Adaptive Multi-factor Authentication (MFA) in BFSI

Date:

Trending

A few months back (just after the Covid pandemic had started) an important change was implemented by a popular retail US Bank, Bank of America.  This was regarding how their retail net-banking customers would be logging into their banking account.  

- Advertisement -

All users of this bank can now set up an additional security measure during login in the form of a one-time authorization code, that would be sent to their registered mobile.  This will be in addition to their user id and password.  In the case of some users who are deemed to have a security risk during login (due to their high-risk score presumably arrived due to their inconsistent login patterns), this process has been made mandatory.  

Since the bank had suspected that post-covid the number of internet logins and transactions is going to be high, they probably implemented these changes to protect attempts to hijack genuine customer accounts by fraudulent means by hackers.

- Advertisement -

This shows that the era of Multi-Factor Authentication (MFA) has truly arrived and is here to stay.  Previously MFA was used only when bank transactions were performed by users, but now they are required even during the login process.  

The bank was using security questions as a second factor, but now probably had deemed that as risky, as typical user answers for popular security questions of theirs, can be lifted from their social media accounts by hackers.  

So where does this lead to?  Probably, to the next stage of MFA, which is Adaptive MFA in BFSI.  

What is Adaptive MFA? 

When a user login into a bank, several patterns about the login can be measured by the bank.  They can use this data to protect the customer from phishing and other hacker attacks. Like the typical time of the day the user logs in, the network & computer the login happens from, the Geolocation (GPS location) the user logs in from, the time they typically spend during the login, the type of transactions they normally perform, etc.  

With this wealth of data in-store, the banks can now assign risk scores for each activity through AI (Artificial Intelligence) and ML (Machine Learning) methods. If during any login there is an abnormal risk score detected for the user, an adaptive MFA authentication can be triggered.  That is, the user during that login session would be made to go through additional factors of authentication as part of their MFA Auth, for example, an OTP coupled with a Push based authentication sent through to the user’s mobile app, plus a security question or even a phone call based verification.  This helps to control or even eliminate the fraudulent access by a hacker, as it begins to happen.

How this prevents fraud?

During adaptive authentication, the key element to note is most of the factors that are used for authentication are instantly generated, so the hacker would not be knowing all the details of the authentication sequence and credentials in advance, for them to execute a phishing attack on the authenticated session of the user.  Even the user would not know these in advance for the hackers to target gullible users to get credentials from them, before the login.

What are the other adaptive authentication factors that can come into play?

MFA is normally performed by:

•    factors that the users know (passwords, security questions, pre-stored user-approved picture patterns and code numbers),

•    factors the users have (like OTP, mobile push authentication, google authentication) and 

•    factors that define who the users are (biometric authentications like retina scan, fingerprints, facial recognition).  

Out of these the first set of factors “the one the users know” are under severe attack by the hackers.  Hence banks will resort slowly to the second and third categories of authentications mentioned above.  These two categories of factors will be hard to pry out or reproduce like the passwords or security questions, for the reasons mentioned above.

What are the challenges in implementing Adaptive MFA?

The primary challenge is how to protect the user experience.  Users normally do not like too many restrictions just to get to their bank account.  Also, not all users are computer or mobile-savvy.  For example, the bank in the question above has instructed the users who do not have a mobile phone or do not have a valid phone number in the file, to call the bank to get authenticated.   

While this may work temporarily, this cannot be done by the user every time as the waiting times for such calls are high.  So, the banks have to arrive at the right mix of technology and user convenience to implement secure MFA login at the right cost to the user.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Raj Srinivas
Raj Srinivas
Primarily from a strong security and product engineering background, he has been the principal architect of MISP (Multi-Domain Identity Services Platform) & CIE (Cloud ID Exchange) – in-house IAM & Security products at 8K Miles.

More Latest Stories

More Articles

GW Casino Review & FAQ: Real Talk for Aussie Punters

With the avalanche of cookie-cutter online casinos hitting Aussie screens, most punters have seen it all—flashy banners, “unbeatable bonuses,” dodgy spins, and recycled features...

Finding the Right Custom Home Builder in Bay City: Reviews & Recommendations

Building a new home is one of life’s most exciting milestones—but it also comes with big decisions. One of the most crucial is choosing the right builder. In Bay City, Michigan, homeowners looking for long-term satisfaction are increasingly seeking out well-reviewed custom home builders...

Pichai Family Foundation to Sell 4,000 Alphabet Shares Worth $708K

The Pichai Family Foundation filed a notice with the U.S. Securities and Exchange Commission...

Sundar Pichai Sales Alphabet Stock Worth $5.6 Million

Alphabet Inc. (NASDAQ: GOOGL) CEO Sundar Pichai filed a notice with the U.S. Securities...

Iran May Exit Nuclear Treaty Under New Bill

Iranian parliamentarians are drafting a bill that could pave the way for the country...

