The Experts below are selected from a list of 9429 Experts worldwide ranked by ideXlab platform
Bünyamin Ciylan - One of the best experts on this subject based on the ideXlab platform.
-
Application Model for Privileged Account Access Control System in Enterprise Networks
Computers & Security, 2019Co-Authors: Erhan Sindiren, Bünyamin CiylanAbstract:Abstract Directory applications are utilized to centrally manage the high number of computers, user Accounts, printers, servers, etc. While using the directory service, Privileged Accounts are used to execute the operation of components and network services within the network infrastructures. These Privileged Accounts have wide authorizations on all the components within the directory service. One of the objectives of cyber-attacks on such systems is to obtain the passwords of such Accounts. Thus, a model is designed and presented in this study in order to enable the Privileged Accounts to be controlled, managed, and followed at minimum cost. This application model enabled the determination of passwords of Privileged user Accounts in accordance with the fundamental IT security principles, establishment of stronger passwords, clarification of the limits of duties of IT personnel, a decrease in their work load, and an increase in the awareness of managers about IT security.
Erhan Sindiren - One of the best experts on this subject based on the ideXlab platform.
-
Application Model for Privileged Account Access Control System in Enterprise Networks
Computers & Security, 2019Co-Authors: Erhan Sindiren, Bünyamin CiylanAbstract:Abstract Directory applications are utilized to centrally manage the high number of computers, user Accounts, printers, servers, etc. While using the directory service, Privileged Accounts are used to execute the operation of components and network services within the network infrastructures. These Privileged Accounts have wide authorizations on all the components within the directory service. One of the objectives of cyber-attacks on such systems is to obtain the passwords of such Accounts. Thus, a model is designed and presented in this study in order to enable the Privileged Accounts to be controlled, managed, and followed at minimum cost. This application model enabled the determination of passwords of Privileged user Accounts in accordance with the fundamental IT security principles, establishment of stronger passwords, clarification of the limits of duties of IT personnel, a decrease in their work load, and an increase in the awareness of managers about IT security.
Sarah A Cunha - One of the best experts on this subject based on the ideXlab platform.
-
addressing the inadequacies of role based access control rbac models for highly Privileged administrators introducing the snap principle for mitigating Privileged Account breaches
International Journal of Intelligent Computing Research, 2015Co-Authors: Samuel Moses, Dale C Rowe, Sarah A CunhaAbstract:In this paper, we discuss how RBAC systems fail to protect highly Privileged Accounts used for system administration. We introduce how Secondary NonAdmin Privileged (SNAP) Accounts can mitigate a variety of attacks targeting Privileged Accounts. Both justification and a methodology for implementing this approach are presented along with case-studies showing how real attacks can be mitigated. Three different variations we have termed i-SNAP, s-SNAP and t-SNAP are compared. Other studies have shown that over 92% of critical vulnerabilities require administrative access and we present multiple casestudies that demonstrate the effectiveness of our proposed solution. Also discussed are procedural, technical and educational processes that will increase the effectiveness of this approach. We conclude with a critical assessment of the SNAP approach and include its potential limitations.
Samuel Moses - One of the best experts on this subject based on the ideXlab platform.
-
addressing the inadequacies of role based access control rbac models for highly Privileged administrators introducing the snap principle for mitigating Privileged Account breaches
International Journal of Intelligent Computing Research, 2015Co-Authors: Samuel Moses, Dale C Rowe, Sarah A CunhaAbstract:In this paper, we discuss how RBAC systems fail to protect highly Privileged Accounts used for system administration. We introduce how Secondary NonAdmin Privileged (SNAP) Accounts can mitigate a variety of attacks targeting Privileged Accounts. Both justification and a methodology for implementing this approach are presented along with case-studies showing how real attacks can be mitigated. Three different variations we have termed i-SNAP, s-SNAP and t-SNAP are compared. Other studies have shown that over 92% of critical vulnerabilities require administrative access and we present multiple casestudies that demonstrate the effectiveness of our proposed solution. Also discussed are procedural, technical and educational processes that will increase the effectiveness of this approach. We conclude with a critical assessment of the SNAP approach and include its potential limitations.
Nuruliansyah Hendra - One of the best experts on this subject based on the ideXlab platform.
-
Penerapan Privileged Access Management Menggunakan One Identity Pada Sebuah Perusahaan
'LPPM Universitas Ibn Khaldun Bogor', 2020Co-Authors: Nuruliansyah HendraAbstract:One Identity Priveged Access Management (PAM) is a solution for a series of efforts to reduce security risks and help companies secure, control, monitor, analyze, and regulate Privileged access rights to data and applications from very important organizations. The PAM solution allows companies to provide full credentials such as Administrators on Windows, Root on UNIX, Cisco Enable on Cisco devices, and embedded passwords found in applications and scripts or restricting access to ordinary users. All Privileged Account activities are recorded by analyzing real time activities and data. Password sharing activities can be eliminated, so security can be improved and compliance with privileges of Privileged access rights is more efficient and manageable. Problems that can be explained when the user privileges password access rights do not have regular rules to change the password periodically in accordance with the security policy (password policy) even to obtain information that has accessed the network device using a special Account or other permitted Account . The purpose of this study is (i) to obtain information about changes in passwords periodically based on the configuration that has been set in the PAM system and adjusted to the password policy rules, (ii) get information about who is accessing the network device and the Account accessed. The research method that is carried out is (i) collecting data from the system that will be implemented, (ii) directly accessing the system that has data and viewing information thoroughly into the system, (iii) matching the type of system with the system supported by the PAM application system then integrate it. Testing is done by accessing the target system using Privileged access rights through the PAM application system. The results obtained (i) can facilitate password users not to remember passwords too often, (ii) can avoid sharing password information, (iii) change passwords regularly, (iv) find out all user password activities against a set of targets network systems that are permitted to be accessed, (v) record all access activities in the form of videos