58
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
3. Adaptive Authentication
a. Contextual Risk Assessment: Utilize risk-based authentication systems powered by artificial intelligence (AI) or machine learning that dynamically assess the risk level of each login attempt based on: • User geolocation and time zone. • Device fingerprinting (type of device, OS, browser). • IP reputation and previous login activity. • User behavioral patterns (behavioral biometrics). b. Additional Verification Actions: • The system must be capable of executing additional authentication when anomalies or increased risks are detected, such as: a. Login from a new device. b. Attempted access from suspicious countries or IP addresses. c. Sudden changes in the user’s login pattern. • Additional authentication may include an extra OTP verification, biometric re-verification, or approval via an official mobile app. c. Fraud Detection and Learning: • Authentication algorithms must be integrated with a fraud detection module that is continuously updated based on findings from past incidents and threat intelligence information. • The system must be capable of adapting its responses to new trends such as credential stuffing, session hijacking, and social engineering-based phishing.
Made with FlippingBook Ebook Creator