Add files using upload-large-folder tool
Browse filesThis view is limited to 50 files because it contains too many changes. See raw diff
- .gitattributes +37 -0
- 06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4 +3 -0
- 06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4 +3 -0
- 07 - Cryptography/001 Intro to cryptography OB 1.4.mp4 +3 -0
- 07 - Cryptography/002 Crypto Terms OB 1.4.mp4 +3 -0
- 07 - Cryptography/003 Goals Cryptography OB 1.4.mp4 +3 -0
- 07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4 +3 -0
- 07 - Cryptography/005 Ciphers OB 1.4.mp4 +3 -0
- 07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4 +3 -0
- 07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4 +3 -0
- 07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4 +3 -0
- 07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4 +3 -0
- 07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4 +3 -0
- 07 - Cryptography/011 Hashing OB 1.4.mp4 +3 -0
- 07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4 +3 -0
- 07 - Cryptography/013 Digital Signatures OB 1.4.mp4 +3 -0
- 07 - Cryptography/014 Intro to PKI OB 1.4.mp4 +3 -0
- 07 - Cryptography/015 PKI Purpose OB 1.4.mp4 +3 -0
- 07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4 +3 -0
- 07 - Cryptography/017 PKI Process OB 1.4.mp4 +3 -0
- 07 - Cryptography/018 Certificates OB 1.4.mp4 +3 -0
- 07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4 +3 -0
- 07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4 +3 -0
- 07 - Cryptography/021 Steganography OB 1.4.mp4 +3 -0
- 07 - Cryptography/022 Blockchain OB 1.4.mp4 +3 -0
- 07 - Cryptography/023 Salting OB 1.4.mp4 +3 -0
- 07 - Cryptography/024 TPM OB 1.4.mp4 +3 -0
- 07 - Cryptography/025 Secure Enclave OB 1.4.mp4 +3 -0
- 07 - Cryptography/026 Obfuscation OB 1.4.mp4 +3 -0
- 07 - Cryptography/027 Tokenization OB 1.4.mp4 +3 -0
- 07 - Cryptography/028 Key Escrow OB 1.4.mp4 +3 -0
- 07 - Cryptography/029 HSM OB 1.4.mp4 +3 -0
- 08 - Social Engineering/001 Social Engineering OB 2.2.mp4 +3 -0
- 08 - Social Engineering/002 Phishing OB 2.2.mp4 +3 -0
- 08 - Social Engineering/003 Vishing OB 2.2.mp4 +3 -0
- 08 - Social Engineering/004 Smishing OB 2.2.mp4 +3 -0
- 08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4 +3 -0
- 11 - Security Principles/010 IDSIPS OB 3.2_en.srt +912 -0
- 11 - Security Principles/011 Load Balancer OB 3.2_en.srt +380 -0
- 11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt +356 -0
- 11 - Security Principles/013 Firewalls OB 3.2_en.srt +520 -0
- 11 - Security Principles/014 VPN OB 3.2_en.srt +672 -0
- 11 - Security Principles/015 SD-WAN OB 3.2_en.srt +228 -0
- 11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt +400 -0
- 11 - Security Principles/017 Quick Quiz.html +479 -0
- 12 - Data Protection/001 Regulated Data OB 3.3_en.srt +148 -0
- 12 - Data Protection/002 Intellectual Property OB 3.3_en.srt +696 -0
- 12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt +276 -0
- 12 - Data Protection/004 Data Classification OB 3.3_en.srt +644 -0
.gitattributes
CHANGED
|
@@ -96,3 +96,40 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
|
|
| 96 |
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 97 |
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 98 |
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 96 |
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 97 |
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 98 |
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 99 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/016[[:space:]]Request[[:space:]]Forgery[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 100 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/017[[:space:]]Directory[[:space:]]Traversal[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 101 |
+
06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/018[[:space:]]Indicators[[:space:]]of[[:space:]]Malicious[[:space:]]Activity[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 102 |
+
07[[:space:]]-[[:space:]]Cryptography/002[[:space:]]Crypto[[:space:]]Terms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 103 |
+
07[[:space:]]-[[:space:]]Cryptography/001[[:space:]]Intro[[:space:]]to[[:space:]]cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 104 |
+
07[[:space:]]-[[:space:]]Cryptography/003[[:space:]]Goals[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 105 |
+
07[[:space:]]-[[:space:]]Cryptography/005[[:space:]]Ciphers[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 106 |
+
07[[:space:]]-[[:space:]]Cryptography/006[[:space:]]Symmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 107 |
+
07[[:space:]]-[[:space:]]Cryptography/007[[:space:]]Symmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 108 |
+
07[[:space:]]-[[:space:]]Cryptography/004[[:space:]]Algorithm[[:space:]]vs[[:space:]]Keys[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 109 |
+
07[[:space:]]-[[:space:]]Cryptography/009[[:space:]]Asymmetric[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 110 |
+
07[[:space:]]-[[:space:]]Cryptography/008[[:space:]]Asymmetric[[:space:]]Encryption[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 111 |
+
07[[:space:]]-[[:space:]]Cryptography/010[[:space:]]Hybrid[[:space:]]Cryptography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 112 |
+
07[[:space:]]-[[:space:]]Cryptography/012[[:space:]]Hashing[[:space:]]Algorithms[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 113 |
+
07[[:space:]]-[[:space:]]Cryptography/013[[:space:]]Digital[[:space:]]Signatures[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 114 |
+
07[[:space:]]-[[:space:]]Cryptography/014[[:space:]]Intro[[:space:]]to[[:space:]]PKI[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 115 |
+
07[[:space:]]-[[:space:]]Cryptography/011[[:space:]]Hashing[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 116 |
+
07[[:space:]]-[[:space:]]Cryptography/015[[:space:]]PKI[[:space:]]Purpose[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 117 |
+
07[[:space:]]-[[:space:]]Cryptography/016[[:space:]]SSLTLS[[:space:]]Handshake[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 118 |
+
07[[:space:]]-[[:space:]]Cryptography/017[[:space:]]PKI[[:space:]]Process[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 119 |
+
07[[:space:]]-[[:space:]]Cryptography/018[[:space:]]Certificates[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 120 |
+
07[[:space:]]-[[:space:]]Cryptography/019[[:space:]]PKI[[:space:]]Root[[:space:]]of[[:space:]]Trust[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 121 |
+
07[[:space:]]-[[:space:]]Cryptography/020[[:space:]]PKI[[:space:]]Verification[[:space:]]and[[:space:]]Revocation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 122 |
+
07[[:space:]]-[[:space:]]Cryptography/022[[:space:]]Blockchain[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 123 |
+
07[[:space:]]-[[:space:]]Cryptography/021[[:space:]]Steganography[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 124 |
+
07[[:space:]]-[[:space:]]Cryptography/023[[:space:]]Salting[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 125 |
+
07[[:space:]]-[[:space:]]Cryptography/024[[:space:]]TPM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 126 |
+
07[[:space:]]-[[:space:]]Cryptography/025[[:space:]]Secure[[:space:]]Enclave[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 127 |
+
07[[:space:]]-[[:space:]]Cryptography/026[[:space:]]Obfuscation[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 128 |
+
07[[:space:]]-[[:space:]]Cryptography/027[[:space:]]Tokenization[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 129 |
+
07[[:space:]]-[[:space:]]Cryptography/028[[:space:]]Key[[:space:]]Escrow[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 130 |
+
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/001[[:space:]]Social[[:space:]]Engineering[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 131 |
+
07[[:space:]]-[[:space:]]Cryptography/029[[:space:]]HSM[[:space:]]OB[[:space:]]1.4.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 132 |
+
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/004[[:space:]]Smishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 133 |
+
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/003[[:space:]]Vishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 134 |
+
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/002[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
|
| 135 |
+
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/006[[:space:]]Misinformation[[:space:]]and[[:space:]]Disinformation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
|
06 - Signs of Attacks/016 Request Forgery OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:7fb67cb33e669a0cd4db9d175ab0af64cf6e2f395928443fba926e046fc6628e
|
| 3 |
+
size 252434757
|
06 - Signs of Attacks/017 Directory Traversal OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:e1744255f84e98cd7a85e260f4fc4c456a930a8571773c1fd4b050aab4b2b0a7
|
| 3 |
+
size 55519440
|
06 - Signs of Attacks/018 Indicators of Malicious Activity OB 2.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:a06d972cbc8ff0a0f5b8a0649fdaa9420454c21fc6ca8bc85c96236a062be796
|
| 3 |
+
size 165107189
|
07 - Cryptography/001 Intro to cryptography OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:f410dce7cb4466cf86b270c58220847a1b2f51ea6d5c26c8cbdff507a7b0146d
|
| 3 |
+
size 96326919
|
07 - Cryptography/002 Crypto Terms OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:4cc3556f416a37507fb252d2fcb7a996064cef75b2e419837b7599182af66fa7
|
| 3 |
+
size 61060517
|
07 - Cryptography/003 Goals Cryptography OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:9d6ea104492a374d07c1016b6b3503ab89fc91d8adebba0c830495dd01b8c89f
|
| 3 |
+
size 158674618
|
07 - Cryptography/004 Algorithm vs Keys OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:bd0304e7831242c9f3d707d88bf9856f97d6277b74d575b9f8a96aaf40b98c15
|
| 3 |
+
size 904992896
|
07 - Cryptography/005 Ciphers OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:44c1f607cb008792070ba7bc251a782124aa6b4674fd3ad4923b099c04b6bee7
|
| 3 |
+
size 70642872
|
07 - Cryptography/006 Symmetric Encryption OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:906c0006508ac8feebd61b1a0a4236cb2a073add324119275f6653f3819e6ce3
|
| 3 |
+
size 301229092
|
07 - Cryptography/007 Symmetric Algorithms OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:6e3357e07a707570a5d682d8711ce37c3257871f01c1cd9f57259d102c765260
|
| 3 |
+
size 208197734
|
07 - Cryptography/008 Asymmetric Encryption OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:d30021a868903bbb6ab27a33c128faaa343205a4698dda444d1cff8cdc4899ec
|
| 3 |
+
size 262306688
|
07 - Cryptography/009 Asymmetric Algorithms OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:bc4dbc91ef6e892dab0aeef519323e3958ec5cf1ce1db38b429d073da21e96d2
|
| 3 |
+
size 99626564
|
07 - Cryptography/010 Hybrid Cryptography OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:b4c0b7ee7d7b0df27553d841c16df9d203d01d47527a33c0ddadd96219b95743
|
| 3 |
+
size 157908953
|
07 - Cryptography/011 Hashing OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:849824f981dde0483565115c45f8a19348912f37864040c2b47282373b86a777
|
| 3 |
+
size 628967987
|
07 - Cryptography/012 Hashing Algorithms OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:690cf391d2d7106d916db9e072c2fe74c170e259fc4bfa27a8008d18dec5e460
|
| 3 |
+
size 80731663
|
07 - Cryptography/013 Digital Signatures OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:7dd7fb58914ad32f6f6037638e36e90d4e8c5e4870af7330d6862ec5ebe11888
|
| 3 |
+
size 181001409
|
07 - Cryptography/014 Intro to PKI OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:4f8ac279e3d05da47bb0b7ead6b020e9b23a7ff9145d497f2c3680f7fbc8974d
|
| 3 |
+
size 46048784
|
07 - Cryptography/015 PKI Purpose OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:b6a8128beb36e602748800e10f620fac19457721cfec27ba8a1208a8e8ea12c7
|
| 3 |
+
size 133257759
|
07 - Cryptography/016 SSLTLS Handshake OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:62b288a9b3d91f94aa4c663902299a0b3ca0c5e205f4f4c20e900c47806db25c
|
| 3 |
+
size 322894899
|
07 - Cryptography/017 PKI Process OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:2df30749129881a7cdb3eab017a1014418a5a912554e22b8eb690cf4509aa84a
|
| 3 |
+
size 227238978
|
07 - Cryptography/018 Certificates OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:289b439dc3db3773da97e6e921bc16082cc4444a987c3656c4a1d5b857b828c0
|
| 3 |
+
size 256419507
|
07 - Cryptography/019 PKI Root of Trust OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:52767a81cd65b574262fbbd167b541891ab823e4ac5db0e29ed817cbda7e6dc4
|
| 3 |
+
size 81385638
|
07 - Cryptography/020 PKI Verification and Revocation OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:209b9a6ce812392bc253484a273d19429e764f0bcdcd28708ea3e58839128724
|
| 3 |
+
size 119243591
|
07 - Cryptography/021 Steganography OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:5d9c971a71471963a520a76520af39e504725a61525bc23c8f5d6709490ba1c8
|
| 3 |
+
size 123486561
|
07 - Cryptography/022 Blockchain OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:ed31645711f61269c6b6fa2247c7449246b79aaafce6519c607363918480a821
|
| 3 |
+
size 166936677
|
07 - Cryptography/023 Salting OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:292386772cd6a1688e30efb201a3988ca58d06e896327cfd71fdaae5ffac4877
|
| 3 |
+
size 106670783
|
07 - Cryptography/024 TPM OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:f74bc83f1e5177358d6e3e3e86d1f672f862d0020c9acbd846a82f86fcf17699
|
| 3 |
+
size 211209531
|
07 - Cryptography/025 Secure Enclave OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:ce54c6de590a73b2aef9782418559b1a6786fdce05d43f42062ebfc39a900367
|
| 3 |
+
size 48690063
|
07 - Cryptography/026 Obfuscation OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:7ba3668198ef774869f0fbe4319f1ea976482d18207dda79987d4378752c580c
|
| 3 |
+
size 73746741
|
07 - Cryptography/027 Tokenization OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:2277841e3deee35b12cc4fccfb98aff9375d8702e7f442aa74490a2d740ecefd
|
| 3 |
+
size 130278517
|
07 - Cryptography/028 Key Escrow OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:5c6271142b89e04576eed08ad160813cefe56719b9af87f786a9510fa7caadea
|
| 3 |
+
size 51540744
|
07 - Cryptography/029 HSM OB 1.4.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:99202e513878337137a489c03b2c879e67c59e0db229c0c1c1e1742a2252f81f
|
| 3 |
+
size 144313020
|
08 - Social Engineering/001 Social Engineering OB 2.2.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:1b587c47573275e81970968d5e20e90df0fd2e7d8f98c6ec6f7bf5dbb34e378c
|
| 3 |
+
size 66534314
|
08 - Social Engineering/002 Phishing OB 2.2.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:32a70e3ca9956d8b8f75af1d0b550e43d275be845e0c144849a5775c60845682
|
| 3 |
+
size 215560454
|
08 - Social Engineering/003 Vishing OB 2.2.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:dcf480e016947a06fea15c3193380cb7c1833950a49957f0e8f5fb76222acc85
|
| 3 |
+
size 165005146
|
08 - Social Engineering/004 Smishing OB 2.2.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:b55d80c0072c02bf3e4d2532d021c9d07fb581e5601030ab9ff18e69663d5649
|
| 3 |
+
size 57310806
|
08 - Social Engineering/006 Misinformation and Disinformation OB 2.2.mp4
ADDED
|
@@ -0,0 +1,3 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
version https://git-lfs.github.com/spec/v1
|
| 2 |
+
oid sha256:d4a538f128b09d0177e2f5a358dd49a0d2bd111550e618bb33ddd367785f342b
|
| 3 |
+
size 165923487
|
11 - Security Principles/010 IDSIPS OB 3.2_en.srt
ADDED
|
@@ -0,0 +1,912 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:06,000
|
| 3 |
+
One of the most common network, software and or device that you should have set up in your network
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:06,000 --> 00:00:14,000
|
| 7 |
+
today is an IDs, Intrusion Detection Systems, or IPS intrusion prevention systems, and the simple
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:14,000 --> 00:00:21,000
|
| 11 |
+
reason is that there is no way you can go around to every machine and check if an intrusion is coming
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:21,000 --> 00:00:23,000
|
| 15 |
+
from one of those machines.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:23,000 --> 00:00:27,000
|
| 19 |
+
And the other reason is because the best one is actually free.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:27,000 --> 00:00:32,000
|
| 23 |
+
You see, I want to talk in this, in this particular one, in this particular video, that's going
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:32,000 --> 00:00:33,000
|
| 27 |
+
to be pretty long.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:33,000 --> 00:00:35,000
|
| 31 |
+
By the way, a lot of slides is going to cover here.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:35,000 --> 00:00:41,000
|
| 35 |
+
In this particular video, we want to go through all the things we need to know about IDs and IPS for
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:41,000 --> 00:00:45,000
|
| 39 |
+
our exam and why you need to have one of these in your network if you don't.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:45,000 --> 00:00:48,000
|
| 43 |
+
By the way, the free one I'm talking about is snort.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:48,000 --> 00:00:50,000
|
| 47 |
+
Snort is is maintained by Cisco.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:50,000 --> 00:00:58,000
|
| 51 |
+
It is the best, in Andrew's opinion IDs out there and it is 100% free maintained by Cisco.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:58,000 --> 00:01:01,000
|
| 55 |
+
Let's get started with what exactly is it?
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:01,000 --> 00:01:03,000
|
| 59 |
+
I want to give you a scenario before I get started.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:05,000 --> 00:01:09,000
|
| 63 |
+
Imagine you have a network with 500 computers.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:09,000 --> 00:01:15,000
|
| 67 |
+
All of a sudden people starts calling the help desk and they say, oh, there's tons of network traffic.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:15,000 --> 00:01:16,000
|
| 71 |
+
The network is too slow.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:16,000 --> 00:01:18,000
|
| 75 |
+
No one can get to the internet.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:18,000 --> 00:01:20,000
|
| 79 |
+
File services are not loaded.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:20,000 --> 00:01:24,000
|
| 83 |
+
Well, there is some kind of thing going on in this network.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:24,000 --> 00:01:26,000
|
| 87 |
+
Somebody is using up all the traffic.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:26,000 --> 00:01:29,000
|
| 91 |
+
Maybe there's a worm spreading from machine to machine.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:29,000 --> 00:01:33,000
|
| 95 |
+
Maybe somebody has a virus that's downloading and utilizing all the bandwidth.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:34,000 --> 00:01:35,000
|
| 99 |
+
You got two choices.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:35,000 --> 00:01:44,000
|
| 103 |
+
You can decide to do nothing, or you can go to every single one of the machines and attempt to to to
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:44,000 --> 00:01:46,000
|
| 107 |
+
find which one of them is broken.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:46,000 --> 00:01:48,000
|
| 111 |
+
This is a nightmare scenario.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:48,000 --> 00:01:55,000
|
| 115 |
+
This is a scenario that I had faced at Tia many, many years ago because I was an idiot and didn't have
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:55,000 --> 00:01:55,000
|
| 119 |
+
one.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:56,000 --> 00:01:59,000
|
| 123 |
+
Now we do and we have them in every one of our locations.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:59,000 --> 00:02:01,000
|
| 127 |
+
We have IDs snorting in particular set up.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:01,000 --> 00:02:07,000
|
| 131 |
+
So if there is some kind of intrusion, especially like worm or viruses or malware on the student machines,
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:07,000 --> 00:02:09,000
|
| 135 |
+
we could say, okay, it's that machine and that lab, let's go fix it.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:10,000 --> 00:02:17,000
|
| 139 |
+
IDs are able to suck up the network traffic on your network, analyze the traffic and say, that computer
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:17,000 --> 00:02:19,000
|
| 143 |
+
over there, that one is bad.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:19,000 --> 00:02:25,000
|
| 147 |
+
That's why you need to have these particular things now when it comes to this.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:25,000 --> 00:02:32,000
|
| 151 |
+
It's basically a technology for real time monitoring and analysis of network activity and data for potential
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:32,000 --> 00:02:32,000
|
| 155 |
+
intrusions.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:33,000 --> 00:02:34,000
|
| 159 |
+
Now, what is it going to do?
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:34,000 --> 00:02:39,000
|
| 163 |
+
Well, it's going to monitor and analyze user and systems activities to see what's happening on it.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:39,000 --> 00:02:41,000
|
| 167 |
+
It's going to audit our systems and configuration.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:41,000 --> 00:02:43,000
|
| 171 |
+
If there's any vulnerabilities, it'll let you know.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:43,000 --> 00:02:48,000
|
| 175 |
+
It looks at the integrity of critical systems and any kind of data files.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:48,000 --> 00:02:51,000
|
| 179 |
+
It's going to recognize different patterns.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:51,000 --> 00:02:55,000
|
| 183 |
+
And maybe if there is any kind of abnormal activities out there.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:56,000 --> 00:03:02,000
|
| 187 |
+
Now in this video we want to talk, not just okay, this is what an IDs does, but I want to talk.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:03:02,000 --> 00:03:05,000
|
| 191 |
+
Exactly how does it is it a passive active.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:06,000 --> 00:03:07,000
|
| 195 |
+
Is it a behavioral based.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:07,000 --> 00:03:10,000
|
| 199 |
+
Is it a signature based IDs.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:10,000 --> 00:03:12,000
|
| 203 |
+
Um, is it an IDs or an IDs?
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:12,000 --> 00:03:14,000
|
| 207 |
+
These are all terms that you can need to know for your exam.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:14,000 --> 00:03:16,000
|
| 211 |
+
So let's knock them out okay.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:16,000 --> 00:03:23,000
|
| 215 |
+
The first thing I want to talk about is how does an IDs know that this traffic is good or this traffic
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:23,000 --> 00:03:24,000
|
| 219 |
+
is bad.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:24,000 --> 00:03:29,000
|
| 223 |
+
How does it is how is it able to differentiate good traffic versus bad traffic.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:29,000 --> 00:03:31,000
|
| 227 |
+
So this goes into its detection.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:31,000 --> 00:03:38,000
|
| 231 |
+
There's two ways the IDs is able to detect either it's a knowledge based system or it's a behavior or
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:38,000 --> 00:03:40,000
|
| 235 |
+
slash anomaly based systems.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:40,000 --> 00:03:44,000
|
| 239 |
+
So knowledge based systems are also known as signature based systems.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:44,000 --> 00:03:48,000
|
| 243 |
+
They have a signature for all known vulnerabilities.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:48,000 --> 00:03:54,000
|
| 247 |
+
This thing has a database of all the vulnerabilities that are out there, all of the different worms
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:54,000 --> 00:03:55,000
|
| 251 |
+
and attacks that are out there.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:55,000 --> 00:03:56,000
|
| 255 |
+
This is good.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:56,000 --> 00:03:59,000
|
| 259 |
+
I like these these types of systems.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:59,000 --> 00:04:04,000
|
| 263 |
+
They're you know, the main reason here is because it has a very low false alarm.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:04,000 --> 00:04:10,000
|
| 267 |
+
And what that means is this when this system tells you there is a virus, oh, there's probably a virus,
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:10,000 --> 00:04:11,000
|
| 271 |
+
there is an intrusion.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:11,000 --> 00:04:13,000
|
| 275 |
+
There is a worm going on in there.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:13,000 --> 00:04:17,000
|
| 279 |
+
Alarms are more standardized and more easily to understand because it's coming from a signature.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:17,000 --> 00:04:23,000
|
| 283 |
+
The same way you have to update your antivirus software with signatures the same way this particular
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:23,000 --> 00:04:24,000
|
| 287 |
+
thing works.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:24,000 --> 00:04:29,000
|
| 291 |
+
The disadvantage with this though, you have to continuously update the signatures.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:29,000 --> 00:04:35,000
|
| 295 |
+
Like if you have snort, you have to go and get the definitions, the updates on a consistent basis.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:36,000 --> 00:04:41,000
|
| 299 |
+
Um, and the other problem, if it's a signature based system, is you're waiting on the manufacturer
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:41,000 --> 00:04:48,000
|
| 303 |
+
of the device or the software to actually send you the signature for new, unique, or for all the new
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:48,000 --> 00:04:49,000
|
| 307 |
+
attacks that are coming out.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:49,000 --> 00:04:55,000
|
| 311 |
+
So if there's a new attack, a unique attack that the manufacturer doesn't know about yet, you're going
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:55,000 --> 00:04:59,000
|
| 315 |
+
to get killed with it because the devices just doesn't know about it.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:59,000 --> 00:05:04,000
|
| 319 |
+
Now, what you should do is then turn the device into what's called an anomaly based device, or also
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:05:04,000 --> 00:05:06,000
|
| 323 |
+
known as behavioral devices.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:05:06,000 --> 00:05:09,000
|
| 327 |
+
So behavioral based detection is this.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:05:09,000 --> 00:05:15,000
|
| 331 |
+
What it does is that it creates a baseline or learn the patterns of the normal activity within your
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:05:15,000 --> 00:05:16,000
|
| 335 |
+
network.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:16,000 --> 00:05:21,000
|
| 339 |
+
It then it builds this statistical pattern of traffic within your network.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:21,000 --> 00:05:25,000
|
| 343 |
+
Any deviations, any variations from that.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:25,000 --> 00:05:32,000
|
| 347 |
+
It's going to tell you the great thing, the reason why it does this, since it's adapting to the traffic,
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:32,000 --> 00:05:35,000
|
| 351 |
+
anything that's abnormal that people haven't done before, boom.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:35,000 --> 00:05:38,000
|
| 355 |
+
It tells you right away that there's something going on there.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:38,000 --> 00:05:44,000
|
| 359 |
+
You should check it out so it's able to tell you new or unique attacks that are out there.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:46,000 --> 00:05:49,000
|
| 363 |
+
It's less dependent on operating system vulnerability.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:49,000 --> 00:05:52,000
|
| 367 |
+
It's not going to find, you know, this is not going to affect it.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:52,000 --> 00:05:54,000
|
| 371 |
+
Now the disadvantage is there.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:54,000 --> 00:05:56,000
|
| 375 |
+
It's a higher false alarm.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:56,000 --> 00:05:58,000
|
| 379 |
+
This is going to suck.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:58,000 --> 00:06:03,000
|
| 383 |
+
Because if somebody decides to transfer a big file, the IDs is like, well, they've never done that
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:06:03,000 --> 00:06:07,000
|
| 387 |
+
before and sends out an alarm and you're probably going to go investigate it.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:06:07,000 --> 00:06:10,000
|
| 391 |
+
Uh, usage pattern often changes in network.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:06:10,000 --> 00:06:17,000
|
| 395 |
+
And because of this, if user if user behavior pattern changes lots of false alarms.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:06:17,000 --> 00:06:18,000
|
| 399 |
+
Now.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:06:18,000 --> 00:06:23,000
|
| 403 |
+
IEDs are generally going to be a passive device.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:06:23,000 --> 00:06:28,000
|
| 407 |
+
Passive means that they just sit back and write passive responses.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:06:28,000 --> 00:06:29,000
|
| 411 |
+
They just sit back.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:06:29,000 --> 00:06:34,000
|
| 415 |
+
They make a log of the event, and they just tell you they'll send you a notification, either through
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:06:34,000 --> 00:06:38,000
|
| 419 |
+
an email or a text message saying, hey, you know what?
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:06:39,000 --> 00:06:41,000
|
| 423 |
+
With that email, you know what?
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:06:41,000 --> 00:06:44,000
|
| 427 |
+
There is a there is a virus on that machine.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:06:44,000 --> 00:06:46,000
|
| 431 |
+
There's a worm on that particular machine.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:06:46,000 --> 00:06:51,000
|
| 435 |
+
So they're just basically telling you they're not going to do anything about the attack.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:51,000 --> 00:06:54,000
|
| 439 |
+
They're just going to they're just going to inform you that it's there.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:55,000 --> 00:06:59,000
|
| 443 |
+
Now, an active response is when it changes the environment to block it.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:59,000 --> 00:07:05,000
|
| 447 |
+
Modifying ACLs, blocking ports, blocking traffic, blocking certain network address, disable communications
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:07:05,000 --> 00:07:06,000
|
| 451 |
+
on network segments.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:07:06,000 --> 00:07:11,000
|
| 455 |
+
This is more of going to be of an IPS, not just an IDs, which we'll come to in a little while.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:07:13,000 --> 00:07:18,000
|
| 459 |
+
Now, when it comes to IDs, there's really two main ways you're going to have them.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:07:18,000 --> 00:07:19,000
|
| 463 |
+
Ideally, you're going to have both.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:07:19,000 --> 00:07:24,000
|
| 467 |
+
You're going to have what's called a whole space IDs, and you're going to have a network based IDs.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:07:25,000 --> 00:07:30,000
|
| 471 |
+
Now, a host based IDs is something that you're going to install on your computer, on your desktop,
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:07:30,000 --> 00:07:33,000
|
| 475 |
+
just like you would on anti-malware.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:07:33,000 --> 00:07:39,000
|
| 479 |
+
Now, if you have endpoint security software like Symantec's or Broadcom endpoint, McAfee endpoint
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:07:39,000 --> 00:07:45,000
|
| 483 |
+
endpoint security software generally will come with a host based IDs on it.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:07:46,000 --> 00:07:50,000
|
| 487 |
+
Well, this is going to do is going to just monitor the host machine.
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:07:50,000 --> 00:07:55,000
|
| 491 |
+
Maybe you go to a particular website, maybe you were downloading something, maybe an email brought
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:07:55,000 --> 00:07:57,000
|
| 495 |
+
in a particular malware.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:07:58,000 --> 00:08:02,000
|
| 499 |
+
The host base IDs is going to be able to detect that.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:08:02,000 --> 00:08:06,000
|
| 503 |
+
Now this is going to respond by logging the activity and notifying you.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:08:06,000 --> 00:08:12,000
|
| 507 |
+
But it's probably going to notify a central console that, for example, the help desk, that something
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:08:12,000 --> 00:08:13,000
|
| 511 |
+
needs to be done here.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:08:13,000 --> 00:08:17,000
|
| 515 |
+
Now the advantages there is that it can detect anomalies on the whole systems.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:08:17,000 --> 00:08:20,000
|
| 519 |
+
Uh, that that the network IDs can.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:08:20,000 --> 00:08:24,000
|
| 523 |
+
So if there's something going on in this machine that doesn't flow around the network traffic, the
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:08:24,000 --> 00:08:25,000
|
| 527 |
+
network IDs can, but this could.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:08:26,000 --> 00:08:30,000
|
| 531 |
+
Now, the disadvantage, it's always going to be more costly because it's a per device.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:08:30,000 --> 00:08:35,000
|
| 535 |
+
So if you have a 10,000 device imagine 10,000 times the cost of each of those things.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:08:36,000 --> 00:08:40,000
|
| 539 |
+
Lots of administrative attention on each machine can detect network attacks.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:08:40,000 --> 00:08:49,000
|
| 543 |
+
One of the problems I have with installing endpoint security, even though we need it with Hids in particular,
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:08:49,000 --> 00:08:51,000
|
| 547 |
+
is because it just consumes a lot of resources.
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:08:51,000 --> 00:08:54,000
|
| 551 |
+
It slows your machine down, not significantly, but it does.
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:08:54,000 --> 00:08:59,000
|
| 555 |
+
If you're running high, intense applications and you really need all your power and you put that IDs
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:08:59,000 --> 00:09:01,000
|
| 559 |
+
on there, you might want to up your Ram and CPU.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:09:03,000 --> 00:09:05,000
|
| 563 |
+
Easier for intrusion to to discover and disable.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:09:05,000 --> 00:09:09,000
|
| 567 |
+
And I h IDs because they're right on the machine.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:09:09,000 --> 00:09:15,000
|
| 571 |
+
With less security, the logs are maintained in the system, and that means that hackers can easily
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:09:15,000 --> 00:09:18,000
|
| 575 |
+
manipulate it, especially if it's on one machine.
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:09:18,000 --> 00:09:20,000
|
| 579 |
+
Your machine in particular.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:09:21,000 --> 00:09:23,000
|
| 583 |
+
Now the other one is going to be a network based idea.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:09:23,000 --> 00:09:25,000
|
| 587 |
+
So what exactly is that?
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:09:25,000 --> 00:09:30,000
|
| 591 |
+
A network based IDs is not just a piece of software on a desktop.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:09:30,000 --> 00:09:32,000
|
| 595 |
+
A network based IDs is a computer.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:09:32,000 --> 00:09:33,000
|
| 599 |
+
Like if you have snort.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:09:33,000 --> 00:09:34,000
|
| 603 |
+
All right.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:09:34,000 --> 00:09:36,000
|
| 607 |
+
So if I open the calculator.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:09:36,000 --> 00:09:44,000
|
| 611 |
+
So for example if you have snort you would install snort on a computer.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:09:44,000 --> 00:09:45,000
|
| 615 |
+
All right.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:09:45,000 --> 00:09:46,000
|
| 619 |
+
Just a normal desktop.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:09:46,000 --> 00:09:50,000
|
| 623 |
+
And what you're going to do is you're just going to plug it in to the switch.
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:09:50,000 --> 00:09:55,000
|
| 627 |
+
Now once you guys look at this diagram that I have here, here's how you would set up your network.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:09:55,000 --> 00:09:58,000
|
| 631 |
+
You would first take your switch.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:09:58,000 --> 00:10:04,000
|
| 635 |
+
You would install snort on a normal everyday computer, ideally a type of a server.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:10:04,000 --> 00:10:08,000
|
| 639 |
+
And you're going to do what's called port spanning Port Spanner or Port Marion.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:10:08,000 --> 00:10:10,000
|
| 643 |
+
What this means let me get the switch here.
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:10:10,000 --> 00:10:18,000
|
| 647 |
+
So what this means is this you would have to go into the switch and you would select one of these ports
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:10:18,000 --> 00:10:19,000
|
| 651 |
+
to be this port spanner.
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:10:19,000 --> 00:10:25,000
|
| 655 |
+
Let's say you go with this port right here, the second port you would go into the switches configuration.
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:10:25,000 --> 00:10:28,000
|
| 659 |
+
If you guys studied Cisco you'll be familiar with this.
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:10:28,000 --> 00:10:30,000
|
| 663 |
+
If you go into the switch you would port span this switch.
|
| 664 |
+
|
| 665 |
+
167
|
| 666 |
+
00:10:30,000 --> 00:10:35,000
|
| 667 |
+
And what's going to happen here is that all traffic that comes through the rest of these switches,
|
| 668 |
+
|
| 669 |
+
168
|
| 670 |
+
00:10:35,000 --> 00:10:40,000
|
| 671 |
+
all these ports will be copied to this second port that I have here.
|
| 672 |
+
|
| 673 |
+
169
|
| 674 |
+
00:10:40,000 --> 00:10:43,000
|
| 675 |
+
So what this is doing is that all traffic.
|
| 676 |
+
|
| 677 |
+
170
|
| 678 |
+
00:10:43,000 --> 00:10:49,000
|
| 679 |
+
So let's say somebody is talking from this port here to this port, maybe this port to this port, this
|
| 680 |
+
|
| 681 |
+
171
|
| 682 |
+
00:10:49,000 --> 00:10:49,000
|
| 683 |
+
port, to this port.
|
| 684 |
+
|
| 685 |
+
172
|
| 686 |
+
00:10:49,000 --> 00:10:50,000
|
| 687 |
+
What?
|
| 688 |
+
|
| 689 |
+
173
|
| 690 |
+
00:10:50,000 --> 00:10:50,000
|
| 691 |
+
It doesn't matter.
|
| 692 |
+
|
| 693 |
+
174
|
| 694 |
+
00:10:51,000 --> 00:10:55,000
|
| 695 |
+
Okay, as all these ports are talking, traffic coming in and out, all these ports.
|
| 696 |
+
|
| 697 |
+
175
|
| 698 |
+
00:10:55,000 --> 00:11:01,000
|
| 699 |
+
This switch is sending a copy of every single one of the frames to that port.
|
| 700 |
+
|
| 701 |
+
176
|
| 702 |
+
00:11:02,000 --> 00:11:03,000
|
| 703 |
+
Now.
|
| 704 |
+
|
| 705 |
+
177
|
| 706 |
+
00:11:03,000 --> 00:11:04,000
|
| 707 |
+
What happens then?
|
| 708 |
+
|
| 709 |
+
178
|
| 710 |
+
00:11:04,000 --> 00:11:11,000
|
| 711 |
+
Well, what's going to happen then is that remember, the snort box is connected to that span port.
|
| 712 |
+
|
| 713 |
+
179
|
| 714 |
+
00:11:12,000 --> 00:11:19,000
|
| 715 |
+
The snort box snorts up all of this traffic, analyzes it in its database, and it's going to be able
|
| 716 |
+
|
| 717 |
+
180
|
| 718 |
+
00:11:19,000 --> 00:11:24,000
|
| 719 |
+
to tell you if there is some kind of intrusion on this machine, or this machine or that machine or
|
| 720 |
+
|
| 721 |
+
181
|
| 722 |
+
00:11:24,000 --> 00:11:26,000
|
| 723 |
+
that segment and so on.
|
| 724 |
+
|
| 725 |
+
182
|
| 726 |
+
00:11:26,000 --> 00:11:28,000
|
| 727 |
+
So it reads all the incoming packet.
|
| 728 |
+
|
| 729 |
+
183
|
| 730 |
+
00:11:28,000 --> 00:11:31,000
|
| 731 |
+
It searches for any kind of suspicious patterns.
|
| 732 |
+
|
| 733 |
+
184
|
| 734 |
+
00:11:31,000 --> 00:11:34,000
|
| 735 |
+
Uh, when threats are discovered based on the severity.
|
| 736 |
+
|
| 737 |
+
185
|
| 738 |
+
00:11:36,000 --> 00:11:37,000
|
| 739 |
+
Uh, it will alert you now.
|
| 740 |
+
|
| 741 |
+
186
|
| 742 |
+
00:11:37,000 --> 00:11:40,000
|
| 743 |
+
It cannot monitor encrypted.
|
| 744 |
+
|
| 745 |
+
187
|
| 746 |
+
00:11:40,000 --> 00:11:40,000
|
| 747 |
+
It's going to be this one.
|
| 748 |
+
|
| 749 |
+
188
|
| 750 |
+
00:11:40,000 --> 00:11:41,000
|
| 751 |
+
This.
|
| 752 |
+
|
| 753 |
+
189
|
| 754 |
+
00:11:41,000 --> 00:11:43,000
|
| 755 |
+
It can't monitor encrypted traffic.
|
| 756 |
+
|
| 757 |
+
190
|
| 758 |
+
00:11:43,000 --> 00:11:49,000
|
| 759 |
+
If you use a lot of encrypted traffic, it may not be able to see it harder for attackers to discover.
|
| 760 |
+
|
| 761 |
+
191
|
| 762 |
+
00:11:49,000 --> 00:11:55,000
|
| 763 |
+
Have very little, little negative effect on traffic because it's just copying traffic over.
|
| 764 |
+
|
| 765 |
+
192
|
| 766 |
+
00:11:55,000 --> 00:12:00,000
|
| 767 |
+
It's not like it's going to be flying extra traffic around the network now.
|
| 768 |
+
|
| 769 |
+
193
|
| 770 |
+
00:12:00,000 --> 00:12:06,000
|
| 771 |
+
And Nids is like, snort, I think is something we should all have on our networks.
|
| 772 |
+
|
| 773 |
+
194
|
| 774 |
+
00:12:06,000 --> 00:12:06,000
|
| 775 |
+
Why?
|
| 776 |
+
|
| 777 |
+
195
|
| 778 |
+
00:12:06,000 --> 00:12:08,000
|
| 779 |
+
Because once again it's free.
|
| 780 |
+
|
| 781 |
+
196
|
| 782 |
+
00:12:08,000 --> 00:12:11,000
|
| 783 |
+
Please install it if you don't have it now.
|
| 784 |
+
|
| 785 |
+
197
|
| 786 |
+
00:12:12,000 --> 00:12:13,000
|
| 787 |
+
All right.
|
| 788 |
+
|
| 789 |
+
198
|
| 790 |
+
00:12:13,000 --> 00:12:14,000
|
| 791 |
+
You're not really going to find many things.
|
| 792 |
+
|
| 793 |
+
199
|
| 794 |
+
00:12:14,000 --> 00:12:17,000
|
| 795 |
+
That is pure ideas in today's world.
|
| 796 |
+
|
| 797 |
+
200
|
| 798 |
+
00:12:17,000 --> 00:12:22,000
|
| 799 |
+
Today's world with all the unified devices that are out there, we're going to get some kind of an IP.
|
| 800 |
+
|
| 801 |
+
201
|
| 802 |
+
00:12:22,000 --> 00:12:24,000
|
| 803 |
+
A snort is technically an IPS.
|
| 804 |
+
|
| 805 |
+
202
|
| 806 |
+
00:12:24,000 --> 00:12:26,000
|
| 807 |
+
So what exactly is the IPS?
|
| 808 |
+
|
| 809 |
+
203
|
| 810 |
+
00:12:26,000 --> 00:12:28,000
|
| 811 |
+
An IPS is an inline device.
|
| 812 |
+
|
| 813 |
+
204
|
| 814 |
+
00:12:28,000 --> 00:12:29,000
|
| 815 |
+
I want you guys watch this diagram here.
|
| 816 |
+
|
| 817 |
+
205
|
| 818 |
+
00:12:29,000 --> 00:12:31,000
|
| 819 |
+
So you see this firewall.
|
| 820 |
+
|
| 821 |
+
206
|
| 822 |
+
00:12:31,000 --> 00:12:35,000
|
| 823 |
+
The IDs sits like a normal box off the firewall.
|
| 824 |
+
|
| 825 |
+
207
|
| 826 |
+
00:12:35,000 --> 00:12:39,000
|
| 827 |
+
It grabs traffic to protect your internal network.
|
| 828 |
+
|
| 829 |
+
208
|
| 830 |
+
00:12:39,000 --> 00:12:46,000
|
| 831 |
+
Notice the IPS technically is the firewall a lot of IPS like so this has an IPS built into it.
|
| 832 |
+
|
| 833 |
+
209
|
| 834 |
+
00:12:46,000 --> 00:12:49,000
|
| 835 |
+
You just have to pay to enable its license.
|
| 836 |
+
|
| 837 |
+
210
|
| 838 |
+
00:12:49,000 --> 00:12:56,000
|
| 839 |
+
So what an IPS does is that not only does it examine the traffic to detect intrusions, but if it finds
|
| 840 |
+
|
| 841 |
+
211
|
| 842 |
+
00:12:56,000 --> 00:13:01,000
|
| 843 |
+
intrusions or problems, it prevents the vulnerabilities it prevents.
|
| 844 |
+
|
| 845 |
+
212
|
| 846 |
+
00:13:01,000 --> 00:13:08,000
|
| 847 |
+
It can shut segments down, it can shut hoses off, it can choose what to forward and what to block.
|
| 848 |
+
|
| 849 |
+
213
|
| 850 |
+
00:13:08,000 --> 00:13:11,000
|
| 851 |
+
So it prevents attacks from happening in your network.
|
| 852 |
+
|
| 853 |
+
214
|
| 854 |
+
00:13:11,000 --> 00:13:14,000
|
| 855 |
+
So this is something important to consider.
|
| 856 |
+
|
| 857 |
+
215
|
| 858 |
+
00:13:14,000 --> 00:13:22,000
|
| 859 |
+
IPS IPS is of course going to be better than an IDs system, but any which way.
|
| 860 |
+
|
| 861 |
+
216
|
| 862 |
+
00:13:22,000 --> 00:13:26,000
|
| 863 |
+
Remember snort is free and it is an ID it is a network IPS.
|
| 864 |
+
|
| 865 |
+
217
|
| 866 |
+
00:13:26,000 --> 00:13:30,000
|
| 867 |
+
If you go to the website and you look at it, you'll notice it says that.
|
| 868 |
+
|
| 869 |
+
218
|
| 870 |
+
00:13:30,000 --> 00:13:31,000
|
| 871 |
+
All right.
|
| 872 |
+
|
| 873 |
+
219
|
| 874 |
+
00:13:31,000 --> 00:13:37,000
|
| 875 |
+
To end this discussion, IDs IPS are mandatory devices in my opinion, on any network.
|
| 876 |
+
|
| 877 |
+
220
|
| 878 |
+
00:13:37,000 --> 00:13:39,000
|
| 879 |
+
In my opinion, this is not for your exam.
|
| 880 |
+
|
| 881 |
+
221
|
| 882 |
+
00:13:39,000 --> 00:13:41,000
|
| 883 |
+
I'm just telling you this from experience.
|
| 884 |
+
|
| 885 |
+
222
|
| 886 |
+
00:13:41,000 --> 00:13:47,000
|
| 887 |
+
If you have a network that's more than ten computers, please put an IDs in just between me and you.
|
| 888 |
+
|
| 889 |
+
223
|
| 890 |
+
00:13:47,000 --> 00:13:49,000
|
| 891 |
+
If you're installing snort, it doesn't need a lot of resources.
|
| 892 |
+
|
| 893 |
+
224
|
| 894 |
+
00:13:49,000 --> 00:13:53,000
|
| 895 |
+
Use an old box, old computer you have in a corner.
|
| 896 |
+
|
| 897 |
+
225
|
| 898 |
+
00:13:53,000 --> 00:13:55,000
|
| 899 |
+
Put an SSD into it.
|
| 900 |
+
|
| 901 |
+
226
|
| 902 |
+
00:13:55,000 --> 00:13:56,000
|
| 903 |
+
Install snort, put Linux on it.
|
| 904 |
+
|
| 905 |
+
227
|
| 906 |
+
00:13:56,000 --> 00:13:58,000
|
| 907 |
+
Do not install on windows.
|
| 908 |
+
|
| 909 |
+
228
|
| 910 |
+
00:13:58,000 --> 00:14:03,000
|
| 911 |
+
It doesn't work really well and have some fun monitoring traffic and securing your network.
|
| 912 |
+
|
11 - Security Principles/011 Load Balancer OB 3.2_en.srt
ADDED
|
@@ -0,0 +1,380 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:07,000
|
| 3 |
+
When you're building large networks, that's going to take in tens of thousands or millions of requests.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:07,000 --> 00:00:13,000
|
| 7 |
+
One critical device that you're going to need to set up is something we call a load balancer.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:13,000 --> 00:00:15,000
|
| 11 |
+
What exactly is it?
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:15,000 --> 00:00:15,000
|
| 15 |
+
What?
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:15,000 --> 00:00:16,000
|
| 19 |
+
I want to show you a picture of it.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:16,000 --> 00:00:20,000
|
| 23 |
+
Let's just jump a couple of slides around before we come back to it.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:20,000 --> 00:00:24,000
|
| 27 |
+
So I want you guys watch this particular diagram again.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:24,000 --> 00:00:25,000
|
| 31 |
+
We'll come back to this in a minute.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:25,000 --> 00:00:29,000
|
| 35 |
+
But what a load balancer does is exactly what it says it does.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:29,000 --> 00:00:31,000
|
| 39 |
+
It balances a load.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:31,000 --> 00:00:37,000
|
| 43 |
+
Let's say you have let's say these five computers each represents 1000 connections.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:37,000 --> 00:00:39,000
|
| 47 |
+
So right now you've got 5000 connections coming in.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:39,000 --> 00:00:40,000
|
| 51 |
+
You have a choice.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:40,000 --> 00:00:44,000
|
| 55 |
+
You can just have one single web server taking all the connections.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:44,000 --> 00:00:48,000
|
| 59 |
+
And if that server dies oh well every no more internet site for them.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:48,000 --> 00:00:49,000
|
| 63 |
+
Your sites down.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:49,000 --> 00:00:51,000
|
| 67 |
+
The best thing here is to get a load balancer.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:51,000 --> 00:00:56,000
|
| 71 |
+
What a load balancer does is that it distributes the load between two different servers.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:56,000 --> 00:00:59,000
|
| 75 |
+
So look at it right now it's given this one server.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:00:59,000 --> 00:01:01,000
|
| 79 |
+
It's computer one is getting this.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:01,000 --> 00:01:03,000
|
| 83 |
+
Then it's given this to computer two.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:03,000 --> 00:01:05,000
|
| 87 |
+
And when computer three comes in gives it to this one.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:05,000 --> 00:01:09,000
|
| 91 |
+
Computer four comes in gives it to this one, five comes in to this one.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:09,000 --> 00:01:09,000
|
| 95 |
+
Then six would go.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:09,000 --> 00:01:15,000
|
| 99 |
+
So it's going like this 123456789.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:15,000 --> 00:01:16,000
|
| 103 |
+
So what is it doing.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:16,000 --> 00:01:18,000
|
| 107 |
+
It's distributing the load between the machines.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:18,000 --> 00:01:26,000
|
| 111 |
+
That way one machine doesn't get all the load of the internet of the website requests is basically splitting
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:26,000 --> 00:01:27,000
|
| 115 |
+
it 5050.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:27,000 --> 00:01:33,000
|
| 119 |
+
This of course helps to speed up the traffic on the speed up traffic hitting the system.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:33,000 --> 00:01:34,000
|
| 123 |
+
So what exactly is it?
