rsa – the big picture

25
RSA Identity Protection and Verification Adaptive Authentication, Anti-eFraud Solutions David Mateju RSA Sales Consultant [email protected]

Upload: garrett-clarke

Post on 03-Jan-2016

41 views

Category:

Documents


0 download

DESCRIPTION

RSA Identity Protection and Verification Adaptive Authentication, Anti-eFraud Solutions David Mateju RSA Sales Consultant [email protected]. Encryption Store, Transport. IT infrastructure. information. Access Authentication, Authorization , Anti-fraud Solutions. DLP Data Loss Prevention. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: RSA – The Big Picture

RSA Identity Protectionand VerificationAdaptive Authentication, Anti-eFraud Solutions

David MatejuRSA Sales [email protected]

Page 2: RSA – The Big Picture

RSA – The Big Picture

IT infrastructure

information

EncryptionStore, Transport

SIEMSecurity Information and Event Management

DLPData Loss Prevention

AccessAuthentication, Authorization,

Anti-fraud Solutions

Page 3: RSA – The Big Picture

RSA – The Big Picture

IT infrastructure

information

RSA Encryption andKey Management Suite

RSA enVision Platform

RSAData LossPrevention

Suite

RSA Access Manager

RSA Federated Identity Manager

RSA SecurID

RSA Digital Certificate Solutions

RSA Identity Protection and Verification Suite

Page 4: RSA – The Big Picture

Access

RSA Identity Protection and Verification Suite

Page 5: RSA – The Big Picture

What is Crimeware? Two Broad Classifications

Identity Theft Crimeware

Steals online credentials or any personal data required for identity

takeover, with intent of using the stolen identity to steal funds

• Examples: Keyloggers, screen-scrapers, local pharming Trojans

Funds Transfer Crimeware

Performs unauthorized online transactions to steal funds

Trojans that “hijack” online banking or other secure sessions of infected

users to carry out fraudulent transactions after user has logged out

• Examples: Session-hijacking Trojans, Man-in-the-Browser

Page 6: RSA – The Big Picture

Why On-line?

Universally accessible

Little chance of being caught

Cheap (little infrastructure necessary)

Scalable

Less violent (no gangsters from Jersey to shoot you)

Page 7: RSA – The Big Picture

Is it organized crime?

YES. It is organized. And involves organized crime.

InsidersATM fraudetc.

Universal MITM Phishing Kit

The Fraudster Supply Chain

Page 8: RSA – The Big Picture

Crimeware Ecosystem – Organized Crime

Trojan developers offer guarantied replacement in case the trojan is detected by anti-virus applications

Page 9: RSA – The Big Picture

Future Trojan Developments (“Anti-Anti-Trojan”)

Inline Anti-Virus “tester” and “fixer”

Page 10: RSA – The Big Picture

Need a Piece of Crimeware?

WebMoney Trojan = $500 Snatch Trojan+Rootkit = $600

Limbo personalized $500 / $350 discountedLimbo logs (50MB) $30FTP Checker / Iframer $35Dream BotBuilder $500 + $25 for updatesPinch $30 + $5 for updatesMpack $700 w/ support

Page 11: RSA – The Big Picture

Business of Trojans

Page 12: RSA – The Big Picture

Crimeware Ecosystem – Infection Service

Page 13: RSA – The Big Picture

Zeus Trojan as an example …

Tracking one variant of a very popular tool-kit

In first two weeks infected 32,000 computers• Roughly 4,000 infections a day

No effective anti-virus update available• Highly polymorphic, no consistent binary signature

To date we have recovered 60,000 compromised users and their credentials from this tool-kit alone

Zeus is also known as WSNPOEM

Page 14: RSA – The Big Picture

RSA Identity Protection and Verification Suite

RSA Adaptive Authenticationand Transaction Monitoring (with Risk Engine)

RSA FraudAction

RSA eFraudNetwork

Page 15: RSA – The Big Picture

Behind the Scenes – The RSA Risk Engine

Over 100 risk indicators (factors) are monitored

Self-learning provides immediate response to new threats

Page 16: RSA – The Big Picture

0%

10%

20%

30%

40%

50%

60%

70%

80%

90%

100%

0%1%2%3%4%5%6%7%8%9%

% flagged

% d

etec

ted

Everything Only trx data Only IP & device data Only dev profile

Impact of components on detection

1% flag rate>80% detection !

3% flag rate>95% detection !!

Page 17: RSA – The Big Picture

RSA eFraudNetworkThe World’s Largest Online Fraud Fighting Community

Page 18: RSA – The Big Picture

RSA Adaptive AuthenticationRSA Transaction Monitoring

Fraudulent transfers down by 90%, much higher security

User authentication costs down

Page 19: RSA – The Big Picture

RSA FraudAction – RSA non-stop serviceRSA’s 24x7 Anti-Fraud Command Center

Page 20: RSA – The Big Picture

Anti Trojan - A Systematic Approach to Mitigation

Command & Control Bot-Herder

Infection / Update Drop Zone

Less than 25% of infected PCs are protected by AV

applications. Even less effectively protected against the

specific threat.

RSA’s Anti-Trojan

Solution

Victim’s PC

Page 21: RSA – The Big Picture

Anti Trojan - A Systematic Approach to Mitigation

Command & Control Bot-Herder

Infection / Update

Block(browsers, ISPs)

Shutdown

Block(firewalls, ISPs, content filtering)

Shutdown

(or)

Monitor

Block(firewalls, ISPs, content filtering)

Shutdown

(or)

Monitor

Drop Zone

Page 22: RSA – The Big Picture

Additional Anti-Trojan Services

Only service on market offering these services

Page 23: RSA – The Big Picture

RSA – World “Web Anti-Fraud” Leader

Page 24: RSA – The Big Picture

RSA “Anti-Fraud” Solutions – Selected Customers

Australia:• Adelaide Bank

Canada:• Royal Bank of Canada

France:• Le Crédit Lyonnais

India:• HDFC Bank

Italy:• Banca Popolare di Sondrio

Japan:• Mizuho Bank

• Nomura Securities

• Sony Bank Inc.

• Sumitomo Mitsui Banking Corporation

• The Bank of Fukuoka

South Africa:• Standard Bank

UK:• Barclays Bank

• ING Direct

USA:• Bank of America

• Bank of the West

• Baxter Credit Union

• Century Bank

• Commerce Bancorp, Inc.

• E*Trade

• Eglin Federal Credit Union

• Finance Center Federal Credit Union

• Mid America Bank

• State Employees' Credit Union (SECU)

• Susquehanna Bancshares

• TCF Financial Corporation

• Tennessee Valley Federal Credit Union

Page 25: RSA – The Big Picture