• No results found

NEW THREATS AND COUNTERMEASURES Identity Theft and Unauthorized Profiling vs Identity Management

N/A
N/A
Protected

Academic year: 2021

Share "NEW THREATS AND COUNTERMEASURES Identity Theft and Unauthorized Profiling vs Identity Management"

Copied!
51
0
0

Loading.... (view fulltext now)

Full text

(1)

NEW THREATS AND COUNTERMEASURES

Identity Theft and Unauthorized Profiling vs

Identity Management

, Ernesto Damiani

(joint work with Marco Cremonini,

Sabrina De Capitani di Vimercati, Pierangela Samarati) Università degli Studi di Milano

Dipartimento di Tecnologie dell'Informazione Crema (CR)

(2)

Types of Cyber Crime

Security Threats and Violations Access Control Violations Integrity/ Privacy Violations Fraud/ Identity Theft Denial of Service/ Sabotage Confidentiality Authentication Nonrepudiation
(3)

Identity Theft – Generic Definition

Š

Identity theft is a crime in which an impostor obtains

key pieces of personal information

in order to

impersonate someone else.

Š

Identity theft and identity fraud are terms used to

refer to all types of crime in which someone

wrongfully obtains and uses another person's

personal data in some way that involves fraud or

deception, typically for economic gain.

(4)

Identity Theft – Legal Definitions

Š

The

Identity Theft

and Assumption Deterrence Act

of 1998 (

Identity Theft

Act) was passed to address

the problem of

Identity Theft

. This act (codified at 18

U.S.C. § 1028) makes it a federal crime when

anyone.

„

Knowingly transfers or uses, without lawful

authority, a means of identification of another

person with the intent to commit, or to aid or abet,

any unlawful activity that constitutes a violation of

Federal law, or that constitutes a felony under any

applicable state or local law

Š European Union: the EU (European Union) Privacy Directive

(5)

Identity Theft Statistics

Š In 1995, 8806 financial crimes investigation cases were related to identity theft.

Š In 1996 there were 8686 cases

Š 1997 there were 9455 cases.

Š In 2002, an estimated 500,000 to 700,000 people were victimized by identity theft

Š U.S. statistics showing ID-theft losses are growing 20 percent a year

Source: Janine Benner, Beth Givens, and Ed Mierzwinski, <www.privacyrights.org/ar/wcr.htm>

Š The Federal Trade Commission says, 6 percent of the 86,168 people who reported identity theft to the agency said a family member was responsible. /

(6)

Identity Theft Cost

Š In 2002, The General Accounting Office (GAO) released the second edition of a 19097 report to Congressional requesters entitled, "Identity

Fraud: Information on Prevalence, Cost, and Internet Impact is Limited."

„ The report noted that the Secret Service quantified identity

theft losses to individuals and financial institutions at $442 million in fiscal year 1995, $450 million in fiscal year 1996, and $745 million in fiscal year 1997. This involved only those cases of financial crime that the Secret Service itself had

tracked.

Š MasterCard stated that dollar losses related to identity theft fraud

represent 96% of member banks' overall fraud losses of $407 million in 2001. Also in 2001, U.S. fraud losses of VISA member banks totaled $490 million or about 0.1% of billing transactions.

(7)

Interesting Scams

Š

In 2002, the FBI has arrested Philip Cummings, who

is alleged to have started the scam while he worked

on the help desk at

Teledata Communications Inc.

(TCI), a company in Bay Shore, N.Y., that provides

banks and other entities with computerized access to

consumer credit reports from the three commercial

credit history bureaus -- Equifax Inc., Experian

Information Solutions Inc. and Trans Union LLC.

Š

Federal investigators have charged three men they

say were involved in a massive identity theft scheme

that spanned three years, involved more than 30,000

victims and, so far, has resulted in more than $2.7

million in losses

.
(8)

Interesting Scams - continued

Š

FTD.COM Leaks Credit Card Numbers to the

Internet.

Source: Gerald Quakenbush, BugTraq

Š

Identity Thieves Strike e-Bay.

Source: Paul Festa Staff Writer, CNET News.com November 22, 2002

Š

Identity Theft Targeted H&R Block Customers

Source: AP Newswire, November 4, 2002

Š

Latest ID Theft Scam: Fake Job Listings

Source: www.cnn.com, Saturday, March 1, 2003

Š

TriWest Healthcare Alliance Corp Broke Into

And Record Stolen

Source: Dennis Wagner ,The Arizona
(9)

Id Theft Categories

Š

Account takeover identity theft

„

The impostor uses personal information to gain

access to the person's existing accounts

„

Example: credit card fraud; cell phone fraud

„

A real life story

Š

True name and account takeover

„

True name identity theft means that the thief uses

personal information to open new accounts.

