Application Security

profilesbadugula
winsec_ppt08_l01_db.pdf

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

ISOL534

Application Security

© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Security Strategies in Windows

Platforms and Applications

Lesson 1

Security Features in

Microsoft® Windows®

Page 4Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Learning Objectives

 Explain information security and how it applies to the

Microsoft Windows operating systems.

 Explain security features of the Microsoft Windows

operating system.

Page 5Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Key Concepts

 Information security

 Microsoft Windows and the typical IT infrastructure

 Anatomy of Microsoft Windows systems and their

application vulnerabilities

 Purpose of access control, authentication, and

creating users and groups

 Security features of directory services

Page 6Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Chapter 1 Slides

Chapter 1: Microsoft Windows and the

Threat Landscape

Page 7Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Security Controls

Type of Control

Type of Function

• Administrative

• Technical

• Physical

• Preventive

• Detective

• Corrective

Page 8Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

C-I-A

Page 9Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

A Sample IT Infrastructure

Page 10Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Microsoft EULA Sections

Potentially unwanted software

Internet-based services

Limitation and exclusion of damages

Exclusions from warranty

Limitation and exclusion of damages for breach of warranty

Page 11Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Common Windows

Vulnerabilities

Access Control

• Weak passwords

• Weak permissions

• Shared user accounts

Infrastructure

• No firewall

• No malware protection

• Weak security policy

• Weak drive encryption

Software

• Unneeded software running

• Unpatched software

• Weak applications

Page 12Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Realizing Threats

 Steps attackers take to realize threats:

Search for accessible computers.

Scan computers for running

services/applications.

Research potential

vulnerabilities.

Develop attack plan.

Carry out attack.

Page 13Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Protecting from Threats

 Steps you can take to protect from threats:

Apply all available security patches.

Use a firewall to protect and hide computers from external scans.

Disable unneeded

services and programs.

Configure all necessary services

and programs to limit access.

Perform penetration tests to search for unprotected

vulnerabilities.

Page 14Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Discovery-Analysis-Remediation

Cycle

Page 15Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Common Forms of Attack

Threat Description

Trojan horse A malicious program that tricks users into

running it—often through social

engineering

Backdoor Programs that allow unauthorized access

Denial of service Any action that dramatically slows down or

blocks access to one or more resources

Robot/intermediary

process

A process that runs on one target

computer that launches attacks on other

computers

Unprotected

Windows Share

A situation that allows attackers to install

tools, including malicious software

Page 16Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Common Forms of Attack (Cont.)

Threat Description

Mobile code Java/ActiveX malicious code that is

sent to clients before being executed

Cross-site scripting Specially crafted malicious code used

to attack Web applications

Packet sniffing The process of collecting network

messages as they travel across a

network in hopes of divulging

sensitive information, such as

passwords

Page 17Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Chapter 2 Slides

Chapter 2: Security in the Microsoft Windows

Operating System

Page 18Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Organization of the Windows

Operating System

Page 19Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Windows Process Table

Contents

Page 20Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Basic Windows Operating

System Architecture

Page 21Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Identification and Authentication

 Identification—a claim to be someone

 Authentication—evidence to prove you are

who you claim to be

• Type I–What you know (password)

• Type II–What you have (token)

• Type III–What you are (biometrics)

Page 22Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Access Control Methods

Access Control Methods

• Discretionary access control (DAC)

• Mandatory access control (MAC)

• Role-based access control (RBAC)

Page 23Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Tokens, Rights, and Permissions

 Security access token (SAT)

 User rights: Actions a user can carry out

 Permissions: What a user can do to a

specific object

Page 24Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Computer Management Tool

Page 25Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Windows Users and Groups

 User account as primary identification is

used by Windows

 Group allows a logical collection of user

accounts

 SAT allows local rights to be written

Page 26Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Active Directory

 Directory services implemented through

centralized shared database, user and

group definitions, and shared access

controls

 Domains and organizational units (OUs)

group computers

 Shared data stored on a domain controller

Page 27Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Active Directory (Continued)

 Central user definitions simplify security

administration

 User have the same security identifier (SID)

anywhere in the domain

 Workgroup users have different SIDs for

each computer

Page 28Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Implement Users, Groups, and

Active Directory

Define user IDs for each

user.

Define roles for each user category.

Determine authorization for each role.

Install Active Directory (AD).

Create AD permissions for network-wide roles.

Page 29Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Where Active Directory is Most

Valuable

 Enterprise applications

 Networks with shared resources

 Centralized administration

 Administrators that manage multiple

computers

 Users that connect from different computers

Page 30Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Multilayered Defense

Firewall

Access Control

Encryption

Protected Resource

Page 31Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Windows Security Monitoring

and Maintenance Security Monitoring

Define security goals

Describe secure behavior as a baseline

Sample performance information and compare with the baseline

Report anomalies

Identify Vulnerabilities

Identify vulnerabilities

Make a plan to address each vulnerability

Page 32Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Summary

 Information security

 Microsoft Windows and the typical IT infrastructure

 Anatomy of Microsoft Windows systems and their

application vulnerabilities

 Purpose of access control, authentication, and

creating users and groups

 Security features of directory services

Page 33Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Virtual Lab

 Implementing Access Controls with

Windows Active Directory

Page 34Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

OPTIONAL SLIDES

Page 35Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company

www.jblearning.com

All rights reserved.

Seven Domains of a Typical IT

Infrastructure