Category: Latest
Be Cautious: You could be Giving out your Own Passwords
There are two types of hacking or unauthorized access to accounts. The first involves password cracking tools, but most organizations have cyber security features in place to prevent these attacks. However, it’s the second type of attack that can cripple any organization or person’s accounts and databases, and that is a social engineering attack. 〈 “ Social engineers are criminals who take advantage of human behaviour to pull off an online scam or hacking attack. Successful social engineers are confident and in complete control of the situation “ 〉 Social engineers generally use two techniques – one is by simple observation while the other is the proactive effort. In the first case, the social engineer simply observes a person’s social networking profiles such as Linkedin profiles etc., and all other data available about him. Most people have passwords that they can easily remember, and for that they use the words that are closely related to them. People share every detail of their lives on social networking sites including their date of birth, favourite colour, pet’s name and everything possibly related to them. This information is freely available. This makes it pretty easy for the hackers/ social engineers to guess passwords in such a scenario and fix it. It’s always advisable to be discrete with respect to the data shared on social media. Such data is also collected by the online questionnaires and market research forms that people request to fill in public places. In the second case, the attack is pre-planned and a complete checklist is made of the person or companies including likes and dislikes, passions, hobbies and professional credentials etc. The second stage of physical access now comes into the picture. For example, three income tax officials turn up at your office for an inspection along with relevant badges and check all the office computers and documents. In the process they lodge key loggers into your computers, whereby they will receive an email of every key stroke made on the computers, thereby giving out your passwords and confidential data. An example of this kind of attack would be where a social engineer researches about a person let’s say Mr. A, and collects that the person is fond of foreign holidays. The social engineer calls up this person as the authorized representative from a reputed travel agency and offers a mind-blowing holiday package. He asks Mr. A the version of PDF reader he is using on his laptop. The conversation is very friendly and inspires trust in the mind of Mr. A. The social engineer sends the holiday proposal in a PDF format which is not compatible with the PDF reader installed by Mr. A, and along with the proposal sends a compatible PDF reader for Mr. A to download and read the proposal. The PDF reader has malware attached that gives the social engineer access into Mr. A’s computer Another example of this type of social engineering attack is where a very pretty woman, who is a journalist, goes to meet the system administrator of a big company, to get his opinion on cyber security. She goes easy and flirts with him and after taking his opinion pushes off. In the course she ‘accidently’ leaves her pen drive behind with him. The ensuing impact of the girl would make him curious to know more about her and hence he accesses her pen drive. The pen drive is infected with key logger and Trojan malware, which make the company’s networks very vulnerable. The 4 basic principles which most social engineers follow are: They project confidence: They do not sneak around, they proactively approach people and draw attention towards themselves. They give you something: Probably just a small favor which creates trust and a perception of indebtedness. They use humor as that is one tool which is endearing and disarming. They make a request and offer a reason and research shows people are likely to respond to any reasoned request. Attacks by social engineers are offences in India under Section 43 of the Information Technology Act, 2000. This section reads as under: Penalty and compensation for damage to computer, computer system etc. If any person without the permission of the owner or any other person who is in-charge; Accesses or secures access to such computer, computer system or computer network or computer resource; Downloads, copies or extracts any data, computer data base or information from such computer, computer system or computer network including information or data held or stored in any removable storage medium; Introduces or causes to be introduced any computer contaminant or computer virus into any computer, computer system or computer network; Damages or causes to be damaged any computer, computer system or computer network, data, computer database or any other programmes residing in such computer, computer system or computer network; Disrupts or causes disruption of any computer, computer system or computer network;] Denies or causes the denial of access to any person authorised to access any computer, computer system or computer network by any means; Provides any assistance to any person to facilitate access to a computer, computer system or computer network in contravention of the provisions of this Act, rules or regulations made thereunder; Charges the services availed by a person to the account of another person by tampering with or manipulating any computer, computer system, or computer network, Destroys, deletes or alters any information residing in a computer resource or diminishes its value or utility or affects it injuriously by any means; he shall be liable to pay damages by way of compensation to the person so affected. 〈 “A victim is required to make a Complaint in the prescribed format along with the applicable fees to The Adjudicating Officer, Information Technology Act, 2000. Under the provisions of the Rules for the conduct of Adjudicating Proceedings, the Adjudicating officer shall decide every application in 4 months and the whole matter in 6 months “ 〉 The biggest weakness lies not in computer systems, but lies in human…
INTERPOL Digital Security Challenge
