Active Directory
Microsoft developed a directory service for a Microsoft Domain network and this directory service is referred to as Active Directory. It is included in most Windows Server Operating Systems as a set of processes and services.
Active Directory uses Lightweight Directory Access Protocol (LDAP) versions 2 and 3, Microsoft's version of Kerberos, and DNS.
To understand above sentences we need to understand what Directory Service, Microsoft Domain, Domain Controller is. Lets find out what it is.
Directory Service
To administer, manage, locate and organize everyday items and network resources we require a share information infrastructure. Everyday items and network resources can include any or all of files, folders, users, groups, printers, volumes, devices, telephone numbers and other objects.
Directory Service is a service or infrastructure to map the names of network resources to their respective network addresses. It is a critical component of a network operating system. Such service is provided by a server and that server is known as directory server. Each network resources is called object.
What directory service does is, it defines a namespace for the network. Namespace assigns a name, called unique identifier, to each of above mentioned objects. Directories have a set of rules determining how network resources are named and identified; basic requirement is that the identifiers need to be unique and unambiguous.
When user uses a directory services there is no need for user to remember the physical address of a network resource. User can locate the resource using name. However, some directory services may include access control mechanism which could limit the accessibility and availability of directory information to authorized users.
Microsoft Domain
Microsoft domain is a computer network in which all user accounts, computers, printers and other security principals are registered with a central database located on one or more clusters of central computers known as domain controllers. Authentication takes place on domain controllers.
Each user who uses computers within a domain receives a unique user account that can be assigned access to resources within the domain. Active directory is the Windows component in charge of maintaining that central database.
Domain Controller
On Microsoft Servers, a domain controller (DC) is a server computer that responds to security authentication requests (logging in, checking permissions, etc.) within a Windows domain.
In other words, a server running Active Directory Domain Services (AD DS) is called a domain controller. It authenticates and authorizes all users and computers in a Windows Domain type network. It assigns and enforces security policies for all computers and installing or updating software.
Example:
When a user logs into a computer that is part of windows domain, Active Directory is the one that checks thus submitted password and determines whether the user is a system administrator or normal user. Also, it allows management and storage of information at admin level and provides authentication and authorization mechanisms.
Lightweight Directory Access Protocol (LDAP)
The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.
This blog contains notes from different learning sites. This notes falls in Information Security, Cyber Security, Network Security and other Security Domain class. Any suggestion to make this site helpful is truly welcome :)
Showing posts with label Authentication. Show all posts
Showing posts with label Authentication. Show all posts
Wednesday, March 4, 2020
Saturday, February 1, 2020
Windows Server: Active Directory and its Fundamentals
Active Directory
Microsoft developed a directory service for a Microsoft Domain network and this directory service is referred to as Active Directory. It is included in most Windows Server Operating Systems as a set of processes and services.
Active Directory uses Lightweight Directory Access Protocol (LDAP) versions 2 and 3, Microsoft's version of Kerberos, and DNS.
To understand above sentences we need to understand what Directory Service, Microsoft Domain, Domain Controller is. Lets find out what it is.
Directory Service
To administer, manage, locate and organize everyday items and network resources we require a share information infrastructure. Everyday items and network resources can include any or all of files, folders, users, groups, printers, volumes, devices, telephone numbers and other objects.
Directory Service is a service or infrastructure to map the names of network resources to their respective network addresses. It is a critical component of a network operating system. Such service is provided by a server and that server is known as directory server. Each network resources is called object.
What directory service does is, it defines a namespace for the network. Namespace assigns a name, called unique identifier, to each of above mentioned objects. Directories have a set of rules determining how network resources are named and identified; basic requirement is that the identifiers need to be unique and unambiguous.
When user uses a directory services there is no need for user to remember the physical address of a network resource. User can locate the resource using name. However, some directory services may include access control mechanism which could limit the accessibility and availability of directory information to authorized users.
Microsoft Domain
Microsoft domain is a computer network in which all user accounts, computers, printers and other security principals are registered with a central database located on one or more clusters of central computers known as domain controllers. Authentication takes place on domain controllers.
Each user who uses computers within a domain receives a unique user account that can be assigned access to resources within the domain. Active directory is the Windows component in charge of maintaining that central database.
Domain Controller
On Microsoft Servers, a domain controller (DC) is a server computer that responds to security authentication requests (logging in, checking permissions, etc.) within a Windows domain.