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:34,000 --> 00:01:41,000
|
| 127 |
+
Well, it's basically a device or software that evenly distributes network or application traffic across
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:41,000 --> 00:01:45,000
|
| 131 |
+
multiple servers to prevent any single one of them from becoming overburdened.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:45,000 --> 00:01:48,000
|
| 135 |
+
It improves performance and reliability.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:48,000 --> 00:01:48,000
|
| 139 |
+
It makes it quick.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:01:48,000 --> 00:01:52,000
|
| 143 |
+
But if one of those servers die, your whole website doesn't go offline.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:01:52,000 --> 00:01:56,000
|
| 147 |
+
It does become slower because now one machine has to serve all of them.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:01:56,000 --> 00:01:59,000
|
| 151 |
+
Load balancers comes in different in two kinds.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:01:59,000 --> 00:02:01,000
|
| 155 |
+
You have a hardware and a software.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:01,000 --> 00:02:06,000
|
| 159 |
+
What I have here is a hardware load balancer from Barracuda, very famous device.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:06,000 --> 00:02:13,000
|
| 163 |
+
So a hardware load balancer is a physical device specifically designed for balancing the load.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:13,000 --> 00:02:19,000
|
| 167 |
+
They are more powerful, more expensive, and most of most of most of the load balancers we have today,
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:19,000 --> 00:02:23,000
|
| 171 |
+
especially on large server farms, web server farms are going to be these kinds of devices.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:23,000 --> 00:02:24,000
|
| 175 |
+
You could do this.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:25,000 --> 00:02:26,000
|
| 179 |
+
With software.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:27,000 --> 00:02:31,000
|
| 183 |
+
So for example Windows Server supports this.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:31,000 --> 00:02:33,000
|
| 187 |
+
These are applications that can run on a standard hardware.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:33,000 --> 00:02:37,000
|
| 191 |
+
And cloud environments are more flexible and more cost effective.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:37,000 --> 00:02:41,000
|
| 195 |
+
Now when you set up a load balancer, there's basically two kinds of setups.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:41,000 --> 00:02:44,000
|
| 199 |
+
You have what's called active passive.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:44,000 --> 00:02:46,000
|
| 203 |
+
And the other one is called active active.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:46,000 --> 00:02:47,000
|
| 207 |
+
So what is exactly this one.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:02:47,000 --> 00:02:53,000
|
| 211 |
+
So active passive is this this is really not to improve performance.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:02:53,000 --> 00:02:56,000
|
| 215 |
+
This one is to improve reliability.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:02:56,000 --> 00:02:58,000
|
| 219 |
+
What this means is that what you do.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:02:59,000 --> 00:03:07,000
|
| 223 |
+
Is you're going to have one server take on all of the requests, all of them.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:07,000 --> 00:03:11,000
|
| 227 |
+
Maybe this is good for you because you don't have a lot of requests.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:11,000 --> 00:03:16,000
|
| 231 |
+
Maybe you have a really beefy server with a big line, and you don't need to split the request between
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:16,000 --> 00:03:16,000
|
| 235 |
+
them.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:16,000 --> 00:03:22,000
|
| 239 |
+
It doesn't make sense, because the request you have is only utilized in a small percentage of resources
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:22,000 --> 00:03:23,000
|
| 243 |
+
on the machine.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:23,000 --> 00:03:25,000
|
| 247 |
+
So what you do, you set up this thing called active passive.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:25,000 --> 00:03:26,000
|
| 251 |
+
So one machine is active.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:26,000 --> 00:03:28,000
|
| 255 |
+
It's taking all the requests.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:28,000 --> 00:03:32,000
|
| 259 |
+
And then if this machine fails then this one kicks in.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:32,000 --> 00:03:33,000
|
| 263 |
+
So this is a failover server.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:33,000 --> 00:03:37,000
|
| 267 |
+
So if the primary one fails the failover kicks in.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:37,000 --> 00:03:40,000
|
| 271 |
+
So it has to have some kind of failover mechanism between them.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:40,000 --> 00:03:41,000
|
| 275 |
+
So the switch knows it.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:03:41,000 --> 00:03:47,000
|
| 279 |
+
The hardware load balancer generally will knows it ideally for scenarios where uninterrupted service
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:03:47,000 --> 00:03:48,000
|
| 283 |
+
is critical.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:03:49,000 --> 00:03:53,000
|
| 287 |
+
But you don't need the power of just two of them at the same time.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:03:53,000 --> 00:03:57,000
|
| 291 |
+
It provides a reliable backup in case a primary one fails.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:03:57,000 --> 00:04:01,000
|
| 295 |
+
So once again, if you just don't need that power, this is going to work out.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:01,000 --> 00:04:08,000
|
| 299 |
+
Now, if you have massive amounts of client traffic coming in and you have 50 servers set up there,
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:08,000 --> 00:04:13,000
|
| 303 |
+
and you need all of your servers to be hammering out those requests, this is your thing here.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:13,000 --> 00:04:14,000
|
| 307 |
+
Both.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:15,000 --> 00:04:21,000
|
| 311 |
+
Load balancers are active in shared traffic simultaneously, so they're both sharing the traffic.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:21,000 --> 00:04:26,000
|
| 315 |
+
Traffic is distributed between two, generally two load balancers or different hoses.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:26,000 --> 00:04:28,000
|
| 319 |
+
Um they use something called round robin.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:28,000 --> 00:04:29,000
|
| 323 |
+
So you get it, then you get it.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:29,000 --> 00:04:31,000
|
| 327 |
+
So it'll be like you get it, then you get it, then you get it.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:31,000 --> 00:04:34,000
|
| 331 |
+
If there was three of them, it would be like, you get it, you get it, you get it.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:34,000 --> 00:04:38,000
|
| 335 |
+
Usage for high end traffic environments this year.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:38,000 --> 00:04:42,000
|
| 339 |
+
The big advantages here good capacity and reliability.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:42,000 --> 00:04:48,000
|
| 343 |
+
Now this could be done with multiple load balancers or it could be done with a single load balancer.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:04:48,000 --> 00:04:51,000
|
| 347 |
+
Although if you have multiple load balancers because if this device fails you're in trouble.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:04:51,000 --> 00:04:56,000
|
| 351 |
+
So you could have multiple load balancers uh, different forms.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:04:56,000 --> 00:04:59,000
|
| 355 |
+
Maybe each load balancer has ten machines.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:04:59,000 --> 00:05:02,000
|
| 359 |
+
There are different ways to set this up for your exam.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:02,000 --> 00:05:04,000
|
| 363 |
+
Just understand what a load balancer is.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:04,000 --> 00:05:05,000
|
| 367 |
+
It is what it says it is.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:05,000 --> 00:05:07,000
|
| 371 |
+
It distributes loads between machines.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:07,000 --> 00:05:14,000
|
| 375 |
+
Key reason for that is going to be because we want to not just distribute the traffic, but we want
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:14,000 --> 00:05:20,000
|
| 379 |
+
the reliability in case one of those machines fail, it doesn't bring down the entire network.
|
| 380 |
+
|
11 - Security Principles/012 802.1x and EAP OB 3.2_en.srt
ADDED
|
@@ -0,0 +1,356 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:00,000
|
| 3 |
+
All right.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:00,000 --> 00:00:02,000
|
| 7 |
+
Take a look at the switch that I have here.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:02,000 --> 00:00:03,000
|
| 11 |
+
So we got this switch.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:03,000 --> 00:00:07,000
|
| 15 |
+
We plug you're going to plug your computer into my switch.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:07,000 --> 00:00:10,000
|
| 19 |
+
And you're going to be able to gain access to the network.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:10,000 --> 00:00:17,000
|
| 23 |
+
Or are you one of the just having a switch lying around is one of the worst things you can ever do.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:17,000 --> 00:00:23,000
|
| 27 |
+
If you're right now, if your switch is set up to the point where anyone can just walk in, plug a computer
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:23,000 --> 00:00:28,000
|
| 31 |
+
into it, and gain full network access without any form of authentication.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:28,000 --> 00:00:29,000
|
| 35 |
+
That is bad news.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:29,000 --> 00:00:36,000
|
| 39 |
+
So what we want to do is we want to be able we put this down before it kills me here.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:36,000 --> 00:00:41,000
|
| 43 |
+
We want to be able to do what is called port security.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:41,000 --> 00:00:43,000
|
| 47 |
+
But what exactly is that?
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:43,000 --> 00:00:48,000
|
| 51 |
+
So port security is used to secure network ports on computers and network devices, and particularly
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:48,000 --> 00:00:55,000
|
| 55 |
+
switches guarding against on authorized access and insurance, secure communication.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:55,000 --> 00:00:57,000
|
| 59 |
+
This is more than likely going to be secured.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:57,000 --> 00:01:03,000
|
| 63 |
+
Network switch ports now generally, port security can also mean things like filtering ports through
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:03,000 --> 00:01:04,000
|
| 67 |
+
TCP and UDP.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:04,000 --> 00:01:05,000
|
| 71 |
+
This is going to be done with like firewalls.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:06,000 --> 00:01:10,000
|
| 75 |
+
It's meant to stop unauthorized access to your network.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:10,000 --> 00:01:15,000
|
| 79 |
+
But in this particular video, what I want to talk about is not just filtering traffic through ports.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:15,000 --> 00:01:17,000
|
| 83 |
+
This is going to be done generally through a firewall.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:17,000 --> 00:01:21,000
|
| 87 |
+
I want to talk about the physical port security, like on this switch.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:21,000 --> 00:01:28,000
|
| 91 |
+
And in particular there's two terms that we want to be familiar with something called 821 X and EAP
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:28,000 --> 00:01:31,000
|
| 95 |
+
or Extensible Authentication Protocol.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:31,000 --> 00:01:32,000
|
| 99 |
+
Let me explain what this is to you.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:32,000 --> 00:01:36,000
|
| 103 |
+
So 821 x you have to come into the switch and enable these things.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:36,000 --> 00:01:40,000
|
| 107 |
+
You you configure the ports on the switch and you enable this.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:40,000 --> 00:01:42,000
|
| 111 |
+
This is an IEEE standard.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:43,000 --> 00:01:44,000
|
| 115 |
+
For port.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:44,000 --> 00:01:46,000
|
| 119 |
+
Port based access control.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:46,000 --> 00:01:50,000
|
| 123 |
+
It's used to authenticate device that are attempting to connect to your LAN.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:50,000 --> 00:01:53,000
|
| 127 |
+
And you can also do this for your wireless connection.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:53,000 --> 00:01:59,000
|
| 131 |
+
Also not just for your wired switch, but you can also enable it on your wireless.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:59,000 --> 00:02:00,000
|
| 135 |
+
Here's how it works.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:00,000 --> 00:02:06,000
|
| 139 |
+
When a device attempts to connect to a network that's that has 801 enabled, the authenticator blocks
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:06,000 --> 00:02:11,000
|
| 143 |
+
all traffic except the 8021, and the client is authenticated.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:11,000 --> 00:02:12,000
|
| 147 |
+
Now I want to show you guys something.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:12,000 --> 00:02:14,000
|
| 151 |
+
I have a diagram of this from Wikipedia.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:15,000 --> 00:02:21,000
|
| 155 |
+
So when you want to connect to a network, notice the switch that is going to be utilizing.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:22,000 --> 00:02:24,000
|
| 159 |
+
That's going to be utilizing 801 x.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:24,000 --> 00:02:31,000
|
| 163 |
+
So what you do is you configure the switch to say if the computer does not authenticate and go through
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:31,000 --> 00:02:34,000
|
| 167 |
+
8 to 1 x, we're not going to allow you access in.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:34,000 --> 00:02:37,000
|
| 171 |
+
So it only accepts that kind of access.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:37,000 --> 00:02:38,000
|
| 175 |
+
So here's how it works.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:39,000 --> 00:02:40,000
|
| 179 |
+
The supplicant is you.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:40,000 --> 00:02:41,000
|
| 183 |
+
That's the user.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:41,000 --> 00:02:44,000
|
| 187 |
+
You connect to the switch and you're trying to gain access to the network.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:44,000 --> 00:02:51,000
|
| 191 |
+
But before the switch can grant you access to the LAN resources, what you have to do, you have to
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:51,000 --> 00:02:55,000
|
| 195 |
+
send a request to the authenticator to switch.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:55,000 --> 00:03:00,000
|
| 199 |
+
The authenticator then sends that request to an authentication server.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:00,000 --> 00:03:04,000
|
| 203 |
+
That authentication server is going to authenticate you username password.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:04,000 --> 00:03:08,000
|
| 207 |
+
It can do a variety of different things certificate based authentication.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:08,000 --> 00:03:10,000
|
| 211 |
+
So there's many different ways it can do this.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:10,000 --> 00:03:16,000
|
| 215 |
+
You can use a Radius server something we'll cover in another class in another video when the when the
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:16,000 --> 00:03:23,000
|
| 219 |
+
authentication server said it's okay, then the authenticator tells you and then you can access resources.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:24,000 --> 00:03:29,000
|
| 223 |
+
Now the supplicant I just mentioned to you, you send the credential to the authenticator, which forwards
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:29,000 --> 00:03:30,000
|
| 227 |
+
them to the authentication server.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:30,000 --> 00:03:34,000
|
| 231 |
+
And the authentication server is something that's going to run like a Radius server.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:34,000 --> 00:03:39,000
|
| 235 |
+
If the server approves it, it gives you access and then you can access the network.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:39,000 --> 00:03:42,000
|
| 239 |
+
Now you notice I have these things called EAP here.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:42,000 --> 00:03:46,000
|
| 243 |
+
See that EAP stands for Extensible Authentication Protocol.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:46,000 --> 00:03:50,000
|
| 247 |
+
You are authenticating to a particular device.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:50,000 --> 00:03:53,000
|
| 251 |
+
This here is this is the protocol that's going to allow that.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:54,000 --> 00:03:56,000
|
| 255 |
+
It's a framework frequently used in network access.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:57,000 --> 00:03:58,000
|
| 259 |
+
All right.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:58,000 --> 00:04:02,000
|
| 263 |
+
It's designed to support multiple authentication passwords, tokens, certificates.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:02,000 --> 00:04:07,000
|
| 267 |
+
So if you want to authenticate to my network and you plug a computer into my switch.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:08,000 --> 00:04:11,000
|
| 271 |
+
You're going to have to provide either some kind of certificate.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:11,000 --> 00:04:13,000
|
| 275 |
+
You can use tokens.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:14,000 --> 00:04:15,000
|
| 279 |
+
Uh, certificates is a good one.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:15,000 --> 00:04:16,000
|
| 283 |
+
I like that one.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:17,000 --> 00:04:19,000
|
| 287 |
+
The worst, of course, is passwords.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:19,000 --> 00:04:21,000
|
| 291 |
+
This thing is widely used.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:21,000 --> 00:04:25,000
|
| 295 |
+
It's mostly it was widely used in PGP or point to point connections.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:26,000 --> 00:04:26,000
|
| 299 |
+
Um.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:27,000 --> 00:04:34,000
|
| 303 |
+
But it's a lot of time now using 821 X, and it's used generally in conjunction with a Radius server
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:34,000 --> 00:04:35,000
|
| 307 |
+
to centralize authentication.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:35,000 --> 00:04:40,000
|
| 311 |
+
That way you can have tons of switches all foward to a single.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:41,000 --> 00:04:44,000
|
| 315 |
+
Authentication server like a radius.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:45,000 --> 00:04:47,000
|
| 319 |
+
Why would you want this?
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:47,000 --> 00:04:47,000
|
| 323 |
+
Right?
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:47,000 --> 00:04:48,000
|
| 327 |
+
You think about this.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:49,000 --> 00:04:53,000
|
| 331 |
+
One of the worst things that can happen to somebody walking into a network and just plug a computer
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:53,000 --> 00:04:57,000
|
| 335 |
+
into your to plug a computer into your network, gain all your network access.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:04:57,000 --> 00:04:59,000
|
| 339 |
+
That would severely suck.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:04:59,000 --> 00:05:01,000
|
| 343 |
+
The best thing to do is to have this on your network.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:01,000 --> 00:05:07,000
|
| 347 |
+
Now, it's not difficult to set up, but it is more setup that needs to get done.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:07,000 --> 00:05:12,000
|
| 351 |
+
That way, when somebody plugs a computer into your network, you're 100% sure this person actually
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:12,000 --> 00:05:14,000
|
| 355 |
+
belongs in the network.
|
| 356 |
+
|
11 - Security Principles/013 Firewalls OB 3.2_en.srt
ADDED
|
@@ -0,0 +1,520 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:04,000
|
| 3 |
+
In this course, I discussed a lot of different ways to secure a network.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:04,000 --> 00:00:11,000
|
| 7 |
+
But when it comes to network security, Network Security 101 is a firewall.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:11,000 --> 00:00:17,000
|
| 11 |
+
And in this video we're going to talk about firewalls in particularly like this little firewall that
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:17,000 --> 00:00:19,000
|
| 15 |
+
I have right here.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:19,000 --> 00:00:19,000
|
| 19 |
+
All right.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:19,000 --> 00:00:20,000
|
| 23 |
+
That one has two USBs.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:20,000 --> 00:00:21,000
|
| 27 |
+
This one doesn't.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:21,000 --> 00:00:23,000
|
| 31 |
+
All right let's get started with different kinds of firewall.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:23,000 --> 00:00:26,000
|
| 35 |
+
And I'm going to explain to you that this is an next generation firewall.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:26,000 --> 00:00:28,000
|
| 39 |
+
And what makes this one unique.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:28,000 --> 00:00:29,000
|
| 43 |
+
Let's get started.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:30,000 --> 00:00:36,000
|
| 47 |
+
When it comes to basic network security, one of the most basic things you've got to have on a computer
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:37,000 --> 00:00:38,000
|
| 51 |
+
or on a network is a firewall.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:38,000 --> 00:00:44,000
|
| 55 |
+
Now firewalls comes in to basically going to come in two main designs.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:44,000 --> 00:00:48,000
|
| 59 |
+
You have, uh, host based firewalls and network firewalls.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:48,000 --> 00:00:49,000
|
| 63 |
+
This is a network firewall.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:49,000 --> 00:00:55,000
|
| 67 |
+
You have a host based firewall that's installed on your physical box, like on your your desktop, like
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:00:55,000 --> 00:00:56,000
|
| 71 |
+
Windows Firewall.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:00:56,000 --> 00:00:59,000
|
| 75 |
+
Now, what exactly is it?
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:00:59,000 --> 00:01:02,000
|
| 79 |
+
Well, a network security system, it's basically a network.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:02,000 --> 00:01:05,000
|
| 83 |
+
The monitors and controls incoming and outgoing network traffic.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:05,000 --> 00:01:10,000
|
| 87 |
+
Whether that's coming into your host or coming into your network, typically establishes a barrier between
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:10,000 --> 00:01:14,000
|
| 91 |
+
a trusted, secure internal network and an outside external network.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:14,000 --> 00:01:19,000
|
| 95 |
+
So if it's a network, if it's a network based firewall, they're talking about this one here has a
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:19,000 --> 00:01:20,000
|
| 99 |
+
Wang port.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:22,000 --> 00:01:27,000
|
| 103 |
+
Anything connected here would be considered on the public side, and anything connected here, the land
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:27,000 --> 00:01:29,000
|
| 107 |
+
port would be considered good traffic.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:29,000 --> 00:01:32,000
|
| 111 |
+
Now it's implemented in hardware and software.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:32,000 --> 00:01:35,000
|
| 115 |
+
So obviously this is an appliance that we would have.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:35,000 --> 00:01:41,000
|
| 119 |
+
Of course you would have software firewalls like something uh, that you would install like like Windows
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:41,000 --> 00:01:41,000
|
| 123 |
+
Firewall.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:41,000 --> 00:01:42,000
|
| 127 |
+
That's a good example.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:42,000 --> 00:01:46,000
|
| 131 |
+
But you can also have like Symantec's or Broadcom endpoint, McAfee endpoint.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:46,000 --> 00:01:49,000
|
| 135 |
+
These will generally come with software based firewalls.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:49,000 --> 00:01:54,000
|
| 139 |
+
They're going to enforce a security policy like allow or disallow these kinds of traffic.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:01:54,000 --> 00:01:58,000
|
| 143 |
+
They control the flow of traffic does not differentiate data versus command.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:01:58,000 --> 00:02:02,000
|
| 147 |
+
It just doesn't know whether something is a command or a particular data.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:02,000 --> 00:02:06,000
|
| 151 |
+
So it might be difficult to detect that controls the flow of traffic.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:06,000 --> 00:02:10,000
|
| 155 |
+
Um, controls the flow of traffic between hosts and network.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:10,000 --> 00:02:16,000
|
| 159 |
+
Now, there are different kinds of firewalls that we want to be familiar with for our exam.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:16,000 --> 00:02:23,000
|
| 163 |
+
The first kind of firewall that came out when I was a little boy was packet filtering firewalls.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:23,000 --> 00:02:26,000
|
| 167 |
+
And these things are not firewalls, they were just routers.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:26,000 --> 00:02:32,000
|
| 171 |
+
When an access control list, they were subject to many kinds of attacks and they do not exist today.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:33,000 --> 00:02:37,000
|
| 175 |
+
Today we're all stateful packet inspection.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:37,000 --> 00:02:38,000
|
| 179 |
+
This was known as stateless.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:38,000 --> 00:02:43,000
|
| 183 |
+
The reason for this is because this type of firewall didn't know traffic that left.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:43,000 --> 00:02:46,000
|
| 187 |
+
So it was subject to something called source routing.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:46,000 --> 00:02:49,000
|
| 191 |
+
Once again, this thing doesn't really exist.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:49,000 --> 00:02:54,000
|
| 195 |
+
All firewalls today and all the firewalls that I'm going to be talking about, such as web application
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:54,000 --> 00:03:04,000
|
| 199 |
+
firewalls, utms, and next gen firewalls are all based on stateful packet inspection or Spice or stateful
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:04,000 --> 00:03:05,000
|
| 203 |
+
inspection firewalls.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:05,000 --> 00:03:08,000
|
| 207 |
+
This is the most they're more advanced than packet filtering.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:08,000 --> 00:03:09,000
|
| 211 |
+
They keep a track.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:09,000 --> 00:03:12,000
|
| 215 |
+
They have a state table of who left and who's coming back in.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:12,000 --> 00:03:19,000
|
| 219 |
+
They're incredibly popular on all firewall technology, including what I have here is based on it now.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:20,000 --> 00:03:26,000
|
| 223 |
+
One kind of firewall that is popular if you're hosting web servers is going to be something called a
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:26,000 --> 00:03:29,000
|
| 227 |
+
WAF or a web application firewall.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:29,000 --> 00:03:34,000
|
| 231 |
+
The design to protect web applications by filtering and monitoring web traffic.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:34,000 --> 00:03:39,000
|
| 235 |
+
Let me show you guys a particular diagram from a very famous company called Akamai.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:39,000 --> 00:03:42,000
|
| 239 |
+
So imagine you have a web for a web server farm.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:42,000 --> 00:03:43,000
|
| 243 |
+
All right.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:43,000 --> 00:03:44,000
|
| 247 |
+
All these are all your web servers.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:44,000 --> 00:03:51,000
|
| 251 |
+
You have all kinds of end users coming through the internet to get to your web server.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:51,000 --> 00:03:59,000
|
| 255 |
+
You put the web application firewall between you and the public, any kind of negative traffic that
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:59,000 --> 00:04:06,000
|
| 259 |
+
is attempting to hit your web servers, things such as SQL injection, cross site scripting, session
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:06,000 --> 00:04:11,000
|
| 263 |
+
hijacking, anything that's negative that's going to attempt to hit your.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:12,000 --> 00:04:14,000
|
| 267 |
+
Hit your, uh, your web server.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:14,000 --> 00:04:16,000
|
| 271 |
+
This thing is going to stop.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:16,000 --> 00:04:20,000
|
| 275 |
+
So this is really important if you're running web applications.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:21,000 --> 00:04:23,000
|
| 279 |
+
Uh, they operate at the application layer.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:23,000 --> 00:04:24,000
|
| 283 |
+
The rules are customized.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:24,000 --> 00:04:26,000
|
| 287 |
+
They're generally could be a hardware or software.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:26,000 --> 00:04:31,000
|
| 291 |
+
But a lot of times now, being that a lot of people have all their web servers are in the cloud, they're
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:31,000 --> 00:04:33,000
|
| 295 |
+
probably going to be part of a cloud service.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:34,000 --> 00:04:38,000
|
| 299 |
+
Now, the other two confuses a lot of folks.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:38,000 --> 00:04:41,000
|
| 303 |
+
And I'll tell you the difference between them, because as I go through them, they're going to sound
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:41,000 --> 00:04:42,000
|
| 307 |
+
alike.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:42,000 --> 00:04:50,000
|
| 311 |
+
Unified threat management systems are this this, by the way, is is this one this is an NDF w.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:51,000 --> 00:04:55,000
|
| 315 |
+
So if you go to Sonicwall and you look up Sonicwall firewalls, you'll see this this big across the
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:55,000 --> 00:04:58,000
|
| 319 |
+
top next generation firewalls.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:58,000 --> 00:04:59,000
|
| 323 |
+
But what exactly is this one now?
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:59,000 --> 00:05:00,000
|
| 327 |
+
Utms.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:05:00,000 --> 00:05:07,000
|
| 331 |
+
This is a great this is a big comprehensive solution that includes things like antivirus, anti-spyware,
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:05:07,000 --> 00:05:11,000
|
| 335 |
+
firewalls, intrusion detections, preventions, and content filtering.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:12,000 --> 00:05:13,000
|
| 339 |
+
They're easy to use.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:13,000 --> 00:05:14,000
|
| 343 |
+
They're very.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:14,000 --> 00:05:20,000
|
| 347 |
+
They come pre-built with many policies ideal for small to mid sized business.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:20,000 --> 00:05:22,000
|
| 351 |
+
Now it's going to sound the same.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:22,000 --> 00:05:24,000
|
| 355 |
+
Okay, I'm just giving you a heads up now.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:24,000 --> 00:05:28,000
|
| 359 |
+
Far more advanced than traditional firewalls include functionalities.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:28,000 --> 00:05:29,000
|
| 363 |
+
Deep packet inspection.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:29,000 --> 00:05:36,000
|
| 367 |
+
They include intrusion prevention systems application awareness deep packet inspection.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:36,000 --> 00:05:39,000
|
| 371 |
+
They can actually see within the packet good threat intelligence.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:39,000 --> 00:05:44,000
|
| 375 |
+
They will also come with antivirus, anti-spyware firewall, intrusion detection, prevention system
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:44,000 --> 00:05:46,000
|
| 379 |
+
and content filtering.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:46,000 --> 00:05:50,000
|
| 383 |
+
These two things sound very much alike.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:50,000 --> 00:05:55,000
|
| 387 |
+
Now, if you are a small business and you just want something to take out the box and you just plug
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:55,000 --> 00:05:58,000
|
| 391 |
+
it in and it comes with a great set of policies.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:58,000 --> 00:06:01,000
|
| 395 |
+
UTM is easy to manage and it comes with most policies.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:06:01,000 --> 00:06:07,000
|
| 399 |
+
If you're looking for something more customizable to best match your business needs, then you get the
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:06:07,000 --> 00:06:08,000
|
| 403 |
+
Ngfw.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:06:08,000 --> 00:06:11,000
|
| 407 |
+
These particular are the engine firewalls.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:06:11,000 --> 00:06:18,000
|
| 411 |
+
The engine firewalls are much more customizable, more robust than the Utms.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:06:19,000 --> 00:06:20,000
|
| 415 |
+
Okay, so keep that in mind.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:06:20,000 --> 00:06:22,000
|
| 419 |
+
The difference is customization.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:06:22,000 --> 00:06:26,000
|
| 423 |
+
One is just really more customization than others.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:06:26,000 --> 00:06:27,000
|
| 427 |
+
Okay.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:06:27,000 --> 00:06:29,000
|
| 431 |
+
Great discussion on firewalls.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:06:29,000 --> 00:06:36,000
|
| 435 |
+
Now I'm not sure if you guys remember the OSI model from previous classes, but one of the things that
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:36,000 --> 00:06:42,000
|
| 439 |
+
we should be familiar with is where firewalls operate layer four and layer seven.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:42,000 --> 00:06:49,000
|
| 443 |
+
So layer four firewalls focus on data transport because they operate at the transport layer, the control
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:49,000 --> 00:06:50,000
|
| 447 |
+
traffic based on TCP, UDP.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:06:51,000 --> 00:06:54,000
|
| 451 |
+
You got to remember something at the basic level.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:54,000 --> 00:06:56,000
|
| 455 |
+
All firewalls do one thing.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:56,000 --> 00:07:03,000
|
| 459 |
+
They block ports at the most conceptual level of firewall should block ports and ports operate at layer
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:07:03,000 --> 00:07:06,000
|
| 463 |
+
four, your transport layer, not your network layer.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:07:06,000 --> 00:07:08,000
|
| 467 |
+
That's going to be IP.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:07:09,000 --> 00:07:16,000
|
| 471 |
+
Now, if the firewall can read into the application and stop certain traffic based on things like a
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:07:16,000 --> 00:07:22,000
|
| 475 |
+
URL, this is going to be a layer four firewall inspects the content of the traffic there, make more
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:07:22,000 --> 00:07:26,000
|
| 479 |
+
informed pretty much decisions, so keep that in mind.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:07:26,000 --> 00:07:28,000
|
| 483 |
+
Now application.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:07:28,000 --> 00:07:34,000
|
| 487 |
+
Anytime you hear the terms application firewall that is considered application firewall is considered
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:07:34,000 --> 00:07:35,000
|
| 491 |
+
a layer seven.
