Kerberos Protocol: Security Attacks and Solution

Shatha Hameed Qatinah, Ibrahim Ahmed Al-Baltah · 2024

Kerberos protocol is one of the famous network authentication protocols that manages and facilitates user authentication processes across networks to gain safe access to resources. This protocol relies on the role of Active Directory in a Windows environment to authenticate users in a network. It generates tickets that work as identifiers and validity for users over a network. Attackers are always seeking to illegally obtain tickets to gain access to the network resources. However, this paper focuses on the most prominent attacks that this protocol is exposed to and explains them, along with the solutions proposed by several researchers to mitigate golden ticket attacks that take advantage of a vulnerability in the Kerberos authentication protocol. Therefore, this paper proposed an enhanced approach for mitigating this type of serious attack by adding an additional validation layer for users who have a golden ticket in the server of the service. After decrypting the service ticket, the resources server verifies that the ticket was issued by the Ticket Granting Service (TGS), a trusted authority, by examining the KRBTGT signature. If the ticket is deemed a golden ticket, the server of the service will signal the biometric validation layer to perform biometric verification on the user of this ticket. Verifies the client's identity again using biometric credentials that are kept in a secure database on the resources server. This biometric validation layer is adding a new role for the services server that will require using several additional tools to obtain a perfect biometric validation layer. That is ensuring just authorized access for golden tickets is the lofty target of hackers and the focus of many researchers to limit its attacks.

Read the paper · More papers on PaperTik