Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

5/9/2019
10:30 AM
Chris Ryan
Chris Ryan
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

Fighting Back Against Tech-Savvy Fraudsters

Staying a step ahead requires moving beyond the security techniques of the past.

It seems that a new fraud scheme emerges  every day. And with billions of compromised credentials, criminals have been implementing a high volume of fraud attacks on organizations across all industries.

The latest fraud scheme — known as credential stuffing — involves criminals who have access to advanced systems and technology using the stolen credentials to log in to online accounts. While credential stuffing has been around for a few years, the current iteration of the scheme is so advanced that criminals can make login requests appear to come from different IP addresses and different browsers. This helps bypass fraud prevention defenses that recognize multiple attempts from a single IP address.

But beyond the technological advances that criminals leverage, the challenge for most organizations is the tendency for people to reuse usernames and passwords across multiple sites. That means the credentials that were stolen may not have originated from the affected organization. And according to Experian's "2019 Global Identity & Fraud Report," more than two in five consumers worldwide have already experienced a fraudulent event online at some point in their lives. To make matters worse, organizations still heavily rely on usernames and passwords as the primary security method — confirmed by the report, which showed passwords, PIN codes, and security questions remain the most widely used authentication methods by businesses.

While organizations can take the steps to educate consumers on best practices for online security and passwords, there needs to be more proactive measures to protect people's accounts and information. If not, the risk of account takeover fraud could increase exponentially — especially with the prevalence among consumers to use mobile devices to access online accounts. According to Javelin Strategy & Research's "2019 Identity Fraud Study," in 2018, 17% of account takeover victims had their mobile phone account compromised, compared with 10% in 2017.

As increasing numbers of people use smartphones and tablets for financial transactions and email, organizations must explore heightened fraud prevention measures, such as advanced device intelligence. The use of device characteristics needs to be more sophisticated than the traditional collection of high-level attributes like browser type, operating system version, and IP address. These characteristics are often easy to spoof, enabling criminals to mask the origin of the login request.

Organizations tend to prioritize identifying devices that they're familiar with, but it may be more important to authenticate the devices that they don't recognize. We have the advanced data and technology to help businesses analyze and assess characteristics that go beyond the use of cookies to verify an individual's identity, letting an organization more accurately isolate credential-stuffing attacks.

For example, if most credentials are being used from a specific geolocation — particularly one that has been used in previous attacks — it could indicate fraudulent behavior. But businesses can also analyze the velocity at which the information and device is being used — criminals tend to reuse data and access multiple accounts from the same device at a high volume within a short period of time.

Device intelligence is only one component of a successful fraud prevention and identity management strategy. The combination of device identification technology with advanced analytics, such as biometrics, machine learning, digital tokenization, and document verification can help an organization uncover anomalies that may indicate fraudulent behavior. But more importantly, these advanced measures protect people's information while requiring little effort on behalf of the consumer.

The earlier in the process that an organization can detect fraud, the more damage to a customer's account and identity it can prevent. And that means a happy, loyal customer.

Criminals will always look to exploit weaknesses and vulnerabilities within an organization's systems; however, technology and advanced analytics can help businesses counteract the threat. There is no silver bullet for fraud prevention, but there are multiple approaches that help businesses make the right fraud decisions and protect people's identities.

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Chris Ryan is a Senior Fraud Solutions Consultant at Experian. He delivers expertise that helps clients make the most from data, technology, and investigative resources to combat and mitigate fraud risks across the industries that Experian serves. Ryan provides clients with ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/30/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5991
PUBLISHED: 2020-10-30
NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.
CVE-2020-15273
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be executed by entering specific characters in the account that can ac...
CVE-2020-15276
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
CVE-2020-15277
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.
CVE-2020-7373
PUBLISHED: 2020-10-30
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is ...