* Cydelity adds a layer of defense in the battle against phishing
endif; ?>Forget that spam e-mail urging you to visit a special Web site to input your personal data and verify your bank account. That is so last-year when it comes to phish attempts. Today’s phishers are getting more sophisticated, using man-in-the-middle tactics that are virtually undetectable by either the user or the legitimate Web site, until it’s too late.
An article in Secure Computing describes an attempt to usurp account data from PayPal customers by inserting a phishing site between the user and the legitimate PayPal site. Since the phishing page communicates with both the user and PayPal, neither party realizes there is a site in the middle stealing confidential information. Citibank was also the victim of such a scheme this past summer. Experts predict this is the wave of the future for phishing.
Perhaps the most alarming aspect of this new tactic is that it is designed to circumvent even multi-factor user authentication schemes. For example, if you suspect a fake site is asking for your information, you might enter bogus information when prompted for your user ID, password, or a token-generated key. Because the phishing site is communicating with the real site, the bogus authentication information returns an error, just as it would if you entered it straight into the real site. This might confuse you or cause you to think that the phishing site is the real thing, leading you to give your valid identity information to a bad site.
For many security solutions, the lock is at the front door of a network or an application. But what happens if someone gets past the front door? Typically, he has free access to do whatever a legitimate user can do. This is where Cydelity gets in the game.Cydelity calls itself “the last line of defense” in your many layers of security. Cydelity has a fraud detection system called eSentry that looks for behavioral patterns and identifies risky activities. Once this risky behavior is identified, the application owner can take some type of remedial action, such as locking the person out of an application, or preventing him from doing something.
Most IT security measures look at the technical aspects of whether or not a user can do something. For instance, does this user have a valid user ID? Does he possess a required security dongle? Does he have the correct WEP key?
Cydelity, however, looks at what the user is doing relative to appropriate business behavior. For instance, is the user trying to transfer all the funds from a bank account to an offshore account? Is the user attempting to use a credit card, issued to a customer in New York, from a PC located in Romania? Is the user making numerous attempts to access children’s profiles on a social networking site? All of these actions should sound an alarm, and with eSentry, they do.
Here’s how eSentry works. First, it sniffs all network traffic, and finds only the traffic that matters. For example, eSentry doesn’t care about someone wanting to download a marketing brochure, but it does care about someone wanting to pay bills online. Then it aggregates all the pertinent traffic into an analytic engine that has been taught how to look for inappropriate behavior from a business context.
When misbehavior is spotted, eSentry issues an alarm. Alarms can be “inline” or “offline.” An inline alarm takes immediate action, such as forcing a user to reauthenticate himself, or locking the user out of an application. An offline alarm triggers good old-fashioned casework, such as an investigation led by fraud specialists.
While the banking industry seems like the most likely customer for eSentry, there are all sorts of applications where this type of “behavioral fingerprinting” could be useful. For instance, click fraud. A Web site that generates revenue from clicks can use eSentry to determine if thousands of clicks are coming from a single source. Or social networks like MySpace. Predators sometimes set up bots to try to establish chat sessions with dozens of kids at a time. This kind of repetitive behavior can be revealed and the traffic from the source blocked. Other applications that would benefit from this kind of technology would include e-commerce, online gaming and online gambling.
As misuse of the Internet and private networks becomes more sophisticated, our defense mechanisms need to grow in sophistication as well. Cydelity’s eSentry is one more line of defense to prevent or stop unwanted behavior.
* For more about man-in-the-middle and other phishing attempts, read “”Sport phishing morphs into cybercrime wave” at NetworkWorld.com.




