Showing posts with label System security. Show all posts
Showing posts with label System security. Show all posts

Friday, August 5, 2011

Access Control Administration

Once an organization develops a security policy, supporting procedures, standards, and guidelines, it must choose the type of access control model: DAC, MAC, or role-based. After choosing a model, the organization must select and implement different access control technologies and techniques. Access control matrices, restricted interfaces, and content-dependent, context-dependent, and rule-based controls are just a few of the choices.

Centralized Access Control Administration

AAA protocol is the authentication protocol used,  AAA stands for authentication, authorization, and auditing.Depending upon the protocol, there are different ways to authenticate a user in this client/server architecture. The traditional authentication protocols are Password Authentication Protocol (PAP), Challenge Handshake Authentication Protocol (CHAP), and a newer method referred to as Extensible Authentication Protocol (EAP).

Remote Authentication Dial-In User Service (RADIUS) is a network protocol and provides client/server authentication and authorization, and audits remote users. RADIUS uses UPD. Terminal Access Controller Access Control System (TACACS) provide same functionality as RADIUS with a few differences
in some of its characteristics.TACACS uses TCP.  RADIUS encrypts the user’s password only as it is being transmitted from the RADIUS client to the RADIUS server. Other information, as in the username, accounting, and authorized services, is passed in cleartext.  TACACS+ encrypts all of this data between the client and server and thus does not have the vulnerabilities inherent in the RADIUS protocol.

RADIUS is the appropriate protocol when simplistic username/password authentication can take place and users only need an Accept or Deny for obtaining access, as in ISPs. TACACS+ is the better choice for environments that require more sophisticated authentication steps and tighter control over more complex authorization activities, as in corporate networks.

Diameter is another AAA protocol that provides the same type of functionality as RADIUS and TACACS+ but also provides more flexibility and capabilities to meet the new demands of today’s complex and diverse networks. RADIUS and TACACS+ are client/server protocols, which means the server portion cannot send unsolicited commands to the client portion.Diameter is a peer-based protocol that allows either end to initiate communication.

Decentralized Access Control Administration

A decentralized access control administration method gives control of access to the people closer to the resources—the people who may better understand who should and should not have access to certain files, data, and resources. But centralized Access Control Administration is recommended in implementations to maintain the privacy of the system.

Access Control Models

The main characteristics of the three different access control models are important to understand.
  • DAC (Discretionary Access Control) Data owners decide who has access to resources, and ACLs are used to enforce the security policy.
  • MAC(Mandatory Access Control) Operating systems enforce the system’s security policy through the use of security labels. Eg: security clearance,In a military environment, the classifications
    could be top secret, secret, confidential, and unclassified.A commercial organization might use confidential, proprietary, corporate, and sensitive.
  • RBAC(Role-Based Access Control) Access decisions are based on each subject’s role and/or functional position.
Once an organization determines what type of access control model it is going to use, it needs to identify and refine its technologies and techniques to support that model.

Access Control Techniques

Access control techniques are used to support the access control models.
  • Access control matrix Table of subjects and objects that outlines their access relationships
  • ACL Bound to an object and indicates what subjects can access it
  • Capability table Bound to a subject and indicates what objects that subject can access
  • Content-based access Bases access decisions on the sensitivity of the data, not solely on subject identity
  • Context-based access Bases access decisions on the state of the situation, not solely on identity or content sensitivity
  • Restricted interface Limits the user’s environment within the system, thus limiting access to objects
  • Rule-based access Restricts subjects’ access attempts by predefined rules

Thursday, August 4, 2011

Single Sign On(SSO) Technologies

If the user has to enter different User ID and User password every time he access a service like printer, file server, it becomes overhead to the user to remember all the usernames and passwords. They tend to write them down and then the security is exposed. Managing user password and renewing them is an overhead to the administrators too. If user has to remember on password only enforce more security in to that password using longer passwords with higher entropy.  SSO offers one time user authentication (User ID and Password) and he is good to access all the services. One bottleneck in achieving SSO is the inadequate system interoperability of services.

