Detecting Abuse of Authentication Mechanisms – Abridged

Summary

Malicious cyber actors are abusing trust in federated authentication environments to access protected data. An “on premises” federated identity provider or single sign-on (SSO) system lets an organization use the authentication systems they already own (e.g. tokens, authentication apps, one-time passwords, etc.) to grant access to resources, including resources in “off premises” cloud services. These systems often use cryptographically signed automated messages called “assertions” shared via Security Assertion Markup Language (SAML) to show that users have been authenticated. When an actor can subvert authentication mechanisms, they can gain illicit access to a wide range of an organizations assets.

In some cases, actors have stolen keys from the SSO system that allow them to sign assertions and impersonate any legitimate user who could be authenticated by the system. On 7 December, NSA reported on an example where a zeroday vulnerability was being used to compromise VMware Access®1 and VMware Identity Manager®2 servers, allowing actors to forge authentication assertions and thus gain access to the victim’s protected data. In other cases, actors have gained enough privileges to create their own keys and identities such as “service principals” (cloud applications that act on behalf of a user) or even their own fake SSO system. According to public reporting, in some cases, the SolarWinds Orion®3 code compromise provided actors initial access to an on-premises network which led to access within the cloud.

Note that these techniques alone do not constitute vulnerabilities in the design principles of federated identity management, the SAML protocol, or on-premises and cloud identity services. The security of identity federation in any cloud environment directly depends on trust in the on-premises components that perform authentication, assign privileges, and sign SAML tokens. If any of these components is compromised, then the trust in the federated identity system can be
abused for unauthorized access.

To defend against these techniques, organizations should pay careful attention to locking down SSO configuration and service principal usage, as well as hardening the systems that run on-premises identity and federation services. Monitoring the use of SSO tokens and the use of service principals in the cloud can help detect the compromise of identity services. While these techniques apply to all cloud environments that support on-premises federated authentication, the following specific mitigations are focused on Microsoft Azure®4 federation. Many of the techniques can be generalized to other environments as well.

Disclaimer of Endorsement

The information and opinions contained in this document are provided “as is” and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.

Purpose

This document was developed in furtherance of NSA’s cybersecurity missions, including its responsibilities to identify and disseminate threats to National Security Systems, Department of Defense, and Defense Industrial Base information systems, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.

Contact

Client Requirements / General Cybersecurity Inquiries: Cybersecurity Requirements Center, 410-854-4200, Cybersecurity_Requests@nsa.gov

Media inquiries / Press Desk: Media Relations, 443-634-0721, MediaRelations@nsa.gov

Detecting Abuse of Authentication Mechanisms – Abridged

AUTHENTICATION_MECHANISMS_CSA_EXEC_U_OO_198854_20

Detecting Abuse of Authentication Mechanisms

AUTHENTICATION_MECHANISMS_CSA_U_OO_198854_20

The Thinking Conservative
The Thinking Conservativehttps://www.thethinkingconservative.com/
The goal of THE THINKING CONSERVATIVE is to help us educate ourselves on conservative topics of importance to our freedom and our pursuit of happiness. We do this by sharing conservative opinions on all kinds of subjects, from all types of people, and all kinds of media, in a way that will challenge our perceptions and help us to make educated choices.

Columns

Secession’s Hotel California

England’s King George III found out the hard way that the very genesis of the American ethos is running our own affairs liberated from bureaucratic control. 

Vaccine Induced AIDS is a Thing Now

Podcaster Liz Wheeler discusses a Yale Medical School report about mRNA COVID-19 vaccines causing what may now be determined to be "vaccine" induced AIDS.

Feral Pharma-Phile Libs Riot Over RFK Jr. Investigating SSRI Safety

The progressive meltdown ensued after Secretary RFK Jr. confirmed he is going to re-evaluate the scam that is SSRIs, which I have covered at AP previously.

Congressional Millionaires May Get DOGED!

Rumor says 163 members of Congress may undergo a forensic audit by DOGE to determine how their net worth so rapidly outpaced their $174,000 annual salaries.

Savory Schadenfreude: Lib Violins Out For Fired Bureaucrats Crying on TikTok

My friend asked me why I’m riding the Musk/Trump train. I’m not fully on board with Trump/Musk’s agenda and I don’t trust Musk further than I could throw him.

News

Buffett Offers Advice to Trump on Government Spending After Paying $26.8 Billion in Tax

In letter to shareholders, Warren Buffett reflected on Berkshire Hathaway’s successes while offering Trump admin some advice on stewardship of the U.S. economy.

Cartel-Linked Smugglers Arrested in US–Mexico Operation

An enforcement operation conducted as part of a bilateral cooperation between the US and Mexico led to disruptions and arrests in human smuggling operations.

Supreme Court Declines to Allow Trump Admin to Immediately Fire Watchdog Official

The U.S. Supreme Court on Feb. 21 declined to allow the Trump administration to immediately fire Office of Special Counsel chief Hampton Dellinger.

Grenell Outlines Trump’s Plan to Revamp the Kennedy Center

Richard Grenell, interim executive director of the Kennedy Center in Washington, outlined President Donald Trump’s vision for the performing arts venue.

Nation’s Biggest School Districts Stand to Lose Billions Over Trump’s DEI Order

Five largest U.S. public school districts to lose $5 billion in federal funds per year if they don't comply with Trump’s EOs barring ideologies such as DEI.

Los Angeles Mayor Removes Fire Chief Over Alleged Lack of Preparation for Palisades Fire

Mayor of Los Angeles, Karen Bass, removed city’s fire chief because chief had not prepared the dept to fight fires when they broke out earlier this year.

Inflation Expectations Jump to 30-Year High, Consumer Confidence Falls

U.S. consumer confidence tumbled to a 15-month low in Feb, as inflation fears surged and expectations for the broader economy and personal finances deteriorated.

Texas Measles Outbreak Grows to 90 Cases, Health Officials Say

A outbreak of measles cases in western Texas has grown to 90 cases since last month, according to new data released on Friday by state health officials.
spot_img

Related Articles

Popular Categories

MAGA Business Central