Showing posts with label SSCP. Show all posts
Showing posts with label SSCP. Show all posts

Sunday, March 10, 2013

CASP Now Approved for DoD 8570

The CompTIA Advanced Security Practitioner (CASP) certification is a newer certification from CompTIA that is starting to get more attention. It was recently approved as one of the certifications by Department of Defense (DoD) and is listed on the same level as the CISSP certification in some categories.

 I have written about the (CASP) certification in the past in these blogs:

Where Does CASP Fit In?

A common question that many people ask is "Where does the CASP fit in when compared to other security certifications. The following list includes some common security certifications from easiest to most difficult:
There are other certifications but these are some that are commonly pursued by many individuals.

It's easier to understand how the CASP fits into the DoD certifications if you understand the basics of the certification levels. The following topics explain the DoD IT hierarchy, shows how different certifications fit into different levels.

DoD Approved 8570 Baseline Certifications

As an extension of Appendix 3 to the DoD 8570.01-Manual, several certifications have been approved as Information Assurance (IA) baseline certifications for the IA Workforce. Personnel performing IA functions must obtain one of the certifications required for their position category or specialty and level.

This page provides a listing of the specific certifications required at each level, but here's a short summary.

DoD Information Technology Hierarchy

The DoD IT hierarchy is divided into three general levels (Level I, Level II, and Level III) and each of the IA levels are related to one of these levels.

Level I

Level I is the basic computing environment and often referred to as a local computing environment. In general, this refers to desktop and laptop computers and hand held computing devices. A computing environment may have one or more servers.

Level II

Level II is the networking environment. It can include an operations network, a logistics network, and a human resources network.   Level II networks are connected to Level I computing environments.

Level III

Level III refers to an enclave environment. It consists of two or more networks controlled by enclave security policies and procedures. A Level III enclave environment is connected to one or more Level II network environments.

Information Assurance Technical (IAT)

In general, IAT positions include anyone that require privileged access to a DoD information system Computing, Network, or Enclave environment. For example, anyone requiring administrative access for a system fits into this category. IAT Level I
IAT Level II
IAT Level III

Information Assurance Management (IAM)

In general, IAM positions include anyone that has responsibility for managing information system security for a DoD Information System Computing, Network, or Enclave environment.
IAM Level I
IAM Level II
IAM Level III

Information Assurance System Architect and Engineer (IASAE)

In general, IASAE positions include anyone that has responsibility for the design, development, implementation, and/or integration of a DoD IA architecture, system, or system component for a DoD Information System Computing, Network, or Enclave environment?

IASAE Level I
IASAE Level II
IASAE Level III
  • CISSP - ISSEP
  • CISSP - ISSAP

Summary

The CompTIA Advanced Security Practitioner (CASP) certification is now approved for certain DoD levels. Because of this, you can expect to see this certification to get more recognition and respect going forward. In some cases, this is on the same level as the CISSP certification.

Monday, February 18, 2013

Risk Management


If you're planning on taking the Security+SSCP, or CISSP exam you should understand the common risk management methods used by security professionals. As an example, Objective 2.1 "Explain risk related concepts" for the CompTIA Security+ exam lists risk-avoidance, transference, acceptance, mitigation, and deterrence.  

Risk management is the practice of identifying, monitoring, and limiting risks to a manageable level. It doesn’t eliminate risks, but instead identifies methods to limit or mitigate them. The amount of risk that remains after managing risk is residual risk.

The primary goal of risk management is to reduce risk to a level that the organization will accept. Senior management is ultimately responsible for residual risk—the amount of risk that remains after mitigating risk. Management must choose a level of acceptable risk based on their organizational goals. They decide what resources (such as money, hardware, and time) to dedicate to mitigate the risk.

Practice Question

Consider this question:

Q. Joe is evaluating security controls related to a known vulnerability. This vulnerability has resulted in two events in the past year resulting in losses of $3,000 each. A third-party company says they can eliminate the losses at a cost of $5,000. What should you do?

