diff --git a/.gitattributes b/.gitattributes index 781751064c5b7d25795701f8db6c7131a394e321..8272af31b311785108f0a0d047f4ca74fb3d1e6a 100644 --- a/.gitattributes +++ b/.gitattributes @@ -65,3 +65,34 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text 04[[:space:]]-[[:space:]]Threats/006[[:space:]]Hacktivist[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text 04[[:space:]]-[[:space:]]Threats/007[[:space:]]Organized[[:space:]]Crime[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text 04[[:space:]]-[[:space:]]Threats/008[[:space:]]Shadow[[:space:]]IT[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/001[[:space:]]Vulnerabilities[[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +04[[:space:]]-[[:space:]]Threats/009[[:space:]]Threat[[:space:]]Vectors[[:space:]]and[[:space:]]Attack[[:space:]]Surfaces[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/003[[:space:]]Race[[:space:]]Conditions[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/004[[:space:]]Malicious[[:space:]]Updates[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/002[[:space:]]Memory[[:space:]]injection[[:space:]]and[[:space:]]buffer[[:space:]]overflows[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/005[[:space:]]OS-Based[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/007[[:space:]]XSS[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/008[[:space:]]Hardware[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/006[[:space:]]SQL[[:space:]]Injections[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/009[[:space:]]VM[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/011[[:space:]]Supply[[:space:]]Chain[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/010[[:space:]]Cloud-specific[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/012[[:space:]]Cryptographic[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/013[[:space:]]Misconfiguration[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/014[[:space:]]Mobile[[:space:]]Device[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +05[[:space:]]-[[:space:]]Vulnerabilities/015[[:space:]]Zero-day[[:space:]]Vulnerabilities[[:space:]][[:space:]]OB[[:space:]]2.3.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/001[[:space:]]Malware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/002[[:space:]]Viruses[[:space:]][[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/004[[:space:]]Trojans[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/003[[:space:]]Worms[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/006[[:space:]]Spyware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/007[[:space:]]Rootkit[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/008[[:space:]]Logic[[:space:]]Bomb[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/005[[:space:]]Ransomware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/010[[:space:]]Bloatware[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/009[[:space:]]Keyloggers[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/012[[:space:]]DNS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/013[[:space:]]Onpath[[:space:]]Attack[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/011[[:space:]]DDOS[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/014[[:space:]]Credential[[:space:]]Replay[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text +06[[:space:]]-[[:space:]]Signs[[:space:]]of[[:space:]]Attacks/015[[:space:]]Privilege[[:space:]]Escalation[[:space:]]OB[[:space:]]2.4.mp4 filter=lfs diff=lfs merge=lfs -text diff --git a/04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2.mp4 b/04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..181f3a1ff432718243d18cecf1cb799ef669be6a --- /dev/null +++ b/04 - Threats/009 Threat Vectors and Attack Surfaces OB 2.2.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:0ea8bb280b7aa00ee6e5ff91314a79037663623e7fc0b5bc46c28628bd17c02d +size 358178371 diff --git a/05 - Vulnerabilities/001 Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/001 Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..59784638ef804bc69aee780548cba230eca78ad8 --- /dev/null +++ b/05 - Vulnerabilities/001 Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:cb6b5599cca6eea9c2736821187b2aca950a91ed895c076d4afa1a635fda33d4 +size 51453967 diff --git a/05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3.mp4 b/05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5e9c67d9016c57d3a196da337777618515737ed3 --- /dev/null +++ b/05 - Vulnerabilities/002 Memory injection and buffer overflows OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:f68268c8a6df35545a34b6537ff1ae3457a4a8a1f3413909a541023c7c3533fe +size 303240221 diff --git a/05 - Vulnerabilities/003 Race Conditions OB 2.3.mp4 b/05 - Vulnerabilities/003 Race Conditions OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..9fa8d42528b33d6eaa72948d4116f4c79f2dfaa8 --- /dev/null +++ b/05 - Vulnerabilities/003 Race Conditions OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:827629d12a9db8054ddd7bb753593d6cd2cd3395f43a6309f817875330c90f57 +size 218816868 diff --git a/05 - Vulnerabilities/004 Malicious Updates OB 2.3.mp4 b/05 - Vulnerabilities/004 Malicious Updates OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..57109ff719fb52b5826f04daa892e575438e5589 --- /dev/null +++ b/05 - Vulnerabilities/004 Malicious Updates OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:224434b0ef6bdf7a0421decbf0ac02826ca27f1b0b631d052af6e86d3d65205a +size 69037281 diff --git a/05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..0e97a13242b4293aaaf807b46f4c268d37004682 --- /dev/null +++ b/05 - Vulnerabilities/005 OS-Based Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:58c34142c72f36bd099bc2e9175544ef81586d217f9782088d54545c5f48c0ec +size 226457460 diff --git a/05 - Vulnerabilities/006 SQL Injections OB 2.3.mp4 b/05 - Vulnerabilities/006 SQL Injections OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..b9346f553ef00902c857a2fd1c4fc65e92d43845 --- /dev/null +++ b/05 - Vulnerabilities/006 SQL Injections OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:eac89091ca6406c03551377c8688fd4f52d61ea836f83a9a88fca22983059eb0 +size 408025612 diff --git a/05 - Vulnerabilities/007 XSS OB 2.3.mp4 b/05 - Vulnerabilities/007 XSS OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5f0ddadc7823cd1c75a862c6c16a05df24899d20 --- /dev/null +++ b/05 - Vulnerabilities/007 XSS OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:1ebc247a98f8eb09c18681b79469de174d97f5b3bde93a4d44d1f383a772ef17 +size 135683436 diff --git a/05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..98e3ea89be62837189a0f9d7753ae22d0fa26efc --- /dev/null +++ b/05 - Vulnerabilities/008 Hardware Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7300861fccd624dcc80384ffec805620c4605fa31cd3435e4fca9f74433ce30d +size 175563789 diff --git a/05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..372611dbc9e39292555caefacb3b41a02942f2a4 --- /dev/null +++ b/05 - Vulnerabilities/009 VM Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:7ac9de70b4d06911c5960aa76d9d9e178d5fd0d57d42cf7c553f0df071456adc +size 89576988 diff --git a/05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..c6e25a7425978db0308673f27a60c6d13c9476bd --- /dev/null +++ b/05 - Vulnerabilities/010 Cloud-specific Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:22e716b22c428835c49530cf3483a6b38b841fbc70b803e0055513dbb7c020f2 +size 316842710 diff --git a/05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..1e8f944f420ad699873fc388885d52452a9c207f --- /dev/null +++ b/05 - Vulnerabilities/011 Supply Chain Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:09f04bddcaebb5f48817b818fe3db8c8df91a70cc8e1cf628d74965009d87964 +size 269551046 diff --git a/05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..b7c481886963b6188171fd2c641c426b21c3d353 --- /dev/null +++ b/05 - Vulnerabilities/012 Cryptographic Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:0d9d15aa0b12a658e8ccce53dd290c49c87091e21c64ecff4f22e24b404ceba7 +size 198706946 diff --git a/05 - Vulnerabilities/013 Misconfiguration OB 2.3.mp4 b/05 - Vulnerabilities/013 Misconfiguration OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..002d2aea2fe77e4b333d0926488360a6b66d8e93 --- /dev/null +++ b/05 - Vulnerabilities/013 Misconfiguration OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:85c11b70fa06e0769ea994ff665d1bf07a2b0c03cdd67298bf1f2eb45b97c5fa +size 176934829 diff --git a/05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..c145488aa1195fe566a3066843b07b93d7f4ad88 --- /dev/null +++ b/05 - Vulnerabilities/014 Mobile Device Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:0fbe44a5da82866917e877f6218b89d8453d1fcfae4552f30b87cc3935a1bfde +size 428914675 diff --git a/05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3.mp4 b/05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..f1a9e61c2a8921b8f55e7f7f34f627948c68d7a5 --- /dev/null +++ b/05 - Vulnerabilities/015 Zero-day Vulnerabilities OB 2.3.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:12993189b8460e9f3acfed58036f5a19a4b20ef26605359d2fa858e4b3dd0009 +size 180828460 diff --git a/06 - Signs of Attacks/001 Malware OB 2.4.mp4 b/06 - Signs of Attacks/001 Malware OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5bf2df3d024115afebd1df69060eec333c660a3e --- /dev/null +++ b/06 - Signs of Attacks/001 Malware OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b81cb76d342e2cf86c742e50cfcb7d13c031c85aa5ea688543554782e20aad07 +size 35123665 diff --git a/06 - Signs of Attacks/002 Viruses OB 2.4.mp4 b/06 - Signs of Attacks/002 Viruses OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5c31d420f71bad477b772ffaea043c9b0a344979 --- /dev/null +++ b/06 - Signs of Attacks/002 Viruses OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:15d6f166dbb596a6b3bb9e2f6da2cbfed8b994740dfa98146fbaf91769413057 +size 314530848 diff --git a/06 - Signs of Attacks/003 Worms OB 2.4.mp4 b/06 - Signs of Attacks/003 Worms OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..3bb1859850911c6928b42eb34f39a9eab0f0f744 --- /dev/null +++ b/06 - Signs of Attacks/003 Worms OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:3e83018efbed549c09b383906c59a3c4460f03cff47704283c4c7888340fe6e9 +size 216076980 diff --git a/06 - Signs of Attacks/004 Trojans OB 2.4.mp4 b/06 - Signs of Attacks/004 Trojans OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..f3368b20f5483980d4b67a8778ffacd2268541af --- /dev/null +++ b/06 - Signs of Attacks/004 Trojans OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:ebe35a406da737d6f80d67253e884141c0f52aee970099aa8425df24b1e6396a +size 156627975 diff --git a/06 - Signs of Attacks/005 Ransomware OB 2.4.mp4 b/06 - Signs of Attacks/005 Ransomware OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..464bc02892f0880106cb46f9330deeaa8953ebad --- /dev/null +++ b/06 - Signs of Attacks/005 Ransomware OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:cba44cc2f789d7f0f71483eae60d97a517b718f29d2817e5815b1a000bf425bd +size 249594928 diff --git a/06 - Signs of Attacks/006 Spyware OB 2.4.mp4 b/06 - Signs of Attacks/006 Spyware OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..38f1181d19fc4e8ff9d88545211f3fa191f58c7d --- /dev/null +++ b/06 - Signs of Attacks/006 Spyware OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fa3bb793eb84c4f30d6036707ff90ef34fd5c478c7159cef46d5c268b09165df +size 142438065 diff --git a/06 - Signs of Attacks/007 Rootkit OB 2.4.mp4 b/06 - Signs of Attacks/007 Rootkit OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..a1c2601b2cde4224b92c9d1605f0dbe99c5ecee9 --- /dev/null +++ b/06 - Signs of Attacks/007 Rootkit OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:a587afe5ed336a341348c0f88fedbf5a5f4d27cf8cfafb8899c085755d158695 +size 154446570 diff --git a/06 - Signs of Attacks/008 Logic Bomb OB 2.4.mp4 b/06 - Signs of Attacks/008 Logic Bomb OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..3d7447ecead66262a66278a312ee517dcac1b099 --- /dev/null +++ b/06 - Signs of Attacks/008 Logic Bomb OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:923d96eca9619dc8fd2982cdf24f4f9397626c36f5dd66cbc3386f2b91bbbc52 +size 101035815 diff --git a/06 - Signs of Attacks/009 Keyloggers OB 2.4.mp4 b/06 - Signs of Attacks/009 Keyloggers OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..2d99c6c4371d99ce7be83b9b4e8f4af963c73ac1 --- /dev/null +++ b/06 - Signs of Attacks/009 Keyloggers OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:2679df59b2c32e13cc3300549d25a8dc8a0d97f17800d367c74bd4193928ebc9 +size 237412212 diff --git a/06 - Signs of Attacks/010 Bloatware OB 2.4.mp4 b/06 - Signs of Attacks/010 Bloatware OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..82e04865e203d4dcff8fad3f86446e6e91f115f1 --- /dev/null +++ b/06 - Signs of Attacks/010 Bloatware OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:fac8a4f1ace9423b2a2c0dd5461d0e98c56c5ff76f77b0b051af18f59ee0fe9c +size 74555519 diff --git a/06 - Signs of Attacks/011 DDOS OB 2.4.mp4 b/06 - Signs of Attacks/011 DDOS OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..ae29b39231ecaae4ef3ec0bd2706942a0e5ece33 --- /dev/null +++ b/06 - Signs of Attacks/011 DDOS OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:69dcc08a90ce0d4cf044b01258d8e48b84c7e34b84bac088d57543d5579db03e +size 613421399 diff --git a/06 - Signs of Attacks/012 DNS OB 2.4.mp4 b/06 - Signs of Attacks/012 DNS OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..da84b50e87a6d6b5a4899232147bc1d7a32211a3 --- /dev/null +++ b/06 - Signs of Attacks/012 DNS OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b612b9f273589d5f6721a35735ea5ed9fd8379f95084693b1b835e872681a8dc +size 483439518 diff --git a/06 - Signs of Attacks/013 Onpath Attack OB 2.4.mp4 b/06 - Signs of Attacks/013 Onpath Attack OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..5f9276adb51b00908e43ab673742ef6c5d0e21b0 --- /dev/null +++ b/06 - Signs of Attacks/013 Onpath Attack OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:68088df41f07e4224ed283a402705a7a282be595a3658a10edb77010f1085c5c +size 285525484 diff --git a/06 - Signs of Attacks/014 Credential Replay OB 2.4.mp4 b/06 - Signs of Attacks/014 Credential Replay OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..c2dcec5d075aba94b09a7b28634c1a885407ecd2 --- /dev/null +++ b/06 - Signs of Attacks/014 Credential Replay OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:57f8c7337a266a61625b6f6b8cc1391a578baede810e98a3899df66a98ab58df +size 192202206 diff --git a/06 - Signs of Attacks/015 Privilege Escalation OB 2.4.mp4 b/06 - Signs of Attacks/015 Privilege Escalation OB 2.4.mp4 new file mode 100644 index 0000000000000000000000000000000000000000..f6c343e267e4223183f6de0b1218bc824e44cd8c --- /dev/null +++ b/06 - Signs of Attacks/015 Privilege Escalation OB 2.4.mp4 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:521b6ee434ae5b7389c51416249182d8b4b6a8aead0235b28082f271380afcf2 +size 176957870 diff --git a/07 - Cryptography/008 Asymmetric Encryption OB 1.4_en.srt b/07 - Cryptography/008 Asymmetric Encryption OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..16b3dccc1515f56ab49496bfce8e264c8253e856 --- /dev/null +++ b/07 - Cryptography/008 Asymmetric Encryption OB 1.4_en.srt @@ -0,0 +1,852 @@ +1 +00:00:00,000 --> 00:00:00,000 +Okay. + +2 +00:00:00,000 --> 00:00:02,000 +So we just covered symmetric encryption. + +3 +00:00:02,000 --> 00:00:08,000 +And if you remember correctly the key to choosing to encrypt is the same key that's used to decrypt. + +4 +00:00:08,000 --> 00:00:13,000 +When in this video I want to take a deep dive into the concepts of asymmetric cryptography. + +5 +00:00:13,000 --> 00:00:19,000 +Now I briefly mentioned that asymmetric and symmetric combines together in a hybrid cryptography system + +6 +00:00:19,000 --> 00:00:21,000 +to actually transport secure data. + +7 +00:00:21,000 --> 00:00:23,000 +So you actually. + +8 +00:00:24,000 --> 00:00:28,000 +Can't really do secure communication today technically without asymmetric. + +9 +00:00:28,000 --> 00:00:30,000 +So let's get a deep dive into it. + +10 +00:00:30,000 --> 00:00:32,000 +But what exactly is it you see? + +11 +00:00:32,000 --> 00:00:33,000 +Asymmetric encryption. + +12 +00:00:33,000 --> 00:00:34,000 +So the word symmetric means the same. + +13 +00:00:34,000 --> 00:00:36,000 +Asymmetric is going to mean different. + +14 +00:00:37,000 --> 00:00:38,000 +Is known. + +15 +00:00:38,000 --> 00:00:43,000 +First of all I want to mention is something we call public key cryptography. + +16 +00:00:43,000 --> 00:00:43,000 +All right. + +17 +00:00:43,000 --> 00:00:45,000 +Public key cryptography. + +18 +00:00:45,000 --> 00:00:50,000 +Now, keep in mind, if anybody ever says you read in any book, they say something like secret key + +19 +00:00:50,000 --> 00:00:53,000 +cryptography or private key cryptography. + +20 +00:00:53,000 --> 00:00:58,000 +That is symmetric public key cryptography is asymmetric. + +21 +00:00:59,000 --> 00:01:06,000 +This is a cryptographic system that uses pairs of keys, a public key which is given out widely, and + +22 +00:01:06,000 --> 00:01:08,000 +a private key which is only known to the users. + +23 +00:01:08,000 --> 00:01:13,000 +So everybody has two keys, a public key and a private key. + +24 +00:01:13,000 --> 00:01:17,000 +The public key encryption decrypts and it's given with anyone. + +25 +00:01:17,000 --> 00:01:20,000 +The private key can also encrypt and decrypt, and it's kept with the owner. + +26 +00:01:20,000 --> 00:01:21,000 +No one gets it. + +27 +00:01:21,000 --> 00:01:26,000 +Remember that everybody in the crypto system has two keys. + +28 +00:01:26,000 --> 00:01:32,000 +So for example, let's say I got me Mary and Bob. + +29 +00:01:32,000 --> 00:01:33,000 +Well easy. + +30 +00:01:33,000 --> 00:01:35,000 +I'm going to have a public private key. + +31 +00:01:35,000 --> 00:01:37,000 +Mary is going to have a public private key. + +32 +00:01:37,000 --> 00:01:42,000 +And Bob is going to have and Bob is going to have a public everybody has a public private key. + +33 +00:01:42,000 --> 00:01:46,000 +The way the encryption process works is different than symmetric and symmetric. + +34 +00:01:46,000 --> 00:01:50,000 +I generate the data, I generate the key I encrypted, give them the data, give them the key. + +35 +00:01:50,000 --> 00:01:51,000 +They use the key to decrypt the data. + +36 +00:01:51,000 --> 00:01:53,000 +This is going to work different. + +37 +00:01:53,000 --> 00:01:58,000 +And for that I want to I want to draw a little diagram here to get you guys an understanding of the + +38 +00:01:58,000 --> 00:02:00,000 +encryption and decryption process. + +39 +00:02:02,000 --> 00:02:05,000 +So let's go in here and let me just draw. + +40 +00:02:05,000 --> 00:02:07,000 +Let's say you have two users on a network. + +41 +00:02:07,000 --> 00:02:11,000 +There's Andrew and there's Mary. + +42 +00:02:11,000 --> 00:02:18,000 +Now the way the encryption process works here is that I'm going to have a public private Mary also has + +43 +00:02:18,000 --> 00:02:20,000 +a public private key. + +44 +00:02:20,000 --> 00:02:24,000 +But let's say I want to transfer data to Mary. + +45 +00:02:24,000 --> 00:02:26,000 +I want to give Mary the answers to the exam. + +46 +00:02:26,000 --> 00:02:27,000 +So. + +47 +00:02:28,000 --> 00:02:29,000 +How am I going to do it? + +48 +00:02:29,000 --> 00:02:31,000 +Well, I have data. + +49 +00:02:32,000 --> 00:02:34,000 +That I want to transfer to Mary. + +50 +00:02:34,000 --> 00:02:38,000 +What I'm going to do and says, hey, Mary, you you're free. + +51 +00:02:38,000 --> 00:02:41,000 +Okay, Mary, can you send me your public key? + +52 +00:02:41,000 --> 00:02:45,000 +Mary sends me her public key, and I encrypt the data with the public key. + +53 +00:02:45,000 --> 00:02:47,000 +And now I got cipher text. + +54 +00:02:47,000 --> 00:02:50,000 +I send it to Mary, a cipher text. + +55 +00:02:50,000 --> 00:02:57,000 +Mary then utilizes her private key to decrypt this data to get the plain text or the data. + +56 +00:02:58,000 --> 00:02:59,000 +So. + +57 +00:03:01,000 --> 00:03:02,000 +I put some lines here. + +58 +00:03:02,000 --> 00:03:07,000 +So that's the decryption process encryption and decryption process. + +59 +00:03:07,000 --> 00:03:12,000 +Now technically it doesn't actually work like this because we don't actually do this. + +60 +00:03:13,000 --> 00:03:15,000 +Uh, we use it in a hybrid method, but I'm going to cover that later. + +61 +00:03:15,000 --> 00:03:17,000 +But for now, just this is good enough. + +62 +00:03:18,000 --> 00:03:20,000 +Now I want to point out a couple of things here. + +63 +00:03:20,000 --> 00:03:23,000 +You notice that I never utilized any of my keys. + +64 +00:03:24,000 --> 00:03:26,000 +I utilize the person that was receiving the data keys. + +65 +00:03:26,000 --> 00:03:28,000 +I utilize their public key, right? + +66 +00:03:28,000 --> 00:03:29,000 +Did you see that? + +67 +00:03:29,000 --> 00:03:30,000 +Think about going to Amazon. + +68 +00:03:30,000 --> 00:03:33,000 +When you go to Amazon, you don't have any keys, but Amazon does. + +69 +00:03:34,000 --> 00:03:36,000 +Keep this in mind when I get to SSL. + +70 +00:03:36,000 --> 00:03:41,000 +So this is a really important system because there's a couple of things here I want to point out. + +71 +00:03:41,000 --> 00:03:46,000 +Notice the public key encrypted the data and a private key decrypted data. + +72 +00:03:46,000 --> 00:03:47,000 +That's a concept you need to understand. + +73 +00:03:48,000 --> 00:03:52,000 +So when one key encrypts, only the other key can decrypt it. + +74 +00:03:52,000 --> 00:03:56,000 +So when a public key encrypts, only the corresponding private key can decrypt it. + +75 +00:03:56,000 --> 00:03:59,000 +If the private key encrypts it and it does encrypt. + +76 +00:03:59,000 --> 00:04:03,000 +For those of you that say no in a digital signature, a private key does decrypt. + +77 +00:04:03,000 --> 00:04:03,000 +I'm sorry. + +78 +00:04:03,000 --> 00:04:04,000 +Encrypt. + +79 +00:04:05,000 --> 00:04:07,000 +If the private encrypt the public decrypts. + +80 +00:04:07,000 --> 00:04:13,000 +Remember that when one key encrypts, only the corresponding other key can decrypt it. + +81 +00:04:13,000 --> 00:04:17,000 +The public key cannot encrypt and decrypt at the same time. + +82 +00:04:17,000 --> 00:04:20,000 +The private key cannot encrypt and decrypt at the same time. + +83 +00:04:20,000 --> 00:04:23,000 +When one encrypts the other, one must decrypt. + +84 +00:04:23,000 --> 00:04:24,000 +And that's what you see here. + +85 +00:04:24,000 --> 00:04:26,000 +We take the data. + +86 +00:04:26,000 --> 00:04:29,000 +We encrypt it with Mary's public key. + +87 +00:04:30,000 --> 00:04:34,000 +She gets the ciphertext and she decrypts it with her private key to get the data. + +88 +00:04:34,000 --> 00:04:38,000 +So that's something that you must understand here. + +89 +00:04:38,000 --> 00:04:38,000 +Now. + +90 +00:04:39,000 --> 00:04:42,000 +That's the encryption process how it works. + +91 +00:04:42,000 --> 00:04:47,000 +But there are some advantages and disadvantages with this particular system. + +92 +00:04:48,000 --> 00:04:51,000 +First of all, its advantages. + +93 +00:04:51,000 --> 00:04:53,000 +Well, it solves a problem of key distribution. + +94 +00:04:53,000 --> 00:04:55,000 +You notice that we can all communicate. + +95 +00:04:55,000 --> 00:04:59,000 +There's no there's no need to share keys, right? + +96 +00:04:59,000 --> 00:05:05,000 +If you remember, the problem with symmetric encryption was how do we get the key across the network + +97 +00:05:05,000 --> 00:05:07,000 +and how do we get the key from this guy to this guy. + +98 +00:05:07,000 --> 00:05:08,000 +Well, this is not a problem anymore. + +99 +00:05:08,000 --> 00:05:11,000 +Now I just take somebody's public key and I encrypt it and give it to them. + +100 +00:05:11,000 --> 00:05:18,000 +Anyone that intercepts the connection between me and Mary can't decrypt it because they don't have Mary's + +101 +00:05:18,000 --> 00:05:18,000 +private key. + +102 +00:05:19,000 --> 00:05:22,000 +So it solves the problem of distribution of the key. + +103 +00:05:23,000 --> 00:05:25,000 +You don't need to have a billion keys. + +104 +00:05:25,000 --> 00:05:28,000 +You don't need to have keys between people. + +105 +00:05:28,000 --> 00:05:34,000 +For example, all you need to do to find the number of keys and asymmetric that would be needed if you + +106 +00:05:34,000 --> 00:05:39,000 +are using just pure asymmetric if you have two users, four keys, right? + +107 +00:05:39,000 --> 00:05:44,000 +If you have eight people, each of them would just need two keys with 16 keys. + +108 +00:05:44,000 --> 00:05:45,000 +That's it. + +109 +00:05:45,000 --> 00:05:46,000 +This times it by two. + +110 +00:05:46,000 --> 00:05:46,000 +Easy enough. + +111 +00:05:47,000 --> 00:05:52,000 +So the key distribution, the key management is pretty easy. + +112 +00:05:53,000 --> 00:05:59,000 +It provides a method for digital signature which is important for authentication and repudiation. + +113 +00:05:59,000 --> 00:06:03,000 +It has the ability to do non-repudiation authentication. + +114 +00:06:03,000 --> 00:06:09,000 +And the reason is because there is something unique to you. + +115 +00:06:10,000 --> 00:06:13,000 +There's something unique to you which is your private key. + +116 +00:06:14,000 --> 00:06:16,000 +Let me give you guys an example of this. + +117 +00:06:16,000 --> 00:06:18,000 +Let's say there is Andrew. + +118 +00:06:19,000 --> 00:06:20,000 +Andrew has a memo. + +119 +00:06:22,000 --> 00:06:22,000 +That's me. + +120 +00:06:22,000 --> 00:06:26,000 +I have a memo that I want to give to everybody in the company. + +121 +00:06:27,000 --> 00:06:32,000 +If I encrypt now I have two keys, a public and a private key. + +122 +00:06:32,000 --> 00:06:38,000 +Remember, if my public key encrypts, only my private key decrypts, if my private encrypts, only + +123 +00:06:38,000 --> 00:06:47,000 +my public decrypts, my private key is given to no one in the entire world but my private, and my private + +124 +00:06:47,000 --> 00:06:48,000 +key is given to no one in the world. + +125 +00:06:48,000 --> 00:06:50,000 +But my public key is given to everyone in the world. + +126 +00:06:51,000 --> 00:06:59,000 +What I could do is this I could encrypt this memo with my private key to get ciphertext. + +127 +00:07:00,000 --> 00:07:01,000 +Okay. + +128 +00:07:01,000 --> 00:07:04,000 +And then I could give this out to everybody in the business. + +129 +00:07:04,000 --> 00:07:06,000 +Who can decrypt this memo? + +130 +00:07:07,000 --> 00:07:08,000 +Everyone. + +131 +00:07:08,000 --> 00:07:09,000 +Why? + +132 +00:07:09,000 --> 00:07:13,000 +Because it was encrypted with the private key, not the public key. + +133 +00:07:13,000 --> 00:07:14,000 +The public key. + +134 +00:07:14,000 --> 00:07:16,000 +Everybody has my public key. + +135 +00:07:16,000 --> 00:07:17,000 +Hence the name public. + +136 +00:07:17,000 --> 00:07:19,000 +Well, why would I do that? + +137 +00:07:19,000 --> 00:07:21,000 +Why would I encrypt something so the world can decrypt? + +138 +00:07:21,000 --> 00:07:23,000 +It kind of defeats the purpose. + +139 +00:07:23,000 --> 00:07:26,000 +No, the purpose is non-repudiation. + +140 +00:07:26,000 --> 00:07:29,000 +The purpose is you would be 100% sure. + +141 +00:07:29,000 --> 00:07:32,000 +And I cannot deny that that memo came from me. + +142 +00:07:32,000 --> 00:07:36,000 +If you use my private key to decrypt the data, I'm sorry. + +143 +00:07:36,000 --> 00:07:42,000 +My public key to decrypt the data, then, you know, it had to be encrypted with something only I have, + +144 +00:07:42,000 --> 00:07:44,000 +which is my private key. + +145 +00:07:45,000 --> 00:07:51,000 +So this forms the basis of a digital signature, which we'll talk about later in the course. + +146 +00:07:51,000 --> 00:07:53,000 +So it does that versus symmetric. + +147 +00:07:53,000 --> 00:07:55,000 +And you see symmetric encryption. + +148 +00:07:55,000 --> 00:07:56,000 +Everybody was sharing a key. + +149 +00:07:56,000 --> 00:07:58,000 +There was nothing unique to someone. + +150 +00:07:58,000 --> 00:08:01,000 +Everybody had basically the same key. + +151 +00:08:01,000 --> 00:08:03,000 +Everybody needed the same key to encrypt and decrypt the data. + +152 +00:08:03,000 --> 00:08:06,000 +They were part of that communication. + +153 +00:08:07,000 --> 00:08:08,000 +Now. + +154 +00:08:08,000 --> 00:08:09,000 +It sounds good. + +155 +00:08:09,000 --> 00:08:12,000 +No key distribution problem, right? + +156 +00:08:12,000 --> 00:08:13,000 +No problem distributing the key. + +157 +00:08:13,000 --> 00:08:15,000 +Okay, that's no problem doing that. + +158 +00:08:15,000 --> 00:08:17,000 +We don't need a billion keys. + +159 +00:08:17,000 --> 00:08:18,000 +We don't need a lot of keys. + +160 +00:08:18,000 --> 00:08:23,000 +If we don't, you know, we have a lot of users, so key management is easy. + +161 +00:08:24,000 --> 00:08:28,000 +Uh, we have this easy thing of doing digital signatures. + +162 +00:08:29,000 --> 00:08:32,000 +But why don't we use it to encrypt bulk data? + +163 +00:08:32,000 --> 00:08:37,000 +In today's world, we actually don't use asymmetric encryption to encrypt larger data. + +164 +00:08:37,000 --> 00:08:43,000 +Now, basically any data for that matter, the actual private information per se, we don't actually + +165 +00:08:43,000 --> 00:08:49,000 +use it to encrypt bulk data or large amounts of data because it is very slow. + +166 +00:08:50,000 --> 00:08:56,000 +You see, it's computationally intensive, much more than symmetric encryption, making it slower for + +167 +00:08:56,000 --> 00:08:57,000 +large amounts of data. + +168 +00:08:57,000 --> 00:09:00,000 +It requires also a careful management of those private keys. + +169 +00:09:01,000 --> 00:09:03,000 +If your private key is compromised, you need a new pair. + +170 +00:09:03,000 --> 00:09:05,000 +And it's because of. + +171 +00:09:06,000 --> 00:09:08,000 +This point right here. + +172 +00:09:08,000 --> 00:09:09,000 +See that point right there? + +173 +00:09:09,000 --> 00:09:13,000 +This computationally intensive? + +174 +00:09:14,000 --> 00:09:20,000 +Uh, problem is really what doesn't make it replace symmetric. + +175 +00:09:20,000 --> 00:09:22,000 +Somebody say is asymmetric going to replace symmetric. + +176 +00:09:22,000 --> 00:09:27,000 +No it's not because it's you really can't use it for large blocks of data because it's too -- slow. + +177 +00:09:28,000 --> 00:09:31,000 +So if you notice these two algorithms, they cancel each other out. + +178 +00:09:31,000 --> 00:09:33,000 +So one is fast, one is slow. + +179 +00:09:33,000 --> 00:09:36,000 +One has a problem with with distributing keys. + +180 +00:09:36,000 --> 00:09:40,000 +One doesn't have this problem distributing keys one can't doesn't have something unique to the user. + +181 +00:09:40,000 --> 00:09:41,000 +But this one does. + +182 +00:09:41,000 --> 00:09:46,000 +It seems like all the bad is good here and all the bad, all the good is bad there. + +183 +00:09:47,000 --> 00:09:48,000 +You get the point. + +184 +00:09:49,000 --> 00:09:50,000 +So what do we do? + +185 +00:09:50,000 --> 00:09:52,000 +Well, there's a way to combine them again. + +186 +00:09:52,000 --> 00:09:54,000 +Hybrid cryptography is a video on that. + +187 +00:09:54,000 --> 00:09:55,000 +Talk about that later. + +188 +00:09:56,000 --> 00:09:57,000 +Now. + +189 +00:09:57,000 --> 00:10:05,000 +Because things like it has ability to be unique to people, because it has that digital signature and + +190 +00:10:05,000 --> 00:10:06,000 +the safe distribution of keys. + +191 +00:10:06,000 --> 00:10:10,000 +It basically is a cornerstone for protecting all data on the internet today, because things like SSL + +192 +00:10:10,000 --> 00:10:11,000 +can't work without it. + +193 +00:10:12,000 --> 00:10:14,000 +So keep that in mind for now. + +194 +00:10:14,000 --> 00:10:18,000 +I need you guys to understand what a what asymmetric is. + +195 +00:10:18,000 --> 00:10:19,000 +Quick recap as we end this. + +196 +00:10:20,000 --> 00:10:22,000 +Asymmetric is based on the principle of two keys. + +197 +00:10:22,000 --> 00:10:27,000 +Everybody in the asymmetric realm has two keys a public key and a private key. + +198 +00:10:27,000 --> 00:10:31,000 +The public key to give out to anyone the private key they keep only to themselves. + +199 +00:10:31,000 --> 00:10:36,000 +When one key encrypts, only the other one can decrypt, they both encrypt and decrypt. + +200 +00:10:36,000 --> 00:10:36,000 +So now. + +201 +00:10:38,000 --> 00:10:39,000 +Pros and cons. + +202 +00:10:39,000 --> 00:10:45,000 +The good thing is that it's easy to distribute keys because if the keys the secrets are not shared, + +203 +00:10:45,000 --> 00:10:47,000 +you can give your public key to anyone. + +204 +00:10:47,000 --> 00:10:50,000 +But if they encrypt, only your private key can can decrypt it. + +205 +00:10:51,000 --> 00:10:57,000 +This is good because if there's something unique to your private key now, you can use it for non-repudiation, + +206 +00:10:57,000 --> 00:10:58,000 +like with digital signatures. + +207 +00:10:59,000 --> 00:11:00,000 +But what's bad about it? + +208 +00:11:00,000 --> 00:11:02,000 +Well, it's too slow. + +209 +00:11:02,000 --> 00:11:06,000 +It's very, very computationally intensive. + +210 +00:11:06,000 --> 00:11:09,000 +And for those reasons you cannot use it to encrypt bulk data. + +211 +00:11:09,000 --> 00:11:14,000 +So that way we have to find a way to encrypt bulk data, which we'll talk about coming up later in hybrid + +212 +00:11:14,000 --> 00:11:15,000 +cryptography. + +213 +00:11:15,000 --> 00:11:19,000 +But before we do that, let's take a look at some of the asymmetric algorithms. + diff --git a/07 - Cryptography/009 Asymmetric Algorithms OB 1.4_en.srt b/07 - Cryptography/009 Asymmetric Algorithms OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1620080dc850b25ad84a64274232e94e0c666d54 --- /dev/null +++ b/07 - Cryptography/009 Asymmetric Algorithms OB 1.4_en.srt @@ -0,0 +1,268 @@ +1 +00:00:00,000 --> 00:00:07,000 +Okay, let's take a look at different asymmetric algorithms that you need to know or at least understand + +2 +00:00:07,000 --> 00:00:07,000 +for your exam. + +3 +00:00:07,000 --> 00:00:13,000 +Now, you don't need to know the math behind them or how it works, but you do need to know what they + +4 +00:00:13,000 --> 00:00:15,000 +are and maybe some pros and cons about them. + +5 +00:00:15,000 --> 00:00:19,000 +So let's go ahead and get started on this now. + +6 +00:00:20,000 --> 00:00:27,000 +The world's most famous asymmetric algorithm is RSA d most famous algorithm out there. + +7 +00:00:27,000 --> 00:00:34,000 +I would say 80% of communications that utilizes certificates is basically going to run on RSA. + +8 +00:00:34,000 --> 00:00:43,000 +Now, RSA is based on the difficulty of factoring the product of two large prime numbers. + +9 +00:00:43,000 --> 00:00:47,000 +Now, I'm not going to get into the math, but that's something you probably might see on a question + +10 +00:00:47,000 --> 00:00:47,000 +here and there. + +11 +00:00:47,000 --> 00:00:52,000 +It does use as large key sizes from 1024 to 4096. + +12 +00:00:52,000 --> 00:00:57,000 +Most of the RSA keys that I see is going to be 2048 bit. + +13 +00:00:58,000 --> 00:01:04,000 +This is widely used in things like digital signatures, key exchanges and of course SSL, TLS. + +14 +00:01:05,000 --> 00:01:10,000 +The other one is elliptic curve cryptography, now elliptic curve. + +15 +00:01:10,000 --> 00:01:13,000 +This is based on a different form of math. + +16 +00:01:13,000 --> 00:01:18,000 +The elliptic curves over a specific field a finite field. + +17 +00:01:18,000 --> 00:01:24,000 +It offers a higher degree of security with a smaller key size compared to RSA now because it's a different + +18 +00:01:24,000 --> 00:01:25,000 +form of math. + +19 +00:01:26,000 --> 00:01:32,000 +It has the advantage of being very secure with a small key versus RSA. + +20 +00:01:32,000 --> 00:01:34,000 +For it to be secure, it needs a big key. + +21 +00:01:34,000 --> 00:01:39,000 +For example, like I said, most of the RSA keys ECC is 2048 bit. + +22 +00:01:41,000 --> 00:01:50,000 +Notice that this one here, it says here that 256 bit key in ECC is considered as secure as a 3072 bit. + +23 +00:01:50,000 --> 00:01:52,000 +So that's a giant thing if you think about it. + +24 +00:01:52,000 --> 00:01:57,000 +256 bit is has the same security as 3072. + +25 +00:01:57,000 --> 00:01:58,000 +Now if you're thinking, well, why does that matter so much? + +26 +00:01:58,000 --> 00:02:07,000 +Because the bigger the key, the more CPU you need, the more memory you need to store that key. + +27 +00:02:07,000 --> 00:02:10,000 +Now if you're thinking, well, it's only bits, it's not that much, right? + +28 +00:02:10,000 --> 00:02:19,000 +If you get four gigs of if you have four gigabyte of memory, that's 32 billion bits of memory in your + +29 +00:02:19,000 --> 00:02:19,000 +computer. + +30 +00:02:19,000 --> 00:02:20,000 +And this is only four. + +31 +00:02:20,000 --> 00:02:21,000 +But remember, if you're a server. + +32 +00:02:22,000 --> 00:02:28,000 +And you have thousands or millions of connections, and you're managing all the keys for all these connections, + +33 +00:02:28,000 --> 00:02:30,000 +which is going to get bogged down pretty quickly. + +34 +00:02:30,000 --> 00:02:31,000 +All right. + +35 +00:02:31,000 --> 00:02:32,000 +Did you know four gigs is 32 billion? + +36 +00:02:32,000 --> 00:02:33,000 +Did you know that? + +37 +00:02:34,000 --> 00:02:36,000 +Four gigabyte is 32 billion bits. + +38 +00:02:37,000 --> 00:02:39,000 +If you don't know, you better study some A-plus. + +39 +00:02:39,000 --> 00:02:41,000 +Learn your conversion. + +40 +00:02:41,000 --> 00:02:44,000 +Uh, so EC is getting more popular. + +41 +00:02:44,000 --> 00:02:50,000 +I want to mention it was taught that EC was going to replace RSA at some point due to its efficiency. + +42 +00:02:50,000 --> 00:02:54,000 +I haven't really seen that yet, but supposedly EC is replace it. + +43 +00:02:54,000 --> 00:02:54,000 +Why? + +44 +00:02:54,000 --> 00:02:58,000 +It's going to give you more security, smaller key size and it basically does everything. + +45 +00:02:58,000 --> 00:02:59,000 +RSA. + +46 +00:03:00,000 --> 00:03:01,000 +Thus. + +47 +00:03:01,000 --> 00:03:06,000 +Now the other two are also famous, just not as famous as those two. + +48 +00:03:06,000 --> 00:03:09,000 +Diffie-Hellman was the first. + +49 +00:03:10,000 --> 00:03:10,000 +The first. + +50 +00:03:10,000 --> 00:03:15,000 +I'm pretty sure the first is, uh, asymmetric algorithm out there. + +51 +00:03:15,000 --> 00:03:17,000 +It was created by two guys, Diffie and Hellman. + +52 +00:03:18,000 --> 00:03:23,000 +Uh, this here was created for the passing of secret keys or symmetric keys. + +53 +00:03:23,000 --> 00:03:24,000 +That was its objectives. + +54 +00:03:24,000 --> 00:03:29,000 +It wasn't really meant to encrypt data or do any of the other things like RSA and ECC does. + +55 +00:03:31,000 --> 00:03:35,000 +Uh, it's most used again is to pass the secret keys that was out there. + +56 +00:03:35,000 --> 00:03:37,000 +The other one was Elgamal. + +57 +00:03:38,000 --> 00:03:45,000 +And this here was basically based on Diffie-Hellman, uh, and it provides a basis of other algorithms. + +58 +00:03:45,000 --> 00:03:47,000 +And this is really where this one was. + +59 +00:03:47,000 --> 00:03:50,000 +So the most used is going to be RSA. + +60 +00:03:51,000 --> 00:03:54,000 +ECC and Diffie-Hellman. + +61 +00:03:54,000 --> 00:03:58,000 +Out there, there's going to be the most used one for your exam. + +62 +00:03:58,000 --> 00:04:05,000 +I really don't need you guys to memorize all the bit, strings and or key sizes out there for these + +63 +00:04:05,000 --> 00:04:11,000 +algorithms, but I do need you guys to know this is a symmetric this is an asymmetric algorithm. + +64 +00:04:11,000 --> 00:04:12,000 +Here are the pros. + +65 +00:04:12,000 --> 00:04:15,000 +And here is the cons of using symmetric and asymmetric. + +66 +00:04:15,000 --> 00:04:17,000 +That's generally what your exam asks. + +67 +00:04:17,000 --> 00:04:19,000 +So make sure you note them for your tests. + diff --git a/07 - Cryptography/010 Hybrid Cryptography OB 1.4_en.srt b/07 - Cryptography/010 Hybrid Cryptography OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..bea045577dc1e1cdbcb94824ec796992cda173ab --- /dev/null +++ b/07 - Cryptography/010 Hybrid Cryptography OB 1.4_en.srt @@ -0,0 +1,488 @@ +1 +00:00:00,000 --> 00:00:07,000 +In this video, I'm going to teach you how to combine asymmetric and symmetric to form the perfect cryptosystem. + +2 +00:00:07,000 --> 00:00:09,000 +This is called hybrid cryptography. + +3 +00:00:09,000 --> 00:00:12,000 +And before I get into it, I want to point out something. + +4 +00:00:12,000 --> 00:00:14,000 +A lot of security guys don't know this. + +5 +00:00:14,000 --> 00:00:20,000 +A lot of people read books and different watch different videos about symmetric and asymmetric and things + +6 +00:00:20,000 --> 00:00:24,000 +there and think that, for example, asymmetric is implemented by itself. + +7 +00:00:24,000 --> 00:00:25,000 +It's not. + +8 +00:00:25,000 --> 00:00:26,000 +Let me show you guys something. + +9 +00:00:26,000 --> 00:00:28,000 +So here is the Wikipedia article on hybrid cryptography. + +10 +00:00:28,000 --> 00:00:30,000 +I know, I know what you're gonna say, okay. + +11 +00:00:30,000 --> 00:00:33,000 +You know, it's not the best system out there, but it's it's good enough. + +12 +00:00:34,000 --> 00:00:35,000 +Hybrid cryptosystem. + +13 +00:00:36,000 --> 00:00:37,000 +I'm just going to go down here. + +14 +00:00:37,000 --> 00:00:38,000 +I want to read this part here for you. + +15 +00:00:38,000 --> 00:00:46,000 +Notice it says all practical implementations of public key cryptography today employ the use of a hybrid + +16 +00:00:46,000 --> 00:00:47,000 +system. + +17 +00:00:48,000 --> 00:00:50,000 +All okay. + +18 +00:00:50,000 --> 00:00:56,000 +Basically any time we use asymmetric encryption it's never basically used by itself. + +19 +00:00:56,000 --> 00:01:03,000 +All implementations of it that we use in the real world, and not just the theoretical world is based + +20 +00:01:03,000 --> 00:01:05,000 +on a hybrid cryptosystem. + +21 +00:01:05,000 --> 00:01:09,000 +And in this video I want you guys to learn what that is like. + +22 +00:01:09,000 --> 00:01:11,000 +What exactly is a hybrid cryptosystem. + +23 +00:01:11,000 --> 00:01:14,000 +And I want to draw you guys a quick diagram how it's done. + +24 +00:01:15,000 --> 00:01:16,000 +So let's get let's get into this. + +25 +00:01:16,000 --> 00:01:19,000 +So what exactly is a hybrid cryptosystem. + +26 +00:01:19,000 --> 00:01:24,000 +Well as you can imagine it takes the it takes the good of symmetric. + +27 +00:01:24,000 --> 00:01:27,000 +The good of asymmetric combines them. + +28 +00:01:27,000 --> 00:01:29,000 +Remember one there basically were like opposites. + +29 +00:01:29,000 --> 00:01:31,000 +What's good here is bad here. + +30 +00:01:31,000 --> 00:01:31,000 +What's bad here. + +31 +00:01:31,000 --> 00:01:32,000 +What's good here. + +32 +00:01:32,000 --> 00:01:34,000 +So if we combine them we get the perfect system. + +33 +00:01:34,000 --> 00:01:35,000 +That's really what it is. + +34 +00:01:36,000 --> 00:01:43,000 +Basically, when we combine them, we're going to use the asymmetric algorithms for the secure key exchange. + +35 +00:01:43,000 --> 00:01:47,000 +And then we're going to use the symmetric for encrypting the actual data. + +36 +00:01:47,000 --> 00:01:52,000 +Remember something symmetric is good at encrypting bulk data. + +37 +00:01:52,000 --> 00:01:53,000 +Asymmetric is not. + +38 +00:01:53,000 --> 00:01:56,000 +But asymmetric doesn't have a problem of key exchange. + +39 +00:01:56,000 --> 00:01:59,000 +Now if asymmetric has to encrypt. + +40 +00:02:00,000 --> 00:02:01,000 +Just a symmetric key. + +41 +00:02:01,000 --> 00:02:04,000 +It's cool because a symmetric key is pretty small. + +42 +00:02:04,000 --> 00:02:07,000 +It's only 256 bits or 128 bit. + +43 +00:02:07,000 --> 00:02:12,000 +It's not the size of a picture, which could be four megabytes, which would be 32 billion bits. + +44 +00:02:12,000 --> 00:02:18,000 +So remember this in the process that I'm about to cover now, I'm going to cover this exact process. + +45 +00:02:18,000 --> 00:02:21,000 +The text is listed here right now. + +46 +00:02:21,000 --> 00:02:24,000 +So I want to show you the hybrid cryptography system. + +47 +00:02:24,000 --> 00:02:28,000 +Now let's say there is Andy. + +48 +00:02:29,000 --> 00:02:31,000 +And there's Mary. + +49 +00:02:31,000 --> 00:02:35,000 +So we have Mary M-a-r-y and Andy. + +50 +00:02:35,000 --> 00:02:38,000 +So I have a public private key. + +51 +00:02:38,000 --> 00:02:39,000 +Public. + +52 +00:02:39,000 --> 00:02:40,000 +Private key. + +53 +00:02:41,000 --> 00:02:44,000 +Now, reality is, I don't really need keys here. + +54 +00:02:44,000 --> 00:02:47,000 +I'm just putting it there because everybody technically the system has it. + +55 +00:02:47,000 --> 00:02:51,000 +But remember, if you're on the internet and you're using things that you don't have any public private + +56 +00:02:51,000 --> 00:02:52,000 +keys in your machine. + +57 +00:02:53,000 --> 00:02:54,000 +Now here's how it works. + +58 +00:02:54,000 --> 00:03:00,000 +So let's say I have data that I want to transfer to Mary. + +59 +00:03:01,000 --> 00:03:04,000 +Here's what I'm going to do on my computer. + +60 +00:03:04,000 --> 00:03:07,000 +I am going to generate a symmetric key. + +61 +00:03:07,000 --> 00:03:11,000 +This symmetric key is known as a session key. + +62 +00:03:11,000 --> 00:03:15,000 +The session key is a symmetric key like an AES session key. + +63 +00:03:16,000 --> 00:03:22,000 +What I'm going to do is I'm going to encrypt this data with this to form ciphertext. + +64 +00:03:24,000 --> 00:03:25,000 +Okay. + +65 +00:03:25,000 --> 00:03:32,000 +So ciphertext is the data is encrypted with the symmetric key to form ciphertext. + +66 +00:03:32,000 --> 00:03:36,000 +What I'm going to do is I'm going to then say hey Mary, send me your public key. + +67 +00:03:36,000 --> 00:03:39,000 +Mary sends me her public key, but I'm not going to encrypt the data with it. + +68 +00:03:39,000 --> 00:03:41,000 +The data has already been encrypted. + +69 +00:03:41,000 --> 00:03:44,000 +What am I going to encrypt the symmetric key if you said that. + +70 +00:03:44,000 --> 00:03:44,000 +Correct. + +71 +00:03:44,000 --> 00:03:46,000 +So I have ciphertext data. + +72 +00:03:47,000 --> 00:03:51,000 +And now I have ciphertext symmetric key. + +73 +00:03:52,000 --> 00:03:54,000 +What I do is now I send this to Mary. + +74 +00:03:54,000 --> 00:04:03,000 +Mary receives the ciphertext symmetric key and she receives ciphertext data. + +75 +00:04:03,000 --> 00:04:04,000 +You guys see that? + +76 +00:04:04,000 --> 00:04:04,000 +Yep. + +77 +00:04:05,000 --> 00:04:07,000 +How does Mary get the data? + +78 +00:04:07,000 --> 00:04:14,000 +Well, now Mary utilizes her private key to decrypt the symmetric key. + +79 +00:04:14,000 --> 00:04:18,000 +Remember, the symmetric key was encrypted with her public, so it could only be decrypted with her + +80 +00:04:18,000 --> 00:04:19,000 +private. + +81 +00:04:19,000 --> 00:04:23,000 +And now Mary has the symmetric key. + +82 +00:04:23,000 --> 00:04:26,000 +She then uses that symmetric key to decrypt the data. + +83 +00:04:26,000 --> 00:04:27,000 +Now she has the pure data. + +84 +00:04:28,000 --> 00:04:32,000 +So that is the process of asymmetric. + +85 +00:04:32,000 --> 00:04:34,000 +So let's sorry hybrid cryptography. + +86 +00:04:34,000 --> 00:04:36,000 +Let's do a quick quick review. + +87 +00:04:37,000 --> 00:04:37,000 +Okay. + +88 +00:04:37,000 --> 00:04:39,000 +So remember I don't need keys. + +89 +00:04:39,000 --> 00:04:40,000 +So what do I do. + +90 +00:04:40,000 --> 00:04:44,000 +I have the data I generate a symmetric key on this machine. + +91 +00:04:44,000 --> 00:04:50,000 +I then encrypt that symmetric key uh with Mary's public key. + +92 +00:04:50,000 --> 00:04:52,000 +See that I took it I gave it to her. + +93 +00:04:52,000 --> 00:04:56,000 +She gave it to me, I encrypt it, and now I have ciphertext data. + +94 +00:04:57,000 --> 00:05:01,000 +Uh, I have the ciphertext data, and I have ciphertext symmetric key and send it to her. + +95 +00:05:01,000 --> 00:05:03,000 +Now I want you to watch this connection. + +96 +00:05:03,000 --> 00:05:08,000 +If there's a hacker right here, the hacker is seeing ciphertext data and ciphertext symmetric key. + +97 +00:05:08,000 --> 00:05:10,000 +Everything you basically see is ciphertext. + +98 +00:05:10,000 --> 00:05:12,000 +He never sees plaintext. + +99 +00:05:12,000 --> 00:05:16,000 +When she receives it, she uses her private key to decrypt the symmetric key. + +100 +00:05:17,000 --> 00:05:21,000 +And then uses that symmetric key to decrypt the ciphertext data to get the data. + +101 +00:05:21,000 --> 00:05:30,000 +So I got data from me to her using a combination of of symmetric and asymmetric keys. + +102 +00:05:30,000 --> 00:05:33,000 +This is the most efficient way of doing this. + +103 +00:05:35,000 --> 00:05:40,000 +Now hybrid cryptography system combines this. + +104 +00:05:40,000 --> 00:05:43,000 +All right combines the efficiency of symmetric key. + +105 +00:05:43,000 --> 00:05:44,000 +So we get notice the data. + +106 +00:05:44,000 --> 00:05:47,000 +The bulk data was using the symmetric. + +107 +00:05:47,000 --> 00:05:55,000 +And of course that incredible key exchange process or easy management of the keys in asymmetric was + +108 +00:05:55,000 --> 00:05:55,000 +use. + +109 +00:05:56,000 --> 00:06:01,000 +One of the great things is that even if a symmetric key is compromised, it only affects one session + +110 +00:06:01,000 --> 00:06:03,000 +every time I encrypt data. + +111 +00:06:03,000 --> 00:06:05,000 +Every session I make a brand new session key. + +112 +00:06:06,000 --> 00:06:08,000 +This is very scalable and used in numerous systems. + +113 +00:06:08,000 --> 00:06:17,000 +In fact, all implementations of things like SSL, all web connections nowadays is basically that what + +114 +00:06:17,000 --> 00:06:21,000 +I showed you there, that diagram I wrote are just basically just draw it for you, as is the basis + +115 +00:06:21,000 --> 00:06:23,000 +of the SSL handshake. + +116 +00:06:23,000 --> 00:06:29,000 +There's more to it, but that's basically the basis of how the whole SSL handshake works. + +117 +00:06:30,000 --> 00:06:32,000 +So all types of converters, email, VPNs and so on. + +118 +00:06:32,000 --> 00:06:40,000 +Anywhere that we have a symmetric anywhere that is symmetric uses asymmetric encryption, we'll have + +119 +00:06:40,000 --> 00:06:42,000 +hybrid cryptography okay. + +120 +00:06:42,000 --> 00:06:47,000 +So you may want to watch that process again understand the pros and cons of it and the process. + +121 +00:06:47,000 --> 00:06:53,000 +Don't worry too much about the algorithm, but just remember all practical implementations of asymmetric + +122 +00:06:53,000 --> 00:06:55,000 +utilizes hybrid cryptography. + diff --git a/07 - Cryptography/011 Hashing OB 1.4_en.srt b/07 - Cryptography/011 Hashing OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..abe5c0c73500f1300d14bc1a7663cd3c482108e1 --- /dev/null +++ b/07 - Cryptography/011 Hashing OB 1.4_en.srt @@ -0,0 +1,1600 @@ +1 +00:00:00,000 --> 00:00:05,000 +In this video, we're going to get started in the beautiful world of cryptographic hashes. + +2 +00:00:05,000 --> 00:00:11,000 +Now we covered asymmetric and symmetric asymmetric and a asymmetric and symmetric works directly on + +3 +00:00:11,000 --> 00:00:13,000 +data and produces things like ciphertext. + +4 +00:00:13,000 --> 00:00:15,000 +In this one we're going to do something different. + +5 +00:00:15,000 --> 00:00:20,000 +What we're going to be doing is we're going to be taking data of any length and turn it into a fixed + +6 +00:00:20,000 --> 00:00:21,000 +length hash. + +7 +00:00:21,000 --> 00:00:24,000 +This doesn't actually encrypt the data at all. + +8 +00:00:24,000 --> 00:00:26,000 +This is just a cryptographic number. + +9 +00:00:26,000 --> 00:00:31,000 +It's basically a value that represents the data. + +10 +00:00:31,000 --> 00:00:35,000 +It's not used to replace the data and it's not used to be decrypted. + +11 +00:00:35,000 --> 00:00:38,000 +This is something that's best shown than me trying to explain it. + +12 +00:00:38,000 --> 00:00:39,000 +Let me show it to you. + +13 +00:00:39,000 --> 00:00:42,000 +And then we're going to get into the nitty gritty detail. + +14 +00:00:42,000 --> 00:00:44,000 +I'm going to be showing you a hash function. + +15 +00:00:44,000 --> 00:00:49,000 +The most used hash function on the planet basically is going to be Sha 256. + +16 +00:00:49,000 --> 00:00:52,000 +We're going to get more into this function later on in the in these lessons. + +17 +00:00:52,000 --> 00:00:55,000 +But let's take a look. + +18 +00:00:55,000 --> 00:00:57,000 +So here I am at uh, this website. + +19 +00:00:57,000 --> 00:01:02,000 +And this is going to be a live view of a cryptographic hash functions getting done. + +20 +00:01:02,000 --> 00:01:05,000 +Now the link to this website is in the slides. + +21 +00:01:05,000 --> 00:01:06,000 +So I want to show you guys something. + +22 +00:01:07,000 --> 00:01:12,000 +I'm going to be entering my text at the bottom and at the bottom, at the top and at the bottom you're + +23 +00:01:12,000 --> 00:01:15,000 +going to get your cryptographic hash output. + +24 +00:01:15,000 --> 00:01:15,000 +Let's see. + +25 +00:01:15,000 --> 00:01:25,000 +So I'm going to say did you guys know I have many certifications. + +26 +00:01:25,000 --> 00:01:32,000 +Now I want you guys to watch something every single time I touch that keyboard. + +27 +00:01:33,000 --> 00:01:35,000 +The whole hash function chain. + +28 +00:01:35,000 --> 00:01:38,000 +You see this function, right. + +29 +00:01:38,000 --> 00:01:41,000 +This particular output, this string. + +30 +00:01:42,000 --> 00:01:43,000 +Represents this data. + +31 +00:01:44,000 --> 00:01:51,000 +If this data is modified in its slightest, this entire string will change. + +32 +00:01:52,000 --> 00:01:55,000 +For example, I want you guys to select on the screen. + +33 +00:01:55,000 --> 00:01:56,000 +We make this bigger so we can all see. + +34 +00:01:58,000 --> 00:01:58,000 +Okay. + +35 +00:01:59,000 --> 00:02:00,000 +Select any value here. + +36 +00:02:00,000 --> 00:02:04,000 +It doesn't matter what this any value, any one of these. + +37 +00:02:04,000 --> 00:02:06,000 +Maybe you got this one or maybe this eight here. + +38 +00:02:06,000 --> 00:02:08,000 +And I'm just going to click in the data. + +39 +00:02:08,000 --> 00:02:09,000 +And I'm just going to add a period. + +40 +00:02:09,000 --> 00:02:10,000 +That's it. + +41 +00:02:10,000 --> 00:02:11,000 +I'm just going to add a period. + +42 +00:02:12,000 --> 00:02:13,000 +Did it change. + +43 +00:02:13,000 --> 00:02:14,000 +More than likely it changed. + +44 +00:02:14,000 --> 00:02:15,000 +All right. + +45 +00:02:15,000 --> 00:02:17,000 +This whole thing basically changes. + +46 +00:02:17,000 --> 00:02:19,000 +Almost all those values will change. + +47 +00:02:20,000 --> 00:02:20,000 +Let me continue. + +48 +00:02:20,000 --> 00:02:27,000 +Notice that there's two main properties I need you guys to know every single time I type something. + +49 +00:02:28,000 --> 00:02:29,000 +Uh, watch it change. + +50 +00:02:29,000 --> 00:02:31,000 +But there's something else that's not changing. + +51 +00:02:31,000 --> 00:02:33,000 +Let's let me see if you detect it. + +52 +00:02:33,000 --> 00:02:41,000 +So I hope you will get more certs than I have. + +53 +00:02:42,000 --> 00:02:43,000 +Okay. + +54 +00:02:43,000 --> 00:02:43,000 +Nope. + +55 +00:02:43,000 --> 00:02:44,000 +I put an extra space. + +56 +00:02:44,000 --> 00:02:45,000 +Let me remove it. + +57 +00:02:45,000 --> 00:02:51,000 +Notice every single time I type the hash is changing. + +58 +00:02:51,000 --> 00:02:53,000 +But there's something not changing. + +59 +00:02:53,000 --> 00:02:56,000 +And what's not changing is the size of this. + +60 +00:02:56,000 --> 00:02:58,000 +This thing stays the same. + +61 +00:02:58,000 --> 00:03:00,000 +Doesn't matter how much text I put. + +62 +00:03:00,000 --> 00:03:02,000 +You see, if I copy this here. + +63 +00:03:04,000 --> 00:03:06,000 +I paste it into that box. + +64 +00:03:06,000 --> 00:03:12,000 +Once again, the hash changes, but the size of the hash is not changing. + +65 +00:03:12,000 --> 00:03:16,000 +No matter what I put in here, the hash size of the hash will not change. + +66 +00:03:16,000 --> 00:03:22,000 +See, if I go in here and I put and I keep doing, it doesn't matter how many times I copy paste it, + +67 +00:03:22,000 --> 00:03:23,000 +it will not change. + +68 +00:03:24,000 --> 00:03:26,000 +This is a very unique characteristics of this hash. + +69 +00:03:26,000 --> 00:03:32,000 +You see this particular value represents all this data. + +70 +00:03:33,000 --> 00:03:39,000 +So if anybody manipulates this data in any which way and you have this hash value. + +71 +00:03:39,000 --> 00:03:43,000 +So let's say I send you the data all of this and I send you this hash. + +72 +00:03:44,000 --> 00:03:45,000 +Okay. + +73 +00:03:45,000 --> 00:03:49,000 +You'll be able to tell if anybody manipulated it, because if somebody manipulates this data, maybe + +74 +00:03:49,000 --> 00:03:52,000 +they went in here after this morning, they put a space. + +75 +00:03:52,000 --> 00:03:53,000 +Then of course, the hash will change. + +76 +00:03:53,000 --> 00:03:55,000 +You would know somebody modified that somehow. + +77 +00:03:56,000 --> 00:03:57,000 +And that's what hashing is. + +78 +00:03:57,000 --> 00:04:04,000 +Hashing is about detecting modification of the data, the hash value, the string of characters that + +79 +00:04:04,000 --> 00:04:05,000 +we saw. + +80 +00:04:05,000 --> 00:04:07,000 +That was a 256 bit hash. + +81 +00:04:07,000 --> 00:04:10,000 +What we saw here, this is 256 bit. + +82 +00:04:10,000 --> 00:04:12,000 +It's just written. + +83 +00:04:13,000 --> 00:04:16,000 +It's written in a different format than you would know in in binary. + +84 +00:04:16,000 --> 00:04:17,000 +Okay. + +85 +00:04:17,000 --> 00:04:21,000 +So in this particular one it's, uh, hexadecimal. + +86 +00:04:21,000 --> 00:04:23,000 +So it's 0298F. + +87 +00:04:23,000 --> 00:04:26,000 +Now it's a base 16. + +88 +00:04:26,000 --> 00:04:28,000 +So don't worry too much about the specific math. + +89 +00:04:28,000 --> 00:04:29,000 +Just know that this is 200. + +90 +00:04:29,000 --> 00:04:31,000 +This is 256 bit hash. + +91 +00:04:31,000 --> 00:04:37,000 +And any kind of changes in here will result in a change here. + +92 +00:04:37,000 --> 00:04:40,000 +Now let's talk about these characteristics of this. + +93 +00:04:42,000 --> 00:04:45,000 +Because there's a lot of things here we should be able to understand. + +94 +00:04:45,000 --> 00:04:49,000 +Number one is that when it comes to hashing what are we doing. + +95 +00:04:49,000 --> 00:04:52,000 +Well we're converting an input of any length. + +96 +00:04:52,000 --> 00:04:54,000 +Like I mentioned any length. + +97 +00:04:54,000 --> 00:04:59,000 +It could be something as small as one bit all the way to terabytes of data. + +98 +00:04:59,000 --> 00:05:06,000 +Doesn't matter into a fixed size string of text using a mathematical function. + +99 +00:05:06,000 --> 00:05:07,000 +That's the hash function. + +100 +00:05:07,000 --> 00:05:08,000 +That's what we just saw. + +101 +00:05:09,000 --> 00:05:14,000 +Now a hash function takes data input data, like a message produces that fixed length hash. + +102 +00:05:14,000 --> 00:05:17,000 +Now the thing to know is that it's you can't go back. + +103 +00:05:17,000 --> 00:05:18,000 +And we'll talk about that in a minute. + +104 +00:05:20,000 --> 00:05:24,000 +A good hash function produces a unique and distinct value for every single input. + +105 +00:05:24,000 --> 00:05:27,000 +Even a small change results in a significant one. + +106 +00:05:27,000 --> 00:05:31,000 +So that means that every time you type text in, you're going to get a different output. + +107 +00:05:31,000 --> 00:05:34,000 +Every time the text changes, the output changed. + +108 +00:05:34,000 --> 00:05:35,000 +Now we saw that. + +109 +00:05:35,000 --> 00:05:39,000 +Now, just in case you don't have your following, just the slides, I give you a few examples. + +110 +00:05:39,000 --> 00:05:42,000 +But you saw that here where that was this website I gave you. + +111 +00:05:42,000 --> 00:05:43,000 +This is a link I was at. + +112 +00:05:43,000 --> 00:05:49,000 +So you would just type in the value type in your text, the hash function, and then it would give you + +113 +00:05:49,000 --> 00:05:51,000 +the different hashes. + +114 +00:05:51,000 --> 00:05:54,000 +Now this particular website has more than just Sha 256. + +115 +00:05:54,000 --> 00:06:03,000 +I think it has MD5 three shot 253 356 or I'm sorry 384 512 this is a variety of different ones there. + +116 +00:06:03,000 --> 00:06:10,000 +Now there are some things that I want to talk about in terms of hashing, right. + +117 +00:06:10,000 --> 00:06:13,000 +Some characteristics that we want to be familiar with. + +118 +00:06:13,000 --> 00:06:16,000 +Number one is that it's deterministic. + +119 +00:06:16,000 --> 00:06:26,000 +The same input always produces the same output every single time you hash that text. + +120 +00:06:26,000 --> 00:06:31,000 +It should always give you that exact exact output. + +121 +00:06:31,000 --> 00:06:34,000 +If the text is modified, the output is different. + +122 +00:06:34,000 --> 00:06:41,000 +And I want to show you guys, uh, I want to show you guys this, uh, in their. + +123 +00:06:42,000 --> 00:06:43,000 +So here's what I'm going to do. + +124 +00:06:45,000 --> 00:06:47,000 +I'm going to highlight all this and I'm going to. + +125 +00:06:49,000 --> 00:06:51,000 +Put I have. + +126 +00:06:51,000 --> 00:06:53,000 +I want to show you guys something because this is going to make more sense. + +127 +00:06:53,000 --> 00:06:55,000 +Have I have many certs. + +128 +00:06:55,000 --> 00:06:55,000 +All right. + +129 +00:06:55,000 --> 00:06:56,000 +This is my message. + +130 +00:06:56,000 --> 00:07:02,000 +Every time I do this, every time I type this text, it should give me this exact hash. + +131 +00:07:02,000 --> 00:07:07,000 +Doesn't matter where any time you run this text it should always give you this hash. + +132 +00:07:07,000 --> 00:07:12,000 +So let me just go here and I'm going to say Sha 256 online. + +133 +00:07:13,000 --> 00:07:14,000 +I'm just going to go to another website. + +134 +00:07:15,000 --> 00:07:16,000 +I'm just going to use theirs okay. + +135 +00:07:16,000 --> 00:07:17,000 +This is another website. + +136 +00:07:17,000 --> 00:07:19,000 +And let's drag this one here. + +137 +00:07:19,000 --> 00:07:22,000 +So we have two inputs on our screen. + +138 +00:07:22,000 --> 00:07:27,000 +So let's see if what I do here this this output should be matched in this one. + +139 +00:07:27,000 --> 00:07:28,000 +So let's see if we get it right. + +140 +00:07:28,000 --> 00:07:32,000 +So I'm going to take this I'm going to copy this I'm going to put it into this screen now. + +141 +00:07:32,000 --> 00:07:34,000 +So again it's the same function just a different site. + +142 +00:07:35,000 --> 00:07:37,000 +I'm just showing you that the output is going to match watch. + +143 +00:07:37,000 --> 00:07:41,000 +So I just put that there and let's see if the output matches. + +144 +00:07:41,000 --> 00:07:43,000 +Now I'm not going to go one by one here. + +145 +00:07:43,000 --> 00:07:46,000 +But the first couple should be fine e f. + +146 +00:07:46,000 --> 00:07:48,000 +Let's see this one. + +147 +00:07:48,000 --> 00:07:52,000 +Output F90F90 okay. + +148 +00:07:52,000 --> 00:07:55,000 +What is it n with this one ends in 3266. + +149 +00:07:55,000 --> 00:07:56,000 +This one ends in three two, six, six. + +150 +00:07:56,000 --> 00:07:56,000 +See that? + +151 +00:07:57,000 --> 00:07:59,000 +So if I go in here and I say I have. + +152 +00:08:01,000 --> 00:08:04,000 +66 shirts. + +153 +00:08:04,000 --> 00:08:10,000 +So if I go in here and I say same thing six. + +154 +00:08:12,000 --> 00:08:15,000 +66 certs should match. + +155 +00:08:15,000 --> 00:08:16,000 +Let's see again. + +156 +00:08:16,000 --> 00:08:19,000 +So look at this e f f. + +157 +00:08:20,000 --> 00:08:21,000 +E f f. + +158 +00:08:21,000 --> 00:08:22,000 +Okay, great. + +159 +00:08:22,000 --> 00:08:23,000 +This matches perfectly. + +160 +00:08:23,000 --> 00:08:25,000 +It ends in 0303. + +161 +00:08:25,000 --> 00:08:26,000 +So this one ends in 0303. + +162 +00:08:27,000 --> 00:08:28,000 +Exactly. + +163 +00:08:28,000 --> 00:08:34,000 +So any time you type that text using that function, you should always get that output. + +164 +00:08:34,000 --> 00:08:36,000 +That's what that's the point I'm trying to make here. + +165 +00:08:36,000 --> 00:08:43,000 +Now that's important to understand because when we come to passwords, the world of password management + +166 +00:08:43,000 --> 00:08:46,000 +you're going to need to know that, uh, okay. + +167 +00:08:46,000 --> 00:08:48,000 +So it's deterministic. + +168 +00:08:48,000 --> 00:08:49,000 +It's fast. + +169 +00:08:49,000 --> 00:08:52,000 +It should be able it doesn't really matter the size of it. + +170 +00:08:52,000 --> 00:08:55,000 +It should be able to compute the hash relatively quickly. + +171 +00:08:56,000 --> 00:08:58,000 +It should be preimage resistant. + +172 +00:08:58,000 --> 00:09:01,000 +Now this is something you have to understand. + +173 +00:09:01,000 --> 00:09:04,000 +It is considered one way. + +174 +00:09:04,000 --> 00:09:07,000 +What does that mean if I give you. + +175 +00:09:08,000 --> 00:09:16,000 +A hash value, you should not be able to reconstruct the original input. + +176 +00:09:16,000 --> 00:09:19,000 +Well, what does that mean? + +177 +00:09:19,000 --> 00:09:21,000 +Well let's see. + +178 +00:09:21,000 --> 00:09:23,000 +So if I give you. + +179 +00:09:25,000 --> 00:09:31,000 +If I give you this value, there is no way you should be going back. + +180 +00:09:31,000 --> 00:09:32,000 +It's one way. + +181 +00:09:32,000 --> 00:09:32,000 +It's. + +182 +00:09:32,000 --> 00:09:35,000 +Take the data, produce a cryptographic hash. + +183 +00:09:35,000 --> 00:09:42,000 +You should never be able to turn this the cash value into the text itself. + +184 +00:09:43,000 --> 00:09:47,000 +In fact, it's probably not even feasible because when you have large amounts of text, it's not feasible + +185 +00:09:48,000 --> 00:09:57,000 +because you can have data that's 20MB, that's 160 bits being brought down to 256 bits. + +186 +00:09:58,000 --> 00:09:58,000 +Okay. + +187 +00:09:58,000 --> 00:09:59,000 +That's like me. + +188 +00:09:59,000 --> 00:10:03,000 +You know, if you take a four megabyte file, that's 32 billion bits. + +189 +00:10:03,000 --> 00:10:08,000 +That's like me giving you $256 and say, go make 4 billion, $32 million. + +190 +00:10:08,000 --> 00:10:10,000 +Not very hard to do. + +191 +00:10:10,000 --> 00:10:15,000 +So it is considered a one way function. + +192 +00:10:15,000 --> 00:10:15,000 +Okay. + +193 +00:10:15,000 --> 00:10:17,000 +What are some other function of this. + +194 +00:10:17,000 --> 00:10:18,000 +Let's see. + +195 +00:10:19,000 --> 00:10:19,000 +Okay. + +196 +00:10:19,000 --> 00:10:26,000 +So the other thing here we have is going to be small changes leads to large differences. + +197 +00:10:26,000 --> 00:10:28,000 +Now that means that we saw this earlier. + +198 +00:10:28,000 --> 00:10:32,000 +You make one small change to to the text. + +199 +00:10:32,000 --> 00:10:36,000 +Remember when I just added a space or just one letter change or put a period or something. + +200 +00:10:36,000 --> 00:10:38,000 +The whole hash will change. + +201 +00:10:38,000 --> 00:10:40,000 +This is called the avalanche effect. + +202 +00:10:40,000 --> 00:10:44,000 +What that means is that basically it's like a cascading effect. + +203 +00:10:44,000 --> 00:10:46,000 +Okay, you change it, then it changes the entire hash. + +204 +00:10:47,000 --> 00:10:51,000 +Now, the one I want to spend a couple of minutes on is called collision resistance. + +205 +00:10:51,000 --> 00:10:53,000 +What exactly is this? + +206 +00:10:53,000 --> 00:10:55,000 +Well, you have to understand how this thing works. + +207 +00:10:55,000 --> 00:10:57,000 +It basically takes data. + +208 +00:10:58,000 --> 00:11:01,000 +Of any length and it produces this fixed length string of text. + +209 +00:11:01,000 --> 00:11:02,000 +This hash. + +210 +00:11:03,000 --> 00:11:09,000 +You see, collisions occur when two different messages produces the same hash. + +211 +00:11:09,000 --> 00:11:10,000 +That's really bad. + +212 +00:11:11,000 --> 00:11:13,000 +You see, you have to understand how it functions. + +213 +00:11:13,000 --> 00:11:15,000 +And let's talk about how it functions. + +214 +00:11:15,000 --> 00:11:20,000 +So like how do you end up with a collision. + +215 +00:11:21,000 --> 00:11:21,000 +We. + +216 +00:11:21,000 --> 00:11:24,000 +First of all, you have to understand the hash value. + +217 +00:11:24,000 --> 00:11:28,000 +The hash value algorithm a hash algorithm comes in bit string. + +218 +00:11:28,000 --> 00:11:32,000 +For example, Sha like we saw was 256. + +219 +00:11:32,000 --> 00:11:36,000 +That means that the output that it's giving you is 256 bit. + +220 +00:11:37,000 --> 00:11:41,000 +There's another famous one called MD5, although you shouldn't be using it. + +221 +00:11:41,000 --> 00:11:44,000 +It was pretty famous that has 128 bit. + +222 +00:11:44,000 --> 00:11:52,000 +And if you remember earlier in the video, when we say 128 bit 256 bits, that tells me that's those + +223 +00:11:52,000 --> 00:11:53,000 +are the number of digits in the hash. + +224 +00:11:53,000 --> 00:11:55,000 +So how many possible hash you can have? + +225 +00:11:55,000 --> 00:11:57,000 +Well, the number of bits tell you that. + +226 +00:11:57,000 --> 00:12:06,000 +So if it's 128 bit there's 2 to 128 number of hashes available to be used. + +227 +00:12:07,000 --> 00:12:12,000 +It's not an unlimited number of hashes out there, it is just a fixed number of hashes. + +228 +00:12:12,000 --> 00:12:15,000 +Although it's a big pool, it's still a pool. + +229 +00:12:15,000 --> 00:12:16,000 +It's still a fixed number. + +230 +00:12:17,000 --> 00:12:22,000 +For example, let's say I'm really, really crazy and I make a hash function. + +231 +00:12:22,000 --> 00:12:25,000 +A hash function that's two bits. + +232 +00:12:25,000 --> 00:12:28,000 +Two bits only gives me four possible hashes. + +233 +00:12:28,000 --> 00:12:38,000 +So if you're using my for my hash function to to do to to hash your data with, it'll be easy to have + +234 +00:12:38,000 --> 00:12:43,000 +multiple different data having the exact same hash because only four possible hashes. + +235 +00:12:44,000 --> 00:12:45,000 +So. + +236 +00:12:45,000 --> 00:12:51,000 +Because the hash functions of today uses like 128, 256, 384, 512. + +237 +00:12:52,000 --> 00:12:53,000 +Crazy amount of hashes. + +238 +00:12:54,000 --> 00:12:57,000 +Collisions are not very likely, but they're not impossible. + +239 +00:12:58,000 --> 00:13:00,000 +And there is a paradox. + +240 +00:13:00,000 --> 00:13:04,000 +I want to talk to you guys about today that makes it somewhat possible. + +241 +00:13:04,000 --> 00:13:15,000 +So for example MD5, the hash function of MD5, MD5 is 128 bit two to the 128 is a number 38 zeros, + +242 +00:13:15,000 --> 00:13:16,000 +37 zeros. + +243 +00:13:16,000 --> 00:13:16,000 +I forgot this number. + +244 +00:13:16,000 --> 00:13:18,000 +It's a crazy big number. + +245 +00:13:18,000 --> 00:13:23,000 +So what is the probability that two different messages produce the same hash? + +246 +00:13:23,000 --> 00:13:28,000 +It's not impossible because again there's a fixed number of hashes, but it doesn't seem likely. + +247 +00:13:30,000 --> 00:13:32,000 +I want to show you guys a couple of things. + +248 +00:13:32,000 --> 00:13:33,000 +First of all I want to show you a collision. + +249 +00:13:33,000 --> 00:13:36,000 +So here is a diagram that we have. + +250 +00:13:36,000 --> 00:13:39,000 +So this is the normal this is the collision. + +251 +00:13:39,000 --> 00:13:47,000 +So in the normal look at the text the red fox runs across the box box and input field hashes it. + +252 +00:13:47,000 --> 00:13:53,000 +And he gets this this this uh this output the yellow fox different message hashes to get this. + +253 +00:13:53,000 --> 00:13:54,000 +But they're different right. + +254 +00:13:54,000 --> 00:13:55,000 +This is normal. + +255 +00:13:55,000 --> 00:13:57,000 +Different messages, different hash. + +256 +00:13:57,000 --> 00:14:04,000 +The collision occurs when you take the red fox and the yellow fox to different messages, hashes it + +257 +00:14:04,000 --> 00:14:05,000 +with the same function. + +258 +00:14:05,000 --> 00:14:09,000 +But now all of a sudden you have the exact same hash. + +259 +00:14:09,000 --> 00:14:14,000 +This is the collision two different messages producing the same hash function. + +260 +00:14:16,000 --> 00:14:19,000 +Now, this is a kind of a weakness. + +261 +00:14:19,000 --> 00:14:20,000 +All right. + +262 +00:14:20,000 --> 00:14:22,000 +MD5 has multiple collision. + +263 +00:14:22,000 --> 00:14:23,000 +That's what you should never use it. + +264 +00:14:24,000 --> 00:14:27,000 +Uh, you should be using Sha 256 and above. + +265 +00:14:27,000 --> 00:14:32,000 +An example of this I want to mention is something we call a birthday attack against passwords. + +266 +00:14:32,000 --> 00:14:34,000 +The birthday attack is like a password thing. + +267 +00:14:35,000 --> 00:14:36,000 +Most people know it as a password. + +268 +00:14:36,000 --> 00:14:37,000 +I'll explain what this is to you. + +269 +00:14:37,000 --> 00:14:40,000 +The what's called the birthday paradox. + +270 +00:14:41,000 --> 00:14:46,000 +So I'm going to give you guys and I'm gonna explain why this is related to hashing. + +271 +00:14:46,000 --> 00:14:49,000 +I'm going to give you guys something to think about. + +272 +00:14:49,000 --> 00:14:50,000 +All right. + +273 +00:14:50,000 --> 00:14:52,000 +Here's a type of a math function. + +274 +00:14:52,000 --> 00:14:53,000 +You have to do a little bit of math. + +275 +00:14:53,000 --> 00:14:55,000 +Don't worry it's not complex. + +276 +00:14:55,000 --> 00:14:57,000 +If I put 30 people in a room. + +277 +00:14:58,000 --> 00:15:03,000 +What is the probability that any two people have the exact same birthday? + +278 +00:15:03,000 --> 00:15:07,000 +In that year there's 365 possible combinations of birthday, right? + +279 +00:15:07,000 --> 00:15:11,000 +January 1st, January 2nd, January 3rd, 365 combinations. + +280 +00:15:12,000 --> 00:15:14,000 +There's 30 people in the room. + +281 +00:15:14,000 --> 00:15:18,000 +If I was to ask you guys if we were to, um. + +282 +00:15:20,000 --> 00:15:25,000 +If we were to just grab two people that any two people, what's the probability that if we grab any + +283 +00:15:25,000 --> 00:15:27,000 +two people, they have the same birthday? + +284 +00:15:27,000 --> 00:15:29,000 +Would you say that number is small? + +285 +00:15:29,000 --> 00:15:30,000 +1%, 2%. + +286 +00:15:30,000 --> 00:15:31,000 +Would you say it's moderate? + +287 +00:15:31,000 --> 00:15:33,000 +30, 40, 50, 60%? + +288 +00:15:33,000 --> 00:15:34,000 +Would you say it's high? + +289 +00:15:34,000 --> 00:15:34,000 +80? + +290 +00:15:34,000 --> 00:15:35,000 +90%. + +291 +00:15:37,000 --> 00:15:39,000 +Well without me giving it to you. + +292 +00:15:39,000 --> 00:15:40,000 +Let me just show you. + +293 +00:15:40,000 --> 00:15:42,000 +So here I have. + +294 +00:15:42,000 --> 00:15:45,000 +I went to Wikipedia and I looked up birthday attack. + +295 +00:15:45,000 --> 00:15:48,000 +You see, the birthday attack is a brute force. + +296 +00:15:48,000 --> 00:15:49,000 +Is a brute force collision. + +297 +00:15:49,000 --> 00:15:50,000 +Attack? + +298 +00:15:51,000 --> 00:15:54,000 +It works on something we call the birthday paradox. + +299 +00:15:54,000 --> 00:15:55,000 +Now what? + +300 +00:15:55,000 --> 00:15:56,000 +This is. + +301 +00:15:56,000 --> 00:15:57,000 +This is what I was just explaining. + +302 +00:16:00,000 --> 00:16:05,000 +A scenario where a teacher with a class of 30 students actually everyone's birthday to determine whether + +303 +00:16:05,000 --> 00:16:08,000 +any two students have the same birthday. + +304 +00:16:08,000 --> 00:16:14,000 +Although this may seem small, the probability of one student having the same birthday as any other + +305 +00:16:14,000 --> 00:16:16,000 +is actually 70%. + +306 +00:16:16,000 --> 00:16:23,000 +Now, most of my students generally say 1% or 2%, but in actuality it's actually 70%. + +307 +00:16:23,000 --> 00:16:24,000 +It's not a small number. + +308 +00:16:25,000 --> 00:16:31,000 +In fact, if you put, I believe it's 60 people in a room, there's a 90 or 99% people percentage that + +309 +00:16:31,000 --> 00:16:34,000 +they're going to have two, two people are going to have the same birthday. + +310 +00:16:35,000 --> 00:16:40,000 +And if you're wondering, what the hell does that have to do with passwords or hashing collision. + +311 +00:16:40,000 --> 00:16:47,000 +You see, the birthday paradox teaches us a very important thing about the laws of probability. + +312 +00:16:47,000 --> 00:16:50,000 +What seems improbable is actually more probable than we believe. + +313 +00:16:50,000 --> 00:16:57,000 +Although it seems like 30 people with 365 combinations seems like a very small likelihood, it's actually + +314 +00:16:57,000 --> 00:16:58,000 +very likely. + +315 +00:16:58,000 --> 00:17:00,000 +You see, how does this relate to hashing? + +316 +00:17:00,000 --> 00:17:01,000 +Is this. + +317 +00:17:02,000 --> 00:17:08,000 +There's two to the 128 bit number of hashes when you use an MD5 hash. + +318 +00:17:08,000 --> 00:17:10,000 +There's an unlimited number of messages. + +319 +00:17:10,000 --> 00:17:16,000 +The probability of two messages having the same hash seems very unlikely because there's so many hashes. + +320 +00:17:16,000 --> 00:17:19,000 +But the birthday paradox says actually there is. + +321 +00:17:19,000 --> 00:17:22,000 +There is no way to defeat the birthday paradox. + +322 +00:17:22,000 --> 00:17:23,000 +There's no way to stop it. + +323 +00:17:23,000 --> 00:17:27,000 +It's just the laws of math, except if you increase the number of birthdays. + +324 +00:17:27,000 --> 00:17:32,000 +So instead of having 365 put 1000 combinations, then that percentage drops, that 70 goes down. + +325 +00:17:32,000 --> 00:17:37,000 +So the way to break it is to increase the pool of possible hashes. + +326 +00:17:37,000 --> 00:17:40,000 +Or in this come in this one pool of possible birthdays. + +327 +00:17:41,000 --> 00:17:42,000 +Now. + +328 +00:17:43,000 --> 00:17:45,000 +How does a birthday attack relate to passwords? + +329 +00:17:45,000 --> 00:17:47,000 +Well, first of all, just what a heads up. + +330 +00:17:47,000 --> 00:17:52,000 +When we get to the password section, I'm going to tell you guys remember hashing all passwords are + +331 +00:17:52,000 --> 00:17:52,000 +hash. + +332 +00:17:52,000 --> 00:17:55,000 +Computers don't store your passwords. + +333 +00:17:56,000 --> 00:17:59,000 +As password as a plaintext, it stores it as hashes. + +334 +00:17:59,000 --> 00:18:00,000 +Let me show you guys something. + +335 +00:18:02,000 --> 00:18:06,000 +So a computer if your password is password one. + +336 +00:18:06,000 --> 00:18:09,000 +This is what the computer stores this. + +337 +00:18:11,000 --> 00:18:11,000 +Okay. + +338 +00:18:11,000 --> 00:18:14,000 +It does not store your plaintext password. + +339 +00:18:14,000 --> 00:18:20,000 +All computers, all computing systems doesn't store this plaintext. + +340 +00:18:20,000 --> 00:18:21,000 +It stores this. + +341 +00:18:22,000 --> 00:18:28,000 +So when you type in your password as password one, it then rehashes this and matches it to what it + +342 +00:18:28,000 --> 00:18:29,000 +has on file. + +343 +00:18:30,000 --> 00:18:35,000 +Remember, it's one way even if people compromise your system and steal your steal the hash, they should + +344 +00:18:35,000 --> 00:18:36,000 +never be able to work it backwards. + +345 +00:18:36,000 --> 00:18:37,000 +Because remember what I said? + +346 +00:18:37,000 --> 00:18:43,000 +Hashing is one way where the birthday paradox comes into play, or the birthday attack comes into play + +347 +00:18:43,000 --> 00:18:44,000 +is like this. + +348 +00:18:45,000 --> 00:18:49,000 +It comes into play when your password is car, car. + +349 +00:18:49,000 --> 00:18:53,000 +And then I come to you and it says, hey man, I guess your password. + +350 +00:18:53,000 --> 00:18:54,000 +And you're like, okay, what is it? + +351 +00:18:54,000 --> 00:18:56,000 +And I say, it's van, van. + +352 +00:18:56,000 --> 00:18:59,000 +And you're like, no, it's car. + +353 +00:18:59,000 --> 00:19:00,000 +And I said, nope, it's van. + +354 +00:19:00,000 --> 00:19:01,000 +So you say prove it. + +355 +00:19:01,000 --> 00:19:03,000 +So I go to the machine. + +356 +00:19:03,000 --> 00:19:08,000 +And I type in your username and I type the word van and boom, it logs me in. + +357 +00:19:08,000 --> 00:19:09,000 +You like me. + +358 +00:19:09,000 --> 00:19:11,000 +I change my password so I log out. + +359 +00:19:11,000 --> 00:19:15,000 +Then you come, you type your same username, you type the word car and you press enter and boom. + +360 +00:19:15,000 --> 00:19:16,000 +It logs you in too. + +361 +00:19:16,000 --> 00:19:17,000 +It's odd. + +362 +00:19:17,000 --> 00:19:20,000 +It's two different words logging into the same account. + +363 +00:19:20,000 --> 00:19:23,000 +It's like this one account has two different password. + +364 +00:19:23,000 --> 00:19:24,000 +Know what's happening? + +365 +00:19:24,000 --> 00:19:26,000 +There is the collision of where. + +366 +00:19:27,000 --> 00:19:28,000 +Password. + +367 +00:19:28,000 --> 00:19:34,000 +One is producing this hash and another text is producing the same hash as password one. + +368 +00:19:34,000 --> 00:19:39,000 +The computer thinks car and van is the same thing because it's the same hash. + +369 +00:19:40,000 --> 00:19:41,000 +That's a birthday attack. + +370 +00:19:41,000 --> 00:19:42,000 +How do you defeat it? + +371 +00:19:42,000 --> 00:19:43,000 +Use a big hash. + +372 +00:19:43,000 --> 00:19:45,000 +Don't use a 128 bit hash. + +373 +00:19:45,000 --> 00:19:49,000 +Remember I said you can only beat the birthday attack if you increase the number of birthdays. + +374 +00:19:49,000 --> 00:19:50,000 +How do you beat it? + +375 +00:19:50,000 --> 00:19:52,000 +Don't use the same number. + +376 +00:19:52,000 --> 00:19:54,000 +Don't use small birthdays. + +377 +00:19:54,000 --> 00:19:56,000 +Don't use a pool with a small amount of birthdays. + +378 +00:19:56,000 --> 00:19:56,000 +Use a big one. + +379 +00:19:56,000 --> 00:19:57,000 +Don't use 128. + +380 +00:19:57,000 --> 00:19:58,000 +Use 256. + +381 +00:19:58,000 --> 00:20:00,000 +That's the one we should be using today. + +382 +00:20:00,000 --> 00:20:05,000 +Sha 256 all right, a lot of stuff in hashing. + +383 +00:20:05,000 --> 00:20:07,000 +But before I go, let's do a quick recap of hashing. + +384 +00:20:07,000 --> 00:20:09,000 +So hash is a cryptographic function. + +385 +00:20:09,000 --> 00:20:13,000 +It takes data of any length, produces a fixed length hash. + +386 +00:20:13,000 --> 00:20:14,000 +It's a one way thing. + +387 +00:20:14,000 --> 00:20:18,000 +You cannot take the the hash function and turn it back into the plaintext. + +388 +00:20:18,000 --> 00:20:20,000 +It should be quick. + +389 +00:20:20,000 --> 00:20:23,000 +In other words, the computation should be very, very fast. + +390 +00:20:23,000 --> 00:20:28,000 +Any change to the data results in a change to the cryptographic hash. + +391 +00:20:28,000 --> 00:20:29,000 +Why are we doing this? + +392 +00:20:29,000 --> 00:20:30,000 +The big word is integrity. + +393 +00:20:30,000 --> 00:20:34,000 +We're able to detect modification on the data and determine integrity. + +394 +00:20:34,000 --> 00:20:37,000 +And remember what collisions are the. + +395 +00:20:37,000 --> 00:20:39,000 +We should be able to resist collisions. + +396 +00:20:39,000 --> 00:20:41,000 +And the way we do that is by using bigger hashes. + +397 +00:20:41,000 --> 00:20:46,000 +Collision is when two messages produce the same, the exact same hash. + +398 +00:20:47,000 --> 00:20:51,000 +An example of this is the birthday attack, which we just which we just spoke about. + +399 +00:20:51,000 --> 00:20:55,000 +So so remember what the characteristics of hashes. + +400 +00:20:55,000 --> 00:20:59,000 +And now let's take a look at the different functions in the in the next video. + diff --git a/07 - Cryptography/012 Hashing Algorithms OB 1.4_en.srt b/07 - Cryptography/012 Hashing Algorithms OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..391cb6f249b3ce9f0fafff691b2884942df53a12 --- /dev/null +++ b/07 - Cryptography/012 Hashing Algorithms OB 1.4_en.srt @@ -0,0 +1,240 @@ +1 +00:00:00,000 --> 00:00:05,000 +Okay, before I get into this, I want you guys to remember I have a table at the end of this section + +2 +00:00:05,000 --> 00:00:09,000 +that's going to summarize everything that I'm about to cover with you guys. + +3 +00:00:09,000 --> 00:00:13,000 +So this video we're going to be taking a look at all the different hash functions that are out there. + +4 +00:00:13,000 --> 00:00:15,000 +Once again, don't memorize all of this. + +5 +00:00:15,000 --> 00:00:20,000 +I just need you to know which ones are hash functions, which one are symmetric functions, and which + +6 +00:00:20,000 --> 00:00:22,000 +ones are asymmetric functions or algorithms. + +7 +00:00:22,000 --> 00:00:23,000 +Let's take a look. + +8 +00:00:23,000 --> 00:00:32,000 +So when it comes to hashing algorithm uh Sha or the secure hash algorithm, those series is going to + +9 +00:00:32,000 --> 00:00:34,000 +be the most famous one. + +10 +00:00:34,000 --> 00:00:41,000 +In fact Sha two, which comes the 256 bit version of it, is one of the most popular hashing function + +11 +00:00:41,000 --> 00:00:42,000 +on the planet. + +12 +00:00:43,000 --> 00:00:48,000 +So the secure hash algorithm is a series of government hash functions. + +13 +00:00:48,000 --> 00:00:49,000 +This is promoted by NIST. + +14 +00:00:49,000 --> 00:00:53,000 +And if you know one thing in the world of security, if it's good enough for the government, it's generally + +15 +00:00:53,000 --> 00:00:54,000 +good enough for us. + +16 +00:00:54,000 --> 00:00:59,000 +The original Sha one was 160 bit hash. + +17 +00:00:59,000 --> 00:01:04,000 +This one here should no longer be used because it is subject to collisions. + +18 +00:01:04,000 --> 00:01:07,000 +Remember, how you beat collisions is by having a bigger hash function. + +19 +00:01:08,000 --> 00:01:11,000 +Sha two came in a variety of sizes. + +20 +00:01:11,000 --> 00:01:13,000 +Uh 256 bit. + +21 +00:01:13,000 --> 00:01:17,000 +It came in 512 and it also was 384. + +22 +00:01:17,000 --> 00:01:18,000 +I think this one came in. + +23 +00:01:18,000 --> 00:01:22,000 +So it did came in multiple sizes. + +24 +00:01:22,000 --> 00:01:24,000 +Now I don't need you guys to worry about the blocks. + +25 +00:01:24,000 --> 00:01:27,000 +I just need you guys to know basically the bit sizes on that. + +26 +00:01:27,000 --> 00:01:32,000 +There was a Sha three that came out that uh, is a newer version of that. + +27 +00:01:34,000 --> 00:01:37,000 +One of the most famous old school one was MD5. + +28 +00:01:37,000 --> 00:01:40,000 +Now MD5 should not be used. + +29 +00:01:40,000 --> 00:01:48,000 +MD5 has a lot of collisions because it doesn't have a very large, um, output at 128 bit. + +30 +00:01:48,000 --> 00:01:51,000 +Although it's big in today's world, it's not big anymore. + +31 +00:01:51,000 --> 00:01:53,000 +It is subject to collisions. + +32 +00:01:54,000 --> 00:02:03,000 +Now, the other one here is a ripe re and ripe MD uh or message digest. + +33 +00:02:03,000 --> 00:02:07,000 +This is an alternative to the Sha algorithms that are out there. + +34 +00:02:07,000 --> 00:02:10,000 +And these have a variety of different block sizes. + +35 +00:02:10,000 --> 00:02:14,000 +Now I did put it on the text here, but I do summarize it for you guys right here. + +36 +00:02:15,000 --> 00:02:21,000 +Realistically, I don't need you guys to know all this last column. + +37 +00:02:21,000 --> 00:02:23,000 +What I do need you guys to know is to know this column. + +38 +00:02:23,000 --> 00:02:26,000 +Know that these are basically. + +39 +00:02:28,000 --> 00:02:29,000 +Uh, hash functions. + +40 +00:02:29,000 --> 00:02:35,000 +So on the exam, if they give you something, a scenario that you have to use this particular algorithm + +41 +00:02:35,000 --> 00:02:40,000 +for, like for example, if they send your encrypted data across a network, don't select any of these + +42 +00:02:40,000 --> 00:02:42,000 +because these are hash functions. + +43 +00:02:42,000 --> 00:02:44,000 +They don't encrypt data, right. + +44 +00:02:44,000 --> 00:02:45,000 +They produce hash functions. + +45 +00:02:45,000 --> 00:02:46,000 +They're used for integrity. + +46 +00:02:46,000 --> 00:02:48,000 +So that's what you should know. + +47 +00:02:48,000 --> 00:02:53,000 +But if you want to see what what algorithm can change, data can detect if data has been modified. + +48 +00:02:53,000 --> 00:02:56,000 +Those hash functions, that's what they're there for. + +49 +00:02:56,000 --> 00:02:56,000 +All right. + +50 +00:02:56,000 --> 00:02:59,000 +So don't you know don't go crazy. + +51 +00:02:59,000 --> 00:02:59,000 +Oh my God. + +52 +00:02:59,000 --> 00:03:03,000 +And you know, you just maybe this column here you should know. + +53 +00:03:03,000 --> 00:03:04,000 +And it's pretty easy right. + +54 +00:03:04,000 --> 00:03:05,000 +Because. + +55 +00:03:05,000 --> 00:03:10,000 +Ripemd sha md5, just the ones you're probably going to see. + +56 +00:03:10,000 --> 00:03:13,000 +So it's basically only three of them you really should keep in mind. + +57 +00:03:14,000 --> 00:03:14,000 +Okay. + +58 +00:03:14,000 --> 00:03:20,000 +Make sure you know these, um, as a real life security person, just remember, Sha256 should be your + +59 +00:03:20,000 --> 00:03:21,000 +minimum. + +60 +00:03:21,000 --> 00:03:28,000 +Don't use hash functions that are generally under 256 bit in the world of security. + diff --git a/07 - Cryptography/013 Digital Signatures OB 1.4_en.srt b/07 - Cryptography/013 Digital Signatures OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..61dce85ac7bb72662a1e257366018d1b678bb9b1 --- /dev/null +++ b/07 - Cryptography/013 Digital Signatures OB 1.4_en.srt @@ -0,0 +1,636 @@ +1 +00:00:00,000 --> 00:00:07,000 +So far we have covered a lot symmetric asymmetric hashing hybrid cryptography. + +2 +00:00:07,000 --> 00:00:10,000 +So far we covered a lot in this topic. + +3 +00:00:10,000 --> 00:00:14,000 +We're going to be combining a lot of what we learned to produce a particular function that I need you + +4 +00:00:14,000 --> 00:00:16,000 +guys to know, because we use it a lot. + +5 +00:00:16,000 --> 00:00:19,000 +And that's called a digital signature. + +6 +00:00:19,000 --> 00:00:23,000 +Now a digital signature is not a not a way to encrypt data. + +7 +00:00:23,000 --> 00:00:28,000 +So it doesn't provide confidentiality, but it's a way that when you send data to someone, they know + +8 +00:00:28,000 --> 00:00:33,000 +it came from you, you can prove it came from you and it wasn't modified. + +9 +00:00:33,000 --> 00:00:39,000 +And a digital signature is going to utilize some of the things we learned in in asymmetric and hashing + +10 +00:00:39,000 --> 00:00:40,000 +in order to get it done. + +11 +00:00:40,000 --> 00:00:46,000 +So in this video, I want to go through what exactly is a digital signature and what is the process? + +12 +00:00:46,000 --> 00:00:50,000 +What is the process to make a signature and to verify a signature? + +13 +00:00:50,000 --> 00:00:51,000 +Let's get into it. + +14 +00:00:52,000 --> 00:00:55,000 +So what exactly is a digital signature? + +15 +00:00:55,000 --> 00:01:02,000 +Well, it's a cryptographic technique used to validate the authentic unity and integrity of a message + +16 +00:01:02,000 --> 00:01:03,000 +software digital document. + +17 +00:01:03,000 --> 00:01:09,000 +Now a lot of times we digitally sign things like digital certificates and even PDF files. + +18 +00:01:09,000 --> 00:01:11,000 +Word documents can all be digitally signed. + +19 +00:01:11,000 --> 00:01:14,000 +Emails very famous to be digitally signed. + +20 +00:01:14,000 --> 00:01:18,000 +Also, when you're doing a digital signature, you must remember. + +21 +00:01:19,000 --> 00:01:25,000 +A digital signature is authenticity or authentication, its integrity and non-repudiation. + +22 +00:01:25,000 --> 00:01:27,000 +It is not confidentiality. + +23 +00:01:27,000 --> 00:01:30,000 +The data goes in plain text. + +24 +00:01:30,000 --> 00:01:31,000 +You have to remember this. + +25 +00:01:31,000 --> 00:01:40,000 +So if I have an email that I digitally sign and I send you that email, the email goes in plain text. + +26 +00:01:40,000 --> 00:01:43,000 +That means if if all I did was digitally sign it. + +27 +00:01:44,000 --> 00:01:46,000 +And I sent it to you. + +28 +00:01:46,000 --> 00:01:47,000 +And a hacker sniffs the line. + +29 +00:01:47,000 --> 00:01:50,000 +The hacker would be able to read the email because the email is not encrypted. + +30 +00:01:50,000 --> 00:01:56,000 +But when you receive it, you'll know that it came from me. + +31 +00:01:57,000 --> 00:02:01,000 +I wouldn't be able to deny that it came from me. + +32 +00:02:01,000 --> 00:02:02,000 +Non-repudiation. + +33 +00:02:02,000 --> 00:02:06,000 +And you're going to be 100% sure it was never modified. + +34 +00:02:06,000 --> 00:02:07,000 +All right. + +35 +00:02:07,000 --> 00:02:09,000 +So that's these three things. + +36 +00:02:09,000 --> 00:02:11,000 +Confirms the signature was created by a sender. + +37 +00:02:11,000 --> 00:02:14,000 +So you'll know it came from me. + +38 +00:02:14,000 --> 00:02:17,000 +And I can't deny that it came from me. + +39 +00:02:17,000 --> 00:02:17,000 +All right. + +40 +00:02:17,000 --> 00:02:22,000 +So the authenticity, the non-repudiation, and then you'll know it was never modified. + +41 +00:02:22,000 --> 00:02:24,000 +That's the point that you guys need to get. + +42 +00:02:25,000 --> 00:02:29,000 +Once again, digital signatures does not encrypt the data. + +43 +00:02:29,000 --> 00:02:31,000 +The data is actually transferred in plain text. + +44 +00:02:31,000 --> 00:02:34,000 +Now, if you want to encrypt the data, well, that's a whole different thing. + +45 +00:02:34,000 --> 00:02:41,000 +Maybe then you can combine with SSL, IPsec or other types of secure, secure algorithms. + +46 +00:02:41,000 --> 00:02:45,000 +But if you're just using digital signatures, you're not going to get that. + +47 +00:02:46,000 --> 00:02:52,000 +Now in this video, I want to talk to you guys about the creation and the verification of it. + +48 +00:02:52,000 --> 00:03:00,000 +I do have all the texts listed here, but I have the, uh, I have a process that I drew out that I + +49 +00:03:00,000 --> 00:03:02,000 +want to go over with you that covers all of this. + +50 +00:03:02,000 --> 00:03:07,000 +So if you're watching, if you're reading this instead of watching it, well, you guys can read this, + +51 +00:03:07,000 --> 00:03:12,000 +but since you're with me, I'm going to explain it to you in this particular. + +52 +00:03:14,000 --> 00:03:15,000 +In this. + +53 +00:03:15,000 --> 00:03:16,000 +Uh, where is my. + +54 +00:03:16,000 --> 00:03:17,000 +Here we go. + +55 +00:03:17,000 --> 00:03:18,000 +In this process. + +56 +00:03:18,000 --> 00:03:20,000 +So I watch you guys watch this. + +57 +00:03:20,000 --> 00:03:25,000 +So I'm going to show you how we are going to generate a signature. + +58 +00:03:26,000 --> 00:03:26,000 +Okay. + +59 +00:03:26,000 --> 00:03:28,000 +We're going to generate a digital signature. + +60 +00:03:28,000 --> 00:03:30,000 +We're going to attach it to a document send it to the receiver. + +61 +00:03:30,000 --> 00:03:31,000 +Let's see how this is done. + +62 +00:03:31,000 --> 00:03:33,000 +So here we have the sender and the. + +63 +00:03:35,000 --> 00:03:37,000 +And the receiver. + +64 +00:03:37,000 --> 00:03:42,000 +Mary I'm always sending Mary things because okay, so here's how it's done okay. + +65 +00:03:43,000 --> 00:03:46,000 +You take a plain text message? + +66 +00:03:46,000 --> 00:03:48,000 +This is the message. + +67 +00:03:48,000 --> 00:03:53,000 +And then what you're going to do is you're going to hash it, hash the entire message. + +68 +00:03:53,000 --> 00:03:58,000 +And this produces that cryptographic hash that, remember, if you remember in the hashing video was + +69 +00:03:58,000 --> 00:03:59,000 +just a string of characters. + +70 +00:03:59,000 --> 00:04:01,000 +Basically it produces the digest. + +71 +00:04:01,000 --> 00:04:03,000 +Remember the digest hash. + +72 +00:04:03,000 --> 00:04:03,000 +Same thing. + +73 +00:04:04,000 --> 00:04:15,000 +Then what the sender does is the sender encrypts this digest with the sender's private key. + +74 +00:04:16,000 --> 00:04:18,000 +That is. + +75 +00:04:18,000 --> 00:04:18,000 +All right. + +76 +00:04:18,000 --> 00:04:20,000 +Then they're using an RSA key here. + +77 +00:04:20,000 --> 00:04:22,000 +That is the digital signature. + +78 +00:04:23,000 --> 00:04:24,000 +So let's get this straight. + +79 +00:04:25,000 --> 00:04:26,000 +If I'm the sender. + +80 +00:04:26,000 --> 00:04:27,000 +I took the message. + +81 +00:04:28,000 --> 00:04:30,000 +I hashed it. + +82 +00:04:30,000 --> 00:04:34,000 +I did encrypt the hash with my private key. + +83 +00:04:34,000 --> 00:04:35,000 +Not my public key. + +84 +00:04:36,000 --> 00:04:37,000 +My private key. + +85 +00:04:37,000 --> 00:04:38,000 +Why the private key? + +86 +00:04:38,000 --> 00:04:44,000 +Because the only person in the world that has my private key is me. + +87 +00:04:44,000 --> 00:04:46,000 +No one else. + +88 +00:04:46,000 --> 00:04:52,000 +So a digital signature in its purest form is an encrypted hash. + +89 +00:04:52,000 --> 00:04:53,000 +Really all it is? + +90 +00:04:53,000 --> 00:04:56,000 +It's encrypted with an asymmetric algorithm. + +91 +00:04:56,000 --> 00:04:58,000 +In this one they're using RSA. + +92 +00:04:58,000 --> 00:05:00,000 +You can also use ECC here. + +93 +00:05:00,000 --> 00:05:08,000 +So what I do is I take this digital signature and I attach it to the document and I send it to the receiver. + +94 +00:05:10,000 --> 00:05:13,000 +Mary has the document okay. + +95 +00:05:14,000 --> 00:05:15,000 +And the digital signature. + +96 +00:05:15,000 --> 00:05:18,000 +But remember it's all going in plain text signatures. + +97 +00:05:18,000 --> 00:05:20,000 +Everything is in plain text. + +98 +00:05:20,000 --> 00:05:21,000 +What does Mary do? + +99 +00:05:21,000 --> 00:05:23,000 +So Mary is like, okay, I got this signature. + +100 +00:05:23,000 --> 00:05:27,000 +Mary is like, okay, I need to verify, you know, that this actually came from Andy. + +101 +00:05:27,000 --> 00:05:28,000 +How is she going to do it? + +102 +00:05:28,000 --> 00:05:29,000 +Next slide. + +103 +00:05:30,000 --> 00:05:31,000 +How does she do it? + +104 +00:05:31,000 --> 00:05:31,000 +Well. + +105 +00:05:32,000 --> 00:05:33,000 +Here's what she's going to do. + +106 +00:05:34,000 --> 00:05:37,000 +So receiver again. + +107 +00:05:37,000 --> 00:05:37,000 +Mary. + +108 +00:05:40,000 --> 00:05:46,000 +Mary has to go through a couple of things, but Mary does is she takes this digitally signed message. + +109 +00:05:46,000 --> 00:05:49,000 +She removes the digital signature from it. + +110 +00:05:49,000 --> 00:05:51,000 +So now she has the plain text message. + +111 +00:05:51,000 --> 00:05:58,000 +She then hashes it with the same algorithm that I used to hash the original message, and she ends up + +112 +00:05:58,000 --> 00:05:58,000 +with a digest. + +113 +00:05:59,000 --> 00:06:02,000 +She then takes the digital signature right? + +114 +00:06:02,000 --> 00:06:09,000 +And she decrypts it with my the sender's. + +115 +00:06:09,000 --> 00:06:11,000 +Public key. + +116 +00:06:11,000 --> 00:06:12,000 +Why the sender's public key? + +117 +00:06:12,000 --> 00:06:19,000 +Because, remember, in the generation, it was the sender's private key that was used to. + +118 +00:06:20,000 --> 00:06:23,000 +Encrypt the actual hash. + +119 +00:06:23,000 --> 00:06:28,000 +So what she's doing here is she's decrypting the signature with the public key. + +120 +00:06:29,000 --> 00:06:32,000 +If the private encrypts, the public has to decrypt that. + +121 +00:06:33,000 --> 00:06:36,000 +Provides the message digest. + +122 +00:06:36,000 --> 00:06:41,000 +So what she's going to do now is she's going to compare the hash that she generated from the message, + +123 +00:06:41,000 --> 00:06:45,000 +and she's going to compare the hash that was generated from the signature she just decrypted. + +124 +00:06:45,000 --> 00:06:53,000 +And she's going to see do they compare if the message is from the digital signatures matches. + +125 +00:06:54,000 --> 00:06:54,000 +Right. + +126 +00:06:54,000 --> 00:06:58,000 +If the if this digest matches this digest, then it could be trusted by. + +127 +00:06:59,000 --> 00:07:00,000 +Well. + +128 +00:07:01,000 --> 00:07:05,000 +If the two digests are matching, it shows that the message was never modified. + +129 +00:07:06,000 --> 00:07:06,000 +Right. + +130 +00:07:06,000 --> 00:07:08,000 +Because if there's any modification to digest would change. + +131 +00:07:08,000 --> 00:07:13,000 +And she knows 100% that it came from me. + +132 +00:07:13,000 --> 00:07:13,000 +Why? + +133 +00:07:13,000 --> 00:07:17,000 +Because she used my public key to decrypt that. + +134 +00:07:17,000 --> 00:07:20,000 +If she had used somebody else public key, it would never match. + +135 +00:07:20,000 --> 00:07:23,000 +It would look like more garbage or more ciphertext. + +136 +00:07:24,000 --> 00:07:27,000 +So that is the process of a digital signature. + +137 +00:07:28,000 --> 00:07:31,000 +Now digital signatures are widely used. + +138 +00:07:31,000 --> 00:07:34,000 +Now, if you by the way, if you don't understand this process and you want to do it, you know, watch + +139 +00:07:34,000 --> 00:07:35,000 +this video a couple of times. + +140 +00:07:35,000 --> 00:07:38,000 +But digital signatures are widely used. + +141 +00:07:38,000 --> 00:07:41,000 +In fact, there's a whole standard on it. + +142 +00:07:41,000 --> 00:07:46,000 +So one time that you may want to be familiar with is something we call the DSS or the digital signature + +143 +00:07:46,000 --> 00:07:52,000 +standard, because when you produce a signature, the person has to know what algorithm you use, right? + +144 +00:07:52,000 --> 00:07:55,000 +They have to know, did he use Sha256? + +145 +00:07:55,000 --> 00:07:55,000 +512. + +146 +00:07:55,000 --> 00:08:03,000 +Sha Sha two Sha three uh, you could use ECC as the asymmetric or RSA. + +147 +00:08:04,000 --> 00:08:07,000 +So there is a standard for this, right? + +148 +00:08:07,000 --> 00:08:13,000 +So NSA created the digital digital signature algorithm. + +149 +00:08:13,000 --> 00:08:16,000 +The digital signature algorithm utilizes either. + +150 +00:08:16,000 --> 00:08:20,000 +So the DSA is either it's shot 2 or 3. + +151 +00:08:20,000 --> 00:08:28,000 +With RSA there's another one called Ecdsa which is instead of using RSA they use elliptic curve. + +152 +00:08:28,000 --> 00:08:28,000 +All right. + +153 +00:08:28,000 --> 00:08:32,000 +So just be familiar that there is a signature standard for this. + +154 +00:08:33,000 --> 00:08:36,000 +Digital signatures are really important digital signatures. + +155 +00:08:36,000 --> 00:08:43,000 +When somebody signs a document you are 100% sure it came from that person and it was never modified. + +156 +00:08:43,000 --> 00:08:47,000 +You have to remember that because I'm about to bring everything together when we talk about public key + +157 +00:08:47,000 --> 00:08:48,000 +infrastructure. + +158 +00:08:48,000 --> 00:08:51,000 +So remember that once a digital signature is done. + +159 +00:08:52,000 --> 00:08:59,000 +You're 100% sure that it came from that person and it was never modified. + diff --git a/07 - Cryptography/014 Intro to PKI OB 1.4_en.srt b/07 - Cryptography/014 Intro to PKI OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..91daf6a716647e7984b87b94896435470913a1fb --- /dev/null +++ b/07 - Cryptography/014 Intro to PKI OB 1.4_en.srt @@ -0,0 +1,124 @@ +1 +00:00:00,000 --> 00:00:04,000 +In this video, I want to start the discussion of the public key infrastructure. + +2 +00:00:04,000 --> 00:00:10,000 +But before we get into that, I want to go to Amazon and I want to clear up some things about Amazon + +3 +00:00:10,000 --> 00:00:11,000 +that we should know. + +4 +00:00:11,000 --> 00:00:13,000 +Before we get into this topic, let's take a look. + +5 +00:00:13,000 --> 00:00:16,000 +So here I am at Amazon.com. + +6 +00:00:16,000 --> 00:00:19,000 +Now the question is going to be how do I know? + +7 +00:00:19,000 --> 00:00:24,000 +How does this computer know that this is Amazon. + +8 +00:00:24,000 --> 00:00:27,000 +Like do you trust the browser? + +9 +00:00:27,000 --> 00:00:34,000 +Okay, it says Amazon.com on it, but how does this computer know that this is Amazon.com? + +10 +00:00:34,000 --> 00:00:36,000 +Is there a trust factor? + +11 +00:00:36,000 --> 00:00:41,000 +Did Amazon tell this computer something that says, hey, I'm Amazon.com and the computer is like, + +12 +00:00:41,000 --> 00:00:45,000 +okay, well, I guess you are, but how can the machine verify that? + +13 +00:00:46,000 --> 00:00:51,000 +Well, you guys probably already know the answer to this is because it has a certificate. + +14 +00:00:51,000 --> 00:00:55,000 +This connection is secured using TLS. + +15 +00:00:55,000 --> 00:00:58,000 +And how do we know connections are secured? + +16 +00:00:58,000 --> 00:01:00,000 +Well, on most browsers, if not all. + +17 +00:01:00,000 --> 00:01:08,000 +When you look at a connection like on Amazon, you'll notice that we have a little lock icon. + +18 +00:01:08,000 --> 00:01:10,000 +If I go to this icon, I click on it. + +19 +00:01:10,000 --> 00:01:12,000 +It says the connection is secure. + +20 +00:01:12,000 --> 00:01:15,000 +I click here and it says the certificate is valid. + +21 +00:01:15,000 --> 00:01:19,000 +But what exactly is this particular certificate? + +22 +00:01:19,000 --> 00:01:23,000 +What is the purpose of this certificate and what you know? + +23 +00:01:23,000 --> 00:01:30,000 +What exactly is it doing that makes this computer trust that this is Amazon.com? + +24 +00:01:31,000 --> 00:01:39,000 +A certificate is basically nothing more than a document that contains Amazon's public key and a signature + +25 +00:01:39,000 --> 00:01:43,000 +from a certificate authority saying that that's actually Amazon in a nutshell. + +26 +00:01:43,000 --> 00:01:44,000 +That's what it is. + +27 +00:01:44,000 --> 00:01:51,000 +But in this section of the course, I'm going to go in depth into more into all the fields on that certificate. + +28 +00:01:51,000 --> 00:01:57,000 +What exactly is a certificate authority and why is, you know, why do we need it? + +29 +00:01:57,000 --> 00:02:01,000 +Why is it so important that your connection be trusted or secure? + +30 +00:02:01,000 --> 00:02:02,000 +Okay. + +31 +00:02:02,000 --> 00:02:05,000 +So let's go ahead and get started in this section. + diff --git a/07 - Cryptography/016 SSLTLS Handshake OB 1.4_en.srt b/07 - Cryptography/016 SSLTLS Handshake OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..46c3fc0a4f1b20e0929ad0f10e5f1cc2fde96e52 --- /dev/null +++ b/07 - Cryptography/016 SSLTLS Handshake OB 1.4_en.srt @@ -0,0 +1,1176 @@ +1 +00:00:00,000 --> 00:00:06,000 +In this video, I'm going to be going over the SSL handshake, something that you really have to understand, + +2 +00:00:06,000 --> 00:00:10,000 +not just for your exam, but exactly how this cryptography work. + +3 +00:00:10,000 --> 00:00:17,000 +When you buy something on Amazon or any website or any website that is secured using TLS or SSL. + +4 +00:00:17,000 --> 00:00:22,000 +Now for this course and in particular this section, TLS and SSL is the same thing. + +5 +00:00:22,000 --> 00:00:26,000 +So if I ever say SSL, TLS remember something SSL is not used anymore. + +6 +00:00:26,000 --> 00:00:31,000 +SSL is replaced by TLS, but a lot of people still reference it. + +7 +00:00:31,000 --> 00:00:34,000 +Like if you go online, you Google SSL certificate. + +8 +00:00:34,000 --> 00:00:36,000 +They're not really SSL, they're all TLS certificate. + +9 +00:00:37,000 --> 00:00:42,000 +So for argument's sake, we'll just say we'll just use the terms SSL for the remainder of the course. + +10 +00:00:42,000 --> 00:00:44,000 +Remember it is actually TLS. + +11 +00:00:44,000 --> 00:00:46,000 +Now let's get started. + +12 +00:00:46,000 --> 00:00:49,000 +So in this video we want to talk about the SSL handshake. + +13 +00:00:49,000 --> 00:00:55,000 +Now the presentation that I'm going to be using the diagram I'm going to be using comes from Ibm.com. + +14 +00:00:55,000 --> 00:01:01,000 +And that particular link I will be sharing with you guys on the slide. + +15 +00:01:01,000 --> 00:01:06,000 +And I want to show you guys what that looks like now, so you can check it out whenever you get a minute. + +16 +00:01:06,000 --> 00:01:08,000 +Uh, here's Ibm.com. + +17 +00:01:09,000 --> 00:01:12,000 +This was last updated 2021 the SSL handshake. + +18 +00:01:12,000 --> 00:01:12,000 +So I took this. + +19 +00:01:12,000 --> 00:01:13,000 +I put it on the slide. + +20 +00:01:13,000 --> 00:01:18,000 +Of course, I put the link here for you guys to review it also, and I want to go over this with you + +21 +00:01:19,000 --> 00:01:21,000 +if you're asking yourself well why? + +22 +00:01:21,000 --> 00:01:25,000 +Because this is going to explain to you at a high level overview. + +23 +00:01:25,000 --> 00:01:29,000 +Exactly how does a connection work? + +24 +00:01:29,000 --> 00:01:36,000 +Like when you go to Amazon.com and you try to purchase something, you go to Yahoo YouTube. + +25 +00:01:36,000 --> 00:01:37,000 +It doesn't matter. + +26 +00:01:37,000 --> 00:01:39,000 +They're all secure sites. + +27 +00:01:39,000 --> 00:01:43,000 +In fact, all sites on the internet right now are secured using SSL. + +28 +00:01:43,000 --> 00:01:46,000 +How exactly this whole encryption process work? + +29 +00:01:46,000 --> 00:01:47,000 +Now I want to point out something. + +30 +00:01:47,000 --> 00:01:52,000 +The SSL handshake presentation that I'm using from IBM is a high level. + +31 +00:01:52,000 --> 00:01:55,000 +It's not very detailed and it's not very technical. + +32 +00:01:55,000 --> 00:01:56,000 +For your exam. + +33 +00:01:56,000 --> 00:01:58,000 +You don't need to be detailed and technical. + +34 +00:01:59,000 --> 00:02:02,000 +If you take my course, I'll get more in depth into it. + +35 +00:02:02,000 --> 00:02:04,000 +But for this course you don't need that. + +36 +00:02:04,000 --> 00:02:08,000 +You just need to have a good understanding or a high level overview understanding. + +37 +00:02:08,000 --> 00:02:09,000 +Let's get started on it. + +38 +00:02:09,000 --> 00:02:18,000 +So I go to Amazon.com and here I am at Amazon and I can see that my connection is secure. + +39 +00:02:18,000 --> 00:02:21,000 +And if you notice is it secure. + +40 +00:02:21,000 --> 00:02:22,000 +Yeah, it's fully secured. + +41 +00:02:22,000 --> 00:02:25,000 +Because if you notice I have an Https right here. + +42 +00:02:25,000 --> 00:02:28,000 +So this is utilizing SSL. + +43 +00:02:28,000 --> 00:02:31,000 +Now the question is going to be how do I know. + +44 +00:02:31,000 --> 00:02:32,000 +Like it's actually working. + +45 +00:02:32,000 --> 00:02:34,000 +And you know what's happening in the background. + +46 +00:02:34,000 --> 00:02:40,000 +Well one of the things is that every single website you go to that is secure is going to have this little + +47 +00:02:40,000 --> 00:02:41,000 +lock icon. + +48 +00:02:41,000 --> 00:02:42,000 +So I'm going to click on this little lock icon. + +49 +00:02:42,000 --> 00:02:46,000 +This lock icon tells me the connection is secure. + +50 +00:02:46,000 --> 00:02:49,000 +And you can't have a secure connection without a certificate. + +51 +00:02:49,000 --> 00:02:52,000 +So I'm going to go to connection to secure certificate is valid. + +52 +00:02:52,000 --> 00:02:53,000 +I'm just going to click on this. + +53 +00:02:53,000 --> 00:02:56,000 +This is Amazon certificate. + +54 +00:02:56,000 --> 00:02:58,000 +Now what exactly is a certificate. + +55 +00:02:58,000 --> 00:03:04,000 +Well a certificate really serves two main purpose in the world of encryption. + +56 +00:03:04,000 --> 00:03:09,000 +Number one, it serves as a trusted as an external validation of trust. + +57 +00:03:09,000 --> 00:03:15,000 +So right now Amazon is not saying that I'm Amazon because I'm Amazon. + +58 +00:03:16,000 --> 00:03:20,000 +Amazon is telling your computer that it's Amazon. + +59 +00:03:20,000 --> 00:03:24,000 +Not because I said it's Amazon or because Amazon said it's Amazon. + +60 +00:03:24,000 --> 00:03:31,000 +It's saying that because this authority Digicert says that this is Amazon.com and this is important. + +61 +00:03:31,000 --> 00:03:35,000 +External validation creates trust. + +62 +00:03:35,000 --> 00:03:36,000 +Let me explain this to you. + +63 +00:03:37,000 --> 00:03:40,000 +So I'm Andrew Ramsdale okay. + +64 +00:03:40,000 --> 00:03:44,000 +I'm the guy with the 66 certifications, the world's best selling book. + +65 +00:03:45,000 --> 00:03:47,000 +But do you know that for sure? + +66 +00:03:47,000 --> 00:03:49,000 +Do you know if I'm that person? + +67 +00:03:49,000 --> 00:03:54,000 +There is a guy that wrote the world's best selling book on Amazon for project management. + +68 +00:03:54,000 --> 00:03:58,000 +There is a guy that made a, you know, a lot of different videos and has helped hundreds of thousands + +69 +00:03:58,000 --> 00:04:02,000 +of people pass exams, but am I that person? + +70 +00:04:02,000 --> 00:04:03,000 +Do you trust me? + +71 +00:04:03,000 --> 00:04:05,000 +If I told you I'm Andrew, do you? + +72 +00:04:05,000 --> 00:04:06,000 +How do you know? + +73 +00:04:06,000 --> 00:04:09,000 +How do you know I am that person? + +74 +00:04:09,000 --> 00:04:10,000 +How do you. + +75 +00:04:10,000 --> 00:04:12,000 +You know I am that entity. + +76 +00:04:13,000 --> 00:04:15,000 +Well, I'm just telling you I am. + +77 +00:04:15,000 --> 00:04:16,000 +Is that okay if I tell you? + +78 +00:04:16,000 --> 00:04:19,000 +Or would you like for me to produce my driver's license? + +79 +00:04:19,000 --> 00:04:20,000 +Like if I told you. + +80 +00:04:20,000 --> 00:04:21,000 +Okay. + +81 +00:04:21,000 --> 00:04:23,000 +Here's my driver's license. + +82 +00:04:23,000 --> 00:04:24,000 +Would you believe me then? + +83 +00:04:25,000 --> 00:04:27,000 +So if you say yes, okay. + +84 +00:04:27,000 --> 00:04:34,000 +If you show me your license, that shows me that your Andrew and that picture matches you, then you, + +85 +00:04:34,000 --> 00:04:36,000 +then you're more likely or you will believe it. + +86 +00:04:36,000 --> 00:04:41,000 +That tells me something that tells me that you don't trust me. + +87 +00:04:41,000 --> 00:04:44,000 +You trust the DMV. + +88 +00:04:44,000 --> 00:04:46,000 +You have a trust with the DMV. + +89 +00:04:46,000 --> 00:04:53,000 +And if the DMV says that this guy is Andrew, then you trust that you're like, okay, that that guy + +90 +00:04:53,000 --> 00:04:54,000 +must be Andrew. + +91 +00:04:54,000 --> 00:04:56,000 +Do you understand what I'm saying here? + +92 +00:04:56,000 --> 00:05:00,000 +What I'm trying to tell you is you don't have a trust with me. + +93 +00:05:00,000 --> 00:05:02,000 +You have a trust with the DMV. + +94 +00:05:02,000 --> 00:05:08,000 +And because the DMV is saying that I'm Andrew now, you believe, okay, he's Andrew, but you don't + +95 +00:05:08,000 --> 00:05:10,000 +believe a word that comes out of my mouth. + +96 +00:05:10,000 --> 00:05:13,000 +You believe what the DMV is saying? + +97 +00:05:13,000 --> 00:05:15,000 +And why do you believe the DMV? + +98 +00:05:15,000 --> 00:05:16,000 +That's the question. + +99 +00:05:16,000 --> 00:05:18,000 +Why do you believe the DMV? + +100 +00:05:18,000 --> 00:05:25,000 +Well, because I couldn't get the license if I didn't show my passport. + +101 +00:05:25,000 --> 00:05:27,000 +Bank statements. + +102 +00:05:27,000 --> 00:05:29,000 +Uh, I forgot all the documents. + +103 +00:05:29,000 --> 00:05:29,000 +Right? + +104 +00:05:29,000 --> 00:05:30,000 +You got to get in New York. + +105 +00:05:30,000 --> 00:05:31,000 +You got to get all these points. + +106 +00:05:31,000 --> 00:05:32,000 +Right. + +107 +00:05:32,000 --> 00:05:34,000 +So I had to show all these identity documents. + +108 +00:05:34,000 --> 00:05:37,000 +And that's the reason why you trust the DMV. + +109 +00:05:37,000 --> 00:05:40,000 +Well, you see, in computers, it's the same thing. + +110 +00:05:41,000 --> 00:05:42,000 +Computers. + +111 +00:05:42,000 --> 00:05:45,000 +Don't trust a website to say it's a web. + +112 +00:05:45,000 --> 00:05:48,000 +It doesn't trust the website to say it's that website. + +113 +00:05:49,000 --> 00:05:50,000 +It trusses. + +114 +00:05:50,000 --> 00:05:55,000 +Your computer has a pre list of authorities that it trusts. + +115 +00:05:55,000 --> 00:05:57,000 +Quote unquote DMVs. + +116 +00:05:57,000 --> 00:05:59,000 +These are going to be called certificate authorities. + +117 +00:05:59,000 --> 00:06:02,000 +Your computer has a pre list of certificate authorities that it trusts. + +118 +00:06:02,000 --> 00:06:07,000 +Similarly to how your mind has a list of people that it trusts like DMVs. + +119 +00:06:08,000 --> 00:06:14,000 +So when these authorities give out, quote unquote, driver's license, we'll call them certificates, + +120 +00:06:14,000 --> 00:06:16,000 +two different websites. + +121 +00:06:16,000 --> 00:06:21,000 +When your computer go to them, your computer is like, hey, how do I know this is Amazon? + +122 +00:06:21,000 --> 00:06:26,000 +And then you look at your computer, looks at the certificate and say, well, how do I know this is + +123 +00:06:26,000 --> 00:06:26,000 +Amazon? + +124 +00:06:26,000 --> 00:06:31,000 +Well, it's coming from somebody I trust Digicert in particular. + +125 +00:06:31,000 --> 00:06:33,000 +And how do I know this is Amazon? + +126 +00:06:33,000 --> 00:06:43,000 +Because Digicert is saying that this is Amazon and because your computer is able to trust. + +127 +00:06:43,000 --> 00:06:46,000 +Uh digicert you now trust that this is Amazon. + +128 +00:06:46,000 --> 00:06:48,000 +That's how this game works. + +129 +00:06:49,000 --> 00:06:54,000 +There are certain websites where there's something called a self-signed certificate. + +130 +00:06:54,000 --> 00:06:55,000 +We'll talk more about this later. + +131 +00:06:55,000 --> 00:07:00,000 +But self-signed certificates is when the company it's trust it's issued by Amazon to Amazon to Amazon + +132 +00:07:00,000 --> 00:07:01,000 +is saying I'm Amazon. + +133 +00:07:01,000 --> 00:07:04,000 +You don't trust that a lot of people don't trust self-signed certificates. + +134 +00:07:04,000 --> 00:07:08,000 +In fact, when internal organizations do it internally, it's not considered external trust because + +135 +00:07:08,000 --> 00:07:10,000 +nobody trusts it externally. + +136 +00:07:10,000 --> 00:07:11,000 +Self-signed. + +137 +00:07:11,000 --> 00:07:15,000 +That's like me making my own ID it's like, hey, you trust I'm Andrew when I here is an ID that I made + +138 +00:07:15,000 --> 00:07:16,000 +on my computer last time. + +139 +00:07:16,000 --> 00:07:17,000 +It says I'm Andrew. + +140 +00:07:17,000 --> 00:07:18,000 +Do you trust that? + +141 +00:07:18,000 --> 00:07:18,000 +No. + +142 +00:07:18,000 --> 00:07:22,000 +You trust the driver's license because it comes from the DMV. + +143 +00:07:23,000 --> 00:07:25,000 +So that's this concept of trust. + +144 +00:07:25,000 --> 00:07:27,000 +That's why trust is important. + +145 +00:07:27,000 --> 00:07:34,000 +Your computer needs to have some kind of external validation that this is Amazon. + +146 +00:07:34,000 --> 00:07:35,000 +And what's doing that. + +147 +00:07:35,000 --> 00:07:39,000 +The certificate is doing that now a certificate I mentioned. + +148 +00:07:39,000 --> 00:07:39,000 +It's two things. + +149 +00:07:39,000 --> 00:07:46,000 +Not just establishing that trust, but the certificate is a way to give the public key. + +150 +00:07:46,000 --> 00:07:49,000 +And that's important because that's going to become part of this handshake. + +151 +00:07:49,000 --> 00:07:50,000 +And I want to show you guys that. + +152 +00:07:51,000 --> 00:07:57,000 +So by looking if I go to details on this certificate on here. + +153 +00:07:57,000 --> 00:07:59,000 +So this is the Amazon certificate that we have. + +154 +00:07:59,000 --> 00:08:02,000 +And you notice I have a variety of fields here. + +155 +00:08:02,000 --> 00:08:11,000 +So if I go down and I look into all of these fields that is listed here notice subject public key info. + +156 +00:08:12,000 --> 00:08:14,000 +Subjects public key algorithm. + +157 +00:08:14,000 --> 00:08:17,000 +It's an RSA key that they're using. + +158 +00:08:17,000 --> 00:08:19,000 +Remember RSA is asymmetric. + +159 +00:08:19,000 --> 00:08:22,000 +But here is Amazon's actual public key. + +160 +00:08:22,000 --> 00:08:25,000 +This is a it's written it looks weird. + +161 +00:08:25,000 --> 00:08:29,000 +It's written in a hex but it's a 2048 bit RSA key. + +162 +00:08:29,000 --> 00:08:32,000 +This is Amazon's actual public key. + +163 +00:08:33,000 --> 00:08:35,000 +Remember there is a public and a private key. + +164 +00:08:35,000 --> 00:08:41,000 +So Amazon is allowing the transport of their public key to the world. + +165 +00:08:41,000 --> 00:08:47,000 +Now if you remember how asymmetric works in the world of asymmetric cryptography your public key is + +166 +00:08:47,000 --> 00:08:47,000 +given to the world. + +167 +00:08:47,000 --> 00:08:52,000 +The question is how is Amazon distributing the public key to the rest of the world? + +168 +00:08:52,000 --> 00:08:54,000 +Well, that's done using a certificate. + +169 +00:08:54,000 --> 00:08:58,000 +So certificates are ways to pass the public key around. + +170 +00:08:58,000 --> 00:09:00,000 +And that brings me to the SSL handshake. + +171 +00:09:00,000 --> 00:09:06,000 +So exactly when I go to Amazon, what exactly happens in the background. + +172 +00:09:06,000 --> 00:09:09,000 +How am I getting this secure trust between them? + +173 +00:09:09,000 --> 00:09:15,000 +How am I security transferring data and that brings me to the SSL handshake that I have right here. + +174 +00:09:15,000 --> 00:09:18,000 +And again I took this from the IBM website. + +175 +00:09:19,000 --> 00:09:20,000 +Uh. + +176 +00:09:20,000 --> 00:09:25,000 +And the link is provided at the top of me. + +177 +00:09:25,000 --> 00:09:25,000 +All right. + +178 +00:09:25,000 --> 00:09:26,000 +Somewhere around there. + +179 +00:09:27,000 --> 00:09:28,000 +Uh, so let's get into it. + +180 +00:09:28,000 --> 00:09:32,000 +So now the steps are going to be listed on the left side of the screen. + +181 +00:09:32,000 --> 00:09:34,000 +And I want to go over the diagram. + +182 +00:09:34,000 --> 00:09:40,000 +So let's say in this diagram the client is you will put Andy. + +183 +00:09:42,000 --> 00:09:43,000 +And the server is Amazon. + +184 +00:09:46,000 --> 00:09:50,000 +Now I go to Amazon.com and I press enter. + +185 +00:09:50,000 --> 00:09:50,000 +I type. + +186 +00:09:51,000 --> 00:09:51,000 +Well, I don't go. + +187 +00:09:51,000 --> 00:09:54,000 +I type Amazon.com and I press enter. + +188 +00:09:54,000 --> 00:09:55,000 +What happens? + +189 +00:09:55,000 --> 00:09:58,000 +The client issues a secure request session. + +190 +00:09:58,000 --> 00:10:03,000 +So it's me going to Amazon and says, Hey Amazon, I need to set up a secure session with you. + +191 +00:10:03,000 --> 00:10:09,000 +Amazon sends back an X509 certificate. + +192 +00:10:09,000 --> 00:10:11,000 +That's the type of certificate that they're using. + +193 +00:10:11,000 --> 00:10:11,000 +Now. + +194 +00:10:11,000 --> 00:10:14,000 +In reality, almost all certificates are x509. + +195 +00:10:14,000 --> 00:10:16,000 +They send back. + +196 +00:10:16,000 --> 00:10:21,000 +The certificate that I showed you containing their public key. + +197 +00:10:21,000 --> 00:10:24,000 +Now that we spoke about that, I showed you you. + +198 +00:10:24,000 --> 00:10:31,000 +When you receive it, you're going to authenticate that certificate against a list of known certificate + +199 +00:10:31,000 --> 00:10:32,000 +authorities. + +200 +00:10:32,000 --> 00:10:33,000 +This is important. + +201 +00:10:33,000 --> 00:10:35,000 +This is the part of the trust. + +202 +00:10:35,000 --> 00:10:39,000 +So when you receive Amazon Cert, you're like, well, who gave him this cert? + +203 +00:10:39,000 --> 00:10:39,000 +Okay. + +204 +00:10:39,000 --> 00:10:41,000 +It was given by Digicert. + +205 +00:10:41,000 --> 00:10:45,000 +Do you trust Digicert yes I do again your computer does all this. + +206 +00:10:45,000 --> 00:10:49,000 +Your computer trusts Digicert now. + +207 +00:10:49,000 --> 00:10:50,000 +What happened? + +208 +00:10:50,000 --> 00:10:57,000 +You, the client on your computer, generate a symmetric key. + +209 +00:10:58,000 --> 00:11:05,000 +Once you generate the symmetric key, you then encrypt it with the server's public key and you send + +210 +00:11:05,000 --> 00:11:06,000 +it back. + +211 +00:11:06,000 --> 00:11:08,000 +Notice the arrow to Amazon. + +212 +00:11:08,000 --> 00:11:09,000 +So here's what you're doing. + +213 +00:11:09,000 --> 00:11:18,000 +You're going to generate, for example, an AES 120 beta 128 bit or 256 bit AES key. + +214 +00:11:18,000 --> 00:11:21,000 +You're then going to send it to Amazon.com. + +215 +00:11:21,000 --> 00:11:23,000 +Amazon. + +216 +00:11:23,000 --> 00:11:27,000 +Remember it was encrypted with their what public key. + +217 +00:11:27,000 --> 00:11:28,000 +So what does Amazon do. + +218 +00:11:29,000 --> 00:11:32,000 +Amazon once they receive. + +219 +00:11:33,000 --> 00:11:36,000 +Uh, your symmetric key encrypted with their public key. + +220 +00:11:36,000 --> 00:11:38,000 +They decrypt it with their corresponding. + +221 +00:11:38,000 --> 00:11:39,000 +What? + +222 +00:11:39,000 --> 00:11:39,000 +Private key. + +223 +00:11:39,000 --> 00:11:44,000 +Remember, if you encrypt something with Amazon's public key, only Amazon's private key can decrypt + +224 +00:11:44,000 --> 00:11:44,000 +it. + +225 +00:11:45,000 --> 00:11:52,000 +Now Amazon has that public has that symmetric key or that session key that you make. + +226 +00:11:52,000 --> 00:11:55,000 +Now the client and the server knows both. + +227 +00:11:55,000 --> 00:12:02,000 +Now the client and server now both know that symmetric key and the what happens to the rest of it. + +228 +00:12:02,000 --> 00:12:10,000 +Well you Amazon and you and Amazon will now use that symmetric key to encrypt data. + +229 +00:12:10,000 --> 00:12:11,000 +So what happens is this. + +230 +00:12:12,000 --> 00:12:16,000 +You generate a symmetric key, you encrypt it with Amazon's public key. + +231 +00:12:16,000 --> 00:12:19,000 +Remember I showed you the actual public key there. + +232 +00:12:20,000 --> 00:12:22,000 +You encrypt it with that public key. + +233 +00:12:22,000 --> 00:12:23,000 +You send it to Amazon. + +234 +00:12:23,000 --> 00:12:25,000 +Amazon then decrypts it with their private key. + +235 +00:12:26,000 --> 00:12:27,000 +Now they have the symmetric key. + +236 +00:12:27,000 --> 00:12:28,000 +You have the symmetric key. + +237 +00:12:28,000 --> 00:12:36,000 +Anything that you send to Amazon username passwords credit cards address products you want to buy, + +238 +00:12:36,000 --> 00:12:39,000 +search queries, anything that you want to send to Amazon. + +239 +00:12:39,000 --> 00:12:41,000 +You encrypt it with that symmetric key. + +240 +00:12:41,000 --> 00:12:41,000 +Send it to Amazon. + +241 +00:12:41,000 --> 00:12:43,000 +Amazon already has the symmetric key. + +242 +00:12:44,000 --> 00:12:46,000 +Amazon wants to send you back web pages. + +243 +00:12:46,000 --> 00:12:51,000 +They want to send you back product listing confirmations and whatever they encrypt it with that symmetric + +244 +00:12:51,000 --> 00:12:51,000 +key. + +245 +00:12:51,000 --> 00:12:56,000 +Remember symmetric the same key used to encrypt is the same key used to decrypt. + +246 +00:12:56,000 --> 00:13:04,000 +So all of this is happening in the background when you go and when when you go to Amazon and you purchase + +247 +00:13:04,000 --> 00:13:04,000 +anything. + +248 +00:13:05,000 --> 00:13:05,000 +All right. + +249 +00:13:05,000 --> 00:13:08,000 +So that's something that you guys want to keep in mind as you use this. + +250 +00:13:08,000 --> 00:13:15,000 +So if I go back here, if I go back to Amazon, all of what I just mentioned. + +251 +00:13:16,000 --> 00:13:17,000 +Happens. + +252 +00:13:17,000 --> 00:13:21,000 +So what if you go to another website? + +253 +00:13:21,000 --> 00:13:21,000 +All right. + +254 +00:13:21,000 --> 00:13:24,000 +What if you go to another, uh. + +255 +00:13:26,000 --> 00:13:26,000 +Website? + +256 +00:13:26,000 --> 00:13:27,000 +Google.com. + +257 +00:13:27,000 --> 00:13:28,000 +Let's go to google.com. + +258 +00:13:29,000 --> 00:13:31,000 +Google.com. + +259 +00:13:31,000 --> 00:13:33,000 +Everything I just happened just happened. + +260 +00:13:33,000 --> 00:13:35,000 +Everything I just went through just happened. + +261 +00:13:35,000 --> 00:13:36,000 +So let's do a quick review. + +262 +00:13:36,000 --> 00:13:37,000 +What happened? + +263 +00:13:37,000 --> 00:13:40,000 +When I went to Google, I sent the request to Google. + +264 +00:13:41,000 --> 00:13:43,000 +Google sent me back their certificate. + +265 +00:13:43,000 --> 00:13:44,000 +Where is it? + +266 +00:13:44,000 --> 00:13:49,000 +Well, if I click on the lock icon and I go to connection to secure and I say certificate, this is + +267 +00:13:49,000 --> 00:13:50,000 +Google certificate. + +268 +00:13:50,000 --> 00:13:55,000 +By acquiring Google certificate, I acquire Google's public key. + +269 +00:13:56,000 --> 00:13:58,000 +This is the fingerprint if I go here. + +270 +00:13:59,000 --> 00:14:00,000 +Whereas Google here we go. + +271 +00:14:00,000 --> 00:14:01,000 +Google's public key. + +272 +00:14:01,000 --> 00:14:03,000 +So I acquired a public key. + +273 +00:14:03,000 --> 00:14:05,000 +What do I do with the public key? + +274 +00:14:05,000 --> 00:14:08,000 +I generate a symmetric key on my computer. + +275 +00:14:09,000 --> 00:14:15,000 +I then encrypt that symmetric key with Google's public key send it to Google. + +276 +00:14:15,000 --> 00:14:17,000 +Google then decrypts it with their private key. + +277 +00:14:17,000 --> 00:14:19,000 +Now they have the symmetric key. + +278 +00:14:19,000 --> 00:14:20,000 +I have the symmetric key. + +279 +00:14:20,000 --> 00:14:26,000 +What Google does is Google then encrypts the web page that I just saw on my screen and sends it to my + +280 +00:14:26,000 --> 00:14:26,000 +machine. + +281 +00:14:26,000 --> 00:14:31,000 +When my machine gets it, it decrypts it with symmetric key, all the search queries and all the pages + +282 +00:14:31,000 --> 00:14:36,000 +that goes back and forth between me and Google is now encrypted with that symmetric key. + +283 +00:14:36,000 --> 00:14:41,000 +What I just explained to you is the easiest way to understand SSL. + +284 +00:14:41,000 --> 00:14:44,000 +This is the simplest explanation of it. + +285 +00:14:44,000 --> 00:14:49,000 +Now it does get technical verification of signatures and all that, but you don't need to know that + +286 +00:14:49,000 --> 00:14:50,000 +for your exam. + +287 +00:14:50,000 --> 00:14:51,000 +Understand the SSL handshake. + +288 +00:14:51,000 --> 00:14:55,000 +And now you see why it's so important to have certificates. + +289 +00:14:55,000 --> 00:15:00,000 +Because without those certificates, the whole connection wouldn't be able to start. + +290 +00:15:00,000 --> 00:15:01,000 +There'd be no way of passing that public key. + +291 +00:15:01,000 --> 00:15:06,000 +There'll be no way to verify that that's Google's public key or Amazon's public key. + +292 +00:15:06,000 --> 00:15:08,000 +But how do we get a certificate? + +293 +00:15:08,000 --> 00:15:09,000 +How do we set this thing up? + +294 +00:15:10,000 --> 00:15:12,000 +Well that we'll cover next. + diff --git a/07 - Cryptography/017 PKI Process OB 1.4_en.srt b/07 - Cryptography/017 PKI Process OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ce75a9858f0905d8196e4a8d062a27ccbdc3de26 --- /dev/null +++ b/07 - Cryptography/017 PKI Process OB 1.4_en.srt @@ -0,0 +1,664 @@ +1 +00:00:00,000 --> 00:00:00,000 +Okay. + +2 +00:00:00,000 --> 00:00:05,000 +You have just been assigned the job of installing a certificate on a computer. + +3 +00:00:05,000 --> 00:00:09,000 +Your new your the new system administrator for a company. + +4 +00:00:09,000 --> 00:00:13,000 +And they said, well, we have a web server that we want to put a certificate on. + +5 +00:00:13,000 --> 00:00:16,000 +What is the process and exactly how is this done? + +6 +00:00:16,000 --> 00:00:21,000 +So in this video I'm going to walk you guys through the process of how you can get a certificate, a + +7 +00:00:21,000 --> 00:00:24,000 +trusted certificate on a computer. + +8 +00:00:24,000 --> 00:00:26,000 +Let's get started in this one. + +9 +00:00:26,000 --> 00:00:32,000 +Now, in order to do this, there are basically four components that I need you to know for your exam. + +10 +00:00:32,000 --> 00:00:37,000 +When it comes to getting a certificate, the first thing is that digital certificate. + +11 +00:00:37,000 --> 00:00:40,000 +This is what you want to install on your computer. + +12 +00:00:40,000 --> 00:00:42,000 +If you remember I went over the SSL handshake. + +13 +00:00:43,000 --> 00:00:48,000 +And the SSL handshake begins with the passing of that digital certificate. + +14 +00:00:48,000 --> 00:00:51,000 +So this is a digital document that provides the public key. + +15 +00:00:51,000 --> 00:00:55,000 +It also has a digital signature that provides the trust to the organization. + +16 +00:00:55,000 --> 00:00:58,000 +Where are we going to get the certificates from? + +17 +00:00:58,000 --> 00:01:01,000 +You're going to get that from a certificate authority. + +18 +00:01:01,000 --> 00:01:07,000 +This is a trusted entity that manages certificates and digitally signs the certificate. + +19 +00:01:07,000 --> 00:01:08,000 +This is the entity. + +20 +00:01:08,000 --> 00:01:15,000 +This is the DMV, I should say that verifies you are who you say you are. + +21 +00:01:15,000 --> 00:01:23,000 +Now, before the CA can give you a certificate, the CA needs to verify that you're you, that you're + +22 +00:01:23,000 --> 00:01:25,000 +actually that company. + +23 +00:01:25,000 --> 00:01:28,000 +You're not trying to steal someone's identity, that you are Bob Jones. + +24 +00:01:28,000 --> 00:01:30,000 +That's the registration authority. + +25 +00:01:30,000 --> 00:01:31,000 +That's their job. + +26 +00:01:31,000 --> 00:01:38,000 +They're going to verify that the person is who they say they are for the CA before the CA can issue + +27 +00:01:38,000 --> 00:01:38,000 +them a cert. + +28 +00:01:38,000 --> 00:01:45,000 +And when you start to give out your certificate on the internet, you're going to have to get it validated. + +29 +00:01:45,000 --> 00:01:48,000 +People that receive it is going to validate, hey, this certificate is still good. + +30 +00:01:48,000 --> 00:01:51,000 +It's kind of like me giving you my driver's license. + +31 +00:01:51,000 --> 00:01:54,000 +And you're like, well, I don't know. + +32 +00:01:54,000 --> 00:01:57,000 +It's this driver's license actually came from the DMV that's still valid. + +33 +00:01:57,000 --> 00:02:02,000 +So you call up a number to check if the license is valid. + +34 +00:02:02,000 --> 00:02:04,000 +That's the validation authority. + +35 +00:02:04,000 --> 00:02:07,000 +Now, I went to Wikipedia and I took their diagram. + +36 +00:02:07,000 --> 00:02:10,000 +I should say I borrowed it the diagram. + +37 +00:02:10,000 --> 00:02:12,000 +But I do have the link right here to it. + +38 +00:02:12,000 --> 00:02:17,000 +So here is the uh all of the information that we need. + +39 +00:02:17,000 --> 00:02:21,000 +Now I'm going to go through it, uh, at a high level right now. + +40 +00:02:21,000 --> 00:02:25,000 +And then we'll take a look at the slides in order to, to go more details into it. + +41 +00:02:25,000 --> 00:02:29,000 +So this is you right here. + +42 +00:02:29,000 --> 00:02:29,000 +This is you. + +43 +00:02:29,000 --> 00:02:35,000 +So the way you start this process is you what what you're going to do. + +44 +00:02:35,000 --> 00:02:36,000 +Let's put you on this. + +45 +00:02:37,000 --> 00:02:42,000 +What you're going to do is you're going to generate the public private key on your machine. + +46 +00:02:42,000 --> 00:02:49,000 +So you have a web server and you're going to create what's called a certificate request certificate, + +47 +00:02:49,000 --> 00:02:52,000 +sign in requests or CSR on your machine. + +48 +00:02:52,000 --> 00:02:56,000 +What this does is that this is going to generate a public and a private key. + +49 +00:02:57,000 --> 00:02:58,000 +On your computer. + +50 +00:02:58,000 --> 00:03:02,000 +The certificate authority does not generate the public private keys. + +51 +00:03:02,000 --> 00:03:04,000 +It signs your public private key. + +52 +00:03:04,000 --> 00:03:08,000 +You generate that public private key pair on your machine. + +53 +00:03:08,000 --> 00:03:09,000 +So you generate. + +54 +00:03:09,000 --> 00:03:12,000 +This is going to be your private key. + +55 +00:03:13,000 --> 00:03:15,000 +And you generate your public key. + +56 +00:03:15,000 --> 00:03:21,000 +What you do now is you then take this and you submit it to a registration authority. + +57 +00:03:21,000 --> 00:03:29,000 +Now, the registration authority is the entity that verifies that you are who you say you are. + +58 +00:03:29,000 --> 00:03:36,000 +For example, let's say you are a hacker and you want to reproduce Amazon.com. + +59 +00:03:36,000 --> 00:03:41,000 +Well, you just can't go and get a certificate with the name Amazon.com because you're going to have + +60 +00:03:41,000 --> 00:03:43,000 +to prove that you are Amazon. + +61 +00:03:43,000 --> 00:03:50,000 +If you are organization A or B or C, and you want to get a certificate for that organization, you're + +62 +00:03:50,000 --> 00:03:54,000 +going to have to verify that you are that company and depend how it's done. + +63 +00:03:54,000 --> 00:03:58,000 +It may just be checking the domain actually belongs to you, or it may be that they're going to check + +64 +00:03:58,000 --> 00:04:00,000 +that the company actually exists. + +65 +00:04:00,000 --> 00:04:03,000 +That's the registration authority. + +66 +00:04:03,000 --> 00:04:06,000 +So the registration authority stamps that OKC okay. + +67 +00:04:06,000 --> 00:04:08,000 +This is Bob. + +68 +00:04:08,000 --> 00:04:10,000 +This is company A this is what. + +69 +00:04:10,000 --> 00:04:12,000 +And you can trust them. + +70 +00:04:12,000 --> 00:04:16,000 +The registration authority then sends your public key. + +71 +00:04:16,000 --> 00:04:17,000 +To the CA. + +72 +00:04:17,000 --> 00:04:26,000 +The CA then takes all of your company information, all this great stuff that was given to them, including + +73 +00:04:26,000 --> 00:04:32,000 +your public key and what the CA does is it then sends you back a certificate. + +74 +00:04:32,000 --> 00:04:39,000 +Now on the certificate it contains your public key, but it also contains a digital signature from the + +75 +00:04:39,000 --> 00:04:39,000 +CA. + +76 +00:04:40,000 --> 00:04:45,000 +Now if you remember what a digital signature is, a digital signature verifies that something actually + +77 +00:04:45,000 --> 00:04:48,000 +came from that entity and it was never modified. + +78 +00:04:48,000 --> 00:04:58,000 +So when you receive this certificate and you install it on your web server, this certificate was never + +79 +00:04:58,000 --> 00:05:00,000 +actually issued by you, was it? + +80 +00:05:00,000 --> 00:05:01,000 +It came from who? + +81 +00:05:01,000 --> 00:05:02,000 +The certificate authority. + +82 +00:05:02,000 --> 00:05:06,000 +The only thing it has that you really gave it was basically a public key. + +83 +00:05:06,000 --> 00:05:08,000 +But the certificate has more information. + +84 +00:05:08,000 --> 00:05:12,000 +I have a video coming up later on all the other data that the certificate contains. + +85 +00:05:12,000 --> 00:05:18,000 +So what you do is you install that certificate on your machine. + +86 +00:05:18,000 --> 00:05:20,000 +Now you're done with these entities. + +87 +00:05:20,000 --> 00:05:27,000 +Now somebody comes to Shop.com or whatever your website is, and the first thing you're going to do, + +88 +00:05:27,000 --> 00:05:32,000 +if you remember the SSL handshake is you're going to do what you're going to send them that certificate + +89 +00:05:32,000 --> 00:05:35,000 +so you can start the SSL connection. + +90 +00:05:35,000 --> 00:05:36,000 +You send them the certificate. + +91 +00:05:36,000 --> 00:05:38,000 +Well, how do they know the certificate is still valid? + +92 +00:05:38,000 --> 00:05:42,000 +How do they know your website hasn't been hacked or something went wrong? + +93 +00:05:42,000 --> 00:05:47,000 +You didn't renew the certificate, you became malicious and your company is stealing data now. + +94 +00:05:48,000 --> 00:05:52,000 +Well, what they do is they send their certificate to a validation authority. + +95 +00:05:52,000 --> 00:05:57,000 +Now notice the CA also sent information to the validation authority. + +96 +00:05:57,000 --> 00:05:59,000 +To day I issue this cert. + +97 +00:05:59,000 --> 00:06:05,000 +And if anybody ever wants to check if it's good just let them know it's okay because we did issue that. + +98 +00:06:06,000 --> 00:06:12,000 +The validation authority when they when the user gets it, checks it and says okay it's good. + +99 +00:06:12,000 --> 00:06:14,000 +Tells back to use a yeah, this is good. + +100 +00:06:14,000 --> 00:06:14,000 +You can use it. + +101 +00:06:14,000 --> 00:06:17,000 +And this starts the entire SSL connection. + +102 +00:06:18,000 --> 00:06:24,000 +So this is the PKI process in a nutshell with a CA, an RA and a VA. + +103 +00:06:24,000 --> 00:06:33,000 +Now I just want to point out something that even though in this particular diagram it looks like it's + +104 +00:06:33,000 --> 00:06:34,000 +different entities. + +105 +00:06:34,000 --> 00:06:37,000 +RA it's all the same entity. + +106 +00:06:37,000 --> 00:06:39,000 +Generally this like Digicert. + +107 +00:06:40,000 --> 00:06:44,000 +Uh, GoDaddy or whoever you're using as your public key. + +108 +00:06:44,000 --> 00:06:45,000 +It's always the same entity. + +109 +00:06:45,000 --> 00:06:48,000 +It's not going to be like it's three different businesses. + +110 +00:06:48,000 --> 00:06:56,000 +But in organizations that utilizes internal certs, they can have different machines to do this particular + +111 +00:06:56,000 --> 00:06:57,000 +job. + +112 +00:06:57,000 --> 00:07:00,000 +Now let's take a look at some things here. + +113 +00:07:00,000 --> 00:07:04,000 +Now everything I covered is in detail on these two sections. + +114 +00:07:04,000 --> 00:07:06,000 +So I'm going to go over them quickly since we covered it already. + +115 +00:07:06,000 --> 00:07:09,000 +So the certificate signing request. + +116 +00:07:09,000 --> 00:07:13,000 +So this is the part of it where we had to. + +117 +00:07:14,000 --> 00:07:15,000 +Obtain. + +118 +00:07:15,000 --> 00:07:19,000 +This is the request we're going to send to the CA to get that digital certificate. + +119 +00:07:19,000 --> 00:07:19,000 +All right. + +120 +00:07:19,000 --> 00:07:24,000 +So the first thing we're going to be doing is in order to do this, we're going to have to include things + +121 +00:07:24,000 --> 00:07:29,000 +like our organization name, our domain name, what country we're in, and of course our public key. + +122 +00:07:29,000 --> 00:07:31,000 +So this is what we're sending. + +123 +00:07:31,000 --> 00:07:35,000 +Now the first thing you want to do is you want to start this process. + +124 +00:07:35,000 --> 00:07:41,000 +When you want to get a certificate is you have to go to your machine and you have to create a key pair, + +125 +00:07:41,000 --> 00:07:43,000 +that public private key pair. + +126 +00:07:43,000 --> 00:07:44,000 +Remember the private key is kept secret. + +127 +00:07:44,000 --> 00:07:46,000 +The public key is given to anyone. + +128 +00:07:46,000 --> 00:07:48,000 +You want to fill in the details. + +129 +00:07:48,000 --> 00:07:49,000 +All right. + +130 +00:07:49,000 --> 00:07:52,000 +The certificate is going to have a is going to need a lot of information. + +131 +00:07:52,000 --> 00:07:55,000 +All this information the name of your company where it's located state. + +132 +00:07:55,000 --> 00:07:58,000 +And I'm going to show you certificate details in the next video. + +133 +00:07:58,000 --> 00:08:01,000 +And you're going to see a certificate has all this information. + +134 +00:08:02,000 --> 00:08:08,000 +So you create this, uh, you create it using a software. + +135 +00:08:08,000 --> 00:08:14,000 +And this is going to be submitted in a format that the CAS can understand that format. + +136 +00:08:14,000 --> 00:08:18,000 +But I get into technical is called PK, CS number ten. + +137 +00:08:18,000 --> 00:08:21,000 +This is the format that it's submitted into. + +138 +00:08:21,000 --> 00:08:27,000 +This is just a file format, if you think about it like an Excel file as dot xls x. + +139 +00:08:27,000 --> 00:08:28,000 +That's the file format. + +140 +00:08:28,000 --> 00:08:29,000 +This is just the file format. + +141 +00:08:29,000 --> 00:08:30,000 +What does it contain? + +142 +00:08:30,000 --> 00:08:33,000 +Well, the public key and all the corresponding information. + +143 +00:08:34,000 --> 00:08:38,000 +Now you submit the CSR to the RA to the CA. + +144 +00:08:38,000 --> 00:08:39,000 +What happens here? + +145 +00:08:40,000 --> 00:08:43,000 +Uh, they will validate your identity. + +146 +00:08:43,000 --> 00:08:44,000 +They'll validate that you're good. + +147 +00:08:45,000 --> 00:08:50,000 +And once they can validate all that information, we'll talk more about validations coming up a little + +148 +00:08:50,000 --> 00:08:51,000 +bit later. + +149 +00:08:51,000 --> 00:08:53,000 +But they're going to validate that you're good. + +150 +00:08:53,000 --> 00:08:58,000 +Sometimes they may validate your just your domain name or sometimes they'll do an extended validation. + +151 +00:08:58,000 --> 00:09:03,000 +We're going to do more than a domain name that you actually own that domain, but you actually own that + +152 +00:09:03,000 --> 00:09:04,000 +business. + +153 +00:09:04,000 --> 00:09:06,000 +Then the certificate is issued to you. + +154 +00:09:06,000 --> 00:09:12,000 +You install it on your web server, and you're ready to rock and roll with the SSL connection. + +155 +00:09:12,000 --> 00:09:12,000 +Okay. + +156 +00:09:12,000 --> 00:09:16,000 +So that's the process of how to get a certificate. + +157 +00:09:17,000 --> 00:09:24,000 +Now I want you guys to keep in mind that this is a very easy and simple process. + +158 +00:09:24,000 --> 00:09:28,000 +It's if you've ever installed a certificate on a web server, it's a very simple thing. + +159 +00:09:28,000 --> 00:09:33,000 +You go to the web server, you do a few clicks that give you doing an IIs server, and you create that + +160 +00:09:33,000 --> 00:09:34,000 +certificate request. + +161 +00:09:34,000 --> 00:09:38,000 +You go to your CA, you basically install it there and they give you a certificate. + +162 +00:09:38,000 --> 00:09:39,000 +You put it back on your web server. + +163 +00:09:39,000 --> 00:09:44,000 +There's something that's done actually doesn't take very long, a few minutes if you know the skills + +164 +00:09:44,000 --> 00:09:44,000 +to do it. + +165 +00:09:44,000 --> 00:09:46,000 +So it's not complex to do. + +166 +00:09:46,000 --> 00:09:50,000 +But for your exam you want to be able to understand the process, which is what we just went over. + diff --git a/07 - Cryptography/018 Certificates OB 1.4_en.srt b/07 - Cryptography/018 Certificates OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9af7bc663cbd56132e8324ecc49ad034cabce32d --- /dev/null +++ b/07 - Cryptography/018 Certificates OB 1.4_en.srt @@ -0,0 +1,824 @@ +1 +00:00:00,000 --> 00:00:02,000 +In this video we're going to be talking about certificates. + +2 +00:00:02,000 --> 00:00:05,000 +What exactly is on a certificate? + +3 +00:00:05,000 --> 00:00:07,000 +Now, I already went over that. + +4 +00:00:07,000 --> 00:00:11,000 +It has the signature from the, uh, certificate authority. + +5 +00:00:12,000 --> 00:00:13,000 +It also has your public key. + +6 +00:00:13,000 --> 00:00:14,000 +But what else does it contain? + +7 +00:00:14,000 --> 00:00:16,000 +Let's get into that. + +8 +00:00:16,000 --> 00:00:17,000 +I want to talk about the format. + +9 +00:00:17,000 --> 00:00:20,000 +Self-signed certificates versus third party certificates. + +10 +00:00:20,000 --> 00:00:21,000 +Let's knock it out. + +11 +00:00:21,000 --> 00:00:26,000 +The first thing I want to do is I want to show you guys when you have a certificate. + +12 +00:00:27,000 --> 00:00:29,000 +Now, a certificate has a variety of different fields. + +13 +00:00:29,000 --> 00:00:31,000 +It's not just the couple things. + +14 +00:00:31,000 --> 00:00:35,000 +In fact, it has a couple different things on it, from a version number to the subject's name, the + +15 +00:00:35,000 --> 00:00:38,000 +company's name, your public key. + +16 +00:00:38,000 --> 00:00:43,000 +Who gave you the certificate, how long it's valid for, what digital signature algorithm you're using, + +17 +00:00:43,000 --> 00:00:47,000 +and a unique serial number to identify the certificate. + +18 +00:00:47,000 --> 00:00:48,000 +You know the certificate types. + +19 +00:00:48,000 --> 00:00:53,000 +Now, I do want to mention this, that all certificates that are coming out today is going to be the + +20 +00:00:53,000 --> 00:00:55,000 +X509 certificate. + +21 +00:00:55,000 --> 00:00:57,000 +It's going to be a certificate format. + +22 +00:00:57,000 --> 00:01:02,000 +Now the certificate types are going to be either it's going to be self-signed or it's going to be third + +23 +00:01:02,000 --> 00:01:04,000 +party issue, which we'll take a look at in a few minutes. + +24 +00:01:04,000 --> 00:01:14,000 +So I want to show you all of these fields on an actual certificate so you can better understand what + +25 +00:01:14,000 --> 00:01:14,000 +I'm talking about. + +26 +00:01:14,000 --> 00:01:16,000 +So let's go to Amazon.com. + +27 +00:01:16,000 --> 00:01:17,000 +Here we are back again. + +28 +00:01:18,000 --> 00:01:19,000 +Connection is secure. + +29 +00:01:19,000 --> 00:01:22,000 +Let's take a look at some of the things I mentioned. + +30 +00:01:22,000 --> 00:01:23,000 +So we're going to go to detail. + +31 +00:01:23,000 --> 00:01:25,000 +So we have all the data. + +32 +00:01:25,000 --> 00:01:29,000 +So right now I'm just going to expand some of these boxes so you can see them. + +33 +00:01:30,000 --> 00:01:32,000 +Uh first of all what version is it. + +34 +00:01:32,000 --> 00:01:34,000 +Well this is version three certificate. + +35 +00:01:34,000 --> 00:01:35,000 +Here is a serial number. + +36 +00:01:35,000 --> 00:01:38,000 +Now this is a unique number that is unique to this certificate. + +37 +00:01:38,000 --> 00:01:40,000 +No certificate should have this. + +38 +00:01:40,000 --> 00:01:42,000 +The signature algorithm. + +39 +00:01:43,000 --> 00:01:49,000 +Now, I mentioned that a digital signature using the DSS standards is generally some kind of asymmetric + +40 +00:01:49,000 --> 00:01:51,000 +algorithm and a hashing algorithm. + +41 +00:01:51,000 --> 00:01:56,000 +In this one, we're going to be using Sha 256 with RSA. + +42 +00:01:56,000 --> 00:01:58,000 +Pretty pretty standard. + +43 +00:01:58,000 --> 00:02:00,000 +Who gave us the certificate. + +44 +00:02:00,000 --> 00:02:04,000 +Now Digicert is one of the biggest provider of certificate. + +45 +00:02:04,000 --> 00:02:08,000 +Digicert took over from Symantec's who took over VeriSign. + +46 +00:02:08,000 --> 00:02:11,000 +VeriSign being one of the most popular names out there. + +47 +00:02:11,000 --> 00:02:16,000 +But Digicert is now them, and there's a lot of big names in this space. + +48 +00:02:16,000 --> 00:02:17,000 +Uh, such as? + +49 +00:02:18,000 --> 00:02:23,000 +I know GoDaddy gives out a lot of certificates, you can get Google search and so on. + +50 +00:02:23,000 --> 00:02:24,000 +How long is it valid? + +51 +00:02:24,000 --> 00:02:24,000 +What? + +52 +00:02:24,000 --> 00:02:26,000 +A certificate is not valid forever. + +53 +00:02:26,000 --> 00:02:31,000 +In fact, you have to renew certificates generally every 1 to 3 years. + +54 +00:02:31,000 --> 00:02:41,000 +You notice, uh, this particular certificate is valid basically from 1127 23 to 11 1124. + +55 +00:02:41,000 --> 00:02:46,000 +So this is about a one year, a little less than a one year certificate. + +56 +00:02:46,000 --> 00:02:54,000 +The subject, well, the chronological or the key name, this certificate is only for WW dot amazon.com. + +57 +00:02:54,000 --> 00:02:58,000 +So this is certificate can only be used at WW dot. + +58 +00:02:58,000 --> 00:03:01,000 +So this is going to be a certificate only for this website. + +59 +00:03:01,000 --> 00:03:03,000 +But who exactly. + +60 +00:03:04,000 --> 00:03:05,000 +I'm. + +61 +00:03:05,000 --> 00:03:06,000 +So where is the public key on this. + +62 +00:03:06,000 --> 00:03:08,000 +So the subject's public key. + +63 +00:03:08,000 --> 00:03:09,000 +So we have. + +64 +00:03:10,000 --> 00:03:12,000 +The the public key algorithm. + +65 +00:03:12,000 --> 00:03:13,000 +It's an RSA key. + +66 +00:03:13,000 --> 00:03:15,000 +Here is the public key. + +67 +00:03:15,000 --> 00:03:19,000 +Now in here there are some additional things I don't. + +68 +00:03:19,000 --> 00:03:23,000 +You don't need to go into all of these things such as certificate policies and all that. + +69 +00:03:23,000 --> 00:03:29,000 +But what I