{"id":12186,"date":"2016-02-16T15:00:53","date_gmt":"2016-02-16T23:00:53","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=12186"},"modified":"2016-02-16T10:12:09","modified_gmt":"2016-02-16T18:12:09","slug":"traps-preventing-successful-attacks-on-legacy-atm-endpoints","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2016\/02\/traps-preventing-successful-attacks-on-legacy-atm-endpoints\/","title":{"rendered":"Traps: Preventing Successful Attacks on Legacy ATM Endpoints"},"content":{"rendered":"<p>Microsoft discontinued support of the venerable Windows XP operating system (OS) in April 2014. This OS had been a workhorse for over 12 years with a foothold on consumers, enterprises, and embedded systems such as automated teller machines (ATMs).<\/p>\n<p>A year later, it was estimated that 75 percent of the world\u2019s ATMs (2.2 million) were still running on Windows XP. Given the quantity of devices and the geographically dispersed nature of the ATMs, it is reasonable to assume that many of these devices have yet to be upgraded from Windows XP as any upgrade project is logistically daunting. And since Microsoft no longer provides software patches for any security holes, these devices are now more susceptible to malware and viruses. Some financial institutions made custom, extended support arrangements with Microsoft for a short timeframe to provide some protection as upgrade plans were put into motion.<!--more--><\/p>\n<p>Another factor that many banks and credit unions had to consider was the impending Mastercard deadline for Europay Mastercard Visa (EMV) chip-enabled ATMs. Beginning October 2016, liability for fraud will shift to the ATM owner. Consequently, some institutions opted to accommodate both the Windows XP and EMV chip reader upgrades as part of an overall, strategic plan to refresh their ATM technology.\u00a0\u00a0 Based on the age of the installed base, this may require both new hardware and software. ATM industry experts have estimated the cost of this upgrade to range from $1,000 to $3,500 per ATM.<\/p>\n<p>For Windows XP-based ATMs that continue to face delays in upgrades, one option would be to add advanced endpoint protection such as Palo Alto Networks Traps. Windows devices are then protected from malware and exploits -- without the use of signatures. Traps can disrupt the relatively small number of techniques that malicious entities must use to compromise Windows systems and the remaining Windows XP-based ATMs can be protected even in the absence of future software patches. By implementing Traps, we can help restore confidence in these aging, but still highly visible customer touch points.<\/p>\n<p>In the more general case for financial institutions, Traps can also be used to protect any Windows-based servers, desktops (both physical and virtual), and laptops from malware and exploits. This extends the benefit across the entire inventory of Windows devices from customer-facing ATMs to corporate personal computers and servers.<\/p>\n<p>To learn more about how Traps can protect your endpoints, please visit:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.paloaltonetworks.com\/products\/endpoint-security.html\" target=\"_blank\">Traps - Advanced Endpoint Protection<\/a><\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.com\/content\/dam\/paloaltonetworks-com\/en_US\/assets\/pdf\/tech-briefs\/security-platform-financial-services.pdf\" target=\"_blank\">Security Platform for Financial Services Solution Brief<\/a><\/li>\n<\/ul>\n<p><a href=\"http:\/\/go.paloaltonetworks.com\/ignite2016\"><div style=\"max-width:100%\" data-width=\"500\"><span class=\"ar-custom\" style=\"padding-bottom:33.4%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-12021 size-large lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-500x167.png\" alt=\"Ignite 2016 register now\" width=\"500\" height=\"167\" srcset=\"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-500x167.png 500w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-230x77.png 230w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-510x170.png 510w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now-120x40.png 120w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2016\/02\/Ignite-2016-register-now.png 900w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/span><\/div><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft discontinued support of the venerable Windows XP operating system (OS) in April 2014. This OS had been a workhorse for over 12 years with a foothold on consumers, enterprises, and embedded &hellip;<\/p>\n","protected":false},"author":171,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[598,416,1229],"tags":[46,398],"coauthors":[1702],"class_list":["post-12186","post","type-post","status-publish","format-standard","hentry","category-endpoint-2","category-financial-services","category-security-platform","tag-microsoft","tag-windows-xp"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/12186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/171"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=12186"}],"version-history":[{"count":1,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/12186\/revisions"}],"predecessor-version":[{"id":12187,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/12186\/revisions\/12187"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=12186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=12186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=12186"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=12186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}