SlideShare a Scribd company logo
MICHAEL THELANDER, SR DIR OF PRODUCT MARKETING
U SIN G “ FR AU D PR EVEN TION ” TEC H N OLOGIES TO
D ELIVER BETTER AU TH EN TIC ATION
DECEMBER 2017
RECOGNISING THE
GOOD GUYS
2
3
Is this a fraudster?
Have we been hit
by this person
before?
Has anyone else
been fooled?
What are the
signals that alarm
us?
Is this a great
customer?
How can I give them
a better experience?
Can I stop ATO?
Can authentication
have less friction?
AGENDA
4
WHAT IS DEVICE RECOGNITION?
WHAT ARE THE RESULTS?
CAN WE DETECT EVASION
ACTIVITY?
DO WE GET BETTER SECURITY?
WHAT IS DEVICE
RECOGNITION?
AND WHAT CAN YOU DO WITH IT?
6
THE DNA OF A DEVICE
HUNDREDS OF DEVICE ATTRIBUTES COMBINE TO CREATE A DIGITAL FINGERPRINT
7
 WiFi (or Bluetooth) MAC Address
 Network configuration
 iOS Device Model
 Battery level / AC mode
 Device orientation
 File system size
 Physical memory
 Number attached accessories
 Has proximity sensor?
 Screen brightness and resolution
 System uptime
 iOS Device Name (MD5 Hash)
 OS Name and/or version
 Device advertising UUID
 Kernel version
 iCloud Ubiquity Token
 Application Vendor UUID /name/vers
 Is Simulator?
THE DNA OF A DEVICE
HUNDREDS OF DEVICE ATTRIBUTES COMBINE TO CREATE A DIGITAL FINGERPRINT
 Locale language / currency code
 WiFi MAC Address
 Bluetooth MAC Address
 Network configuration
 Is plugged in?
 Device orientation
 File system size
 Physical memory
 CPU Type
 CPU count
 CPU Speed
 Screen brightness
 Screen resolution
 System uptime
 iOS Device Name (MD5 Hash)
 Device advertising UUID
 Current latitude
 Current longitude
 Current altitude
 Application Vendor UUID
 Bundle ID
 Application Version
 Application name
 Process name
 Executable name
 Application orientation
 Locale language code
 Locale currency code
 Are location services enabled?
 Time zone
 Currently registered radio
technology
 Carrier name
 Carrier ISO country code
 Carrier mobile country code
 Carrier mobile network code
 Does carrier allow VOIP?These attributes combine to provide a unique, indisputable digital fingerprint
8
CLEARKEY
D E V I C E - B A S E D A U T H E N T I C A T I O N F O R B E T T E R C U S T O M E R E X P E R I E N C E
Machine learning compares user devices
Transparent authentication eliminates friction
Turns the user’s device into a possession factor
Adaptive, contextual response drives subsequent
authentication strategies and actions
MINIMUM
THRESHOLD
MAXIMUM
THRESHOLD
Original
Device Print
Returning
Device Print
DEVICE ID IP / GEO
DEVICE
CONTEXTINTEGRITY REPUTATION
Match Grant
Access
No Match
or
Risk Signals
• Rooted
• Jailbroken
• Anomalies
• Watchlist
• Configuration
• Emulator
Account-to-
Device Pairing &
Risk Evaluation
Persistent
Session
Token
Login
User
Access
Customer
Access
Login
Device
Registration SUCCESS
Step-Up
***
HOW CLEARKEY WORKS
D E V I C E - B A S E D A U T H E N T I C A T I O N F O R B E T T E R C U S T O M E R
E X P E R I E N C E
***
WHAT ARE THE
RESULTS?
11
CLEARKEY
R E G I S T E R O R “ P A I R ” T H E D E V I C E D U R I N G T H E C U S T O M E R ’ S J O U R N E Y
12
CLEARKEY CUSTOMER EXAMPLES
M E A S U R I N G R E S U L T S
Positive Match,
minimal change
No device associated with
the account
New registrations
as a %
A device is
registered, but it’s
not this one
13
OPTIMUM EXPERIENCE FOR ONLINE GAMING
M O B I L E A P P “ O P T - I N ” U S I N G D E D I C A T E D E M A I L & E X P L A I N E R
True out-of-band
solution:
Good experience
for majority, but did
require some tuning
Variations in workflow
and offerings required
tuning, but now
delivering highest
recognition rate of all
customers at over 95%
14
OPTIMUM EXPERIENCE FOR ONLINE RETAIL
W E B B R O W S E R “ O P T - I N ” W I T H D E D I C AT E D P R O M P T P A G E
Many users receive
immediate benefit
from improved
experience
Dedicated prompt page
explained the value of
registering a device,
made a “don’t
remember me” option
available
15
OPTIMUM EXPERIENCE FOR ONLINE BANKING
M O B I L E A P P W I T H A U T O - R E G I S T R A T I O N O N D O W N L O A D
Many users benefit
from improved
experience within 6
months
Almost 85% of users see
expedited journey with no
step-up authentication
until a higher-risk action
is taken
16
ON TOP OF THAT, STOP ATO
A C U S T O M E R Q U O T E
“With ClearKey in place we’ve virtually
eliminated successful account takeovers
… even though attempts are at an all-time
high because of the stolen
credential market.”
