5. More Recently … (2008-2010) Sergey Aleynikov, former Goldman Sachs computer programmer/prop trader indicted and prosecuted on charges of HFT algorithm theft. UBS filed a lawsuit against three former quants alleging to have stolen proprietary algorithmic trading software with the intent of using it at their new employer. Ukrainian hacker Oleksandr Dorozhko charged for insider trading by SEC. Mr Dorozhko traded option contracts on information gained by accessing earnings data from a staging server prior to their release date. 5
6. Even More Recently … (Dec 2010 - Jan 2011) Romanian Registry (Carbon Trading Platform) 1.6 million CO2 certificated from Holcim Cement account were stolen. Credits were transferred to hacker controlled accounts in EU states. Czech / Austrian Registry (Carbon Trading Platform) Two million credits worth 2.8 million were stolen and transferred to other registries and / or sold to other market participants. 6
7. Even More Recently … (Dec 2010 - Jan 2011) NASDAQ Director’s Desk Application Currently being investigated for a potential breach, the Directors Desk application is an EMS application that allows executives to share sensitive documents including earnings data, board minutes etc. 7
8. Common Theme / Trends Attackers are still leveraging the low hanging fruit in terms of security issues used to compromise these systems. As of 2011, the threats are increasing both in scale and sophistication. Outsider threat is increasing 8
11. Trade Optimized Strategy Engine WHAT Class of applications used for submission and analysis of investment/trading strategies. WHO Used mainly by Funds/Banks/Investment Management firms employing Global Macro/Event driven trading strategies HOW Third party Brokers, Analysts, Economists access the application to upload trading strategies/ideas. The application uses both statistical and/or proprietary algorithms to index/rate submitted strategies Traders trade the most optimum strategy 11
12. Case Study - Trade Optimized Strategy Engine Issues (Weak Input Validation) 12
14. OTC Trading Platforms WHAT Predominantly dealer applications for trading over-the-counter derivatives. WHO Used by almost all banks dealing in credit derivatives markets - CDO, CDS, IRS etc Mainly used for structuring instruments, based on client requirements which are then traded directly or through a dealer. Mainly used by front office quants/traders HOW Trades are executed using commercial and/or bespoke platforms etc Post Trade processing can be carried in-house or outsourced. 14
15. Case Study – Bank OTC Trading Platform Issues (Trade Data / Client Discovery Attack) 15
17. Thick Client Trading Platforms WHAT Any front, middle or back office trading application. Often developed for business/analyst staff and/or used to extend trading services to third-party clients. 17
18. Case Study - Thick Client Trading Platform Issues (Forex Broker-Dealer Application) 18
21. Indices Applications Definition Index - A basket/collection/group of securities to track the performance of a market/sector/asset. Can be traded as Futures/Options contracts or used as the underlying for other products. WHO Mostly developed and managed by Exchanges, Rating agencies and Banks. HOW A committee or bespoke methods / benchmarks are used to rebalance indices. 21
22. Case Study - Index Rebalancing/Turnover Attacks 22
23. Computational Grids WHAT High performance computing grids used for running solvers, simulations and analysis of financial time series data. (Monitcarlo, Volatility, OP etc) WHO Mostly institutions and departments involved with financial modeling. Users tend to be quants, traders and analysts. HOW Models are submitted to the grid environment using Web services, custom APIs and/or remote access. 23
27. What is FIX Protocol ? The Financial Information eXchange (FIX) protocol is an electronic communications protocol initiated in 1992 for international real-time exchange of information related to the securities transactions and markets – Wikipeda In other words, the protocol facilitates the buying and selling of securities electronically. 27
28. Who Uses FIX FIX is widely used by both the buy side (institutions) as well as the sell side (brokers/dealers) in the financial markets. Amongst its users are hedge funds, mutual funds, investment banks, brokers and stock exchanges Transaction types supported: Pretty much all asset classes i.e Equities, Bond, Derivatives and Forex. 28
30. Why Investigate FIX ? FIX security is often overlooked in favor of Operating System and Host Security To demonstrate that FIX based front running is possible and not difficult to exploit To identify mitigating factors and strategies for some of the existing issues within FIX protocol 30
33. Order Front Running (Demo) Demo Environment: Algorithmic Trading Environment – A simulated algorithmic/high frequency trading environment Brokerage Account – Hacker Controlled brokerage account to reply orders. Order Sniffer - Note The following examples used during this demonstration are not intended to suggest any insecurities or weaknesses in the third party applications and are only to be seen as a case study to demonstrate FIX protocol insecurities. 33