Showing posts with label Authentication. Show all posts
Showing posts with label Authentication. Show all posts

Wednesday, March 4, 2020

Windows Server: Active Directory and its Fundamentals

Active Directory
Microsoft developed a directory service for a Microsoft Domain network and this directory service is referred to as Active Directory. It is included in most Windows Server Operating Systems as a set of processes and services.
Active Directory uses Lightweight Directory Access Protocol (LDAP) versions 2 and 3, Microsoft's version of Kerberos, and DNS.


To understand above sentences we need to understand what Directory Service, Microsoft Domain, Domain Controller is. Lets find out what it is.

Directory Service
To administer, manage, locate and organize everyday items and network resources we require a share information infrastructure. Everyday items and network resources can include any or all of files, folders, users, groups, printers, volumes, devices, telephone numbers and other objects. 
Directory Service is a service or infrastructure to map the names of network resources to their respective network addresses. It is a critical component of a network operating system. Such service is provided by a server and that server is known as directory server. Each network resources is called object.
What directory service does is, it defines a namespace for the network. Namespace assigns a name, called unique identifier, to each of above mentioned objects. Directories have a set of rules determining how network resources are named and identified; basic requirement is that the identifiers need to be unique and unambiguous.
When user uses a directory services there is no need for user to remember the physical address of a network resource. User can locate the resource using name. However, some directory services may include access control mechanism which could limit the accessibility and availability of directory information to authorized users.


Microsoft Domain
Microsoft domain is a computer network in which all user accounts, computers, printers and other security principals are registered with a central database located on one or more clusters of central computers known as domain controllers. Authentication takes place on domain controllers.
Each user who uses computers within a domain receives a unique user account that can be assigned access to resources within the domain. Active directory is the Windows component in charge of maintaining that central database.

Domain Controller
On Microsoft Servers, a domain controller (DC) is a server computer that responds to security authentication requests (logging in, checking permissions, etc.) within a Windows domain.
In other words, a server running Active Directory Domain Services (AD DS) is called a domain controller. It authenticates and authorizes all users and computers in a Windows Domain type network. It assigns and enforces security policies for all computers and installing or updating software.


Example: 
When a user logs into a computer that is part of windows domain, Active Directory is the one that checks thus submitted password and determines whether the user is a system administrator or normal user. Also, it allows management and storage of information at admin level and provides authentication and authorization mechanisms.

Lightweight Directory Access Protocol (LDAP)
The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

Saturday, February 1, 2020

Windows Server: Active Directory and its Fundamentals

Active Directory
Microsoft developed a directory service for a Microsoft Domain network and this directory service is referred to as Active Directory. It is included in most Windows Server Operating Systems as a set of processes and services.
Active Directory uses Lightweight Directory Access Protocol (LDAP) versions 2 and 3, Microsoft's version of Kerberos, and DNS.


To understand above sentences we need to understand what Directory Service, Microsoft Domain, Domain Controller is. Lets find out what it is.

Directory Service
To administer, manage, locate and organize everyday items and network resources we require a share information infrastructure. Everyday items and network resources can include any or all of files, folders, users, groups, printers, volumes, devices, telephone numbers and other objects. 
Directory Service is a service or infrastructure to map the names of network resources to their respective network addresses. It is a critical component of a network operating system. Such service is provided by a server and that server is known as directory server. Each network resources is called object.
What directory service does is, it defines a namespace for the network. Namespace assigns a name, called unique identifier, to each of above mentioned objects. Directories have a set of rules determining how network resources are named and identified; basic requirement is that the identifiers need to be unique and unambiguous.
When user uses a directory services there is no need for user to remember the physical address of a network resource. User can locate the resource using name. However, some directory services may include access control mechanism which could limit the accessibility and availability of directory information to authorized users.

Further your career! 

Microsoft Domain
Microsoft domain is a computer network in which all user accounts, computers, printers and other security principals are registered with a central database located on one or more clusters of central computers known as domain controllers. Authentication takes place on domain controllers.
Each user who uses computers within a domain receives a unique user account that can be assigned access to resources within the domain. Active directory is the Windows component in charge of maintaining that central database.

Domain Controller
On Microsoft Servers, a domain controller (DC) is a server computer that responds to security authentication requests (logging in, checking permissions, etc.) within a Windows domain.
In other words, a server running Active Directory Domain Services (AD DS) is called a domain controller. It authenticates and authorizes all users and computers in a Windows Domain type network. It assigns and enforces security policies for all computers and installing or updating software.

Udemy Generic 300x250 

Example: 
When a user logs into a computer that is part of windows domain, Active Directory is the one that checks thus submitted password and determines whether the user is a system administrator or normal user. Also, it allows management and storage of information at admin level and provides authentication and authorization mechanisms.

Lightweight Directory Access Protocol (LDAP)
The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.

Thursday, January 9, 2020

CISSP: Other Security Concepts


Other Security Concepts

  • Identification:Claiming to be an identity when attempting to access a secured area or system. E.g. username
  • Authentication: Proving that you are that identity. E.g. password
  • Authorization: Defining the permissions (i.e., allow/grant and/or deny) of a resource and object access for a specific identity
  • Auditing: Recording a log of the events and activities related to the system and subjects
  • Accounting(aka accountability): Reviewing logs files to check for compliance and violations in order to hold subjects accountable for their actions. Human accountability is ultimately dependent on the strength of the authentication process.