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:07:35,000 --> 00:07:37,000
|
| 495 |
+
Because remember layer seven is application.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:07:37,000 --> 00:07:41,000
|
| 499 |
+
But generally if the exam doesn't specify anything it says what layer is a firewall.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:07:41,000 --> 00:07:42,000
|
| 503 |
+
It's layer four.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:07:42,000 --> 00:07:46,000
|
| 507 |
+
Unless they say something like web application firewall.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:46,000 --> 00:07:51,000
|
| 511 |
+
Uh, by the way, proxy servers are also a type of a firewall.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:51,000 --> 00:07:54,000
|
| 515 |
+
And that's a proxy server is a layer seven device.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:07:54,000 --> 00:07:58,000
|
| 519 |
+
So keep that in mind in case you got a question about that on your test.
|
| 520 |
+
|
11 - Security Principles/014 VPN OB 3.2_en.srt
ADDED
|
@@ -0,0 +1,672 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:03,000
|
| 3 |
+
One very popular thing to do today is to work from home.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:03,000 --> 00:00:07,000
|
| 7 |
+
Maybe you're doing that right now, or maybe you're looking for a job to work from home.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:07,000 --> 00:00:14,000
|
| 11 |
+
The technology that allows work from home, that allows you to connect to a corporate network and utilize
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:14,000 --> 00:00:19,000
|
| 15 |
+
all the corporate network resources, is called a VPN.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:19,000 --> 00:00:20,000
|
| 19 |
+
So what exactly is that?
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:21,000 --> 00:00:23,000
|
| 23 |
+
Well, here's what it is.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:23,000 --> 00:00:28,000
|
| 27 |
+
A VPN is a technology that creates an encrypted connection over a less secure network.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:28,000 --> 00:00:34,000
|
| 31 |
+
It builds on top of an existing physical network, provides a connection mechanism between you and that
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:34,000 --> 00:00:38,000
|
| 35 |
+
corporate network, generally across a public network such as the internet.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:38,000 --> 00:00:41,000
|
| 39 |
+
It allows secure connection between endpoints.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:41,000 --> 00:00:48,000
|
| 43 |
+
Basically, it's going to allow employees to securely access corporate intranet or internal resources
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:48,000 --> 00:00:50,000
|
| 47 |
+
can securely connect.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:50,000 --> 00:00:53,000
|
| 51 |
+
It can even connect global offices together.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:53,000 --> 00:00:56,000
|
| 55 |
+
And it provides a connection over the public internet.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:56,000 --> 00:00:58,000
|
| 59 |
+
Now let me give you some good examples of this.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:58,000 --> 00:01:01,000
|
| 63 |
+
So I use VPNs quite often.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:01,000 --> 00:01:03,000
|
| 67 |
+
In fact, I work from home quite a lot.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:03,000 --> 00:01:07,000
|
| 71 |
+
When I'm at home, I want to be able to access the server at work.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:07,000 --> 00:01:11,000
|
| 75 |
+
That server at work has a database with all the students and the information for the school.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:11,000 --> 00:01:16,000
|
| 79 |
+
It has a file server for different documents that I need access to so I could stay home.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:16,000 --> 00:01:20,000
|
| 83 |
+
I connect to my workplace VPN and then it's like I'm sitting there.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:20,000 --> 00:01:27,000
|
| 87 |
+
I have access to every single thing in the actual network to have a bunch of locations.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:27,000 --> 00:01:30,000
|
| 91 |
+
For example, we have a location in Long Island, New York and Manhattan.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:31,000 --> 00:01:33,000
|
| 95 |
+
In New York City, Midtown Manhattan.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:33,000 --> 00:01:40,000
|
| 99 |
+
We connect these two locations with a VPN, so folks in Manhattan can share data with folks in Long
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:40,000 --> 00:01:41,000
|
| 103 |
+
Island.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:41,000 --> 00:01:43,000
|
| 107 |
+
So VPNs are pretty robust.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:43,000 --> 00:01:49,000
|
| 111 |
+
You can use it as a user access VPN, like I'm using it to connect to my workplace, or you can use
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:49,000 --> 00:01:51,000
|
| 115 |
+
it to connect different sites together.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:51,000 --> 00:01:52,000
|
| 119 |
+
Now.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:54,000 --> 00:01:55,000
|
| 123 |
+
Take a look at this here.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:55,000 --> 00:01:58,000
|
| 127 |
+
This here is called a site to site VPN.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:58,000 --> 00:01:59,000
|
| 131 |
+
This is like site one.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:59,000 --> 00:02:02,000
|
| 135 |
+
Could be like our new Manhattan site.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:02,000 --> 00:02:05,000
|
| 139 |
+
Site two could be like our Long Island site.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:05,000 --> 00:02:09,000
|
| 143 |
+
And notice it's going across the internet utilizing VPN devices.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:09,000 --> 00:02:11,000
|
| 147 |
+
What would you say would do that?
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:11,000 --> 00:02:14,000
|
| 151 |
+
This is what we use to do our VPN.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:14,000 --> 00:02:16,000
|
| 155 |
+
Our Sonicwall is our VPN buddy.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:16,000 --> 00:02:21,000
|
| 159 |
+
We set up the VPN on this device, and I'm going to go through some of the technology that this thing
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:21,000 --> 00:02:22,000
|
| 163 |
+
uses.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:22,000 --> 00:02:29,000
|
| 167 |
+
This thing uses IPsec is what it utilizes to create a tunnel between the two endpoints.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:29,000 --> 00:02:32,000
|
| 171 |
+
And we'll describe what that is coming up in a few minutes.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:32,000 --> 00:02:33,000
|
| 175 |
+
So.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:33,000 --> 00:02:37,000
|
| 179 |
+
This type of VPN is a virtual point to point connection.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:38,000 --> 00:02:45,000
|
| 183 |
+
All right through and it encapsulate the data, virtual encapsulation of the data to the untrusted internet.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:45,000 --> 00:02:47,000
|
| 187 |
+
So it's all encrypted.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:47,000 --> 00:02:48,000
|
| 191 |
+
How does it do it?
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:48,000 --> 00:02:50,000
|
| 195 |
+
Well, it does it by tunnelling.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:51,000 --> 00:02:51,000
|
| 199 |
+
All right.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:51,000 --> 00:02:56,000
|
| 203 |
+
Tunneling means that it encapsulate all the packets inside of something else.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:57,000 --> 00:03:00,000
|
| 207 |
+
When it comes to tunneling, they're basically two tunnels.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:00,000 --> 00:03:06,000
|
| 211 |
+
VPNs utilizes in today's world to transport confidential companies data.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:06,000 --> 00:03:13,000
|
| 215 |
+
We're going to utilize either a TLS tunnel or we're going to be using L2, TCP with IPsec tunnels.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:13,000 --> 00:03:14,000
|
| 219 |
+
All right.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:14,000 --> 00:03:17,000
|
| 223 |
+
Those are going to be the two tunnels that we're going to be needing to know.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:19,000 --> 00:03:26,000
|
| 227 |
+
So the first thing I want to show you is what's called an LL2MLS tunnel or SSL tunnels.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:26,000 --> 00:03:33,000
|
| 231 |
+
These are tunnels or tunnels that are set up utilizing TLS, SSL, the operator layer four of the OSI
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:33,000 --> 00:03:34,000
|
| 235 |
+
model.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:34,000 --> 00:03:40,000
|
| 239 |
+
Now, if you remember from cryptography or if you haven't watched that section yet, go through it.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:40,000 --> 00:03:43,000
|
| 243 |
+
In cryptography, I go through the whole SSL handshake with you.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:43,000 --> 00:03:44,000
|
| 247 |
+
It's very secure.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:44,000 --> 00:03:47,000
|
| 251 |
+
We are using SSL all the time.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:47,000 --> 00:03:50,000
|
| 255 |
+
Every website you go to is protected with SSL.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:50,000 --> 00:03:56,000
|
| 259 |
+
What we're doing is we're encapsulating the VPN traffic or tunneling it into an SSL.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:56,000 --> 00:03:59,000
|
| 263 |
+
Now we're going to use this for encryption.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:59,000 --> 00:04:01,000
|
| 267 |
+
No need to open any additional ports.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:01,000 --> 00:04:05,000
|
| 271 |
+
Mostly use on user access VPN.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:05,000 --> 00:04:06,000
|
| 275 |
+
Now what does that mean.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:06,000 --> 00:04:11,000
|
| 279 |
+
These are going to be VPNs that you use to access a corporate network, not necessarily between site
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:11,000 --> 00:04:19,000
|
| 283 |
+
to site, like my Manhattan location to our Long Island location, maybe just a website or access to
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:19,000 --> 00:04:26,000
|
| 287 |
+
a client that needs access to a client that needs to be installed, something like OpenVPN we also use
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:26,000 --> 00:04:29,000
|
| 291 |
+
as a client, but things like Sonicwall.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:30,000 --> 00:04:32,000
|
| 295 |
+
Has SSL based VPNs.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:32,000 --> 00:04:35,000
|
| 299 |
+
And with that, I'm going to show you guys what that looks like.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:35,000 --> 00:04:39,000
|
| 303 |
+
There's a link there that you guys can try that I have already opened for you.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:39,000 --> 00:04:41,000
|
| 307 |
+
So when you went to that link.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:42,000 --> 00:04:43,000
|
| 311 |
+
Uh, I want to show you.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:43,000 --> 00:04:44,000
|
| 315 |
+
Oh, here we go.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:44,000 --> 00:04:46,000
|
| 319 |
+
So when you guys went to that link.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:48,000 --> 00:04:50,000
|
| 323 |
+
This is a demo of their SSL based VPN.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:50,000 --> 00:04:55,000
|
| 327 |
+
So you would just view the demo and it's going to log you into the VPN.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:55,000 --> 00:04:58,000
|
| 331 |
+
So this is actually what what it looks like.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:04:58,000 --> 00:05:00,000
|
| 335 |
+
It doesn't want to work here for us.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:00,000 --> 00:05:03,000
|
| 339 |
+
Hopefully this works for us.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:04,000 --> 00:05:06,000
|
| 343 |
+
All right demo let's log in.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:06,000 --> 00:05:07,000
|
| 347 |
+
You just demo.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:07,000 --> 00:05:08,000
|
| 351 |
+
And the password is like password.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:08,000 --> 00:05:10,000
|
| 355 |
+
It puts it there for you.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:10,000 --> 00:05:11,000
|
| 359 |
+
So this is a VPN.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:11,000 --> 00:05:13,000
|
| 363 |
+
This is an SSL based VPN.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:13,000 --> 00:05:18,000
|
| 367 |
+
And basically I have access to things like a file share on their network.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:18,000 --> 00:05:21,000
|
| 371 |
+
And I can go in and I can access particular files.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:21,000 --> 00:05:25,000
|
| 375 |
+
As you can see, uh, I can go in and, um.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:26,000 --> 00:05:27,000
|
| 379 |
+
What else more we have here.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:27,000 --> 00:05:30,000
|
| 383 |
+
RDP to a particular computer.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:30,000 --> 00:05:33,000
|
| 387 |
+
Let's say we know what is going to log me into one of their systems.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:33,000 --> 00:05:37,000
|
| 391 |
+
So now look, I'm logging in to a system on their network.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:38,000 --> 00:05:40,000
|
| 395 |
+
This is all done through the web browser, right?
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:40,000 --> 00:05:42,000
|
| 399 |
+
This is all done.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:42,000 --> 00:05:43,000
|
| 403 |
+
This is a computer.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:05:43,000 --> 00:05:43,000
|
| 407 |
+
It's already logged in.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:05:43,000 --> 00:05:45,000
|
| 411 |
+
Is this that screen?
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:05:45,000 --> 00:05:45,000
|
| 415 |
+
See?
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:05:46,000 --> 00:05:50,000
|
| 419 |
+
Yeah, it's a really old system that Sonic was given the demo on old server here.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:05:50,000 --> 00:05:52,000
|
| 423 |
+
So let me close this out.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:05:53,000 --> 00:05:55,000
|
| 427 |
+
So you can access Outlook Web access.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:05:55,000 --> 00:05:58,000
|
| 431 |
+
So it's just a demo that you can set up.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:05:58,000 --> 00:06:00,000
|
| 435 |
+
Now this is great.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:00,000 --> 00:06:05,000
|
| 439 |
+
If you set up a VPN like this, there's really nothing for no one to install.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:05,000 --> 00:06:11,000
|
| 443 |
+
It's heavily secured because it runs on TLS, which is pretty much the standards of all internet security.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:11,000 --> 00:06:17,000
|
| 447 |
+
Now let's talk of another kind of implementation we can implement.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:06:17,000 --> 00:06:20,000
|
| 451 |
+
And that's going to be what's called L2 Tpns.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:20,000 --> 00:06:25,000
|
| 455 |
+
L2 Tpns are layer two tunneling protocol.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:25,000 --> 00:06:32,000
|
| 459 |
+
These are kind of VPNs that were basically a hybrid of what was called L2 f and an older one called
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:32,000 --> 00:06:32,000
|
| 463 |
+
PCP.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:06:33,000 --> 00:06:34,000
|
| 467 |
+
It's basically a point to point tunnel.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:06:34,000 --> 00:06:40,000
|
| 471 |
+
And it utilizes something called IPsec in order to encrypt your data, which we'll talk about in a minute.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:06:40,000 --> 00:06:47,000
|
| 475 |
+
It supports all types of radius are used on like windows boxes or Texas for, uh, Cisco boxes.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:06:47,000 --> 00:06:51,000
|
| 479 |
+
Now, IPsec is something you want to be familiar with for your exam.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:06:51,000 --> 00:06:58,000
|
| 483 |
+
Instead of using something such as TLS to secure your VPN, you can use IPsec.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:06:58,000 --> 00:07:01,000
|
| 487 |
+
IPsec is a standalone VPN protocol.
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:07:01,000 --> 00:07:09,000
|
| 491 |
+
It's the main security anytime you set up L2tpv3, L2, TCP based VPNs, which you could do on my Sonicwall,
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:07:09,000 --> 00:07:11,000
|
| 495 |
+
you're going to use IPsec.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:07:11,000 --> 00:07:16,000
|
| 499 |
+
IPsec comes in a variety of different components that you want to be familiar with for your exam.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:07:16,000 --> 00:07:18,000
|
| 503 |
+
If you're asking, what the hell is all this?
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:07:18,000 --> 00:07:26,000
|
| 507 |
+
Well, when you set it up on the firewall on your VPN devices, particularly things like VPN concentrators,
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:26,000 --> 00:07:32,000
|
| 511 |
+
when you set these things up, like on a VPN concentrator, especially IPsec, you have to determine,
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:32,000 --> 00:07:35,000
|
| 515 |
+
do you want to set it up with RH or ESP?
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:07:35,000 --> 00:07:40,000
|
| 519 |
+
Ideally, you'll do both RH if you configure this, provides authentication.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:07:41,000 --> 00:07:44,000
|
| 523 |
+
Integrity and non-repudiation of the data.
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:44,000 --> 00:07:48,000
|
| 527 |
+
That's important because you don't want anybody to log in authentication.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:48,000 --> 00:07:52,000
|
| 531 |
+
You want to check if the data was modified and you want to be verified where the data is coming from.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:07:53,000 --> 00:07:57,000
|
| 535 |
+
E does not support, uh, encryption of the data.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:07:57,000 --> 00:08:02,000
|
| 539 |
+
It doesn't support confidentiality of data that's going to be encapsulating security payload.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:08:02,000 --> 00:08:03,000
|
| 543 |
+
So make sure you enable both boxes.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:08:03,000 --> 00:08:06,000
|
| 547 |
+
In fact, when you set up a VPN, these two are enabled by default.
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:08:06,000 --> 00:08:16,000
|
| 551 |
+
Now also when you set up these kinds of firewalls, uh, VPNs, especially in IPsec, it runs in two
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:08:16,000 --> 00:08:19,000
|
| 555 |
+
modes tunnel mode and transport mode.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:08:19,000 --> 00:08:20,000
|
| 559 |
+
In tunnel mode.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:08:20,000 --> 00:08:25,000
|
| 563 |
+
What's happening here is that it's it's protecting the IP header.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:08:25,000 --> 00:08:29,000
|
| 567 |
+
Notice this green box right here the IP header I could just highlight it.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:08:29,000 --> 00:08:34,000
|
| 571 |
+
It protects the IP header and trailer and the payload being the data.
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:08:35,000 --> 00:08:43,000
|
| 575 |
+
It encapsulates everything an IP header includes, like the source IP and destination IP in transport
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:08:43,000 --> 00:08:45,000
|
| 579 |
+
mode is just the payload that's being detected.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:08:45,000 --> 00:08:47,000
|
| 583 |
+
The final destination is visible.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:08:47,000 --> 00:08:55,000
|
| 587 |
+
So if you're going across a network where you control all the routers so it can encrypt and decrypt
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:08:55,000 --> 00:08:59,000
|
| 591 |
+
the packet at every one of the routers, then it's okay to use tunnel mode.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:08:59,000 --> 00:09:03,000
|
| 595 |
+
But if it has to go across a network that you can't control, you're probably going to set it up in
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:09:03,000 --> 00:09:05,000
|
| 599 |
+
transport mode.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:09:05,000 --> 00:09:06,000
|
| 603 |
+
Now.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:09:07,000 --> 00:09:10,000
|
| 607 |
+
When it comes to setting up a VPN.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:09:10,000 --> 00:09:12,000
|
| 611 |
+
In today's world.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:09:12,000 --> 00:09:18,000
|
| 615 |
+
As of right now, as I speak to you, more and more VPNs are being deployed with TLS setup, and the
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:09:18,000 --> 00:09:23,000
|
| 619 |
+
reason for that is because TLS doesn't require you to open a bunch of ports.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:09:23,000 --> 00:09:29,000
|
| 623 |
+
Like if you want to set up an L2, TCP based VPN, it's much easier to configure and more familiar to
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:09:29,000 --> 00:09:30,000
|
| 627 |
+
users.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:09:30,000 --> 00:09:35,000
|
| 631 |
+
And just like you saw with the Sonicwall, you could pretty much run it off of your browser versus L2.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:09:35,000 --> 00:09:40,000
|
| 635 |
+
TCP based VPNs almost always have to have you install a client on the machine.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:09:40,000 --> 00:09:43,000
|
| 639 |
+
That client needs to be configured.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:09:43,000 --> 00:09:49,000
|
| 643 |
+
Different types of L2, TCP, or VPN keys needs to be set up on the machine, so it's much more of an
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:09:49,000 --> 00:09:54,000
|
| 647 |
+
administrative work if you control the machines like the clients, like the clients that people are
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:09:54,000 --> 00:09:57,000
|
| 651 |
+
using at home is owned by the company.
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:09:57,000 --> 00:09:59,000
|
| 655 |
+
The company sets it up and they can't do anything on that machine.
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:09:59,000 --> 00:10:00,000
|
| 659 |
+
But companies work.
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:10:00,000 --> 00:10:03,000
|
| 663 |
+
Then it's probably okay to use an L2, TCP based VPN.
|
| 664 |
+
|
| 665 |
+
167
|
| 666 |
+
00:10:03,000 --> 00:10:10,000
|
| 667 |
+
If not, if people are working from home and they're utilizing their own machine, the best thing to
|
| 668 |
+
|
| 669 |
+
168
|
| 670 |
+
00:10:10,000 --> 00:10:14,000
|
| 671 |
+
do is use a TLS or SSL VPN.
|
| 672 |
+
|
11 - Security Principles/015 SD-WAN OB 3.2_en.srt
ADDED
|
@@ -0,0 +1,228 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:04,000
|
| 3 |
+
In today's world, networking is becoming crazy complex.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:04,000 --> 00:00:10,000
|
| 7 |
+
You see, back in the days when you worked in a large network, you had generally one data center that
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:10,000 --> 00:00:14,000
|
| 11 |
+
the company controlled and all the other branch offices would connect to it.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:15,000 --> 00:00:18,000
|
| 15 |
+
But today it's a lot complex.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:18,000 --> 00:00:19,000
|
| 19 |
+
And I want to show you a diagram.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:20,000 --> 00:00:25,000
|
| 23 |
+
Now I want you guys to forget all the connection into the cloud for now.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:25,000 --> 00:00:30,000
|
| 27 |
+
I want you guys just to look at this thing here with just where it says data center.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:30,000 --> 00:00:36,000
|
| 31 |
+
Back in the days when we had set up networks, what we would do is we would just have every branch would
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:36,000 --> 00:00:43,000
|
| 35 |
+
connect to the data center, like this branch here would connect to the data center, this branch data
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:43,000 --> 00:00:45,000
|
| 39 |
+
center, this branch data center, this branch, this branch, this branch.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:46,000 --> 00:00:48,000
|
| 43 |
+
And everything was like a centralized thing.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:49,000 --> 00:00:52,000
|
| 47 |
+
But now it's all over the place.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:52,000 --> 00:01:00,000
|
| 51 |
+
Right now the applications are in the cloud all over, split across different cloud based systems.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:01:00,000 --> 00:01:06,000
|
| 55 |
+
The applications are stored partially in the data center and partially in the cloud.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:06,000 --> 00:01:08,000
|
| 59 |
+
Now branch offices are going to the cloud.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:08,000 --> 00:01:10,000
|
| 63 |
+
They're also going to the data center.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:10,000 --> 00:01:12,000
|
| 67 |
+
Some of the app is in the cloud.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:12,000 --> 00:01:14,000
|
| 71 |
+
Some of it is in the data center.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:14,000 --> 00:01:17,000
|
| 75 |
+
Some of the policies in the data center, some of the policy in the cloud.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:17,000 --> 00:01:20,000
|
| 79 |
+
This can get complex very fast, very quick.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:20,000 --> 00:01:22,000
|
| 83 |
+
So there's a couple of things here.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:23,000 --> 00:01:26,000
|
| 87 |
+
Let's talk about software defined networking.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:26,000 --> 00:01:35,000
|
| 91 |
+
Software defined networking is basically to simplify a branch office networking and get optimal application
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:35,000 --> 00:01:36,000
|
| 95 |
+
performance.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:36,000 --> 00:01:42,000
|
| 99 |
+
It provides a centralized control function to securely and intelligently intelligently transfer network
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:42,000 --> 00:01:43,000
|
| 103 |
+
traffic.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:43,000 --> 00:01:46,000
|
| 107 |
+
What I need you guys to know for your exam is this.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:46,000 --> 00:01:52,000
|
| 111 |
+
This thing overlays your network and what it does is that it's going to allow for efficient network,
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:52,000 --> 00:02:01,000
|
| 115 |
+
um, traffic that allows applications to be used correctly and efficiently, making data routing more
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:02:01,000 --> 00:02:02,000
|
| 119 |
+
efficient.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:02,000 --> 00:02:06,000
|
| 123 |
+
You see, if we don't have this, the data routing would be all over the.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:06,000 --> 00:02:10,000
|
| 127 |
+
They would have to go and pull some of the data from the cloud and pull it, some of it from the data
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:10,000 --> 00:02:10,000
|
| 131 |
+
center.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:11,000 --> 00:02:17,000
|
| 135 |
+
Another thing you want to have in here when you set this up is sassy SASE.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:17,000 --> 00:02:20,000
|
| 139 |
+
It stands for Secure Access Service Edge.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:20,000 --> 00:02:22,000
|
| 143 |
+
This is a cloud native network and architect.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:22,000 --> 00:02:26,000
|
| 147 |
+
It combines network security functions with Wan capability.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:26,000 --> 00:02:31,000
|
| 151 |
+
It merges the SD SD-Wan capabilities with security services.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:31,000 --> 00:02:32,000
|
| 155 |
+
What is it doing?
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:32,000 --> 00:02:38,000
|
| 159 |
+
Well, this is going to allow those tunnels that you see between those connections to become encrypted,
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:38,000 --> 00:02:41,000
|
| 163 |
+
to connect them to cloud based services, to make them more efficient.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:41,000 --> 00:02:44,000
|
| 167 |
+
So let's go back here and talk more about this.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:45,000 --> 00:02:47,000
|
| 171 |
+
So when you set up things like SD-Wan.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:47,000 --> 00:02:53,000
|
| 175 |
+
SD-Wan is going to allow you to efficiently utilize all types of network connections.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:55,000 --> 00:02:57,000
|
| 179 |
+
All types of multiple connections.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:57,000 --> 00:03:02,000
|
| 183 |
+
So imagine you're sitting in this branch office and you need to access some of the applications in the
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:03:02,000 --> 00:03:04,000
|
| 187 |
+
cloud, some of it in the data center.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:03:04,000 --> 00:03:06,000
|
| 191 |
+
Applications can even be split apart.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:06,000 --> 00:03:10,000
|
| 195 |
+
Now you have SD-Wan, comes in, sets up a variety.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:10,000 --> 00:03:16,000
|
| 199 |
+
It's it's a type of software defined networking or Sdn that allows it.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:16,000 --> 00:03:21,000
|
| 203 |
+
It's basically a higher controller level that sits over all these connections and determines the best,
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:21,000 --> 00:03:25,000
|
| 207 |
+
most efficient and secure path to get through the data.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:25,000 --> 00:03:27,000
|
| 211 |
+
If you're wondering, why do we do all this?
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:27,000 --> 00:03:34,000
|
| 215 |
+
Well, imagine right now how complex networking is without getting too technical and in depth into it,
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:34,000 --> 00:03:36,000
|
| 219 |
+
because you don't need it basically for your exam.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:36,000 --> 00:03:38,000
|
| 223 |
+
What this really is going to allow you to do?
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:39,000 --> 00:03:44,000
|
| 227 |
+
All the apps the company is using is is going to make it faster and more secure to use.
|
| 228 |
+
|
11 - Security Principles/016 Selecting Effective Controls OB 3.2_en.srt
ADDED
|
@@ -0,0 +1,400 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:07,000
|
| 3 |
+
So far we have seen quite a lot of different security security network appliances that we can implement.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:07,000 --> 00:00:13,000
|
| 7 |
+
But there's a couple of things that we got to think about selecting the effective controls, selecting
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:13,000 --> 00:00:21,000
|
| 11 |
+
the right amount of security to apply to a network, selecting the right device that we have to put
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:21,000 --> 00:00:28,000
|
| 15 |
+
in our network, selecting the right configuration that we put onto these devices.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:28,000 --> 00:00:31,000
|
| 19 |
+
So in this video we want to talk about selecting effective controls.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:31,000 --> 00:00:36,000
|
| 23 |
+
What is the process of identifying and implementing the right security measure for your organization.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:37,000 --> 00:00:40,000
|
| 27 |
+
Now this is going to get very complex.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:40,000 --> 00:00:43,000
|
| 31 |
+
Every single organization is built differently.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:43,000 --> 00:00:45,000
|
| 35 |
+
Every organization has assets of different value.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:45,000 --> 00:00:48,000
|
| 39 |
+
Every organization values assets differently.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:48,000 --> 00:00:53,000
|
| 43 |
+
Some organization doesn't have much value on their data on their.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:53,000 --> 00:00:54,000
|
| 47 |
+
Because you know why?
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:54,000 --> 00:00:56,000
|
| 51 |
+
Well, maybe some of the employee data.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:56,000 --> 00:01:00,000
|
| 55 |
+
But the company's main data don't really put a value on because it's all public knowledge.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:00,000 --> 00:01:01,000
|
| 59 |
+
Think of like a.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:02,000 --> 00:01:03,000
|
| 63 |
+
Like something on.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:03,000 --> 00:01:04,000
|
| 67 |
+
If you're managing Wikipedia.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:04,000 --> 00:01:08,000
|
| 71 |
+
All the data that Wikipedia have, it's pretty much public data.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:08,000 --> 00:01:13,000
|
| 75 |
+
The only thing that's private is their credit card information that they collect and the employee resources.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:13,000 --> 00:01:16,000
|
| 79 |
+
But if you work for the military, it's vastly different.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:16,000 --> 00:01:23,000
|
| 83 |
+
Everything there, most of it, especially like in the NSA, it's all private or top secret information
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:23,000 --> 00:01:24,000
|
| 87 |
+
versus Wikipedia.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:24,000 --> 00:01:31,000
|
| 91 |
+
90% of what they collect is public data, vast differences between organization and what they value,
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:31,000 --> 00:01:33,000
|
| 95 |
+
vast differences on how they value it.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:33,000 --> 00:01:38,000
|
| 99 |
+
So when you select security controls, these are things you have to consider.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:38,000 --> 00:01:42,000
|
| 103 |
+
And that starts with a risk assessment starts with a thorough risk assessment.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:42,000 --> 00:01:49,000
|
| 107 |
+
What exactly identify what exact risks do you guys face and how do you want to mitigate those potential
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:49,000 --> 00:01:50,000
|
| 111 |
+
threats?
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:51,000 --> 00:01:54,000
|
| 115 |
+
I mentioned at the beginning of this course Layered Defense.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:55,000 --> 00:01:57,000
|
| 119 |
+
You have to implement a variety of different controls.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:57,000 --> 00:01:59,000
|
| 123 |
+
No single point.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:00,000 --> 00:02:00,000
|
| 127 |
+
All right.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:00,000 --> 00:02:01,000
|
| 131 |
+
No single.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:01,000 --> 00:02:02,000
|
| 135 |
+
Everything needs layered.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:02,000 --> 00:02:03,000
|
| 139 |
+
Layered approach.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:03,000 --> 00:02:07,000
|
| 143 |
+
And what you should be consideration is what are the different layers.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:07,000 --> 00:02:08,000
|
| 147 |
+
How are you going to layer them?
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:08,000 --> 00:02:13,000
|
| 151 |
+
You may have cameras in different locations and maybe you need security guard and cameras.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:13,000 --> 00:02:19,000
|
| 155 |
+
Maybe you you have particularly, uh, doors that are built a certain way and you don't have security
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:19,000 --> 00:02:21,000
|
| 159 |
+
guards, things to consider.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:21,000 --> 00:02:28,000
|
| 163 |
+
But if there's one thing I know, but living long enough in this world, a lot of times the consideration
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:28,000 --> 00:02:31,000
|
| 167 |
+
may come to selecting the right controls for your business.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:31,000 --> 00:02:36,000
|
| 171 |
+
Unfortunately, almost always comes back to money.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:37,000 --> 00:02:38,000
|
| 175 |
+
Evaluating the course.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:38,000 --> 00:02:42,000
|
| 179 |
+
What is the cost of implementing a control against the potential risk benefit that is given?
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:43,000 --> 00:02:48,000
|
| 183 |
+
If there's one thing we're going to talk about when we get to a risk assessment is can't spend $10,
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:48,000 --> 00:02:51,000
|
| 187 |
+
protecting $5 doesn't make sense.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:51,000 --> 00:02:58,000
|
| 191 |
+
A lot of times, the control that we select, the kind of firewall that we implement, the kind of IDs
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:58,000 --> 00:03:06,000
|
| 195 |
+
that we put into place, um, whether we have a load balancer, the type of VPN we set up, a lot of
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:06,000 --> 00:03:08,000
|
| 199 |
+
these things are going to be determined basically.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:08,000 --> 00:03:09,000
|
| 203 |
+
And do you have the budget for it?
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:09,000 --> 00:03:10,000
|
| 207 |
+
Yeah.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:10,000 --> 00:03:16,000
|
| 211 |
+
We all want the latest and greatest engine firewall, but we can't afford it because it's super expensive.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:16,000 --> 00:03:19,000
|
| 215 |
+
So you have to be able to understand that cost is a big thing.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:19,000 --> 00:03:24,000
|
| 219 |
+
Another thing that you have to really keep in consideration is regulation.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:24,000 --> 00:03:30,000
|
| 223 |
+
Certain regulations will make it mandatory for you to encrypt and store certain data in a certain way.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:30,000 --> 00:03:35,000
|
| 227 |
+
For example, in HIPAA regulation, you're going to have to secure a certain medical records.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:35,000 --> 00:03:37,000
|
| 231 |
+
If you follow PCI compliance.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:37,000 --> 00:03:41,000
|
| 235 |
+
This is a kind of a standard that you're going to have to encrypt credit card information.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:41,000 --> 00:03:47,000
|
| 239 |
+
So the controls you select their technical stability, assessing the technical capability of feasibilities
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:47,000 --> 00:03:47,000
|
| 243 |
+
controls.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:47,000 --> 00:03:49,000
|
| 247 |
+
Can you even implement it?
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:49,000 --> 00:03:55,000
|
| 251 |
+
Does your environment even support a particular control that you want to implement every time you implement
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:55,000 --> 00:03:59,000
|
| 255 |
+
a particular risk, maybe a new kind of firewall or a load balancer or something?
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:04:00,000 --> 00:04:07,000
|
| 259 |
+
You know it identifies more risk into the organization's control, should be directly relevant for the
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:07,000 --> 00:04:09,000
|
| 263 |
+
risk that they're implementing does.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:10,000 --> 00:04:16,000
|
| 267 |
+
And the other thing is that if you implement this control, does it result in reducing a particular
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:16,000 --> 00:04:18,000
|
| 271 |
+
risk, the risk of hackers breaking in?
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:18,000 --> 00:04:19,000
|
| 275 |
+
So you put a firewall in place.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:19,000 --> 00:04:21,000
|
| 279 |
+
Does the firewall address that?
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:22,000 --> 00:04:27,000
|
| 283 |
+
The risk of a worm spreading around inside of a network.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:27,000 --> 00:04:28,000
|
| 287 |
+
Does the firewall address that?
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:28,000 --> 00:04:32,000
|
| 291 |
+
Well, network firewalls generally is not going to stop a worm from spreading around inside of the network
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:32,000 --> 00:04:33,000
|
| 295 |
+
if it's already there.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:33,000 --> 00:04:35,000
|
| 299 |
+
Host based firewalls does.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:35,000 --> 00:04:42,000
|
| 303 |
+
So you have to make sure that the what you're implementing addresses that risk stability and adaptability.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:42,000 --> 00:04:44,000
|
| 307 |
+
Controls should be able to scale with the company.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:44,000 --> 00:04:52,000
|
| 311 |
+
Don't buy a particular appliance, and it's only good for 100 users in the company right now is at 80,
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:52,000 --> 00:04:53,000
|
| 315 |
+
and it's going to go to 200in a few months.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:53,000 --> 00:04:54,000
|
| 319 |
+
That's not scalable.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:55,000 --> 00:05:01,000
|
| 323 |
+
Always evaluate regular monitor, review and update these types of controls for effectiveness is going
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:05:01,000 --> 00:05:02,000
|
| 327 |
+
to be important.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:05:02,000 --> 00:05:04,000
|
| 331 |
+
Monitor your environment.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:05:05,000 --> 00:05:15,000
|
| 335 |
+
If there's one thing we know in it that sometimes I can't stand is the constant nonstop change of technology,
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:15,000 --> 00:05:21,000
|
| 339 |
+
such as different kinds of software, hardware, different kinds of attacks that comes out, pushes
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:21,000 --> 00:05:26,000
|
| 343 |
+
us to consistently modify and change the technology that we work in.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:27,000 --> 00:05:28,000
|
| 347 |
+
Our environments will change.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:28,000 --> 00:05:35,000
|
| 351 |
+
Whatever it secure environment that you're working in right now will not will cease to exist and completely
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:35,000 --> 00:05:38,000
|
| 355 |
+
do a major change.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:39,000 --> 00:05:45,000
|
| 359 |
+
I guarantee you, within the next 5 to 8 years on on a general rotation, every 5 to 8 years, the whole
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:45,000 --> 00:05:46,000
|
| 363 |
+
thing will change.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:46,000 --> 00:05:51,000
|
| 367 |
+
All technology changes, all the operating systems will change, all the devices will change.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:51,000 --> 00:05:55,000
|
| 371 |
+
For example, Sonicwall is not going to allow us to keep using this particular device because they're
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:55,000 --> 00:05:56,000
|
| 375 |
+
going to say it's outdated.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:56,000 --> 00:05:57,000
|
| 379 |
+
We'll have to get a new one.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:58,000 --> 00:06:04,000
|
| 383 |
+
So the and a consistent changes is the control effective new attacks will come out.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:06:04,000 --> 00:06:05,000
|
| 387 |
+
And then what are you going to do.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:06:05,000 --> 00:06:09,000
|
| 391 |
+
You're going to have to update your devices, update your software.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:06:09,000 --> 00:06:13,000
|
| 395 |
+
If there's one thing that's a constant when it managing security.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:06:13,000 --> 00:06:19,000
|
| 399 |
+
One thing that's that's a constant when managing security uh, is change.
|
| 400 |
+
|
11 - Security Principles/017 Quick Quiz.html
ADDED
|
@@ -0,0 +1,479 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
<!DOCTYPE html>
|
| 2 |
+
<html lang="en">
|
| 3 |
+
<head>
|
| 4 |
+
<meta charset="UTF-8" />
|
| 5 |
+
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
|
| 6 |
+
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
| 7 |
+
<title>Quiz</title>
|
| 8 |
+
<style>
|
| 9 |
+
* {
|
| 10 |
+
font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
|
| 11 |
+
"Open Sans", "Helvetica Neue", sans-serif;
|
| 12 |
+
margin: 0;
|
| 13 |
+
padding: 0;
|
| 14 |
+
box-sizing: border-box;
|
| 15 |
+
font-size: 16px;
|
| 16 |
+
}
|
| 17 |
+
|
| 18 |
+
main {
|
| 19 |
+
padding-top: 48px;
|
| 20 |
+
}
|
| 21 |
+
|
| 22 |
+
:root {
|
| 23 |
+
--large-device-width: 850px;
|
| 24 |
+
--primary-color: #0f172a;
|
| 25 |
+
--secondary-color: #020617;
|
| 26 |
+
--primary-text-color: #c7d1dd;
|
| 27 |
+
--secondary-text-color: #061602;
|
| 28 |
+
--success-background: hsl(159, 82%, 24%);
|
| 29 |
+
--success-foreground: hsl(164, 86%, 16%);
|
| 30 |
+
--success: hsl(160, 84%, 39%);
|
| 31 |
+
--danger: #ef4444;
|
| 32 |
+
--warning: #f59e0b;
|
| 33 |
+
--info-background: hsl(218, 81%, 8%);
|
| 34 |
+
--info-foreground: hsl(217, 91%, 85%);
|
| 35 |
+
--border-color: #d1d7dc;
|
| 36 |
+
--check-box-size: 20px;
|
| 37 |
+
/* control the size */
|
| 38 |
+
--check-box-color: var(--info-foreground);
|
| 39 |
+
/* the active color */
|
| 40 |
+
}
|
| 41 |
+
|
| 42 |
+
body {
|
| 43 |
+
position: relative;
|
| 44 |
+
background-color: #020617;
|
| 45 |
+
color: var(--primary-text-color);
|
| 46 |
+
}
|
| 47 |
+
|
| 48 |
+
#score-stats-container {
|
| 49 |
+
position: fixed;
|
| 50 |
+
z-index: 10;
|
| 51 |
+
top: 0;
|
| 52 |
+
height: 40px;
|
| 53 |
+
width: 100%;
|
| 54 |
+
background-color: var(--info-background);
|
| 55 |
+
|
| 56 |
+
padding: 0px 16px;
|
| 57 |
+
color: var(--info-foreground);
|
| 58 |
+
font-weight: 600;
|
| 59 |
+
display: flex;
|
| 60 |
+
align-items: center;
|
| 61 |
+
justify-content: space-between;
|
| 62 |
+
}
|
| 63 |
+
|
| 64 |
+
#quiz-container {
|
| 65 |
+
border-radius: 8px;
|
| 66 |
+
display: flex;
|
| 67 |
+
gap: 16px;
|
| 68 |
+
flex-direction: column;
|
| 69 |
+
}
|
| 70 |
+
|
| 71 |
+
input[type="radio"] {
|
| 72 |
+
height: var(--check-box-size);
|
| 73 |
+
aspect-ratio: 1;
|
| 74 |
+
border: calc(var(--check-box-size) / 8) solid #939393;
|
| 75 |
+
padding: calc(var(--check-box-size) / 8);
|
| 76 |
+
background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
|
| 77 |
+
content-box;
|
| 78 |
+
border-radius: 50%;
|
| 79 |
+
outline-offset: calc(var(--check-box-size) / 10);
|
| 80 |
+
-webkit-appearance: none;
|
| 81 |
+
-moz-appearance: none;
|
| 82 |
+
appearance: none;
|
| 83 |
+
cursor: pointer;
|
| 84 |
+
font-size: inherit;
|
| 85 |
+
transition: 0.3s;
|
| 86 |
+
}
|
| 87 |
+
|
| 88 |
+
input[type="radio"]:checked {
|
| 89 |
+
border-color: var(--check-box-color);
|
| 90 |
+
background-size: 100% 100%;
|
| 91 |
+
}
|
| 92 |
+
|
| 93 |
+
input[type="radio"]:disabled {
|
| 94 |
+
background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
|
| 95 |
+
opacity: 0.5;
|
| 96 |
+
cursor: not-allowed;
|
| 97 |
+
}
|
| 98 |
+
|
| 99 |
+
label {
|
| 100 |
+
display: inline-flex;
|
| 101 |
+
align-items: center;
|
| 102 |
+
gap: 10px;
|
| 103 |
+
cursor: pointer;
|
| 104 |
+
padding: 4px 6px;
|
| 105 |
+
border-radius: 4px;
|
| 106 |
+
}
|
| 107 |
+
|
| 108 |
+
@media (max-width: 767px) {
|
| 109 |
+
input[type="radio"],
|
| 110 |
+
label {
|
| 111 |
+
cursor: default;
|
| 112 |
+
}
|
| 113 |
+
|
| 114 |
+
#quiz-container {
|
| 115 |
+
margin-left: 8px;
|
| 116 |
+
margin-right: 8px;
|
| 117 |
+
}
|
| 118 |
+
}
|
| 119 |
+
|
| 120 |
+
/* PC (Desktop devices) */
|
| 121 |
+
@media (min-width: 768px) {
|
| 122 |
+
body {
|
| 123 |
+
display: flex;
|
| 124 |
+
justify-content: center;
|
| 125 |
+
}
|
| 126 |
+
|
| 127 |
+
main {
|
| 128 |
+
max-width: var(--large-device-width);
|
| 129 |
+
}
|
| 130 |
+
|
| 131 |
+
#score-stats-container {
|
| 132 |
+
max-width: var(--large-device-width);
|
| 133 |
+
}
|
| 134 |
+
|
| 135 |
+
dialog {
|
| 136 |
+
max-width: var(--large-device-width);
|
| 137 |
+
}
|
| 138 |
+
}
|
| 139 |
+
|
| 140 |
+
@media print {
|
| 141 |
+
input[type="radio"] {
|
| 142 |
+
background: none !important;
|
| 143 |
+
border-color: #939393 !important;
|
| 144 |
+
}
|
| 145 |
+
|
| 146 |
+
input[type="radio"]:checked {
|
| 147 |
+
border-color: #939393 !important;
|
| 148 |
+
}
|
| 149 |
+
}
|
| 150 |
+
|
| 151 |
+
.question-lable {
|
| 152 |
+
display: flex;
|
| 153 |
+
align-items: center;
|
| 154 |
+
gap: 8px;
|
| 155 |
+
}
|
| 156 |
+
|
| 157 |
+
button {
|
| 158 |
+
-webkit-tap-highlight-color: transparent;
|
| 159 |
+
-webkit-touch-callout: none;
|
| 160 |
+
-webkit-user-select: none;
|
| 161 |
+
user-select: none;
|
| 162 |
+
outline: none;
|
| 163 |
+
position: relative;
|
| 164 |
+
overflow: hidden;
|
| 165 |
+
cursor: pointer;
|
| 166 |
+
}
|
| 167 |
+
|
| 168 |
+
.button {
|
| 169 |
+
background-color: var(--success-background);
|
| 170 |
+
border: none;
|
| 171 |
+
color: #f4f5f7;
|
| 172 |
+
opacity: 0.8;
|
| 173 |
+
font-size: 18px;
|
| 174 |
+
flex-grow: 1;
|
| 175 |
+
padding: 8px 16px;
|
| 176 |
+
border-radius: 8px;
|
| 177 |
+
}
|
| 178 |
+
|
| 179 |
+
.button:hover {
|
| 180 |
+
opacity: 1;
|
| 181 |
+
}
|
| 182 |
+
|
| 183 |
+
.explanation-btn {
|
| 184 |
+
border: none;
|
| 185 |
+
color: var(--success);
|
| 186 |
+
background-color: transparent;
|
| 187 |
+
}
|
| 188 |
+
|
| 189 |
+
#submit-button:active::after {
|
| 190 |
+
background-color: #ef4444;
|
| 191 |
+
}
|
| 192 |
+
|
| 193 |
+
.single-question-container {
|
| 194 |
+
background-color: var(--primary-color);
|
| 195 |
+
display: flex;
|
| 196 |
+
flex-direction: column;
|
| 197 |
+
gap: 8px;
|
| 198 |
+
padding: 16px;
|
| 199 |
+
border-radius: 8px;
|
| 200 |
+
}
|
| 201 |
+
|
| 202 |
+
#modal-content {
|
| 203 |
+
padding: 16px;
|
| 204 |
+
line-height: 24px;
|
| 205 |
+
}
|
| 206 |
+
|
| 207 |
+
dialog::backdrop {
|
| 208 |
+
background: rgba(0, 0, 0, 0.5);
|
| 209 |
+
}
|
| 210 |
+
|
| 211 |
+
dialog {
|
| 212 |
+
position: fixed;
|
| 213 |
+
border: 1px solid var(--border-color);
|
| 214 |
+
background-color: var(--primary-color);
|
| 215 |
+
color: rgb(240, 241, 248);
|
| 216 |
+
padding: 16px;
|
| 217 |
+
border-radius: 8px;
|
| 218 |
+
width: 80vw;
|
| 219 |
+
max-height: 80vh;
|
| 220 |
+
overflow: auto;
|
| 221 |
+
top: 50%;
|
| 222 |
+
left: 50%;
|
| 223 |
+
-webkit-transform: translateX(-50%) translateY(-50%);
|
| 224 |
+
-moz-transform: translateX(-50%) translateY(-50%);
|
| 225 |
+
-ms-transform: translateX(-50%) translateY(-50%);
|
| 226 |
+
transform: translateX(-50%) translateY(-50%);
|
| 227 |
+
}
|
| 228 |
+
|
| 229 |
+
#close-modal-btn {
|
| 230 |
+
position: absolute;
|
| 231 |
+
top: 4px;
|
| 232 |
+
right: 4px;
|
| 233 |
+
padding: 2px 8px;
|
| 234 |
+
border-radius: 2px;
|
| 235 |
+
border: none;
|
| 236 |
+
background-color: var(--danger);
|
| 237 |
+
}
|
| 238 |
+
|
| 239 |
+
.correct-answer label {
|
| 240 |
+
border: 2px solid var(--success);
|
| 241 |
+
width: 100%;
|
| 242 |
+
}
|
| 243 |
+
|
| 244 |
+
.incorrect-answer label {
|
| 245 |
+
border: 2px solid var(--danger);
|
| 246 |
+
width: 100%;
|
| 247 |
+
}
|
| 248 |
+
|
| 249 |
+
.options-container {
|
| 250 |
+
display: flex;
|
| 251 |
+
flex-direction: column;
|
| 252 |
+
gap: 4px;
|
| 253 |
+
}
|
| 254 |
+
|
| 255 |
+
#quiz-meta-container {
|
| 256 |
+
border-radius: 8px;
|
| 257 |
+
background-color: var(--primary-color);
|
| 258 |
+
margin-bottom: 12px;
|
| 259 |
+
padding: 8px;
|
| 260 |
+
}
|
| 261 |
+
|
| 262 |
+
#quiz-title {
|
| 263 |
+
text-align: center;
|
| 264 |
+
font-size: 24px;
|
| 265 |
+
margin-bottom: 8px;
|
| 266 |
+
}
|
| 267 |
+
|
| 268 |
+
#quiz-description {
|
| 269 |
+
line-height: 1.5;
|
| 270 |
+
padding: 2px 6px;
|
| 271 |
+
}
|
| 272 |
+
</style>
|
| 273 |
+
</head>
|
| 274 |
+
|
| 275 |
+
<body onload="main()">
|
| 276 |
+
<main>
|
| 277 |
+
<section id="quiz-meta-container">
|
| 278 |
+
<h1 id="quiz-title"></h1>
|
| 279 |
+
<p id="quiz-description"></p>
|
| 280 |
+
</section>
|
| 281 |
+
<section id="score-stats-container">
|
| 282 |
+
<div id="score-card">
|
| 283 |
+
Score: <span id="current-score">999</span> of
|
| 284 |
+
<span id="pass-percent">999%</span>
|
| 285 |
+
</div>
|
| 286 |
+
<div>Correct: <span id="correct-answers">999</span></div>
|
| 287 |
+
<div>Incorrect: <span id="wrong-answers">999</span></div>
|
| 288 |
+
</section>
|
| 289 |
+
|
| 290 |
+
<section id="quiz-container"></section>
|
| 291 |
+
|
| 292 |
+
<dialog id="modal" class="modal-container">
|
| 293 |
+
<div id="modal-content">
|
| 294 |
+
<p id="modal-text"></p>
|
| 295 |
+
</div>
|
| 296 |
+
</dialog>
|
| 297 |
+
</main>
|
| 298 |
+
|
| 299 |
+
<script>
|
| 300 |
+
const quizData = {"quiz_id": 6180138, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74728886, "assessment_type": "multiple-choice", "prompt": {"question": "<p>An organization decides to implement a system that segregates its network into different segments based on the function and security level. What is this an example of?</p>", "relatedLectureIds": "", "feedbacks": ["", "This scenario exemplifies the implementation of Security zones. By segregating the network into different segments based on function and security level, the organization can apply appropriate security measures for each zone, thereby enhancing overall security and managing risks more effectively. This differs from Device placement, which is about the strategic positioning of physical devices, and Attack surface, which refers to the total number of points where an unauthorized user can try to enter data or extract data.", "", ""], "answers": ["<p>Device placement</p>", "<p>Security zones</p>", "<p>Attack surface</p>", "<p>Connectivity</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "An organization decides to implement a system that segregates its network into different segments based on the function and security level. What is this an example of?", "related_lectures": []}, {"_class": "assessment", "id": 74728890, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A company's network automatically shuts down its connection when a system failure is detected to prevent potential security breaches. What type of failure mode does this represent?</p>", "relatedLectureIds": "", "feedbacks": ["", "This scenario represents a Fail-closed failure mode. In a fail-closed setup, when a system failure is detected, the network automatically shuts down its connection, which prevents potential security breaches during the downtime. This contrasts with Fail-open, where the system remains operational even after detecting a failure, potentially exposing it to security risks.", "", ""], "answers": ["<p>Fail-open</p>", "<p>Fail-closed</p>", "<p>Active device attribute</p>", "<p>Inline device placement</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A company's network automatically shuts down its connection when a system failure is detected to prevent potential security breaches. What type of failure mode does this represent?", "related_lectures": []}, {"_class": "assessment", "id": 74728896, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A company uses a technology that inspects incoming and outgoing network traffic and blocks potential threats based on a set of security rules. What is this technology?</p>", "relatedLectureIds": "", "feedbacks": ["", "This scenario describes an Intrusion Prevention System (IPS). An IPS monitors network traffic to detect and prevent identified threats, acting based on predefined security rules. This is distinct from a Proxy server, which acts as an intermediary for requests from clients, a Load balancer, which distributes network traffic across multiple servers, and a Jump server, used as a secure and controlled entry point to a remote network.", "", ""], "answers": ["<p>Proxy server</p>", "<p>Intrusion Prevention System (IPS)</p>", "<p>Load balancer</p>", "<p>Jump server</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A company uses a technology that inspects incoming and outgoing network traffic and blocks potential threats based on a set of security rules. What is this technology?", "related_lectures": []}, {"_class": "assessment", "id": 74728898, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A large corporation employs a solution that allows its employees to securely access the company's internal network from remote locations. What does this represent?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "This scenario represents the use of a Virtual Private Network (VPN). A VPN allows secure access to a private network over the internet, enabling employees to access internal network resources remotely while maintaining data security and privacy. This is different from general Remote access, which can include non-VPN methods, Tunneling, which is a broader concept often part of VPN technology, and SD-WAN, which is a more specific approach to managing wide-area networks.", ""], "answers": ["<p>Remote access</p>", "<p>Tunneling</p>", "<p>Virtual Private Network (VPN)</p>", "<p>Software-defined wide area network (SD-WAN)</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "A large corporation employs a solution that allows its employees to securely access the company's internal network from remote locations. What does this represent?", "related_lectures": []}, {"_class": "assessment", "id": 74728906, "assessment_type": "multiple-choice", "prompt": {"question": "<p>To enhance network security, a company implements a switch that requires devices to be authenticated before they can access the network. What technology is being used?</p>", "relatedLectureIds": "", "feedbacks": ["This scenario describes the use of Port security with 802.1X. The 802.1X standard is used to control network access, requiring devices to be authenticated before they can access the network. This helps in preventing unauthorized devices from connecting to the network. EAP is a protocol used in network access authentication, but 802.1X specifically refers to the port-based network access control.", "", "", ""], "answers": ["<p>Port security with 802.1X</p>", "<p>EAP (Extensible Authentication Protocol)</p>", "<p>Firewall</p>", "<p>Jump server</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "To enhance network security, a company implements a switch that requires devices to be authenticated before they can access the network. What technology is being used?", "related_lectures": []}]};
|
| 301 |
+
let correct = new Set();
|
| 302 |
+
let incorrect = new Set();
|
| 303 |
+
let totalNumberOfQuestions = 0;
|
| 304 |
+
const quizTitle = quizData.quiz_title;
|
| 305 |
+
const quizDescription = quizData.quiz_description;
|
| 306 |
+
const questionData = quizData.questions;
|
| 307 |
+
const passPercent = quizData.pass_percent;
|
| 308 |
+
const modalTextElement = document.getElementById("modal-text");
|
| 309 |
+
const quizContainerElement = document.getElementById("quiz-container");
|
| 310 |
+
|
| 311 |
+
const dialog = document.querySelector("dialog");
|
| 312 |
+
const showButton = document.getElementById("view-explanatin");
|
| 313 |
+
const closeButton = document.getElementById("close-modal-btn");
|
| 314 |
+
const quizTitleElement = document.getElementById("quiz-title");
|
| 315 |
+
const quizDescriptionElement = document.getElementById("quiz-description");
|
| 316 |
+
|
| 317 |
+
function main() {
|
| 318 |
+
// update quiz meta data
|
| 319 |
+
document.title = quizTitle;
|
| 320 |
+
quizTitleElement.innerHTML = quizTitle;
|
| 321 |
+
quizDescriptionElement.innerHTML = quizDescription;
|
| 322 |
+
|
| 323 |
+
const passPercentElement = document.getElementById("pass-percent");
|
| 324 |
+
passPercentElement.innerHTML = passPercent + "%";
|
| 325 |
+
totalNumberOfQuestions = questionData.length;
|
| 326 |
+
// shuffle the questionData to randomize the order of the questions
|
| 327 |
+
for (let i = questionData.length - 1; i > 0; i--) {
|
| 328 |
+
const j = Math.floor(Math.random() * (i + 1));
|
| 329 |
+
[questionData[i], questionData[j]] = [questionData[j], questionData[i]];
|
| 330 |
+
}
|
| 331 |
+
|
| 332 |
+
let formattedQuestions = questionData.map(formatSingleQuestionData);
|
| 333 |
+
updateScore();
|
| 334 |
+
// display the formattedQuestions
|
| 335 |
+
formattedQuestions.forEach((question, idx) => {
|
| 336 |
+
renderSingleQuestion(question, idx + 1);
|
| 337 |
+
});
|
| 338 |
+
}
|
| 339 |
+
|
| 340 |
+
/**
|
| 341 |
+
* Formats the question data from the given QuizData object.
