RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2

Scoring system for assessment of security of the cryptocurrency exchanges

Product
Developers: Group-IB (Group of information security), CryptoIns
Date of the premiere of the system: 2018/11/06
Branches: Internet services,  Insurance
Technology: Cybersecurity - Information loss preventions,  cybersecurity - the Fraud detection system (fraud)

Content

2018: Announcement

The Russian firm Group-IB and the Swiss insurance company Aspis which possesses the CryptoIns project announced on November 6, 2018 creation of the international scoring system which will allow to estimate reliability of the cryptocurrency exchanges in terms of cyber security.

The scoring model of assessment of cyber security of the cryptoexchanges allows to perform the insurance program of means of clients

The cryptoexchanges regularly suffer from cyber attacks from which damage is already very high. During 2017 and the first three quarters 2018 the cumulative damage of the exchanges from cyber attacks, under calculations of experts of Group-IB, was not less than $877 million. At least 13 cryptoexchanges underwent direct cracking, however hackers quite often attack also end users that also results in damage to the exchanges. In 2016-2017 the number of similar incidents grew more than three times. In no small measure it is connected with rapid growth of cost of cryptocurrencies during this period.

Lack of reliability and safety of storage of cryptocurrency assets and their transfers — the key factor which is frightening off the corporate investors who are engaged in management of cryptoassets. Group-IB considers that, as of November, 2018, the industry has no opportunities effectively to protect assets of clients from hackers and swindlers.

File:Aquote1.png
In these circumstances insurance of cryptocurrency assets at the cryptoexchanges is a good method to be protected from risks about which the most part of users have no concept — Andrey Busargin, the director of division of protection of brands in Group-IB said. — Certainly, to create an insurance product, it is necessary to attract the independent experts specializing in fight against cyberthreats and having access to unique data sources for assessment of security of the cryptocurrency exchanges. Those exchanges which cooperate with Group-IB help us to create more detailed model of cyber security which, eventually, will help to increase their own security and to attract new clients.
File:Aquote2.png

Carries out the assessment of security of the Group-IB cryptoexchanges by a number of criteria, including on the level of technical security, reliability of storage of keys, passwords and personal data of clients. Group-IB also estimates infrastructure and architecture to define methods of opposition to potential threats. Public data from open sources — the presentations, information on creators, public security policy form the basis. Sometimes, with the consent of founders of the exchange, assessment of security includes penetration tests using methods of social engineering: in this case experts of Group-IB try to make a compromise of network through the most vulnerable link in any organization — people.

Also the quality of risk management systems, independent ratings and existence of identification procedures of clients and anti-money laundering is estimated.

Group-IB also creates the card of incidents for each exchange which shows all history of the attacks, including fraudulent, attempts to compromise users or investors, etc.

In turn, scoring of CryptoIns includes assessment of turnovers, activities of traders, the internal commissions and other characteristics. On the basis of these data of the exchange about four risk groups, on degree threat increase will be sorted. Insurance services will not be provided to users of the exchanges which got into the fourth group.

According to the same classification also the sizes of the commission of the insurer will be defined. It will average 1.9%, at the same time the upper limit will make 15 bitcoins (or the equivalent amount in other cryptocurrencies). Validity period of the insurance contract will make or 90 or 365 days, with a possibility of prolongation.

File:Aquote1.png
Formulation of the question, in principle, indicates "growing" of the market of cryptocurrencies — Mikhail Zaytsev, the information security expert of SEC Consult Services company believes. — Demand for the scoring for the cryptoexchanges and considering both financial aspect, and a question of cyber security in general means that investors believe that the cryptocurrency industry can become not only a speculative, but also strategic source of income. But at first for this purpose it is necessary to separate grains from a ryegrass — i.e., to define what exchanges can be considered reliable and what it is impossible.
File:Aquote2.png

Analysts of CryptoIns believe that by 2023 the universal market of insurance of cryptocurrency assets will be estimated by $7 billion[1]

You look also the Blockchain and cryptocurrency



Notes