GROUP TEST l Security Innovators Throwdown
»
Silver Tail Systems
raud is arguably the number Silver Tail Mitigation allows these
F one criminal activity of choice
today. Fraud that targets web-
sites may be the easiest fraud to com-
changes immediately based on a rule
set instead of requiring the complete
redevelopment of the site. Here
mit, and web fraud is very profitable is where the two products work
for the fraudster – with little chance together. Forensics understands the
of prosecution. Unfortunately, it is website, its traffic and its business/
not necessary for an attacker to pen- page flows. It then communicates
etrate a website to commit web fraud. to Mitigation, which performs rule-
Most successful attacks today are based changes. Administrators and
client-side attacks or man-in-the-mid- web designers develop the rule set
dle (session hijacking) attacks. The and test it in a safe environment
answer is simple: control all access to before deploying it. That allows
the web server. But how does one do nearly attendant-free administration
that, if it’s so simple? That’s a good of the site regardless of the fraud
question and the answer is at the attempts against it.
heart of Silver Tail Systems’ solutions to AT A GLANCE This is no trivial feat as may well be
the problem. imagined. Rebuilding the page flows on
The company has two services, Forensics Product: Forensics and Mitigation a very large website is a huge engineering
and Mitigation, that separately address parts Company: Silver Tail Systems undertaking. The company targets these
of the problem and together offer a solid www.silvertailsystems.com/index.php/ very large sites and that seems to us to be
solution to it. The Forensics product mostly Cost: $10K-50K per month per product. appropriate. The ability of the Mitigation
provides early warning and analysis, while The problem it solves: Sophisticated product to change page flows based on
Mitigation actually makes emergency chang- web fraud attacks. a rule set that responds to actions of an
es in the website if it is compromised. These What w