Showing posts with label Authentication. Show all posts
Showing posts with label Authentication. Show all posts

Saturday, September 21, 2013

iPhone 5S: A Biometrics Turning Point?

Future: Mobile Devices Will Boost Interest in Advanced Authentication

Apple's decision to include a fingerprint scanner in its new iPhone 5S is an important step toward bringing biometrics-based authentication into the mainstream. But there's still a long way to go before biometrics supplant usernames and passwords at the enterprise level.

Owners of the new phone can use a fingerprint to physically unlock their devices instead of using a numeric passcode. Apple will also let users confirm purchases from the iTunes store by swiping a finger on the sensor.

Apple have not yet revealed whether they will allow third-party developers to take advantage of the new TouchID fingerprint technology to build biometrics-based authentication into their apps. While TouchID is an important milestone toward getting users comfortable with using biometrics as an authentication credential, the technology has to expand beyond the Apple universe before it can truly be considered a game-changer or a significant security breakthrough.

Biometrics authentication is not new to the mobile space. Some laptop vendors, including Lenovo, have included fingerprint readers in their devices for several years. Plus, a number of smart phones and tablets already incorporate biometrics to authenticate users. And security vendor McAfee recently introduced an online file storage service that relies on voice recognition to authenticate users. But all of these vendors use closed, proprietary models, which has made it difficult for biometrics to gain traction in the marketplace.

Market penetration for PCs and laptops with fingerprint sensors is about 20 percent, according to the FIDO Alliance, an industry group focused on open standards for authentication. Even if a majority of iPhone users opt for the iPhone 5S, overall smart phone market penetration for fingerprint scanners will remain low, considering that research firm IDC estimates Apple has about 17 percent smart phone market share.

The iPhone's popularity and its reputation as a trendsetter could help more consumers feel comfortable with the idea of using fingerprint scanners on a regular basis. And once they are used to the idea of fingerprint scanners, other types of biometrics won't be far behind. TouchID is the "first example of the potential for large-scale mass-market mobile biometric authentication.

Friday, December 7, 2012

10 Key Considerations for Mobile Security

Simple steps to consider for Enterprise Mobile Security

With the expansion of mobile device usage in enterprises as a communication method for corporate and personal information, mobile devices have become an additional source of risk to the enterprise.

To assist the business in managing the risk, several security controls should be considered when deploying mobile devices. They include, but are not limited to:  

1) Strong authentication

2) Data loss prevention (DLP) and data protection controls: Data protection controls include data-at-rest encryption and secure-channel communication.

3) Life-cycle management for enterprise apps: This refers to the ability to inventory, report and control apps on a mobile device, which includes provisioning, updating and deleting enterprise apps.

4) Malware protection

5) Device compliance and antitheft methods: This refers to the ability to perform compliance inspections on the device according to corporate policy and implement loss/antitheft capabilities.

6) Privacy controls: Privacy controls include restricting available device information and real-time auditing of apps to assist with data leakage events.

7) SMS archiving

8) Selective wipe capabilities: Selective wipe refers to the ability to remove specific apps/files from the device without affecting an employee’s personal data and environment (i.e., bring your own device).

9) URL filtering 

Over-the-air (OTA) device management: OTA is a requirement for mobile management and includes device life-cycle management (i.e., discovery, registration, update, deletion, decommissioning).

Monday, June 25, 2012

Recent Survey Reveals Banks Investing More in Emerging Technologies

2012's Top Anti-Fraud Tech Investments


Banks and credit unions say investments in enhanced fraud detection, monitoring systems and customer and member education top their lists for fighting fraud this year.


That's according to BankInfoSecurity's second annual Faces of Fraud survey. A full report on the survey is now available.


More than half of the more than 200 financial institutions that participated in this year's survey say they have increased funding for new fraud technology and personnel.


Top Anti-Fraud Investments


In addition to enhanced detection, monitoring and education, other top anti-fraud investments for banks and credit unions this year include:
  • Improved out-of-band verification;
  • Enhanced controls over account activities;
  • More internal and external audits;
  • Improved vendor management practices;
  • More anti-money-laundering tools;
  • Enhanced dual authorization through different access devices;
  • Improved tracking of high-risk customers and members.
Refer here to download the report.

