International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1717205

1717205 Vol 2 · Issue 6 Download Paper

Lessons Learned from Offline Assessment of Security-Critical Systems: The Case of Microsoft Active Directory

Olasunkanmi Oluwasanjo Ladapo Adetomiwa A. Dosunmu Demilade Jooda Toyosi O Abolaji

Subject area: Science,Engineering and Technology  ·  Area of research: Security-Critical Systems

DOI: 10.64388/IREV2I6-1717205

Abstract

Security evaluation of enterprise-level identity and access management infrastructure has emerged as a central imperative within contemporary information security governance and practice. Centralised directory services occupy a foundational position in enterprise computing environments, governing authentication, authorisation, and privilege assignment across complex networked architectures. As such, they represent high-value targets for both external adversaries and malicious insider actors whose exploitation of these systems can yield catastrophic consequences for organisational confidentiality, integrity, and availability. This study presents a comprehensive scholarly review of non-intrusive evaluation methodologies applied to such identity management platforms, integrating conceptual frameworks, practitioner literature, and documented field experiences to derive generalisable lessons applicable across diverse organisational and jurisdictional contexts. The investigation critically examines the theoretical foundations of non-intrusive evaluation within identity management paradigms, analyses architectural vulnerability characteristics inherent to enterprise directory environments, and evaluates the methodological and tooling dimensions encountered in structured security audits. Empirical observations are drawn from assessment experiences spanning multiple operational settings, including developing-economy contexts in Africa and elsewhere, where security governance maturity may diverge substantially from global benchmarks. A structured threat modelling perspective contextualises identified vulnerabilities within the contemporary adversarial landscape, whilst targeted remediation and hardening strategies are articulated in alignment with internationally recognised security principles and established control frameworks. Policy and governance implications arising from assessment outcomes are examined through the lens of authoritative standards frameworks and evolving regulatory expectations. Future scholarly directions are proposed with attention to automated analysis capabilities, cross-domain standardisation, and governance alignment in resource-constrained organisational environments. Through rigorous synthesis and critical analysis, this study contributes substantially to academic and professional discourse on enterprise security evaluation, offering actionable insights for practitioners and policymakers responsible for the protection of critical identity infrastructure.

Keywords

Identity And Access Management; Offline Security Assessment; Privilege Escalation; Directory Service Vulnerabilities; Threat Modelling; Security Governance

References

[1] Adewole, A.P., Anuar, N.B., Kamsin, A., Varathan, K.D. and Ismail, S.A. (2017) 'Malicious accounts: Dark of the social networks', Journal of Network and Computer Applications, 79, pp. 41–67. https://doi.org/10.1016/j.jnca.2016.11.030

[2] Al Shebli, H.M.Z. and Beheshti, B.D. (2018). A study on the penetration testing process and tools. In 2018, IEEE Long Island Systems, Applications and Technology Conference (LISAT) (pp. 1-7). IEEE.DOI: 10.1109/LISAT.2018.8378035

[3] Almohri, H.M., Watson, L.T., Yao, D., and Ou, X. (2015). Security optimization of dynamic networks with probabilistic graph modeling and linear programming. IEEE Transactions on Dependable and Secure Computing, 13(4), pp.474-487.https://doi.org/10.1109/TDSC.2015.2411264

[4] Anderson, R. (2010). Security engineering: a guide to building dependable distributed systems. John Wiley & Sons.

[5] Andress, J. (2014). The basics of information security: understanding the fundamentals of InfoSec in theory and practice. Syngress.

[6] Asnar, Y. and Massacci, F., (2011). A method for security governance, risk, and compliance (GRC): A goal-process approach. In International School on Foundations of Security Analysis and Design (pp. 152-184). Berlin, Heidelberg: Springer Berlin Heidelberg.https://doi.org/10.1007/978-3-642-23082-0_6

[7] Bertino, E. and Sandhu, R. (2005). Database security concepts, approaches, and challenges. IEEE Transactions on Dependable and Secure Computing, 2(1), pp.2-19.https://doi.org/10.1109/TDSC.2005.9

[8] Blobel, B., Nordberg, R., Davis, J.M., and Pharow, P. (2006). Modelling privilege management and access control. International Journal of Medical Informatics, 75(8), pp.597-623.https://doi.org/10.1016/j.ijmedinf.2005.08.010

