Tuesday, January 29, 2013

Solving Substantiation with SAML

Organizations are deploying distributed, hybrid architectures that can span multiple security domains. At any moment, a user could be accessing the corporate data center, the organization’s cloud infrastructure, or even a third party, #SaaS web application. #SAML can provide the identity information necessary to implement an enterprise-wide single sign-on solution.

Proving or asserting one’s identity in the physical world is often as simple as showing a driver’s license or state ID card. As long as the photo matches the face, that’s typically all that is needed to verify identity. This substantiation of identity is a physical form of authentication, and depending on the situation, the individual is then authorized either to receive something or to do something, for instance, enter a bar, complete a purchase, etc.

In the digital world, identity verification is not as easy as showing the computer monitor a driver’s license. To gain entry, you must provide information like a name, password, randomly generated token number—something you have, something you know, or something you are—to prove you are who you say you are.

Gaining access to corporate assets is no different. Many organizations have multiple different resource portals, however, each requiring digital proof of identity. Their users may also need to access partner portals, cloud based Software as a Service (SaaS) applications, or distributed, hybrid infrastructures that span multiple data centers, each requiring a unique user name and password. In addition, the average employee must maintain about 15 different passwords for both her private and corporate identities, with many of those passwords also being used for social media and other risky entities. Statistics show that 35 to 50 percent of help desk calls are related to password problems, with each call costing a company between $25 and $50 per request.

Security Assertion Markup Language (SAML) is an XML-based standard that allows secure web domains to exchange user authentication and authorization data. It directly addresses the problem of how to provide the users of web browsers with single sign-on (SSO) convenience. With SAML, an online service provider can contact a separate online identity provider to authenticate users who are attempting to access secure content. For example, a user might need to log in to Salesforce.com, but Salesforce (the service provider) has no mechanism to validate the user. Salesforce would then send a request to an identity provider, such as F5 BIG-IP Access Policy Manager (APM), to validate the requesting user’s identity. BIG-IP APM version 11.3 supports SAML federation, acting as either a service provider or an identity provider, enhancing the employee’s online experience and potentially reducing password-related tickets at the help desk.

BIG-IP APM version 11.3 can act as either a SAML service provider or a SAML identity provider, enabling both federation and SSO within an enterprise.

BIG-IP APM as a Service Provider

When a user initiates a request from a SAML IdP and the resources, such as an internal SharePoint site, are protected by BIG-IP APM, BIG-IP APM consumes that SAML assertion (claim) and validates its trustworthiness. This ultimately allows the user access to the resource. If the user goes directly to BIG-IP APM (as an SP) to access a resource (like SharePoint), then the user will be directed to the IdP to authenticate and get an assertion. Once a user is authenticated with a SAML IdP and accesses a resource behind BIG-IP APM, he or she will not need to authenticate again. 

BIG-IP APM as an Identity Provider

Provided there is an SP that accepts assertions, a user can authenticate with BIG-IP APM to create an assertion. BIG-IP APM authenticates the user and displays resources. When the user clicks on an application, BIG-IP APM generates an assertion. That assertion can be passed on to the SP, which allows access to the resource without further authentication. When the user visits the SP first, the process is SP initiated; when the user goes directly to the IdP (in this case, BIG-IP APM) first to authenticate, the process is IdP initiated.

BIG-IP APM in a SAML Federation

SAML can be used to federate autonomous BIG-IP APM systems. This allows a user to connect to one BIG-IP device, authenticate, and transparently move to other participating BIG-IPs devices. Session replication is not part of SAML, but administrators can populate session information on participating systems. This means that BIG-IP device federation does not enable the use of a single session within the federation; it only enables information exchange among multiple members of the federation.  Each participating BIG-IP device maintains its own independent session with the client, and each has its own access policy that executes separately and independently.
Participating federation members can exchange information with any other federation members outside of sessions where needed. A common configuration is to have a dedicated BIG-IP device as a primary member to which users are authenticated and that provides information to other members. This allows a number of other BIG-IP devices to work in conjunction with that primary member.  The primary member is dedicated as an IdP, while the other participating members operate as SPs

Benefits

The benefits of deploying BIG-IP APM as a SAML solution certainly include better password management, fewer help desk calls, and an improved user experience, but BIG-IP APM can also add additional context to requests. For instance, it can include endpoint inspection results as attributes to inform the application of the client’s security posture. In addition, IT administrators do not need to retrofit applications (e.g., .NET apps do not need a Kerberos claims plug-in). Another advantage is extensive session variable support, which allows organizations to
customize each user session. BIG-IP APM can bring SAML to resources and applications with minimal back-end changes—or none. These benefits all complement the values of BIG-IP APM to the overall traffic management of an organization’s IT infrastructure.

