1/53
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Identity and Access Management System (IAM)
This system of Access Control has 4 main processes: identification, authentication, authorization, and accounting
Identification
Creating an account or ID that uniquely represents the user, device, or process on the network.
Authentication
Proving that a subject is who or what it claims to be when it attempts to access the resource. A BLANK factor determines what sort of credential the subject can use.
For example, people might be BLANK by providing a password; a computer system could be authenticated using a token such as a digital certificate.
Authorization
Determining what rights subjects should have on each resource, and enforcing those rights. A BLANK model determines how these rights are granted. For example, in a discretionary model, the object owner can allocate rights. In a mandatory model, rights are predetermined by system-enforced rules and cannot be changed by any user within the system.
MAC is a mandatory model in this part of AAA since it has a robust framework for enforcing security policies. There are also BLANK factors which are the things used to verify an entity’s identity
Accounting
Tracking authorized usage of a resource or use of rights by a subject and alerting when unauthorized use is detected or attempted.
Authentication Methods (Factors)
Knowledge factor—Something you know (such as a password).
Ownership factor—Something you have (such as a smart card).
Human or biometric factor—Something you are (such as a fingerprint).
Behavioral factor—Something you do (such as making a signature).
Location factor—Somewhere you are, such as only being able to log into an account from a specific location, known as geofencing.
Time factor—Somewhen you are (such as only being permitted to start a session during work hours or using an access token before it expires).
Local Authentication
This is referred to as the authentication provider, the software architecture and code that have the mechanisms by which the user is authenticated.
Relies on cryptographic hashes for safety when stored
Single Sign-on system (SSO)
This system allows the user to authenticate once to a local device and be authorized to access compatible application servers without having to enter credentials again
Kerberos
A SSO authentication service that is based on a time-sensitive, ticket-granting system. Used on Windows network Sign-in
Consists of 3 parts:
Client - requests services
Server - from which the service is requested
Key Distribution Center (KDC) - to vouch for their identity
Digital Certificate
These are used to authenticate machines when using Transport Layer Security (TLS) and can be installed on a web or email server to validate its identity and establish secure transmission channel.
Asymmetric Encryption Key
A type of encryption that generates a key pair, a public and private one which can‘t be derived from the public key. It can be used in the following ways:
The public key can encrypt the message, only decryptable by the private, not vise versa
When you want to authenticate yourself to others, you create a signature using your private key while giving others the public one to verify the signature, so since only you know the private key, its a good authenticator
Symmetric Encryption Key
A type of encryption that creates a single key which can both encrypt and decrypt messages, in order to secure it, a public key gets used to encrypt this type of key.
Public Key Infrastructure (PKI)
This infrastructure aims to prove that the owners of public keys are who they say they are by having them obtain a digital certificate which is validated by a certificate authority (CA)
Certificate MUST HAVE - contains info about the subject and certificates grantor and signed by a CA to show it was issued by the CA
Self-Signed Certificate
A type of digital certificate not signed by a trusted certificate authority (CA)
Key Management
This type of management refers to operational considerations for the various stages in the lifecycle of an encryption key or key pair, it involves the following stages:
Key generation - asymmetric or symmetric
Storage - prevents unauthorized access
Revocation - prevents key use if compromised
Expiration and Renewal - gives the certificate a “shelf - life” for more security
Decentralized Key Management Model
A model which means that keys are generated and managed directly on the PC or user account that will use the certificate.
Easy to set up but key compromise detection is more difficult
Centralized Key Management Model
A model which means that keys are generated using a tool like a key management system, with a dedicated system for generation and storage.
Uses Key Management Interoperability Protocol (KMIP) when a device needs to perform a cryptographic operation
Federated Identity
A type of identity, a form of authentication and authorization that uses your credentials from a website or app to log into another website or app (such as using google credentials to automatically log into Facebook) Its a company trusting accounts created and managed by a different company
Interoperable Federation Protocols
This type of protocol uses claim based identity, while technical implementation and terminology its model is similar to Kerberos SSO:
The principal attempts to access a service provider.
The service provider redirects the principal to the IdP.
The principal authenticates with the identity provider.
If authentication is successful, the principal obtains a claim, in the form of some sort of token or document signed by the IdP.
The principal presents the claim to the service provider.
The SP can validate that the IdP has signed the claim because of its trust relationship with the IdP.