Examples of Single Sign-On Technologies 
  • Kerberos Authentication protocol that uses a KDC (Key Distribution center) and tickets, and is based on symmetric key cryptography 
  • SESAME(Secure European System for Applications in a Multi-vendor Environment) Authentication protocol that uses a PAS(Privileged attribute server like KDC) and PACs(Privileged attribute certificates), and is based on symmetric and asymmetric cryptography 
  • Security domains Resources working under the same security policy and managed by the same group 
  • Thin clients Terminals that rely upon a central server for access control, processing, and storage

Wednesday, July 27, 2011

Access control

Access control is what subject can control what objects and what type of commands and operations they can carry out.

Access control categories:
  • Administrative controls (personal controls, Supervisory structure, security awareness training, testing)
  • Physical controls ( Network segregation, Perimeter Security, Computer controls, work area separation, cabling, control zones)
  • Technical controls (System access, network architecture, Network access, encryption and protocols, auditing)
Access control types

  • Preventive - keep undesirable events form happening
  • Detective - identify undesirable events that have taken place
  • Corrective - correct undesirable events that have taken place
  • Deterrent - Discourage security violations form taking place (we are serious about security "Beware of dogs")
  • Recovery - Restore resources and capabilities after a violation or accident
  • Compensation - provide alternatives to other controls (based on cost/benefit analysis)

Process of getting access in to the system
  • Identification - publicly known information but shouldn't be descriptive(username, userID)
  • Authentication - Something you know(password,pin),something you have(smartcard,token) and something you are(biometrics). Strong authentication is two of authentication components.
  • Authorization - ACL
  • Accountability
It is important to asses the your passwords by trying to crack the password your self using the tools available. Password can be cracked using dictionary attack and exhaustive attacks.Rainbow table make password cracking easier by machining hash values. As solution for this we can use one time passwords with a authentication server(challenge response authentication).

Smart cards are good method of authentication.There are two types of smart cards, contact and contact(in/out chip) less(small antenna inside). Fault generation is one of the attack against smart card. Fault generation is manipulating the something outside the card(reader) to get into the data in smart card. Then there are software attacks exploiting the software flaws inside the card. Side channel attack means we are not doing anything to the card, just watch and gather information(gathering radiation, time it took to authenticate).Micro probing is connecting to the circuits directing by peeling of the chip on the card.

Data classification and clearance

Data classification is really important in the industry. There are lot of news in security leakages due to poor data classification.In the military data classification and clearance has higher importance. In military they classify data as unclassified data, confidential data, secret data and top secret data. why we don't call all the data top secret and consider it done. If we do so we waste cost in putting unnecessary security measures and waste lot of man power in managing them. So it is really important to design data classification model appropriate to our industry.Also it is important to define the security clearance.we have to define who are the data owners, what are their responsibilities and data classification in the organization. To start we should build a security policy which outline everything that we decided upon.Then we have our procedures, guidelines and standards to define it further.

Too many classification levels are impractical and add confusion. Too few classification levels gives the perception of little value and use. And there should be no overlap between classification levels.It is very common that lot of companies have three classification levels.Also we should follow a standardize approach for our information classification criteria.

Weakest link in security is people.That's why employ management is really important when you look in at enterprise security.80% of threat are internal and 20% are external(80/20 rule).People make mistakes.Policies should enforce in recruiting people, firing people and security training.

Hiring and Firing procedures:

Pre employment
  • Background check
  • security clearance
  • Credit check
  • drug screening
Termination procedures:
  • Complete an exit interview (review non-disclosure agreement)
  • Individual must surrender ID, keys and company assets
  • User's accounts must be disabled

Tuesday, July 26, 2011

Enterprise security architecture

Layered approach : provide layers of defense that the attacker has to break before accessing an asset

Industries follow this approach and then think their system is secure. But they forget that the remote access and wireless network doesn't have enough layers in position. Security requirement can be identified as functional requirements and assurance requirements.Organization choose to be certified against the BS7799 standard to provide confidence to their customer base and partners. That is why industries make effort to comply with these standards.