CAN WE DETECT
EVASION ACTIVITY?
WHAT IF THEY DON’T WANT TO BE
RECOGNISED?
18
RISK INSIGHT FROM THE USER’S DEVICE
EvidenceDevice & Age Risk Profile
Geo-
location
Anomaly Watch ListsVelocity
ISP Watch List
Transactions per
Account
Timezone / Geo
Mismatch
Subscriber
Evidence Exists
Transaction
Amount Range
Geolocation
Mismatch
Device new to
Subscriber
IP Address Range
List
Global Trans
Device Velocity
Device Not
Provided
Evidence Exists
Billing/Shipping
Mismatch
Proxy In Use
New Device,
Existing Acct
Email Domain List
Countries Per Acct
or Device
Suspect Device
Data
IP Address RiskCountry List
Age of the
Association
Browser Language
Trans per
IP/Device/Acct
TOR Exit Node IP
Device Risk
(Local or Global)
Mobile Carrier
Country List
Registered
Acct/Dev Pair
ISP Organization
List
$S Value per
Device or Acct
VM in Use
Language and
Country Risk
IP Address
Distance
Device Type List
Devices per
Account
Mobile Emulator
Detected
Jailbreak/Root
Detected
IP Address
Mismatch
Accts (Created)
per Device
ISP Mismatch
POSITIVE RULES TRIGGERED
EVASION RULES TRIGGERED
19
RISK INSIGHT FROM THE USER’S DEVICE
EvidenceDevice & Age Risk Profile
Geo-
location
Anomaly Watch ListsVelocity
ISP Watch List
Transactions per
Account
Timezone / Geo
Mismatch
Subscriber
Evidence Exists
Transaction
Amount Range
Geolocation
Mismatch
Device new to
Subscriber
IP Address Range
List
Global Trans
Device Velocity
Device Not
Provided
Evidence Exists
Billing/Shipping
Mismatch
Proxy In Use
New Device,
Existing Acct
Email Domain List
Countries Per Acct
or Device
Suspect Device
Data
IP Address RiskCountry List
Age of the
Association
Browser Language
Trans per
IP/Device/Acct
TOR Exit Node IP
Device Risk
(Local or Global)
Mobile Carrier
Country List
Registered
Acct/Dev Pair
ISP Organization
List
$S Value per
Device or Acct
VM in Use
Language and
Country Risk
IP Address
Distance
Device Type List
Devices per
Account
Mobile Emulator
Detected
Jailbreak/Root
Detected
IP Address
Mismatch
Accts (Created)
per Device
ISP Mismatch
+1000POSITIVE RULES TRIGGERED
EVASION RULES TRIGGERED
20
RISK INSIGHT FROM THE USER’S DEVICE
EvidenceDevice & Age Risk Profile
Geo-
location
Anomaly Watch ListsVelocity
ISP Watch List
Transactions per
Account
Timezone / Geo
Mismatch
Subscriber
Evidence Exists
Transaction
Amount Range
Geolocation
Mismatch
Device new to
Subscriber
IP Address Range
List
Global Trans
Device Velocity
Device Not
Provided
Evidence Exists
Billing/Shipping
Mismatch
Proxy In Use
New Device,
Existing Acct
Email Domain List
Countries Per Acct
or Device
Suspect Device
Data
IP Address RiskCountry List
Age of the
Association
Browser Language
Trans per
IP/Device/Acct
TOR Exit Node IP
Device Risk
(Local or Global)
Mobile Carrier
Country List
Registered
Acct/Dev Pair
ISP Organization
List
$S Value per
Device or Acct
VM in Use
Language and
Country Risk
IP Address
Distance
Device Type List
Devices per
Account
Mobile Emulator
Detected
Jailbreak/Root
Detected
IP Address
Mismatch
Accts (Created)
per Device
ISP Mismatch
POSITIVE RULES TRIGGERED
EVASION RULES TRIGGERED
Watch ListsVelocity
ISP Watch List
Transactions per
Account
IP Address Range
