How to Protect Online Transactions

The trusty telephone is emerging as one of the key elements in new multifactor authentication schemes designed to protect online banking and other web-based financial transactions from rapidly evolving security threats.

By Julie Sartain
Mon, February 06, 2012

Network World — The trusty telephone is emerging as one of the key elements in new multifactor authentication schemes designed to protect online banking and other web-based financial transactions from rapidly evolving security threats.

New federal guidelines, which took effect last month, recommend multiple layers of security controls beyond the traditional username/password, particularly out-of-band authentication methods.

RELATED: We need two-factor authentication for handsets

While the Federal Financial Institutions Examination Council (FFIEC) rules apply specifically to banks, credit unions, mortgage lenders, and savings and loans, every organization that deals in online financial transactions such as shopping portals, credit card companies, online bill payments, etc. is affected.

Point, counterpoint

One of the main weapons in the today's hacker arsenal is password phishing. In this scenario, hackers use phishing emails to steal online banking credentials and break into user accounts.

In response, banks and other financial institutions have deployed technologies like device identification, challenge questions and one-time password tokens, according to Sarah Fender, vice president of product management at authentication vendor PhoneFactor.

Forrester analyst Andras Cser emphasizes that login IDs and passwords are no longer enough. He says preselected images, challenge questions, device information, and device reputation are all effective second factor authenticators.

But the problem with many of those "in-band" authentication methods is that the device itself might be infected with malware, adds Fender.

Plus there are more advanced threats, such as keyloggers, Man in the Browser (MITB) and Man in the Middle (MITM) attacks, which require even more sophisticated security measures.

Gartner analyst Ant Allan says, "Virtually every authentication technique can be compromised or circumvented. Authentication is better than legacy passwords to minimize the risk for 'quick and dirty' attacks such as phishing, but there is a limit to the utility of seeking higher-assurance methods that are harder to compromise directly. At some point, the attackers will move to MITB attacks, which hijack already authenticated sessions, effectively bypassing authentication, to manipulate transaction details or insert bogus transactions."

Allan says there are two advanced technologies that are effective in combatting the current crop of attacks: Web Fraud Detection and Transaction Verification.

According to Allan, Web Fraud Detection evaluates contextual information about the user's connectivity (endpoint identity, geographic location, and so on) and looks for anomalous transactional behavior (compared to user history and to other users; e.g., are multiple users making transfers to the same new account?). (See "Well organized, sophisticated, fast cybercriminals scare U.S. banks".)

Transaction Verification uses a number of techniques to confirm that the transaction details received by the bank (a) originated with the user and (b) are what the user intended. Interactive transaction confirmation via an out-of-band method, as outlined in the FFIEC guidance, is effective for desktop browser sessions and is possibly the most attractive option.

Continue Reading

Originally published on www.networkworld.com. Click here to read the original story.
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Gartner's report affirms the key role of web content management as part of a larger digital marketing strategy for engaging and serving customers/citizens. In this must read Gartner Magic Quadrant for WCM, analysts evaluate technology providers based on their ability to execute and completeness of vision.
The web content management (WCM) market is growing based on customer experience (CXM) needs, including multichannel delivery, content targeting, analytics, and integration with other CXM technologies.
Many factors influence what "ideal" approach organizations should take when planning to implement a fabric-based infrastructure policy. This presentation charts the likely evolution of the market for fabric-based infrastructures, to help IT leaders determine the most appropriate vendor approach.

Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.
A patchwork of job schedulers can cause many inefficiencies, hindering IT's ability to serve the business. An enterprise approach solves these issues and adds new value. Five steps can take you from a costly mishmash to benefits like increased productivity, lower costs, and better service.
What is workload automation, and how does it compare to traditional job scheduling? IDC tackles these questions and more in a new white paper.
You'll read about:

* Key factors increasing IT complexity - and how to manage them

* Building an automation strategy

* Definition and components of today's workload automation software
IT organizations of all sizes are looking for ways to reduce cost in their data center. While larger enterprises can more easily muster the necessary skills and resources in pursuit of this goal, mid-sized organizations typically have limited time and funds they can denote.
Traditional communication methods are no longer sufficient to meet the pace of business today. Video Conferencing is an essential business tool. Dimension Data is revolutionizing the process of doing business and making video conferencing fast, simple and affordable.
Business users increasingly demand 24x7 availability of their data while IT departments face the challenge of ensuring maximum availability while operating with limited budgets.
Date: Wednesday, May 23, 2012
Time: 11:00 a.m. PDT / 2:00 p.m. EDT

IT security faces challenges as never before. At one end of the spectrum, industrialized exploits hammer organizations with a volume and frequency of attacks that only a few short years ago would have been unimaginable.
Learn how to get the most from your cloud investment in our on-demand webinar from BMC and InformationWeek. You'll hear how integrating the cloud into your production workload brings critical business benefits.
Date: May 31, 2012
Time: 1 PM EST

Organizations are reaping the benefits of simplifying IT, lowering costs and dramatically improving transactional throughput by deploying optimized application-to-disk solutions. These pre-tuned, tested solutions encompass a wide variety of applications and use cases. Hear from industry experts, and IT executives, how these full-stack solutions can achieve three times faster deployment times and up to 75% reductions in acquisition and operational costs.
Find out when you join EMA Senior Analyst, Torsten Volk, for a discussion on the 2012 trends in workload automation and how these trends contribute to better connecting workload automation to business processes. These trends are derived from EMA's empirical research work conducted for the 2012 Workload Automation Radar Report.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links

Learn how Accenture helps clients become high-performing businesses

Choose New and slash the number of devices you manage

Customized information views & Twitter events at New Fulcrum Point

Splunk translates machine data into "aha" moments for IT and the business.

ManageEngine Desktop Central - Automate and Audit Your Desktop Management! Learn More...

Cloud Readiness Starts with Intel® Technology

Visit the Virtually There Learning Page to learn how to use virtualization to your competitive advantage.

High performance. Delivered. Click to see Accenture's client successes

CYBERMARYLAND | Learn Why Maryland is the Epicenter for Cybersecurity

Get Ethernet speeds from 1 Mbps to 10 Gbps - Comcast Business Class

Cognizant. Leading in Business, Application & Technology Services

Collaboration: driving better business outcomes

Managed Hosting Buyer's Guide - Benefits to key considerations

Click to see how Accenture has delivered high performance to clients

Learn how Accenture helps clients become high-performing businesses.

Choose New and manage one device instead of 170

Choose New for 8x the firewall and NAT performance

Check out a smart way of mobilizing your business with enterprise-ready Samsung Mobile.

Redefine your data center with HP servers.

Enhance your business with Windstream IT Solutions. Speak to someone local.

BlackBerry® Mobile Fusion. Different mobile devices. One platform.

Akamai Kona Security. Web security so you can innovate fearlessly

Click to see how Accenture has delivered high performance to clients

Free: Hunter Muller's "The Transformational CIO."

Join us for an upcoming Microsoft 365 live online demo event.

Discover your easiest path to unified communications

Virtualizing Your Infrastructure Just Got Easier

Gain cutting-edge insights at MIT in 2-5 day executive programs.

See how Accenture helps clients perform at the highest levels

Connect with global CIOs now at Enterprise CIO Forum

Resource Center