In other words, a server running Active Directory Domain Services (AD DS) is called a domain controller. It authenticates and authorizes all users and computers in a Windows Domain type network. It assigns and enforces security policies for all computers and installing or updating software.
Example:
When a user logs into a computer that is part of windows domain, Active Directory is the one that checks thus submitted password and determines whether the user is a system administrator or normal user. Also, it allows management and storage of information at admin level and provides authentication and authorization mechanisms.
Lightweight Directory Access Protocol (LDAP)
The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.
Microsoft developed a directory service for a Microsoft Domain network and this directory service is referred to as Active Directory. It is included in most Windows Server Operating Systems as a set of processes and services.
Active Directory uses Lightweight Directory Access Protocol (LDAP) versions 2 and 3, Microsoft's version of Kerberos, and DNS.
To understand above sentences we need to understand what Directory Service, Microsoft Domain, Domain Controller is. Lets find out what it is.
Directory Service
To administer, manage, locate and organize everyday items and network resources we require a share information infrastructure. Everyday items and network resources can include any or all of files, folders, users, groups, printers, volumes, devices, telephone numbers and other objects.
Directory Service is a service or infrastructure to map the names of network resources to their respective network addresses. It is a critical component of a network operating system. Such service is provided by a server and that server is known as directory server. Each network resources is called object.
What directory service does is, it defines a namespace for the network. Namespace assigns a name, called unique identifier, to each of above mentioned objects. Directories have a set of rules determining how network resources are named and identified; basic requirement is that the identifiers need to be unique and unambiguous.
When user uses a directory services there is no need for user to remember the physical address of a network resource. User can locate the resource using name. However, some directory services may include access control mechanism which could limit the accessibility and availability of directory information to authorized users.
Microsoft Domain
Microsoft domain is a computer network in which all user accounts, computers, printers and other security principals are registered with a central database located on one or more clusters of central computers known as domain controllers. Authentication takes place on domain controllers.
Each user who uses computers within a domain receives a unique user account that can be assigned access to resources within the domain. Active directory is the Windows component in charge of maintaining that central database.
Domain Controller
On Microsoft Servers, a domain controller (DC) is a server computer that responds to security authentication requests (logging in, checking permissions, etc.) within a Windows domain.
In other words, a server running Active Directory Domain Services (AD DS) is called a domain controller. It authenticates and authorizes all users and computers in a Windows Domain type network. It assigns and enforces security policies for all computers and installing or updating software.
Example:
When a user logs into a computer that is part of windows domain, Active Directory is the one that checks thus submitted password and determines whether the user is a system administrator or normal user. Also, it allows management and storage of information at admin level and provides authentication and authorization mechanisms.
Lightweight Directory Access Protocol (LDAP)
The Lightweight Directory Access Protocol (LDAP) is an open, vendor-neutral, industry standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network.
Thursday, January 9, 2020
CISSP: Other Security Concepts
Other Security Concepts
- Identification:Claiming to be an identity when attempting to access a secured area or system. E.g. username
- Authentication: Proving that you are that identity. E.g. password
- Authorization: Defining the permissions (i.e., allow/grant and/or deny) of a resource and object access for a specific identity
- Auditing: Recording a log of the events and activities related to the system and subjects
- Accounting(aka accountability): Reviewing logs files to check for compliance and violations in order to hold subjects accountable for their actions. Human accountability is ultimately dependent on the strength of the authentication process.
Note: Identification, Authentication and Auditing are required to establish Accountability.
Tuesday, January 2, 2018
Cryptography: AAA - Authentication
Another important cybersecurity model is the AAA or triple A model, which doesn't have anything to do with the American Automobile Association :D
The first A refers to authentication, which is the process of proving you are who you say you are. When you claim you are someone, that's called identification. When you prove it, that's authentication. If I drove from Rochester to Canada and told the border patrol, "I'm Jonathan S. Wiseman, let me into Canada," I would get some strange looks at the very least. Authentication requires proof in one of three possible forms:
Using two passwords is not multifactor authentication because they both fall under the same something you know category. It's like putting two locks on your door at home that could be opened with the same key. There was a belief at some point that biometrics would simply replace passwords. But especially with all the data breaches in recent years, it's very clear that while you can change your password, you simply cannot change your biometrics. If your biometrics are stolen, then what? You also lose anonymity when using credentials that are directly tied to you. Your profile can easily be constructed, tied to all your actions, linking together everything you do and everywhere you go in cyberspace. Not that sharing credentials is necessarily a good thing, but if you temporarily had to, for instance, in an emergency situation and biometrics was the only option, then what would you do? What happens when you grow a beard and the biometric authentication fails? False positives and false negatives are legitimate issues and could restrict or even allow access in error.
