Skip to content

Latest commit

 

History

History
84 lines (68 loc) · 5.17 KB

File metadata and controls

84 lines (68 loc) · 5.17 KB

Logo

Domain 5 - Identity and Access Management

Elevator pitch

Who are you? How do I verify who you are, and once I do, what should I allow you to do, and how do I ensure

Topics

Type 1 Authentication: Something you know

Passwords

  • Static passwords: A password that doesnt' change over time.
  • Dynamic Passowrds: Passwords taht are changed on regular intervals e.g. LAPS
  • One-time passwords: A variant of dynamic passwords that's changed every time it is used.
  • Passphrases: a 'longer' password e.g. natural language sentences "I have a plan. Attack!"
  • Salts: A random value added to a password prior to hashing, which will encrypt differently.

Password Attacks

  • Dictionary: A word list, e.g. rockyou.txt
  • Hybrid Attack: appends, prepends or changes characters in words from a dictionary before hashing
  • Brute Force: calculates hash outputs for every possible password
  • Rainbow Tables: a database that contains the precomputed hashed output for most or all passwords

Type 2 Authentication: Something you have

  • Synchronous dynamic password token: Generates passwords at fixed time intervals. Entered along with a passphrase or password.
  • Asynchronoous dynamic password token: Generates onetime passwords after the user enters a PIN in the token device.

Type 3 Authentication: Something you are

Biometric Systems and Accuracy

  • False Acceptance Rate (FAR): unauthorized subjects are accepted as valid
  • False Rejection Rate (FRR): authorized subjects are rejected.
  • Crossover Error Rate (CER): the point where FAR and FRR are equal. This describes the overall accuracy of the system

Access Control models

  • Rule-Based: Much broader scenarios than individual subjects accessing objects e.g. a Firewall – RBAC: Role Based Access Control. Defined rules or restrictions for accesing objects in a system
  • DAC: Users have direct control over all programs and files
  • MAC: Opposite of DAC. Using a policy or Hardware/Software component to restrict access

Identity Managemnet

  • Federated Identity Management: applies SSO at a wider scale ranging from cross-organiztional to Internet scale.
  • SAML: An XML based framework for exchanging security information
  • LDAP: A common open protocol for interfacing and querying directory service informaiton provided by network operating systems.
  • Kerberos: Authentication service used to support SSO using symmetric encryption providing mutual authentication of clients and servers

Kerberos Components

  • Principal: Client (user) or service
  • Realm: A logical Kerberos network
  • ticket: Data authenticating a principal's identity
  • Credentials: A ticket and service key
  • KDC: Key Distribution Center, authenticates principles
  • TGS: Ticket Granting Service
  • TGT: Ticket Granting Ticket
  • C/S: Client Server, regarding communications between the two

Kerberos Steps

AAA (Auentication, Authorization, Accounting)

  • It refers to five elements: Identification, authentication, authorization, auditing, and accounting.
  • Authentication: The process of verifyhing or testing the identity claimed by a subject is valid.
  • Authorization: The process ensuring the subject accessing the object has the necessary rights and privileges.
  • Accounting: The process of holding someone responsible for something. Accoutability is possible if a subject's identity and actions can be tracked and verified.

Access Control Protocols

  • RADIUS: Remote Authentication Dial In User Servcie. An AAA system comuunicating over UDP (ports 1812, 1813).
  • Diameter: A successor to RADIUS
  • TACACS/TACACS+: Terminal access controller access control system. A centralized access control system requiring users to sen4d and ID and static password for authentication. TACACS+ allows for two-factor strong authentication. Uses UDP (port 49). TACACS+ uses TCP (port 49)
  • PAP/CHAP: PAP (Password Authentication Protocol) is insecure as passwords are sent in clear text. CHAP (Challenge Handshake Authentication Protocol). Provides protection against playback attacks.

Useful Links