Showing posts with label Auditing. Show all posts
Showing posts with label Auditing. Show all posts

Auditing E-Commerce Web Sites

Auditing E-Commerce Web Sites

Using the Internet for E-commerce is not an obscure concept; it is a matter of good business sense. However, if retail organizations ignore the malicious abilities of attackers, they are selling themselves short. There are dozens of Web sites, and an equal number of news groups and chat rooms, dedicated to verifying stolen credit card information so they can use it to commit fraud or sell it to someone else who would commit fraud in the future.

There are a number of entities involved in online credit card transactions:

  • Credit card holder. The person or organization to which a credit card has been issued.

  • Issuing financial institution. The financial institution that issues the credit card to the credit card holder, also known as the "issuer."

  • Acquiring financial institution. This institution contracts with merchants to accept and process their credit card transactions. It is possible for acquirers to contract with third-party processors to provide these services. Acquiring financial institutions are also known as "merchant banks" and the organizations' accounts are known as "merchant accounts."

  • Payment gateway. This is a service allowing an E-commerce merchant to connect to the acquirer or its merchant processor to complete a credit card transaction in real-time.

  • Service provider. Includes any third-party support entity, e.g., shopping carts, Web servers, payment processors, fulfillment houses, etc. This term is also used to describe a payment gateway alliance.

Of course, online credit card transactions not only include the entities above, but they also include three essential processing actions:

  1. Authorization. This action takes place at the time a credit card transaction occurs. It is the process by which an issuer approves, or declines, a credit card transaction.

  2. Authentication. This process involves the verification of the cardholder and the credit card. At the time of authorization, the E-commerce merchant should use fraud prevention controls and tools to validate the credit cardholder's identity and the credit card being used to make a purchase.

  3. Settlement. When a product has been purchased by a cardholder, the E-commerce merchant can initiate the settlement of a transaction through an acquirer and initiate the transfer of funds from the issuer to the merchant account.

This is an example of a real-time processing for an online credit card transaction. It is not as complicated as many people think. Processing events may vary slightly depending on the acquirer relationship, business requirements, and systems used, but they generally follow the credit card authorization process:

  • The cardholder orders items from an E-commerce merchant by entering the credit card number, identifying information, and any shipping information.

  • The information transmission is transmitted through the Internet to the merchant server. The payment gateway receives the information from the merchant server; the information is formatted, and transmitted to the acquirer.

  • The acquirer electronically sends the authorization to the issuer, who approves or declines the transaction.

Credit Card Authentication

It is the responsibility of the E-commerce merchant to apply tools and controls in verifying the cardholder's identity and validity of the transaction and avoid fraud. These are a few generally accepted tools and controls in avoiding fraud:

  • Address Verification Service (AVS). This service allows the E-commerce merchant to check a cardholder's billing address with the issuer. AVS provides online merchants with a key indicator verifying whether the transaction is valid or not.

  • Credit Card Verification Value 2 (CVV2). This is a three digit number printed on the signature panel of the credit card helping to validate that a customer has a genuine card in her possession and that the credit card account is valid. CVV2 numbers are present on most major credit cards.

  • Advanced fraud screens. These fraud-detection services examine the transactions generated by online E-commerce sites. These services calculate in realtime the level of risk associated with each transaction and provide the merchant with risk scores. These scores permit merchants to identify potentially fraudulent orders and behavior patterns.

Settlement

This process is the operation by which money flows from the issuer to the acquirer. Once the goods or services have been delivered, the E-commerce merchant captures and batches the related transactions for settlement. The batch is electronically submitted to the various acquirers for processing.

The acquirer electronically submits the transaction to issuer for payment. The issuer transmits the payment to the acquirer who credits the E-commerce merchant's account.

Chargeback Issues

With literally millions of credit card transactions, it is inevitable that there will be chargebacks. Chargebacks are transactions that are returned to the acquirer, to the issuer, then to the merchant. There are many reasons for chargebacks:

  • Customer disputed transactions

  • Fraud

  • Authorization issues

  • Inaccurate or incomplete transaction information

  • Transaction processing errors

The majority of chargebacks are initiated when the cardholder reviews her bank statement and notifies the issuer that there is a problem with a transaction. When this happens, the issuer usually requests an explanation of the problem from the card-holder. If the issuer determines there is a basis for a chargeback, then the matter is referred to the acquirer who debits the merchant's account. It is generally the responsibility of the merchant to resolve the chargeback.

