Secure NT Domain Access
Secure NT Domain Access
With Authentication Manager® and SecurID®For Product Inquiries call 1-800-495-1095
For Product Purchases call (949) 509-6560
Download this document in Adobe Acrobat format for archiving and printing. Security Dynamics Secure NT Domain Access solution combines the industry's leading strong, two-factor user authentication and encryption technologies to protect the vital assets and resources stored in NT domains within the corporate network. Built on the award-winning Authentication Manager and SecurID network security system, Security Dynamics' Secure NT Domain Access protects against popular security threats to local area networks -- such as unauthorized user access, user masquerading and data tampering -- as well as a myriad of increasingly popular NT attacks.
Highlights:
Significantly enhances native Windows NT security features
Adds strong user authentication
Protects sensitive departmental resources
Secures vital NT network administrator accounts
Leverages public key technologies to manage user credentials
Easy to use, deploy and administer
Supports Windows NT and Windows 95 environments
Plugs into any existing NT domain structure
In recent years, significant advances in communication technologies have enabled organizations to make their corporate networks accessible to business partners, customers and consultants. Subsequently, this trend has forced organizations to evolve their corporate security strategies to protect their vital and often sensitive corporate data and resources residing on local area networks.Securing only the perimeter of the network is no longer enough to protect against unauthorized user access and malicious network attacks. As organizations become more aware of security breaches, they are finding that most attacks are coming from inside the firewall--from people such as temporary employees, disgruntled employees, unauthorized users, hackers and others with malicious intent.
![]()
A 1998 CSI/FBI study of more than 520 security practitioners in U.S. corporations, government agencies, financial institutions and universities, concluded that the largest segment of organizations -- a staggering 44% of the respondents -- reported unauthorized access by employees as their number one security threat. The study further concluded that among all the various types of security breaches, such as denial of service attacks, outside penetration and theft of proprietary information, the most serious financial losses resulted from unauthorized access by insiders, with 18 respondents reporting more than $50 million in losses.
The leader in authentication management, encryption and access control, Security Dynamics has a proven track record in providing organizations with effective solutions to protect their networks from unauthorized access, regardless of whether it originates inside or outside the organization. Designed especially for Windows NT networks, Security Dynamics' Secure NT Domain Access solution enables organizations to protect their most valuable resources and information stored inside the network perimeter -- including file and print services and applications such as Microsoft Exchange and other Microsoft BackOffice applications. The Secure NT Domain Access solution is a natural extension of existing security technologies and policies, including firewalls and remote access security solutions. Although these traditional security measures protect the network from unauthorized access from outside the network, they do not protect network resources from internal attacks.
Security Dynamics' Secure NT Domain Access solution significantly enhances native NT security features by integrating strong, two-factor user authentication, thus requiring users to positively identify themselves as authorized users prior to accessing sensitive corporate resources within a particular NT domain.
Strong, two-factor user authentication
Strong, two-factor user authentication is the cornerstone of any IT security program. Without the ability to strongly authenticate the user, a product's security features are insufficient. Native NT security features allow you to protect access to resources and sensitive administrator accounts by using user names and static passwords. However, static passwords can be easily guessed or "cracked," making them easy targets for unauthorized users. As a result, organizations that rely solely on passwords for user authentication cannot be certain that the user accessing the sensitive information is in fact authorized to do so. Security Dynamics' SecurID authentication technology eliminates this security threat by enforcing native NT access controls.SecurID authenticators come in many different form factors, including hand-held hardware tokens and key fobs, and software tokens. The strength of the SecurID solution is rooted in Security Dynamics' patented algorithm that generates a one-time, pseudo-random passcode that changes every 60 seconds. The same algorithm is incorporated in the Authentication Manager network security software. When the user enters the current one-time code as indicated by SecurID, along with a unique personal identification number (PIN), the Authentication Manager validates the passcode and permits the user access. By combining these two factors -- the one-time passcode and secret PIN -- organizations can be certain that only authorized employees, business partners, and consultants are gaining access to company confidential information.
Seamless integration with Windows NT
Security Dynamics' Secure NT Domain Access solution is tightly integrated with native Windows NT security and management features. As a result, the solution is designed to plug directly into an organization's existing NT domain structure so that domain reconfiguration is not necessary. In addition, network administrators can manage this powerful security solution from the same NT control panel environment to which they are accustomed. This solution also records log information in the native NT log files so network administrators can view and audit authentication activity in the familiar NT log files.Easy for end-users
This solution is remarkably intuitive and easy to use for end-users. In addition to the typical NT logon process, Security Dynamics introduces one simple but extremely important step that requires each user to prove their identity.The user presses CTRL + ALT + DEL to begin the typical NT domain logon process. As a result, the user is prompted to enter his or her user name, static NT password and the name of the NT Domain being accessed. The only change to this familiar process is that once the user enters this information he or she is immediately prompted by a second screen that requires the user to enter a unique, one-time passcode generated by the user's SecurID authenticator. This process proves the user really is who he or she claims to be at the time of logon, and not someone who has cracked, guessed or stolen the individual's static password. If the user is unable to provide a valid SecurID passcode he or she is denied access.
