K
of
,U
Access
Control
Methodologies
- lecture 5
sh
Dr. Huwaida
Tagelsir
Access Control Methodologies - lecture 5
ou
Elshoush
sh
Introduction
Access Control
El
Models
Mandatory AC
Dr. Huwaida Tagelsir Elshoush
Discretionary AC
a
Role-based AC
University of Khartoum - Sudan
id
AC Faculty of Mathematical Sciences
Administration
wa
Department of Computer Science
Authentication htelshoush@[Link]
Hu
DB Security
.
Dr
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 1 / 38
Presentation Topics at a Glance
Access
Control
Methodologies
- lecture 5 1 Introduction
Dr. Huwaida
Tagelsir
Elshoush 2 Access Control Models
Introduction Mandatory AC
Access Control Discretionary AC
Models
Mandatory AC
Role-based AC
Discretionary AC
Role-based AC
AC
3 AC Administration
Administration
Authentication 4 Authentication
DB Security
5 DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 2 / 38
Learning Objectives
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush Define access control
Introduction
Access Control List the THREE access control models
Models
Mandatory AC
Discretionary AC
Role-based AC Describe logical access control methods
AC
Administration
Authentication Define authentication services and mechanisms
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 3 / 38
Access Control
Access
Control
Methodologies
- lecture 5
Access control is a process to determine ”Who does
Dr. Huwaida
Tagelsir what to what” based on a policy.
Elshoush
Introduction
It is controlling access of
Access Control
Models who gets in and out of the system and
Mandatory AC
Discretionary AC
Role-based AC who uses what resources, when, and in what amounts
AC
Administration
Authentication Access control is restricting access to a system or system
DB Security resources based on something other than the identity of
the user
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 4 / 38
Access Control Terminology
Access Definition of access control:
Control
Methodologies
It is a collection of methods and components that
- lecture 5 supports
Dr. Huwaida confidentiality
Tagelsir
Elshoush integrity
Introduction
Access Control
Goal: allow only authorized subjects to access permitted
Models objects
Mandatory AC
Discretionary AC
Role-based AC
AC
Subject
Administration The entity that requests access to a resource
Authentication Example: computer user
DB Security
Object
The resource a subject attempts to access
Example: file or hardware device
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 5 / 38
Access Control Terminology
Access
Control
Methodologies
- lecture 5 Identification
Dr. Huwaida Presenting credentials
Tagelsir
Elshoush Example: delivery driver presenting employee badge
Introduction
Access Control Authentication
Models
Mandatory AC Checking the credentials
Discretionary AC
Role-based AC
Example: examining the delivery driver’s badge
AC
Administration
Authentication
Authorization
DB Security Granting permission to take action
Example: allowing delivery driver to pick up package
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 6 / 38
Basic Steps in Access Control
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush
Introduction
Access Control
Models
Mandatory AC
Discretionary AC
Role-based AC
AC
Administration
Authentication
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 7 / 38
Data Ownership
Access
Control
Methodologies
- lecture 5
Different layers of responsibility for ensuring security of
Dr. Huwaida organization’s information
Tagelsir
Elshoush Data owner
Introduction
Bears ultimate responsibility, sets classification levels
Access Control
Models
Mandatory AC Data custodian
Discretionary AC
Role-based AC
Enforces security policies, often a member of IT
AC department
Administration
Authentication
DB Security
Data user
Accesses data on a day-to-day basis
responsible for following the organization’s security policies
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 8 / 38
Roles in Access Control
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush
Introduction
Access Control
Models
Mandatory AC
Discretionary AC
Role-based AC
AC
Administration
Authentication
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 9 / 38
Access Control Process and Terminology
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush
Introduction
Access Control
Models
Mandatory AC
Discretionary AC
Role-based AC
AC
Administration
Authentication
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 10 / 38
Access Control
Access
Control
Methodologies
- lecture 5 Least privilege philosophy
Dr. Huwaida A subject is granted permissions needed to accomplish
Tagelsir
Elshoush required tasks and nothing more
Introduction
Access Control Information leakage
Models
Mandatory AC Lack of controls lets people without need to access data
Discretionary AC
Role-based AC E.g.: physician needs data about the patient’s health and
AC not about the insurance
Administration
Authentication
DB Security Controls
Mechanisms put into place to allow or disallow object
access
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 11 / 38
Controls
Access
Control
Methodologies
- lecture 5
Dr. Huwaida Controls organized into different categories
Tagelsir
Elshoush
Introduction
Common categories
Access Control
Administrative
Models enforce security rules through policies
Mandatory AC
Discretionary AC
Role-based AC
Logical
AC
Administration
implement object access restrictions
Authentication
Physical
DB Security
limit physical access to hardware
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 12 / 38