Audit Program Items

E-commerce merchants must take all possible steps to reduce and treat risk. Auditors can play a significant role in this arena and should include audit program items that tip the scales in the E-commerce merchant's favor.

  • Record all key elements of fraudulent transactions, names, addresses, shipping addresses, e-mail, credit card numbers, and items purchased. Auditors should verify the existence and currency of a database containing this information.

  • Document that all fraud database items are used for comparison before any transactions are processed by the merchant.

  • Establish internal transaction controls to identify high-risk transactions prior to authorization. These controls should include:

    • Setting review limits based on the number and dollar amount of transactions approved within a specified number of days. Adjust these limits to fit prior cardholder purchasing patterns.

    • Setting review limits based on a single transaction amount.

    • Ensuring that velocity limits, frequency by which the credit card number and associated information, are checked across multiple characteristics, including shipping address, telephone number, and e-mail address. The term "velocity" in this context is degree of frequency that a credit card is used at an E-commerce Web site. It can also mean the number, within a given time period, that credit cards are submitted from a single IP address. Is there a mechanism prescribed by policy that requires contact with customers who exceed these control limits in an effort to determine whether the cardholder's activity is authorized and legitimate?

  • In the Web server interface, does it require the cardholder to input the card type, e.g., MasterCard, American Express, etc.? Does it also require the customer to input the card number and CVV2? Does the merchant's Web site verify that the card type and numerical sequence identifying the card type coincide?

  • Does the merchant's Web site require the cardholder to enter the card's expiration date and is there a mechanism to verify that the credit card number, name imprinted on it, and the expiration date coincide?

  • Does the merchant's Web site require a customer to enter a legitimate e-mail address?

  • Does the merchant's Web site require a customer to enter a legitimate CVV2 number and are these numbers verified with the credit card's other pertinent information?

  • Has the merchant implemented AVS verification?

Implementing Fraud Screening to Identify High-Risk Transactions

In the E-commerce world, the greatest risk is that of fraud committed by customers. There are a variety of tools and techniques that will help identify and deal with online fraud.

  • Implement fraud screening tools to identify high-risk credit card transactions. This can include online transactions:

    • Matching credit card data stored in the organization's internal negative files.

    • Exceed velocity limits and internal controls.

    • Identify the persons, potential credit card attackers, who are submitting Authorize-Only transactions that are never captured or settled.

    • Identify the persons, potential credit card attackers, who are submitting transactions of low amounts, less than $5, to a Web site in an attempt to merely verify the credit card number and cardholder's information.

    • Notification of an AVS mismatch.

  • Develop and implement an effective manual transaction review procedure to investigate high-risk credit card transactions. The purpose of this activity is to significantly reduce online fraud as a percentage of revenue, thereby minimizing the impact on legitimate sales.

  • Treat anonymous e-mail addresses as high-risk. It is important to note that many online merchants have discovered that anonymous e-mail addresses have a substantially higher fraud rate than e-mail accounts with well-known Internet Service Providers. Organizations should take more steps requiring these types of e-mail addresses to pass additional verification requirements before permitting them to transact online credit card business.

  • Identify and screen high-risk shipping addresses. Fraud can be reduced by comparing the client's shipping address to high-risk shipping in third-party databases and in the organization's own negative files. Of particular note is the shipping address located in a different mail-code than the billing address's mail-code. Particular attention should be paid to mail drops, prisons (of particular note in a prison address is the inclusion of the inmate number), hospitals, and addresses of known fraudulent activity.

  • Organizations should develop and implement policies and procedures addressing shipping addresses different from the billing address.

  • Organizations should treat addresses outside the merchant's country as being high-risk. Transactions involving cards issued outside the merchant's country of origin and having foreign shipping and billing addresses should be regarded as high-risk. Organizations must be careful the AVS will not likely be useful in such cases. Organizations should require higher transaction scrutiny and customer verification for international online transactions. Controls should be enforced regarding transaction velocity thresholds for these transactions. Internal policies and procedures must address cases where there is not third-party AVS available, where billing and shipping addresses differ, and the client uses an anonymous e-mail address.

