Considerations in Mitigating Kerberos Vulnerabilities for Active Directory
George Andrei Cordis, Felicia Mirabela Costea, George Pecherle, Robert Ștefan Győrödi, Cornelia Aurora Győrödi
Abstract
George Andrei Cordis, Felicia Mirabela Costea, George Pecherle, Robert Ștefan Győrödi, Cornelia Aurora Győrödi
Abstract
Active Directory (AD) is widely used by organizations to manage authentication and access control for their users, computers, and services. Besides other protocols, AD relies on Kerberos to securely authenticate users, but it has been found to have vulnerabilities that can be exploited by attackers. This research paper discusses these vulnerabilities, the risks they pose to AD security, and different approaches that organizations can take to mitigate them. These approaches include using stronger encryption, limiting privileged accounts, requiring multi-factor authentication, and monitoring log data for suspicious activity. It's important for organizations to keep AD and Kerberos updated with the latest security patches and follow best practices for secure configuration. By implementing these strategies, organizations can strengthen the security of their AD infrastructure and minimize the risk of successful attacks that could lead to the compromise of critical assets and sensitive data.
OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Active Directory (AD) is widely used by organizations to manage authentication and access control for their users, computers, and services. Besides other protocols, AD relies on Kerberos to securely authenticate users, but it has been found to have vulnerabilities that can be exploited by attackers. This research paper discusses these vulnerabilities, the risks they pose to AD security, and different approaches that organizations can take to mitigate them. These approaches include using stronger encryption, limiting privileged accounts, requiring multi-factor authentication, and monitoring log data for suspicious activity. It's important for organizations to keep AD and Kerberos updated with the latest security patches and follow best practices for secure configuration. By implementing these strategies, organizations can strengthen the security of their AD infrastructure and minimize the risk of successful attacks that could lead to the compromise of critical assets and sensitive data.
Key concepts: Kerberos, Computer security, Authentication (law), Computer science, Access control, Compromise, Directory, Directory service