Redesigning Security Strategy to Protect the Navigation Layer
In a recent conversation with Fahmida Rashid, senior writer at eWeek, the concept of the Navigation Layer and how companies can begin to secure this layer of the Web was of particular interest. I wanted to briefly recap the highlights of this discussion, as it may be helpful for organizations looking to improve their Navigation Layer security to protect against malware and abuses of site logic.
Ultimately we all know that having the right security strategy in place from the outset is cheaper and better because it means that protections are in place from the get-go, and you avoid the potential losses associated with data breaches, business logic abuse and various forms of cyberattacks. However, what kinds of costs are organizations looking at if they have to now (with greater awareness) go back to their Websites and applications and make sure that they are secure at the Navigation Layer so as not to be taken advantage of by cybercriminals?
Re-doing your security from scratch is not a viable option as it requires enormous development efforts and project resources as well as the expertise to actually build systems to monitor the Navigation layer,which is typically not readily available. Moreover, it’s an ongoing challenge to keep home-grown systems up to date with the latest attack signatures and advanced analytics. Patch jobs are also tough for the same reasons, though depending on the site this may be more or less expensive and resourcing the expertise remains a key hurdle.
Companies can’t, however, sit back and ignore the Navigation Layer threat, as that approach pretty much equates to covering your eyes and ears and pretending everything is a-OK.
As a result, more companies are turning to third party solutions to supplement or solely provide risk detection and mitigation systems at the Navigation Layer. A few key things for companies to consider when evaluating third party solutions include:
· How much back-end development work is needed to get the solution deployed? Does site code need to be modified?
· Does the solution provide signature-based detection, heuristic models, or both?
· How much visibility will the solution have into the site traffic? Will it be able to see more than individual login and transaction events?
· Is it able to monitor for emerging threats or can it only detect attacks that are already known? How quickly can it adapt to new threats?
· How well does the solution scale for larger websites?
Companies certainly have their work cut out for them, but an accurate evaluation of build vs. buy options – once you consider development, deployment, project management, product management, statisticians/scientists, fraud analysis, hardware, and resource bandwidth made unavailable for other projects – will almost always show that purchasing a proven solution is the more cost effective option.
January 26, 2012 Posted by Jesse McKenna | Detection, Fraud, information security, Prevention | Detection, Fraud, information security, Navigation Layer, Prevention | Leave a Comment
About
Silver Tail is leading the fight against business logic abuse with 3rd generation fraud prevention.
Hackers are no longer high school kids trying to one-up their friends or criminals trying to just break-in to sites. Instead, today’s sophisticated hacker is organized crime, strategically targeting websites, stealing billions of dollars from companies and their customers. Vendors providing web application security and intrusion prevention have forced hackers to become much more innovative in their means of attacking websites. These hackers now target the legitimate business logic of websites to perpetrate their fraud, including hijack threats, velocity attacks and gaming schemes. Silver Tail is using the deep domain expertise of its team to provide software that combat business logic abuse in real-time.
Silver Tail was founded by a team of fraud prevention experts who built anti-fraud and anti-phishing tools at eBay and PayPal. Through their experience and proprietary algorithms, they have built a system that is scalable, minimizes false positive rates, and is extremely flexible to adapt to changing attack vectors.
Blogroll
Related
-
Recent Posts
- The Groundswell of Internet Governance Initiatives
- Did Google Make the Right Move to Protect the Android Market?
- Silver Tail Systems and MasterCard Join Together to Protect E-Commerce Websites
- Silver Tail Systems and MasterCard Join Forces to Secure Digital Payments for E-Commerce Merchants
- Being Proactive About Data Protection
Feedburner
RSS Feed
Tags
419 scam APWG Attack Intelligence Summit award Best of Show business logic abuse business logic flaws conference Cost of fraud credit cards cross-site-scripting cybersecurity Detection efraudnetwork FFIEC financial institutions Finovate FinovateStartup09 Fraud government information security Investigation law enforcement malware Man-in-the-Browser man-in-the-mobile Navigation Layer nigerian scam Online Fraud online security password password guessing Phishing Prevention ROI rsa conference scams SEC guidance security Social engineering Social Networks software-as-a-service Trust Webinar Zeus
-
Archives
- February 2012 (5)
- January 2012 (4)
- December 2011 (7)
- November 2011 (8)
- October 2011 (9)
- September 2011 (5)
- August 2011 (7)
- July 2011 (7)
- June 2011 (6)
- May 2011 (4)
- April 2011 (6)
- March 2011 (5)
-
Categories
- behavior analysis
- business logic abuse
- Business Logic Flaw
- Business Process Abuse
- Compliance
- Cost of fraud
- Data Loss
- Detection
- education
- Fraud
- Gaming
- General
- information security
- Investigation
- Man-in-the-Browser
- Online Fraud
- Payment
- Phishing
- predictive analytics
- Prevention
- risk management
- Social engineering
- Social Networks
- Trust
- Uncategorized
- web logic abuse
- Zeus
-
RSS
Entries RSS
Comments RSS
