Friday, October 7, 2016

Identity and Access Management

Identity and Access Management

Security Principles
  1.     Availability
  2.     Integrity
  3.     Confidentiality
   
Identification -> Authentication -> Authorization -> Accountability  (IAAA)

Identification and Authentication
    One-to-One and One-to-Many
   
  •         Identification Component Requirements
  •         Access Control Review
  •         IAAA
       
    Identity Management
  •         Directories
  •         Web Access Management
  •         Password Management
  1.             Password Synchronization
  2.             Self-service password reset
  3.             Assisted password reset
           
        Legacy Single sign-on
        Account Management
        Provisioning
            Authoritative System of Record
        Profile Update
        Biometrics
  1.             Processing Speed
  2.             Fingerprint
  3.             Palm Scan
  4.             Hand Geometry
  5.             Retina Scan (Extremely Invasive and involve a number of privacy issues)
  6.             Iris Scan
  7.             Signature Dynamics
  8.             Keystroke Dynamics
  9.             Voice Print
  10.             Facial Scan
  11.             Hand Topography
        Passwords        Password Policies
  1.                 Electronic monitoring
  2.                 Access the password file
  3.                 Brute-firse attacks
  4.                 Dictionary attacks
  5.                 Social Engineering
  6.                 Rainbow table
Password Checkers            
Password Hashing and Encryption            
Password Aging            
Limit Logon Attempts            
Cogntive Password             
One-Time Password             
The Token Devices            
Synchronous (OneKey, RSA SecurID, Banking Devices)             
Asynchronous (challenge/response scheme to authenticate the user; challenge + nonce (random value) ; users enters the random value + username; encrypted sent to server; server decrypts; user authenticated)
      

Cryptographic Keys
            Passphrase
            Memory Cards
            Smart Card
            Smart Card Attacks
                Interoperability
  1.                     ISO/IEC 14443-1 Physical Characterstics
  2.                     ISO/IEC 14443-3 Initialization and anticollision
  3.                     ISO/IEC 14443-4 Transmission protocol
  •         Radio-Frequency Identification (RFID)
  •         Authorization
  •         Access Criteria
  •         Default to No Access
  •         Need to Know
            Authorization Creep
  •         Single Sign-On
  •             Kerberos
                Kerberos and Password-Guessing Attacks
  •         Security Domains
       
  •     Directory Services
        Thin Clients
  •     Federation
        Digital Identity
   
    Access Control and Markup Languages
  1.         SPML
  2.         SAML
  3.         OpenID
  4.         OAuth
  5.         Identity as a Service
  6.         Integrated Identity Services
  7.         Establishing Connectivity
  8.         Esatblishing Trust
  9.         Incremental Testing
       
    Access Control Models
        DAC - Discretionary Access Control
            Identity-Based Access Control
        MAC - Mandatory Access Control
            Sensitivity Levels
        RBAC - Role-Based Access Control
            Core RBAC
            Hierarchical RBAC
                Limited Hierarchy
                Gerneral Hierarchy
                Static Separation of Duty (SSD) Relations through RBAC
                Dynamic Separation of Duties (DSD) Relations through RBAC
        RB-RBAC - Rule-Based Access Control
   
    Access Control Techniques and Technologies
  1.         Contrained User Interfaces
  2.         Access Control Matrix
  3.         Capability Table
  4.         Access Control Lists
  5.         Content-Dependent Access Control
  6.         Context-Dependent Access Control
   
    Access Control Administration
        Centralized Access Control Administration
        RADIUS - Remote Authentication Dial-In User Service
        TACACS - Terminal Access Controller Access Control System
        Diameter (protocol)
            Mobile IP
        Decentralized Access Control Administration
       
    Access Control Methods
        Access Control Layers
            Administrative controls
                Personnel Controls
                Supervisory Structure
                Security-Awareness Training
                Testing
            Physical controls
                Network Segregation
                Perimeter Security
                Computer Controls
                Work Area Separation
                Cabling
                Control Zone
            Technical controls
                System Access
                Network Architecture
                Network Access
                Encryption and Protocols
                Auditing
   
    Accountability
        Review of Audit Information
        SEM & SIEM
        Protecing Audit Data and Log Information
        Keystroke Monitoring
       
    Access Control Practices
        Unauthorized Disclosure of Information
        Object Reuse
        Emanation Security
        TEMPEST
        White Noise
        Control Zone
   
    Access Control Monitoring
        IDS - Intrusion Detection Systems
        Network-Based IDSs
        Host-Based IDSs            Signature-based
                Pattern matching
                Stateful matching
            Anamoly-based
                Statistical anamoly-based
                Protocol anamoly-based
                Traffic anamoly-based
                Rule- or heuristic-based
        Knowledge- or Signature-Based Intrusion Detection
        State-Based IDSs
        Statistical Anamoly-Based IDS
        Protocol Anamoly-Based IDS
        Traffic Anamoly-Based IDS
        Rule-Based IDS
        IDS Sensors
        Network Traffic       
        IPS - Intrusion Prevention Systems
  1.             Switched Environments
  2.             Honeypot
  3.             Intrusion Responses
  4.             Network Sniffers
           
    Threats to Access Control
        Dictionary Attack
            Countermeasures
        Brute-Force Attacks
            Countermeasures
        Spoofing at Logon
        Phishing and Pharming
  1.             Spear-phishing
  2.             Whaling