ellen_messmer
Senior Editor, Network World

Banks under gun to bolster online security

News
Sep 4, 20064 mins

Federal guidance pushes industry to find safer ways to protect transactions.

Federal mandate spurs banks to try out new security technologies.

“After the initial log-in, we’ve added a PIN guard, which is an [automated teller machine]-like pad to combat keyloggers,” says Rudy Wolfs, CIO at ING Direct, a savings bank with $62 billion in assets and 4.1 million customers in the United States. The PIN guard is meant to foil keyloggers, by requiring use of a mouse instead of a keyboard.

ING Direct developed its own PIN guard, but also turned to security products and services from RSA Security that include a way to present random questions during the logon process that can be answered by legitimate users. ING Direct also uses a software token to profile a user’s machine for security purposes (a method known as device identification), and an antiphishing and fraud-detection service that rates online account use according to several risk factors.

Tech Credit Union, in San Jose, says its online security processes also are intended to comply with the beefed-up FFIEC online banking regulations. Tech Credit Union provides online banking services, including account viewing, bill paying and Automated Clearing House-based transfers to other banks.

Victor Smilgys, vice president of e-commerce at the credit union, says the logon process still is based on authenticating through user name and password, but it also requires the legitimate accountholder to select prechosen images from a randomly presented group of images. Like ING Direct’s Web site, Tech Credit Union’s site can identity remotely an accountholder’s machine through a software token. “We recognize a member by the computer when they register,” Smilgys says.

Tech Credit Union relies on RSA Security and Digital Defense for this variety of online banking security protections. Similar security software and services are offered by Entrust and VeriSign, among others.

While handheld, one-time password tokens are viewed as strong two-factor authentication, few banks in the United States have adopted them as a consumer-banking strategy for satisfying the FFIEC guidelines.

CitiBank three months ago said it would be handing out free Digipass GO3 tokens to its CitiBusiness Online customers. These small-to-midsize commercial customers, numbering about 100,000, are expected to use the Digipass token when online for cash management. Without the token, they get a limited view of their account data but can’t transfer funds. A Citibank spokesman says the bank has no immediate plans to provide hardware tokens to consumer customers.

In an update issued in mid-August to clarify what it expects banks to be doing by year-end, the FFIEC said it won’t require the use of hardware tokens for authentication.

In addition, the FFIEC stated it wasn’t recommending multifactor authentication “over layered security or other compensating controls.”

The FFIEC primarily wants to see evidence that risk is mitigated in high-risk transactions.

“The term layered security includes other risk-mitigating controls that would not strictly be considered multifactor authentication,” the FFIEC stated in the update, adding it wants banks to identity “other factors appropriate for consideration in the risk assessment.”

While that kind of message sounds vague – and suggests regulators are giving banks great discretion in how they beef up security – it makes sense to Robert Kirby, manager of information security architecture at TD Banknorth, a Portland, Maine, financial institution with $40 billion in assets.

TD Banknorth has installed vulnerability-assessment and risk-assessment software from Skybox as one step in satisfying the FFIEC regulations. “The FFIEC is requiring risk assessment, and we see Skybox as part of our risk-assessment process,” Kirby says.

The FFIEC’s pronouncements are not only giving existing security products and services a boost, but also spurring new ones.

West Palm Beach, Fla.-based Authentium, for example, says this November it expects to introduce software called VirtualATM that could be used by banks or ISPs to lock down computers, according to Cory O’Donnell, vice president of marketing.

VirtualATM creates a VPN tunnel from a bank customer’s computer to the bank’s Web site and uses client software or an applet-based control to connect securely a Web browser conducting a transaction. It would halt interaction with other desktop applications, such as keyloggers, spyware or other malicious agents, according to Authentium.

Although there are no banks or ISPs now using VirtualATM, which will be offered as a software-development toolkit, Cox Communications is interested in beta-testing it.