Sometime numbering of the IT security standards are confusing.BS7799 security standard has two parts. After ISO took BS7799 under their wings, they introduced their own numbering.

BS7799 part 1 - ISO17799 outlines control objectives and a range of controls that can be used to meet those objectives
BS7799 part 2 - ISO27001 outlines how a security program can be setup and maintained.

COBIT defines the method of building the IT inf structure. COBIT is control objective for information related technology.this is not just about security.COBIT is a whole structure how to set up IT infrastructure. In COBIT there are four domains ;
  1. Planning and Organization
  2. Acquisition and implementation
  3. delivery and support
  4. Monitoring
In security we are just looking at the delivery and support domain.COBIT is great but it is really time consuming to implement.For security professional there are special things to learn form COBIT
  • Management of IT security
  • IT security plan
  • Identity management
  • User account management
  • Security testing,surveillance and monitoring
Whole point of COBIT is keep IT alignment with business.It has performance indicators and define goals.COBIT is a very high level approach to the information security. That's how the auditors look at. They look at the control objective and check whether the control is in place.

security governance is that security is controlled by not just IT but with board members and senior management.Everybody who suppose to be involved should involve in the security.Security policy, standards, baseline, guideline and procedures have to act together to realize strong security.

Data owner is the person who responsible for protecting the data.custodian usually the IT department to the actual security setup to make sure it meet that protection level.

Risk management

Risk management is difficult because we are looking at the future. Most of the time enterprises have the question, "what is acceptable risk level". They have to comply with the regulations, look at their assets that they have to protect, asses the importance of their assets to understand their sufficient security level. How much enough security is a cost benefit balance.

(1) Planing the risk management:
  • Identify Teams
  • Identify Scope
  • Identify Methods (Qualitative and quantitative)
  • Identify tools
  • Understand acceptable risk level

every company has a different risk appetite.That means how much risk they are willing to take.acceptable risk level has to be set in the enterprise. business derives are going to help define the acceptable risk level and the management has to set the level. Team is just bring the information to the management.But this is very abstract. Then we define security policies. Security policies should reflect the acceptable risk level in the system.

(2) Collect Information:
  • Identify Assets
  • Assign value to assets
  • Identify vulnerability and threats
  • Calculate risks
  • Cost/benefit analysis
  • Uncertainty analysis

Collecting information is a time consuming process.it is really important to identify the assets that are to be protected.There are tangible(hardware) and intangible(data, reputation) assets. Intangible assets are harder to protect. how to assign a value to an assets?Have to determine the cost, adversary, reliability and criticallily.We have to consider if something happen to a specific asset what will cost to the company in near term and long term.
We have to determine the type of analysis we are going to carried out. whether it is qualitative or quantitative is depends on the requirement of the company. managers like to see quantitative analysis. Quantitative has do with monetary values and qualitative is opinion based.

Qualitative analysis is commonly used in the industry.Experts will rate the level of risk.If we defines levels according to the probability of occurrence vs consequences of occurrence, there are levels like minor risks,high incidence risks, contingency risks and significant risks. we have to address the significant risk first and then the rest.

Single Loss expectancy (SLE) = Asset value x exposure factor


Exposure factor is the percentage of the damage that we think take place if the vulnerability is exploited. We look at one asset and one threat, then we calculate the cost impact of this on the company.

Probability of something to take place, we call it Annual rate of occurrence (ARO). ARO is number of expected incidents annually. ARO is annual metric. once year means ARM is 1.0.

Annual loss expectancy (ALE) = SLE x ARO

ALE is the potential loos that company can be gone through.This is how we determine which risk we correct first. This help us to categorize the treats and define the road map and budget allocation.

Purely quantitative analysis can't take place, but purely qualitative analysis can. We can be exact on the values that will happen in the future. That is why most of the industries choose qualitative analysis over quantitative analysis.