do need you guys to know is there is something we call a CRL distribution point, certificate + +70 +00:03:29,000 --> 00:03:35,000 +revocation list distribution point, which you can find on the certificate itself to check if the certificate + +71 +00:03:35,000 --> 00:03:37,000 +has been revoked. + +72 +00:03:37,000 --> 00:03:40,000 +That is something we're going to cover a little bit later. + +73 +00:03:41,000 --> 00:03:45,000 +If I just take a look at the general part of the certificate, you can see it's just giving me some + +74 +00:03:45,000 --> 00:03:50,000 +of the basic information that I had their start on expires on. + +75 +00:03:50,000 --> 00:03:57,000 +So this is going to be some of the main fields that you should understand about a certificate. + +76 +00:03:58,000 --> 00:04:02,000 +Now when you get a certificate let's go back to slides here. + +77 +00:04:02,000 --> 00:04:03,000 +Oops. + +78 +00:04:04,000 --> 00:04:05,000 +Uh, there's a couple of things here. + +79 +00:04:06,000 --> 00:04:12,000 +When you get a certificate, there's what's called an entity certificate, what's called a domain validation + +80 +00:04:12,000 --> 00:04:14,000 +certificate and extended validation. + +81 +00:04:14,000 --> 00:04:20,000 +When you go out and you purchase a certificate from somebody like Digicert, a domain validation just + +82 +00:04:20,000 --> 00:04:26,000 +checks if you actually own the domain Amazon.com, but it doesn't verify if that business is associated + +83 +00:04:26,000 --> 00:04:27,000 +with that domain. + +84 +00:04:27,000 --> 00:04:30,000 +That's going to be called an extended validation. + +85 +00:04:30,000 --> 00:04:36,000 +Sometimes if you go to a website and the the bar at the top turns green, that's an extended validation + +86 +00:04:36,000 --> 00:04:37,000 +certificate. + +87 +00:04:37,000 --> 00:04:41,000 +Another type of certificate you can get is what's called a wild card certificate. + +88 +00:04:41,000 --> 00:04:44,000 +So wild card certificates if you notice it has a wild card. + +89 +00:04:44,000 --> 00:04:49,000 +If you remember the one on Amazon was just WW dot amazon.com. + +90 +00:04:50,000 --> 00:04:53,000 +That can't be used for anything but that w w dot. + +91 +00:04:53,000 --> 00:04:59,000 +If you go and you get a wildcard certificate with a wildcard, you notice how I have this wildcard at + +92 +00:04:59,000 --> 00:05:00,000 +Tidcombe. + +93 +00:05:00,000 --> 00:05:05,000 +So we could use it for t w w dot t edu comm. + +94 +00:05:05,000 --> 00:05:07,000 +You can use it for mail at tidcombe. + +95 +00:05:07,000 --> 00:05:13,000 +We can use it maybe for if you had a subdomain called vpn at t com ftp at tidcombe. + +96 +00:05:13,000 --> 00:05:17,000 +So you can use it for multiple subdomains. + +97 +00:05:17,000 --> 00:05:26,000 +Now I do want to talk about when you get a certificate, you can get them either from yourself or you + +98 +00:05:26,000 --> 00:05:29,000 +can get them from a certificate authority like Digicert. + +99 +00:05:30,000 --> 00:05:34,000 +And there are many, like I said, Digicert GoDaddy. + +100 +00:05:34,000 --> 00:05:37,000 +I use a site called cheap SSL. + +101 +00:05:37,000 --> 00:05:40,000 +Uh, so there is a ton of them. + +102 +00:05:40,000 --> 00:05:42,000 +I'm not going to get into all the different names. + +103 +00:05:42,000 --> 00:05:43,000 +It's out of the scope here. + +104 +00:05:43,000 --> 00:05:49,000 +But if you just go to Google and you type, uh, SSL certificates or purchase certificates, you know + +105 +00:05:49,000 --> 00:05:51,000 +what I'll do that when I get here so I can show you some of the names here. + +106 +00:05:51,000 --> 00:05:52,000 +Okay. + +107 +00:05:52,000 --> 00:05:53,000 +But let's go. + +108 +00:05:53,000 --> 00:05:59,000 +Self-signed certificates A self-signed certificate is a certificate that you make internally in your + +109 +00:05:59,000 --> 00:06:01,000 +organization. + +110 +00:06:01,000 --> 00:06:05,000 +The problem with a self-signed certificate is the trust level. + +111 +00:06:05,000 --> 00:06:10,000 +Okay, so this is something that you make internally, and it has no independence of trust. + +112 +00:06:10,000 --> 00:06:12,000 +In other words, only you trust it. + +113 +00:06:12,000 --> 00:06:15,000 +Only your organization trusts it. + +114 +00:06:15,000 --> 00:06:18,000 +Now, you're probably saying yourself, well, is it useful? + +115 +00:06:18,000 --> 00:06:27,000 +Well, it's it's useful as much, externally speaking, as an ID that you make inside. + +116 +00:06:28,000 --> 00:06:28,000 +Okay. + +117 +00:06:28,000 --> 00:06:28,000 +Think about this. + +118 +00:06:28,000 --> 00:06:34,000 +If you are a company and you create badges for all your employees. + +119 +00:06:35,000 --> 00:06:41,000 +Those employees can't use your company badges or IDs to externally validate anything externally. + +120 +00:06:41,000 --> 00:06:44,000 +They can't give it to highway patrol and says, this is me, right? + +121 +00:06:44,000 --> 00:06:48,000 +Nobody's going to know what kind of stupid ID is this? + +122 +00:06:48,000 --> 00:06:49,000 +We don't trust this. + +123 +00:06:49,000 --> 00:06:52,000 +But people in your organization will. + +124 +00:06:52,000 --> 00:07:02,000 +So if you want to set up SSL connection within your organization, that is okay because it's all trusted + +125 +00:07:02,000 --> 00:07:04,000 +internally, but you need that SSL connection. + +126 +00:07:04,000 --> 00:07:07,000 +Then I recommend a self-signed certificate. + +127 +00:07:07,000 --> 00:07:08,000 +The cost is free. + +128 +00:07:08,000 --> 00:07:09,000 +That's what makes it good. + +129 +00:07:09,000 --> 00:07:13,000 +It's actually free versus Digicert can cost a couple GS a year. + +130 +00:07:14,000 --> 00:07:15,000 +A couple of thousand dollars. + +131 +00:07:15,000 --> 00:07:19,000 +So the use case here is going to be for internal networks applications. + +132 +00:07:19,000 --> 00:07:26,000 +If you need to issue certificates for smart cards, people log in internal SSL on web servers, internally + +133 +00:07:26,000 --> 00:07:29,000 +speaking, where it never touches the external world. + +134 +00:07:30,000 --> 00:07:32,000 +This is a good solution. + +135 +00:07:32,000 --> 00:07:35,000 +It's free and you should be doing this. + +136 +00:07:35,000 --> 00:07:36,000 +I. + +137 +00:07:36,000 --> 00:07:41,000 +In fact at TI we have a ton of self-signed certificates on all of our internal servers now. + +138 +00:07:42,000 --> 00:07:48,000 +If what you're doing is going to be external facing and you need that external validation, you need + +139 +00:07:48,000 --> 00:07:56,000 +that DMV, I should say to validate your request, then you can go and get a third party certificate. + +140 +00:07:56,000 --> 00:07:58,000 +And before I get into this, you know what? + +141 +00:07:58,000 --> 00:08:00,000 +Let me just show it to you. + +142 +00:08:01,000 --> 00:08:02,000 +Uh, all the different. + +143 +00:08:04,000 --> 00:08:09,000 +So I'm going to go to Google and I am going to say. + +144 +00:08:11,000 --> 00:08:12,000 +Where is my, uh. + +145 +00:08:12,000 --> 00:08:12,000 +Here we go. + +146 +00:08:12,000 --> 00:08:12,000 +Oh. + +147 +00:08:12,000 --> 00:08:13,000 +Let's stop. + +148 +00:08:13,000 --> 00:08:13,000 +Here we go. + +149 +00:08:13,000 --> 00:08:20,000 +So I'm going to go to Google, and here we go with all kinds of certificates. + +150 +00:08:20,000 --> 00:08:22,000 +All these names here are going to start popping up. + +151 +00:08:23,000 --> 00:08:30,000 +Uh, and notice I have uh, Comodo certificates are popular, GoDaddy certificates are popular. + +152 +00:08:30,000 --> 00:08:32,000 +There's one that says cheap SSL. + +153 +00:08:32,000 --> 00:08:34,000 +I use this one on a private web server. + +154 +00:08:36,000 --> 00:08:38,000 +Uh, you can get them from Digicert. + +155 +00:08:38,000 --> 00:08:43,000 +GoDaddy and Digicert is going to be your big player in the game. + +156 +00:08:43,000 --> 00:08:48,000 +So if you want a certificate, this is going to be where you're going to get the the biggest, uh, + +157 +00:08:48,000 --> 00:08:56,000 +certificates from like the highest name I would say comes from Digicert, but Digicert certificates + +158 +00:08:56,000 --> 00:08:57,000 +are not cheap. + +159 +00:08:58,000 --> 00:09:03,000 +They're pretty expensive and they do have extended validation certificates and so on. + +160 +00:09:03,000 --> 00:09:03,000 +Okay. + +161 +00:09:03,000 --> 00:09:05,000 +So you guys can check that if you want a certificate. + +162 +00:09:05,000 --> 00:09:10,000 +There's tons of certificate external parties that you can get a third party cert from. + +163 +00:09:10,000 --> 00:09:13,000 +But the question is why would you want a third party cert. + +164 +00:09:13,000 --> 00:09:16,000 +And the reason is a third party certificate. + +165 +00:09:16,000 --> 00:09:19,000 +It's all about trust. + +166 +00:09:19,000 --> 00:09:27,000 +You see, the difference between a self-signed certificate and a third party certificate is just here. + +167 +00:09:27,000 --> 00:09:30,000 +It's not the level of encryption strength. + +168 +00:09:30,000 --> 00:09:31,000 +It's just a trust. + +169 +00:09:31,000 --> 00:09:40,000 +For example, let's say I create an ID in my house that has my name, my picture, my wait, no, my + +170 +00:09:40,000 --> 00:09:43,000 +height and my eye color and my address. + +171 +00:09:43,000 --> 00:09:49,000 +It has the exact same information as my driver's license. + +172 +00:09:49,000 --> 00:09:55,000 +Then what is the difference between my ID and internal ID and the driver's license? + +173 +00:09:56,000 --> 00:09:59,000 +Nothing except the trust. + +174 +00:09:59,000 --> 00:10:04,000 +People are more likely to trust the DMV stamp than they are to trust me, saying I'm me. + +175 +00:10:04,000 --> 00:10:05,000 +That is the only difference. + +176 +00:10:05,000 --> 00:10:10,000 +So when you get a third party certificate, you're not going to get any more IT security. + +177 +00:10:10,000 --> 00:10:12,000 +I'm going to get a higher level encryption, for example. + +178 +00:10:12,000 --> 00:10:19,000 +In fact, if you generate an internally, you can select to use bigger RSA keys, or you can select + +179 +00:10:19,000 --> 00:10:23,000 +a type of uh, RSA key or the type of hashing you want to use. + +180 +00:10:23,000 --> 00:10:25,000 +So you can actually even make it more secure. + +181 +00:10:25,000 --> 00:10:32,000 +For example, if I internally, if I put the weight on my ID versus the DMV doesn't have that, then + +182 +00:10:32,000 --> 00:10:39,000 +technically my internal ID has more unique identifying factors than the DMV does, but the DMV comes + +183 +00:10:39,000 --> 00:10:40,000 +with that trust factor. + +184 +00:10:41,000 --> 00:10:41,000 +All right. + +185 +00:10:41,000 --> 00:10:42,000 +This trust factor. + +186 +00:10:42,000 --> 00:10:49,000 +So the CA the external CA like Digicert they're going to give you that certificate. + +187 +00:10:49,000 --> 00:10:54,000 +They're going to sign digitally signed with a digital signature on the certificate to verify that it + +188 +00:10:54,000 --> 00:10:55,000 +came from them. + +189 +00:10:56,000 --> 00:10:57,000 +This is going to be. + +190 +00:10:57,000 --> 00:11:00,000 +The trust is most central to most secure communication. + +191 +00:11:00,000 --> 00:11:02,000 +If you're doing Https, where are you going to use this? + +192 +00:11:02,000 --> 00:11:07,000 +You should be using third party certificates for anything that is public facing websites. + +193 +00:11:07,000 --> 00:11:11,000 +Anything that faces the public that public users come to. + +194 +00:11:11,000 --> 00:11:12,000 +The cost? + +195 +00:11:12,000 --> 00:11:14,000 +It will be a cost and it can vary. + +196 +00:11:14,000 --> 00:11:18,000 +You can get a certificate for a few bucks a year to a few thousand dollars a year, depending on the + +197 +00:11:18,000 --> 00:11:19,000 +entity. + +198 +00:11:19,000 --> 00:11:24,000 +I'm not going to get into the exact why it depends on warranty and how much you trust them, and if + +199 +00:11:24,000 --> 00:11:27,000 +they can get hacked and how secure they are. + +200 +00:11:28,000 --> 00:11:29,000 +I'm not going to get into all that. + +201 +00:11:29,000 --> 00:11:30,000 +It's not needed for your course, but it does. + +202 +00:11:30,000 --> 00:11:32,000 +There is a cost associated with this. + +203 +00:11:33,000 --> 00:11:35,000 +Bottom line goes like this. + +204 +00:11:35,000 --> 00:11:42,000 +If you're going to get a certificate for internal access, and you will never have any kind of external + +205 +00:11:42,000 --> 00:11:49,000 +access into that machine, self-signed certificates may be just fine, but if any external access is + +206 +00:11:49,000 --> 00:11:56,000 +required to that machine, for example, like a public website, make sure to get a third party certificate. + diff --git a/07 - Cryptography/019 PKI Root of Trust OB 1.4_en.srt b/07 - Cryptography/019 PKI Root of Trust OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ae4d95cd11fcd9e90d4b3f34339aec66ee186e3f --- /dev/null +++ b/07 - Cryptography/019 PKI Root of Trust OB 1.4_en.srt @@ -0,0 +1,220 @@ +1 +00:00:00,000 --> 00:00:00,000 +Okay. + +2 +00:00:00,000 --> 00:00:06,000 +When you're building a PKI, especially internally, you're going to want to understand how the structure + +3 +00:00:06,000 --> 00:00:08,000 +of the PKI is laid out. + +4 +00:00:08,000 --> 00:00:14,000 +So in this video, we want to take a look at that particular structure, uh, of a PKI. + +5 +00:00:14,000 --> 00:00:18,000 +Now, this this topic in particular is called the root of trust. + +6 +00:00:18,000 --> 00:00:20,000 +And it's how the PKI are managed. + +7 +00:00:20,000 --> 00:00:21,000 +It's basically how you structure it. + +8 +00:00:22,000 --> 00:00:27,000 +So when you set up a PKI, you have a root CA. + +9 +00:00:27,000 --> 00:00:30,000 +Underneath that you have what's called subordinate CAS. + +10 +00:00:30,000 --> 00:00:30,000 +All right. + +11 +00:00:30,000 --> 00:00:32,000 +Now why do we have this? + +12 +00:00:32,000 --> 00:00:34,000 +Well you see this root CA. + +13 +00:00:34,000 --> 00:00:37,000 +This root CA technically doesn't issue certificates. + +14 +00:00:37,000 --> 00:00:39,000 +Let's go back to the process of getting a certificate. + +15 +00:00:39,000 --> 00:00:44,000 +If you remember in that process the CA digitally signs your certificate. + +16 +00:00:45,000 --> 00:00:52,000 +If you remember how a digital signature works is that the CA utilizes its private key, it hashes all + +17 +00:00:52,000 --> 00:00:53,000 +the information on your. + +18 +00:00:53,000 --> 00:00:58,000 +The way it's done is that it will hash all the information on a certificate to company. + +19 +00:00:58,000 --> 00:01:04,000 +Name your domain name, uh, the certificate start and end dates. + +20 +00:01:04,000 --> 00:01:10,000 +It then hashes all this information and then it encrypts it with its private key. + +21 +00:01:10,000 --> 00:01:11,000 +Remember how signatures are done. + +22 +00:01:12,000 --> 00:01:18,000 +So if that certificate like for example, let's say Digicert. + +23 +00:01:18,000 --> 00:01:19,000 +If Digicert. + +24 +00:01:20,000 --> 00:01:26,000 +Ever gets compromised and their private key is compromised. + +25 +00:01:26,000 --> 00:01:33,000 +Every single certificate, the millions and millions of certificate that Digicert has ever given out, + +26 +00:01:33,000 --> 00:01:35,000 +becomes invalid instantly. + +27 +00:01:35,000 --> 00:01:38,000 +Because then anybody could remake the certificate because they have the private key. + +28 +00:01:38,000 --> 00:01:40,000 +And of course, everybody had the public key. + +29 +00:01:40,000 --> 00:01:41,000 +It was always public. + +30 +00:01:41,000 --> 00:01:51,000 +So in order to help minimize this kind of impact, what we do is we set up a root CA and then subordinate + +31 +00:01:51,000 --> 00:01:51,000 +CAS. + +32 +00:01:51,000 --> 00:01:55,000 +Now the reason why you have this is because of this. + +33 +00:01:55,000 --> 00:01:57,000 +You you set up a root CA. + +34 +00:01:58,000 --> 00:02:05,000 +And this root CA will then issue a certificate to the subordinate CAS which can then issue it to even + +35 +00:02:05,000 --> 00:02:06,000 +lower CAS. + +36 +00:02:06,000 --> 00:02:11,000 +The reason you do this is because then you can take the root CA offline when I mean offline. + +37 +00:02:11,000 --> 00:02:17,000 +This is a computer that is literally unplugged, shut off, and put into a vault a couple thousand feet + +38 +00:02:17,000 --> 00:02:23,000 +in the air because this is certify and this and this is certifying this. + +39 +00:02:23,000 --> 00:02:31,000 +So technically speaking, if somebody hacks the company and they hack this lower CA right here at the + +40 +00:02:31,000 --> 00:02:34,000 +bottom, then you know what? + +41 +00:02:34,000 --> 00:02:39,000 +All the certificate that's issued by this cert by DCA is invalidated. + +42 +00:02:39,000 --> 00:02:42,000 +Not everything in the entire organization. + +43 +00:02:42,000 --> 00:02:48,000 +So what this does is this helps to minimize the impact of the data breach or the attack. + +44 +00:02:48,000 --> 00:02:49,000 +That's what you would want. + +45 +00:02:49,000 --> 00:02:55,000 +This you don't you never want to just start issuing certificate from your root CA because if that root + +46 +00:02:55,000 --> 00:02:56,000 +CA. + +47 +00:02:57,000 --> 00:02:58,000 +Is. + +48 +00:02:59,000 --> 00:03:03,000 +If that route C is ever compromised, every search you've ever given is invalidated. + +49 +00:03:03,000 --> 00:03:06,000 +But if you branch it off into four subordinates. + +50 +00:03:07,000 --> 00:03:11,000 +Then if one of those is compromised, there's just those certs are compromised, not the other three. + +51 +00:03:11,000 --> 00:03:16,000 +So that's why you would want to use this kind of structure. + +52 +00:03:16,000 --> 00:03:19,000 +Now this kind of structure is only done well. + +53 +00:03:19,000 --> 00:03:20,000 +It's done basically for two reasons. + +54 +00:03:20,000 --> 00:03:25,000 +Number one easier to administer and of course for the data protection. + +55 +00:03:25,000 --> 00:03:29,000 +That way if something happens, not everything becomes invalidated. + diff --git a/07 - Cryptography/020 PKI Verification and Revocation OB 1.4_en.srt b/07 - Cryptography/020 PKI Verification and Revocation OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3d102a6838ffa4c2c3118030980b462f16125ccf --- /dev/null +++ b/07 - Cryptography/020 PKI Verification and Revocation OB 1.4_en.srt @@ -0,0 +1,372 @@ +1 +00:00:00,000 --> 00:00:00,000 +Okay. + +2 +00:00:00,000 --> 00:00:05,000 +When you receive a certificate from someone, you have to verify that it actually came from them. + +3 +00:00:05,000 --> 00:00:11,000 +There's a couple of things here that we need to know for our exam when it comes to this process of verification. + +4 +00:00:11,000 --> 00:00:14,000 +And again, this is when a user wants to validate your certificate. + +5 +00:00:14,000 --> 00:00:19,000 +So somebody comes to an app, maybe like a web app that you made or a device that you're using. + +6 +00:00:19,000 --> 00:00:23,000 +Maybe you have certificates installed on your on your firewall for VPN and so on. + +7 +00:00:23,000 --> 00:00:25,000 +Somebody comes there and they get a certificate. + +8 +00:00:25,000 --> 00:00:27,000 +They want to verify that it's coming from you. + +9 +00:00:27,000 --> 00:00:31,000 +If I get into that, do I want to talk about a firm that you may see appear on your exam? + +10 +00:00:31,000 --> 00:00:32,000 +It's called certificate pinning. + +11 +00:00:32,000 --> 00:00:35,000 +This is a techniques that helps to prevent man in the middle attacks. + +12 +00:00:35,000 --> 00:00:39,000 +What it does is that it hard codes the SSL public key into an app. + +13 +00:00:40,000 --> 00:00:44,000 +This means that when the output device communicates with the server to compare the SSL certificates + +14 +00:00:44,000 --> 00:00:46,000 +public key with the one in the app. + +15 +00:00:46,000 --> 00:00:48,000 +Now let me give you an example how this works. + +16 +00:00:48,000 --> 00:00:48,000 +So. + +17 +00:00:49,000 --> 00:00:54,000 +Let's say you have an application, and every time people come, they get your certificate and then + +18 +00:00:54,000 --> 00:00:55,000 +they check the certificate. + +19 +00:00:55,000 --> 00:01:00,000 +Now, what you can do in order to prevent people from intercepting or changing anything, you can hardcode + +20 +00:01:00,000 --> 00:01:02,000 +the public key in the application itself. + +21 +00:01:02,000 --> 00:01:07,000 +So then the certificate that's given to them by the SSL process, they can then compare it to the application's + +22 +00:01:07,000 --> 00:01:08,000 +public key. + +23 +00:01:08,000 --> 00:01:16,000 +That way no one can intercept the certificate or change it and say that this is their certificate of + +24 +00:01:16,000 --> 00:01:19,000 +any kind, because you have a hardcoded the public key in the app. + +25 +00:01:20,000 --> 00:01:21,000 +Okay. + +26 +00:01:21,000 --> 00:01:24,000 +Let's move on here quickly to the verification process. + +27 +00:01:24,000 --> 00:01:28,000 +So when you get a certificate all right a couple of things here. + +28 +00:01:28,000 --> 00:01:33,000 +The certificate verification process includes verifying the digital signature of the CA is authentic. + +29 +00:01:33,000 --> 00:01:35,000 +And they trust the CA. + +30 +00:01:35,000 --> 00:01:39,000 +So when you receive a certificate you're going to check okay. + +31 +00:01:39,000 --> 00:01:41,000 +Who the certificate came from. + +32 +00:01:41,000 --> 00:01:42,000 +Digicert. + +33 +00:01:42,000 --> 00:01:49,000 +I want you guys to keep in mind that your computer has a list of already pre-approved certificate authorities + +34 +00:01:49,000 --> 00:01:50,000 +that it trusts. + +35 +00:01:50,000 --> 00:01:55,000 +You're then going to check that a signature on it to make sure it's good. + +36 +00:01:56,000 --> 00:02:02,000 +One of the things that you guys will check is what's called a CRL, the certificate revocation list. + +37 +00:02:02,000 --> 00:02:06,000 +This is a published list of certificates that have been revoked. + +38 +00:02:06,000 --> 00:02:08,000 +Let's talk about this revocation process. + +39 +00:02:08,000 --> 00:02:16,000 +Sometimes when you get a certificate, you yourself may want to revoke the certificate for reasons such + +40 +00:02:16,000 --> 00:02:19,000 +as you're changing the server and the server is not valid anymore. + +41 +00:02:19,000 --> 00:02:23,000 +The server crashed, your server was hacked, and you lost the private key. + +42 +00:02:23,000 --> 00:02:27,000 +Something happened internally and you don't want to use that certificate anymore. + +43 +00:02:27,000 --> 00:02:33,000 +So you call your certificate provider like Digicert and say, well, can you reissue this cert? + +44 +00:02:33,000 --> 00:02:34,000 +Desert we have is no good. + +45 +00:02:35,000 --> 00:02:37,000 +So maybe your server got hacked. + +46 +00:02:37,000 --> 00:02:40,000 +So you call Digicert and say, well, my server got hacked. + +47 +00:02:40,000 --> 00:02:42,000 +I need a brand new certificate. + +48 +00:02:42,000 --> 00:02:43,000 +So Digicert says, no problem. + +49 +00:02:43,000 --> 00:02:48,000 +Here's a brand new certificate with a and you generate a new public private key pair. + +50 +00:02:48,000 --> 00:02:50,000 +Now what happens to that old certificate? + +51 +00:02:50,000 --> 00:02:53,000 +You see the old certificate that Digicert issued? + +52 +00:02:53,000 --> 00:02:56,000 +It's still technically valid. + +53 +00:02:56,000 --> 00:02:56,000 +Here's why. + +54 +00:02:56,000 --> 00:03:00,000 +Because the public the the expiration date hasn't occurred yet. + +55 +00:03:00,000 --> 00:03:01,000 +So it's not expired. + +56 +00:03:02,000 --> 00:03:04,000 +The signature is still valid. + +57 +00:03:04,000 --> 00:03:10,000 +Remember, signature is the hash of the certificate encrypted with the CA's private key. + +58 +00:03:11,000 --> 00:03:13,000 +That's still valid. + +59 +00:03:13,000 --> 00:03:16,000 +So anybody that receives that certificate is going to think it's valid. + +60 +00:03:16,000 --> 00:03:24,000 +So what we do is we will publish a list of certificates that's revoked. + +61 +00:03:24,000 --> 00:03:27,000 +So when people come to the website, they're going to check the CRL list. + +62 +00:03:27,000 --> 00:03:32,000 +Or they check this thing called Ocsp, an online certificate status protocol. + +63 +00:03:32,000 --> 00:03:35,000 +This is a real time validation with the CA. + +64 +00:03:35,000 --> 00:03:36,000 +This is a is this valid? + +65 +00:03:36,000 --> 00:03:37,000 +The CA is like yeah that's good. + +66 +00:03:38,000 --> 00:03:43,000 +Now the certificate usually contains the data that you're going to be trusting such as that public key. + +67 +00:03:43,000 --> 00:03:46,000 +So this is the revocation that I was mentioning. + +68 +00:03:46,000 --> 00:03:51,000 +So when it's compromised it gets added to the certificate revocation list. + +69 +00:03:51,000 --> 00:03:57,000 +If you want a real time validation that the certificate is actually good. + +70 +00:03:57,000 --> 00:04:00,000 +Then you use all CSP. + +71 +00:04:00,000 --> 00:04:01,000 +Know that for your exam. + +72 +00:04:01,000 --> 00:04:02,000 +There's a real time. + +73 +00:04:02,000 --> 00:04:07,000 +So right now, almost all of us, every time we go to Amazon or we get the certificate, we use this + +74 +00:04:07,000 --> 00:04:10,000 +protocol to check if that certificate is still valid. + +75 +00:04:11,000 --> 00:04:15,000 +Another time you may see on your exam is something we call certificate stapling. + +76 +00:04:15,000 --> 00:04:16,000 +All right. + +77 +00:04:16,000 --> 00:04:20,000 +And what this does is that it avoids the client from sending the Ocsp request. + +78 +00:04:20,000 --> 00:04:27,000 +Instead, the web server itself checks the validation with the CA now certificate stapling is this. + +79 +00:04:27,000 --> 00:04:34,000 +Every time you get, uh, the certificate, you have to check with the ocsp. + +80 +00:04:34,000 --> 00:04:35,000 +Is it good? + +81 +00:04:35,000 --> 00:04:35,000 +Okay, great. + +82 +00:04:35,000 --> 00:04:36,000 +Let me use it. + +83 +00:04:36,000 --> 00:04:44,000 +How about if I just the actual web server gets the validation, and then when you receive the certificate, + +84 +00:04:44,000 --> 00:04:48,000 +you're receiving the validation that you're looking for and the certificate. + +85 +00:04:48,000 --> 00:04:48,000 +So that's what this does. + +86 +00:04:48,000 --> 00:04:51,000 +It makes it a lot easier so you don't have to waste time. + +87 +00:04:51,000 --> 00:04:52,000 +Keep going here. + +88 +00:04:53,000 --> 00:04:54,000 +Okay. + +89 +00:04:54,000 --> 00:04:56,000 +Revocation is a is a pretty important thing. + +90 +00:04:56,000 --> 00:05:01,000 +At some point, if in your history of managing web servers or managing this kind of technology like + +91 +00:05:01,000 --> 00:05:06,000 +SSL, you're probably going to have to revoke a cert when a cert is revoked. + +92 +00:05:06,000 --> 00:05:11,000 +It has to be a way for other users in the public internet, or in turn, your organization to note that + +93 +00:05:11,000 --> 00:05:15,000 +certificate is no good and these are the ways that it's done. + diff --git a/07 - Cryptography/021 Steganography OB 1.4_en.srt b/07 - Cryptography/021 Steganography OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..2ddb788e56d7af027781721529335dc857933dc0 --- /dev/null +++ b/07 - Cryptography/021 Steganography OB 1.4_en.srt @@ -0,0 +1,392 @@ +1 +00:00:00,000 --> 00:00:05,000 +Okay, let's talk of a pretty cool technology called steganography. + +2 +00:00:05,000 --> 00:00:11,000 +Now, steganography is basically a technique where you're able to encode a hidden message into different + +3 +00:00:11,000 --> 00:00:17,000 +things, such as pictures, audio files, video files, or text files. + +4 +00:00:17,000 --> 00:00:20,000 +And I have a link here that I want you guys to try. + +5 +00:00:20,000 --> 00:00:25,000 +I'm going to show you guys how to use that, and I'm going to show you guys how we can take an image + +6 +00:00:25,000 --> 00:00:27,000 +and encode a secret message into it. + +7 +00:00:27,000 --> 00:00:31,000 +Why is this bad and somewhat good? + +8 +00:00:31,000 --> 00:00:38,000 +So let's say you're working in an organization and you are a bad person, and you want to get secret + +9 +00:00:38,000 --> 00:00:44,000 +data out of that organization right in front of their faces, and they would never know. + +10 +00:00:44,000 --> 00:00:46,000 +So here's what you do. + +11 +00:00:46,000 --> 00:00:51,000 +You go to the office and you take a group picture with all your bosses and everyone, and then you take + +12 +00:00:51,000 --> 00:00:53,000 +that picture and you put it on your computer. + +13 +00:00:53,000 --> 00:01:00,000 +What you do then is you take the company's secret information, secret data, and you encode it into + +14 +00:01:00,000 --> 00:01:00,000 +the picture. + +15 +00:01:01,000 --> 00:01:07,000 +Then what you do is you email the picture out outside to your personal private email. + +16 +00:01:07,000 --> 00:01:12,000 +And then what happens is when you get home, you decode the picture and you take the message out the + +17 +00:01:12,000 --> 00:01:13,000 +picture. + +18 +00:01:13,000 --> 00:01:19,000 +So this picture is flying around the internet, but the picture is actually just a front for the secret + +19 +00:01:19,000 --> 00:01:21,000 +message that lies behind it. + +20 +00:01:21,000 --> 00:01:24,000 +It's actually really easy to do, and you can even do a website that does it. + +21 +00:01:24,000 --> 00:01:26,000 +And I'll show you guys how easy it is. + +22 +00:01:26,000 --> 00:01:31,000 +Now, what I'm describing to you here is called image steganography. + +23 +00:01:31,000 --> 00:01:37,000 +And this what they do is they modify LSB the least significant bit in the image. + +24 +00:01:37,000 --> 00:01:42,000 +Basically, they're going to modify the image to the point where the human eyes can notice that the + +25 +00:01:42,000 --> 00:01:44,000 +image has actually been modified. + +26 +00:01:44,000 --> 00:01:50,000 +You could also do this with audio file concealing the information within audio files, or particularly + +27 +00:01:50,000 --> 00:01:54,000 +all kinds of video files like MP4 video files are famous for this. + +28 +00:01:54,000 --> 00:01:59,000 +You can even embed it into white spaces into certain text document. + +29 +00:01:59,000 --> 00:02:06,000 +Now for this I want to show you guys how it's done, and I'll give you guys some ways of how to detect + +30 +00:02:06,000 --> 00:02:06,000 +it. + +31 +00:02:06,000 --> 00:02:07,000 +So let's take a look here. + +32 +00:02:07,000 --> 00:02:11,000 +Here I am at that particular website that I just showed you. + +33 +00:02:11,000 --> 00:02:14,000 +Now on my desktop. + +34 +00:02:14,000 --> 00:02:15,000 +Let me pull up my desktop here. + +35 +00:02:17,000 --> 00:02:19,000 +On my desktop, I have an image. + +36 +00:02:21,000 --> 00:02:24,000 +I have this image that I just downloaded, royalty free image. + +37 +00:02:24,000 --> 00:02:26,000 +And let's see what it looks like. + +38 +00:02:26,000 --> 00:02:28,000 +This image of a laptop that I have. + +39 +00:02:28,000 --> 00:02:33,000 +So what I'm going to do is I'm going to encode select file. + +40 +00:02:33,000 --> 00:02:34,000 +I'm going to choose my image. + +41 +00:02:36,000 --> 00:02:37,000 +There is my desktop. + +42 +00:02:37,000 --> 00:02:38,000 +Here we go. + +43 +00:02:38,000 --> 00:02:39,000 +Image image image. + +44 +00:02:39,000 --> 00:02:47,000 +So I select the image and I'm going to put a message that says Andrew has many certifications. + +45 +00:02:47,000 --> 00:02:48,000 +That's my message. + +46 +00:02:48,000 --> 00:02:50,000 +And this is your original image. + +47 +00:02:50,000 --> 00:02:53,000 +Now you're not going to notice a difference when it encodes it. + +48 +00:02:54,000 --> 00:02:55,000 +Okay. + +49 +00:02:55,000 --> 00:03:00,000 +So here's the binary representation of the actual image that it's that it's encoding it into. + +50 +00:03:00,000 --> 00:03:05,000 +And here is the actual stick node image. + +51 +00:03:06,000 --> 00:03:07,000 +It says message hidden in the image. + +52 +00:03:07,000 --> 00:03:10,000 +You can't tell the difference between that and this. + +53 +00:03:11,000 --> 00:03:16,000 +Now, when you try it on your computer, try to see the human eyes cannot tell. + +54 +00:03:16,000 --> 00:03:19,000 +Now what I'm going to do is I'm going to right click and I'm going to save this one. + +55 +00:03:21,000 --> 00:03:24,000 +And uh, we're going to call it now, I already tried this. + +56 +00:03:24,000 --> 00:03:27,000 +I wanted to try it before it before showing to you. + +57 +00:03:27,000 --> 00:03:34,000 +So we're going to call S I stick node image for now dot png. + +58 +00:03:34,000 --> 00:03:34,000 +All right. + +59 +00:03:34,000 --> 00:03:36,000 +So we're going to save this. + +60 +00:03:37,000 --> 00:03:38,000 +All right, that's it. + +61 +00:03:38,000 --> 00:03:39,000 +It's saved. + +62 +00:03:39,000 --> 00:03:43,000 +Now, if I open up the image, you notice it pretty much is the same thing. + +63 +00:03:43,000 --> 00:03:49,000 +Now, let's say I can give this image to a lot of people around the internet. + +64 +00:03:49,000 --> 00:03:53,000 +Uh, no one would know unless you actually know there is an image. + +65 +00:03:53,000 --> 00:03:55,000 +So let's close out this site. + +66 +00:03:55,000 --> 00:03:57,000 +I'm going to reopen it. + +67 +00:03:59,000 --> 00:04:00,000 +So you can see it's all brand new. + +68 +00:04:00,000 --> 00:04:02,000 +So I'm going to go to decode this time. + +69 +00:04:02,000 --> 00:04:04,000 +I'm going to select the file. + +70 +00:04:05,000 --> 00:04:07,000 +Including the downloads folder. + +71 +00:04:07,000 --> 00:04:07,000 +We had it. + +72 +00:04:08,000 --> 00:04:09,000 +Here we go. + +73 +00:04:10,000 --> 00:04:12,000 +So this is the image the input I'm just going to click on decode. + +74 +00:04:13,000 --> 00:04:15,000 +And notice my message has just popped up. + +75 +00:04:16,000 --> 00:04:18,000 +You can see the message right there at the top. + +76 +00:04:19,000 --> 00:04:19,000 +All right. + +77 +00:04:19,000 --> 00:04:20,000 +Very good. + +78 +00:04:20,000 --> 00:04:22,000 +So that is steganography. + +79 +00:04:22,000 --> 00:04:29,000 +Steganography is just the way of embedding a message into an image, or a text file, or a movie file + +80 +00:04:29,000 --> 00:04:29,000 +or audio file. + +81 +00:04:29,000 --> 00:04:35,000 +Now, the way you can tell is the file size. + +82 +00:04:35,000 --> 00:04:35,000 +All right. + +83 +00:04:35,000 --> 00:04:40,000 +The way you can tell if an image has signal, you would need to have that original file. + +84 +00:04:40,000 --> 00:04:46,000 +And if you believe that an image has some kind of steganography behind it, look at the file size. + +85 +00:04:46,000 --> 00:04:49,000 +Another thing you can do is run it against a hash checker. + +86 +00:04:49,000 --> 00:04:53,000 +The hash of the images would be different because one of them just has more information than the other. + +87 +00:04:53,000 --> 00:04:55,000 +There are some ways of checking. + +88 +00:04:55,000 --> 00:04:58,000 +Other than that, there's not many different ways of stopping this thing. + +89 +00:04:58,000 --> 00:05:04,000 +Steganography is difficult to detect, but it's as difficult to detect. + +90 +00:05:05,000 --> 00:05:14,000 +But this is why you should limit the output in or send in of things like, uh, images and audio files + +91 +00:05:14,000 --> 00:05:15,000 +outside your organization. + +92 +00:05:15,000 --> 00:05:20,000 +Because now that you know that this exists, maybe you shouldn't allow images to go out. + +93 +00:05:20,000 --> 00:05:25,000 +In fact, one of the dumbest things I see organizations do sometimes. + +94 +00:05:25,000 --> 00:05:32,000 +I got an email from a bank, like legitimate email from a representative of a bank, and in it they + +95 +00:05:32,000 --> 00:05:35,000 +have the logo of the bank and the email signature of the person. + +96 +00:05:35,000 --> 00:05:42,000 +That's smart, because if the head of the bank realizes that they can embed messages into that little + +97 +00:05:42,000 --> 00:05:44,000 +logo, I don't think they would have allowed it. + +98 +00:05:44,000 --> 00:05:49,000 +So it's important to know what this thing is and realize it's difficult to detect. + diff --git a/07 - Cryptography/022 Blockchain OB 1.4_en.srt b/07 - Cryptography/022 Blockchain OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..4264d04ff874e6819b8a540dc69b91cb4080dbba --- /dev/null +++ b/07 - Cryptography/022 Blockchain OB 1.4_en.srt @@ -0,0 +1,476 @@ +1 +00:00:00,000 --> 00:00:03,000 +In this video, we're going to talk of a pretty famous technology. + +2 +00:00:03,000 --> 00:00:06,000 +And that technology is called blockchain. + +3 +00:00:06,000 --> 00:00:09,000 +Now blockchain I'm going to show you guys how a blockchain is built. + +4 +00:00:09,000 --> 00:00:15,000 +But this particular technology is famous in cryptocurrencies where most people hears it from. + +5 +00:00:15,000 --> 00:00:21,000 +But blockchain can be applied to many different applications, whether it's an accounting application, + +6 +00:00:21,000 --> 00:00:24,000 +banking transactions or all different kinds of financial transactions. + +7 +00:00:24,000 --> 00:00:25,000 +You can use a blockchain. + +8 +00:00:25,000 --> 00:00:27,000 +So it's not just for cryptocurrency. + +9 +00:00:27,000 --> 00:00:30,000 +In fact, this video has nothing to do with cryptocurrency. + +10 +00:00:30,000 --> 00:00:31,000 +Let's get started. + +11 +00:00:31,000 --> 00:00:38,000 +So blockchain let's take a look at some definitions before I show you exactly how a blockchain is built. + +12 +00:00:38,000 --> 00:00:46,000 +So a blockchain is known as a decentralized and distributed ledger technology known for its role in + +13 +00:00:46,000 --> 00:00:47,000 +underpinning cryptocurrency. + +14 +00:00:47,000 --> 00:00:53,000 +Like I mentioned now a blockchain is just a chain of blocks where each block represents a list of transaction. + +15 +00:00:53,000 --> 00:00:58,000 +Each transaction in the blockchain is secured through a cryptographic principle known as hashing, which + +16 +00:00:58,000 --> 00:01:00,000 +we covered earlier in the course. + +17 +00:01:00,000 --> 00:01:05,000 +The blockchain is decentralized and maintain across a network of computers across all of the nodes in + +18 +00:01:05,000 --> 00:01:07,000 +that particular system. + +19 +00:01:07,000 --> 00:01:10,000 +It does utilize a hash function. + +20 +00:01:10,000 --> 00:01:15,000 +Each block contains a cryptographic hash of the previous block, chaining them together. + +21 +00:01:15,000 --> 00:01:17,000 +This ensures that each block is added to. + +22 +00:01:17,000 --> 00:01:21,000 +Jim cannot be altered without messing up all the blocks that comes after it. + +23 +00:01:22,000 --> 00:01:24,000 +Lots of information here. + +24 +00:01:24,000 --> 00:01:27,000 +Let me show you it and it'll make more sense. + +25 +00:01:27,000 --> 00:01:29,000 +So I have an image. + +26 +00:01:30,000 --> 00:01:33,000 +Uh, from Money.com. + +27 +00:01:33,000 --> 00:01:38,000 +And I want to show you guys what is, you know, what exactly is how how a blockchain works. + +28 +00:01:38,000 --> 00:01:43,000 +So first of all, when they say the word decentralized ledger, let's take the word ledger. + +29 +00:01:43,000 --> 00:01:48,000 +Ledger literally means list when they say a list of transactions. + +30 +00:01:48,000 --> 00:01:54,000 +When you design a blockchain, you design how many of these transactions are going to be stored on every + +31 +00:01:54,000 --> 00:01:55,000 +single block. + +32 +00:01:55,000 --> 00:01:58,000 +So every block can hold a list of transactions. + +33 +00:01:58,000 --> 00:02:02,000 +Let's say you're a reseller and you're selling books. + +34 +00:02:03,000 --> 00:02:04,000 +Okay. + +35 +00:02:04,000 --> 00:02:07,000 +Each block for you holds three transactions. + +36 +00:02:07,000 --> 00:02:12,000 +It holds who bought the book when they bought the book, and how much money they spent buying the book. + +37 +00:02:12,000 --> 00:02:13,000 +And again, this is a list. + +38 +00:02:13,000 --> 00:02:18,000 +Anything that you can, anything that you can put a make a list out of, you can make a blockchain out + +39 +00:02:18,000 --> 00:02:18,000 +of. + +40 +00:02:18,000 --> 00:02:21,000 +So let's say each block holds three transactions. + +41 +00:02:21,000 --> 00:02:26,000 +And I'll show you why the blockchain is so powerful and why people like using it. + +42 +00:02:26,000 --> 00:02:28,000 +So each block is three transactions. + +43 +00:02:28,000 --> 00:02:32,000 +So in the first block you put transaction number one. + +44 +00:02:32,000 --> 00:02:38,000 +Let's say Bob bought a book for $10 and the book was, uh, Excel. + +45 +00:02:38,000 --> 00:02:45,000 +Then the second book was bought by Mary for 20 bucks, and she bought a word book. + +46 +00:02:45,000 --> 00:02:49,000 +And, uh, number three was Peter. + +47 +00:02:49,000 --> 00:02:54,000 +He bought a CISSP book for a $30 CISSP book. + +48 +00:02:54,000 --> 00:02:55,000 +It doesn't matter what it is. + +49 +00:02:55,000 --> 00:02:58,000 +Just know it's three transaction. + +50 +00:02:58,000 --> 00:03:06,000 +What you do is you take your entire three transaction, all three of them, everything about them, + +51 +00:03:06,000 --> 00:03:07,000 +and you hash it. + +52 +00:03:07,000 --> 00:03:14,000 +Now, the most famous hash they use is a crypto is a, uh, Sha 256 is the most famous hash they use. + +53 +00:03:14,000 --> 00:03:19,000 +If you remember the hash in videos, how I was able to type text in the box and they generate a hash, + +54 +00:03:19,000 --> 00:03:20,000 +the same thing here. + +55 +00:03:20,000 --> 00:03:23,000 +They're just going to put all the transaction in and boom, generate a hash. + +56 +00:03:23,000 --> 00:03:26,000 +This is the hash that comes out of this block. + +57 +00:03:27,000 --> 00:03:29,000 +There is no previous hash or zero. + +58 +00:03:30,000 --> 00:03:31,000 +Then what they do? + +59 +00:03:32,000 --> 00:03:40,000 +Is they go to the next block and they put another one, two, three transaction. + +60 +00:03:40,000 --> 00:03:41,000 +Whatever they are, it doesn't matter for now. + +61 +00:03:42,000 --> 00:03:45,000 +And then they hash it. + +62 +00:03:45,000 --> 00:03:46,000 +But here's what they do. + +63 +00:03:46,000 --> 00:03:50,000 +This block starts out with the this previous hash. + +64 +00:03:50,000 --> 00:03:55,000 +This hash comes right here 6UP2. + +65 +00:03:55,000 --> 00:04:02,000 +So it takes the three transaction plus this hash to produce this hash. + +66 +00:04:02,000 --> 00:04:11,000 +Then it takes this hash puts it here I'm talking the hash value itself 8Y5C9. + +67 +00:04:11,000 --> 00:04:14,000 +And then it does 123 transaction. + +68 +00:04:15,000 --> 00:04:16,000 +And it. + +69 +00:04:17,000 --> 00:04:18,000 +And it gets a hash. + +70 +00:04:18,000 --> 00:04:20,000 +Now this is great. + +71 +00:04:20,000 --> 00:04:21,000 +Why is this good? + +72 +00:04:21,000 --> 00:04:22,000 +This is a blockchain. + +73 +00:04:22,000 --> 00:04:25,000 +If you ever wanted to know what exactly is a blockchain, this is how it works. + +74 +00:04:25,000 --> 00:04:26,000 +Why is this good? + +75 +00:04:26,000 --> 00:04:32,000 +Because remember in the world of hashing, if anything changes, it changes all of the files within + +76 +00:04:32,000 --> 00:04:33,000 +it, right? + +77 +00:04:33,000 --> 00:04:37,000 +If anything changes, if if anything changes in the transaction, the hash will change. + +78 +00:04:37,000 --> 00:04:39,000 +This is a this is a great technology. + +79 +00:04:39,000 --> 00:04:46,000 +And the reason we do this is because if anyone ever manipulates a transaction, let's say any one of + +80 +00:04:46,000 --> 00:04:48,000 +these first transaction. + +81 +00:04:49,000 --> 00:04:55,000 +Then this hash will change, which will then invalidate this hash, which will then invalidate this + +82 +00:04:55,000 --> 00:04:56,000 +hash. + +83 +00:04:56,000 --> 00:05:01,000 +In other words, any time you manipulate a block, all the block that goes forward after that becomes + +84 +00:05:01,000 --> 00:05:02,000 +invalidated. + +85 +00:05:03,000 --> 00:05:04,000 +And here's a pretty cool part. + +86 +00:05:05,000 --> 00:05:12,000 +This ledger, this block chain, these lists of blocks or all these blocks are stored across thousands + +87 +00:05:12,000 --> 00:05:14,000 +of machines across your network. + +88 +00:05:14,000 --> 00:05:16,000 +They all have the exact same ledger. + +89 +00:05:16,000 --> 00:05:19,000 +So when somebody manipulates this one, they'll be able to tell, hey, you know what? + +90 +00:05:19,000 --> 00:05:21,000 +That ledger is different than my ledger. + +91 +00:05:21,000 --> 00:05:22,000 +What's the difference here? + +92 +00:05:22,000 --> 00:05:24,000 +So it's decentralized. + +93 +00:05:24,000 --> 00:05:27,000 +Decentralized means it's not stored on a single machine. + +94 +00:05:27,000 --> 00:05:29,000 +In fact, it's stored on tons of machines. + +95 +00:05:29,000 --> 00:05:33,000 +If anybody ever does a manipulation, it updates all the ledgers, and people are going to see. + +96 +00:05:33,000 --> 00:05:39,000 +Well, technically, the only blocks that should ever be manipulated is this block four. + +97 +00:05:39,000 --> 00:05:40,000 +Then block five. + +98 +00:05:40,000 --> 00:05:43,000 +If anybody is changing blocks 2 or 3, that's a problem. + +99 +00:05:43,000 --> 00:05:45,000 +So that's the concept of a blockchain. + +100 +00:05:45,000 --> 00:05:51,000 +Now one thing that you may see pop up on your exam is a firm we call an open public ledger. + +101 +00:05:52,000 --> 00:05:54,000 +This is a decentralized and transparent record. + +102 +00:05:54,000 --> 00:05:58,000 +Keeping the ledger is accessible to anyone provides a permanent record of all transactions. + +103 +00:05:58,000 --> 00:06:05,000 +Now, there are websites out there that has all of the crypto currency transaction. + +104 +00:06:05,000 --> 00:06:09,000 +So if you ever find somebody who's cryptocurrency number. + +105 +00:06:11,000 --> 00:06:16,000 +Uh, you can actually put it into the public ledger, and the ledger is going to show you all the transactions + +106 +00:06:16,000 --> 00:06:17,000 +against that. + +107 +00:06:17,000 --> 00:06:25,000 +So all the transactions that you take, utilize in a particular cryptocurrency is public to everyone. + +108 +00:06:25,000 --> 00:06:29,000 +So they could see that this was used to purchase this, this and this was used in these transactions, + +109 +00:06:29,000 --> 00:06:30,000 +but they don't know who owns it. + +110 +00:06:31,000 --> 00:06:34,000 +So that is what a public ledger is. + +111 +00:06:35,000 --> 00:06:42,000 +Once again, keep in mind that, uh, blockchains is not something unique only to cryptocurrency. + +112 +00:06:42,000 --> 00:06:46,000 +Although it was pretty much invented with crypto, the creation of Bitcoin, it's not being utilized + +113 +00:06:46,000 --> 00:06:50,000 +in tons of applications, so make sure you're familiar with it. + +114 +00:06:50,000 --> 00:06:51,000 +It's all about integrity. + +115 +00:06:51,000 --> 00:06:58,000 +Public ledgers, especially blockchains, is not about confidentiality because technically in a public + +116 +00:06:58,000 --> 00:06:59,000 +ledger, it's all available. + +117 +00:06:59,000 --> 00:07:01,000 +The big key word there is integrity. + +118 +00:07:01,000 --> 00:07:06,000 +That means that if anybody manipulates any transaction on the blockchain, you're going to be able to + +119 +00:07:06,000 --> 00:07:12,000 +detect it, making it one of the best technologies, best in upcoming technologies going forward. + diff --git a/07 - Cryptography/023 Salting OB 1.4_en.srt b/07 - Cryptography/023 Salting OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..707174dad6d0766301276fc7eca6efd7dfa78bba --- /dev/null +++ b/07 - Cryptography/023 Salting OB 1.4_en.srt @@ -0,0 +1,352 @@ +1 +00:00:00,000 --> 00:00:06,000 +One of the worst technologies that still exists today that secures almost all the data on the planet + +2 +00:00:06,000 --> 00:00:07,000 +is passwords. + +3 +00:00:07,000 --> 00:00:08,000 +Oh, I hate passwords. + +4 +00:00:08,000 --> 00:00:10,000 +There's so many passwords to remember. + +5 +00:00:10,000 --> 00:00:16,000 +You always got to remember a complex password, and then it's easily hacked unless we salt it. + +6 +00:00:16,000 --> 00:00:20,000 +In this video, I want to talk about a topic called Sultan. + +7 +00:00:20,000 --> 00:00:24,000 +And Sultan is predominantly used to secure passwords. + +8 +00:00:24,000 --> 00:00:29,000 +Now, I do have a link in an article we're going to look at on Wikipedia that really shows in depth + +9 +00:00:29,000 --> 00:00:30,000 +salt. + +10 +00:00:30,000 --> 00:00:33,000 +And I want to explain this to you guys, but what exactly is it? + +11 +00:00:33,000 --> 00:00:37,000 +So Sultan is used to enhance the security of stored passwords. + +12 +00:00:37,000 --> 00:00:38,000 +It involves listen carefully. + +13 +00:00:38,000 --> 00:00:47,000 +Add in a unique random string of characters known as a salt to each password before it's hashed. + +14 +00:00:47,000 --> 00:00:50,000 +Now, in order to move on, you got to understand something. + +15 +00:00:50,000 --> 00:00:54,000 +When you store a password, a computer does not store the plaintext. + +16 +00:00:54,000 --> 00:00:58,000 +So if your password is password one, two, three, it doesn't store password 123. + +17 +00:00:58,000 --> 00:01:00,000 +It stores the hash of that. + +18 +00:01:01,000 --> 00:01:02,000 +Now remember I showed you guys hashing. + +19 +00:01:03,000 --> 00:01:05,000 +So it will store just the hash value. + +20 +00:01:05,000 --> 00:01:12,000 +When you come back to type in your password, it just you type in password one, two, three then hashes + +21 +00:01:12,000 --> 00:01:14,000 +it and compare it to the hash it has. + +22 +00:01:14,000 --> 00:01:16,000 +If it matches up boom, it logs you in. + +23 +00:01:16,000 --> 00:01:17,000 +That's the normal operation. + +24 +00:01:17,000 --> 00:01:20,000 +But how does Sultan work? + +25 +00:01:20,000 --> 00:01:23,000 +Well, I have the process listed here. + +26 +00:01:24,000 --> 00:01:26,000 +Okay, in case you're reading this at a later time. + +27 +00:01:27,000 --> 00:01:32,000 +Uh, but I want to go to this article, uh, on Wikipedia, and I want to show it to you, actually, + +28 +00:01:32,000 --> 00:01:34,000 +uh, more and more in practice. + +29 +00:01:34,000 --> 00:01:39,000 +So let's go to that link that you see on the slide. + +30 +00:01:39,000 --> 00:01:40,000 +Um. + +31 +00:01:41,000 --> 00:01:43,000 +And here we go. + +32 +00:01:44,000 --> 00:01:47,000 +Okay, so here's the link I just put on the slide there. + +33 +00:01:47,000 --> 00:01:48,000 +And this is going to be Sultan. + +34 +00:01:48,000 --> 00:01:50,000 +Now I want to show you guys a couple of things. + +35 +00:01:50,000 --> 00:01:51,000 +First of all. + +36 +00:01:53,000 --> 00:01:55,000 +So here is user one. + +37 +00:01:55,000 --> 00:01:57,000 +This is their password. + +38 +00:01:57,000 --> 00:01:59,000 +This is the hash of their password. + +39 +00:02:00,000 --> 00:02:00,000 +Okay. + +40 +00:02:00,000 --> 00:02:01,000 +That's the. + +41 +00:02:01,000 --> 00:02:05,000 +This is the 256 bit hash that's generated by Sha 256. + +42 +00:02:06,000 --> 00:02:15,000 +What the computer does with Sultan is that instead of just having the hash of just this password, what + +43 +00:02:15,000 --> 00:02:17,000 +the computer does is that it generates a salt. + +44 +00:02:17,000 --> 00:02:22,000 +This thing, it's a random set of a string of characters. + +45 +00:02:22,000 --> 00:02:28,000 +What it does now is that it will append this to your password. + +46 +00:02:29,000 --> 00:02:31,000 +Notice this is your password 123. + +47 +00:02:32,000 --> 00:02:36,000 +And then it appends all this random stuff to it and then hashes this. + +48 +00:02:38,000 --> 00:02:41,000 +Ash is all the things I just highlighted to form this. + +49 +00:02:41,000 --> 00:02:46,000 +So what's stored in the computer's password file is not this hash of password one, two, three. + +50 +00:02:46,000 --> 00:02:47,000 +It's this thing. + +51 +00:02:47,000 --> 00:02:51,000 +And this is incredibly difficult to crack. + +52 +00:02:51,000 --> 00:02:54,000 +Very few brute force in modern time will ever crack this. + +53 +00:02:54,000 --> 00:02:57,000 +Look how long this is, and look how complex it is. + +54 +00:02:58,000 --> 00:03:05,000 +So what it does is that it will take your password, append the salt, then hash it and then store it. + +55 +00:03:06,000 --> 00:03:11,000 +When you come to log in, the verification process would be you type in password one, two, three. + +56 +00:03:11,000 --> 00:03:12,000 +You never know assault. + +57 +00:03:12,000 --> 00:03:13,000 +You type in password 123. + +58 +00:03:13,000 --> 00:03:19,000 +It then re appends the salt, rehashes it and see oh okay. + +59 +00:03:19,000 --> 00:03:20,000 +Does it match what they have? + +60 +00:03:20,000 --> 00:03:21,000 +Yes okay. + +61 +00:03:21,000 --> 00:03:22,000 +It's correct. + +62 +00:03:22,000 --> 00:03:27,000 +Now if you're wondering does this really increase the security? + +63 +00:03:27,000 --> 00:03:29,000 +The answer is absolutely. + +64 +00:03:31,000 --> 00:03:36,000 +You see, one of the things here we have to remember, some people say, well, if I come to the prompt + +65 +00:03:36,000 --> 00:03:38,000 +and I keep typing in the past one, it might crack it. + +66 +00:03:38,000 --> 00:03:44,000 +You see, the way they crack password is they steal the hash, and then they run a brute force attack + +67 +00:03:44,000 --> 00:03:45,000 +against the hash. + +68 +00:03:45,000 --> 00:03:49,000 +No one knows your password except your head, except your brain. + +69 +00:03:49,000 --> 00:03:51,000 +But they know the hash. + +70 +00:03:51,000 --> 00:03:54,000 +The hash is technically not that difficult to get. + +71 +00:03:54,000 --> 00:03:58,000 +And if they get a hash that has a whole bunch of random string of character, what they're going to + +72 +00:03:58,000 --> 00:04:00,000 +do is they're going to brute force that hash. + +73 +00:04:00,000 --> 00:04:04,000 +And even if they guess the hash, that's technically not your password because your password is one, + +74 +00:04:04,000 --> 00:04:05,000 +two, three. + +75 +00:04:05,000 --> 00:04:13,000 +So if they use a massive super alien machine to crack that hash and find out your password with the + +76 +00:04:13,000 --> 00:04:15,000 +salt, it's not your password. + +77 +00:04:15,000 --> 00:04:16,000 +Because you know what? + +78 +00:04:16,000 --> 00:04:21,000 +When they type in your password, which they believe is your password, one, two, three plus the salt + +79 +00:04:21,000 --> 00:04:24,000 +is then going to re append the old salt. + +80 +00:04:25,000 --> 00:04:26,000 +And it's never going to work. + +81 +00:04:26,000 --> 00:04:35,000 +Sultan, remember, drastically improves your passwords, drastically improves the password. + +82 +00:04:35,000 --> 00:04:37,000 +Now you have to set this up. + +83 +00:04:37,000 --> 00:04:43,000 +Sultan is done in many applications and web applications especially will utilize Sultan. + +84 +00:04:43,000 --> 00:04:47,000 +So Sultan is an important topic in the world of IT security. + +85 +00:04:47,000 --> 00:04:53,000 +Anytime you hear someone do or build in a web application, ask them will the password be salted? + +86 +00:04:53,000 --> 00:04:56,000 +If not as an IT security security professional? + +87 +00:04:56,000 --> 00:05:01,000 +Tell them, I would highly recommend you salt the password. + +88 +00:05:01,000 --> 00:05:04,000 +That way the system is super secure. + diff --git a/07 - Cryptography/024 TPM OB 1.4_en.srt b/07 - Cryptography/024 TPM OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..cd5c58b45f9822e90af89738ec89a515a6f63690 --- /dev/null +++ b/07 - Cryptography/024 TPM OB 1.4_en.srt @@ -0,0 +1,284 @@ +1 +00:00:00,000 --> 00:00:05,000 +One of the most dangerous things that can ever happen in the world of it is when you're a security administrator + +2 +00:00:05,000 --> 00:00:12,000 +and you get a call that one of your employee has lost their laptop, because on this laptop contains + +3 +00:00:12,000 --> 00:00:18,000 +all the company's data, all that person's email, it doesn't matter how secure their password is. + +4 +00:00:18,000 --> 00:00:23,000 +You see, if I want the data off of this laptop, I don't need to know your password. + +5 +00:00:23,000 --> 00:00:31,000 +All I got to do unscrew the bottom, take out the bottom, take out the hard drive, take that hard + +6 +00:00:31,000 --> 00:00:33,000 +drive and mount it to my computer. + +7 +00:00:33,000 --> 00:00:36,000 +Whether it's a Sata drive Mdot, it doesn't matter. + +8 +00:00:36,000 --> 00:00:38,000 +I'm just going to plug the drive into my machine. + +9 +00:00:38,000 --> 00:00:44,000 +And there's a lot of external Mdot two and Sata connectors and whatever I can use to externally mount + +10 +00:00:44,000 --> 00:00:47,000 +your hard drive onto my desktop. + +11 +00:00:47,000 --> 00:00:51,000 +And now I can open all the files on your hard drive. + +12 +00:00:51,000 --> 00:00:53,000 +I don't care about logging into your windows. + +13 +00:00:53,000 --> 00:00:55,000 +All I want to do is steal your data. + +14 +00:00:55,000 --> 00:01:00,000 +This is a nightmare scenario for any it department. + +15 +00:01:00,000 --> 00:01:03,000 +So what do we do with devices like this? + +16 +00:01:03,000 --> 00:01:05,000 +Or god forbid, even more devices like this? + +17 +00:01:05,000 --> 00:01:11,000 +You see, especially when it comes to computers like this, we need to do what is called hard drive + +18 +00:01:11,000 --> 00:01:12,000 +encryption. + +19 +00:01:13,000 --> 00:01:16,000 +We need to encrypt the hard drive. + +20 +00:01:16,000 --> 00:01:21,000 +That way, if anybody does what I just say, I've taken the hard drive out, mounted it to a machine, + +21 +00:01:21,000 --> 00:01:24,000 +and seeing all the files in it, they won't be able to see anything. + +22 +00:01:24,000 --> 00:01:26,000 +Because the drive is encrypted. + +23 +00:01:26,000 --> 00:01:28,000 +The drive has to be encrypted. + +24 +00:01:28,000 --> 00:01:30,000 +This is called disk encryption. + +25 +00:01:30,000 --> 00:01:38,000 +And one of the ways of doing that is by utilizing oops, a TPM or a TPM chip. + +26 +00:01:38,000 --> 00:01:44,000 +A lot of these corporate laptops comes built with something we call a TPM chip. + +27 +00:01:45,000 --> 00:01:52,000 +TPM Trusted Platform module is a hardware component designed to secure hardware by integrating cryptographic + +28 +00:01:52,000 --> 00:01:53,000 +keys. + +29 +00:01:53,000 --> 00:01:59,000 +It's basically a device, okay that allows the generation of storage of cryptographic keys. + +30 +00:01:59,000 --> 00:02:04,000 +TPMs can generate encryption keys, keeping them private, keeping the private portion of these keys + +31 +00:02:04,000 --> 00:02:06,000 +safe within a TPM chip itself. + +32 +00:02:07,000 --> 00:02:10,000 +Now it's used for multiple purposes. + +33 +00:02:10,000 --> 00:02:14,000 +Number one, it's used to do things like disk encryption. + +34 +00:02:14,000 --> 00:02:16,000 +Now if you have windows. + +35 +00:02:17,000 --> 00:02:19,000 +Windows 11, and so on. + +36 +00:02:19,000 --> 00:02:24,000 +Windows 10 11, the higher versions of it, the business editions of it, you can have BitLocker, like + +37 +00:02:24,000 --> 00:02:26,000 +I have BitLocker on this machine. + +38 +00:02:26,000 --> 00:02:28,000 +I also have BitLocker on this machine. + +39 +00:02:28,000 --> 00:02:31,000 +You turn on BitLocker encryption. + +40 +00:02:31,000 --> 00:02:37,000 +And what BitLocker does if the machine has a TPM chip, is that it will encrypt the hard drive and it'll + +41 +00:02:37,000 --> 00:02:40,000 +store the cryptographic keys on the TPM chip. + +42 +00:02:40,000 --> 00:02:46,000 +If you remove the hard drive, you wouldn't be able to see anything because you'll need to decrypt it. + +43 +00:02:46,000 --> 00:02:50,000 +But the cryptographic keys is on the TPM chip. + +44 +00:02:50,000 --> 00:02:53,000 +Now, the TPM chip will be like something that's sorted into the motherboard. + +45 +00:02:53,000 --> 00:02:56,000 +It wouldn't be able something you could just rip off. + +46 +00:02:57,000 --> 00:03:02,000 +The TPM can also store and manage keys using the process of verifying the boot process. + +47 +00:03:02,000 --> 00:03:06,000 +That way no malware can try to load up in the boot process. + +48 +00:03:06,000 --> 00:03:10,000 +So TPM is super important right now. + +49 +00:03:10,000 --> 00:03:13,000 +If you're managing an IT department, you must. + +50 +00:03:13,000 --> 00:03:21,000 +And I say you must ensure that all your laptops especially have TPM, anything that's mobile. + +51 +00:03:22,000 --> 00:03:25,000 +So exactly what is it? + +52 +00:03:25,000 --> 00:03:30,000 +Well, it's basically it's a secure it has what's called a crypto processor that's designed to carry + +53 +00:03:30,000 --> 00:03:32,000 +out cryptographic operations. + +54 +00:03:32,000 --> 00:03:39,000 +The primary purpose of it, once again, is to ensure that we create cryptographic keys to keep our + +55 +00:03:39,000 --> 00:03:40,000 +disk secure. + +56 +00:03:40,000 --> 00:03:45,000 +This is going to be the two main beneficial aspects of a TPM chip. + +57 +00:03:45,000 --> 00:03:47,000 +I can't emphasize this enough. + +58 +00:03:47,000 --> 00:03:48,000 +One time. + +59 +00:03:49,000 --> 00:03:55,000 +Now this actually, this laptop actually has, uh, a TPM chip. + +60 +00:03:55,000 --> 00:03:56,000 +It is fully encrypted. + +61 +00:03:56,000 --> 00:04:01,000 +It does have the data of the business on it because it has my email and I am the CEO of the business. + +62 +00:04:01,000 --> 00:04:03,000 +It has my email, it has work I'm working on. + +63 +00:04:04,000 --> 00:04:06,000 +And one time I left it in the back of an Uber. + +64 +00:04:07,000 --> 00:04:09,000 +And you know, it didn't bother me much. + +65 +00:04:09,000 --> 00:04:12,000 +I called the Uber like the moment I figured out I left it. + +66 +00:04:12,000 --> 00:04:17,000 +It didn't like my heart didn't sink because I realized, well, even if somebody steals this laptop. + +67 +00:04:18,000 --> 00:04:20,000 +My password is super secure. + +68 +00:04:20,000 --> 00:04:23,000 +They probably not be able to get in, but if they do take the hard drive out. + +69 +00:04:24,000 --> 00:04:28,000 +They'll never get anything out of it, because the TPM in which obviously the laptop is back with me, + +70 +00:04:28,000 --> 00:04:30,000 +I called Uber and the driver dropped it back. + +71 +00:04:30,000 --> 00:04:35,000 +So make sure you use TPM chips, especially on all mobile devices. + diff --git a/07 - Cryptography/025 Secure Enclave OB 1.4_en.srt b/07 - Cryptography/025 Secure Enclave OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1807706ccbcb5711af2cfa865d6d3b8a89cbaa8d --- /dev/null +++ b/07 - Cryptography/025 Secure Enclave OB 1.4_en.srt @@ -0,0 +1,124 @@ +1 +00:00:00,000 --> 00:00:05,000 +When a computer is processing data, one of the things that the computer must be able to do, especially + +2 +00:00:05,000 --> 00:00:09,000 +secure processing, is that it has to be able to like segment that off. + +3 +00:00:09,000 --> 00:00:16,000 +You don't want things like processing of thumbprints or passwords to just be in any place of memory. + +4 +00:00:16,000 --> 00:00:21,000 +We have this concept called a secure enclave. + +5 +00:00:21,000 --> 00:00:25,000 +This provides a highly secure space within a device. + +6 +00:00:25,000 --> 00:00:29,000 +Memory, where sensitive data can be stored in cryptographic operations is done on. + +7 +00:00:29,000 --> 00:00:33,000 +And this basically isolates it from the other operating systems and processes. + +8 +00:00:33,000 --> 00:00:35,000 +Why would you do this? + +9 +00:00:35,000 --> 00:00:43,000 +Well, cryptographic processes generally in things does things like encrypt and decrypt sensitive data. + +10 +00:00:43,000 --> 00:00:48,000 +It checks things like passwords or facial recognition or biometrics. + +11 +00:00:48,000 --> 00:00:51,000 +You don't want this to just be in any part of a computer memory. + +12 +00:00:51,000 --> 00:00:51,000 +Why? + +13 +00:00:51,000 --> 00:00:55,000 +Because then other programs can read it and steal that data. + +14 +00:00:55,000 --> 00:01:01,000 +So what we do is we set up secure enclaves, and this is going to be done within the actual software + +15 +00:01:01,000 --> 00:01:02,000 +and hardware. + +16 +00:01:03,000 --> 00:01:04,000 +So what does it do? + +17 +00:01:04,000 --> 00:01:10,000 +Well, it ensures that sensitive data, like fingerprints, is stored in an environment that is separated, + +18 +00:01:10,000 --> 00:01:12,000 +segregated from the rest of the operating system. + +19 +00:01:12,000 --> 00:01:14,000 +This protects it from any malware. + +20 +00:01:14,000 --> 00:01:19,000 +So let's say you don't even know you have malicious software in your machine. + +21 +00:01:20,000 --> 00:01:25,000 +So you try to decode a file or log in with something, let's say a thumbprint. + +22 +00:01:26,000 --> 00:01:30,000 +Well, you don't really have to worry too much about the malware getting it, because you're using this + +23 +00:01:30,000 --> 00:01:33,000 +concept on your operating system and on your hardware. + +24 +00:01:34,000 --> 00:01:39,000 +Some of the key features, basically hardware isolation, the data and operations with data are isolated + +25 +00:01:39,000 --> 00:01:42,000 +at the hardware level, so software can't break it. + +26 +00:01:42,000 --> 00:01:47,000 +It limits access and is generally considered tamper resistant, making physical attacks very difficult + +27 +00:01:47,000 --> 00:01:50,000 +to get it on high secure systems. + +28 +00:01:50,000 --> 00:01:56,000 +This is one of the things you're going to have to make sure is built into the system, because you could + +29 +00:01:56,000 --> 00:02:02,000 +have malware or malicious software on your machine and not know it, and then secure operations could + +30 +00:02:02,000 --> 00:02:04,000 +be taking place in the malware can be stealing it. + +31 +00:02:04,000 --> 00:02:08,000 +But if you use a secure enclave, that is much less likely to happen. + diff --git a/07 - Cryptography/026 Obfuscation OB 1.4_en.srt b/07 - Cryptography/026 Obfuscation OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e5a215c6dd6b3a05b9c66c62f20112ace0b3255c --- /dev/null +++ b/07 - Cryptography/026 Obfuscation OB 1.4_en.srt @@ -0,0 +1,252 @@ +1 +00:00:00,000 --> 00:00:06,000 +Sometimes when you are playing around with data or have to have test data, you have to be careful because + +2 +00:00:06,000 --> 00:00:09,000 +a lot of data in the business is considered confidential. + +3 +00:00:09,000 --> 00:00:13,000 +But sometimes when you're building an application, you need data to work with. + +4 +00:00:13,000 --> 00:00:16,000 +You need large data sets to actually work with. + +5 +00:00:16,000 --> 00:00:22,000 +Now in this video, I want to show you guys a topic we're going to refer to as data obfuscation. + +6 +00:00:22,000 --> 00:00:28,000 +Obfuscation is basically the process of disguising sensitive, confidential or sensitive data protected + +7 +00:00:28,000 --> 00:00:30,000 +basically from unauthorized access. + +8 +00:00:30,000 --> 00:00:32,000 +Now I'm going to try this. + +9 +00:00:32,000 --> 00:00:32,000 +Here. + +10 +00:00:32,000 --> 00:00:35,000 +We have another video coming up on tokenization. + +11 +00:00:35,000 --> 00:00:38,000 +But I'm going to I want to show you guys what obfuscation is going to do. + +12 +00:00:39,000 --> 00:00:42,000 +And I'm going to go to that link and I want to show you guys what it does. + +13 +00:00:42,000 --> 00:00:45,000 +So basically it's going to hide the data. + +14 +00:00:45,000 --> 00:00:51,000 +Let's say you're writing a program like your source code to the program in order to make it difficult + +15 +00:00:51,000 --> 00:00:53,000 +for people to find the original source code. + +16 +00:00:53,000 --> 00:00:57,000 +If they see the source code they decompile the program is you can obfuscate it. + +17 +00:00:57,000 --> 00:00:58,000 +Let me show you guys what it looks like. + +18 +00:00:58,000 --> 00:01:02,000 +So if you follow that link in this slide there, this is what you would have gotten. + +19 +00:01:02,000 --> 00:01:07,000 +And here's this is a JavaScript Obfuscator tool. + +20 +00:01:07,000 --> 00:01:15,000 +And you notice that this is this is basically just the JavaScript that when ran it just says hello world. + +21 +00:01:15,000 --> 00:01:18,000 +It's the first thing you learn when you learn JavaScript or Java in general. + +22 +00:01:18,000 --> 00:01:22,000 +This is a comment that says paste your JavaScript code here. + +23 +00:01:22,000 --> 00:01:24,000 +Now this is going to obfuscate it. + +24 +00:01:24,000 --> 00:01:25,000 +So you can use this. + +25 +00:01:25,000 --> 00:01:28,000 +You can actually put your code in here if you write code and obfuscate it. + +26 +00:01:28,000 --> 00:01:30,000 +So if I say obfuscate watch what happens. + +27 +00:01:30,000 --> 00:01:33,000 +Ooh, that looks kind of crazy doesn't it? + +28 +00:01:33,000 --> 00:01:37,000 +Now if you run this code. + +29 +00:01:38,000 --> 00:01:38,000 +Okay. + +30 +00:01:38,000 --> 00:01:44,000 +If you run this code, it will run the code that we saw here. + +31 +00:01:44,000 --> 00:01:49,000 +This output obfuscated code technically is this. + +32 +00:01:49,000 --> 00:01:54,000 +Except as you notice, it looks kind of crazy. + +33 +00:01:56,000 --> 00:01:56,000 +It's obfuscate that. + +34 +00:01:57,000 --> 00:01:59,000 +So it's actually all there. + +35 +00:01:59,000 --> 00:02:01,000 +But it is difficult. + +36 +00:02:01,000 --> 00:02:04,000 +It basically hides a lot of the code, but it's still usable. + +37 +00:02:05,000 --> 00:02:09,000 +Now there are some other ways here that we can do. + +38 +00:02:09,000 --> 00:02:10,000 +Obfuscation. + +39 +00:02:10,000 --> 00:02:14,000 +What I showed you there is basically like a code code obfuscation, but it tells you the principle that + +40 +00:02:14,000 --> 00:02:18,000 +basically you're hiding your sensitive data. + +41 +00:02:18,000 --> 00:02:20,000 +There are a couple of things here we want to talk about. + +42 +00:02:21,000 --> 00:02:22,000 +First of all. + +43 +00:02:22,000 --> 00:02:23,000 +Data masking. + +44 +00:02:23,000 --> 00:02:28,000 +Data masking is when you create a substitute version of a data set. + +45 +00:02:28,000 --> 00:02:32,000 +The values are changed, but the data but the format remains the same. + +46 +00:02:32,000 --> 00:02:36,000 +An organization can run tests or training sessions if they were using real data. + +47 +00:02:36,000 --> 00:02:41,000 +So let's say you have a let's say you made a financial application and you got to test how credit cards, + +48 +00:02:41,000 --> 00:02:44,000 +you know, how much credit cards it can hold when instead of putting in real credit card numbers, just + +49 +00:02:44,000 --> 00:02:49,000 +take the take the actual credit card number and create a different version of it that's not real, and + +50 +00:02:49,000 --> 00:02:50,000 +then use that data. + +51 +00:02:50,000 --> 00:02:50,000 +Masking. + +52 +00:02:51,000 --> 00:02:56,000 +Encryption is something that we have spent an enormous amount of time in the encryption section on. + +53 +00:02:56,000 --> 00:03:00,000 +So remember encryption will hide the meaning of information. + +54 +00:03:00,000 --> 00:03:01,000 +It's part of what it does. + +55 +00:03:02,000 --> 00:03:05,000 +The next thing you're going to want to be familiar with is called tokenization. + +56 +00:03:05,000 --> 00:03:09,000 +Tokenization, depending on the exam you're taking, will be covered on your test. + +57 +00:03:09,000 --> 00:03:14,000 +Tokenization creates tokens to represent certain data. + +58 +00:03:14,000 --> 00:03:16,000 +Keep an eye on that door in the next video when I cover it. + +59 +00:03:17,000 --> 00:03:21,000 +But obfuscation is something that is important there. + +60 +00:03:21,000 --> 00:03:25,000 +They come up lots of times when you have to use sensitive data. + +61 +00:03:25,000 --> 00:03:30,000 +You want to process sensitive data without actually having the sensitive data. + +62 +00:03:30,000 --> 00:03:31,000 +You'll see what I mean next. + +63 +00:03:31,000 --> 00:03:32,000 +Tokenization. + diff --git a/07 - Cryptography/027 Tokenization OB 1.4_en.srt b/07 - Cryptography/027 Tokenization OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..eedffde3b4f85c864cc974e6d56485250dadab3e --- /dev/null +++ b/07 - Cryptography/027 Tokenization OB 1.4_en.srt @@ -0,0 +1,472 @@ +1 +00:00:00,000 --> 00:00:06,000 +Okay, I want to go to Best Buy and I'm going to buy the PlayStation five, which I've been meaning + +2 +00:00:06,000 --> 00:00:10,000 +to buy for a minute now, and I'm going to pay with PayPal. + +3 +00:00:10,000 --> 00:00:11,000 +Okay. + +4 +00:00:11,000 --> 00:00:14,000 +Now you're probably wondering, what does this have to do with my class? + +5 +00:00:14,000 --> 00:00:16,000 +Well, you'll see soon, so I'm going to pay with PayPal. + +6 +00:00:16,000 --> 00:00:23,000 +If you know how PayPal works is you basically are going to go to PayPal site, authenticate with PayPal, + +7 +00:00:23,000 --> 00:00:28,000 +and you're going to tell you're going to approve the charge through PayPal. + +8 +00:00:28,000 --> 00:00:29,000 +And then PayPal pays Best Buy. + +9 +00:00:29,000 --> 00:00:35,000 +So technically you never provide your payment information to Best Buy. + +10 +00:00:35,000 --> 00:00:41,000 +You provide it to PayPal, who then charges you and then provides the money to Best Buy. + +11 +00:00:41,000 --> 00:00:42,000 +Let's go do that. + +12 +00:00:43,000 --> 00:00:46,000 +So here I am at, uh, bestbuy.com. + +13 +00:00:46,000 --> 00:00:51,000 +And I got my PlayStation five in the shopping cart and I'm ready to pay, but I'm not going to go to + +14 +00:00:51,000 --> 00:00:54,000 +checkout and pay it through Best Buy, because I don't want to give Best Buy my credit card. + +15 +00:00:55,000 --> 00:00:57,000 +Now, I legitimately do this. + +16 +00:00:57,000 --> 00:00:59,000 +If the site does support PayPal, I do always use it. + +17 +00:00:59,000 --> 00:01:01,000 +So I'm going to go to PayPal checkout. + +18 +00:01:02,000 --> 00:01:04,000 +Okay, let's wait for this to load up. + +19 +00:01:04,000 --> 00:01:08,000 +And you'll notice now it wants me to log in. + +20 +00:01:08,000 --> 00:01:11,000 +Now I'm actually not going to go through this, but I want to show you something. + +21 +00:01:11,000 --> 00:01:13,000 +You notice it's paypal.com. + +22 +00:01:13,000 --> 00:01:15,000 +But I want you guys to see this. + +23 +00:01:15,000 --> 00:01:16,000 +You see this right here? + +24 +00:01:16,000 --> 00:01:17,000 +What does that say? + +25 +00:01:18,000 --> 00:01:19,000 +It says token. + +26 +00:01:19,000 --> 00:01:23,000 +I know it's a little hard to see in the video because it's, you know, it's a browser here, but notice + +27 +00:01:23,000 --> 00:01:26,000 +it says token is equal to and it gives me a token. + +28 +00:01:27,000 --> 00:01:27,000 +Hmm. + +29 +00:01:28,000 --> 00:01:29,000 +Let's talk about that. + +30 +00:01:29,000 --> 00:01:31,000 +So here's how this is going to work. + +31 +00:01:31,000 --> 00:01:33,000 +I'm going to go to Bestbuy.com. + +32 +00:01:33,000 --> 00:01:35,000 +I am going to then use PayPal. + +33 +00:01:36,000 --> 00:01:37,000 +I'm going PayPal. + +34 +00:01:37,000 --> 00:01:40,000 +Best buy will tell PayPal to charge me the 500 bucks. + +35 +00:01:41,000 --> 00:01:44,000 +I will then input all my information and allow PayPal to charge me. + +36 +00:01:45,000 --> 00:01:50,000 +Best buy will never, ever see my billing data. + +37 +00:01:50,000 --> 00:01:51,000 +They'll never see my credit card data. + +38 +00:01:52,000 --> 00:01:59,000 +All they're going to see is a token, that string of characters that you see at the top of the screen. + +39 +00:02:00,000 --> 00:02:02,000 +And for you guys, it'll be over here somewhere. + +40 +00:02:03,000 --> 00:02:04,000 +That string is a token. + +41 +00:02:04,000 --> 00:02:07,000 +Now, that token represents payment to Best Buy. + +42 +00:02:07,000 --> 00:02:15,000 +That token means that tomorrow morning or whenever PayPal is going to pay, PayPal will then pay Best + +43 +00:02:15,000 --> 00:02:15,000 +Buy. + +44 +00:02:15,000 --> 00:02:17,000 +The token represents money to them. + +45 +00:02:18,000 --> 00:02:22,000 +Now that's what tokenization is all about. + +46 +00:02:22,000 --> 00:02:31,000 +So tokenization is a process of substituting sensitive data with non-sensitive data equivalents, known + +47 +00:02:31,000 --> 00:02:38,000 +as tokens that have no real value to it or exploitable meaning or value. + +48 +00:02:38,000 --> 00:02:42,000 +In other words, if I just give you the token, there's not much you can do with this token. + +49 +00:02:42,000 --> 00:02:46,000 +This token is pretty useless to you except to the person who gave you the token. + +50 +00:02:46,000 --> 00:02:49,000 +That person papal, who gave BestBuy the token. + +51 +00:02:49,000 --> 00:02:55,000 +They know that that token means I got to pay Best Buy 500 because I charge Andrew 500. + +52 +00:02:55,000 --> 00:02:57,000 +That's what it means. + +53 +00:02:57,000 --> 00:03:03,000 +The primary purpose of tokenization is to safeguard sensitive data while maintaining its usability for + +54 +00:03:03,000 --> 00:03:05,000 +certain processes or application. + +55 +00:03:06,000 --> 00:03:08,000 +That is his whole point. + +56 +00:03:08,000 --> 00:03:11,000 +It's safeguarding the sensitive data, my credit card data. + +57 +00:03:11,000 --> 00:03:18,000 +Its basic principle is that in tokenization, sensitive data are basically replaced with randomly generated + +58 +00:03:18,000 --> 00:03:18,000 +tokens. + +59 +00:03:19,000 --> 00:03:21,000 +And then those things are referenced. + +60 +00:03:21,000 --> 00:03:26,000 +So the reference mechanism, the actual sensitive data is stored securely on the token servers. + +61 +00:03:26,000 --> 00:03:28,000 +That's going to be on PayPal. + +62 +00:03:28,000 --> 00:03:31,000 +So we expect PayPal to secure our information. + +63 +00:03:31,000 --> 00:03:34,000 +So this is the concept of tokenization. + +64 +00:03:35,000 --> 00:03:42,000 +Now I want to show you guys a process that I got from Wikipedia. + +65 +00:03:42,000 --> 00:03:46,000 +I think it's really good to to review it, something a little bit more complex, something that we're + +66 +00:03:46,000 --> 00:03:48,000 +going to be dealing a lot with in real life. + +67 +00:03:50,000 --> 00:03:56,000 +So let's take a look at this big process that we have here. + +68 +00:03:56,000 --> 00:03:59,000 +This is tokenization from Wikipedia. + +69 +00:03:59,000 --> 00:04:00,000 +This is the. + +70 +00:04:01,000 --> 00:04:06,000 +The picture that they have, and you're going to see how we're going to use a token server to replace + +71 +00:04:06,000 --> 00:04:07,000 +our credit card. + +72 +00:04:07,000 --> 00:04:11,000 +So no one gets a credit card, and all we're doing is giving them a token. + +73 +00:04:11,000 --> 00:04:11,000 +Okay. + +74 +00:04:11,000 --> 00:04:13,000 +So we have what's called a remote token server. + +75 +00:04:13,000 --> 00:04:16,000 +This is going to be the person like PayPal. + +76 +00:04:16,000 --> 00:04:16,000 +All right. + +77 +00:04:16,000 --> 00:04:18,000 +This is like PayPal address. + +78 +00:04:18,000 --> 00:04:19,000 +So here's what you do. + +79 +00:04:19,000 --> 00:04:23,000 +You tell them that you have a credit card and this is your credit card 1234. + +80 +00:04:23,000 --> 00:04:26,000 +You send your credit card number to the remote token server. + +81 +00:04:26,000 --> 00:04:28,000 +The token server then gives you a token. + +82 +00:04:29,000 --> 00:04:30,000 +Now the token looks like a credit card. + +83 +00:04:30,000 --> 00:04:32,000 +It basically ends in 2819. + +84 +00:04:33,000 --> 00:04:36,000 +You want to go shopping, so you go shopping. + +85 +00:04:37,000 --> 00:04:43,000 +You tell the merchant, hey, I want to buy this thing for $10, and I want to be paying with 2819. + +86 +00:04:43,000 --> 00:04:45,000 +So you basically tell them that. + +87 +00:04:46,000 --> 00:04:51,000 +Now you say, can you process this credit card for 2.819 at $10? + +88 +00:04:51,000 --> 00:04:56,000 +The merchant is doing this right, so the merchant knows okay, you're going to be using a this token + +89 +00:04:56,000 --> 00:04:58,000 +so the merchant doesn't know your credit card. + +90 +00:04:58,000 --> 00:05:01,000 +So the merchant sends the request to the token server. + +91 +00:05:02,000 --> 00:05:06,000 +The token server knows that 2819 is the 12345 credit card. + +92 +00:05:06,000 --> 00:05:10,000 +It then builds that credit card and says yeah, yeah, that's all good. + +93 +00:05:10,000 --> 00:05:12,000 +Sends it back to the merchant. + +94 +00:05:12,000 --> 00:05:13,000 +Says, yeah, it's all good. + +95 +00:05:13,000 --> 00:05:15,000 +Send them the send them the goods. + +96 +00:05:15,000 --> 00:05:17,000 +And then it tells you on your app, you know what? + +97 +00:05:17,000 --> 00:05:20,000 +Hey, you just paid for pizza or whatever Ellen and you were doing. + +98 +00:05:22,000 --> 00:05:24,000 +That is a process of tokenization. + +99 +00:05:24,000 --> 00:05:25,000 +Tokenization is very important. + +100 +00:05:25,000 --> 00:05:33,000 +Tokenization allows us to use our sensitive data all over the world without actually using our sensitive + +101 +00:05:33,000 --> 00:05:34,000 +data. + +102 +00:05:34,000 --> 00:05:40,000 +It allows us to give out sensitive data to merchants that we don't really know without actually giving + +103 +00:05:40,000 --> 00:05:40,000 +them. + +104 +00:05:40,000 --> 00:05:43,000 +I'll give you guys a quick tip. + +105 +00:05:43,000 --> 00:05:46,000 +I know this is a security class, but here's a quick tip. + +106 +00:05:46,000 --> 00:05:52,000 +Personally speaking, any time you go to a website that supports PayPal, use it. + +107 +00:05:53,000 --> 00:05:58,000 +The reason is because I like PayPal checkouts, because then I don't have to give a billion people my + +108 +00:05:58,000 --> 00:05:59,000 +credit card, right? + +109 +00:05:59,000 --> 00:06:06,000 +The the less people that have my credit card, the less likely it gets compromised in some kind of data + +110 +00:06:06,000 --> 00:06:07,000 +leak. + +111 +00:06:07,000 --> 00:06:12,000 +Massive vendors, best Buy, higher hotels, different banks. + +112 +00:06:12,000 --> 00:06:16,000 +Every week on some news you hear, some company got hacked and their credit they lost their credit card. + +113 +00:06:16,000 --> 00:06:19,000 +The best thing you can do is use the token man. + +114 +00:06:19,000 --> 00:06:20,000 +Just let it go with PayPal. + +115 +00:06:20,000 --> 00:06:26,000 +That way you only have to worry about one company being hacked PayPal versus 100 other companies. + +116 +00:06:26,000 --> 00:06:28,000 +And yeah, that is what tokenization. + +117 +00:06:28,000 --> 00:06:34,000 +I highly recommend you use it because it allows us to basically to have our sensitive data out there + +118 +00:06:34,000 --> 00:06:36,000 +without it actually being out there. + diff --git a/07 - Cryptography/028 Key Escrow OB 1.4_en.srt b/07 - Cryptography/028 Key Escrow OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..d0724b825f0558773a5cd51b24107612f3d2341a --- /dev/null +++ b/07 - Cryptography/028 Key Escrow OB 1.4_en.srt @@ -0,0 +1,140 @@ +1 +00:00:00,000 --> 00:00:06,000 +When doing business with certain government agencies, they may require you to escrow the cryptographic + +2 +00:00:06,000 --> 00:00:12,000 +keys, and on the certain scenarios, they'll be able to get these cryptographic keys. + +3 +00:00:12,000 --> 00:00:14,000 +What exactly is this? + +4 +00:00:14,000 --> 00:00:16,000 +Well, this is called a key escrow. + +5 +00:00:16,000 --> 00:00:23,000 +Key escrow, like it basically says, is when you escrow or you put your cryptographic keys into third + +6 +00:00:23,000 --> 00:00:24,000 +party entities. + +7 +00:00:24,000 --> 00:00:30,000 +So it's when cryptographic keys are stored securely so that under certain conditions, a third party + +8 +00:00:30,000 --> 00:00:31,000 +can access them. + +9 +00:00:31,000 --> 00:00:36,000 +Now this arrangement is often used to facilitate data recovery, compliance with law enforcement requests, + +10 +00:00:36,000 --> 00:00:38,000 +or maintain business continuity. + +11 +00:00:38,000 --> 00:00:40,000 +Let's talk a little bit about this. + +12 +00:00:40,000 --> 00:00:41,000 +So. + +13 +00:00:42,000 --> 00:00:48,000 +Let's say you go and you are doing storing manipulating data for the NSA. + +14 +00:00:48,000 --> 00:00:53,000 +The NSA may require you to have a key escrow set up. + +15 +00:00:53,000 --> 00:01:00,000 +What that means is that the encryption keys that you're using to encrypt the data that the NSA is relying + +16 +00:01:00,000 --> 00:01:06,000 +you for, for you to be using for them, they want you to store that in a third party entity, because + +17 +00:01:06,000 --> 00:01:12,000 +if you go out of business, you get hacked, your company goes down all the systems, something goes + +18 +00:01:12,000 --> 00:01:13,000 +wrong with it. + +19 +00:01:13,000 --> 00:01:14,000 +They'll need their data back. + +20 +00:01:14,000 --> 00:01:16,000 +They'll it's their data. + +21 +00:01:16,000 --> 00:01:18,000 +How are they going to get the encryption keys? + +22 +00:01:18,000 --> 00:01:20,000 +Will you manage the company? + +23 +00:01:20,000 --> 00:01:24,000 +And you don't want to give them the encryption keys because it's it's your company, it's your service. + +24 +00:01:24,000 --> 00:01:26,000 +But now your company is gone. + +25 +00:01:26,000 --> 00:01:30,000 +There's really no way to get it back unless it was stored with a third party entity. + +26 +00:01:30,000 --> 00:01:36,000 +That third party entity can then give the NSA, and it's going to be by all contractual methods. + +27 +00:01:37,000 --> 00:01:41,000 +It has to be something in a contract between you and the NSA that under under these circumstances, + +28 +00:01:41,000 --> 00:01:47,000 +like me going out of business that you can be in, the NSA can get the keys. + +29 +00:01:47,000 --> 00:01:52,000 +So the NSA goes to a judge, gets the order. + +30 +00:01:52,000 --> 00:01:54,000 +The judge then tells them, hey, okay, you go and get the keys. + +31 +00:01:54,000 --> 00:01:57,000 +They go to the third party entity that's storing the keys. + +32 +00:01:57,000 --> 00:01:58,000 +They get the keys to decrypt the data. + +33 +00:01:58,000 --> 00:02:00,000 +So that's where key escrow comes in. + +34 +00:02:02,000 --> 00:02:08,000 +It is not something that is very common in the world of security, but in certain application development, + +35 +00:02:08,000 --> 00:02:14,000 +data storage, data processing, key escrow is quite famous in those kinds of things. + diff --git a/07 - Cryptography/029 HSM OB 1.4_en.srt b/07 - Cryptography/029 HSM OB 1.4_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..8b9277a7cdbc65d1fe0f4f840f995f3ca48e89d1 --- /dev/null +++ b/07 - Cryptography/029 HSM OB 1.4_en.srt @@ -0,0 +1,356 @@ +1 +00:00:00,000 --> 00:00:04,000 +When it comes to cryptography, computers don't like doing them. + +2 +00:00:04,000 --> 00:00:11,000 +The reason is because cryptography is very, very taxing or resource intensive on your processor and + +3 +00:00:11,000 --> 00:00:14,000 +of course storing all that stuff in your memory. + +4 +00:00:14,000 --> 00:00:23,000 +But what if I told you that I can get a dedicated device, that you can offload all the generation of + +5 +00:00:23,000 --> 00:00:25,000 +your cryptographic processing to? + +6 +00:00:26,000 --> 00:00:35,000 +This device in particular, is known as a hardware security module, so you can go and purchase. + +7 +00:00:36,000 --> 00:00:43,000 +Something like a PCI, PCI card or a dedicated device like this that you can attach to your network. + +8 +00:00:43,000 --> 00:00:47,000 +And what this thing does is that it offloads all of your web servers. + +9 +00:00:47,000 --> 00:00:51,000 +They don't have to be managing generating all those encryption keys. + +10 +00:00:51,000 --> 00:00:58,000 +So it's a physical or cloud device that provides secure cryptographic processing that includes key generation, + +11 +00:00:58,000 --> 00:01:01,000 +storage, encryption and decryption services. + +12 +00:01:01,000 --> 00:01:07,000 +So what this is going to do, is it really offloading all the cryptographic processes to a device that + +13 +00:01:07,000 --> 00:01:11,000 +has what is called a quote unquote crypto processor? + +14 +00:01:11,000 --> 00:01:20,000 +It's basically a CPU that's designed to do the processes of encryption, generating and generating keys, + +15 +00:01:20,000 --> 00:01:23,000 +uh, destroying keys, encrypting and decrypting now. + +16 +00:01:24,000 --> 00:01:30,000 +It's going to do things like specific cryptographic operation, encryption decryption, digital signing, + +17 +00:01:30,000 --> 00:01:32,000 +key generation, key management. + +18 +00:01:32,000 --> 00:01:37,000 +It provides a good secure environment for this for the entire life cycle of encryption. + +19 +00:01:37,000 --> 00:01:43,000 +Now, I mentioned once again that you could get this thing in a physical format. + +20 +00:01:43,000 --> 00:01:49,000 +You could get it as a type of a PCIe card, or you could get it as a type of a device. + +21 +00:01:50,000 --> 00:01:54,000 +Now newer is going to be a cloud based HSM. + +22 +00:01:54,000 --> 00:02:01,000 +So I want to just I gave you guys a link there to Amazon's cloud based HSM that I want to show you guys. + +23 +00:02:01,000 --> 00:02:02,000 +And I want you guys to take a look at this. + +24 +00:02:02,000 --> 00:02:05,000 +So this is the link you just have on the slide there. + +25 +00:02:06,000 --> 00:02:08,000 +So here's your cloud HSM. + +26 +00:02:08,000 --> 00:02:15,000 +And this is Amazon selling their hardware security module on AWS. + +27 +00:02:15,000 --> 00:02:16,000 +And what is this thing going to do. + +28 +00:02:16,000 --> 00:02:21,000 +Well generate and use cryptographic keys on a dedicated. + +29 +00:02:21,000 --> 00:02:28,000 +And I want to talk about this Fips 142 level three single tenant HSM instance. + +30 +00:02:29,000 --> 00:02:32,000 +Now what this is saying is that this thing is very secure. + +31 +00:02:32,000 --> 00:02:34,000 +It's level three secure. + +32 +00:02:34,000 --> 00:02:35,000 +We'll cover that in a minute. + +33 +00:02:35,000 --> 00:02:42,000 +But now you can do it in the cloud instead of having a dedicated device, do it for you. + +34 +00:02:44,000 --> 00:02:50,000 +Notice that Amazon said something about Phipps. + +35 +00:02:50,000 --> 00:02:52,000 +What exactly is that? + +36 +00:02:52,000 --> 00:02:56,000 +Well, I want to talk about that in this video, and I want to show you the levels that it comes in. + +37 +00:02:56,000 --> 00:03:04,000 +So these cryptographic modules, these hsms, uh, are rated by a certain level. + +38 +00:03:04,000 --> 00:03:13,000 +And that comes from an this standard called Fips or the Federal Information Processing Standard Dash + +39 +00:03:13,000 --> 00:03:13,000 +two. + +40 +00:03:13,000 --> 00:03:19,000 +This is developed by NIST and it specifies requirements for cryptographic modules used within federal + +41 +00:03:19,000 --> 00:03:20,000 +systems. + +42 +00:03:20,000 --> 00:03:25,000 +Now if you remember the old saying, what's good enough for the government is good enough for me. + +43 +00:03:25,000 --> 00:03:28,000 +So the government gives these things particular rating. + +44 +00:03:28,000 --> 00:03:30,000 +Now we notice Amazon was a three. + +45 +00:03:30,000 --> 00:03:32,000 +Let's go over them quickly. + +46 +00:03:32,000 --> 00:03:34,000 +I want you guys for your exam. + +47 +00:03:34,000 --> 00:03:39,000 +Be familiar with these levels but don't memorize all the text I have here. + +48 +00:03:39,000 --> 00:03:41,000 +I just put a lot of additional information. + +49 +00:03:41,000 --> 00:03:45,000 +Just know that the higher the level, the more secure it is. + +50 +00:03:45,000 --> 00:03:46,000 +All right let's talk about this. + +51 +00:03:46,000 --> 00:03:50,000 +So level one is just basic protection of the cryptographic module. + +52 +00:03:50,000 --> 00:03:56,000 +There's no physical security mechanism that secures the cryptographic module the actual device itself. + +53 +00:03:56,000 --> 00:04:03,000 +In fact it depends on the physical security external to the device, such as security guards and windows + +54 +00:04:03,000 --> 00:04:07,000 +and locks, the building and so on to secure the actual device. + +55 +00:04:08,000 --> 00:04:17,000 +Level two adds more physical notice, tamper evident, uh, tamper evidence and role based authentication, + +56 +00:04:17,000 --> 00:04:19,000 +so it's harder to get into. + +57 +00:04:20,000 --> 00:04:23,000 +If somebody tries to tamper with it, we'll be able to detect that. + +58 +00:04:23,000 --> 00:04:25,000 +So it requires tamper. + +59 +00:04:25,000 --> 00:04:26,000 +Physical tamper evidence. + +60 +00:04:26,000 --> 00:04:32,000 +That means any attempt to break into the device and steal whatever the memory chips that are there, + +61 +00:04:32,000 --> 00:04:38,000 +you'll be able to detect that this is going to be for environments where more security is needed, but + +62 +00:04:38,000 --> 00:04:41,000 +you still have physical security in the environment. + +63 +00:04:41,000 --> 00:04:45,000 +This one here, this one is all about physical security in the environment. + +64 +00:04:46,000 --> 00:04:49,000 +When it comes to level three, this is much more robust. + +65 +00:04:49,000 --> 00:04:56,000 +This is stronger physical security measure that prevent the intrusion to gain an access to the critical + +66 +00:04:56,000 --> 00:04:58,000 +security perimeters within the module. + +67 +00:04:58,000 --> 00:05:01,000 +So this one has good physical security of the physical device. + +68 +00:05:01,000 --> 00:05:06,000 +You shouldn't just be able to open it that easily requires full, strong physical security to prevent + +69 +00:05:06,000 --> 00:05:08,000 +unauthorized access. + +70 +00:05:08,000 --> 00:05:14,000 +This is going to be used for high secure environments where it's necessary to tor physical attempts + +71 +00:05:14,000 --> 00:05:16,000 +to the cryptographic modules themselves. + +72 +00:05:17,000 --> 00:05:19,000 +Level four is a whole different thing. + +73 +00:05:19,000 --> 00:05:20,000 +Notice that this is Amazon. + +74 +00:05:20,000 --> 00:05:22,000 +This is where our consumer grade is. + +75 +00:05:23,000 --> 00:05:31,000 +If you're going to take these devices, um, and you're going to be using them on the battlefield of + +76 +00:05:31,000 --> 00:05:33,000 +war, that's a level four. + +77 +00:05:33,000 --> 00:05:40,000 +This in addition to three level four is complete physical isolation, high degree of tamper responses. + +78 +00:05:40,000 --> 00:05:47,000 +It's ideal for environment where we're extremely high levels of security are required hostile operating + +79 +00:05:47,000 --> 00:05:49,000 +conditions like on a battlefield. + +80 +00:05:50,000 --> 00:05:51,000 +Okay. + +81 +00:05:51,000 --> 00:05:56,000 +Just remember, the higher the number, the more secure it is at level one. + +82 +00:05:56,000 --> 00:05:58,000 +You got to make sure you have good physical security. + +83 +00:05:58,000 --> 00:06:03,000 +At level two, you got to make sure that if anybody breaks in, you can tell into the device the need + +84 +00:06:03,000 --> 00:06:04,000 +good physical security. + +85 +00:06:04,000 --> 00:06:12,000 +Level three, super strong, uh, ability to stop physical intrusion into the device. + +86 +00:06:12,000 --> 00:06:17,000 +And level four, it's just stronger that can operate in hostile environments. + +87 +00:06:17,000 --> 00:06:18,000 +Okay. + +88 +00:06:18,000 --> 00:06:21,000 +Make sure you know what a hardware security module is. + +89 +00:06:21,000 --> 00:06:26,000 +And if you find that cryptography is slowing down your machine, maybe it's time to get one. + diff --git a/07 - Cryptography/030 Quick Quiz.html b/07 - Cryptography/030 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..47ec2488c3c72653b4dd73decce08e3aa00e3d00 --- /dev/null +++ b/07 - Cryptography/030 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/08 - Social Engineering/001 Social Engineering OB 2.2_en.srt b/08 - Social Engineering/001 Social Engineering OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..88f561831f046a68aa3399d74ed74f5f990e5db4 --- /dev/null +++ b/08 - Social Engineering/001 Social Engineering OB 2.2_en.srt @@ -0,0 +1,172 @@ +1 +00:00:00,000 --> 00:00:09,000 +If there's one aspect when it comes to it security that is overlooked a lot in IT security or information + +2 +00:00:09,000 --> 00:00:09,000 +technology. + +3 +00:00:09,000 --> 00:00:11,000 +Security is human. + +4 +00:00:11,000 --> 00:00:18,000 +Interaction is the ability to compromise people and then compromise the system. + +5 +00:00:18,000 --> 00:00:23,000 +In this section, we're going to start the discussion of social engineering. + +6 +00:00:23,000 --> 00:00:23,000 +All right. + +7 +00:00:23,000 --> 00:00:28,000 +And there's a variety of different techniques that we're going to be discussing about in this section. + +8 +00:00:28,000 --> 00:00:34,000 +Now before I get started in it, I really want to just say a couple of words. + +9 +00:00:34,000 --> 00:00:35,000 +And that's going to be. + +10 +00:00:36,000 --> 00:00:41,000 +In the world of security, your weakest link is not your firewall. + +11 +00:00:41,000 --> 00:00:46,000 +It's not going to be that file server with permissions, your or your encryption algorithm, your IDs + +12 +00:00:46,000 --> 00:00:48,000 +systems, your Windows server. + +13 +00:00:48,000 --> 00:00:52,000 +The weakest link in security are these two guys. + +14 +00:00:52,000 --> 00:00:53,000 +People. + +15 +00:00:53,000 --> 00:00:58,000 +People are the weakest link in security. + +16 +00:00:58,000 --> 00:01:00,000 +So what exactly is social engineering? + +17 +00:01:00,000 --> 00:01:03,000 +Well, since we know people can be manipulated. + +18 +00:01:03,000 --> 00:01:08,000 +Social engineering is a range of malicious activities accomplished through human interaction. + +19 +00:01:08,000 --> 00:01:15,000 +It involves tricking people into breaking normal security procedures and best practices to gain unauthorized + +20 +00:01:15,000 --> 00:01:21,000 +access to systems, networks, physical locations, or for some kind of financial gain. + +21 +00:01:21,000 --> 00:01:25,000 +Now you guys got to remember something about people. + +22 +00:01:25,000 --> 00:01:32,000 +You see, if you think about this, when you look at it, security and you look at like a firewall, + +23 +00:01:32,000 --> 00:01:33,000 +you see this firewall. + +24 +00:01:33,000 --> 00:01:41,000 +If this firewall is configured for something like blocking a port, no matter what I tell it. + +25 +00:01:41,000 --> 00:01:44,000 +Hello, firewall, can you unblock that port? + +26 +00:01:44,000 --> 00:01:46,000 +It's not going to unblock the port because I talked to it. + +27 +00:01:47,000 --> 00:01:48,000 +Okay. + +28 +00:01:48,000 --> 00:01:54,000 +I would have to find some kind of vulnerability, technical vulnerability against it in order to beat + +29 +00:01:54,000 --> 00:01:54,000 +it. + +30 +00:01:54,000 --> 00:01:57,000 +And that's where it becomes difficult. + +31 +00:01:57,000 --> 00:02:05,000 +So that's why most hackers, a lot of great hackers, will not try to break through your firewall, + +32 +00:02:05,000 --> 00:02:08,000 +but they'll try to break through your people. + +33 +00:02:08,000 --> 00:02:11,000 +People can be manipulated. + +34 +00:02:11,000 --> 00:02:18,000 +People can be easily manipulated, not just manipulated, depending on who that person is. + +35 +00:02:18,000 --> 00:02:24,000 +I always say this to people managing information technology systems, security managers. + +36 +00:02:24,000 --> 00:02:31,000 +You are as strong as your weakest employee or your strongest, your weakest link, your weakest link + +37 +00:02:31,000 --> 00:02:32,000 +being people. + +38 +00:02:32,000 --> 00:02:36,000 +And if you have someone that's easily compromised, someone where I can just call and say, hey, I'm + +39 +00:02:36,000 --> 00:02:38,000 +Andrew from the help desk, can you give me your password? + +40 +00:02:38,000 --> 00:02:38,000 +And they give it. + +41 +00:02:38,000 --> 00:02:41,000 +That's as strong as your entire security system. + +42 +00:02:41,000 --> 00:02:48,000 +So let's get started and look at different social engineering tactics that they can use against your + +43 +00:02:48,000 --> 00:02:49,000 +folks at work. + diff --git a/08 - Social Engineering/002 Phishing OB 2.2_en.srt b/08 - Social Engineering/002 Phishing OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..77ca17594a81a52056a63b21f72b50f91e5756ea --- /dev/null +++ b/08 - Social Engineering/002 Phishing OB 2.2_en.srt @@ -0,0 +1,276 @@ +1 +00:00:00,000 --> 00:00:04,000 +Imagine sitting at your computer and you just received an email. + +2 +00:00:04,000 --> 00:00:11,000 +In the email, it says that it's from your local Social Security Administration, and someone has compromised + +3 +00:00:11,000 --> 00:00:13,000 +your Social Security number. + +4 +00:00:13,000 --> 00:00:18,000 +So you click on a link and it takes you to what looks like the Social Security website looks exactly + +5 +00:00:18,000 --> 00:00:18,000 +like. + +6 +00:00:18,000 --> 00:00:20,000 +It is basically a mirror of the site. + +7 +00:00:20,000 --> 00:00:25,000 +It then tells you to enter the current social security number and addresses you have for you to for + +8 +00:00:25,000 --> 00:00:29,000 +them to pull up the case so you can resolve your Social Security problem. + +9 +00:00:30,000 --> 00:00:35,000 +Now, if this sounds weird, this is an actual attack that did occur a long time ago. + +10 +00:00:35,000 --> 00:00:40,000 +Now, this particular kind of attack is called phishing attacks. + +11 +00:00:40,000 --> 00:00:43,000 +Phishing attacks is a form of a social engineering. + +12 +00:00:43,000 --> 00:00:49,000 +It's basically when they attempt to trick you or trick an individual into providing sensitive information + +13 +00:00:49,000 --> 00:00:52,000 +by masquerading as some kind of trustworthy entity. + +14 +00:00:53,000 --> 00:00:59,000 +Imagine getting an email from Microsoft stating that you need to log in to your Microsoft account because + +15 +00:00:59,000 --> 00:01:00,000 +somebody has hacked the account. + +16 +00:01:00,000 --> 00:01:07,000 +So when you click the link to log in and you log in, they basically steal your username and password. + +17 +00:01:07,000 --> 00:01:09,000 +Imagine you get an email from PayPal. + +18 +00:01:09,000 --> 00:01:15,000 +This was famous that saying that the PayPal account has been compromised to log into the PayPal account. + +19 +00:01:15,000 --> 00:01:17,000 +And then you they give you the link. + +20 +00:01:17,000 --> 00:01:19,000 +So you click to log in to the PayPal account. + +21 +00:01:19,000 --> 00:01:23,000 +And the moment they and the moment you do that, it steals the username and password. + +22 +00:01:24,000 --> 00:01:30,000 +This is generally carried out through email, but phishing can occur using text messages, social media, + +23 +00:01:30,000 --> 00:01:31,000 +and even phone calls. + +24 +00:01:31,000 --> 00:01:32,000 +Now. + +25 +00:01:34,000 --> 00:01:36,000 +What is it that they're trying to do? + +26 +00:01:36,000 --> 00:01:40,000 +For example, with the PayPal thing, it's all about stealing your credential. + +27 +00:01:40,000 --> 00:01:43,000 +They can also do this to steal financial information. + +28 +00:01:43,000 --> 00:01:46,000 +They can also tell you to click on a particular link. + +29 +00:01:46,000 --> 00:01:50,000 +They want you to click on to install malware or even your private information. + +30 +00:01:50,000 --> 00:01:55,000 +You're going to steal things like your name, your address, social security number and so on. + +31 +00:01:55,000 --> 00:01:57,000 +Now these are generally phishing. + +32 +00:01:57,000 --> 00:02:02,000 +Fishing is incredibly popular, and I'm pretty sure you're probably all familiar with that crazy email + +33 +00:02:02,000 --> 00:02:03,000 +you get. + +34 +00:02:03,000 --> 00:02:06,000 +They want you to click on this link so you can log in somewhere. + +35 +00:02:06,000 --> 00:02:08,000 +How do you stop this? + +36 +00:02:08,000 --> 00:02:16,000 +Well, the best way to stop social engineering is, without a doubt, almost always user education. + +37 +00:02:16,000 --> 00:02:22,000 +Train the users to detect different kinds of social engineering attacks. + +38 +00:02:22,000 --> 00:02:27,000 +For example, if they get an email that looks like it's coming from the help desk, teach them. + +39 +00:02:27,000 --> 00:02:31,000 +Don't click on any links, call the help desk and verify that they actually sent it. + +40 +00:02:32,000 --> 00:02:37,000 +Another great thing is if you can't trust your users, because they might be all kinds of new attacks + +41 +00:02:37,000 --> 00:02:38,000 +that you may not be able to come up with. + +42 +00:02:38,000 --> 00:02:44,000 +You do email filtering, filter out potentially bad emails. + +43 +00:02:44,000 --> 00:02:48,000 +You can use all kinds of email corporate email software for this. + +44 +00:02:48,000 --> 00:02:53,000 +Another great thing that I think all of us should have on our computers is multi factor or two factor, + +45 +00:02:53,000 --> 00:02:58,000 +at least MFA or two for multi factor or two factor authentication things such as. + +46 +00:02:58,000 --> 00:03:04,000 +If I log in to your account you're going to have to um, going to have to put provide a password and + +47 +00:03:04,000 --> 00:03:07,000 +a smart card or some kind of biometrics that goes along with it. + +48 +00:03:07,000 --> 00:03:12,000 +This is important because if they do steal your credential, your password, they won't be able to log + +49 +00:03:12,000 --> 00:03:15,000 +in without that second factor authentication. + +50 +00:03:15,000 --> 00:03:19,000 +And the other thing here you want to do is have good incident responses. + +51 +00:03:19,000 --> 00:03:26,000 +If something does occur and somebody's credential does get compromised or identity gets compromised, + +52 +00:03:26,000 --> 00:03:30,000 +it is super important that there is an incident response team that comes out and responds to this incident + +53 +00:03:30,000 --> 00:03:31,000 +quickly. + +54 +00:03:31,000 --> 00:03:35,000 +If not, the company data could be stolen very fast or they can steal more of it. + +55 +00:03:36,000 --> 00:03:40,000 +I can't emphasize this enough, but this is a technology based course. + +56 +00:03:40,000 --> 00:03:42,000 +I'm not going to spend a lot of time on this particular thing. + +57 +00:03:42,000 --> 00:03:47,000 +You just need to know what it is for your exam and some of the steps I mentioned how to stop it. + +58 +00:03:47,000 --> 00:03:53,000 +But in the real world of information security, phishing is incredibly, incredibly common. + +59 +00:03:53,000 --> 00:04:02,000 +In fact, on a daily basis, I personally will receive about 5 to 10 phishing emails, something from + +60 +00:04:02,000 --> 00:04:08,000 +Best Buy that I need to review my antivirus or something from Geeksquad, something from PayPal, something + +61 +00:04:08,000 --> 00:04:09,000 +from some banking website. + +62 +00:04:09,000 --> 00:04:12,000 +It is incredibly common to get phishing. + +63 +00:04:12,000 --> 00:04:19,000 +I am telling you guys, there were points in my life where some of those emails had me thinking, I'm + +64 +00:04:19,000 --> 00:04:24,000 +not going to get into it, but one time I did click on a link which I believed was valid and the machine + +65 +00:04:24,000 --> 00:04:27,000 +got malware infected. + +66 +00:04:27,000 --> 00:04:32,000 +I'm not going to get into the specifics of it, but if I can get caught with something that is very + +67 +00:04:32,000 --> 00:04:34,000 +particular, it's actually a spear phishing attack. + +68 +00:04:35,000 --> 00:04:38,000 +Uh, if I can get caught on a phishing attack, so can anyone. + +69 +00:04:38,000 --> 00:04:41,000 +So be careful out there on the internet and make sure to train your users. + diff --git a/08 - Social Engineering/003 Vishing OB 2.2_en.srt b/08 - Social Engineering/003 Vishing OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f7b6a22f4e6e56c5c9fa75a9966e4827ff92c196 --- /dev/null +++ b/08 - Social Engineering/003 Vishing OB 2.2_en.srt @@ -0,0 +1,352 @@ +1 +00:00:00,000 --> 00:00:03,000 +One day you're sitting down in the couch watching some TV. + +2 +00:00:03,000 --> 00:00:06,000 +You look at your phone, the bank is calling. + +3 +00:00:06,000 --> 00:00:08,000 +It says Chase Bank on it. + +4 +00:00:08,000 --> 00:00:11,000 +You pick up the phone and Chase Bank says your account has been compromised. + +5 +00:00:11,000 --> 00:00:14,000 +Somebody has withdraw all the money from your account. + +6 +00:00:14,000 --> 00:00:17,000 +You say, oh, crap, what's going to happen now? + +7 +00:00:17,000 --> 00:00:22,000 +They say, okay, let me have the last four digits of your Social Security number so they can authenticate + +8 +00:00:22,000 --> 00:00:25,000 +your account, or they may ask the entire Social Security number. + +9 +00:00:25,000 --> 00:00:28,000 +You give it to them, and then the phone hangs up. + +10 +00:00:28,000 --> 00:00:29,000 +Hmm. + +11 +00:00:29,000 --> 00:00:30,000 +What just happened there? + +12 +00:00:30,000 --> 00:00:36,000 +So you call back the number that was on the phone, and then you realize that this number is going nowhere. + +13 +00:00:36,000 --> 00:00:38,000 +In fact, the number is disconnected. + +14 +00:00:38,000 --> 00:00:40,000 +So you call Chase Bank and you ask Chase Bank. + +15 +00:00:40,000 --> 00:00:41,000 +Hey, did you do this? + +16 +00:00:41,000 --> 00:00:43,000 +And Chase Bank says nothing wrong with your account. + +17 +00:00:45,000 --> 00:00:50,000 +Time goes by and you realize a few days later your bank account is actually empty. + +18 +00:00:50,000 --> 00:00:53,000 +Somebody did actually take money out of your account. + +19 +00:00:53,000 --> 00:00:56,000 +This is not an uncommon scenario. + +20 +00:00:56,000 --> 00:01:00,000 +What I just told you there really does occur on a daily basis. + +21 +00:01:00,000 --> 00:01:03,000 +You see, the attack I'm talking about is called vision. + +22 +00:01:03,000 --> 00:01:08,000 +It's a form of vision, but it basically utilizes voice through the phone. + +23 +00:01:08,000 --> 00:01:11,000 +Vision is basically voice vision. + +24 +00:01:12,000 --> 00:01:17,000 +So when they use phone calls to impersonate trusted entities or organization with the goal of manipulating + +25 +00:01:17,000 --> 00:01:22,000 +you into giving them sensitive information, remember the part in the scenario where you gave them the + +26 +00:01:22,000 --> 00:01:23,000 +last four digits of your Social Security number? + +27 +00:01:23,000 --> 00:01:26,000 +Well, generally, if you call the bank, they're going to ask you for that. + +28 +00:01:26,000 --> 00:01:27,000 +They generally don't ask you the full thing. + +29 +00:01:27,000 --> 00:01:31,000 +They may say, give me the last four digits or give me the last four digits of the card or something + +30 +00:01:31,000 --> 00:01:34,000 +like that to authenticate you, but you gave it to them. + +31 +00:01:34,000 --> 00:01:37,000 +They were able to then call the bank as you and take your money. + +32 +00:01:37,000 --> 00:01:41,000 +So this is unlike phishing, which generally is like emails. + +33 +00:01:41,000 --> 00:01:44,000 +This one relies on spoken communications. + +34 +00:01:44,000 --> 00:01:47,000 +Now there's a couple of things that they're going to use. + +35 +00:01:47,000 --> 00:01:49,000 +Some of the main characteristics here. + +36 +00:01:49,000 --> 00:01:50,000 +They might make it urgent. + +37 +00:01:50,000 --> 00:01:53,000 +Notice they said that somebody stole all your money. + +38 +00:01:53,000 --> 00:01:56,000 +So it's really urgent that you talk to them right now. + +39 +00:01:57,000 --> 00:02:00,000 +They employ some kind of urgency or they may fear you. + +40 +00:02:00,000 --> 00:02:01,000 +They may say that, well. + +41 +00:02:02,000 --> 00:02:05,000 +The FBI or your tax return hasn't been filed. + +42 +00:02:05,000 --> 00:02:12,000 +You a lot of taxes and the tax authority is put a lien on your house and police is going to come pick + +43 +00:02:12,000 --> 00:02:13,000 +you up right away. + +44 +00:02:13,000 --> 00:02:16,000 +Intimidation and fear manipulating you to comply. + +45 +00:02:16,000 --> 00:02:17,000 +Right now. + +46 +00:02:17,000 --> 00:02:23,000 +Notice in this scenario, they wanted you to comply right away because your money was going to be gone. + +47 +00:02:24,000 --> 00:02:26,000 +They spoofed the caller ID when you got it. + +48 +00:02:26,000 --> 00:02:27,000 +It said Chase Bank on it. + +49 +00:02:27,000 --> 00:02:31,000 +They spoofed the caller I.D. to make it show that it was coming from Chase Bank. + +50 +00:02:31,000 --> 00:02:33,000 +Then they request sensitive information. + +51 +00:02:33,000 --> 00:02:35,000 +The last four digits of your Social Security number. + +52 +00:02:35,000 --> 00:02:38,000 +They may even ask for pins, passwords, credit card details, and so on. + +53 +00:02:38,000 --> 00:02:43,000 +Voice phishing is very, very effective depending on who you get on the phone. + +54 +00:02:43,000 --> 00:02:45,000 +So how do you fix it? + +55 +00:02:45,000 --> 00:02:51,000 +Well, the best way to fix it, I've always said, in any kind of social engineering attack is always + +56 +00:02:51,000 --> 00:02:54,000 +going to be education and training. + +57 +00:02:54,000 --> 00:02:56,000 +Tell people to detect this. + +58 +00:02:56,000 --> 00:03:03,000 +Unfortunately, a lot of people that are getting socially engineered or phishing attack against them + +59 +00:03:03,000 --> 00:03:05,000 +that are successful is a lot of elderly folks. + +60 +00:03:05,000 --> 00:03:10,000 +If there's one thing I did is I taught my mother because she is a pretty elderly person and they don't + +61 +00:03:10,000 --> 00:03:15,000 +really understand technology and what could be done with the information that they're given out. + +62 +00:03:15,000 --> 00:03:21,000 +So you have to educate them, not just your users, but educate family members, especially the elderly, + +63 +00:03:21,000 --> 00:03:26,000 +because they grew up in a time when this type of stuff didn't exist, to recognize various phishing + +64 +00:03:26,000 --> 00:03:33,000 +attempts and never, ever, ever, ever give out information over the phone with just somebody calling + +65 +00:03:33,000 --> 00:03:33,000 +you. + +66 +00:03:33,000 --> 00:03:41,000 +It's different if you go to the banking website, not by a link in an email, but actually go to chase.com, + +67 +00:03:41,000 --> 00:03:45,000 +find the phone number on chase.com and then call them. + +68 +00:03:45,000 --> 00:03:51,000 +That is a different scenario, not you receiving a call or some kind of email. + +69 +00:03:51,000 --> 00:03:52,000 +Have a verification. + +70 +00:03:52,000 --> 00:03:57,000 +Encourage recipients of phone calls to independently verify the identity of the person that they're + +71 +00:03:57,000 --> 00:03:57,000 +calling. + +72 +00:03:58,000 --> 00:03:59,000 +Callback known numbers. + +73 +00:03:59,000 --> 00:04:04,000 +For example, if you get a call and you believe, okay, it might be true, tell them, okay, how can + +74 +00:04:04,000 --> 00:04:05,000 +I know that this is Chase Bank? + +75 +00:04:06,000 --> 00:04:06,000 +You know what? + +76 +00:04:06,000 --> 00:04:09,000 +I'm going to give me some kind of if you believe it's true. + +77 +00:04:09,000 --> 00:04:13,000 +Once again, tell them, okay, give me a case number or something. + +78 +00:04:13,000 --> 00:04:17,000 +I'm going to hang up and I'm going to go to Chase, and I'm going to find the actual number of Chase. + +79 +00:04:17,000 --> 00:04:20,000 +I'm going to call and give them back that number to see if this is real. + +80 +00:04:20,000 --> 00:04:27,000 +Another thing is always try to use multifactor two factor authentication, use a Pin, a Pin, along + +81 +00:04:27,000 --> 00:04:31,000 +with like a bank card or some kind of biometrics with passwords and so on. + +82 +00:04:31,000 --> 00:04:34,000 +This adds that extra layer just in case you're compromised, just in case you're compromised. + +83 +00:04:34,000 --> 00:04:35,000 +Vision attempts. + +84 +00:04:35,000 --> 00:04:40,000 +There are hundreds, maybe thousands of phishing attacks going on, as I'm speaking to you just here + +85 +00:04:40,000 --> 00:04:41,000 +in the United States. + +86 +00:04:41,000 --> 00:04:44,000 +So keep in mind this is not something uncommon. + +87 +00:04:44,000 --> 00:04:45,000 +It's very common. + +88 +00:04:45,000 --> 00:04:48,000 +And believe it or not, it's actually pretty successful a lot of times. + diff --git a/08 - Social Engineering/004 Smishing OB 2.2_en.srt b/08 - Social Engineering/004 Smishing OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..498196fe3bf251bdd1ea08e0aecaa5d813c3f363 --- /dev/null +++ b/08 - Social Engineering/004 Smishing OB 2.2_en.srt @@ -0,0 +1,208 @@ +1 +00:00:01,000 --> 00:00:02,000 +Oh, man. + +2 +00:00:02,000 --> 00:00:03,000 +You know what? + +3 +00:00:03,000 --> 00:00:09,000 +I just got a text message on my phone that my account at Chase Bank has been compromised. + +4 +00:00:09,000 --> 00:00:11,000 +Let me just check out this text message. + +5 +00:00:11,000 --> 00:00:16,000 +Okay, so the text message has a link in it that it wants me to click on to log in to Chase Bank. + +6 +00:00:16,000 --> 00:00:16,000 +Let me do that. + +7 +00:00:17,000 --> 00:00:17,000 +Okay. + +8 +00:00:17,000 --> 00:00:22,000 +So I've clicked on the link and it wants me to, um, enter the Chase Bank username and password. + +9 +00:00:24,000 --> 00:00:25,000 +Let me check the URL. + +10 +00:00:25,000 --> 00:00:26,000 +Actually, you know what? + +11 +00:00:26,000 --> 00:00:28,000 +The URL doesn't really look like. + +12 +00:00:28,000 --> 00:00:29,000 +Chase. + +13 +00:00:29,000 --> 00:00:36,000 +This scenario in particularly is a form of phishing, but it's known as submission because what this + +14 +00:00:36,000 --> 00:00:42,000 +in this scenario, what the bad guys are doing is they're not utilizing voice like vision or some kind + +15 +00:00:42,000 --> 00:00:43,000 +of email. + +16 +00:00:43,000 --> 00:00:45,000 +They're actually just using SMS. + +17 +00:00:45,000 --> 00:00:47,000 +This is basically text messages. + +18 +00:00:47,000 --> 00:00:53,000 +So remember for your exam submission is when they use text messages or some kind of instant messaging + +19 +00:00:53,000 --> 00:00:56,000 +to the actual person's device. + +20 +00:00:56,000 --> 00:00:57,000 +Now. + +21 +00:00:57,000 --> 00:00:58,000 +What are they trying to do? + +22 +00:00:58,000 --> 00:01:04,000 +Well, it's going to be the primary like the same goal as they did in vision or in normal phishing with + +23 +00:01:04,000 --> 00:01:05,000 +an email. + +24 +00:01:05,000 --> 00:01:10,000 +So the primary goal is to manipulate you into disclosing sensitive information or taking action to compromise. + +25 +00:01:10,000 --> 00:01:11,000 +So. + +26 +00:01:11,000 --> 00:01:13,000 +They're trying to manipulate me. + +27 +00:01:13,000 --> 00:01:14,000 +They want me to take action. + +28 +00:01:14,000 --> 00:01:21,000 +So the first thing they want to do messages so they send these messages are designed to appear as if + +29 +00:01:21,000 --> 00:01:22,000 +they're from Chase Bank. + +30 +00:01:22,000 --> 00:01:23,000 +It looks like it was. + +31 +00:01:23,000 --> 00:01:26,000 +And it's urgent because my account was compromised. + +32 +00:01:26,000 --> 00:01:27,000 +And they want me to take a quick response. + +33 +00:01:27,000 --> 00:01:29,000 +They request information. + +34 +00:01:29,000 --> 00:01:34,000 +So when I clicked on the link, they then want me to put in my my username and my password. + +35 +00:01:34,000 --> 00:01:40,000 +Now attackers can manipulate the sender information to make it appear that it's coming from a trusted + +36 +00:01:40,000 --> 00:01:40,000 +source. + +37 +00:01:40,000 --> 00:01:48,000 +They can spoof the messages, they can spoof messages that is coming from, for example, Chase Bank. + +38 +00:01:48,000 --> 00:01:49,000 +How do you stop this? + +39 +00:01:49,000 --> 00:01:53,000 +Well, submission once again, just like vision, except it's done with a text message. + +40 +00:01:53,000 --> 00:01:55,000 +The best thing here is to do education and training. + +41 +00:01:55,000 --> 00:01:58,000 +Well, we want to do is we want to train our users. + +42 +00:01:59,000 --> 00:02:03,000 +Tell them don't click on links that comes through your text messages. + +43 +00:02:03,000 --> 00:02:04,000 +Never click on any link. + +44 +00:02:04,000 --> 00:02:07,000 +Come through any text message you could verify it. + +45 +00:02:07,000 --> 00:02:11,000 +Call Chase Bank and say, did you send me a text message with a particular link? + +46 +00:02:11,000 --> 00:02:17,000 +And of course, you could install security apps on people's phones to detect and block different kinds + +47 +00:02:17,000 --> 00:02:18,000 +of submission. + +48 +00:02:18,000 --> 00:02:20,000 +Attack submission guys is common. + +49 +00:02:20,000 --> 00:02:21,000 +It is very common. + +50 +00:02:21,000 --> 00:02:23,000 +I get this a couple times a week. + +51 +00:02:23,000 --> 00:02:28,000 +I'll get some weird random thing for me to click on that's going to cause a major problem. + +52 +00:02:28,000 --> 00:02:32,000 +So watch out and don't click on any links on any text message. + diff --git a/08 - Social Engineering/005 Spear Phishing OB 2.2_en.srt b/08 - Social Engineering/005 Spear Phishing OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..eef51fcd921f033937aaa0b2387539266f6bf143 --- /dev/null +++ b/08 - Social Engineering/005 Spear Phishing OB 2.2_en.srt @@ -0,0 +1,360 @@ +1 +00:00:00,000 --> 00:00:03,000 +I have 66 certifications. + +2 +00:00:03,000 --> 00:00:08,000 +A lot of those are different forms of it and many, many in IT security. + +3 +00:00:09,000 --> 00:00:12,000 +For me to get hacked, you have to be really, really good. + +4 +00:00:12,000 --> 00:00:20,000 +And there was one day I got hacked, I got Phished attack, I got an email that looked at super legit, + +5 +00:00:21,000 --> 00:00:23,000 +and it had a link in it that I clicked. + +6 +00:00:23,000 --> 00:00:25,000 +In fact, it was an attachment. + +7 +00:00:25,000 --> 00:00:31,000 +I double clicked the attachment which looked like a PDF and boom, the machine got infected. + +8 +00:00:31,000 --> 00:00:32,000 +Quick story. + +9 +00:00:33,000 --> 00:00:37,000 +And you'll understand what kind of attack this is and why it's dangerous. + +10 +00:00:37,000 --> 00:00:39,000 +So we are a licensed school. + +11 +00:00:39,000 --> 00:00:40,000 +We are an accredited school. + +12 +00:00:41,000 --> 00:00:43,000 +One day somebody with authority. + +13 +00:00:43,000 --> 00:00:50,000 +I'm not going to say where, but somebody with authority sent me an email from a particular department, + +14 +00:00:50,000 --> 00:00:53,000 +high department within the education department. + +15 +00:00:53,000 --> 00:00:54,000 +Now, I know this person. + +16 +00:00:54,000 --> 00:00:59,000 +I have never met this person, but I know this person deals with fines towards school. + +17 +00:01:00,000 --> 00:01:03,000 +Now I get an email from this person. + +18 +00:01:03,000 --> 00:01:07,000 +It's generally not good because this person is going to find me, I did something wrong or school is + +19 +00:01:07,000 --> 00:01:08,000 +in trouble. + +20 +00:01:08,000 --> 00:01:11,000 +So I got this email from this person. + +21 +00:01:12,000 --> 00:01:14,000 +I saw it, I panicked, right? + +22 +00:01:14,000 --> 00:01:15,000 +I was like, what did we do? + +23 +00:01:15,000 --> 00:01:16,000 +What did we do? + +24 +00:01:16,000 --> 00:01:19,000 +Of course it has an attachment that has the person's signature. + +25 +00:01:19,000 --> 00:01:24,000 +I didn't check much and boom, I double clicked on the attachment. + +26 +00:01:24,000 --> 00:01:26,000 +Instantly I noticed nothing happened. + +27 +00:01:26,000 --> 00:01:32,000 +The attachment never opened and then I noticed the machine got really slow. + +28 +00:01:32,000 --> 00:01:34,000 +So what I did, I hold the power button down. + +29 +00:01:34,000 --> 00:01:38,000 +I shut it off completely, unplugged it, call the tech guy and says, wipe this machine out. + +30 +00:01:38,000 --> 00:01:39,000 +It's been infected. + +31 +00:01:40,000 --> 00:01:43,000 +I would then call that person myself. + +32 +00:01:44,000 --> 00:01:46,000 +And this person didn't even know who the hell I was. + +33 +00:01:46,000 --> 00:01:47,000 +And I said, you send me something. + +34 +00:01:47,000 --> 00:01:49,000 +She's like, I never sent it. + +35 +00:01:49,000 --> 00:01:50,000 +I don't know what you're talking about. + +36 +00:01:51,000 --> 00:01:57,000 +What I believed happened was that this person was compromised and they were sending out. + +37 +00:01:57,000 --> 00:02:03,000 +They were then using the account to send out emails with some kind of malicious attachment, or they + +38 +00:02:03,000 --> 00:02:05,000 +had targeted me, which is what I believe. + +39 +00:02:05,000 --> 00:02:07,000 +Somebody targeted my organization. + +40 +00:02:07,000 --> 00:02:14,000 +They knew who we were accredited by, and they targeted me in particular because they know I'm the boss. + +41 +00:02:15,000 --> 00:02:22,000 +You see, this kind of attack is one of the most effective attacks there is. + +42 +00:02:22,000 --> 00:02:22,000 +This. + +43 +00:02:22,000 --> 00:02:29,000 +If I was a bad guy and I am trying to steal information from an organization, I am telling you guys + +44 +00:02:29,000 --> 00:02:35,000 +and I've told all my hacking class, if I want to steal information, this is how I do it. + +45 +00:02:35,000 --> 00:02:39,000 +If I want to get information from you, I'm going to target you. + +46 +00:02:39,000 --> 00:02:46,000 +You see, unlike phishing attacks, where it is just done to mass people and it's very general, spear + +47 +00:02:46,000 --> 00:02:52,000 +phishing is a targeted phishing where they customize the attack emails, messages, and communication + +48 +00:02:52,000 --> 00:02:54,000 +to appeal to specific victims. + +49 +00:02:54,000 --> 00:03:00,000 +Now it's going to tailor to specific individuals or personal organizations. + +50 +00:03:00,000 --> 00:03:06,000 +Now there's another form of phishing called Whalen that I want to quickly mention spear phishing. + +51 +00:03:06,000 --> 00:03:07,000 +And Whalen. + +52 +00:03:07,000 --> 00:03:12,000 +Whalen is a form of phishing attacks where they go after if you see the storm, make sure you understand + +53 +00:03:12,000 --> 00:03:12,000 +it. + +54 +00:03:12,000 --> 00:03:15,000 +Whalen is where they go after the big fish in the ocean. + +55 +00:03:15,000 --> 00:03:17,000 +So for me, they spear fished me. + +56 +00:03:17,000 --> 00:03:23,000 +But because I'm the CEO, it's considered Whalen when they go after the biggest person in the organization. + +57 +00:03:23,000 --> 00:03:26,000 +So if you're phishing the biggest fish you're Whalen. + +58 +00:03:26,000 --> 00:03:28,000 +Remember that worm for your exam. + +59 +00:03:28,000 --> 00:03:29,000 +So remember what spear phishing is. + +60 +00:03:29,000 --> 00:03:31,000 +It's an incredibly targeted email. + +61 +00:03:31,000 --> 00:03:33,000 +I give you guys another example. + +62 +00:03:33,000 --> 00:03:35,000 +How good is the security in your organization. + +63 +00:03:35,000 --> 00:03:38,000 +If I spearfish your organization here's what I would do. + +64 +00:03:39,000 --> 00:03:46,000 +I'm going to make a memo, a PDF that uh, is going to have malware attached to it. + +65 +00:03:47,000 --> 00:03:51,000 +I'm going to find your company directory and I'm going to email this memo to everyone. + +66 +00:03:51,000 --> 00:03:52,000 +But here's the catch. + +67 +00:03:52,000 --> 00:03:53,000 +Here's what I'm going to do. + +68 +00:03:53,000 --> 00:03:57,000 +I'm going to make it come from spoofed the email from the CEO. + +69 +00:03:57,000 --> 00:04:05,000 +And the title of the email is going to be, um, reduction, uh, 20% reduction to the following employees + +70 +00:04:05,000 --> 00:04:06,000 +of pay. + +71 +00:04:06,000 --> 00:04:10,000 +And then the body of the email is going to says, unfortunately, your pay will be reduced this year. + +72 +00:04:10,000 --> 00:04:14,000 +Please check the attachment to see what your new compensation will be. + +73 +00:04:14,000 --> 00:04:16,000 +Let me ask you guys a question. + +74 +00:04:16,000 --> 00:04:18,000 +How many of your employees will click on that? + +75 +00:04:18,000 --> 00:04:20,000 +It's very targeted. + +76 +00:04:20,000 --> 00:04:24,000 +It's not to the general public, it's just a specific group of employees. + +77 +00:04:24,000 --> 00:04:25,000 +This would be incredibly effective. + +78 +00:04:25,000 --> 00:04:29,000 +That's why spear phishing is incredibly effective. + +79 +00:04:30,000 --> 00:04:32,000 +The only way to stop this is, of course, user training. + +80 +00:04:33,000 --> 00:04:40,000 +For example, if you teach the users that no matter what, we don't care if the email comes from the + +81 +00:04:40,000 --> 00:04:43,000 +CEO, we don't care if it comes from your boss or your it doesn't matter. + +82 +00:04:43,000 --> 00:04:44,000 +You don't open it, you don't click on it. + +83 +00:04:44,000 --> 00:04:45,000 +You don't click on links. + +84 +00:04:46,000 --> 00:04:48,000 +Have good policies and procedures in place. + +85 +00:04:48,000 --> 00:04:56,000 +If you believe that this email is something that is not good, something that contains bad links, Senate + +86 +00:04:56,000 --> 00:05:00,000 +Information Security, let them check it out and then revert it back to you. + +87 +00:05:00,000 --> 00:05:03,000 +Also have good email filtering can detect some common ones. + +88 +00:05:03,000 --> 00:05:08,000 +Keep in mind guys, spear phishing in Andrew's opinion, is the most effective attack out there because + +89 +00:05:08,000 --> 00:05:14,000 +it specifically targets one individual, allowing the hackers to customize the message to that person, + +90 +00:05:14,000 --> 00:05:17,000 +making them think it's legit. + diff --git a/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2_en.srt b/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..8f0604500255e5b034f9b3d2c94e655a5acb0a99 --- /dev/null +++ b/08 - Social Engineering/006 Misinformation and Disinformation OB 2.2_en.srt @@ -0,0 +1,332 @@ +1 +00:00:00,000 --> 00:00:06,000 +One of the things I really don't do a lot of are things like Facebook and Twitter. + +2 +00:00:06,000 --> 00:00:08,000 +I do a lot of video on social media. + +3 +00:00:08,000 --> 00:00:11,000 +If you guys know me personally, I do a lot of YouTube videos. + +4 +00:00:12,000 --> 00:00:15,000 +Uh, but I just don't do the Facebook thing. + +5 +00:00:15,000 --> 00:00:23,000 +And the the main reason is because there is a lot of misinformation and disinformation on Facebook. + +6 +00:00:23,000 --> 00:00:31,000 +There is a lot of people spreading information that is completely false, intentional and unintentional. + +7 +00:00:31,000 --> 00:00:35,000 +So this brings me to this thing misinformation. + +8 +00:00:35,000 --> 00:00:42,000 +What exactly does it mean misinformation refers to, given out of basically false information or inaccurate, + +9 +00:00:42,000 --> 00:00:46,000 +often unintentionally, without generally without malicious intent? + +10 +00:00:46,000 --> 00:00:52,000 +Way too often I've seen on people on Facebook or other social media, especially Twitter, also, where + +11 +00:00:52,000 --> 00:01:00,000 +they retweet reshare on Facebook information that you can look at it and know it's not real. + +12 +00:01:00,000 --> 00:01:05,000 +And if you actually just took a two second Google search, we figure out that the information is absolutely + +13 +00:01:05,000 --> 00:01:06,000 +false. + +14 +00:01:06,000 --> 00:01:12,000 +Then comes disinformation, on the other hand, involves the deliberate spreading of false or misleading + +15 +00:01:12,000 --> 00:01:15,000 +with the intent to deceive, manipulate, or harm. + +16 +00:01:15,000 --> 00:01:22,000 +Now, in certain countries, in certain times during, for example, political elections and all that, + +17 +00:01:22,000 --> 00:01:26,000 +this may be something that's common as people spread a lot of false information. + +18 +00:01:26,000 --> 00:01:31,000 +Some people are doing this intentionally for disinformation, and some people are doing it maybe because + +19 +00:01:31,000 --> 00:01:33,000 +they're not sure now. + +20 +00:01:34,000 --> 00:01:40,000 +A lot of times when it comes to this, especially misinformation, some of the main characteristics + +21 +00:01:40,000 --> 00:01:43,000 +of misinformation is generally accidental. + +22 +00:01:43,000 --> 00:01:45,000 +They come across something and they think, okay, let me try that. + +23 +00:01:45,000 --> 00:01:46,000 +Try sharing it. + +24 +00:01:46,000 --> 00:01:48,000 +They're not generally doing it to malicious. + +25 +00:01:48,000 --> 00:01:51,000 +They think they're doing it to help you. + +26 +00:01:51,000 --> 00:02:00,000 +For example, what if I'm a Facebook user and I figured out that, uh, eating a whole lot of red meat, + +27 +00:02:00,000 --> 00:02:02,000 +it's going to make you make your heart strong. + +28 +00:02:03,000 --> 00:02:05,000 +Now if you believe that. + +29 +00:02:05,000 --> 00:02:06,000 +Okay. + +30 +00:02:06,000 --> 00:02:06,000 +Good. + +31 +00:02:06,000 --> 00:02:07,000 +That that's that's on you. + +32 +00:02:07,000 --> 00:02:09,000 +If I don't believe it, that's on me. + +33 +00:02:09,000 --> 00:02:09,000 +Right. + +34 +00:02:10,000 --> 00:02:11,000 +This is not a debate on that. + +35 +00:02:12,000 --> 00:02:12,000 +All right. + +36 +00:02:12,000 --> 00:02:16,000 +Uh, doesn't matter what you believe here, but let's say I believe that. + +37 +00:02:17,000 --> 00:02:20,000 +And I start to spread it and I start to spread it. + +38 +00:02:21,000 --> 00:02:22,000 +Then what happens then? + +39 +00:02:22,000 --> 00:02:26,000 +Some people may say, well, that's false information, but I'm not trying to harm you. + +40 +00:02:26,000 --> 00:02:27,000 +Right? + +41 +00:02:27,000 --> 00:02:32,000 +I'm trying to help you because I believe that eating red meat, eating beef fat every for every meal + +42 +00:02:32,000 --> 00:02:33,000 +is amazingly good for you. + +43 +00:02:33,000 --> 00:02:37,000 +I think so, and I want to spread that information. + +44 +00:02:37,000 --> 00:02:39,000 +This is misinformation now. + +45 +00:02:39,000 --> 00:02:40,000 +Unintentional Kwanzaa. + +46 +00:02:40,000 --> 00:02:43,000 +While not deliberate mis, it can lead to security vulnerabilities. + +47 +00:02:43,000 --> 00:02:45,000 +False information is acted upon. + +48 +00:02:45,000 --> 00:02:46,000 +Now. + +49 +00:02:47,000 --> 00:02:51,000 +For example, notice it says can lead to security vulnerabilities. + +50 +00:02:51,000 --> 00:02:56,000 +People can give out information about organizations that they think is there. + +51 +00:02:56,000 --> 00:03:01,000 +That's true, but it's not true, causing people to have false beliefs about that business. + +52 +00:03:02,000 --> 00:03:04,000 +This information, this is deliberate. + +53 +00:03:04,000 --> 00:03:05,000 +Campaigns are carried out. + +54 +00:03:05,000 --> 00:03:10,000 +Intention to deceive or manipulate generally could be for political things. + +55 +00:03:10,000 --> 00:03:16,000 +There was a lot of, uh, disinformation when they were making all kinds of crypto scams, when people + +56 +00:03:16,000 --> 00:03:18,000 +were saying, oh, this crypto is going to be good and you're going to make a ton of money. + +57 +00:03:18,000 --> 00:03:21,000 +And then when people were buying into it, then the thing would tanked. + +58 +00:03:21,000 --> 00:03:23,000 +It was like a pump and dump scheme. + +59 +00:03:24,000 --> 00:03:31,000 +There is malicious intent generally to seek harm or discord to all types of folks around they targeted. + +60 +00:03:31,000 --> 00:03:33,000 +Now, disinformation are well planned. + +61 +00:03:33,000 --> 00:03:34,000 +They're going to target people. + +62 +00:03:34,000 --> 00:03:35,000 +So be careful with this one. + +63 +00:03:36,000 --> 00:03:40,000 +Now, this is a kind of social engineering and the best way to. + +64 +00:03:41,000 --> 00:03:41,000 +Six. + +65 +00:03:41,000 --> 00:03:45,000 +Almost all kinds of social engineering is once again user training. + +66 +00:03:45,000 --> 00:03:51,000 +Promote media literacy, and individuals don't take any information you find on social media. + +67 +00:03:51,000 --> 00:03:53,000 +You do your own research. + +68 +00:03:53,000 --> 00:03:58,000 +Use research from sites that you know that you can trust. + +69 +00:03:58,000 --> 00:04:03,000 +Okay, if I come and I tell you guys that drinking 20 beers a day is good for you because it's been + +70 +00:04:03,000 --> 00:04:05,000 +good for me, maybe that's not good information. + +71 +00:04:05,000 --> 00:04:11,000 +Maybe you should go to your local health department or your country's health websites and see what is + +72 +00:04:11,000 --> 00:04:14,000 +the recommended dosage of alcohol, for example. + +73 +00:04:14,000 --> 00:04:14,000 +Dose. + +74 +00:04:14,000 --> 00:04:15,000 +Don't listen to me. + +75 +00:04:15,000 --> 00:04:17,000 +I might be crazy. + +76 +00:04:18,000 --> 00:04:22,000 +So you want to make sure that you understand this particular one. + +77 +00:04:22,000 --> 00:04:25,000 +Train users not to take information like that. + +78 +00:04:25,000 --> 00:04:30,000 +Like I mentioned, fact checking, verifying the data, cyber hygiene, educate users. + +79 +00:04:30,000 --> 00:04:33,000 +That's what this is all about, letting them look for the source of the information. + +80 +00:04:33,000 --> 00:04:39,000 +If we can teach users that never to take information just for granted. + +81 +00:04:39,000 --> 00:04:43,000 +Any time you get information, verify the information. + +82 +00:04:43,000 --> 00:04:48,000 +Verify the source of the information, verified with authorities that you can trust before believing + +83 +00:04:48,000 --> 00:04:52,000 +in any information, especially on social media. + diff --git a/08 - Social Engineering/007 Impersonation OB 2.2_en.srt b/08 - Social Engineering/007 Impersonation OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..382681bf3f244c5cdecfef2b47e4e55c8bf78210 --- /dev/null +++ b/08 - Social Engineering/007 Impersonation OB 2.2_en.srt @@ -0,0 +1,320 @@ +1 +00:00:00,000 --> 00:00:05,000 +One of the most common hacking techniques out there is when they try to steal your information, they're + +2 +00:00:05,000 --> 00:00:08,000 +successful and then they impersonate you. + +3 +00:00:08,000 --> 00:00:12,000 +So in this in this section, let's take a look at this thing we call impersonation. + +4 +00:00:12,000 --> 00:00:17,000 +This is when the attacker assumes the identity of a legitimate user. + +5 +00:00:17,000 --> 00:00:20,000 +Now if you're thinking, well, nobody's going to know my password, man. + +6 +00:00:20,000 --> 00:00:22,000 +They're not going to be able to impersonate me. + +7 +00:00:23,000 --> 00:00:24,000 +Not so easy. + +8 +00:00:24,000 --> 00:00:28,000 +I don't need your username and password to impersonate you. + +9 +00:00:28,000 --> 00:00:30,000 +All I need to know is what is your email? + +10 +00:00:30,000 --> 00:00:34,000 +Because then I can just spoof your email address to become you. + +11 +00:00:34,000 --> 00:00:35,000 +In fact, it is easy. + +12 +00:00:35,000 --> 00:00:39,000 +I can literally take my course Certified Ethical Hacker. + +13 +00:00:39,000 --> 00:00:42,000 +We have tools that allows me to spoof. + +14 +00:00:42,000 --> 00:00:48,000 +I could literally send you an email that would come from Andrew at fbi.gov in maybe 30s. + +15 +00:00:48,000 --> 00:00:52,000 +So spoofing an email is something very, very easy. + +16 +00:00:52,000 --> 00:00:57,000 +So impersonating people don't think that you have to steal someone's login credentials or mimic their + +17 +00:00:57,000 --> 00:01:00,000 +voice or biometric identifiers to do this. + +18 +00:01:00,000 --> 00:01:03,000 +The question is why would they do this? + +19 +00:01:03,000 --> 00:01:08,000 +If they can impersonate other people, then they can then use that impersonation to accomplish specific + +20 +00:01:08,000 --> 00:01:09,000 +tasks. + +21 +00:01:10,000 --> 00:01:13,000 +If I can impersonate the voice under the email. + +22 +00:01:13,000 --> 00:01:19,000 +If I stole the credentials of like using stolen credentials of like the CEO. + +23 +00:01:19,000 --> 00:01:23,000 +What happens here is that then I can steal the company's information. + +24 +00:01:23,000 --> 00:01:27,000 +I can take companies private data, resell that private data. + +25 +00:01:27,000 --> 00:01:30,000 +If that company has information such as credit card information. + +26 +00:01:30,000 --> 00:01:33,000 +If I can grab that information, of course, that's worth tons of money. + +27 +00:01:34,000 --> 00:01:37,000 +So how would they get your how would they steal your credentials? + +28 +00:01:37,000 --> 00:01:40,000 +Phishing attacks by calling you and asking you for your passwords. + +29 +00:01:40,000 --> 00:01:44,000 +We talked about keyloggers already, and of course asking you for your password. + +30 +00:01:44,000 --> 00:01:45,000 +Uh, deception. + +31 +00:01:45,000 --> 00:01:50,000 +Attackers may use social to trick you into revealing it, right? + +32 +00:01:50,000 --> 00:01:56,000 +If I impersonate a CEO or impersonate a help desk person, for example, I may say, hey, I'm Bob from + +33 +00:01:56,000 --> 00:01:57,000 +the help desk. + +34 +00:01:57,000 --> 00:02:00,000 +Would you, uh, can you help me fix your machine? + +35 +00:02:00,000 --> 00:02:03,000 +Let me have your username and password so I can fix something on your machine. + +36 +00:02:04,000 --> 00:02:06,000 +They target a wide range of system. + +37 +00:02:07,000 --> 00:02:12,000 +It can be from any platform difficult to detect since the attacker appears to be a legitimate can be + +38 +00:02:12,000 --> 00:02:15,000 +challenging to detect such an intrusion. + +39 +00:02:15,000 --> 00:02:16,000 +Do you know why? + +40 +00:02:16,000 --> 00:02:17,000 +Imagine this. + +41 +00:02:17,000 --> 00:02:22,000 +Imagine I impersonate your help desk. + +42 +00:02:22,000 --> 00:02:27,000 +I called Mary at your help desk, says, hey, Mary, I'm Andrew from the help desk, and I. + +43 +00:02:27,000 --> 00:02:29,000 +There's a problem with your machine I need to fix. + +44 +00:02:29,000 --> 00:02:30,000 +Can you help me with this? + +45 +00:02:30,000 --> 00:02:33,000 +Mary says, sure, Andrew, I said, Mary, okay. + +46 +00:02:33,000 --> 00:02:39,000 +I need your username and password so I can log in to your machine and correct the error. + +47 +00:02:39,000 --> 00:02:42,000 +If not, your machine is going to die in a few minutes, so she gives it to me. + +48 +00:02:42,000 --> 00:02:45,000 +I log in, I steal all the data, I log back out. + +49 +00:02:45,000 --> 00:02:47,000 +I tell Mary your machine is good enough. + +50 +00:02:47,000 --> 00:02:48,000 +Mary, I fixed it. + +51 +00:02:48,000 --> 00:02:49,000 +Thank you. + +52 +00:02:49,000 --> 00:02:49,000 +Here's the thing. + +53 +00:02:49,000 --> 00:02:52,000 +Mary is never going to report that to the help desk. + +54 +00:02:52,000 --> 00:02:52,000 +Why? + +55 +00:02:52,000 --> 00:02:55,000 +Because the help desk called her. + +56 +00:02:55,000 --> 00:02:55,000 +Remember? + +57 +00:02:55,000 --> 00:02:57,000 +She never believed she was hacked. + +58 +00:02:57,000 --> 00:02:58,000 +She didn't even know she was hacked. + +59 +00:02:58,000 --> 00:03:01,000 +So this is very difficult to detect. + +60 +00:03:02,000 --> 00:03:08,000 +One of the best ways to stop this is, of course, going to be multi-factor authentication. + +61 +00:03:08,000 --> 00:03:12,000 +Having strong password change your password regularly. + +62 +00:03:12,000 --> 00:03:12,000 +All right. + +63 +00:03:12,000 --> 00:03:15,000 +This way it's harder for people to steal your credential. + +64 +00:03:15,000 --> 00:03:23,000 +So multi-factor authentication such as maybe a smart card and a and a password changing your password + +65 +00:03:23,000 --> 00:03:28,000 +regularly make hard to guess password in the past password section we'll talk of why you should be using + +66 +00:03:28,000 --> 00:03:30,000 +I don't think eight characters anymore. + +67 +00:03:30,000 --> 00:03:31,000 +We should probably go to ten characters now. + +68 +00:03:32,000 --> 00:03:37,000 +User education and training, of course, teach users to potentially detect these type of attacks, + +69 +00:03:37,000 --> 00:03:40,000 +keeping an eye on monitoring systems for unusual attempts. + +70 +00:03:40,000 --> 00:03:47,000 +For example, if Mary never really accesses those files and all of a sudden she's accessing it, the + +71 +00:03:47,000 --> 00:03:49,000 +real helpdesk and says, Mary, why are you accessing those files? + +72 +00:03:49,000 --> 00:03:54,000 +We notice the login system is showing that she's like, well, aren't you guys accessing it for me? + +73 +00:03:54,000 --> 00:03:57,000 +You're going to be like, no, what's in us all of a sudden? + +74 +00:03:57,000 --> 00:03:58,000 +You just detected the hack. + +75 +00:03:59,000 --> 00:04:00,000 +Have a good incident planning. + +76 +00:04:00,000 --> 00:04:02,000 +Because if there is an attempt. + +77 +00:04:03,000 --> 00:04:07,000 +Have a plan to respond to it, to detect this isolated and fix it. + +78 +00:04:08,000 --> 00:04:13,000 +Impersonation is a very common way to get into systems. + +79 +00:04:13,000 --> 00:04:18,000 +It's a very common thing they do in social engineering to steal your credentials, to get information, + +80 +00:04:18,000 --> 00:04:22,000 +sensitive information and cause chaos in your business. + diff --git a/08 - Social Engineering/008 Business Email Compromise OB 2.2_en.srt b/08 - Social Engineering/008 Business Email Compromise OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..31d28239111f3bb50f20705c9a45143e8367d68d --- /dev/null +++ b/08 - Social Engineering/008 Business Email Compromise OB 2.2_en.srt @@ -0,0 +1,228 @@ +1 +00:00:00,000 --> 00:00:05,000 +The other day, I got an email from an organization that I do business with or a credit card company. + +2 +00:00:05,000 --> 00:00:06,000 +The email came in. + +3 +00:00:06,000 --> 00:00:11,000 +It looks absolutely legit telling me that I need to click on this particular link. + +4 +00:00:11,000 --> 00:00:16,000 +Obviously, I did not click on the link because I knew that they wouldn't have access. + +5 +00:00:16,000 --> 00:00:24,000 +This is a kind of an attack where they are compromising the business email of an organization. + +6 +00:00:25,000 --> 00:00:26,000 +They're trying to. + +7 +00:00:26,000 --> 00:00:30,000 +The attacker attempts to gain access to corporate email and impersonate the owner. + +8 +00:00:30,000 --> 00:00:35,000 +A lot of times they do this using spoofing, by the way, impersonate the owner to defraud the company's + +9 +00:00:35,000 --> 00:00:37,000 +employees, its customers for a particular training. + +10 +00:00:37,000 --> 00:00:39,000 +I was a customer or partners. + +11 +00:00:39,000 --> 00:00:42,000 +The attacker requests transfer of funds or sensitive data. + +12 +00:00:42,000 --> 00:00:48,000 +So this one here was actually asking me for username and passwords to do funds transfer. + +13 +00:00:48,000 --> 00:00:50,000 +Now I didn't click on it and it was all a bunch of garbage. + +14 +00:00:50,000 --> 00:00:55,000 +Now, when it comes to impersonation of an email, a couple of things here. + +15 +00:00:55,000 --> 00:00:56,000 +It's done. + +16 +00:00:56,000 --> 00:00:58,000 +Generally targeted email spoofing. + +17 +00:00:58,000 --> 00:01:00,000 +That's really what this does. + +18 +00:01:00,000 --> 00:01:03,000 +The attacker often spoofs or hijacked the corporate email. + +19 +00:01:03,000 --> 00:01:05,000 +Hijacking is different than spoofing. + +20 +00:01:05,000 --> 00:01:11,000 +So spoofing is I don't have any access to your account, but I'm able to send an email that appears + +21 +00:01:11,000 --> 00:01:12,000 +that it comes from you. + +22 +00:01:12,000 --> 00:01:15,000 +So let's say your and your name is Bob and you work with the FBI. + +23 +00:01:15,000 --> 00:01:17,000 +So your email is Bob at fbi.gov. + +24 +00:01:17,000 --> 00:01:19,000 +But I can send an email as Bob's Fbi.gov. + +25 +00:01:19,000 --> 00:01:26,000 +I can't receive email as Bob at fbi.gov, but I don't know anything about your passwords or anything + +26 +00:01:26,000 --> 00:01:26,000 +like that. + +27 +00:01:27,000 --> 00:01:33,000 +But if I socially engineer you and I'm able to get your password and I've hijacked your kind of taken + +28 +00:01:33,000 --> 00:01:38,000 +control of it, they're generally going to use when they compromise your business email. + +29 +00:01:38,000 --> 00:01:44,000 +They're going to use some kind of sophisticated, uh, email and techniques and social engineering techniques + +30 +00:01:44,000 --> 00:01:45,000 +to do it. + +31 +00:01:45,000 --> 00:01:51,000 +These attacks usually involve carefully crafted phishing emails and advanced social to manipulate employees. + +32 +00:01:52,000 --> 00:01:53,000 +Why are they doing this? + +33 +00:01:53,000 --> 00:01:58,000 +Generally, it comes with some kind of financial motive funds transfer, stealing of credit card information. + +34 +00:01:58,000 --> 00:02:00,000 +They may customize these email. + +35 +00:02:02,000 --> 00:02:08,000 +Now one of the things here with when they do business email compromise is that it's a lack of malware. + +36 +00:02:08,000 --> 00:02:11,000 +Unlike other ones, this one doesn't involve malware. + +37 +00:02:11,000 --> 00:02:12,000 +All right. + +38 +00:02:12,000 --> 00:02:14,000 +They're just trying to impersonate you. + +39 +00:02:14,000 --> 00:02:16,000 +Take over your email account. + +40 +00:02:16,000 --> 00:02:24,000 +Now, the way to stop this is, of course, once again training your employees on a regular basis not + +41 +00:02:24,000 --> 00:02:25,000 +to get compromised. + +42 +00:02:25,000 --> 00:02:26,000 +Don't click on links. + +43 +00:02:27,000 --> 00:02:32,000 +What if you get an email from your email provider stating that you need to reset the password in your + +44 +00:02:32,000 --> 00:02:34,000 +email because it's been compromised? + +45 +00:02:34,000 --> 00:02:35,000 +That is a way they will get you. + +46 +00:02:35,000 --> 00:02:38,000 +When you click on the link, they steal your password. + +47 +00:02:38,000 --> 00:02:39,000 +That is a way they will. + +48 +00:02:39,000 --> 00:02:41,000 +They're going to compromise your email. + +49 +00:02:41,000 --> 00:02:47,000 +Now, we haven't gotten into the full security of emails, and when we do, we'll talk about certain + +50 +00:02:47,000 --> 00:02:50,000 +authentication methods that you're going to need to know for your exam. + +51 +00:02:50,000 --> 00:02:53,000 +SPF, DKIM, dMarc. + +52 +00:02:53,000 --> 00:02:58,000 +These are ways to ensure that no one can spoof a company's email. + +53 +00:02:58,000 --> 00:03:01,000 +They just can't send email as an organization. + +54 +00:03:01,000 --> 00:03:04,000 +We'll talk about these methods coming up a little bit later. + +55 +00:03:04,000 --> 00:03:10,000 +But remember, email is the number one way to deliver malware to do all kinds of phishing attacks. + +56 +00:03:10,000 --> 00:03:12,000 +So this is not something once again, that's uncommon. + +57 +00:03:12,000 --> 00:03:14,000 +It's very actually very common. + diff --git a/08 - Social Engineering/009 Pretexting OB 2.2_en.srt b/08 - Social Engineering/009 Pretexting OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..36949445fd8a56c6549b739db13b94b4ea48c209 --- /dev/null +++ b/08 - Social Engineering/009 Pretexting OB 2.2_en.srt @@ -0,0 +1,324 @@ +1 +00:00:00,000 --> 00:00:05,000 +Few days ago, I got a phone call from the IRS. + +2 +00:00:05,000 --> 00:00:13,000 +The IRS told me that the tax returns I filed were completely off, and they have put a levy on my home. + +3 +00:00:13,000 --> 00:00:19,000 +I owe $3,000, and if I don't pay it, they have, um, sent out a warrant for my arrest. + +4 +00:00:19,000 --> 00:00:22,000 +And if I don't pay it right away over the phone. + +5 +00:00:22,000 --> 00:00:23,000 +Are you ready for this with gift cards? + +6 +00:00:24,000 --> 00:00:29,000 +Uh, I'm going to be arrested in about two, about 2 to 3 hours. + +7 +00:00:29,000 --> 00:00:31,000 +So I need to pay them right away. + +8 +00:00:31,000 --> 00:00:35,000 +And I can't hang up the phone because the cops are on the way. + +9 +00:00:36,000 --> 00:00:36,000 +Hmm. + +10 +00:00:36,000 --> 00:00:38,000 +What do you guys think I did? + +11 +00:00:38,000 --> 00:00:39,000 +I bought the gift cards and paid them. + +12 +00:00:39,000 --> 00:00:40,000 +No, no, I didn't do that. + +13 +00:00:40,000 --> 00:00:44,000 +Uh, so this kind of attack here is called Pretexting. + +14 +00:00:44,000 --> 00:00:52,000 +Now, pretexting is when they fabricate a story or scenario to deceive a target into doing something. + +15 +00:00:52,000 --> 00:00:58,000 +In this particular one, they wanted me to buy gift cards, for whatever reason, for $3,000. + +16 +00:00:58,000 --> 00:01:00,000 +The reason, by the way, they do gift cards because it's not trackable. + +17 +00:01:00,000 --> 00:01:01,000 +And once you give them the number, it's gone. + +18 +00:01:02,000 --> 00:01:07,000 +Um, the attacker often conducts extensive research to make this story as. + +19 +00:01:07,000 --> 00:01:10,000 +Possible, you know, realistic as possible. + +20 +00:01:10,000 --> 00:01:13,000 +It involves the attacker pretending this is where the word pretexting come from. + +21 +00:01:13,000 --> 00:01:17,000 +To be someone they're not like a trusted authority like the IRS. + +22 +00:01:17,000 --> 00:01:18,000 +If you don't know the IRS. + +23 +00:01:18,000 --> 00:01:21,000 +The IRS is a tax collection agency in the United States. + +24 +00:01:21,000 --> 