|
| 342 |
+
*
|
| 343 |
+
* @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
|
| 344 |
+
* @return {Object} The formatted question object with the following properties:
|
| 345 |
+
* - id: The ID of the question.
|
| 346 |
+
* - question: The text of the question.
|
| 347 |
+
* - answers: The array of answer options.
|
| 348 |
+
* - correctAnswer: The text of the correct answer.
|
| 349 |
+
* - explanation: The explanation of the correct answer.
|
| 350 |
+
*/
|
| 351 |
+
function formatSingleQuestionData(singleQuizData = null) {
|
| 352 |
+
const { prompt, correct_response, id } = singleQuizData;
|
| 353 |
+
const questionText = prompt.question;
|
| 354 |
+
const answers = prompt.answers;
|
| 355 |
+
const correctAnswer = correct_response[0];
|
| 356 |
+
const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
|
| 357 |
+
const questionObj = {
|
| 358 |
+
id: id,
|
| 359 |
+
question: questionText,
|
| 360 |
+
answers: answers,
|
| 361 |
+
correctAnswer: correctAnswerText,
|
| 362 |
+
explanation: prompt?.explanation || "",
|
| 363 |
+
};
|
| 364 |
+
return questionObj;
|
| 365 |
+
}
|
| 366 |
+
|
| 367 |
+
/**
|
| 368 |
+
* Renders a single question with its options and submit button.
|
| 369 |
+
*
|
| 370 |
+
* @param {Object} singleQuestionData - The data of the question to render.
|
| 371 |
+
* @param {number} rootIndex - The index of the question in the quiz.
|
| 372 |
+
* @return {void} return nothing.
|
| 373 |
+
*/
|
| 374 |
+
|
| 375 |
+
const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
|
| 376 |
+
const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
|
| 377 |
+
// shuffle the answers to randomize the order of the answers
|
| 378 |
+
for (let i = answers.length - 1; i > 0; i--) {
|
| 379 |
+
const j = Math.floor(Math.random() * (i + 1));
|
| 380 |
+
[answers[i], answers[j]] = [answers[j], answers[i]];
|
| 381 |
+
}
|
| 382 |
+
const optionsHTML = answers
|
| 383 |
+
.map((option, index) => {
|
| 384 |
+
const optionId = `${id}_${index}`;
|
| 385 |
+
|
| 386 |
+
return `
|
| 387 |
+
<div class="question-lable">
|
| 388 |
+
<input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
|
| 389 |
+
<label for="${optionId}">${option}</label>
|
| 390 |
+
</div>
|
| 391 |
+
`;
|
| 392 |
+
})
|
| 393 |
+
|
| 394 |
+
.join("");
|
| 395 |
+
|
| 396 |
+
const container = document.createElement("div");
|
| 397 |
+
container.innerHTML = `
|
| 398 |
+
<form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
|
| 399 |
+
<div style="display: flex;justify-content: space-between;">
|
| 400 |
+
<p style="font-weight: 600">Question ${rootIndex}:</p>
|
| 401 |
+
<button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
|
| 402 |
+
</div>
|
| 403 |
+
<p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
|
| 404 |
+
<div class="options-container">
|
| 405 |
+
${optionsHTML}
|
| 406 |
+
</div>
|
| 407 |
+
<div style="display: flex; gap: 8px;">
|
| 408 |
+
<button type="submit" id="submit-button" class="button">Submit</button>
|
| 409 |
+
</div>
|
| 410 |
+
</form>
|
| 411 |
+
`;
|
| 412 |
+
quizContainerElement.appendChild(container);
|
| 413 |
+
};
|
| 414 |
+
|
| 415 |
+
/**
|
| 416 |
+
* Updates the score on the page based on the number of correct and incorrect answers.
|
| 417 |
+
*
|
| 418 |
+
* @return {void} This function does not return a value.
|
| 419 |
+
*/
|
| 420 |
+
function updateScore() {
|
| 421 |
+
const currentParcentageElement = document.getElementById("current-score");
|
| 422 |
+
const correctAnswerElement = document.getElementById("correct-answers");
|
| 423 |
+
const wrongAnswerElement = document.getElementById("wrong-answers");
|
| 424 |
+
correctAnswerElement.innerHTML = correct.size;
|
| 425 |
+
wrongAnswerElement.innerHTML = incorrect.size;
|
| 426 |
+
const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
|
| 427 |
+
currentParcentageElement.innerHTML = score;
|
| 428 |
+
}
|
| 429 |
+
|
| 430 |
+
/**
|
| 431 |
+
* Handles the event when the submit button is clicked.
|
| 432 |
+
*
|
| 433 |
+
* @param {Event} e - The event object.
|
| 434 |
+
* @return {void} This function does not return anything.
|
| 435 |
+
*/
|
| 436 |
+
const submitButtonListener = (e) => {
|
| 437 |
+
e.preventDefault();
|
| 438 |
+
const formData = new FormData(e.target);
|
| 439 |
+
const form = e.target;
|
| 440 |
+
const selectedOption = e.target.querySelector('input[type="radio"]:checked');
|
| 441 |
+
if (!selectedOption) {
|
| 442 |
+
alert("Please select an answer!");
|
| 443 |
+
return;
|
| 444 |
+
}
|
| 445 |
+
|
| 446 |
+
let isCorrect = false;
|
| 447 |
+
const { answer: userAnswer } = Object.fromEntries(formData.entries());
|
| 448 |
+
const correctAnswer = e.target.dataset.correctAnswer;
|
| 449 |
+
const questionId = e.target.dataset.questionId;
|
| 450 |
+
if (userAnswer == correctAnswer) {
|
| 451 |
+
correct.add(questionId);
|
| 452 |
+
incorrect.delete(questionId);
|
| 453 |
+
isCorrect = true;
|
| 454 |
+
} else {
|
| 455 |
+
incorrect.add(e.target.dataset.questionId);
|
| 456 |
+
correct.delete(questionId);
|
| 457 |
+
}
|
| 458 |
+
updateScore();
|
| 459 |
+
|
| 460 |
+
const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
|
| 461 |
+
|
| 462 |
+
form.querySelectorAll(".question-lable").forEach((label) => {
|
| 463 |
+
label.classList.remove("correct-answer", "incorrect-answer");
|
| 464 |
+
});
|
| 465 |
+
selectedOption.closest(".question-lable").classList.add(resultClass);
|
| 466 |
+
};
|
| 467 |
+
|
| 468 |
+
function renderExplanation(ev) {
|
| 469 |
+
modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
|
| 470 |
+
dialog.showModal();
|
| 471 |
+
dialog.addEventListener("click", (event) => {
|
| 472 |
+
if (event.target === dialog) {
|
| 473 |
+
dialog.close();
|
| 474 |
+
}
|
| 475 |
+
});
|
| 476 |
+
}
|
| 477 |
+
</script>
|
| 478 |
+
</body>
|
| 479 |
+
</html>
|
12 - Data Protection/001 Regulated Data OB 3.3_en.srt
ADDED
|
@@ -0,0 +1,148 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:07,000
|
| 3 |
+
Most organizations nowadays will follow some kind of regulations pertaining to the data that it collects.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:07,000 --> 00:00:12,000
|
| 7 |
+
In today's world, especially in the United States, we have tons of laws that we have to follow, whether
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:12,000 --> 00:00:18,000
|
| 11 |
+
it's collecting medical information and having to follow HIPAA compliance, collecting credit card information,
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:18,000 --> 00:00:22,000
|
| 15 |
+
and following things such as PCI standards now.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:23,000 --> 00:00:26,000
|
| 19 |
+
What happens is this is known as regulated data.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:26,000 --> 00:00:32,000
|
| 23 |
+
This includes data that's subject to all kinds of regulatory requirements, different kind of laws and
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:32,000 --> 00:00:34,000
|
| 27 |
+
regulations, personal data.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:34,000 --> 00:00:41,000
|
| 31 |
+
So if you work in places, if you collect personal data and your organization does business or is located
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:41,000 --> 00:00:43,000
|
| 35 |
+
in Europe, you'll have to follow GDPR.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:44,000 --> 00:00:45,000
|
| 39 |
+
Uh, in the United States.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:45,000 --> 00:00:51,000
|
| 43 |
+
Here we have things like HIPAA compliance where health health information and then financial data,
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:52,000 --> 00:00:55,000
|
| 47 |
+
uh, for PCI compliance is going to be like credit card information.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:55,000 --> 00:01:01,000
|
| 51 |
+
Now, all of these laws here, uh, that are covered, we're going to be covering some of these laws
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:01:01,000 --> 00:01:03,000
|
| 55 |
+
a little bit later in this course.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:03,000 --> 00:01:04,000
|
| 59 |
+
So hold on to that.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:04,000 --> 00:01:09,000
|
| 63 |
+
But for now we want to talk about how just that data is regulated.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:09,000 --> 00:01:14,000
|
| 67 |
+
Don't think that by collecting people's information, especially people's name, address, social security
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:14,000 --> 00:01:20,000
|
| 71 |
+
number, health care information, like diseases, they may have, medications, they may be taken credit
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:20,000 --> 00:01:21,000
|
| 75 |
+
card information.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:21,000 --> 00:01:24,000
|
| 79 |
+
This is all data that's going to be regulated.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:24,000 --> 00:01:32,000
|
| 83 |
+
In fact things that GDPR, the general data protection, this uh, things like GDPR, this is a this
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:32,000 --> 00:01:36,000
|
| 87 |
+
is a this is basically a law that protects Europeans.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:36,000 --> 00:01:36,000
|
| 91 |
+
Okay.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:36,000 --> 00:01:38,000
|
| 95 |
+
Or the European Union citizens data.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:38,000 --> 00:01:41,000
|
| 99 |
+
Things like browsing information is what this collects.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:41,000 --> 00:01:48,000
|
| 103 |
+
So when you start collecting data on your users, you have to keep in mind that a lot of the data will
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:48,000 --> 00:01:54,000
|
| 107 |
+
be subject to certain laws and regulations within the country that you're collecting that data from.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:54,000 --> 00:01:59,000
|
| 111 |
+
Compliance with these legal and regulatory standards are critical.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:59,000 --> 00:02:05,000
|
| 115 |
+
First of all, it will be against the law if you don't, and it's probably going to be mandatory.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:02:05,000 --> 00:02:12,000
|
| 119 |
+
This involves good security measurements, access control, and of course ensuring the privacy or confidentiality
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:12,000 --> 00:02:15,000
|
| 123 |
+
and integrity of the data.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:15,000 --> 00:02:22,000
|
| 127 |
+
So don't think that you can just set up a business or don't think most companies can just go and set
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:22,000 --> 00:02:28,000
|
| 131 |
+
up businesses, start collecting information and not worry about the laws that they should be following.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:28,000 --> 00:02:35,000
|
| 135 |
+
So make sure as a security professional, you are aware of what local laws within your country that
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:35,000 --> 00:02:38,000
|
| 139 |
+
you should be following when it comes to data compliance.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:38,000 --> 00:02:43,000
|
| 143 |
+
And also if you're collecting data from overseas or you're doing business overseas from your country,
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:43,000 --> 00:02:46,000
|
| 147 |
+
what laws you should be following there also.
|
| 148 |
+
|
12 - Data Protection/002 Intellectual Property OB 3.3_en.srt
ADDED
|
@@ -0,0 +1,696 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:08,000
|
| 3 |
+
People and organizations in today's world create specific things such as invention, expression, such
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:08,000 --> 00:00:12,000
|
| 7 |
+
as art, or expressions like write in a book.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:12,000 --> 00:00:16,000
|
| 11 |
+
These things that they create is valuable to them and is worth money to them.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:17,000 --> 00:00:23,000
|
| 15 |
+
In fact, I am an author and I wrote one of the world's best selling project management book, the PMP
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:23,000 --> 00:00:25,000
|
| 19 |
+
Exam Prep Simplified.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:25,000 --> 00:00:29,000
|
| 23 |
+
Now, this particular book is an expression of me.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:29,000 --> 00:00:31,000
|
| 27 |
+
This particular book does bring me in an income.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:31,000 --> 00:00:36,000
|
| 31 |
+
And for anybody to steal my particular work would result in damages to me.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:36,000 --> 00:00:41,000
|
| 35 |
+
You see, organizations also have this problem, especially with people that create inventions.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:41,000 --> 00:00:45,000
|
| 39 |
+
If you make a unique invention that only you.
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:46,000 --> 00:00:48,000
|
| 43 |
+
Uh, should be using in order to profit from that invention.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:48,000 --> 00:00:50,000
|
| 47 |
+
Because that is your idea.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:50,000 --> 00:00:52,000
|
| 51 |
+
You need to protect your invention.
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:52,000 --> 00:00:54,000
|
| 55 |
+
I need to protect my expression.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:54,000 --> 00:00:57,000
|
| 59 |
+
You see, this is called intellectual property.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:00:58,000 --> 00:00:59,000
|
| 63 |
+
This is the creation.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:00:59,000 --> 00:01:01,000
|
| 67 |
+
This is creations of the mind.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:01,000 --> 00:01:09,000
|
| 71 |
+
Like inventions, literacy work, artistic work, design symbols and names that is used in commerce.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:09,000 --> 00:01:16,000
|
| 75 |
+
Now, in this video, I want to go through the different ways we can that we can use to protect our
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:16,000 --> 00:01:17,000
|
| 79 |
+
intellectual property.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:17,000 --> 00:01:17,000
|
| 83 |
+
Our.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:17,000 --> 00:01:21,000
|
| 87 |
+
The organization thinks that copyrights and patents and trademarks.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:21,000 --> 00:01:23,000
|
| 91 |
+
That's what we're cover in this video.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:23,000 --> 00:01:29,000
|
| 95 |
+
IP theft can result in significant economic loss and competitive disadvantage.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:29,000 --> 00:01:34,000
|
| 99 |
+
Now, if this is something that I have personal experience with because I have personally experienced
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:34,000 --> 00:01:41,000
|
| 103 |
+
this, my study guide or my book was published on Amazon, and Amazon has exclusive rights as the only
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:41,000 --> 00:01:43,000
|
| 107 |
+
distributor of the book.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:44,000 --> 00:01:46,000
|
| 111 |
+
After a couple of years and it was doing well.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:46,000 --> 00:01:50,000
|
| 115 |
+
All of a sudden we started having a seller that started to sell my book.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:50,000 --> 00:01:51,000
|
| 119 |
+
They were buying.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:51,000 --> 00:01:55,000
|
| 123 |
+
They were printing the book themselves and selling it on Amazon.
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:55,000 --> 00:01:59,000
|
| 127 |
+
They were priced at Amazon, so people were buying their book and we didn't realize it for a while.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:59,000 --> 00:02:03,000
|
| 131 |
+
So we actually lost a significant amount of money due to IP theft.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:03,000 --> 00:02:05,000
|
| 135 |
+
This book is copyrighted.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:05,000 --> 00:02:11,000
|
| 139 |
+
Protection includes rights management, strict access control, even watermarking to trace and identify
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:11,000 --> 00:02:13,000
|
| 143 |
+
unauthorized copies.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:13,000 --> 00:02:15,000
|
| 147 |
+
Now, the book does have a unique mark that we know.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:15,000 --> 00:02:17,000
|
| 151 |
+
If you copy it, we'll know.
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:17,000 --> 00:02:22,000
|
| 155 |
+
So how does organizations protect their intellectual property?
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:22,000 --> 00:02:27,000
|
| 159 |
+
Well, let's go through some of the most common ways that you're going to need to know for your exam.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:27,000 --> 00:02:30,000
|
| 163 |
+
The first one here I have is copyrights.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:30,000 --> 00:02:37,000
|
| 167 |
+
So copyrights are laws that protects against unauthorized duplication of an original creative work.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:37,000 --> 00:02:41,000
|
| 171 |
+
Now when people think of okay, what can I copyright?
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:41,000 --> 00:02:49,000
|
| 175 |
+
Well, these are some of the things here that you can copyright, literacy work, musical work, uh,
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:49,000 --> 00:02:56,000
|
| 179 |
+
all kinds of pictorial work like pictures, motion pictures, sound recordings, architectural work,
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:56,000 --> 00:02:59,000
|
| 183 |
+
all of these are copyrightable.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:59,000 --> 00:03:03,000
|
| 187 |
+
Now I want to before I get into this, I want to make something clear.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:03:03,000 --> 00:03:09,000
|
| 191 |
+
The moment work is created, it is copyrighted.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:10,000 --> 00:03:11,000
|
| 195 |
+
There's two kinds of copyrights.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:11,000 --> 00:03:13,000
|
| 199 |
+
In the United States.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:13,000 --> 00:03:17,000
|
| 203 |
+
There is a regular copyright, and then there's a registered copyright.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:18,000 --> 00:03:25,000
|
| 207 |
+
The moment you have an idea of an expression of some kind and you draw it on a piece of paper, or you
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:25,000 --> 00:03:29,000
|
| 211 |
+
write it down on a piece of paper, it is automatically copyrighted.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:29,000 --> 00:03:32,000
|
| 215 |
+
You do not need to register it.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:33,000 --> 00:03:40,000
|
| 219 |
+
Now, if you feel that this work will be public, will be on the public shelves, such as a book on
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:40,000 --> 00:03:45,000
|
| 223 |
+
Amazon, or you're going to be selling this picture online, or it's going to be like a motion picture
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:45,000 --> 00:03:49,000
|
| 227 |
+
where everybody's going to be seeing it, or it's going to be some kind of play or something like that,
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:50,000 --> 00:03:52,000
|
| 231 |
+
then it's best to get it registered.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:52,000 --> 00:03:58,000
|
| 235 |
+
A registered copyright is when you go to your copyright office, like we do here in the United States,
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:58,000 --> 00:04:01,000
|
| 239 |
+
and we submit the work to the Copyright Office.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:04:01,000 --> 00:04:02,000
|
| 243 |
+
And we claim that that is our work.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:04:02,000 --> 00:04:09,000
|
| 247 |
+
The Copyright Office then puts a stamp on it that says, as of this day, Bob says this is his work.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:04:09,000 --> 00:04:14,000
|
| 251 |
+
They actually don't check to see if anybody else owns it, but they're just saying that that it is there.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:04:15,000 --> 00:04:16,000
|
| 255 |
+
Now, why do we want to register?
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:04:16,000 --> 00:04:18,000
|
| 259 |
+
What's the benefit of registration?
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:18,000 --> 00:04:23,000
|
| 263 |
+
When you register a copyright, it's the only time you can actually bring lawsuits against people.
