Chronicling innovation and game changing developments in Enterprise Security through partnerships with Oracle and other industry leaders.
Thursday, August 27, 2009
Location, Location, Location!!!
In the growing area of risk based authentication where organizations from banks to governmental departments are looking to share more information and services with people there is a much greater risk/fear of fraud.
Information Security vendors such as Oracle, RSA, Verisign, and others have complimented their existing Web Access Control technologies like Oracle Access Manager (OAM) with Risk Based Authentication solutions such as Oracle Adaptive Access Manager (OAAM) which assess the risk of fraud at the moment of a transaction and, based on policy, respond by allowing/denying the transaction or requiring secondary or “Step-up Authentication”.
In these scenarios, the more context available to the transaction the better risk analysis. Knowing that a banking customer who lives in Oslo, Norway is trying to send a wire transfer out of the account is actually logging in from Seattle, WA gives makes it simple to understand the potential risk.
IP data enables core risk assessments made within OAAM including; website visitor location (i.e. block high risk locations), network characteristice (i.e. is the visitor connected through an anonymzing proxy—intentionally masking their location), IP data provides an “IP fingerprint” of a visitor.
To help deliver this intelligence to customers Oracle partners with Quova as the preferred IP provider for OAAM. They provide specific ROI advantages over competitors.. Quova’s unmatched accuracy and depth of proxy intelligence data result in increased fraud catch and lower false positive escalations.
And Quova is the only provider that subjects its research process and data quality to annual independent audit by PricewaterhouseCoopers. Quova is widely recognized as the market leader and is in use throughout the anti-fraud marketplace. Quova for OAAM customers include; Monster.com, DFCU, ICICI Bank, National City Corporation.
To Learn more about Quova:
Contact Jon Heintschel
650-528-3739 or jheintschel@quova.com
To Learn more about OAAM
http://www.oracle.com/technology/products/id_mgmt/oaam/index.html
Or to learn about the Oracle Access Suite:
http://www.oracle.com/products/middleware/identity-management/access-management-suite.html
Saturday, August 1, 2009
Why the Public Sector needs Bio-Metric Solutions and how ORCL + Daon can help
Why are government organizations looking for this?
- Stronger security to mitigate fraud & ID theft (more details below)
- Strong Authentication without tokens (more details below)
Why has it not been adopted already?
- Requirements for end-points to capture & verify biometrics
- Complexity of provisioning & sharing biometrics across platforms and regions
So how can we be successful now?
- Provisioning credentials & enabling cross platform SSO
- Managing roles and fine grain entitlements
What is the real scoop on Fraud:
- eCommerce Fraud Losses Projected to Grow to $3.6 Billion in 2008
- Merchants estimate that 1.4% of their online sales will line the pockets of fraudsters
Source: CyberSource eCommerce Fraud Survey, 2007 - Société Générale €5 billion in trading loss due to unauthorized trades
- Trader executed €50 billion of unauthorized trades and attempted to cover over his losses. When the bank discovered the fraud it had to unwind the position in 3 days, resulting in €5 billion in loss and triggering a world wide financial market sell-off.
Source: CNN, January 2008 - $17 Million remediation cost for 45 million stolen credit card numbers
Breach of TJ Maxx’s IT systems led to the lost of 45 million credit and debit card numbers over a period of 18 months. Estimated revenue impact from negative press coverage was $4.5 billion.
Source: Information Week, May 2007
So why is Strong Authentication not enough?
- Tokens & Smart Cards require the device to be present, credentials still can be stolen and subject to man in the middle attacks and other Phishing or Virus/Malware breaches
- Conversly, Biometric Credentials can not be stolen or replicated, user does not have to carry/track additional tools.
- They can be verified for uniqueness against state, local, federal & international databases
Rapidly identify potential threats or risky persons.
This is where it gets tricky
- Capturing & Storing Credentials
- High cost of having devices at the end-points to capture data
- Tremendous disparity in capture/read devices & algorithms
- It is difficult to future proof your deployment when devices, algorithms, and infrastructure continuously evolving
- Risk of being out of date by the time of production deployment
- Challenging to provisioning credentials and synchronize biometrics with apps & infrastructure
- Challenge for using single biometric authentication for SSO
So how do you maximize the ROI?
- Govt. & Ent. require solutions that compliment & enhance entire IT IDM infrastructure to justify investment.