00:01:27,000 +If you're watching this overseas now, whether it's impersonation scam, investment scam, phishing + +25 +00:01:27,000 --> 00:01:33,000 +scam, they're always going to come up with some elaborate scenario or stories for me to believe it. + +26 +00:01:35,000 --> 00:01:37,000 +They're targeting something sensitive. + +27 +00:01:37,000 --> 00:01:43,000 +It could be some kind of sensitive information they want out of me, or some financial information that + +28 +00:01:43,000 --> 00:01:44,000 +they want out of me. + +29 +00:01:44,000 --> 00:01:46,000 +They're going to manipulate me. + +30 +00:01:46,000 --> 00:01:49,000 +They often pose as a trusted individual again, such as the IRS. + +31 +00:01:49,000 --> 00:01:56,000 +They may even pose as police officers, and they might customize this to me, usually involve specific + +32 +00:01:56,000 --> 00:01:58,000 +targets, so they might customize it to you. + +33 +00:01:58,000 --> 00:02:08,000 +So if your CEO or if let me flip that, your CEO calls you and tells you that he's stuck. + +34 +00:02:08,000 --> 00:02:12,000 +And this is a common thing, by the way, he's stuck in a country to send him a gift card for him to + +35 +00:02:12,000 --> 00:02:14,000 +get help or hurt to get help. + +36 +00:02:15,000 --> 00:02:17,000 +This is a form of that also. + +37 +00:02:17,000 --> 00:02:24,000 +Now, one of the things that I want to make clear is two things that people get confused often is pretexting + +38 +00:02:24,000 --> 00:02:25,000 +versus impersonation. + +39 +00:02:26,000 --> 00:02:27,000 +All right. + +40 +00:02:27,000 --> 00:02:30,000 +Pretexting relies on fabricated scenario. + +41 +00:02:30,000 --> 00:02:35,000 +So pretexting is more interaction between the attacker and the victim, with the attacker playing a + +42 +00:02:35,000 --> 00:02:36,000 +role. + +43 +00:02:36,000 --> 00:02:43,000 +Versus impersonation, they directly assume the identity of that person using stolen credentials. + +44 +00:02:43,000 --> 00:02:47,000 +So impersonation there instantly they assume the role of that person. + +45 +00:02:47,000 --> 00:02:51,000 +But generally Pretexting has a big scenario that goes with it. + +46 +00:02:51,000 --> 00:02:52,000 +Um. + +47 +00:02:53,000 --> 00:02:55,000 +For you to act right away. + +48 +00:02:55,000 --> 00:02:58,000 +Now, once again, how are you going to solve this? + +49 +00:02:58,000 --> 00:02:58,000 +Right? + +50 +00:02:58,000 --> 00:03:00,000 +What is the way to fix Pretexting? + +51 +00:03:00,000 --> 00:03:04,000 +Well, like every social engineering out there, you're going to have to do employee training. + +52 +00:03:04,000 --> 00:03:05,000 +That's the main thing. + +53 +00:03:05,000 --> 00:03:08,000 +Regular training sessions is going to be the main thing. + +54 +00:03:09,000 --> 00:03:11,000 +You're going to want to verify identity. + +55 +00:03:11,000 --> 00:03:15,000 +So somebody calls you from the IRS, just say, you know what, let me hang up, give me the case number, + +56 +00:03:15,000 --> 00:03:20,000 +and let me call the IRS number that I know of that I'm going to get from a trusted source. + +57 +00:03:20,000 --> 00:03:22,000 +And then I'll talk to you then. + +58 +00:03:23,000 --> 00:03:24,000 +Just don't take it for them. + +59 +00:03:24,000 --> 00:03:25,000 +Limited information. + +60 +00:03:25,000 --> 00:03:26,000 +Educate employees. + +61 +00:03:26,000 --> 00:03:27,000 +Do not overshare. + +62 +00:03:27,000 --> 00:03:33,000 +Give information to anyone and if this does occur to the organization, have a good, clear protocol + +63 +00:03:33,000 --> 00:03:34,000 +for reporting this. + +64 +00:03:34,000 --> 00:03:39,000 +The organization employees should have a good way that they can report this kind of incident right away. + +65 +00:03:39,000 --> 00:03:43,000 +These kinds of scams are incredibly common in today's world. + +66 +00:03:44,000 --> 00:03:45,000 +I love these scams. + +67 +00:03:45,000 --> 00:03:46,000 +There's something off topic. + +68 +00:03:47,000 --> 00:03:52,000 +Anytime I get these kinds of pretexting thing that I'm in trouble or something like that, tax authorities, + +69 +00:03:52,000 --> 00:03:55,000 +some cop calling me or whatever, I played a whole game out. + +70 +00:03:55,000 --> 00:03:55,000 +Why? + +71 +00:03:55,000 --> 00:03:57,000 +Because it's fun to do with them. + +72 +00:03:57,000 --> 00:04:00,000 +I like to see what they say, and I like to know where this is going to go if I have time. + +73 +00:04:02,000 --> 00:04:04,000 +I'll play the whole game because I want to see where it's going. + +74 +00:04:04,000 --> 00:04:07,000 +And then at the end I'll say, I just wasted your time, by the way. + +75 +00:04:07,000 --> 00:04:09,000 +But it was really interesting how you did this. + +76 +00:04:09,000 --> 00:04:13,000 +Your life must be miserable for you to be doing a job, and then they get really mad and hang up. + +77 +00:04:13,000 --> 00:04:19,000 +But it is interesting to see and unfortunately, folks are getting you guys got to remember something + +78 +00:04:19,000 --> 00:04:27,000 +about these stupid hacks that we IT folks may feel, oh, who falls for that somebody is because if + +79 +00:04:27,000 --> 00:04:29,000 +no one was falling for it, they would have stopped it a long time ago. + +80 +00:04:29,000 --> 00:04:34,000 +That means that somebody and a lot of people are falling and getting scammed with these. + +81 +00:04:34,000 --> 00:04:36,000 +So make sure you train people not to get scammed. + diff --git a/08 - Social Engineering/010 Watering Hole OB 2.2_en.srt b/08 - Social Engineering/010 Watering Hole OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..efcffa7edd129bc9f0d0d903c5e55073ef4254f5 --- /dev/null +++ b/08 - Social Engineering/010 Watering Hole OB 2.2_en.srt @@ -0,0 +1,276 @@ +1 +00:00:00,000 --> 00:00:05,000 +As a tech person, I encounter all kinds of crazy errors on all kinds of systems. + +2 +00:00:05,000 --> 00:00:08,000 +There is a famous form that I like to visit. + +3 +00:00:08,000 --> 00:00:11,000 +I like to voice my problems there and other tech folks will help me out. + +4 +00:00:11,000 --> 00:00:15,000 +In fact, a few weeks ago I had a problem with a cloud based systems. + +5 +00:00:15,000 --> 00:00:19,000 +I typed a problem in there and somebody gracefully was able to tell me how to solve it. + +6 +00:00:19,000 --> 00:00:21,000 +Thank you to that person. + +7 +00:00:21,000 --> 00:00:22,000 +Now. + +8 +00:00:23,000 --> 00:00:25,000 +A lot of the people on the forum have the same interest. + +9 +00:00:25,000 --> 00:00:27,000 +We're all techs and we're all looking to help each other. + +10 +00:00:27,000 --> 00:00:30,000 +In fact, a lot of times I help them also. + +11 +00:00:30,000 --> 00:00:33,000 +If I know the problem and I see it, I'm going to help them. + +12 +00:00:34,000 --> 00:00:40,000 +But you see this kind of forms or these kinds of sites where it's a specific group of people that go + +13 +00:00:40,000 --> 00:00:47,000 +to, you see, what can happen is that we could be targeted with specific malware, and there is an + +14 +00:00:47,000 --> 00:00:53,000 +attack that we have to be familiar with, not just for exam, but as tech people just using the internet. + +15 +00:00:53,000 --> 00:00:54,000 +It's called a watering hole. + +16 +00:00:54,000 --> 00:01:00,000 +Watering hole attack is where the attacker seeks to compromise specific group of end users by infecting + +17 +00:01:00,000 --> 00:01:02,000 +websites that they're known to visit frequently. + +18 +00:01:02,000 --> 00:01:07,000 +The goal is to infect users computers and gain access to the network or the place of work. + +19 +00:01:07,000 --> 00:01:08,000 +Now here's what it is. + +20 +00:01:10,000 --> 00:01:14,000 +What the attacker does in this particular attack is they go to the watering hole. + +21 +00:01:14,000 --> 00:01:17,000 +Now it's called watering hole for this reason. + +22 +00:01:17,000 --> 00:01:23,000 +Think about in the desert, there's a little tiny, uh, river that the crocodiles live in and there's + +23 +00:01:23,000 --> 00:01:24,000 +no water anywhere else. + +24 +00:01:24,000 --> 00:01:30,000 +So anytime an animal wants some water, the animal goes to drink the water from the watering hole and + +25 +00:01:30,000 --> 00:01:32,000 +boom, the crocodile comes out and eats their face. + +26 +00:01:32,000 --> 00:01:34,000 +That's what this is. + +27 +00:01:34,000 --> 00:01:37,000 +You see, all of us tech guys goes to this particular form. + +28 +00:01:37,000 --> 00:01:44,000 +So if all of us tech guys are going to this form, so we are the ones that's being targeted, a popular + +29 +00:01:44,000 --> 00:01:46,000 +website that we go to. + +30 +00:01:46,000 --> 00:01:47,000 +So we're the one that's populated. + +31 +00:01:47,000 --> 00:01:52,000 +What they're going to do is they're going to exploit a vulnerability on that site and infect the website + +32 +00:01:52,000 --> 00:01:54,000 +with some kind of malware. + +33 +00:01:54,000 --> 00:02:02,000 +Once they exploit it and we go to this particular website, then our machine is or could be become infected + +34 +00:02:02,000 --> 00:02:05,000 +if they do it by what's called a drive by download. + +35 +00:02:05,000 --> 00:02:07,000 +So drive by downloads are this. + +36 +00:02:07,000 --> 00:02:10,000 +It's when you go to a website that's infected and boom, it infects your website. + +37 +00:02:10,000 --> 00:02:11,000 +You don't even know. + +38 +00:02:11,000 --> 00:02:13,000 +It just happens in the background. + +39 +00:02:13,000 --> 00:02:14,000 +You didn't do anything. + +40 +00:02:15,000 --> 00:02:18,000 +It might even redirect you to a malicious site. + +41 +00:02:18,000 --> 00:02:23,000 +So there may be something on there that redirects you to a malicious site that then installs the malware. + +42 +00:02:23,000 --> 00:02:25,000 +So this is a watering hole attack. + +43 +00:02:25,000 --> 00:02:31,000 +A watering hole attack is when, let's say you're an attacker, you find where a large number of particular + +44 +00:02:31,000 --> 00:02:31,000 +users go. + +45 +00:02:31,000 --> 00:02:37,000 +You infect that site with malware, and when they go, you hope to infect those folks at the watering + +46 +00:02:37,000 --> 00:02:40,000 +hole or the particular website to stop this. + +47 +00:02:40,000 --> 00:02:45,000 +One of the things is to organizations that are running these sites should do regular website security + +48 +00:02:45,000 --> 00:02:51,000 +audits for organizations, ensuring that their own website don't become a part of a watering hole. + +49 +00:02:51,000 --> 00:02:56,000 +So if you're running like a Reddit, if you're Reddit, if you work for Reddit, for example, you're + +50 +00:02:56,000 --> 00:02:58,000 +going to want to make sure that your company doesn't become a watering hole. + +51 +00:02:58,000 --> 00:03:04,000 +Become a place for watering hole attacks, train your users and employed with the risk of visiting especially + +52 +00:03:04,000 --> 00:03:05,000 +untrusted sites. + +53 +00:03:06,000 --> 00:03:07,000 +I use. + +54 +00:03:07,000 --> 00:03:08,000 +Some of the forms I use are. + +55 +00:03:08,000 --> 00:03:14,000 +Some of them are not the best place out there, but they get the job done and some of them are really + +56 +00:03:14,000 --> 00:03:15,000 +trusted sites. + +57 +00:03:16,000 --> 00:03:20,000 +The other thing here is make sure everything is updated, because a lot of times they may. + +58 +00:03:20,000 --> 00:03:25,000 +A lot of times the malware may take advantage of an unpatched machine, and especially if you don't + +59 +00:03:25,000 --> 00:03:27,000 +have antivirus, that's a problem. + +60 +00:03:27,000 --> 00:03:28,000 +So make sure you have the latest and antivirus. + +61 +00:03:28,000 --> 00:03:33,000 +The other thing you want to do is probably segment your network, because if your machine does get become + +62 +00:03:33,000 --> 00:03:38,000 +infected with some kind of malware, at least the infection will spread across the network. + +63 +00:03:38,000 --> 00:03:40,000 +It'll just be stuck within that segment of the network. + +64 +00:03:40,000 --> 00:03:45,000 +So if you're in marketing, it'll only affect marketing computers, not every computer on the network. + +65 +00:03:46,000 --> 00:03:51,000 +Watering hole attack is more common than you than you should believe in it. + +66 +00:03:51,000 --> 00:03:55,000 +Although it may sound like something that doesn't happen much, it does happen much. + +67 +00:03:56,000 --> 00:04:02,000 +Because there's a lot of websites out there that are constantly being compromised. + +68 +00:04:02,000 --> 00:04:09,000 +Web technology changes so frequently and exploits comes up very quick, and that makes this kind of + +69 +00:04:09,000 --> 00:04:12,000 +attack more common than you believe. + diff --git a/08 - Social Engineering/011 Brand Impersonation OB 2.2_en.srt b/08 - Social Engineering/011 Brand Impersonation OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..b136c9967cf47516e7fa149fbed9ea2eb99f731d --- /dev/null +++ b/08 - Social Engineering/011 Brand Impersonation OB 2.2_en.srt @@ -0,0 +1,220 @@ +1 +00:00:00,000 --> 00:00:08,000 +Few days ago, I got an email from Amazon that was giving me a code to 50% off everything on Amazon. + +2 +00:00:08,000 --> 00:00:10,000 +Doesn't matter what the price is it? + +3 +00:00:10,000 --> 00:00:12,000 +But I had to use the link in the email. + +4 +00:00:12,000 --> 00:00:17,000 +So I clicked on the link and it took me to a website, Amazon.com. + +5 +00:00:17,000 --> 00:00:23,000 +It looked at exactly like Amazon.com, but I had to log in, provide my credit card information so I + +6 +00:00:23,000 --> 00:00:24,000 +can start shopping. + +7 +00:00:25,000 --> 00:00:32,000 +You see, in this kind of an attack that that I'm describing to you, somebody was impersonated brand + +8 +00:00:32,000 --> 00:00:39,000 +impersonation Amazon why did they want to do why are they impersonating an entire company? + +9 +00:00:39,000 --> 00:00:40,000 +The reason that they're doing this. + +10 +00:00:41,000 --> 00:00:48,000 +The attacker mimics impersonate the brand identity of a highly reputable company to deceive victim, + +11 +00:00:48,000 --> 00:00:53,000 +usually for the purpose of stealing sensitive data, username, passwords, credit card information, + +12 +00:00:53,000 --> 00:00:56,000 +or they may even be doing this to spread malware. + +13 +00:00:56,000 --> 00:01:00,000 +This is going to occur generally through some kind of email that they may try to get you. + +14 +00:01:00,000 --> 00:01:07,000 +They may have fake websites set up, or even a fake social media profiles set up to impersonate a particular + +15 +00:01:07,000 --> 00:01:08,000 +company. + +16 +00:01:08,000 --> 00:01:15,000 +Once again, if they can get you to believe that they're Amazon, they're Microsoft, they're Apple, + +17 +00:01:16,000 --> 00:01:20,000 +they're Verizon, they're whoever, you're probably going to click on it. + +18 +00:01:20,000 --> 00:01:24,000 +And if they get you to click on it off with your head, they're stealing your data. + +19 +00:01:24,000 --> 00:01:28,000 +Now the use of counterfeit brand elements, what they're going to do is they're going to go and they're + +20 +00:01:28,000 --> 00:01:33,000 +going to rip Amazon site out the logos, the branding style, all the visual elements. + +21 +00:01:33,000 --> 00:01:37,000 +They're going to reproduce Amazon and make it look exactly like Amazon. + +22 +00:01:37,000 --> 00:01:42,000 +They're going to send out fake emails, and they're going to set up a fake website that mimics the real + +23 +00:01:42,000 --> 00:01:43,000 +trusted brand. + +24 +00:01:43,000 --> 00:01:50,000 +You're not going to be able to tell the URL may even be very close to Amazon.com. + +25 +00:01:50,000 --> 00:01:52,000 +They may misspell a word. + +26 +00:01:52,000 --> 00:01:54,000 +Maybe they have a, uh. + +27 +00:01:54,000 --> 00:01:59,000 +Instead, they may change the A or one of the A's to an Or something, so it's harder to see. + +28 +00:01:59,000 --> 00:02:02,000 +They're going to exploit trusted brand because you already trust Amazon. + +29 +00:02:02,000 --> 00:02:06,000 +You know if you if you get a something from Amazon.com, it's some kind of email. + +30 +00:02:06,000 --> 00:02:10,000 +You're more likely to look at it because you trust Amazon versus some store you don't know. + +31 +00:02:10,000 --> 00:02:12,000 +So this is going to target a broad audience. + +32 +00:02:13,000 --> 00:02:14,000 +All right. + +33 +00:02:14,000 --> 00:02:15,000 +Targets abroad on it. + +34 +00:02:15,000 --> 00:02:19,000 +They're going to send this to a lot of people are unlike targeted or spearfishing. + +35 +00:02:19,000 --> 00:02:22,000 +This one is going to go to a lot of folks. + +36 +00:02:22,000 --> 00:02:23,000 +How do you mitigate this. + +37 +00:02:23,000 --> 00:02:29,000 +Well if you work in a company such as Amazon, Google, Apple, all these giant businesses, you have + +38 +00:02:29,000 --> 00:02:30,000 +to protect your brand. + +39 +00:02:30,000 --> 00:02:35,000 +You have to be on a constant lookout for fake websites, fake emails that they're going to be sending + +40 +00:02:35,000 --> 00:02:41,000 +out to impersonate you, to steal your user's information, regularly monitor the internet for unauthorized + +41 +00:02:41,000 --> 00:02:44,000 +a brand identity, maybe publish something on social media. + +42 +00:02:44,000 --> 00:02:46,000 +Hey, be careful, we will never send emails. + +43 +00:02:46,000 --> 00:02:47,000 +Everything will. + +44 +00:02:47,000 --> 00:02:49,000 +If we do, it will have these things in it. + +45 +00:02:50,000 --> 00:02:52,000 +Make the public aware. + +46 +00:02:52,000 --> 00:02:53,000 +Put them on social media. + +47 +00:02:53,000 --> 00:02:59,000 +Good internal security measures that people cannot steal your information. + +48 +00:02:59,000 --> 00:03:01,000 +Prevent data breaches even within your own business. + +49 +00:03:01,000 --> 00:03:04,000 +And if this does happen, make sure you have a good incident response plan. + +50 +00:03:04,000 --> 00:03:10,000 +So if this does happen and somebody is stealing your brand without your knowledge, this can be, uh, + +51 +00:03:10,000 --> 00:03:16,000 +remediated and respond to quickly, including maybe even taking legal action against them for imposing + +52 +00:03:16,000 --> 00:03:18,000 +on things like copyrights and trademarks. + +53 +00:03:18,000 --> 00:03:21,000 +This is serious business, and it's happened quite a lot. + +54 +00:03:21,000 --> 00:03:26,000 +I'm pretty sure you guys have probably experienced you've probably been to a website that's a fake website. + +55 +00:03:26,000 --> 00:03:32,000 +You got an email that looks exactly like it's coming from a trusted source, but it was actually fake. + diff --git a/08 - Social Engineering/012 Typosquatting OB 2.2_en.srt b/08 - Social Engineering/012 Typosquatting OB 2.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..c95865660edfa0c9aa7d43f92cb27c0aefe9f7fe --- /dev/null +++ b/08 - Social Engineering/012 Typosquatting OB 2.2_en.srt @@ -0,0 +1,380 @@ +1 +00:00:00,000 --> 00:00:02,000 +One of the best websites to read the news on is Yahoo! + +2 +00:00:02,000 --> 00:00:05,000 +And I want to show you how to read the news on Yahoo! + +3 +00:00:05,000 --> 00:00:08,000 +Don't click away because you got to see this Yahoo! + +4 +00:00:08,000 --> 00:00:10,000 +You got to see this on Yahoo man. + +5 +00:00:10,000 --> 00:00:11,000 +You're going to be amazed. + +6 +00:00:11,000 --> 00:00:13,000 +So I'm going to go to Yahoo here. + +7 +00:00:15,000 --> 00:00:16,000 +All right Yahoo! + +8 +00:00:18,000 --> 00:00:18,000 +The hell? + +9 +00:00:18,000 --> 00:00:19,000 +This isn't a Yahoo! + +10 +00:00:19,000 --> 00:00:20,000 +What the hell is this? + +11 +00:00:22,000 --> 00:00:23,000 +What the hell is this? + +12 +00:00:23,000 --> 00:00:24,000 +The right type. + +13 +00:00:24,000 --> 00:00:25,000 +Yahoo! + +14 +00:00:25,000 --> 00:00:26,000 +I'm pretty sure I did. + +15 +00:00:29,000 --> 00:00:30,000 +Hmm'hmm. + +16 +00:00:31,000 --> 00:00:33,000 +The right type of. + +17 +00:00:33,000 --> 00:00:34,000 +I saw what happened. + +18 +00:00:34,000 --> 00:00:35,000 +You know what? + +19 +00:00:36,000 --> 00:00:36,000 +Oh, boy. + +20 +00:00:36,000 --> 00:00:39,000 +Now this wants to install malware that literally is malware. + +21 +00:00:39,000 --> 00:00:41,000 +I think I made a mistake. + +22 +00:00:41,000 --> 00:00:47,000 +Replay the video and notice I did not type YH0. + +23 +00:00:47,000 --> 00:00:53,000 +I made a mistake on my keyboard and I typed it u instead of y because if you look on the keyboard, + +24 +00:00:53,000 --> 00:00:56,000 +y is next to u typo. + +25 +00:00:57,000 --> 00:00:58,000 +I made a typo. + +26 +00:00:59,000 --> 00:01:02,000 +Typo type in Yahoo's domain name. + +27 +00:01:03,000 --> 00:01:06,000 +This kind of attack is called Typosquatting. + +28 +00:01:06,000 --> 00:01:10,000 +Now that is a real typo squad and that is absolutely real. + +29 +00:01:10,000 --> 00:01:11,000 +Okay. + +30 +00:01:12,000 --> 00:01:21,000 +I've known that one for a while now that you, a hero, goes to a fake website that installs malware + +31 +00:01:21,000 --> 00:01:23,000 +on people's machine, as you saw that you could. + +32 +00:01:23,000 --> 00:01:26,000 +Don't try it on your computer and you get infected. + +33 +00:01:26,000 --> 00:01:29,000 +But if you have a test machine that you want to try, knock yourself out. + +34 +00:01:29,000 --> 00:01:30,000 +I don't recommend it though. + +35 +00:01:30,000 --> 00:01:33,000 +Never recommend you guys to get hacked. + +36 +00:01:33,000 --> 00:01:34,000 +So. + +37 +00:01:35,000 --> 00:01:37,000 +Typosquatting is this? + +38 +00:01:37,000 --> 00:01:44,000 +Typosquatting is a cyberattack where attackers registered domain names that are misspelling of a popular + +39 +00:01:44,000 --> 00:01:44,000 +website. + +40 +00:01:45,000 --> 00:01:46,000 +Okay. + +41 +00:01:46,000 --> 00:01:48,000 +And then they are mimic well-known domain names. + +42 +00:01:48,000 --> 00:01:50,000 +So it looks very similar. + +43 +00:01:50,000 --> 00:01:54,000 +The aim is to deceive internet users who make typographical errors. + +44 +00:01:54,000 --> 00:02:00,000 +So you put your hand on your keyboard and you notice you got to pick your finger up to get to the Y. + +45 +00:02:00,000 --> 00:02:05,000 +But it's probably easier to get to the U and boom, your machine is in trouble, leading them to a malicious + +46 +00:02:05,000 --> 00:02:08,000 +or deceptive website like I just did. + +47 +00:02:08,000 --> 00:02:16,000 +Now, a lot of times they're going to have ways to misspell like misspell legitimate things, for example + +48 +00:02:16,000 --> 00:02:18,000 +G or GL, all these things. + +49 +00:02:18,000 --> 00:02:23,000 +I'm not sure if that one is real and I'm not going to try, but what you guys should be doing is registering. + +50 +00:02:23,000 --> 00:02:30,000 +If you own your company, register all the variations and you could try different variations of Google, + +51 +00:02:30,000 --> 00:02:34,000 +like put Google with one O instead of two O's. + +52 +00:02:34,000 --> 00:02:35,000 +You'll notice it goes right back to Google. + +53 +00:02:35,000 --> 00:02:36,000 +So Google knows this. + +54 +00:02:36,000 --> 00:02:38,000 +What they're going to do is they're going to. + +55 +00:02:39,000 --> 00:02:45,000 +Find all the variations and misspelling of their domain names and redirect it to the real domain. + +56 +00:02:45,000 --> 00:02:53,000 +So bad guys don't don't make don't make trouble and typo squad folks into going to fake websites. + +57 +00:02:53,000 --> 00:02:59,000 +It exploits user mistake strategy, relies on users common typing errors and you gotta remember something. + +58 +00:02:59,000 --> 00:03:07,000 +If Google gets 100 million google.com typing in every single day, even if 1% of that is bad, it's + +59 +00:03:07,000 --> 00:03:10,000 +still 1 million people can go to malicious websites. + +60 +00:03:10,000 --> 00:03:13,000 +Think about that for a second variety of malicious intents. + +61 +00:03:13,000 --> 00:03:16,000 +They can want to install malware. + +62 +00:03:16,000 --> 00:03:19,000 +I think was that site I showed you phishing scams. + +63 +00:03:19,000 --> 00:03:24,000 +They may be even selling counterfeits, so they may have variations of Amazon that looks like it. + +64 +00:03:25,000 --> 00:03:26,000 +Fake fake websites. + +65 +00:03:26,000 --> 00:03:28,000 +And I noticed that the the fake Yahoo! + +66 +00:03:28,000 --> 00:03:30,000 +They had a big redirect. + +67 +00:03:31,000 --> 00:03:31,000 +All right. + +68 +00:03:31,000 --> 00:03:33,000 +Sometimes it may even look like the real one. + +69 +00:03:33,000 --> 00:03:36,000 +Now you want to be able to train your users on this. + +70 +00:03:36,000 --> 00:03:42,000 +Educate them about the risk of typosquatting and be careful with the URL before pressing enter. + +71 +00:03:43,000 --> 00:03:46,000 +One great thing you guys should be doing is the use of bookmarking. + +72 +00:03:46,000 --> 00:03:49,000 +Don't always try to go and type in URLs. + +73 +00:03:49,000 --> 00:03:51,000 +Bookmark the URL. + +74 +00:03:51,000 --> 00:03:52,000 +That way you have to keep typing it. + +75 +00:03:52,000 --> 00:03:55,000 +Less typing, less room for errors. + +76 +00:03:55,000 --> 00:04:01,000 +I'm pretty sure somebody out there right now is typing Yahoo with the U instead of the Y. + +77 +00:04:02,000 --> 00:04:08,000 +Advanced web browser and security tools can detect and alert people that this is a big fake website. + +78 +00:04:08,000 --> 00:04:12,000 +And if you own the company, you guys should be doing this. + +79 +00:04:12,000 --> 00:04:15,000 +They should register all the common misspelling names. + +80 +00:04:15,000 --> 00:04:17,000 +Now how do you find the misspelling names? + +81 +00:04:17,000 --> 00:04:21,000 +The easiest way to do this is to look on the keyboard and find the letters. + +82 +00:04:21,000 --> 00:04:26,000 +If your company name is a J, it starts with a J, the domain name. + +83 +00:04:26,000 --> 00:04:33,000 +You may want to register h y uh, u I k and m. + +84 +00:04:33,000 --> 00:04:35,000 +Basically what I'm doing is that I'm going around the key. + +85 +00:04:35,000 --> 00:04:36,000 +I'm going around the J's. + +86 +00:04:36,000 --> 00:04:40,000 +Now obviously this is going to result in a whole lot of domain names. + +87 +00:04:40,000 --> 00:04:46,000 +But if you are a super oops if you are a super popular website. + +88 +00:04:47,000 --> 00:04:52,000 +Whereby if you are a super popular website, you might need to do this. + +89 +00:04:52,000 --> 00:04:57,000 +Like for example, if you're Google and you're getting 100 million hits every day, as you guys can + +90 +00:04:57,000 --> 00:05:03,000 +see, this is something that even I can get caught with because sometimes I'm typing really quick and + +91 +00:05:03,000 --> 00:05:05,000 +boom, I'm not checking and I can get caught with it. + +92 +00:05:05,000 --> 00:05:09,000 +It's happened before and it's probably happened to you, uh, also. + +93 +00:05:09,000 --> 00:05:10,000 +So be sure. + +94 +00:05:11,000 --> 00:05:14,000 +To use bookmarks more often. + +95 +00:05:14,000 --> 00:05:17,000 +Train your users and be careful when typing in those URLs. + diff --git a/08 - Social Engineering/013 Training against Phishing OB 5.6_en.srt b/08 - Social Engineering/013 Training against Phishing OB 5.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..7b0ad1909bbf647a0b1590c612239b6b73bf49ce --- /dev/null +++ b/08 - Social Engineering/013 Training against Phishing OB 5.6_en.srt @@ -0,0 +1,700 @@ +1 +00:00:00,000 --> 00:00:04,000 +In an organization, you're going to implement all kinds of security controls from firewalls, intrusion + +2 +00:00:04,000 --> 00:00:10,000 +detection systems, all kinds of physical security things, and to keep your organizations actually + +3 +00:00:10,000 --> 00:00:12,000 +secure, like door locks. + +4 +00:00:12,000 --> 00:00:19,000 +But in my opinion, one of the most control to implement, and I would argue at certain times better + +5 +00:00:19,000 --> 00:00:22,000 +than this firewall is user training. + +6 +00:00:22,000 --> 00:00:30,000 +You see, if we can teach users not to click on certain links in email, not to give away certain information + +7 +00:00:30,000 --> 00:00:33,000 +or how to suspect that, hey, this is not right. + +8 +00:00:33,000 --> 00:00:34,000 +This is bad. + +9 +00:00:34,000 --> 00:00:35,000 +Don't click on this. + +10 +00:00:35,000 --> 00:00:36,000 +Don't answer this. + +11 +00:00:36,000 --> 00:00:37,000 +Don't go here. + +12 +00:00:37,000 --> 00:00:38,000 +Don't do this. + +13 +00:00:38,000 --> 00:00:44,000 +User training is really important because if you don't train your users, you're going to keep getting + +14 +00:00:44,000 --> 00:00:45,000 +attacks over and over. + +15 +00:00:45,000 --> 00:00:49,000 +You see, attackers can't break through this firewall. + +16 +00:00:49,000 --> 00:00:51,000 +They can't just get through this device. + +17 +00:00:51,000 --> 00:00:53,000 +This device is hard core, hard as hell to get through. + +18 +00:00:53,000 --> 00:01:00,000 +But if we get a user to click on a link, then the user initiated the connection from behind the firewall, + +19 +00:01:00,000 --> 00:01:05,000 +and the firewall lets it through because the firewall thought, hey, this guy over here wants it and + +20 +00:01:05,000 --> 00:01:07,000 +I have to do whatever the people in here want. + +21 +00:01:07,000 --> 00:01:09,000 +Nothing for the people outside. + +22 +00:01:10,000 --> 00:01:14,000 +So how do we stop all these kinds of external threats? + +23 +00:01:14,000 --> 00:01:17,000 +Well, one of the best ways to do it is to do user training. + +24 +00:01:17,000 --> 00:01:22,000 +And one of the most important thing to guard against is going to be phishing attacks. + +25 +00:01:22,000 --> 00:01:27,000 +I'm not talking phishing, a stream of actual fish, but phishing with a pH. + +26 +00:01:27,000 --> 00:01:32,000 +This is a kind of a social engineering attack where attackers deceives deceives individuals into provide + +27 +00:01:32,000 --> 00:01:39,000 +insensitive information such as log in credentials or financial details by masquerading as a trustworthy + +28 +00:01:39,000 --> 00:01:41,000 +entity in digital communications. + +29 +00:01:41,000 --> 00:01:44,000 +Now, I want you guys to understand this. + +30 +00:01:44,000 --> 00:01:46,000 +What exactly is phishing? + +31 +00:01:46,000 --> 00:01:52,000 +You've probably got that email from some bank that you probably dealt business with or you didn't. + +32 +00:01:52,000 --> 00:01:55,000 +You probably got an email from PayPal or something. + +33 +00:01:55,000 --> 00:01:59,000 +There's a there has been fraudulent activity against your account. + +34 +00:01:59,000 --> 00:02:02,000 +Click on this link to log into your bank so they can steal your credential. + +35 +00:02:03,000 --> 00:02:04,000 +This is a common thing. + +36 +00:02:04,000 --> 00:02:06,000 +Phishing happens every day. + +37 +00:02:06,000 --> 00:02:09,000 +In fact, I probably get 2 to 3 phishing emails every single day. + +38 +00:02:09,000 --> 00:02:10,000 +And maybe you too. + +39 +00:02:11,000 --> 00:02:13,000 +Now in this video, we're talking about user training. + +40 +00:02:14,000 --> 00:02:17,000 +How do we train our users to detect phishing emails? + +41 +00:02:17,000 --> 00:02:21,000 +How do we tell them or teach them that, hey, you know what? + +42 +00:02:21,000 --> 00:02:22,000 +That is bad. + +43 +00:02:22,000 --> 00:02:24,000 +Don't click on that. + +44 +00:02:24,000 --> 00:02:27,000 +Now, some phishing emails could be really convincing. + +45 +00:02:27,000 --> 00:02:29,000 +So what you do is you do all kinds of training. + +46 +00:02:29,000 --> 00:02:31,000 +We have another video coming on that how to train them. + +47 +00:02:31,000 --> 00:02:33,000 +But you do all kinds of training. + +48 +00:02:33,000 --> 00:02:34,000 +Then you have to test. + +49 +00:02:34,000 --> 00:02:37,000 +Do they actually did they actually learn something? + +50 +00:02:37,000 --> 00:02:40,000 +One of the ways of doing that is by doing a phishing campaign yourself. + +51 +00:02:40,000 --> 00:02:45,000 +This involves sending fraudulent communications, often emails that appear to come from legitimate sources + +52 +00:02:45,000 --> 00:02:46,000 +to users. + +53 +00:02:47,000 --> 00:02:52,000 +The campaigns are usually mass distributed, targeting a large number of recipients and hope that someone + +54 +00:02:52,000 --> 00:02:53,000 +will respond. + +55 +00:02:53,000 --> 00:02:59,000 +These campaigns mimic the look and feel of legitimate emails, comments from companies, banks, or + +56 +00:02:59,000 --> 00:02:59,000 +email. + +57 +00:03:00,000 --> 00:03:00,000 +A government. + +58 +00:03:00,000 --> 00:03:06,000 +Now, what this does in campaigns or fishing campaigns, but you're going to be doing here is you're + +59 +00:03:06,000 --> 00:03:13,000 +basically going to be sending out emails to a mass number of users that looks like it comes from a bank + +60 +00:03:13,000 --> 00:03:14,000 +or some financial institutions. + +61 +00:03:14,000 --> 00:03:16,000 +You're going to see who clicks on it. + +62 +00:03:16,000 --> 00:03:21,000 +Now there's actual software that does this, and there's organizations that does this for you to test + +63 +00:03:21,000 --> 00:03:22,000 +your users to see. + +64 +00:03:22,000 --> 00:03:27,000 +Hey, does your users actually know that this is a phishing email? + +65 +00:03:27,000 --> 00:03:31,000 +And then they track, like how many people click the link, how many people gave the data and how many + +66 +00:03:31,000 --> 00:03:32,000 +people didn't? + +67 +00:03:32,000 --> 00:03:35,000 +That way you know who needs to be retrained. + +68 +00:03:36,000 --> 00:03:41,000 +You want to teach your users how to recognize a phishing email, right? + +69 +00:03:41,000 --> 00:03:45,000 +Just don't test their ability to to to not get fish. + +70 +00:03:45,000 --> 00:03:47,000 +But how do they know? + +71 +00:03:47,000 --> 00:03:48,000 +Hey, that's a phishing email. + +72 +00:03:48,000 --> 00:03:50,000 +Well, there are things to look for. + +73 +00:03:50,000 --> 00:03:51,000 +For example. + +74 +00:03:52,000 --> 00:03:53,000 +Did the exodus? + +75 +00:03:53,000 --> 00:04:00,000 +Is it asking them for their private data, like their username and password or their credit card information? + +76 +00:04:00,000 --> 00:04:01,000 +Lots of time, folks. + +77 +00:04:01,000 --> 00:04:06,000 +That sends these things out may not have the right grammar, the right spelling. + +78 +00:04:06,000 --> 00:04:09,000 +That's always something that I've looked for before. + +79 +00:04:09,000 --> 00:04:14,000 +Suspicious links or email addresses that don't match the send the sponsored senders. + +80 +00:04:14,000 --> 00:04:18,000 +So sometimes they may say we're from Bank of America, but when you really check the email, it's from + +81 +00:04:18,000 --> 00:04:19,000 +a Gmail account. + +82 +00:04:19,000 --> 00:04:21,000 +Probably not the right way. + +83 +00:04:22,000 --> 00:04:23,000 +Uh, urgent or threatening language. + +84 +00:04:23,000 --> 00:04:27,000 +Okay, if you don't do this right now, all your data is going to be wiped out. + +85 +00:04:27,000 --> 00:04:31,000 +For example, offers them offers to anything that's too good to be true. + +86 +00:04:31,000 --> 00:04:32,000 +It's probably not true. + +87 +00:04:32,000 --> 00:04:33,000 +In other words, you win a million. + +88 +00:04:33,000 --> 00:04:36,000 +Have you guys ever heard of the worldwide lottery? + +89 +00:04:36,000 --> 00:04:36,000 +Have you guys? + +90 +00:04:36,000 --> 00:04:37,000 +I've seen this. + +91 +00:04:37,000 --> 00:04:40,000 +I've gotten emails about this many years ago. + +92 +00:04:41,000 --> 00:04:42,000 +They send you this thing called a worldwide lottery. + +93 +00:04:42,000 --> 00:04:45,000 +You've won the worldwide lottery because you have an email account. + +94 +00:04:45,000 --> 00:04:47,000 +You win a certain amount, amount of money. + +95 +00:04:47,000 --> 00:04:51,000 +You got to provide your personal information, unexpected attachments. + +96 +00:04:51,000 --> 00:04:53,000 +They're going to say open this attachment famous. + +97 +00:04:53,000 --> 00:04:58,000 +So this is like when they send you something from like Fedex telling you, oh, your package is delayed. + +98 +00:04:58,000 --> 00:04:59,000 +Check this out. + +99 +00:04:59,000 --> 00:04:59,000 +Label out. + +100 +00:05:00,000 --> 00:05:04,000 +Responding to reported suspicious messages. + +101 +00:05:04,000 --> 00:05:07,000 +It's critical that the organizations have a clear process. + +102 +00:05:07,000 --> 00:05:19,000 +How are you going to deal with when somebody receives bad emails, like, how does that person respond + +103 +00:05:19,000 --> 00:05:19,000 +to this? + +104 +00:05:19,000 --> 00:05:23,000 +So let's say you're a user in an organization and you just got a phishing email. + +105 +00:05:23,000 --> 00:05:24,000 +What do you do? + +106 +00:05:24,000 --> 00:05:25,000 +Right? + +107 +00:05:25,000 --> 00:05:27,000 +Does the organization actually have a reporting process. + +108 +00:05:27,000 --> 00:05:32,000 +So this involves educating employees on how to report suspected phishing emails. + +109 +00:05:32,000 --> 00:05:35,000 +Do you have a dedicated team or channel for them to track this? + +110 +00:05:36,000 --> 00:05:37,000 +Unreported. + +111 +00:05:37,000 --> 00:05:44,000 +Take immediate action if a phishing attempt is confirmed, such as blocking the sender's email, alerting + +112 +00:05:44,000 --> 00:05:49,000 +other employees and securely, and securing potential compromise accounts. + +113 +00:05:49,000 --> 00:05:52,000 +So if somebody was phishing, they gave away the credential. + +114 +00:05:52,000 --> 00:05:53,000 +Make sure to change that conduct. + +115 +00:05:53,000 --> 00:05:56,000 +Follow up investigations here is going to be super important. + +116 +00:05:56,000 --> 00:06:00,000 +Now anomalous behavior activity. + +117 +00:06:00,000 --> 00:06:01,000 +Here's what this is. + +118 +00:06:01,000 --> 00:06:06,000 +Teach them how to detect when behaviors is not normal. + +119 +00:06:06,000 --> 00:06:11,000 +So anomalous behavior refers to activities or actions within the organization network systems. + +120 +00:06:11,000 --> 00:06:13,000 +That is not normal. + +121 +00:06:13,000 --> 00:06:16,000 +The deviate from the norm or expected pattern. + +122 +00:06:16,000 --> 00:06:21,000 +Such behavior is critical for early detection of security incidents, including those that are risky, + +123 +00:06:21,000 --> 00:06:23,000 +unexpected, or unintentional. + +124 +00:06:23,000 --> 00:06:25,000 +Now, when it comes to. + +125 +00:06:26,000 --> 00:06:28,000 +Well, odd things happen. + +126 +00:06:28,000 --> 00:06:33,000 +I'm going to give you guys an example of, of of an anomalous user activity or behavior. + +127 +00:06:34,000 --> 00:06:38,000 +Let's say a user is supposed to they come to work every day at 9:00. + +128 +00:06:38,000 --> 00:06:39,000 +They leave at 5:00. + +129 +00:06:39,000 --> 00:06:45,000 +What if you notice that at 9:00 in their night, that system is downloading and changing data? + +130 +00:06:46,000 --> 00:06:47,000 +That's pretty odd, isn't it? + +131 +00:06:47,000 --> 00:06:48,000 +Right. + +132 +00:06:48,000 --> 00:06:48,000 +That's pretty. + +133 +00:06:48,000 --> 00:06:49,000 +That's not normal. + +134 +00:06:50,000 --> 00:06:51,000 +Normal is 9 to 5. + +135 +00:06:51,000 --> 00:06:53,000 +Why are they doing this at 9:00 now? + +136 +00:06:53,000 --> 00:06:57,000 +It could be because they just got VPN access and they just remote desktop into their machine. + +137 +00:06:57,000 --> 00:07:00,000 +It could be, but it probably isn't. + +138 +00:07:00,000 --> 00:07:02,000 +It sounds like somebody have hacked the machine. + +139 +00:07:02,000 --> 00:07:03,000 +So. + +140 +00:07:04,000 --> 00:07:09,000 +We want to teach our users that, teach them that, hey, if you if you detect anything that's out of + +141 +00:07:09,000 --> 00:07:12,000 +the norm to report that, especially if it's your account. + +142 +00:07:12,000 --> 00:07:13,000 +So risky behavior. + +143 +00:07:13,000 --> 00:07:18,000 +This involves actions that significantly increase the likelihood of security or data loss. + +144 +00:07:18,000 --> 00:07:24,000 +So let our teach your users that these are going to be things that are risky things that you probably + +145 +00:07:24,000 --> 00:07:30,000 +want to report, such as employees bypassing security protocols, using unauthorized devices access + +146 +00:07:30,000 --> 00:07:33,000 +and sensitive data without a legitimate need. + +147 +00:07:33,000 --> 00:07:38,000 +If you're working in IT security and you see any of this, you got to be like, hey, that's not normal. + +148 +00:07:38,000 --> 00:07:39,000 +They shouldn't be doing that. + +149 +00:07:39,000 --> 00:07:45,000 +You should have good security awareness program that educate employees on what constitutes risky behavior + +150 +00:07:45,000 --> 00:07:48,000 +and consequences that may happen. + +151 +00:07:49,000 --> 00:07:51,000 +Unexpected behaviors. + +152 +00:07:51,000 --> 00:07:57,000 +These are activities that are out of the ordinary for, uh, for particular users or systems that are + +153 +00:07:57,000 --> 00:07:59,000 +not immediately malicious. + +154 +00:07:59,000 --> 00:08:04,000 +Security awareness training should emphasize the importance of reporting unexpected behavior. + +155 +00:08:04,000 --> 00:08:06,000 +Now, I mentioned unexpected behavior earlier. + +156 +00:08:06,000 --> 00:08:12,000 +This is like when a user is trying to access data at 9:00 in the night, or accessing data on the weekends + +157 +00:08:12,000 --> 00:08:14,000 +when they generally does not. + +158 +00:08:15,000 --> 00:08:16,000 +Now, sometimes. + +159 +00:08:16,000 --> 00:08:18,000 +People do things. + +160 +00:08:19,000 --> 00:08:22,000 +That didn't didn't mean to. + +161 +00:08:22,000 --> 00:08:24,000 +This is going to be unintentional. + +162 +00:08:24,000 --> 00:08:30,000 +This is security incidents that occurred due to unintentional actions, such as them clicking unofficial + +163 +00:08:30,000 --> 00:08:34,000 +link or mis configuring a system or accidentally sharing information. + +164 +00:08:34,000 --> 00:08:41,000 +The best way to stop unintentional behavior is to train them on how to recognize that their actions + +165 +00:08:41,000 --> 00:08:42,000 +could affect the systems. + +166 +00:08:42,000 --> 00:08:48,000 +A lot of times, people don't realize that their account, if compromised, can really affect the entire + +167 +00:08:48,000 --> 00:08:49,000 +network. + +168 +00:08:49,000 --> 00:08:50,000 +So it's something we want to do. + +169 +00:08:50,000 --> 00:08:53,000 +We want to educate them on that. + +170 +00:08:53,000 --> 00:08:54,000 +Okay. + +171 +00:08:54,000 --> 00:08:57,000 +So you train your users well when it comes to phishing. + +172 +00:08:58,000 --> 00:09:02,000 +You have to train our users against that, because that's going to be the number one way that they're + +173 +00:09:02,000 --> 00:09:06,000 +going to try to break into your organization through your users is by doing phishing. + +174 +00:09:06,000 --> 00:09:09,000 +Fishing is only getting more and more complicated every single day. + +175 +00:09:09,000 --> 00:09:13,000 +That's why you got to make sure you train your users well. + diff --git a/08 - Social Engineering/014 Security Awareness Program OB 5.6_en.srt b/08 - Social Engineering/014 Security Awareness Program OB 5.6_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..6d9697a8bea577585dbdcf3ee1fee184c422d08d --- /dev/null +++ b/08 - Social Engineering/014 Security Awareness Program OB 5.6_en.srt @@ -0,0 +1,656 @@ +1 +00:00:00,000 --> 00:00:07,000 +When it comes to teaching users good security practices, an organization must implement good security + +2 +00:00:07,000 --> 00:00:08,000 +awareness training. + +3 +00:00:08,000 --> 00:00:14,000 +Security awareness training is when the organization is going to go through a variety of different topics + +4 +00:00:14,000 --> 00:00:20,000 +that I want to mention some of them in this video that users should be aware of, so they're more secure + +5 +00:00:20,000 --> 00:00:22,000 +when utilizing company systems. + +6 +00:00:22,000 --> 00:00:25,000 +For example, don't click on that link, don't answer this call. + +7 +00:00:25,000 --> 00:00:26,000 +Don't give out this information. + +8 +00:00:26,000 --> 00:00:32,000 +So what we want to do is we want to equip our users with knowledge and skills needed to recognize, + +9 +00:00:32,000 --> 00:00:38,000 +respond to, and prevent any kind of security threats against the organization that's coming through + +10 +00:00:38,000 --> 00:00:38,000 +them. + +11 +00:00:38,000 --> 00:00:43,000 +For example, like from a phishing attempt, we spoke about, effective user training covers a wide + +12 +00:00:43,000 --> 00:00:45,000 +range of topics and practices. + +13 +00:00:45,000 --> 00:00:47,000 +Ensure that users understand their role. + +14 +00:00:47,000 --> 00:00:51,000 +It acts as a first line of defense against all kinds of cyber threats. + +15 +00:00:51,000 --> 00:00:54,000 +And if you're wondering, okay, so what are some of these things that we want to cover? + +16 +00:00:54,000 --> 00:00:55,000 +Let's go over them. + +17 +00:00:56,000 --> 00:01:02,000 +Now, a lot of the security training that we're going to be teaching them may come in the form of in + +18 +00:01:02,000 --> 00:01:03,000 +a company's handbook. + +19 +00:01:03,000 --> 00:01:08,000 +A lot of organizations have policies and their procedures, things that they want their users to do + +20 +00:01:08,000 --> 00:01:11,000 +or not do already in the company handbook. + +21 +00:01:11,000 --> 00:01:13,000 +So this is probably one of the first place that people can look. + +22 +00:01:13,000 --> 00:01:20,000 +So these are going to be comprehensive guides that outline the organization's cybersecurity policies, + +23 +00:01:20,000 --> 00:01:21,000 +procedures and expectations. + +24 +00:01:21,000 --> 00:01:27,000 +It generally serves as a reference point to understand what their users should be doing and not doing. + +25 +00:01:29,000 --> 00:01:30,000 +Training includes. + +26 +00:01:30,000 --> 00:01:35,000 +Being familiarized in training should include familiarizing the employees with these handbooks so they + +27 +00:01:35,000 --> 00:01:39,000 +should look over the company's handbook or the information security handbook. + +28 +00:01:39,000 --> 00:01:41,000 +A lot of times company gives these out. + +29 +00:01:41,000 --> 00:01:46,000 +It could be built into the company's own handbook, or it could be a separate handbook that the companies + +30 +00:01:46,000 --> 00:01:46,000 +give out. + +31 +00:01:46,000 --> 00:01:52,000 +The users have to read, sign that they read and acknowledge it, and then give back a sign, some kind + +32 +00:01:52,000 --> 00:01:53,000 +of a sign page. + +33 +00:01:54,000 --> 00:01:57,000 +Teach your users how to be situational aware. + +34 +00:01:57,000 --> 00:02:02,000 +Training should focus on their ability to detect potential cybersecurity threats every day, such as + +35 +00:02:02,000 --> 00:02:03,000 +a phishing email. + +36 +00:02:03,000 --> 00:02:09,000 +This includes suspicious emails, unusual system behavior for example, if a user see that there's some + +37 +00:02:09,000 --> 00:02:15,000 +kind of encryption message pop up on their screen, or users see that the system is very slow, or the + +38 +00:02:15,000 --> 00:02:18,000 +mouse is moving erratically on the screen like somebody took control of it. + +39 +00:02:18,000 --> 00:02:20,000 +They should know that to report that. + +40 +00:02:22,000 --> 00:02:24,000 +Insider threats. + +41 +00:02:24,000 --> 00:02:29,000 +So a lot of times when people think of somebody stealing your data and hacking your information, a + +42 +00:02:29,000 --> 00:02:33,000 +lot of times that comes from outside the organization, not really. + +43 +00:02:33,000 --> 00:02:36,000 +A lot of times that's from the inside the organization. + +44 +00:02:36,000 --> 00:02:40,000 +Insider threats are employees that are already working with you, that are probably trying to destroy + +45 +00:02:40,000 --> 00:02:46,000 +your system or, and, or steal your information could be for competitor purpose or just for malicious + +46 +00:02:46,000 --> 00:02:48,000 +gains or personal malicious gains. + +47 +00:02:48,000 --> 00:02:50,000 +I should say you want to teach. + +48 +00:02:50,000 --> 00:02:56,000 +Users should be educated about these risks posed by insider threats, whether it's intentional or unintentional. + +49 +00:02:56,000 --> 00:02:59,000 +How do you recognize sign about a potential insider threats? + +50 +00:02:59,000 --> 00:03:06,000 +For example, what if they see that Bob is not happy working at this company, but they noticed that + +51 +00:03:06,000 --> 00:03:11,000 +Bob plugs in a memory stick and is copying a lot of data off their systems. + +52 +00:03:11,000 --> 00:03:12,000 +That could be a potential insider threat. + +53 +00:03:12,000 --> 00:03:18,000 +What if they noticed that Bob is going to the filing cabinet a lot more often, and just photocopying + +54 +00:03:18,000 --> 00:03:19,000 +data and walking out? + +55 +00:03:20,000 --> 00:03:25,000 +That could be a potential insider threats, and people should be reporting that teach users how to manage + +56 +00:03:25,000 --> 00:03:32,000 +passwords is not much I can say here, other than people don't know how to create strong, secure passwords. + +57 +00:03:32,000 --> 00:03:35,000 +Teach them ways to memorize those passwords. + +58 +00:03:36,000 --> 00:03:43,000 +Uh, tell them don't reuse passwords and show them ways and methods of how they could, how they could + +59 +00:03:43,000 --> 00:03:49,000 +actually not reuse password, but also make it easy teach them about password management tools, things + +60 +00:03:49,000 --> 00:03:51,000 +like LastPass. + +61 +00:03:51,000 --> 00:03:56,000 +Uh, in which case that's a password manager that you can use to manage passwords and keep them nice + +62 +00:03:56,000 --> 00:03:57,000 +and complex. + +63 +00:03:59,000 --> 00:04:07,000 +Sometimes you might be walking down your parking lot or the road and you see a USB stick on the ground. + +64 +00:04:07,000 --> 00:04:07,000 +So what do you do? + +65 +00:04:07,000 --> 00:04:08,000 +You pick it up. + +66 +00:04:08,000 --> 00:04:09,000 +You want to know what's inside. + +67 +00:04:09,000 --> 00:04:10,000 +You plug it into your system. + +68 +00:04:10,000 --> 00:04:13,000 +By doing that, you just gave yourself a back door. + +69 +00:04:13,000 --> 00:04:19,000 +This is that's a very famous hack, by the way, in which case they just leave malicious memory sticks + +70 +00:04:19,000 --> 00:04:25,000 +or removable drive on the road, or in the parking lot of the bank and bank employees, or somebody + +71 +00:04:25,000 --> 00:04:27,000 +just picks it up, plugs it in, and boom, it's a back door. + +72 +00:04:27,000 --> 00:04:30,000 +It gives the attacker access to the internal system. + +73 +00:04:30,000 --> 00:04:36,000 +Now, removable media like USB drive trainers should highlight the dangers of non trusted media. + +74 +00:04:36,000 --> 00:04:39,000 +Make sure people don't plug it in. + +75 +00:04:40,000 --> 00:04:41,000 +He also has cables. + +76 +00:04:41,000 --> 00:04:44,000 +By the way, there are these, uh, charging cables. + +77 +00:04:44,000 --> 00:04:46,000 +They look like good charging cables. + +78 +00:04:46,000 --> 00:04:49,000 +Uh, you guys can check out a website called Hak5. + +79 +00:04:49,000 --> 00:04:50,000 +They sell these cables. + +80 +00:04:50,000 --> 00:04:52,000 +They look like normal cables. + +81 +00:04:52,000 --> 00:04:56,000 +They look like a normal Apple or USB charging cable. + +82 +00:04:56,000 --> 00:04:59,000 +But when you plug it in and you charge your phone and your computer, boom! + +83 +00:04:59,000 --> 00:05:00,000 +It steals your data. + +84 +00:05:03,000 --> 00:05:05,000 +Train your users how to detect social engineer. + +85 +00:05:05,000 --> 00:05:09,000 +And one of the most common attack vectors is, of course, social engineering phishing. + +86 +00:05:09,000 --> 00:05:11,000 +Remember, it's a kind of a social engineering. + +87 +00:05:11,000 --> 00:05:16,000 +Teach them how to detect calls, in which case it may be asking them for information. + +88 +00:05:16,000 --> 00:05:19,000 +Tell them how to resist social engineering, basically. + +89 +00:05:19,000 --> 00:05:22,000 +Hang up the phone, what is pretext and beaten and so on. + +90 +00:05:22,000 --> 00:05:23,000 +Now. + +91 +00:05:23,000 --> 00:05:25,000 +Operational security measures. + +92 +00:05:25,000 --> 00:05:32,000 +Let them know all the different things that we do in the organization to maintain the CIA, right? + +93 +00:05:32,000 --> 00:05:37,000 +Covert things like how we handle documents, how do we dispose of sensitive information, like teach + +94 +00:05:37,000 --> 00:05:38,000 +them? + +95 +00:05:38,000 --> 00:05:42,000 +Well, when you're finished this financial document to please shred it, just don't put it in the garbage + +96 +00:05:42,000 --> 00:05:44,000 +and make sure backups are done. + +97 +00:05:45,000 --> 00:05:51,000 +Now, if they're going to be working from home, that pulls a whole new thing, because when somebody + +98 +00:05:51,000 --> 00:05:54,000 +is at home, you can't control that system. + +99 +00:05:54,000 --> 00:06:00,000 +So remote and or hybrid work is unique because they're going to be working from home. + +100 +00:06:00,000 --> 00:06:02,000 +Is their home network secure? + +101 +00:06:02,000 --> 00:06:05,000 +Are they using a VPN to get into the network? + +102 +00:06:05,000 --> 00:06:07,000 +The importance of maintaining physical security at home? + +103 +00:06:07,000 --> 00:06:12,000 +Because if somebody breaks into their home and steals the company's equipment, especially if the company's + +104 +00:06:12,000 --> 00:06:15,000 +laptop, the company's data could be in trouble risk. + +105 +00:06:15,000 --> 00:06:20,000 +Make sure they don't take the laptop to Starbucks and join those Starbucks public Wi-Fi, so educate + +106 +00:06:20,000 --> 00:06:21,000 +them about that. + +107 +00:06:22,000 --> 00:06:28,000 +Now they have to be somewhere in there when we teach them about reporting and monitoring. + +108 +00:06:29,000 --> 00:06:35,000 +Now, if they detect some kind of bad activity, what do they do? + +109 +00:06:35,000 --> 00:06:36,000 +How do they report it? + +110 +00:06:36,000 --> 00:06:42,000 +So this practice involves continuous observation of network and systems of what's happening. + +111 +00:06:42,000 --> 00:06:46,000 +This enabled organizations to quickly detect and respond to threats. + +112 +00:06:46,000 --> 00:06:49,000 +The fast that people report threats, the faster we respond. + +113 +00:06:49,000 --> 00:06:51,000 +This ensures ongoing compliance. + +114 +00:06:51,000 --> 00:06:56,000 +Now there's what's called initial reporting and what's called reoccurring monitoring and reporting. + +115 +00:06:56,000 --> 00:07:02,000 +So initial reporting is referred to action taken by user automated system when a potential security + +116 +00:07:02,000 --> 00:07:03,000 +threat is identified. + +117 +00:07:03,000 --> 00:07:08,000 +What's the procedure in your organization that if they detect that something has gone wrong, how do + +118 +00:07:08,000 --> 00:07:15,000 +they report that that's initial reported or I just I found this phishing email and I mistakenly clicked + +119 +00:07:15,000 --> 00:07:15,000 +on it. + +120 +00:07:15,000 --> 00:07:15,000 +What do I do? + +121 +00:07:15,000 --> 00:07:17,000 +You know, or I got this phishing email. + +122 +00:07:17,000 --> 00:07:19,000 +How do I report this. + +123 +00:07:19,000 --> 00:07:23,000 +And then you must do this on a continuous, continuous way. + +124 +00:07:23,000 --> 00:07:25,000 +Don't think it stops. + +125 +00:07:25,000 --> 00:07:28,000 +It's continuously going. + +126 +00:07:28,000 --> 00:07:33,000 +You're going to continuously be receiving this and tell your users to continuously keep reporting it. + +127 +00:07:33,000 --> 00:07:36,000 +So do regular security audits. + +128 +00:07:36,000 --> 00:07:42,000 +Conduct security audits of the organization to see are we still maintaining good security practices + +129 +00:07:42,000 --> 00:07:45,000 +and identify and close any vulnerabilities? + +130 +00:07:45,000 --> 00:07:51,000 +Continuous monitoring includes tools for implementing tools and processes for real time monitoring. + +131 +00:07:52,000 --> 00:07:52,000 +Now. + +132 +00:07:53,000 --> 00:07:55,000 +When it comes to good security program. + +133 +00:07:56,000 --> 00:07:57,000 +The development is ongoing. + +134 +00:07:57,000 --> 00:08:01,000 +Don't think you're going to develop a good security training program and you're done. + +135 +00:08:01,000 --> 00:08:04,000 +Actually, you basically just got started because it never ends. + +136 +00:08:04,000 --> 00:08:05,000 +Why? + +137 +00:08:05,000 --> 00:08:07,000 +Because security changes every day. + +138 +00:08:07,000 --> 00:08:09,000 +So it's an ongoing process. + +139 +00:08:09,000 --> 00:08:14,000 +Create and enhance it and maintain the effectiveness of your security awareness program utilizes a dynamic + +140 +00:08:14,000 --> 00:08:19,000 +and effective security awareness program that educates and engages people. + +141 +00:08:19,000 --> 00:08:25,000 +Now, education is good teaching people, but engage them doing phishing campaigns. + +142 +00:08:25,000 --> 00:08:28,000 +Let them become part of the actual education. + +143 +00:08:29,000 --> 00:08:31,000 +Stays current with the evolving landscape. + +144 +00:08:31,000 --> 00:08:36,000 +Remember, what we teach them today is outdated, could be outdated tomorrow. + +145 +00:08:36,000 --> 00:08:37,000 +What we teach them. + +146 +00:08:37,000 --> 00:08:39,000 +What kind of phishing emails are out there today? + +147 +00:08:39,000 --> 00:08:41,000 +Tomorrow it could be a whole new method of phishing emails then. + +148 +00:08:41,000 --> 00:08:42,000 +Now we have to go and teach them. + +149 +00:08:43,000 --> 00:08:43,000 +And of course. + +150 +00:08:43,000 --> 00:08:48,000 +And finally, when you've set up your program, you got to execute your program. + +151 +00:08:48,000 --> 00:08:53,000 +This refers to the practical application and enactment of the Design Cyber Security Awareness training + +152 +00:08:53,000 --> 00:08:53,000 +program. + +153 +00:08:54,000 --> 00:08:58,000 +So it's a critical this is critical because this is where we're going to put the strategies into place. + +154 +00:08:58,000 --> 00:09:00,000 +So we have to implement the program. + +155 +00:09:00,000 --> 00:09:03,000 +We got to make sure the people follow this program. + +156 +00:09:03,000 --> 00:09:09,000 +We have to train the user as well to ensure that they understand what role they play, what they should + +157 +00:09:09,000 --> 00:09:14,000 +be doing, what they shouldn't be doing, how to detect potential threats, where they reported, where + +158 +00:09:14,000 --> 00:09:20,000 +do you continuously report it, and don't think your security awareness training program is a one shot? + +159 +00:09:20,000 --> 00:09:21,000 +It's a one time thing. + +160 +00:09:21,000 --> 00:09:23,000 +It's a continuous thing. + +161 +00:09:23,000 --> 00:09:25,000 +Don't forget, employees comes and go all the time. + +162 +00:09:25,000 --> 00:09:28,000 +Employees that you have today are not going to be with you tomorrow. + +163 +00:09:28,000 --> 00:09:34,000 +And of course the security measures changes the firewall, change the vision, change the attack changes. + +164 +00:09:34,000 --> 00:09:37,000 +So this is something that's definitely ongoing. + diff --git a/08 - Social Engineering/015 Quick Quiz.html b/08 - Social Engineering/015 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..9eceac6aea9867b5deb0e2fc02b01fec11b6de3d --- /dev/null +++ b/08 - Social Engineering/015 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/09 - Securing IT Assets/001 Segmentation OB 2.5_en.srt b/09 - Securing IT Assets/001 Segmentation OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..eaf452f870f8b5eeb5d8d1ec9d9daa9eb3bb1b83 --- /dev/null +++ b/09 - Securing IT Assets/001 Segmentation OB 2.5_en.srt @@ -0,0 +1,308 @@ +1 +00:00:00,000 --> 00:00:08,000 +When it comes to protecting a network, one of the most important things you must do is call segmentation + +2 +00:00:08,000 --> 00:00:10,000 +or segmenting your network. + +3 +00:00:10,000 --> 00:00:11,000 +Why would you segment networks? + +4 +00:00:11,000 --> 00:00:15,000 +Well, I want to show you guys a couple of things. + +5 +00:00:15,000 --> 00:00:15,000 +All right. + +6 +00:00:15,000 --> 00:00:17,000 +Look at the picture I have at the bottom. + +7 +00:00:17,000 --> 00:00:24,000 +Now in this picture what they have done is they have segmented this network with something we call VLANs. + +8 +00:00:24,000 --> 00:00:31,000 +Segmentation is about splitting a network into multiple segments or subnets, each functioning as a + +9 +00:00:31,000 --> 00:00:33,000 +smaller, separate network. + +10 +00:00:33,000 --> 00:00:35,000 +Now why do we do this. + +11 +00:00:35,000 --> 00:00:40,000 +Well it's going to not only is it going to increase security, but it's also going to increase performance + +12 +00:00:40,000 --> 00:00:41,000 +on the actual network. + +13 +00:00:41,000 --> 00:00:46,000 +Now I have a switch here and this is a Cisco switch. + +14 +00:00:46,000 --> 00:00:52,000 +And this particular switch here is a Cisco 2900 series switch. + +15 +00:00:52,000 --> 00:00:57,000 +This particular switch supports VLANs or virtual Lans. + +16 +00:00:57,000 --> 00:01:00,000 +Now this is not really a networking class to go over virtual Lans. + +17 +00:01:00,000 --> 00:01:01,000 +But remember something. + +18 +00:01:01,000 --> 00:01:05,000 +Virtual Lans allows you to segment an entire network. + +19 +00:01:05,000 --> 00:01:11,000 +And if computers let's say on this segment right here, computers on this segment, let's say this is + +20 +00:01:11,000 --> 00:01:17,000 +a Vlan, computers on this Vlan will not be able to communicate with computers on this particular Vlan. + +21 +00:01:18,000 --> 00:01:23,000 +So what you're doing with a switch like this is you're separating the network traffic. + +22 +00:01:23,000 --> 00:01:26,000 +So let's say I go into this switch and I configured a switch. + +23 +00:01:26,000 --> 00:01:32,000 +When I configured a switch I say like this one here is going to be Vlan one. + +24 +00:01:32,000 --> 00:01:34,000 +This is going to be a count in. + +25 +00:01:34,000 --> 00:01:37,000 +This one here is going to be Vlan two. + +26 +00:01:37,000 --> 00:01:38,000 +This is going to be sales. + +27 +00:01:38,000 --> 00:01:40,000 +This one here is Vlan three. + +28 +00:01:40,000 --> 00:01:42,000 +This is going to be all my management. + +29 +00:01:42,000 --> 00:01:48,000 +So computers here can't communicate with computers here and can't communicate with computers here. + +30 +00:01:48,000 --> 00:01:54,000 +In fact, all the broadcast traffic that we have within our networks will stay within these ports. + +31 +00:01:54,000 --> 00:01:58,000 +They will not be able to jump over into ports over here. + +32 +00:01:58,000 --> 00:02:00,000 +They will not be able to jump over to ports over here. + +33 +00:02:00,000 --> 00:02:04,000 +Why is this important, though, when it comes to the world of security? + +34 +00:02:04,000 --> 00:02:11,000 +Let's say this computer right here that's plugged in to this port, let's say this computer gets infected + +35 +00:02:11,000 --> 00:02:16,000 +with a virus, this computer, and particularly a worm, if you remember worms from malware section. + +36 +00:02:16,000 --> 00:02:20,000 +If this port gets a worm, what is that worm going to do? + +37 +00:02:20,000 --> 00:02:26,000 +That worm is going to scan this port, this port, this port, and this port to infect it. + +38 +00:02:26,000 --> 00:02:29,000 +Remember, the worms infects computers by itself. + +39 +00:02:29,000 --> 00:02:34,000 +But if you have it with VLANs and you have segmented your network, then the worm cannot jump the Vlan + +40 +00:02:34,000 --> 00:02:35,000 +and go here. + +41 +00:02:36,000 --> 00:02:36,000 +All right. + +42 +00:02:36,000 --> 00:02:40,000 +The worm wouldn't be able to cross the segments and jump over. + +43 +00:02:40,000 --> 00:02:45,000 +So that way whatever happens here in this Vlan stays there. + +44 +00:02:45,000 --> 00:02:47,000 +It doesn't go anywhere else. + +45 +00:02:47,000 --> 00:02:51,000 +That's why you want to have segmentation in the world of security. + +46 +00:02:51,000 --> 00:02:55,000 +It is super important to do segmentation. + +47 +00:02:55,000 --> 00:03:01,000 +Now segmentation is because when you vlan them, if you notice in this diagram I have here, when they + +48 +00:03:01,000 --> 00:03:06,000 +did the VLANs two, three and four, they were also run on a different subnet. + +49 +00:03:06,000 --> 00:03:12,000 +This is 10.10 dot 20 that 30 and that 40 all slash 20 fours. + +50 +00:03:12,000 --> 00:03:13,000 +Hopefully you guys know networking. + +51 +00:03:14,000 --> 00:03:18,000 +Um and this is done with a switch just like that one that I just put down there. + +52 +00:03:18,000 --> 00:03:21,000 +So why do we want to do segmentation. + +53 +00:03:21,000 --> 00:03:24,000 +Segmentation is done to increase security. + +54 +00:03:24,000 --> 00:03:30,000 +That way if something happens on one segment, it does not affect what happens on another segment. + +55 +00:03:30,000 --> 00:03:31,000 +If a computer. + +56 +00:03:32,000 --> 00:03:38,000 +Gets infected on one segment, that infection doesn't flow to all the segments in the network. + +57 +00:03:38,000 --> 00:03:41,000 +The another thing we want to do it for is increasing of speed. + +58 +00:03:41,000 --> 00:03:46,000 +Remember, the more computers on a switch, the more broadcast than you have. + +59 +00:03:46,000 --> 00:03:46,000 +You don't have collisions. + +60 +00:03:46,000 --> 00:03:51,000 +It's not a it's not a hub, but you're going to have a lot of broadcast and traffic and then everybody + +61 +00:03:51,000 --> 00:03:52,000 +can access anything. + +62 +00:03:52,000 --> 00:03:56,000 +Another good reason you want to segment network is just to separation of traffic. + +63 +00:03:56,000 --> 00:03:57,000 +So let's say Vlan two. + +64 +00:03:57,000 --> 00:04:01,000 +In this diagram is sales and this is accounting Vlan three. + +65 +00:04:01,000 --> 00:04:07,000 +Well do you want sales people being able to see and log in to the accounting servers. + +66 +00:04:07,000 --> 00:04:09,000 +Salespeople don't need access to that. + +67 +00:04:09,000 --> 00:04:12,000 +So we're restricting what they can access to. + +68 +00:04:12,000 --> 00:04:19,000 +This is another reason segmentation is amazing for security when it comes to network security. + +69 +00:04:19,000 --> 00:04:24,000 +It is vital and super important that you segment your network. + +70 +00:04:24,000 --> 00:04:33,000 +Segmentation is one of the most basic network security technology that we should be implementing. + +71 +00:04:33,000 --> 00:04:34,000 +All right. + +72 +00:04:34,000 --> 00:04:35,000 +As simple as that. + +73 +00:04:35,000 --> 00:04:44,000 +In my opinion, segmentation is just as important as firewalls and patching your machine intrusion detection + +74 +00:04:44,000 --> 00:04:44,000 +systems. + +75 +00:04:44,000 --> 00:04:46,000 +It's basic security. + +76 +00:04:46,000 --> 00:04:54,000 +So make sure that you segment your network to not just increase its speed, but also importantly, increase + +77 +00:04:54,000 --> 00:04:55,000 +its security. + diff --git a/09 - Securing IT Assets/002 Isolation OB 2.5_en.srt b/09 - Securing IT Assets/002 Isolation OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9ffd6982d6b11f21dda4ad0433f3716b2557ba98 --- /dev/null +++ b/09 - Securing IT Assets/002 Isolation OB 2.5_en.srt @@ -0,0 +1,348 @@ +1 +00:00:00,000 --> 00:00:01,000 +On my desk. + +2 +00:00:01,000 --> 00:00:02,000 +I have a laptop. + +3 +00:00:02,000 --> 00:00:04,000 +This is my personal laptop. + +4 +00:00:04,000 --> 00:00:13,000 +This laptop contains top secret, super ultra top secret data that I don't want anybody to ever access. + +5 +00:00:13,000 --> 00:00:14,000 +So how do I keep it secure? + +6 +00:00:14,000 --> 00:00:18,000 +Well, it's it has drive encryption, so it's fully encrypted. + +7 +00:00:18,000 --> 00:00:22,000 +And what I did was that it's not connected to any network. + +8 +00:00:22,000 --> 00:00:24,000 +It doesn't have a wireless card. + +9 +00:00:24,000 --> 00:00:26,000 +I took out the wireless card that was inside of it. + +10 +00:00:27,000 --> 00:00:30,000 +Uh, it doesn't have any particular network cables going into it. + +11 +00:00:30,000 --> 00:00:38,000 +There is no way to access this machine unless you physically come and stand in front of it and log in + +12 +00:00:38,000 --> 00:00:40,000 +like I am doing right now. + +13 +00:00:40,000 --> 00:00:45,000 +There's no way no computer on this network can access this machine. + +14 +00:00:46,000 --> 00:00:50,000 +This computer is thought to be in this topic of this video. + +15 +00:00:50,000 --> 00:00:54,000 +This computer is thought to be in isolation. + +16 +00:00:55,000 --> 00:00:57,000 +What exactly is isolation? + +17 +00:00:58,000 --> 00:01:05,000 +Isolation is generally a process where you completely, completely and I mean complete, completely + +18 +00:01:05,000 --> 00:01:10,000 +segregate different parts of a computer network, system or application to prevent unauthorized access + +19 +00:01:10,000 --> 00:01:14,000 +and minimize the risk of contamination from malicious attacks. + +20 +00:01:14,000 --> 00:01:18,000 +So in this one, this is a computer. + +21 +00:01:18,000 --> 00:01:24,000 +You can also isolate entire networks in, particularly some kind of a network that stores or manages + +22 +00:01:24,000 --> 00:01:27,000 +complex or very top secret information. + +23 +00:01:27,000 --> 00:01:28,000 +Why do we do this? + +24 +00:01:28,000 --> 00:01:34,000 +Well, we do this to contain potential security breaches and limit their impact on all types of broader + +25 +00:01:34,000 --> 00:01:34,000 +systems. + +26 +00:01:35,000 --> 00:01:36,000 +Now. + +27 +00:01:36,000 --> 00:01:42,000 +If this sounds like the topic I covered previously, which is segmentation. + +28 +00:01:42,000 --> 00:01:45,000 +You see there's segmentation and there's isolation. + +29 +00:01:46,000 --> 00:01:49,000 +And this is a topic that confuses most IT folks. + +30 +00:01:49,000 --> 00:01:52,000 +And there is a difference between them. + +31 +00:01:52,000 --> 00:01:55,000 +You see the difference between isolation and segmentation is this. + +32 +00:01:55,000 --> 00:01:59,000 +And isolation is about completely separation. + +33 +00:01:59,000 --> 00:02:07,000 +There is no connection and no possible connection between the isolated system or network and any other + +34 +00:02:07,000 --> 00:02:08,000 +computer system or network. + +35 +00:02:08,000 --> 00:02:14,000 +So when this when a system is isolated, there is no way to access that system. + +36 +00:02:14,000 --> 00:02:17,000 +You can also isolate an entire section of a network. + +37 +00:02:18,000 --> 00:02:20,000 +Let's say I have three machines in the corner over there. + +38 +00:02:21,000 --> 00:02:26,000 +I can put a little switch and just have those three machines communicate with each other, but nothing + +39 +00:02:26,000 --> 00:02:26,000 +else. + +40 +00:02:26,000 --> 00:02:29,000 +Nothing else is plugged into that switch and there's no wireless. + +41 +00:02:29,000 --> 00:02:30,000 +Nothing. + +42 +00:02:30,000 --> 00:02:32,000 +Nothing more can hit those machines. + +43 +00:02:32,000 --> 00:02:35,000 +That's an isolated section of your network. + +44 +00:02:35,000 --> 00:02:42,000 +But if you remember from, uh, segmenting your network, they're all plugged in to the switch. + +45 +00:02:42,000 --> 00:02:45,000 +They're all on the VLANs of the switch. + +46 +00:02:45,000 --> 00:02:45,000 +Right? + +47 +00:02:45,000 --> 00:02:46,000 +They all are. + +48 +00:02:46,000 --> 00:02:47,000 +Some of them are here, some of them are here. + +49 +00:02:48,000 --> 00:02:55,000 +And even though they're separated by the VLANs they can still communicate with routers. + +50 +00:02:55,000 --> 00:03:00,000 +You can even set up points where Vlan one and Vlan two can communicate with each other. + +51 +00:03:01,000 --> 00:03:08,000 +So in segmentation they could there still is a type of a connection between the machines. + +52 +00:03:08,000 --> 00:03:13,000 +They may all go through a router to get to the internet for example, but in isolation none of that + +53 +00:03:13,000 --> 00:03:14,000 +now. + +54 +00:03:16,000 --> 00:03:19,000 +Segmentation is about dividing a larger entity. + +55 +00:03:19,000 --> 00:03:20,000 +Interconnect. + +56 +00:03:20,000 --> 00:03:23,000 +In isolation, the isolated systems do not interact. + +57 +00:03:23,000 --> 00:03:24,000 +All right. + +58 +00:03:25,000 --> 00:03:28,000 +If this one is isolated, it interacts with nothing. + +59 +00:03:28,000 --> 00:03:32,000 +But if within the isolated segment, they can communicate with each other, but they can't communicate + +60 +00:03:32,000 --> 00:03:36,000 +with with anyone else, they do not interact with each other. + +61 +00:03:36,000 --> 00:03:40,000 +So if one segment is isolated then this segment is isolated. + +62 +00:03:40,000 --> 00:03:41,000 +They can't communicate. + +63 +00:03:41,000 --> 00:03:47,000 +Remember that, whereas in segmentation, different segments may still have control, interactions and + +64 +00:03:47,000 --> 00:03:48,000 +connectivity. + +65 +00:03:48,000 --> 00:03:52,000 +Remember I told you you can allow connections between Vlan one and Vlan two. + +66 +00:03:53,000 --> 00:04:00,000 +Use case isolation is always more than likely going to use for highly sensitive operations where security + +67 +00:04:00,000 --> 00:04:05,000 +is super important, such as handling classified or top secret data. + +68 +00:04:05,000 --> 00:04:09,000 +Versus segmentation is a more common approach almost. + +69 +00:04:09,000 --> 00:04:10,000 +And I'll give you guys an example. + +70 +00:04:11,000 --> 00:04:16,000 +Almost all networks corporate networks today are isolated, are segmented. + +71 +00:04:16,000 --> 00:04:16,000 +And. + +72 +00:04:18,000 --> 00:04:24,000 +Uh, you're going to have segmentations for things like the accounting network, the sales network, + +73 +00:04:24,000 --> 00:04:29,000 +IT management research and development and so on and so on. + +74 +00:04:29,000 --> 00:04:36,000 +So all the all the different, I should say, divisions or functions within a business, but where the + +75 +00:04:36,000 --> 00:04:42,000 +business keeps its top secret, I mean, top secret data, not like credit card information, but more + +76 +00:04:42,000 --> 00:04:47,000 +like business secrets that only very few people will have access to. + +77 +00:04:47,000 --> 00:04:52,000 +And if that information is released, it can cause severe damage. + +78 +00:04:52,000 --> 00:05:00,000 +In systems like that, you're probably going to isolate it, because if there is ever any kind of malware + +79 +00:05:00,000 --> 00:05:06,000 +that can cross the Vlan, or there's deficiencies in this switch that does allow inter Vlan connections. + +80 +00:05:07,000 --> 00:05:12,000 +Then you're losing data because the data is at potentially to be lost. + +81 +00:05:12,000 --> 00:05:18,000 +But if this system, if this network or this machine is on or this machine itself is isolated, there's + +82 +00:05:18,000 --> 00:05:21,000 +nothing that can get to it, making it a super secure machine. + +83 +00:05:21,000 --> 00:05:25,000 +It's like the old saying, what's the world's most secure machine turned off and unplugged? + +84 +00:05:25,000 --> 00:05:27,000 +So basically that's what it is. + +85 +00:05:27,000 --> 00:05:28,000 +Okay. + +86 +00:05:28,000 --> 00:05:31,000 +So make sure you understand the difference between segmentation and isolation. + +87 +00:05:31,000 --> 00:05:36,000 +And depending on the classification of the data you may decide to segment it or isolate it. + diff --git a/09 - Securing IT Assets/003 Access Control OB 2.5_en.srt b/09 - Securing IT Assets/003 Access Control OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..39875a5a654ec0f68fe679562093154ebaf6ebd4 --- /dev/null +++ b/09 - Securing IT Assets/003 Access Control OB 2.5_en.srt @@ -0,0 +1,156 @@ +1 +00:00:00,000 --> 00:00:06,000 +When you work in a network, they're basically going to be two things in that network subjects and objects. + +2 +00:00:06,000 --> 00:00:14,000 +Within every single network, there's somebody trying to use something or some process software trying + +3 +00:00:14,000 --> 00:00:15,000 +to accomplish or use something. + +4 +00:00:16,000 --> 00:00:18,000 +And these are going to be referred to as subjects and objects. + +5 +00:00:19,000 --> 00:00:22,000 +Now, most of the time when people hear the word subjects, they think in users. + +6 +00:00:22,000 --> 00:00:23,000 +And it generally is. + +7 +00:00:23,000 --> 00:00:29,000 +But don't forget, subjects can also be processes that is trying to access a particular resource, like + +8 +00:00:29,000 --> 00:00:31,000 +a hardware or another piece of software. + +9 +00:00:31,000 --> 00:00:34,000 +Objects are things that subjects want. + +10 +00:00:34,000 --> 00:00:39,000 +For example, if you're a user in a network and you're trying to access a particular folder on a particular + +11 +00:00:39,000 --> 00:00:43,000 +system, that's going to be the object that you're trying to access. + +12 +00:00:43,000 --> 00:00:48,000 +Now, the whole world of information security is based on this. + +13 +00:00:48,000 --> 00:00:50,000 +This concept of access control. + +14 +00:00:50,000 --> 00:00:57,000 +And access control is basically controlling access between these subjects and objects. + +15 +00:00:57,000 --> 00:01:05,000 +Now really it's about granting or denying specific requests to obtain and use information and related + +16 +00:01:05,000 --> 00:01:06,000 +processes and services. + +17 +00:01:06,000 --> 00:01:14,000 +So we are going to be granting and or denying access to objects from these particular subjects. + +18 +00:01:14,000 --> 00:01:17,000 +This whole concept is called access control. + +19 +00:01:17,000 --> 00:01:20,000 +Now I want you guys to notice this concept. + +20 +00:01:20,000 --> 00:01:28,000 +Well, doesn't matter what security book you read, you're studying for a plus net plus security plus + +21 +00:01:28,000 --> 00:01:34,000 +C is a Cism, CISSP, all the security certifications, and even basic security. + +22 +00:01:34,000 --> 00:01:40,000 +One of the most conceptual thing they're going to say well, make sure to have access control. + +23 +00:01:40,000 --> 00:01:42,000 +Access control is a big word. + +24 +00:01:42,000 --> 00:01:47,000 +All it means is controlling, granting or denying access between subjects and objects. + +25 +00:01:47,000 --> 00:01:49,000 +The question is, how do you do that? + +26 +00:01:49,000 --> 00:01:52,000 +Well, that's going to be a whole different thing. + +27 +00:01:52,000 --> 00:01:59,000 +All of the things we do, such as windows permissions, usage of ACLs, firewalls, encryptions are + +28 +00:01:59,000 --> 00:02:06,000 +all considered access control because things like encryption and windows permission is how you're going + +29 +00:02:06,000 --> 00:02:10,000 +to provide access for Bob to access a particular folder. + +30 +00:02:11,000 --> 00:02:17,000 +So users are identified and granted certain rights to access and perform certain functions within their + +31 +00:02:17,000 --> 00:02:19,000 +actual systems. + +32 +00:02:19,000 --> 00:02:21,000 +So remember what access control is. + +33 +00:02:21,000 --> 00:02:24,000 +It's controlling the access between the subjects and the objects. + +34 +00:02:24,000 --> 00:02:31,000 +We want to make sure that subjects are granted only the access they need to objects that they need access + +35 +00:02:31,000 --> 00:02:33,000 +to, to get their job done. + +36 +00:02:33,000 --> 00:02:34,000 +Now we're going to expand on this. + +37 +00:02:34,000 --> 00:02:39,000 +So all the other things that I'm going to be covering, things like encryption, firewall, windows + +38 +00:02:39,000 --> 00:02:43,000 +permissions, all these other things that we're going to be covering in the realm of security is to + +39 +00:02:43,000 --> 00:02:47,000 +control the access between subjects and objects. + diff --git a/09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5_en.srt b/09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..efb437e8a940e3c52d6d2609b2257ac17b153a44 --- /dev/null +++ b/09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5_en.srt @@ -0,0 +1,300 @@ +1 +00:00:00,000 --> 00:00:07,000 +When you go and work in a particular network, you want to make sure that your users don't have too + +2 +00:00:07,000 --> 00:00:08,000 +much power. + +3 +00:00:08,000 --> 00:00:16,000 +There is a principle that all security professionals have to follow, and that principle is known as + +4 +00:00:16,000 --> 00:00:19,000 +the principle of least privilege. + +5 +00:00:19,000 --> 00:00:20,000 +What exactly is that? + +6 +00:00:20,000 --> 00:00:25,000 +Well, in its simplest form, it's just making sure that people don't have too much rights and too much + +7 +00:00:25,000 --> 00:00:27,000 +power on the network. + +8 +00:00:27,000 --> 00:00:28,000 +That's really all it is. + +9 +00:00:28,000 --> 00:00:29,000 +So what is it referred to? + +10 +00:00:29,000 --> 00:00:36,000 +Well, it's about limiting access, limiting access rights, limiting access rights for users accounts + +11 +00:00:36,000 --> 00:00:41,000 +and computing processes to only those resources absolutely required to do their job. + +12 +00:00:41,000 --> 00:00:43,000 +Let me give you some examples. + +13 +00:00:43,000 --> 00:00:46,000 +So let's say you have somebody in the accounting department. + +14 +00:00:47,000 --> 00:00:48,000 +They work in accounting. + +15 +00:00:48,000 --> 00:00:51,000 +Do they need access to the company's CRM? + +16 +00:00:52,000 --> 00:00:54,000 +They don't do sales. + +17 +00:00:54,000 --> 00:00:56,000 +CRM is what the sales people use. + +18 +00:00:56,000 --> 00:00:59,000 +Do they need access to the company's top secret data? + +19 +00:00:59,000 --> 00:01:00,000 +No. + +20 +00:01:00,000 --> 00:01:03,000 +Do they need access to the company's research and development data? + +21 +00:01:03,000 --> 00:01:04,000 +No. + +22 +00:01:04,000 --> 00:01:08,000 +They should only have access to one thing, just the accounting application. + +23 +00:01:08,000 --> 00:01:14,000 +And if they work in accounts receivable, in which case they're sending out invoices and receiving payments, + +24 +00:01:14,000 --> 00:01:15,000 +then that's all they should have. + +25 +00:01:15,000 --> 00:01:17,000 +They shouldn't be able to enter bills and pay bills. + +26 +00:01:17,000 --> 00:01:20,000 +They shouldn't be able to do bank reconciliation. + +27 +00:01:20,000 --> 00:01:23,000 +And if they're doing bank reconciliation, they shouldn't be paying bills. + +28 +00:01:23,000 --> 00:01:25,000 +This is the principles of least privilege. + +29 +00:01:25,000 --> 00:01:34,000 +Notice I am giving you access to objects that only you need to do, only your job. + +30 +00:01:34,000 --> 00:01:40,000 +You will have no other access, so dictates that individual or systems should be granted just minimal + +31 +00:01:40,000 --> 00:01:41,000 +access. + +32 +00:01:41,000 --> 00:01:46,000 +Now, a lot of times when people think principles of least privilege, they're thinking about user access + +33 +00:01:46,000 --> 00:01:46,000 +control. + +34 +00:01:46,000 --> 00:01:48,000 +This is what I'm just talking about. + +35 +00:01:49,000 --> 00:01:54,000 +Restricting them just to their job function. + +36 +00:01:54,000 --> 00:01:55,000 +Only that. + +37 +00:01:55,000 --> 00:01:59,000 +Another thing is, people shouldn't have too much power on a system. + +38 +00:02:00,000 --> 00:02:01,000 +Notice I have this one. + +39 +00:02:01,000 --> 00:02:02,000 +Administrative accounts. + +40 +00:02:03,000 --> 00:02:08,000 +System administrators have accounts with extensive privileges, but they should use accounts with standard + +41 +00:02:08,000 --> 00:02:09,000 +privileges. + +42 +00:02:09,000 --> 00:02:10,000 +This is a. + +43 +00:02:11,000 --> 00:02:13,000 +This is a no brainer on a network. + +44 +00:02:13,000 --> 00:02:20,000 +So if you work as an administrator right now in an organization, you probably have the administrator + +45 +00:02:20,000 --> 00:02:21,000 +password. + +46 +00:02:21,000 --> 00:02:25,000 +In other words, you are an administrator on the actual system. + +47 +00:02:25,000 --> 00:02:28,000 +When you log in, you can install any application. + +48 +00:02:29,000 --> 00:02:32,000 +You could change any settings, you could do whatever you want. + +49 +00:02:33,000 --> 00:02:33,000 +Why? + +50 +00:02:33,000 --> 00:02:35,000 +Because you're the network admin. + +51 +00:02:35,000 --> 00:02:40,000 +But you should never use that account to do daily tasks like check emails. + +52 +00:02:40,000 --> 00:02:44,000 +What if you mistakenly click on email and get the whole network infected with a worm? + +53 +00:02:44,000 --> 00:02:49,000 +Now that worm can run through the network as an administrator, for example. + +54 +00:02:49,000 --> 00:02:51,000 +Good principles of least privilege. + +55 +00:02:51,000 --> 00:02:57,000 +Your administrators will have two account, one with the admin privileges and one with non admin privileges. + +56 +00:02:57,000 --> 00:02:59,000 +Just a standard user account. + +57 +00:03:00,000 --> 00:03:07,000 +So when the administrator logs in to do his daily task daily things check in email, responding to people. + +58 +00:03:07,000 --> 00:03:09,000 +Browse on websites. + +59 +00:03:09,000 --> 00:03:11,000 +Use the standard user account. + +60 +00:03:11,000 --> 00:03:18,000 +When the administrator has to do administrative work installing software, then the administrator will + +61 +00:03:18,000 --> 00:03:20,000 +log in with the administrator account. + +62 +00:03:20,000 --> 00:03:26,000 +Another thing here is that the principle of least privileges is not just about users, it's also about + +63 +00:03:26,000 --> 00:03:27,000 +software and processes. + +64 +00:03:27,000 --> 00:03:32,000 +And what this is, is applications and services have to operate with least privileges. + +65 +00:03:33,000 --> 00:03:36,000 +Applications shouldn't be run in as administrators. + +66 +00:03:36,000 --> 00:03:40,000 +There are certain applications that will require admin privileges to even start. + +67 +00:03:40,000 --> 00:03:44,000 +That's probably not a good idea, because if that application is hacked, it can corrupt the entire + +68 +00:03:44,000 --> 00:03:45,000 +operating system. + +69 +00:03:45,000 --> 00:03:46,000 +It's not. + +70 +00:03:46,000 --> 00:03:48,000 +That app is basically running as an administrator. + +71 +00:03:48,000 --> 00:03:49,000 +So you don't want that. + +72 +00:03:49,000 --> 00:03:56,000 +You want to just limit the power of the application to just standard processes or standard elevation + +73 +00:03:56,000 --> 00:03:58,000 +versus an administrator elevation. + +74 +00:03:59,000 --> 00:04:04,000 +The principle of least privileges is one of the most common and basic IT security principle that is + +75 +00:04:04,000 --> 00:04:08,000 +out there, and it's one you need to make sure that your network is implementing. + diff --git a/09 - Securing IT Assets/005 Access Control List OB 2.5_en.srt b/09 - Securing IT Assets/005 Access Control List OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9a971d151c0ad7932fff90715bc09b6028a7c1a8 --- /dev/null +++ b/09 - Securing IT Assets/005 Access Control List OB 2.5_en.srt @@ -0,0 +1,136 @@ +1 +00:00:00,000 --> 00:00:07,000 +Whenever you configure devices such as my lovely firewall that I have here, which we will configure + +2 +00:00:07,000 --> 00:00:08,000 +later, by the way. + +3 +00:00:08,000 --> 00:00:09,000 +All right. + +4 +00:00:09,000 --> 00:00:14,000 +Later on in this section, in this course, when we get to firewalls, I'm going to log in to this device + +5 +00:00:14,000 --> 00:00:16,000 +and we'll set up some we'll open some ports. + +6 +00:00:16,000 --> 00:00:19,000 +I'll show you guys how to do port opening and all that great stuff on here. + +7 +00:00:19,000 --> 00:00:29,000 +Now when you configure devices like firewalls or routers, you're basically what you're doing is you're + +8 +00:00:29,000 --> 00:00:31,000 +going to allow in or disallow. + +9 +00:00:31,000 --> 00:00:36,000 +For example, when I configure this firewall I'm going to allow a certain port. + +10 +00:00:36,000 --> 00:00:41,000 +Maybe we have a web server on our network that we need to allow people to access. + +11 +00:00:41,000 --> 00:00:45,000 +Maybe we have certain VPNs that I need to allow. + +12 +00:00:45,000 --> 00:00:50,000 +You see this this particular thing I'm talking about is called an access control list. + +13 +00:00:50,000 --> 00:00:53,000 +Notice definition for your exam. + +14 +00:00:53,000 --> 00:00:56,000 +This is a list used by routers and other networking devices. + +15 +00:00:56,000 --> 00:00:58,000 +And again you can use it on a firewall. + +16 +00:00:58,000 --> 00:01:01,000 +And it's like the picture here I have is this device. + +17 +00:01:01,000 --> 00:01:08,000 +Uh this is a list that used by routers on the network devices to authorize or deny traffic to or from + +18 +00:01:08,000 --> 00:01:10,000 +a particular IP address based on a set of rules. + +19 +00:01:10,000 --> 00:01:15,000 +Now, in this particular one, they're doing it by IP address because they're talking about a router. + +20 +00:01:15,000 --> 00:01:21,000 +It can also be used on file system for managing access and controlling access to files and directories. + +21 +00:01:21,000 --> 00:01:25,000 +An access control list is not just something on a router, it's something on a firewall. + +22 +00:01:25,000 --> 00:01:27,000 +It's something on a on a folder. + +23 +00:01:27,000 --> 00:01:28,000 +It's something on a switch. + +24 +00:01:28,000 --> 00:01:37,000 +It's something that we use to either grant or deny access to users and or processes or computers. + +25 +00:01:37,000 --> 00:01:43,000 +So things like routers and switches, firewalls and even files and folders. + +26 +00:01:43,000 --> 00:01:46,000 +Now I do have a video coming up where we're going to talk about file permissions. + +27 +00:01:46,000 --> 00:01:52,000 +And when you see me grant access or deny access to somebody that's actually an ACL. + +28 +00:01:52,000 --> 00:01:55,000 +So remember what the ACL stands for. + +29 +00:01:55,000 --> 00:02:02,000 +Access control list is basically like it says, it's a list that controls access between the subjects + +30 +00:02:02,000 --> 00:02:03,000 +and the objects. + +31 +00:02:03,000 --> 00:02:08,000 +It's the list that says this one is denied, this one is allowed or nothing is allowed. + +32 +00:02:08,000 --> 00:02:09,000 +All is denied. + +33 +00:02:10,000 --> 00:02:11,000 +So that's all it is. + +34 +00:02:11,000 --> 00:02:17,000 +And it's implemented on a wide variety of things, such as files and folders to physical devices. + diff --git a/09 - Securing IT Assets/006 Filesystem Permissions OB 2.5_en.srt b/09 - Securing IT Assets/006 Filesystem Permissions OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3de7b83272da82a6dc1f51de626a634eda348b33 --- /dev/null +++ b/09 - Securing IT Assets/006 Filesystem Permissions OB 2.5_en.srt @@ -0,0 +1,688 @@ +1 +00:00:00,000 --> 00:00:05,000 +As a network administrator, one of the most important things you're going to be doing in terms of managing + +2 +00:00:05,000 --> 00:00:11,000 +and dealing with security is ensuring that people gets the right access to the resources they need, + +3 +00:00:11,000 --> 00:00:18,000 +and particularly things like files, documents, Excel sheets, uh, different types of databases and + +4 +00:00:18,000 --> 00:00:19,000 +so on. + +5 +00:00:19,000 --> 00:00:25,000 +This is an important topic because in this video I'm talking about file system permissions. + +6 +00:00:25,000 --> 00:00:28,000 +In this video I want to show you guys a folder and how this is actually done. + +7 +00:00:28,000 --> 00:00:33,000 +So what exactly is this file system permissions are the settings with files and directories. + +8 +00:00:33,000 --> 00:00:38,000 +Directories means another word for folder in a computer system that determine who can write. + +9 +00:00:38,000 --> 00:00:42,000 +Who can read, write and execute a particular file or directory. + +10 +00:00:43,000 --> 00:00:47,000 +They're basically this is the fundamentals of IT security. + +11 +00:00:47,000 --> 00:00:52,000 +For example, when you walk into an organization and you're working in that business and you double + +12 +00:00:52,000 --> 00:00:56,000 +click on on a file, do you have access to it or do you not have access to it? + +13 +00:00:56,000 --> 00:00:59,000 +They say access denied or it may grant you access. + +14 +00:00:59,000 --> 00:01:01,000 +And then you can get granular with the access. + +15 +00:01:01,000 --> 00:01:06,000 +For example, people may be able to read documents they wouldn't be able to add to it. + +16 +00:01:07,000 --> 00:01:11,000 +People will be able to write to documents or just be able to open it with execution. + +17 +00:01:12,000 --> 00:01:15,000 +Or you can give them control where they can add, they can delete. + +18 +00:01:15,000 --> 00:01:18,000 +So there's a variety of different permissions that can be done. + +19 +00:01:18,000 --> 00:01:22,000 +So I'm going to show you guys that in a few minutes there are different categories. + +20 +00:01:22,000 --> 00:01:26,000 +And I'm going to walk through some of those with you in this video coming up in a minute. + +21 +00:01:26,000 --> 00:01:27,000 +There's the owner the individual created. + +22 +00:01:27,000 --> 00:01:30,000 +The file generally has full permission over it. + +23 +00:01:30,000 --> 00:01:35,000 +They'll be able to read, write, execute, modify, delete and so on. + +24 +00:01:35,000 --> 00:01:38,000 +There are groups of users that we can add in, for example. + +25 +00:01:39,000 --> 00:01:42,000 +Understand the concept of groups and users. + +26 +00:01:42,000 --> 00:01:44,000 +Users belongs in groups. + +27 +00:01:44,000 --> 00:01:46,000 +And I'll show you that concept in this video too. + +28 +00:01:46,000 --> 00:01:51,000 +So for example, you can have Jane, Mary and Bob. + +29 +00:01:51,000 --> 00:01:54,000 +Maybe Jane and Bob works in the accounting group. + +30 +00:01:54,000 --> 00:01:55,000 +So you would have a group called accountant. + +31 +00:01:55,000 --> 00:02:00,000 +So when you assign permissions, don't assign permissions to individual users, assign permissions to + +32 +00:02:00,000 --> 00:02:03,000 +groups of people like the account and group. + +33 +00:02:03,000 --> 00:02:05,000 +That way you don't have to do it individually. + +34 +00:02:05,000 --> 00:02:09,000 +Speeds up time, makes it easier to manage, and then others, whoever else needs access may be. + +35 +00:02:09,000 --> 00:02:13,000 +Everyone else on the network could read it, but maybe they can't edit it. + +36 +00:02:14,000 --> 00:02:22,000 +So in this video, what I want to do with you guys is I want to show you guys, uh, users groups and + +37 +00:02:22,000 --> 00:02:25,000 +how to assign permissions on it. + +38 +00:02:25,000 --> 00:02:30,000 +Now, you don't need to know this part for your exam, but it's good to see the aspect of it. + +39 +00:02:30,000 --> 00:02:34,000 +If you've never seen this before, if you've done this a lot of work, just move on to the next video. + +40 +00:02:34,000 --> 00:02:35,000 +Let's get started on this. + +41 +00:02:35,000 --> 00:02:36,000 +So. + +42 +00:02:36,000 --> 00:02:40,000 +Here I am at my desktop and I'm going to create some users. + +43 +00:02:40,000 --> 00:02:41,000 +We're going to create some. + +44 +00:02:41,000 --> 00:02:43,000 +We're going to create A22 users. + +45 +00:02:43,000 --> 00:02:45,000 +I'm going to put them into a group okay. + +46 +00:02:45,000 --> 00:02:47,000 +So I'm going to right click on start. + +47 +00:02:47,000 --> 00:02:49,000 +This is Windows 10 by the way. + +48 +00:02:50,000 --> 00:02:52,000 +Very similar in Windows 11, by the way. + +49 +00:02:52,000 --> 00:02:56,000 +Uh, if you're using a mac, get windows. + +50 +00:02:57,000 --> 00:02:58,000 +It's my only thing. + +51 +00:02:58,000 --> 00:02:59,000 +So I'm going to right click on start. + +52 +00:02:59,000 --> 00:03:01,000 +I'm going to go to a computer management. + +53 +00:03:02,000 --> 00:03:04,000 +And let this open up. + +54 +00:03:04,000 --> 00:03:04,000 +Is it going to open up? + +55 +00:03:04,000 --> 00:03:05,000 +Here we go. + +56 +00:03:05,000 --> 00:03:07,000 +So I'm going to go to local users and groups. + +57 +00:03:07,000 --> 00:03:08,000 +I'm going to go to users. + +58 +00:03:08,000 --> 00:03:10,000 +And I'm going to make a couple of users. + +59 +00:03:10,000 --> 00:03:11,000 +We're going to say right click. + +60 +00:03:11,000 --> 00:03:12,000 +We're going to say new user. + +61 +00:03:12,000 --> 00:03:14,000 +And I'm going to say this one is Bob. + +62 +00:03:16,000 --> 00:03:16,000 +Oops. + +63 +00:03:16,000 --> 00:03:18,000 +We got to put in a password in there. + +64 +00:03:18,000 --> 00:03:19,000 +We do have a password policy. + +65 +00:03:20,000 --> 00:03:21,000 +Confirm the password. + +66 +00:03:21,000 --> 00:03:25,000 +Put in a nice complex we don't need to use to change a password. + +67 +00:03:25,000 --> 00:03:27,000 +We're going to create this user. + +68 +00:03:27,000 --> 00:03:28,000 +Okay. + +69 +00:03:28,000 --> 00:03:29,000 +So we got Bob. + +70 +00:03:29,000 --> 00:03:30,000 +We're going to make another user. + +71 +00:03:30,000 --> 00:03:32,000 +We're going to call this one Mary. + +72 +00:03:32,000 --> 00:03:34,000 +Give Mary a nice complex password. + +73 +00:03:41,000 --> 00:03:42,000 +All right. + +74 +00:03:42,000 --> 00:03:42,000 +Create, Mary. + +75 +00:03:42,000 --> 00:03:43,000 +Here we go. + +76 +00:03:43,000 --> 00:03:46,000 +Okay, so we got Bob, and we have Mary. + +77 +00:03:46,000 --> 00:03:48,000 +Now what I want to talk to you guys about. + +78 +00:03:48,000 --> 00:03:50,000 +This is how we would create users. + +79 +00:03:50,000 --> 00:03:56,000 +And when you do file system permissions, you don't assign the permission just to a user. + +80 +00:03:56,000 --> 00:03:58,000 +You assign a generate to groups. + +81 +00:03:58,000 --> 00:04:02,000 +If you manage a very small network and you only have like 5 or 6 users, it's fine. + +82 +00:04:02,000 --> 00:04:06,000 +But if you have big networks with thousands of people, you should put groups. + +83 +00:04:06,000 --> 00:04:10,000 +Groups are ways of just grouping users together, and it's generally done by departments like these. + +84 +00:04:10,000 --> 00:04:13,000 +People are an accountant, they're in finances and so on. + +85 +00:04:13,000 --> 00:04:14,000 +Okay. + +86 +00:04:14,000 --> 00:04:16,000 +Let's go in here and create that group now. + +87 +00:04:16,000 --> 00:04:19,000 +So we're going to go to groups I'm going to right click here. + +88 +00:04:19,000 --> 00:04:20,000 +And I'm going to say new group. + +89 +00:04:20,000 --> 00:04:23,000 +And you notice it doesn't really have a lot of options. + +90 +00:04:23,000 --> 00:04:25,000 +It's just asking me hey what's the group name. + +91 +00:04:25,000 --> 00:04:28,000 +So we're just going to go in here and say, uh, let's say. + +92 +00:04:29,000 --> 00:04:30,000 +Sales. + +93 +00:04:30,000 --> 00:04:32,000 +Everybody here works for sales. + +94 +00:04:32,000 --> 00:04:33,000 +Create this group. + +95 +00:04:33,000 --> 00:04:34,000 +Close this out. + +96 +00:04:34,000 --> 00:04:40,000 +Now, the thing with groups is that groups in its simplest form, doesn't really have any users in it. + +97 +00:04:40,000 --> 00:04:41,000 +You have to add users to group. + +98 +00:04:41,000 --> 00:04:44,000 +Remember, group is a way to quote unquote group the users. + +99 +00:04:44,000 --> 00:04:46,000 +So I'm just going to go in here to sales. + +100 +00:04:46,000 --> 00:04:47,000 +Double click on this. + +101 +00:04:49,000 --> 00:04:52,000 +And we are going to click add. + +102 +00:04:53,000 --> 00:04:58,000 +And we're going to search for Bob, and we're going to add Bob and Mary in here. + +103 +00:05:00,000 --> 00:05:00,000 +We're gonna apply that. + +104 +00:05:00,000 --> 00:05:05,000 +We're going to say, okay, so now that we have this, now what I want to talk to you guys about is + +105 +00:05:05,000 --> 00:05:06,000 +going to be. + +106 +00:05:07,000 --> 00:05:10,000 +So we have two users and we have a group. + +107 +00:05:10,000 --> 00:05:13,000 +What I want to show you guys is how we're going to do file permissions. + +108 +00:05:13,000 --> 00:05:18,000 +This way we can add permissions, uh, to a particular folder. + +109 +00:05:19,000 --> 00:05:21,000 +Was she able to do it by users and then by groups. + +110 +00:05:21,000 --> 00:05:23,000 +So you have a good understanding of this. + +111 +00:05:23,000 --> 00:05:24,000 +Let's take a look. + +112 +00:05:24,000 --> 00:05:25,000 +So I'm going to make a folder. + +113 +00:05:27,000 --> 00:05:31,000 +We are going to call this sales document. + +114 +00:05:32,000 --> 00:05:35,000 +And now I'm going to set the permissions on it. + +115 +00:05:35,000 --> 00:05:36,000 +So I'm going to right click on it. + +116 +00:05:36,000 --> 00:05:37,000 +I'm going to go to properties. + +117 +00:05:38,000 --> 00:05:39,000 +And we're going to go to security tab. + +118 +00:05:39,000 --> 00:05:44,000 +So here in the security tab you'll notice that I'm the owner I'm the one that created this. + +119 +00:05:44,000 --> 00:05:47,000 +You notice it says full control for me. + +120 +00:05:47,000 --> 00:05:50,000 +So I have full control of this particular folder. + +121 +00:05:52,000 --> 00:05:53,000 +Uh, the system. + +122 +00:05:53,000 --> 00:05:56,000 +This is the actual windows operating system, and this is the full administrator. + +123 +00:05:56,000 --> 00:06:00,000 +So we're going to leave those folks on there because that's fine. + +124 +00:06:00,000 --> 00:06:05,000 +I'm the owner, I created this, and any administrator will have access to this folder. + +125 +00:06:05,000 --> 00:06:08,000 +So what we're going to do here is we're going to say edit and we're going to say add. + +126 +00:06:08,000 --> 00:06:12,000 +And we can go in there and I want to show you how you can just add a user. + +127 +00:06:12,000 --> 00:06:14,000 +So we could say Mary click okay. + +128 +00:06:15,000 --> 00:06:21,000 +And we could say Mary, notice that Mary has read and execute. + +129 +00:06:21,000 --> 00:06:25,000 +So this means that she can open it, open any files that's within that folder. + +130 +00:06:25,000 --> 00:06:28,000 +And she can even see all the documents in there. + +131 +00:06:29,000 --> 00:06:30,000 +I'm going to apply that. + +132 +00:06:30,000 --> 00:06:33,000 +If I add Bob, search for Bob. + +133 +00:06:33,000 --> 00:06:35,000 +Let's say Bob has more permissions. + +134 +00:06:35,000 --> 00:06:36,000 +We can give Bob up to modify. + +135 +00:06:36,000 --> 00:06:39,000 +So what modify means is that he can open files. + +136 +00:06:39,000 --> 00:06:44,000 +He can write to files where it means he can update files and he can create new files. + +137 +00:06:44,000 --> 00:06:49,000 +The difference between modify and write is that in write he can add to files, but he can't make new + +138 +00:06:49,000 --> 00:06:50,000 +ones and modify he could. + +139 +00:06:51,000 --> 00:06:52,000 +You don't want to give people full control. + +140 +00:06:52,000 --> 00:06:58,000 +Full control means that they can actually add and remove permissions and you don't want that. + +141 +00:06:59,000 --> 00:07:00,000 +So I would do okay. + +142 +00:07:00,000 --> 00:07:01,000 +And I would say okay and okay. + +143 +00:07:01,000 --> 00:07:07,000 +Now in this, in this settings that I just did here with you guys was Mary. + +144 +00:07:07,000 --> 00:07:12,000 +She can if you if I log out of the machine and log back in, you'll notice that she can't add or delete + +145 +00:07:12,000 --> 00:07:14,000 +anything from the folder. + +146 +00:07:14,000 --> 00:07:20,000 +All she can do is read whatever documents is in there while Bob, he can add, delete, modify anything + +147 +00:07:20,000 --> 00:07:20,000 +in there. + +148 +00:07:20,000 --> 00:07:25,000 +Now this is file system permissions in terms of users. + +149 +00:07:25,000 --> 00:07:28,000 +When you have groups it's the same process. + +150 +00:07:28,000 --> 00:07:30,000 +Except you're not add an individual, you just add in groups. + +151 +00:07:30,000 --> 00:07:33,000 +If you have the whole account and group, you wouldn't need to add users. + +152 +00:07:33,000 --> 00:07:35,000 +So I'm just going to right click on this. + +153 +00:07:35,000 --> 00:07:36,000 +Let's do it with the group. + +154 +00:07:37,000 --> 00:07:40,000 +I'm going to go to edit and I'm going to remove this. + +155 +00:07:40,000 --> 00:07:44,000 +It's not very efficient to add just users. + +156 +00:07:44,000 --> 00:07:45,000 +It's better to add a group. + +157 +00:07:45,000 --> 00:07:50,000 +So you notice we're going to be searching this when we did sales right. + +158 +00:07:51,000 --> 00:07:52,000 +Here we go. + +159 +00:07:52,000 --> 00:07:53,000 +Here's the sales. + +160 +00:07:53,000 --> 00:07:55,000 +And you can see it's a group notice like two people. + +161 +00:07:55,000 --> 00:07:57,000 +We're going to give the sales people modify in here. + +162 +00:07:58,000 --> 00:07:58,000 +Fly that. + +163 +00:07:58,000 --> 00:08:05,000 +Okay, so now when Mary and Bob, Mary or Bob log in, they have modified permissions. + +164 +00:08:05,000 --> 00:08:08,000 +So using groups makes it a lot easier. + +165 +00:08:09,000 --> 00:08:10,000 +So that users in groups. + +166 +00:08:10,000 --> 00:08:16,000 +You also saw that the owner, which is I have full control over it, and you notice that file system + +167 +00:08:16,000 --> 00:08:18,000 +permissions is a very basic thing. + +168 +00:08:18,000 --> 00:08:20,000 +It is not complex. + +169 +00:08:20,000 --> 00:08:24,000 +As you can see, this video doesn't take that long, less than ten minutes to do, but it's something + +170 +00:08:24,000 --> 00:08:25,000 +that is vital. + +171 +00:08:25,000 --> 00:08:32,000 +There is no reason why people should have more access than they need in any network to get their job + +172 +00:08:32,000 --> 00:08:32,000 +done. + diff --git a/09 - Securing IT Assets/007 Application Allow List OB 2.5_en.srt b/09 - Securing IT Assets/007 Application Allow List OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..79e2ee5f1c3fd46f87ffe21085f3c1426d13b279 --- /dev/null +++ b/09 - Securing IT Assets/007 Application Allow List OB 2.5_en.srt @@ -0,0 +1,224 @@ +1 +00:00:00,000 --> 00:00:05,000 +I remember growing up and my mother always told me the more choices, the more mistakes. + +2 +00:00:05,000 --> 00:00:07,000 +So she always limited my choices. + +3 +00:00:07,000 --> 00:00:12,000 +And in an organization, in order to keep it secure, we need to be more like my mother. + +4 +00:00:12,000 --> 00:00:13,000 +We need to limit choices. + +5 +00:00:13,000 --> 00:00:19,000 +We need to ensure that users can't install anything they want on on a computer. + +6 +00:00:19,000 --> 00:00:24,000 +One of the things that we have to have installed on our computer, on our network or policy that we + +7 +00:00:24,000 --> 00:00:29,000 +should have, or a network, is what's called an application allowed list. + +8 +00:00:29,000 --> 00:00:30,000 +What exactly is that? + +9 +00:00:30,000 --> 00:00:36,000 +Well, it's basically a control mechanisms that permit only pre-approved applications to run on a system + +10 +00:00:36,000 --> 00:00:37,000 +or a network. + +11 +00:00:37,000 --> 00:00:42,000 +Applications not on the list are by default block or should not be running. + +12 +00:00:44,000 --> 00:00:47,000 +Now this here is really important. + +13 +00:00:47,000 --> 00:00:53,000 +Back in the days, this thing, we used to have two terms back in the days and we changed the terms + +14 +00:00:53,000 --> 00:00:55,000 +used to be called whitelist and blacklist. + +15 +00:00:55,000 --> 00:00:58,000 +Whitelist would be like these are the list of applications that are allowed on blacklist. + +16 +00:00:58,000 --> 00:01:00,000 +Are applications not allowed. + +17 +00:01:00,000 --> 00:01:02,000 +So in an application allow this. + +18 +00:01:02,000 --> 00:01:07,000 +What you do is you publish a list of apps that people can install, maybe on their phone list of apps. + +19 +00:01:07,000 --> 00:01:09,000 +That's acceptable. + +20 +00:01:09,000 --> 00:01:10,000 +List of application. + +21 +00:01:10,000 --> 00:01:12,000 +Uh, that's acceptable on computers. + +22 +00:01:12,000 --> 00:01:13,000 +Why would you do this? + +23 +00:01:13,000 --> 00:01:15,000 +Because it limits what people can install. + +24 +00:01:16,000 --> 00:01:17,000 +Okay. + +25 +00:01:17,000 --> 00:01:21,000 +It's basically denying things by default. + +26 +00:01:21,000 --> 00:01:26,000 +In other words, if something is not on the list, it's denied by default. + +27 +00:01:26,000 --> 00:01:33,000 +So if your if your company basically only utilize 4 or 5 different applications, then just put it on + +28 +00:01:33,000 --> 00:01:34,000 +that list. + +29 +00:01:34,000 --> 00:01:40,000 +For example, here at TI we use Microsoft Office very specialized database for managing students and + +30 +00:01:40,000 --> 00:01:40,000 +Adobe products. + +31 +00:01:40,000 --> 00:01:44,000 +That's all that we have on our application allowed list, nothing else that we ever need. + +32 +00:01:45,000 --> 00:01:52,000 +That means that no one is allowed to install any application on their machine, on their devices, or + +33 +00:01:52,000 --> 00:01:58,000 +on any processes that is not associated with things on the application allowed list. + +34 +00:01:58,000 --> 00:02:03,000 +Now, this is opposite to the more common known as practice of blocking known apps. + +35 +00:02:03,000 --> 00:02:06,000 +There are some companies that uses a blacklist approach in that. + +36 +00:02:06,000 --> 00:02:09,000 +In that approach, they're saying, well, don't install these things like these are the things you + +37 +00:02:09,000 --> 00:02:10,000 +don't want to put up. + +38 +00:02:11,000 --> 00:02:14,000 +These are the things you shouldn't be installing, but then everything else is allowed. + +39 +00:02:15,000 --> 00:02:20,000 +The more restrictive way would be to have an application allowed less. + +40 +00:02:20,000 --> 00:02:24,000 +That way, if somebody ever has a question, hey, can I install this? + +41 +00:02:24,000 --> 00:02:26,000 +Well, look at the application allowed list. + +42 +00:02:26,000 --> 00:02:28,000 +Well, it says no, that's not on the list. + +43 +00:02:28,000 --> 00:02:28,000 +I can't do it. + +44 +00:02:29,000 --> 00:02:31,000 +This limits what they can install. + +45 +00:02:31,000 --> 00:02:36,000 +And like my mother told me, the more choices, the more mistakes. + +46 +00:02:36,000 --> 00:02:37,000 +So what am I going to do? + +47 +00:02:37,000 --> 00:02:39,000 +I'm going to do what my mother did. + +48 +00:02:39,000 --> 00:02:45,000 +I'm going to restrict every single body to just a list of things that they can choose from that I have + +49 +00:02:45,000 --> 00:02:47,000 +tested, make sure they're not vulnerable. + +50 +00:02:47,000 --> 00:02:51,000 +I am also going to be supporting them and updating them. + +51 +00:02:51,000 --> 00:02:59,000 +So before an organization makes the application allowed list, they should be testing those applications + +52 +00:02:59,000 --> 00:03:02,000 +to make sure that they're compatible with their systems. + +53 +00:03:02,000 --> 00:03:04,000 +They don't cause any crashes. + +54 +00:03:04,000 --> 00:03:09,000 +Hopefully you do your work on the vendors of those published applications to make sure those vendors + +55 +00:03:09,000 --> 00:03:15,000 +keeps them updated and make sure that they're secure, because this is the one of the best ways to keep + +56 +00:03:15,000 --> 00:03:17,000 +your network secure. + diff --git a/09 - Securing IT Assets/008 Patching OB 2.5_en.srt b/09 - Securing IT Assets/008 Patching OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f2afa0c16f1cff5fe6f4f827f0aeb43968ae2d1b --- /dev/null +++ b/09 - Securing IT Assets/008 Patching OB 2.5_en.srt @@ -0,0 +1,344 @@ +1 +00:00:00,000 --> 00:00:05,000 +One of the most basic things you can do as a security administrator is keeping your machines updated. + +2 +00:00:05,000 --> 00:00:10,000 +You see software manufacturers and hardware manufacturers when they produce the hardware and or the + +3 +00:00:10,000 --> 00:00:17,000 +software, they can't predict all of the different problems bugs that can appear. + +4 +00:00:17,000 --> 00:00:22,000 +They can't predict all the different ways people are going to try to get around the software in order + +5 +00:00:22,000 --> 00:00:23,000 +to hack it. + +6 +00:00:23,000 --> 00:00:25,000 +So what they do, they release it. + +7 +00:00:25,000 --> 00:00:31,000 +And over time, hackers finds vulnerabilities, finds bugs or ways to hack their system. + +8 +00:00:32,000 --> 00:00:34,000 +Now what is it that the manufacturers do? + +9 +00:00:34,000 --> 00:00:34,000 +Well, they do this. + +10 +00:00:34,000 --> 00:00:35,000 +They patch it. + +11 +00:00:35,000 --> 00:00:37,000 +So what exactly is that? + +12 +00:00:37,000 --> 00:00:42,000 +This is about applying updates patches to software or systems. + +13 +00:00:42,000 --> 00:00:47,000 +These patches generally fix vulnerabilities, correct bugs, or some of them even provide new features. + +14 +00:00:47,000 --> 00:00:50,000 +So let's talk about patching here for a second because. + +15 +00:00:51,000 --> 00:00:54,000 +These are quite a few things to know about it. + +16 +00:00:54,000 --> 00:00:55,000 +All right. + +17 +00:00:55,000 --> 00:01:01,000 +And although it seems like basic 101, we should be updating our systems. + +18 +00:01:01,000 --> 00:01:03,000 +It's not uncommon. + +19 +00:01:03,000 --> 00:01:09,000 +In fact, it's very common to hear some organization was hacked yesterday, lost all the company data. + +20 +00:01:09,000 --> 00:01:09,000 +Why? + +21 +00:01:09,000 --> 00:01:11,000 +Because they didn't patch the machine. + +22 +00:01:11,000 --> 00:01:18,000 +Vulnerabilities in systems is generally happens or generally happens when some attacker finds that there + +23 +00:01:18,000 --> 00:01:19,000 +is a hole. + +24 +00:01:19,000 --> 00:01:19,000 +Maybe you're watching. + +25 +00:01:19,000 --> 00:01:21,000 +This one's a hole in the wall. + +26 +00:01:21,000 --> 00:01:22,000 +They found that hole. + +27 +00:01:22,000 --> 00:01:26,000 +And they're able to inject exploited to take advantage of the system. + +28 +00:01:27,000 --> 00:01:28,000 +What is the software maker? + +29 +00:01:28,000 --> 00:01:30,000 +Do they release the update? + +30 +00:01:30,000 --> 00:01:33,000 +But for some reason it never installed the update. + +31 +00:01:33,000 --> 00:01:35,000 +They got hacked and lost the data. + +32 +00:01:36,000 --> 00:01:39,000 +This is much more common than you can imagine. + +33 +00:01:39,000 --> 00:01:41,000 +Now, how do you push out the updates? + +34 +00:01:41,000 --> 00:01:45,000 +Well, there's really two ways to do it at home. + +35 +00:01:45,000 --> 00:01:46,000 +One at home. + +36 +00:01:46,000 --> 00:01:51,000 +The way you're going to do it, and I recommend is generally to have windows updates, for example, + +37 +00:01:51,000 --> 00:01:54,000 +or any application updates turned on to be automatic. + +38 +00:01:54,000 --> 00:01:59,000 +So what that means is that as the updates comes out, it boom installs on your computer. + +39 +00:01:59,000 --> 00:02:02,000 +In fact, every time you're logged into your machine and Microsoft says, hey, there's a bunch of updates, + +40 +00:02:02,000 --> 00:02:04,000 +can you restart your machine to do it? + +41 +00:02:04,000 --> 00:02:05,000 +Yes. + +42 +00:02:05,000 --> 00:02:07,000 +Do it because you don't want your machine vulnerable. + +43 +00:02:08,000 --> 00:02:11,000 +The other way, though, is the way organizations do it. + +44 +00:02:12,000 --> 00:02:16,000 +Organizations generally have a procedure that they follow. + +45 +00:02:16,000 --> 00:02:17,000 +They just don't push out. + +46 +00:02:17,000 --> 00:02:19,000 +They don't have automatic updates. + +47 +00:02:19,000 --> 00:02:22,000 +They have servers such as the Windows Update Server. + +48 +00:02:22,000 --> 00:02:25,000 +This is a machine that downloads all the updates. + +49 +00:02:25,000 --> 00:02:27,000 +So let's say there's 1000 machines in your network. + +50 +00:02:27,000 --> 00:02:31,000 +This is a server that downloads all the updates at Microsoft currently have. + +51 +00:02:32,000 --> 00:02:36,000 +Then the organization can go through and test each update against their systems. + +52 +00:02:36,000 --> 00:02:40,000 +You see, updating is great, but. + +53 +00:02:40,000 --> 00:02:42,000 +Updating has an issue. + +54 +00:02:42,000 --> 00:02:50,000 +Sometimes updates can wipe out configuration change like I had an update one time, wipe out a driver + +55 +00:02:50,000 --> 00:02:55,000 +and killed video cards for a large segment of our business. + +56 +00:02:55,000 --> 00:03:03,000 +So sometimes these updates can wipe out configuration, kill drivers, cause certain custom applications + +57 +00:03:03,000 --> 00:03:06,000 +to stop working, and even third party applications. + +58 +00:03:06,000 --> 00:03:11,000 +In other words, everything can be working great and fine today. + +59 +00:03:11,000 --> 00:03:16,000 +And then tomorrow we all come back and because the automatic updates were turned on, half of your segment + +60 +00:03:16,000 --> 00:03:18,000 +is dead or a bunch of machines don't work. + +61 +00:03:18,000 --> 00:03:23,000 +What if the update changes the driver on the Nic cards, and now none of the Nic cards in the company + +62 +00:03:23,000 --> 00:03:23,000 +work? + +63 +00:03:23,000 --> 00:03:25,000 +The whole network just got disabled. + +64 +00:03:26,000 --> 00:03:28,000 +Before in organizations. + +65 +00:03:28,000 --> 00:03:29,000 +They push out updates. + +66 +00:03:29,000 --> 00:03:30,000 +They're going to test the update. + +67 +00:03:30,000 --> 00:03:35,000 +Generally, they'll download the update to a test machine that has configurations similar to all the + +68 +00:03:35,000 --> 00:03:36,000 +computers in the network. + +69 +00:03:36,000 --> 00:03:44,000 +They're then going to they're then going to, uh, test it, make sure to install the updates, make + +70 +00:03:44,000 --> 00:03:46,000 +sure all the applications work when they're 100% good. + +71 +00:03:46,000 --> 00:03:50,000 +Then they're going to deploy those updated prescheduled time. + +72 +00:03:50,000 --> 00:03:54,000 +Now this of course is a problem because what happens here is the update comes out Tuesday. + +73 +00:03:54,000 --> 00:03:58,000 +The organization tests it Wednesday deploys it Thursday. + +74 +00:03:58,000 --> 00:04:02,000 +That means all day Wednesday the company was vulnerable. + +75 +00:04:02,000 --> 00:04:06,000 +But this is how it works. + +76 +00:04:06,000 --> 00:04:11,000 +You know they're vulnerable for a short period of time and then the company has to weigh is it worth + +77 +00:04:11,000 --> 00:04:13,000 +it to be vulnerable or. + +78 +00:04:14,000 --> 00:04:17,000 +Is it okay to push it out and cause a problem? + +79 +00:04:18,000 --> 00:04:19,000 +That's something the company has to weigh out. + +80 +00:04:19,000 --> 00:04:25,000 +But 99% of businesses out there, big businesses out there will generally test the update before rolling + +81 +00:04:25,000 --> 00:04:27,000 +the updates out. + +82 +00:04:27,000 --> 00:04:30,000 +Okay, but any which way, I want you guys to understand. + +83 +00:04:30,000 --> 00:04:33,000 +Their updates are vital. + +84 +00:04:33,000 --> 00:04:35,000 +Doesn't matter how much antivirus you have. + +85 +00:04:35,000 --> 00:04:39,000 +Okay, doesn't matter how much anti malware or how great your systems are, if you don't keep your machines + +86 +00:04:39,000 --> 00:04:45,000 +updated, you are vulnerable to all kinds of attacks. + diff --git a/09 - Securing IT Assets/009 Configuration Enforcement OB 2.5_en.srt b/09 - Securing IT Assets/009 Configuration Enforcement OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..49fec26b006d08a74ddb568dfa83048fbbedeaca --- /dev/null +++ b/09 - Securing IT Assets/009 Configuration Enforcement OB 2.5_en.srt @@ -0,0 +1,192 @@ +1 +00:00:00,000 --> 00:00:02,000 +So I'm holding up my sonic wall. + +2 +00:00:02,000 --> 00:00:08,000 +Configuring this device is not very complex, but once I configure the device, I got to make sure that + +3 +00:00:08,000 --> 00:00:13,000 +no one changes it without some kind of a change approval process. + +4 +00:00:13,000 --> 00:00:17,000 +You see, this device protects your entire network. + +5 +00:00:17,000 --> 00:00:20,000 +If anybody mis configures this device keyword configure. + +6 +00:00:20,000 --> 00:00:26,000 +If somebody mis configures this device or changes the configuration that we originally set up or that + +7 +00:00:26,000 --> 00:00:29,000 +we thought to be great, they could be punching a hole in my network. + +8 +00:00:29,000 --> 00:00:37,000 +For example, what if some knucklehead goes in here and opens up port 21, opens up port 80, opens + +9 +00:00:37,000 --> 00:00:39,000 +up some remote desktop port 3389. + +10 +00:00:39,000 --> 00:00:42,000 +That's going to cause a giant security flaw in your network. + +11 +00:00:42,000 --> 00:00:48,000 +So that brings me to this particular this particular topic. + +12 +00:00:48,000 --> 00:00:53,000 +And the topic here I'm talking about is called configuration enforcement. + +13 +00:00:53,000 --> 00:00:54,000 +What exactly is this? + +14 +00:00:54,000 --> 00:00:59,000 +Well, it's setting up and maintaining hardware and software configurations in an organization. + +15 +00:00:59,000 --> 00:01:02,000 +According to predefined security standards and policies. + +16 +00:01:02,000 --> 00:01:07,000 +So we want to make sure that all the hardware, not just this. + +17 +00:01:07,000 --> 00:01:13,000 +How about the switch that I have here or the router I have over there, the IDs systems. + +18 +00:01:13,000 --> 00:01:20,000 +The intrusion doesn't intrusion detection or prevention systems, your DLP systems, your Siem systems, + +19 +00:01:20,000 --> 00:01:26,000 +your server software, all the different software and hardware that we have on our network is configured + +20 +00:01:26,000 --> 00:01:30,000 +at a certain set of standards that we follow. + +21 +00:01:30,000 --> 00:01:34,000 +If anybody changes these things, they could be punching a hole in your network. + +22 +00:01:34,000 --> 00:01:36,000 +They could be causing availability issues. + +23 +00:01:36,000 --> 00:01:38,000 +They bringing down hardware. + +24 +00:01:38,000 --> 00:01:42,000 +It involves actively managing and enforcing these configurations to system. + +25 +00:01:42,000 --> 00:01:48,000 +The way to do this is to have stringent change management policies, which is something we'll talk more + +26 +00:01:48,000 --> 00:01:50,000 +about later on in the course. + +27 +00:01:51,000 --> 00:01:55,000 +So in change management processes, what you're doing is you're saying, well, if anybody wants to + +28 +00:01:55,000 --> 00:02:01,000 +change the configuration of this device, they have to go through a particular procedure or a process + +29 +00:02:01,000 --> 00:02:03,000 +that says, why do you want to change it? + +30 +00:02:03,000 --> 00:02:04,000 +What are you going to be changes? + +31 +00:02:04,000 --> 00:02:06,000 +What are the impact of the changes? + +32 +00:02:06,000 --> 00:02:10,000 +Is there a rollback procedure that if these changes go wrong, when are we going to schedule it? + +33 +00:02:10,000 --> 00:02:11,000 +Is it approved? + +34 +00:02:11,000 --> 00:02:12,000 +It's disapproved. + +35 +00:02:12,000 --> 00:02:14,000 +Let's get the changes scheduled. + +36 +00:02:14,000 --> 00:02:15,000 +Let's install it. + +37 +00:02:15,000 --> 00:02:17,000 +Let's test it and make sure it functions. + +38 +00:02:17,000 --> 00:02:18,000 +It's a lot of things there. + +39 +00:02:18,000 --> 00:02:19,000 +If you think about it. + +40 +00:02:19,000 --> 00:02:27,000 +There should never be a point where configuration in an organization changes without some kind of assessment + +41 +00:02:27,000 --> 00:02:30,000 +and approval or disapproval because. + +42 +00:02:31,000 --> 00:02:39,000 +When it comes to configuration, the wrong configuration can lead to really bad, really, really bad + +43 +00:02:39,000 --> 00:02:40,000 +security vulnerabilities. + +44 +00:02:40,000 --> 00:02:42,000 +It can lead to hackers breaking in. + +45 +00:02:42,000 --> 00:02:45,000 +It can lead to data being stolen. + +46 +00:02:46,000 --> 00:02:50,000 +So make sure that you manage configurations where you enforce configuration on devices. + +47 +00:02:50,000 --> 00:02:52,000 +Have a good change management policy. + +48 +00:02:52,000 --> 00:02:54,000 +So this never happens. + diff --git a/09 - Securing IT Assets/010 Decommissioning OB 2.5_en.srt b/09 - Securing IT Assets/010 Decommissioning OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..fee06b42583f21dcfdc09df8b963431127036107 --- /dev/null +++ b/09 - Securing IT Assets/010 Decommissioning OB 2.5_en.srt @@ -0,0 +1,316 @@ +1 +00:00:00,000 --> 00:00:03,000 +I absolutely love my sonic wall. + +2 +00:00:03,000 --> 00:00:03,000 +Okay. + +3 +00:00:03,000 --> 00:00:07,000 +And this is actually in the history of Tia. + +4 +00:00:07,000 --> 00:00:12,000 +This is the third one that we have over the life, over the life of this business. + +5 +00:00:12,000 --> 00:00:15,000 +We change these devices and the question is, why do we do that? + +6 +00:00:15,000 --> 00:00:18,000 +Well, because they become old. + +7 +00:00:18,000 --> 00:00:20,000 +And when they become old, they don't stop functioning. + +8 +00:00:20,000 --> 00:00:20,000 +All right. + +9 +00:00:20,000 --> 00:00:23,000 +These things will stay on for like ten years. + +10 +00:00:23,000 --> 00:00:28,000 +And, you know, as long as you have a good IT room this thing for like ten years and keep functioning. + +11 +00:00:28,000 --> 00:00:30,000 +I've never seen these things break. + +12 +00:00:30,000 --> 00:00:35,000 +But they do come to what's called the end of life, the EOL. + +13 +00:00:35,000 --> 00:00:43,000 +And what that means is that Sonic Wall themself, the company, they will actually stop sending out + +14 +00:00:43,000 --> 00:00:45,000 +updates to the device. + +15 +00:00:45,000 --> 00:00:50,000 +Now, if there is ever a vulnerability against it, P you're going to be vulnerable because if you use + +16 +00:00:50,000 --> 00:00:52,000 +an old device, there's no updates for it. + +17 +00:00:52,000 --> 00:00:56,000 +So let's say I'm using this device and Sonic Wall stopped supporting it. + +18 +00:00:56,000 --> 00:00:58,000 +If they stop supporting it, what happens then? + +19 +00:00:58,000 --> 00:01:01,000 +There is no more updates to it. + +20 +00:01:01,000 --> 00:01:07,000 +This is an end of life device, not this one, but the others that we have used, you see in an organization. + +21 +00:01:08,000 --> 00:01:10,000 +It comes a time where everything dies. + +22 +00:01:10,000 --> 00:01:13,000 +In other words, things are decommissioned. + +23 +00:01:13,000 --> 00:01:19,000 +For example, in a few more years, maybe in about 3 or 4 years, we'll have to decommission this device. + +24 +00:01:19,000 --> 00:01:28,000 +You guys may have databases, servers, uh, particular kinds of other devices, like routers and switches + +25 +00:01:28,000 --> 00:01:30,000 +that are decommissioned. + +26 +00:01:30,000 --> 00:01:31,000 +Now, what exactly is this? + +27 +00:01:31,000 --> 00:01:35,000 +Well, it's basically the process of formally removing an IT asset. + +28 +00:01:35,000 --> 00:01:42,000 +IT assets most people think is hardware, but it's also software or systems from an operational use. + +29 +00:01:42,000 --> 00:01:49,000 +It involves safely, safely and systematically retiring these assets to ensure no security vulnerabilities + +30 +00:01:49,000 --> 00:01:51,000 +introduced during or after the process. + +31 +00:01:51,000 --> 00:01:52,000 +Now, what do we mean by that? + +32 +00:01:52,000 --> 00:01:59,000 +Well, here's one of the common things that I saw quite often when things are decommissioned, you see, + +33 +00:01:59,000 --> 00:02:07,000 +when you're decommissioning, for example, a server, that server has what data if that server is not + +34 +00:02:07,000 --> 00:02:07,000 +decommissioned, right. + +35 +00:02:07,000 --> 00:02:11,000 +And you don't have the right process for it, they might just pull the server out of the rack and put + +36 +00:02:11,000 --> 00:02:12,000 +the thing in the garbage. + +37 +00:02:12,000 --> 00:02:15,000 +But what about all the data that was on those drives? + +38 +00:02:15,000 --> 00:02:21,000 +The organization needs to have a procedure to decommission that server. + +39 +00:02:21,000 --> 00:02:25,000 +That's going to be things like removing the hard drives, taking out the hard drives out of the server, + +40 +00:02:25,000 --> 00:02:28,000 +and destroying the memory chips that can still have data on it. + +41 +00:02:29,000 --> 00:02:30,000 +There's going to be nothing. + +42 +00:02:30,000 --> 00:02:33,000 +There's going to be no other data on the process or anything like that. + +43 +00:02:33,000 --> 00:02:39,000 +But things like removing the memory chips, removing the hard drives from them, the hard drives. + +44 +00:02:39,000 --> 00:02:41,000 +We haven't talked about hard drives yet. + +45 +00:02:42,000 --> 00:02:45,000 +Uh, but whenever we get around to it, we'll talk to hard drives somewhere in this course. + +46 +00:02:46,000 --> 00:02:48,000 +Are you going to degaussed those hard drive? + +47 +00:02:48,000 --> 00:02:49,000 +Are you going to shred those hard drives? + +48 +00:02:49,000 --> 00:02:51,000 +It's going to be part of your decommissioning. + +49 +00:02:51,000 --> 00:02:54,000 +So you have to have a process to decommission that server. + +50 +00:02:54,000 --> 00:02:57,000 +The process may be different for a device like this. + +51 +00:02:57,000 --> 00:03:00,000 +For a device like this, you may just factory reset it. + +52 +00:03:00,000 --> 00:03:05,000 +Just don't put it in the garbage, because if you just put it in the garbage and somebody do dumpster + +53 +00:03:05,000 --> 00:03:06,000 +diving, what is that? + +54 +00:03:06,000 --> 00:03:12,000 +That's an IT security firm where people go through your trash to find information on you. + +55 +00:03:12,000 --> 00:03:18,000 +So somebody dumpster dive this find this device gets into it, and then they can potentially brute force + +56 +00:03:18,000 --> 00:03:20,000 +the password, get into it. + +57 +00:03:20,000 --> 00:03:25,000 +They can take the they can see how we configure our network. + +58 +00:03:25,000 --> 00:03:26,000 +So you don't want that. + +59 +00:03:26,000 --> 00:03:28,000 +So maybe you factory reset it. + +60 +00:03:28,000 --> 00:03:29,000 +Maybe you shred it. + +61 +00:03:29,000 --> 00:03:37,000 +Every organization depending on what data that particular hardware and or software was stored, may + +62 +00:03:37,000 --> 00:03:40,000 +have to be deleted, wiped, shred. + +63 +00:03:40,000 --> 00:03:42,000 +There has to be a procedure for this and it's different for everything. + +64 +00:03:42,000 --> 00:03:50,000 +If there is a a database like a SQL server database, you just don't delete the database and degaussed + +65 +00:03:50,000 --> 00:03:52,000 +the hard drives or throw the hard drives away. + +66 +00:03:52,000 --> 00:03:56,000 +No, you have to remember a database has tons of data the organization still wants. + +67 +00:03:56,000 --> 00:04:02,000 +Is the data exported out of the database and stored in another database, or is the data just thrown + +68 +00:04:02,000 --> 00:04:02,000 +out? + +69 +00:04:02,000 --> 00:04:05,000 +Maybe the data is really old and not useful anymore. + +70 +00:04:06,000 --> 00:04:09,000 +Or maybe it's a it's an insurance company, a medical insurance company. + +71 +00:04:09,000 --> 00:04:13,000 +They have to keep the records for 100 years because regulation says so. + +72 +00:04:13,000 --> 00:04:17,000 +So the data has to be changed, formatted and then put into another system. + +73 +00:04:17,000 --> 00:04:22,000 +So when you're thinking decommission, the point I'm trying to make here is that you need to have a + +74 +00:04:22,000 --> 00:04:30,000 +process and a procedure within the organization to decommission hardware, software, all kinds of different + +75 +00:04:30,000 --> 00:04:31,000 +networks and systems out there. + +76 +00:04:31,000 --> 00:04:33,000 +You just don't put it in the garbage. + +77 +00:04:33,000 --> 00:04:36,000 +You don't ever want to open your system to vulnerabilities. + +78 +00:04:36,000 --> 00:04:41,000 +And you guys have to remember, this is going to be specific to different organizations and industries + +79 +00:04:41,000 --> 00:04:45,000 +that you follow, because regulations does dictate a lot of this. + diff --git a/09 - Securing IT Assets/011 Monitoring OB 2.5_en.srt b/09 - Securing IT Assets/011 Monitoring OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..a35ceca69183336964e22fbc36499ffeb97b9c62 --- /dev/null +++ b/09 - Securing IT Assets/011 Monitoring OB 2.5_en.srt @@ -0,0 +1,148 @@ +1 +00:00:00,000 --> 00:00:06,000 +When you work on a network, be prepared to see all kinds of traffic flowing through your network. + +2 +00:00:06,000 --> 00:00:14,000 +One of the main things we have to do as a network administrator is to continuously monitor our network + +3 +00:00:14,000 --> 00:00:18,000 +with all kinds of different software and hardware that we have. + +4 +00:00:18,000 --> 00:00:24,000 +So what exactly is monitoring what is continuously and actively examining various aspects of your network, + +5 +00:00:24,000 --> 00:00:28,000 +your systems or applications to ensure they're operating securely? + +6 +00:00:28,000 --> 00:00:34,000 +Now, this is going to be done with many of the different hardware and software devices that I'm going + +7 +00:00:34,000 --> 00:00:40,000 +to cover later, things like intrusion prevention and detection, both network based and host based, + +8 +00:00:40,000 --> 00:00:45,000 +both network based and host based firewalls, Siem systems and our DLP systems. + +9 +00:00:45,000 --> 00:00:51,000 +This combine all of these different hardware and software that I have listed here, is going to allow + +10 +00:00:51,000 --> 00:00:57,000 +us to monitor all the network traffic, applications and activities that the users are doing. + +11 +00:00:57,000 --> 00:01:00,000 +For example, Bob opened in that folder. + +12 +00:01:01,000 --> 00:01:06,000 +Uh, can be tracked with things such as different form of log files. + +13 +00:01:06,000 --> 00:01:09,000 +Those log files are read by Siem systems. + +14 +00:01:09,000 --> 00:01:09,000 +Bob. + +15 +00:01:09,000 --> 00:01:14,000 +Emailing that data out of the organizations can be tracked with a DLP system. + +16 +00:01:14,000 --> 00:01:19,000 +Traffic entering and flowing around the networks are generally could be read by intrusion prevention + +17 +00:01:19,000 --> 00:01:20,000 +and detection systems. + +18 +00:01:20,000 --> 00:01:25,000 +You also have firewalls that could prevent or stop traffic from coming in and out flowing those. + +19 +00:01:25,000 --> 00:01:31,000 +So there is a lot of ways that we are going to monitor our network traffic. + +20 +00:01:31,000 --> 00:01:35,000 +This is going to help us to detect unusual suspicious activity. + +21 +00:01:35,000 --> 00:01:39,000 +It's going to help us to identify potential security breaches. + +22 +00:01:39,000 --> 00:01:43,000 +And if the network gets really slow, traffic starts to slow down. + +23 +00:01:43,000 --> 00:01:48,000 +What these things are going to do is these things are going to allow us to see what can we improve to + +24 +00:01:48,000 --> 00:01:50,000 +improve the network performance. + +25 +00:01:50,000 --> 00:01:56,000 +I hear a lot about people always saying are they say quite often, especially when a network is too + +26 +00:01:56,000 --> 00:01:58,000 +slow, everything is too slow. + +27 +00:01:58,000 --> 00:02:01,000 +It takes me long to transfer this or go to this website. + +28 +00:02:01,000 --> 00:02:05,000 +It may be because there's a particular reason here, maybe because there's too much traffic. + +29 +00:02:05,000 --> 00:02:09,000 +And if we have a lot of these things in place and more, these are just some of them, all right. + +30 +00:02:09,000 --> 00:02:12,000 +There's not all of them, but these are the ones I'm going to be covering coming up later in the course. + +31 +00:02:13,000 --> 00:02:17,000 +Um, if we have these things, we can identify where the bottleneck is. + +32 +00:02:17,000 --> 00:02:19,000 +We could see where things are wrong. + +33 +00:02:19,000 --> 00:02:25,000 +So it's really important to understand that as a network administrator, you're not sitting there playing + +34 +00:02:25,000 --> 00:02:28,000 +solitaire all day like I did in early 2000. + +35 +00:02:28,000 --> 00:02:35,000 +Now you have all of these great different kinds of IPS firewalls, Siem systems, DLP systems, and + +36 +00:02:35,000 --> 00:02:41,000 +so on that you can use to actively monitor it, actively see all the traffic, hopefully fix it and + +37 +00:02:41,000 --> 00:02:48,000 +stop, prevent and detect all kinds of network or suspicious activities. + diff --git a/09 - Securing IT Assets/012 Hardening Techniques OB 2.5_en.srt b/09 - Securing IT Assets/012 Hardening Techniques OB 2.5_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..221c7dcbe909ab50aed7578a10c6e233fd1cfb77 --- /dev/null +++ b/09 - Securing IT Assets/012 Hardening Techniques OB 2.5_en.srt @@ -0,0 +1,632 @@ +1 +00:00:00,000 --> 00:00:01,000 +Okay. + +2 +00:00:01,000 --> 00:00:05,000 +You just got a job as a network administrator in an organization. + +3 +00:00:05,000 --> 00:00:05,000 +I said that wrong. + +4 +00:00:06,000 --> 00:00:09,000 +Network security administrator in an organization. + +5 +00:00:09,000 --> 00:00:15,000 +And you're wondering what are some techniques that I can use in order to harden, Harden all of the + +6 +00:00:15,000 --> 00:00:17,000 +devices in my company? + +7 +00:00:17,000 --> 00:00:23,000 +What I'm about to cover in this section, which is called hardening techniques, is things that we're + +8 +00:00:23,000 --> 00:00:31,000 +going to apply not just to my laptop sitting on my desk, but you can also apply it to hardware devices + +9 +00:00:31,000 --> 00:00:32,000 +such as the switch. + +10 +00:00:32,000 --> 00:00:38,000 +So a lot of the things going on here seems like it's applying to my desktop, which it does, but it + +11 +00:00:38,000 --> 00:00:42,000 +can also some of them can also apply here, like changing, you know, your default passwords. + +12 +00:00:42,000 --> 00:00:44,000 +So let's get into this section. + +13 +00:00:45,000 --> 00:00:47,000 +Put this at the side here. + +14 +00:00:47,000 --> 00:00:52,000 +Let's get into this section and see what are some hardening techniques that we should be doing to keep + +15 +00:00:52,000 --> 00:00:53,000 +our network safe. + +16 +00:00:53,000 --> 00:00:54,000 +So what exactly are we doing here. + +17 +00:00:54,000 --> 00:00:59,000 +Well, this is the practice to reinforce the security of the system by hardening our systems. + +18 +00:00:59,000 --> 00:01:03,000 +We want to reduce vulnerabilities, minimize the attack surface. + +19 +00:01:03,000 --> 00:01:05,000 +The attack surface is this. + +20 +00:01:06,000 --> 00:01:08,000 +The more things you have running, the more likely you can get attacked. + +21 +00:01:09,000 --> 00:01:14,000 +For example, if you just have windows and one application, well, just windows or that app can get + +22 +00:01:14,000 --> 00:01:14,000 +hacked. + +23 +00:01:14,000 --> 00:01:21,000 +But if you have windows and 400 applications, that's a big attack surface, because any of those applications + +24 +00:01:21,000 --> 00:01:27,000 +that get hacked can lead to windows being hacked to protect against threats, unauthorized access attacks, + +25 +00:01:27,000 --> 00:01:28,000 +or even data breaches. + +26 +00:01:28,000 --> 00:01:32,000 +These techniques are generally going to be in involved. + +27 +00:01:32,000 --> 00:01:37,000 +We're going to have to configure our systems network settings in a way that maximizes security. + +28 +00:01:37,000 --> 00:01:41,000 +Now some of these I have already covered like encryption. + +29 +00:01:41,000 --> 00:01:45,000 +Some of these we're going to expand more about later in the course. + +30 +00:01:45,000 --> 00:01:47,000 +So let's get started here on a bunch of them. + +31 +00:01:48,000 --> 00:01:50,000 +The first thing up is encryption. + +32 +00:01:50,000 --> 00:01:55,000 +Now, we do have a giant section in the course on encryption that I really enjoy teaching. + +33 +00:01:55,000 --> 00:02:00,000 +In fact, before filming this video, this section, I did all the encryption videos. + +34 +00:02:00,000 --> 00:02:01,000 +So hopefully you guys have fun with that. + +35 +00:02:01,000 --> 00:02:02,000 +What exactly is encryption? + +36 +00:02:02,000 --> 00:02:07,000 +Well, it's about converting data into a coded format that can be easily understood by anyone. + +37 +00:02:07,000 --> 00:02:12,000 +In other words, create an ciphertext is used to protect data at rest or data in transit. + +38 +00:02:12,000 --> 00:02:14,000 +Remember encryption does not affect. + +39 +00:02:15,000 --> 00:02:17,000 +Data in use. + +40 +00:02:17,000 --> 00:02:20,000 +So there's three states of data rest, transit and in use. + +41 +00:02:20,000 --> 00:02:21,000 +We'll cover more of this later. + +42 +00:02:21,000 --> 00:02:23,000 +So we want to be able to encrypt our data. + +43 +00:02:23,000 --> 00:02:25,000 +Always choose encrypted data. + +44 +00:02:25,000 --> 00:02:27,000 +Now how do how do we implement this in real life. + +45 +00:02:27,000 --> 00:02:30,000 +Well don't use protocols that are insecure. + +46 +00:02:30,000 --> 00:02:32,000 +Only use secure protocols. + +47 +00:02:32,000 --> 00:02:34,000 +Don't use Http. + +48 +00:02:34,000 --> 00:02:36,000 +Use Https. + +49 +00:02:36,000 --> 00:02:39,000 +Another thing here is disabling ports and protocols. + +50 +00:02:39,000 --> 00:02:45,000 +This includes any kind of unnecessary or unnecessary unused ports or communication protocol. + +51 +00:02:45,000 --> 00:02:50,000 +How do we close ports on a on a computer? + +52 +00:02:53,000 --> 00:02:56,000 +This device is famous for closing ports. + +53 +00:02:56,000 --> 00:02:57,000 +This is a firewall. + +54 +00:02:57,000 --> 00:03:02,000 +In its simplest form, a firewall will block all the ports on your machine. + +55 +00:03:02,000 --> 00:03:07,000 +Now you have software based or host based firewalls like Windows Firewall, and you have network based + +56 +00:03:07,000 --> 00:03:12,000 +firewalls like this device, which blocks traffic coming in and out of your network. + +57 +00:03:12,000 --> 00:03:14,000 +A firewall will close out your ports. + +58 +00:03:14,000 --> 00:03:19,000 +By default, almost all the ports are closed, but a good network administrator hardening a device like + +59 +00:03:19,000 --> 00:03:21,000 +this will check to see. + +60 +00:03:21,000 --> 00:03:26,000 +Is there any ports on this device that is open that shouldn't be open? + +61 +00:03:26,000 --> 00:03:29,000 +As a network administrator, you should log in. + +62 +00:03:29,000 --> 00:03:34,000 +Security administrator should log into a device like this on a consistent basis, regular basis, or + +63 +00:03:34,000 --> 00:03:38,000 +especially if you're new, is there unnecessary ports? + +64 +00:03:38,000 --> 00:03:42,000 +Do they have ports open into computers that just doesn't exist anymore? + +65 +00:03:42,000 --> 00:03:44,000 +Endpoint security. + +66 +00:03:44,000 --> 00:03:49,000 +Endpoint security is a very particular piece of software and generally installed security software on + +67 +00:03:49,000 --> 00:03:50,000 +individual devices. + +68 +00:03:50,000 --> 00:03:56,000 +These will generally include antivirus, anti-malware, and even things like firewalls and intrusion + +69 +00:03:56,000 --> 00:03:57,000 +detection system. + +70 +00:03:57,000 --> 00:04:03,000 +Symantec's endpoint security, now called Broadcom endpoint security software, our favorite endpoint + +71 +00:04:03,000 --> 00:04:04,000 +security software. + +72 +00:04:04,000 --> 00:04:09,000 +A lot of you guys know antivirus software or anti-malware. + +73 +00:04:09,000 --> 00:04:16,000 +When you install an endpoint security package, it's just not going to give you anti antivirus or anti + +74 +00:04:16,000 --> 00:04:16,000 +malware. + +75 +00:04:16,000 --> 00:04:22,000 +It's going to give you a firewall and an intrusion prevention system all in one software package. + +76 +00:04:22,000 --> 00:04:28,000 +So remember this endpoint security is not just firewall not just antivirus. + +77 +00:04:28,000 --> 00:04:34,000 +It's more generally generally some kind of firewall and intrusion detection and prevention system all + +78 +00:04:34,000 --> 00:04:36,000 +within the endpoint software. + +79 +00:04:36,000 --> 00:04:41,000 +Now if you don't have endpoint software you may have to install your own firewall. + +80 +00:04:41,000 --> 00:04:47,000 +The good news is that if you're running windows, windows will come with its own host based firewall. + +81 +00:04:47,000 --> 00:04:53,000 +I told you guys earlier, there are two kinds of firewalls that we have in networks today, ones that + +82 +00:04:53,000 --> 00:04:58,000 +sits on the computer on your host, such as my Windows Firewall. + +83 +00:04:58,000 --> 00:05:07,000 +So Windows Firewall on this laptop is a host based firewall, a firewall that I have sitting here. + +84 +00:05:07,000 --> 00:05:09,000 +This is a network based firewall. + +85 +00:05:09,000 --> 00:05:10,000 +Why do you need both? + +86 +00:05:10,000 --> 00:05:17,000 +Well, let's say some knucklehead downloaded a virus on his computer. + +87 +00:05:17,000 --> 00:05:20,000 +He let it in, or he brought it from home at a USB drive. + +88 +00:05:21,000 --> 00:05:22,000 +You know what happens? + +89 +00:05:22,000 --> 00:05:27,000 +Well, that virus starts to spread internal to the network. + +90 +00:05:27,000 --> 00:05:28,000 +It never touches this device. + +91 +00:05:28,000 --> 00:05:31,000 +This device only protects you for data coming in from the internet. + +92 +00:05:31,000 --> 00:05:35,000 +So now that virus is spreading throughout the network, that virus wants to get through a port. + +93 +00:05:35,000 --> 00:05:41,000 +This host based firewall can stop that because this machine is protected. + +94 +00:05:41,000 --> 00:05:45,000 +This this windows installation is protected by Windows Firewall. + +95 +00:05:45,000 --> 00:05:51,000 +But if a virus or a worm is trying to come through the firewall from externally speaking, they're going + +96 +00:05:51,000 --> 00:05:53,000 +to have to bypass this device. + +97 +00:05:53,000 --> 00:05:55,000 +So you need both, not just one. + +98 +00:05:57,000 --> 00:06:04,000 +So remember, it's a software controlled software application controls traffic to a single host. + +99 +00:06:04,000 --> 00:06:05,000 +It does have predefined rules. + +100 +00:06:05,000 --> 00:06:12,000 +This is different than a network firewall that guards your entire network the host perimeter. + +101 +00:06:13,000 --> 00:06:14,000 +Intrusion prevention system. + +102 +00:06:14,000 --> 00:06:17,000 +Now, later on in the course we're going to talk more. + +103 +00:06:17,000 --> 00:06:21,000 +By the way, when I say later, I'm not sure what the order is they're going to use. + +104 +00:06:21,000 --> 00:06:23,000 +So it means that I haven't covered it yet. + +105 +00:06:23,000 --> 00:06:29,000 +I always remember that, uh, whole host prevention systems, this here is basically a software that + +106 +00:06:29,000 --> 00:06:32,000 +can prevent intrusions trying to come through your system. + +107 +00:06:32,000 --> 00:06:37,000 +It monitors and analyze behavior and configurations to prevent any kind of malicious software. + +108 +00:06:37,000 --> 00:06:40,000 +So let's say you go to a website. + +109 +00:06:41,000 --> 00:06:44,000 +And that website has some kind of malicious software on it. + +110 +00:06:44,000 --> 00:06:49,000 +And before you know it, it tries to infect your machine. + +111 +00:06:49,000 --> 00:06:59,000 +Well, our host base prevention system, or IPS or IPS this year can stop that from infecting your computer. + +112 +00:07:01,000 --> 00:07:03,000 +You buy a device like this. + +113 +00:07:04,000 --> 00:07:05,000 +Hardened technique 101. + +114 +00:07:05,000 --> 00:07:06,000 +Change the default password. + +115 +00:07:07,000 --> 00:07:10,000 +Way too often the preset default passwords. + +116 +00:07:10,000 --> 00:07:12,000 +It comes with these devices. + +117 +00:07:12,000 --> 00:07:19,000 +All of them have the same all Linksys devices, for example username, admin, password admin, admin, + +118 +00:07:19,000 --> 00:07:19,000 +admin. + +119 +00:07:19,000 --> 00:07:27,000 +Many devices username is just password, username, password is the password, and username is admin. + +120 +00:07:27,000 --> 00:07:31,000 +You can guess a lot of the default username and password. + +121 +00:07:31,000 --> 00:07:36,000 +Another famous one is username admin password 12345 6 or 1 2345678. + +122 +00:07:37,000 --> 00:07:39,000 +Those are some of the most common ones I've also seen. + +123 +00:07:39,000 --> 00:07:40,000 +Password one. + +124 +00:07:40,000 --> 00:07:41,000 +Password two. + +125 +00:07:41,000 --> 00:07:43,000 +These are common things that people can guess. + +126 +00:07:43,000 --> 00:07:46,000 +You don't want people breaking into your network because you didn't change your default password on + +127 +00:07:46,000 --> 00:07:47,000 +the device, do you? + +128 +00:07:47,000 --> 00:07:57,000 +So at a bare minimum, you want to be able to change the default password, make it long and complex + +129 +00:07:57,000 --> 00:08:00,000 +like we covered in the password section. + +130 +00:08:00,000 --> 00:08:12,000 +Now, the last thing here that I highly recommend people do is to remove unnecessary software when you + +131 +00:08:12,000 --> 00:08:13,000 +have a computer. + +132 +00:08:14,000 --> 00:08:17,000 +Laptop, desktop, anything like that. + +133 +00:08:17,000 --> 00:08:19,000 +You have to remember something. + +134 +00:08:19,000 --> 00:08:23,000 +The more applications you have, the more likely. + +135 +00:08:24,000 --> 00:08:25,000 +You get hacked. + +136 +00:08:25,000 --> 00:08:28,000 +The reason is because your attack surface is bigger. + +137 +00:08:28,000 --> 00:08:35,000 +What you should be doing is identifying and uninstalling software applications that you no longer use, + +138 +00:08:35,000 --> 00:08:40,000 +and are some of them, even though you want to use them, have a vulnerability that hasn't been fixed + +139 +00:08:40,000 --> 00:08:40,000 +or posed. + +140 +00:08:40,000 --> 00:08:41,000 +Security risks. + +141 +00:08:41,000 --> 00:08:47,000 +Removing this can enhance security by reducing the attack surface. + +142 +00:08:47,000 --> 00:08:49,000 +Remember what is the attack surface? + +143 +00:08:49,000 --> 00:08:50,000 +The attack surface. + +144 +00:08:50,000 --> 00:08:56,000 +If you have a lot of applications, there's a lot of quote unquote surface to attack you on. + +145 +00:08:57,000 --> 00:08:57,000 +I write. + +146 +00:08:57,000 --> 00:08:59,000 +The more apps you have, the more likely you get. + +147 +00:08:59,000 --> 00:09:00,000 +You get hacked. + +148 +00:09:00,000 --> 00:09:05,000 +So to reduce the attack surface, unnecessary, outdated software with vulnerabilities that remove removing + +149 +00:09:05,000 --> 00:09:09,000 +this can lessen the number of vulnerabilities or weaknesses. + +150 +00:09:09,000 --> 00:09:11,000 +It can even prevent data breaches. + +151 +00:09:11,000 --> 00:09:15,000 +Some software may not be getting regular updates or you're not updating them. + +152 +00:09:15,000 --> 00:09:18,000 +And if they get breached, they're going to steal your data. + +153 +00:09:19,000 --> 00:09:23,000 +Okay, so in this video we covered some things that maybe you know already. + +154 +00:09:23,000 --> 00:09:25,000 +Maybe you don't. + +155 +00:09:25,000 --> 00:09:30,000 +But these are a lot of these things that are going to apply to your for example like your desktop machine. + +156 +00:09:30,000 --> 00:09:35,000 +Some of them applied to my firewalls that, you know, changing the default passwords on devices. + +157 +00:09:35,000 --> 00:09:41,000 +These are some basic security things that we should all be doing within the organizations to keep our + +158 +00:09:41,000 --> 00:09:43,000 +stuff secure. + diff --git a/09 - Securing IT Assets/013 Quick Quiz.html b/09 - Securing IT Assets/013 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..a72486925695b35be87ea1110ea36b8d42e1ac7b --- /dev/null +++ b/09 - Securing IT Assets/013 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/10 - Security Architecture/001 Cloud OB 3.1_en.srt b/10 - Security Architecture/001 Cloud OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..23405f5e148ada1c9284bc94267b7ac1c23c44c1 --- /dev/null +++ b/10 - Security Architecture/001 Cloud OB 3.1_en.srt @@ -0,0 +1,772 @@ +1 +00:00:00,000 --> 00:00:06,000 +The biggest disruption to technology in today's world is without a doubt, cloud computing. + +2 +00:00:06,000 --> 00:00:10,000 +I remember 15 years ago there was no such thing when cloud computing came out. + +3 +00:00:10,000 --> 00:00:14,000 +It changed the way the entire IT industry works. + +4 +00:00:14,000 --> 00:00:19,000 +So in this video, we want to take a look at some of the characteristics of cloud computing. + +5 +00:00:19,000 --> 00:00:23,000 +What is the service models and deployment models used in the cloud. + +6 +00:00:23,000 --> 00:00:25,000 +So let's take a look at a couple of these things. + +7 +00:00:25,000 --> 00:00:32,000 +So before we get started I'm going to make the assumption that you have all been familiar or are using + +8 +00:00:32,000 --> 00:00:34,000 +cloud computing. + +9 +00:00:34,000 --> 00:00:40,000 +For example, I'm making an assumption that you have used something like Dropbox, in which case you're + +10 +00:00:40,000 --> 00:00:46,000 +storing data in the cloud, maybe using Google Drive or OneDrive, maybe using iCloud to store your + +11 +00:00:46,000 --> 00:00:49,000 +pictures, and if you have an iPhone. + +12 +00:00:49,000 --> 00:00:55,000 +So cloud computing is pretty prominent, as we probably all use it now when it when it comes to cloud + +13 +00:00:55,000 --> 00:01:00,000 +computing for organizations, this is what we're going to be concentrating on in this section. + +14 +00:01:00,000 --> 00:01:03,000 +So what makes cloud computing absolutely amazing. + +15 +00:01:03,000 --> 00:01:06,000 +Well first thing up is that it's a shared resource. + +16 +00:01:06,000 --> 00:01:11,000 +Hardware resources can provide services to device beyond their physical boundaries. + +17 +00:01:11,000 --> 00:01:14,000 +This provides more flexibility and scalability. + +18 +00:01:14,000 --> 00:01:18,000 +So it's a massive pool of shared hardware. + +19 +00:01:18,000 --> 00:01:22,000 +So one of the biggest cloud provider is AWS or Amazon Web Services. + +20 +00:01:23,000 --> 00:01:31,000 +AWS has a massive amount of hardware resources that is shared across all its different users within + +21 +00:01:31,000 --> 00:01:32,000 +the cloud. + +22 +00:01:32,000 --> 00:01:39,000 +Now I'm going to be using some particular terminology customers and the cloud service provider. + +23 +00:01:39,000 --> 00:01:41,000 +So CSP and customers. + +24 +00:01:41,000 --> 00:01:48,000 +So if I go to Amazon right now, AWS and I set up an account and I start to utilize it, I'm going to + +25 +00:01:48,000 --> 00:01:49,000 +be a customer. + +26 +00:01:49,000 --> 00:01:56,000 +And and since Amazon is providing the cloud services, they're known as the cloud service provider or + +27 +00:01:56,000 --> 00:01:56,000 +the CSP. + +28 +00:01:57,000 --> 00:02:03,000 +So they sell the CSP will have a giant amount of hardware resources that they're going to be sharing + +29 +00:02:03,000 --> 00:02:03,000 +out. + +30 +00:02:03,000 --> 00:02:07,000 +The great thing about the cloud is that you pay as you go. + +31 +00:02:07,000 --> 00:02:08,000 +You pay for what you use. + +32 +00:02:08,000 --> 00:02:15,000 +This is absolutely super important because one of the things that makes cloud the best out there is + +33 +00:02:15,000 --> 00:02:17,000 +it's massive amount of cost effectiveness. + +34 +00:02:17,000 --> 00:02:23,000 +You see, in traditional computing, you'd have to buy a server, you would put it into a rack, you + +35 +00:02:23,000 --> 00:02:25,000 +would pay 24 over seven to cool it. + +36 +00:02:25,000 --> 00:02:28,000 +You would pay 24 over seven to power it up. + +37 +00:02:28,000 --> 00:02:31,000 +Also, you would need to have the space to store it. + +38 +00:02:31,000 --> 00:02:36,000 +So these are things that you can have to spend every single month versus in cloud computing. + +39 +00:02:36,000 --> 00:02:38,000 +If you don't use it, you don't pay for it. + +40 +00:02:38,000 --> 00:02:40,000 +They generally charge you by usage. + +41 +00:02:40,000 --> 00:02:47,000 +Sometimes we're going to say this is uh, sometimes we say it's like a utility or utility usages because + +42 +00:02:47,000 --> 00:02:49,000 +it's like a light bulb on the ceiling. + +43 +00:02:49,000 --> 00:02:50,000 +Right? + +44 +00:02:50,000 --> 00:02:51,000 +You're being metered, right? + +45 +00:02:51,000 --> 00:02:53,000 +You have a power meter on your house. + +46 +00:02:53,000 --> 00:02:58,000 +You're being metered, uh, for the amount of usages of the amount of electricity. + +47 +00:02:58,000 --> 00:03:00,000 +Same concept here. + +48 +00:03:00,000 --> 00:03:02,000 +Rapid elasticity city. + +49 +00:03:02,000 --> 00:03:03,000 +Another great feature. + +50 +00:03:04,000 --> 00:03:10,000 +So let's say right now you're using a single processor and four gigs of Ram for your web server. + +51 +00:03:10,000 --> 00:03:17,000 +You don't have a lot of traffic throughout the morning, but by 12:00 a lot of people visit your website. + +52 +00:03:17,000 --> 00:03:18,000 +The cloud is like a rubber band. + +53 +00:03:18,000 --> 00:03:21,000 +It's able to expand and contract. + +54 +00:03:21,000 --> 00:03:23,000 +Hint the terms elastic, right? + +55 +00:03:23,000 --> 00:03:27,000 +So resources can be allocated and reallocated as required. + +56 +00:03:27,000 --> 00:03:32,000 +So in lunchtime it pushes up the Ram, CPU contracts it back again. + +57 +00:03:33,000 --> 00:03:35,000 +Another great feature is high availability. + +58 +00:03:36,000 --> 00:03:43,000 +The cloud is known to be on Amazon does a great job of keeping the availability high high redundancy + +59 +00:03:43,000 --> 00:03:47,000 +in their network, power redundancy, hardware redundancy. + +60 +00:03:47,000 --> 00:03:52,000 +And of course, if you're using it for something like Dropbox, you can have file synchronization. + +61 +00:03:52,000 --> 00:03:56,000 +This makes the file available from anywhere within the cloud section. + +62 +00:03:56,000 --> 00:04:01,000 +Now when it comes to cloud, when we want to deploy. + +63 +00:04:02,000 --> 00:04:03,000 +Uh, cloud services. + +64 +00:04:03,000 --> 00:04:04,000 +How are we going to do it? + +65 +00:04:04,000 --> 00:04:09,000 +There's basically four ones we should know for our exam. + +66 +00:04:09,000 --> 00:04:13,000 +Public, private community and hybrid. + +67 +00:04:13,000 --> 00:04:14,000 +So public cloud. + +68 +00:04:14,000 --> 00:04:17,000 +This is where third party hosts all the equipment. + +69 +00:04:17,000 --> 00:04:23,000 +So if you use things like AWS, Google Cloud, Azure or Microsoft, that's a public cloud. + +70 +00:04:23,000 --> 00:04:27,000 +Everybody can connect to it and anybody can use it. + +71 +00:04:27,000 --> 00:04:31,000 +Some organizations are big enough to host their own cloud equipment. + +72 +00:04:31,000 --> 00:04:37,000 +Basically, they own their own cloud, in which case you may have a particular data center, uh, that's + +73 +00:04:37,000 --> 00:04:40,000 +owned by them that they're sharing out to branch offices. + +74 +00:04:40,000 --> 00:04:44,000 +Private cloud is managed by the business. + +75 +00:04:44,000 --> 00:04:48,000 +Now, oddly enough, you could have private clouds within AWS. + +76 +00:04:48,000 --> 00:04:50,000 +I'm not going to get into that for your exam. + +77 +00:04:50,000 --> 00:04:57,000 +Just know private cloud is generally a, uh, where a single client will utilize that particular cloud + +78 +00:04:57,000 --> 00:04:58,000 +section. + +79 +00:04:58,000 --> 00:05:03,000 +Community cloud is when multiple organizations come together to build a cloud to serve a particular + +80 +00:05:03,000 --> 00:05:09,000 +need, maybe the company's work in a particular industry together, and they can combine and share the + +81 +00:05:09,000 --> 00:05:12,000 +cost to build something that they could both use. + +82 +00:05:12,000 --> 00:05:14,000 +Hybrid cloud more than likely. + +83 +00:05:14,000 --> 00:05:15,000 +A lot of companies have this. + +84 +00:05:16,000 --> 00:05:18,000 +We are probably going to have be part of a public cloud. + +85 +00:05:18,000 --> 00:05:24,000 +And if you're a big company, you probably have a private, public and private, maybe public and community. + +86 +00:05:24,000 --> 00:05:25,000 +So it's a combination. + +87 +00:05:26,000 --> 00:05:32,000 +So these are considered deployment models now when it comes to service models, when you purchase cloud + +88 +00:05:32,000 --> 00:05:38,000 +computing, you can get them a software as a service platform and infrastructure as a service. + +89 +00:05:38,000 --> 00:05:40,000 +What exactly is the difference? + +90 +00:05:40,000 --> 00:05:45,000 +Well, software as a service is basically purchasing an application. + +91 +00:05:46,000 --> 00:05:52,000 +A good example of this is going to be like Salesforce, the software as a service. + +92 +00:05:52,000 --> 00:05:54,000 +QuickBooks online is a software as a service. + +93 +00:05:54,000 --> 00:05:59,000 +So you would log into an application and just pay for the application that you're actually using. + +94 +00:05:59,000 --> 00:06:01,000 +Platform as a service. + +95 +00:06:01,000 --> 00:06:06,000 +Basically, that would give you like a web server and you would just put your web app on that web server. + +96 +00:06:06,000 --> 00:06:09,000 +The cloud provider takes care of all the hardware and generally the operating system. + +97 +00:06:09,000 --> 00:06:14,000 +If they give you just a blank machine and you have to install generally your own operating system, + +98 +00:06:14,000 --> 00:06:18,000 +you have to maintain your own operating system and your application, but they maintain all the hardware + +99 +00:06:18,000 --> 00:06:21,000 +and that's infrastructure as a service. + +100 +00:06:21,000 --> 00:06:24,000 +Now when it comes to these service models. + +101 +00:06:24,000 --> 00:06:35,000 +I do have a table that I have here, all of these different, uh, things that the customer and or the + +102 +00:06:35,000 --> 00:06:36,000 +provider is responsible. + +103 +00:06:36,000 --> 00:06:36,000 +So let's go over there. + +104 +00:06:36,000 --> 00:06:44,000 +So I just mentioned that software and software as a service, the customer is basically required, uh, + +105 +00:06:44,000 --> 00:06:47,000 +going to be responsible for creating and managing user account. + +106 +00:06:47,000 --> 00:06:49,000 +That's all the customer does. + +107 +00:06:49,000 --> 00:06:52,000 +Basically the provider think of Salesforce. + +108 +00:06:52,000 --> 00:06:57,000 +Salesforce is responsible for the app, the operating system, the hardware, the network, the facility. + +109 +00:06:57,000 --> 00:07:00,000 +And now I want to just point this out. + +110 +00:07:00,000 --> 00:07:05,000 +Compliance requirement is done by the customer. + +111 +00:07:05,000 --> 00:07:06,000 +What is why is that? + +112 +00:07:06,000 --> 00:07:14,000 +You notice compliance cannot be passed off to AWS, cannot be passed off to Azure's. + +113 +00:07:14,000 --> 00:07:19,000 +It's your if you follow a particular type of compliance or a regulation, you need to make sure that + +114 +00:07:19,000 --> 00:07:23,000 +the cloud provider does, you know, has those regulations in place. + +115 +00:07:23,000 --> 00:07:29,000 +The reason why I have this one as well, where it says customer is responsible for compliance, is because + +116 +00:07:30,000 --> 00:07:35,000 +if you put something in the cloud and it doesn't meet certain regulatory laws, regulators is not going + +117 +00:07:35,000 --> 00:07:36,000 +to go after Amazon. + +118 +00:07:36,000 --> 00:07:38,000 +They're going to go after you. + +119 +00:07:38,000 --> 00:07:43,000 +You're the one that has to do the work needed to verify that the cloud provider is secure enough to + +120 +00:07:43,000 --> 00:07:44,000 +store your data. + +121 +00:07:46,000 --> 00:07:50,000 +So regulatory compliance customer does this now in platform as a service. + +122 +00:07:50,000 --> 00:07:51,000 +What are you doing. + +123 +00:07:51,000 --> 00:07:56,000 +Well all you're going to be doing is maintaining your user accounts. + +124 +00:07:56,000 --> 00:07:58,000 +You're going to control your application. + +125 +00:07:58,000 --> 00:07:59,000 +And that's it. + +126 +00:07:59,000 --> 00:08:01,000 +You're controlling your application. + +127 +00:08:01,000 --> 00:08:03,000 +In other words, you're putting like your web app on there. + +128 +00:08:03,000 --> 00:08:06,000 +You're going to be creating all the user accounts on them. + +129 +00:08:06,000 --> 00:08:11,000 +But the provider maintains some of the operating system straight down to the hardware and facilities + +130 +00:08:11,000 --> 00:08:12,000 +in infrastructure as a service. + +131 +00:08:12,000 --> 00:08:17,000 +Well, you're going to be responsible for that operating system straight up the application, the operating + +132 +00:08:17,000 --> 00:08:21,000 +system, the users, while the provider takes care of everything else. + +133 +00:08:22,000 --> 00:08:30,000 +Now, all of these are very popular, and I personally believe that we are a lot of a lot of us are + +134 +00:08:30,000 --> 00:08:32,000 +moving towards softwares and services. + +135 +00:08:32,000 --> 00:08:37,000 +More and more things are becoming software as a service, and we just pay a monthly fee to utilize these + +136 +00:08:37,000 --> 00:08:37,000 +things. + +137 +00:08:37,000 --> 00:08:45,000 +But when applications are custom built by the organization, infrastructure or platform as a service + +138 +00:08:45,000 --> 00:08:47,000 +may be options that you want to consider. + +139 +00:08:47,000 --> 00:08:51,000 +When it comes to this, I want you guys to understand a couple of things. + +140 +00:08:51,000 --> 00:08:52,000 +When it comes to responsibility. + +141 +00:08:52,000 --> 00:08:55,000 +Cloud computing is a shared responsibility. + +142 +00:08:55,000 --> 00:09:00,000 +In all of those models, security obligations are divided on both ends. + +143 +00:09:00,000 --> 00:09:04,000 +For example, yes, AWS is responsible. + +144 +00:09:04,000 --> 00:09:07,000 +Let's say you're using platform as a service. + +145 +00:09:07,000 --> 00:09:10,000 +Yes, they're responsible generally to maintain that. + +146 +00:09:10,000 --> 00:09:14,000 +Their facilities keep cool, their equipment stays on and doesn't die. + +147 +00:09:15,000 --> 00:09:22,000 +Uh, no one breaks into the facilities, but you have to ensure that your application is secure. + +148 +00:09:22,000 --> 00:09:24,000 +You have to ensure that it's well programmed. + +149 +00:09:24,000 --> 00:09:28,000 +You have to ensure that you're using the right encryption type protocols. + +150 +00:09:28,000 --> 00:09:31,000 +So it's always going to be the shared responsibility. + +151 +00:09:32,000 --> 00:09:35,000 +Now, I do want to stop right here, and I want to point out something. + +152 +00:09:35,000 --> 00:09:43,000 +When it comes to passing blame, the ultimate responsibility of if data is lost because of cloud computing + +153 +00:09:43,000 --> 00:09:48,000 +lies with the customer and not with the cloud provider. + +154 +00:09:48,000 --> 00:09:50,000 +If on this exam you get a question of. + +155 +00:09:51,000 --> 00:09:57,000 +Well, who's who's going to be held responsible if there was a hack in in a cloud provider and data + +156 +00:09:57,000 --> 00:09:58,000 +was lost. + +157 +00:09:59,000 --> 00:10:02,000 +The customer, the data owner. + +158 +00:10:02,000 --> 00:10:06,000 +Not AWS, not the cloud provider. + +159 +00:10:06,000 --> 00:10:07,000 +Okay. + +160 +00:10:07,000 --> 00:10:08,000 +Why? + +161 +00:10:08,000 --> 00:10:15,000 +Well, because the way the federal government or regulators are going to look at it is you, the organization + +162 +00:10:15,000 --> 00:10:22,000 +you, the customer, didn't do your due diligence in order to actually select the right cloud provider. + +163 +00:10:22,000 --> 00:10:27,000 +You should have made sure that this cloud provider meets the security requirements set by the government. + +164 +00:10:28,000 --> 00:10:29,000 +So keep that in mind. + +165 +00:10:30,000 --> 00:10:34,000 +Hybrid consideration when you're doing hybrid cloud. + +166 +00:10:34,000 --> 00:10:39,000 +Remember, a lot of times we have what's called on prem and cloud resources. + +167 +00:10:39,000 --> 00:10:45,000 +So what I'm talking about here is hybrid is where organization splits data, some of it on premises + +168 +00:10:45,000 --> 00:10:46,000 +and some of it within the cloud. + +169 +00:10:46,000 --> 00:10:51,000 +Be careful with the security integration policy integration can be difficult. + +170 +00:10:51,000 --> 00:10:52,000 +Third party vendors. + +171 +00:10:52,000 --> 00:10:54,000 +Cloud is on you. + +172 +00:10:54,000 --> 00:10:56,000 +When you use cloud, you're relying on third party vendors. + +173 +00:10:56,000 --> 00:10:58,000 +You know when it comes to. + +174 +00:10:59,000 --> 00:11:00,000 +Cloud providers. + +175 +00:11:01,000 --> 00:11:05,000 +Uh, you're putting your data into the cloud. + +176 +00:11:05,000 --> 00:11:06,000 +Where is the data stored? + +177 +00:11:06,000 --> 00:11:08,000 +There is a topic we'll cover later in this course. + +178 +00:11:08,000 --> 00:11:11,000 +Course called data sovereignty. + +179 +00:11:11,000 --> 00:11:11,000 +All right. + +180 +00:11:11,000 --> 00:11:15,000 +We have to be careful where the data is stored, like the geographic location of the data. + +181 +00:11:15,000 --> 00:11:18,000 +That's important things to consider. + +182 +00:11:18,000 --> 00:11:19,000 +The vendor security practices. + +183 +00:11:19,000 --> 00:11:24,000 +Now when we get to later on in the course we'll talk about ISO certifications. + +184 +00:11:24,000 --> 00:11:28,000 +And these are things you're going to want to check to make sure that the cloud provider follows good + +185 +00:11:28,000 --> 00:11:29,000 +security practices. + +186 +00:11:29,000 --> 00:11:31,000 +Cloud computing is here to stay. + +187 +00:11:33,000 --> 00:11:39,000 +Entire organizations are replacing giant sections of their network with cloud computing. + +188 +00:11:39,000 --> 00:11:42,000 +So I want you guys to keep that in mind. + +189 +00:11:42,000 --> 00:11:46,000 +Uh, that sooner or later, your entire it. + +190 +00:11:46,000 --> 00:11:47,000 +That's in all of it. + +191 +00:11:47,000 --> 00:11:50,000 +Probably most of it will be put into the cloud. + +192 +00:11:50,000 --> 00:11:55,000 +So make sure as your career progress, you're familiar with the different deployment models. + +193 +00:11:55,000 --> 00:12:02,000 +The different service models, the pros and cons with them so you can ensure that your data stays secure. + diff --git a/10 - Security Architecture/002 Infrastructure as Code OB 3.1_en.srt b/10 - Security Architecture/002 Infrastructure as Code OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..362d214ed5c82c680c2914761ec6dd16d4dc03f7 --- /dev/null +++ b/10 - Security Architecture/002 Infrastructure as Code OB 3.1_en.srt @@ -0,0 +1,204 @@ +1 +00:00:00,000 --> 00:00:04,000 +I was speaking to an administrator the other day and he was telling me that. + +2 +00:00:05,000 --> 00:00:12,000 +The days of just being able to click next and follow prompts to manage servers is pretty much over. + +3 +00:00:12,000 --> 00:00:13,000 +Everybody has to know how to code. + +4 +00:00:13,000 --> 00:00:15,000 +And they said, well, that kind of sucks. + +5 +00:00:15,000 --> 00:00:17,000 +And I was like, what are you referring to? + +6 +00:00:17,000 --> 00:00:20,000 +He was telling me about infrastructure as a code. + +7 +00:00:20,000 --> 00:00:21,000 +What exactly is this? + +8 +00:00:21,000 --> 00:00:26,000 +So infrastructure as a code is where hardware is managed like software. + +9 +00:00:26,000 --> 00:00:28,000 +Let's talk about software development here for a minute. + +10 +00:00:28,000 --> 00:00:36,000 +When they develop software, they have version controls, they have testing, they have ways that they + +11 +00:00:36,000 --> 00:00:39,000 +write the code and they have integration testing of code. + +12 +00:00:39,000 --> 00:00:41,000 +They have version control of code. + +13 +00:00:41,000 --> 00:00:50,000 +So infrastructure is a code is basically managing hardware devices and configuration as if it was a + +14 +00:00:50,000 --> 00:00:51,000 +piece of software code. + +15 +00:00:51,000 --> 00:00:55,000 +Now if you think about it, I don't want to get into the specifics. + +16 +00:00:55,000 --> 00:00:57,000 +It's beyond the scope of this exam. + +17 +00:00:57,000 --> 00:01:03,000 +But if you think about it, a lot of servers, especially windows servers, is now being managed with + +18 +00:01:03,000 --> 00:01:10,000 +technically code because it's a lot of it now is done through PowerShell scripting, bash programming + +19 +00:01:10,000 --> 00:01:11,000 +for Linux, right? + +20 +00:01:11,000 --> 00:01:14,000 +A lot of administration and managing infrastructure. + +21 +00:01:14,000 --> 00:01:18,000 +All of I mean, you could look at Cisco commands and think think of them as code to a lot of them are + +22 +00:01:18,000 --> 00:01:24,000 +now look as if you're writing code versus back in my days when we were managing servers, there was + +23 +00:01:24,000 --> 00:01:27,000 +yeah, there was a command prompt that didn't do much. + +24 +00:01:27,000 --> 00:01:32,000 +A lot of it was still based on a GUI or a graphical user interface. + +25 +00:01:32,000 --> 00:01:36,000 +So what we're doing now is we're configuring hardware instead of configuring it manually. + +26 +00:01:36,000 --> 00:01:42,000 +What we're doing is we're going to be utilizing codes in order to manage it. + +27 +00:01:42,000 --> 00:01:43,000 +So. + +28 +00:01:44,000 --> 00:01:47,000 +Let's go through this instead of, uh, configuring hardware manually. + +29 +00:01:47,000 --> 00:01:53,000 +It's managed as a collection of elements the same way as we manage code under things like DevOps. + +30 +00:01:53,000 --> 00:01:57,000 +Now the hardware infrastructure is managed like software code. + +31 +00:01:57,000 --> 00:02:03,000 +Software code is going to have version control, pre-deployment testing, uh, custom crafted test code, + +32 +00:02:03,000 --> 00:02:06,000 +reasonableness checks, regression testing. + +33 +00:02:06,000 --> 00:02:08,000 +Like how does this configuration affects another one? + +34 +00:02:09,000 --> 00:02:12,000 +This allows companies to streamline the infrastructure. + +35 +00:02:12,000 --> 00:02:17,000 +It makes it easier to manage, easier to track changes also, and it makes it more secure. + +36 +00:02:17,000 --> 00:02:20,000 +Now, it's not limited to hardware because we could do this. + +37 +00:02:20,000 --> 00:02:22,000 +We'll talk later on about Stns. + +38 +00:02:22,000 --> 00:02:24,000 +You could do this to manage virtual machines also. + +39 +00:02:24,000 --> 00:02:33,000 +Now a lot of it is going to be pushing out changes to to configurations of different kinds of devices + +40 +00:02:33,000 --> 00:02:38,000 +such as routers, switches, virtual machines and servers and so on. + +41 +00:02:38,000 --> 00:02:42,000 +Infrastructure as a code, you don't have to get too complex into it. + +42 +00:02:42,000 --> 00:02:44,000 +Just understand what it is for your exam. + +43 +00:02:44,000 --> 00:02:45,000 +What exactly is it? + +44 +00:02:45,000 --> 00:02:50,000 +It's basically manage all the configurations of all the different hardware, but just not that. + +45 +00:02:51,000 --> 00:02:56,000 +Also all the virtual hardware that we have in our infrastructure, basically as the way we would manage + +46 +00:02:56,000 --> 00:02:58,000 +software, how do we manage software once again? + +47 +00:02:58,000 --> 00:03:04,000 +Well, we're going to have a giant code and database software like they have GitHub where we would check + +48 +00:03:04,000 --> 00:03:09,000 +in code, check out code, do regression testing on code, do version control on code. + +49 +00:03:09,000 --> 00:03:17,000 +Imagine just using instead of software codes we're using configuration device configuration instead + +50 +00:03:17,000 --> 00:03:23,000 +of software called understand what infrastructure is for your exam shouldn't be too complex for your + +51 +00:03:23,000 --> 00:03:23,000 +tests. + diff --git a/10 - Security Architecture/003 Serverless Architecture OB 3.1_en.srt b/10 - Security Architecture/003 Serverless Architecture OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..3c109e45c42f046e0e555c8a3929ef1c69e6b840 --- /dev/null +++ b/10 - Security Architecture/003 Serverless Architecture OB 3.1_en.srt @@ -0,0 +1,168 @@ +1 +00:00:00,000 --> 00:00:00,000 +All right. + +2 +00:00:00,000 --> 00:00:05,000 +I'm about to tell you a terme that technically doesn't exist, but still exists at the same time. + +3 +00:00:06,000 --> 00:00:11,000 +Because this terme, you know, if you read about it in different books, technically there's no such + +4 +00:00:11,000 --> 00:00:14,000 +thing as serverless architecture. + +5 +00:00:14,000 --> 00:00:15,000 +There's always a server. + +6 +00:00:15,000 --> 00:00:17,000 +So here's what this is. + +7 +00:00:17,000 --> 00:00:20,000 +If you're a programmer, you do one thing. + +8 +00:00:20,000 --> 00:00:21,000 +You program write. + +9 +00:00:21,000 --> 00:00:22,000 +You write code. + +10 +00:00:22,000 --> 00:00:24,000 +You check in code, you test code. + +11 +00:00:24,000 --> 00:00:26,000 +Do you want to manage the server? + +12 +00:00:26,000 --> 00:00:31,000 +What's the server installing its operating system, keeping it up to date, checking its log files, + +13 +00:00:31,000 --> 00:00:36,000 +rebooting the services within the operating system, checking the hardware on the machine or the virtual + +14 +00:00:36,000 --> 00:00:37,000 +hardware. + +15 +00:00:38,000 --> 00:00:40,000 +It's a pain to manage a server. + +16 +00:00:40,000 --> 00:00:41,000 +Think about it. + +17 +00:00:41,000 --> 00:00:43,000 +Me thinking about this, thinking it's a pain. + +18 +00:00:43,000 --> 00:00:49,000 +Serverless architecture is a cloud computing concept where code is managed by the customer. + +19 +00:00:49,000 --> 00:00:55,000 +So the customer checks in, checks out the code, utilizes the server and the platform. + +20 +00:00:55,000 --> 00:00:57,000 +The supported hardware is managed by the CSP. + +21 +00:00:57,000 --> 00:01:02,000 +So technically there's no such thing as a serverless architecture. + +22 +00:01:02,000 --> 00:01:07,000 +It's just that in serverless architecture, you do the programmer. + +23 +00:01:07,000 --> 00:01:14,000 +The customer does not manage the server who manages the server, the cloud provider does, or the CSP. + +24 +00:01:14,000 --> 00:01:16,000 +You don't manage the server. + +25 +00:01:16,000 --> 00:01:22,000 +So there still is a server and serverless architecture, except that the programmer does not manage + +26 +00:01:22,000 --> 00:01:22,000 +it. + +27 +00:01:22,000 --> 00:01:24,000 +That's all it means. + +28 +00:01:24,000 --> 00:01:26,000 +So there's always a physical server running somewhere. + +29 +00:01:26,000 --> 00:01:28,000 +Not necessarily physical, but virtual also. + +30 +00:01:29,000 --> 00:01:34,000 +But this execution model allows the designers, the architects, developers to focus on code and not + +31 +00:01:34,000 --> 00:01:36,000 +have to worry about the server. + +32 +00:01:36,000 --> 00:01:38,000 +This is also known. + +33 +00:01:38,000 --> 00:01:41,000 +You might hear the Terme function as a service. + +34 +00:01:41,000 --> 00:01:41,000 +All right. + +35 +00:01:41,000 --> 00:01:44,000 +Application developers on serverless are similar to microservices. + +36 +00:01:44,000 --> 00:01:46,000 +Now we're going to talk about that in a minute. + +37 +00:01:46,000 --> 00:01:51,000 +Because when we're talking microservices we're going to let somebody else manage that server also. + +38 +00:01:51,000 --> 00:01:51,000 +All right. + +39 +00:01:51,000 --> 00:01:56,000 +So just to understand the terms serverless architecture, actually there is no such thing as no server. + +40 +00:01:56,000 --> 00:02:02,000 +There is a server with serverless architecture is referring to is the servers are managed by the cloud + +41 +00:02:02,000 --> 00:02:05,000 +provider, not by the programmers. + +42 +00:02:05,000 --> 00:02:09,000 +The programmers just have to worry about writing codes and not managing servers. + diff --git a/10 - Security Architecture/004 Microservices OB 3.1_en.srt b/10 - Security Architecture/004 Microservices OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..2c10cfeda3332bcacd54d3368caa914707c18633 --- /dev/null +++ b/10 - Security Architecture/004 Microservices OB 3.1_en.srt @@ -0,0 +1,264 @@ +1 +00:00:00,000 --> 00:00:02,000 +Okay, I got a scenario that I want to run by. + +2 +00:00:02,000 --> 00:00:06,000 +You imagine you want to design an e-commerce application. + +3 +00:00:06,000 --> 00:00:11,000 +In this e-commerce application, you want to have a user interface that displays all different kinds + +4 +00:00:11,000 --> 00:00:13,000 +of products that you're going to be selling. + +5 +00:00:13,000 --> 00:00:18,000 +The back end of the application, it has to be able to track inventory. + +6 +00:00:18,000 --> 00:00:24,000 +It has to be have a type of a shopping cart so that you can added into it a specific checkout where + +7 +00:00:24,000 --> 00:00:26,000 +it takes payments worldwide. + +8 +00:00:26,000 --> 00:00:31,000 +It has to be able to store customer information, and it has to be able to do all the accounting tasks, + +9 +00:00:31,000 --> 00:00:36,000 +such as when to reorder inventory, how we run a profit this month or a loss this month, and so on. + +10 +00:00:37,000 --> 00:00:42,000 +Now you call up a programmer and you say, well, can you build this application for me? + +11 +00:00:43,000 --> 00:00:49,000 +If the programmer, the programmer has a choice, the programmer can sit down and code all the different + +12 +00:00:49,000 --> 00:00:56,000 +quote unquote aspects or parts of the application in one giant app. + +13 +00:00:56,000 --> 00:01:01,000 +The things from the from the inventory management to the accounting management to checkout management + +14 +00:01:01,000 --> 00:01:02,000 +and so on. + +15 +00:01:02,000 --> 00:01:07,000 +He could build each of them not separately, but as one giant application. + +16 +00:01:07,000 --> 00:01:10,000 +In other words, it's all dependent on each other. + +17 +00:01:11,000 --> 00:01:15,000 +This is known as what we call monolith design. + +18 +00:01:15,000 --> 00:01:20,000 +Monolith design is a traditional way of building an application. + +19 +00:01:20,000 --> 00:01:26,000 +It's basically one application where everything is built in one big application. + +20 +00:01:26,000 --> 00:01:26,000 +It's not. + +21 +00:01:26,000 --> 00:01:28,000 +You can't separate it or anything like that. + +22 +00:01:29,000 --> 00:01:32,000 +Now let's talk modern times. + +23 +00:01:32,000 --> 00:01:35,000 +In modern times, we don't really do this anymore. + +24 +00:01:35,000 --> 00:01:39,000 +In modern times, we're going to use what's called microservices. + +25 +00:01:39,000 --> 00:01:47,000 +Microservices is when you build the application often and utilize different things from different places, + +26 +00:01:47,000 --> 00:01:52,000 +even hosted by different places, or just build them in different parts and reconnect them using APIs + +27 +00:01:52,000 --> 00:01:55,000 +or application programming interfaces. + +28 +00:01:55,000 --> 00:01:57,000 +Let me show you what I mean here in the diagram. + +29 +00:01:57,000 --> 00:02:01,000 +So let's say you're building your your e-commerce application in microservices. + +30 +00:02:01,000 --> 00:02:04,000 +You're going to have one part of the application maybe for inventory. + +31 +00:02:05,000 --> 00:02:08,000 +You're going to have one part per accountant. + +32 +00:02:08,000 --> 00:02:13,000 +You're going to have one part for a checkout system, you're going to have one part for user management + +33 +00:02:13,000 --> 00:02:14,000 +and so on and so on. + +34 +00:02:14,000 --> 00:02:18,000 +You're going to have one parts for payment processing and so on. + +35 +00:02:18,000 --> 00:02:21,000 +So you have all these different sections of the application that's out there. + +36 +00:02:21,000 --> 00:02:27,000 +The great thing about microservices is that sometimes it doesn't even need to be hosted on one system. + +37 +00:02:27,000 --> 00:02:32,000 +You can have your inventory management system being hosted on a whole different platform, whole different + +38 +00:02:32,000 --> 00:02:38,000 +cloud provider, whole different vendor payment processing, managing a whole different vendor, different + +39 +00:02:38,000 --> 00:02:39,000 +processes. + +40 +00:02:39,000 --> 00:02:44,000 +You can then scale up and down different parts of the application as needed. + +41 +00:02:44,000 --> 00:02:48,000 +For example, what if you released a new product? + +42 +00:02:48,000 --> 00:02:54,000 +Well, you don't necessarily need everything to scale up in monolith designs. + +43 +00:02:54,000 --> 00:02:58,000 +If you want to push scale up the application to intake more orders, you got to scale everything. + +44 +00:02:58,000 --> 00:03:04,000 +But what if you're just doing you're only selling two products, and the only thing that's really being + +45 +00:03:04,000 --> 00:03:06,000 +affected here is the inventory. + +46 +00:03:06,000 --> 00:03:09,000 +And the user creation is being managed here. + +47 +00:03:09,000 --> 00:03:10,000 +Maybe the payment processing. + +48 +00:03:12,000 --> 00:03:16,000 +Um, uh, microservices is really important in today's world. + +49 +00:03:18,000 --> 00:03:19,000 +All right. + +50 +00:03:19,000 --> 00:03:27,000 +Uh, what it does is that it's going to allow us to build application modular and then connect the modular + +51 +00:03:27,000 --> 00:03:31,000 +settings to get it to form the overall application. + +52 +00:03:31,000 --> 00:03:40,000 +The greatest thing is that it allows us to focus on one particular part, expand and collapse or expand + +53 +00:03:40,000 --> 00:03:42,000 +and contract one particular part. + +54 +00:03:43,000 --> 00:03:46,000 +If one thing breaks, it may not break everything that is out there. + +55 +00:03:47,000 --> 00:03:47,000 +All right. + +56 +00:03:47,000 --> 00:03:55,000 +So it allows more complex application to actually be managed a smaller application. + +57 +00:03:55,000 --> 00:03:56,000 +Now this is all great. + +58 +00:03:57,000 --> 00:03:58,000 +It does have some drawbacks. + +59 +00:03:58,000 --> 00:04:05,000 +For example, the connections of the different microservices within the app could be complex versus + +60 +00:04:05,000 --> 00:04:05,000 +if it's monolith. + +61 +00:04:05,000 --> 00:04:08,000 +It's all built and designed together, so it's all work together. + +62 +00:04:08,000 --> 00:04:15,000 +Testing different components of a model of a monolith application could be complex because they weren't + +63 +00:04:15,000 --> 00:04:17,000 +designed at the same versus monolith. + +64 +00:04:17,000 --> 00:04:17,000 +It could. + +65 +00:04:18,000 --> 00:04:20,000 +So they both have their pros and cons. + +66 +00:04:20,000 --> 00:04:27,000 +But as of right now, many, many applications being built today is built using microservices. + diff --git a/10 - Security Architecture/005 Air Gapped OB 3.1_en.srt b/10 - Security Architecture/005 Air Gapped OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..1f4d4d3a2c31a3c051647925f2741214a968a5d0 --- /dev/null +++ b/10 - Security Architecture/005 Air Gapped OB 3.1_en.srt @@ -0,0 +1,220 @@ +1 +00:00:00,000 --> 00:00:07,000 +Sometimes on a network, you're going to have a computer or data that is super secure. + +2 +00:00:07,000 --> 00:00:10,000 +Think about Kentucky Fried Chicken or KFC. + +3 +00:00:10,000 --> 00:00:11,000 +I could use some of that right now. + +4 +00:00:11,000 --> 00:00:13,000 +Think about KFC. + +5 +00:00:13,000 --> 00:00:16,000 +The secret recipe to that chicken. + +6 +00:00:17,000 --> 00:00:19,000 +That recipe is should be kept secret. + +7 +00:00:19,000 --> 00:00:22,000 +It is the company's proprietary secret. + +8 +00:00:22,000 --> 00:00:24,000 +Where are they going to store that recipe? + +9 +00:00:24,000 --> 00:00:31,000 +Well, they should store it on what we're going to call an air gap machine. + +10 +00:00:31,000 --> 00:00:34,000 +What exactly is an is an air gap computer. + +11 +00:00:34,000 --> 00:00:41,000 +So an air gap machine is a machine that is literally cut off from the network. + +12 +00:00:41,000 --> 00:00:47,000 +There is air like, you know, air that we breathe between the machine and the rest of the network. + +13 +00:00:47,000 --> 00:00:50,000 +So look at this diagram that I have here. + +14 +00:00:50,000 --> 00:00:51,000 +You see here's a network, right. + +15 +00:00:51,000 --> 00:00:54,000 +You can see the network lines here connecting the internet. + +16 +00:00:54,000 --> 00:00:56,000 +You've got a computer, you got a router. + +17 +00:00:57,000 --> 00:00:59,000 +But then there's this machine off to the corner here. + +18 +00:00:59,000 --> 00:01:01,000 +And it has no connection. + +19 +00:01:01,000 --> 00:01:07,000 +An air gap machine is physically isolated off the network now. + +20 +00:01:08,000 --> 00:01:09,000 +It doesn't have to be air gap computer. + +21 +00:01:09,000 --> 00:01:11,000 +It could be an air gap network. + +22 +00:01:11,000 --> 00:01:15,000 +Two they provide high security by disconnected from the internet. + +23 +00:01:16,000 --> 00:01:18,000 +And they can be difficult to update and maintain. + +24 +00:01:18,000 --> 00:01:19,000 +Why is that? + +25 +00:01:19,000 --> 00:01:21,000 +Because someone has to manually do it. + +26 +00:01:21,000 --> 00:01:24,000 +This thing will never see the daylights of the internet. + +27 +00:01:24,000 --> 00:01:27,000 +It will never be connected to the internet or any network. + +28 +00:01:27,000 --> 00:01:29,000 +So any updates that needs to go. + +29 +00:01:29,000 --> 00:01:32,000 +Somebody has to manually download it like on a USB stick and take it to it. + +30 +00:01:32,000 --> 00:01:37,000 +The only which way to get data off of this machine is to go sit in front of it. + +31 +00:01:38,000 --> 00:01:38,000 +There's no way. + +32 +00:01:38,000 --> 00:01:39,000 +There's no shared drive or nothing. + +33 +00:01:40,000 --> 00:01:42,000 +There's no network cable in an air gap machine. + +34 +00:01:42,000 --> 00:01:46,000 +There is no wireless connection, nothing. + +35 +00:01:46,000 --> 00:01:47,000 +It doesn't connect to a network. + +36 +00:01:47,000 --> 00:01:53,000 +You could have an air gap network, in which case you can put a switch here and then have 2 or 3 machines + +37 +00:01:53,000 --> 00:01:54,000 +plugged into the switch. + +38 +00:01:54,000 --> 00:01:56,000 +But then that network is connected to nothing. + +39 +00:01:56,000 --> 00:02:00,000 +And if you want to get data off of that network, you have to go and sit in front of it. + +40 +00:02:01,000 --> 00:02:03,000 +The question is, why would you do this? + +41 +00:02:03,000 --> 00:02:05,000 +Well, because of confidentiality. + +42 +00:02:05,000 --> 00:02:11,000 +Whatever is on these air gap machines, whatever data, like that secret recipe you got, whatever is + +43 +00:02:11,000 --> 00:02:16,000 +stored on that particular machine is super secret to you. + +44 +00:02:16,000 --> 00:02:25,000 +Any time we connect a computer or a network to other networks that potentially has an internet connection, + +45 +00:02:25,000 --> 00:02:27,000 +we open up vulnerabilities. + +46 +00:02:27,000 --> 00:02:35,000 +Any machine that has that can get to Google is a big vulnerability because potential malware can be + +47 +00:02:35,000 --> 00:02:35,000 +downloaded. + +48 +00:02:35,000 --> 00:02:38,000 +Machine can its data can be stolen. + +49 +00:02:38,000 --> 00:02:41,000 +But you know what's the best way to secure a machine? + +50 +00:02:41,000 --> 00:02:41,000 +Turn it off and on. + +51 +00:02:41,000 --> 00:02:43,000 +Plug air gap machine. + +52 +00:02:43,000 --> 00:02:45,000 +It just doesn't have any internet doesn't have to be off. + +53 +00:02:45,000 --> 00:02:47,000 +So it's almost there. + +54 +00:02:47,000 --> 00:02:47,000 +All right. + +55 +00:02:47,000 --> 00:02:50,000 +Make sure you understand what air gaps are for your exam. + diff --git a/10 - Security Architecture/006 Software-Defined Networking OB 3.1_en.srt b/10 - Security Architecture/006 Software-Defined Networking OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..bbab42d869423f6dc4ced00173f14b9541f0d585 --- /dev/null +++ b/10 - Security Architecture/006 Software-Defined Networking OB 3.1_en.srt @@ -0,0 +1,324 @@ +1 +00:00:00,000 --> 00:00:07,000 +Okay, one type of networking that is taken off recently and is really helping manage applications within + +2 +00:00:07,000 --> 00:00:12,000 +our network today, is something we're going to call software defined networking. + +3 +00:00:12,000 --> 00:00:19,000 +And to really understand why we need this and the advantages of it, I want to talk about just modern + +4 +00:00:19,000 --> 00:00:21,000 +day networking. + +5 +00:00:21,000 --> 00:00:26,000 +So in modern day networking packets goes through routers and switches. + +6 +00:00:26,000 --> 00:00:34,000 +When a packet arrives at a router, the router determines the next path to the to the actual destination. + +7 +00:00:34,000 --> 00:00:38,000 +It'll decide okay, let's say the router has multiple places to go. + +8 +00:00:38,000 --> 00:00:42,000 +So what happens is the router then has to determine what should I go here? + +9 +00:00:42,000 --> 00:00:42,000 +Should I go here. + +10 +00:00:42,000 --> 00:00:45,000 +And it chooses the most efficient path to the next router. + +11 +00:00:45,000 --> 00:00:48,000 +Then that router may choose it to the next router and so on and so on. + +12 +00:00:48,000 --> 00:00:53,000 +Basically routers really don't see very much beyond the other hop. + +13 +00:00:53,000 --> 00:00:58,000 +Now, while this is fine, it's probably not the most efficient way. + +14 +00:00:58,000 --> 00:01:04,000 +So what we did is we came up with a whole different thing called software defined networking. + +15 +00:01:04,000 --> 00:01:09,000 +And I want to I want you guys to watch this diagram, because I want you to have a good understanding + +16 +00:01:09,000 --> 00:01:09,000 +of what this is. + +17 +00:01:09,000 --> 00:01:14,000 +So you can imagine all the texts and boxes I have doesn't exist. + +18 +00:01:14,000 --> 00:01:17,000 +Let's say there's a computer connected. + +19 +00:01:17,000 --> 00:01:22,000 +To this router, a computer one and this computer connected to this router. + +20 +00:01:22,000 --> 00:01:23,000 +Computer two. + +21 +00:01:23,000 --> 00:01:29,000 +When data starts to traverse the network data is going to go maybe here, maybe here, here, maybe + +22 +00:01:29,000 --> 00:01:32,000 +here, here, here and here. + +23 +00:01:32,000 --> 00:01:33,000 +How did it get that path? + +24 +00:01:33,000 --> 00:01:40,000 +It just got the path because each router is finding the next best link or the fastest link generally + +25 +00:01:40,000 --> 00:01:42,000 +to the next router. + +26 +00:01:42,000 --> 00:01:44,000 +This is not very efficient. + +27 +00:01:44,000 --> 00:01:50,000 +And the reason that this is not efficient is because the routers are just not very aware of the entire + +28 +00:01:50,000 --> 00:01:50,000 +network. + +29 +00:01:50,000 --> 00:01:55,000 +So what we're going to do is we're going to we're going to call up a boss. + +30 +00:01:55,000 --> 00:02:02,000 +We're going to have a boss come in somebody that is big and can watch over all of these particular little + +31 +00:02:02,000 --> 00:02:06,000 +guys, these routers and say, well, they don't want to go from here. + +32 +00:02:06,000 --> 00:02:06,000 +From here. + +33 +00:02:06,000 --> 00:02:07,000 +This is the most efficient path. + +34 +00:02:08,000 --> 00:02:11,000 +This is called an Sdn controller, a controller. + +35 +00:02:11,000 --> 00:02:15,000 +Notice so all the routers are linked to the controller in the diagram. + +36 +00:02:15,000 --> 00:02:20,000 +Now the controller is what's going to determine the best path for the data to take. + +37 +00:02:20,000 --> 00:02:22,000 +You see in networking. + +38 +00:02:22,000 --> 00:02:25,000 +We generally have what's called a data plane. + +39 +00:02:25,000 --> 00:02:28,000 +A data plane is where the data is actually routed. + +40 +00:02:28,000 --> 00:02:32,000 +What we have now is a controller plane or a network controllers. + +41 +00:02:32,000 --> 00:02:40,000 +These are going to be devices or software that basically actually control the path of the data throughout + +42 +00:02:40,000 --> 00:02:41,000 +the entire network. + +43 +00:02:41,000 --> 00:02:46,000 +This allows for an interface with applications easier, so applications don't have to worry about data + +44 +00:02:46,000 --> 00:02:47,000 +routing. + +45 +00:02:48,000 --> 00:02:52,000 +The application speaks to the Sdn controller, making it just more efficient. + +46 +00:02:52,000 --> 00:02:53,000 +Now. + +47 +00:02:53,000 --> 00:02:55,000 +Couple things here. + +48 +00:02:55,000 --> 00:02:56,000 +So what exactly is this? + +49 +00:02:56,000 --> 00:03:02,000 +Well, what Sion does is that it breaks apart the network logic, the control plane from the underlying + +50 +00:03:02,000 --> 00:03:06,000 +routers and switches, uh, underlying routers that forwards traffic. + +51 +00:03:06,000 --> 00:03:07,000 +So routers and switches. + +52 +00:03:07,000 --> 00:03:12,000 +So back in the days, all the logic of the network or what was called a control plane was generally + +53 +00:03:12,000 --> 00:03:13,000 +handled by the router. + +54 +00:03:13,000 --> 00:03:15,000 +Now we're going to break that apart. + +55 +00:03:15,000 --> 00:03:19,000 +We're going to give that to generally the Sdn controller forwarding. + +56 +00:03:19,000 --> 00:03:23,000 +The traffic is still going to be these routers and switches, but they don't really think too much anymore. + +57 +00:03:23,000 --> 00:03:26,000 +The Sdn controller is the brain of the entire thing. + +58 +00:03:26,000 --> 00:03:29,000 +It's a software application that manages the flow of all traffic. + +59 +00:03:29,000 --> 00:03:36,000 +Now you notice there was something on the diagram called southbound and northbound interface. + +60 +00:03:36,000 --> 00:03:40,000 +If I look here, you notice I have a north, a southbound and a northbound. + +61 +00:03:40,000 --> 00:03:46,000 +I notice the southbound sits between the devices and the controller versus the northbound sits between + +62 +00:03:46,000 --> 00:03:49,000 +the application and the controller itself. + +63 +00:03:49,000 --> 00:03:56,000 +So the southbound generally runs on a protocol called Openflow that relays between controllers and switches. + +64 +00:03:56,000 --> 00:04:02,000 +So the controller speaks to the switches and the routers utilizing the southbound interface and then + +65 +00:04:02,000 --> 00:04:02,000 +the northbound. + +66 +00:04:02,000 --> 00:04:07,000 +The applications are business logic works with the controller through this now. + +67 +00:04:07,000 --> 00:04:10,000 +Lots of advantages in setting this up. + +68 +00:04:11,000 --> 00:04:17,000 +First of all, it allows for easy reconfiguration or reprogramming of the network, just like that, + +69 +00:04:17,000 --> 00:04:18,000 +to meet business needs. + +70 +00:04:18,000 --> 00:04:22,000 +No more do you have to reconfigure a bunch of routers, configure the controller or the controller can + +71 +00:04:22,000 --> 00:04:23,000 +automatically do it. + +72 +00:04:23,000 --> 00:04:25,000 +It's a centralized management. + +73 +00:04:25,000 --> 00:04:29,000 +Once you're working on a controller, you can centralize the entire configuration of your network. + +74 +00:04:29,000 --> 00:04:33,000 +It improves one of the main things the efficiency of routing. + +75 +00:04:33,000 --> 00:04:38,000 +And of course, it's very cost effective to manage all instead of having to configure all these types + +76 +00:04:38,000 --> 00:04:42,000 +of hardware, reduces the need for expensive proprietary hardware. + +77 +00:04:42,000 --> 00:04:45,000 +A lot of this thing here is based on open standards, by the way. + +78 +00:04:46,000 --> 00:04:48,000 +Stevens is here to stay. + +79 +00:04:48,000 --> 00:04:50,000 +Applications, I should say. + +80 +00:04:50,000 --> 00:04:55,000 +Networks today are more and more dependent on the applications that we use. + +81 +00:04:55,000 --> 00:04:59,000 +And because of that, we need to implement SNS to keep them effective. + diff --git a/10 - Security Architecture/007 On-Premises OB 3.1_en.srt b/10 - Security Architecture/007 On-Premises OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9520b878e32d3b0f71686a9eae363f715bf6f585 --- /dev/null +++ b/10 - Security Architecture/007 On-Premises OB 3.1_en.srt @@ -0,0 +1,156 @@ +1 +00:00:00,000 --> 00:00:07,000 +While many organizations today will utilize cloud computing, many organizations still has a lot of + +2 +00:00:07,000 --> 00:00:09,000 +their data on prem or on premises. + +3 +00:00:09,000 --> 00:00:13,000 +If on the exam you hear the terms on prem, it just means on premises. + +4 +00:00:13,000 --> 00:00:18,000 +What exactly is on premises is when the infrastructure is fully controlled and managed internally. + +5 +00:00:19,000 --> 00:00:25,000 +Offering complete control over security and also requiring significant resources now on prem has a lot + +6 +00:00:25,000 --> 00:00:29,000 +of advantages versus putting data into the cloud. + +7 +00:00:29,000 --> 00:00:36,000 +So generally in the world of it will say on prem, off prem, so on prem means it's in your it's in + +8 +00:00:36,000 --> 00:00:40,000 +your space, it's in your your floor, your data center. + +9 +00:00:40,000 --> 00:00:42,000 +You manage a machine, you cool the machine. + +10 +00:00:42,000 --> 00:00:43,000 +You own the machine. + +11 +00:00:43,000 --> 00:00:46,000 +Off Prem is generally in some third party vendor site. + +12 +00:00:46,000 --> 00:00:47,000 +It could be. + +13 +00:00:47,000 --> 00:00:50,000 +And it doesn't just have to be cloud, but it could be somebody else. + +14 +00:00:50,000 --> 00:00:56,000 +Managing your own servers now on prem has many security advantages, because you're the one that's going + +15 +00:00:56,000 --> 00:00:58,000 +to be controlling all the security aspects. + +16 +00:00:58,000 --> 00:01:02,000 +You don't have to worry about third parties not implementing the right thing, but this is going to + +17 +00:01:02,000 --> 00:01:03,000 +come at a significant cost. + +18 +00:01:03,000 --> 00:01:08,000 +One of its biggest downfall is cost, because if you manage your own servers, you got to keep them + +19 +00:01:08,000 --> 00:01:09,000 +cool. + +20 +00:01:09,000 --> 00:01:10,000 +You got to keep them powered on. + +21 +00:01:10,000 --> 00:01:12,000 +You need to pay for the physical space. + +22 +00:01:12,000 --> 00:01:14,000 +That includes paying local taxes. + +23 +00:01:14,000 --> 00:01:17,000 +You need to physically secure that particular building. + +24 +00:01:17,000 --> 00:01:19,000 +So it's going to come at a cost. + +25 +00:01:19,000 --> 00:01:24,000 +What we do, what we have to think about, is we have to weigh that cost against the risks. + +26 +00:01:24,000 --> 00:01:29,000 +So if the data goes into AWS and Amazon is managing it. + +27 +00:01:30,000 --> 00:01:34,000 +There is a probability that Amazon gets hacked. + +28 +00:01:34,000 --> 00:01:36,000 +What exactly is that worth to you? + +29 +00:01:36,000 --> 00:01:40,000 +What is that probability that Amazon gets hacked wherever you store that data? + +30 +00:01:40,000 --> 00:01:41,000 +That's something that you have to consider. + +31 +00:01:41,000 --> 00:01:48,000 +There is a probability that that provider gets hacked, that that provider loses your information versus + +32 +00:01:48,000 --> 00:01:50,000 +you having it, the cost of just you maintaining it. + +33 +00:01:50,000 --> 00:01:54,000 +You're probably going to have more security control over. + +34 +00:01:55,000 --> 00:02:00,000 +Uh, your own data because it's on your systems versus something in AWS. + +35 +00:02:00,000 --> 00:02:02,000 +Now, you can argue the point. + +36 +00:02:02,000 --> 00:02:03,000 +I can argue both ways. + +37 +00:02:03,000 --> 00:02:05,000 +Something in AWS could be more secure. + +38 +00:02:05,000 --> 00:02:10,000 +But generally speaking, in my opinion, it is generally more secure on prem. + +39 +00:02:10,000 --> 00:02:14,000 +But on prem does come at a significant cost. + diff --git a/10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1_en.srt b/10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e952de958a7a5400a6aa31138d76102999fe32ce --- /dev/null +++ b/10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1_en.srt @@ -0,0 +1,212 @@ +1 +00:00:00,000 --> 00:00:05,000 +When you're setting up a security system or a particularly a particular type of a network, there's + +2 +00:00:05,000 --> 00:00:09,000 +two terms that you're going to want to keep into consideration when you set these things up. + +3 +00:00:09,000 --> 00:00:15,000 +And that's going to be should we set up centralized systems or decentralized systems? + +4 +00:00:15,000 --> 00:00:21,000 +A centralized system would be, for example, let's say you have a giant company, and they have one + +5 +00:00:21,000 --> 00:00:27,000 +particular data center where everything is managed from all the applications are there, all the policies + +6 +00:00:27,000 --> 00:00:33,000 +are there, and then the branch data and then your branch offices just connects to your centralized + +7 +00:00:33,000 --> 00:00:34,000 +data center. + +8 +00:00:34,000 --> 00:00:37,000 +That's single data center where everything is managed from. + +9 +00:00:37,000 --> 00:00:38,000 +This is great. + +10 +00:00:38,000 --> 00:00:45,000 +There's no problem with that because now it's easy to have consistent policies, consistent configuration, + +11 +00:00:45,000 --> 00:00:48,000 +and everybody gets the same amount of data. + +12 +00:00:48,000 --> 00:00:54,000 +Now, you could decentralize this and end up with a system where you have multiple data centers, managing + +13 +00:00:54,000 --> 00:00:59,000 +all different kinds of applications, and maybe even marrying them to other data center. + +14 +00:00:59,000 --> 00:01:02,000 +This of course, creates good resiliency. + +15 +00:01:02,000 --> 00:01:07,000 +Resiliency is the ability for if the system takes a hit, if one of the data center goes down, your + +16 +00:01:07,000 --> 00:01:09,000 +whole network doesn't drop. + +17 +00:01:09,000 --> 00:01:12,000 +But in a centralized system, it becomes a single point of failure. + +18 +00:01:12,000 --> 00:01:18,000 +Because if you only have one data center where all your branch office goes connects to, and there is + +19 +00:01:18,000 --> 00:01:26,000 +a massive physical security or disaster such as power outages, floods, hurricanes, earthquakes, + +20 +00:01:26,000 --> 00:01:27,000 +it destroys the data center. + +21 +00:01:27,000 --> 00:01:30,000 +Your whole network will drop. + +22 +00:01:30,000 --> 00:01:38,000 +So centralized systems is a big problem when it comes to high availability, always on type system because + +23 +00:01:38,000 --> 00:01:42,000 +it becomes a single point of failure versus a decentralized system. + +24 +00:01:42,000 --> 00:01:48,000 +Well, it reduces the single point of failure because if one drops, then you know what another one + +25 +00:01:48,000 --> 00:01:52,000 +can kick in, especially if they were sharing data with each other. + +26 +00:01:53,000 --> 00:01:58,000 +Now, the problem with decentralized system is that you're going to miss that consistency. + +27 +00:01:58,000 --> 00:02:06,000 +And of course, you're going to not have all of the great, uh, things that comes with centralization, + +28 +00:02:06,000 --> 00:02:11,000 +such as, a lot of times, centralization can reduce costs because now you don't have 15 different data + +29 +00:02:11,000 --> 00:02:16,000 +centers reduce and in particular air costs because now you don't need five administrators for five different + +30 +00:02:16,000 --> 00:02:17,000 +data centers. + +31 +00:02:17,000 --> 00:02:24,000 +But, uh, decentralized systems will give you and remove that single point of failure. + +32 +00:02:24,000 --> 00:02:30,000 +But it could become complicated to monitor its security because you don't have consistent security policies. + +33 +00:02:30,000 --> 00:02:36,000 +And of course, the more options, the more likely the mistake, the bigger the attack surfaces it makes. + +34 +00:02:36,000 --> 00:02:39,000 +Security monitoring and keeping your network, uh, harder. + +35 +00:02:40,000 --> 00:02:44,000 +Now, I'm not going to tell you guys which one is best here. + +36 +00:02:44,000 --> 00:02:46,000 +There's pros and cons with each. + +37 +00:02:46,000 --> 00:02:48,000 +Centralization. + +38 +00:02:48,000 --> 00:02:50,000 +Is a centralized system easy to manage. + +39 +00:02:52,000 --> 00:02:59,000 +Consistent security and policy generally across generally cheaper, decentralized. + +40 +00:02:59,000 --> 00:03:01,000 +Oh, that thing. + +41 +00:03:01,000 --> 00:03:02,000 +Single point of failure. + +42 +00:03:03,000 --> 00:03:05,000 +Decentralized system. + +43 +00:03:05,000 --> 00:03:11,000 +It's all of it's the opposite decentralized system, harder to secure, much, generally speaking, + +44 +00:03:11,000 --> 00:03:13,000 +much more expensive. + +45 +00:03:13,000 --> 00:03:15,000 +But you lose that single point of failure. + +46 +00:03:15,000 --> 00:03:20,000 +This is going to be something that your organization needs to keep intact. + +47 +00:03:20,000 --> 00:03:28,000 +Now, before I move on, I use the analogy of data centers, but it could be a decentralized versus + +48 +00:03:28,000 --> 00:03:31,000 +centralized computer, right? + +49 +00:03:31,000 --> 00:03:38,000 +You can have applications spread across multiple computers, multiple servers in a decentralized setting, + +50 +00:03:38,000 --> 00:03:42,000 +or you can have them stored on one computer and all the clients connect to it. + +51 +00:03:42,000 --> 00:03:46,000 +Think of mainframe versus client server type environment. + +52 +00:03:46,000 --> 00:03:52,000 +Again, all whether you're using a system or you're thinking of data center, centralized and decentralized + +53 +00:03:52,000 --> 00:03:54,000 +will always have the same pros and cons. + diff --git a/10 - Security Architecture/009 Virtualization OB 3.1_en.srt b/10 - Security Architecture/009 Virtualization OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..12a2330a6b1ea64d53c9ba7f65ef52013ae518df --- /dev/null +++ b/10 - Security Architecture/009 Virtualization OB 3.1_en.srt @@ -0,0 +1,476 @@ +1 +00:00:00,000 --> 00:00:02,000 +Over my 20 plus year career. + +2 +00:00:02,000 --> 00:00:07,000 +There's one software that changed the way I studied, the way I deploy things, and it changed the way + +3 +00:00:07,000 --> 00:00:09,000 +the world in it works. + +4 +00:00:09,000 --> 00:00:11,000 +And that is called virtualization. + +5 +00:00:11,000 --> 00:00:15,000 +Now, unless you've been living under a rock, you should know what virtualization is. + +6 +00:00:15,000 --> 00:00:18,000 +If you're taking things like my A+ and my Network+ courses and so on. + +7 +00:00:18,000 --> 00:00:20,000 +You know, I use a ton of virtualization. + +8 +00:00:20,000 --> 00:00:24,000 +If you don't know what it is, let me give you a really one minute introduction to it. + +9 +00:00:24,000 --> 00:00:30,000 +So virtualization is are going to be things like here I have my virtual box, the number one virtual + +10 +00:00:30,000 --> 00:00:34,000 +software that I use because I'm not a business I'm just teaching a course. + +11 +00:00:34,000 --> 00:00:42,000 +So what this does is this allows me to run full fledged or multiple full fledged operating systems on + +12 +00:00:42,000 --> 00:00:43,000 +a single computer. + +13 +00:00:43,000 --> 00:00:46,000 +You notice right now I have a Windows server. + +14 +00:00:46,000 --> 00:00:51,000 +Uh, you can see that this is a Windows Server 2019 that I'm running here in the background. + +15 +00:00:51,000 --> 00:00:54,000 +So I'm actually running this operating system here. + +16 +00:00:54,000 --> 00:01:00,000 +Virtual box allows you to virtualize things not just Windows Server, but all basically all versions + +17 +00:01:00,000 --> 00:01:01,000 +of windows. + +18 +00:01:01,000 --> 00:01:03,000 +You can have a virtualized Mac, by the way. + +19 +00:01:04,000 --> 00:01:09,000 +Um, you can also virtualize all variations of Linux and Unix based systems. + +20 +00:01:09,000 --> 00:01:16,000 +So for example, when I'm teaching things like C and we utilize a lot of Kali Linux, we use a lot of + +21 +00:01:16,000 --> 00:01:17,000 +VirtualBox. + +22 +00:01:17,000 --> 00:01:22,000 +When I'm teaching certain courses, I may have 8 or 9 virtual machines open at once. + +23 +00:01:22,000 --> 00:01:23,000 +You do need resources to run it. + +24 +00:01:23,000 --> 00:01:26,000 +This machine does have 64 gigs of Ram in it. + +25 +00:01:26,000 --> 00:01:32,000 +So let's talk more about virtualization since that's the topic of today's. + +26 +00:01:32,000 --> 00:01:35,000 +And some terms you're going to need to be familiar with. + +27 +00:01:35,000 --> 00:01:40,000 +So virtualization is a creation of a virtual version of something. + +28 +00:01:40,000 --> 00:01:42,000 +More than likely we're talking an operating system. + +29 +00:01:42,000 --> 00:01:46,000 +But you can also virtual things like a software, a server or even storage devices. + +30 +00:01:47,000 --> 00:01:53,000 +Basically, you're going to use a you're going to use to host one or more operating system on your computer + +31 +00:01:53,000 --> 00:01:54,000 +within your memory. + +32 +00:01:54,000 --> 00:01:58,000 +So there is the host machine like my Windows 10 is my host machine. + +33 +00:01:58,000 --> 00:02:03,000 +And then all the guest machines or all the virtual machines that I'm going to be using. + +34 +00:02:04,000 --> 00:02:06,000 +Allows virtually any OS to operate on the hardware. + +35 +00:02:06,000 --> 00:02:09,000 +At the same time, VirtualBox is my preferred one. + +36 +00:02:09,000 --> 00:02:12,000 +The biggest name in this space is going to be VMware. + +37 +00:02:14,000 --> 00:02:17,000 +ESX is a big name brand, but VMware is the brand. + +38 +00:02:17,000 --> 00:02:19,000 +ESX is the product. + +39 +00:02:19,000 --> 00:02:21,000 +You also have Microsoft's Hyper-V. + +40 +00:02:21,000 --> 00:02:27,000 +Now VirtualBox that I'm using is made by Oracle, by the way, easier and faster to backups of an entire + +41 +00:02:27,000 --> 00:02:28,000 +virtual system. + +42 +00:02:28,000 --> 00:02:31,000 +Because you see, a virtual machine is really just a file. + +43 +00:02:31,000 --> 00:02:33,000 +It's just an individual file. + +44 +00:02:33,000 --> 00:02:34,000 +You back up the file. + +45 +00:02:34,000 --> 00:02:36,000 +Basically, the entire machine is backed up. + +46 +00:02:36,000 --> 00:02:43,000 +Now in the in the malware section of the course we talked something called VM escape. + +47 +00:02:43,000 --> 00:02:45,000 +Let me just briefly cover that in this video. + +48 +00:02:45,000 --> 00:02:46,000 +So. + +49 +00:02:47,000 --> 00:02:54,000 +If we look at our Windows Server 2019 that I have here. + +50 +00:02:54,000 --> 00:02:54,000 +All right. + +51 +00:02:54,000 --> 00:02:56,000 +So what happens if. + +52 +00:02:57,000 --> 00:03:03,000 +I start browsing the web on my virtual windows server and malware gets in. + +53 +00:03:03,000 --> 00:03:10,000 +Can malware leave this Windows server and infect the Windows 10 machine? + +54 +00:03:10,000 --> 00:03:20,000 +Well, depending on the severity of that malware, depending on updates within my machine, the probability + +55 +00:03:20,000 --> 00:03:23,000 +is there that would become that would be called a VM escape. + +56 +00:03:24,000 --> 00:03:30,000 +The great thing is that it offers individual instances of of servers and services are going to be run + +57 +00:03:30,000 --> 00:03:31,000 +on the machine. + +58 +00:03:31,000 --> 00:03:33,000 +You can scale it very quickly, quickly. + +59 +00:03:33,000 --> 00:03:36,000 +It's quick to recover from damage, crashed or corrupt. + +60 +00:03:36,000 --> 00:03:42,000 +The reason is because you have save points or snapshots of those VMs, and help desk support can easily + +61 +00:03:42,000 --> 00:03:45,000 +get to it because it's a single interface now. + +62 +00:03:45,000 --> 00:03:50,000 +When it comes to virtualization, there's a software you have to be familiar with. + +63 +00:03:50,000 --> 00:03:54,000 +Virtualization generally utilizes a software called a hypervisor. + +64 +00:03:54,000 --> 00:03:58,000 +Notice terme a note a different kinds of hypervisors that we have out there. + +65 +00:03:58,000 --> 00:04:04,000 +Hypervisors are a type of software firmware that creates and run these VMs. + +66 +00:04:04,000 --> 00:04:06,000 +It allows for the multiple of running. + +67 +00:04:06,000 --> 00:04:09,000 +Each operating system will appear to the operating system. + +68 +00:04:09,000 --> 00:04:16,000 +The guest OS will appear to have the host processor memory by itself, but it's the hypervisor. + +69 +00:04:16,000 --> 00:04:22,000 +So the hypervisor is what's controlling all of the access between the hardware and the guest operating + +70 +00:04:22,000 --> 00:04:23,000 +system. + +71 +00:04:23,000 --> 00:04:25,000 +Now you need to know this. + +72 +00:04:25,000 --> 00:04:28,000 +There's basically two kinds of hypervisors. + +73 +00:04:28,000 --> 00:04:32,000 +There's known as a type one known as bare metal hypervisor. + +74 +00:04:32,000 --> 00:04:35,000 +And then there is a type two hypervisor. + +75 +00:04:35,000 --> 00:04:39,000 +Now VirtualBox like I'm using is a type two hypervisor. + +76 +00:04:39,000 --> 00:04:44,000 +If you're using a server based product that's going to be a type one hypervisor. + +77 +00:04:44,000 --> 00:04:45,000 +So a type one hypervisor. + +78 +00:04:46,000 --> 00:04:55,000 +Runs directly on the on the hardware to manage the guest OS, ESX, Microsoft standalone Hyper-V are + +79 +00:04:55,000 --> 00:04:56,000 +examples of this. + +80 +00:04:56,000 --> 00:05:00,000 +So just for your information, when you install ESXi. + +81 +00:05:00,000 --> 00:05:04,000 +On a machine or VMware standalone. + +82 +00:05:05,000 --> 00:05:05,000 +Uh, Hyper-V. + +83 +00:05:06,000 --> 00:05:09,000 +It's it's it's own operating system. + +84 +00:05:09,000 --> 00:05:12,000 +You don't put windows and then you put this thing on, okay. + +85 +00:05:12,000 --> 00:05:14,000 +Like ESX, there's no like operating system. + +86 +00:05:14,000 --> 00:05:19,000 +You just install it directly on the hardware and then you just install the operating system, the guest + +87 +00:05:19,000 --> 00:05:21,000 +operating systems on top of that. + +88 +00:05:21,000 --> 00:05:22,000 +That is a bare metal. + +89 +00:05:22,000 --> 00:05:25,000 +This is more secure because you know why? + +90 +00:05:25,000 --> 00:05:27,000 +There's no underlying host. + +91 +00:05:27,000 --> 00:05:28,000 +There's no underlying. + +92 +00:05:28,000 --> 00:05:30,000 +For example, I have Windows 10 here. + +93 +00:05:30,000 --> 00:05:31,000 +Windows 10 crashes. + +94 +00:05:31,000 --> 00:05:32,000 +All my VMs can die with it. + +95 +00:05:33,000 --> 00:05:40,000 +So in this one it's just the hypervisor software and all of the VMs versus a type two hypervisor. + +96 +00:05:40,000 --> 00:05:45,000 +Basically, this one runs on a conventional operating system like my Windows 10 think. + +97 +00:05:46,000 --> 00:05:52,000 +So on this setup you have the hardware, we have Windows 10, then you have the VirtualBox, then you + +98 +00:05:52,000 --> 00:05:54,000 +have all of the operating the guest operating system. + +99 +00:05:54,000 --> 00:05:57,000 +If my Windows 10 crashes, everything dies with it. + +100 +00:05:58,000 --> 00:06:01,000 +So these are going to be used in test testing, environment development. + +101 +00:06:01,000 --> 00:06:04,000 +They shouldn't be used for mission critical stuff. + +102 +00:06:04,000 --> 00:06:07,000 +So just for your information here's a quick diagram of this. + +103 +00:06:07,000 --> 00:06:12,000 +So in a traditional non-virtualized machine you have your hardware, you have your operating system + +104 +00:06:12,000 --> 00:06:13,000 +and your apps. + +105 +00:06:13,000 --> 00:06:17,000 +Versus on a virtual architecture like this would be like a type one hypervisor. + +106 +00:06:17,000 --> 00:06:21,000 +You're going to put your hardware, you put your hypervisor on top of that, and then you put your operating + +107 +00:06:21,000 --> 00:06:22,000 +system there. + +108 +00:06:23,000 --> 00:06:28,000 +I don't know where you are in your IT security career, but if you haven't played with virtualization. + +109 +00:06:29,000 --> 00:06:31,000 +Um, that's bad news. + +110 +00:06:31,000 --> 00:06:34,000 +You need to start doing that about two years ago. + +111 +00:06:34,000 --> 00:06:38,000 +So what I highly recommend to do if you haven't done this yet, go out. + +112 +00:06:38,000 --> 00:06:39,000 +Download VirtualBox. + +113 +00:06:39,000 --> 00:06:41,000 +It is absolutely free. + +114 +00:06:41,000 --> 00:06:43,000 +Download a bunch of operating systems and install them. + +115 +00:06:43,000 --> 00:06:46,000 +Download on ubuntu that's absolutely free to download and play with. + +116 +00:06:46,000 --> 00:06:51,000 +You can also get trial versions of different, uh, different versions of windows to install. + +117 +00:06:52,000 --> 00:06:55,000 +Virtualization is how we power up a lot of the cloud based systems. + +118 +00:06:55,000 --> 00:06:57,000 +So this thing is not going anywhere. + +119 +00:06:57,000 --> 00:06:58,000 +It's just getting bigger. + diff --git a/10 - Security Architecture/010 Containerization OB 3.1_en.srt b/10 - Security Architecture/010 Containerization OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..8480b038b9f9939024da7d2c844b0bfa7cb28f32 --- /dev/null +++ b/10 - Security Architecture/010 Containerization OB 3.1_en.srt @@ -0,0 +1,364 @@ +1 +00:00:00,000 --> 00:00:07,000 +I absolutely love virtualization, but I love something called containers even more. + +2 +00:00:07,000 --> 00:00:12,000 +One piece of software that I highly recommend you try out is Dockers. + +3 +00:00:12,000 --> 00:00:17,000 +You can install Dockers on your computer on windows and you can have a lot of fun with it. + +4 +00:00:17,000 --> 00:00:20,000 +Do not install Docker and VirtualBox on the same machine. + +5 +00:00:20,000 --> 00:00:23,000 +I did that and it caused a lot of corruption. + +6 +00:00:23,000 --> 00:00:28,000 +But you can install Docker in many different things, and Docker is basically a container software. + +7 +00:00:28,000 --> 00:00:30,000 +It allows you to create and manage containers. + +8 +00:00:30,000 --> 00:00:32,000 +But what exactly are containers? + +9 +00:00:32,000 --> 00:00:33,000 +Well. + +10 +00:00:34,000 --> 00:00:40,000 +Containers is the evolution of virtualization for internally hosted systems containers. + +11 +00:00:41,000 --> 00:00:46,000 +You know, let me speed up this discussion by saying a container and a virtual machine is the end result + +12 +00:00:46,000 --> 00:00:47,000 +is technically the same thing. + +13 +00:00:47,000 --> 00:00:51,000 +It just containers are a lot faster, easier to manage and set up. + +14 +00:00:51,000 --> 00:00:52,000 +All right. + +15 +00:00:52,000 --> 00:00:57,000 +But the end result is containers will give you the same thing VMs do, except they just do it a lot + +16 +00:00:57,000 --> 00:00:58,000 +faster. + +17 +00:00:58,000 --> 00:01:00,000 +And I'll explain for that. + +18 +00:01:00,000 --> 00:01:03,000 +So you got to understand how containers are built. + +19 +00:01:03,000 --> 00:01:07,000 +So containers will eliminate duplicate OS elements. + +20 +00:01:07,000 --> 00:01:08,000 +Like with virtualization. + +21 +00:01:08,000 --> 00:01:11,000 +It uses a single kernel for multiple operating systems. + +22 +00:01:12,000 --> 00:01:19,000 +Now, before I get into the rest of this, I have a picture that I want you guys to follow along here + +23 +00:01:19,000 --> 00:01:19,000 +with me. + +24 +00:01:20,000 --> 00:01:20,000 +Um. + +25 +00:01:21,000 --> 00:01:24,000 +Take a look at this image that I have here. + +26 +00:01:24,000 --> 00:01:27,000 +So on a virtual machine we have to understand how it works. + +27 +00:01:27,000 --> 00:01:28,000 +On a virtual machine. + +28 +00:01:28,000 --> 00:01:33,000 +You have your hardware, you have your hypervisor, and then you have all the guest operating system, + +29 +00:01:33,000 --> 00:01:38,000 +all the guest operating system on top of this guest operating system. + +30 +00:01:38,000 --> 00:01:43,000 +Then you're going to have all the libraries, all the things that makes the applications work and the + +31 +00:01:43,000 --> 00:01:46,000 +apps you notice on a container. + +32 +00:01:46,000 --> 00:01:47,000 +The end result is the same. + +33 +00:01:47,000 --> 00:01:54,000 +You still have apps, but the only difference here is that instead of running multiple operating systems + +34 +00:01:54,000 --> 00:01:58,000 +here, it's replaced with this thing called a container engine. + +35 +00:01:58,000 --> 00:02:01,000 +What container engines are able to do? + +36 +00:02:02,000 --> 00:02:09,000 +What the container engines are able to do is this they're able to run multiple isolated instances known + +37 +00:02:09,000 --> 00:02:13,000 +as containers on the same operating system kernel. + +38 +00:02:13,000 --> 00:02:14,000 +So what does that mean? + +39 +00:02:14,000 --> 00:02:19,000 +So that means this you think about how this has to work. + +40 +00:02:19,000 --> 00:02:26,000 +If you have let's say you're doing virtual machines and you have five instances. + +41 +00:02:26,000 --> 00:02:28,000 +Let's say you're running uh on ubuntu. + +42 +00:02:28,000 --> 00:02:33,000 +You have five on ubuntu installed on, on on your virtual machine. + +43 +00:02:33,000 --> 00:02:38,000 +The problem is every one of those instances is running the core of the operating system. + +44 +00:02:38,000 --> 00:02:40,000 +It's the same -- OS you're running. + +45 +00:02:40,000 --> 00:02:45,000 +It's just that you're running on Ubuntu one and two three and boot to four and 1 to 5, right? + +46 +00:02:45,000 --> 00:02:50,000 +So you're using a ton of resources to power up five kernels in there. + +47 +00:02:52,000 --> 00:02:56,000 +What a container does is a container creates one instance of that kernel. + +48 +00:02:57,000 --> 00:03:06,000 +And the container engine will now allow the operator to basically create virtual or we should say containers + +49 +00:03:06,000 --> 00:03:09,000 +of five instances of unbuntu to run. + +50 +00:03:09,000 --> 00:03:14,000 +So you have five containers of unbuntu, but it's basically using one OS kernel. + +51 +00:03:14,000 --> 00:03:17,000 +And the container engine is what's managing this. + +52 +00:03:17,000 --> 00:03:20,000 +So if we go back to my slide here. + +53 +00:03:22,000 --> 00:03:25,000 +So what's happening here now is let's say you're running. + +54 +00:03:26,000 --> 00:03:28,000 +Let me erase this to make this a lot easier. + +55 +00:03:28,000 --> 00:03:31,000 +So let's say you're running this progress has has a kernel running. + +56 +00:03:31,000 --> 00:03:32,000 +This has a kernel running. + +57 +00:03:32,000 --> 00:03:33,000 +This has the kernel. + +58 +00:03:33,000 --> 00:03:34,000 +The kernel is the core. + +59 +00:03:34,000 --> 00:03:37,000 +Basically the the core operating system itself. + +60 +00:03:37,000 --> 00:03:41,000 +Now in this one you're running one container. + +61 +00:03:41,000 --> 00:03:43,000 +You're running a container engine running just the. + +62 +00:03:44,000 --> 00:03:49,000 +The kernel here utilizing one of the kernels, and now it's just running. + +63 +00:03:49,000 --> 00:03:51,000 +Now it seems the computer sees it. + +64 +00:03:51,000 --> 00:03:57,000 +The applications are seeing it as three instances of Unbuntu or whatever OS you're using. + +65 +00:03:57,000 --> 00:03:59,000 +Technically just one kernel. + +66 +00:03:59,000 --> 00:04:01,000 +The question is, why are we doing this? + +67 +00:04:01,000 --> 00:04:09,000 +Well, since you are reducing the kernel itself, since you're reducing the number of those instances + +68 +00:04:09,000 --> 00:04:16,000 +that are running, what you're doing is you're going to give yourself 110 to 100 times more application + +69 +00:04:16,000 --> 00:04:18,000 +density per physical server. + +70 +00:04:18,000 --> 00:04:24,000 +That means that you can run a lot more stuff on your machine, because it's utilizing a lot less resources. + +71 +00:04:24,000 --> 00:04:27,000 +In fact, to a container. + +72 +00:04:27,000 --> 00:04:32,000 +Running a Linux version nowadays is a few hundred megs versus an operating system installation could + +73 +00:04:32,000 --> 00:04:33,000 +be a few gigabytes. + +74 +00:04:33,000 --> 00:04:36,000 +Also, it utilizes a lot less resources. + +75 +00:04:36,000 --> 00:04:38,000 +Guys, I am not joking. + +76 +00:04:38,000 --> 00:04:42,000 +I can install Kali or different. + +77 +00:04:43,000 --> 00:04:46,000 +Operating systems from the Docker store. + +78 +00:04:46,000 --> 00:04:47,000 +I'm not going to get into that. + +79 +00:04:47,000 --> 00:04:53,000 +It's not a course on Docker, but you can download and install Docker installations, Linux based installations. + +80 +00:04:53,000 --> 00:04:55,000 +I can do that in minutes, sometimes even seconds. + +81 +00:04:55,000 --> 00:04:59,000 +I can just go put in the address, boom, I download it, it starts right up. + +82 +00:04:59,000 --> 00:05:02,000 +I'm running a brand new operating system now. + +83 +00:05:02,000 --> 00:05:07,000 +Containers only require resources to support the functionality of the app. + +84 +00:05:07,000 --> 00:05:07,000 +Why? + +85 +00:05:07,000 --> 00:05:11,000 +Because technically the operating system is in is already running. + +86 +00:05:11,000 --> 00:05:17,000 +Some deployments eliminate the hypervisor altogether and replace it with a collection of, uh, common + +87 +00:05:17,000 --> 00:05:18,000 +binaries, which makes it a lot easier. + +88 +00:05:18,000 --> 00:05:21,000 +Now keep in mind one one more. + +89 +00:05:21,000 --> 00:05:23,000 +You know, last point here about a container. + +90 +00:05:25,000 --> 00:05:29,000 +Containers are going to give you the same results as a virtual machine. + +91 +00:05:30,000 --> 