in losses annually. Adversaries increasingly acquire card data using skimmers, which are attached to legitimate payment devices including point of sale terminals, gas pumps, and ATMs. Detecting such devices can be difficult, and while many experts offer advice in doing so, there exists no large-scale characterization of skimmer technology to support such defenses. In this paper, we perform the first such study based on skimmers recovered by the NYPD's Financial Crimes Task Force over a 16 month period. After systematizing these devices, we develop the Skim Reaper, a detector which takes advantage of the physical properties and constraints necessary for many skimmers to steal card data. Our analysis shows the Skim Reaper effectively detects 100% of devices supplied by the NYPD. In so doing, we provide the first robust and portable mechanism for detecting card skimmers.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {217599,
author = {Nolen Scaife and Christian Peeters and Patrick Traynor},
title = {Fear the Reaper: Characterization and Fast Detection of Card Skimmers},
booktitle = {27th USENIX Security Symposium (USENIX Security 18)},
year = {2018},
isbn = {978-1-939133-04-5},
address = {Baltimore, MD},
pages = {1--14},
url = {https://www.usenix.org/conference/usenixsecurity18/presentation/scaife},
publisher = {USENIX Association},
month = aug
}

Presentation Video 

Presentation Audio