„

Example: opening new credit card account;

opening a new checking account

(10)

Identity Theft Management

Š Need for secure identity management

„ Ease the burden of managing numerous identities

„ Prevent misuse of identity: preventing identity theft

Š Techniques for preventing identity thefts include

„ Access control, Encryption, Digital Signatures

„ A merchant encrypts the data and signs with the public key of

the recipient

(11)

Platform for Privacy Preferences (P3P):

What is it?

Š P3P is an emerging industry standard that enables web sites t9o

express their privacy practices in a standard format

Š The format of the policies can be automatically retrieved and

understood by user agents

Š It is a product of W3C; World wide web consortium

www.w3c.org

Š When a user enters a web site, the privacy policies of the web site

is conveyed to the user

Š If the privacy policies are different from user preferences, the user

is notified

(12)
(13)

Things To Look For At Work

Š Information security procedures in your workplace.

Š Process to screen employees who have access to personal

information .

Š Keep all personal information in locked files, and establish

secure procedures for data services.

Š Limit use of personal identifiers.

Š Encrypt all personal and confidential information on computers.

Š Secure methods for disposing of personal information

Š 3rd party to carryout privacy audits/investigations that gauge

how vulnerable records are to theft

Š Supply employees with a yearly credit check as a benefit of

(14)

Risorse Web

Š http://www.consumer.gov/idtheft/ - U.S. government's central website for information about identity theft.

Š http://www.ssa.gov/ - Official Website of the Social Security Administration

Š http://www.privacyrights.org/identity.htm - Privacy Rights Clearinghouse

Š http://www.idtheftcenter.org/ - Identity Theft Resource Center

(15)
(16)

Digital Identity Management

Š Digital identity is the identity that a user has to access an electronic

resource

Š A person could have multiple identities

„ A physician could have an identity to access medical resources

and another to access his bank accounts

Š Digital identity management is about managing the multiple

identities

„ Manage databases that store and retrieve identities

„ Resolve conflicts and heterogeneity

„ Make associations

(17)

Digital Identity Management - II

Š Federated Identity Management

„ Corporations work with each other across organizational

boundaries with the concept of federated identity

„ Each corporation has its own identity and may belong to

multiple federations

„ Individual identity management within an organization and

federated identity management across organizations

Š Technologies for identity management

„ Database management, data mining, ontology management,

federated computing

(18)

RFID -- radio frequency identification

Š RFID tags are miniscule microchips the size of grain of sand

Š Retailers adore the concept: RFID tags in clothing and other products Š Networked RFID readers

Š RFID can be tag with credit card you used to buy it and recognizes you by name

Š Disabled at the cash register only if the consumer chooses to "opt out" and asks for the tags to be turned off. "

(19)

Biometrics

Š Early Identication and Authentication (I&A) systems, were based on

passwords

Š Recently physical characteristics of a person are being sued for

identification „ Fingerprinting „ Facial features „ Iris scans „ Blood circulation „ Facial expressions

Š Biometrics techniques will provide access not only to computers but

also to building and homes

(20)

Biometric Technologies

Š Pattern recognition

Š Machine learning

Š Statistical reasoning

Š Multimedia/Image processing and management

Š Managing biometric databases

Š Information retrieval

Š Pattern matching

Š Searching

Š Ontology management

(21)

Secure Biometrics

Š Biometrics systems have to be secure

Š Need to study the attacks for biometrics systems

Š Facial features may be modified:

„ E.g., One can access by inserting another person’s features

„ Attacks on biometric databases is a major concern

Š Challenge is to develop a secure biometric systems

„ Policy, Model, Architecture

(22)

Negotiated Access Control-1

X Trust between two strangers (requestor and service provider) is

established based on parties’ properties

Z Proven through negotiated disclosure of digital credentials or

zero-knowledge proofs.

X Every party can define release policies to protect sensitive

resources.

Z Resources can include services accessible over the Internet,

RBAC roles credentials, policies, and capabilities in

Negotiated AC differs from traditional identity-based access control in the following aspects:

(23)

Negotiated Access Control-2

X Policies describe what properties each party must demonstrate

(e.g., ownership of a driver’s license issued by an EU country) in order to gain access to a resource.

X The parties negotiate directly without involving trusted third

parties, other than credential issuers. Since both parties have policies, peer-to-peer negotiation is appropriate for Web

Services on the Open Web.

Z Instead of carrying out a one-shot authorization and

authentication process, trust is established incrementally

(24)

Negotiation protocol

X A negotiation process is triggered when one party requests to access a resource owned by another party.

Z E.g., a remote requestor tries to access a Web-based service.

