Customers: PJSC Rosbank
Contractors: Group-IB Group of information security Product: Group-IB Fraud Hunting Platform (ранее Secure Bank - Secure Portal)Second product: Group-IB TDS (Threat Detection Service) Project date: 2016/01 - 2019/11
|
2019: Integration of Anti-Malware-on-client technologies with the system of the behavioural analysis Secure Bank
On December 19, 2019 the Group-IB company announced cooperation with Rosbank.
Use of digital technologies is one of crucial elements of strategy of bank therefore Rosbank on a permanent basis improves an antifraud circuit, including taking into account growth of the fraud connected with social engineering concerning clients of banks.
According to Group-IB, fraud using acceptances of social engineering wins first place on extent of distribution of threat for clients of banks in Russia. First of all, it is about phone calls. At the same time, as note in Rosbank, the proportion by the number of the attacks on legal entities and physical person since the beginning of 2019 shows overweight for benefit of the last: if in 2018 35% of fraudulent activity were the share of retail clients, then for 2019 this indicator grew to 65%.
In 2019 we reached partnership with Group-IB company other level. In Rosbank for all clients the Secure Bank technology which allowed to increase significantly system effectiveness of counteraction to fraud at the expense of the analysis of client devices and a customer behavior during the work with the system of the remote banking (RB) is successfully implemented. Secure Bank showed the high speed and quality of identification of suspicious activity in RBS channels at an early stage. It allowed us to lower load of the transaction systems of an antifraud, and, above all, – to considerably expand possibilities for the analysis and prevention of the potential attacks, comments Mikhail Ivanov, the director of the department of information security of Rosbank
|
Integration Anti-Malware-on-client technologies with the system of the behavioural analysis Secure Bank allows to reveal and block the fraudulent attacks using acceptances of social engineering, to detect existence of remote control, harmful software on the user device and also a web injection or application of the stolen accounting data. Based on technologies machine learning, the graph analysis of communications, cross-channel analytics, Secure Bank provides a comprehensive protection of the digital identity of the user and his online sessions with bank. For December, 2019 all pilot tests of Group-IB Secure Bank are successfully complete: a system is implemented in commercial operation for protection of clients – both physical, and legal entities.
Besides, Rosbank uses more than two years Group-IB Brand Protection service which allows to reveal attacks on a brand and also phishing the websites and mobile applications, used for attacks on clients of bank. During this time by the Brand Protection command it was blocked about 5,000 conformable domains from which 15% were fraudulent. Also more than 140 groups in social networks VKontakte and OK to a.r, illegally using a brand of bank were revealed and closed.
Rosbank is one of examples of flexible and adaptive approach to creation of the working strategy of the cyber security which is transformed taking into account emergence of threats and calls of the market. Rosbank as the financial institution answering not only to the Russian, but also international standards, made the decision on expansion of the stack of Group-IB technologies for ensuring protection of the clients. It is the pro-active position directed to the analysis of cyberthreats, Hunting for cybercriminals and rapid response to any atypical activity. For us honor to work with the command of bank separating our approach to cyber security comments Igor Smirnov, the commercial director of Group-IB
|
2016: System implementation of Threat Detection System
Implementation in 2016 of the Threat Detection System (TDS) system became the first Group-IB project and Rosbank. TDS is used for prevention of cyber attacks at an early stage, detectings of threats of the class zero-day and also significantly strengthens possibilities of rapid response to cyberincidents of own SOC (Security Operation Center) of bank.