- Oracle IDM Solutions Provisioning Credentials
- Oracle Identity Manager (OIM) enables automated provisioning or revocation of accounts based on biometric auth/enrolment
- Oracle Role Manager (ORM) ties biometric attributes to user roles
- Oracle Entitlements Server (OES) richly defines fine-grain applications entitlements to grant/limit access to specific functions, data sets, or transactions based on level of authentication, roles, and credentials.
- Gain seamless authentication across applications with Oracle eSSO (OESSO)
- Replaces name/pwd with a a single biometric authentication to increase security level & create single sign-on across web & desktop applications.
- Oracle Adaptive Access Manager (OAAM) Ties biometric authentication with broader authentication context (like device identification and location) to validate the entire transaction and identify anomalies or malicious behavior over time.
Here is how the Daon solution fits in...
For more information on Daon please visit their website.
Wednesday, July 1, 2009
Security solutions for misuse of information & entitlements
After "Who has access to what?” the question is “What are they doing with it?”
Information security has followed a similar path of information technology. First it was about storing and organizing information in databases and securing that information. Then as applications and middleware evolved to deliver that information and application entitlements to users, Identity and Access management suites developed to securily enable access to them.
But once information and entitlements are in the hands of users it is open for misuse. There are many examples of this:
- Accidentally emailing confidential information about M&A to the wrong internal user with the same name like John.Waters@xyzcorp.com instead of Jon.Waters@xyzcorp.com.
- Copying sensitive financial or personal information out of a protected application into a file and posting it on an open file share or SharePoint portal
- Sales person leaving the company who emails a list of accounts and contacts to themselves before going to work for a competitor.
- NT Admin who misues the shared account because they know they are 1 of 30 people with the password and nobody knows who did what with it.
- Former employees hacking into a company database because the password never changes as it is hard coded into applications.
The list of potential risks/attacks goes on and on. To help customers identify these and address them, Oracle has once again expanded the Extended Identity Management Ecosystem to include:
- Privileged Account Management (PAM) – manage shared and cached credentials for privileged accounts
- Data Loss Prevention (DLP) – network and endpoint content-aware monitoring, discovery and blocking
Which is complimented by Oracle IAM solutions that provide consistent Security Services & Policy across layers for
- Compliance – Fine-grained entitlements and identity analytics based on consistent user roles
- Reconciliation – Closed loop implementation & verification of policies across layers
Our DLP partners (including McAfee, Symantec, & ControlGuard ) integrate with Oracle IRM to:
- Discover, classify, quarantine and seal (IRM-encrypt)
- Intercept file copies to removable media, classify, quarantine, seal (IRM-encrypt) & release
DLP integration with Oracle IAM will enable :
- DLP policies via OID or OVD group membership
- Provision/de-provision DLP policies via OIM (groups)
- Feedback/tuning of IAM
Similiarly Oracle PAM partners including Cloakware, Cyber-Ark, Liebsoft, and OpenTrust (formerly Symark) , deliver integrations that allows customers to:
- Leverage OID/OVD as identity/credential store
- PAM policies via OID/OVD groups
- Provision/de-provision policies via OIM (groups)
- Leverage Oracle database as secure policy store
- Secure caching of credentials for unattended application restarts
To learn more about these partners please visit their page on OPN or click on their name above to reach their website directly.
{NOTE: Please click on the above images to see the slides in full size for reading the details}
Tuesday, June 30, 2009
Cloakware and Oracle Work to Integrate Cloakware Password Authority with Oracle Identity and Access Management
Cloakware, the leading provider of privileged password management solutions announced today that it is working with Oracle to extend their suite of Identity Management solutions with Cloakware's flagship product, Password Authority. By combining these two best-in-class products, Oracle is now able to enhance their customers' security management, with a comprehensive solution to manage, protect and monitor access to vital data.
As more and more high-profile data breaches come to light, companies are realizing they need increasingly robust solutions to protect their vital data. A study conducted in January 2009 by the Identity Theft Resource Center of San Diego found that the percentage of breaches attributed to current or former employees more than doubled from 2007 to 2008. In light of findings like this, companies are struggling to balance individuals' access rights to secure information against risk and compliance requirements. Cloakware's patented white-box cryptographic techniques ensure defense-in-depth for end-to-end security of data and keys, especially where insiders have access to the execution environment. Working with Cloakware enables Oracle to offer its customers a solution to securely store and manage privileged passwords for human administrators and runtime applications without changes to the customer's existing infrastructure.
