SlideShare a Scribd company logo
1 of 13
Download to read offline
Reply

Financial Sector Antifraud
   Products and Services




                  V. 1.5 - 31072012
Solution outline
    Reply engineered a point solution to contrast new type of automated
    frauds toward financial institutions online services. The so called “Man in
    The Browser” attacks are hitting the news and are a well known problem for
    large financial institutions as they can circumvent strong authentication and
    transaction monitoring systems.
    Reply solutions provide a unique way to identify such frauds through the
    technological chain, providing “Actionable Intelligence” information directly
    to Enterprise Fraud Management systems or helpdesks.




                       http://www.bbc.co.uk/news/technology-16812064 (02/2012)


2
Reply Security competence centre
    Reply Antifraud Assets:
    • Niche high performance solutions, 100+ clients managed
    • Dedicated Fraud Intelligence Team & CERT
    • Owned Security Operations Centre H24x365, 60+ people dedicated to
       Fraud Contrast & Analysis in the Reply SOC
    • Self developed platforms, some of which released open source for the
       anti-fraud community
    • High involvement in international associations, such as Honeynet Project
    • Flexibility to accomodate client’s integration and service requirements



                                                 Reply was identified by the Italian Banking Association
                                                 (ABI) as a leader for quality intelligence for the
                                                 financial sector. Reply provides monthly report of
                                                 malware trends to all associates


                                                 Reply provides malware intelligence information to UK
                                                 private agencies providing services to law enforcement
                                                 authorities and defence.




3
Reply Answer

    Reply provides focused product and services for contrast
     of emerging fraud phenomena in the financial sector.
                                                              REPLY FRAUD
       ACTIVE FRAUD               ANTIPHISHING
                                                              INTELLIGENCE
        PREVENTION                  SERVICES
                                                                SERVICES

    Active detection of        Active detection and        Intelligence information
    online banking frauds.     shutdown of phishing        tailored on specific
                               clones, leveraging          requirements, Botnet
    Available in SaaS or       multiple sources and        Tracking, Botnet
    On-Premise, 95% avg        client information.         infiltration and
    score on true positives,                               shutdown.
    measurable ROI.            Top level detection rate.




4
Active Fraud Prevention (AFP): Fraud pattern

    The AFP product leverages continuous intelligence activities and
    proprietary platforms in order to actively identify compromised
    clients during an online banking transaction attempt.

    AFP produces Actionable Intelligence: your client’s account
    number, details of the transaction direcly to your customer
    support service and to your enterprise fraud management
    system.

    AFP has extremely low integration requirements.




5
Active Fraud Prevention (AFP): Fraud pattern

    The AFP product leverages continuous intelligence activities and
    proprietary platforms in order to actively identify compromised
    clients during an online banking transaction attempt.

    Typical online banking fraud pattern:



End user
                                                      Online Banking                                    Online Banking
                                                        Front End                                         Back End

    1 The user connects to the home banking website with a client compromised by a trojan.
           2 The connection triggers the trojan that seamlessly interacts with the user session
                    3 Since the attack happens in the user space, both the front end and the back end cannot detect the attack.
                      It is a common pattern to see average transaction volume and execute fraud wire transfer below that, in order
                      not to trigger transaction monitoring systems




6
Active Fraud Prevention (AFP): mitigation


    Leveraging proprietary technology, with an easy to integrate sensor in the
    front end, AFP is capable to detect «weak signals» coming from and infected
    client.

    AFP signatures and sensors are updated frequently by the Reply Fraud
    Intelligence team.




7
Active Fraud Prevention (AFP): Fraud pattern

    Reply AFP is available in the following:

    • Software as a Service
       Fully delivered from ISO/IEC 27001 certified Reply Security
       Operations Centre (SOC).
       •   Licensing is flat for 1Y contract, not dependent on number of
           logs/events/incidents/EPS/etc.
       •   Includes continuous updates of signatures and software components
       •   Full reporting and trend analysis via fully featured BI solution
    • On-premise on hardware/virtual appliance
       Remotely managed by experts team in Reply SOC.
       •   The product is licensed to the client, signatures and software
           components updates are included in the maintenance fee



8
Example of Reply malware detection capabilities




    Geolocalization of one of the monitored Fast Flux domains

9
Reply Antiphishing services

     Reply Antiphishing Service provide value for customer’s reducing
     brand abuse impact on the end user:

     •   Reduction of exposure to cloned websites
     •   High level of detection thanks to smart correlation of own
         managed mailboxes network and weak signals derivd from
         customer available data
     •   Shutdown of clone websites licensed on a flat fashion
     •   Full tracking of closure status via Reply services portal




10
Reply Fraud Intelligence Services

     The Reply Fraud Intelligence Team monitor threats directed
     toward its clients through botnets and trojans. The team can
     provide valuable intelligence information to its customers,
     including:

     •   Detection of malicious code samples
     •   C&C tracking and shutdown
     •   Analysis of detection techniques for new malware behaviours
     •   Full reporting and trend analysis through a full featured
         Busines Intelligence platform




11
Want to try out?

     Our experience tells us that the amount of frauds identified and
     potentially prevented during a Proof Of Concept, highly exceed
     expectations. And the final TCO is just a small portion of the
     saving.


