About
Subscribe

Worldwide financial community tackles increasing fraud attacks

Johannesburg, 07 Oct 2011

The global financial community is responding positively to the continuous growth in online channel fraud by developing effective strategies that focus on risk-based authentication, collecting intelligence and real-time data sharing.

Uri Rivner, Head of New Technologies: Identity Protection of RSA, The Security Division of EMC, says: “We are starting to see greater levels of international corroboration helping law enforcement agencies in the investigation and prosecution of online fraud. It's encouraging to see that the huge investment made is now resulting in success stories.”

A key trend in this development is that, both in South Africa and worldwide, banks have adopted multiple lines of defence. Some, such as behind-the-scenes monitoring, are invisible to consumers, while facilities like additional forms of authentication are familiar and well recognised.

According to Rivner, the focus now is on analysing attacks and collecting intelligence to learn more about how fraudsters operate and the methods they use. This approach enables financial institutions to stay one step ahead of fraud attempts. To this end, financial communities around the globe are sharing data more effectively.

“As far as specific threats are concerned, we are seeing more custom-built Trojans, which use clever social engineering to manipulate users into believing they are interacting with a bank or a Web site. Here again, multiple lines of defence, advanced analytics, intelligence and data sharing, are critical to understanding and anticipating suspicious behaviour,” he says.

“Trojans are used not only to obtain financial information, but also to collect social networking, e-mail accounts and even online dating information. It might be useful to the fraudsters if they know more about their victims. If the individual is a corporate employee, this means the Trojan can collect corporate-related data.

“Enterprises, therefore, need to assume that employees will be compromised at some point, and that perimeter defences are no longer totally effective. Nowadays, it's not a question of how to stop intruders getting into the system, but what to do once they are inside. The industry recognises that the focus, therefore, needs to be on detection and investigation tools inside the enterprise.”

In this regard, Rivner mentions the high industry interest in newly acquired Netwitness, considered the leader in network-level security analysis, threat detection and incident investigation and response.

Rivner advises computer users to allow applications such as browsers, Flash, Java and PDF Reader to perform upgrades when they prompt the user to do so, but only immediately after the computer boots up, as this is an effective means of protection. If the request to update or install new software comes when the user is already browsing online, however, it's best not to upgrade as these are typically attempts to trick the user into downloading some kind of malware.

Commenting on other trends, Rivner says the e-commerce world of airline travel is at high risk. Fraudsters order tickets a day or two before travel, pick up the ticket from an automated kiosk, use a name that is slightly misspelled so a direct check won't match their own name, and provide fake address information. More sinister activities in which stolen credit cards are used include human trafficking and terrorist activities.

Mobile is regarded as the new frontier of fraud attacks, as emerging mobile banking and mobile payment schemes have become a new target for cyber crime. The good news, however, is that defence mechanisms can be better than those used online, and there is a greater chance of identifying fraudulent behaviour with the right technology.

Through its global 24/7 Anti-Fraud Command Centre, RSA leads the global fight against external threats such as phishing, crime-ware and Trojan attacks. The centre works with thousands of hosting entities worldwide to mitigate and shut down attacks.

“The Command Centre also feeds information to partners such as some of the leading providers of Internet browsers to enable attacks to be blocked at the browser and tool bar level, preventing users from divulging information to spoofed Web sites while shut-down efforts continue,” Rivner says.

Share

RSA

RSA, The Security Division of EMC, is the premier provider of security, risk and compliance management solutions for business acceleration. RSA helps the world's leading organisations succeed by solving their most complex and sensitive security challenges. These challenges include managing organisational risk, safeguarding mobile access and collaboration, proving compliance, and securing virtual and cloud environments.

Combining business-critical controls in identity assurance, encryption and key management, SIEM, data loss prevention and fraud protection with industry-leading eGRC capabilities and robust consulting services, RSA brings visibility and trust to millions of user identities, the transactions that they perform and the data that is generated. For more information, please visit www.RSA.com and http://www.EMC.com.

EMC

EMC Corporation is a global leader in enabling business and service providers to transform their operations and deliver IT as a service. Fundamental to this transformation is cloud computing. Through innovative products and services, EMC accelerates the journey to cloud computing, helping IT departments to store, manage, protect and analyse their most valuable asset - information - in a more agile, trusted and cost-efficient way. Additional information about EMC can be found at http://www.EMC.com.

Editorial contacts

Debra de Wet
Redline, a division of DRAFTFCB
(011) 566 6000
Sonelia du Preez
EMC Southern Africa
(011) 581 0033