[9] Charness, N. and Tuffiash, M. (2008). The role of expertise, research, and human factors in capturing, explaining, and producing superior performance. Human factors, 50(3), pp.427-432.https://doi.org/10.1518/001872008X312206

[10] Chenoweth, J.D. (2005). Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management.https://doi.org/10.1080/15536548.2005.10855762

[11] Crossler, R.E., Johnston, A.C., Lowry, P.B., Hu, Q., Warkentin, M., and Baskerville, R. (2013). Future directions for behavioral information security research. Computers&Security, 32, pp.90-101.https://doi.org/10.1016/j.cose.2012.09.010

[12] Desmond, B., Richards, J., Allen, R. and Lowe-Norris, A.G., (2008). Active Directory: Designing, Deploying, and Running Active Directory. " O'Reilly Media, Inc."

[13] Engebretson, P., (2013). The basics of hacking and penetration testing: ethical hacking and penetration testing made easy. Elsevier.

[14] Farahmand, F., Navathe, S.B., Sharp, G.P., and Enslow, P.H. (2005). A management perspective on risk of security threats to information systems. Information Technology and Management, 6(2), pp.203-225.https://doi.org/10.1007/s10799-005-5880-5

[15] Garman, J. (2003). Kerberos: The Definitive Guide: The Definitive Guide. " O'Reilly Media, Inc."

[16] Ghafran, C. and O'Sullivan, N. (2013). The governance role of audit committees: reviewing a decade of evidence. International Journal of Management Reviews, 15(4), pp.381-407.https://doi.org/10.1111/j.1468-2370.2012.00347.x

[17] Hassell, J. (2006). Learning Windows Server 2003. " O'Reilly Media, Inc."

[18] Hellström, T. (2007). Critical infrastructure and systemic vulnerability: Towards a planning framework. Safety science, 45(3), pp.415-430.https://doi.org/10.1016/j.ssci.2006.07.007

[19] Kaminsky, M. (2004). User Authentication and Remote Execution Across Administrative Domains (Doctoral dissertation, Massachusetts Institute of Technology).http://hdl.handle.net/1721.1/28722

[20] Kendrick, T., Chatwin, J., Dowrick, C., Tylee, A., Morriss, R., Peveler, R., Leese, M., McCrone, P., Harris, T., Moore, M., and Byng, R. (2009). Randomised controlled trial to determine the clinical and cost-effectiveness of selective serotonin reuptake inhibitors plus supportive care, versus supportive care alone, for mild to moderate depression with somatic symptoms in primary care. The THREAD (Threshold for AntiDepressant response) study. Health Technology Assessment, 13(22), pp.1-182.

[21] Kennedy, D., O'Gorman, J., Kearns, D., and Aharoni, M. (2011). Metasploit: the penetration tester's guide. No Starch Press.

[22] Kirwan, R. and Mullins, S. (2015). Specialist markets in the early modern book world (Vol. 40). Brill.

[23] Mat Isa, A. (2009). Records management and the accountability of governance (Doctoral dissertation, University of Glasgow).https://eleanor.lib.gla.ac.uk/record=b2702907

[24] Mavrogiannopoulos, N. (2013). Secure communications protocols and the protection of cryptographic keys (Doctoral dissertation, Dissertation presented in partial fulfillment of the requirements for the degree of Doctor in Engineering, Royal Holloway, University of London).

[25] Minasi, M., Gibson, D., Finn, A., Henry, W., and Hynes, B. (2010). Mastering Microsoft Windows Server 2008 R2. John Wiley & Sons.

[26] Mohammed, I.A. (2017). Systematic review of identity access management in information security. International Journal of Innovations in Engineering Research and Technology, 4(7), pp.1-7.

