官术网_书友最值得收藏!

The credentials – authentication and authorization

According to Verizon's 2017 Data Breach Investigations Report (9), the association between threat actor (or just actor), their motives and their modus operandi vary according to the industry. However, the report states that stolen credentials is the preferred attack vector for financial motivation or organized crime. This data is very important, because it shows that threat actors are going after user's credentials, which leads to the conclusion that companies must focus specifically on authentication and authorization of users and their access rights.

The industry agreed that a user's identity is the new perimeter. This requires security controls specifically designed to authenticate and authorize individuals based on their job and need for specific data within the network. Credential theft could be just the first step to enable cybercriminals to have access to your system. Having a valid user account in the network will enable them to move laterally (pivot), and at some point find the right opportunity to escalate privilege to a domain administrator account. For this reason, applying the old concept of defense in depth is still a good strategy to protect a user's identity, as shown in the following diagram:

Here, there are multiple layers of protection, starting with the regular security policy enforcement for accounts, which follow industry best practices such as strong password requirements, a policy requiring frequent password changes, and password strength. Another growing trend to protect user identities is to enforce MFA. One method that is having increased adoption is the callback feature, where the user initially authenticates using his/her credentials (username and password), and receives a call to enter their pin. If both authentication factors succeed, they are authorized to access the system or network. We are going to explore this topic in greater detail in Chapter 6, Chasing User's Identity.

主站蜘蛛池模板: 内乡县| 台中县| 民县| 夏邑县| 呼伦贝尔市| 长汀县| 嘉义市| 乌鲁木齐县| 威远县| 岚皋县| 凌源市| 长寿区| 兴海县| 阿克| 塔河县| 泸溪县| 蒲城县| 丹东市| 昌图县| 阿巴嘎旗| 柳州市| 南丰县| 高唐县| 延津县| 陇川县| 慈利县| 远安县| 泰安市| 普陀区| 贡山| 乌什县| 大关县| 华宁县| 郴州市| 海城市| 屯门区| 苍南县| 彰化市| 石林| 江西省| 普定县|