Access Control Techniques
Access
Control
Methodologies
- lecture 5
Techniques that fit the organization’s needs
Dr. Huwaida
Tagelsir
Elshoush
Considerations include
Introduction Level of security required
Access Control
Models
User and environmental impact of security measures
Mandatory AC
Discretionary AC
Role-based AC
Techniques differ in
AC
Administration The way objects and subjects are identified
Authentication How decisions are made to approve or deny access
DB Security
Policies governing access
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 13 / 38
Access Control Models
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush Standards that provide a predefined framework for
Introduction
hardware or software developers
Access Control
Models
Mandatory AC Used to implement access control in a device or application
Discretionary AC
Role-based AC
AC
Administration
Custodians can configure security based on owner’s
Authentication
requirements
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 14 / 38
Access Control Models
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush Three major access control models
Introduction Mandatory Access Control (MAC)
Access Control
Models
Mandatory AC
Discretionary AC
Discretionary Access Control (DAC)
Role-based AC
AC
Administration Role-Based Access Control (RBAC)
Authentication
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 15 / 38
Mandatory Access Control (MAC)
Access
Control Assigns a security label to each subject and object
Methodologies
- lecture 5
Dr. Huwaida Matches label of subject to label of object to determine
Tagelsir
Elshoush when access should be granted
Introduction
Access Control
A common implementation is rule-based access control
Models It is based on a set of rules that determine users’ access
Mandatory AC
Discretionary AC rights to resources within an organization’s system.
Role-based AC
AC
Administration
Subject demonstrates need to know in addition to proper
Authentication
security clearance
DB Security
Need to know indicates that a subject requires access to
object to complete a particular task
Also known as policy-based access control (PBAC)
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 16 / 38
Mandatory Access Control
Access
Most restrictive access control model
Control
Methodologies
- lecture 5 MAC models are typically designed using the concept of
Dr. Huwaida
Tagelsir information flow control
Elshoush
Introduction Typically found in military settings
Access Control
Models
Mandatory AC
Two elements
Discretionary AC
Labels
Role-based AC
Levels
AC
Administration
Authentication Labels indicate level of privilege
DB Security
To determine if file may be opened:
Compare object and subject labels
Subject must have equal or greater level than object to be
granted access
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 17 / 38
Mandatory Access Control (MAC)
Access
Control
Major implementations of Mandatory Access Control (MAC)
Methodologies Bell-LaPadula model
- lecture 5
Subjects may not create a new object or perform specific
Dr. Huwaida
Tagelsir functions on lower level objects
Elshoush
Works well in organizations that focus on confidentiality
Introduction
Access Control Biba model
Models
Mandatory AC
Focuses on integrity controls
Discretionary AC
Role-based AC
AC
Clark-Wilson Model
Administration Restricts access to a small number of tightly controlled
Authentication access programs
DB Security
Non-interference Model
Often an addition to other models
Ensures that changes at one security level do not bleed
over into other levels
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 18 / 38
Discretionary Access Control (DAC)
Access Discretionary Access Control is a mechanism that
Control
Methodologies grants access privileges to users based on control policies.
- lecture 5
Dr. Huwaida These control policies govern the access of subjects to
Tagelsir
Elshoush objects using the subjects’ identity and authorization rules.
Introduction Explicit access rules that establish who can, or cannot,
Access Control
Models
execute which actions on which resources.
Mandatory AC
Discretionary AC Discretionary: users can be given the ability of passing on
Role-based AC
AC
their privileges to other users, where granting and
Administration revocation of privileges is regulated by an administrative
Authentication policy.
DB Security
They are highly flexible, making them suitable for a large
variety of application domains.
Least restrictive model
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 19 / 38
Discretionary Access Control (DAC)
Access
Control
Uses identity of subject to decide when to grant an access
Methodologies
- lecture 5
request
Dr. Huwaida
Tagelsir
Elshoush All access to an object is defined by the object owner
Introduction
Access Control Most common design in commercial operating systems
Models
Mandatory AC
Generally less secure than mandatory control
Discretionary AC But generally easier to implement and more flexible
Role-based AC
AC
Administration
Includes
Authentication
Identity-based access control
DB Security
Access control lists (ACLs)
Policies governing ACL development
Procedures to implement ACL
Scope of technical solutions in policy
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 20 / 38
DAC weaknesses
Access
However, the same characteristics that make DAC flexible
Control
Methodologies
also make them vulnerable to malicious attacks,
- lecture 5 such as Trojan Horses embedded in application programs.