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:23,000 --> 00:04:24,000
|
| 267 |
+
So if anybody.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:24,000 --> 00:04:30,000
|
| 271 |
+
So let's say you wrote something down on a copyright and somebody else stole your idea and you're sure
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:30,000 --> 00:04:32,000
|
| 275 |
+
of it, you can't sue them yet.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:32,000 --> 00:04:33,000
|
| 279 |
+
You have to go and register it.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:33,000 --> 00:04:34,000
|
| 283 |
+
Then you can sue them.
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:34,000 --> 00:04:35,000
|
| 287 |
+
So it's best to do it right away.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:36,000 --> 00:04:42,000
|
| 291 |
+
Uh, also, you're entitled to all kinds of different damages in case somebody steals your copyright.
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:42,000 --> 00:04:43,000
|
| 295 |
+
This is not a law course.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:43,000 --> 00:04:48,000
|
| 299 |
+
I'm not going to get into the specifics, but if you do have work that are made, publish, go and register
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:48,000 --> 00:04:48,000
|
| 303 |
+
it.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:48,000 --> 00:04:49,000
|
| 307 |
+
Registry.
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:50,000 --> 00:04:51,000
|
| 311 |
+
Registering a copyright.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:51,000 --> 00:04:53,000
|
| 315 |
+
It's actually something that is very easy.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:53,000 --> 00:04:54,000
|
| 319 |
+
I did it myself online.
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:54,000 --> 00:04:55,000
|
| 323 |
+
It takes about ten minutes.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:55,000 --> 00:04:57,000
|
| 327 |
+
Do not pay companies to do it.
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:04:57,000 --> 00:05:01,000
|
| 331 |
+
And I think I paid about $40 to register the book, so keep that in mind.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:05:01,000 --> 00:05:03,000
|
| 335 |
+
It's not difficult.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:03,000 --> 00:05:05,000
|
| 339 |
+
Now remember remember what I'm talking about.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:05,000 --> 00:05:09,000
|
| 343 |
+
Copyrights does not have to be registered to have the protection.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:09,000 --> 00:05:12,000
|
| 347 |
+
The protection we're talking about is right here.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:12,000 --> 00:05:16,000
|
| 351 |
+
So remember a copyright is an expression of idea or resources.
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:16,000 --> 00:05:22,000
|
| 355 |
+
Authors can control how whoever owns the copyright controls how the work is distributed, reproduced
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:22,000 --> 00:05:23,000
|
| 359 |
+
and used now.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:24,000 --> 00:05:28,000
|
| 363 |
+
Copyrights are valid for very long periods of time.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:28,000 --> 00:05:36,000
|
| 367 |
+
It's valid generally for 70 years after the death of the last remaining author, unless it's work for
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:36,000 --> 00:05:36,000
|
| 371 |
+
hire.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:36,000 --> 00:05:44,000
|
| 375 |
+
So work for hire is this work for hire is when somebody hires you to create work for an organization.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:44,000 --> 00:05:48,000
|
| 379 |
+
So if you go to a company and you wrote procedures and policies, that's called work for hire, work
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:48,000 --> 00:05:49,000
|
| 383 |
+
for hire.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:49,000 --> 00:05:56,000
|
| 387 |
+
An anonymous works are protected for 95 years from the date of the first publication of 120 days from
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:56,000 --> 00:05:58,000
|
| 391 |
+
the date of creation, which one ever is shortest?
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:58,000 --> 00:06:03,000
|
| 395 |
+
If it was published dated, it's 95 years or it's 120 years.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:06:04,000 --> 00:06:09,000
|
| 399 |
+
So let's say you're a bad person and you want to steal my book, right?
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:06:09,000 --> 00:06:10,000
|
| 403 |
+
My PMP study guide.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:06:10,000 --> 00:06:17,000
|
| 407 |
+
Well, if you want to steal it well or use it, I'm going to sue you because I have the legal copyright.
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:06:17,000 --> 00:06:22,000
|
| 411 |
+
But if you want to wait for the copyright to expire to republish the work, you have to wait.
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:06:22,000 --> 00:06:26,000
|
| 415 |
+
You have to wait for me to die and then you have to wait 70 years.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:06:27,000 --> 00:06:31,000
|
| 419 |
+
Penalties can penalties is going to be up to $1.1 million in damages.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:06:31,000 --> 00:06:31,000
|
| 423 |
+
Now.
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:06:31,000 --> 00:06:34,000
|
| 427 |
+
This number can change depending on when you're watching this video.
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:06:34,000 --> 00:06:36,000
|
| 431 |
+
Ten years in prison now.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:06:37,000 --> 00:06:41,000
|
| 435 |
+
This is copyright and these are things that are copyrightable that I have here.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:41,000 --> 00:06:47,000
|
| 439 |
+
Now, the other thing here that we can use to protect our IP is going to be trademarks.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:47,000 --> 00:06:55,000
|
| 443 |
+
Trademarks protect words, names, symbols, sounds, shapes, colors, musical tones or a combination.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:56,000 --> 00:07:01,000
|
| 447 |
+
Uh, they protect someone from stealing another person's quote unquote look and feel.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:07:01,000 --> 00:07:04,000
|
| 451 |
+
The primary purpose is to avoid confusion in the marketplace.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:07:04,000 --> 00:07:06,000
|
| 455 |
+
This protects intellectual property.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:07:06,000 --> 00:07:12,000
|
| 459 |
+
The good thing with trademarks is that they're valid, unlike a copyright, which generally, when I
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:07:12,000 --> 00:07:16,000
|
| 463 |
+
die, it's 70 years technically trademarks, you can keep renewing it over and over.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:07:16,000 --> 00:07:18,000
|
| 467 |
+
They're valid for ten years with unlimited renewal.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:07:19,000 --> 00:07:19,000
|
| 471 |
+
Um.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:07:20,000 --> 00:07:22,000
|
| 475 |
+
On unlimited.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:07:22,000 --> 00:07:27,000
|
| 479 |
+
You can renew an unlimited number of times, so you can keep renewing that over and over and over.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:07:27,000 --> 00:07:29,000
|
| 483 |
+
Now, what are things that are going to be trademarked?
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:07:29,000 --> 00:07:32,000
|
| 487 |
+
Lots of things that are trademark are generally things like symbols.
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:07:32,000 --> 00:07:37,000
|
| 491 |
+
The Technical Institute of America, if you look at our name and symbols, those are all trademarks.
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:07:37,000 --> 00:07:41,000
|
| 495 |
+
We own the trademark to the Technical Institute of America.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:07:41,000 --> 00:07:44,000
|
| 499 |
+
The the the actual company's name.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:07:44,000 --> 00:07:48,000
|
| 503 |
+
The Technical Institute of America is a trademark name.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:07:48,000 --> 00:07:52,000
|
| 507 |
+
The symbol of itself, the shield that we use is also trademarked.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:52,000 --> 00:07:56,000
|
| 511 |
+
This helps to ensure that we protect our brand.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:56,000 --> 00:08:01,000
|
| 515 |
+
Many, many companies are trademarking their content, their brands, their logo.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:08:01,000 --> 00:08:04,000
|
| 519 |
+
How do you know when you see a particular logo?
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:08:04,000 --> 00:08:07,000
|
| 523 |
+
You might see a little circle that says TM on it.
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:08:07,000 --> 00:08:10,000
|
| 527 |
+
If you see a little circle with a C with a circle, that's a copyright.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:08:11,000 --> 00:08:13,000
|
| 531 |
+
Now the other one here you have is patents.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:08:13,000 --> 00:08:15,000
|
| 535 |
+
If you have an invention.
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:08:16,000 --> 00:08:21,000
|
| 539 |
+
Unique invention that you have invented to help the world progress.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:08:21,000 --> 00:08:25,000
|
| 543 |
+
You're going to get exclusive use of your invention if you patent your invention.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:08:25,000 --> 00:08:31,000
|
| 547 |
+
So patent protects the right of inventors and their inventions, protection of those who have legal
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:08:31,000 --> 00:08:32,000
|
| 551 |
+
ownership of the patent.
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:08:33,000 --> 00:08:37,000
|
| 555 |
+
The invention, must be new, must be useful, and must not be obvious.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:08:37,000 --> 00:08:42,000
|
| 559 |
+
The owner has exclusive control of the invention for 20 years.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:08:42,000 --> 00:08:47,000
|
| 563 |
+
After that it goes to the public domain and anyone can produce your work.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:08:47,000 --> 00:08:52,000
|
| 567 |
+
This is why when organizations like drug companies first make a drug that they've spent billions of
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:08:52,000 --> 00:08:58,000
|
| 571 |
+
dollars producing, they have about 20 years because they have patent that formula for that drug to
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:08:58,000 --> 00:09:02,000
|
| 575 |
+
sell it as much as they want so they can recuperate their costs.
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:09:02,000 --> 00:09:06,000
|
| 579 |
+
And after that it becomes a generic medication, and then anyone can take the formula.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:09:08,000 --> 00:09:16,000
|
| 583 |
+
Another thing that you want to protect is the secret recipe to the McDonald's Big Mac sauce, or the
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:09:16,000 --> 00:09:20,000
|
| 587 |
+
secret recipe to KFC's fried chicken.
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:09:21,000 --> 00:09:22,000
|
| 591 |
+
It's coming up to lunch time.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:09:22,000 --> 00:09:26,000
|
| 595 |
+
It's actually around 11:00 in the morning, so I'm thinking about I could use a Big Mac right now.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:09:27,000 --> 00:09:36,000
|
| 599 |
+
Organizations have top secret information that they use in order for the survivability of that company.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:09:36,000 --> 00:09:38,000
|
| 603 |
+
These are called trade secrets.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:09:38,000 --> 00:09:45,000
|
| 607 |
+
It's any form of information, device, method, process, or formula such as that Big Mac sauce that,
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:09:45,000 --> 00:09:49,000
|
| 611 |
+
if disclosed, will cause significant damage to the organization.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:09:50,000 --> 00:09:53,000
|
| 615 |
+
Now resources generally is going to provide.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:09:53,000 --> 00:09:59,000
|
| 619 |
+
Must be of competitive value, must be protected from unauthorized use, is proprietary to the company
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:09:59,000 --> 00:10:01,000
|
| 623 |
+
essential for them to survive.
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:10:01,000 --> 00:10:11,000
|
| 627 |
+
Now there is really nothing to register like we do with copyrights or patents or, uh, or trademarks.
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:10:11,000 --> 00:10:13,000
|
| 631 |
+
Trade secrets just has to be protected.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:10:14,000 --> 00:10:18,000
|
| 635 |
+
There is a law in the United States you don't need to know this one for your exam.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:10:18,000 --> 00:10:19,000
|
| 639 |
+
I just put it there.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:10:19,000 --> 00:10:25,000
|
| 643 |
+
For your knowledge, the Espionage Act of 1996 is a law that specifies that if anyone ever steals a
|
| 644 |
+
|
| 645 |
+
162
|
| 646 |
+
00:10:25,000 --> 00:10:31,000
|
| 647 |
+
trade secrets and discloses that they can be fined, as you can see here, potential jail time.
|
| 648 |
+
|
| 649 |
+
163
|
| 650 |
+
00:10:32,000 --> 00:10:38,000
|
| 651 |
+
So the way to protect trade secrets as a security professional is just do your normal security things,
|
| 652 |
+
|
| 653 |
+
164
|
| 654 |
+
00:10:38,000 --> 00:10:45,000
|
| 655 |
+
encrypt it, put good windows permission or file permission like access control firewalls, IDs systems
|
| 656 |
+
|
| 657 |
+
165
|
| 658 |
+
00:10:45,000 --> 00:10:49,000
|
| 659 |
+
may be used potential air gapped systems to store this kind of information.
|
| 660 |
+
|
| 661 |
+
166
|
| 662 |
+
00:10:49,000 --> 00:10:53,000
|
| 663 |
+
Whoever gets the information should be signing a non-disclosure agreement.
|
| 664 |
+
|
| 665 |
+
167
|
| 666 |
+
00:10:53,000 --> 00:10:56,000
|
| 667 |
+
This prohibits them from sharing this information.
|
| 668 |
+
|
| 669 |
+
168
|
| 670 |
+
00:10:56,000 --> 00:11:04,000
|
| 671 |
+
And if they do share it, they could, uh, be subject to potential fines or the company can sue them
|
| 672 |
+
|
| 673 |
+
169
|
| 674 |
+
00:11:04,000 --> 00:11:05,000
|
| 675 |
+
for the loss of income and so on.
|
| 676 |
+
|
| 677 |
+
170
|
| 678 |
+
00:11:07,000 --> 00:11:07,000
|
| 679 |
+
Okay.
|
| 680 |
+
|
| 681 |
+
171
|
| 682 |
+
00:11:07,000 --> 00:11:11,000
|
| 683 |
+
These are some ways that we're going to protect our intellectual property.
|
| 684 |
+
|
| 685 |
+
172
|
| 686 |
+
00:11:11,000 --> 00:11:16,000
|
| 687 |
+
Keep in mind, intellectual property is how lots of organizations survives in today's day and time.
|
| 688 |
+
|
| 689 |
+
173
|
| 690 |
+
00:11:16,000 --> 00:11:21,000
|
| 691 |
+
And a lot of these IPS is essential for the survival of the business.
|
| 692 |
+
|
| 693 |
+
174
|
| 694 |
+
00:11:21,000 --> 00:11:25,000
|
| 695 |
+
So as an IT professional, make sure you protect them.
|
| 696 |
+
|
12 - Data Protection/003 Legal and Financial Data OB 3.3_en.srt
ADDED
|
@@ -0,0 +1,276 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:05,000
|
| 3 |
+
As you collect information, you're going to be collecting different kinds of information in particularly,
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:05,000 --> 00:00:11,000
|
| 7 |
+
some of the data that we collect on a network may be considered, uh, legal information.
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:11,000 --> 00:00:14,000
|
| 11 |
+
While some of the information we collect may be financial information.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:14,000 --> 00:00:20,000
|
| 15 |
+
And then some of this information we collect is easily readable by us.
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:20,000 --> 00:00:24,000
|
| 19 |
+
And versus some of it is not and can only be read by a computer.
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:24,000 --> 00:00:26,000
|
| 23 |
+
So let's talk about the first one I have here.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:26,000 --> 00:00:28,000
|
| 27 |
+
Legal information.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:28,000 --> 00:00:35,000
|
| 31 |
+
A lot of times some of the data that we collect on clients, or that we create ourselves internally
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:35,000 --> 00:00:39,000
|
| 35 |
+
could fall into the to to the realm of legal information.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:39,000 --> 00:00:44,000
|
| 39 |
+
Legal information are things that deals with legal matters, including case files, legal advice and
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:44,000 --> 00:00:46,000
|
| 43 |
+
other sensitive legal documents.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:47,000 --> 00:00:52,000
|
| 47 |
+
A breach of these type, a breach of this kind of information, or the release of this kind of information,
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:52,000 --> 00:00:57,000
|
| 51 |
+
especially if the company is in some kind of a lawsuit, could result in attorney client privileges
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:57,000 --> 00:00:59,000
|
| 55 |
+
being compromised.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:00:59,000 --> 00:01:00,000
|
| 59 |
+
Uh, case integrity.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:00,000 --> 00:01:04,000
|
| 63 |
+
So ensuring the confidentiality encryption of this kind of information is critical.
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:04,000 --> 00:01:05,000
|
| 67 |
+
Let me give you an example.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:06,000 --> 00:01:13,000
|
| 71 |
+
Let's say the organization, uh, has gotten sued by another company because that company is claiming
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:13,000 --> 00:01:16,000
|
| 75 |
+
that it stole its IP topic.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:16,000 --> 00:01:19,000
|
| 79 |
+
We just covered it, stole its design.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:19,000 --> 00:01:26,000
|
| 83 |
+
But your organization has proof that it didn't stole the design, and it actually created the actual
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:26,000 --> 00:01:28,000
|
| 87 |
+
product itself from scratch.
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:28,000 --> 00:01:36,000
|
| 91 |
+
The documents that proves that we created the design ourselves now falls into a legal into a legal case,
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:36,000 --> 00:01:39,000
|
| 95 |
+
or now it becomes legal information.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:39,000 --> 00:01:42,000
|
| 99 |
+
This means that it's going to have to be presented in a court of law.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:42,000 --> 00:01:47,000
|
| 103 |
+
As an IT professional, you're going to have to make sure that you protect the integrity, make sure
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:47,000 --> 00:01:52,000
|
| 107 |
+
that it never gets modified, because you're going to use this as proof in the case you have to encrypt
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:52,000 --> 00:01:57,000
|
| 111 |
+
it so it doesn't get leaked out, or the other sides don't get to see it because they have an assumption
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:57,000 --> 00:01:58,000
|
| 115 |
+
that may not be true.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:58,000 --> 00:02:01,000
|
| 119 |
+
Another thing is financial information.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:02:01,000 --> 00:02:07,000
|
| 123 |
+
It is super easy to get in trouble with the law nowadays, because you're collecting financial information
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:02:07,000 --> 00:02:09,000
|
| 127 |
+
and may not even be realized in it.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:02:09,000 --> 00:02:11,000
|
| 131 |
+
How important it is.
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:02:12,000 --> 00:02:17,000
|
| 135 |
+
This is going to be things, transactions, financial records, credit card information, and other
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:02:17,000 --> 00:02:19,000
|
| 139 |
+
monetary data that you're collecting from your customers.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:19,000 --> 00:02:25,000
|
| 143 |
+
Right now, most organizations that sells products online will collect some kind of payment information.
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:26,000 --> 00:02:30,000
|
| 147 |
+
Now, financial data is always going to be the target for these.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:30,000 --> 00:02:35,000
|
| 151 |
+
I don't want to say always, 90% of the time is going to be the target for these hackers that comes
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:35,000 --> 00:02:37,000
|
| 155 |
+
in, breaks into your company.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:37,000 --> 00:02:40,000
|
| 159 |
+
What they're looking for are those credit card information.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:40,000 --> 00:02:45,000
|
| 163 |
+
We're going to have to do things like encrypted, encrypt the processing and make sure that if there
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:45,000 --> 00:02:50,000
|
| 167 |
+
is standards like PCI compliance, PCI means payment card industry.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:52,000 --> 00:02:54,000
|
| 171 |
+
DSS data security standard.
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:54,000 --> 00:03:01,000
|
| 175 |
+
It's basically a standard that organizations have to follow to secure credit card information or financial
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:03:01,000 --> 00:03:02,000
|
| 179 |
+
information.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:03:02,000 --> 00:03:06,000
|
| 183 |
+
Now, the other thing here that we're going to be talking about is what's called readable data.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:03:06,000 --> 00:03:08,000
|
| 187 |
+
Readable data falls into two kinds.
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:03:08,000 --> 00:03:14,000
|
| 191 |
+
Human readable, US readable and non-human readable things that we can interpret and see on a network,
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:03:14,000 --> 00:03:18,000
|
| 195 |
+
such as text, documents, images, printable information.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:03:18,000 --> 00:03:24,000
|
| 199 |
+
And then non readable is going to be non human readable things that only the computer can read.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:03:24,000 --> 00:03:27,000
|
| 203 |
+
Think of things like machine code.
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:03:27,000 --> 00:03:30,000
|
| 207 |
+
No one can read machine code ones and zeros.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:30,000 --> 00:03:34,000
|
| 211 |
+
Certain kind of log files, encrypted data that only computers can decrypt.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:35,000 --> 00:03:38,000
|
| 215 |
+
Both of these will require protection.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:38,000 --> 00:03:39,000
|
| 219 |
+
Okay.
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:39,000 --> 00:03:41,000
|
| 223 |
+
Both of these will require protection.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:41,000 --> 00:03:45,000
|
| 227 |
+
That only that only that organization or whoever needs to see it.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:45,000 --> 00:03:53,000
|
| 231 |
+
This is going to be things such as encryption, firewalls, intrusion detection systems, access controls
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:53,000 --> 00:03:54,000
|
| 235 |
+
and so on.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:54,000 --> 00:03:57,000
|
| 239 |
+
All the protection mechanisms that we have spoken about.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:57,000 --> 00:04:02,000
|
| 243 |
+
So human readable is, is very likely to get stolen.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:04:02,000 --> 00:04:06,000
|
| 247 |
+
Because that's what if they break into the company, that's what they're going to be coming after.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:04:06,000 --> 00:04:13,000
|
| 251 |
+
Cybercriminals could be attacking non human readable for decryption or misuse of that data.
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:04:14,000 --> 00:04:16,000
|
| 255 |
+
Data protection is super important.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:04:16,000 --> 00:04:18,000
|
| 259 |
+
If the company is in some kind of a lawsuit.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:04:18,000 --> 00:04:23,000
|
| 263 |
+
You've got to remember as a security person to protect that data, because that data could be the one
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:04:23,000 --> 00:04:26,000
|
| 267 |
+
that proves that the company did nothing wrong.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:04:26,000 --> 00:04:29,000
|
| 271 |
+
And you will be collecting tons of financial information.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:04:29,000 --> 00:04:34,000
|
| 275 |
+
So you want to make sure you protect both of them to keep your company secure.
|
| 276 |
+
|
12 - Data Protection/004 Data Classification OB 3.3_en.srt
ADDED
|
@@ -0,0 +1,644 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
1
|
| 2 |
+
00:00:00,000 --> 00:00:05,000
|
| 3 |
+
Organizations today store a lot of information or particularly a lot of data.
|
| 4 |
+
|
| 5 |
+
2
|
| 6 |
+
00:00:05,000 --> 00:00:10,000
|
| 7 |
+
We have tons and tons of data, and the longer that company stays in business, the more data you're
|
| 8 |
+
|
| 9 |
+
3
|
| 10 |
+
00:00:10,000 --> 00:00:11,000
|
| 11 |
+
going to get.
|
| 12 |
+
|
| 13 |
+
4
|
| 14 |
+
00:00:11,000 --> 00:00:18,000
|
| 15 |
+
Now the question comes down to does all of that data have the same value?
|
| 16 |
+
|
| 17 |
+
5
|
| 18 |
+
00:00:18,000 --> 00:00:24,000
|
| 19 |
+
Do we apply the same set of controls to all of all the data?
|
| 20 |
+
|
| 21 |
+
6
|
| 22 |
+
00:00:24,000 --> 00:00:25,000
|
| 23 |
+
The answer is no.
|
| 24 |
+
|
| 25 |
+
7
|
| 26 |
+
00:00:25,000 --> 00:00:27,000
|
| 27 |
+
Different data sets have different value.
|
| 28 |
+
|
| 29 |
+
8
|
| 30 |
+
00:00:27,000 --> 00:00:31,000
|
| 31 |
+
For example, what's on a company's website is public information.
|
| 32 |
+
|
| 33 |
+
9
|
| 34 |
+
00:00:31,000 --> 00:00:35,000
|
| 35 |
+
That particular data, if it's lost, doesn't cost much harm to the business.
|
| 36 |
+
|
| 37 |
+
10
|
| 38 |
+
00:00:35,000 --> 00:00:40,000
|
| 39 |
+
But if the company uses a very particular manufacturing method or formula to produce a product, if
|
| 40 |
+
|
| 41 |
+
11
|
| 42 |
+
00:00:40,000 --> 00:00:45,000
|
| 43 |
+
that's lost, that's going to cause the company significant financial harm.
|
| 44 |
+
|
| 45 |
+
12
|
| 46 |
+
00:00:45,000 --> 00:00:49,000
|
| 47 |
+
We don't protect data, all the data with the same set of controls.
|
| 48 |
+
|
| 49 |
+
13
|
| 50 |
+
00:00:49,000 --> 00:00:58,000
|
| 51 |
+
We don't have unlimited resources to buy things like IDs systems, IPS, endpoint protection, firewall
|
| 52 |
+
|
| 53 |
+
14
|
| 54 |
+
00:00:58,000 --> 00:01:01,000
|
| 55 |
+
encryption, redundant systems, cloud storages, and so on and so on.
|
| 56 |
+
|
| 57 |
+
15
|
| 58 |
+
00:01:01,000 --> 00:01:04,000
|
| 59 |
+
All the different security controls you can think about.
|
| 60 |
+
|
| 61 |
+
16
|
| 62 |
+
00:01:04,000 --> 00:01:10,000
|
| 63 |
+
We don't have unlimited amount of money and people to buy, configure, setup and maintain all those
|
| 64 |
+
|
| 65 |
+
17
|
| 66 |
+
00:01:10,000 --> 00:01:11,000
|
| 67 |
+
controls.
|
| 68 |
+
|
| 69 |
+
18
|
| 70 |
+
00:01:11,000 --> 00:01:14,000
|
| 71 |
+
So what we have is we have a limited set of controls.
|
| 72 |
+
|
| 73 |
+
19
|
| 74 |
+
00:01:14,000 --> 00:01:15,000
|
| 75 |
+
We have a ton of data.
|
| 76 |
+
|
| 77 |
+
20
|
| 78 |
+
00:01:15,000 --> 00:01:22,000
|
| 79 |
+
So we have to take the limited resources and allocate it to ensure the right data gets the right protection.
|
| 80 |
+
|
| 81 |
+
21
|
| 82 |
+
00:01:22,000 --> 00:01:25,000
|
| 83 |
+
Or in other words, the right data gets the right control.
|
| 84 |
+
|
| 85 |
+
22
|
| 86 |
+
00:01:25,000 --> 00:01:27,000
|
| 87 |
+
The question is how do we determine that?
|
| 88 |
+
|
| 89 |
+
23
|
| 90 |
+
00:01:27,000 --> 00:01:29,000
|
| 91 |
+
How do we determine.
|
| 92 |
+
|
| 93 |
+
24
|
| 94 |
+
00:01:29,000 --> 00:01:32,000
|
| 95 |
+
Well, you're going to get those controls and you're going to get those controls.
