Discuss how and why companies use cryptography
Access Control, Authentication, and Public Key Infrastructure
Lesson 14
Testing Access Control Systems
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
1
Learning Objective and Key Concepts
Learning Objective
Mitigate risk from unauthorized access to IT systems through proper testing and reporting.
Key Concepts
System penetration testing and reporting
System vulnerability assessment scanning and reporting
Network and operating system (OS) discovery scan
Scope for penetration test plan
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
2
Penetration Testing
Preferably called security assessment
Process of actively evaluating your information security measures
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Purpose of Testing Access Control Systems
Testing ensures that weaknesses are found and can be dealt with before they are exploited
Tests should incorporate testing methodologies at different stages of development:
Software design
Hardware development
Penetration testing
Penetration testing: The act of simulating an attack on an organization’s resources
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
4
The Software Development Life Cycle
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
What Needs to Be Tested?
Let’s discuss!!
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
All parts of the way that your organization captures, stores, and processes information can be assessed; the systems that the information is stored in, the transmission channels that transport it, and the processes and personnel that manage it.
Off-the-shelf products: operating systems, applications, databases, networking equipments etc.
Bespoke development products: dynamic Web sites, in-house applications etc.
Telephony products: war-dialing, remote access etc.
Wireless products: Wireless fidelity (Wi-Fi), Bluetooth etc.
Personnel: screening process, social engineering etc.
Physical: access controls, dumpster diving etc.
3/30/2015
6
The Security System Life Cycle
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Security Monitoring, Incident Handling, and Testing
Monitoring and incident handling are the day-to-day activities
Testing and upgrading system usually occurs annually
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
8
Security Monitoring, Incident Handling, and Testing (Cont.)
Testing functionality of original design
Before purchase of new system, perform risk assessment on old system
Determine existing major weaknesses
Development of test plan and scope
Impact/vulnerabilities
Breach planning
Gap analysis
Intrusive versus nonintrusive testing
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
9
Vulnerability Scanners
Attempts to identify vulnerabilities in the hosts scanned
Helps identify out-of-date software versions, applicable patches, or system upgrades
Validates compliance with or deviations from the organization's security policy
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Vulnerability scanners take the concept of a port scanner to the next level. Like a port scanner, a vulnerability scanner identifies hosts and open ports, but it also provides information on the associated vulnerabilities (as opposed to relying on human interpretation of the results). Most vulnerability scanners also attempt to provide information on mitigating discovered vulnerabilities.
Vulnerability scanners provide system and network administrators with proactive tools that can be used to identify vulnerabilities before an adversary can find them. A vulnerability scanner is a relatively fast and easy way to quantify an organization's exposure to surface vulnerabilities.
3/30/2015
10
Common Vulnerability Scanners
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Network-based scanners are used primarily for mapping an organization's network and identifying open ports and related vulnerabilities. In most cases, these scanners are not limited by the operating system of targeted systems. The scanners can be installed on a single system on the network and can quickly locate and test numerous hosts.
Host-based scanners have to be installed on each host to be tested and are used primarily to identify specific host operating system and application misconfigurations and vulnerabilities. As host-based scanners are able to detect vulnerabilities at a higher degree of detail than network-based scanners, they usually require not only host (local) access but also a “root” or administrative account.
3/30/2015
11
Network-based scanners
Host-based scanners
Benefits of Vulnerability Scanning
Identifies:
Active hosts on network
Active and vulnerable services (ports) on hosts
Applications and banner grabbing
Operating systems
Vulnerabilities associated with discovered operating systems and applications
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
12
Benefits of Vulnerability Scanning (Continued)
Misconfigured settings
Testing compliance with host application usage or security policies
Establishing a foundation for penetration testing
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
13
Zenmap Configuration Screen
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Sample Nmap Report in Zenmap GUI
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Nessus® Configuration Screen
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Sample Nessus® Report
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Retina Configuration Screen
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Sample Retina Report
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Gap Analysis Within the Seven Domains of a Typical IT Infrastructure
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
20
Penetration Testing and Teams
Penetration testing:
Is most accurate way to assess an infrastructure’s true vulnerability
Simulates actual attack
Is an intrusive testing method
Is risky for the attacking team
Pen test team members should carry authorization memo from upper management
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
21
Seven Domains of a Typical IT Infrastructure
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
From a business perspective, penetration testing helps safeguard your organization against failure, through:
Preventing financial loss through fraud (hackers, extortionists and disgruntled employees) or through lost revenue due to unreliable business systems and processes
Proving due diligence and compliance to your industry regulators, customers and shareholders. Non-compliance can result in your organization losing business, receiving heavy fines, gathering bad public relations, or ultimately failing. At a personal level it can also mean the loss of your job, prosecution, and sometimes even imprisonment.
