410 likes | 543 Views
IBA Banking Security Summit 2009. On-line Banking Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank. Agenda. 1. Opportunity 2. Threats 3. Solutions. The Opportunity. Opportunity. The Internet. The Internet. Source: Internet World Stats as of Q2 08. The Internet.
E N D
IBA Banking Security Summit 2009 On-line Banking Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank
Agenda 1. Opportunity2. Threats3. Solutions
The Opportunity Opportunity
The Internet Source: Internet World Stats as of Q2 08
The Internet Source: Internet World Stats as of Q2 08
The Internet Source: Internet World Stats as of Q2 08
The Internet 19 % 72.5 % 73.8 % 5.2 % 63.8 % 26.1 % 68.6 % 58.1 % 70.7 % Source: Internet World Stats as of Q2 08
The Internet Internet Users 1.46 Billion (22%) World Popl. 6.6 Billion On-line Users 584 Million (40%) Funds Transfer 146 Million (20%) Source: Internet World Stats as of Q2 08
Threat Horizon Focus of attacks Organized Crime High Trojans People Pharming Phishing Data Social Engineering Applications Spam Mail Information Leakage / Theft Sophistication of attacks Unauthorised Access Attackers Profile Infrastructure Application Layer Attacks Network Intrusion Malware Website Defacement Disorganized Crime Password Cracking Low Time in years
The Crimeware Landscape Trend Micro
Other Statistics Top Ten Countries by Attack Volume Distribution of Attacks by Hosting Method
The Fraud Supply Chain Technical Infrastructure • Operational • Infrastructure Tools Hosting Delivery Mules Drops Monetizing Harvesting Fraudster Cash Out Fraudster Communication Fraud forum / chat room Customer Account
Fraud as a Service: “Cut the Middle Man” FaaS • Operational • Infrastructure Tools Hosting Delivery Mules Drops Monetizing Cash Out Fraudster User Account
Trojans • Phishing/Pharming Trojans • Keyloggers/Screen-scrapers • MITB Trojans • Active Keylogger + Proxy (Botnet) Trojan
Fast Flux Modus Operandi : Harvesting • Fast-flux networks
Potentially captured via crimeware, given FI & country coverage Underground Market Place : Credentials for Sale
An online ad promoting lists of stolen credit cards Underground Market Place : Credentials for Sale
Phone fraud services to cash out accounts in USA by taking advantage of inherent weaknesses in the Call Centers. This can spoof any number in the United States. The service enables fraudsters to accept incoming calls, posing as the genuine account holder. Latest Trends : Phone Fraud to cash-out
Chat in the Middle : Phishing Attack attempts to steal consumers’ data via bogus live chat support Pop-up chat session with online banking customer Live Chat session with Bank’s “Fraud Dept” looking to validate personal information for better service Request information which may be typically be used for challenge questions New twist in Phishing attack Latest Trends : Chat in the Middle
Multilayer Protection Bank Customer Customer Awareness & Education
Blocking / Shutdowns Bank Customer Anti-Phishing, Anti-Pharming & Anti-Trojan Service Customer Awareness & Education
Command & Control Bot-Herder Anti-Trojan Service Infection / Update Drop Less than 25% of infected PCs are protected by AV applications. Even less effective against the specific threat. Anti-Trojan Service
Authentication Bank Customer Site-To-User Authentication Anti-Phishing, Anti-Pharming & Anti-Trojan Service Customer Awareness & Education
Strong Authentication Bank Customer Second Factor Adaptive Authentication Site-To-User Authentication Anti-Phishing, Anti-Pharming & Anti-Trojan Service Customer Awareness & Education
Adaptive Authentication Fraud Network
Transaction Monitoring Bank Customer Transaction Monitoring Second Factor Adaptive Authentication Site-To-User Authentication Anti-Phishing, Anti-Pharming & Anti-Trojan Service Customer Awareness & Education
Transaction Monitoring Proprietary and Confidential
Bank Customer Physical, N/W, Application, DB & OS level Security Transaction Monitoring Second Factor Adaptive Authentication Site-To-User Authentication Anti-Phishing, Anti-Pharming & Anti-Trojan Service Customer Awareness & Education
Bank Customer Incident Response, Fraud & Case Management Physical, N/W, Application, DB & OS level Security Transaction Monitoring Second Factor Adaptive Authentication Site-To-User Authentication Anti-Phishing, Anti-Pharming & Anti-Trojan Service Customer Awareness & Education