Details

Zmanjševanje tveganj napadov Kerberos in pršenja gesel v okolju Windows Active Directory
ID Tajnšek, Aljaž (Author), ID Pesek, Matevž (Author)

.pdfPDF - Presentation file, Download (230,40 KB)
MD5: F0DD989B5526B30F0E077F6DCB079DFF
URLURL - Source URL, Visit https://ev.fe.uni-lj.si/4-2025/Tajnsek.pdf This link opens in a new window

Abstract
V clanku opisujemo Windows Active Directory ter mo ˇ znosti za ˇ sˇcite pred napadi, ki ogro ˇ zajo ˇ uporabnike in integriteto podjetja, ki to storitev uporablja. Podrobno smo analizirali in reproducirali tri vrste napadov: enumeracijski napad, napad Kerberos in napad s prsenjem gesel. Vsi trije napadi so usmerjeni proti ˇ uporabnikom ter na razlicne na ˇ cine pridobivajo zgo ˇ sˇcene vrednosti gesel, ki jih napadalci s tehnikami grobe ˇ sile nato pretvarjajo v dejanska uporabniska gesla. Tako lahko s pove ˇ canjem privilegijev pridobijo nepoobla ˇ sˇcen ˇ dostop do omreznih virov in ogrozijo celotno infrastrukturo podjetja. V nadaljevanju predstavimo ustrezne ˇ preventivne ukrepe za zasˇcito stre ˇ znika in najbolj ˇ se prakse za obrambo pred opisanimi napadi, kot so pravilna ˇ konfiguracija Active Directory, okrepitev politike gesel in uvedba rednega spremljanja varnosti streznika.

Language:Slovenian
Keywords:Windows Active Directory, enumeracijski napad, napad Kerberos, napad s pršenjem gesel
Work type:Article
Typology:1.04 - Professional Article
Organization:FE - Faculty of Electrical Engineering
Year:2025
Number of pages:Str. 203-2111
Numbering:Letn. 92, št. 4
PID:20.500.12556/RUL-183574 This link opens in a new window
UDC:004.056
ISSN on article:0013-5852
COBISS.SI-ID:257363459 This link opens in a new window
Publication date in RUL:15.06.2026
Views:101
Downloads:84
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Record is a part of a journal

Title:Elektrotehniški vestnik
Publisher:Strokovna zadruga koncesijoniranih elektrotehnikov, Elektrotehniška zveza Slovenije
ISSN:0013-5852
COBISS.SI-ID:742916 This link opens in a new window

Licences

License:CC BY 4.0, Creative Commons Attribution 4.0 International
Link:http://creativecommons.org/licenses/by/4.0/
Description:This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.

Secondary language

Language:English
Title:Windows Active Directory security mitigating the risks of Kerberos and password spraying attacks
Abstract:
This article describes Windows Active Directory and the possibilities of protection against attacks that threaten users and the integrity of the company that uses this service. We have analyzed in detail and experimentally implemented three types of attacks: enumeration attack, Kerberos attack and password spraying attack. All three attacks are directed against users and in various ways obtain hashed values of passwords, which attackers then convert into actual user passwords using bruteforce techniques. With the obtained passwords, unauthorized individuals can gain access to network resources, increase privileges and compromise the entire company infrastructure. We also present appropriate preventive measures for server protection and best practices for defense against such attacks, such as correct configuration of Active Directory, strengthening password policy and introducing regular monitoring of server security.

Keywords:Windows Active Directory, enumeration attack, Kerberos attack, password spraying attack

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back