Let’s face it: Authentication factors as we know them are not holding down the fort. The practice of providing something you know, something you have and something you are is failing, even when we are asked repeatedly to provide multiple factors of authentication.

Passing Around Passwords

Passwords are a dying breed. The excessive use of passwords, coupled with the need to make them complex and replace them every few months, has driven many users to recycle them across various services. In fact, according to the “TeleSign Consumer Account Security Report 2016,” 71 percent of accounts are guarded by passwords that are used across multiple sites. So when a password is compromised due to a phishing attack or data breach, multiple accounts belonging to that user are also at risk.

Knowledge-based authentication (KBA) makes up the other piece of the “something you know” requirement. According to the TeleSign report, 56 percent of users consider KBA to be their preferred means of additional authentication. Gartner research, however, found that users fail to answer their knowledge-based questions 15–30 percent of the time, while fraudsters answer correctly 60 percent of the time. Malicious actors often find this information on social networks or through phishing schemes.

Shifting Away From SMS Authentication

To fulfill the “something you have” requirement, we used to have physical tokens that generated different one-time passwords (OTPs) every 60 seconds. This practice has shifted to mobile phones, with OTPs being sent as text messages. However, mobile malware can intercept these messages and forward them to fraudsters.

This growing threat influenced the National Institute of Standard and Technology (NIST) to recommend a shift away from SMS-based OTPs.

Sticky Fingers

Biometric authentication is cool. It’s easier to use than other forms of authentication and can be much more secure. Or is it?

It is definitely easier to use fingerprint readers, for example, than to type, which has led to the exponential growth of fingerprint reader-enabled devices. It didn’t take long, however, for cybercriminals to circumvent this technology. Moreover, if the biometrics enrollment process is not properly secured, a cybercriminal — or even a young child — can register his or her own fingerprints with a victim’s password.

Trust, but Verify

New technologies such as behavioral biometrics, which identify anomalies in users’ ongoing behavior, have the potential to replace passwords and help organizations avoid compromise. However, in the cat-and-mouse game of cybercrime, it’s only a matter of time before threat actors devise behavior replay attacks or other forms of circumvention. Isn’t there a better way to manage secure identities rather than continuing to add more hoops for users to jump through?

Read the white paper: Outsmarting Fraudsters with Cognitive Fraud Detection

The key is not in what strategies we use, but rather in how we use them. While users can provide proof of their identities, so, too, can the malicious actors who compromise them; that’s where the principle of “trust, but verify” comes in. When users enter their passwords or use known devices, there should be indicators of malicious intent if the information is being submitted by a fraudster.

Here are a few examples:

  • For “something you know” credentials, indicators should show whether users have been phished or otherwise infected with malware, which would suggest that their credentials may have been stolen.
  • For “something you have,” indicators should help analysts determine whether a user’s device has been compromised by malware or another means of stealing SMS messages. This should put any OTP response by the user in question. In addition, evidence of device-identifying parameters being spoofed or of remote-access Trojans (RATs) being used may indicate that the user’s known-devices identification has been compromised.
  • For “something you are,” it’s critical to identify particular biometrics, such as a specific fingerprints, associated with multiple accounts of various users.

A Complete Identity Picture

When such indicators are coupled with traditional authentication factors, they paint a more holistic picture of identity corroboration, one that shows not only the bright colors of the positive identity indicators, but also the shadows of malicious actors. This delivers a much higher level of trust in the established identity picture. IBM Security’s Identity and Access Management and identity analytics solutions can provide this complete picture.

To keep the identity corroboration process effective, however, it must adapt continuously to identify new attack and risk indicators — but that’s a topic for another post.

More from Fraud Protection

Kronos Malware Reemerges with Increased Functionality

The Evolution of Kronos Malware The Kronos malware is believed to have originated from the leaked source code of the Zeus malware, which was sold on the Russian underground in 2011. Kronos continued to evolve and a new variant of Kronos emerged in 2014 and was reportedly sold on the darknet for approximately $7,000. Kronos is typically used to download other malware and has historically been used by threat actors to deliver different types of malware to victims. After remaining…

How Security Teams Combat Disinformation and Misinformation

“A lie can travel halfway around the world while the truth is still putting on its shoes.” That popular quote is often attributed to Mark Twain. But since we're talking about misinformation and disinformation, you’ll be unsurprised to learn Twain never said that at all. In fact, no one knows who first strung those words together, but the idea that truth spreads slowly while lies spread quickly is at least several hundred years old. The “Twain” quote also serves to…

A View Into Web(View) Attacks in Android

James Kilner contributed to the technical editing of this blog. Nethanella Messer, Segev Fogel, Or Ben Nun and Liran Tiebloom contributed to the blog. Although in the PC realm it is common to see financial malware used in web attacks to commit fraud, in Android-based financial malware this is a new trend. Traditionally, financial malware in Android uses overlay techniques to steal victims’ credentials. In 2022, IBM Security Trusteer researchers discovered a new trend in financial mobile malware that targets…

New DOJ Team Focuses on Ransomware and Cryptocurrency Crime

While no security officer would rely on this alone, it’s good to know the U.S. Department of Justice is increasing efforts to fight cyber crime. According to a recent address in Munich by Deputy Attorney General Lisa Monaco, new efforts will focus on ransomware and cryptocurrency incidents. This makes sense since the X-Force Threat Intelligence Index 2022 named ransomware as the top attack type in 2021. What exactly is the DOJ doing to improve policing of cryptocurrency and other cyber…