List
Global Trans
Device Velocity
Email Domain List
Countries Per Acct
or Device
Browser Language
Trans per
IP/Device/Acct
ISP Organization
List
$S Value per
Device or Acct
Device Type List
Devices per
Account
+500
21
RISK INSIGHT FROM THE USER’S DEVICE
EvidenceDevice & Age Risk Profile
Geo-
location
Anomaly Watch ListsVelocity
ISP Watch List
Transactions per
Account
Timezone / Geo
Mismatch
Subscriber
Evidence Exists
Transaction
Amount Range
Geolocation
Mismatch
Device new to
Subscriber
IP Address Range
List
Global Trans
Device Velocity
Device Not
Provided
Evidence Exists
Billing/Shipping
Mismatch
Proxy In Use
New Device,
Existing Acct
Email Domain List
Countries Per Acct
or Device
Suspect Device
Data
IP Address RiskCountry List
Age of the
Association
Browser Language
Trans per
IP/Device/Acct
TOR Exit Node IP
Device Risk
(Local or Global)
Mobile Carrier
Country List
Registered
Acct/Dev Pair
ISP Organization
List
$S Value per
Device or Acct
VM in Use
Language and
Country Risk
IP Address
Distance
Device Type List
Devices per
Account
Mobile Emulator
Detected
Jailbreak/Root
Detected
IP Address
Mismatch
Accts (Created)
per Device
ISP Mismatch
POSITIVE RULES TRIGGERED
EVASION RULES TRIGGERED
Watch ListsVelocity
ISP Watch List
Transactions per
Account
IP Address Range
List
Global Trans
Device Velocity
Email Domain List
Countries Per Acct
or Device
Browser Language
Trans per
IP/Device/Acct
ISP Organization
List
$S Value per
Device or Acct
Device Type List
Devices per
Account
Watch Lists
ISP Watch List
IP Address Range
List
Email Domain List
Browser Language
ISP Organization
List
Device Type List
Watch Lists
Device Type List
-500
22
RISK INSIGHT FROM THE USER’S DEVICE
EvidenceDevice & Age Risk Profile
Geo-
location
Anomaly Watch ListsVelocity
ISP Watch List
Transactions per
Account
Timezone / Geo
Mismatch
Subscriber
Evidence Exists
Transaction
Amount Range
Geolocation
Mismatch
Device new to
Subscriber
IP Address Range
List
Global Trans
Device Velocity
Device Not
Provided
Evidence Exists
Billing/Shipping
Mismatch
Proxy In Use
New Device,
Existing Acct
Email Domain List
Countries Per Acct
or Device
Suspect Device
Data
IP Address RiskCountry List
Age of the
Association
Browser Language
Trans per
IP/Device/Acct
TOR Exit Node IP
Device Risk
(Local or Global)
Mobile Carrier
Country List
Registered
Acct/Dev Pair
ISP Organization
List
$S Value per
Device or Acct
VM in Use
Language and
Country Risk
IP Address
Distance
Device Type List
Devices per
Account
Mobile Emulator
Detected
Jailbreak/Root
Detected
IP Address
Mismatch
Accts (Created)
per Device
ISP Mismatch
POSITIVE RULES TRIGGERED
EVASION RULES TRIGGERED
Watch ListsVelocity
ISP Watch List
Transactions per
Account
IP Address Range
List
Global Trans
Device Velocity
Email Domain List
Countries Per Acct
or Device
Browser Language
Trans per
IP/Device/Acct
ISP Organization
List
$S Value per
Device or Acct
Device Type List
Devices per
Account
Watch Lists
ISP Watch List
IP Address Range
List
Email Domain List
Browser Language
ISP Organization
List
Device Type List
-1000
DO WE GET BETTER
SECURITY?
WHAT ABOUT PSD2’s SCA REQUIREMENTS?