X The goal of a negotiation between a requestor and a service provider

resp. holding policies Pr and Ps is:

Z Finding a sequence of resources (C1.x , . . . ,Ck.x , Ss)

(Ci.x: credential belonging to party x, S: service), such that when

credential Ci.x is disclosed, its release policy has been satisfied

by credentials disclosed earlier in the sequence.

Z E.g. C2.s is released iff policy Ps includes a rule like “disclose C2.s

if C1.r has been provided by requestor”).

X The use of release policies together with a negotiation process seems

(25)

Privacy Issues

X Privacy issues

PKI does not provide a comprehensive solution for avoiding unauthorized disclosure of personal information.

X Digital Identity Management System (privacy-aware)

New solutions (management of partial identity) with support of privacy related features: privacy, minimal disclosure, anonymity support, legislation support.

(26)

Nyms and Partial Identities

X Digital Identity

Z Nyms

Z Partial Identities

Non-disjoint concepts.

Nyms give users different identities to use when interacting with

other parties in different environments.

Behind a nym, strong authentication tools such as tokens, smart

(27)

Partial Identities

Partial identities are any subset of the properties associated with users (such as name, age, credit-card number, or employment) that the user can select for interacting with other parties.

A partial identity can be named or unnamed, which means it might

(28)
(29)

Multiple and Dependable Digital Identity

(MDDI)

:

Requirements

X Reliability and dependability

Protect users against forgery and related attacks while also

guaranteeing to other parties (such as suppliers and brokers in an ebusiness transaction) that the users can meet transaction-related obligations.

X Controlled information disclosure

Users must have control over which identity to use in specific

circumstances, as well as over its secondary use and the possible replication of any identity information revealed in a transaction.

X Mobility support

The mobile computing infrastructure must be able to take into

account its own peculiarities (such as limited bandwidth and display size) to apply MDDI technology successfully.

(30)

MDDI System Design Issues

(31)

Identities Life Cycle Management

Open issues:

X Provisioning: users must be given the ability to efficiently obtain/create identities.

X Revocation: Identities may become obsolete and not

applicable anymore.

X Profile management: users must be given the ability to

manage their own identity information.

X Prevention of identity proliferation: impose soft/hard limit on the number of identities that can be associated with a single individual.

(32)

Digital Identities Representation

X Ontology: domain ontology, task ontology. Need to allow for sound reasoning about the identity equivalence and trust propagation.

XIdentity interoperability and portability: Identity must be provided in a common interchange format. The identity management service must support extensible mapping between identities.

X Identity extensibility: Unlimited number of attributes that may be associated with an identity.

(33)

Cross-domain Identity Communication

XFederated identity management support: need to investigate techniques for identity composition and

interchange. Challenge is to balance complete retrieval with privacy.

XDistributed profile management: retrieval of different chunks of identity information.

XDistributed update support: Distribution of profile information and update support.

(34)

Controlled Dissemination

X Privacy and secondary usage control: identity attributes should be enriched with privacy preferences. Current

languages are still in their infancy.

X Negotiation protocols (e.g., avoid cases when identity is released and no service is given in return).

X Linkability control between transactions and different information releases.

(35)

Trust management

X Control on single sign-on identity disclosure: SSO approaches delegate to the infrastructure all decisions on identity communication. Solutions are needed enabling users to retain some control on such disclosure.

X Trust models to determine under which conditions a party can trust others for their security and privacy.

E.g., reputation models.

X Support of trust levels for instance non-sensitive

information can be provided directly by the user, while for others certificates may be needed.

(36)

The PRIME Project

X Objective of the project

PRIME focuses on solutions for privacy-enhancing identity management that supports end-users sovereignty over their private sphere and enterprises privacy-compliant data.

Main features:

Z anonymity and end-user control

(37)

Model and Format

X Privacy-aware access control model

New privacy-aware access control model together with an access control protocol for the communication of policies and of identity information among parties.

X Profiles and Ontologies

Z Profiles associated with subjects and objects define the name and value of some properties that characterize the subjects and objects.

Z Ontologies (Subject and Object) contain terms that can be used to make generic assertions on subjects and objects.

(38)

Privacy Policies

X Access control policies. They govern access to data/services managed by the user/server-side party (as in traditional access control).

X Release policies. They govern release of

properties/credentials/PII of the party and specify under which conditions they can be disclosed.

X Data handling policies. Specified by the user that decide how his/her personal information must be managed by the

counterpart (also called Sticky policies).

X Sanitized policies. They provide filtering functionalities on the response to be returned to the counterpart to avoid release of sensitive information related to the policy itself.

