SONY CASE STUDY PROTECTING FROM WEB BROWSER BASED CYBER ATTACKS

Similar documents
VeinID SCANNERS FOR DIGITAL SIGNING. Hitachi s VeinID Solution for signing digital transactions enables new levels of security and user convenience.

FINGER VEIN SERVER FOR RETAIL BANKS

DIGITAL AUTHENTICATION FOR MICROSOFT WINDOWS PCS

HITACHI FINGER VEIN SERVER. Finger Vein Server (FVS) is the heart of Hitachi s finger vein (FV) biometric solution for Retail Banking.

Your security on click Jobs

LIMITE EN COUNCIL OF THE EUROPEAN UNION. Brussels, 26 September 2008 (30.09) (OR. fr) 13567/08 LIMITE ENFOPOL 170 CRIMORG 150

Unique Phishing Attacks (2008 vs in thousands)

Electronic payments in the Netherlands

Protecting Against Online Banking Fraud with F5

Integrated Access Management Solutions. Access Televentures

CYBER SECURITY OPERATION CENTER

10 KEY WAYS THE FINANCIAL SERVICES INDUSTRY CAN COMBAT CYBER THREATS

Red ALERT Apparent Breach of an Unidentified Pharmacy Related Database

FOREWORD DR PHILIP SMITH MBE CHAIRMAN MILTON KEYNES BUSINESS LEADERS PARTNERSHIP

Unit: mm Max Max Max Min 5.06 Max Min ± ± 0.10

FAQ. Usually appear to be sent from official address

The situation of threats in cyberspace in the first half of 2018

CERT Development EFFECTIVE RESPONSE

PHISHING ATTACK TARGETING UNIVERSITY STUDENTS MAY 2016

Quick Heal Total Security for Mac. Simple, fast and seamless protection for Mac.

Key Findings from the Global State of Information Security Survey 2017 Indonesian Insights

Cyber fraud and its impact on the NHS: How organisations can manage the risk

Put Identity at the Heart of Security

2SD2103. Silicon NPN Triple Diffused. Application. Outline. Low frequency power amplifier TO-220FM Base 2. Collector 3. Emitter 2.

White Paper. The Impact of Payment Services Directive II (PSD2) on Authentication & Security

Cyber Security and Data Protection: Huge Penalties, Nowhere to Hide

IP CHANGES IN THE THAI COMPUTER CRIME ACT. Cyber crime in Thailand Introduction & Overview

How to Catch a Thief. Trends & Technologies in the Fight Against Fraud. Rohan Langley SAS

Quick Heal Total Security for Mac. Simple, fast and seamless protection for Mac.

HSM88WK. Proof against high voltage. MPAK package is suitable for high density surface mounting and high speed assembly.

Preempting Cyber Fraud: SWIFT Threat Indicator Sharing Tool. Cyber Security 3.0 Better Together August 18, 2017

Protecting Against Online Fraud. F5 EMEA Webinar August 2014

The Cost of Phishing. Understanding the True Cost Dynamics Behind Phishing Attacks A CYVEILLANCE WHITE PAPER MAY 2015

CYBER SECURITY and Mobile Money: Challenges and Opportunities NOVEMBER 28 TH 2016 PRESENTER: CECIL WILLIAMS

ENISA & Cybersecurity. Dr. Udo Helmbrecht Executive Director, European Network & Information Security Agency (ENISA) 25 October 2010

2SJ76, 2SJ77, 2SJ78, 2SJ79

Quick Heal Total Security Multi-Device (Mac) Simple, fast and seamless protection for Mac.

KASPERSKY FRAUD PREVENTION FOR ENDPOINTS

IP Risk Assessment & Loss Prevention By Priya Kanduri Happiest Minds, Security Services Practice

1SS286. Silicon Schottky Barrier Diode for Various Detector, High Speed Switching

Building a Threat Intelligence Program

JPCERT/CC Incident Handling Report [January 1, March 31, 2018]

1SS106. Silicon Schottky Barrier Diode for Various Detector, High Speed Switching

Legal Foundation and Enforcement: Promoting Cybersecurity

Understanding the Changing Cybersecurity Problem

CYBER SOLUTIONS & THREAT INTELLIGENCE

HD74HC09. Quad. 2-input AND Gates (with open drain outputs) Features. Pin Arrangement

Phishing Activity Trends Report October, 2004

2SK2220, 2SK2221. Silicon N-Channel MOS FET. ADE (Z) 1st. Edition Mar Application. Features. Outline

Security by Default: Enabling Transformation Through Cyber Resilience

Certified Cyber Security Analyst VS-1160

Cyber Crime Update. Mark Brett Programme Director February 2016

THE EFFECTIVE APPROACH TO CYBER SECURITY VALIDATION BREACH & ATTACK SIMULATION

Countering Fraud in Student Funding

Phishing Activity Trends Report August, 2006

WORKSHOP CYBER SECURITY AND CYBERCRIME POLICIES FOR AFRICAN DIPLOMATS. Okechukwu Emmanuel Ibe

The Scenes of Cyber Crime

Guide to credit card security

Regarding the change of names mentioned in the document, such as Hitachi Electric and Hitachi XX, to Renesas Technology Corp.

