Home > Information Security News > Two-factor authentication, vigilance foils password theft
Information Security News:
EMAIL THIS
COLUMN

Two-factor authentication, vigilance foils password theft

By Eric Ogren
05 Nov 2009 | SearchSecurity.IN


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

The state of the art in static password protection policies has left some specialists questioning the usefulness of current password policies.

It's going to take new measures -- a mixture of technology and policy -- to hold users more accountable while addressing new attack methods and the automated connectivity of Web 2.0 behavior.

Traditional password protection policies, such as those described by Jeremiah Grossman, one of the industry's top researchers at WhiteHat Security Inc., can be implemented to reduce the risk of an intruder impersonating a user. However, even if the password policy works, it is often unacceptable for IT to disable accounts after a number of bad logon attempts. The business often relies on out-of-wallet questions to avoid expensive help desk calls and a security investigation.

End users are also storing passwords in their browsers for automatic logon and those passwords are often used for multiple accounts in different businesses. The result is an organization that is dependent on another organization's security program to protect a password.

Making matters even more difficult for IT is the changing nature of the threat landscape. Attackers are finding it more effective to harvest passwords from keystroke loggers, Trojans or phishing scams.

Two factor authentication through the use of mobile phones or tokens for high-value, off premise or privileged accounts is one direction an enterprise can take. Two factor authentication, which usually involves a physical device in addition to knowledge of a password/PIN secret, works because the authentication credential is enormously difficult to guess and the user can report the loss of the device leading to a security reset of the account credentials. An enterprise that uses single sign-on for critical application remote access, but does not rely on a form of two factor authentication and instead entrusts the keys to the kingdom in a single password, has an irresponsible security policy.

Organizations should also be proactively auditing account activity for signs of break-in attacks, including failed logon attempts, concurrent logons and logons at strange hours. Irregular logon activity may indicate an attack in progress (valid username, invalid password) or a potentially compromised password. A simple phone call or email exchange with the affected end user will confirm acceptable user access or a security incident, in which case IT can take corrective actions with the account credentials and launch a security investigation to determine the extent of the breach.

Security organizations are defending against passwords on multiple fronts, while acknowledging that 100% security is unattainable. Endpoint security software has to detect and block keystroke loggers and Trojans to protect passwords. A user responsibly writing down passwords and prohibiting Web browsers from automating logons also reduces the security risk.

The most effective protection is constant vigilance to identify suspicious logon activity.


Eric Ogren is founder and principal analyst of the Ogren Group, which provides industry analyst services for vendors focusing on virtualization and security. Prior to founding the Ogren Group, Eric served as a security industry analyst for the Yankee Group and ESG. Ogren has also served as vice president of marketing at security startups Okena, Sequation and Tizor. He can be reached by sending an email to eric@ogrengroup.com.

Tags: Enterprise risk management strategiesBusiness compliance managementIdentity management, authentication and access control solutionsNetwork and endpoint security tools and technologiesRisk Management StrategiesNetwork Security TacticsHacking countermeasuresVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Enterprise risk management strategies
Noted cryptographer on SSL, encryption and cloud computing
What's a risk management strategy worth to your S&P credit rating?
ISO 27001 certification: Preparation in four steps
Two factor authentication gets token agnostic at Central Bank of India
Considering two-factor authentication? Do cost, risk analysis
PCI tokenization push promising but premature, experts say
Clientless SSL VPN vulnerability and Web browser protection
Information rights management helps L&T protect its knowhow
Cloud Security Alliance releases top cloud computing security threats
Voice data security risks on the rise, say experts

Business compliance management
Noted cryptographer on SSL, encryption and cloud computing
What's a risk management strategy worth to your S&P credit rating?
ISO 27001 certification: Preparation in four steps
Two factor authentication gets token agnostic at Central Bank of India
PCI tokenization push promising but premature, experts say
Information rights management helps L&T protect its knowhow
Voice data security risks on the rise, say experts
Firewall audit tools aid compliance
Interest in data leakage protection, event log management rises
Improving regulatory compliance management through log analysis, SIEM

Identity management, authentication and access control solutions
Two factor authentication gets token agnostic at Central Bank of India
Considering two-factor authentication? Do cost, risk analysis
PCI tokenization push promising but premature, experts say
How to perform an Active Directory health check
Information rights management helps L&T protect its knowhow
Voice data security risks on the rise, say experts
Security awareness is the key... cultivate employee loyalty
Preventing password fatigue with single sign-on (SSO) authentication
How to choose online data backup services for data protection
Protecting enterprise networks from new mobile application downloads

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
knowledge process outsourcing (KPO)  (SearchSecurityIN.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite Papers
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts