December 4, 2017 By Mark Samuels 2 min read

IT decision-makers need to evolve beyond two-factor authentication (2FA) and design new ways to make the user verification process intelligent and risk-aware.

In an article for Harvard Business Review, Sridhar Muppidi, chief technology officer for identity and access management solutions at IBM Security Systems, noted that while existing 2FA systems provide some protection against cyber risks, they are not a panacea. Instead, he suggested that users explore a mixture of push notifications and advanced technologies to verify identities.

Attackers Exploit Two-Factor Authentication

Compared to a single-factor authentication method, such as a password used in isolation, 2FA relies on a second input to assure the system that an individual is authenticated to access a service. Muppidi noted that these one-time passwords are often the first line of defense for companies looking to boost security.

However, single-use passwords can be vulnerable to attack. Muppidi reported that cybercriminals have identified a vulnerability in the method phones used to authenticate identities. They are exploiting this vulnerability to steal valuable data and resources, including cryptocurrencies.

There is also a growing number of cases in which attackers contact mobile network providers and ask to transfer control of a victim’s number to a device under their control, reported The New York Times. Attackers can then receive SMS notifications intended for users, and use this information to reset and access online accounts.

Pursuing Alternative Authentication

Muppidi advised organizations looking to strengthen their authentication methods to tie the push notifications used in a 2FA system to the device rather than to the phone number. Specialist software tools, such as security applications with mobile authentication, can provide assurance in this area.

Smarter management of SMS push notifications is just the first step toward more effective authentication. IT decision-makers must consider modern solutions that include identity access and management technologies controlling access to resources.

Multifactor authentication (MFA) allows enterprises to use a range of techniques to authenticate users and identify where applications flag unexpected activity. Behavioral analytics can complement this approach, and allow IT teams to change security levels based on the value of data and the risks presented.

Improving Verification Methods

The development of verification techniques continues. For example, researchers at Florida International University and Bloomberg have generated a new 2FA system that works by prompting the user to take a picture of a personal object. The system, known as Pixie, could offer a more convenient and secure alternative to traditional authentication processes.

While waiting for these new advancements to come, Muppidi advised companies to establish a layered and risk-based defense. Enterprises should pursue a multifactor approach by using systems and analytics in combination to handle security concerns and combat risks. Additionally, IT decision-makers need to ensure that more of their information security budget is directed toward key prevention and detection techniques, such as behavioral analytics.

More from

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Obtaining security clearance: Hurdles and requirements

3 min read - As security moves closer to the top of the operational priority list for private and public organizations, needing to obtain a security clearance for jobs is more commonplace. Security clearance is a prerequisite for a wide range of roles, especially those related to national security and defense.Obtaining that clearance, however, is far from simple. The process often involves scrutinizing one’s background, financial history and even personal character. Let’s briefly explore some of the hurdles, expectations and requirements of obtaining a…

CISA releases landmark cyber incident reporting proposal

2 min read - Due to ongoing cyberattacks and threats, critical infrastructure organizations have been on high alert. Now, the Cybersecurity and Infrastructure Security Agency (CISA) has introduced a draft of landmark regulation outlining how organizations will be required to report cyber incidents to the federal government. The 447-page Notice of Proposed Rulemaking (NPRM) has been released and is open for public feedback through the Federal Register. CISA was required to develop this report by the Cyber Incident Reporting for Critical Infrastructure Act of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today