24
DEFINING MULTIFACTOR AUTHENTICATION
S T R O N G A N D F L E X I B L E A U T H E N T I C A T I O N
Something you
KNOW
25
DEFINING MULTIFACTOR AUTHENTICATION
S T R O N G A N D F L E X I B L E A U T H E N T I C A T I O N
Something you
KNOW
Something
you ARE
Identity
verified
26
DEFINING MULTIFACTOR AUTHENTICATION
S T R O N G A N D F L E X I B L E A U T H E N T I C A T I O N
Something you
KNOW
Something you
ARE
Something
you HAVE
27
Visit www.iovation.com/resources
28
Visit www.iovation.com/resources
QUESTIONS
?
www.iovation.com
@TheOtherMichael
SENIOR DIRECTOR OF PRODUCT MARKETING
MICHAEL
THELANDER michael.thelander@iovation.com
001.1.503.943.6700

More Related Content

PPTX
Achieving Strong Customer Authentication Without Losing the Customer
PPTX
Has THAT device been involved in past fraud?
PDF
The When, Why and How of Mobile Fraud Prevention
PDF
Get Ready for EMV and Card Not Present Fraud
PPT
Sentegra MobileBeat 2010 Startup Competition Presentation
PPTX
E payment
PDF
Key trends to drive your payments strategy
PPTX
Dynamic authentication rollin'
Achieving Strong Customer Authentication Without Losing the Customer
Has THAT device been involved in past fraud?
The When, Why and How of Mobile Fraud Prevention
Get Ready for EMV and Card Not Present Fraud
Sentegra MobileBeat 2010 Startup Competition Presentation
E payment
Key trends to drive your payments strategy
Dynamic authentication rollin'

What's hot (20)

PPTX
Achieving both GDPR Compliance and a Positive Customer Experience
PDF
Mobile payment-security-risk-and-response
PPTX
Peer to-peer mobile payments
PPTX
Presentation money 2.0
PPTX
Mobile Payments revolution
PDF
SmartGo
PPTX
BlueHornet Webinar: The Rise of the Digital Wallet - New Opportunities for Em...
PDF
Kona Corporate Profile
PDF
Mobile payments, e-money and mobile credit in Japan
PDF
Shufti Pro| Digital Identity Verification Solution
PDF
Smart card to the cloud for convenient, secured nfc payment
PPTX
How we will be paying in 2020 - SPA Technical Director, Lorenzo Gaston at EPC...
PPT
Overview of Mobile Payment Systems
PDF
Mobile payment technology 8.11.2014 final
PPTX
Thoughts on the Future of Payments
PDF
PDF
Sample Report: Global Mobile Payment Methods: Full Year 2015
PDF
The Future of Mobile Payments
PDF
Future Payment Trends
PDF
Mobile Payments
Achieving both GDPR Compliance and a Positive Customer Experience
Mobile payment-security-risk-and-response
Peer to-peer mobile payments
Presentation money 2.0
Mobile Payments revolution
SmartGo
BlueHornet Webinar: The Rise of the Digital Wallet - New Opportunities for Em...
Kona Corporate Profile
Mobile payments, e-money and mobile credit in Japan
Shufti Pro| Digital Identity Verification Solution
Smart card to the cloud for convenient, secured nfc payment
How we will be paying in 2020 - SPA Technical Director, Lorenzo Gaston at EPC...
Overview of Mobile Payment Systems
Mobile payment technology 8.11.2014 final
Thoughts on the Future of Payments
Sample Report: Global Mobile Payment Methods: Full Year 2015
The Future of Mobile Payments
Future Payment Trends
Mobile Payments
Ad

Similar to Lunch and Learn: Recognising the Good Guys (20)

PPTX
Gartner IAM Summit 2017 | Critical Insight: How Device Insight Drives Dynami...
PDF
[Webinar] Does that device smell fishy? Why device risk is an essential eleme...
PPTX
Critical Insight: How Device Risk Delivers Dynamic MFACharlotte 20
PPTX
Multi-factor Authentication for dummies part 2: Adaptive Risk-Based MFA
PPTX
Authentifusion: Clarifying the Future of User Authentication
PPTX
Authentifusion: Clarifying the Future of User Authentication
PPTX
Feeding the Beast-How Fraud Tools Bring Context into Authentication (Gartner ...
PPTX
Authentifusion: Clarifying the Future of Customer Authentication
PPTX
Fraud Prevention Strategies to Fight First-Party Fraud and Synthetic Identity...
PDF
Creating a Winning Experience While Battling Online Fraud
PDF
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...
PPTX
RBMovil Powered by CHARGE Anywhere: MWC
PDF
FOR THE LOVE OF MONEY: Finding and exploiting vulnerabilities in mobile point...
