On Attacking Kerberos Authentication Protocol in Windows Active Directory Services: A Practical Survey

dc.contributor.authorDíaz Motero, Carlos
dc.contributor.authorBermejo Higuera, Juan Ramón
dc.contributor.authorBermejo-Higuera, Javier
dc.contributor.authorSicilia, Juan Antonio
dc.contributor.authorGámez, Nádia
dc.date2021
dc.date.accessioned2022-03-16T10:41:10Z
dc.date.available2022-03-16T10:41:10Z
dc.description.abstractOrganizations use Active Directory Windows service to authenticate users in a network with the extended Kerberos Authentication protocol. Therefore, it is necessary to investigate its resistance to the different types of attacks it can suffer, the best way to detect them and to parameterize it to mitigate the effects of the attacks. This work analyzes the main Kerberos attacks in Active Directory Windows networks, inherent in the design of the protocol and not resolved. For each attack the objective is studied, implementation is developed in a virtual laboratory and detection is analyzed, proposing measures for mitigation and response. Subsequently, they are discussed in a general way and the results of the attacks are analyzed according to some parameters. As conclusions of the work carried out, it should be noted that although the attacks are mostly difficult to implement, their detection is even more complicated, and the damage is very severe so it's necessary to continuously monitor the logs in these environments to detect them and taking into account strict recommendations for mitigation and response.es_ES
dc.identifier.doihttps://doi.org/10.1109/ACCESS.2021.3101446
dc.identifier.issn2169-3536
dc.identifier.urihttps://reunir.unir.net/handle/123456789/12645
dc.language.isoenges_ES
dc.publisherInstitute of Electrical and Electronics Engineers Inc.es_ES
dc.relation.ispartofseries;vol. 9
dc.relation.urihttps://ieeexplore.ieee.org/document/9501961/authors#authorses_ES
dc.rightsopenAccesses_ES
dc.subjectKerberoses_ES
dc.subjectKerberos attack detectiones_ES
dc.subjectKerberos attack's mitigationes_ES
dc.subjectKerberos attackses_ES
dc.subjectWindows active directoryes_ES
dc.subjectScopuses_ES
dc.subjectJCRes_ES
dc.titleOn Attacking Kerberos Authentication Protocol in Windows Active Directory Services: A Practical Surveyes_ES
dc.typearticlees_ES
opencost.publication.doihttps://doi.org/10.1109/ACCESS.2021.3101446
reunir.tag~ARIes_ES

Archivos

Bloque de licencias

Mostrando 1 - 1 de 1
Cargando...
Nombre:
license.txt
Tamaño:
1.27 KB
Formato:
Item-specific license agreed upon to submission
Descripción: