all rights reserved © alcatel-lucent 2008, ##### demo: voice phishing prevention by authenticated...

4
All Rights Reserved © Alcatel-Lucent 2008, ##### Demo: Voice Phishing Prevention by Authenticated Display-name Stanley Chow, Christophe Gustave, Dmitri Vinokurov IPTComm, July 2, 2008

Upload: claire-greene

Post on 27-Mar-2015

213 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: All Rights Reserved © Alcatel-Lucent 2008, ##### Demo: Voice Phishing Prevention by Authenticated Display-name Stanley Chow, Christophe Gustave, Dmitri

All Rights Reserved © Alcatel-Lucent 2008, #####

Demo: Voice Phishing Prevention

by Authenticated Display-name

Stanley Chow, Christophe Gustave, Dmitri Vinokurov

IPTComm, July 2, 2008

Page 2: All Rights Reserved © Alcatel-Lucent 2008, ##### Demo: Voice Phishing Prevention by Authenticated Display-name Stanley Chow, Christophe Gustave, Dmitri

All Rights Reserved © Alcatel-Lucent 20082 | RealName Demo – IPTComm 2008 | July 2008

The problem – Voice Phishing

Someone calls you claiming to be from “Deutsche Bank”, and CallerID agrees.

Question: Is the caller really from Deutsche Bank?

If we want to authenticate a company, what is a company? Legal name? Many companies have complex structures that are unknown

outside the company; joint ventures, branches, outsourcing, etc. Phone number? No way to know them all. Spoofable.

Name in phone book? Words Deutsche and Bank present in 24 names in NA phone directories: Deutsche Bank Ag, Alex Brown-Deutsche Banc., West Deutsche Bank, Deutsche Bank Berkshire Mortgage, Deutsche Bank Florida Na, … plus “DB” abbreviation in lot of names.

Domain name? The only way to get to the web site of Matsushita Electric Industrial Co., Ltd. is to go to www.panasonic.net

Brand? People think of “The Brand” and associate the company with it.

Names are not unique: different jurisdictions may allow the same name.

Page 3: All Rights Reserved © Alcatel-Lucent 2008, ##### Demo: Voice Phishing Prevention by Authenticated Display-name Stanley Chow, Christophe Gustave, Dmitri

All Rights Reserved © Alcatel-Lucent 20083 | RealName Demo – IPTComm 2008 | July 2008

Solution - Demo scenarios

Routine calls (from friends, family members, …) - no need to authenticate.

To authenticate a call, user clicks “Confirm Name” button. Failed authentication.

The display shows the “Authentication failed” result.

Successful authentication. The display shows the registered name, the approving

registry, and the result.

Complicated phishing case. Legitimate “DB Consulting” name is authenticated by

“Health Industry” registry, but pretending to be the Deutsche Bank division. Authentication succeeds but verified by irrelevant registry, thus banking phishing fails.

www.ProveRealName.com

Authenticated

Deutsche Bank

Registry: Canadian Banks

Page 4: All Rights Reserved © Alcatel-Lucent 2008, ##### Demo: Voice Phishing Prevention by Authenticated Display-name Stanley Chow, Christophe Gustave, Dmitri

All Rights Reserved © Alcatel-Lucent 20084 | RealName Demo – IPTComm 2008 | July 2008

www.alcatel-lucent.com