Technical Analysis of Kerberos Attacks inactive Directory and Presentation of Essential Security Hardening Solutions
سال انتشار: 1405
نوع سند: مقاله کنفرانسی
زبان: انگلیسی
مشاهده: 48
فایل این مقاله در 11 صفحه با فرمت PDF قابل دریافت می باشد
- صدور گواهی نمایه سازی
- من نویسنده این مقاله هستم
استخراج به نرم افزارهای پژوهشی:
شناسه ملی سند علمی:
TETSCONF18_009
تاریخ نمایه سازی: 14 شهریور 1405
چکیده مقاله:
Kerberos is the core authentication protocol in Active Directory environments. Although it was designed to prevent credential transmission over the network and reduce replay attacks, design weaknesses, dependency on long-term secrets, and misconfigurations of service accounts have made Kerberos a critical attack surface. This paper provides an in-depth technical analysis of Kerberos architecture and advanced attacks including AS-REPRoasting, Kerberoasting, Silver Ticket, Golden Ticket, Delegation Abuse (Unconstrained, Constrained, RBCD), and Pass-the-Ticket. Furthermore, it presents a comprehensive hardening checklist, detection engineering rules, and threat hunting methodologies. The findings indicate that improper SPN management, RC۴ encryption, and lack of pre-authentication remain the most exploited weaknesses. A proposed defense architecture and detection logic are provided to mitigate these threats.
کلیدواژه ها:
Kerberos ، Active Directory ، Golden Ticket ، Kerberoasting ، AS-REPRoasting ، SPN ، TGT ، MITRE ATT&CK
نویسندگان