2SB727(K) Silicon PNP Epitaxial. Medium speed and power switching complementary pair with 2SD768(K) Base 2. Collector (Flange) 3.

Small Business Is Big Business in Cybercrime A TrendLabs Primer

This Online Gaming Company Didn t Want to Roll the Dice on Security That s Why it Worked with BlackBerry

HD74HC174. Hex D-type Flip-Flops (with Clear) ADE (Z) 1st. Edition Sep Description. Features. Function Table

CASE STUDY: REGIONAL BANK

HD74HC00. Quad. 2-input NAND Gates. Features. Pin Arrangement

Security & Phishing

Fighting Fraud with Behavioral Biometrics and Cognitive Fraud Detection. IBM Security s Brooke Satti Charles on the Power of These New Capabilities

Phishing Activity Trends Report August, 2005

PROJECT RESULTS Summary

1S2075(K) Silicon Epitaxial Planar Diode for High Speed Switching. ADE A (Z) Rev. 1 Aug Features. Ordering Information.

2SK439. Silicon N-Channel MOS FET. Application. Outline. VHF amplifier SPAK. 1. Gate 2. Source 3. Drain

HSM107S. Silicon Schottky Barrier Diode for System Protection. ADE F(Z) Rev 6 Sep Features. Ordering Information.

Caribbean Cyber Security: Not Only Government s Responsibility

HD74HC of-8-line Data Selector/Multiplexer. Description. Features. Function Table

2SK1056, 2SK1057, 2SK1058

Enabling efficiency through Data Governance: a phased approach

HD74HC74. Dual D-type Flip-Flops (with Preset and Clear)

Privileged Account Security: A Balanced Approach to Securing Unix Environments

Featured Articles II Security Research and Development Research and Development of Advanced Security Technology

2SK213, 2SK214, 2SK215, 2SK216

Panda Security 2010 Page 1

Page 1 of 6 Bank card and cheque fraud

HD74AC240/HD74ACT240

Security for Financial Services: Addressing the Perception Gaps in a Dynamic Landscape

2 nd ARF Seminar on Cyber Terrorism PAKISTAN S PERSPECTIVE AND EXPERIENCE WITH REFERENCE TO CERT IN COMBATING CYBER TERRORISM

6 Ways Office 365 Keeps Your and Business Secure

COUNTERING CYBER CHAOS WITH HIPAA COMPLIANCE. Presented by Paul R. Hales, J.D. May 8, 2017

WHITE PAPER. ENSURING SECURITY WITH OPEN APIs. Scott Biesterveld, Lead Solution Architect Senthil Senthil, Development Manager IBS Open APIs

JAPAN CYBER-SAVVINESS REPORT 2016 CYBERSECURITY: USER KNOWLEDGE, BEHAVIOUR AND ATTITUDES IN JAPAN

Cybersecurity in Higher Ed

Phishing Activity Trends

Advanced Malware Protection. Dan Gavojdea, Security Sales, Account Manager, Cisco South East Europe

10025/16 MP/mj 1 DG D 2B

Wayward Wi-Fi. How Rogue Hotspots Can Hijack Your Data and Put Your Mobile Devices at Risk

PROVIDING INVESTIGATIVE SOLUTIONS

Elders Estates Privacy Notice

New Zealand National Cyber Security Centre Incident Summary

Sheltered Harbor protects public confidence in the financial system if a catastrophic event like a cyber attack causes your critical systems,

A new approach to Cyber Security

HD74HC273. Octal D-type Flip-Flops (with Clear) ADE (Z) 1st. Edition Sep Description. Features. Function Table

Transcription:

SONY CASE STUDY PROTECTING FROM WEB BROWSER BASED CYBER ATTACKS Sony Bank in Japan recognises that in the financial sector, vigilance to detect threats and agility to respond to them, are the key attributes required to protect customers and providers from the threats of malware induced transaction fraud. Sony Bank, operating under the MONEYKit online brand, was founded in 2001 and provides a range of financial services including online banking. It has always prioritised the security of its customers and is active in the continuous implementation of the countermeasures that are necessary to combat the threats of malware and cyber crime in the financial sector.