Do you know how to protect your webcam from being hacked? Would you know if a cybercriminal was using your printer to carry out cyberattacks? While most of us are aware of the dangers that cybercriminals can pose to our computers and mobile phones and take steps to protect them, we seldom consider how these threats can affect the growing number of Internet vc connected devices we use in our daily lives. The ‘Internet of Things’ All devices which can connect to the Internet – collectively called the ‘Internet of Things’ or IoT – are potentially at risk of a cyberattack. Everyday personal items like video cameras, refrigerators and televisions can be used by cybercriminals for malicious means. Cyberattacks targeting or using IoT devices have increased significantly in the past two years, according to several reports from the private cybersecurity industry. An example was the Mirai botnet, which in 2016 infected tens of thousands of devices, mostly Internet routers, with weak password security. These were then used in coordinated distributed denial of service (DDoS) attacks against websites worldwide including a university and several media sites. In the world of cybercrime, the number of IoT devices a criminal has access to is seen as a sign of their status. Although police around the world are developing the skills necessary to forensically examine computers and mobile phones, they are often not aware of how to collect evidence from other connected devices. The latest edition of the INTERPOL Digital Security Challenge tackled this threat, with 43 cybercrime investigators and digital forensics experts from 23 countries investigating a simulated cyberattack on a bank launched through an IoT device. “Cybercrime investigations are becoming more and more complex and operational exercises such as the Digital Security Challenge, which simulate some of the hurdles that investigators face every day, are vital for the development of our capacities,” said Peter Goldgruber, Secretary General of the Austrian Ministry of the Interior. Meeting the challenge I n the scenario, cybercriminals attacked a bank in an attempt to steal large sums of money. The investigators analysed the bank’s computers to identify the date, time and files where the malware installed by the criminals. Through this digital forensic examination, the teams discovered the malware was contained in an e-mail attachment sent via a webcam which had been hacked, and not directly from a computer. This is an emerging modus operandi, as it is more difficult to identify the source of the attack. Once the teams accessed the digital data held by the compromised webcam, they identified the command and control server being used to remotely control the device to conduct the cyberattack. Further evidence led to the identification of a second command and control server, and the investigators identified technical vulnerabilities of the servers which could be used to prevent further attacks. Noboru Nakatani, Executive Director of the INTERPOL Global Complex for Innovation said the scenario provided a learning experience on how to conduct real-world investigations more effectively. “The ever-changing world of cybercrime is constantly presenting new challenges for law enforcement, but we cannot successfully counter them by working in isolation. “A multi-stakeholder approach which engages the expertise of the private sector is essential for anticipating new threats and ensuring police have access to the technology and knowledge necessary to detect and investigate cyberattacks,” said Mr Nakatani. Tips for safeguarding IoT devices: Change the factory default passwords – these can be the same for hundreds or thousands of devices, making it easy for criminals to hack; Regularly update all software; Disable features which allow the device to be accessed remotely; Take extra care when buying used devices – you don’t know what the previous owner installed on the device. Sharing expertise Conducted annually, INTERPOL’s Digital Security Challenge helps police worldwide develop the skills necessary to tackle the latest cybercrime threats. The first two events in 2016 and 2017 simulated cyber blackmail involving bitcoin and a ransomware attack. This year’s three-day (19-21 February) event was organized in close I n the Americas, hurricanes, tornadoes and earthquakes are occurring more frequently, so unimpeded mass communication during these events is critical. MNS software is often employed so companies can communicate with their employees, federal agencies, university students and the general public. More channels of communication available in these types of events, means more people can reach safety faster and more lives can be saved. In Western Europe, the second-largest market for MNS software, weather-related incidents occur less often, How Catastrophic Events are Changing Mass-Notification System Market By Robert Brooks – Analyst, Security and Building Technologies, IHS Markit cooperation with the INTERPOL National Central Bureau in Vienna and private sector partners NEC Corporation and Cyber Defense Institute. “NEC has contributed as a strategic partner to INTERPOL’s commitment to improve the cybersecurity skills of investigators throughout the world. For the third year, NEC is honored to have helped develop the Digital Security Challenge by providing our expertise at this cutting-edge event,” said Kozo Matsuo, Vice President of NEC Corporation’s Cyber Security Strategy Division.’ Training sessions to develop participants’ practical knowledge on IoT device analysis and the latest trends in malware-related crime were delivered by specialists from NEC Corporation, InfoSec, Meiya Pico, SECOM, Kaspersky Lab and Trendso the need for MNS software is lower than in the Americas. While individual countries might deal with specific weather threats – like blizzards and freezes in Sweden and flooding in the UK – in 2017 the United States alone experienced four major hurricanes. Mass-notification system (MNS) software used in emergency communication, the primary segment used during a catastrophic event, is expected to grow in the Americas at a compound annual growth rate (CAGR) of 6.8 percent from 2017 to 2021, reaching $293.1 million in 2021. Micro. Support was also provided by the UN Office on Drugs and Crime (UNODC). Kenji Hironaka, President of Cyber Defense Institute said, “We are proud to have provided forensic content and technical support during all three INTERPOL Digital Security Challenge events. We will…
Security Considerations for Code Signing
