Technical Analysis of Kerberos Attacks inactive Directory and Presentation of Essential Security Hardening Solutions

سال انتشار: 1405
نوع سند: مقاله کنفرانسی
زبان: انگلیسی
مشاهده: 48

فایل این مقاله در 11 صفحه با فرمت PDF قابل دریافت می باشد

استخراج به نرم افزارهای پژوهشی:

لینک ثابت به این مقاله:

شناسه ملی سند علمی:

TETSCONF18_009

تاریخ نمایه سازی: 14 شهریور 1405

چکیده مقاله:

Kerberos is the core authentication protocol in Active Directory environments. Although it was designed to prevent credential transmission over the network and reduce replay attacks, design weaknesses, dependency on long-term secrets, and misconfigurations of service accounts have made Kerberos a critical attack surface. This paper provides an in-depth technical analysis of Kerberos architecture and advanced attacks including AS-REPRoasting, Kerberoasting, Silver Ticket, Golden Ticket, Delegation Abuse (Unconstrained, Constrained, RBCD), and Pass-the-Ticket. Furthermore, it presents a comprehensive hardening checklist, detection engineering rules, and threat hunting methodologies. The findings indicate that improper SPN management, RC۴ encryption, and lack of pre-authentication remain the most exploited weaknesses. A proposed defense architecture and detection logic are provided to mitigate these threats.

نویسندگان