Discuss how and why companies use cryptography

profilesarath_007
access_ppt15_l14.pptx

Access Control, Authentication, and Public Key Infrastructure

Lesson 14

Testing Access Control Systems

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

1

Learning Objective and Key Concepts

Learning Objective

Mitigate risk from unauthorized access to IT systems through proper testing and reporting.

Key Concepts

System penetration testing and reporting

System vulnerability assessment scanning and reporting

Network and operating system (OS) discovery scan

Scope for penetration test plan

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

2

Penetration Testing

Preferably called security assessment

Process of actively evaluating your information security measures

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Purpose of Testing Access Control Systems

Testing ensures that weaknesses are found and can be dealt with before they are exploited

Tests should incorporate testing methodologies at different stages of development:

Software design

Hardware development

Penetration testing

Penetration testing: The act of simulating an attack on an organization’s resources

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

4

The Software Development Life Cycle

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

What Needs to Be Tested?

Let’s discuss!!

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

All parts of the way that your organization captures, stores, and processes information can be assessed; the systems that the information is stored in, the transmission channels that transport it, and the processes and personnel that manage it.

Off-the-shelf products: operating systems, applications, databases, networking equipments etc.

Bespoke development products: dynamic Web sites, in-house applications etc.

Telephony products: war-dialing, remote access etc.

Wireless products: Wireless fidelity (Wi-Fi), Bluetooth etc.

Personnel: screening process, social engineering etc.

Physical: access controls, dumpster diving etc.

3/30/2015

6

The Security System Life Cycle

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Security Monitoring, Incident Handling, and Testing

Monitoring and incident handling are the day-to-day activities

Testing and upgrading system usually occurs annually

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

8

Security Monitoring, Incident Handling, and Testing (Cont.)

Testing functionality of original design

Before purchase of new system, perform risk assessment on old system

Determine existing major weaknesses

Development of test plan and scope

Impact/vulnerabilities

Breach planning

Gap analysis

Intrusive versus nonintrusive testing

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

9

Vulnerability Scanners

Attempts to identify vulnerabilities in the hosts scanned

Helps identify out-of-date software versions, applicable patches, or system upgrades

Validates compliance with or deviations from the organization's security policy

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Vulnerability scanners take the concept of a port scanner to the next level. Like a port scanner, a vulnerability scanner identifies hosts and open ports, but it also provides information on the associated vulnerabilities (as opposed to relying on human interpretation of the results). Most vulnerability scanners also attempt to provide information on mitigating discovered vulnerabilities.

Vulnerability scanners provide system and network administrators with proactive tools that can be used to identify vulnerabilities before an adversary can find them. A vulnerability scanner is a relatively fast and easy way to quantify an organization's exposure to surface vulnerabilities.

3/30/2015

10

Common Vulnerability Scanners

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Network-based scanners are used primarily for mapping an organization's network and identifying open ports and related vulnerabilities. In most cases, these scanners are not limited by the operating system of targeted systems. The scanners can be installed on a single system on the network and can quickly locate and test numerous hosts.

Host-based scanners have to be installed on each host to be tested and are used primarily to identify specific host operating system and application misconfigurations and vulnerabilities. As host-based scanners are able to detect vulnerabilities at a higher degree of detail than network-based scanners, they usually require not only host (local) access but also a “root” or administrative account.

3/30/2015

11

Network-based scanners

Host-based scanners

Benefits of Vulnerability Scanning

Identifies:

Active hosts on network

Active and vulnerable services (ports) on hosts

Applications and banner grabbing

Operating systems

Vulnerabilities associated with discovered operating systems and applications

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

12

Benefits of Vulnerability Scanning (Continued)

Misconfigured settings

Testing compliance with host application usage or security policies

Establishing a foundation for penetration testing

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

13

Zenmap Configuration Screen

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Sample Nmap Report in Zenmap GUI

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Nessus® Configuration Screen

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Sample Nessus® Report

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Retina Configuration Screen

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Sample Retina Report

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Gap Analysis Within the Seven Domains of a Typical IT Infrastructure

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

20

Penetration Testing and Teams

Penetration testing:

Is most accurate way to assess an infrastructure’s true vulnerability

Simulates actual attack

Is an intrusive testing method

Is risky for the attacking team

Pen test team members should carry authorization memo from upper management

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

21

Seven Domains of a Typical IT Infrastructure

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

From a business perspective, penetration testing helps safeguard your organization against failure, through:

Preventing financial loss through fraud (hackers, extortionists and disgruntled employees) or through lost revenue due to unreliable business systems and processes

Proving due diligence and compliance to your industry regulators, customers and shareholders. Non-compliance can result in your organization losing business, receiving heavy fines, gathering bad public relations, or ultimately failing. At a personal level it can also mean the loss of your job, prosecution, and sometimes even imprisonment.

