Detecting Abuse of Authentication Mechanisms – Abridged

5Mind. The Meme Platform

Summary

Malicious cyber actors are abusing trust in federated authentication environments to access protected data. An “on premises” federated identity provider or single sign-on (SSO) system lets an organization use the authentication systems they already own (e.g. tokens, authentication apps, one-time passwords, etc.) to grant access to resources, including resources in “off premises” cloud services. These systems often use cryptographically signed automated messages called “assertions” shared via Security Assertion Markup Language (SAML) to show that users have been authenticated. When an actor can subvert authentication mechanisms, they can gain illicit access to a wide range of an organizations assets.

In some cases, actors have stolen keys from the SSO system that allow them to sign assertions and impersonate any legitimate user who could be authenticated by the system. On 7 December, NSA reported on an example where a zeroday vulnerability was being used to compromise VMware Access®1 and VMware Identity Manager®2 servers, allowing actors to forge authentication assertions and thus gain access to the victim’s protected data. In other cases, actors have gained enough privileges to create their own keys and identities such as “service principals” (cloud applications that act on behalf of a user) or even their own fake SSO system. According to public reporting, in some cases, the SolarWinds Orion®3 code compromise provided actors initial access to an on-premises network which led to access within the cloud.

Note that these techniques alone do not constitute vulnerabilities in the design principles of federated identity management, the SAML protocol, or on-premises and cloud identity services. The security of identity federation in any cloud environment directly depends on trust in the on-premises components that perform authentication, assign privileges, and sign SAML tokens. If any of these components is compromised, then the trust in the federated identity system can be
abused for unauthorized access.

To defend against these techniques, organizations should pay careful attention to locking down SSO configuration and service principal usage, as well as hardening the systems that run on-premises identity and federation services. Monitoring the use of SSO tokens and the use of service principals in the cloud can help detect the compromise of identity services. While these techniques apply to all cloud environments that support on-premises federated authentication, the following specific mitigations are focused on Microsoft Azure®4 federation. Many of the techniques can be generalized to other environments as well.

Disclaimer of Endorsement

The information and opinions contained in this document are provided “as is” and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.

Purpose

This document was developed in furtherance of NSA’s cybersecurity missions, including its responsibilities to identify and disseminate threats to National Security Systems, Department of Defense, and Defense Industrial Base information systems, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.

Contact

Client Requirements / General Cybersecurity Inquiries: Cybersecurity Requirements Center, 410-854-4200, Cybersecurity_Requests@nsa.gov

Media inquiries / Press Desk: Media Relations, 443-634-0721, MediaRelations@nsa.gov

Detecting Abuse of Authentication Mechanisms – Abridged

AUTHENTICATION_MECHANISMS_CSA_EXEC_U_OO_198854_20

Detecting Abuse of Authentication Mechanisms

AUTHENTICATION_MECHANISMS_CSA_U_OO_198854_20

Contact Your Elected Officials
The Thinking Conservative
The Thinking Conservativehttps://www.thethinkingconservative.com/
The goal of THE THINKING CONSERVATIVE is to help us educate ourselves on conservative topics of importance to our freedom and our pursuit of happiness. We do this by sharing conservative opinions on all kinds of subjects, from all types of people, and all kinds of media, in a way that will challenge our perceptions and help us to make educated choices.

Babies in Incubators, Redux

No one ever accused Social Justice™ people of having mastered the art of subtlety in their propaganda.

The CFP punts on expansion

Friday marked the official deadline for CFP management committee to inform ESPN of any format shake‑ups for next season. No shake‑up materialized.

Faith, fury, and flash mobs

Once the Twin Cities of St. Paul and Minneapolis were America’s neighborly cities. Today, they're the proud home of the Minneapolis and Mogadishu.

Laws Are Laws, Not Suggestions

Federal law is the law of the land, occupying the highest position in the American legal hierarchy and overrides state and local laws when conflicts arise.

Coming Major Storm Could End Democrats!  

The now proven global warming / climate change hoax could actually cost American lives due to its impact on our power grids.

Top DOJ Official Lays Blame With Minnesota Officials, Says Shooting of Protester ‘Entirely Avoidable’

Deputy AG Todd Blanche responded to demands from local Minnesota Democratic officials after the shooting of a protester by federal immigration officials in the state.

US Storm Leaves Over 1 Million Without Power, Nearly 11,000 Flights Canceled

More than 1 million Americans were without power Jan. 25 as a severe winter storm hit the South and forced airlines to cancel nearly 11000U.S. flights.

Federal Agent Fatally Shot Armed Man in Minneapolis: DHS

One person was shot by federal officers in Minneapolis. Federal authorities maintain that the ICE agent acted in self-defense.

Immediate Citizenship Verification Ordered for All Tenants in HUD-Funded Housing Nationwide

HUD ordered citizenship verification for all HUD-funded housing beneficiaries to ensure benefits aren’t going to ineligible individuals such as illegal immigrants.

Trump Says Canada Will Face 100 Percent Tariffs if It ‘Makes a Deal With China’

President Trump says Canadian goods exported to the United States would be hit with 100 percent tariffs if Canada makes a deal with China.

Trump Rejects Proposal to Let Homebuyers Use 401(k) Funds for Down Payments

President Trump said that he rejected a proposal to allow Americans to withdraw money from their 401(k) accounts for home down payments.

Trump Withdraws Invitation for Canada’s Carney to Join Board of Peace

President Trump has withdrawn his invitation for Canadian PM Mark Carney to join the U.S.-led Board of Peace that will initially focus on rebuilding Gaza.

US Will Work With NATO on Greenland Deal: Trump

The USwill work with NATO to secure Greenland, with America having the freedom to “do anything we want,” President Trump told reporters.
spot_img

Related Articles