|
| 96 |
+
|
| 97 |
+
25
|
| 98 |
+
00:01:32,000 --> 00:01:36,000
|
| 99 |
+
You're going to have a ton of controls and you're not going to have any control.
|
| 100 |
+
|
| 101 |
+
26
|
| 102 |
+
00:01:36,000 --> 00:01:39,000
|
| 103 |
+
The answer is data classification.
|
| 104 |
+
|
| 105 |
+
27
|
| 106 |
+
00:01:39,000 --> 00:01:42,000
|
| 107 |
+
And this starts this discussion on this topic.
|
| 108 |
+
|
| 109 |
+
28
|
| 110 |
+
00:01:43,000 --> 00:01:44,000
|
| 111 |
+
Now.
|
| 112 |
+
|
| 113 |
+
29
|
| 114 |
+
00:01:44,000 --> 00:01:48,000
|
| 115 |
+
Data classification affects all aspects of A of the data.
|
| 116 |
+
|
| 117 |
+
30
|
| 118 |
+
00:01:48,000 --> 00:01:50,000
|
| 119 |
+
When should a data.
|
| 120 |
+
|
| 121 |
+
31
|
| 122 |
+
00:01:50,000 --> 00:01:52,000
|
| 123 |
+
When should the data be backed up?
|
| 124 |
+
|
| 125 |
+
32
|
| 126 |
+
00:01:52,000 --> 00:01:53,000
|
| 127 |
+
Depends on a classification.
|
| 128 |
+
|
| 129 |
+
33
|
| 130 |
+
00:01:53,000 --> 00:01:54,000
|
| 131 |
+
Where should it be stored?
|
| 132 |
+
|
| 133 |
+
34
|
| 134 |
+
00:01:54,000 --> 00:01:56,000
|
| 135 |
+
Depends on this classification.
|
| 136 |
+
|
| 137 |
+
35
|
| 138 |
+
00:01:56,000 --> 00:02:00,000
|
| 139 |
+
Who should have access to it depends on its classification.
|
| 140 |
+
|
| 141 |
+
36
|
| 142 |
+
00:02:00,000 --> 00:02:02,000
|
| 143 |
+
How should it be processed?
|
| 144 |
+
|
| 145 |
+
37
|
| 146 |
+
00:02:02,000 --> 00:02:03,000
|
| 147 |
+
Depends on its classification.
|
| 148 |
+
|
| 149 |
+
38
|
| 150 |
+
00:02:03,000 --> 00:02:05,000
|
| 151 |
+
What type of machine should it be stored on?
|
| 152 |
+
|
| 153 |
+
39
|
| 154 |
+
00:02:05,000 --> 00:02:07,000
|
| 155 |
+
Depends on its classification.
|
| 156 |
+
|
| 157 |
+
40
|
| 158 |
+
00:02:07,000 --> 00:02:08,000
|
| 159 |
+
You get the point.
|
| 160 |
+
|
| 161 |
+
41
|
| 162 |
+
00:02:08,000 --> 00:02:12,000
|
| 163 |
+
Every single aspect of the data.
|
| 164 |
+
|
| 165 |
+
42
|
| 166 |
+
00:02:13,000 --> 00:02:18,000
|
| 167 |
+
Is going to be, or what happens to it is going to be dependent on that classification.
|
| 168 |
+
|
| 169 |
+
43
|
| 170 |
+
00:02:18,000 --> 00:02:24,000
|
| 171 |
+
So data classification helps in determining the level of security controls and handling protocols that
|
| 172 |
+
|
| 173 |
+
44
|
| 174 |
+
00:02:24,000 --> 00:02:26,000
|
| 175 |
+
should be applied to various kinds of data.
|
| 176 |
+
|
| 177 |
+
45
|
| 178 |
+
00:02:27,000 --> 00:02:34,000
|
| 179 |
+
Data classification helps with the creation, usage and determination and destruction of the data.
|
| 180 |
+
|
| 181 |
+
46
|
| 182 |
+
00:02:34,000 --> 00:02:39,000
|
| 183 |
+
For example public information information that's on your public website.
|
| 184 |
+
|
| 185 |
+
47
|
| 186 |
+
00:02:39,000 --> 00:02:44,000
|
| 187 |
+
When the when that server that was just storing public data, whenever you're ready to throw that server
|
| 188 |
+
|
| 189 |
+
48
|
| 190 |
+
00:02:44,000 --> 00:02:48,000
|
| 191 |
+
out or destroy the server, just put it in a garbage.
|
| 192 |
+
|
| 193 |
+
49
|
| 194 |
+
00:02:48,000 --> 00:02:49,000
|
| 195 |
+
Nothing else to do.
|
| 196 |
+
|
| 197 |
+
50
|
| 198 |
+
00:02:49,000 --> 00:02:53,000
|
| 199 |
+
Take out the hard drive and dump it in the bin because everything on the drive is public.
|
| 200 |
+
|
| 201 |
+
51
|
| 202 |
+
00:02:53,000 --> 00:02:59,000
|
| 203 |
+
But if that if that server was storing top secret data, you would want to degauss and shred the hard
|
| 204 |
+
|
| 205 |
+
52
|
| 206 |
+
00:02:59,000 --> 00:03:00,000
|
| 207 |
+
drive.
|
| 208 |
+
|
| 209 |
+
53
|
| 210 |
+
00:03:00,000 --> 00:03:06,000
|
| 211 |
+
So it has a different procedure to destroy the data depending on its classification.
|
| 212 |
+
|
| 213 |
+
54
|
| 214 |
+
00:03:07,000 --> 00:03:12,000
|
| 215 |
+
Now for your exam, the data owner determines the classification.
|
| 216 |
+
|
| 217 |
+
55
|
| 218 |
+
00:03:12,000 --> 00:03:15,000
|
| 219 |
+
You have to remember that who determines classification?
|
| 220 |
+
|
| 221 |
+
56
|
| 222 |
+
00:03:15,000 --> 00:03:17,000
|
| 223 |
+
The data owner does that.
|
| 224 |
+
|
| 225 |
+
57
|
| 226 |
+
00:03:17,000 --> 00:03:21,000
|
| 227 |
+
They will determine how critical it is, how sensitive it is.
|
| 228 |
+
|
| 229 |
+
58
|
| 230 |
+
00:03:21,000 --> 00:03:23,000
|
| 231 |
+
They're going to determine its value.
|
| 232 |
+
|
| 233 |
+
59
|
| 234 |
+
00:03:23,000 --> 00:03:24,000
|
| 235 |
+
They need to know.
|
| 236 |
+
|
| 237 |
+
60
|
| 238 |
+
00:03:24,000 --> 00:03:26,000
|
| 239 |
+
Don't forget the data owner determines Bob has access.
|
| 240 |
+
|
| 241 |
+
61
|
| 242 |
+
00:03:26,000 --> 00:03:28,000
|
| 243 |
+
Mary doesn't, or vice versa.
|
| 244 |
+
|
| 245 |
+
62
|
| 246 |
+
00:03:28,000 --> 00:03:32,000
|
| 247 |
+
They determine how to declassify it if it needs to be or destroy it.
|
| 248 |
+
|
| 249 |
+
63
|
| 250 |
+
00:03:32,000 --> 00:03:38,000
|
| 251 |
+
The whole objective of data classification, like I mentioned earlier, is to get the right controls
|
| 252 |
+
|
| 253 |
+
64
|
| 254 |
+
00:03:38,000 --> 00:03:43,000
|
| 255 |
+
to the right data owner will define the retention requirements.
|
| 256 |
+
|
| 257 |
+
65
|
| 258 |
+
00:03:43,000 --> 00:03:46,000
|
| 259 |
+
Data classifications will also define how long you keep it.
|
| 260 |
+
|
| 261 |
+
66
|
| 262 |
+
00:03:47,000 --> 00:03:54,000
|
| 263 |
+
Basically, the whole point of this entire topic is to the optimization of resources and keeping our
|
| 264 |
+
|
| 265 |
+
67
|
| 266 |
+
00:03:54,000 --> 00:03:55,000
|
| 267 |
+
data secure.
|
| 268 |
+
|
| 269 |
+
68
|
| 270 |
+
00:03:55,000 --> 00:03:56,000
|
| 271 |
+
Now.
|
| 272 |
+
|
| 273 |
+
69
|
| 274 |
+
00:03:57,000 --> 00:03:59,000
|
| 275 |
+
There's a couple of things here I want to mention.
|
| 276 |
+
|
| 277 |
+
70
|
| 278 |
+
00:04:00,000 --> 00:04:05,000
|
| 279 |
+
When it comes to classification, you have to think of the entire CIA.
|
| 280 |
+
|
| 281 |
+
71
|
| 282 |
+
00:04:05,000 --> 00:04:10,000
|
| 283 |
+
How sensitive it is, how critical it is sensitivity and critical, and how critical it is generally
|
| 284 |
+
|
| 285 |
+
72
|
| 286 |
+
00:04:10,000 --> 00:04:12,000
|
| 287 |
+
relate back to confidentiality.
|
| 288 |
+
|
| 289 |
+
73
|
| 290 |
+
00:04:12,000 --> 00:04:19,000
|
| 291 |
+
So you want to keep in mind these particular things when you're thinking about, for example, top secret
|
| 292 |
+
|
| 293 |
+
74
|
| 294 |
+
00:04:19,000 --> 00:04:26,000
|
| 295 |
+
data, secret data, public data, unclassified data, you have to think about these particular things.
|
| 296 |
+
|
| 297 |
+
75
|
| 298 |
+
00:04:26,000 --> 00:04:34,000
|
| 299 |
+
For example, in the military, they they prioritize our emphasized confidentiality.
|
| 300 |
+
|
| 301 |
+
76
|
| 302 |
+
00:04:34,000 --> 00:04:39,000
|
| 303 |
+
Fully emphasizing confidentiality may give up, for example, availability.
|
| 304 |
+
|
| 305 |
+
77
|
| 306 |
+
00:04:41,000 --> 00:04:47,000
|
| 307 |
+
A machine that is super secure, that no one can go in and just tamper with the machine and steal its
|
| 308 |
+
|
| 309 |
+
78
|
| 310 |
+
00:04:47,000 --> 00:04:47,000
|
| 311 |
+
data.
|
| 312 |
+
|
| 313 |
+
79
|
| 314 |
+
00:04:47,000 --> 00:04:52,000
|
| 315 |
+
A machine that's turned off and unplugged airgap the machine.
|
| 316 |
+
|
| 317 |
+
80
|
| 318 |
+
00:04:52,000 --> 00:04:56,000
|
| 319 |
+
Well, if it's air gapped, then only two people can get access to it and they have to put the machine
|
| 320 |
+
|
| 321 |
+
81
|
| 322 |
+
00:04:56,000 --> 00:04:57,000
|
| 323 |
+
on because it's not turned on.
|
| 324 |
+
|
| 325 |
+
82
|
| 326 |
+
00:04:58,000 --> 00:05:02,000
|
| 327 |
+
The problem with this is that, yes, good confidentiality, but it's not available to anyone except
|
| 328 |
+
|
| 329 |
+
83
|
| 330 |
+
00:05:02,000 --> 00:05:03,000
|
| 331 |
+
a few people.
|
| 332 |
+
|
| 333 |
+
84
|
| 334 |
+
00:05:03,000 --> 00:05:10,000
|
| 335 |
+
Low availability in private industries, though, we're going to emphasize the full CIA.
|
| 336 |
+
|
| 337 |
+
85
|
| 338 |
+
00:05:10,000 --> 00:05:12,000
|
| 339 |
+
We're going to want to push the full thing.
|
| 340 |
+
|
| 341 |
+
86
|
| 342 |
+
00:05:12,000 --> 00:05:16,000
|
| 343 |
+
We're going to try to get CIA for most of our data, not all of it.
|
| 344 |
+
|
| 345 |
+
87
|
| 346 |
+
00:05:16,000 --> 00:05:19,000
|
| 347 |
+
Keep your classification scheme simple.
|
| 348 |
+
|
| 349 |
+
88
|
| 350 |
+
00:05:19,000 --> 00:05:24,000
|
| 351 |
+
I'm going to talk about a different classification scheme that we can use, the different terms you
|
| 352 |
+
|
| 353 |
+
89
|
| 354 |
+
00:05:24,000 --> 00:05:25,000
|
| 355 |
+
can use in a minute.
|
| 356 |
+
|
| 357 |
+
90
|
| 358 |
+
00:05:25,000 --> 00:05:28,000
|
| 359 |
+
Here's an example though of a classification scheme.
|
| 360 |
+
|
| 361 |
+
91
|
| 362 |
+
00:05:28,000 --> 00:05:31,000
|
| 363 |
+
So for example this is just an example.
|
| 364 |
+
|
| 365 |
+
92
|
| 366 |
+
00:05:31,000 --> 00:05:34,000
|
| 367 |
+
Like in the military when we're talking protection of data.
|
| 368 |
+
|
| 369 |
+
93
|
| 370 |
+
00:05:34,000 --> 00:05:39,000
|
| 371 |
+
Look at how the different classification will determine what type of controls.
|
| 372 |
+
|
| 373 |
+
94
|
| 374 |
+
00:05:40,000 --> 00:05:41,000
|
| 375 |
+
If you have data.
|
| 376 |
+
|
| 377 |
+
95
|
| 378 |
+
00:05:42,000 --> 00:05:46,000
|
| 379 |
+
Particularly something like on paper, if it's top secret, put it in a vault.
|
| 380 |
+
|
| 381 |
+
96
|
| 382 |
+
00:05:46,000 --> 00:05:49,000
|
| 383 |
+
If it's secret, a safe would be okay.
|
| 384 |
+
|
| 385 |
+
97
|
| 386 |
+
00:05:49,000 --> 00:05:53,000
|
| 387 |
+
Confidential, maybe a filing cabinet with a metal bar and a lock.
|
| 388 |
+
|
| 389 |
+
98
|
| 390 |
+
00:05:53,000 --> 00:05:54,000
|
| 391 |
+
And on classified.
|
| 392 |
+
|
| 393 |
+
99
|
| 394 |
+
00:05:54,000 --> 00:05:54,000
|
| 395 |
+
No protection.
|
| 396 |
+
|
| 397 |
+
100
|
| 398 |
+
00:05:54,000 --> 00:05:55,000
|
| 399 |
+
Leave it on the desk.
|
| 400 |
+
|
| 401 |
+
101
|
| 402 |
+
00:05:55,000 --> 00:06:00,000
|
| 403 |
+
Notice the different classification results in different controls.
|
| 404 |
+
|
| 405 |
+
102
|
| 406 |
+
00:06:01,000 --> 00:06:08,000
|
| 407 |
+
Now, the question that a lot of people ask me is, Andrew, what are the different classification schemes
|
| 408 |
+
|
| 409 |
+
103
|
| 410 |
+
00:06:08,000 --> 00:06:09,000
|
| 411 |
+
that we can use?
|
| 412 |
+
|
| 413 |
+
104
|
| 414 |
+
00:06:09,000 --> 00:06:18,000
|
| 415 |
+
There is no official definition of any potential or any classification scheme that is out there.
|
| 416 |
+
|
| 417 |
+
105
|
| 418 |
+
00:06:18,000 --> 00:06:25,000
|
| 419 |
+
Many books that we read, CISSP books, Security+ books, even the books on Ec-council.
|
| 420 |
+
|
| 421 |
+
106
|
| 422 |
+
00:06:25,000 --> 00:06:31,000
|
| 423 |
+
They're going to vary in the definitions because there's no definition and the exam will never ask you,
|
| 424 |
+
|
| 425 |
+
107
|
| 426 |
+
00:06:31,000 --> 00:06:34,000
|
| 427 |
+
is this secret, top secret or confidential?
|
| 428 |
+
|
| 429 |
+
108
|
| 430 |
+
00:06:34,000 --> 00:06:35,000
|
| 431 |
+
They'll never do that.
|
| 432 |
+
|
| 433 |
+
109
|
| 434 |
+
00:06:35,000 --> 00:06:38,000
|
| 435 |
+
Just understand what data classification is.
|
| 436 |
+
|
| 437 |
+
110
|
| 438 |
+
00:06:38,000 --> 00:06:42,000
|
| 439 |
+
I want to show you an example of what you could use though.
|
| 440 |
+
|
| 441 |
+
111
|
| 442 |
+
00:06:43,000 --> 00:06:46,000
|
| 443 |
+
Uh, this is a classification scheme that you could use.
|
| 444 |
+
|
| 445 |
+
112
|
| 446 |
+
00:06:46,000 --> 00:06:50,000
|
| 447 |
+
And I want to show you how different schemes mean different things.
|
| 448 |
+
|
| 449 |
+
113
|
| 450 |
+
00:06:50,000 --> 00:06:52,000
|
| 451 |
+
So let's take a look here.
|
| 452 |
+
|
| 453 |
+
114
|
| 454 |
+
00:06:52,000 --> 00:06:54,000
|
| 455 |
+
So here's a data classification scheme.
|
| 456 |
+
|
| 457 |
+
115
|
| 458 |
+
00:06:54,000 --> 00:06:57,000
|
| 459 |
+
So on this one we have four classes 0 to 3.
|
| 460 |
+
|
| 461 |
+
116
|
| 462 |
+
00:06:58,000 --> 00:07:01,000
|
| 463 |
+
And on the bottom of the triangle let's go with non-government.
|
| 464 |
+
|
| 465 |
+
117
|
| 466 |
+
00:07:01,000 --> 00:07:03,000
|
| 467 |
+
First let's see a private organization.
|
| 468 |
+
|
| 469 |
+
118
|
| 470 |
+
00:07:03,000 --> 00:07:05,000
|
| 471 |
+
Class zero is no damage.
|
| 472 |
+
|
| 473 |
+
119
|
| 474 |
+
00:07:05,000 --> 00:07:09,000
|
| 475 |
+
Any data that's classified as public has no damage.
|
| 476 |
+
|
| 477 |
+
120
|
| 478 |
+
00:07:09,000 --> 00:07:11,000
|
| 479 |
+
If it's released to the public no damage.
|
| 480 |
+
|
| 481 |
+
121
|
| 482 |
+
00:07:11,000 --> 00:07:12,000
|
| 483 |
+
All right.
|
| 484 |
+
|
| 485 |
+
122
|
| 486 |
+
00:07:12,000 --> 00:07:19,000
|
| 487 |
+
Maybe like upcoming projects, the company is doing class one sensitive does cause damage to the business.
|
| 488 |
+
|
| 489 |
+
123
|
| 490 |
+
00:07:19,000 --> 00:07:23,000
|
| 491 |
+
Things like the company's financial, like its profit and loss statement.
|
| 492 |
+
|
| 493 |
+
124
|
| 494 |
+
00:07:23,000 --> 00:07:25,000
|
| 495 |
+
Serious damage like a class two.
|
| 496 |
+
|
| 497 |
+
125
|
| 498 |
+
00:07:25,000 --> 00:07:27,000
|
| 499 |
+
This one is private.
|
| 500 |
+
|
| 501 |
+
126
|
| 502 |
+
00:07:27,000 --> 00:07:30,000
|
| 503 |
+
This would be like releasing air information about the company's employees.
|
| 504 |
+
|
| 505 |
+
127
|
| 506 |
+
00:07:30,000 --> 00:07:33,000
|
| 507 |
+
And then of course, grave damage to that business.
|
| 508 |
+
|
| 509 |
+
128
|
| 510 |
+
00:07:33,000 --> 00:07:36,000
|
| 511 |
+
Confidential or proprietary data like trade secrets.
|
| 512 |
+
|
| 513 |
+
129
|
| 514 |
+
00:07:36,000 --> 00:07:41,000
|
| 515 |
+
If you are the federal government, here's a classification that you can use.
|
| 516 |
+
|
| 517 |
+
130
|
| 518 |
+
00:07:41,000 --> 00:07:43,000
|
| 519 |
+
Top secret wartime information.
|
| 520 |
+
|
| 521 |
+
131
|
| 522 |
+
00:07:43,000 --> 00:07:44,000
|
| 523 |
+
This is released.
|
| 524 |
+
|
| 525 |
+
132
|
| 526 |
+
00:07:44,000 --> 00:07:48,000
|
| 527 |
+
Grave damage to national security troop deployment information.
|
| 528 |
+
|
| 529 |
+
133
|
| 530 |
+
00:07:48,000 --> 00:07:51,000
|
| 531 |
+
This would be serious damage to national security.
|
| 532 |
+
|
| 533 |
+
134
|
| 534 |
+
00:07:51,000 --> 00:07:56,000
|
| 535 |
+
Confidential is like trade secrets or health care information of government workers that are non classified
|
| 536 |
+
|
| 537 |
+
135
|
| 538 |
+
00:07:56,000 --> 00:07:58,000
|
| 539 |
+
is going to be their version of public.
|
| 540 |
+
|
| 541 |
+
136
|
| 542 |
+
00:07:58,000 --> 00:08:01,000
|
| 543 |
+
Now this is just an example.
|
| 544 |
+
|
| 545 |
+
137
|
| 546 |
+
00:08:01,000 --> 00:08:02,000
|
| 547 |
+
Okay.
|
| 548 |
+
|
| 549 |
+
138
|
| 550 |
+
00:08:02,000 --> 00:08:04,000
|
| 551 |
+
This is just an example.
|
| 552 |
+
|
| 553 |
+
139
|
| 554 |
+
00:08:04,000 --> 00:08:05,000
|
| 555 |
+
All right.
|
| 556 |
+
|
| 557 |
+
140
|
| 558 |
+
00:08:05,000 --> 00:08:10,000
|
| 559 |
+
Here at TI we only use three levels of data classification I know companies that only use two.
|
| 560 |
+
|
| 561 |
+
141
|
| 562 |
+
00:08:10,000 --> 00:08:12,000
|
| 563 |
+
You don't have to use them all.
|
| 564 |
+
|
| 565 |
+
142
|
| 566 |
+
00:08:12,000 --> 00:08:18,000
|
| 567 |
+
But when it comes to data classification, here are some different, uh, terms that you can use.
|
| 568 |
+
|
| 569 |
+
143
|
| 570 |
+
00:08:18,000 --> 00:08:20,000
|
| 571 |
+
Sensitive confidential.
|
| 572 |
+
|
| 573 |
+
144
|
| 574 |
+
00:08:20,000 --> 00:08:21,000
|
| 575 |
+
Public I think has a universal meaning.
|
| 576 |
+
|
| 577 |
+
145
|
| 578 |
+
00:08:21,000 --> 00:08:23,000
|
| 579 |
+
Anyone can access it.
|
| 580 |
+
|
| 581 |
+
146
|
| 582 |
+
00:08:23,000 --> 00:08:25,000
|
| 583 |
+
But for example, what are some companies may call it private.
|
| 584 |
+
|
| 585 |
+
147
|
| 586 |
+
00:08:25,000 --> 00:08:32,000
|
| 587 |
+
Some may call it confidential, what some call sensitive, some may call restricted, what some call
|
| 588 |
+
|
| 589 |
+
148
|
| 590 |
+
00:08:32,000 --> 00:08:34,000
|
| 591 |
+
confidential, some may call it critical.
|
| 592 |
+
|
| 593 |
+
149
|
| 594 |
+
00:08:34,000 --> 00:08:39,000
|
| 595 |
+
And then of course, the military will add things like secret and top secret on top of this.
|
| 596 |
+
|
| 597 |
+
150
|
| 598 |
+
00:08:39,000 --> 00:08:41,000
|
| 599 |
+
Or maybe a line in here with these.
|
| 600 |
+
|
| 601 |
+
151
|
| 602 |
+
00:08:41,000 --> 00:08:45,000
|
| 603 |
+
There really isn't a full definition.
|
| 604 |
+
|
| 605 |
+
152
|
| 606 |
+
00:08:46,000 --> 00:08:50,000
|
| 607 |
+
Now when it comes to your exam and data classification, remember something.
|
| 608 |
+
|
| 609 |
+
153
|
| 610 |
+
00:08:50,000 --> 00:08:52,000
|
| 611 |
+
Data classification is a big terme.
|
| 612 |
+
|
| 613 |
+
154
|
| 614 |
+
00:08:52,000 --> 00:09:00,000
|
| 615 |
+
Data classification is the umbrella terms that affects all controls of the data.
|
| 616 |
+
|
| 617 |
+
155
|
| 618 |
+
00:09:01,000 --> 00:09:04,000
|
| 619 |
+
Like I mentioned earlier in the beginning, let's do a quick recap.
|
| 620 |
+
|
| 621 |
+
156
|
| 622 |
+
00:09:04,000 --> 00:09:11,000
|
| 623 |
+
Data classification affects everything about the data, determines what controls is applied to what
|
| 624 |
+
|
| 625 |
+
157
|
| 626 |
+
00:09:11,000 --> 00:09:15,000
|
| 627 |
+
data, determines who should have access to it, or you can't access this because you're not in the
|
| 628 |
+
|
| 629 |
+
158
|
| 630 |
+
00:09:15,000 --> 00:09:18,000
|
| 631 |
+
top secret clearance, or you can't access this because you don't.
|
| 632 |
+
|
| 633 |
+
159
|
| 634 |
+
00:09:18,000 --> 00:09:20,000
|
| 635 |
+
You can't access confidential data.
|
| 636 |
+
|
| 637 |
+
160
|
| 638 |
+
00:09:20,000 --> 00:09:23,000
|
| 639 |
+
You can access public data, things like that.
|
| 640 |
+
|
| 641 |
+
161
|
| 642 |
+
00:09:23,000 --> 00:09:26,000
|
| 643 |
+
Keep this in mind when answering your exam questions.
|
| 644 |
+
|