Recent security-related incidents indicate the need for a secure software supply chain to protect software products (also referred to as code) during the development, build, distribution, and maintenance phases. Of particular concern is provisioning and updating software that plays a critical role in platform security. A wide range of software products including firmware, operating systems, mobile applications, and application container images must be distributed and updated in a secure and automatic way to prevent forgery and tampering. An effective and common method of protecting software is to apply a digital signature to the code. Digitally signing code provides both data integrity to prove that the code was not modified, and source authentication to identify who was in control of the code at the time it was signed. When the recipient verifies the signature, he is assured that the code came from the source that signed it, and that it has not been modified in transit. “NIST plans to develop further guidance to help organizations evaluating, deploying or managing code signing systems. The high-level recommendations described in this document are expected to form the basis for more detailed recommended practices for code signing” This white paper targets software developers and product vendors who are implementing a code signing system or reviewing the security of an existing system, with the goal of achieving improved security and customer confidence in code authenticity and integrity. System integrators and administrators who are concerned about the trustworthiness of the applications that are installed and run on their systems will learn the properties they should expect from a code signing solution to protect their software supply chain. This white paper describes features and architectural relationships of typical code signing solutions that are widely deployed today. It defines code signing use cases and identifies some security problems that can arise when applying code signing solutions to those use cases. Finally, it provides recommendations for avoiding those problems, and resources for more information. Properly applied, these recommendations will help to ensure that the software supply chain is resistant to attack. NIST plans to develop further guidance to help organizations evaluating, deploying or managing code signing systems. The high-level recommendations described in this document are expected to form the basis for more detailed recommended practices for code signing. The basics of code signing This section provides high-level technical details about how this process works. There are multiple roles in the process: developer, signer and verifier. Developer The developer is the entity responsible for writing, building, and/ or submitting the code that will be signed. This entity maintains a secure development environment, including the source code repository, and will submit code to the signer after it has completed the organization’s software development and testing processes. Signer The signer is the entity responsible for managing the keys used to sign software. This role may be performed by the same organization that developed or built the software, or by an independent party in a position to vouch for the source of the code. The signer generates the code signing private/ public key pair on a device that is sufficiently protected, as the security of this process relies upon the protection of the private key. In many cases, the signer then provides the public key to a certification authority (CA) through a certificate signing request. The CA will confirm the signer’s identity and provides a signed certificate that ties the signer to the provided public key. Anyone can use the public key associated with this certificate to validate the authenticity and integrity of code signed with this key pair. If no CA is used, the public key must instead be distributed using a trusted, out-of-band mechanism. The signer ensures through technical and procedural controls that only authorized code is signed. When code is submitted by developers for signing, the signer verifies their identities and their authority to request a signature. The signer may also take additional steps to verify the code is trustworthy. Ultimately, two or more trusted agents of the code signing system may be needed to approve the request and generate a digital signature. In some cases, the signed code may also be provided to a time stamp authority to indicate when the code was signed. Verifier The verifier is responsible for validating signatures on signed code. The verifier may be a software component provided by the same developer as the signed code (e.g., for a signed firmware update), or it may be a shared component provided by the platform (e.g., the operating system). Architectural components The code signing architecture is composed of a set of logical components that are responsible for different aspects of the code signing process. The code signing/ verifying architecture represented in Figure 1 potentially has four distinct components: the code signing system (CSS), the certification authority (CA), the time stamp authority (TSA), and the verifier(s). Code signing system (CSS) The first component, the CSS, receives code submitted for signing, authenticates and authorizes the submitter, and generates the signature. To generate these signatures the CSS has one or more private signing keys, which need to be carefully protected from extraction or unauthorized use. Certification authority (CA) Typically, a CSS utilizes a CA to enable authenticating the identities of signers. CAs issue certificates to signers in accordance with certificate policies, which specify the security controls and practices the CA follows when issuing certificates, and impose requirements on the subjects of the certificates. NIST Interagency Report 7924 is a reference certificate policy that specifies most of the requirements for a CA that issues code signing certificates. There are also industry groups such as the CA/ Browser Forum and the CA Security Council, that have published requirements documents for the issuance of code signing certificates. Time stamp authority (TSA) Some code signing architectures use a TSA to demonstrate when a particular piece of code was signed. When a TSA is used, signatures are sent to the TSA which applies its own signature and signing time to the package….