IT infrastructure has changed dramatically over the past few years, with many applications moving to cloud-based services. Corporate employees have also morphed into a mobile workforce that requires secure access to that infrastructure any time, from anywhere, and with any device. Bridging the identity gap between physically and logically separated services allows organizations to stay agile in this ever-changing environment and gives users the secure access they need around the clock.

BIG-IP APM version 11.3, in addition to delivering high availability and protecting organizations’ critical assets, provides a SAML 2.0 solution that offers the identity bridge needed to manage access across systems.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, January 22, 2013

Security Bloggers Network Voting

I'm listed in the preliminary round of nominees (to hopefully make it to the final nominees) in two categories for the 2013 Social Security Blogger Awards: Security Bloggers Network Voting

Please share and vote for your favorite through Friday, January 25, even if it's not me.  :-)

The Most Educational Security Blog

clip_image001Critical Watch: http://blog.criticalwatch.com/

clip_image001[1]psilvas blog: http://psilvas.wordpress.com/

clip_image001[2]MichaelPeters.org: http://michaelpeters.org/

The Most Entertaining Security Blog

clip_image001[3]psilvas blog: http://psilvas.wordpress.com/

From Alan Shimel's blog:

A little later then we wanted, but the preliminary round of voting for the 2013 Social Security Blogger Awards is open as of today.  As I wrote in an earlier post we are doing something a little different this year.  In addition to finalists nominated by our judges, we are also letting bloggers and podcasters nominate themselves for the preliminary round.  The top vote getters in each category of the preliminary rounds will be added to the finalists.

Voting for the preliminary round will continue for the rest of this week.  Then voting in the finals will commence.  We hope this will allow a new generation and some "fresh faces" into the award process.

Of course the winners will be announced at the Security Bloggers Meetup at RSA Conference this year.

Thanks!

ps

Related

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, January 21, 2013

HELLO, My Name is Cloud_009...

 ...scrolls across the small 16:9 LCD protruding from my chest cavity. 

In case you missed it, I'm from the future, where we all have become our own personal cloud.  Some clouds you can actually see, like auras, but look somewhat like the classic Peanuts character Pigpen.  We've all become walking antennas, routers, hotspots and hubs for all the other personal clouds.  If auto-discovery is enabled, once you are in range of a 'friend' that you 'like,' a few beeps go off and they appear as an icon right in our own retina.  You remember those smart phones that allowed users to tap the phones to send a picture or file?  Now, all we have to do is crank up some digital audio and do a move called 'The Bump.'  It's based on some ancient 1970's fad dance where participants would lightly 'bump' hips to the beat of the music.  Today we use it to exchange data.  A bump or two and you've shared your music library.  A hip-check, your movie collection.  Passing gas is kinda like your old computer's recycle bin that you need to empty every so often.

All this works in conjunction with the IPv6 chip inserted into the freshly cut umbilical cord of every newborn, so it heals right into the system.  As you grow, the bellybutton also becomes a power source - you can interchange belly-ring connections and power almost any device with the solar plexus.  But we really do not carry 'mobile' devices anymore since their functionality is now mostly built in to our carcasses.  Our ear and earlobe have evolved to have the capability of answering calls or listening to audio just by pushing in the outer ear plug or as you used to call it, the tragus.  The earlobe itself is a highly sensitive bio-metric scanner that'll check your thumbprint and if authenticated, will unlock your car, home or any other item that you program. 

We each have a cloud identifier to distinguish our identity.  I'm Cloud_009.  I used to be Cloud_337528 but since I'm usually happy, have a strong security posture and graduated from ISO University, I was recently upgraded.  You're probably wondering if I know Cloud_007.  We've met a couple times but I try to stay away from the espionage cloud since you really don't know what you may catch in there.  Lots of infecting, crashing and drive-by Bumps. 

I'm also able to segment parts of my cloud for work and play.  Some clouds do top half/bottom half but I like to go right down the middle.  When enabled, my right side handles my work/corporate data and the left does my personal stuff.  Because I'm flexible, the percentages can adjust on the spot when the demand goes up.  From 9-5, I might use up to 80% of my cloud-body for work related computations with the other 20% reserved for bathroom breaks, eating, breathing, recharging and any other personal activities.  The data stays separate, secure and encrypted. 

Well, I got a hologram coming in that I need to watch but it was nice talking with you.  We don't do much of that anymore since most messages are sent telepathically these days.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, January 16, 2013

Inside Look - Enterprise Manager v3.1

I meet with Bruce Butterfield, Principal Software Engineer for Management Solutions, to get an inside look at the new Enterprise Manager v3.1 including the awesome LogIQ.  'Inside Look' takes a deeper dive into BIG-IP Technology.