Sunday, May 13, 2012

Basic checklist for Remove Access Security

The Remote Access Security Checklist


The checklist of must-haves for any remote access policy.


Remote Access Policy Security Checklist


Antivirus software with real-time protection enabled - Make sure company-approved antivirus software is included on all remote access devices and set to update regularly.


Required personal firewall - In addition to antivirus software, a personal firewall should be configured and enabled on all remote devices. If a threat is detected all communications should be blocked.


Defined operating systems - Only allowed operating systems should be able to connect to the corporate network. If your company only uses and supports Windows computers, you should disallow *nix, Macs, etc.


Time out periods – Should be defined and set to when there is no activity on the computer. If there is no activity for 30 minutes for example, enforce a policy so the connection terminates. Be careful to test and make sure a download or upload triggers activity.


Targeted access to systems while on VPN - Only allow access to necessary internal resources. If a department only accesses one application on your internal network only provide them with access to that application.


Non-Disclosure Agreement - Vendors, third party companies, and even employees should sign an NDA in order to gain remote access. This will help protect any confidential information.

Sunday, January 15, 2012

Signcryption: New Technology & Standard to improve Cyber Security

Signcryption is a technology that protects confidentiality and authenticity, seamlessly and simultaneously

For example, when you log in to your online bank account, signcryption prevents your username and password from being seen by unauthorized individuals. At the same time, it confirms your identity for the bank.

UNC Charlotte professor Yuliang Zheng invented the revolutionary new technology and he continues his research in the College of Computing and Informatics. After nearly a three-year process, his research efforts have been formally recognized as an international standard by the International Organization of Standardization (ISO).

News of the ISO adoption comes amidst daily reports of cyber attack and cyber crime around the world. Zheng says the application will also enhance the security and privacy of cloud computing.

“The adoption of signryption as an international standard is significant in several ways,” he said. “It will now be the standard worldwide for protecting confidentiality and authenticity during transmissions of digital information.”

“This will also allow smaller devices, such as smartphones and PDAs, 3G and 4G mobile communications, as well as emerging technologies, such as radio frequency identifiers (RFID) and wireless sensor networks, to perform high-level security functions,” Zheng said.

“And, by performing these two functions simultaneously, we can save resources, be it an individual’s time or be it energy, as it will take less time to perform the task.”

Monday, July 11, 2011

Biometrics Seen as SecurID Alternative?

Exploring Multifactor Authentication

RSA customers who feel victimized by last March's breach of the security vendor's computers have viable options that include continued use of the SecurID authentication tokens, those offered by competitors, or something entirely different: biometrics.

In March, RSA revealed intruders broke into its computers, exposing secret codes for its two-factor authentication SecurID token. Since then, RSA has been working closely with its customers to assure the safety of the product.

The proper precautions RSA provides could satisfy many SecurID user but there is an another option of switching to a competitors' product. Still, at the end of the day, the use of these technologies maintains the status quo. They let you do the same-as-usual type of security. If attacked once, and hacked once, it can certainly be done again. Another approach, would be to implement an alternative factor, such as biometrics.

The concept behind multifactor authentication is that the user provides at least two different factors - something the user has, such as a token; something the user knows, such as a password; and something the user is, such as a fingerprint. In the case of tokens such as SecurID, the factors are what the user has and knows. But users jittery about the security of the has factor could substitute it with the is factor, such as an image of the eye's iris or the sound of a voice.

The enterprise security expert points out that many users own smartphones that, with the right, inexpensive software, can scan an iris or record a voice to produce biometrics that can be employed for authentication. It's not something that can be easily copied from a forensic perspective. Biometrics are a strong play, and they're gaining a lot more acceptance in the industry. What do you think?

Wednesday, July 6, 2011

Webcast: Cloud Security and Smart Security

Security in the cloud – where are we now?

Cloud security is now a very different proposition compared to a year ago with expanding access points, more personal devices, and increasingly sophisticated threats.

In light of this, I thought you might be interested in SC’s upcoming webcast which will give you a valuable, real-world update on where we are today.

