20

Jun 29 - 2016-MultiFactorAuthentication

Embed Size (px)

Citation preview

Page 1: Jun 29 - 2016-MultiFactorAuthentication
Page 2: Jun 29 - 2016-MultiFactorAuthentication

EasyMultiFactorAuthenticationStrategiesandPCIDSS3.2

Page 3: Jun 29 - 2016-MultiFactorAuthentication

HELLO!I am Anirban Banerjee.I am the Founder and CEO of Onion ID.

https://calendly.com/anirban/enterprise-demo/

Page 4: Jun 29 - 2016-MultiFactorAuthentication

Two/Multi Factor Authentication

PCI DSS 3.2

Strategies

Page 5: Jun 29 - 2016-MultiFactorAuthentication

WhatisTwo-FactorAuthentication?

▸ Addsasecondlevelofverificationtothepassword-basedapproach.

▸ Example:atextmessagetoyourphone,avaluefromaRSAtoken.

▸ Ifahackergetsyourusernameandpasswordtheystillwon’tbeabletogetintoyouraccount.

Page 6: Jun 29 - 2016-MultiFactorAuthentication

Whydoweneedthis?

Usernames&Passwordscanbestolen!• Phishing attacks• Samecredentialsacrossapps• Key-loggers• Educatedguesses, socialengineering

2FApreventsattackersfromaccessingyouraccounteveniftheyobtainyourusernameandpassword.

MandatedinVersion3.2ofthePCIDataSecurityStandard

Page 7: Jun 29 - 2016-MultiFactorAuthentication

WhoUsesTwo-Factor?

Page 8: Jun 29 - 2016-MultiFactorAuthentication

MultiFactorAuthentication

Page 9: Jun 29 - 2016-MultiFactorAuthentication

AddingMoreFactors

• Increasethestrengthofauthenticationbyaddingfactors.

• Fivecategoriesofauthenticationmethods• whoyouare,• whatyouknow,• whatyouhave,• whatyoutypicallydo,• thecontext.

• Addingfactorsfromdifferentcategoriescanincreasestrengthonly iftheoverallsetofvulnerabilities isreduced.

Page 10: Jun 29 - 2016-MultiFactorAuthentication

Whatcanweadd?

PhysicalBiometric▸ immutableand

unique• Facial recognition• IrisScan• RetinalScan• FingerprintPalm

Scan• Voice• Livelinessbiometric

factorsinclude:• Pulse.

CAPTCHA;etc

Behavioral/Biometric • basedonperson’s

physicalbehaviouralactivitypatterns

• Keyboardsignature

• Voice

WhoYouAre

Biometric

whatyou

know

whatyou

have

whatyou

DoContext

• UserNameandPassword(UN/PW),

• Apassphrase• aPIN• Ananswertoa

secretquestion

• OneTimePassword(OTP)

• Smartcard• X.509and

PKI• Rarely

usedalone• Usedin

combinationwithUN/PWandaPIN

• Browsingpatterns

• Timeofaccess

• Typeofdevice

• UsedinCombinationwithothermethods

• Location;Timeofaccess;

• Subscriberidentitymodule(SIM)

• Frequencyofaccess;

• Usedwithothermethods

Page 11: Jun 29 - 2016-MultiFactorAuthentication

▸ Combiningtwoormoreauthenticationmethodscanpotentiallyincreaseauthenticationstrength.

▸ However!• Becarefulnottointroducevulnerabilities

• MorefactorsèMorecomplex/costlytoimplement&use.Themorethemerrier?

Page 12: Jun 29 - 2016-MultiFactorAuthentication

Themorethemerrier?

▸ Simplyaddingfactorsdoesnotguaranteemoreprotection

Source: Gartner

Page 13: Jun 29 - 2016-MultiFactorAuthentication

FindingtheBestFactorCombo

UseNeedsandConstraintstoDetermine• Authenticationstrength

• indicatedbythelevelofrisk• TotalCostofOwnership

• Constrainedbybudget• Easeofuse

• universallydesirable,but itislesscriticalthegreatertheconsistency

• Otherconstraints• consistencyandcontrolofthe

endpoint isaparticularconstraint;

Source - Gartner

Page 14: Jun 29 - 2016-MultiFactorAuthentication

PCIDSS3.2

Page 15: Jun 29 - 2016-MultiFactorAuthentication

▸ Feb12018

▸ MultiFactorauthentication foreveryone

▸ Needtoprotectbothconsoleandnonconsolebasedaccess

▸ Newrequirements10.8and10.8.1outlinethatservice providersneedtodetectandreportonfailuresofcritical securitycontrolsystems

▸ Newrequirement11.3.4.1indicatesthatserviceprovidersneedtoperformpenetration testingonsegmentationcontrolseverysixmonths

Highlights

Page 16: Jun 29 - 2016-MultiFactorAuthentication

▸ Serverdoesnotsupport2FAbydefault

▸ AppdoesnotsupportSAML/Oauth

▸ Apphasnonativesupportfor2FA

▸ Regularauditingofaccess

▸ DataPrivacyissues,datasegregationChallenges

Page 17: Jun 29 - 2016-MultiFactorAuthentication

▸ EnableMFAviaBrowserextensionsorWebFilters

▸ UseUXfriendlyMFA:Geo fencing,proximity,fingerprint

▸ SetupauditingsystemsbyparsingSIEMinfo

▸ SetupamonthlyPCImeeting togooverprocessandresults

▸ Commercial tools– OnionIDtodoprivilegemanagementStrategies

Page 18: Jun 29 - 2016-MultiFactorAuthentication

Conclusions

Page 19: Jun 29 - 2016-MultiFactorAuthentication

▸ Passwordbasedauthenticationisnotenoughanymore.

▸ MultiFactorauthentication isheretostay!

▸ Manydifferentoptions,eachwithitsowncostsandvulnerabilities.

▸ Besmart:addingmorefactorswilldefinitelyincreasecostandcomplexity,butmightnot(sufficiently)increasesecurity.

▸ Considerthetrade-offs,customize.Pickthecombinationthatworksforyou.

Conclusions

Page 20: Jun 29 - 2016-MultiFactorAuthentication

THANK YOU!Any questions?You can find more about us at:Onion ID – The Next Generation of Privilege Managementwww.onionid.com , [email protected]: +1-888-315-4745https://calendly.com/anirban/enterprise-demo/