Dr. Huwaida
Tagelsir
Elshoush
The reason is that discretionary authorization models do
Introduction not impose any control on how information is propagated
Access Control
Models
and used once it has been accessed by users authorized to
Mandatory AC do so.
Discretionary AC
Role-based AC
AC
Administration
Relies on decisions by end user to set proper security level
Authentication
DB Security Incorrect permissions may be granted
Subject’s permissions will be ”inherited” by any programs
the subject executes
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 21 / 38
MAC versus DAC
Access
Control
Methodologies
- lecture 5
The mandatory access control (MAC) model counters
Dr. Huwaida
these threats by controlling access centrally.
Tagelsir
Elshoush
An ordinary user cannot change the access rights a user
Introduction
has with respect to a file.
Access Control
Models Once a user logs on to the system the rights he/she has
Mandatory AC
Discretionary AC
are always assigned to all the files he/she creates.
Role-based AC
AC This procedure allows the system to use the concept of
Administration
information flow control to provide additional security.
Authentication
DB Security
Thus, monitoring the ways and types of information that
are propagated from one user to another.
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 22 / 38
Role-based Access Control (RBAC)
Access
Role-based Access Control is also called
Control
Methodologies
Non-discretionary Access Control
- lecture 5
Dr. Huwaida
Tagelsir RBAC assigns permissions to particular roles in an
Elshoush
organization
Introduction
Access Control Users are assigned to those roles
Models
Mandatory AC
Discretionary AC
Role-based AC Uses a subject’s role or task to grant or deny object access
AC
Administration
Works well in environments with high turnover of subjects
Authentication
DB Security
Lattice-based control is a variation of non-discretionary
control
Relationship between subject and object has a set of access
boundaries that define rules and conditions for access
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 23 / 38
Access Control Models
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush
Introduction
Access Control
Models
Mandatory AC
Discretionary AC
Role-based AC
AC
Administration
Authentication
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 24 / 38
Access Control Administration
Access
Control
Methodologies Can be implemented as centralized, decentralized, or
- lecture 5
hybrid
Dr. Huwaida
Tagelsir
Elshoush
Centralized access control administration
Introduction
All requests go through a central authority
Access Control
Models
Mandatory AC Administration is relatively simple
Discretionary AC
Role-based AC
AC Single point of failure, sometimes performance bottlenecks
Administration
Authentication Common packages include:
DB Security Remote Authentication Dial-In User Service (RADIUS)
Challenge Handshake Authentication Protocol (CHAP)
Terminal Access Controller Access Control System
(TACACS)
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 25 / 38
Access Control Administration
Access
Control
Methodologies
- lecture 5
Decentralized access control administration
Dr. Huwaida
Tagelsir
Elshoush
Object access is controlled locally rather than centrally
Introduction
More difficult administration
Access Control
Models Objects may need to be secured at multiple locations
Mandatory AC
Discretionary AC
Role-based AC
AC
More stable
Administration
Not a single point of failure
Authentication
DB Security
Usually implemented using security domains
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 26 / 38
Accountability
Access
Control
Methodologies
- lecture 5
System auditing used by administrators to monitor
Dr. Huwaida
Tagelsir Who is using the system
Elshoush
What users are doing
Introduction
Access Control
Models Logs can trace events back to originating users
Mandatory AC
Discretionary AC
Role-based AC
AC
Process of auditing can have a negative effect on system
Administration performance
Authentication Must limit data collected in logs
DB Security Clipping levels set thresholds for when to start collecting
data
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 27 / 38
Authentication Methods
Access
Control
Methodologies
- lecture 5
Two-factor authentication uses two phases
Dr. Huwaida
Tagelsir Identification
Elshoush
Introduction Authentication
Access Control
Models
Mandatory AC
Discretionary AC
Security practices often require input from multiple
Role-based AC categories of authentication techniques
AC
Administration
Authentication Most complex authentication mechanism is biometrics
DB Security (detection and classification of a subject’s physical
attributes)
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 28 / 38
Authentication Methods
Access Authentication is the process of validating a supplicant’s
Control
Methodologies purported identity.
