Dan Conrad, Field CTO und Principal Technologist bei Commvault, war zu Gast in Folge 12 des Podcasts „The Resilience Rundown“, um mit Moderator Thomas Bryant über Active Directory zu sprechen. Dan verfügt über mehr als zwei Jahrzehnte Erfahrung mit Active Directory.
Häufige Bedrohungen für AD
Thomas mentioned that many people in the industry tend to overlook authentication and Active Directory when they’re planning for cyber incidents. Dan agreed that the most common threats haven’t changed over his career and tend to boil down to people, processes, and mentalities.
Er berichtete, dass die bisherige Verwaltung von Active Directory Mängel aufwies und Administratoren gefährliche oder ausnutzbare Situationen schufen, indem sie sich im gesamten Netzwerk bewegten und alles mit Administratorrechten ausführten.
Die Single-Sign-On-Funktion von Active Directory, so Dan, mache die Nutzung für Benutzer und Administratoren sehr einfach, doch wir hinterließen überall, wo wir hinkämen, Spuren. Und diese Spuren könnten von Angreifern ausgenutzt werden. Er führte zahlreiche Beispiele für Sicherheitsverletzungen an, die darauf zurückzuführen waren, dass die Anmeldedaten eines einzelnen Benutzers kompromittiert worden waren.
Erhöhte Sicherheit
Im Laufe der Jahre haben Administratoren wie Dan Fortschritte bei den Sicherheitspraktiken erzielt, beispielsweise indem sie ihr reguläres Konto getrennt von ihrem Administratorkonto verwalten und Lösungen für die Verwaltung privilegierter Zugriffe einsetzen.
“That’s much more efficient from a security perspective because every time I’m done using it, I check it back in and it changes the password, which nullifies all those hashes I just left across the network so that they can’t be exploited,” he said.
He also mentions the need to be careful about giving out credentials just because someone asks – and keep an eye on third-party domain trust relationships that can put systems at risk.
Bewährte Praktiken
Thomas fragte nach weiteren bewährten Verfahren zum Schutz von Active Directory vor Bedrohungen, die über die Trennung von Rollen und PAM hinausgehen. Dan erwähnte das Installieren von Patches, wobei man die Auswirkungen auf ältere Anwendungen im Auge behalten müsse. Er wies außerdem darauf hin, dass es am wichtigsten sei, so viel wie möglich über Active Directory zu wissen.
“That’s sort of my mentality, that safety net, that you think you know how to detect, you think you know how to patch, you think you know how to do all this stuff,” Dan said. “But if you can’t recover, none of that really matters because there’s going to be something you didn’t know about.”
Die Rolle von Backup und Wiederherstellung
Thomas’ question on the role of backup and recovery in terms of protecting Active Directory prompted Dan to recall some sticky situations from the past. However, he also mentioned that “the other side of that is having the ability to recover at a granular level, is sort of a very relaxing feeling.”
Sehen Sie sichhierden vollständigen Podcast mit dem Rest ihres Gesprächs an.