Fundamental Security Concepts
CIA Triad
These are the fundamental security objectives. (Sometimes also called the AIC Triad)
Confidentiality Prevent disclosure of information to unauthorized individuals or systems. Ex: Encryption of data, Access controls, Two factor authentication etc.
Integrity Messages can't be modified without detection. Same information is shared as sent by the user to the receiver. Ex: Hashing, Digital Signature, Certificates, Non-repudiation etc.
Availability Systems and networks must be up and running. Ex: Redundancy, Fault Tolerance, Patching.
Non-Repudiation
It is about proving the authenticity and integrity of a communication or transaction, preventing parties from later denying their involvement or actions. Ensuring that data sent to any 3rd party is really coming from the sender.
This is done in two steps:
Proof of Integrity
Proof of Origin
Proof of Integrity
The data is consistent and accurate.
To check a cryptographic method called hashing is used. Hashing simply means representing any given data as a short string. So, if the data changes a little bit the receiver can calculate the hash and compare it with the hash sent by the sender to have a proof of integrity. This is also called as a message digest or a fingerprint.
It does not help in identifying the sender.
Proof of Origin
The data is authentic i.e. proof that the information is confirmed to be from the source it claims to be from.
Making sure the signature or the digital signature is not fake.
This is done by creating a digital signature using private key only known to the source and verified using a public key. Since any change if at all made in the msg would invalidate the signature.
The process goes like this:
A msg file is created and a hash string is created for that msg file.
The source uses their private key to encrypt the hash string creating a digital signature and attaching it in the msg file.
The sent msg file when received is separated in two parts:
Digital Signature
Msg file
A hash string is created using the same method as used by the source.
A public key (which is known to all) is used decrypt the digital signature and find the original hash string sent by the source.
After comparing the hash strings we get either:
The hash strings match and verifies that the msg accurate and authentic.
The hash strings did not match which shows that the msg was tampered. Assuming the source itself is not compromised.
AAA Framework
(Authentication, Authorization, Accounting)
Authentication:
Prove you are who you say you are (Identity)
Through help of passwords or other authentication factors Authorization:
Based on your identification and authentication, what access do you have? Accounting:
Keeping logs about resources used like, Login time, data sent and received, logout time etc.
Since most of the times the computers or systems that try to gain access to resources from a server may not always come from one location, then how does one truly authenticate a device? This is done by the help of digital signed certificates. These certificates are issued by the company or the server handlers to computers which they want to give access to. (This provides additional authentication). There are various processes that also rely on certificates like access to VPN from authorized devices or management software can validate the end device. Although identification or simply logging in to a website or server could serve for authentication, this additional level of security is required so that no unknown device that accidently gets access to someone's credentials can access the resources. Ex: Company provided laptops comes with various installed software that checks and authenticates the server that the computer is known to the company and is allowed to connect to company servers through VPN.
An organization must have a trusted Certificate Authority (CA). This CA manages and distributes the required certificates to known and allowed computers.
Now that someone is authenticated how does one authorize what resources they have access to? This is done through various authorization models. We will study about various models in chapter 4. Simply sharing this information individually would work for small number of access but it runs into problem when it is scaled to a large number.
GAP Analysis
This analysis all about "where you are" compared with "where you want to be" in terms of your security. Now the goals could be set towards a known baseline like:
NIST Special Publication 800-171 Revision-2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.
ISO/IEC 27001, Information security management systems. Of course, an organization can also create their own baselines based on requirements needed for security.
The analysis begins by evaluating the existing systems. Along with identifying the weakness and the figure out what are the most effective processes to either compensate or correct those weaknesses. Ultimately creating a detailed analysis report over broad security categories and then breaking them into smaller segments for better understanding.
Zero Trust
In many networks once someone gets in through the firewall the internal network are relatively open. This allows authorized users to get any information they want but also the malicious actors or software. Hence, many security administrators are changing it so that before accessing any data or resource one might need to authenticate themselves each time. (This is called as Zero Trust approach). This means everything must be verified and nothing is inherently trusted. Use of multi-factor authentication, system permissions, additional firewalls etc.
To create such a security setup, one splits the network into functional planes. This applies to all physical, virtual, and cloud components. Separation of functional tasks:
Data plane: Process the frames, packets and network data.
Control Plane: Manages the actions of the data plane by defining policies and rules, like determines how packets should be forwarded or using routing tables, session tables etc.
Controlling Trust:
Adaptive Identity- Considers the source and the requested resources and tries to identify whether trustworthy or not. Looks into risk indicators like relationship with the organization, physical location, type of connection, IP address etc.
Threat scope reduction- By limiting the number of possible entry points.
Policy driven access control- Combines the adaptive identity with a predefined set of rules to truly and closely authenticate the user.
Security Zones: Security is more than a one-to-one relationship. We see where one is trying to connect from and where they are trying to connect to, like trusted and untrusted networks, internal and external networks, through different VPNs, or different teams trying to connect to different teams Marketing, IT, HR etc. These zones help in designing policies for implicit trust as well as to deny access based on zones connection.
Policy Enforcement Point (PEP): To enforce all such policies to any system or subject that is trying to connect to the network, PEP is crucial. PEP acts as a gatekeeper. PEP is not necessarily a single entity but could be a combination of multiple systems working together. PEP does provide the decision, but it just forwards the query to the Policy Decision Point which goes through a process for making an authentication. It is divided into two parts: Policy Engine: This evaluates each access decision based on policy and other information sources (Gives decision). Policy Administrator: It generates any access tokens or credentials if required based on the decision and communicates it back to PEP. Tells PEP to allow or disallow access.
Physical Security
CCTV, access control vestibules (Electronic locks), warning signs, fences, guards and access badges, proper lightning (proper illumination), sensors etc.
Deception and Disruption
Deception is the key for any security breach. But deception can also be used to fool the attacker or bad guys. One such method is called Honeypots. It is a virtual world designed to look and imitate like the real one but not in all aspects. It is used to trap and study the attacker mindset and methods used in attacks. These honeypots are mostly open source and customizable. This also ensues a constant battle to discern the real from the fake between the attacker and the honeypots designer. It is common to combine such smaller honeypots to imitate like a real network which might include firewalls, switches etc. These networks are called Honeynets. For more information: - https://projecthoneypot.org
Going into files and creating dummy files which look important but are just baits for honeynets. Normally no one should access these files until someone is trying to pry into places they are not supposed to. These types of files are called Honeyfiles. If someone tries to access such files an alert can be generated. Honeytokens are pieces of traceable data that is used to track malicious actors. For ex: Sharing fake email addresses and monitoring the internet to see who posts it, or sharing API credentials (of course false ones) in some public access so when these credentials are used notification can be send.
That it for today. Thank you reading. Feel free to comment about the content or for feedback.
Thank You!