PDF
Losant craig baldwin cwin18_toulouse
PPTX
Identity Access Management 101
PPT
WP7 & Azure
PPTX
Wp7 geek night intro developers - saschac
PDF
A modern approach to safeguarding your ICS and SCADA systems
PDF
Risk-Based Approach to Deployment of Omnichannel Biometrics in Sberbank
PDF
2015-06-16 IT Security - What You Need to Know
Gartner IAM Summit 2017 | Critical Insight: How Device Insight Drives Dynami...
[Webinar] Does that device smell fishy? Why device risk is an essential eleme...
Critical Insight: How Device Risk Delivers Dynamic MFACharlotte 20
Multi-factor Authentication for dummies part 2: Adaptive Risk-Based MFA
Authentifusion: Clarifying the Future of User Authentication
Authentifusion: Clarifying the Future of User Authentication
Feeding the Beast-How Fraud Tools Bring Context into Authentication (Gartner ...
Authentifusion: Clarifying the Future of Customer Authentication
Fraud Prevention Strategies to Fight First-Party Fraud and Synthetic Identity...
Creating a Winning Experience While Battling Online Fraud
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...
RBMovil Powered by CHARGE Anywhere: MWC
FOR THE LOVE OF MONEY: Finding and exploiting vulnerabilities in mobile point...
Losant craig baldwin cwin18_toulouse
Identity Access Management 101
WP7 & Azure
Wp7 geek night intro developers - saschac
A modern approach to safeguarding your ICS and SCADA systems
Risk-Based Approach to Deployment of Omnichannel Biometrics in Sberbank
2015-06-16 IT Security - What You Need to Know
Ad

More from TransUnion (20)

PPTX
Leverage Gartner’s Insight for Assessing the Total Cost of Fraud in Your Paym...
PPTX
A New Imperative: Global Privacy and Data Strategies
PPTX
The Business Imperative for Identity, Trust and Data Stewardship
PPTX
2020 i gaming report webinar
PPTX
Financial services report webinar v4
PPTX
Webinar: Roll Out the VIP Path to Play
PPT
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
PPT
Combating Social Engineering and Account Takeover by a Former U.S. Cybercriminal
PPTX
How Confused.com and iovation Fight Ghost Broking
PPTX
Keeping Your Customers Happy and Safe: Authentication and Authorization Strat...
PDF
The Insurance Digital Revolution Has a Fraud Problem
PPTX
PSD2: The Advent of the New Payments Market in Europe
PPTX
How E-Commerce Providers Can Remove ATO from Their Carts
PPTX
2019 iovation Gambling Industry Report Highlights
PPTX
Nice Try, ATO: Use Customers’ Devices to Transparently Enhance Account Security
PPTX
Definitive Guide to Next-generation Fraud Prevention: Techniques for the Mobi...
PPTX
Battling Credit Write-Offs by Identifying Synthetic Identity (Gartner Report ...
PPTX
Working at the Margins: Change Agents in the Converged World (Gartner Report ...
PPTX
Gartner Offers a Converged and Compelling Future (Gartner Report Part 1)
PDF
4 GDPR Hacks to Mitigate Breach Risks Post GDPR
Leverage Gartner’s Insight for Assessing the Total Cost of Fraud in Your Paym...
A New Imperative: Global Privacy and Data Strategies
The Business Imperative for Identity, Trust and Data Stewardship
2020 i gaming report webinar
Financial services report webinar v4
Webinar: Roll Out the VIP Path to Play
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
Combating Social Engineering and Account Takeover by a Former U.S. Cybercriminal
How Confused.com and iovation Fight Ghost Broking
Keeping Your Customers Happy and Safe: Authentication and Authorization Strat...
The Insurance Digital Revolution Has a Fraud Problem
PSD2: The Advent of the New Payments Market in Europe
How E-Commerce Providers Can Remove ATO from Their Carts
2019 iovation Gambling Industry Report Highlights
Nice Try, ATO: Use Customers’ Devices to Transparently Enhance Account Security
Definitive Guide to Next-generation Fraud Prevention: Techniques for the Mobi...
Battling Credit Write-Offs by Identifying Synthetic Identity (Gartner Report ...
Working at the Margins: Change Agents in the Converged World (Gartner Report ...
Gartner Offers a Converged and Compelling Future (Gartner Report Part 1)
4 GDPR Hacks to Mitigate Breach Risks Post GDPR

Recently uploaded (20)

PDF
Design an Analysis of Algorithms I-SECS-1021-03
PPTX
Why Generative AI is the Future of Content, Code & Creativity?
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PPTX
Computer Software and OS of computer science of grade 11.pptx
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PDF
Nekopoi APK 2025 free lastest update
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
System and Network Administration Chapter 2
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
top salesforce developer skills in 2025.pdf
PPTX
assetexplorer- product-overview - presentation
Design an Analysis of Algorithms I-SECS-1021-03
Why Generative AI is the Future of Content, Code & Creativity?
Wondershare Filmora 15 Crack With Activation Key [2025
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
Design an Analysis of Algorithms II-SECS-1021-03
Computer Software and OS of computer science of grade 11.pptx
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
Nekopoi APK 2025 free lastest update
Navsoft: AI-Powered Business Solutions & Custom Software Development
System and Network Administration Chapter 2
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Operating system designcfffgfgggggggvggggggggg
How to Choose the Right IT Partner for Your Business in Malaysia
wealthsignaloriginal-com-DS-text-... (1).pdf
top salesforce developer skills in 2025.pdf
assetexplorer- product-overview - presentation

Lunch and Learn: Recognising the Good Guys

  • 1. MICHAEL THELANDER, SR DIR OF PRODUCT MARKETING U SIN G “ FR AU D PR EVEN TION ” TEC H N OLOGIES TO D ELIVER BETTER AU TH EN TIC ATION DECEMBER 2017 RECOGNISING THE GOOD GUYS
  • 2. 2
  • 3. 3 Is this a fraudster? Have we been hit by this person before? Has anyone else been fooled? What are the signals that alarm us? Is this a great customer? How can I give them a better experience? Can I stop ATO? Can authentication have less friction?
  • 4. AGENDA 4 WHAT IS DEVICE RECOGNITION? WHAT ARE THE RESULTS? CAN WE DETECT EVASION ACTIVITY? DO WE GET BETTER SECURITY?
  • 5. WHAT IS DEVICE RECOGNITION? AND WHAT CAN YOU DO WITH IT?
  • 6. 6 THE DNA OF A DEVICE HUNDREDS OF DEVICE ATTRIBUTES COMBINE TO CREATE A DIGITAL FINGERPRINT
  • 7. 7  WiFi (or Bluetooth) MAC Address  Network configuration  iOS Device Model  Battery level / AC mode  Device orientation  File system size  Physical memory  Number attached accessories  Has proximity sensor?  Screen brightness and resolution  System uptime  iOS Device Name (MD5 Hash)  OS Name and/or version  Device advertising UUID  Kernel version  iCloud Ubiquity Token  Application Vendor UUID /name/vers  Is Simulator? THE DNA OF A DEVICE HUNDREDS OF DEVICE ATTRIBUTES COMBINE TO CREATE A DIGITAL FINGERPRINT  Locale language / currency code  WiFi MAC Address  Bluetooth MAC Address  Network configuration  Is plugged in?  Device orientation  File system size  Physical memory  CPU Type  CPU count  CPU Speed  Screen brightness  Screen resolution  System uptime  iOS Device Name (MD5 Hash)  Device advertising UUID  Current latitude  Current longitude  Current altitude  Application Vendor UUID  Bundle ID  Application Version  Application name  Process name  Executable name  Application orientation  Locale language code  Locale currency code  Are location services enabled?  Time zone  Currently registered radio technology  Carrier name  Carrier ISO country code  Carrier mobile country code  Carrier mobile network code  Does carrier allow VOIP?These attributes combine to provide a unique, indisputable digital fingerprint
  • 8. 8 CLEARKEY D E V I C E - B A S E D A U T H E N T I C A T I O N F O R B E T T E R C U S T O M E R E X P E R I E N C E Machine learning compares user devices Transparent authentication eliminates friction Turns the user’s device into a possession factor Adaptive, contextual response drives subsequent authentication strategies and actions MINIMUM THRESHOLD MAXIMUM THRESHOLD Original Device Print Returning Device Print DEVICE ID IP / GEO DEVICE CONTEXTINTEGRITY REPUTATION
  • 9. Match Grant Access No Match or Risk Signals • Rooted • Jailbroken • Anomalies • Watchlist • Configuration • Emulator Account-to- Device Pairing & Risk Evaluation Persistent Session Token Login User Access Customer Access Login Device Registration SUCCESS Step-Up *** HOW CLEARKEY WORKS D E V I C E - B A S E D A U T H E N T I C A T I O N F O R B E T T E R C U S T O M E R E X P E R I E N C E ***
