Find White Papers
Home
About Us
List Your Papers
    
> Arcot > Protecting Online Customers from Man-in-the-Middle Attacks

Protecting Online Customers from Man-in-the-Middle Attacks

White Paper Published By: Arcot

Man-in-the-Middle attacks can defeat most kinds of multi-factor authentication, including OTP tokens. Financial institutions, brokerages, and other likely targets of MITM attacks should consider the ability of their countermeasures to defeat MITM attacks, as these types of attacks will continue.



Tags : 
authentication, identification, identity, identity theft, arcot, man in the middle, man-in-the-middle, mitm

Arcot
Published:  Jun 04, 2008
Type:  White Paper
Length:  3 pages

Protecting Online Customers from
Man-in-the-Middle AttacksWhitepaper
W H I T E P A P E R
MITM attacks can bypass THE EMERGENCE OF A NEW THREATmany security tools, includ- In 2006, a new type of sophisticated phishing attack appeared on the Internet targeting aing OTP tokens, device bank's business customers. These attacks, called "Man-in-the-Middle", used a fraudu-identification, and knowl-edge-based authentication. lent email to fool the bank's customers into divulging their credentials on a site thatappeared legitimate. What was unusual about these Man-in-the-Middle (MITM) attacks isArcot offers a way to defeat that they succeeded in spite of the customers using one-time password (OTP) tokensMITM automatically that is that generated a unique password every minute.invisible to users, easy todeploy, and low-cost. The fraudulent email stated that someone had tried By intercepting the traffic between the customer to log into the customer's account and that the cus- and the portal, an attacker has the freedom to:tomer needed to "confirm" the account information. . Capture the user's credentials and use them toWhen the customer followed the link, he opened a repeatedly gain access to the portal posing as web site that looked identical to the bank's business the genuine user (when the credential is a fixedportal. When the user entered his credentials, includ- password)ing the token-generated one-time password, the . Log into the system while presenting a "Systemfraudulent site used them to authenticate with the temporarily down" or "I am unable to log you in"legitimate banking portal immediately (See diagram 1) message to make the user think the portal is not available (when the credential is dynamic,The fraudster displayed an "I am unable to log you in" such as with an OTP token)message once users had entered their credentials, . Log into the system and simply relay all activitymaking legitimate customers think the system was between user and the portal until the user tries unavailable. Meanwhile, the fraudster used the to end his session. Then provide a "You are nowcredentials to gain access and initiate unauthorized logged off" message while remaining logged into transfers of funds. the user's account (when the credential is dynamic,such as with an OTP token)
FIGURE 1: MAN-IN-THE-MIDDLE ATTACKS
1. User clicks on link in a phishing email, goes to goes to MITM site and enterscredentials (including token-generated "I am unable to Verification one-time password)log you in" Dialog Real Bank 2. MITM site connects with Bank site and 4 3 Site impersonates legitimate user using phished credentials1 2 3. Bank site grants MITM account accessMan-In-The-MiddleUser Site User Credentials Credentials 4. MITM displays phony page stating systemis unavailable, or waits until user wants to log off, then displays phony page confirming log-off
1Protecting Online Customers from Man-in-the-Middle Attacks Whitepaper
False Sense of Security phishing site replicates the challenge from the domainThis success of the MITM attack highlighted the false sense server, the ArcotID client will not sign the challengeof security that many types of authentication can give IT/ because the fraudulent site does not have valid domainSecurity teams within organizations. In the case of the OTP information. Therefore, the attacker is unable to completetoken, the real-time relay of the legitimate credentials by the the authentication.MITM to the legitimate bank site defeated the security of theOTP token. The validity of a password generated by an OTP The Arcot multi-factor approach to protecting and verifyingtoken is between 30 and 60 seconds, which enabled the user identities is invisible to end-users. The Flash client pro-fraudulent user to capture the temporary password and for- vides an opportunity for IT/Security teams to upgrade users toward it on to the portal, while the password was still alive. strong authentication without requiring any change to thefamiliar username/password login interface. Users log in withThe root problem in an MITM attack is that a user has no way their familiar credentials, and 'behind the scenes' the strengthof verifying who is asking for his authentication information. of PKI-based multi-factor authentication verifies and protectsConsequently, most two-factor credentials, including OTP their identity. tokens, risk analysis engines, personal assurance messagesor pictur... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search