A. Do nothing and save $5,000
B. Mitigate the risk and save $2,000
C. Transfer the risk and save $1,000
D. Transfer the risk and save $2,000

The answer is below, but if you understand some common terms related to risk management, you can answer the question correctly.
Pass the Security+ exam the first time you take it:
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

Risk Avoidance

An organization can avoid a risk by not providing a service or not participating in a risky activity.

For example, an organization may evaluate an application that requires multiple open ports on the firewall that it considers too risky. It can avoid the risk by not using the application. 

Risk Transference

An organization can transfer the risk to another entity. The most common method of risk transference is by purchasing insurance. Another method is by outsourcing the risk, or contracting a third party to manage the risk. 

Risk Acceptance

When the cost of a control outweighs the potential losses of a risk, an organization will often accept the risk. For example, spending $100 in hardware locks to secure a $15 mouse doesn’t make sense. Instead, the organization accepts the risk of someone stealing the mouse.

Similarly, even after implementing controls, some risk remains and the organization accepts this residual risk.

Risk Mitigation

When an organization implements controls to reduce the risk, it is referred to as risk mitigation. These controls may reduce the vulnerabilities or weaknesses in a system, or they may reduce the impact of the threat. For example, up-to-date antivirus software mitigates the risks of malware by reducing a system's vulnerability to malware. 

Risk Deterrence

An organization can deter a risk by implementing some security controls. For example, security guards and monitoring cameras can deter losses from different types of risks. A security guard mitigates the risk of tailgating and cameras can mitigate risks associated with theft.

Some security professionals identify the first four methods of risk management but don’t include risk deterrence. Instead, they include deterrence methods within the risk mitigation category. However, the Security+ objectives list these five.

Quantitative Risk Management

There are times when you need to calculate costs related to risks using a quantitative risk management method. When using a quantitative method you should understand the following terms:
  • Single loss expectancy (SLE). The SLE is the cost of any single loss.
  • Annualized rate of occurrence (ARO). The ARO indicates how many times the loss is expected to occur annually. 
  • Annualized loss expectancy (ALE). The ALE is the SLE x ARO.

Practice Question Answer

Q. Joe is evaluating security controls related to a known vulnerability. This vulnerability has resulted in two events in the past year resulting in losses of $3,000 each. A third-party company says they can eliminate the losses at a cost of $5,000. What should you do?

A. Accept the risk and save $1,000
B. Mitigate the risk and save $2,000
C. Transfer the risk and save $1,000
D. Transfer the risk and save $2,000

Answer

C is the correct answer.  Outsourcing the risk by contracting a third party is risk transference and if you transfer the risk to a third-party, you can save $1,000.

The ARO is 2.

The SLE is $3,000.

The ALE  is $6,000 ($3,000 X 2)

The cost of the control is $5,000.

In this case, you can spend $5,000 to prevent the losses of $6,000 effectively saving $1,000.

Because the cost of the control ($5,000) is less than the expected losses ($6,000), it makes fiscal sense to purchase the control. (An organization will likely evaluate other factors but in general when the cost of the control is less than the losses it's expected to remove, the control is worth the cost. If the control costs more than the losses it can prevent, it is not worth the cost.)

A is not correct. If you accept the risk, you will still be losing $6,000 annually. Based on the scenario, accepting the risk cannot result in a savings of $1,000. However, if the cost of the control was $7,000 (instead of $5,000), accepting the risk could be interpreted as a savings of $1,000.  You could spend $7,000 or do nothing and lose $6,000. Doing nothing (accepting the risk) is $1,000 cheaper.

B is not correct. Mitigating the risk means that you are doing something to reduce it. Outsourcing the risk to a third-party is rarely referred to as mitigating the risk. Also there isn't any math that results in a savings of $2,000 within this scenario.

D is not correct. Outsourcing to a third-party is risk transference. However, this results in a savings of $1,000 rather than $2,000.

