Application Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
ISOL534
Application Security
© 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Security Strategies in Windows
Platforms and Applications
Lesson 1
Security Features in
Microsoft® Windows®
Page 4Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Learning Objectives
Explain information security and how it applies to the
Microsoft Windows operating systems.
Explain security features of the Microsoft Windows
operating system.
Page 5Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Key Concepts
Information security
Microsoft Windows and the typical IT infrastructure
Anatomy of Microsoft Windows systems and their
application vulnerabilities
Purpose of access control, authentication, and
creating users and groups
Security features of directory services
Page 6Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Chapter 1 Slides
Chapter 1: Microsoft Windows and the
Threat Landscape
Page 7Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Security Controls
Type of Control
Type of Function
• Administrative
• Technical
• Physical
• Preventive
• Detective
• Corrective
Page 8Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
C-I-A
Page 9Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
A Sample IT Infrastructure
Page 10Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Microsoft EULA Sections
Potentially unwanted software
Internet-based services
Limitation and exclusion of damages
Exclusions from warranty
Limitation and exclusion of damages for breach of warranty
Page 11Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Common Windows
Vulnerabilities
Access Control
• Weak passwords
• Weak permissions
• Shared user accounts
Infrastructure
• No firewall
• No malware protection
• Weak security policy
• Weak drive encryption
Software
• Unneeded software running
• Unpatched software
• Weak applications
Page 12Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Realizing Threats
Steps attackers take to realize threats:
Search for accessible computers.
Scan computers for running
services/applications.
Research potential
vulnerabilities.
Develop attack plan.
Carry out attack.
Page 13Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Protecting from Threats
Steps you can take to protect from threats:
Apply all available security patches.
Use a firewall to protect and hide computers from external scans.
Disable unneeded
services and programs.
Configure all necessary services
and programs to limit access.
Perform penetration tests to search for unprotected
vulnerabilities.
Page 14Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Discovery-Analysis-Remediation
Cycle
Page 15Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Common Forms of Attack
Threat Description
Trojan horse A malicious program that tricks users into
running it—often through social
engineering
Backdoor Programs that allow unauthorized access
Denial of service Any action that dramatically slows down or
blocks access to one or more resources
Robot/intermediary
process
A process that runs on one target
computer that launches attacks on other
computers
Unprotected
Windows Share
A situation that allows attackers to install
tools, including malicious software
Page 16Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Common Forms of Attack (Cont.)
Threat Description
Mobile code Java/ActiveX malicious code that is
sent to clients before being executed
Cross-site scripting Specially crafted malicious code used
to attack Web applications
Packet sniffing The process of collecting network
messages as they travel across a
network in hopes of divulging
sensitive information, such as
passwords
Page 17Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Chapter 2 Slides
Chapter 2: Security in the Microsoft Windows
Operating System
Page 18Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Organization of the Windows
Operating System
Page 19Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Windows Process Table
Contents
Page 20Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Basic Windows Operating
System Architecture
Page 21Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Identification and Authentication
Identification—a claim to be someone
Authentication—evidence to prove you are
who you claim to be
• Type I–What you know (password)
• Type II–What you have (token)
• Type III–What you are (biometrics)
Page 22Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Access Control Methods
Access Control Methods
• Discretionary access control (DAC)
• Mandatory access control (MAC)
• Role-based access control (RBAC)
Page 23Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Tokens, Rights, and Permissions
Security access token (SAT)
User rights: Actions a user can carry out
Permissions: What a user can do to a
specific object
Page 24Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Computer Management Tool
Page 25Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Windows Users and Groups
User account as primary identification is
used by Windows
Group allows a logical collection of user
accounts
SAT allows local rights to be written
Page 26Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Active Directory
Directory services implemented through
centralized shared database, user and
group definitions, and shared access
controls
Domains and organizational units (OUs)
group computers
Shared data stored on a domain controller
Page 27Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Active Directory (Continued)
Central user definitions simplify security
administration
User have the same security identifier (SID)
anywhere in the domain
Workgroup users have different SIDs for
each computer
Page 28Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Implement Users, Groups, and
Active Directory
Define user IDs for each
user.
Define roles for each user category.
Determine authorization for each role.
Install Active Directory (AD).
Create AD permissions for network-wide roles.
Page 29Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Where Active Directory is Most
Valuable
Enterprise applications
Networks with shared resources
Centralized administration
Administrators that manage multiple
computers
Users that connect from different computers
Page 30Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Multilayered Defense
Firewall
Access Control
Encryption
Protected Resource
Page 31Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Windows Security Monitoring
and Maintenance Security Monitoring
Define security goals
Describe secure behavior as a baseline
Sample performance information and compare with the baseline
Report anomalies
Identify Vulnerabilities
Identify vulnerabilities
Make a plan to address each vulnerability
Page 32Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Summary
Information security
Microsoft Windows and the typical IT infrastructure
Anatomy of Microsoft Windows systems and their
application vulnerabilities
Purpose of access control, authentication, and
creating users and groups
Security features of directory services
Page 33Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Virtual Lab
Implementing Access Controls with
Windows Active Directory
Page 34Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
OPTIONAL SLIDES
Page 35Security Strategies in Windows Platforms and Applications © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company
www.jblearning.com
All rights reserved.
Seven Domains of a Typical IT
Infrastructure