Added controls reduce 'fraudian' slip

By Vivian Yeo, ZDNet Asia
Tuesday, November 21, 2006 05:13 PM

SINGAPORE--Banks need to look beyond two-factor authentication and implement other levels of controls in order to successfully tackle fraud, according to the group security strategist at National Australia Bank.

Speaking Tuesday at the Secure IT 2006 conference here, James Cerantonio noted that identity theft is a growing threat. Citing recent comments from Thomas Harkins, former operations director of Mastercard's fraud division, Cerantonio said that ID theft is "poised to increase by a factor of 20" over the next two years. The financial services segment, in particular, is a heavily targeted sector for financially-motivated attacks.

But authentication, whether session-based or transaction-based, is a limited mode of protection. Cerantonio said: "The weakest link [in fraud management] is in the definition of the 'problem'. The problem is not authentication; it is the authorization of the transaction."

In addition to authenticating user identity, he noted that banks need to put in place tools to secure the Internet infrastructure and identity unusual network behavior.

A proper fraud management system, therefore, should encompass authentication as a component of front-end controls, as well as additional tools such as virus scanning and anti-spyware, he said.

Controls also need to be implemented at the bank's online infrastructure and back-end systems. To protect the Internet infrastructure, banks can engage in IP (Internet Protocol) monitoring and intrusion mechanisms such as intrusion prevention and intrusion detection. Backend controls include tools to detect transaction anomalies.

To better detect fraud, Cerantonio urged financial institutions to gather intelligence at all levels and "correlate date from multiple channels and sources". He added that they then need to use the data or risk losing out financially.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary Part 4: Using OpenAmplify via SOAP

Web Development

Justin James walks you through the process of using the SOAP interface to OpenAmplify from Visual Studio 2008.


Read more »



When technology costs more than human

Blog thumbnail

Movie director James Cameron waited 15 years for technology to catch up before it was sufficiently advanced for him to create the much-anticipated upcoming film, Avatar.

To be released in..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web