Microsoft’s Active Directory Security Feature
Active Directory (AD) security is not a single setting; it is a compilation of settings that is adaptable and can become very complex. The default AD security settings handle the basic control of objects such as user accounts, group accounts, and computer accounts. For small companies, this default configuration might be sufficient. For larger companies, the built-in security will be quickly outgrown quickly and additional security settings and design must be considered and implemented. Regardless of the size of the company, a firm grasp of AD security settings is necessary to ensure a secure and stable IT infrastructure.
The security that you design for AD must be implemented properly to be effective. Failure to do so can leave AD vulnerable to attacks from both within and outside of the LAN. In addition, AD security is very difficult to audit and track if not it is not setup properly. In some cases, it will be easier to start over rather than to attempt to secure the AD environment after it has been installed and configured with many objects, settings, and features.
Saturday, 28 January 2012
LDAP Security Feature
LDAP Security Feature
LDAP stands for Lightweight Directory Access Protocol. It is used for Network Information Services (NIS). NIS systems store common configuration details for computers on a network. These servers also perform directory services and also act as authentication servers.
LDAP:
· Originally started as a front end to X.500
· Provides much of X.500’s functionality at a lower
· implementation cost
· Removed redundant and rarely used operations
· Uses TCP rather than OSI stack.
FUNCTION
security features of LDAP can be invoked in two ways. LDAP contains a function to call TLS mechanisms. LDAPS is a non-official version of the protocol. This is "LDAP over SSL." SSL stands for "Secure Sockets Layer." This was the predecessor of TLS. Despite the name, LDAPS actually uses TLS as its security mechanism. With LDAPS, security procedures are built in.
X.500 Security Feature
Security Feature
- Sophisticated replication using Directory Information Shadowing Protocol (DISP). Replication of data is critical for providing a robust directory service. X.500 DISP provides this service, and gives a lot of flexibility for different replication configurations.
- Access Control. There is a standard and flexible mechanism for specifying access control. This is important to allow open and controlled management of data in the directory, especially when the data is replicated.
- Improvements to information model. There are a number of improvements to the X.500 data model, based on experience with X.500 (1988). These include attribute subtyping, which allows related attributes to be handled in a clean manner and operational attributes, which allow directory management attributes to be distinguished from user data.
Wednesday, 4 January 2012
GPRS Security Feature, Threats and Solution
Security:
GPRS Authentication
The GPRS authentication procedure is handled in the same way as in GSM with the dis- tinction that the procedures are executed in the SGSN. In some cases, the SGSN requests the pairs for a MS from the HLR/AUC corresponding to the IMSI of the MS.
Threats:
Authentication and Authorization
Spoofed Create PDP Context Request – GTP inherently provides no authentication for the SGSNs and GGSNs themselves. This means that given the appropriate subscriber information, an attacker with access to the GRX, another operator attached to the GRX, or a malicious insider can potentially create their own bogus SGSN and create a GTP tunnel to the GGSN of a subscriber. They can then pretend to be the legitimate subscriber when they are not. This can result in an operator providing illegitimate Internet access or possibly unauthorized access to the network of a corporate customer.
Solution:
Ingress and egress packet filtering – This will help prevent the PLMN from being used as source to attack other roaming partners. If the mobile operator is connected to more than one GRX or private roaming peering connections, then this will also help ensure that spoofed roaming partner traffic cannot arrive on paths where that roaming partner is not connected.
GSM Security Feature, Threats and Solution
Security feature:
Signaling and Data Confidentiality
The SIM contains the ciphering key generating algorithm which is used to produce the 64-bit ciphering key. The ciphering key is computed by applying the same random number used in the authentication process to the ciphering key generating algorithm with the individual subscriber authentication key. The ciphering key is used to encrypt and decrypt the data between the MS and BS. An additional level of security is provided by having the means to change the ciphering key, making the system more resistant to eavesdropping. The ciphering key may be changed at regular intervals as required by network design and security considerations.
Threats
• Eavesdropping. This is the capability that the intruder eavesdrops signalling and data connections associated with other users. The required equipment is a modified MS.
• Impersonation of a user. This is the capability whereby the intruder sends signalling and/or user data to the network, in an attempt to make the network believe they originate from the target user. The required equipment is again a modified MS.
• Impersonation of the network. This is the capability whereby the intruder sends signalling and/or user data to the target user, in an attempt to make the target user believe they originate from a genuine network. The required equipment is modified BTS.
Solution:
Fast and Quality Network Adjustment: Full reuse of legacy infrastructures and associated facilities help operators to reduce CAPEX and civil works. Automatic professional network planning & optimization and network adjustment tools shorten network construction dramatically.
Subscribe to:
Posts (Atom)