How to Strengthen Modern Identity Assurance

122 views
•
May 17, 2019
by
RSAC Cybersecurity
YouTube video player
How to Strengthen Modern Identity Assurance

TL;DR

Stronger identity assurance starts by examining how criminals can manipulate every new product, cloud application, and customer interaction. Organizations should account for stolen credentials, reverse voice phishing, online card misuse, human psychology, and the growing gray web, then apply additional authentication and security controls where account takeover opportunities appear.

Transcript

I think it's time for getting started. I have to say that while waiting for the session time to start, this has to be the quietest room ever. You guys didn't even say hi to each other as you were coming in. It was like you could hear a pin drop in here. It was weird. Um, either that, you got... You- you're exhausted because it's Wednesday, so how t... Read More

Key Insights

  • Cybercrime depends on means, opportunity, and motive. Stolen credentials, large amounts of generated data, underground forums, and harvesting tools supply the first two elements, while financial objectives, hacktivism, and nation-state interests provide different and increasingly blurred motivations.
  • The cybercrime ecosystem operates like a business. It creates roles for people with marketing, pricing, business-model, and engineering skills, including those who promote illicit offerings, determine how they are sold, or manage command-and-control capabilities.
  • The gray web is an emerging area where cybercriminals interact in plain sight. Traditional dark-web activity continues, but visible platforms and ordinary online services can also be manipulated to support identity theft, credential harvesting, and account takeover.
  • Cybercriminal manipulation targets four primal triggers: fear, flight, financial interest, and fornication. Ransomware can exploit fear, while sextortion exploits sexual pressure, demonstrating why organizations must consider both emotional and technical vulnerabilities when evaluating attacks.
  • Reverse voice phishing works by replacing a legitimate organization's listed telephone number with a fraudulent one. Victims call what appears to be a trusted institution, then disclose information such as a PIN or mother's maiden name to criminals posing as legitimate representatives.
  • New products and services create potential attack opportunities. Before releasing a cloud-based application or another connected service, an organization should examine how criminals could manipulate its human interactions, computer systems, workflows, and points of vulnerability.
  • Credential value varies by industry, account profile, associated cards, and brand. The discussion identifies retail and e-commerce accounts as attractive targets because stolen payment information can be used online when physical card protections create barriers in stores.
  • Online purchasing and store pickup can support fraud workflows. Criminals can combine stolen credentials and payment cards with established mule networks, buy merchandise through e-commerce systems, and send mules to collect the goods from physical retail locations.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the means, opportunity, and motive model of cybercrime?

The model describes crime through three necessary dimensions: means, opportunity, and motive. In cybercrime, stolen credentials, extensive data creation, forums, and harvesting tools provide means and opportunity. Motives differ among threat actors and can include financial gain, hacktivist opposition, or nation-state objectives. These motivations are increasingly blurred as the criminal ecosystem continues to evolve.

Q: How does the cybercrime underground operate like a business?

The cybercrime underground supports specialized and transferable business skills. Marketing participants can promote illicit products or services, business participants can establish pricing and commercial models, and engineers can manage technical infrastructure such as command-and-control systems. This division of labor creates opportunities for people with different capabilities and allows the broader criminal ecosystem to continue developing and expanding.

Q: What is the gray web in cybercrime?

The gray web is the emerging environment where cybercriminals interact and manipulate services in plain sight. It differs from the traditional image of criminals operating only through hidden dark-web spaces. Dark-web activity remains present, but ordinary online platforms can expose users to attacks when criminals alter trusted information or exploit routine digital behaviors to harvest identity data.

Q: How do criminals use psychology to manipulate victims?

Criminals manipulate victims through four primal triggers identified as fear, flight, financial interest, and fornication. Ransomware illustrates the use of fear, while sextortion illustrates sexual pressure. Understanding these triggers helps individuals and organizations recognize that attacks can exploit emotion as well as technology, especially when new products and services introduce unfamiliar interactions or vulnerabilities.

Q: How does reverse voice phishing steal identity information?

Reverse voice phishing begins when a criminal replaces a legitimate organization's telephone number in a service such as a map listing. A person searches for a bank or business, sees an apparently legitimate result, and calls the fraudulent number. The impersonator then requests sensitive details, including a PIN or mother's maiden name, and harvests the information supplied by the caller.

Q: Why should security teams assess new cloud applications for manipulation?

Every new product or service can introduce additional opportunities for criminal manipulation. When an organization releases a cloud-based application, it should examine how attackers might exploit the service's human interactions and computer-based components. Reviewing these potential vulnerability points before and during rollout helps the organization understand how its employees, customers, partners, workflows, and authentication processes could be targeted.

Q: Why are e-commerce credentials attractive to cybercriminals?

E-commerce credentials are attractive because payment cards with chips create a barrier at physical stores but provide no equivalent protection during online shopping. Criminals who already possess stolen cards and carding infrastructure can therefore use them in e-commerce sessions. If an online merchant lacks additional levels of authentication, those fraudulent transactions may be easier for criminals to complete.

Q: How can store pickup be exploited in account takeover fraud?

Criminals can use stolen credentials and payment cards to place online orders at retailers that offer pickup in physical stores. Established mule networks can then send people to collect the purchased merchandise. This process lets criminals continue using stolen cards without cloning physical cards, while connecting an e-commerce transaction to an existing system for retrieving and moving fraudulently purchased goods.

Summary & Key Takeaways

  • Cybercrime can be understood through means, opportunity, and motive. Stolen credentials, enormous daily data creation, underground tools, and accessible forums provide the means and opportunities. Motives include financial gain, hacktivism, and nation-state objectives, although these categories increasingly overlap as the criminal ecosystem expands and operates more like a business.

Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