Protecting your brand by avoiding loss of consumer confidence and business reputation

3/30/2015

22

Rules of Engagement

Specific Internet Protocol (IP) addresses or ranges to be tested

Any restricted hosts, systems, and subnets not to be tested

A list of acceptable testing techniques, such as social engineering and denial of service (DoS), and tools, such as password crackers and network sniffers

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Formal permissions are often called the rules of engagement.

3/30/2015

23

Rules of Engagement (Continued)

Times when testing is to be conducted (for example, during business hours, after business hours)

Identification of a finite period for testing

IP addresses of the machines from which penetration testing will be conducted

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Formal permissions are often called the rules of engagement.

IP addresses help administrators to differentiate the legitimate penetration testing attacks from actual malicious attacks.

3/30/2015

24

Penetration Testing Teams

Red Team

The attacker

Blue Team

The defending team

Attacker and defender know test is taking place

Tiger Team

External testers who operate in a double-blind penetration test

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

25

Performing the Penetration Test: Methodology

Technological, or focus on uncovering weaknesses to social engineering

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

26

Planning and preparation

Information gathering

Vulnerability detection

Penetration attempt

Analysis and reporting

Clean-up

Preparing the Final Test Report

Identify gaps and risk exposures and assess impact

Develop remediation plans for closing identified security gaps prioritized by risk exposure

Prepare cost magnitude estimate

Prioritize security solutions based on risk exposure

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

3/30/2015

27

Summary

System penetration testing and reporting

System vulnerability assessment scanning and reporting

Network and operating system (OS) discovery scan

Scope for penetration test plan

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Virtual Lab

Authenticating Security Communications with Digital Signatures

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

If your educational institution included the Jones & Bartlett labs as part of the course curriculum, use this script to introduce the lab:

 

"In this lesson, you learned that testing is a crucial activity for any IT department because it provides assurance that access controls and other security systems are working as designed.

 

In the lab for this lesson, you will use the encryption utility GnuPG (GPG) to test the security of the message transmission. To do that, you will create a digitally signed message for another user. Then, you will retrieve that message (as the other user) and use GPG to verify the digital signature."

3/30/2015

29

OPTIONAL SLIDES

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Security Auditing

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Define the physical scope of audit

Document audit results

Specify and implement new/updated controls

Perform security risk assessment

Develop the audit plan

Define the process scope of the audit

Conduct historical due diligence

Purpose of Security Audit

How difficult are passwords to crack?

Do network assets have access control lists?

Do access logs exist that record who accesses what data?

Are personal computers regularly scanned for adware or malware?

Who has access to back-up media in the organization?

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Security audits are best understood by focusing on the specific questions they are designed to answer.

3/30/2015

32

Why Conduct a Penetration Test or Vulnerability Scan?

Let’s discuss!!!!

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

From a business perspective, penetration testing helps safeguard your organization against failure, through:

Preventing financial loss through fraud (hackers, extortionists and disgruntled employees) or through lost revenue due to unreliable business systems and processes

Proving due diligence and compliance to your industry regulators, customers and shareholders. Non-compliance can result in your organization losing business, receiving heavy fines, gathering bad public relations, or ultimately failing. At a personal level it can also mean the loss of your job, prosecution, and sometimes even imprisonment.

Protecting your brand by avoiding loss of consumer confidence and business reputation

3/30/2015

33

Penetration Testing—Formal Permissions

Why are formal permissions required to conduct penetration testing???

Let’s discuss!!

Page ‹#›

Access Control, Authentication, and PKI

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Since penetration testing is designed to simulate an attack and use tools and techniques that may be restricted by law, federal regulations, and organizational policies, it is imperative to get formal permission for conducting penetration testing prior to starting.

3/30/2015

34