(39)

Access Request

Each request is characterized by:

X the Subject that makes the request, defined as a pair:

Z User: identifier of the human entity (possible anonymous)

that connected to the system and submitted the request. Z Purpose: reason for which data are being requested and

will be used (e.g., Commercial, Teaching, Research, etc.).

X the Action that is being requested (e.g., read, write, download).

(40)

Access Request:

Examples

<tom.smith,research>, read, object1

user tom.smith requires to read object1 for research purposes.

<john.doe, _>, read, object1

user john.doe with undeclared purpose requires to read object1.

<_,_,>, browse, object5

an anonymous user with undeclared purpose requires to browse object5.

(41)

Subject and Object

Information

X Each party's portfolio contains properties that the party can use to

gain (or offer) services:

Z data declarations: statements issued by the party.

Z credentials: statements issued and signed (i.e., certified) by authorities trusted for making the statements.

X To refer to specific data in a credential we introduce the concept of

credential term.

Z A credential term is an expression of the form

credential name(predicate list)

X Users and Objects can be grouped into groups.

(42)

Basic elements of the

language-1

X A predicate declaration where the argument is a list of

predicates of the form predicate name(arguments);

X A binary predicate credential where the first argument is a

credential term and the second argument is a public key term.

Intuitively, a ground atom credential(c;K) is evaluated to

true if and only if there exists a credential c verifiable with public

key K.

X A set of standard built-in mathematic predicates, such as

(43)

Basic elements of the

language-2

X A set of location-based predicates of the form

predicate name(arguments);

X A set of trusted-based predicates of the form

predicate name(arguments);

X A set of non predefined predicates that evaluate information

(44)

Obligation

X An obligation establishes how a released personal data must be

managed by the counterpart.

X Obligations are associated to release policies and linked to

released data.

X Types of obligations:

Z Transactional Obligation: to be immediately enforced (e.g. delete PII data as soon as the transaction is over)

Z Data Retention and Handling Obligation: driven by

(45)

Access Control rules - 1

X An access is granted if there is satisfaction of at least one of the

AC rules that apply to the given request.

X Rule structure:

Z subject identifies the subject to which the rule refers. Z subject-expression is an expression defining

conditions on the subject that must be evaluated on the subject's portfolio (declarations and credentials);

subject

WITH subject-expression

CAN action

FOR purpose ON object WITH object-expression

IF conditions FOLLOW obligations

(46)

Access Control rules - 2

Z action is the action to which the rule refers (e.g., read, write, etc.).

Z purpose is the purpose to which the rule refers and

represents how the data is going to be used by the recipient. Z object identifies the object to which the rule refers.

Z object-expression is an expression defining conditions on the object that must be evaluated on object's data (stored in DB or other repositories).

subject WITH subject-expression CAN action

FOR purpose

ON object

WITH object-expression

IF conditions FOLLOW obligations

(47)

Access Control rules - 3

Z conditions is a boolean expression of generic conditions that an access request to which the rule applies has to

satisfy. For instance, trust properties, or the user's consent to disclose.

Z obligations is a boolean expression of obligations that the server must follow when manage the

information/data/PII. E.g., all accesses against a certain type of data for a given purpose must be logged.

subject WITH subject-expression CAN action

FOR purpose ON object WITH object-expression

IF conditions

FOLLOW obligations

(48)

Examples of rules - 1

X A registered user who works as a doctor, can read for research

the patientXXX-Data with the agreement of the patient.

registeredUsers WITH declaration(equal(user.work,

"doctor")) CAN read FOR research ON patientXXX-Data

with declaration(equal(object.patient_agreement, yes)) IF no-condition FOLLOW no-obligation

(49)

Examples of rules – 2

X Anybody with age>18 can book two seat for the movie "Full

Metal Jacket" giving a credit card and accepting a contract. Server must delete credit card after the end of transaction.

Anonymous WITH declaration(greater than(user.age,18)) CAN book FOR no-purpose ON movie with

declaration(equal(object.title, "Full Metal Jacket")) IF sign_Contract() and credential(credit_card, K)

(50)

Open problems

X Policy correctness

Z Unfortunately, real-world policies tend to be very complex.

Z Policy errors could allow outsiders to gain inappropriate

access to services, possibly inflicting huge and costly damages.

X Leakage in automated negotiation

Z Very specific policies may leak information about what we

want to protect.

Z Malicious services may try to get information which is not

(51)

Conclusions

Š

Identity: a central concept in the

e-infrastructure

Š

Identity theft/misuse and unauthorized

profiligs: two major security threats

Š

Identity management: a key technology

References

Related documents

Control identities Manage user identities and their roles, provision users for access to resources, ensure compliance with identity and access policies, and monitor user