Traditional Switch Port Security
With Cybersecurity becoming an increasingly important factor in designing modern Ethernet networks, ComNet have launched an industry first edge security feature that is both simple, secure and easy to configure and use. The ComNet exclusive Port Guardian feature has the capability to physically disable a port if unauthorized access is detected. The value in Port Guardian comes in situations where network intrusion is attempted by disconnecting an IP addressable device at the edge to connect to the network. When Port Guardian senses this disconnect, an SNMP notification is sent to the head end and the affected port is physically locked out, preventing access. The network administrator can re-enable the port once the threat is eliminated. This feature also thwarts access through ‘Spoofing’ by disabling the port as soon as an interruption is sensed. Layer 2 managed switches can typically implement port security which consists of checking incoming packets for a matching MAC address. If a packet with a valid MAC address is received on a particular port then the switch will allow that packet to pass through the switching fabric of the switch as normal. If a packet with an invalid MAC source address is received on the switch port then that packet is dropped by the switch and is not allowed to proceed any further and therefore, this provides a basic level of security as only traffic from the user defined MAC address is allowed on that port. With this method it is therefore possible to easily implement basic port security against a potential intruder from removing the original device and replacing it with a device designed for network intrusion or from cutting the cable that went to the original device and connecting this cable to their own network intrusion device to gain access to the network. This level of protection is common amongst most layer 2 managed switches on the market today and indeed all ComNet managed switches support this capability as standard. This feature is referred to by many names including (but not limited to) the following: Port locking. MAC locking. Port security. MAC filtering. What’s wrong with traditional switch port security? The issue with the traditional Layer 2 MAC filtering/ locking as previously described is that it can be defeated with relative ease in a matter of minutes by using readily available software which can artificially alter the MAC address of the sender to match whatever the potential intruder wants. In the example below the intruder will alter the MAC address of their laptop to use the same MAC address of the authorised camera and gain access to the network. How would the intruder know what MAC to spoof? So how would a potential intruder know the MAC address of the camera (in this example) in order to be able to spoof that address from their laptop and gain network access? This could be done in several ways but one simple way could be to use a low cost network tap device so the camera is briefly unplugged and then connected to the tap and then quickly re-connected to the network again. The operator would see video loss for some seconds but would unlikely put this down to a potential intruder if it was even noticed at all. How does port guardian prevent such intrusions? At the basic level Port Guardian works as a layer 1 protection system so the actual data being sent on the port is not important and the switch does not need to know anything about it. Port Guardian constantly monitors the enabled ports and as soon as it detects that a cable has been unplugged or there is a link down event that port will be immediately disabled and the network administrator notified via an SNMP alert (and optionally by a local contact relay if supported on the particular switch model) to the potential intrusion. What happens after Port Guardian locks out a port? Once Port Guardian has been triggered on a certain port then that port is in a permanent lock out condition and will appear to be dead to the potential intruder (no LEDs or anything will work on that port). The port will remain in this lock out condition even if the original legitimate device is re-connected. The lock out state can only be cleared by the network administrator through one of 4 possible methods as outlined below SNMP reset command issued. Reset via Web GUI. Port Guardian reset command issued from the local USB serial port CLI. A contact input is closed (only available on models that have contact inputs). The contact input method is user configurable and is not enabled by default. What about cycling power to the switch? This is another user configurable option. The port lock out states can be set to clear on a power cycle or they can be set to go into lock out condition in the event of a power cycle (this would be the most secure option). So how can Port Guardian be used in networks? There are really two distinct ways to use the Port Guardian feature and the correct implementation depends on how secure the location is where your remote ComNet edge switch (with Port Guardian feature) is located. An outline description and visual example of both scenarios follows. Edge switch in secure location scenario I f the ComNet edge field switch is installed within a secure location then there is no concern about an intruder gaining access to the physical switch itself so one could enable Port Guardian just on the ports where he has edge devices connected that are physically located outside of the secure location and not enable Port Guardian on the uplink port(s) which are part of the secure network. In this scenario one could also set the option to have a power cycle clear any locked out ports as again he would not be as concerned with a potential intruder being able to power cycle the switch itself. Edge switch in…
Synology Strengthening NAS Portfolio in India
