Animation user experience

الثقة التكيفية المستمرة

دون أي مساومة بين سهولة استخدام المستخدم ومستوى الأمان

المصادقة القائمة على المخاطر: سهلة الاستخدام، ولكن هل هي غير آمنة؟

نقضي بالفعل في المتوسط ما يقارب 11 ساعة سنويًا في إدخال كلمات المرور وإعادة تعيينها. وغالبًا ما يُضاف إلى ذلك عامل مصادقة إضافي، مثل كلمة المرور لمرة واحدة . صحيح أن هذا الإجراء يعزز مستوى الأمان ويساعد على منع الاستيلاء على الحسابات، لكنه من جهة أخرى يضيف خطوة إضافية تزيد من التعقيد، كما تحاول المصادقة القائمة على المخاطر معالجة هذه الإشكالية من خلال تقليل تكرار وقوة عملية تسجيل الدخول قدر الإمكان. إلا أن هذا النهج قد يؤدي إلى تسويات خطيرة، إذ إن تقييم المخاطر يتم مرة واحدة فقط عند تسجيل الدخول، وبالتالي لا يأخذ في الحسبان سلوك المستخدم بعد إتمام عملية المصادقة

 

أصبحت المصادقة الثنائية تُتجاوز بشكل متزايد من خلال هجمات الرجل في الوسط. يتسلل المهاجمون خفيةً إلى قناة الاتصال بين المستخدم ومزود الخدمة، حيث ينتحلون صفة كل طرف أمام الآخر، ما يتيح لهم التحايل على آلية المصادقة الثنائية. وفي الغالب، يكون الضرر قد وقع بالفعل عند إدراك المستخدم لحدوث هذا الخداع. تسهم آليات تسجيل الدخول الحديثة مثل فيدو 2 في منع هذا النوع من الهجمات، إلا أنها لا تزال حتى الآن غير مدعومة على نطاق واسع

 

المصادقة ليست تصريحًا مطلقًا للوصول

.حتى لا تأتي الأمن السيبراني على حساب سهولة الاستخدام، يجب أن تتم عملية تحليل المخاطر بشكل مستمر
.يتم تحليل سلوك المستخدم بالفعل قبل التحقق من الهوية. كما تستمر عملية تقييم جميع حساسات/مستشعرات المخاطر المتاحة حتى بعد إتمام المصادقة

.في حال الاشتباه بوجود بوت، قد يُطلب عامل أمني إضافي أو حل اختبار كابتشا
.وعند وجود حالة اشتباه مؤكدة، يتم تسجيل خروج المستخدم أو حتى حظر الحساب بالكامل

.ذلك لأن نجاح عملية تسجيل الدخول لا يجب أن يُعد تصريحًا مطلقًا أو إذنًا غير مقيّد

حاجز دخول متعدد المستويات بفضل طبقات أمنية متعددة

.ليست جميع البيانات والتطبيقات متساوية في متطلبات الأمان. وحتى داخل التطبيق الواحد، قد توجد مناطق ووظائف متفاوتة من حيث درجة الحساسية
.من خلال تقسيم مستويات الأمان إلى عدة طبقات، يتم ضمان توفير القدر اللازم فقط من الحماية في كل مرحلة

.يتم الوصول إلى المناطق الحساسة في الغالب نادرًا أو ليس في بداية الاستخدام، مما يتيح تأجيل المصادقة القوية أو الاستغناء عنها كليًا في المراحل الأولى
.وبذلك تبقى عتبة الدخول منخفضة، ولا يضطر المستخدمون إلى إضاعة وقت إضافي في إجراءات ومتطلبات الأمان

الراحة والأمان

مع الثقة التكيفية المستمرة

تعني الثقة التكيفية المستمرة مستوى أعلى من الأمان، مع تقليل التفاعلات المرهِقة في الوقت نفسه وبفضل التحليل المستمر للمخاطر يمكن تعزيز الأمن ليعمل بشكل أكبر في الخلفية دون التأثير على تجربة المستخدم

Risk sensors and trust providers

Continuous risk assessment requires a stream of risk and trust signals from different sources:

  • User identity: Is the user still anonymous? Has he already been weakly or strongly authenticated? Has his identity been verified, e.g. by badge check?
  • Access context: Is the access from a known device? At the usual time? Where is the user located? Is the device up-to-date with the latest software? Or is it even infected with malware? To ensure that compromised systems do not cause any damage on the server side, their access should be prevented at an early stage.
  • Reputation analysis: Unwanted clients from suspicious IP addresses, botnets or TOR addresses are quickly detected and blocked. For this purpose, Airlock relies on the BrightCloud® Threat Intelligence Service from Webroot®.
  • Anomaly detection: Suspicious user behaviour is detected using machine learning. Airlock Anomaly Shield can block automated attack tools, vulnerability scanners or bots, for example.

Thanks to the high level of usability with the new central security infrastructure, we have created a unique Raiffeisen identity for our customers. Customer focus and trustworthiness have top priority in our e-banking solution. With the Airlock Suite, we were able to meet these high requirements.

Stevan Dronjak, Team Lead Web Application Security Raiffeisen Schweiz

Read reference story

Cooperation between IAM and WAAP

Continuous risk analysis is only possible by constantly inspecting all data traffic. A WAAP solution such as Airlock Gateway is therefore the ideal component to orchestrate the various risk sensors. Depending on the risk signal, the trust level is lowered accordingly. The IAM, on the other hand, is an ideal trust provider. It ensures that the minimum security level is respected, which depends on the risk appetite of the respective application or function. If the current trust level is below this threshold, the IAM requests a proof of trust from the user: This can be, for example, a login or the entry of an additional authentication factor.

Minimum risk with maximum convenience

For combining security and user convenience, IAM and WAAP work together. This is the success formula of Airlock Secure Access Hub: Airlock IAM and Airlock Gateway jointly ensure that the trust level is always above the required security threshold. Communication between Gateway and IAM takes place via Airlock Control API.

Gartner calls this principle Continuous Adaptive Trust (CAT) 3).

MFA can reduce identity-related risks, but a naïve focus on counting authentication factors can diminish efficacy and add user friction. IAM-focused security and risk management leaders should move analytics to the fore to enable continuous adaptive trust and thus optimize risk mitigation and UX.

With CAT, the security mechanisms can stay in the background, which means that user experience is not compromised. This creates trust, because users and customers are not annoyed by tedious security interactions and feel more secure at the same time.

Ready for excellent IT security?

Contact us now.
Ergon Informatik AG0041442688700 Ergon Informatik AG