  • 11. 11 CLEARKEY R E G I S T E R O R “ P A I R ” T H E D E V I C E D U R I N G T H E C U S T O M E R ’ S J O U R N E Y
  • 12. 12 CLEARKEY CUSTOMER EXAMPLES M E A S U R I N G R E S U L T S Positive Match, minimal change No device associated with the account New registrations as a % A device is registered, but it’s not this one
  • 13. 13 OPTIMUM EXPERIENCE FOR ONLINE GAMING M O B I L E A P P “ O P T - I N ” U S I N G D E D I C A T E D E M A I L & E X P L A I N E R True out-of-band solution: Good experience for majority, but did require some tuning Variations in workflow and offerings required tuning, but now delivering highest recognition rate of all customers at over 95%
  • 14. 14 OPTIMUM EXPERIENCE FOR ONLINE RETAIL W E B B R O W S E R “ O P T - I N ” W I T H D E D I C AT E D P R O M P T P A G E Many users receive immediate benefit from improved experience Dedicated prompt page explained the value of registering a device, made a “don’t remember me” option available
  • 15. 15 OPTIMUM EXPERIENCE FOR ONLINE BANKING M O B I L E A P P W I T H A U T O - R E G I S T R A T I O N O N D O W N L O A D Many users benefit from improved experience within 6 months Almost 85% of users see expedited journey with no step-up authentication until a higher-risk action is taken
  • 16. 16 ON TOP OF THAT, STOP ATO A C U S T O M E R Q U O T E “With ClearKey in place we’ve virtually eliminated successful account takeovers … even though attempts are at an all-time high because of the stolen credential market.”
  • 17. CAN WE DETECT EVASION ACTIVITY? WHAT IF THEY DON’T WANT TO BE RECOGNISED?
  • 18. 18 RISK INSIGHT FROM THE USER’S DEVICE EvidenceDevice & Age Risk Profile Geo- location Anomaly Watch ListsVelocity ISP Watch List Transactions per Account Timezone / Geo Mismatch Subscriber Evidence Exists Transaction Amount Range Geolocation Mismatch Device new to Subscriber IP Address Range List Global Trans Device Velocity Device Not Provided Evidence Exists Billing/Shipping Mismatch Proxy In Use New Device, Existing Acct Email Domain List Countries Per Acct or Device Suspect Device Data IP Address RiskCountry List Age of the Association Browser Language Trans per IP/Device/Acct TOR Exit Node IP Device Risk (Local or Global) Mobile Carrier Country List Registered Acct/Dev Pair ISP Organization List $S Value per Device or Acct VM in Use Language and Country Risk IP Address Distance Device Type List Devices per Account Mobile Emulator Detected Jailbreak/Root Detected IP Address Mismatch Accts (Created) per Device ISP Mismatch POSITIVE RULES TRIGGERED EVASION RULES TRIGGERED
  • 19. 19 RISK INSIGHT FROM THE USER’S DEVICE EvidenceDevice & Age Risk Profile Geo- location Anomaly Watch ListsVelocity ISP Watch List Transactions per Account Timezone / Geo Mismatch Subscriber Evidence Exists Transaction Amount Range Geolocation Mismatch Device new to Subscriber IP Address Range List Global Trans Device Velocity Device Not Provided Evidence Exists Billing/Shipping Mismatch Proxy In Use New Device, Existing Acct Email Domain List Countries Per Acct or Device Suspect Device Data IP Address RiskCountry List Age of the Association Browser Language Trans per IP/Device/Acct TOR Exit Node IP Device Risk (Local or Global) Mobile Carrier Country List Registered Acct/Dev Pair ISP Organization List $S Value per Device or Acct VM in Use Language and Country Risk IP Address Distance Device Type List Devices per Account Mobile Emulator Detected Jailbreak/Root Detected IP Address Mismatch Accts (Created) per Device ISP Mismatch +1000POSITIVE RULES TRIGGERED EVASION RULES TRIGGERED
