office 365 tietoturvan heikon lenkki?

29
The weakest link of Office 365 security EUNIS 2015 Dundee, Scotland @NestoriSyynimaa

Upload: phamthuan

Post on 14-Feb-2017

217 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Office 365 tietoturvan heikon lenkki?

The weakest link of Office 365 security

EUNIS 2015 Dundee, Scotland

@NestoriSyynimaa

Page 2: Office 365 tietoturvan heikon lenkki?

About the speaker

• Dr. Nestori Syynimaa MBCS CITP • Enterprise Architect @ CSC Ltd

• Owner @ Gerenios Ltd

• Senior-consultant @ Sovelto Plc

• MCT, MCSA (Office 365), MCE

• www.linkedin.com/in/nestori

Page 3: Office 365 tietoturvan heikon lenkki?

Purpose

• Target audience: IT professionals – contains a lot of technical details

• Introduce Office 365 security principals and general security issues

• Show some security threats, forensics and mitigation

• Accessing other person’s confidential data is against the law!

• Question: What is the weakest link of Office 365 security?

3

Page 4: Office 365 tietoturvan heikon lenkki?

Contents

• Office 365 security basics

• Office 365 & Azure identity scenarios

• Accessing confidential information

• (Demo)

4

Page 5: Office 365 tietoturvan heikon lenkki?

Office 365 security basics

Page 6: Office 365 tietoturvan heikon lenkki?

£/user/month

Page 7: Office 365 tietoturvan heikon lenkki?

28.-29.5.2015 Tech Conference 2015 7

Page 8: Office 365 tietoturvan heikon lenkki?

Cloud Security Surface Area

Page 9: Office 365 tietoturvan heikon lenkki?

Office 365 security model

Page 10: Office 365 tietoturvan heikon lenkki?

Core components

Page 11: Office 365 tietoturvan heikon lenkki?

Office 365 (Azure) admin & user roles Role Description

Global admin Access to all administrative features. Only role that can be used assign admin rights to others.

Billing admin Can make purchases, manage subscriptions and support tickets, and monitor service health.

User management admin Resets passwords, monitors service health, and manages user accounts, user groups, and service requests.

Password admin Resets passwords, manages service requests, and monitors service health. Password admins are limited to resetting passwords for users and other password admins.

Service admin Manages service requests and monitors service health.

User No access to administrative features.

Page 12: Office 365 tietoturvan heikon lenkki?

Identity scenarios

Page 13: Office 365 tietoturvan heikon lenkki?

Office 365 scenarios Synced IdentityCloud Identity

Office 365 Azure

Active Directory

Active Directory DirSync

Office 365 Azure

Active Directory

Federated Identity

Active Directory DirSync

Office 365 Azure

Active Directory

AD FSActive Directory

Cloud

On-premise

Cloud

On-premise

Cloud

On-premise

Synced IdentityCloud Identity

Office 365 Azure

Active Directory

Active Directory DirSync

Office 365 Azure

Active Directory

Federated Identity

Active Directory DirSync

Office 365 Azure

Active Directory

AD FSActive Directory

Cloud

On-premise

Cloud

On-premise

Cloud

On-premise

Synced IdentityCloud Identity

Office 365 Azure

Active Directory

Active Directory DirSync

Office 365 Azure

Active Directory

Federated Identity

Active Directory DirSync

Office 365 Azure

Active Directory

AD FSActive Directory

Cloud

On-premise

Cloud

On-premise

Cloud

On-premise

Page 14: Office 365 tietoturvan heikon lenkki?

AD FS endpoints

AD FS

On-premise

AD FS proxy

Browser

Lync

Outlook

DMZ InternetBrowser

Lync

Outlook

Active

MEX

Web

Active

MEX

Web

ActiveSyncActiveSync

Basic Authentication

AD FS endpoints

Page 15: Office 365 tietoturvan heikon lenkki?

Accessing confidential information

Page 16: Office 365 tietoturvan heikon lenkki?

Challenges

• We need to secure information – all the time

• Intruder needs success only once..

• Things change – we need to change too

• Definition of insanity (A. Einstein): • “..doing the same thing over and over and expecting different results”

Page 17: Office 365 tietoturvan heikon lenkki?

Source of security threats

Page 18: Office 365 tietoturvan heikon lenkki?

Security paths

Threat

Agents

Attack

Attack

Attack

Weakness

Weakness

Weakness

Weakness

Control

Control

Control

Asset

Function

Asset

Impact

Impact

Impact

Attack

Vectors

Security

Weaknesses

Security

Controls

Technical

Impacts

Business

Impacts

OWASP (2013)

Page 19: Office 365 tietoturvan heikon lenkki?

Most Critical Web Application Security Risks

1. Injection

2. Broken Authentication and Session Management

3. Cross-Site Scripting (XSS)

4. Insecure Direct Object References

5. Security Misconfiguration

6. Sensitive Data Exposure

7. Missing Function Level Access Control

8. Cross-Site Request Forgery (CSRF)

9. Using Known Vulnerable Components

10. Unvalidated Redirects and Forwards

OWASP (2013)

Page 20: Office 365 tietoturvan heikon lenkki?

The weakest link: Dave the Administrator

21

Page 21: Office 365 tietoturvan heikon lenkki?

“DEMO”

Motivated Intruder Test:

• Accessing user’s mailbox without getting caught

Page 22: Office 365 tietoturvan heikon lenkki?

Give mailbox permission

Page 23: Office 365 tietoturvan heikon lenkki?

Change user password

Page 24: Office 365 tietoturvan heikon lenkki?
Page 25: Office 365 tietoturvan heikon lenkki?

Restoring user’s original password

Page 26: Office 365 tietoturvan heikon lenkki?

Altering AD FS rules

Page 27: Office 365 tietoturvan heikon lenkki?

Gaining admin rights

28

Page 28: Office 365 tietoturvan heikon lenkki?

Summary

• The weakest link of Office 365 is on-premise security misconfiguration

• Cloud services requires new kind of skills

• Securing the on-premise environment is (even more) crucial • Minimum admin rights

• Identify and protect critical components

• Use BitLocker and IDM

• Provide training to your key personnel

Page 29: Office 365 tietoturvan heikon lenkki?

Thank you!

@NestoriSyynimaa

linkedin.com/in/nestori

www.o365.center