“hiding in the web” - kpmg international1.2.3.4 do you use ip addresses to identify users,...

24
“HIDING IN THE WEB” THE GROWING THREAT OF LOCATION FRAUD David Briggs - Chairman

Upload: others

Post on 16-Jun-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

“HIDING IN THE WEB”THE GROWING THREAT OF LOCATION FRAUD

David Briggs - Chairman

Page 2: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

1. Ge(o)nesis…

Page 3: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

UIGEA= States’ Rights

Page 4: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized
Page 5: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

NJ NV DE GA

10 million transactions/day250 million devices

US iGaming Licensed

Geolocation Compliance

Service Provider

Market Share

Tested and Verified by

European Division of GeoComply

Page 6: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

Verify Accuracy & Integrity: 350 Checks

Page 7: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

2. So what..?

Page 8: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

What’s The Big Deal About Geolocation?

Page 9: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

VPN Penetration By Market

Page 10: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

Do you use IP addresses to identify users, profile

risk and/or determine location for compliance?

1.2.3.4

Page 11: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

1.2.3.4

Do you use IP addresses to identify users, profile

risk and/or determine location for compliance?

• 884 datacenters offering anonymized web hosting

• 11,202 sets of distinct IP ranges

• 296,293,554 individual IP’s held by DataCenters

VPN/Proxy Gaming SiteDevices

Page 12: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

Do you use IP addresses to identify users, profile

risk and/or determine location for compliance?

• 160,604,000 (and counting!) IP v4 address held by data centers/VPN’s

• 4,294,967,296 (4.29 billion) IPV4 addresses

• 340,282,366,920,938,463,463,374,607,431,768,211,456 (2128 ≈ 3x1038)

IPV6 addresses

VPN/Proxy Gaming SiteDevices

Page 13: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

Do you use IP addresses to identify users, profile

risk and/or determine location for compliance?

• Mobile data traffic to represent 20% of total IP traffic in 2017 -

- up from just 8% of total IP traffic in 2016

• None of that has any usable geolocation data!

• Causing issues with both False Positives as well as an obvious

and easy spoofing method for fraudsters.

VPN/Proxy Gaming SiteDevices

Page 14: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

3. Case Studies

Page 15: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized
Page 16: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

Google Searches @ Launch of Pokemon GO

Page 17: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized
Page 18: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

- Recent UK research indicates that 11-

15 year-olds emerged as the group

most engaged in digital piracy

- And this group actively introduce

their parents and grandparents to the

latest “hacks” to fake location online

Page 19: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized
Page 20: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

4. Can you close the door

to VPN’s/VM’s?

Page 21: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

Multi-faceted threats require a multi-faceted response

Page 22: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized

DevicesGeoGuard Shield

GeoGuard

Proxy/Data Center/VM

Detection

Proxy Site

IP Address &

Fingerprint

Machine Learning

Closing the open door to malicious Data Center

connections is just an API away…

Page 23: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized
Page 24: “HIDING IN THE WEB” - KPMG International1.2.3.4 Do you use IP addresses to identify users, profile risk and/or determine location for compliance? • 884 datacenters offering anonymized