"Extending the Oracle Identity and Access Management Suite with third party platforms provides enhanced efficiency, a higher level of integration and increased effectiveness in terms of application-centric security and risk management," said Ron Huddleston, vice president, North America Technology Channel Sales, at Oracle. "Cloakware's Password Authority is a key part of this eco-system, augmenting our identity management suite."
Password Authority leverages multiple integration points into the Oracle Identity and Access Management Suite, including:
- Oracle Internet Directory (OID) - Password Authority can manage the passwords for accounts held in OID as well as for service accounts that authenticate against OID.
- Oracle Identity Manager (OIM) - Password Authority ensures that password management is synchronized with roles and access rules.
- Oracle WebLogic Server - Password Authority automates the run-time replacement of current passwords in connection strings/connection pools and the management of WebLogic administrator accounts.
- Oracle Database 11g Real Application Cluster (RAC) - Password Authority makes use of the Oracle database as its secure repository for all passwords, and is capable of supporting a geographically distributed database installation. Password Authority is also capable of maintaining and releasing Oracle Database passwords to humans and applications.
"Companies are now starting to understand the importance of employing strict standards to manage access to critical information and protect digital assets; the risks are too high to ignore," said David Canellos, senior vice president, sales and marketing at Irdeto and Cloakware. "By integrating Cloakware Password Authority with Oracle's Identity and Access Management Suite, customers will have a single solution to proactively address security deficiencies and reduce cost and risk in their IT infrastructure."
The combined solution will be demonstrated in Oracle's Hospitality Suite during the Burton Catalyst Conference in San Diego, July 27-31, 2009. The demonstration will highlight how Cloakware's latest product version, Password Authority 4.1, secures password storage, access and lifecycle management for shared privileged administrator and programmatic passwords within the Oracle Identity and Access Management Suite. For more information, please visit http://datacenter.cloakware.com.
Cloakware is a member of the Oracle PartnerNetwork.
About the Oracle PartnerNetwork
Oracle PartnerNetwork is a global business network of more than 20,000 companies who deliver innovative software solutions based on Oracle software. Through access to Oracle's premier products, education, technical services, marketing and sales support, the Oracle PartnerNetwork program provides partners with the resources they need to be successful in today's global economy. Oracle partners are able to offer their customers leading-edge solutions backed by Oracle's position as the world's largest enterprise software company. Partners who are able to demonstrate superior product knowledge, technical expertise and a commitment to doing business with Oracle qualify for the Certified Partner levels. http://oraclepartnernetwork.oracle.com
About Cloakware
Cloakware, an Irdeto company and part of the Naspers group, provides innovative, secure, proven software technology solutions that enable customers to protect business and digital assets in enterprise, consumer and government markets. Cloakware's two main product lines include: Cloakware Datacenter Solutions which help organizations meet governance, risk management and compliance (GRC) objectives for privileged password management while ensuring business continuity and the security of mission-critical data and IT infrastructure. Cloakware Consumer Product Solutions protect software and content on PCs, set-top boxes, mobile phones and media players. Protecting more than one billion deployed applications, Cloakware is the security cornerstone of many of the world's largest, most recognizable and technologically advanced companies. Headquartered in Vienna, VA and Ottawa, Canada, Cloakware has regional sales offices worldwide. http://www.cloakware.com/
Trademarks
Oracle is a registered trademark of Oracle Corporation and/or its affiliates.
Datasheet:
http://www.oracle.com/products/middleware/identity-management/docs/cloakware-datasheet.pdf
Monday, September 22, 2008
Oracle Forms Oracle Identity Assurance Partner Alliance
Oracle OpenWorld, San Francisco – September 22, 2008
News Facts
- Further extending its leading Identity and Access Management solution offering that helps organizations combat online fraud and improve overall enterprise security, Oracle today launched the Oracle Identity Assurance Partner Alliance.
- Through the alliance, Oracle and members of the alliance plan to deliver solutions that pre-integrate Oracle’s Identity Management Suite with partner technologies to offer capabilities such as identity proofing, Internet geolocation, multi-factor authentication, out-of-band authentication, endpoint security and secure remote access.