Summary

Ensure you understand the basics of a risk management methods when taking any security-based exam such as the Security+SSCP, or CISSP exams. The primary methods are known as risk avoidance, risk transference, risk acceptance, risk mitigation, and risk deterrence.


Saturday, February 16, 2013

Smurf Attacks


If you're planning on taking the Security+SSCP, or CISSP exam you should know about many of the attack types such as the smurf attack.  As an example, Objective "3.2 Analyze and differentiate among types of attacks"  for the CompTIA Security+ exam lists several common types of attacks including the smurf attack.

A smurf attack spoofs the source address of a broadcast ping packet to flood a victim with ping replies. That's a complex sentence, so it's worthwhile breaking this down. 

A Ping is Normally Unicast

A ping is normally a unicast message sent from one computer to one computer. It sends ICMP echo requests to one computer, and the receiving computer responds with ICMP echo responses.  Figure 1 shows how this works. Computer 1 is sending out a unicast ping to computer 3 and computer 3 responds with ICMP replies.
Ping uses unicast
Figure 1
If you receive the responses you know that the other computer is operational.

Note: Because ICMP is used in many types of attacks, many firewalls block ICMP echo requests. If you don't receive ping responses back it doesn't necessarily mean the other computer is not operational. It could be because the ping is being blocked by a firewall.

On Windows systems, ping sends out four ICMP requests and gets back four replies. On  some other operating systems, ping continues until stopped. You can add the -t switch to ping on Windows systems causing ping requests to continue until stopped.
Pass the Security+ exam the first time you take it:
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

A Smurf Attack Sends the Ping Out as a Broadcast

Instead of using a unicast message, a smurf attack sends out the ping request as a broadcast.  In a broadcast, one computer sends the packet to all other computers in the subnet. These computers then reply to the single computer that sent the broadcast ping as shown in Figure 2. Computer 1 is sending out a broadcast ping to all the computers on the subnet and each one of them are now responding, flooding the computer with ping replies.
Ping using broadcast instead of unicast
Figure 2
If computer 1 is the attacker, the results of Figure 2 aren't very beneficial.  If something isn't changed, the attacker gets attacked.

The Smurf Attack Spoofs the Source IP

If the source IP address isn’t changed, the computer sending out the broadcast ping will get flooded with the ICMP replies. Instead, the smurf attack substitutes the source IP with the IP address of the victim, and the victim gets flooded with these ICMP replies. Figure 3 shows how computer 1 can send out the smurf attack using computer 2's IP address as the source IP address. All the computers on the subnet then flood computer 2 with ICMP replies.
Broadcast ping spoofing the source IP address
Figure 3

Smurf Attacks Use Amplifying Networks

A smurf amplifier is a computer network used in a smurf attack. This is easily prevented by blocking IP directed broadcasts used by smurf attacks. However, if a router or a firewall isn't configured to protect the network, it can become part of the attack.

Figure 4 shows how this works. The attacker (computer 1) sends a broadcast ping into the amplifying network with a spoofed source IP address of computer 6. Each computer in the amplifying network receives the broadcast and then responds by flooding the victim (computer 6) with ping replies.
Smurf attack using amplifying network
Figure 4

Not Blue Packets

The rumor that a smurf attack is one where attackers send out little blue packets that report back to Papa Smurf is simply not true.
Smurfs

Summary

Ensure you understand the basics of a smurf attack when taking any security-based exam such as the Security+SSCP, or CISSP exams. A smurf attack spoofs the source address of a broadcast ping packet to flood a victim with ping replies. Smurf attacks are known to use amplifying networks but administrators commonly block this rules on a router or firewall.

Monday, April 9, 2012

SSCP Practice Test Questions

If you've been studying for the SSCP exam, you may be looking for a good source of SSCP practice test questions. You'll find that the SSCP Systems Security Certified Practitioner All-in-One Exam Guide covers the content in the exam but I'm hearing that test questions from the studISCope test banks are the most helpful.

