Safe, friction-free user interactions

Issue 2 2021 Information Security

F5 announced the addition of new SaaS products to its application security portfolio. Device ID and Shape Recognize make use of unique data and analytics capabilities, streamlining customer experiences by removing login friction for users while guarding against fraud.

“APIs play an essential role in unlocking and extending the reach of digital experiences for organisations in every industry sector—a scenario that, unfortunately, also constitutes a larger attack surface for hackers,” said Haiyan Song, EVP of Security at F5. “Accordingly, we believe that the new epicentre for cybersecurity is around applications and APIs and that the most significant challenge for security professionals is to safeguard an ever-growing number of digital experiences. To help today’s customers succeed, security must be native to applications and APIs, continuous, applied in real time and powered by data and AI.”

Today’s announcement comes ahead of the publication of F5 Labs’ 2021 Application Protection Report, which attributes more than two-thirds of API security incidents to incomplete authentication and authorisation at API endpoints.

Combining strategic fraud defences with application security

F5’s new solutions represent a notable security portfolio enhancement for the business and follow on from the acquisition of Shape Security, which was completed in January 2020.

Device ID is a real-time, high-precision device identifier that helps customers better understand the devices interacting with websites and mobile apps. The solution uses advanced signal collection and proven machine learning algorithms to assign a unique identifier to each device based on its browser, OS hardware and network attributes. For returning devices, usage behaviours can be analysed to facilitate the reduction of fraud and a smooth experience for known good users—meaning they can spend more time enjoying digital experiences and less time proving (and re-proving) device legitimacy. Previously free to Shape customers, the solution is now being made available to all F5 customers at no charge, helping jumpstart customers’ data and analytics journey with security.

Shape Recognize leverages the intelligence of Shape’s extensive telemetry, building on the capabilities of Device ID with insights around login history, environment and integrity across the network to further enhance the consumer experience and remove authentication friction. The solution delivers top-line revenue through recognition of legitimate users, rescuing known, good consumers from the frustration of excessive logins and re-authentication. Recognize achieves this by accurately identifying returning consumers and other legitimate users in real-time through the power of deep analytics, behavioural and contextual awareness and the broad reach of the Shape network. With this level of insight, web and mobile applications can dynamically reduce or eliminate login friction, leading to increased revenue and vastly improved consumer convenience.

Both solutions complement the Shape AI Fraud Engine (SAFE), which was launched in October 2020. SAFE uses a closed-loop machine learning approach to detect and block fraud in real-time. SAFE identifies and stops account takeover, malicious account origination, exploitation of stolen accounts and other fraudulent activities. Powered by Shape’s AI engine and data-driven insights generated from evaluating over a billion transactions a day, SAFE seeks out and eliminates fraudsters’ efforts across all points of the user’s journey, including login, account creation and other activities that could otherwise serve as potential targets. As a fully managed service, SAFE also reduces the often-overwhelming workload on fraud teams, blocking threats that would otherwise require costly investigation and remediation.

For additional perspective on today’s news and F5’s approach to security, please see Haiyan Song’s blog at www.f5.com/company/blog/secure-your-apps-and-apis--everywhere-




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...