Synology® the global leading provider of network attached storage (NAS), IP surveillance and network equipment solutions, forays into India market with the rollout of its cutting-edge series of NAS solutions in the country. With a proven history of transforming the way users manage data, perform surveillance, and manage the network in the cloud age, Synology has set new benchmarks in the enterprise IT space, leveraging latest technologies and unprecedented innovation coupled with an exceptional customer service. The company has announced strategic partnerships with both online as well as offline channels to make its solutions available in the country. Synology’s offline distributors in India include Supertron, EBM, while Amazon will serve as the company’s online retailer. Four complete product lines of industry-leading NAS that are designed to meet different requirements and needs from personal users, small offices, SMBs, and enterprises (including XS/XS+ series; Plus series; Value series and J series) provided by the company are now available in India. The company will also be unveiling the latest DiskStation Manager 6.2 (DSM6.2) OS update along with new applications and services in the country soon. The company has registered a historic 30 percent CAGR growth in India since the year 2015 with SMBs contributing to a major chunk of this growth. Synology will also ink new partnerships in the country in the year 2018 along with organizing reseller events and trade shows as well as studying consumer behavior to ensure last mile market presence in the ongoing year. Synology creates network attached storage, IP surveillance solutions, and network equipment that transform the way users manage data, conduct surveillance, and manage network in the cloud era. By taking full advantage of the latest technologies, Synology aims to help users centralize data storage and backup, share files on-the-go, implement professional surveillance solutions, and manage network in reliable and affordable ways. Synology is committed to delivering products with forward-thinking features and the best in class customer services. “India is aggressively marking its presence as a growth engine in the global economy, owing to an unparalleled growth in the SMB segment as well as ambitious government initiatives like Smart City Programme. We at Synology are committed to aiding this growth in the country with our industry-leading NAS solutions which help organizations gain more agility and streamline their work processes” – Mike Chen Marketing Director, Synology
Banker’s Legal Guide to Deal with Phishing Scams and Cyber Crimes in India
Online banking has revolutionized banking transactions whereby money could be transferred at a single click. It has been a time saver and has been an extremely convenient method to undertake commercial transactions. However, it has led to litigations against banks as well, as with online banking also come phishing emails. Phishing emails in these cases are those which purport to have been sent by the bank with the look and feel of a legitimate email. They ask the user to enter their username and password to reconfirm their accounts, with invariabe threats that if the confirmation is not made, the account would be frozen immediately. In many cases these emails are spoofed also whereby a third party sends an email using the email id of the bank, but that can be easily identified by reading the complete header of the email. Many users panic on receiving such emails and immediately give out their personal sensitive data like banking passwords to third parties purporting to be representing the bank. They realize that they have been duped only when money is withdrawn by such third parties from their bank accounts. There has been a slew of litigation against banks whereby the victims of phishing scams file complaints against the banks under the Information Technology Act, 2000. The grounds on which such complaints are filed attracts Section 43, Section 43A and Section 72A of the Information Technology Act. Section 43 deals with unauthorised access, and the complainant in most of the cases alleges violation of Section 43A which is for accessing or securing access to a computer, computer system or computer network without permission of the owner or the person in charge. However, banks have a very strong legal defence to this cause because the unauthorised access is done by a third party and not by the bank. The banks on receipt of any information from an online banking services user that his account has been wrongfully debited, must ask him if he responded to any email asking for his password, and also asks him to submit documentary proof of that email to the bank. If the user admits that he has replied to such phishing email, the bank requires him to submit a letter to the bank to that effect in order to enable the bank to freeze his account, whereby further unauthorised money transfer from his account could be stopped. The bank should intimate the user by an official letter to file a complaint with the cyber crime cell, and the bank should also file an FIR against the beneficiary account holders in whose accounts the money has been unauthorisedly credited. This is important to prove the proactive efforts of the bank in a litigation by a victim against the bank under the Information Technology Act. Section 72A of the Information Technology Act for punishment for disclosure of information in breach of lawful contract reads as under: Save as otherwise provided in this Act or any other law for the time being in force, any person including an intermediary who, while providing services under the terms of lawful contract, has secured access to any material containing personal information about another person, with the intent to cause or knowing that he is