(ISC)2 changes the questions in their live test bank regularly and they also update their practice test questions in the studISCope banks. Here's a link: https://www.expresscertifications.com/ISC2/Catalog.aspx.

The SSCP is a good next step for many people that have taken and passed the Security+ exam. It will give you a good idea of what to expect from the premier security certification - CISSP - if you choose to take it. Also, many people have the experience to meet the requirements for SSCP, but not CISSP. As a reminder, the requirements are:
  • For the SSCP, you need one year of experience in one the seven (ISC)2 domains.
  • For the CISSP, you need five years of experience on one of the ten domains.
Good luck.

Tuesday, February 28, 2012

Protocol IDs for Security+ and SSCP Exams

If you're preparing for the Security+ or SSCP exams, you'll need to know a few of the protocol IDs used by TCP/IP. The protocol ID is a number embedded in the header of the packet to identify the protocol. It is used for many protocols that are not identified with a port number.

I recently wrote a blog titled Ports for Network+, Security+, and SSCP Exams which covered the relevant port numbers for these exams. Both port numbers and protocol IDs are used to identify protocols by devices such as routers and firewalls. However, they are different numbers. For example, Hypertext Transfer Protocol (HTTP) uses port number 80, but it is not accurate to say that it uses protocol ID 80. In fact, there isn't a protocol ID that identifies HTTP.

Practice Test Question

Test your knowledge of protocol IDs with this question. This is an example that you may see on the SSCP exam.

Q. You want to block DoS attacks using ping at a firewall. What would you do?

A. Block port 1 at the firewall

B. Block protocol ID 1 at the firewall

C. Block port 6 at the firewall

D. Block protocol ID 6 at the firewall

Answer at end of blog

Protocol IDs

The following table identifies some of the commonly used protocol IDs that you may be tested on.
Protocol Protocol ID
ICMP - Internet Control Message Protocol 1
IGMP - Internet Group Management Protocol 2
TCP - Transmission Control Protocol 6
UDP - User Datagram Protocol 17
IPsec ESP - Internet Protocol security Encapsulating Security Payload 50
IPsec AH - Internet Protocol security Authentication Header 51
You are more likely to be tested on the protocol IDs in the SSCP exam. If you do see this content on the Security+ exam, it will probably only focus on IPsec ESP or IPsec AH. If you want to see a full listing of protocol ID numbers, check out this list on Internet Assigned Numbers Authority (IANA).
Pass the Security+ exam the first time you take it:
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide
Routers and firewalls use access control lists (ACLs) to filter traffic. They can filter traffic based on IP addresses, network IDs, ports, and protocol IDs. The ports are used to filter traffic using well-known ports mapped to specific protocols. For example, you can block or allow outgoing email by closing or opening port 25, the well-known port for Simple Mail Transport Protocol (SMTP). Similarly, you can block ICMP traffic (used by ping) by blocking any traffic using protocol ID 1.

Q. You want to block DoS attacks using ping at a firewall. What would you do?

A. Block port 1 at the firewall

B. Block protocol ID 1 at the firewall

C. Block port 6 at the firewall

D. Block protocol ID 6 at the firewall

Answer: B

Ping uses Internet Control Message Protocol (ICMP) and ICMP is identified with protocol ID 1. Blocking protocol ID 1 blocks all pings including a denial-of-service (DoS) attack using ping.

Ports 1 and 6 are unrelated to ping or ICMP so would not have any effect on blocking pings.

Protocol ID 6 identifies Transmission Control Protocol (TCP) so by blocking protocol ID 6, you would block all TCP traffic.


Saturday, February 25, 2012

Ports for Network+, Security+, and SSCP Exams

If you're planning on taking a certification exam such as CompTIA Security+, CompTIA Network+, or SSCP you should have many of the well-known ports memorized. The objectives for the CompTIA Network+ exam lists many of the protocols and the ports spelling out exactly what you need to know. Similarly, the objectives for the CompTIA Security+ exam lists several protocols with a statement to identify the ports for each. The SSCP exam objectives are very generic but do indicate port numbers are needed.