[27] Nichols, J.A., Taylor, B.A., and Curtis, L. (2016), April. Security resilience: Exploring Windows domain-level defenses against post-exploitation authentication attacks. In Proceedings of the 11th Annual Cyber and Information Security Research Conference (pp. 1-4).https://doi.org/10.1145/2897795.2897800

[28] Niemimaa, E. and Niemimaa, M. (2017). Information systems security policy implementation in practice: from best practices to situated practices. European journal of information systems, 26(1), pp.1-20.https://doi.org/10.1057/s41303-016-0025-y

[29] NIST (2007) Guide to Intrusion Detection and Prevention Systems (IDPS), Special Publication 800-94. Gaithersburg: National Institute of Standards and Technology. DOI: https://doi.org/10.6028/NIST.SP.800-94

[30] NIST (2008) Technical Guide to Information Security Testing and Assessment, Special Publication 800-115. Gaithersburg: National Institute of Standards and Technology. DOI: https://doi.org/10.6028/NIST.SP.800-115

[31] NIST (2011) Guide for Conducting Risk Assessments, Special Publication 800-30 Rev 1. Gaithersburg: National Institute of Standards and Technology. DOI: https://doi.org/10.6028/NIST.SP.800-30r1

[32] NIST (2013b) Guide to Attribute-Based Access Control (ABAC) Definition and Considerations, Special Publication 800-162. Gaithersburg: National Institute of Standards and Technology. DOI: https://doi.org/10.6028/NIST.SP.800-162

[33] Nist, J.T.F.T.I., (2013). Security and privacy controls for federal information systems and organizations. NIST Special Publication, pp.800-53.https://doi.org/10.6028/NIST.SP.800-53r4

[34] Nordlander, P. (2010). Architectures and standards for hardening of an integrated security system.

[35] Nozaki, M.K. and Tipton, H.F. eds. (2016). Information Security Management Handbook, Volume 5 (Vol. 5). CRC Press.

[36] Olayemi, O.J. (2014). A socio-technological analysis of cybercrime and cybersecurity in Nigeria. International Journal of Sociology and Anthropology, 6(3), p.116.https://doi.org/10.5897/IJSA2013.0510

[37] Pfleeger, C.P. and Pfleeger, S.L. (2015).Security in Computing. 5th edn. Upper Saddle River: Prentice Hall.

[38] Rebollo, O., Mellado, D., Fernández-Medina, E. and Mouratidis, H. (2015). Empirical evaluation of a cloud computing information security governance framework. Information and Software Technology, 58, pp.44-57.https://doi.org/10.1016/j.infsof.2014.10.003

[39] Sandhu, R.S. and Samarati, P., (2002). Access control: principle and practice. IEEE Communications Magazine, 32(9), pp.40-48. https://doi.org/10.1109/35.312842

[40] Settu, R. and Raj, P., (2013). Cloud application modernization and migration methodology. In Cloud Computing: Methods and Practical Approaches (pp. 243-271). London: Springer London.https://doi.org/10.1007/978-1-4471-5107-4_12

[41] Shinder, D.L. and Cross, M. (2008). Scene of the Cybercrime. Elsevier.

[42] Shostack, A. (2014). Threat modeling: Designing for security. John wiley& sons.

[43] Stallings, W. (2017). Format-preserving encryption: Overview and NIST specification. Cryptologia, 41(2), pp.137-152.https://doi.org/10.1080/01611194.2016.1169457

[44] Stumpf, S.A., Doh, J.P., and Clark, K.D. (2002). Professional services firms in transition: challenges and opportunities for improving performance. Organizational Dynamics, 31(3), pp.259-279.

[45] Vacca, J.R. ed., 2012. Computer and information security handbook. Newnes.

[46] Van Bossuyt, D.L. (2012). A risk-informed decision-making framework accounting for early-phase conceptual design of complex systems. Oregon State University.https://search.proquest.com/openview/8adf7df5485b0a26bc906f0326147a48/1?pq-origsite=gscholar&cbl=18750

[47] Vilarinho, T.C. (2009). Trusted secure service design. Skolan för informations- ochkommunikationsteknik, Kungliga Tekniskahögskolan.https://www.tvilarinho.com/publications/TrustedSecureServiceDesign.pdf

[48] Von Solms, R. and Van Niekerk, J. (2013). From information security to cyber security. Computers&Security, 38, pp.97-102.https://doi.org/10.1016/j.cose.2013.04.004

[49] Whitman, M.E. and Mattord, H.J., (2009). Principles of information security (p. 656). Boston, MA: Thomson Course Technology.