likely to cause wrongful loss or wrongful gain discloses, without the consent of the person concerned, or in breach of a lawful contract, such material to any other person shall be punished with imprisonment for a term which may extend to three years, or with a fine which may extend to five lakh rupees, or with both.” The main contention of the complainant would be that the bank has access to his password and misused it. However, as per RBI norms all banks have 128 bit encryption of passwords and the bank does not have any access to the same. The complainants in most cases attempt to bring the bank within the definition of an ‘Intermediary’ under the Information Technology Act; however, the exceptions to intermediary liability under Section 79 of the Information Technology Act, 2000, apply to a bank in this case because of the following reasons: The function of the bank is limited to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored. The bank does not- i) initiate the transmission, ii) select the receiver of the transmission, and iii) select or modify the information contained in the transmission The bank observes due diligence while discharging his duties under this Act and also observes such other guidelines as the Central Government may prescribe in this behalf. The banks are required to maintain ISO 27001 standards because they handle confidential and sensitive personal data of users of their services. In brief, the banks need to undertake the following steps in order to be able to succeed in any litigation against them: They should provide a handbook to the online banking services users at the time they apply for such services. The handbook should mention directions for safe use of online banking and should also contain complete information about phishing emails and scams, including information on how users can protect themselves from such phishing attacks. The online banking services application should have an Indemnity clause, whereby the user indemnifies the bank. The terms and conditions of online banking should contain Indemnity clauses with respect to password of the user, online transactions and use of bank’s services. There should be a security tips page which warns users of phishing emails each time they log in for online banking. Customers/ users should be proactively informed about all the Cyber threats. There should be Cyber security and Cyber law compliance panel. This panel should comprise of cyber security experts who should ensure that proper cyber security measures are always in place and the cyber lawyer in the panel should ensure that the online banking user agreement clauses are up-to-date to restrict the bank’s liability in an environment where new cyber crimes get…
Top Video Surveillance Trends for 2018
Demand for professional video surveillance cameras has been growing quickly and is forecast to continue growing in 2018. It is estimated that less than 10 million surveillance cameras were shipped globally in 2006, which grew to over 100 million in 2016, and is forecast to make over 130 million during 2018. Despite this increase in demand, the average price of cameras and other video surveillance equipment will continue to fall quickly. As a result, IHS Markit forecasts that in terms of US dollar revenues the world market for video surveillance equipment will grow at an annual rate of less than 6% in 2018. It will be challenging for vendors to continue to grow revenues and margins, but there will be opportunities for well-placed vendors. For example, both the South East Asian and Indian markets are forecast to grow at higher than average rates. There is also great potential for the next generation of products powered by technologies like deep learning and cloud computing. So, what will be the big stories during 2018? Deep learning, GDPR compliance and drone detection technologies are just some of the trends discussed in this eighth annual trends IHS white paper. The following articles are designed to provide some guidance on the top trends for 2018 in the video surveillance industry. IHS Analyses The A to I of Video Surveillance Terminology By – Jon Cropley Big Differences between the Chinese Market and the Rest of the World By – Jon Cropley General Data Protection Regulation (GDPR) By – Josh Woodhouse Video Surveillance Fault Tolerance By – Josh Woodhouse Forensic Video Analytics as a Service By – Josh Woodhouse The Evolution of Deep Learning in Video Surveillance By – Monica Wang Drone Detection Technologies By – Oliver Philippou
Biometrics at the ATM
In the quest to secure our identity in an increasingly connected digital world, biometrics is flourishing throughout the globe. According to a TechSci Research report, India’s biometrics market is projected to grow at a CAGR of around 31% during 2016 – 2021. Government, banking & finance, energy & power, and consumer electronics are the key end user segments where deployment of biometric systems is witnessing an increase, and this trend is expected to continue over the next five years. In many banking services markets, biometrics is successfully authenticating millions of users at the ATM while improving the user experience, increasing transaction security and delivering trust in transactions. Accelerated adoption of biometric authentication at the ATM and related banking solutions (such as securing government pension payments, teller transactions and the opening of new accounts) are in large measure because biometrics is the only authentication method that ‘binds’ a user’s digital credentials to a person – a critical capability for eliminating digital identity theft in an environment that has become increasingly complex and vulnerable to security threats. Increasing security can create barriers to legitimate access, but biometrics bring security and convenience together, simplifying