The full session and sign up can be found at http://www.scwebcasts.tv.

I have pasted a few more details below though for your reference.

SECURING THE CLOUD - LOCKING DOWN 2011’s MULTIPLE ACCESS POINTS

Going live on 14th July 10:00 am ET / New York, 3pm / London @ http://www.scwebcasts.tv

The webcast will give you tools to:
  • Facilitate strong end user and multifactor authentication in public and private clouds to secure identity and protect your business
  • Keep up to date with current cloud technology and gain architectural perspectives to manage user activity and log ins
  • Gain visibility across the multiple layers of cloud security and assure data protection and ownership in storage and encryption
  • Integrate outsourced IT services with in-house programmes to maximize staff productivity and reduce costs
You may also be interested in another 2 of SC’s recent projects which have proved very popular with group members:
  1. SC WEBCAST: Smart Security for SMEs: Key Cyber-Threats And How To Tackle Them – Going live on July 12 at 10:00 am ET / New York, 3pm / London at http://www.scwebcasts.tv.
  2. SC STUDIO SHOW: The Risks and Rewards of Archiving – hard-hitting video available now at http://www.scstudio.tv.
If you can’t make the live date of the webcasts, you can of course watch them on-demand in the archive at your leisure at http://www.scwebcasts.tv .

As always, feel free to get in touch with any questions.

Wednesday, June 29, 2011

New FFIEC Guidance will help to reduce the increasing security threats?

Final FFIEC Authentication Guidance Issued

The
Federal Financial Institutions Examination Council has formally released the long-awaited supplement to its "Authentication in an Internet Banking Environment" guidance, which was first issued by the FFIEC in October 2005.

Formal assessments for compliance with the
new guidance will begin in January 2012.

The purpose of the supplement is to reinforce the risk-management framework described in the original guidance and update the FFIEC member agencies' supervisory expectations regarding customer authentication, layered security, and other controls in the increasingly hostile online environment.

The official supplement highlights the need for:
  • Better risk assessments;
  • Effective strategies for mitigating known online risks;
  • Improved customer and employee fraud awareness.
In a news release about the official update, the FFIEC says growing sophistication of online threats have increased risks for financial institutions and their customers. "Customers and financial institutions have experienced substantial losses from online account takeovers," the FFIEC states. "Effective security is essential for financial institutions to safeguard customer information, reduce fraud stemming from the theft of sensitive customer information, and promote the legal enforceability of financial institutions' electronic agreements and transactions."

The FFIEC says it will continue to work closely with financial institutions to promote security in electronic banking. Examiners have been directed to formally assess financial institutions under the enhanced expectations outlined in the supplement beginning in January 2012.

The FFIEC is made up of the following regulatory agencies:
the Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency, National Credit Union Administration and Office of Thrift Supervision.

Please refer here to read the changes in the new FFIEC guidance.

Wednesday, April 6, 2011

'Tricked' RSA Worker Opened Backdoor to APT Attack

APT Presents New Attack Doctrine Built to Evade Existing Defenses

A well-crafted e-mail with the subject line "2011 Recruitment Plan" tricked an RSA employee to retrieve from a junk-mail folder and open a message containing a virus that led to a sophisticated attack on the company's information systems, a top technologist at the security vendor says in a blog.

An Excel spreadsheet attached to the e-mail contained a zero-day exploit that led to the installation of a backdoor virus, exploiting an Adobe Flash vulnerability, which Adobe has since patched, writes Uri Rivner, head of new technologies, identity protection and verification at RSA, in a blog posted Friday.

RSA unveiled on March 17 that an attacker targeted its SecurID two-factor authentication product in what it termed an advanced persistent threat breach. An APT refers to sophisticated and clandestine means to gain continual, persistent intelligence on a group such as a nation or corporation. The RSA official says the attacker initially harvested access credentials from the compromised employee and performed privilege escalation on non-administrative users in the targeted systems, and then moved on to gain access to key high value targets, which included process experts and IT and non-IT specific server administrators.