Security Assertion Markup Language (SAML)
A type of assertion or claim that are used to implement user identity assertions and transmits claims between the principal (PC user), service provider (site or app you’re trying to query), and identity provider (IdP like Google)
Written in eXtensible Markup Language (XML), comms are established with HTTP / HTTPS and Simple Object Access Protocol (SOAP). Secure tokens are signed using XML signature specification
Remote Authentication
A type of authentication which has the host running a remote access server or terminal server that accepts login requests via another host OVER a network
Using a VPN or IF its with a different host over a private network then by running a Secure Shell (SSH) server service or Remote Desktop Protocol (RDP) terminal access server in order for the admin to start a session from their management workstation
Authentication, Authorization, Accounting (AAA) architecture
A type of architecture used for remote access / remote authentication since storing credentials is risky, these devices are more vulnerable, and its difficult to sync accounts, credentials, and SSO authorizations
It has the following components:
Supplicant - device requesting access
Network access server or Network access point (NAS or NAP) - edge network appliances (switch, AP, VPN gateway) or AAA clients or authenticators
AAA Server - authentication server in local network, either golds database of accounts n creds or has access to a directory server that can authenticate requests and issue SSO authorization.
- Types of AAA server : RADIUS and TACACS+
Remote Authentication Dial-In User Service (RADIUS)
A remote user service that is widely used for client device access over VPN's. Using UDP ports 1812 and 1813 and each RADIUS client must be configured with the IP address of the RADIUS server plus the same shared secret
Terminal Access Controller Access Control System (TACACS+)
Similar to RADIUS but designed by CISCO to be more flexible and reliable by separating AAA into their own discrete processes, supported on third party and open source RADIUS implementations. Often used in authenticating Admin access to routers and switches by using TCP over port 49, TCP reliable delivery makes it easier to detect when a server is down.
It separates AAA into their discrete processes
It encrypts the entire authentication process, while RADIUS only encrypts the password.
Sudo and User Account Control
"Superuser do" in Linux and UAC in Windows allow a user to temporarily elevate permissions without having to fully sign out and in to use a different account.
Directory Service
A type of directory of user accounts for everyone on your network, including entities for appliances such as printers and shared folders. It allows you to control and manage user accounts, appliances, security, to all accounts within the directory.
Common services include:
Microsoft Active Directory
OpenLDAP
Discretionary Access Control (DAC)
This model is based on the primacy of the resource owner. In a BLANK model, every resource has an owner. The owner creates a file or service although ownership can be assigned to another user. The owner has full control over the resource, and they can modify its access control list (ACL) to grant rights to others.
Discretionary: every resource has an owner and its to the owners discretion to change ACL, not a managing admin and so on.
Role-Base Access Control (RBAC)
A model in which an organization defines its authorizations in terms of the tasks that an employee or service must be able to perform and turning each set of permissions into a role. Each principal (user or service account) is allocated to one or more roles. Under this system, the right to modify the permissions assigned to each role is reserved to a system owner. Nondiscretionary
A principal earns a right indirectly by having it through a role, and not directly by having rights assigned. This model is in the middle between DAC and MAC as it is flexible, more scalable than DAC, and safer than DAC. Admins must not be allowed to increase or escalate their own roles arbitrarily
Privileged access management (PAM)
This refers to policies, procedures, and technical controls to prevent the malicious abuse of privileged accounts by internal threat actors and to mitigate risks from weak configuration control over authorizations. These controls identify and document privileged accounts, giving visibility into their use and managing the credentials used to access them.
The principle of this are:
- Least privilege
- Separation of duties
Least Privilege
A principle of PAM, it means that a user is granted sufficient rights to perform their job and no more to mitigate risk.
Authorization creep refers to a situation where a user acquires more and more rights, either directly or by being added to security groups and roles. BLANK should be ensured by closely analyzing business workflows to assess what privileges are required and by performing regular account audits.
Separation of Duties
A principle of PAM, its a means of establishing checks and balances against the possibility that critical systems or procedures can be compromised by insider threats.
Duties and responsibilities should be divided among individuals to prevent ethical conflicts or abuse of powers.
X.500 Series Standards
Most directory services are based on this standard.
Each object has a unique ID called a Distinguished Name: made up of attribute value pairs, separated by commas, with the most specific attribute listed first (relative distinguished name) and successive attributes become broader
Lightweight Directory Access Protocol (LDAP)
A protocol used to QUERY and UPDATE an X.500-like directory. BLANK is widely supported in current directory products, most notably in Windows Active Directory. Insecure BLANK messaging uses TCP and UDP port 389 by default.
This type of directory should only be accessible from the private network, disabling access over public interface in port 389 TCP UDP
LDAP Security Binding
The security process for LDAP, also known as authentication, since as a TCP/IP protocol its not secure, it can be implemented in the following ways:
Simple bind
Simple Authentication and Security Layer (SASL)
LDAP Secure (LDAPS)
Simple Bind
A type of LDAP binding in which the client must supply its distinguished name (DN) and password, but these are passed as plaintext.
