{"id":1859,"date":"2019-07-15T14:17:26","date_gmt":"2019-07-15T12:17:26","guid":{"rendered":"https:\/\/adm-adria.nevtron.si\/?p=1859"},"modified":"2019-07-15T14:17:26","modified_gmt":"2019-07-15T12:17:26","slug":"ustrezen-nivo-dostopa-je-kljucen-za-preprecitev-varnostnega-incidenta","status":"publish","type":"post","link":"https:\/\/adm-adria.si\/en\/2019\/07\/ustrezen-nivo-dostopa-je-kljucen-za-preprecitev-varnostnega-incidenta\/","title":{"rendered":"Ustrezen nivo dostopa je klju\u010den za prepre\u010ditev varnostnega incidenta"},"content":{"rendered":"<p>Klju\u010dne sisteme in aplikacije v ve\u010dini primerov \u0161e vedno varujemo enako kot pred leti. V tem \u010dasu je tehnologija nadzora napredovala, a \u0161e vedno najdemo re\u0161itve, ki se v zadnjem desetletju niso tehnolo\u0161ko spremenile.<\/p>\n<p>SIEM re\u0161itve zajemajo in obdelujejo ogromne koli\u010dine dogodkov, zato za svoje delo potrebujejo veliko strojne mo\u010di, kot rezultat pa vrnejo obvestilo o dogodkih, ki so se zgodili v preteklosti.\u00a0Namesto prepre\u010devanja varnostnih incidentov, je na voljo obve\u0161\u010danje o incidentih, do katerih je pri\u0161lo. Samo prepre\u010devanje incidentov je prepu\u0161\u010deno po\u017earnim zidovom in neomajnem zaupanju v varno in zaupanja vredno obna\u0161anje skrbnikov.<\/p>\n<p><strong><em>Pomembna je tako ustrezna obravnava skrbni\u0161kih ra\u010dunov kot tudi poskus prepre\u010devanja ne\u017eelenih aktivnosti, \u0161e preden se zgodijo!<\/em><\/strong><\/p>\n<p>Prvi korak sodobnega pristopa je sprememba na\u010dina dostopa do sistemov in aplikacij, in sicer z\u00a0<strong>dvo-faktorsko prijavo<\/strong>\u00a0<em>(ang. Two-Factor Authentication,\u00a0<strong>2FA<\/strong>)<\/em>.<\/p>\n<p>Pri tem se lahko osredoto\u010dimo na poljuben nabor uporabnikov ali sistemov, za katere postane dvo-faktorska prijava obvezna.<\/p>\n<p>Priporo\u010damo dve re\u0161itvi, preprosti za uporabo, ki hkrati nudita napredno za\u0161\u010dito uporabni\u0161kih ra\u010dunov kot obla\u010dna storitev ali namestitev direktno v okolje naro\u010dnika!<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/bit.ly\/2Yy7GN3\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Starling two-factor Authentication<\/a>\u00a0<\/strong>(obla\u010dna re\u0161itev za 2FA)<\/li>\n<li><strong><a href=\"https:\/\/bit.ly\/2FXJEnx%20\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Defender<\/a>\u00a0<\/strong>(Lokalna re\u0161itev za 2FA)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Za uspe\u0161en nadzor\u00a0<strong>priviligiranih ra\u010dunov<\/strong>\u00a0<em>(ang.\u00a0<\/em>Privileged Access Management,\u00a0<strong>PAM<\/strong>), je poleg spremljanja dogodkov pomemben tudi vidik snemanja celotne seje skrbni\u0161kih posegov na sistemih. Snemajo se lahko RTP, SSH, VNC, VmWare Horizont in ICA protokoli. Samo snemanje ne zadostuje, zato je potrebno tudi zaznavanje odprtih aplikacij (avtomatsko zapiranje seje) in nadzor vnosa, ki prepre\u010duje neza\u017eelene aktivnosti (nadzor nad vnosom podatkov).<\/p>\n<div class=\"teads-adCall\"><\/div>\n<p>Snemanje lahko poteka brez vednosti uporabnika, saj se vr\u0161i na omre\u017enem nivoju in ne kot zajemanje serije slik na delovni postaji ali stre\u017eniku.<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/bit.ly\/2YFDteW%20\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">One Identity Safeguard<\/a>\u00a0<\/strong>(upravljanje, snemanje in analiza privilegiranih dostopov (PAM))<\/li>\n<\/ul>\n<p><strong><em>Nad klju\u010dnimi sistemi naj bdijo re\u0161itve, ki poleg branja dnevnikov tudi spremljajo dogajanje.