Financial, E-commerce and Healthcare verticals are the high-value targets ATO attacks, given the sensitive data handled coupled with 24×7 online presence. SaaS applications are also very susceptible to automated attacks for the same reasons. Anthem, Sony, eBay, Adobe, and Ashley Madison have all dealt with data breaches in the recent past; certainly the trend points to more data breaches in the making. Here we will focus on a B2B SaaS application hosted by a large healthcare provider where the customers PHI/PII data is at risk from account takeover fraud. Needless to say, suffering a data breach would have a devastating impact on the business.
Digging deeper into their use case, you can see that protection against credential stuffing attacks, especially for their login/registration pages, is of utmost importance. They do have a high number of failed login attempts (>20% of the total), so the solution has to be able to distinguish between legitimate users and malicious users/bots with 100% accuracy. The healthcare provider had already ruled out endpoint protection mechanisms since there were several flaws in that approach as evidenced by the several variants of Man in the Middle Attacks- MITM, MITB, and MITC. Obfuscation-based solutions could only inspect headers and cookies and were wreaking havoc on existing downstream and upstream application optimization and security solutions.
Leave it to Imperva, “The Knight in Shining Armor”, with ThreatRadar Bot Protection and Account Takeover services to come and save the day. Account Takeover is one of the many applications of the Imperva SecureSphere ThreatRadar Solution. Imperva uses a combination of device profiling, device risk evaluation, and Web Application Firewall mitigation rules to detect and block Account Takeover. Imperva solution has many benefits:
- Proactive detection of account takeover before fraud happens
- Actionable device intelligence usable for Fraud IR
- Frictionless user experience
- Reduced workload for Security Ops
Imperva SecureSphere ThreatRadar Bot Protection solution has similar powerful applications in the Financial and Ecommerce verticals as well. In the next blog of this series, we will delve into the details (secret sauce) of how Imperva SecureSphere ThreatRadar Bot Protection works and the different inputs that drive the correlation engine.
You can also watch this youtube video about Imperva SecureSphere ThreatRadar
Try Imperva for Free
Protect your business for 30 days on Imperva.