If the attacker thinks they can exist in the environment without being detected, they may continue in a stealth mode for a long while. If they think they run the risk of being detected, however, they move much faster and complete the third, and most 'noisy' stage of the attack. Since RSA detected this attack in progress, it is likely the attacker had to move very quickly to accomplish anything in this phase.

While RSA made it clear that certain information was extracted, it's interesting to note that the attack was detected by its Computer Incident Response Team in progress

Saturday, April 2, 2011

No news is bad news for two-factor logins

Assume SecurID is broken?

It's been a week since RSA dropped a vaguely worded bombshell on 30,000 customers that the soundness of the SecurID system they used to secure their corporate and governmental networks was compromised after hackers stole confidential information concerning the two-factor authentication product.

For seven days, reporters, researchers, and customers have called on RSA, and its parent corporation EMC, to specify what data was lifted – or at the very least to say if it included details that could allow government or corporate spies to predict the one-time passwords that SecurID tokens generate every 60 seconds. And for seven days, the company has resolutely refused to answer. Instead, RSA has parroted Security 101 how-tos about strong passwords, support-desk best practices, and the dangers of clicking on email attachments.

Officials from RSA and EMC have steadfastly refused to give yes or no answers to two questions that have profound consequences for the 40 million or so accounts that are protected by SecurID: Were the individual seed values used to generate a new pseudo-random number exposed and, similarly, was the mechanism that maps a token's serial number to its seed leaked?

Without the answers to those two basic questions, RSA customers can't make educated decisions about whether to continue relying on SecurID to prevent unauthorized logins to their sensitive networks. After all, if the breach on RSA's servers exposed the seeds and the mapping mechanism, SecurID customers have lost one of the factors offered by the two-factor authentication product.

An RSA spokesman released an updated statement earlier this week that said in part: “Our investigation to date has revealed that the attack resulted in certain information being extracted from RSA’s systems. Even with this information being extracted, RSA SecurID technology continues to be an effective authentication solution for customers.” (Notice the statement didn't say “an effective two-factor authentication solution.”)

The statement went on to say that revealing additional details “could enable others to try to compromise our customers’ RSA SecurID implementations, so we are not disclosing further information.”

Translation: Yes, we were hacked, and yes, the hackers made off with confidential information that compromises the security of a product you've spent huge amounts of money on, but you'll just have to trust us that you're still safe.

In the wake of this information blackout, the prudent thing for customers to do is to assume that SecurID seeds have been lifted, and to also assume that the mechanism that maps a particular token's serial number to its individual seed has also been taken. That means if attackers can trick individual SecurID users into giving out the number printed on the back of their token, its two-factor protection has been broken. The same applies if a company's database of serial numbers is breached.

That assumption would be consistent with an advisory RSA sent to customers on Monday urging them to strengthen the personal identification numbers that are used along with a user ID and the one-time password, since the PIN would be the single factor of authentication left.

SecurID's two-factor authentication may not be broken, but until RSA comes clean and provides some yes or no answers to two simple questions, it's better to assume it is. The network security you preserve may be your own.

Tuesday, March 29, 2011

RSA SecurID Breach

RSA Says Hackers Take Aim At Its SecurID Products calling it Advanced Persistent Threat

RSA Executive Chairman Art Coviello, in a posting on the RSA website Thursday, said a company investigation led officials to believe the attack is in the category of an advanced persistent threat. An APT refers to sophisticated and clandestine means to gain continual, persistent intelligence on a group such as a nation or corporation.

In a letter posted on the RSA website on Thursday, Coviello promised qualified transparency in addressing this problem. "As appropriate," he said, "we will share our experiences from these attacks with our customers, partners and the rest of the security vendor ecosystem and work in concert with these organizations to develop means to better protect all of us from these growing and ever more sophisticated forms of cybersecurity threat."

To help customers, RSA issued nine recommendations it says should strengthen SecurID implemantions (see RSA's 9 Recommendations to SecurID Customers).

SecurID consists of a token, either hardware or software, that generates an authentication code at fixed intervals - about once a minute, for instance - using a built-in clock and an encoded random key known as a seed. The seed is different for each token, and is loaded into the corresponding RSA SecurID server as the tokens are acquired.

