Aggregators are third-party vendors who provide account aggregation services by collating login information of users across multiple enterprises. The originating IP addresses when users log in from a protected portal versus when they come in through such aggregators are different. Many enterprises use the services of these account and data aggregation service providers to expand their online reach.
Transactions originating from (or routed through) aggregators "trusted" to the organization are considered low-risk. For this purpose, RiskMinder provides the ability to configure a list of these aggregators so that all transactions originating from the aggregators’ IP addresses are assigned a low Score, and the ALLOW Advice.
RiskMinder uniquely identifies an aggregator by combining their IP address range and a unique Aggregator ID. This Aggregator ID must also be sent to RiskMinder along with the transaction.
RiskMinder also enables you to specify up to three unique IDs for each aggregator at any time. This allows for the periodical rotation of the ID for the purpose of enhanced security. During this rotation, RiskMinder continues to recognize the previous ID in addition to the new ID to allow updates to the aggregator at a later time.
Use the Manage List Data and Category Mappings page to perform the following tasks related to trusted aggregators:
To add a trusted aggregator, perform the following tasks:
The Manage List Data and Category Mappings page is displayed.
The ruleset configuration information is displayed.
The updated Trusted Aggregator Configuration page appears.
The Trusted IP List table with the range that you just added for the aggregator appears at the end of the page.
The changes are not yet active and are not available to your end users.
See "Migrating to Production" for instructions to do so.
RiskMinder enables you to update the Aggregator IDs. The periodic update of these IDs is referred to as rotation of Aggregator IDs.
Important! Periodic rotation or change of the Aggregator IDs is recommended for security purposes. You can decide this rotation duration according to your business rules.
After an ID is updated, you must ensure that the latest Aggregator ID is conveyed to the aggregator. There might be a delay in propagating the Aggregator IDs. In this duration, RiskMinder recognizes the old, as well as the new Aggregator ID associated with the IP address.
Note: The transactions originating from the aggregator-end must contain this aggregator ID in the form specified by RiskMinder APIs.
To update an aggregator ID:
The Trusted Aggregator Configuration information with the Aggregator ID(s) for the selected aggregator appears.
The updated Aggregator ID(s) for the aggregator appears, and the next empty Aggregator ID is displayed.
The changes are not yet active and are not available to your end users.
See "Migrating to Production" for instructions to do so.
To delete a trusted aggregator, perform the following tasks:
The Trusted Aggregator Configuration information appears.
The changes are not yet active and are not available to your end users.
See "Migrating to Production" for instructions to do so.
|
Copyright © 2013 CA.
All rights reserved.
|
|