{"id":46073,"date":"2020-03-06T12:20:29","date_gmt":"2020-03-06T12:20:29","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/06\/the-compromise-and-misuse-of-privileged-identity\/"},"modified":"2020-03-06T12:20:35","modified_gmt":"2020-03-06T12:20:35","slug":"the-compromise-and-misuse-of-privileged-identity","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/06\/the-compromise-and-misuse-of-privileged-identity\/","title":{"rendered":"The compromise and misuse of privileged identity"},"content":{"rendered":"\n<p><em>As the compromise and misuse of identity is often at the core of modern threats, privilege accounts are a prime target for phishing and social campaigns. Peter Draper, Technical Director EMEA, Gurucul, discusses how  <\/em> <em>Privileged Access Management monitoring enables companies to mitigate against insider threats.  <\/em><\/p>\n\n\n\n<p>It\u2019s widely accepted by today\u2019s cybersecurity departments that many serious data breaches can be traced back to the abuse of privileged credentials and yet teams still struggle to integrate this realisation into day-to-day operations. <\/p>\n\n\n\n<p>On the face of it, this shouldn\u2019t be happening. Organisations have been making big investments in IT security tools such as Security Information Event Management (SIEM), next-generation firewalls and intrusion prevention systems (IPS), as well as a variety of anomaly detection systems, email and web filtering and Data Leak Prevention (DLP). Despite this, data breaches continue to plague companies, with new avenues for attack appearing such as unsecured Remote Desktop Protocol (RDP) and VPN servers, oiled by a steady flow of software vulnerabilities, including \u2018surprise\u2019 zero days.<\/p>\n\n\n\n<p>Organisations feel compelled to open their networks to cope\nwith an increasingly mobile, remote workforce, to the cloud and IoT, and to\nenable a complex web of remote access used by suppliers and service providers.\nMany of those connections, including those to cloud applications, are accessed\nusing powerful privileged account credentials that represent a security risk.\nThese accounts are difficult to find and controlling and monitoring access to\nthem is challenging.<\/p>\n\n\n\n<p>From the attacker\u2019s side, bypassing these privileged account\ncredentials to access sensitive systems is little more than a percentages game.\nWith so many avenues to target them \u2013 social engineering, phishing attacks, zero\ndays and collaboration with malicious insiders \u2013 penetrating an organisation\u2019s\nnetwork is about patience. If at first you don\u2019t succeed, keep trying because\nit\u2019s a certainty that a new weakness will emerge.<\/p>\n\n\n\n<p>Once armed with the credentials to get behind an organisation\u2019s defences, attackers look to grab what they can, such as SSH keys, certificates and domain admin hashes to move laterally on the network. It\u2019s a despairing thought that among the thousands of privileged accounts attackers might aim for, it takes only one to seed a major data breach that brings an organisation to its knees. <\/p>\n\n\n\n<p><strong>Privileged Access Management (PAM)<\/strong><\/p>\n\n\n\n<p>This isn\u2019t just about threats from outside the organisation, but the ones emanating from inside it too. According to Gurucul\u2019s Cybersecurity Insiders\u2019 <em>2020 Insider Threat Report<\/em>, security professionals are well aware of the threat posed by unsecured privileged accounts, with 63% agreeing that privileged users pose the biggest risk from inside an organisation and 68% saying they felt vulnerable to insider attacks generally. Almost all of these organisations will have deployed multiple layers of security solutions to contain threats from outside the organisation, but conventional security tools do not defend against privileged account misuse. When the same scenarios are modelled inside the network, there is often no defence at all.<\/p>\n\n\n\n<p>A major problem hindering organisations has been the inherent difficulty in identifying and securing privileged accounts, including those in the cloud. Consequently, many invested in Identity and Access Management (IAM). While IAM is good at managing user identities tied to a known person, it struggles to cope with identities that aren\u2019t defined in this way such as admin accounts used to manage IT resources. Finding these privileged identities can be difficult, let alone stopping a malicious party from accessing them. <\/p>\n\n\n\n<p>For this reason, organisations have increasingly turned to\nPrivileged Access Management (PAM) systems which impose control and management\non accounts using the principle of least privilege. Unfortunately, even PAM\nstruggles under real-world conditions in which many privileged accounts slip\nthrough the net to the extent that Gurucul estimates from customer data that up\nto half remain unknown to IAM or PAM platforms. <\/p>\n\n\n\n<p><strong>Hidden accounts<\/strong><\/p>\n\n\n\n<p>Insider abuse is often cast as a general willingness by one or more employees to misuse systems but an essential part of this is the way they exploit privileged access. This can be both abuse of privileged accounts for which an individual has permission, but which is being misused, as well as access to non-authorised accounts. Clearly, permissions don\u2019t act as a barrier to either because one form of access might appear legitimate while the other would remain invisible.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              <\/p>\n\n\n\n<p>On top of this is access bloat where over time multiple users have been given access to a resource. This is not only a bad idea because it stretches user management but expands the attack surface for cybercriminals looking to execute a phishing attack. Finally, there is the under-estimated weakness of credentials and root keys left exposed in the cloud, which can allow an attacker to not only set themselves up as the admin but potentially lock out existing ones. Indeed, the cloud poses huge challenges of its own, not least because it has been the biggest driver for the expansion of privileged and risky accounts. <\/p>\n\n\n\n<p>This uncertainty can now be addressed using Identity Analytics (IdA) technology, which uses Machine Learning to discover and analyse privileged accounts and account access, working as an extension to existing IAM and PAM to spot accounts that are not being controlled. This includes not only accounts that have acquired more privileges after they were provisioned but also privileged credentials embedded within applications and unstructured data.\u00a0IdA is particularly effective at finding associated accounts that might aid hidden backdoor access, which are today a major risk area for organisations of all sizes.<\/p>\n\n\n\n<p>Using Machine Learning to do this is ideal because it\u2019s a technology perfectly suited to detecting anomalous access once it has modelled what baseline access looks like for an organisation. It\u2019s also good at spotting and risk scoring orphaned or dormant \u2018access outlier\u2019 accounts that will often be unknown to admins. Once these accounts have been brought to the attention of admins, decisions can be made about which to de-provision or impose additional authentication upon on the basis of peers, activities and context, a process which can be automated through API integration with provisioning platforms. Achieving the same result through manual methods and old-world rules \u2013 the traditional technique for housekeeping privileged accounts \u2013 would be both time consuming and almost certainly fail at some point. <\/p>\n\n\n\n<p>It\u2019s a lot to take in: organisations move to IAM, mature with PAM and then fill in the gaps and exceptions with IdA. But what is ultimately driving this evolution is the increasing complexity of businesses that now depend on cloud access, rapid development and ever more layered security. This is how business is and there is no evidence these trends will slow down. IdA, then, is another technology a company can use to make sense of this riskier world. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the compromise and misuse of identity is often at the core of modern threats, privilege accounts are a prime target for phishing and social campaigns. Peter Draper, Technical Director EMEA, Gurucul, discusses how Privileged Access Management monitoring enables companies to mitigate against insider threats. It\u2019s widely accepted by today\u2019s cybersecurity departments that many serious [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":46074,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[11445,3694,11446,3518,11447],"class_list":["post-46073","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories","tag-gurucul","tag-identity-and-access-management","tag-insider-attacks","tag-privileged-access-management","tag-unsecured-privileged-accounts"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46073","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=46073"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46073\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/46074"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=46073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=46073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=46073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}