  • Organizations must assess risks based on the purchase of merchandise that is easily remarketed, for example electronic products or jewelry.

  • Organizations should have a policy regarding contacting the credit card issuer to confirm cardholder's information prior to shipping goods related to a high-risk transaction.

Signs of Possible Online Credit Card Fraud

These are some of the possible indicators that attackers are attempting to commit fraud at the E-commerce Web site. Organizations need to be mindful of these signs and take appropriate steps to avoid becoming a victim of fraud. Auditors should include these signs as being addressed by the organization's policies and procedures in their audit programs.

  • Multiple credit cards being used from a single IP address. Multiple (more than two) cards are a good indication a fraud scheme is afoot.

  • Orders consisting of several of the same item. Having multiples of the same item increases the fraudster's chances of success.

  • Orders composed of "big-ticket" items with rushed shipping. These are usually items identified as having maximum resale value with little regard for shipping costs increasing the profit potential for the criminal.

  • Orders shipped to a single receiving address but purchased on multiple cards. These transactions could also be characteristic of account numbers generated by special software or stolen.

  • Multiple transactions on one card or similar cards with a single billing address or a single card with multiple shipping addresses. This activity represents an organized fraudulent activity rather than one individual at work.

If an online transaction is approved by the credit card issuer, the organization should consider sending a confirming e-mail to the customer before completing and sending the order. If the transaction is declined, the organization should have policies and procedures that specify the means by which the organization handles such transaction declinations.

Auditors should review the method by which the company handles declined transactions. Consideration should be given to having customer service employees review online transaction authorizations declined by issuers and obtain corrected information or an alternate payment that allows the organization to safely proceed. These employees must be mindful of transactions containing incorrect card expiration dates, incorrect billing addresses, incorrect name spelling, incorrect mailing addresses, or incorrect CVV2 information. Incorrect information should be retained as part of the organization's negative information database that is used for comparison with future transaction attempts.

Attackers can gain access to a business' online Web site through shopping carts or payment gateway processor systems. Attackers are also very adept at finding security holes in weak or default passwords. With an attacker invading an E-commerce site, it is possible for the attacker to emulate the merchant and begin processing debits and credits without the merchant's knowledge. It is a fraudulent practice for attackers to offset the deposit credits with debits, thereby attempting to avoid detection by deposit-volume monitoring by the true merchant's bank.

Here is a short checklist for merchants to monitor online authorizations and transactions:

  • On a daily basis, organizations must review their transaction logs for Authorize-only transactions and small amount transactions (less than $5). An unusually high number will likely indicate attackers testing the merchant's system.

  • On a daily basis, organizations must review their transactions for an unusually high amount or volume of credits. This could indicate fraud.

  • On a daily basis, organizations must review their transactions for identical transaction amounts.

  • On a daily basis, organizations must review their transactions for multiple transactions from a single IP address.

  • Organizations must thoroughly review their online transactions before they are settled. This affords the opportunity to void potentially fraudulent or erroneous transactions before they are submitted for settlement.

  • All pertinent passwords must be at least ten characters in length, with a combination of special characters, numbers, and capital letters. These passwords must be changed at least every 30 days or less.

  • All credit card numbers and related cardholder information must be stored on a secure server inside a guarded interior system and away from the DMZ where the Web site is located.

Auditing Wireless Networks: Who Is Listening to My Network Traffic?

In today's business environment, the installation of wireless networks has taken a center-stage position. Wireless permits an organization to use networked devices in locations where Cat 5 cable is not available.

The Institute of Electrical and Electronics Engineers (IEEE, www.ieee.org) has taken a lead position in the creation and development of wireless networking protocols. In 1990, IEEE established the 802.11 working group. One of their goals was the creation of a wireless local area network (WLAN) standard. The standard specified an operating frequency in the 2.4 GHz band that had been specified for industrial, scientific, and medical use. Seven years later, in 1997, the IEEE adopted the first WLAN standard with data rates of 1 Mbps and 2 Mbps. In 1999, the working group approved two extensions to the 802.11 protocol. The first, 802.11a, operates in the Unlicensed National Information Infrastructure band of 5 GHz with a transfer rate of 54 Mbps. This standard protocol only allowed clients within 40 to 50 feet, due to power restrictions enforced by the Federal Communications Commission (FCC). The second adopted standard is one of the more popular WLAN protocols, 802.11b. This protocol operates on the 2.4 GHz band with operating distances sometimes exceeding 1000 feet and has speeds near 11 Mbps. It is the 802.11b standard known popularly as "Wi-Fi," Wireless Fidelity.

