+ All Categories
Home > Documents > The State of End-User Security Global Data from … State of End-User Security Global Data from...

The State of End-User Security Global Data from … State of End-User Security Global Data from...

Date post: 25-Mar-2018
Category:
Upload: doandan
View: 222 times
Download: 1 times
Share this document with a friend
42
SESSION ID: #RSAC Andreas Baumhof The State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ThreatMetrix Inc. @abaumhof
Transcript
Page 1: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

SESSION ID:

#RSAC

Andreas Baumhof

The State of End-User Security Global Data from 30,000+ Websites

MBS-F02

Chief Technology OfficerThreatMetrix Inc.@abaumhof

Page 2: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Goal of this talk

2

Everybody talks mobile, but do we really know what’s out there? What is hype, what is myth?

Provide detailed data that will help you

To differentiate theoretical attacks from reality

Understand the risk surface you are facing

Enable you to make more informed decisions for your mobile strategy

Page 3: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

ThreatMetrix Digital Identity Network

3

All data presented in this talk is powered by the ThreatMetrix Digital Identity Network

Page 4: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Digital Identity Network

4

Consists mainly of Financial Services, Online Retailers and Social Media sites

Main use cases are account logins (76%), payments (21%) and account creations (3%)

Global data from every single country

In short: It is representative data

Page 5: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Explosion of mobile transactions

5

Page 6: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Mobile share of transactions

6

Page 7: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Mobile Statistics for Top Digital Nations

7

Page 8: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Mobile Transaction Trends - Daily

8

Page 9: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Threat view

Page 10: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

2004 – First virus for mobile (Cabir)

10

Page 11: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Security is not an afterthought anymore

11

Page 12: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

So why is this skyrocketing?

12

792 14,259 89,556 403,002

1,612,008

5,158,426

11,864,379

2011 2012 e2013 e2014 e2015 e2016 e2017

Number of Unique New Mobile Malware Strains Released Per Year

Source: McAfee Labs, Aite Group

Page 13: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Software with the most vulnerabilities in 2015

13

Source: http://www.cvedetails.com/

In iOS9: 4 CVE’s with Impact: “Visiting a maliciously crafted website may lead to arbitrary

code execution”

Page 14: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Mobile traffic is different

14

Traditional securitymeasures don’t work aswell as they did in the

past

Page 15: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSACMost high risk transactions are still from the non-mobile channel

15

Page 16: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSACBrowser spoofing is one of the most common “attacks”

16

Page 17: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSACBrowser spoofing is significantly higher on mobile than on non-mobile

17

Page 18: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Detailed statistics

Page 19: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Mobile and Non-mobile OS is converging

19

Data is for all transactions, not just mobile transactions

Page 20: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

iOS is leading the charge

20

Page 21: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSACReversed picture if we look at the high risk transactions

21

Page 22: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Jailbroken devices

22

Page 23: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Jailbreak detection methods

23

Most common identifier for Jailbreak

file:///private/var/lib/cydia

file:///private/var/stash

file:///private/var/lib/apt

Beware though

You would miss 65% of jailbroken detections if you “just” focus on these

Page 24: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

How are people connecting?

24

Page 25: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Location is important

25

On a native mobile device, location can be obtained in many ways

GPS

IP (True IP, DNS IP, …)

Signal strength

Page 26: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

How accurate is the IP Address Location?

26

Connection type: Cellular

Page 27: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

How accurate is the IP Address Location?

27

Connection type: Wifi

Page 28: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

IP Address Anomalies

28

Interesting anomalies can be found by interrogating the IP address of the device and comparing it to the IP address of its used DNS server

IP Geo DNS IP Geo

Russia USA

Ukraine USA

USA Russia

USA Iran, Islamic Republic of

… …

Page 29: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Other anomalies (Xposed)

29

Still on a very low level (< 0.1%), but growing

Page 30: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Device Encryption

30

Android only

Page 31: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSACSurprisingly, mobile app transactions represent more high risk transactions

31

Page 32: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Myths / Assumptions

Page 33: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Operating systems are converging

33

Windows 10

Mac OS/X – iOS

Android – Chrome

When is an OS a mobile OS?

Page 34: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Different OS’s have different attack surface

34

No surprise

Ecosystem

Mobile Ecosystemis much more diverse

Page 35: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Jailbreaking

35

Jailbroken devices are not as commonly used on a global scale

But they do represent a significantly higher risk if they are being used

Page 36: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

OS anomalies

36

There are plenty of anomalies with mobile traffic that is there for the taking

Browser-string vs TCP fingerprint

Page 37: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Take advantage of additional information from mobile devices

Page 38: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Mobile Location

38

IP Address Location

DNS IP Address Location

Hardware / GPS Location

Carrier Location

Page 39: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Huge amount of forensics information available

39

Jailbreak detection

Root Cloaking detection

OS anomalies

Mobile App Integrity

Mobile App Reputation

Page 40: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Conclusion

Page 41: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Mobile is part of the omni-channel

✔✗

Page 42: The State of End-User Security Global Data from … State of End-User Security Global Data from 30,000+ Websites MBS-F02 Chief Technology Officer ... Ukraine USA USA Russia USA Iran,

#RSAC

Rich data + advanced models = win

42


Recommended