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush
There are three widely used authentication mechanisms, or
authentication factors:
Introduction 1 Something a supplicant knows
Access Control
Models
Example: Password, PIN, Challenge question
Mandatory AC
Discretionary AC
Role-based AC
2 Something a supplicant has
AC Example: Smart Card, token, ATM cards
Administration
Authentication 3 Something a supplicant is or produces
DB Security Example of something a supplicant is: fingerprints, iris
scans
Example: something a supplicant produces: voice patterns,
signatures
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 29 / 38
Single Sign-On
Access
Control
Methodologies
- lecture 5
User’s choice in multi-application environments
Dr. Huwaida
Tagelsir
Elshoush Avoids multiple logins
Introduction
Access Control Transfer of identity from one system to another in a
Models
Mandatory AC
trusted group
Discretionary AC
Role-based AC
AC Requires additional work for administrators
Administration
Authentication
DB Security Kerberos is an example of good SSO systems in use
Kerberos developed at MIT
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 30 / 38
Kerberos
Access
Control Uses symmetric key cryptography
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Provides end-to-end security
Elshoush Intermediate machines cannot read message content
Introduction
Access Control
Models
Used in distributed environments
Mandatory AC
Discretionary AC
Role-based AC
Implemented with a central server
AC
Administration
Authentication Includes a data repository and an authentication process
DB Security
Weaknesses:
Single point of failure
Short life for session key
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 31 / 38
Attacks
Access
Control Brute force attack
Methodologies
- lecture 5 Try all possible combinations of characters to satisfy Type
Dr. Huwaida 1 authentication (password guessing)
Tagelsir
Elshoush
Introduction Dictionary attack
Access Control Subset of brute force
Models
Mandatory AC Instead of all possible combinations, uses a list of common
Discretionary AC
Role-based AC
passwords
AC
Administration
Spoofing attack
Authentication
DB Security
Create fake login program, prompt for User ID, password
Return login failure message, store captured information
Social engineering attack
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 32 / 38
Policies for Vulnerability Handling
Access
Control
Methodologies
- lecture 5
Dr. Huwaida Log all data - login, transaction
Tagelsir
Elshoush
Introduction Analyze data in real time
Access Control
Models
Mandatory AC Set security alerts based on data analysis
Discretionary AC
Role-based AC
AC
Administration Develop scenarios for system shut off
Authentication
DB Security
Disseminate policies related to vulnerability handling
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 33 / 38
Access Control Devices
Access
Control
Methodologies
- lecture 5
Dr. Huwaida Successful access control system includes number of
Tagelsir
Elshoush components, depending on system’s needs for
authentication and authorization
Introduction
Access Control
Models
Mandatory AC
Strong authentication requires at least two forms of
Discretionary AC
Role-based AC
authentication to authenticate the supplicant’s identity
AC
Administration
The technology to manage authentication based on what a
Authentication
supplicant knows is widely integrated into the networking
DB Security
and security software systems in use across the IT industry
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 34 / 38
Database Security - Access Control
Access
Control
Methodologies
- lecture 5
Dr. Huwaida
Tagelsir
Elshoush Commands GRANT and REVOKE control access to a
Introduction
database
Access Control
Models
Mandatory AC GRANT list-of-privileges ON DATABASE database-name
Discretionary AC
Role-based AC
TO user-name—PUBLIC
AC
Administration
Authentication
REVOKE is the opposite of GRANT
DB Security
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 35 / 38
Access Control Policy
Access
Control
Methodologies
- lecture 5
Verify user identity using operating system login
Dr. Huwaida
Tagelsir
Elshoush
Granularity is the roughness or fineness with which access
Introduction
can be controlled
Access Control
Models
Mandatory AC
Discretionary AC
Two dimensions to access granularity:
Role-based AC
Size of unit of access
AC
Administration
Database
Table
Authentication
Column
DB Security
Selected Rows
Scope of actions allowed on the data
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 36 / 38
Scope of Actions
Access
Control SELECT
Methodologies
- lecture 5 Allows the use of the SELECT statement on the named
Dr. Huwaida tables and views
Tagelsir
Elshoush
Introduction
INSERT
Access Control
Allows the use of the INSERT statement on the named
Models tables and views
Mandatory AC
Discretionary AC
Role-based AC
AC
UPDATE
Administration Allows the use of the UPDATE statement on the named
Authentication tables and views
DB Security
DELETE
Allows the use of the DELETE statement on the named
tables and views
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 37 / 38
Scope of Actions
Access
Control
Methodologies
- lecture 5
INDEX
Dr. Huwaida
Tagelsir Allows the use of the CREATE INDEX and DROP INDEX
Elshoush
statement on the named tables and views
Introduction
Access Control
Models ALTER
Mandatory AC
Discretionary AC
Allows the use of the ALTER TABLE statement on the
Role-based AC named tables
AC
Administration
Authentication ALL
DB Security Allows the use of all the statements on all named tables
and views
Dr. Huwaida Tagelsir Elshoush Access Control Methodologies - lecture 5 38 / 38