Basic Wi-Fi Architecture

One basic workstation to other compatible client is known as the independent basic service. It provides peer-to-peer communication links between two or more wireless devices with the use of an Access Point, AP, device. In other words, the devices connected via the wireless links are known as "cells" and generally do not have any outside connections other than their connections to each other. This connection structure is known as "Ad hoc." For example, three laptops are connected via their 802.11b wireless network interface cards. In this fashion, they may transact their business through this rudimentary peer-to-peer wireless network.


Experience Note

Peer-to-peer wireless networking is the default setting for most wireless network cards.

The most common WLAN infrastructure is known as the "basic service set" where an access point (AP) and at least one wireless client are required. The AP is a device that acts as a router connecting networks, and the wireless client acts in a similar fashion to a Network Interface Card for the client device. APs are relatively small hardware devices that require very little technical knowledge and time to install. In most cases, APs can be purchased for less than $200. Wireless clients are easily installed in desktops and laptops and frequently cost less than $100. In most WLAN architectures, the AP is the connection point between the LAN and the Internet or other open-ended network, while the wireless clients are installed in workstations and mobile systems.

Connections between the AP and its clients are initiated with the proper Service Set Identifier, SSID. Basically, the SSID is the name the owner gives the WLAN network. It is supposed to provide a logical separation between the AP and its clients. In theory, clients must have been configured with the same SSID as the AP in order to connect. It is important to remember that APs act in very similar fashion to routers, and the wireless clients act in similar fashion to NIC cards.


Experience Note

It is possible for wireless clients to be placed in a promiscuous mode by placing the word "any" or leaving the configuration blank in the client's SSID configuration. In essence, this configuration will sniff the air for WLANs and possibly connect if the network does not have any other security features. Some APs are configured to broadcast their SSIDs to any receiving wireless clients. In this fashion, the wireless client connects to the sending AP without being required to know the SSID beforehand.

Most WLANs have the ability to be configured for Wired Equivalence Protection, WEP. This is an encryption method between the AP and clients. Due to flaws in WEP, it is possible for attackers to record a significant amount of the encrypted traffic between AP and clients, deduce the encryption, and decipher the traffic. This attack requires a significant amount of recorded traffic and specialized software. Regardless, successfully attacking a wireless network, featuring WEP, can be done by tenacious persons. It is simply a matter of patience and skill.


Experience Note

Any traffic that is encrypted is better than clear text traffic. If a wireless network is passing traffic of a sensitive nature, the traffic should be passed over a Virtual Privacy Network, VPN, ensuring privacy and authentication. Many manufacturers are offering APs supporting VPN technology at inexpensive prices.

802.11b Information Packet Types

Beacon packets are typically transmitted continually by APs. These packets contain the SSID, maximum transfer rate, and MAC address of the AP. Generally, APs send from six to ten beacon packets every second. Probe packets are sent by clients to APs while attempting to join a network. Probe packets request the SSID of the network it wishes to join. If an AP permits the client to associate with the target network, the AP responds with a response containing the SSID. Data packets are simply TCP/IP encapsulations of the data being exchanged between the client and the AP. Ad hoc packets are similar to beacon packets, except they are exchanged client card to client card instead of through an AP.

Wi-Fi Network Detection

Active detection is the condition where the client transmits probe packet requests and listens for responses to them. This is the process followed by Netstumbler (www.netstumbler.com). Active detection requires the wireless client to be located within the radio frequency range of the AP to exchange traffic with the target network.

Passive detection is the process where the client merely listens to all detectable traffic in the air and extracts pertinent information from the intercepted packets. The client needs to be within the useable range of the AP to detect the packets. Passive detection cannot locate an AP that is not broadcasting. The wireless sniffer application, Airsnort, available at airsnort.shmoo.com, uses this listening detection method. If an attacker uses the passive detection method, it is virtually impossible to detect an attacker monitoring the target network.