Losses can be potential or delayed.We have to look at what are the potential losses and what the delayed loses. Potential means what will happen quickly.Incident of a virus attack, the potential loss will be the inaccessibility of server. And the delayed loss will be loss of reputation.

cost/benefit calculation for countermeasure system also depends on lot of variables.It depends on variables like cost, maintenance fee, impact on productivity and number of man powers.

Value of countermeasure = (ALE before we put the counter measure) - (ALE after putting the countermeasure) - Annual cost of the countermeasure

If this value is negative it means implementing the countermeasure is not cost beneficial.Not just cost, there are whole list of things that we have to look at in a countermeasure. Does it fall in to least privilege, is it flexible, does it provide uniform protection, is it modular in nature,does it require human intervention, does is provide auditing functionality,does it been tested and can it be tested. when when people are involved that is where mistakes are taken place.

Disadvantages of quantitative analysis are it requires large amount of preliminary work, formulas are complex and inflexible and there are no real standards on how to carry this out.In qualitative approach assigning rating values are simple, allow for flexibility in processes and reporting results and it requires less preliminary work. Disadvantages of qualitative analysis are it is subjective, it is opinion and hard to map in to the budget. But this the most used in the industry.

Following formulas are conceptual formulas and you can not put values in to those.

Total risk = Threats x vulnerability x asset value

Total risk is when we didn't put any countermeasures in place. If we act upon the vulnerability that is the residual risk.Residual risk shows that countermeasure reduced the risk but not get rid of all the threats.

Residual risk = Threats x vulnerability x asset value x control gap
(control gap = what the control can not protect against)

Total risk - Controls = Residual risk

When we showed the results of the analysis they need some confidence on the information that used for the analysis. uncertainty analysis assign the amount of trust on the information that we are using.

Management is liable to take action on the risks.Four ways to dealing with risks: mitigation, transfer, acceptance and avoidance.Management need to know what to do with the information they collected.

(3) Management's responses to identified risks:
  • Risk mitigation - implement countermeasures
  • Risk transfer - Third-party involvement like purchasing cyber insurance
  • Risk acceptance - Informed decision, no action taken when it is not cost beneficial
  • Risk avoidance - decide to stop activity
Risk acceptance:
  • cost decision
  • pain decision
  • visibility decision

RISK MANAGEMENT

PLAN -> COLLECT INFORMATION -> DEFINE RECOMMENDATIONS

Due diligence and due care on secure systems

Standards are best practices and it is better to follow open standards to build secure systems. In interconnected systems everybody depends on others. Following open standards make the interconnection easier and leverage interoperability. Introducing propriety security systems is not the best practice. When building a secure system we should consider following control categories. 
  • Administrator controls (Defining policies, Awareness training, Risk management)
  • Technical controls (Routers, IDS, Encryption, Auditing)
  • Physical controls (locks, security guards)
All of these categories have to work together to achieve holistic security.But in the real enterprises there are gaps between technical people and managers. Technical people complain that top management don't listen to their requests. And the managers says that they only hear the request of more money. These gaps creates vulnerabilities in the system. Technical people have to understand to make a business case according to the business drives.

Companies consider only the technology when they building security programs. They should consider technology, business process and people using them. Security people have to understand the regulations and legal requirements (Federal laws, State laws).When laws come in to agencies (regulatory bodies) they define regulations. Also security people have to understand the business drivers and the level of risk.

Due diligence and due care is important in building security systems.Due  diligence is accessing the vulnerabilities in the system and the due care is do something about it and fix the problem. Due diligence is uncovering potential dangers, carrying assessments, perform analysis on assessment data, implement risk management and researching and understanding the vulnerabilities, threats and risks.If you brought in to court because of an attack on the your enterprise security system, due diligence is your protector.

Regulation enforce industries to comply with the security. Regulations are important to prevent corruption. USA took a serious look on regulation  after the ENRON downfall.