{"id":16808,"date":"2020-05-25T12:29:34","date_gmt":"2020-05-25T16:29:34","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/atm-protection-updated\/16808\/"},"modified":"2021-05-14T18:21:42","modified_gmt":"2021-05-14T14:21:42","slug":"atm-protection-updated","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/atm-protection-updated\/16808\/","title":{"rendered":"ATMs need quarantines too!"},"content":{"rendered":"<p>I take more than a hundred flights in the average year. Usually traveling with companions, I fly all <a href=\"https:\/\/eugene.kaspersky.com\/2020\/01\/23\/the-extraordinary-things-ive-done-and-seen-in-the-year-of-the-lord-of-twenty-nineteen\/\" target=\"_blank\" rel=\"noopener noreferrer\">around the world<\/a> \u2014 and while we\u2019re abroad, we pay by card or phone, mostly with contactless services such as Apple or Google Pay, practically everywhere. In China you can even use WeChat to buy fruits and vegetables from grannies at markets. And the current coronavirus pandemic has only made the use of virtual money more popular.<\/p>\n<p>At the other end of the spectrum, you get the odd surprise: In Hong Kong of all places, taxis take cash \u2014 only \u2014 and just last year, I ate in two Frankfurt restaurants that required cash. What?!! Instead of enjoying our post-dinner brandy, we had to go on a long search for an ATM and withdraw euros. The humanity! (Question: Am I missing inconvenient travel surprises these days? Answer: So much!)<\/p>\n<p>Anyway, all this just goes to show that despite progressive payment systems being in place all around the globe, good old ATMs won\u2019t be going away anytime soon.<\/p>\n<p>So, what am I driving at, here? Of course, <em>cybersecurity<\/em>!<\/p>\n<p>ATMs mean money. They\u2019ve been hacked; they\u2019re still getting hacked; and they\u2019ll continue to be hacked. Indeed, the hacking is only getting worse: Our <a href=\"https:\/\/securelist.com\/atm-pos-malware-landscape-2017-2019\/96750\/\" target=\"_blank\" rel=\"noopener noreferrer\">research<\/a> indicates that the number of ATMs attacked by malware more than doubled from 2017 to 2019.<\/p>\n<p>So, can ATMs be monitored constantly, inside and out? Actually, no.<\/p>\n<p>You can still find plenty of ATMs with very slow connections \u2014 on streets, in stores, in subway and metro stations, and scattered around lots of well-trafficked and out-of-the-way spots. Some of them have barely enough bandwidth to manage transactions, let alone to keep an eye on what\u2019s going on around them.<\/p>\n<p>Given the lack of monitoring, we stepped in to fill the gaps and improve ATM security. We applied <a href=\"https:\/\/eugene.kaspersky.com\/2020\/05\/18\/go-easy-on-the-traffic\/\" target=\"_blank\" rel=\"noopener noreferrer\">the best practices of optimization<\/a> (something we can claim mastery of \u2014 with 25 years of experience but no false modesty), and also radically reduced the amount of <a href=\"https:\/\/eugene.kaspersky.com\/2020\/05\/18\/go-easy-on-the-traffic\/\" target=\"_blank\" rel=\"noopener noreferrer\">traffic<\/a> needed for our dedicated immunization against ATM threats \u2014 <a href=\"https:\/\/me-en.kaspersky.com\/enterprise-security\/embedded-systems?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">Kaspersky Embedded Systems Security<\/a>.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2020\/05\/25203033\/ATM-protection-updated-screenshot-EN.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2020\/05\/25203033\/ATM-protection-updated-screenshot-EN.jpg\" alt=\"Kaspersky Embedded Systems Security user interface\" width=\"959\" height=\"428\" class=\"aligncenter size-full wp-image-16809\"><\/a><\/p>\n<p>Get this: its minimum Internet connection speed requirement is \u2026 56 kilobits per second. I had a 56K dial-up modem in 1998!<\/p>\n<p>The average speed of <a href=\"https:\/\/www.speedtest.net\/insights\/blog\/russia-internet-speeds-4g-2019\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">4G Internet today<\/a> in developed nations is 30,000 to 120,000 kilobits per second. And 5G promises 100,000,000-plus kbps (that is, if people don\u2019t <a href=\"https:\/\/www.businessinsider.com\/attacks-cellphone-towers-coronavirus-5g-conspiracy-2020-4\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">destroy<\/a> all of the towers before then). But don\u2019t let prehistoric Internet speeds fool you; the protection couldn\u2019t be better. Indeed, many an effective manager could learn a thing or two from us about optimization without loss of quality.<\/p>\n<h2>How Kaspersky Embedded Systems Security protects ATMs<\/h2>\n<p>In addition to <a href=\"https:\/\/media.kaspersky.com\/en\/business-security\/enterprise\/Kaspersky_Embedded_Systems_Security_DS_ENG_final.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">existing functions<\/a>, here\u2019s the new stuff. Kaspersky Embedded Systems Security can now block:<\/p>\n<ul>\n<li>The <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/port\/\" target=\"_blank\" rel=\"noopener noreferrer\">ports<\/a> that cybercriminals use for their attacks after scanning for virtual entry points on the ATM to find the most vulnerable;<\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/three-little-pigs\/33796\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Brute forcing<\/a> \u2014 one of the simplest and most popular ways of finding out a password. The attackers use software to test possible combinations and, alas, often get in;<\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/ddos-quiz\/17385\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">DoS attacks<\/a> and <a href=\"https:\/\/www.kaspersky.com\/blog\/exploits-problem-explanation\/9448\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">exploits<\/a>. If the crooks do connect to an ATM, they proceed to throw so much data at it that the ATM\u2019s hardware simply can\u2019t cope. That\u2019s why they\u2019re called DoS attacks \u2014 Denial of Service \u2014 they simply force the target to stop providing service.<\/li>\n<\/ul>\n<p>Now for a bit of showing off. Large banks are using Kaspersky Embedded Systems Security on thousands of ATMs all around the world, as do a great many transportation companies and retail giants. Accordingly, you can expect a reduction in the number of news items about hacked ATMs very soon.<\/p>\n<p>Still have questions? Head on over to our <a href=\"https:\/\/me-en.kaspersky.com\/enterprise-security\/embedded-systems?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">Kaspersky Embedded Systems Security product page<\/a>.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"glossary\">\n","protected":false},"excerpt":{"rendered":"<p>How we optimized our solution for ATM protection, and why.<\/p>\n","protected":false},"author":13,"featured_media":16811,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1318,1916],"tags":[1232,2263],"class_list":{"0":"post-16808","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-enterprise","9":"tag-atms","10":"tag-solutions"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/atm-protection-updated\/16808\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/atm-protection-updated\/21351\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/atm-protection-updated\/22416\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/atm-protection-updated\/20545\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/atm-protection-updated\/18941\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/atm-protection-updated\/22759\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/atm-protection-updated\/21794\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/atm-protection-updated\/28397\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/atm-protection-updated\/8365\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/atm-protection-updated\/35652\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/atm-protection-updated\/14952\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/atm-protection-updated\/15482\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/atm-protection-updated\/13494\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/atm-protection-updated\/24101\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/atm-protection-updated\/12284\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/atm-protection-updated\/25453\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/atm-protection-updated\/22291\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/atm-protection-updated\/27630\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/atm-protection-updated\/27462\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/atms\/","name":"ATMs"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/16808","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=16808"}],"version-history":[{"count":5,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/16808\/revisions"}],"predecessor-version":[{"id":18347,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/16808\/revisions\/18347"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/16811"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=16808"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=16808"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=16808"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}