Well known port numbers are matched to specific protocols and when you see the port, you should be able to identify the protocol. Sometimes you may be given the protocol and be required to identify the port. There are 1024 well known TCP and UDP (numbered 0 through 1023) but you don't need to memorize them all. However, you do need to know certain ports for the CompTIA Security+, CompTIA Network+, and SSCP exams.

Logical Ports

The well-known ports are logical ports and have nothing to do with physical ports. For example, port 80 is the port used for Hypertext Transfer Protocol (HTTP) and port 443 is the port used for Hypertext Transfer Protocol Secure (HTTPS).

In contrast, a physical port on a switch or router is used to make a physical connection between devices. You can touch the physical port while the logical port is simply a number embedded in the packet.

Every packet has both a source port and a destination port along with a source IP address and a destination IP address. The IP address is used to get the packet to the destination system and when the packet is received, TCP/IP uses the port information to determine how to handle the packet. This blog on Understanding Ports for Security+ describes the process of how logical ports are used in more detail.
Pass the Security+ exam the first time you take it:
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

TCP and UDP

Each of these logical ports are technically identified as either a Transmission Control Protocol (TCP) port or a User Datagram Protocol (UDP) port depending on which transport protocol they use. For example, HTTP can use either UDP port 80 or TCP port 80. It almost always uses TCP for guaranteed delivery but both TCP port 80 and UDP port 80 are reserved for HTTP.

Some protocols use only the UDP port. For example, Trivial File Transport Protocol (TFTP) uses UDP port 69 but not TCP port 69.

As you advance in the IT field, you'll find that you need to know whether a protocol is using a TCP port or a UDP port. However for these exams, this depth of knowledge is rarely needed. Instead, you should focus on memorizing the port number. If you want to know specifically which transport protocol is used for any protocol, check out Wikipedia's list of TCP and UDP port numbers.

Interestingly, Internet Assigned Numbers Authority (IANA) previously identified which transport protocol was used for each port in their Service Name and Transport Protocol Port Number Registry . However, they seem to have defaulted to just listing both TCP and UDP for each port. For example, Telnet (defined in RFC 854) only uses TCP port 23, not UDP. However, IANAs port number registry lists both TCP and UDP for Telnet.

Network+ Ports

When preparing for the Network+ exam, you should know these ports.
Protocol Port
FTP - File Transport Protocol 20, 21
SSH - Secure Shell 22
Telnet 23
SMTP - Simple Mail Transport Protocol 25
DNS - Domain Name System 53
DHCP - Dynamic Host Configuration Protocol 67, 68
TFTP - Trivial File Transport Protocol 69
HTTP - Hypertext Transfer Protocol 80
HTTPS - Hypertext Transfer Protocol Secure 443
SSL VPN - Secure Sockets Layer virtual private network 443
POP3 - Post Office Protocol version 3 110
NTP - Network Time Protocol 123
IMAP4 - Internet message access protocol version 4 143
SNMP - Simple Network Management Protocol 161
IPsec - Internet Protocol security (through the use of ISAKMP - Internet Security Association and Key Management Protocol) 500
RDP - Remote Desktop Protocol 3389
When you know the ports and understand the protocols, questions are much easier to answer. For example, consider this practice test question that could be in a Network+, Security+, or SSCP exam:

Q. What port do you need to close to block outgoing email?

A. Port 22

B. Port 25

C. Port 110

D. Port 443

Answer at the end of the blog.