- Oracle plans to test and deliver unified solutions which are designed to help enable organizations utilize their existing infrastructure investments with new authentication technologies to create a broad-reaching view of transactions, users and their environment. Additionally, the integrations are intended to enable customers to more easily detect areas of risk and respond through secondary authentication measures.
- These authentication and security solutions work in a heterogeneous environment including Oracle and non-Oracle information systems and Enterprise Applications. They will also be pre-integrated with Oracle’s data, Fusion Middleware and Business Applications.
- Members of the alliance include: ActivIdentity, Bio-Key, IDology, Juniper Networks, Quantum Secure, Quova, StrikeForce Technologies and VASCO, all members of Oracle PartnerNetwork, Oracle’s global partner program.
- Pre-built integrations from Juniper and Quova are available today.
Context-Aware Security
- Unlike traditional security solutions that only examine user roles and privileges to grant access, Oracle Adaptive Access Manager provides context-aware security that guarantees fraud protection using a variety of identifying information, including the identity of a user’s machine, IP address, geographic location and historical transaction information.
- By unifying identity assurance and enhancing the context of a transaction to drive risk-based decisions from the desktop to the perimeter of the enterprise and into the business application infrastructure, Oracle and its partners plan to deliver improved security and superior convenience to end users.
Supporting Quotes
- “With the increasing sophistication of security threats, rising online fraud and growing regulations governing online data privacy, organizations need robust end-to-end security solutions,” said Amit Jasuja, vice president, Oracle Identity Management. “However, critical systems that enable fraud protection by linking multiple aspects of a user's identity are often siloed or part of a security infrastructure that is operated in stand-alone fashion. By unifying complementary technologies, the Oracle Identity Assurance Partner Alliance aims to improve overall enterprise security by offering better protection from identity theft and stronger controls to safeguard intellectual property.”
- “ActivIdentity is delighted to join the Oracle Identity Assurance Partner Alliance,” said Jerome Becquart, vice president of Products and Services at ActivIdentity. “As an established leader in the identity assurance space, we welcome Oracle’s initiative to further enhance interoperability in the identity ecosystem.”
- “Oracle's strategy of bringing industry leading solutions together to provide real-time ID theft prevention solutions delivers a higher value for Enterprise customers," said John Dancu, CEO and president of IDology, Inc. "We are excited to be a part of this network."
“Juniper is delighted to be a member of the Oracle Identity Assurance Partner Alliance,” said Sanjay Beri, vice president, Access Solutions, Juniper Networks. “The reality of today's extended enterprise is a workforce that is not only increasingly mobile, but one that includes non-employees such as partners, suppliers and contractors. Ensuring high productivity requires providing granular access to key mission-critical applications anytime, anywhere, and from any device for these diverse constituencies. Securing this access and preventing fraud and ID theft is a huge challenge that Juniper and Oracle are addressing to deliver greater value to customers.” - “We are proud to be a member of the Oracle Identity Assurance Partner Alliance and are excited to be part of this distinguished group of companies that are dedicated to enterprise security,” said Bill Varga, executive vice president of Business Development at Quova.
“StrikeForce Technologies is excited to participate in Oracle’s Identity Assurance Partner Alliance. Our participation is expected to help Oracle and StrikeForce customers further prevent identity theft – an ever increasing problem for all,” said Mark L. Kay, CEO, StrikeForce Technologies Inc. “Our participation in the alliance should better enable us to provide organizations with a fully integrated authentication solution that meets several mandates.” - “VASCO Data Security is excited to join the Oracle Identity Assurance Partner Alliance and bring its experience and expertise in strong authentication to this group,” said Adam Dolby, director, Strategic Alliances, VASCO. “VASCO's continuous efforts in raising awareness and public education about secure authentication practices such as one-time passwords and electronic signatures fit very well into the Oracle Alliance. We are proud to be part of this group in its endeavor to create a comprehensive real time solution for proactive fraud prevention."
Supporting Resources
- Identity Management Resource Library
- Service-Oriented Security: An Application-Centric Look at Identity Management
- Oracle Adaptive Access Manager
- Oracle Access Management Suite
- Webcast: The Brave New World of Consumer Authentication with Burton Group
- Independent Analyst Reports Regarding Oracle Software
- Download Oracle Software
About Oracle
Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. For more information about Oracle, please visit our Web site at http://www.oracle.com/.
Trademarks
Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners.
This document is for informational purposes only and may not be incorporated into a contract or agreement.
