NuDetect
In today’s digital world, we understand preventing and stopping automated fraud. With increasing numbers of account takeovers, automated attacks, and new account fraud, our integration partnership with NuData Security, a Mastercard company, offers you the technology necessary to validate your real end users from fraudsters.
How does it work?
NuDetect is a behavioral analysis product that utilizes tracked end user behavioral data to determine fraudulent activity and assigning it a “score.” As an admin user, configuring your NuDetect settings gives you the ability to set and enforce a score threshold that will trigger a risk event on suspicious and fraudulent activity. For example, if an end user’s activity is given a score of 300 (red) and the institution has a score threshold of 225 (yellow), then the end user’s session would require extra authorization through 2FA.
- Settings
- Nudetect
- Score configuration
The numeric score returned by Mastercard NuDetect indicates the level of risk. Scores that are equal to or above the configured threshold triggers a risk event that is different depending on the location.
- Login
- Suspicious traffic: A score equal to or above this number triggers the end user to complete 2FA (even if the end user previously checked Remember Me). While Mastercard recommends setting a score at or less than 200, we suggest you start with a score slightly higher based on your institution’s existing traffic.
Fraudulent traffic: A score equal to or above this number prevents the end user from logging in to Banno Apps. This score should be set higher than the Suspicious traffic score and high enough that only obvious fraudulent activity is blocked. If login is blocked for a suspected fraudster or bot, an error message displays on the login page stating, We couldn’t find you. Please check the information that you provided and try again, with the option for the end user to select a Call now button or OK button. In the rare event that a legitimate end user is blocked, there’s no way to unblock the individual, because our typical methods—–manually resetting enrollment or self-serve account recovery—–are unavailable. Instead, the end user needs to work with your institution to understand why they have a high NuDetect score so they can take measures to lower their score.
- Enrollment
- A score equal to or above this number prevents the end user from proceeding to enroll. When recovery fails, the following 403 error displays to the end user: Oops! Something went wrong on our end. Please try again. While Mastercard recommends setting a score at or less than 500, we suggest you start with a score slightly higher based on your institution’s existing traffic.
- Recovery
- A score equal to or above this number prevents the end user from recovering an account. When recovery fails, the following 403 error displays to the end user: We couldn’t find that for you. Please check the information that you provided and try again. If you haven’t enrolled yet, try that instead. While Mastercard recommends setting a score at or less than 500, we suggest you start with a score slightly higher based on your institution’s existing traffic.
- High risk prompt
- A score equal to or above this number prevents the end user from proceeding through the high risk action, deauthorizes the device, and forces the user back out to the login to reauthorize by logging in. By deauthorizing the device, the user will be forced to re-enter a new 2FA code. Traffic passing through the High Risk Prompt will be displayed as “AuthorizeHighRisk”.
As you become more comfortable with the NuDetect platform, we suggest you eventually adjust scores closer to Mastercards’ recommendations.
Tracking biometric and PIN logins on Banno Mobile
Made available to everyone in early 2025, institutions can track biometric and PIN logins on Banno Mobile. Previously, only full logins (accessing from Banno Online or entering username and password on Mobile) were tracked, but now every time a user accesses Banno Apps, you have the ability to send that data to NuDetect. Not only will this improve NuDetect’s picture of your users’ behavior, it also makes all of the Mobile activity available within the NuDetect portal.
Important considerations
Due to the potential increase in tracked mobile sessions, this feature could impact your overall session volume and potentially affect your billing. To give you complete control:
- This feature is turned OFF by default, no support case needed.
- You can easily enable it within your existing NuDetect settings in Banno People.
- If you notice a significant increase in sessions and wish to adjust, you can simply disable the feature.
Resources & training
In addition to utilizing NuDetect within Banno People, a separate dashboard through NuDetect displays detailed analytics surrounding end user interactions in your digital environments. This video demo will help train you on how to drill into events and their impacts, filter data, build rules using the configuration engine, and much more. You can also watch the video demo separated into the following sections:
FAQ
- How does a blacklisted IP impact configured NuDetect scores?
- After adding a blacklist IP, Mastercard adds an automatic 500 score on top of the configured score. For example, if you have a 200 score set at login, it will effectively be a 700 score if it’s blacklisted.
- How does an end user lower their score?
- Please refer to your NuDetect documentation for information on score responses and behavioral signals.
- What happens to a user if they exceed a set score on a high risk prompt?
- After the user tries to enter their password, they will receive a 403 error stating: “For security purposes, you’ll need to sign-in again.” They will then be pushed back to the login and their device will be de-authorized. Meaning they will need to re-authorize their session and the device by entering their password and 2FA code.
- How can I correlate sessions in NuDetect with users in Banno?
- Within NuDetect portals, the Account value (often presented as a column header) is populated with your user’s username. You can investigate activity within Banno People and correlate it easily with sessions within NuDetect portals with that username, and vice versa.
- How can I manage blocklists and allowlists?
- This can be done within NuDetect’s legacy portal.
- How do blocklists and allowlists affect one another?
- White/Allowlist takes priority over Black/Blocklist. If a country is blocklisted, a user can be allowed by entering one of their datapoints (Account/username, DeviceId, etc.) into the white/allowlist. It would be wise to only do this temporarily, however.
- How will enabling tracking of biometric and PIN logins on Banno Mobile affect our account holders?
- If an account holder has only been logging in using biometrics/PIN without completing a full login or attempting a high risk action, their device will be considered a new device in NuDetect, and a score of 100 will be added. Normal usage will then level off the score. It may be worth raising your thresholds for a short time after enabling biometric/PIN tracking to account for this, or simply keeping a closer eye on scores.