Coviello said RSA's investigation revealed that the attack resulted in information being extracted from the company's IT systems. "While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack," Coviello said. "We are very actively communicating this situation to RSA customers and providing immediate steps for them to take to strengthen their SecurID implementations."

Coviello said RSA has no evidence that customer security related to other RSA products has been similarly affected. "We do not believe that either customer or employee personally identifiable information was compromised as a result of this incident," he said, adding that RSA will give its SecurID customers the tools, processes and support required to strengthen the security of their IT systems in the face of this incident.

The attack came one day after the top cybersecurity executive at the Department of Homeland Security told Congress that government and private-sector IT systems are at risk from such attacks. "Sensitive information is routinely stolen from both government and private sector networks," Philip Reitinger, DHS deputy undersecretary for national protection and programs told the House Homeland Security Committee. "We currently cannot be certain that our information infrastructure will remain accessible and reliable during a time of crisis."

Saturday, March 12, 2011

HSBC to issue credit card sized Internet banking keycode device

OTP Card or SecurID tokens? What about soft tokens?

HSBC is to issue all customers with a one-time password code reader that can be used without the need to insert a Chip and PIN card.

The device, which is small enough to keep in a wallet or purse, generates a unique PIN code each time a customer logs on to their accounts. Users must enter a personal four-digit PIN to generate the six digit passcode.

Called the HSBC Secure Key, it differs from the approach taken by other UK banks such as the Co-operative Bank, Barclays, RBS and Nationwide which have equipped customers instead with bulkier Chip and PIN card readers.

The device will be issued to all new HSBC customers that register for online banking from 23 March and will be rolled out to all existing customers over the coming months.

Monday, February 28, 2011

New Authentication Guidance

Draft Puts More Responsibility on Banks

A preliminary draft of new online authentication guidance from the Federal Financial Institutions Examination Council puts greater responsibility on the shoulders of financial institutions to enhance their security and prevent fraud.

The FFIEC has yet to formally unveil its long-awaited update to 2005's authentication guidance, but a December 2010 draft document entitled "Interagency Supplement to Authentication in an Internet Banking Environment" was reportedly distributed to the FFIEC's member agencies.

While it's likely that this draft will be amended before the final release of the new guidance, the current document calls for five key areas of improvement:

•Better risk assessments to help institutions understand and respond to emerging threats, including man-in-the-middle or man-in-the-browser attacks, as well as keyloggers;

•Widespread use of multifactor authentication, especially for so-called "high-risk" transactions;

•Layered security controls to detect and effectively respond to suspicious or anomalous activity;

•More effective authentication techniques, including improved device identification and protection, as well as stronger challenge questions;

•Heightened customer education initiatives, particularly for commercial accounts.

Risk Assessments

Risk assessments are addressed first in the draft, leveling some criticism at banking institutions for not being diligent about regular assessments.

The document says risk assessments should include regular reviews of internal systems, analyzing their abilities to:

•Detect and thwart established threats, such as malware;

•Respond to changes related to customer adoption of electronic banking;

•Respond to changes in functionality offered through e-banking;

•Analyze actual incidents of security breaches, identity theft or fraud experienced by the institution;

•Respond to changes in the internal and external threat environment.

Authentication for High-Risk Transactions

The FFIEC's definition of "high-risk transactions" remains unchanged. But the supplement does acknowledge that, since 2005, more consumers and businesses are conducting online transactions.

Layered Security

Layered security includes different controls at different points in a transaction process. If one control or point is compromised, another layer of controls is in place to thwart or detect fraud. Agencies say they expect security programs to include, at minimum:

•Processes designed to detect and effectively respond to suspicious or anomalous activity;

•Enhanced controls for users who are granted administrative privileges to set up users or change system configurations, such as defined users, users' privileges, and application configurations and/or limitations.

Effectiveness of Authentication Techniques

Part of the layered security approach, the draft suggests, should include stronger device identification, which could include use of "one-time" cookies to create a more complex digital fingerprint of the PC by looking at characteristics such as PC configuration, Internet protocol address and geo-location.

Although no device authentication method can mitigate all threats, the supplement says, "the Agencies consider complex device identification to be more secure and preferable to simple device identification."