Note: Identification, Authentication and Auditing are required to establish Accountability.

Tuesday, January 2, 2018

Cryptography: AAA - Authentication

 Another important cybersecurity model is the AAA or triple A model, which doesn't have anything to do with the American Automobile Association :D

The first A refers to authentication, which is the process of proving you are who you say you are. When you claim you are someone, that's called identification. When you prove it, that's authentication. If I drove from Rochester to Canada and told the border patrol, "I'm Jonathan S. Wiseman, let me into Canada," I would get some strange looks at the very least. Authentication requires proof in one of three possible forms:
  • Something you know, like a password; 
  • something you have, like a key fob; 
  • something you are -- biometrics. 
When you combine more than one of these categories, that's called multifactor authentication, and that really is the future of authentication. Multifactor authentication makes it really hard to authenticate as someone else -- impersonating them. Because if a hacker steals your password, he'd also have to possess a small key fob with a code that rotates in parallel with code on the server you're logging into. Or he'd need your iris, retina, or hand geometry.


Using two passwords is not multifactor authentication because they both fall under the same something you know category. It's like putting two locks on your door at home that could be opened with the same key. There was a belief at some point that biometrics would simply replace passwords. But especially with all the data breaches in recent years, it's very clear that while you can change your password, you simply cannot change your biometrics. If your biometrics are stolen, then what? You also lose anonymity when using credentials that are directly tied to you. Your profile can easily be constructed, tied to all your actions, linking together everything you do and everywhere you go in cyberspace. Not that sharing credentials is necessarily a good thing, but if you temporarily had to, for instance, in an emergency situation and biometrics was the only option, then what would you do? What happens when you grow a beard and the biometric authentication fails? False positives and false negatives are legitimate issues and could restrict or even allow access in error.

These are the most compelling arguments for a combination of authentication methods known as 2FA or two-factor authentication. Many companies like Google, LinkedIn, and banks have recently enabled their sites for this 2FA system. Sending codes to your phone through SMS, short message service -- text messages -- you use these codes that are texted to your phone in addition to a password to access an account. NIST, the National Institute of Standards and Technology subsequently denounced two-factor authentication through text messages. They stated that 2FA with SMS should be deprecated immediately due to the fact that SMS messages can be intercepted or redirected. NIST recommended other options like Google authenticator or even certain USB dongles. However, Google, Twitter, Facebook, and tons of other major websites are still using text messages for two-factor authentication today. NIST's demand at least to this point has been completely ignored by both companies and their users.

Monday, March 13, 2017

Cryptography: Authentication and Access Control

An organization makes each lead system administrator responsible for the security of the system he or she runs. However, the management determines what programs are to be on the system and how they are to be configured.

  • Describe the security problem(s) that this division of power would create. 
Security mechanism in a company depends on who is responsible for the company’s security. The power to implement appropriate controls must reside with those who are responsible. If management determines what programs are to be on the system, then the system administrators who are responsible for the security, who see the need for security measures will be unable to implement the appropriate security measures. Since management is not aware of the technical aspects of security as much as system administrators it’s possible for management to make some poor choices with regard to cost, resources, security measures. Also coordination among the system coordinators is also pivotal in an organization and this coordination might be compromised if management makes the key security decisions.
Coursera DS Design 10Coursera AH Purple Design 2Coursera General Design 2 Green
  • How would you fix them? 
The problem can be fixed by providing system administrators (knowledgeable people) with more control and sufficient resources for administering computer systems. Management should consult the system administrators before making any decision on security issues. If the company has several divisions each should have separate system administrator then the company can have one security head who is knowledged about security issues and who heads all the systems administrators. Management should leave all the key security decisions to him. Security head should take care of delegating the appropriate security tasks to the concerned system administrators. Part of the management role requires them to know about the cost, resources, security polices etc, and management can get up to date about these by consulting the security head.


Career skills to jumpstart your future.  Start your future with a Business Analytics Certificate.

Thursday, June 25, 2015

Usable Security - Authentication

1. Fingerprint recognition is generally faster than password entry for authentication.
banner  
2. Following are measures of usability for authentication systems:
  • Speed
  • How easy it is to learn
  • Likelihood of error
3. Limitations on the number of incorrect logins in a fixed time frame improves security of a traditional password system.
4. Smudge Attack: On phone that touched the face it was easiest to find password information.
5. Typing in a numeric code on a keypad is not a type of gesture based authentication.
6. Following are type of gesture based authentication:
  • Connecting dots on a grid
  • Drawing a signature on a touch screen
  • Swiping multiple fingers in a line or shape
7. Following are method for obtaining a second factor authentication code:
  • From an app designed to create codes
  • In a text message
  • Off a device that generates codes
8. Following are type of biometric authentication:
  • Facial recognition
  • Free gesture
  • Voice analysis
9. Two factor authentication DOES NOT improve the security and usability of a system.
10. Most secure passwords are collection of words like: I am not Easy T0 Find 
instead of likes:
  • dz&w4%lfc
  • hello etc.