Security+ Ports

When preparing for the Security+ exam, you should know these ports.
Protocol Port
FTP - File Transport Protocol 20, 21
SSH - Secure Shell 22
SFTP - Secure File Transport Protocol (uses SSH) 22
SCP - Secure Copy (uses SSH) 22
Telnet 23
SMTP - Simple Mail Transport Protocol 25
TACACS - Terminal Access Controller Access-Control System 49
DNS - Domain Name System 53
DHCP - Dynamic Host Configuration Protocol 67, 68
TFTP - Trivial File Transport Protocol 69
HTTP - Hypertext Transfer Protocol 80
HTTPS - Hypertext Transfer Protocol Secure 443
SSL VPN - Secure Sockets Layer virtual private network 443
Kerberos 88
POP3 - Post Office Protocol version 3 110
NNTP - Network News Transfer Protocol 119
IMAP4 - Internet message access protocol version 4 143
SNMP - Simple Network Management Protocol 161
SNMP Trap - Simple Network Management Protocol Trap 162
LDAP - Lightweight Directory Access Protocol 389
ISAKMP (VPN) - Internet Security Association and Key Management Protocol (virtual private network) 500
Syslog 514
L2TP - Layer 2 Tunneling Protocol 1701
PPTP - Point-to-Point Tunneling Protocol 1723
RDP - Remote Desktop Protocol 3389

SSCP Ports

The list of SSCP ports is a little easier for me to create. It's simply all of the ports listed in the previous two tables. The (ISC)2 objectives do not list specific ports that you need to know but instead include the words "Commonly Used Ports and Protocols". Theortically, they can ask you about any of the ports but you're unlikely to see anything other than what is listed here. If you do, please let me know.

Practice Test Question Answer

Q. What port do you need to close to block outgoing email?

A. Port 22

B. Port 25

C. Port 110

D. Port 443

Answer: B

Port 25 is used for SMTP and SMTP is used for outgoing email.

Port 22 is used for SSH, SFTP, and SCP but not for email.

Port 110 is used for POP3 but POP3 is only used for incoming email, not outgoing email.

Port 443 is used for HTTPS, not email.

Wednesday, February 1, 2012

DoS, Smurf, and Fraggle Attacks

Denial of service (DoS) attacks such as smurf and fraggle attacks are important to understand when studying for any security certification including Security+, SSCP, or CISSP. Smurf and fraggle attacks are similar but they have subtle differences.

DoS Attack

A DoS attack comes from a single entity and is intended to make a computer’s resources or services unavailable to users. DoS attacks against a server prevent the server from responding to legitimate requests from users. A distributed DoS (DDoS) attack comes from multiple attackers at the same time.


Pass the Security+ exam the first time you take it.
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide




Smurf Attack

A smurf attack uses Internet Control Management Protocol (ICMP) to send a broadcast ping with a spoofed source address. It's easier to understand this by looking at one step at a time.
  • Normal ping. A regular ping sends one or more ICMP echo requests to a system and the system responds with one or more ICMP echo replies. This provides verification the remote system is operational. A regular ping uses unicast. In other words, the ICMP packet is addressed to one system from one system.
  • Broadcast ping. A broadcast ping is not normal. It sends the ICMP echo request to a broadcast address sending it to virtually all systems on the network. Each system will then respond to the system that sent it flooding this system with ICMP echo replies.
  • Spoofed source broadcast ping. The smurf attack spoofs the source address with the address of the victim, and then sends it out as a broadcast ping. Each system on the network will then respond, and flood the victim with echo replies.
There's an important point to remember though. Routers do not pass broadcast packets. This was actually a change in RFC 2644 released in 1999 in direct response to smurf attacks and the use of networks as smurf amplifiers. RFC 2644 is an update to RFC 1812 which stated that a router must default to forwarding directed broadcasts. Routers today comply with RFC 2644 so smurf attacks are limited to a broadcast domain. They will not go beyond a router.

With this in mind, it would be rare to see a smurf attack. However, that doesn't mean it won't be tested.

Note: Many firewalls block ICMP packets to prevent any type of attack using ICMP. If a ping succeeds, it verifies that the system is operational. However, if a ping fails it doesn't prove that the system is not operational. ICMP may be blocked preventing the ping.


