Security Advisor Middle East | Issue 24

Page 25

OPINION

So how do you spend a penny or less to discover privileged accounts and rate their risk? Look no further than your existing operations and security teams.

are not equal. Some are worth a penny (figuratively) and others a lot more based on risk. A domain administrator account is of higher value than a local administrator account with a unique password (although that may be good enough to leverage for future lateral movement). Treating every privileged account the same is foolish. You could make the same argument for a database admin account verses a restricted account used with Open Database Connectivity (ODBC) for database reporting. Both are privileged but owning the database verses just extracting data is not the same. Yes, both could be a devastating attack vector responsible for a breach but owning the database is the highest privileges you can get. Therefore, this could potentially allow a threat actor to maintain a persistent stealth presence (if cynical and crafty enough) until the organisation identifies the breach. So, just what should you do to take credential and privileges to the next level: • Identify crown jewels (sensitive data and systems) within the www.tahawultech.com

environment. This will help form the backbone for quantifying risk. If you do not have this currently mapped out, it is an exercise worth pursuing. • Discover all of your privileged accounts using existing tools, free solutions (there are plenty), or via a dedicated privileged solution. • Map the discovered accounts to crown jewel assets. This can be done by hostname, subnets, AD queries, zones, or other logical groupings based on business functions. • Measure the risk of the asset. This can be done using basic critical, high, medium, and low ranking but should also consider the crown jewels present and any other risk vectors like vulnerabilities. Each of these metrics will help weight the asset score. If you are looking for a standardised starting place, consider Common Vulnerability Scoring System (CVSS) and Environmental metrics. • Finally, overlay the discovered accounts. The risk of the asset

will help determine how likely a privileged account can be compromised (via vulnerabilities) and help prioritise asset remediation outside of the account mapping. In the real world, a database with sensitive information may have a few critical vulnerabilities from time to time, in-between patch cycles, and be considered a critical risk when they are present regardless of the accounts identified. When patch remediation occurs, the asset may still be high risk, if privileged access is not managed, and will drop in risk if privileges are session monitored and access controlled. Criticality can be from vulnerabilities or unrestricted, unmanaged, and undelegated access in addition to attack vectors that have workable exploits. Spending a penny to find them and map them is a much safer security mechanism than foolishly leaving them unattended. Thus, a penny wise to understand your privileged accounts verses a password foolish used in a breach 01.2018

25


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.