OAAM UIO Proxy Oracle Fusion Middleware Online Documentation Library

23-16 Oracle Fusion Middleware Developers Guide for Oracle Adaptive Access Manager AnswerSolution : Globalized virtual authentication device image files including the authentication registration flows are not provided. The deployment team develop these.

23.9 Man-in-the-MiddleMan-in-the-Browser

QuestionProblem : I use mobile transaction authentication number to sign each transaction using an OTP via SMS. SMS costs are high. How can Oracle Adaptive Access Manager help? In addition, I want a solution that protects against Man-in-the-Middle MiTMMan-in-the-Browser MiTB attacks. AnswerSolution : 1. Use Oracle Adaptive Access Manager to assess risk and base the use of secondary authentication such as mTAN on risk. Then, SMS can be sent for transactions that are medium to high risk instead of all transactions. 2. One of the best ways to protect against MiTM and MiTB is to perform transactional risk analysis. For example, check to see if the target account has ever been used by this user before or if the user has ever performed a transfer over set dollar amount thresholds. To perform transactional analysis in real-time today requires native integration with the Web application. 3. Use PinPad to input the target account number. This ensures that the account number entered by the user cannot be easily changed in a session hijacking situation. The account number is not sent over the wire and cannot be easily altered by a MiTMMiTB. 4. It is recommended that KeyPad and PinPad virtual authentication devices always be used over HTTPS. The virtual authentication devices send the one time random data generated on the end-users machine mouse click coordinates to the server FAQTroubleshooting 23-17 to be decoded and HTTPS provides the traditional encryption in addition. No client software or logic resides on the end-users machine to be compromised. 5. With Oracle Adaptive Access Manager extremely high risk transfers can be blocked all together. Blocking high risk transfers reduces the fraud regardless of the authentication methods used.

23.10 Failure Counter

For the auto failure counter increment to work, Client Type for updateAuthStatus must be set to 9 QuestionAnswer. 23-18 Oracle Fusion Middleware Developers Guide for Oracle Adaptive Access Manager Part VIII Part VIII Glossary This part contains the glossary.