Protecting your brand by avoiding loss of consumer confidence and business reputation
3/30/2015
22
Rules of Engagement
Specific Internet Protocol (IP) addresses or ranges to be tested
Any restricted hosts, systems, and subnets not to be tested
A list of acceptable testing techniques, such as social engineering and denial of service (DoS), and tools, such as password crackers and network sniffers
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Formal permissions are often called the rules of engagement.
3/30/2015
23
Rules of Engagement (Continued)
Times when testing is to be conducted (for example, during business hours, after business hours)
Identification of a finite period for testing
IP addresses of the machines from which penetration testing will be conducted
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Formal permissions are often called the rules of engagement.
IP addresses help administrators to differentiate the legitimate penetration testing attacks from actual malicious attacks.
3/30/2015
24
Penetration Testing Teams
Red Team
The attacker
Blue Team
The defending team
Attacker and defender know test is taking place
Tiger Team
External testers who operate in a double-blind penetration test
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
25
Performing the Penetration Test: Methodology
Technological, or focus on uncovering weaknesses to social engineering
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
26
Planning and preparation
Information gathering
Vulnerability detection
Penetration attempt
Analysis and reporting
Clean-up
Preparing the Final Test Report
Identify gaps and risk exposures and assess impact
Develop remediation plans for closing identified security gaps prioritized by risk exposure
Prepare cost magnitude estimate
Prioritize security solutions based on risk exposure
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
3/30/2015
27
Summary
System penetration testing and reporting
System vulnerability assessment scanning and reporting
Network and operating system (OS) discovery scan
Scope for penetration test plan
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Virtual Lab
Authenticating Security Communications with Digital Signatures
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
If your educational institution included the Jones & Bartlett labs as part of the course curriculum, use this script to introduce the lab:
"In this lesson, you learned that testing is a crucial activity for any IT department because it provides assurance that access controls and other security systems are working as designed.
In the lab for this lesson, you will use the encryption utility GnuPG (GPG) to test the security of the message transmission. To do that, you will create a digitally signed message for another user. Then, you will retrieve that message (as the other user) and use GPG to verify the digital signature."
3/30/2015
29
OPTIONAL SLIDES
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Security Auditing
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Define the physical scope of audit
Document audit results
Specify and implement new/updated controls
Perform security risk assessment
Develop the audit plan
Define the process scope of the audit
Conduct historical due diligence
Purpose of Security Audit
How difficult are passwords to crack?
Do network assets have access control lists?
Do access logs exist that record who accesses what data?
Are personal computers regularly scanned for adware or malware?
Who has access to back-up media in the organization?
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Security audits are best understood by focusing on the specific questions they are designed to answer.
3/30/2015
32
Why Conduct a Penetration Test or Vulnerability Scan?
Let’s discuss!!!!
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
From a business perspective, penetration testing helps safeguard your organization against failure, through:
Preventing financial loss through fraud (hackers, extortionists and disgruntled employees) or through lost revenue due to unreliable business systems and processes
Proving due diligence and compliance to your industry regulators, customers and shareholders. Non-compliance can result in your organization losing business, receiving heavy fines, gathering bad public relations, or ultimately failing. At a personal level it can also mean the loss of your job, prosecution, and sometimes even imprisonment.
Protecting your brand by avoiding loss of consumer confidence and business reputation
3/30/2015
33
Penetration Testing—Formal Permissions
Why are formal permissions required to conduct penetration testing???
Let’s discuss!!
Page ‹#›
Access Control, Authentication, and PKI
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Since penetration testing is designed to simulate an attack and use tools and techniques that may be restricted by law, federal regulations, and organizational policies, it is imperative to get formal permission for conducting penetration testing prior to starting.
3/30/2015
34