  • 20. 20 RISK INSIGHT FROM THE USER’S DEVICE EvidenceDevice & Age Risk Profile Geo- location Anomaly Watch ListsVelocity ISP Watch List Transactions per Account Timezone / Geo Mismatch Subscriber Evidence Exists Transaction Amount Range Geolocation Mismatch Device new to Subscriber IP Address Range List Global Trans Device Velocity Device Not Provided Evidence Exists Billing/Shipping Mismatch Proxy In Use New Device, Existing Acct Email Domain List Countries Per Acct or Device Suspect Device Data IP Address RiskCountry List Age of the Association Browser Language Trans per IP/Device/Acct TOR Exit Node IP Device Risk (Local or Global) Mobile Carrier Country List Registered Acct/Dev Pair ISP Organization List $S Value per Device or Acct VM in Use Language and Country Risk IP Address Distance Device Type List Devices per Account Mobile Emulator Detected Jailbreak/Root Detected IP Address Mismatch Accts (Created) per Device ISP Mismatch POSITIVE RULES TRIGGERED EVASION RULES TRIGGERED Watch ListsVelocity ISP Watch List Transactions per Account IP Address Range List Global Trans Device Velocity Email Domain List Countries Per Acct or Device Browser Language Trans per IP/Device/Acct ISP Organization List $S Value per Device or Acct Device Type List Devices per Account +500
  • 21. 21 RISK INSIGHT FROM THE USER’S DEVICE EvidenceDevice & Age Risk Profile Geo- location Anomaly Watch ListsVelocity ISP Watch List Transactions per Account Timezone / Geo Mismatch Subscriber Evidence Exists Transaction Amount Range Geolocation Mismatch Device new to Subscriber IP Address Range List Global Trans Device Velocity Device Not Provided Evidence Exists Billing/Shipping Mismatch Proxy In Use New Device, Existing Acct Email Domain List Countries Per Acct or Device Suspect Device Data IP Address RiskCountry List Age of the Association Browser Language Trans per IP/Device/Acct TOR Exit Node IP Device Risk (Local or Global) Mobile Carrier Country List Registered Acct/Dev Pair ISP Organization List $S Value per Device or Acct VM in Use Language and Country Risk IP Address Distance Device Type List Devices per Account Mobile Emulator Detected Jailbreak/Root Detected IP Address Mismatch Accts (Created) per Device ISP Mismatch POSITIVE RULES TRIGGERED EVASION RULES TRIGGERED Watch ListsVelocity ISP Watch List Transactions per Account IP Address Range List Global Trans Device Velocity Email Domain List Countries Per Acct or Device Browser Language Trans per IP/Device/Acct ISP Organization List $S Value per Device or Acct Device Type List Devices per Account Watch Lists ISP Watch List IP Address Range List Email Domain List Browser Language ISP Organization List Device Type List Watch Lists Device Type List -500
  • 22. 22 RISK INSIGHT FROM THE USER’S DEVICE EvidenceDevice & Age Risk Profile Geo- location Anomaly Watch ListsVelocity ISP Watch List Transactions per Account Timezone / Geo Mismatch Subscriber Evidence Exists Transaction Amount Range Geolocation Mismatch Device new to Subscriber IP Address Range List Global Trans Device Velocity Device Not Provided Evidence Exists Billing/Shipping Mismatch Proxy In Use New Device, Existing Acct Email Domain List Countries Per Acct or Device Suspect Device Data IP Address RiskCountry List Age of the Association Browser Language Trans per IP/Device/Acct TOR Exit Node IP Device Risk (Local or Global) Mobile Carrier Country List Registered Acct/Dev Pair ISP Organization List $S Value per Device or Acct VM in Use Language and Country Risk IP Address Distance Device Type List Devices per Account Mobile Emulator Detected Jailbreak/Root Detected IP Address Mismatch Accts (Created) per Device ISP Mismatch POSITIVE RULES TRIGGERED EVASION RULES TRIGGERED Watch ListsVelocity ISP Watch List Transactions per Account IP Address Range List Global Trans Device Velocity Email Domain List Countries Per Acct or Device Browser Language Trans per IP/Device/Acct ISP Organization List $S Value per Device or Acct Device Type List Devices per Account Watch Lists ISP Watch List IP Address Range List Email Domain List Browser Language ISP Organization List Device Type List -1000
  • 23. DO WE GET BETTER SECURITY? WHAT ABOUT PSD2’s SCA REQUIREMENTS?
  • 24. 24 DEFINING MULTIFACTOR AUTHENTICATION S T R O N G A N D F L E X I B L E A U T H E N T I C A T I O N Something you KNOW
  • 25. 25 DEFINING MULTIFACTOR AUTHENTICATION S T R O N G A N D F L E X I B L E A U T H E N T I C A T I O N Something you KNOW Something you ARE Identity verified
  • 26. 26 DEFINING MULTIFACTOR AUTHENTICATION S T R O N G A N D F L E X I B L E A U T H E N T I C A T I O N Something you KNOW Something you ARE Something you HAVE
  • 29. QUESTIONS ? www.iovation.com @TheOtherMichael SENIOR DIRECTOR OF PRODUCT MARKETING MICHAEL THELANDER michael.thelander@iovation.com 001.1.503.943.6700