1、Fortifying AuthenticationFortifying AuthenticationJulien RichardDirector Infosec-LastwallCISSP|OSCP|CRTP|CRISC|CISA|CSSLP|CCSP|Pentest+|CEH|GCP-CDLWhat the heck is Phishing Resistant MFA?KEY TAKEAWAY:Understand the benefits of transitioning to phishing-resistant MFA solutions.#whoami#whoamiOver 25 y
2、ears experience in the IT fieldBackground in Penetration TestingDirector of Infosec at LastwallWorked in many highly regulated industriesFounder of Atlantic Cybersecurity CollectiveAdvisory Board Member at Canadian Cybersecurity NetworkPolicy Village at BSides OttawaTo sum it up:Im passionate about
3、supporting the information security communitys diverse needs,from mentoring newcomers to collaborating with experienced professionals.Julien RichardCISSP|OSCP|CRTP|CRISC|CISA|CSSLP|CCSP|Pentest+|CEH|GCP-CDL01ChallengesA look at challenges in traditional MFAPhishing Resistant MFAHow do they help?MFA
4、PrimerBrief overview of MFA.0203Case StudiesInsights from real world scenarios04TakeawaysLets review05Multi-Factor Authentication Primer01AUTHENTICATIONAUTHENTICATIONConfirms a users or entitys identity within a system.(password)AUTHORIZATIONControls the access and permissions of users or entities.(
5、shared file)IDENTIFICATIONDistinguishes an entity or user in a system.(username)WHAT IS A FACTOR?Something you know.Something you have.Something you are.IMPORTANT:A password with security questions isnt MFA.CHALLENGES02CHALLENGES OF EACH FACTORSticky NotesBreachesSocial Engineering/PhishingBrute For
6、ce AttacksKeyloggingShoulder SurfingAttacker-in-the-MiddleDevice TheftSIM SwappingSocial Engineering/PhishingMalwareCloningAttacker-in-the-MiddleSOMETHING YOU KNOWSOMETHING YOU HAVESpoofingBreachesReplay AttacksSocial Engineering/PhishingQuality AttacksDeepfakesAttacker-in-the-MiddleSOMETHING YOU AR