[50] Yu, P.K. (2012). Region codes and the territorial mess. Cardozo Arts & Ent. LJ, 30, p.187.

How to cite this paper

Olasunkanmi Oluwasanjo Ladapo, Adetomiwa A. Dosunmu, Demilade Jooda, Toyosi O Abolaji "Lessons Learned from Offline Assessment of Security-Critical Systems: The Case of Microsoft Active Directory" Iconic Research And Engineering Journals Volume 2 Issue 6 2018 Page 277-299 https://doi.org/10.64388/IREV2I6-1717205
Olasunkanmi Oluwasanjo Ladapo, Adetomiwa A. Dosunmu, Demilade Jooda, Toyosi O Abolaji "Lessons Learned from Offline Assessment of Security-Critical Systems: The Case of Microsoft Active Directory" Iconic Research And Engineering Journals, vol. 2, no. 6, Dec. 2018, doi: https://doi.org/10.64388/IREV2I6-1717205
Olasunkanmi Oluwasanjo Ladapo, Adetomiwa A. Dosunmu, Demilade Jooda, Toyosi O Abolaji (2018). Lessons Learned from Offline Assessment of Security-Critical Systems: The Case of Microsoft Active Directory. Iconic Research And Engineering Journals, 2(6). doi: https://doi.org/10.64388/IREV2I6-1717205
Olasunkanmi Oluwasanjo Ladapo, Adetomiwa A. Dosunmu, Demilade Jooda, Toyosi O Abolaji "Lessons Learned from Offline Assessment of Security-Critical Systems: The Case of Microsoft Active Directory" Iconic Research And Engineering Journals, vol. 2, no. 6, Dec. 2018. Crossref, https://doi.org/10.64388/IREV2I6-1717205
@article{1717205,
      author = {Olasunkanmi Oluwasanjo Ladapo, Adetomiwa A. Dosunmu, Demilade Jooda, Toyosi O Abolaji},
      title = {Lessons Learned from Offline Assessment of Security-Critical Systems: The Case of Microsoft Active Directory},
      journal = {Iconic Research And Engineering Journals},
      year = {2018},
      volume = {2},
      number = {6},
      pages = {277-299},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1717205.pdf},
      abstract = {Security evaluation of enterprise-level identity and access management infrastructure has emerged as a central imperative within contemporary information security governance and practice. Centralised directory services occupy a foundational position in enterprise computing environments, governing authentication, authorisation, and privilege assignment across complex networked architectures. As such, they represent high-value targets for both external adversaries and malicious insider actors whose exploitation of these systems can yield catastrophic consequences for organisational confidentiality, integrity, and availability. This study presents a comprehensive scholarly review of non-intrusive evaluation methodologies applied to such identity management platforms, integrating conceptual frameworks, practitioner literature, and documented field experiences to derive generalisable lessons applicable across diverse organisational and jurisdictional contexts. The investigation critically examines the theoretical foundations of non-intrusive evaluation within identity management paradigms, analyses architectural vulnerability characteristics inherent to enterprise directory environments, and evaluates the methodological and tooling dimensions encountered in structured security audits. Empirical observations are drawn from assessment experiences spanning multiple operational settings, including developing-economy contexts in Africa and elsewhere, where security governance maturity may diverge substantially from global benchmarks. A structured threat modelling perspective contextualises identified vulnerabilities within the contemporary adversarial landscape, whilst targeted remediation and hardening strategies are articulated in alignment with internationally recognised security principles and established control frameworks. Policy and governance implications arising from assessment outcomes are examined through the lens of authoritative standards frameworks and evolving regulatory expectations. Future scholarly directions are proposed with attention to automated analysis capabilities, cross-domain standardisation, and governance alignment in resource-constrained organisational environments. Through rigorous synthesis and critical analysis, this study contributes substantially to academic and professional discourse on enterprise security evaluation, offering actionable insights for practitioners and policymakers responsible for the protection of critical identity infrastructure.},
      keywords = {Identity And Access Management; Offline Security Assessment; Privilege Escalation; Directory Service Vulnerabilities; Threat Modelling; Security Governance},
      month = {December},
      doi = {https://doi.org/10.64388/IREV2I6-1717205}
  }