on-line banking risks & countermeasures by vishal salvi – ciso hdfc bank

41
Confidential Confidential On-line Banking On-line Banking Risks & Countermeasures Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank By Vishal Salvi – CISO HDFC Bank IBA Banking Security Summit 2009

Upload: channing-thompson

Post on 30-Dec-2015

25 views

Category:

Documents


0 download

DESCRIPTION

IBA Banking Security Summit 2009. On-line Banking Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank. Agenda. 1. Opportunity 2. Threats 3. Solutions. The Opportunity. Opportunity. The Internet. The Internet. Source: Internet World Stats as of Q2 08. The Internet. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

On-line Banking On-line Banking Risks & CountermeasuresRisks & Countermeasures

By Vishal Salvi – CISO HDFC BankBy Vishal Salvi – CISO HDFC Bank

IBA Banking Security Summit 2009

Page 2: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Agenda

1. Opportunity1. Opportunity2. Threats2. Threats3. Solutions3. Solutions

Page 3: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Opportunity

OpportunityOpportunity

Page 4: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Internet

Page 5: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Internet

Source: Internet World Stats as of Q2 08

Page 6: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Internet

Source: Internet World Stats as of Q2 08

Page 7: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Internet

Source: Internet World Stats as of Q2 08

Page 8: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Internet

Source: Internet World Stats as of Q2 08

19 %

72.5 %

73.8 %

5.2 %

63.8 %

26.1 %

68.6 %

58.1 %

70.7 %

Page 9: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Internet

Source: Internet World Stats as of Q2 08

World Popl. 6.6 Billion

Internet Users 1.46 Billion (22%)

On-line Users584 Million (40%)

Funds Transfer146 Million (20%)

Page 10: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Threats

Page 11: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Infrastructure

Applications

Data

People

So

ph

isti

ca

tio

n o

f a

tta

ck

s

Low

High

Focus of attacks

Time in years

Password Cracking

Website Defacement

Malware

Network Intrusion

Application Layer Attacks

Unauthorised Access

Information Leakage / Theft

Spam Mail

Social Engineering

Phishing

Pharming

Organized

Crime

Disorganized

Crime

Att

ac

ke

rs P

rofi

le

Trojans

Threat Horizon

Page 12: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Threat Horizon

Page 13: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Trend Micro

The Crimeware Landscape

Page 14: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Phishing

Page 15: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Phishing Stats

Page 16: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Other Statistics

Distribution of Attacks by Hosting Method Top Ten Countries by Attack Volume

Page 17: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

The Underground Fraud Ecosystem

Page 18: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

TechnicalInfrastructure

Cash OutFraudster

The Fraud Supply Chain

HarvestingFraudster

OperationalInfrastructure

CommunicationFraud forum / chat room

Customer Account

Tools Hosting Delivery Mules Drops Monetizing

Page 19: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Cash OutFraudster

Fraud as a Service: “Cut the Middle Man”

OperationalInfrastructure

User Account

Mules Drops Monetizing

FaaS

Tools Hosting Delivery

Page 20: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Trojans

• Phishing/Pharming Trojans• Keyloggers/Screen-scrapers• MITB Trojans• Active Keylogger + Proxy (Botnet) Trojan

Page 21: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Modus Operandi : Harvesting

– Fast-flux networks

Fast FluxFast Flux

Page 22: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Underground Market Place : Credentials for Sale

• Potentially captured via crimeware, given FI & country coverage

Page 23: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Underground Market Place : Credentials for Sale

• An online ad promoting lists of stolen credit cards

Page 24: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Underground Market Place : Herding Mules

Page 25: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Phone fraud services to cash out accounts in USA by taking advantage of inherent

weaknesses in the Call Centers. This can spoof any number in the United States. The

service enables fraudsters to accept incoming calls, posing as the genuine account holder.

Latest Trends : Phone Fraud to cash-out

Page 26: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Chat in the Middle : Phishing Attack attempts to steal consumers’ data via bogus live chat support– Pop-up chat session with online banking customer– Live Chat session with Bank’s “Fraud Dept” looking to validate personal

information for better service• Request information which may be typically be used for challenge questions

– New twist in Phishing attack

Latest Trends : Chat in the Middle

Page 27: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Solutions

Page 28: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Multilayer Protection

Customer Awareness & EducationCustomer Awareness & Education

BankBank CustomerCustomer

Page 29: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Awareness

Page 30: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Anti-Phishing, Anti-Pharming & Anti-Trojan ServiceAnti-Phishing, Anti-Pharming & Anti-Trojan Service

Customer Awareness & EducationCustomer Awareness & Education

Blocking / Shutdowns

BankBank CustomerCustomer

Page 31: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Infection / Update DropCommand & Control Bot-Herder

Less than 25% of infected PCs are protected by AV

applications. Even less effective against

the specific threat.

Anti-Trojan Service

Anti-Trojan Service

Page 32: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Site-To-User AuthenticationSite-To-User Authentication

Anti-Phishing, Anti-Pharming & Anti-Trojan ServiceAnti-Phishing, Anti-Pharming & Anti-Trojan Service

Customer Awareness & EducationCustomer Awareness & Education

Authentication

BankBank CustomerCustomer

Page 33: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Site-To-User Authentication

Page 34: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Second Factor Adaptive AuthenticationSecond Factor Adaptive Authentication

Site-To-User AuthenticationSite-To-User Authentication

Anti-Phishing, Anti-Pharming & Anti-Trojan ServiceAnti-Phishing, Anti-Pharming & Anti-Trojan Service

Customer Awareness & EducationCustomer Awareness & Education

Strong Authentication

BankBank CustomerCustomer

Page 35: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Adaptive Authentication

Fraud Network

Page 36: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Transaction MonitoringTransaction Monitoring

Second Factor Adaptive AuthenticationSecond Factor Adaptive Authentication

Site-To-User AuthenticationSite-To-User Authentication

Anti-Phishing, Anti-Pharming & Anti-Trojan ServiceAnti-Phishing, Anti-Pharming & Anti-Trojan Service

Customer Awareness & EducationCustomer Awareness & Education

Transaction Monitoring

BankBank CustomerCustomer

Page 37: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidentialProprietary and Confidential

Transaction Monitoring

Page 38: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Physical, N/W, Application, DB & OS level SecurityPhysical, N/W, Application, DB & OS level Security

Transaction MonitoringTransaction Monitoring

Second Factor Adaptive AuthenticationSecond Factor Adaptive Authentication

Site-To-User AuthenticationSite-To-User Authentication

Anti-Phishing, Anti-Pharming & Anti-Trojan ServiceAnti-Phishing, Anti-Pharming & Anti-Trojan Service

Customer Awareness & EducationCustomer Awareness & Education

BankBank CustomerCustomer

Page 39: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Traditional layers of Security

Page 40: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential

Physical, N/W, Application, DB & OS level SecurityPhysical, N/W, Application, DB & OS level Security

Transaction MonitoringTransaction Monitoring

Second Factor Adaptive AuthenticationSecond Factor Adaptive Authentication

Site-To-User AuthenticationSite-To-User Authentication

Anti-Phishing, Anti-Pharming & Anti-Trojan ServiceAnti-Phishing, Anti-Pharming & Anti-Trojan Service

Customer Awareness & EducationCustomer Awareness & Education

Incident Response, Fraud & Case ManagementIncident Response, Fraud & Case Management

BankBank CustomerCustomer

Page 41: On-line Banking  Risks & Countermeasures By Vishal Salvi – CISO HDFC Bank

ConfidentialConfidential