802.11b Headers

Wireless network headers contain the most basic packet information: the MAC of the transmitting source, destination, SSID, WEP information, supported transfer rates, the channel, and the direction of the communication. It is important for auditors to note that WEP only encrypts the data packets. Packets in the link-layer such as beaconing, probes, etc., are not encrypted. They are exchanged in clear text.

WEP

WEP effectiveness is determined by its key-length, the number of flawed systems generating packet traffic, and the traffic levels on the network. If there are no systems generating data traffic, then attackers are not going to have the opportunity to capture weak keys. WEP has the flaw of being a shared secret key encryption method. Once the system's key is compromised, all systems must be updated with a new WEP key. The new key must be of a greater length or the newly generated and shared key will have the same weaknesses as the compromised key. Compromised keys may result from attackers, former employees, or lost systems.

Cloaking SSIDs

Currently, there are many manufacturers that have the feature of blanking the SSID from the beacon packets. Unless the client knows the correct SSID, it cannot associate with the AP and join the network. However, this protection is possibly transparent as a client joining the network, the AP sends its SSID to the client in the clear. This becomes important in that every time a client exchanges traffic with an AP, the SSID is broadcast in clear text. Legitimate users actually facilitate the AP sending the SSID. Attackers can force an AP to disclose its SSID by attacking it with jamming transmissions and as the clients attempt to rejoin the network, there is an exchange of the SSID in cleartext. Jamming consists of any strong 2.4 GHz transmitter.

Some manufacturers attempt to protect APs by disabling their beaconing ability. This is not a panacea either, such as cloaking the SSID is disclosed as users join the network. Auditors should remember that APs not transmitting the SSID and having their beaconing disabled are merely steps toward system security. Like WEP, they are not the only steps.

Wi-Fi Audit Program Features

Signal strength is one of the features of WLANs that permits attackers to gain a foothold in your system. Walls, doors, glass, and other types of building construction will not provide sufficient containment of the wireless signal. The AP placed inside a typical office can transmit a signal anywhere up to 1000+ feet. In many settings, a signal broadcast in any direction will place it in a neighboring office, road, or parking lot. Vertical signal reception must also be considered in that offices located above and beneath should be factors when selecting a location for the AP. Attackers have been known to engage in a practice known as "war driving," in which they spend their time driving from location to location equipped with a laptop, wireless client, and specialized software in search of unsecured Wi-Fi networks. Some attackers have gone as far as integrating their war-driving network interceptions with GPS and have created maps where wireless networks and their corresponding SSIDs are listed. Several Internet Web sites are dedicated to showing the location and SSIDs of unsecured networks. Of particular interest to attackers are those unprotected wireless networks located in business conference rooms. Software designed to locate unprotected wireless networks is available from www.netstumbler.com.

Many wireless network administrators feel that configuring their networks to recognize specific Network Interface Cards in the form of their individual MAC, Media Access Control, addresses is a measure that goes a long way to securing their networks from unauthorized intruders. MACs are individually significant digital addresses assigned to NICs. MACs identify the specific component and theoretically belong only to that component and none other in the world.

So, if an administrator configures her system to accept only specific MACs, then all others should not be permitted access. In this fashion, MAC filtering provides a significant degree of wireless network security. It is important to remember that there are software utilities that allow attackers to spoof their MAC addresses, however considering the large number of possible digital MAC combinations, there are a hundred million combinations, and the probability of guessing a MAC address is practically impossible. So if an intruder successfully spoofed an authorized MAC address, the intruder has had access to an authorized piece of equipment or has successfully intercepted an authorized MAC that was broadcast in the clear without being encrypted such as a VPN. Having an accurate inventory of equipment and accompanying identifying numbers, such as the MAC, can provide some avenue as to how the MAC was compromised.

Features associated with Wired Equivalent Privacy (WEP) have given wireless administrators and senior managers a false sense of security. In short, it is possible to break WEP contingent on the tenacity, and luck, of the attacker. Even when WEP is properly deployed on a wireless network, it is possible to break the encryption and gain access to the AP. It is important to know that WEP encryption keys are static and configured manually.

