IAM Flashcards
Clipping level
Prevent administrative overhead
Allow extra failed login
Prevent password guessing by locking the user from a certain timeframe or admin unlock
3 types of authentification ?
Type 1 : something’s you know
Type 2: something you have
Type 3: something you are
Token HOTP
HMAC based one time password
Generate code when asked valid until used
Token TOTP
Time based one time password
Synchronized
FRR (false rejection rate)
Type 1 error
Authorized users are rejected
FAR (false accept rate)
Type 2 error
Unauthorized user is granted access
CER (crossover error rate)
The meeting point between frr and far, this is where we want to be
ABAC
Attribute based access control
Access granted based on subject objects AND conditions
Also named as pbac or cbac
Who, what, where are you connected from, what time is it ?
RUBAC
Rule access based
Rule as acl and firewall