Find White Papers
Home
About Us
List Your Papers
    
> ArcSight > Detecting, investigating & responding to fraudulent transactions is essential for business operation

Detecting, investigating & responding to fraudulent transactions is essential for business operation

White Paper Published By: ArcSight

This document will outline the requirements for an effective fraud mitigation solution. It will detail a solution that considers the entirety of an organization’s fraud mitigation strategy.



Tags : 
fraud, siem, arcsight, mitigating fraud, intrusion prevention systems, fraudsters, fraud policy, insider threats

ArcSight
Published:  Mar 04, 2009
Type:  White Paper
Length:  8 pages

White Paper
Mitigating Fraud with the ArcSight
SIEM Platform
Table of Contents
Executive Overview 3Today's Fraud Solutions 4 ArcSight's Approach 4 Key Capabilities 5 Summary 8About ArcSight 8
Mitigating Fraud with the ArcSight SIEM Platform 2Executive Overview"A business, agency, or individual that thinks it is invulnerable to fraud is, in fact, the most inviting to fraudsters." Howard Silverstone and Howard DaviaFraud 101Techniques and Strategies for Detection
Detecting, investigating and responding to fraudulent transactions from within and outside an organization is an essential function of business operations. This is the case for virtually any organization that requires Web, Web services and non-Web applications to run their business. Unfortunately, most organizations have inadequate solutions in place to deter fraudsters and lack the support tools for fraud investigators to quickly identify fraud and respond to the threats effectively. In fact, Ernst & Young sited in their 9th Global Fraud Study that over 40% of respondents do not even have a formal anti-fraud policy let alone detection, investigation and response solutions. For fraudsters, as the risk of detection increases the desirability of the target decreases. Thus prudence dictates that while fraud may never be eliminated entirely, by leveraging solutions that can accurately detect fraudulent activity, overall business risk can be mitigated.When most organizations start thinking about fraud solutions, a number of questions generally arise:. Do we not already have an adequate solution?. Are there tools that can "really" detect fraud?. We are watching our applications - isn't that enough?. Monitoring external fraud is hard enough, how can we possibly monitor fraud from internal, trusted users?The ArcSight SIEM Platform is designed to integrate with fraud solutions much the way it does today with products such as firewalls, routers and intrusion prevention systems. Through this integration, organizations can benefit from more comprehensive analysis such as correlation, anomaly detection, and pattern discovery. More holistic reporting, visual analytics and incident response can also be leveraged. Perhaps most importantly, all the capabilities can be applied beyond applications and address a wide-range of internal and external threats.This document will outline the requirements for an effective fraud mitigation solution. It will detail a solution that considers the entirety of an organization's fraud mitigation strategy.
Mitigating Fraud with the ArcSight SIEM Platform 3Today's Fraud SolutionsMost fraud solutions today are myopic in their approach. They do a good job detecting fraudulent application transactions following a user's authentication - i.e. post-authentication, for a small set of business applications when those actions are perpetrated by external users. This is an important issue to address, but it leaves holes in the overall fraud mitigation strategy. For example, most organizations consist of more than a few business applications, they contain:. Network Infrastructure (routers and switches). Security Products (firewalls and intrusion prevention). Mission-Critical Assets (business applications, sensitive data stores, identity management, access control). Physical Security and Telephony Solutions (badge readers, video, call center applications)Looking at any one of these areas may provide limited value; however, looking at all of these areas collectively ensures more holistic risk mitigation. Additionally, by having a broader perspective that includes the mission critical assets and all the supporting data, detecting fraudulent transactions perpetrated by trusted users, insiders with legitimate access, becomes more probable. Finally, current solutions tend to be heavily focused on post-authentication within a given application. For example, once a user accesses the application by providing their credentials and proceeds to engage in nefarious activity within that application. There is no question that monitoring for this is necessary, which is why ArcSight collects events from these point fraud solutions. But prior to post-authentication is pre-authentication, and during this phase several types of attacks can be addressed such as brute force attacks.
ArcSight's ApproachArcSight addresses the issue of fraud with the ArcSight SIEM Platform. The ArcSight SIEM Platform i... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search