     To organise a POC for Reply AFP solution, please contact
     d.vitali@reply.eu




12
Thanks

More Related Content

Recently uploaded

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfhans926745
 

Recently uploaded (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 

Featured

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...DevGAMM Conference
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationErica Santiago
 

Featured (20)

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 

Reply financial sector antifraud services and products

  • 1. Reply Financial Sector Antifraud Products and Services V. 1.5 - 31072012
  • 2. Solution outline Reply engineered a point solution to contrast new type of automated frauds toward financial institutions online services. The so called “Man in The Browser” attacks are hitting the news and are a well known problem for large financial institutions as they can circumvent strong authentication and transaction monitoring systems. Reply solutions provide a unique way to identify such frauds through the technological chain, providing “Actionable Intelligence” information directly to Enterprise Fraud Management systems or helpdesks. http://www.bbc.co.uk/news/technology-16812064 (02/2012) 2
  • 3. Reply Security competence centre Reply Antifraud Assets: • Niche high performance solutions, 100+ clients managed • Dedicated Fraud Intelligence Team & CERT • Owned Security Operations Centre H24x365, 60+ people dedicated to Fraud Contrast & Analysis in the Reply SOC • Self developed platforms, some of which released open source for the anti-fraud community • High involvement in international associations, such as Honeynet Project • Flexibility to accomodate client’s integration and service requirements Reply was identified by the Italian Banking Association (ABI) as a leader for quality intelligence for the financial sector. Reply provides monthly report of malware trends to all associates Reply provides malware intelligence information to UK private agencies providing services to law enforcement authorities and defence. 3
  • 4. Reply Answer Reply provides focused product and services for contrast of emerging fraud phenomena in the financial sector. REPLY FRAUD ACTIVE FRAUD ANTIPHISHING INTELLIGENCE PREVENTION SERVICES SERVICES Active detection of Active detection and Intelligence information online banking frauds. shutdown of phishing tailored on specific clones, leveraging requirements, Botnet Available in SaaS or multiple sources and Tracking, Botnet On-Premise, 95% avg client information. infiltration and score on true positives, shutdown. measurable ROI. Top level detection rate. 4
  • 5. Active Fraud Prevention (AFP): Fraud pattern The AFP product leverages continuous intelligence activities and proprietary platforms in order to actively identify compromised clients during an online banking transaction attempt. AFP produces Actionable Intelligence: your client’s account number, details of the transaction direcly to your customer support service and to your enterprise fraud management system. AFP has extremely low integration requirements. 5
  • 6. Active Fraud Prevention (AFP): Fraud pattern The AFP product leverages continuous intelligence activities and proprietary platforms in order to actively identify compromised clients during an online banking transaction attempt. Typical online banking fraud pattern: End user Online Banking Online Banking Front End Back End 1 The user connects to the home banking website with a client compromised by a trojan. 2 The connection triggers the trojan that seamlessly interacts with the user session 3 Since the attack happens in the user space, both the front end and the back end cannot detect the attack. It is a common pattern to see average transaction volume and execute fraud wire transfer below that, in order not to trigger transaction monitoring systems 6
  • 7. Active Fraud Prevention (AFP): mitigation Leveraging proprietary technology, with an easy to integrate sensor in the front end, AFP is capable to detect «weak signals» coming from and infected client. AFP signatures and sensors are updated frequently by the Reply Fraud Intelligence team. 7
  • 8. Active Fraud Prevention (AFP): Fraud pattern Reply AFP is available in the following: • Software as a Service Fully delivered from ISO/IEC 27001 certified Reply Security Operations Centre (SOC). • Licensing is flat for 1Y contract, not dependent on number of logs/events/incidents/EPS/etc. • Includes continuous updates of signatures and software components • Full reporting and trend analysis via fully featured BI solution • On-premise on hardware/virtual appliance Remotely managed by experts team in Reply SOC. • The product is licensed to the client, signatures and software components updates are included in the maintenance fee 8
  • 9. Example of Reply malware detection capabilities Geolocalization of one of the monitored Fast Flux domains 9
  • 10. Reply Antiphishing services Reply Antiphishing Service provide value for customer’s reducing brand abuse impact on the end user: • Reduction of exposure to cloned websites • High level of detection thanks to smart correlation of own managed mailboxes network and weak signals derivd from customer available data • Shutdown of clone websites licensed on a flat fashion • Full tracking of closure status via Reply services portal 10
  • 11. Reply Fraud Intelligence Services The Reply Fraud Intelligence Team monitor threats directed toward its clients through botnets and trojans. The team can provide valuable intelligence information to its customers, including: • Detection of malicious code samples • C&C tracking and shutdown • Analysis of detection techniques for new malware behaviours • Full reporting and trend analysis through a full featured Busines Intelligence platform 11
  • 12. Want to try out? Our experience tells us that the amount of frauds identified and potentially prevented during a Proof Of Concept, highly exceed expectations. And the final TCO is just a small portion of the saving. To organise a POC for Reply AFP solution, please contact d.vitali@reply.eu 12