Studying SSCP?
This book covers the new objectives effective Feb 1, 2012.
SSCP Systems Security Certified Practitioner All-in-One Exam Guide




Fraggle Attack

Fraggle attacks are similar to smurf attacks but instead of using ICMP, they use UDP ports 7 and 19.

As described earlier, the ping command uses ICMP and it is used to check if a system is operational. Tools are available that use UDP instead of ICMP and instead of checking to see if a system is operational, they check to see if the system is listening on a specific port. This is commonly done with many different types of vulnerability scanners used by both attackers and security administrators.

Chargen (character generator) is an older protocol described in RFC 864 (dated May 1983). A system listens on either TCP or UDP port 19 (known as the chargen port) for chargen requests. When a connection is established to this port, the system would respond with a constant stream of characters to the original system. Typically the original system would use TCP or UDP port 7 (known as the echo port) but this isn't required. When the original system begins receiving the characters, it knows the target system is operational, and closes the connection.

In a fraggle attack, a spoofed broadcast packet is sent to port 17. The spoofed address is the address of the victim. Since it is broadcast, it goes to every system on the network. If port 17 is open and the character generator service is running on these systems, they will send a stream of characters to the victim.

Realistically, systems today will not have port 17 open or the chargen service running. Additionally, routers do not pass broadcasts so any attacks are limited to a single network. Said another way, it is very unlikely you will ever see a fraggle attack today.


Looking for quality Practice Test Questions for the SY0-301 Security+ exam?
CompTIA Security+: Get Certified Get Ahead- SY0-301 Practice Test Questions




Basic Protection

In addition to ensuring that routers are configured in compliance with RFC 2644 and do not pass broadcasts, there are some other basic steps that protect you from these types of attacks:
  • Disable unnecessary services and protocols. If a service or protocol is not needed on a system, it should not be enabled. I cannot think of a system in use today that would need the chargen service so it should be disabled if it is even available on the system.
  • Close unneeded ports. If a port is not needed, it should be closed on both network-based and host-based firewalls. With the port closed, all traffic is blocked and attacks are stopped.
  • Use ingress filters on firewalls. Don't allow traffic into a network that shouldn't be there. A common ingress filter on a boundary firewall (between the Internet and an internal network), blocks all traffic coming from the Internet with a spoofed private IP address.

Summary

In summary, DoS attacks such as smurf and fraggle attacks attempt to prevent a system from responding to legitimate attacks. A smurf attack sends a broadcast ping with a spoofed IP address (the IP address of the victim), and ping uses ICMP. A fraggle attack uses UDP ports 7 and 19 instead of ICMP, and sends broadcast UDP traffic with a spoofed IP address (the IP address of the victim).

Monday, December 26, 2011

Identification, Authentication, and Authorization

If you're studying for one of the security certifications like CISSP, SSCP, or Security+ it's important to understand the difference between identification, authentication, and authentication. These concepts are intertwined, but have specific differences. When looking at these topics, especially for the SSCP and CISSP exams, it's important to understand the differences between subjects and objects.
  • Subject. A subject is the active entity that accesses an object. For example, when a user accesses a file, the user is the subject. Other subjects include programs, processes, and any entity that can access a resource.
  • Object. An object is a passive entity that is being accessed by a subject. For example, when a user accesses a file, the file is the object. Other objects include databases, computers, printers, or any other resource that can be accessed by a subject.


Pass the Security+ exam the first time you take it.
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide




Identification

Identification occurs when a user (or any subject) claims or professes an identity. This can be accomplished with a username, a process ID, a smart card, or anything else that can uniquely identify a subject. Security systems use this identity when determining if a subject can access an object.


Looking for quality Practice Test Questions for the SY0-301 Security+ exam?
CompTIA Security+: Get Certified Get Ahead- SY0-301 Practice Test Questions




Authentication

Authentication is the process of proving an identity and it occurs when subjects provide appropriate credentials to prove their identity. For example, when a user provides the correct password with a username, the password proves that the user is the owner of the username. In short, the authentication provides proof of a claimed identity.

