Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

Least-Privilege Technology Still Swimming Upstream, But Making Progress

Fundamental shift in endpoint security might be easier with rollout of Windows 7, experts say

The least-privilege security model is one of the oldest and best-known endpoint strategies in the industry. It has the support -- at least on paper -- of Microsoft, and products for implementing it have been available for years. Yet so far, researchers estimate that only 20 percent of corporate endpoints are using those technologies.

So what's everybody waiting for?

For those who came in late, the least-privilege concept was developed in military circles more than a decade ago. Put simply, it states that people -- and their PCs -- should be given access only to information (and software) they expressly need to do their jobs. It's basically the "need to know" concept applied to computers -- each endpoint starts with no access and no administrative rights, and access to applications and data is given only when the end user is deemed to have a need for it.

On paper, the least-privilege concept appears ideal for the business environment, where many security breaches are caused by end users who accidentally leak data or hackers who exploit Windows administrative rights. Microsoft has lent its support to the least-privilege concept with the development of User Access Control (UAC), which creates "standard user rights" on end stations, eliminating the default administrative rights that previously characterized most Windows deployments.

In practice, however, only a small percentage of PCs currently use least-privilege technology. Analysts and other experts point to three chief inhibitors to its deployment: technology, complexity, and culture.

The first problem -- technology -- has to do with Windows itself. In the past, Windows has always granted the user administrative rights as a default, and therefore many applications developers have created software that uses those rights. Intuit QuickBooks, for example, offers several features that rely on administrative privileges, and the program wouldn't work properly if those rights were not there. Many other applications, particularly industry-specific and home-grown apps, also require admin privileges to operate.

"The biggest reason why least-privilege technology hasn't caught on is because of the applications that require admin rights in order to work," says Scott McCarley, director of marketing at BeyondTrust, a security software vendor that specializes in least-privilege. "If you've got programs that won't work without those rights, you're in a tough spot."

BeyondTrust, which works closely with Microsoft, has developed a tool called Privilege Manager, which enables the PC to access administrative rights when it needs them to operate a specific application or task -- and keeps those rights restricted the rest of the time. Of the 20 percent of end stations that currently use least-privilege, many are running the BeyondTrust software, and the company doubled its sales last year.

BeyondTrust maintains that many of today's most popular hacks would be impossible on Windows computers that don't have administrative rights. In a study conducted earlier this year, the company found that of all the vulnerabilities Microsoft labeled as "critical" in 2008, some 92 percent exploited administrative privileges in some fashion.

"Implement least-privilege without admin rights, and 92 percent of those vulnerabilities would have been mitigated," McCarley said. "That's a big step in the right direction."

But analysts say the second inhibitor -- complexity -- still stands in the way of implementation. "[Least-privilege] is a very effective control, but nearly impossible to implement on Windows XP," says Rich Mogull, founder of Securosis, a security consulting firm. "You can do it, but it's pretty hard and has a high impact on the user experience. Thus we see organizations focusing on [Group Policy Objects] and third-party security tools, since dropping to regular user permissions is so disruptive."

In an 2008 interview, Bill Jensen, a product marketing manager at Check Point, said complexity is the chief reason why least-privilege technology hasn't taken off.

"Unfortunately, there are always bugs, even at the kernel level, that can potentially circumvent security privileges," Jensen said. "Least-privilege means defining an individualized security policy for every single person or application. This is, well, nigh impossible."

For this reason, Check Point advocates the use of "default deny" technology that is implemented, not surprisingly, in the firewall. But McCarley says default deny is too restrictive, and doesn't solve the admin rights problem. This argument -- which basicially boils down to whether access rights should be defined in the network or at the endpoint -- adds another level of complexity to the discussion, and makes IT people even more reluctant to implement least-privilege technology.

Many enterprises are solving the problem by leaving administrative rights in their Windows machines, but severely restricting users' ability to access them, Mogull says. But with the rollout of Windows 7, Microsoft will make UAC and standard configurations part of the OS, and that will make the least-privilege concept much easier to deploy, he notes. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
7 SMB Security Tips That Will Keep Your Company Safe
Steve Zurier, Contributing Writer,  10/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: The old using of sock puppets for Shoulder Surfing technique. 
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8071
PUBLISHED: 2019-10-17
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
CVE-2019-10752
PUBLISHED: 2019-10-17
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
CVE-2019-12611
PUBLISHED: 2019-10-17
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupn...
CVE-2019-13657
PUBLISHED: 2019-10-17
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.
CVE-2019-15626
PUBLISHED: 2019-10-17
The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.