 

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, January 8, 2013

Lost Records a Day Shows Doctors are Blasé

#HealthCare #Privacy Challenges

patient privacy usatoday I always wanted to write, 'In the USA Today, today' in the Life section snapshots sidebar there is an interesting stat from a December 2012 Ponemon Institute study of 80 health care organizations showing that the data lost or stolen most often are our medical records at 48% and billing/insurance records at 48% followed by payment details at 24%.  Multiple responses were allowed which is why the percentages break 100.  What is more alarming is that over the last two years, 94% of health care organizations have been breached at least once and 45% have had 5 or more incidents!  What is sad is that over half (54%) have little or no confidence that they can detect patient data loss.

I know many of us often delay or avoid the doctors for fear that we might get diagnosed with something terrible but maybe now we'll avoid with the notion, 'eh, I'm healthy and I don't want to be afflicted with identity theft disease.'  Ask your doctor about ITD - common side effects include increased heart rate, depression, headaches, loss of appetite and in some patients, bank account drainage.  Why risk it?  Heck, the last time my wife went to her now previous doctor and asker her about how she complies with HIPAA, the doctor didn't even know what that was!  How can that be?  How can a practicing physician be unaware of HIPAA?  That's like a bank unaware of PCI or the numerous other financial regulatory requirements.  But is it 'unaware' or 'just don't care.'

The primary causes of health care data breach include lost or stolen devices along with employee or 3rd party mistakes and they only learned of the breach because of an audit.  Data gets moved around amongst various parties for multiple reasons it is often hard to determine who and where leaked it.

Suggestions include appointing senior security roles reporting to the board, securing mobile devices, using encryption, develop breach plans that are ready and tested, education and as more health care organizations turn to the cloud, understand and control that risk - whatever it may be.

Oh, and have a seat, we'll be with you in a moment.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, January 3, 2013

Is TV's Warm Glowing Warming Glow Fading?

If Homer only knew back in 1994 that smartphone mobile apps would someday start to creep into precious TV viewing time, he probably would have written, 'No Smartphone and No Specialty Beer Make Homer Go Crazy,' in the Simpson's classic Treehouse of Horror V.  It's no surprise that time spent on mobile apps have overtaken time spent on desktop web usage.  Typical smartphone owners have an average of 41 apps per device, 9 more than they had last year according to the Nielsen report, State of the Appnation – A Year of Change and Growth in U.S. Smartphones.   Mobile app usage has jumped 35% from 94 minutes a day a year ago to almost 130 minutes a day today while desktop web usage dropped from 72 to 70 minutes a day, according to Flurry.  Almost twice as much time mobile app'ing than web browsing.  Many of us probably spend more than two hours a day fiddling with mobile apps.  And the time spent doing that is now challenging our beloved TV viewing time. 

mobile-app-tv-consumption Based on United States Bureau of Labor Statistics for 2010 and 2011, Flurry estimates that Americans watch about 168 minutes of television a day.  They expect that tablet and smartphone apps will compete with TV as the primary method for media consumption.  Personally, I think that might occur in many households, but with internet capable TVs and our love of the big screen, I don't think it'll go away.  In fact, I think the TV will become more of a communications hub.  Simply a big monitor on the wall that handles video calls, closed circuit cameras, streaming media, broadcast media, web surfing and any other IP related task.  Moving around and mobile, cool...but sitting on my couch, I'd rather look at a larger screen than some 5 inch display.  Just me.  I've mentioned in the past that, I think that TVs, cars and any other connected device could be considered BYOD in the near future.  Why wouldn’t a mobile employee want secure VDI access from his car’s Ent/GPS display?  Why couldn’t someone check their corporate email from the TV during commercials?

The category of top apps is also shifting.  While gaming is still the top app at 43% (down from 50%), entertainment apps and utilities gained more of our attention at the expense of games and social networking (30% to now 26% of our time).  Clearly mobile apps are touching many aspects of our life and as more BYOD deployments occur in 2013, there will probably be more business specific apps on our devices and our daily 'media' consumption will rise.  Yet, I gotta believe that (at least in the U.S.), we love our televisions so much and I have a hard time thinking that we're going to shove them aside for something we can carry in our pocket.  At least in the home.  And as more TVs get cameras, are internet ready, have our favorite streaming channels loaded, allow us to check email and can browse the web (all the things a smartphone can do with the processing power), I think we may gravitate back to a family on the living room couch.  Do you think mobile apps will overtake TV one day?

As an aside, I was having a little trouble coming up with a blog topic to start 2013 but anytime I can include a 1990's reference, a Simpsons quote and BYOD in the same entry, that's a pretty good start to the year.
ps
References:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]