There are several methods of authentication that I'll cover in another post, but in short they are:
  • Something you know, such as a password or PIN
  • Something you have, such as a smart card, CAC, PIV, or RSA token
  • Something you are, using biometrics


Studying SSCP?
This book covers the new objectives effective Feb 1, 2012.
SSCP Systems Security Certified Practitioner All-in-One Exam Guide




Authorization

Once a user is identified and authenticated, they can be granted authorization based on their proven identity. It's important to point out that you can't have separate authorization without identification and authentication. In other words, if everyone logs on with the same account you can grant access to resources for everyone, or block access to resources for everyone. If everyone uses the same account, you can't differentiate between users. However, when users have been authenticated with different user accounts, they can be granted access to different resources based on their identity.

In summary, it's important to understand the differences between identification, authentication, and authorization when studying for security exams such as the Security+, SSCP, or CISSP exams. Identification occurs when a subject claims an identity (such as with a username) and authorization occurs when a subject proves their identity (such as with a password). Once the subject has a proven identity, authorization techniques can grant or block access to objects based on their proven identities.

Wednesday, December 21, 2011

Single Sign-On (SSO) and Federated Identity Management

If you're studying for one of the security certifications such as CISSP, SSCP, or Security+ it's important to understand single sign-on (SSO) concepts and federated access.

SSO refers to the ability of a user to log on or access multiple systems by providing credentials only once. It enhances security by requiring users to use and remember only one set of credentials for authentication. Once signed on using SSO, this one set of credentials is used throughout a user’s entire session.


Pass the Security+ exam the first time you take it.
CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide

Kerberos

Kerberos is an authentication protocol commonly used to help support SSO in many networks. When users authenticate, a Key Distribution Center (KDC) issues the user an encrypted time-stamped ticket-granting ticket (TGT). The TGT is cached on the user's system and normally has a lifetime of 10 hours but can be renewed. Kerberos uses symmetric cryptography to encrypt tickets and in most current implementations it uses Advanced Encryption Standard (AES). The KDC is also referred to as an authentication server (AS) or sometimes as a Kerberos authentication server (KAS).

When the user later wants to access a resource such as a file on a server, the user's system submits the TGT with a request to access the resource. The KDC validates the TGT and sends the user a ticket (sometimes called a service ticket) for the resource. The user's system then submits this ticket to the host of the resource (in this case the file server) with a request to access the resource. The host checks with the KDC to ensure that the ticket is valid and if so, allows access as long as the user is authorized.

Kerberos requires all systems to be time synchronized and the default in version 5 is for all systems to be within five minutes of each other. If a system is more than five minutes off, the KDC won't issue a TGT or any other tickets, effectively blocking all non-anonymous access on a network. It uses a database of credentials to authenticate users and uses port 88 by default.
A drawback with Kerberos is that it represents a single point of failure. If the KDC fails, all authentication stops. Additionally, if the KDC is compromised, all credentials are compromised.

Studying SSCP?
This book covers the new objectives effective Feb 1, 2012.
SSCP Systems Security Certified Practitioner All-in-One Exam Guide

Federated Identity Management

Identity management refers to the management of user identities and their credentials. For example, usernames and passwords are stored in a database that can be accessed by Kerberos to authenticate users. Users claim an identity and prove their identity by authenticating, such as with a password. In federated identity management, organizations join a group of organizations called a federation. All the organizations within the federation agree on a method to share identities between the organizations.
Once the federation is configured, users are able to log on one time within their organization and then access resources in other organizations without logging on again. This is usually transparent to the user.

As an example, I have worked in an organization where we logged on with smart cards. We had access to training sites hosted by other organizations but part of a federated identity management system. All we had to do was access the web site using a web browser, and our credentials were automatically recognized without requiring us to take any additional steps.

In summary, SSO methods can increase security by reducing the number of passwords users must remember. Federated access allows an organization to share identities between different organizations in a common group, or federation of organizations.