December 4, 2017 By Mark Samuels 2 min read

IT decision-makers need to evolve beyond two-factor authentication (2FA) and design new ways to make the user verification process intelligent and risk-aware.

In an article for Harvard Business Review, Sridhar Muppidi, chief technology officer for identity and access management solutions at IBM Security Systems, noted that while existing 2FA systems provide some protection against cyber risks, they are not a panacea. Instead, he suggested that users explore a mixture of push notifications and advanced technologies to verify identities.

Attackers Exploit Two-Factor Authentication

Compared to a single-factor authentication method, such as a password used in isolation, 2FA relies on a second input to assure the system that an individual is authenticated to access a service. Muppidi noted that these one-time passwords are often the first line of defense for companies looking to boost security.

However, single-use passwords can be vulnerable to attack. Muppidi reported that cybercriminals have identified a vulnerability in the method phones used to authenticate identities. They are exploiting this vulnerability to steal valuable data and resources, including cryptocurrencies.

There is also a growing number of cases in which attackers contact mobile network providers and ask to transfer control of a victim’s number to a device under their control, reported The New York Times. Attackers can then receive SMS notifications intended for users, and use this information to reset and access online accounts.

Pursuing Alternative Authentication

Muppidi advised organizations looking to strengthen their authentication methods to tie the push notifications used in a 2FA system to the device rather than to the phone number. Specialist software tools, such as security applications with mobile authentication, can provide assurance in this area.

Smarter management of SMS push notifications is just the first step toward more effective authentication. IT decision-makers must consider modern solutions that include identity access and management technologies controlling access to resources.

Multifactor authentication (MFA) allows enterprises to use a range of techniques to authenticate users and identify where applications flag unexpected activity. Behavioral analytics can complement this approach, and allow IT teams to change security levels based on the value of data and the risks presented.

Improving Verification Methods

The development of verification techniques continues. For example, researchers at Florida International University and Bloomberg have generated a new 2FA system that works by prompting the user to take a picture of a personal object. The system, known as Pixie, could offer a more convenient and secure alternative to traditional authentication processes.

While waiting for these new advancements to come, Muppidi advised companies to establish a layered and risk-based defense. Enterprises should pursue a multifactor approach by using systems and analytics in combination to handle security concerns and combat risks. Additionally, IT decision-makers need to ensure that more of their information security budget is directed toward key prevention and detection techniques, such as behavioral analytics.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today