As an added benefit, once a user has strongly authenticated themselves to a particular domain he or she can access all relevant documents, resources and applications that the user has authorized access to without having to re-authenticate. However, network administrators do have the option to determine how long a SecurID authenticated session will last. This allows the organization to deploy this solution according to its particular security requirements.
Leverage X.509 digital certificates and SSL encryption
Security Dynamics' Secure NT Domain Access solution combines strong-user authentication with public key technologies that include X.509 digital certificates and SSL encryption. Digital certificates and SSL encryption work in harmony with SecurID authenticators to perform several critical functions that make this solution possible. SecurID authenticators provide the strong two-factor user authentication, while digital certificates and SSL are used to securely exchange and manage the SecurID authenticated traffic.The end result is that users need only to authenticate once per session in order to access all relevant documents, resources and applications.
Protect sensitive administrator accounts with strong-user authentication
The administrator or "super user" accounts in the Windows NT environment are designed to provide the network administrator with unrestricted access to all resources, applications and log files across the network. In simple terms, these accounts provide the proverbial "keys to the kingdom," letting administrators perform tasks such as starting and stopping applications or accessing log files. If used with good intentions, these capabilities offer a number benefits. When used improperly or with malicious intentions, this level of unrestricted access can be extremely dangerous. A hacker could use these accounts to disable intrusion detection software or easily erase his footprints in log files.Given these privileges, it comes as no surprise that administrator accounts are the primary targets of many NT attacks. Unfortunately, most organization still rely on static passwords to protect these accounts, leaving them susceptible to brute password attacks, network sniffing or stolen passwords. Security Dynamics' solution protects against these attacks using strong, two-factor user authentication. As a result, even if a hacker were to obtain an administrator's user name and static password, he would be denied access to the NT network and resources because the hacker would not be able to supply the one-time passcode generated by the administrator's SecurID authenticator.
Easy to deploy and administer
Solution components
Security Dynamics' Secure NT Domain Access solution consists of the following components:
Platforms requirements
- Authentication Manager network security software
- Authentication Agent v 4.2 for Windows NT (includes client software and certificate utility)
- SecurID authenticators -- all form factors
Server: Windows NT 4.0 (with service pack 3)
Desktop: Windows 95 (retail and OSR2)
Windows NT 3.5.1 (with service pack 5)
Windows NT 4.0 (with service pack 3)
Security Dynamics' Secure NT Domain Access solution is designed to be easy to deploy and administer. It supports phased deployments to offer organizations the flexibility to first lock down their most security-sensitive departments (e.g. finance, legal, human resources, R&D) or accounts (e.g. administrators and back-up administrators), and then deploy the solution more broadly over time to other departments and across the entire enterprise. Administration is made simple because of the tight integration with the native NT management environment and features that make it easy to deploy and install client software, such as self-extracting files and the ability to leverage software distribution packages, such as Microsoft's SMS product.SecurID enforces user accountability
Security Dynamics' solution requires that each individual must be in possession of a SecurID authenticator in order to gain access to NT domain resources or applications such as Microsoft Exchange and other BackOffice applications. No two users can use the same passcode that is generated from each SecurID authenticator. The end result is that users can now be held accountable for the activities they perform.Benefit from proven security experience with Authentication Manager
Because Security Dynamics' Secure NT Domain Access solution is based on award-winning Authentication Manager software, it takes advantage of years of security experience in more than 9,000 customer environments. It also leverages a scalable and reliable architecture that protects 80% of the Global 100 organizations and more than 65% of the Fortune 500.SecurID authenticators offer portability for users
SecurID offers an easy-to-use, portable credential allowing only authorized users to access your critical business applications and resources within your NT domains. SecurID authenticators allow users to logon in various places as they move around the office, the campus or the globe.Leverage your investment
In addition to securing NT domain resources, the Authentication Manager and SecurID system manages authentication in other vital network environments, including remote access, VPNs and Web applica- tions. A single investment in Authentication Manager and SecurID can deliver multiple security solutions that allow you to maximize your return.Security Dynamics, Authentication Manager and SecurID are trademarks of RSA Security, Inc. All other trademarks are the property of their respective owners. ©2003 RSA Security, Inc. All rights reserved.
| ESC Home Page |
© 2006 Enterprise Systems Consulting, Inc. all rights reserved. Copyright & Legal Disclaimer