IN RECENT YEARS, SOLUTIONS AGAINST ONLINE BANKING TRANSACTIONAL FRAUD HAVE EXPANDED. IN JANUARY 2015, SONY BANK ADOPTED PHISHWALL CLIENTLESS, A SERVER SIDE SOLUTION, WHICH CAN DETECT ANY WEBSITE CONTENT TAMPERING CAUSED BY MALWARE INFECTION ON THE CLIENT. WE INTERVIEWED MR. TATSUYA FUKUSHIMA, GENERAL MANAGER OF SYSTEM PLANNING DEPARTMENT AND MR. SHUICHIRO SUMIMOTO, MANAGER OF SYSTEM PLANNING DEPARTMENT OF SONY BANK REGARDING THE ADOPTION OF PHISHWALL CLIENTLESS AND ITS OPERATIONS.

WE STARTED RESEARCHING PRODUCTS THAT PREVENT TRANSACTIONAL FRAUD FROM OCCURRING WHILE DISCUSSING AND IMPLEMENTING VARIOUS WEB SECURITY COUNTERMEASURES. Nowadays there are several ways to prevent transactional fraud from happening such as acquiring an EVSSL certificate, taking down any phishing sites and creating a one-time password system. However, sometimes we find that when global prevalence of fraudulent transactions increase, our customers become quite concerned and it becomes necessary to investigate and review our website security. Our desire to protect our customers accounts and improve security led us to consider new ways of improving our security. In the beginning of our investigation. we realised that solutions to protect against transactional fraud were predominantly client based solutions whereby the customer would need to install software and this could be inconvenient for our client base. However in the case of Phishwall Clientless from SecureBrain, it does not require client software installation. Mr. Fukushima

THE CONCLUSIVE FACTOR IN SELECTING PHISHWALL CLIENTLESS WAS THAT IT CAN PROTECT ALL OF OUR CUSTOMERS WHILE KEEPING UP WITH THE DOMESTIC SITUATION ON FRAUD. Sony Bank is an internet bank and unlike an ordinary bank it has no branch office that customers can visit. When a case arises whereby a money transaction cannot occur, there are no alternatives for our customers to access their banks. Our management team has a policy to provide highest quality of web security for the sake of our customers accounts. As a result of this it was important that whatever solution we implemented was easily adaptable for our entire customer base. SecureBrain is one of the leading domestic cyber security companies, which has large market share in this area. Additionally, SecureBrain has a very close relationship with the Tokyo Metropolitan Police Department giving us the confidence that they would be very effective at offering online fraud solutions against domestic attacks. Furthermore, the SecureBrain solution was cost effective and within the budget from what we expected for our security solution. Mr. Fukushima

QUICK INFORMATION FEEDBACK AND RESPONSE IMPROVING OUR DETECTION QUALITY. We began by running some penetration tests on PhishWall Clientless with an actual banking malware in order to measure the effectiveness of the solution against any potential attacks. Usually this proves to be quite difficult as it requires revealing the core technology of the product, however SecureBrain was very co-operative during this process. As a result of their co-operation, we were able to both test and integrate the product in the span of 3 months. When a malware attack occurs, we require rapid response and support. PhishWall Clientless performs well and helps us gain better insights on the attacks. Furthermore, to keep up with the latest threats, the solution is frequently updated to maintain detection against new threats. We also admire SecureBrain for proposing new measures to help improve our security level. Mr. Sumimoto EXPECT TO CONTINUE TO BE WELL BALANCED PRODUCT INCLUDING TECHNOLOGY AND COST EFFECTIVENESS. Cost effectiveness is very important because a product cannot be used if it does not fit our budget due to high costs even though it has the superior technology. On the other hand, it is meaningless if the product does not keep up with the latest threat even if the cost is low. I expect SecureBrain to continue to provide a well balanced solution that s cost effective. Mr. Fukushima

PHISHWALL CLIENTLESS OVERVIEW Sony Case Study PhishWall Clientless System Checks malware infection when accessing internet banking system. Detection Report Malware tampers with website contents Financial Institutions Fake pop-up X Blocks illegal money transfer and displays alert message.

FURTHER INFORMATION SecureBrain Corporation is owned by Hitachi Systems Ltd. It is a specialised security company providing solutions and services to keep enterprises and their customers safe from the effects of cybercrime. Please contact Hitachi Europe Limited for further information about Hitachi s cyber security solution (PhishWall). 2016 Hitachi Europe Limited. All copyrights and intellectual property rights are owned by and reserved by Hitachi Europe Limited and its subsidiaries. Hitachi Europe Limited s prior written consent is required before any part of this document is reproduced.

CONTACT DETAILS Information Systems Group, Hitachi Europe Limited, Whitebrook Park, Lower Cookham Road, Maidenhead, Berkshire, SL6 8YA. digitalsecurity@hitachi-eu.com http://digitalsecurity.hitachi.eu