authentication while making it more robust and reliable. The technology has now advanced to the point that today’s fingerprint sensors can distinguish between legitimate and counterfeit biometric characteristics, a capability known as liveness detection. Another innovation allows the deployment of intelligent encryption-enabled and tamper-resistant fingerprint devices that further strengthen secure authentication and protect user privacy. Biometrics authentication will only grow in importance moving forward. We live in an environment where each of us has a growing list of digital identities for an expanding set of applications, stored on a variety of ID cards, tokens, smartphones and other mobile smart devices. Again, biometrics has the unique ability to bind this multitude of digital identities to an individual’s single, true identity. The challenge is how to verify this true identity in a manner that is private, secure and non-intrusive. Biometric authentication solves this challenge, creating a more satisfying and convenient user experience while ensuring that transactions are trusted and secure. The challenge of authentication at the ATM Worldwide, ATMs generally require that users validate their identity with something they have such as a card, and something they know such as a PIN. This has been in practice for decades, but is increasingly vulnerable to fraud; the more digital credentials and identities we store on ID cards, tokens and smart devices, the worse the problem turns into. According to the Norton Cyber Security Insights Report 2016, 49% of India’s online population, or more than 115 million Indians, are affected by cybercrime at some point with the country ranking second in terms of highest number of victims. Only biometrics can securely bind these digital identities to the actual person with whom they are associated. Plus, every new digital identity is just one more element to manage, and one more threat to someone’s one, true identity. In the last three years, public sector banks (PSBs) in India have lost a total of INR 22,743 crore, on account of various banking frauds. Banks are tackling the fraud problem with approaches like EMV cards. But only biometrics can confirm ‘who’ is actually transacting, and whether that person is a legitimate bank customer or a fraudster. To do this while protecting privacy and combating identity fraud, the biometric solution must use liveness detection to distinguish live fingerprints from fakes while ensuring that ATMs aren’t difficult to use. Biometrics binds a unique individual to his or her true identity, and determines ‘who’ is actually using the system, while eliminating the hassle and security risks of PINs and passwords. Biometrics also eliminates the need to carry or remember anything, allowing access and transactions with the touch of a finger. It is the only true means of making security more convenient while also linking or binding digital identities to the individual. Moving forward, using biometrics to authenticate mobile payments and other bank transactions will likely become a very big market driver. As Gartner predicted, by 2016, 30% of all organizations would be using biometrics on mobile devices and has long upheld the conviction that biometric solutions are the must-have for enterprise mobile authentication. With applications like Apple Pay and initiatives from the FIDO Alliance and others, biometric authentication is becoming more prominent in consumer-facing applications. Meanwhile, with new technology adoption comes new risks: as biometric applications become increasingly widespread, and are relied upon for securing personal transactions, deployed solutions are likely to be targeted for attack. Consequently, it will be increasingly important for those deploying biometric authentication to understand that not all biometric devices and solutions are created equal. For example, many ATMs are outdoor; in that case the biometric device at the ATM should be able to obtain high quality image under the conditions that are common in ATM environment such as dry, humid, ambient light, with large population and wide demographics. Considering major challenges such as high quality image acquisition, fake finger attacks, man in middle/ replay attacks, a thorough evaluation of biometric technology in target environment with target population is strongly recommended. ATM transactions must be convenient, and all identities used to conduct them must be protected. Banks must balance and even combine security and convenience as they manage risk, and biometric authentication makes this possible. It enables us to protect our one true identity in a way that is balanced, reasonable and efficient. Nothing in life is without risk but there are no longer valid technical or business reasons to rely on outdated security systems and practices. With biometrics, we can securely and conveniently use a myriad of digital credentials, knowing that our true identity is protected. We don’t have to forfeit security for convenience or vice-versa – we get both. Sujan Parthasaradhi Director of Biometric Applications, APAC, HID Global
FSIE 2018 : Brings the Entire Fire Safety & Security Industry to Bengaluru