These are the most compelling arguments for a combination of authentication methods known as 2FA or two-factor authentication. Many companies like Google, LinkedIn, and banks have recently enabled their sites for this 2FA system. Sending codes to your phone through SMS, short message service -- text messages -- you use these codes that are texted to your phone in addition to a password to access an account. NIST, the National Institute of Standards and Technology subsequently denounced two-factor authentication through text messages. They stated that 2FA with SMS should be deprecated immediately due to the fact that SMS messages can be intercepted or redirected. NIST recommended other options like Google authenticator or even certain USB dongles. However, Google, Twitter, Facebook, and tons of other major websites are still using text messages for two-factor authentication today. NIST's demand at least to this point has been completely ignored by both companies and their users.
The first A refers to authentication, which is the process of proving you are who you say you are. When you claim you are someone, that's called identification. When you prove it, that's authentication. If I drove from Rochester to Canada and told the border patrol, "I'm Jonathan S. Wiseman, let me into Canada," I would get some strange looks at the very least. Authentication requires proof in one of three possible forms:
- Something you know, like a password;
- something you have, like a key fob;
- something you are -- biometrics.
Using two passwords is not multifactor authentication because they both fall under the same something you know category. It's like putting two locks on your door at home that could be opened with the same key. There was a belief at some point that biometrics would simply replace passwords. But especially with all the data breaches in recent years, it's very clear that while you can change your password, you simply cannot change your biometrics. If your biometrics are stolen, then what? You also lose anonymity when using credentials that are directly tied to you. Your profile can easily be constructed, tied to all your actions, linking together everything you do and everywhere you go in cyberspace. Not that sharing credentials is necessarily a good thing, but if you temporarily had to, for instance, in an emergency situation and biometrics was the only option, then what would you do? What happens when you grow a beard and the biometric authentication fails? False positives and false negatives are legitimate issues and could restrict or even allow access in error.
These are the most compelling arguments for a combination of authentication methods known as 2FA or two-factor authentication. Many companies like Google, LinkedIn, and banks have recently enabled their sites for this 2FA system. Sending codes to your phone through SMS, short message service -- text messages -- you use these codes that are texted to your phone in addition to a password to access an account. NIST, the National Institute of Standards and Technology subsequently denounced two-factor authentication through text messages. They stated that 2FA with SMS should be deprecated immediately due to the fact that SMS messages can be intercepted or redirected. NIST recommended other options like Google authenticator or even certain USB dongles. However, Google, Twitter, Facebook, and tons of other major websites are still using text messages for two-factor authentication today. NIST's demand at least to this point has been completely ignored by both companies and their users.
Monday, March 13, 2017
Cryptography: Authentication and Access Control
An organization makes each lead system administrator responsible
for the security of the system he or she runs. However, the management
determines what programs are to be on the system and how they are to be
configured.


- Describe the security problem(s) that this division of power would create.
- How would you fix them?
Thursday, June 25, 2015
Usable Security - Authentication
1. Fingerprint recognition is generally faster than password entry for authentication.
2. Following are measures of usability for authentication systems:
4. Smudge Attack: On phone that touched the face it was easiest to find password information.
5. Typing in a numeric code on a keypad is not a type of gesture based authentication.
6. Following are type of gesture based authentication:
10. Most secure passwords are collection of words like: I am not Easy T0 Find
instead of likes:
2. Following are measures of usability for authentication systems:
- Speed
- How easy it is to learn
- Likelihood of error
4. Smudge Attack: On phone that touched the face it was easiest to find password information.
5. Typing in a numeric code on a keypad is not a type of gesture based authentication.
6. Following are type of gesture based authentication:
- Connecting dots on a grid
- Drawing a signature on a touch screen
- Swiping multiple fingers in a line or shape
- From an app designed to create codes
- In a text message
- Off a device that generates codes
- Facial recognition
- Free gesture
- Voice analysis
10. Most secure passwords are collection of words like: I am not Easy T0 Find
instead of likes:
- dz&w4%lfc
- hello etc.
Subscribe to:
Posts (Atom)