The need for stronger challenge questions is also noted, as yet another layer institutions can use to authenticate and identify a device and a user.

Customer Education and Awareness

As part of the effort to educate consumer and commercial customers about fraud risks and security measures, the draft states financial institutions should explain what protections are and are not provided under Regulation E. The drafted guidance also suggests banking institutions offer:

•An explanation of under what circumstances and through what means the institution may contact a customer and request the customer's electronic banking credentials;

•A suggestion that commercial online banking customers perform a related risk assessment and controls evaluation periodically;

•A listing of alternative risk control mechanisms that customers may consider implementing to mitigate their own risk;

•A listing of institutional contacts for customers' discretionary use in the event they notice suspicious account activity or experience customer information security-related events.

Stronger Fraud Detection

Beyond the supervisory expectations, the draft guidance includes an appendix that discusses the current threat landscape and compensating controls, including anti-malware software for customers, as well as transaction monitoring/anomaly detection software.

Similar Guidance in Australia?

Well - I am not sure, if we have something like Federal Financial Institutions Examination Council (FFIEC) or similar council in Australia. Until, we find the answer for the question, we should start using the available guideliness available.

Tuesday, July 27, 2010

What's Needed to Improve Strong Authentication

New Authentication Guidance Coming?

Out-of-band authentication - This method sends the additional authentication factor to the user via a different channel from the one he or she is using to access the bank site. For example, a one-time password sent via text message to the user's mobile phone when logging in with a web browser on a PC. The user has to enter the correct OTP within a short time window (usually a few minutes) in order to initiate the session. This authentication helps against man-in-the-middle attacks.


Out-of-band transaction verification - This sends a verification request to the user in the same way as out-of-band authentication, so that the user is required to review and authorize a high-risk transaction that takes place within an online banking session before the transaction is allowed to proceed. This authentication method helps against MITM and man-in-the-browser attacks.


Device identification - This authentication method uniquely identifies the software and hardware being used to access the online banking session. The device, in effect, becomes an authentication factor. This method helps against manipulation of this information by fraudsters such as spoofing IP addresses or deleting cookies.


Mutual authentication - This method is used in addition to authenticating the user to the site, authenticating the site to the user. The most prevalent way of doing this is with Extended Validation SSL certificates. EV/SSL causes the address bar in the browser to turn green when he or she is on the bank's actual website. Other methods include displaying electronic seals on the server and displaying of a user-selected icon in the browser when the user is accessing the genuine bank server. This method helps against phishing, DNS cache poisoning, and other re-direct attacks.


Transaction monitoring - This is not strictly an authentication tool, but monitoring online sessions for high-risk activity such as known trojan behaviors, both at initiation and while the session is in progress, is a very strong complement to these other various authentication techniques described here. Flagged activities have to be acted upon in real time - examples of appropriate responses include sending an alert to the user or an out-of-band transaction verification as described above, blocking access to the online account, or blocking the bank account. Helps against all types of fraud attacks.


Browser-based controls - Institutions can use client-side tools that lock down the user's web browser against malware infection and exposure of sensitive data. This approach helps against a wide array of online fraud attacks, particularly MITM and MITB.


While none of these techniques is completely "airtight" on its own, each one has its own strengths and weaknesses. When used together, they form a solid defense-in-depth approach to protecting the institution's "electronic front door".

Friday, May 14, 2010

Improved Online Security for a Tenth of the Cost

Leak-proof error correction-based protocol to ensure integrity

Computer scientists in the United Kingdom are developing a system that would offer a high level of security at one-tenth the cost of existing systems that use special quantum technology. The fiber-optics system would offer security to two online users by broadcasting a continuous stream of information around the communication loop.


Access to the information would be limited to users who have a secret key. "It is like using background noise to allow two users to share a secret that no one else knows," says University of Hertfordshire professor Bruce Christianson. The fiber-optics system uses a leak-proof error correction-based protocol to ensure integrity.

"Various people have proposed similar ideas in the past, but our system has introduced a novel error correcting scheme, which means we can use cheap fiber-optics technology and make it work at amazingly high transmission rates," Christianson notes.

Refer here for more details.