combating cybercrime with behavior analysis

29
Combating Cybercrime with Behavior Analysis

Upload: nucaptcha

Post on 18-Dec-2014

873 views

Category:

Technology


0 download

DESCRIPTION

Our CTO recently did a web presentation to (ISC)2 on Combating Cybercrime with Behavior Analysis. Implementing behavior analysis has been getting some traction in the security field. A recent Forrester Research report stated one North American retailer reduced fraud losses from a peak of $2M in 2001 to $180,000 in 2010 after implementing third-party behaviour management services and advanced fraud-detection rules. The video addresses using data analysis, security response, and constant auditing in building an effective behaviour analysis system.

TRANSCRIPT

Page 1: Combating Cybercrime with Behavior Analysis

Combating Cybercrime with

Behavior Analysis

Page 2: Combating Cybercrime with Behavior Analysis

Who Am I?

•  Christopher Bailey, Chief Technology Officer at NuCaptcha

•  NuCaptcha specializes in adaptive authentication

2

Page 3: Combating Cybercrime with Behavior Analysis

The High Cost of Cybercrime

“CyberSource estimates total revenue loss in North America due to online fraud is $3.4 billion—a $700 million increase over 2010.”

2012 Online Fraud Report; CyberSource

3

Page 4: Combating Cybercrime with Behavior Analysis

Behavior Analysis Defends Against Cybercrime

4

Page 5: Combating Cybercrime with Behavior Analysis

Behavior Analysis is Effective

“Forrester Research reports one North American retailer reduced fraud losses from a peak of $2 million in 2001 to $180,000 in 2010 after implementing third-party behavior management services and advanced fraud-detection rules.”

Forrester Research Case Study: “Online Retailer Uses New Fraud Detection Systems To Cut Fraud Loss Rates”

5

Page 6: Combating Cybercrime with Behavior Analysis

Behavior Analysis Overview

6

Page 7: Combating Cybercrime with Behavior Analysis

Challenges

“In our business, catching the bad guys can be really difficult. Since there’s nothing being shipped, we’ve got to stop them up front. Our real challenge is trying to find them fast and reject the order outright.”

New Era Tickets, Vice President of Client Services Steve Geib

7

Page 8: Combating Cybercrime with Behavior Analysis

Part 1: Data Analysis

8

Page 9: Combating Cybercrime with Behavior Analysis

“To improve fraud detection and combat fraud, focus on gathering as much data as possible on every transaction, no matter how trivial it may seem.”

CyberSource 2012 Report on Online Crime

Collect Lots of Data!

9

Page 10: Combating Cybercrime with Behavior Analysis

Three Types of Analysis

•  Inter-user analysis

•  Intra-user analysis

•  Extra-user analysis

10

Page 11: Combating Cybercrime with Behavior Analysis

Inter-user Analysis

11

Page 12: Combating Cybercrime with Behavior Analysis

Intra-user Analysis

12

Page 13: Combating Cybercrime with Behavior Analysis

Extra-user Analysis

13

Page 14: Combating Cybercrime with Behavior Analysis

Combining Signals

14

Page 15: Combating Cybercrime with Behavior Analysis

Data Analysis Review

•  Build behavior baselines

•  Detect anomalies and outliers

•  Signal a risk

15

Page 16: Combating Cybercrime with Behavior Analysis

Part 2: Security Response

16

Page 17: Combating Cybercrime with Behavior Analysis

Response Selection

•  Rule based systems –  If X then

•  Point based systems –  If points > Y then – Points ~= Level of Risk

17

Page 18: Combating Cybercrime with Behavior Analysis

Keep it Flexible

“Anomalies such as shipping 10 computers to a single home address can also be a sign of potential fraud. Recognizing this activity requires flexible rule sets that can recognize not just static strings but also regular expressions or wildcards.”

Forrester Research Case Study: “Online Retailer Uses New Fraud Detection Systems To Cut Fraud Loss Rates”

18

Page 19: Combating Cybercrime with Behavior Analysis

Response Types

•  Absolute

•  Deferred

•  Secondary Authentication

19

Page 20: Combating Cybercrime with Behavior Analysis

Deferred Responses

20

Page 21: Combating Cybercrime with Behavior Analysis

Response Costs

•  Every response has a potential benefit

•  Every response has a potential cost

21

Page 22: Combating Cybercrime with Behavior Analysis

Security Response Review

•  Be Flexible

•  Keep it Simple

•  Know the Costs

22

Page 23: Combating Cybercrime with Behavior Analysis

Part 3: Auditing

23

Page 24: Combating Cybercrime with Behavior Analysis

Auditing in Three Steps

•  Monitor Accuracy

•  Investigate Changes

•  Update the Model

24

Page 25: Combating Cybercrime with Behavior Analysis

Respond to Changes

“The hardest thing about fraud is it’s so dynamic… what we’re chasing today is not what we’ll be chasing six months from now.”

Laura Lively, ShopNBC’s Credit Investigation Manager

25

Page 26: Combating Cybercrime with Behavior Analysis

Auditing Review

•  Verify responses are: – Appropriate – Effective

•  Audit Process: – Monitor –  Investigate – Update

26

Page 27: Combating Cybercrime with Behavior Analysis

BAS in Three Parts Review

27

Page 28: Combating Cybercrime with Behavior Analysis

In Summary

•  Cybercrime is costly to businesses

•  BAS helps fight cybercrime

•  BAS is a three step process

28

Page 29: Combating Cybercrime with Behavior Analysis

Questions? Click on the questions tab on your screen, type in your question, name

and e-mail address; then hit submit.

29