The second edition of the leading trade event for fire safety and security – Fire and Security India Expo (FSIE) is to be held at Bangalore International Exhibition Centre (BIEC) in Bengaluru during 22-24 February 2018. The fair will witness over 150 leading brands displaying their technological advancements, and products and solutions catering to the wide demand of the industry. With over 10,500 square metre of exhibition space, FSIE 2018 will have live product demonstrations along with conferences and workshops addressing key topics related to fire safety and security. Buyer-seller meetings, trade delegations are some of the other concurrent events to be a part of the expo. The Finest India Skills & Talent (FIST Awards) 2018 in the field of fire safety and security will recognise the achievements of the most innovative, reliable and cost-effective products, services and solutions spanning a wide range of fields across the fire safety and security industries. The three-day trade fair will be a part of the Build Fair Alliance, a consortium of co-located events that are proposed to be conducted at the same venue coinciding with FSIE, thereby ensuring maximum number of footfalls from stakeholders of building automation and construction industry. This year the event will be co-located alongside ACREX India – leading exhibition on HVAC technology, and ISH 2018 – leading exhibition showcasing plumbing systems. The alliance of the three events together is expected to attract over 50,000 business visitors during the three days. In India, awareness about fire safety and security has grown exponentially. It has intensified over the last decade as a direct result of the country’s economic evolution. As IT and retail markets rapidly expand coupled with an increase in setting up large commercial factories, the stakes in terms of assets, investments and resources are too huge to be put at fire and security risk. Continuing to drive the demand for fire safety and security is also the government’s focus on infrastructure development, especially with initiatives like the Smart City Mission. Pankaj Dharkar, President, Fire and Security Association of India shares, “Fire & Security Association of India (FSAI) and NuernbergMesse India joined hands together to organise the Fire & Security India Expo earlier last year, and this is the second edition of the annual trade event. The event is poised to attract the largest gathering of trade professionals witnessing product demonstrations and latest innovations by the leading brands participating at FSIE 2018 from world over.” By being the wide platform forum that it is, FSIE will bring to the fire safety and security industry, a uniquely concentrated market overview of integrated solutions for fire protection and security, especially those that intelligently combine innovation and technology. As part of exhibits, installations and discussions, the latest technology in fire safety & security will be on display during the expo, along with their uses, advantages and ways of deployment. This will empower decision-makers with first-hand information, as well as open the stakeholders’ eyes to new possibilities. Sajid Desai, CEO, NuernbergMesse India shares, “The second edition of Fire & Security India Expo (FSIE) is a multi-dimensional platform that combines solutions for passive, active and organisational fire safety and security management. Here, official experts, architects and developers, MEP consultants, OEMs, security experts, building engineers, members of leading security and fire prevention bodies as well as fire safety & security representatives from retail, hospitality, healthcare, real estate, facility management, IT-ITEs industry and other stakeholders will gather to disseminate information, gather knowledge, exchange ideas, exhibit, debate innovative perspectives, solutions and products for fire safety and security.” Leading players including IDEX Corporation, A.D.N. Fire Safety Pvt Ltd, Advanced International, Apollo Fire Detectors Ltd, Arihant Fire Protection Services Pvt. Ltd., Bharti Fire Engineers, Coopro Safety India Pvt Ltd, DDS Limited, FFE Ltd, IDEX India Pvt Ltd, Lubi Industries LLP, Naffco India Pvt Ltd, New Age Firefighting Co Ltd, Nohmi Bosai (India) Pvt Ltd, NSC Sicherheitstechnik GmbH, Prama Hikvision (India) Pvt. Ltd., Rapidrop India Pvt Ltd, Ravel Electronics Pvt. Ltd., Safex Fire Services Ltd, Securiton AG, Shah Bhogilal Jethalal & Bros, Topaz Fire Systems Pvt Ltd, Winco Valves Pvt Ltd among many others are ensuring that the event is the standalone platform for business excellence in the fire safety & security domain. “The Indian fire and safety equipment market is expected to reach USD 4.94 billion by 2019. With the increased growth of the economy coupled with the government rules and regulations, the future of the Indian fire safety & security market is very bright.” – Pankaj Dharkar
Videonetics Partners with Kolkata Traffic Police To Celebrate Road Safety Week 2018
Videonetics, one of the world-leading visual computing platform development companies, partnered with Kolkata Traffic Police by showcasing its complete suite of intelligent traffic management system (ITMS) at the exhibition held from 10th to 12th January 2018 at Kolkata, in celebration of Road Safety Week 2018. The exhibition was organized with an aim to propagate Kolkata Police’s mission of ‘Safe Drive & Save Life.’ The exhibition was well attended by Sr. Police Officials, engineering and technology firms, road engineering, traffic management experts and urban planners from all over India, Bangladesh, Nepal, and other SAARC countries. Videonetics ITMS comprises automatic number plate recognition (ANPR), red light violation detection (RLVD), no helmet detection, overspeed detection, no parking detection, wrong way detection, traffic congestion detection and automated e-challan system. “As our country’s mission is to build safe & smart cities and creating safer environment for all, we at Videonetics have been innovating state-of-the-art technologies to meet challenging requirements of traffic management, aiming to deter traffic violations, reduce accidents and provide road safety to all. We congratulate Kolkata Traffic Police for the tremendous success of the exhibition which successfully brought all stakeholders under one common platform and helped create much needed public awareness towards road safety,” expressed, Avinash Trivedi, VP at Videonetics.