Strong authentication and Smart Cards - ActivIdentity Blog

ActivIdentity Blog

« Back to Blog Homepage

Strong authentication and Smart Cards - ActivIdentity Blog

Jun 9, 2011 3:46pm by Julian Lovelock | 0 Comment
Bookmark and Share
For the last twenty years enterprise system security has been based on a very simple principle. Anyone already inside the network is decent and can get to pretty much any resource just by knowing the relevant password, whereas those outside the network need strong authentication. Call it the perimeter defense model. OTP tokens for VPN authentication; static passwords to log onto the ERP system once your inside. It’s the IT equivalent to having a strong lock on the front door of your building and a weak lock on your filing cabinet. You know, the one with your genius plans for world domination. Oh, and hiding the key to the filing cabinet on the very next shelf directly across.

And yet, to be honest, for most of those 20 years this strategy was good enough for a lot of companies. There were a few cases of people breaking in through a window, (think SQL injection attack on the company website) but this was usually fixed by bolstering the perimeter defenses or installing a burglar alarm (think Intrusion Detection Systems). Anyway, fitting strong locks to every internal door and filing cabinet (think strong authentication for laptops, workstations, servers and applications) was prohibitively expensive.

So what’s changed? Actually a couple of things have changed. Firstly, there’s the ubiquitous and ominous ‘Advanced Persistent Threat’. As the name implies, this is a broad term, but the pattern is often formulaic: Research your target both at an organizational level (suppliers, IT systems, etc.) and at an individual level (place of work, boss, vacation periods). Information that we would have once considered personal and private is now shared freely on business and social networking sites. Secondly, build yourself a piece of malware tailored to the target environment. Check out your friendly not-so-local-hacker website for starter kits and helpful tips. Thirdly, attach the malware to an email (it can look as innocuous as an attached .pdf file or a link to a website that is infected with a zero day vulnerability), make it look like it’s from a trustworthy source, and send it. Ideally, give it an enticing title such as ‘2011 Recruitment Plan’. Chances are that your unwitting target will open the attachment and you will have infected the recipient’s computer. You are inside the perimeter and no amount of strong authentication could have stopped you from getting there.

Now the attackers take advantage of the misplaced trust that is afforded to users already inside the network. Weak static passwords are all that stand between them and almost any system resource on the network. From the beach head of that one compromised machine they can sniff passwords, guess passwords, brute force password files, and take advantage of the fact that most users use the same password for multiple logins. With time they will gain access to any system they want.

Hence my assertion that strong authentication at the perimeter only is no longer sufficient. Eventually a persistent thieve will find a way into the building. If the contents are valuable to you, its time to start putting strong locks on the doors to your rooms and your filing cabinets. In IT terms -- that means implementing strong authentication at the level of individual desktop, laptops, servers and applications.

The other thing that’s changed - its no longer prohibitively expensive.
Tags: Enterprise System Security - Strong Authentication - OTP tokens

Post a Comment

All fields are required.

Name
Email
CAPTCHA Image
Please enter the text in the image above*

Legal Disclaimer
Some of the individuals posting to this blog website work for ActivIdentity Corporation ("ActivIdentity"). Opinions expressed in the blog postings and in any corresponding comments are the personal opinions of the original authors, not of ActivIdentity. The blog postings are provided for informational purposes only and are not meant to be an endorsement or representation by ActivIdentity or any other party. This blog website is available to the public. ActivIdentity moderates the comments and comments will not be posted until they are approved by the moderator. ActivIdentity does not guarantee that your comments will be posted to this blog website and ActivIdentity may refuse to post any comments in its sole discretion. No information you consider confidential should be posted to this blog website. By posting comments, you agree to be solely responsible for the content of all information you contribute, link to, or otherwise upload to this blog website. You release ActivIdentity from any liability related to your use of this blog website and the content on this blog website. Your use of this blog website is also subject to the terms and conditions of the ActivIdentity Legal Notice available at http://www.actividentity.com/legal/ (the "Legal Notice"). The blog postings are "materials" and any comments that you post to this blog website are "feedback," each as defined in the Legal Notice.
Bookmark and Share
Alltop, all the top stories
 Subscribe to our RSS Feed

Search Blog

Category

Identity & Access Management

Recent Posts

Apr 10, 2012: Preventing Scalable MitB Attacks - ActivIdentity Blog
Mar 9, 2012: Charges Brought Against Anonymous Hackers and Top Risks of Mobile Banking – Industry News Wrap-Up – ActivIdentity Blog
Feb 24, 2012: Identity Fraud via Mobile Devices and Cybersecurity Legislation Concerns – Industry News Wrap-Up – ActivIdentity Blog
Feb 24, 2012: Risk-based Authentication – ActivIdentity Blog
Feb 17, 2012: Android Malware & Bipartisan Cyber Security Bill – Industry News Wrap-Up – ActivIdentity Blog
Feb 13, 2012: Mobile Banking vs. Online Banking – Industry News Wrap-Up – ActivIdentity Blog
Feb 6, 2012: Explaining OCSP through the DigiNotar Attack – ActivIdentity Blog
Feb 3, 2012: Top 10 Security Threats of 2012 – Industry News Wrap-Up – ActivIdentity Blog
Dec 19, 2011: Mobile Security & Identity Theft – Industry News Wrap Up - ActivIdentity Blog
Dec 9, 2011: 2011 Cyber Attacks – Security Industry News Wrap-up – ActivIdentity Blog

Recent Comments

Evelin: Yes beuscae it's a Yes beuscae it's a Security...
jaffa: Great thing.
Interior Savings Online Banking: Internal financial savings on the web consumer...
john : You are we need to try more tactics to protect...
Murugesan: It differ from bank to bank, meergr to meergr. For...

Blogroll

The Forrester Blog For Security & Risk Professionals
Computer Weekly: David Lacey's IT Security Blog
Infosecurity Magazine: Security Viewpoint
Pro Security Zone: Editor's Blog
IT Pro
Adventures in Security
ha.ckers.org
Information Security: Security Bytes
Krebs on Security
SC: Data Breach Blog
Schneier on Security
Securosis
GovInfoSecurity.com: The Security Scrutinizer
GCN Tech Blog
Cybersecurity
Gartner Blog Network
Cnet: Insecurity Complex
Computerworld: Security Impact Blog
Computerworld: Security is Sexy
eWeek Security Watch
InformationWeek Security Weblog
Network World: Security Strategies Alert
ZDNet.com: Zero Day
Bank Info Security: Industry Insights
Bank Technology News
CRN Community: Hot Topics
Threatpost: Digital Underground