IS Decisions are proud to introduce one of our leading products, UserLock, to the EduGeek community.
UserLock is a versatile suite that provides educational organizations with a protective layer at the forefront of their Windows Active Directory network to help secure access for students, teachers and faculty.
If you’re responsible for IT security at a school, college or university, we don’t envy you. Educational organizations represent a repository of so many valuable data types (personal information, payment information, health records, cutting-edge research data, etc.) which makes them a leading target for attacks.
In your challenging IT administration and support roles, not only do you need to keep out the external threats to your network; you also need to ensure that you protect against users sometimes poor understanding of IT security. Often, attempts to encourage users to change their behaviour is challenging, despite tireless efforts on promoting security awareness in your schools and workplaces.
What’s more, the traditional culture of education promotes the free exchange of ideas, whilst the instant access to information benefits the academic aims and goals of any educational institution.
IT teams need to find appropriate ways to balance academic openness whilst securing the appropriate access users should have.
Striking this balance between an open, yet secure network remains a challenge. IT professionals need help to identify when any kind of threat actor (external or insider) attempts to strike and do so in a way that does not inhibit the day-to-day activities of faculty, staff, and students.
Spotting the attacker in education
Spotting an attacker is difficult, they often use compromised user credentials to access any and all data available to that account which means that the attacker is simply accessing whatever data the user already has permission to.
In these situations, how are you supposed to spot inappropriate access when it's already been defined as authorised?
Individuals working against your institutions typically fall into one of three categories:
- Malicious Users – These are already authorised users that have shifted their loyalty from the education institution to themselves and are engaged in some kind of inappropriate activity (such as undermining network security, data theft, etc.) that benefits themselves over the organization
- Compromised Users – These are the unwitting participants in phishing and social engineering scams. They take the bait and help to infect endpoints with malware that may be the attack (as in the case of ransomware) or simply provide a backdoor for further actions by online criminal groups
- External Attacker – Today, this is more likely to be a member of an organized group than a lone attacker. These attacks leverage hacking, social, malware, and other techniques to create a way into your network. Once inside, they work to take on one or more sets of elevated credentials to provide them with greater access and an ability to move about the network in an attempt to locate valuable data
In most cases, the only way to really tell if an account has been exploited, is a malicious insider or an outside attacker, is by allowing them to perform actions (such as launching applications, authenticating to systems, accessing data, etc.) and determine whether their actions are inappropriate.
Given that the majority of your userbase does not act the same way in the next class – let alone the next week or month – it makes more sense to spot the malicious account by looking at leading indicators of threat activity, rather than waiting for the effects of said activity.
One of the most accurate indicators is one that no malicious insider or external threat actor can get around – the logon.
Stopping threats at the logon
The simplest and most common action beginning almost every attack is the logon. Nearly all attacks require a logon using recognised internal credentials. Network resource access (file shares, email, VLE etc.), external access via VPN, remote desktop access, and more all share the common requirement of a logon.
Logon management makes the logon itself a scrutinized and protected event. The ability to successfully logon (and remain logged on) becomes more than just whether the right credentials are used.
A logon management solution will detect suspicious access attempts based on customized and granular logon policies that are set for that particular account. It will act accordingly - either denying or approving the logon - and alert IT (or the appropriate user themselves) if stipulated.
No logon, no threat
Some of the potential scenarios that are can now be prevented include:
- Genuine but compromised logins from exploited users are now useless to malicious insiders or would-be attackers
- Careless user behaviour such as password sharing, shared workstations left unlocked or logging into multiple computers simultaneously can now be prevented
- Access to any data/resource is now always identifiable and attributed to an individual user. This accountability discourages an insider from acting maliciously and makes all users more careful with their actions
- Suspicious activity is flagged and allows IT departments the chance to react instantly.
- Users can be notified with tailor-made message and alerts – including alerts on their own trusted access. Informed employees are another line of defence in the security of your networks
Whilst no technology can completely eliminate the chance of an attack, there is a way to drastically reduce the potential risks. Logon management offers greater control for admins to restrict various careless user behaviours, as well as encouraging good practice is adopted through alerts and notifications delivered to the end user.
On a Windows Active Directory network this is achieved with the logon security solution UserLock.



Recommended Comments
There are no comments to display.