Simple Authentication and Security Layer (SASL)
This framework in LDAP binding allows a client and server to negotiate authentication and encryption parameters to make a connection over TCP port 389 secure. The client and server negotiate the use of a supported authentication mechanism, such as Kerberos. The STARTTLS command can be used to require certificate-based encryption (sealing) and message integrity (signing).
LDAP Secure (LDAPS)
(LDAP Binding) The server is installed with a digital certificate, which it uses to set up a secure Transport Layer Security (TLS) session to authenticate the server and protect the user's LDAP credentials and data. BLANK uses port 636.
Security Groups
These are used to group user accounts for administrative purposes and can be used to assign permissions, but they do not inherently focus on job functions or roles.
B
The user's username and group memberships
What does an access key contain when generated by the server's security service for an authenticated user?
A
The user's password and login time
B
The user's username and group memberships
C
The IP address and MAC address of the user's device
D
The user's browsing history and application usage
Perimeter Security Model
This system of focusing on the boundary between the public and private network and trusting everything that has connected via internal switches is called the BLANK
Defense in Depth
Like internet of things, an umbrella term/concept that positions the layers of diverse security control categories and functions as opposed to relying on perimeter controls.
Endpoint Security
A set of procedures and technologies designed to restrict both remote and local network access at a device level and to ensure that each endpoint device is hardened to mitigate vulnerabilities.
Hardening
A process of making a host or app configuration secure by reducing its attack surface, through running only necessary services, installing monitoring software to protect against malware and intrusions, and establishing a maintenance schedule to ensure the system is patched to be secure against software exploits.
Includes the following:
Change default PW and creds (at least 14 characters for net appliances)
Enforce PW length/complexity requirements
Configure role-based access
Disable unneeded network services
Disable insecure protocols
Linux System Commands
Command | What it does |
|---|
| Shows the current status of the |
| Starts the FTP service |
| Stops the FTP service |
| Stops and starts the service again |
| Checks whether the service is configured to start at boot |
| Configures the service to start automatically at boot |
| Prevents the service from starting automatically at boot |
Nmap Linux Commands (network map)
nmap -h — displays Nmap help/options.
man nmap — opens the Nmap manual.
ip a — displays network interfaces and IP/network information.
nmap 192.168.222.0/24 — scans the subnet for hosts and open services.
nmap -p 1-65535 -sV 192.168.222.207 — scans all ports on that host and attempts to identify service/software versions.
Nmap options used
-h → help
-p 1-65535 → scan ports 1 through 65,535
-sV → detect service/software versions
Simple Network Management Protocol (SNMP)
BLANK is used to monitor and manage network devices. To secure BLANK traffic, use SNMPv3 with authentication and encryption, or protect BLANK traffic using IPsec. Older versions, SNMPv1 and SNMPv2c, lack built-in encryption and can expose sensitive management data.
SNMPv3 = secure version with authentication and encryption support.
IPsec = can encrypt and protect SNMP traffic.
SNMPv1/v2c = older versions that lack encryption.
Internal-only access = helpful additional protection, but not sufficient by itself.
Network Access Control (NAC)
BLANK is a system for authenticating endpoints before they can fully connect to the network This is principally designed to mitigate risks from rogue devices and services. A basic type of BLANK can be implemented by configuring port security mechanisms.
Port Security Mechanisms
Preventing a device attached to a switch port from communicating on the network unless it matches a given MAC address or other protection profile.
Completely disabling ports creates administrative overhead and potential for errors, and it does not provide complete protection because an attacker could replace a device connected to an enabled port with their own laptop. This led to the development of more sophisticated port security methods.
Sinkhole VLAN
A VLAN with no route to the network, used to isolate switch ports to prevent attachment of unauthorized devices.
Switchport
Command/subcommand used on CISCO switches in order to prevent unauthorized attachment of devices.BLANK port-security maximumBLANK port-security mac-address stickyBLANK port-security violation restrict
MAC Filtering
BLANK controls which MAC addresses are permitted to connect to a particular switch port. A switch can use a static list of valid MAC addresses or limit the number of permitted addresses.
Sticky MACs
BLANKs are a dynamic method where the switch learns and records the first permitted MAC addresses connected to a port.
For example, with a maximum of two MAC addresses, the first two are recorded and traffic from different MAC addresses is dropped. Learned addresses can be removed after being unused for a specified time.
MAC Violation Modes
If a device connects using a MAC address that violates policy, the switch port enters a violation state:
Protect Mode: Drops frames from invalid MAC addresses but keeps the interface open (Only on sticky MACs)
Restrict Mode: Drops invalid frames, logs/alerts the violation, but keeps the interface open.
Shutdown Mode: Disables the port and sends alerts. The port must be manually re-enabled with no shutdown. This is the default mode.