Is Your Online Bank Really Secure? -...

27
Is Your Online Bank Really Secure? Zoltan Szalai / eBanking Solution Manager April 25, 2013

Transcript of Is Your Online Bank Really Secure? -...

Page 1: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

Is Your Online Bank Really

Secure?

Zoltan Szalai / eBanking Solution Manager April 25, 2013

Page 2: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 2

Page 3: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 3

Gemalto for You ONE THIRD OF THE WORLD’S POPULATION USE OUR SOLUTIONS EVERYDAY

BANKS & RETAIL

TELECOM

TRANSPORT

GOVERNMENT

ENTERPRISE

Page 4: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 4

40

70

200

MILLION ADVANCED DEVICES

MILLION DEVICES

EMPLOYEES

About eBanking

Over €2 BILLION in Revenue in 2012

€250+ MILLION Software and

Value Added Services

BILLION Intelligent Cards Produced and

Personalized on a Yearly Basis

14 R&D Centers

1,400 Scientists

15 Production Sites

28 Presonalization Centers

74 Sales & Marketing Offices

10,000 + Employees

100 Nationalities

43 Countries

About Gemalto

60

25

20%

MILLION IN REVENUE 2012

MILLION IN REVENUE 2009

EXPECTED ANNUAL GROWTH

Business Overview

Page 5: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 5

Gemalto’s Position 2013 MAGIC QUADRANT FOR STRONG AUTHENTICATION FROM GARTNER

As of March, 2013

Page 6: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 6

Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE” SECTOR TOP 20 COMPANIES

As at March 27, 2013

Company Name Country Revenue (€bn)

1 MICROSOFT UNITED STATES 55.2

2 ORACLE UNITED STATES 27.5

3 SAP GERMANY 16.2

4 CATAMARAN UNITED STATES 7.7

5 SYMANTEC UNITED STATES 4.9

6 VMWARE UNITED STATES 3.6

7 CA UNITED STATES 3.5

8 ADOBE SYSTEMS UNITED STATES 3.4

9 INTUIT UNITED STATES 3.2

10 IT HOLDINGS JAPAN 3.0

11 INVENSYS UK 2.9

12 AMDOCS UK 2.5

13 SALESFORCE.COM UNITED STATES 2.4

14 GEMALTO NETHERLANDS 2.2

15 CERNER UNITED STATES 2.0

Page 8: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 8

Frauds & Mitigation

Page 10: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 10

Phishing Attack

are familiar with phishing

Low to very low knowledge of other attacks Source: RSA Online Fraud Report

Victim

Bank Server

1) Sends fake

“security” email

with fake link

2) Enters secure

information on

fake internet

bank site

Fake Server

3) Obtains account

information

4) Using obtained

account information

on real internet

bank site

Page 11: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 11

Man-in-the-Middle Attack

Victim

Bank Server

Malware Waits for

Transaction and

Modifies Details!!!

Page 12: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 12

Man-in-the-Browser Attack

Website Seen

by the Customer

Website Seen

by the Bank

Malware Changes

Transaction Details

Malware Changes

Balance Information

Malware Inside the Browser

Page 14: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 14

eFrauds in the Region

Page 15: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 15

Ezio Solution

Page 16: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 16

Gemalto Ezio Suite

Ezio Suite is the market’s most versatile

and easy-to-implement

eBanking security solution with a proven

track-record of 100+ large-scale roll-outs.

STRONG E-BANKING AUTHENTICATION ARCHITECTED FOR CHOICE

200+BANKS

ONE

SERVER MULTIPLE

CHANNELS

ALL EZIO

DEVICES WORK IN

PARALLEL

STANDARD

COMPLIANT INCL. OATH,

CAP/EMV, PKI

70m DELIVERED

DEVICES

Token-

Agnostic Appliance

Delivery

Page 17: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 17

Introduction to New Ezio Server

Pre-Hardened All-in-One Box Appliance

Providing Multi-Factor Authentication

Used by 30+ Banks &

Millions of Users

R&D and Produced in Singapore

Page 18: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 18

Advantages of Ezio Server

Multi-Million User

Deployment

Token Agnostic

Authentication Brokering

Thousand Transactions per Second

Multi-Token Support per

User

End-to-End Encryption of Passwords

Supports Global

Standards

Page 20: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 20

Evolution is Leading to Mobile

Page 21: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 21

Day-to-Day eBanking is Partially Transiting to Mobile

Find Nearest Branch /

ATM

Block Lost/Stolen

Card

Check Balance

View Transaction

History

Make Money Transfer

Page 22: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 22

Ezio Mobile Solutions

Access Bank with Web Browser

Protected by Mobile Token

Access Bank with Native Application

Protected by Mobile SDK

Page 23: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 23

Ezio Mobile SDK

OTP Computation

Smartphone Support

Secure Storage

Secure Personalization

Security Expertise

Device Fingerprint

Easy to Integrate API

Future Proof

Page 24: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 24

Ezio Mobile Token

OTP Computation

Smartphone Support

Customizable

Based on Ezio SDK

Page 25: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 25

Summary

Page 26: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

eBanking Security 26

Why EZIOTM

from Gemalto?

Global Presence – Local Touch

All-in-One Physical Appliance

Wide Range of Security Devices

Most Secure Mobile Solution Available Today

Page 27: Is Your Online Bank Really Secure? - PCWorld.bgidg.bg/...16...Is_Your_Online_Bank_Really_Secure.pdf · 6 eBanking Security Gemalto’s Position ICB - “TECHNOLOGY – SOFTWARE”

Thank You!

Zoltan Szalai / eBanking Solution Manager April 25, 2013