WEP protocol requires the same secret key to be shared by all wireless clients within the cell. The flaws are highlighted in the manner that WEP uses Initialization Vectors, IV, in establishing the encrypted link between the AP and the authorized clients. If a determined attacker intercepts a sufficient amount of wireless traffic, he can penetrate the wireless network's WEP and gain access using available software. [12]

Beyond the idea of restricted MACs and WEP deployment, the only viable solution of private and authorized system traffic is the deployment of a Virtual Privacy Network, VPN. This is not without its issues, but it is a means of allowing only authorized clients to use the system's facilities and provides an encrypted tunnel between clients and other system components. The following factors determine whether it is worth the trouble to deploy a VPN system:

  • What is the sensitivity of the traffic this system is going to be seeing?

  • What is the importance of privacy?

  • Is it important for my wireless network to eliminate unauthorized users?

  • Is my wireless network connected to other sensitive system components? What are the risks if an attacker gained access, through the wireless network, to other network elements?


Experience Note

Recently, an auditor saw a financial processing sub-network that was separated from the organization's other internal network by a firewall. None of the workstations in the financial unit was allowed Internet access as an added precaution due to the perceived sensitivity of the unit's work. Many employees complained they were being treated poorly, so their organization established a wireless network with separate Internet workstations on each employee's desk allowing them to use the Internet for official purposes. This wireless network was not connected to any internal network and only serviced the employee's Internet needs.

Wireless Denial-of-Service Attacks

Wi-Fi networks can become victims to denial-of-service attacks in the same fashion as wired networks. They have some of their own issues distinct from conventionally wired systems.

  • Users with malicious intent can configure a wireless client to transmit thousands of connection requests to an AP eventually leading to a complete shutdown of the AP. This makes a strong auditor argument for system logging and having the MACs assigned to specific machines with accurate inventories.

  • Extraneous radio frequency (RF) generation can result in Wi-Fi jamming from sources such as an arc-welder. Having an AP that cannot receive the transmissions of its assigned clients due to powerful RF jamming from a nearby construction project or body and fender repair shop will not receive intended traffic.

  • In wireless systems, it is possible to reach a saturation of RF devices. This is true in 802.11b, 802.11a, 802.11g, and Bluetooth systems. In essence, there are more users than the system can handle.

Auditor Considerations for Wireless Networks

Wireless networks have a different set of system security countermeasures than hardwire systems do. These are some audit program features that may be worth incorporating:

  • APs should have the correct antenna configuration.

  • If the system has the ability to attenuate the signal strength, has the broadcast signal strength been reduced sufficiently to cover the intended area and no more?

  • Turn off the SSID broadcasting at the AP. If this is not possible, consider using another vendor if restricting unauthorized users is a primary consideration.

  • What SSID naming convention was used? SSIDs should not disclose any useful information about the wireless system, for example: Finanzoffice, HRMail, or BWINET.

  • What is the level of security dependence on the client's MAC as an access authenticator? Wireless systems must not solely depend on MAC layer filters as their only security measure. This is one of those steps that should be part of the whole system authentication process. Remember that MACs can be spoofed.

  • Does the target system have an Intrusion Detection System, IDS, configured to alert administrators in the event an excessive amount of ARP, Address Resolution Protocol, replies are detected on the system? Remember that ARP associates MAC with IP addresses.

  • Is the system configured with software tools that will provide notification when IP to MAC bindings change. One such tool is called Arpwatch and is available at www.nrg.ee.lbl.gov.

  • Has a VPN solution been effectively implemented between the target system and the clients? Use a third party VPN solution to connect the clients to a single AP with each use being routed to the appropriate VPN endpoint in the organization's network.

  • Are there multiple APs to access different segments of the system, each with a unique SSID?

  • Does the organization's current policy prohibit the installation of APs and other hardware/software without prior written approval of the information security officer?

  • Are all APs logically located outside the organization's perimeter firewall?

  • Are all unused internal switch ports disabled?

  • Is there a systemwide mechanism to monitor any new MAC addresses on the organization's internal system? How effective is this monitoring?

Popular Posts