NSE India, Cyprus Stock Exchange Sign MoU for Dual Listings, Financial Innovation

India’s National Stock Exchange (NSE) and the Cyprus Stock Exchange signed a memorandum of...

Khair and Tunu Wood Seized in Major Operation by Jammu Forest Department

Acting on specific intelligence, the Forest Department team in Tehsil Bhalwal intercepted and seized...

36 Bangladeshi Nationals Held Without Visas in Delhi

The Delhi Police has apprehended 36 Bangladeshi nationals residing illegally in India. The dedicated...

Zuckerberg Offloads $5.8 Mn More in Meta Shares as June Sales Top $37 Million

Meta CEO Mark Zuckerberg has filed to sell another $5.8 million worth of company shares, adding to a series of trades that have brought...

Congo: Over 29 dead as floods, landslides hit Kinshasa

At least 29 people died in Kinshasa after heavy rains over the weekend triggered...

Sharp Bettors vs Recreational Bettors: What Sets Them Apart?

In the U.S. alone, over $120 billion was legally wagered on sports in 2023,...

HCLTech to Power The Standard’s Digital Shift with AI-Led IT Solutions

HCLTech, a leading global technology company, announced an expansion of its partnership with Standard...

Air India Plane Crash: Over 60 victims identified via DNA

Days after Air India’s Ahmedabad-to-London flight crashed with 242 passengers and crew on board,...

What You Need to Consider When Starting an HVAC Company

Entering the HVAC industry is a significant business decision that comes with both challenges and opportunities. As one of the most crucial services in...

Cybersecurity Theater: Why Companies Still Fall for the Illusion of Control

The world now experiences daily security breaches on evening news while ransomware groups operate like major Fortune 500 companies yet enterprises seem to be pretending they are secure. Welcome to the cybersecurity theatre which presents itself through software dashboards and certificates and PowerPoint presentations that...

India’s Tier 2 & 3 Cities: The New Battleground for Smart Delivery

India’s economic narrative is undergoing a profound transformation, shifting its gaze from the bustling...

Football: Messi, Trezeguet Miss as Inter Miami Draw Al Ahly in Club World Cup Opener

Lionel Messi’s Inter Miami were held to a goalless draw by Egypt’s Al Ahly...

Manipur: Security Forces Seize 328 Guns, 9,300 Rounds in Joint Raids

In a major crackdown, security forces recovered a large cache of arms and ammunition...

Israel-Iran War: IAEA Confirms Damage at Iran’s Natanz Plant

The International Atomic Energy Agency’s Director General Rafael Grossi has confirmed the destruction of...

Boeing Pledges Full Support to Probe in Air India Plane Crash

Following the tragic plane crash of Air India Flight 171 near Ahmedabad, Boeing President...

Ahmedabad Plane Crash: DGCA Orders Air India To Conduct Extra Security Checks on Boeing 787s

Directorate General of Civil Aviation has directed Air India to carry out additional safety...

Sri Lanka To Raise Electricity Tariff By 15 Percent

Sri Lanka will increase electricity tariffs by 15% starting June 12, the Public Utilities...

London-Ahmedabad Plane Crash: Air India to Operate Relief Flights

Air India is operating two relief flights for the next of kin of passengers...

Microsoft Announces Quarterly Dividend To Board Of Directors

Global technology giant Microsoft Corporation (NASDAQ: MSFT) announced a quarterly dividend of $0.83 per...

HCLTech to Power The Standard’s Digital Shift with AI-Led IT Solutions

HCLTech, a leading global technology company, announced an expansion of its partnership with Standard...

ICG Transfers Distressed MV Wan Hai 503 to Tug Offshore Warrior in Kochi

In a key maritime operation, the Indian Coast Guard (ICG) successfully transferred the tow...

Civil Aviation Ministry: High-Level Panel to Probe Air India Flight Crash

The Ministry of Civil Aviation has constituted a high-level multi-disciplinary committee to investigate the...

India Distances Itself from SCO Stance on Israel’s Attack On Iran, Calls for Dialogue

India has opted out of a recent Shanghai Cooperation Organisation (SCO) statement that strongly...

Los Angeles Protests: President Trump Deploys 700 Marines, 200 to Secure Federal Building

As nationwide protests against the Trump administration are expected to unfold across the U.S....

Air India Plane Crash: Over 60 victims identified via DNA

Days after Air India’s Ahmedabad-to-London flight crashed with 242 passengers and crew on board,...

London-Ahmedabad Plane Crash: Air India to Operate Relief Flights

Air India is operating two relief flights for the next of kin of passengers...

Air India passenger plane flying from Ahmedabad to London crashed

A London-bound Air India passenger plane carrying 242 people, including 2 pilots and 10...

Microsoft Announces Quarterly Dividend To Board Of Directors

Global technology giant Microsoft Corporation (NASDAQ: MSFT) announced a quarterly dividend of $0.83 per...