下载PDF
Microservices and API Security Enhancement for OFX’s International Wire Transfer Business
技术
- 应用基础设施与中间件 - 事件驱动型应用
- 网络安全和隐私 - 应用安全
适用行业
- 电网
- 国家安全与国防
适用功能
- 质量保证
用例
- 供应链可见性(SCV)
- 篡改检测
服务
- 云规划/设计/实施服务
- 测试与认证
挑战
OFX 是一家位于澳大利亚悉尼的国际金融转账平台,每年通过其网络应用程序处理超过 220 亿美元的资金。最近迁移到云后,OFX 寻求在其云优先微服务基础设施中提高可见性并防范开放 Web 应用程序安全项目 (OWASP) 攻击和身份验证滥用。合作伙伴通过与 OFX 网络内的微服务通信的 API 与 OFX 平台进行交互。数字安全主管 Richard Lane 的任务是建立安全计划和团队。他的目标是确保他们的微服务不会隐式信任他人,并寻求一种能够提供可见性的产品。他想要一种易于安装、使用并有效自动阻止恶意流量(包括登录)的解决方案,而不会导致生产事故。
关于客户
OFX是一家总部位于澳大利亚悉尼的国际金融转账平台。它每年通过其网络应用程序处理超过 220 亿美元的资金。该公司最近完成了历时三年的全面云迁移。 OFX 的合作伙伴通过 API 与平台进行交互,这些 API 与 OFX 网络内的微服务进行通信。该公司正在寻找一种解决方案,以提高其云优先微服务基础设施中的可见性并防范开放 Web 应用程序安全项目 (OWASP) 攻击和身份验证滥用。
解决方案
OFX 在其中间层环境中部署了 Signal Sciences,并在其 Web 服务器上设置了代理。这使他们能够获得深入的应用程序可见性。使用与轻量级代理通信的 Signal Sciences Web 服务器模块插件,安全团队和云架构师能够轻松部署,而不会给工程团队带来负担。在几分钟内安装软件后,安全团队使用 Signal Sciences 发现应用程序错误并更有效地解决根本原因。质量保证团队通过易于使用的仪表板使用 Signal Sciences 监控作为其发布协议的一部分,以快速发现任何问题。他们还使用 Signal Sciences Power Rules 来记录成功和失败的登录尝试,为其正常身份验证流量建立基线。凭借低风险承受能力和低流量,OFX 使用电源规则创建自定义阈值,以便在恶意身份验证流量偏离正常行为时主动发出警报和阻止。
运营影响
数量效益
相关案例.
Case Study
Hydro One Leads the Way In Smart Meter Development
In 2010, Ontario’s energy board mandated that time-of-use (TOU) pricing for consumers be available for all consumers on a regulated price plan. To meet this requirement, Hydro One needed to quickly deploy a smart meter and intelligent communications network solution to meet the provincial government’s requirement at a low cost. The network needed to cover Hydro One’s expansive service territory, which has a land mass twice the size of Texas, and its customers live in a mix of urban, rural, and remote areas, some places only accessible by air, rail, boat or snowmobile. Most importantly, the network needed to enable future enterprise-wide business efficiencies, modernization of distribution infrastructure and enhanced customer service. To meet these needs, Hydro One conceptualized an end-to-end solution leveraging open standards and Internet Protocols (IP) at all communication levels. The utility drew upon industry leaders like Trilliant to realize this vision.
Case Study
Selling more with Whirlpool
Whirlpool wanted to add connectivity to appliances and transform the company's relationship with customers. Traditionally, Whirlpool interaction with customers was limited to purchases made once every ten years. Connected washer and dryers provide exciting new features like remote management of start times and inter-machine communication.
Case Study
SAS® Analytics for IoT: Smart Grid
Companies face falling revenues, rising infrastructure costs, and increasing risk of outages caused by inconsistent energy production from renewable sources. Less money is coming in as more people and organizations take steps to curb their energy use. Utilities are paying more to maintain and build infrastructure due to increasing complexity, resulting from the rising number of intermittent and variable renewable energy sources connected in the distribution grid.
Case Study
Enel Secures Italian Power Generation Network
Electric energy operators around the world are working to increase the reliability and cyber resiliency of their systems. This includes Enel, a global power company that manages and monitors the Italian power grid. This grid:• Serves 31 million customers• Has a net installed energy capacity exceeding 31 gigawatts• Includes more than 500 power generation plants,including hydroelectric, thermoelectric, and wind• Is managed and monitored by Enel 24/7/365• Is operated by Terna, the Italian Transmission System Operator (TSO)Enel is responsible for the availability of the grid’s underlying ICS and industrial network. It also manages Regional Control Centers and Interconnection Centers which connect with the TSO. The TSO manages the flow of energy to the grid plus controls and remotely regulates the power generation of power plants, increasing and decreasing power production as required. The complex system of interaction and cooperation between Enel and the TSO has strong security implications as well as operational and business challenges.
Case Study
IoT based Energy Quality Availability Monitoring Solution
There were several challenges faced:Since this data would be in the public domain, accuracy and authenticity of this data were of paramount importance. It should be able to withstand scrutiny.It is challenging to build an appliance that can withstand a wide range of voltage fluctuations from as low at 90v to as high as 320v. Since the device would be installed in remote locations, its resilience was of paramount importance.The device would have to deal with poor network coverage and have the ability to store and re-transmit data if networks were not available, which is often the case in rural India. The device could store up to 30 days of data.The platform that deals with the data should be readily available and highly reliable and never lose a packet of data.
Case Study
Data Capture for Afghanistan Forces
Electronic equipments on the field of Afghanistan provided information on the status of the vehicle and to identify potential threats surrounding it to the British Force. The monitoring and interpretation of this data requires robust and sophisticated digitization for data capture and communication.