by Paul Desmond

How Schwab shuts out hackers

News
Jan 29, 20078 mins

Charles Schwab implements sophisticated system aimed at preventing unauthorized Web site logons.

It’s a simple promise that Charles Schwab & Co. makes to its customers, but one with security ramifications that ripple throughout the company: “Schwab will cover 100% of any losses in any of your Schwab accounts due to unauthorized activity.”

It’s a simple promise that Charles Schwab & Co. makes to its customers, but one with security ramifications that ripple throughout the company: “Schwab will cover 100% of any losses in any of your Schwab accounts due to unauthorized activity.”

What the pledge means in practice is that security extends to every corner of the Schwab organization, according to Kostas Konstantinides, director of client Web services for Schwab. “Security is beyond IT definitely at Schwab,” he says. “It’s also at the branches, it’s in our mailing of statements. Everything that has to do with interacting with clients has a security element attached to it.”

Technology, of course, plays a central role when it comes to the company’s Web site. Konstantinides told attendees at the recent Network World IT Roadmap event in San Francisco about the latest tool in the Schwab arsenal to help protect customers’ online accounts from unauthorized logons. The very week of the conference, Schwab had gone live with its implementation of VeriSign’s Fraud Detection System. The system is designed to weed out suspicious logon attempts and either deny them outright, mark them for human evaluation or escalate them to an additional level of authentication.

Finding the right tool

Schwabs use of the Fraud Detection System is the culmination of an evaluation process that began in early 2005. The goal was to find an additional security layer beyond the existing back-end firewalls and intrusion-detection systems that could help protect the $1.4 trillion in assets the company maintains in 6.8 million brokerage accounts.

Schwab looked at various types of security measures to authenticate Web site visitors, from password expiration schemes to one-time passwords, biometrics and knowledge-based authentication. One criteria was the vendor had to provide a single product and also deliver the majority of the security as part of a user’s online experience, as opposed to forcing users to some form of out-of-band security mechanism, such as a token.

“When you put in a criteria like that, the list becomes relatively small,” Konstantinides says, noting VeriSign quickly bubbled to the top. In early 2006, Schwab began looking at the VeriSign Fraud Detection System in depth. At that point, the product was relatively new, with few customer installations. Indeed, VeriSign only publicly announced it as a service in February 2006. Rather than use it as a service, however, Schwab bought the software and worked with VeriSign to implement it on Schwab servers.

“We took a very deep look at the product and its capabilities and had our IT folks evaluate the method it was using to do the fraud detection,” says Konstantinides, whose role falls on the business side of the house at Schwab but has been involved with Schwab.com since its inception. “We determined it was something that we could integrate in our environment and that it was flexible enough to handle new forms of attacks, not only the ones that were known.”

Schwab's security

Customer experience was also high on Schwab’s list of criteria. If a customer’s session wasn’t considered risky, the company didn’t want to be bothering that customer with additional authentication requests.

The VeriSign system fit the bill because it is a self-learning system that takes into account past user behavior in determining whether a logon attempt is suspicious. Users who follow the same routine time after time will have no problem. Only when they do something different will the system raise a red flag and, potentially, throw up a challenge.

Getting to that point meant spending time adjusting system parameters. “We ran six months of data into the system with known fraud cases and tweaked it to the point where there was an acceptable level of false positive interventions, while it caught a good deal of the fraud,” Konstantinides says.

Schwab also built in a cut-off capability, such that if there was a problem with the Fraud Detection System it could quickly be taken offline. Security would revert to the previous user ID and password, without affecting the client experience. The company also implemented the product in silent mode for a time to observe its behavior and ensure all was well.

Going live

Those tests went well enough that Schwab cut over to production mode the week of Nov. 30. Now the system handles suspicious activities in a number of ways.

For users, the process remains the same – they use an ID and password. Logon attempts that are not deemed to be at all suspicious are simply approved, with no further user intervention. In cases that are somewhat suspicious, such as when a user logs on from a different computer, a user is still allowed to log on, but the system creates a case for a fraud analyst to examine later. The fraud analyst will determine if a similar type of logon attempt will warrant manual intervention in the future. If not, the analyst can “teach” the system not to flag the same behavior again.

Where a user logon attempt is clearly fraud, such as from a previously restricted IP address, the system simply disallows the logon attempt.

Schwab will soon be going live with an improvement on the authentication process for suspicious logon attempts. In such cases, the user will be asked to select a phone number from those on file for their account. An automated system will call the number and give the user a code to enter. If the code is entered correctly, the system learns not to challenge the same behavior again. If the client doesn’t authenticate correctly, perhaps closing their browser instead, the system will again intervene until the client successfully authenticates. Such a scenario will also create a case for a fraud analyst to examine, and potentially follow up on manually. That capability is expected to go live in the second quarter, Konstantinides says.

Still, the system is already delivering impressive results, as the company expected it would when the system caught all the known fraud cases that Schwab threw at it during initial testing.

“It’s not 100%, but Schwab is not dependent just on this for security,” Konstantinides says, noting the company has a layered approach with back-end systems that can capture unauthorized logins further downstream. “What we’ve done is taken a lot of that logic and brought it to the front end. This allows us to do immediate intervention and basically resolve any issues up front.”

Consider the visible

During his IT Roadmap talk, Konstantinides presented three Schwab security considerations:

• Security is everybody’s business – don’t pay attention and it will hurt business

• The best security is not always visible

• Security which is not visible might not always satisfy client needs

Regarding that last point, he says it’s important for client peace of mind to present visible examples of security, so customers know Schwab does have security measures in place. “We can do that, or we can try to explain to every client that we have a sophisticated system in place protecting them. Sometimes it’s easier to just do the visible things,” he says.

Such visible things include offering hardware tokens for authentication and occasionally reminding clients to change their passwords, which Schwab does every six months. “That is very basic, very simple,” Konstantinides says. “But if done properly and if you change your password regularly it does help protect against fraud.”

Meanwhile, the security guarantee acts as a motivator for the company to pay attention to security while the Fraud Detection System is an example of good security that’s not visible. Asked to determine what kind of ROI the fraud system is delivering, Konstantinides says it’s possible to take a static measure and say that by preventing fraud targeted at certain accounts the system saved X number of dollars. But a better method, he says, is to look at the fraud numbers across the industry and whether Schwab’s share is decreasing.

“The system is relatively new and I can’t say that there’s been a direct effect yet,” he says. But when he looks at the fraud numbers that others in the industry are reporting, he says, “We haven’t seen the level that others have been reporting – or anywhere near.”

Desmond is events editor for Network World and president of PDEdit, an IT publishing company in Southborough, Mass. Reach him at paul@pdedit.com.