<\/em><\/strong><\/p>\n<p>Aktivni imenik\u00a0<em>(ang. Active Directory, AD)<\/em>\u00a0spremljamo direktno preko API klicev, ki dnevnikov niti ne potrebujejo (skrbnik lahko izklju\u010di vse mo\u017enosti spremljanja preko GPO),spremljajo pa vse dogodke! Enako velja za Datote\u010dni sistem, SharePoint, Exchange, Office 365 in Azure AD. Celoten nadzor in vsi dogodki se zbirajo na enem mestu ter jih po \u017eelji skupaj z dnevniki vseh sistemov bele\u017eimo in shranjujemo na dalj\u0161i rok, saj je kompresija podatkov 1:40 (tudi v praksi in ne samo na papirju).<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/bit.ly\/2XtWEfq\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Change Auditor<\/a>\u00a0<\/strong>(zagotavlja popoln nadzor nad spremembami v realnem \u010dasu)<\/li>\n<li><strong><a href=\"https:\/\/bit.ly\/2xxiTS6\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">InTrust solution<\/a>\u00a0<\/strong>(prejema, varno zbira in shranjuje podatke o dogodkih (Log))<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong><em>Najpomembnej\u0161i so \u0161e vedno podatki v bazah podatkov.<\/em><\/strong><\/p>\n<p>Dostop do podatkov ni ve\u010d samoumevno dovoljen vsem skrbnikom brez omejitev. Poleg snemanja sej, je potrebno imeti sistem, ki prepre\u010di nedovoljene poizvedbe na sami bazi podatkov ter vra\u010da podatke, maskirane ali \u0161ifrirane v delu, ki ga ne \u017ealimo pokazati!<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/bit.ly\/2XPSNse%20\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Cirro<\/a>\u00a0<\/strong>(upravljanje podatkov, nadzor podatkov in kontrola dostopov)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Vsi omenjeni sklopi ne omogo\u010dajo le detekcije, ampak prepre\u010dujejo in izvajajo popoln nadzor nad skrbni\u0161kimi ra\u010duni. Tako se ustvarja kredibilna revizijska sled, saj so vsi nadzorni sistemi name\u0161\u010deni tako, da skrbniki kon\u010dnih sistemov niso \u0161e skrbniki nadzornih sistemov. Tudi v nadzorne sisteme vpeljemo lo\u010devanje vlog!<\/p>","protected":false},"excerpt":{"rendered":"<p>Klju\u010dne sisteme in aplikacije v ve\u010dini primerov \u0161e vedno varujemo enako kot pred leti. V tem \u010dasu je tehnologija nadzora napredovala, a \u0161e vedno najdemo re\u0161itve, ki se v zadnjem desetletju niso tehnolo\u0161ko spremenile. SIEM re\u0161itve zajemajo in obdelujejo ogromne koli\u010dine dogodkov, zato za svoje delo potrebujejo veliko strojne mo\u010di, kot rezultat pa vrnejo obvestilo [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1860,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1859","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-novice"],"_links":{"self":[{"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/posts\/1859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/comments?post=1859"}],"version-history":[{"count":1,"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/posts\/1859\/revisions"}],"predecessor-version":[{"id":1861,"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/posts\/1859\/revisions\/1861"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/media\/1860"}],"wp:attachment":[{"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/media?parent=1859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/categories?post=1859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/adm-adria.si\/en\/wp-json\/wp\/v2\/tags?post=1859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}