00:05:34,000 +It's just going to do it a whole lot faster. + diff --git a/10 - Security Architecture/011 High Availability OB 3.1_en.srt b/10 - Security Architecture/011 High Availability OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..511d505068f2fc596e12527f5f919985d25f26fe --- /dev/null +++ b/10 - Security Architecture/011 High Availability OB 3.1_en.srt @@ -0,0 +1,316 @@ +1 +00:00:00,000 --> 00:00:06,000 +Any time you design a network, you're going to probably hope to build a network with what is called + +2 +00:00:06,000 --> 00:00:07,000 +high availability. + +3 +00:00:07,000 --> 00:00:09,000 +High availability. + +4 +00:00:10,000 --> 00:00:17,000 +Is when systems engineer engineer system at agreed level of operational performance, typically uptime + +5 +00:00:17,000 --> 00:00:19,000 +for a higher than normal period. + +6 +00:00:19,000 --> 00:00:26,000 +High availability means your system should have very little downtime. + +7 +00:00:26,000 --> 00:00:30,000 +Now, high availability is really minimization of downtime. + +8 +00:00:30,000 --> 00:00:35,000 +The primary goal is to minimize downtime, both planned and unplanned availability. + +9 +00:00:35,000 --> 00:00:36,000 +Now let's talk. + +10 +00:00:36,000 --> 00:00:37,000 +Let's say you have a computer network. + +11 +00:00:38,000 --> 00:00:38,000 +All right. + +12 +00:00:38,000 --> 00:00:41,000 +That computer network has servers on it. + +13 +00:00:41,000 --> 00:00:43,000 +It has printers that your users need. + +14 +00:00:43,000 --> 00:00:47,000 +You want your you want your network to be up as much as possible. + +15 +00:00:47,000 --> 00:00:52,000 +But this is going to require massive amounts of redundancy in a network. + +16 +00:00:52,000 --> 00:00:55,000 +There's what's called planned and unplanned downtime. + +17 +00:00:55,000 --> 00:00:59,000 +Planned downtime is when you take down like a server or a switch from maintenance guys. + +18 +00:00:59,000 --> 00:01:04,000 +If you're running a Windows server, at some point, you have to install updates and reboot it. + +19 +00:01:04,000 --> 00:01:07,000 +This is a planned downtime because this can take a few minutes. + +20 +00:01:07,000 --> 00:01:11,000 +And in fact, when you're installing those updates, it might take a couple more minutes. + +21 +00:01:11,000 --> 00:01:14,000 +So you may do a 30 minute downtime. + +22 +00:01:14,000 --> 00:01:17,000 +But in the world of business, 30 minutes can be millions of dollars. + +23 +00:01:17,000 --> 00:01:18,000 +That's loss. + +24 +00:01:18,000 --> 00:01:19,000 +That's planned. + +25 +00:01:19,000 --> 00:01:21,000 +Downtime, of course, is unplanned downtime. + +26 +00:01:22,000 --> 00:01:24,000 +When a worm infection network, you never thought about it. + +27 +00:01:24,000 --> 00:01:29,000 +When the server blows up unexpectedly that you didn't think about it, you just didn't plan for it. + +28 +00:01:30,000 --> 00:01:33,000 +The objective here is you want high availability. + +29 +00:01:33,000 --> 00:01:37,000 +You see, high availability is cyber. + +30 +00:01:37,000 --> 00:01:41,000 +You want high redundancy, redundant components. + +31 +00:01:42,000 --> 00:01:44,000 +Backup components. + +32 +00:01:44,000 --> 00:01:46,000 +Raid system. + +33 +00:01:46,000 --> 00:01:51,000 +Continuous backup clusters are going to be ways to ensure high redundancy. + +34 +00:01:51,000 --> 00:01:56,000 +That way, if a component like imagine you have a Raid system, a Raid five on a hard drive, if one + +35 +00:01:56,000 --> 00:01:58,000 +of the hard drive fails, the other one will. + +36 +00:01:58,000 --> 00:01:59,000 +They'll just keep functioning. + +37 +00:01:59,000 --> 00:02:02,000 +The other ones will make up for that lost drive. + +38 +00:02:02,000 --> 00:02:04,000 +Failover mechanisms. + +39 +00:02:04,000 --> 00:02:06,000 +If one system fails, fails, over to another one. + +40 +00:02:06,000 --> 00:02:09,000 +We talked about this in clustering reliability. + +41 +00:02:09,000 --> 00:02:13,000 +How reliable is that system and how stable is that particular system. + +42 +00:02:14,000 --> 00:02:16,000 +Um, reliability is operate without failure. + +43 +00:02:16,000 --> 00:02:22,000 +That means it's highly reliable versus stable is maintaining performance. + +44 +00:02:22,000 --> 00:02:23,000 +You know what's not reliable? + +45 +00:02:23,000 --> 00:02:27,000 +Seagate hard drive the worst garbage ever made. + +46 +00:02:27,000 --> 00:02:31,000 +I have never gotten a Seagate hard drive to last more than five hours. + +47 +00:02:31,000 --> 00:02:33,000 +Western digital I'll put it in a machine. + +48 +00:02:33,000 --> 00:02:34,000 +It'll last me a couple of years. + +49 +00:02:34,000 --> 00:02:36,000 +A Seagate, maybe ten minutes. + +50 +00:02:36,000 --> 00:02:37,000 +It's dead. + +51 +00:02:37,000 --> 00:02:38,000 +Gotta return to the manufacturer. + +52 +00:02:38,000 --> 00:02:39,000 +I hate Seagate. + +53 +00:02:39,000 --> 00:02:43,000 +I have returned every Seagate hard drive in my life. + +54 +00:02:43,000 --> 00:02:45,000 +Um, is it reliable? + +55 +00:02:45,000 --> 00:02:45,000 +No. + +56 +00:02:45,000 --> 00:02:48,000 +It can't operate without a failure for very long. + +57 +00:02:48,000 --> 00:02:55,000 +Stability, though, is how that performance work when it comes to maintaining high availability. + +58 +00:02:55,000 --> 00:02:56,000 +High. + +59 +00:02:56,000 --> 00:02:59,000 +That means you're going to need very low downtime. + +60 +00:02:59,000 --> 00:03:02,000 +You're going to have to build high redundancy. + +61 +00:03:02,000 --> 00:03:06,000 +You're going to have to have massive failover mechanisms, and you're going to have to make sure that + +62 +00:03:06,000 --> 00:03:07,000 +it is reliable. + +63 +00:03:07,000 --> 00:03:11,000 +Now, all of this will come with a cost, okay. + +64 +00:03:11,000 --> 00:03:18,000 +Implementing redundant power supply, redundant power lines, uh, redundant hard drives, clusters + +65 +00:03:18,000 --> 00:03:24,000 +of servers of course will come with cost because to power up two servers instead of one costs money + +66 +00:03:24,000 --> 00:03:27,000 +to cool two servers instead of one cost money. + +67 +00:03:28,000 --> 00:03:30,000 +The question is, is it worth it? + +68 +00:03:30,000 --> 00:03:32,000 +Well, it depends what it is. + +69 +00:03:32,000 --> 00:03:39,000 +If that server, that network, that web server goes down and 30 minutes is worth millions of dollars, + +70 +00:03:39,000 --> 00:03:40,000 +think Amazon here. + +71 +00:03:40,000 --> 00:03:42,000 +What if Amazon goes down for ten minutes? + +72 +00:03:42,000 --> 00:03:44,000 +How much how much money does it lose? + +73 +00:03:44,000 --> 00:03:45,000 +Maybe millions or billions. + +74 +00:03:45,000 --> 00:03:46,000 +Who knows. + +75 +00:03:46,000 --> 00:03:53,000 +So imagine you're losing millions of dollars for every minute the system is down. + +76 +00:03:53,000 --> 00:03:55,000 +Then high availability makes sense. + +77 +00:03:55,000 --> 00:04:01,000 +But if if you go down and you're not losing very much money, maybe a few hundred dollars, then it + +78 +00:04:01,000 --> 00:04:04,000 +probably wouldn't make sense to spend half $1 million on high availability. + +79 +00:04:04,000 --> 00:04:09,000 +You have to understand the risks before selecting the solution. + diff --git a/10 - Security Architecture/012 IoT OB 3.1_en.srt b/10 - Security Architecture/012 IoT OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f7263b95693ed0b7a78a65ef180c38ec0ee0f62e --- /dev/null +++ b/10 - Security Architecture/012 IoT OB 3.1_en.srt @@ -0,0 +1,396 @@ +1 +00:00:00,000 --> 00:00:06,000 +The world is changing rapidly and more and more things are gaining IP addresses. + +2 +00:00:06,000 --> 00:00:07,000 +Think about this. + +3 +00:00:07,000 --> 00:00:14,000 +Did you guys realize that how many devices in your house is connected to your network, your fridge, + +4 +00:00:14,000 --> 00:00:18,000 +your stove, your microwave, your table, your TV? + +5 +00:00:18,000 --> 00:00:22,000 +Hell, even your watch, uh, your car. + +6 +00:00:22,000 --> 00:00:24,000 +So many things. + +7 +00:00:24,000 --> 00:00:25,000 +Oh, your door lock. + +8 +00:00:25,000 --> 00:00:27,000 +I put one of those in my house recently. + +9 +00:00:27,000 --> 00:00:28,000 +Your door lock. + +10 +00:00:28,000 --> 00:00:30,000 +I can open and close my door. + +11 +00:00:30,000 --> 00:00:31,000 +From my phone. + +12 +00:00:31,000 --> 00:00:40,000 +Now you see, this world of where everything is connected to the internet is known as the Internet of + +13 +00:00:40,000 --> 00:00:42,000 +Things topic for your exam. + +14 +00:00:42,000 --> 00:00:44,000 +Know what this is and know some of its downfalls. + +15 +00:00:44,000 --> 00:00:47,000 +And then I'll give you guys some things that we can do to secure it. + +16 +00:00:47,000 --> 00:00:52,000 +The Internet of Things is the network of physical objects that traditionally are not connected to the + +17 +00:00:52,000 --> 00:00:56,000 +internet, but now is things such as home automation devices. + +18 +00:00:56,000 --> 00:00:58,000 +Remote controlling and monitoring is all here. + +19 +00:00:58,000 --> 00:01:04,000 +Now this is going to include everything from house appliances, Hvac system, cars, your pin, your + +20 +00:01:04,000 --> 00:01:07,000 +your your shoes, maybe maybe your pants. + +21 +00:01:07,000 --> 00:01:07,000 +I don't know. + +22 +00:01:08,000 --> 00:01:11,000 +Lots and lots of things here are now connected to the internet. + +23 +00:01:11,000 --> 00:01:19,000 +Now, I'm not going to go into all the different devices, but the Internet of Things has a major problem + +24 +00:01:19,000 --> 00:01:26,000 +and that is if something is remotely accessible, it makes it accessible to the bad guys. + +25 +00:01:26,000 --> 00:01:31,000 +The bad guys can now do things that they haven't even imagined. + +26 +00:01:31,000 --> 00:01:34,000 +Now let's go through some of those attacks that we should be worried about. + +27 +00:01:34,000 --> 00:01:38,000 +So when the Internet of Things happen, here are some things that can happen. + +28 +00:01:38,000 --> 00:01:40,000 +Well, imagine you have a lamp. + +29 +00:01:40,000 --> 00:01:44,000 +Somebody can hold you hostage and say, uh, maybe I'm sorry. + +30 +00:01:44,000 --> 00:01:48,000 +A door lock controls for smart door locks. + +31 +00:01:48,000 --> 00:01:48,000 +I'm not. + +32 +00:01:48,000 --> 00:01:50,000 +And lights in your house. + +33 +00:01:50,000 --> 00:01:51,000 +Imagine a hacker emails you. + +34 +00:01:51,000 --> 00:01:54,000 +I'm not letting you in your house till you pay me some money. + +35 +00:01:54,000 --> 00:02:00,000 +What if a hacker infests, uh, send malware to your fridge, spoil all your food? + +36 +00:02:00,000 --> 00:02:03,000 +What happens if your drive. + +37 +00:02:03,000 --> 00:02:03,000 +You know what's even scary? + +38 +00:02:03,000 --> 00:02:05,000 +I was just talking, thinking about. + +39 +00:02:05,000 --> 00:02:11,000 +You're driving around road one day and your driverless internet accessible car. + +40 +00:02:11,000 --> 00:02:16,000 +And a hacker gets on the microphone and says, if you don't pay me ten GS right now, I'm crashing his + +41 +00:02:16,000 --> 00:02:17,000 +car in your debt. + +42 +00:02:17,000 --> 00:02:19,000 +See, this is why I drive a big old pickup truck. + +43 +00:02:19,000 --> 00:02:20,000 +Never have to worry about that. + +44 +00:02:20,000 --> 00:02:21,000 +Nothing. + +45 +00:02:21,000 --> 00:02:23,000 +Nothing electronic about that one. + +46 +00:02:25,000 --> 00:02:27,000 +Uh, so what happens if that happens? + +47 +00:02:27,000 --> 00:02:28,000 +Right? + +48 +00:02:28,000 --> 00:02:32,000 +Takes over the car, infotainment systems, locks, locks, the car from you. + +49 +00:02:32,000 --> 00:02:37,000 +God forbid you have a pacemaker and somebody, a remote attacker comes in and says, if you don't pay + +50 +00:02:37,000 --> 00:02:38,000 +me money, I'm going to kill you. + +51 +00:02:38,000 --> 00:02:40,000 +I'm going to stop your heart from working. + +52 +00:02:40,000 --> 00:02:44,000 +All these personal fitness devices can get hacked, by the way. + +53 +00:02:44,000 --> 00:02:46,000 +Like this smartwatch I'm wearing. + +54 +00:02:46,000 --> 00:02:47,000 +What if you have insulin? + +55 +00:02:47,000 --> 00:02:53,000 +Uh, what if you have, uh, insulin problems and it can stop the pump from working? + +56 +00:02:53,000 --> 00:02:56,000 +Or they hack the vehicle systems and crash your car, which you spoke about. + +57 +00:02:57,000 --> 00:03:00,000 +Oh, my God, what is the future holds. + +58 +00:03:00,000 --> 00:03:01,000 +You know, this is a security class. + +59 +00:03:01,000 --> 00:03:07,000 +And I'm glad you're watching this video because you, my friend, you are in the right class because + +60 +00:03:07,000 --> 00:03:10,000 +there's a lot of jobs coming up for our security folks, and I'm. + +61 +00:03:12,000 --> 00:03:16,000 +You know, I'm happy that we're going to have jobs in the future. + +62 +00:03:16,000 --> 00:03:22,000 +But I'm also scared for the future because generally when people think of it, security, we thought + +63 +00:03:22,000 --> 00:03:24,000 +of people stealing data, not physically harming us. + +64 +00:03:24,000 --> 00:03:29,000 +The problem with IoT is that now it becomes to the point where it's not just stealing our data and making + +65 +00:03:29,000 --> 00:03:31,000 +our lives miserable or stealing our money. + +66 +00:03:31,000 --> 00:03:36,000 +Now it's physically killing us when they stop the pacemaker or crash your car or don't allow you in + +67 +00:03:36,000 --> 00:03:37,000 +your house. + +68 +00:03:37,000 --> 00:03:40,000 +Now it's physically starting to really affect us. + +69 +00:03:41,000 --> 00:03:44,000 +What can we do with the IoT devices? + +70 +00:03:44,000 --> 00:03:51,000 +Just basically going to be three security things we should know for exam and two of them you should + +71 +00:03:51,000 --> 00:03:52,000 +already know. + +72 +00:03:52,000 --> 00:03:58,000 +Obviously password management, a lot of these devices are remotely connected to and managed through + +73 +00:03:58,000 --> 00:03:59,000 +some kind of user interface. + +74 +00:03:59,000 --> 00:04:07,000 +Think about logging into your nest thermostat or logging into your TV, logging into your fridge. + +75 +00:04:07,000 --> 00:04:11,000 +Uh, IoT devices also include printers logging into your printers. + +76 +00:04:11,000 --> 00:04:12,000 +It does have a username and password. + +77 +00:04:12,000 --> 00:04:15,000 +You may have default passwords. + +78 +00:04:15,000 --> 00:04:16,000 +Number two is updates. + +79 +00:04:16,000 --> 00:04:19,000 +Way too often we don't update these these devices. + +80 +00:04:19,000 --> 00:04:25,000 +When was the last you guys downloaded and installed an update for your watch or your TV or your fridge, + +81 +00:04:25,000 --> 00:04:27,000 +your coffee maker, or your car? + +82 +00:04:27,000 --> 00:04:30,000 +We have to keep and consistently install updates on these devices. + +83 +00:04:30,000 --> 00:04:36,000 +Now, when it comes to a corporate network, what you should be doing is segmenting these devices off. + +84 +00:04:36,000 --> 00:04:42,000 +For example, in the corporate network, maybe you have a fridge or a coffee maker in the break room + +85 +00:04:42,000 --> 00:04:48,000 +that is connected to the internet that that's great, but I want you to remember something. + +86 +00:04:48,000 --> 00:04:56,000 +If you if somebody hacks that fridge or that fridge has a vulnerability that gives an attacker a way + +87 +00:04:56,000 --> 00:05:03,000 +into your network, yes, you are securing all your workstations and you got all kinds of antivirus + +88 +00:05:03,000 --> 00:05:07,000 +and firewalls and endpoint protection on all the hosts in your network. + +89 +00:05:07,000 --> 00:05:09,000 +But your fridge has a default password. + +90 +00:05:09,000 --> 00:05:11,000 +It kind of defeats the purpose, right? + +91 +00:05:11,000 --> 00:05:16,000 +If they can get in and from the fridge, then scan all the traffic, scan your network and steal your + +92 +00:05:16,000 --> 00:05:16,000 +data. + +93 +00:05:16,000 --> 00:05:18,000 +It kind of defeats the purpose. + +94 +00:05:18,000 --> 00:05:23,000 +So we want to segment these things off, put them off on a network by themselves. + +95 +00:05:23,000 --> 00:05:30,000 +Things that are easily hacked like printers, fridges, coffee, all the IoT devices. + +96 +00:05:30,000 --> 00:05:32,000 +So something to keep in mind. + +97 +00:05:32,000 --> 00:05:32,000 +All right. + +98 +00:05:32,000 --> 00:05:34,000 +For your exam, how do we protect from IoT? + +99 +00:05:34,000 --> 00:05:38,000 +Change password password management updates and segment them. + diff --git a/10 - Security Architecture/013 ICS OB 3.1_en.srt b/10 - Security Architecture/013 ICS OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e905a9b40cbdb52c12ff09017cc4fdfa923ff84e --- /dev/null +++ b/10 - Security Architecture/013 ICS OB 3.1_en.srt @@ -0,0 +1,280 @@ +1 +00:00:00,000 --> 00:00:02,000 +You know what would be pretty devastating? + +2 +00:00:02,000 --> 00:00:05,000 +If I lose power to my house, that would really suck. + +3 +00:00:05,000 --> 00:00:07,000 +Or to my business. + +4 +00:00:07,000 --> 00:00:07,000 +Or anywhere. + +5 +00:00:07,000 --> 00:00:09,000 +Imagine a life without electricity. + +6 +00:00:09,000 --> 00:00:13,000 +Well, that could become somewhat of a reality. + +7 +00:00:13,000 --> 00:00:21,000 +You see a lot of the software that powers up power plants and power grids, a lot of the quote unquote + +8 +00:00:21,000 --> 00:00:29,000 +systems that runs utilities like power, water, gas and so on, oil and so on. + +9 +00:00:29,000 --> 00:00:30,000 +These things are very old. + +10 +00:00:30,000 --> 00:00:33,000 +These things were built in the 1960s. + +11 +00:00:33,000 --> 00:00:43,000 +A lot of these, what we will call industrial control systems, were built in an era when there was + +12 +00:00:43,000 --> 00:00:45,000 +no such thing as a as a computer. + +13 +00:00:45,000 --> 00:00:50,000 +These things, for example, nuclear power plants built in the 1960s. + +14 +00:00:50,000 --> 00:00:54,000 +Power supply are power grids built in the 1950s, 60s, 70s and 80s. + +15 +00:00:54,000 --> 00:01:01,000 +Unless something was built in that in the 2000, it really it might not be aware that there is a network. + +16 +00:01:01,000 --> 00:01:09,000 +One of the scariest things to me in IT security is if these things are hacked, if these things are + +17 +00:01:09,000 --> 00:01:11,000 +hacked, it can create mass chaos. + +18 +00:01:11,000 --> 00:01:14,000 +Imagine entire cities without power. + +19 +00:01:14,000 --> 00:01:18,000 +Imagine entire communities without water or without gas. + +20 +00:01:18,000 --> 00:01:19,000 +What would happen? + +21 +00:01:19,000 --> 00:01:22,000 +Infrastructure going down basically. + +22 +00:01:22,000 --> 00:01:25,000 +This is something that we need to protect now for our exam. + +23 +00:01:25,000 --> 00:01:29,000 +We do need to understand a couple couple terms about this. + +24 +00:01:29,000 --> 00:01:34,000 +So if you see on your exam industrial control system, think of all of these kinds of systems electrical, + +25 +00:01:34,000 --> 00:01:38,000 +water, gas and even all data lines are going to be classified here. + +26 +00:01:38,000 --> 00:01:46,000 +These kinds of systems will run on a particular protocol we call SCADA, SCADA, supervisory Control + +27 +00:01:46,000 --> 00:01:55,000 +and Data Acquisition or DC DCS distributed control system or PLCs now often found in here. + +28 +00:01:55,000 --> 00:02:02,000 +Now, there has been vulnerabilities against these kinds of systems running these kinds of protocols + +29 +00:02:02,000 --> 00:02:03,000 +that makes these system functions. + +30 +00:02:03,000 --> 00:02:08,000 +Remember, these systems are not technically the old ones are not technical systems. + +31 +00:02:08,000 --> 00:02:11,000 +They're all about opening and closing valves. + +32 +00:02:11,000 --> 00:02:14,000 +They have a variety of different sensors that allows them to work. + +33 +00:02:14,000 --> 00:02:20,000 +One of the things we want to do with ICS systems is to segment them off the network, potentially air + +34 +00:02:20,000 --> 00:02:25,000 +gap in the system, meaning that they're not remotely accessible to some internet connection. + +35 +00:02:25,000 --> 00:02:27,000 +There's been many hacks. + +36 +00:02:27,000 --> 00:02:35,000 +There have been published where people have found access into water supply systems around the world, + +37 +00:02:35,000 --> 00:02:40,000 +and could have potentially shut that off for those local communities or power grids for that, um, + +38 +00:02:41,000 --> 00:02:42,000 +or power grids. + +39 +00:02:42,000 --> 00:02:46,000 +So this is not something to take lightly when it comes to ICS. + +40 +00:02:46,000 --> 00:02:50,000 +It's not something a lot of IT security people worry about. + +41 +00:02:50,000 --> 00:02:56,000 +But if you work in the world of maintaining infrastructure, especially for government agencies, or + +42 +00:02:56,000 --> 00:03:02,000 +if you work in infrastructure company like a company that sells gas, for example, uh, here in here + +43 +00:03:02,000 --> 00:03:03,000 +in New York, we have Con Edison. + +44 +00:03:03,000 --> 00:03:08,000 +If you work for like Con Edison, you have to be worried about these things because attackers will come + +45 +00:03:08,000 --> 00:03:09,000 +after you. + +46 +00:03:09,000 --> 00:03:11,000 +They could create chaos. + +47 +00:03:12,000 --> 00:03:13,000 +How can we secure them? + +48 +00:03:13,000 --> 00:03:19,000 +Well, securing them, one of the first things we want to do is we want to be able to isolate the systems, + +49 +00:03:19,000 --> 00:03:25,000 +complete air gap off the network, or if that's not possible, maybe segment them off the network. + +50 +00:03:25,000 --> 00:03:29,000 +You also, if possible, to update them. + +51 +00:03:29,000 --> 00:03:31,000 +Some of these systems may be still be receiving updates. + +52 +00:03:31,000 --> 00:03:33,000 +That's important to install. + +53 +00:03:33,000 --> 00:03:38,000 +And of course if there's any kind of password management or anything like that, there have been some + +54 +00:03:38,000 --> 00:03:42,000 +really famous ICS attacks. + +55 +00:03:43,000 --> 00:03:45,000 +Uh, there was one. + +56 +00:03:45,000 --> 00:03:48,000 +I'm not going to get into the specifics on it. + +57 +00:03:48,000 --> 00:03:50,000 +Uh, you know, you don't need to know it. + +58 +00:03:50,000 --> 00:03:59,000 +There was one where in Iran they were running a, uh, to develop nuclear, to develop nuclear weapons. + +59 +00:03:59,000 --> 00:04:04,000 +The United States, supposedly United States and Israel develop a kind of a worm that infected their + +60 +00:04:04,000 --> 00:04:06,000 +systems and eventually blew it up. + +61 +00:04:07,000 --> 00:04:09,000 +If you know the name of it, let me know. + +62 +00:04:09,000 --> 00:04:11,000 +That's a very famous one. + +63 +00:04:11,000 --> 00:04:11,000 +All right. + +64 +00:04:11,000 --> 00:04:12,000 +I'm not going to get. + +65 +00:04:12,000 --> 00:04:18,000 +I told you, I'm going to get into the specifics of it, but these things generally do occur. + +66 +00:04:18,000 --> 00:04:19,000 +By the way, the name is Stuxnet. + +67 +00:04:19,000 --> 00:04:22,000 +If you didn't know the name of it, you can look that up. + +68 +00:04:22,000 --> 00:04:24,000 +That was a pretty interesting ICS attack. + +69 +00:04:24,000 --> 00:04:27,000 +But these things are happening more and more. + +70 +00:04:27,000 --> 00:04:30,000 +It's becoming more and more scarier and hopefully it stays secure. + diff --git a/10 - Security Architecture/014 RTOS and Embedded Systems OB 3.1_en.srt b/10 - Security Architecture/014 RTOS and Embedded Systems OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..e0a2013b99e075a676c277d4e37ee88bb82ac544 --- /dev/null +++ b/10 - Security Architecture/014 RTOS and Embedded Systems OB 3.1_en.srt @@ -0,0 +1,216 @@ +1 +00:00:00,000 --> 00:00:05,000 +You are surrounded by all kinds of technology that does really specific things. + +2 +00:00:05,000 --> 00:00:06,000 +You're surrounded. + +3 +00:00:06,000 --> 00:00:10,000 +You know, when people think of a system like an operating system, most of us think Windows and Mac, + +4 +00:00:10,000 --> 00:00:13,000 +but in reality, there's a lot more to that. + +5 +00:00:13,000 --> 00:00:13,000 +Think about this. + +6 +00:00:13,000 --> 00:00:18,000 +In reality, we have operating systems that are built into cameras, microphones. + +7 +00:00:18,000 --> 00:00:24,000 +I have a microphone device sitting here, uh, the little operating system that runs on this particular + +8 +00:00:24,000 --> 00:00:26,000 +Sony camera that's sitting in front of me. + +9 +00:00:26,000 --> 00:00:31,000 +We have all these kinds of operating systems that are running on little tiny chips around the place. + +10 +00:00:31,000 --> 00:00:34,000 +So in this video, let's take a look at two things. + +11 +00:00:34,000 --> 00:00:38,000 +We're taking a look at real time operating system or RTOs. + +12 +00:00:38,000 --> 00:00:41,000 +Um and the other one will take a look at is embedded system. + +13 +00:00:41,000 --> 00:00:43,000 +So what exactly is a real time operating system? + +14 +00:00:43,000 --> 00:00:50,000 +This is a specialized OS designed for managing hardware resources of a computer or embedded system. + +15 +00:00:50,000 --> 00:00:54,000 +Notice our embedded system in a way that ensures a specific task. + +16 +00:00:54,000 --> 00:00:57,000 +It's really about doing a specific task. + +17 +00:00:57,000 --> 00:01:01,000 +It you know, the two of its main thing is that it's very. + +18 +00:01:02,000 --> 00:01:07,000 +Determined a mystic can pronounces for repeating an input will result in the same output. + +19 +00:01:07,000 --> 00:01:09,000 +It keeps doing one thing over and over and over. + +20 +00:01:09,000 --> 00:01:10,000 +It doesn't. + +21 +00:01:10,000 --> 00:01:14,000 +It doesn't have to know a thousand different things like windows. + +22 +00:01:14,000 --> 00:01:14,000 +It does. + +23 +00:01:14,000 --> 00:01:16,000 +One thing goes back, does one thing. + +24 +00:01:16,000 --> 00:01:17,000 +It's high performance. + +25 +00:01:17,000 --> 00:01:20,000 +It's meant to be fast and crazy responsive. + +26 +00:01:21,000 --> 00:01:27,000 +A lot of times we use these things in for safety and security, frequently used in critical systems + +27 +00:01:27,000 --> 00:01:33,000 +like medical devices such as machines, that keeps people alive or flight controllers. + +28 +00:01:33,000 --> 00:01:36,000 +They generally have a very small footprint. + +29 +00:01:36,000 --> 00:01:43,000 +Now, the other thing here we have are going to be what's called an embedded system, specialized computing + +30 +00:01:43,000 --> 00:01:47,000 +that performs a dedicated function or designed for something. + +31 +00:01:47,000 --> 00:01:49,000 +This is generally going to be within a larger system. + +32 +00:01:49,000 --> 00:01:51,000 +So maybe you have something like a robotic arm. + +33 +00:01:51,000 --> 00:01:56,000 +So, uh, in a, in a bigger system, the thing that controls a robotic arm would be like an embedded + +34 +00:01:56,000 --> 00:01:58,000 +system, dedicated function. + +35 +00:01:58,000 --> 00:02:03,000 +Unlike general purpose computers think Windows Embedded are designed to do a specific task. + +36 +00:02:03,000 --> 00:02:09,000 +The control system in a washing machine or a flight controller is an embedded system. + +37 +00:02:09,000 --> 00:02:12,000 +It's often integrated directly into the hardware. + +38 +00:02:12,000 --> 00:02:18,000 +It's not going to have like potentially, uh, like how we have like, uh, a big hard drive in a, + +39 +00:02:18,000 --> 00:02:19,000 +in a normal machine. + +40 +00:02:19,000 --> 00:02:22,000 +They're closely integrated with physical environments. + +41 +00:02:22,000 --> 00:02:24,000 +They typically control physical operations. + +42 +00:02:24,000 --> 00:02:25,000 +So. + +43 +00:02:26,000 --> 00:02:30,000 +When it comes to embedded systems in real time operating systems, these are something that you're going + +44 +00:02:30,000 --> 00:02:32,000 +to find all around you. + +45 +00:02:32,000 --> 00:02:39,000 +The only thing that ever runs windows, like Windows 10 and 11 that user interact with is generally + +46 +00:02:39,000 --> 00:02:40,000 +what we install. + +47 +00:02:40,000 --> 00:02:43,000 +Windows 10 does have different windows. + +48 +00:02:43,000 --> 00:02:48,000 +I remember windows XP and stuff had different versions of it, like embedded versions of it, but then + +49 +00:02:48,000 --> 00:02:50,000 +it was done to a specific task. + +50 +00:02:50,000 --> 00:02:51,000 +So keep this in mind. + +51 +00:02:51,000 --> 00:02:57,000 +All the devices that you guys see perform in all kinds of functions around you, things in your car, + +52 +00:02:57,000 --> 00:03:01,000 +things in the medical office, operating systems, in the camera or your microphone. + +53 +00:03:01,000 --> 00:03:06,000 +Systems that I'm using all require some kind of an operating system to run. + +54 +00:03:06,000 --> 00:03:07,000 +And that's what these are. + diff --git a/10 - Security Architecture/015 Security Architecture Considerations OB 3.1_en.srt b/10 - Security Architecture/015 Security Architecture Considerations OB 3.1_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..f732ed01a68b0733f8a43e712c379dbdc4b79d1d --- /dev/null +++ b/10 - Security Architecture/015 Security Architecture Considerations OB 3.1_en.srt @@ -0,0 +1,724 @@ +1 +00:00:00,000 --> 00:00:06,000 +When it comes to selecting the right computing resources, such as should we go with monolithic design + +2 +00:00:06,000 --> 00:00:08,000 +or should we go with microservices? + +3 +00:00:08,000 --> 00:00:11,000 +Should we go with virtualization, or should we go with containers? + +4 +00:00:11,000 --> 00:00:14,000 +Should we go with on prem or off prem in the cloud? + +5 +00:00:14,000 --> 00:00:14,000 +Right. + +6 +00:00:14,000 --> 00:00:17,000 +There is a lot to consider. + +7 +00:00:17,000 --> 00:00:22,000 +And in this video I want to give you guys some things to consider when we go out and use. + +8 +00:00:22,000 --> 00:00:23,000 +Tell your boss. + +9 +00:00:23,000 --> 00:00:26,000 +Well, I want to move the entire data center to the cloud. + +10 +00:00:26,000 --> 00:00:28,000 +What's your reasoning for that? + +11 +00:00:28,000 --> 00:00:30,000 +Have you considered some of the things here? + +12 +00:00:30,000 --> 00:00:36,000 +When you tell the boss or you tell the programmer, let's design this in microservices versus monolith. + +13 +00:00:36,000 --> 00:00:38,000 +Have you considered some of these things? + +14 +00:00:39,000 --> 00:00:41,000 +Let's go through some things here to think about. + +15 +00:00:41,000 --> 00:00:45,000 +Now some of these have already covered and spoken about, so let's go through them. + +16 +00:00:45,000 --> 00:00:46,000 +This shouldn't take too long. + +17 +00:00:46,000 --> 00:00:52,000 +The first thing I want to talk about is whatever you're choosing, does it have a high availability + +18 +00:00:52,000 --> 00:00:54,000 +or does it have low availability? + +19 +00:00:54,000 --> 00:00:58,000 +For example, cloud services will generally contain a high availability. + +20 +00:00:58,000 --> 00:01:00,000 +It's critical to keep systems online. + +21 +00:01:00,000 --> 00:01:04,000 +You never want to choose something that has low availability. + +22 +00:01:04,000 --> 00:01:09,000 +For example, if you put this data into the cloud, it may cost x, y, z. + +23 +00:01:09,000 --> 00:01:12,000 +But if you put it here, well, we only have a single server. + +24 +00:01:12,000 --> 00:01:18,000 +And because it's a single server with a single power supply, we only have a single air conditioner. + +25 +00:01:18,000 --> 00:01:19,000 +We don't have a single instances of run. + +26 +00:01:19,000 --> 00:01:21,000 +It has a lower availability. + +27 +00:01:22,000 --> 00:01:25,000 +Now high availability is going to contain things like redundancy. + +28 +00:01:25,000 --> 00:01:27,000 +Do you have good redundancy in your network? + +29 +00:01:27,000 --> 00:01:29,000 +You may or you may not. + +30 +00:01:29,000 --> 00:01:36,000 +And then downtime, you may say, well if we put it in the cloud you may have very little downtime. + +31 +00:01:36,000 --> 00:01:38,000 +But if you keep it here, you may have more downtime. + +32 +00:01:39,000 --> 00:01:41,000 +But what is a productivity loss? + +33 +00:01:41,000 --> 00:01:47,000 +I mean, if the thing is not mission critical and if it doesn't use if you don't lose a lot during the + +34 +00:01:47,000 --> 00:01:50,000 +downtime, maybe it's okay to keep it here. + +35 +00:01:50,000 --> 00:01:52,000 +Something to consider. + +36 +00:01:52,000 --> 00:01:57,000 +The next thing you want to consider is how much of a hit it can take before cracking. + +37 +00:01:57,000 --> 00:02:03,000 +So resiliency are designed to handle and quickly recover from failure attacks or errors. + +38 +00:02:03,000 --> 00:02:10,000 +If you build a system with Raid redundant array of independent or inexpensive disks, if you have a + +39 +00:02:10,000 --> 00:02:10,000 +hard. + +40 +00:02:10,000 --> 00:02:13,000 +If you have a system of Raid, it is a good, resilient system. + +41 +00:02:13,000 --> 00:02:14,000 +It can take a hit. + +42 +00:02:14,000 --> 00:02:19,000 +One of those hard drives can take a hit and blow out, especially on a raid 5 or 1, and the system + +43 +00:02:19,000 --> 00:02:21,000 +can keep on going. + +44 +00:02:22,000 --> 00:02:27,000 +This involves not only technical measures like redundant and fault tolerant systems, but strategies + +45 +00:02:27,000 --> 00:02:28,000 +of how to manage it. + +46 +00:02:28,000 --> 00:02:33,000 +So does whatever you're choosing have high resiliency. + +47 +00:02:33,000 --> 00:02:37,000 +For example, the cloud has good resiliency on prem may not. + +48 +00:02:39,000 --> 00:02:41,000 +Cos this is the ultimate. + +49 +00:02:41,000 --> 00:02:46,000 +I know a lot of you guys looked at this and say, well, you know, what's the most important one to + +50 +00:02:46,000 --> 00:02:47,000 +senior management? + +51 +00:02:47,000 --> 00:02:49,000 +Cos it's like this will determine everything else. + +52 +00:02:49,000 --> 00:02:49,000 +I'm with you. + +53 +00:02:49,000 --> 00:02:51,000 +I feel your pain here. + +54 +00:02:51,000 --> 00:02:57,000 +But cos we can't discount it, cost is going to determine almost everything we have to balance security + +55 +00:02:57,000 --> 00:03:00,000 +needs with our budget. + +56 +00:03:00,000 --> 00:03:06,000 +Security will always result in more money controls, costs, money. + +57 +00:03:06,000 --> 00:03:10,000 +Security has to balance functionality and costs. + +58 +00:03:10,000 --> 00:03:16,000 +You see, security has a way of limiting functionality and increasing costs. + +59 +00:03:16,000 --> 00:03:17,000 +That's what it does. + +60 +00:03:17,000 --> 00:03:21,000 +It limits functionality, more functionality, bigger your attack surface. + +61 +00:03:21,000 --> 00:03:27,000 +But security hardware, software, control procedure, people and so on has costs. + +62 +00:03:27,000 --> 00:03:31,000 +You have to you have to balance that against the assets. + +63 +00:03:31,000 --> 00:03:32,000 +This is going to require risk assessment. + +64 +00:03:33,000 --> 00:03:38,000 +Does reducing functionality on the asset and increasing the cost to maintain the asset. + +65 +00:03:38,000 --> 00:03:39,000 +Is it worth it? + +66 +00:03:39,000 --> 00:03:43,000 +Well, if it's people's private information, if that's the asset, then yes. + +67 +00:03:44,000 --> 00:03:47,000 +This include upfront costs for hardware, software, and so on. + +68 +00:03:47,000 --> 00:03:52,000 +Overlooking long terme costs, such as those associated with updates and incidents could be a problem. + +69 +00:03:52,000 --> 00:03:56,000 +Never just look at the upfront costs of purchasing something. + +70 +00:03:56,000 --> 00:03:58,000 +Look at how look at the maintenance costs over time. + +71 +00:03:58,000 --> 00:04:04,000 +If you do decide to go with an outsource or third party, what's the responsiveness, for example, + +72 +00:04:04,000 --> 00:04:05,000 +of a help desk? + +73 +00:04:05,000 --> 00:04:10,000 +The ability to detect and respond to security threats rapidly is critical. + +74 +00:04:10,000 --> 00:04:12,000 +What if there is a problem? + +75 +00:04:12,000 --> 00:04:17,000 +Let's say you purchased this device and there is a massive vulnerability on this device. + +76 +00:04:17,000 --> 00:04:19,000 +Is Sonicwall going to respond fast? + +77 +00:04:19,000 --> 00:04:25,000 +Generally they do monitoring of systems and and different mechanisms for them to quickly respond. + +78 +00:04:26,000 --> 00:04:29,000 +Of course we want to reduce the number of impacts here. + +79 +00:04:29,000 --> 00:04:31,000 +The other thing is scalability. + +80 +00:04:31,000 --> 00:04:36,000 +You don't want to buy a system that's only good for a small organization. + +81 +00:04:36,000 --> 00:04:41,000 +The problem with this device, I believe this device is limited to 50 users. + +82 +00:04:43,000 --> 00:04:44,000 +There are space that we had this. + +83 +00:04:44,000 --> 00:04:45,000 +We don't use this. + +84 +00:04:45,000 --> 00:04:47,000 +I use it in my house basically now. + +85 +00:04:47,000 --> 00:04:53,000 +But, uh, we had this one of our locations and it was only done for, I think it was ten years or 12 + +86 +00:04:53,000 --> 00:04:53,000 +years. + +87 +00:04:53,000 --> 00:04:55,000 +It was for a small office. + +88 +00:04:55,000 --> 00:04:57,000 +We had small admin office. + +89 +00:04:57,000 --> 00:05:03,000 +So this is not very scalable, but they have devices that can take 500 600 users when you purchase. + +90 +00:05:04,000 --> 00:05:10,000 +Just don't go with the cheapest option if if this one is $700 and the bigger one was 1000 bucks. + +91 +00:05:11,000 --> 00:05:13,000 +Look at the company's growth. + +92 +00:05:13,000 --> 00:05:14,000 +Is the company projected to grow? + +93 +00:05:14,000 --> 00:05:16,000 +If it is, get the bigger one? + +94 +00:05:16,000 --> 00:05:18,000 +If it's not, maybe this one is more than sufficient. + +95 +00:05:18,000 --> 00:05:22,000 +Is it scalable to the needs of your business now? + +96 +00:05:22,000 --> 00:05:26,000 +Can it handle increased users, higher transactions, and so on? + +97 +00:05:26,000 --> 00:05:31,000 +Cloud computing of course, if you're computing on prem to cloud, cloud of course can grow as your + +98 +00:05:31,000 --> 00:05:33,000 +business grows. + +99 +00:05:33,000 --> 00:05:35,000 +Is it easy to deploy? + +100 +00:05:35,000 --> 00:05:38,000 +Nobody wants a complicated thing here, man. + +101 +00:05:38,000 --> 00:05:42,000 +We want things that are simplicity and straightforward to deploy. + +102 +00:05:42,000 --> 00:05:42,000 +Because. + +103 +00:05:42,000 --> 00:05:43,000 +Remember. + +104 +00:05:44,000 --> 00:05:51,000 +Complexity in security solutions can more than likely result in misconfiguration. + +105 +00:05:51,000 --> 00:05:57,000 +If something is very complex to configure in the world of IT security, more than likely they're going + +106 +00:05:57,000 --> 00:05:59,000 +to misconfigured that particular thing. + +107 +00:05:59,000 --> 00:06:05,000 +Complex deployment can lead to errors, security gaps, increased time to deployment. + +108 +00:06:05,000 --> 00:06:08,000 +Make sure the solution is easy to deploy. + +109 +00:06:09,000 --> 00:06:10,000 +Now. + +110 +00:06:11,000 --> 00:06:15,000 +Can you transfer some of the risks that are out there? + +111 +00:06:15,000 --> 00:06:21,000 +Uh, risk transference and risk management is a type of is basically something we're going to do. + +112 +00:06:23,000 --> 00:06:29,000 +It's something that we're going to do when we hand over risk to third party risk transfer is basically + +113 +00:06:29,000 --> 00:06:30,000 +buying of insurance. + +114 +00:06:30,000 --> 00:06:36,000 +So in certain high risks you can transfer risk to third party such as insurance companies be part of + +115 +00:06:36,000 --> 00:06:38,000 +a strategic decision. + +116 +00:06:38,000 --> 00:06:41,000 +It's important to understand the risk of transfer. + +117 +00:06:41,000 --> 00:06:47,000 +If you buy insurance and you give over risk, then it's the insurance company to take over that particular + +118 +00:06:47,000 --> 00:06:47,000 +risk. + +119 +00:06:48,000 --> 00:06:53,000 +Is it easy to recover systems if the systems does go down, is it easy to recover it? + +120 +00:06:53,000 --> 00:06:58,000 +Well, something on a cloud based system, it is easy to recover as they may have multiple instances. + +121 +00:06:58,000 --> 00:07:03,000 +Or for example, like on a virtual machine, it's easy to recover a system because you can easily back + +122 +00:07:03,000 --> 00:07:07,000 +up an instance versus on a physical machine. + +123 +00:07:07,000 --> 00:07:10,000 +Our patch is available for your particular computer. + +124 +00:07:10,000 --> 00:07:11,000 +Maybe it is, maybe it's not. + +125 +00:07:12,000 --> 00:07:16,000 +And then how long will patches be available for? + +126 +00:07:16,000 --> 00:07:22,000 +For example, if you purchase a system that's nearing its end of life and the manufacturer says we will + +127 +00:07:22,000 --> 00:07:27,000 +stop supporting the system in six months, probably not a good idea to purchase it. + +128 +00:07:27,000 --> 00:07:34,000 +Most manufacturers of devices, services, and software will patch their system over time, but they + +129 +00:07:34,000 --> 00:07:38,000 +almost all of them have an end of life that you should be familiar with. + +130 +00:07:39,000 --> 00:07:41,000 +Inability to patch. + +131 +00:07:41,000 --> 00:07:45,000 +It's not feasible to patch the are certain scenario with this possible. + +132 +00:07:45,000 --> 00:07:46,000 +For example. + +133 +00:07:47,000 --> 00:07:50,000 +A system that is dead in a scenario. + +134 +00:07:50,000 --> 00:07:51,000 +Patches is not feasible. + +135 +00:07:51,000 --> 00:07:53,000 +Alternative security may be needed. + +136 +00:07:53,000 --> 00:07:55,000 +Maybe you can isolate the system off the network. + +137 +00:07:55,000 --> 00:08:01,000 +For example, let's say you have some kind of processing system that processes certain transactions + +138 +00:08:02,000 --> 00:08:04,000 +that is mission critical to your business. + +139 +00:08:04,000 --> 00:08:06,000 +You guys can't find anything like it. + +140 +00:08:07,000 --> 00:08:09,000 +And the company that made it went out of business. + +141 +00:08:09,000 --> 00:08:11,000 +I've been through this before. + +142 +00:08:11,000 --> 00:08:15,000 +The best thing to do is to take that thing off the network, segment it out, or even potentially airgap + +143 +00:08:15,000 --> 00:08:21,000 +that system because people will be able to take that system out. + +144 +00:08:21,000 --> 00:08:23,000 +I'll give you guys a quick story, I do MRIs. + +145 +00:08:23,000 --> 00:08:24,000 +There was a problem with me. + +146 +00:08:24,000 --> 00:08:30,000 +While I have to do MRIs on a consistent basis, one of the MRIs facility I went to in the year 2022, + +147 +00:08:31,000 --> 00:08:36,000 +the machine that the they were using to run the machine, to run the MRI machine, I swear to God, + +148 +00:08:36,000 --> 00:08:38,000 +was running windows XP. + +149 +00:08:38,000 --> 00:08:44,000 +No, windows XP has been dead for the past ten years, but maybe that thing only runs on that particular + +150 +00:08:44,000 --> 00:08:45,000 +operating system. + +151 +00:08:45,000 --> 00:08:47,000 +Hopefully it was air gapped. + +152 +00:08:47,000 --> 00:08:49,000 +So there are systems that people still use. + +153 +00:08:49,000 --> 00:08:51,000 +Don't think that they are. + +154 +00:08:52,000 --> 00:08:53,000 +All the systems are updatable. + +155 +00:08:53,000 --> 00:08:59,000 +There are many companies and government agencies that are using operating systems and software that + +156 +00:08:59,000 --> 00:09:01,000 +are no longer supported. + +157 +00:09:02,000 --> 00:09:08,000 +Do you even have power requirements for your for the system you're choosing? + +158 +00:09:08,000 --> 00:09:10,000 +The energy needed. + +159 +00:09:10,000 --> 00:09:14,000 +For example, if you decide, well, I want to host everything on site. + +160 +00:09:15,000 --> 00:09:21,000 +Well, you know, when it comes to power, uh, you know, when it comes to hosting everything on site, + +161 +00:09:21,000 --> 00:09:23,000 +you're going to have to spend a lot of money on electricity. + +162 +00:09:23,000 --> 00:09:29,000 +Um, not just to keep this thing plugged in, but to keep the air conditioned running. + +163 +00:09:29,000 --> 00:09:34,000 +Do you have do you have the power to power up an air condition in your panels because you still got + +164 +00:09:34,000 --> 00:09:36,000 +to power up your entire building? + +165 +00:09:36,000 --> 00:09:43,000 +Something to think about if you decide to choose specific software to do things, do you even have the + +166 +00:09:43,000 --> 00:09:45,000 +compute and resources for that? + +167 +00:09:46,000 --> 00:09:51,000 +Uh, this includes running advanced security software, analyzing large amounts of data. + +168 +00:09:51,000 --> 00:09:57,000 +So if you run a lot of things internally and you install things like Siem systems, security information, + +169 +00:09:57,000 --> 00:10:00,000 +events like log in systems, you're going to have to process that information. + +170 +00:10:00,000 --> 00:10:05,000 +Do you have the compute and resources or does this become a bottleneck for you? + +171 +00:10:05,000 --> 00:10:06,000 +Okay. + +172 +00:10:06,000 --> 00:10:09,000 +So just run through this. + +173 +00:10:09,000 --> 00:10:11,000 +You know, before you choose the system that's out there. + +174 +00:10:11,000 --> 00:10:14,000 +These are things that you may want to consider. + +175 +00:10:14,000 --> 00:10:17,000 +I know a lot of people think about cost, but people don't think about power. + +176 +00:10:17,000 --> 00:10:19,000 +People don't think about patching. + +177 +00:10:19,000 --> 00:10:23,000 +People don't think about vendor support. + +178 +00:10:23,000 --> 00:10:26,000 +People don't think, can we get insurance on this product? + +179 +00:10:26,000 --> 00:10:32,000 +There's a lot of things there that I covered that many people that are choosing these systems may not + +180 +00:10:32,000 --> 00:10:33,000 +think about. + +181 +00:10:33,000 --> 00:10:37,000 +Way too often do we think about costs and forget everything else? + diff --git a/10 - Security Architecture/016 Quick Quiz.html b/10 - Security Architecture/016 Quick Quiz.html new file mode 100644 index 0000000000000000000000000000000000000000..df4f9dbd6f6f19a6cbe9d89b4832d04d901893ed --- /dev/null +++ b/10 - Security Architecture/016 Quick Quiz.html @@ -0,0 +1,479 @@ + + + + + + + Quiz + + + + +
+
+

+

+
+
+
+ Score: 999 of + 999% +
+
Correct: 999
+
Incorrect: 999
+
+ +
+ + + + +
+ + + + diff --git a/11 - Security Principles/001 Infrastructure Considerations OB 3.2_en.srt b/11 - Security Principles/001 Infrastructure Considerations OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..086b60f55879c11db14afe17a01d2bbcdaf3c0c2 --- /dev/null +++ b/11 - Security Principles/001 Infrastructure Considerations OB 3.2_en.srt @@ -0,0 +1,68 @@ +1 +00:00:00,000 --> 00:00:06,000 +When it comes to networking, it's really important to understand how your infrastructure is designed. + +2 +00:00:06,000 --> 00:00:13,000 +You see, when we're when we're thinking about it, security in general, we have to consider the infrastructure. + +3 +00:00:13,000 --> 00:00:19,000 +We have to think about all the different aspects of the IT infrastructure that needs to be secured and + +4 +00:00:19,000 --> 00:00:21,000 +protected against cyber threats. + +5 +00:00:21,000 --> 00:00:26,000 +What are the different things that can be affected by cyber threats? + +6 +00:00:26,000 --> 00:00:29,000 +That's going to be things like the workstations, which the users does work on. + +7 +00:00:29,000 --> 00:00:35,000 +That's where they process the data, the servers that are storing the data and also processing the data. + +8 +00:00:35,000 --> 00:00:38,000 +These are going to be two of the main things that we have to protect. + +9 +00:00:38,000 --> 00:00:42,000 +Now when we secure infrastructures, we're going to be using a wide variety of devices that I want to + +10 +00:00:42,000 --> 00:00:47,000 +cover in this section, whether you have different forms or different types of firewalls in your business, + +11 +00:00:47,000 --> 00:00:53,000 +intrusion detection systems, VPN concentrators, and so on, we want to take a look and understand + +12 +00:00:53,000 --> 00:00:58,000 +these kinds of systems, different versions of them, the pros and cons of different types of them. + +13 +00:00:58,000 --> 00:01:05,000 +Also, it's really important that when you walk into a network as a security professional, you know + +14 +00:01:05,000 --> 00:01:09,000 +what it takes or what it needs in order to be secure. + +15 +00:01:09,000 --> 00:01:13,000 +What devices, what software should I be implementing? + +16 +00:01:13,000 --> 00:01:16,000 +How should it be designed in order to keep it secure? + +17 +00:01:16,000 --> 00:01:18,000 +So let's get started in this section. + diff --git a/11 - Security Principles/002 Device Placement OB 3.2_en.srt b/11 - Security Principles/002 Device Placement OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..29d9bc38b1b3284cd5bd01b827dc5691940962b4 --- /dev/null +++ b/11 - Security Principles/002 Device Placement OB 3.2_en.srt @@ -0,0 +1,132 @@ +1 +00:00:00,000 --> 00:00:07,000 +When you purchase network devices or any kind of general computing devices, whether it's some kind + +2 +00:00:07,000 --> 00:00:12,000 +of a workstation, it's a router, it's a switch, it's a firewall, it's an intrusion detection system, + +3 +00:00:12,000 --> 00:00:14,000 +it's a load balancer. + +4 +00:00:14,000 --> 00:00:22,000 +Any kind of equipment that you purchase, you have to know where to place this device within your network. + +5 +00:00:22,000 --> 00:00:26,000 +You're going to have different parts of the network that requires different forms of security. + +6 +00:00:26,000 --> 00:00:31,000 +For example, you may have a part of the network that only stores top secret information. + +7 +00:00:31,000 --> 00:00:37,000 +You don't want devices to go into that part of the network that isn't at a certain classification level, + +8 +00:00:37,000 --> 00:00:39,000 +or operating at a certain level. + +9 +00:00:40,000 --> 00:00:46,000 +If you have places that just stores public data, it should probably be different the devices you put + +10 +00:00:46,000 --> 00:00:47,000 +there than at the top secret. + +11 +00:00:48,000 --> 00:00:54,000 +So when you're thinking about this, when it comes to device placement, this is the strategic positioning + +12 +00:00:54,000 --> 00:00:55,000 +of hardware components. + +13 +00:00:55,000 --> 00:00:58,000 +It includes physical and network locations. + +14 +00:00:58,000 --> 00:01:02,000 +For example, where do we place servers, routers, switches, and other components? + +15 +00:01:02,000 --> 00:01:03,000 +Things to think about. + +16 +00:01:03,000 --> 00:01:07,000 +You just don't take a server and put it in a in a public location. + +17 +00:01:07,000 --> 00:01:10,000 +Do you know you have to know where do you want to physically place it? + +18 +00:01:10,000 --> 00:01:13,000 +That server should be put into a server room. + +19 +00:01:13,000 --> 00:01:17,000 +That server room should have good environmental factors to keep it cool. + +20 +00:01:17,000 --> 00:01:18,000 +For example. + +21 +00:01:19,000 --> 00:01:21,000 +Now does it need redundancy? + +22 +00:01:22,000 --> 00:01:27,000 +Maybe that workstation doesn't need redundancy, or maybe that switch doesn't need it because it's a + +23 +00:01:27,000 --> 00:01:28,000 +small set of users. + +24 +00:01:28,000 --> 00:01:33,000 +But if you've got a core switch, you probably want good redundancy in that particular switch. + +25 +00:01:33,000 --> 00:01:34,000 +How much scalability is needed? + +26 +00:01:34,000 --> 00:01:39,000 +Maybe because that system is growing or you have a large user base over there. + +27 +00:01:39,000 --> 00:01:44,000 +Effective placement is critical because if you place devices in the wrong place, you could be opening + +28 +00:01:44,000 --> 00:01:48,000 +up all kinds of security problems degrading your network. + +29 +00:01:48,000 --> 00:01:52,000 +And you can also be breaking systems if the device is in place, right. + +30 +00:01:53,000 --> 00:01:57,000 +It's really important to know when you're looking at a network. + +31 +00:01:57,000 --> 00:02:05,000 +It's really important to know where each device could be physically placed, because you don't want + +32 +00:02:05,000 --> 00:02:11,000 +to put a I once again, a work a server in a room that's completely hot and then it blows up. + +33 +00:02:11,000 --> 00:02:14,000 +So keep this in mind when placing devices. + diff --git a/11 - Security Principles/003 Security Zones OB 3.2_en.srt b/11 - Security Principles/003 Security Zones OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..37c21b9580c1ab3fe68b578a93dec93df363b959 --- /dev/null +++ b/11 - Security Principles/003 Security Zones OB 3.2_en.srt @@ -0,0 +1,264 @@ +1 +00:00:00,000 --> 00:00:05,000 +Every single network out there has at least two zones. + +2 +00:00:05,000 --> 00:00:06,000 +Now, what is a zone? + +3 +00:00:06,000 --> 00:00:10,000 +A zone is basically a separation of a network, and they're generally named. + +4 +00:00:10,000 --> 00:00:13,000 +And what happens in each zone has a very particular functionality. + +5 +00:00:13,000 --> 00:00:16,000 +So in this video we want to take a look at security zones. + +6 +00:00:16,000 --> 00:00:19,000 +And I'll show you about three different security zones. + +7 +00:00:19,000 --> 00:00:21,000 +So what exactly security zones. + +8 +00:00:21,000 --> 00:00:27,000 +These zones are segments within a network that have distinct levels of security controls, and are separated + +9 +00:00:27,000 --> 00:00:30,000 +by physical or logical means. + +10 +00:00:30,000 --> 00:00:35,000 +Now, most networks generally have two zones. + +11 +00:00:35,000 --> 00:00:36,000 +All right. + +12 +00:00:36,000 --> 00:00:38,000 +Most network you at home have two zones. + +13 +00:00:38,000 --> 00:00:43,000 +You have an external zone or an internet zone, and you have an internal zone of where you keep your + +14 +00:00:43,000 --> 00:00:45,000 +internal computers. + +15 +00:00:45,000 --> 00:00:48,000 +Corporate networks today may also have a DMZ zone. + +16 +00:00:48,000 --> 00:00:51,000 +This is a zone where they put publicly accessible servers. + +17 +00:00:51,000 --> 00:00:52,000 +I have a picture. + +18 +00:00:52,000 --> 00:00:53,000 +I'll show you that in a second. + +19 +00:00:53,000 --> 00:00:58,000 +So what's the primary goal is to control access and exposure to different areas of the network. + +20 +00:00:58,000 --> 00:01:04,000 +So for example an external zone is much more accessible to the internet than to the internal world and + +21 +00:01:04,000 --> 00:01:07,000 +have different controls than internal zones. + +22 +00:01:07,000 --> 00:01:12,000 +So here is a picture of a place that has three zones. + +23 +00:01:12,000 --> 00:01:15,000 +So if you notice this is the internet. + +24 +00:01:15,000 --> 00:01:18,000 +So this here would be like an external zone. + +25 +00:01:18,000 --> 00:01:19,000 +Then they have a DMZ. + +26 +00:01:19,000 --> 00:01:21,000 +So this is the demilitarized zone. + +27 +00:01:21,000 --> 00:01:29,000 +Demilitarized zones is basically router uh servers such as a web server or a mail server that's publicly + +28 +00:01:29,000 --> 00:01:32,000 +accessible to the world in this scenario. + +29 +00:01:32,000 --> 00:01:36,000 +This is an organization that's basically hosting their own web server. + +30 +00:01:36,000 --> 00:01:41,000 +So they have their own web server, they have their own mail server here, and then they have an internal + +31 +00:01:41,000 --> 00:01:42,000 +network. + +32 +00:01:42,000 --> 00:01:48,000 +So this particular company, they have three zones as we see they have an external zone. + +33 +00:01:48,000 --> 00:01:52,000 +They have a DMZ or demilitarized zone. + +34 +00:01:52,000 --> 00:01:56,000 +Uh and then they have a private network or internal zone. + +35 +00:01:56,000 --> 00:02:01,000 +So for those of you guys at home, you probably don't have a DMZ. + +36 +00:02:01,000 --> 00:02:03,000 +Now these two brick things here are firewalls. + +37 +00:02:03,000 --> 00:02:05,000 +So the firewalls is protecting it. + +38 +00:02:05,000 --> 00:02:08,000 +The question is why would you need a DMZ. + +39 +00:02:08,000 --> 00:02:11,000 +And that brings me to this discussion on the demilitarized zone. + +40 +00:02:11,000 --> 00:02:21,000 +What exactly is this corporate networks today that hosts public servers, public servers such as we + +41 +00:02:21,000 --> 00:02:26,000 +have our mail server and we have our mail server and our web server. + +42 +00:02:26,000 --> 00:02:32,000 +You see, when you host your own servers, like maybe you could definitely go online and set up a website + +43 +00:02:32,000 --> 00:02:35,000 +and have somebody else host it for you, like GoDaddy. + +44 +00:02:35,000 --> 00:02:38,000 +Or you could just set up a server in your house and host it. + +45 +00:02:38,000 --> 00:02:44,000 +The problem with doing that is that if you put that web server inside of your network, like just as + +46 +00:02:44,000 --> 00:02:50,000 +a normal computer behind your firewall, what happens is public traffic. + +47 +00:02:50,000 --> 00:02:53,000 +Somebody that wants to access it would be in your network. + +48 +00:02:53,000 --> 00:02:58,000 +If that web server is compromised from somebody outside, you better best bet they can now see all the + +49 +00:02:58,000 --> 00:03:01,000 +data in your network, because that server is in your network. + +50 +00:03:01,000 --> 00:03:06,000 +So what corporate does is that we are going to put our web servers in front of one firewall. + +51 +00:03:06,000 --> 00:03:10,000 +So this would be like firewall one and firewall two. + +52 +00:03:10,000 --> 00:03:14,000 +So w here firewall one, firewall two. + +53 +00:03:14,000 --> 00:03:15,000 +So what's happening here. + +54 +00:03:15,000 --> 00:03:20,000 +The way this works is people from the internet that wants the web page on this web server would go through + +55 +00:03:20,000 --> 00:03:21,000 +this link. + +56 +00:03:22,000 --> 00:03:24,000 +Get the data, get the web page. + +57 +00:03:24,000 --> 00:03:26,000 +And then they would go right back out. + +58 +00:03:26,000 --> 00:03:28,000 +Notice they never come in the private network. + +59 +00:03:28,000 --> 00:03:32,000 +If you had that web server though in the private network you would actually have public traffic in there. + +60 +00:03:32,000 --> 00:03:35,000 +And that's not something you want. + +61 +00:03:35,000 --> 00:03:41,000 +So dms's are good to set up in corporate networks, because it allows you to segment off those particular + +62 +00:03:41,000 --> 00:03:47,000 +servers that needs access to the or is internet accessible? + +63 +00:03:47,000 --> 00:03:50,000 +You never want internet accessible service in your network. + +64 +00:03:50,000 --> 00:03:53,000 +Once again, if they're compromised, you better. + +65 +00:03:53,000 --> 00:03:54,000 +Best bet. + +66 +00:03:54,000 --> 00:03:55,000 +So is your internal network. + diff --git a/11 - Security Principles/004 Attack Surface OB 3.2_en.srt b/11 - Security Principles/004 Attack Surface OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..24cbccec3c419e369551abb94a33c1d6e17e9bb1 --- /dev/null +++ b/11 - Security Principles/004 Attack Surface OB 3.2_en.srt @@ -0,0 +1,188 @@ +1 +00:00:00,000 --> 00:00:05,000 +One thing that we must do when we manage it security is to reduce our attack surface. + +2 +00:00:05,000 --> 00:00:07,000 +Notice Terme for your exam. + +3 +00:00:07,000 --> 00:00:09,000 +What exactly is an attack surface? + +4 +00:00:09,000 --> 00:00:16,000 +When an attack surface refers to the total number of points where an unauthorized the attacker and basically + +5 +00:00:16,000 --> 00:00:18,000 +can try to enter and extract data. + +6 +00:00:18,000 --> 00:00:22,000 +It includes all the exposed areas that are vulnerable to cyber attacks. + +7 +00:00:22,000 --> 00:00:25,000 +This is both physical and digital aspects. + +8 +00:00:25,000 --> 00:00:26,000 +So let's get more into this. + +9 +00:00:26,000 --> 00:00:31,000 +So an attack surface is basically where somebody can get in. + +10 +00:00:31,000 --> 00:00:39,000 +The more complex your network is and the bigger your network is, the bigger your footprint is on this + +11 +00:00:39,000 --> 00:00:41,000 +planet, the more attack surfaces you have. + +12 +00:00:41,000 --> 00:00:47,000 +Let's go over some examples of digital attack surfaces and physical attack surfaces. + +13 +00:00:47,000 --> 00:00:52,000 +So the first one up we'll talk about is the easiest one to understand is physical attack surfaces. + +14 +00:00:53,000 --> 00:00:56,000 +Think about this if you have a built in, all right. + +15 +00:00:56,000 --> 00:00:59,000 +If you have a built in, it's a big building. + +16 +00:00:59,000 --> 00:01:02,000 +It has ten entry points into the building. + +17 +00:01:02,000 --> 00:01:06,000 +Uh, you may have security guards at some, you may have turnstiles at others, and so on. + +18 +00:01:06,000 --> 00:01:09,000 +This, of course, is a giant attack surface. + +19 +00:01:09,000 --> 00:01:12,000 +The more points into that building, the bigger your attack surface. + +20 +00:01:12,000 --> 00:01:14,000 +The more people coming in, the more the attack surface. + +21 +00:01:15,000 --> 00:01:20,000 +Remember, an attack surface is points where people can get in and extract data or cause harm to your + +22 +00:01:20,000 --> 00:01:21,000 +system. + +23 +00:01:22,000 --> 00:01:28,000 +So the more points that you have coming in, if you have no physical location, well then you know what? + +24 +00:01:28,000 --> 00:01:34,000 +Maybe you don't have much of a physical attack surface if all the company is digital, but if you have + +25 +00:01:34,000 --> 00:01:40,000 +a lot of workstations, you have a lot of different networks that are set up, a lot of internet lines + +26 +00:01:40,000 --> 00:01:42,000 +coming in, lots of different firewalls. + +27 +00:01:42,000 --> 00:01:45,000 +You have VPN accessible, you have remote desktop accessible. + +28 +00:01:45,000 --> 00:01:51,000 +All of these creates potential points that an attacker can get into your network. + +29 +00:01:52,000 --> 00:02:00,000 +Now, one of the things that you should be doing as a security administrator is you should be looking + +30 +00:02:00,000 --> 00:02:06,000 +at what are the potential points, what are is the number of points that we have, both digital and + +31 +00:02:06,000 --> 00:02:09,000 +physical, that people could potentially get in. + +32 +00:02:09,000 --> 00:02:12,000 +And the best thing to do is to reduce the number of them. + +33 +00:02:12,000 --> 00:02:17,000 +The more you reduce them, well, the better it is, because then there's just less to manage. + +34 +00:02:17,000 --> 00:02:21,000 +But sometimes the number of them being reduced is not possible. + +35 +00:02:21,000 --> 00:02:23,000 +For example, if you own a building. + +36 +00:02:24,000 --> 00:02:25,000 +The best. + +37 +00:02:25,000 --> 00:02:30,000 +The best thing you can do when owning a physical structure is to have one entry point. + +38 +00:02:30,000 --> 00:02:33,000 +So you could monitor and track everyone that comes in and out. + +39 +00:02:33,000 --> 00:02:39,000 +The problem with that is it's probably against the law, as most fire code requires two entry points, + +40 +00:02:39,000 --> 00:02:44,000 +one in just in case one gets, uh, hit with a fire and nobody can get out. + +41 +00:02:44,000 --> 00:02:47,000 +So entry and exit points, I should say. + +42 +00:02:47,000 --> 00:02:51,000 +So a lot of fire code has by required to have two entry exit points. + +43 +00:02:51,000 --> 00:02:54,000 +This of course is by is by law. + +44 +00:02:54,000 --> 00:02:55,000 +And you can't break the law. + +45 +00:02:55,000 --> 00:03:01,000 +So if it comes to the point where you can't reduce the number of attack surfaces or entry points, then + +46 +00:03:01,000 --> 00:03:09,000 +what you should be doing is to secure all of them as best as possible, because by securing them, you + +47 +00:03:09,000 --> 00:03:12,000 +will be able to reduce your attacks. + diff --git a/11 - Security Principles/005 Failure Modes OB 3.2_en.srt b/11 - Security Principles/005 Failure Modes OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..0aab39325843f536727848cfe7c8a8734e131a76 --- /dev/null +++ b/11 - Security Principles/005 Failure Modes OB 3.2_en.srt @@ -0,0 +1,316 @@ +1 +00:00:00,000 --> 00:00:05,000 +If there's one thing I know is that this device here, my sonic wall, will fail at some point. + +2 +00:00:05,000 --> 00:00:12,000 +Every single device in your network, every single thing that you use to control logical security, + +3 +00:00:12,000 --> 00:00:18,000 +such as a firewall or things you could use to control physical security, such as door locks, will + +4 +00:00:18,000 --> 00:00:22,000 +fail at some point, as most of everything will fail at some point in its life. + +5 +00:00:22,000 --> 00:00:28,000 +So in this video, I want to talk about something we call failure modes. + +6 +00:00:28,000 --> 00:00:36,000 +And failure modes is important because we know device fails, software fails, physical security things + +7 +00:00:36,000 --> 00:00:39,000 +fail, such as door locks will fail. + +8 +00:00:39,000 --> 00:00:42,000 +For example, you walk into a building, you walk in through an automated door. + +9 +00:00:42,000 --> 00:00:44,000 +At some point, that door may fail. + +10 +00:00:44,000 --> 00:00:45,000 +What if it runs out of power? + +11 +00:00:45,000 --> 00:00:48,000 +So we want to know what happens when it fails. + +12 +00:00:48,000 --> 00:00:55,000 +Because when these kinds of things fail, does it result in all the traffic coming in and your network + +13 +00:00:55,000 --> 00:00:56,000 +being hacked? + +14 +00:00:57,000 --> 00:01:00,000 +Does it result in the door being completely left open? + +15 +00:01:00,000 --> 00:01:03,000 +Well, well, we're going to take a look at this. + +16 +00:01:03,000 --> 00:01:09,000 +So failure modes are the different manner or conditions under which a system, network or component + +17 +00:01:09,000 --> 00:01:12,000 +can fail to perform its intended function. + +18 +00:01:12,000 --> 00:01:17,000 +This includes hardware or software failures, and it's a different set of scenarios that could lead + +19 +00:01:17,000 --> 00:01:22,000 +to security breaches or data loss, or even worse, the loss of life. + +20 +00:01:22,000 --> 00:01:31,000 +Now for our exam, I want to talk about two different types of failure what's called fail open and fail + +21 +00:01:31,000 --> 00:01:32,000 +close. + +22 +00:01:32,000 --> 00:01:38,000 +So here's what fail open is this is when the system defaults to an open state during failure. + +23 +00:01:38,000 --> 00:01:40,000 +What does that mean? + +24 +00:01:40,000 --> 00:01:49,000 +That means that if a system fails, it'll allow all traffic to come in and out the system. + +25 +00:01:49,000 --> 00:01:49,000 +Now. + +26 +00:01:49,000 --> 00:01:55,000 +For example, let's say you have this firewall set up on a guest network. + +27 +00:01:55,000 --> 00:01:58,000 +The network doesn't really need any security whatsoever. + +28 +00:01:58,000 --> 00:02:00,000 +There's really nothing there to protect. + +29 +00:02:00,000 --> 00:02:01,000 +And everything there is public data. + +30 +00:02:02,000 --> 00:02:07,000 +Well, in the in the event that this device fail, you don't want your 200 guests out of internet. + +31 +00:02:07,000 --> 00:02:10,000 +So what happens is this device will fail. + +32 +00:02:10,000 --> 00:02:13,000 +Let's say it's Ram chips bad or it gets corrupted. + +33 +00:02:13,000 --> 00:02:15,000 +What happens is that it allows all traffic to flow through. + +34 +00:02:15,000 --> 00:02:18,000 +This would be considered a fail open. + +35 +00:02:19,000 --> 00:02:25,000 +Now, in the world of physical security, this gets very important in the world of physical security. + +36 +00:02:25,000 --> 00:02:28,000 +We may call this thing fail safe in the terms of physical security. + +37 +00:02:28,000 --> 00:02:30,000 +Here's why. + +38 +00:02:30,000 --> 00:02:34,000 +You see, in physical security, let's say you have the outside of a building. + +39 +00:02:34,000 --> 00:02:36,000 +You have a automated door. + +40 +00:02:36,000 --> 00:02:39,000 +It's, you know, you walk through, it opens, it closes. + +41 +00:02:40,000 --> 00:02:47,000 +Now, our turnstile, for example, not turnstile, um, revolving doors, turnstile, revolving doors. + +42 +00:02:47,000 --> 00:02:49,000 +And it works with electrical power. + +43 +00:02:49,000 --> 00:02:53,000 +If the power runs out, what happens and the system fails? + +44 +00:02:53,000 --> 00:02:55,000 +It doesn't have any more power, does it? + +45 +00:02:55,000 --> 00:02:57,000 +Just lock the doors? + +46 +00:02:57,000 --> 00:02:59,000 +Does it lock the revolving door? + +47 +00:03:00,000 --> 00:03:03,000 +Or does it just allow and it just opens up? + +48 +00:03:03,000 --> 00:03:05,000 +For security reasons. + +49 +00:03:05,000 --> 00:03:07,000 +We wanted to open up. + +50 +00:03:07,000 --> 00:03:10,000 +We wanted to fail open. + +51 +00:03:10,000 --> 00:03:15,000 +That way people can get in and out just in case there is a fire. + +52 +00:03:15,000 --> 00:03:17,000 +Something's going on in the building. + +53 +00:03:17,000 --> 00:03:19,000 +What if the fire department needs to get in the building? + +54 +00:03:19,000 --> 00:03:24,000 +If they have to break the door down, that's precious seconds to minutes. + +55 +00:03:24,000 --> 00:03:25,000 +That's being lost. + +56 +00:03:25,000 --> 00:03:28,000 +The other one here is going to be fail closed. + +57 +00:03:28,000 --> 00:03:32,000 +The system defaults to close or a lock state when failed. + +58 +00:03:32,000 --> 00:03:39,000 +Now, most of the time, if our firewalls, for example I have this on my network, if this device fail, + +59 +00:03:39,000 --> 00:03:40,000 +it locks. + +60 +00:03:40,000 --> 00:03:42,000 +Nothing comes in, nothing comes out. + +61 +00:03:42,000 --> 00:03:46,000 +It completely stops the flow of traffic. + +62 +00:03:46,000 --> 00:03:53,000 +Now let's say there is a very secure room in a building. + +63 +00:03:53,000 --> 00:03:55,000 +In this room, there's tons of money and stuff like that. + +64 +00:03:55,000 --> 00:03:58,000 +If there's no power, the door should stay locked. + +65 +00:03:58,000 --> 00:03:59,000 +Nothing comes out. + +66 +00:03:59,000 --> 00:04:03,000 +This here would be considered a failed secure in the world of physical security. + +67 +00:04:03,000 --> 00:04:05,000 +We would use the word fail secure. + +68 +00:04:05,000 --> 00:04:08,000 +Basically the same thing as fail close in the world of physical security. + +69 +00:04:08,000 --> 00:04:14,000 +But just remember for now, fail close means when the system fails, it locks up. + +70 +00:04:14,000 --> 00:04:16,000 +Nothing comes in, nothing comes out. + +71 +00:04:17,000 --> 00:04:24,000 +Now the choice between fail open and fail close is really going to be based on the system, the designer, + +72 +00:04:24,000 --> 00:04:26,000 +and where the system is placed. + +73 +00:04:26,000 --> 00:04:33,000 +Sometimes regulation dictates that the system has to fail open in case it fails, uh, especially if + +74 +00:04:33,000 --> 00:04:35,000 +it deals with human life. + +75 +00:04:36,000 --> 00:04:36,000 +Okay. + +76 +00:04:36,000 --> 00:04:38,000 +Make sure you understand these terms for your exam. + +77 +00:04:38,000 --> 00:04:45,000 +They're very popular terms to know for your exam because remember, fail open and fail close is mission + +78 +00:04:45,000 --> 00:04:45,000 +critical. + +79 +00:04:45,000 --> 00:04:50,000 +Not only can it stop your network from being attacked, but it can also save your life. + diff --git a/11 - Security Principles/006 Device Attributes OB 3.2_en.srt b/11 - Security Principles/006 Device Attributes OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..9355e006fd20b6673d0e149bdf9911d8b8223157 --- /dev/null +++ b/11 - Security Principles/006 Device Attributes OB 3.2_en.srt @@ -0,0 +1,280 @@ +1 +00:00:00,000 --> 00:00:01,000 +On a network. + +2 +00:00:01,000 --> 00:00:04,000 +Devices can play multiple roles. + +3 +00:00:04,000 --> 00:00:07,000 +Sometimes they're in the role of just capturing traffic. + +4 +00:00:07,000 --> 00:00:09,000 +Sometimes they're in a role of manipulating traffic. + +5 +00:00:09,000 --> 00:00:12,000 +Sometimes they're in the role of doing both. + +6 +00:00:12,000 --> 00:00:18,000 +What I'm talking about here is device attributes, and this refers to the properties and operational + +7 +00:00:18,000 --> 00:00:21,000 +behavior of those devices on your network. + +8 +00:00:21,000 --> 00:00:27,000 +And particularly I'm really talking about like security devices like this Cisco firewall or my famous + +9 +00:00:27,000 --> 00:00:28,000 +Sonicwall. + +10 +00:00:28,000 --> 00:00:33,000 +Now these attributes are going to determine how these devices interact with the network traffic, its + +11 +00:00:33,000 --> 00:00:36,000 +role and its role in the network security. + +12 +00:00:36,000 --> 00:00:41,000 +Now, I'm not going to get into the specifics of firewalls and IDs, but I will be mentioning them in + +13 +00:00:41,000 --> 00:00:48,000 +this video because coming up in the in a couple of videos from now, we'll talk more about IDs and firewalls + +14 +00:00:48,000 --> 00:00:48,000 +like this. + +15 +00:00:48,000 --> 00:00:50,000 +So we'll need to know those terms. + +16 +00:00:50,000 --> 00:00:52,000 +As I mentioned them right now. + +17 +00:00:52,000 --> 00:00:58,000 +Now a couple of terms we want to know is what's called active devices versus passive devices. + +18 +00:00:58,000 --> 00:01:05,000 +So an active device is a device that actively modify or influence network traffic. + +19 +00:01:05,000 --> 00:01:09,000 +They make real time decisions such as block redirect or modify traffic. + +20 +00:01:09,000 --> 00:01:10,000 +What does that sound like to you? + +21 +00:01:10,000 --> 00:01:12,000 +A device that can block traffic. + +22 +00:01:12,000 --> 00:01:15,000 +A device that can modify traffic, redirect traffic? + +23 +00:01:15,000 --> 00:01:17,000 +Yeah, that sounds like a firewall. + +24 +00:01:17,000 --> 00:01:24,000 +If you know that firewall are devices that can determine you're not going here or you're going here. + +25 +00:01:24,000 --> 00:01:27,000 +Now, a passive device doesn't do anything with the traffic. + +26 +00:01:27,000 --> 00:01:30,000 +It just sits back and it watches the traffic flow. + +27 +00:01:30,000 --> 00:01:34,000 +It monitors and analyzes traffic without altering it. + +28 +00:01:34,000 --> 00:01:39,000 +This is more like a network based intrusion detection system. + +29 +00:01:39,000 --> 00:01:40,000 +We'll do this. + +30 +00:01:40,000 --> 00:01:46,000 +They gather and report the data of any suspicious activity once again like a network intrusion detection + +31 +00:01:46,000 --> 00:01:47,000 +system. + +32 +00:01:47,000 --> 00:01:49,000 +Now also. + +33 +00:01:49,000 --> 00:01:53,000 +We have what's called inline versus tap. + +34 +00:01:53,000 --> 00:01:59,000 +So inline are devices that are placed directly in the path of the traffic. + +35 +00:02:00,000 --> 00:02:02,000 +Traffic must pass through the device. + +36 +00:02:02,000 --> 00:02:08,000 +Essentially for proactive security measures where immediate action is needed versus a tap or a monitor + +37 +00:02:08,000 --> 00:02:08,000 +mode. + +38 +00:02:08,000 --> 00:02:14,000 +The device is connected in a way that it's there to absorb traffic passively, uh, without being in + +39 +00:02:14,000 --> 00:02:17,000 +direct traffic path, ideally for ongoing monitoring of threats. + +40 +00:02:17,000 --> 00:02:18,000 +Now, let me give you guys an example. + +41 +00:02:19,000 --> 00:02:23,000 +This is a firewall that you would hook up in your network. + +42 +00:02:23,000 --> 00:02:27,000 +I want to show you the ports so that it's a little hard to see it here. + +43 +00:02:27,000 --> 00:02:29,000 +But you see this one here. + +44 +00:02:29,000 --> 00:02:33,000 +It says Wang, are you going to see this is the Wang port right here. + +45 +00:02:33,000 --> 00:02:34,000 +Okay. + +46 +00:02:34,000 --> 00:02:35,000 +And this is the Lan port. + +47 +00:02:35,000 --> 00:02:39,000 +So you would connect onto this Wang port. + +48 +00:02:39,000 --> 00:02:42,000 +You're going to connect your firewall. + +49 +00:02:42,000 --> 00:02:43,000 +I'm sorry. + +50 +00:02:43,000 --> 00:02:45,000 +Your router, your ISP router. + +51 +00:02:45,000 --> 00:02:50,000 +Like your Verizon router in this port right here, the the LAN port. + +52 +00:02:50,000 --> 00:02:53,000 +But you're going to do is you're going to connect a switch. + +53 +00:02:54,000 --> 00:02:59,000 +Now in that switch, you can then connect all of your different devices. + +54 +00:02:59,000 --> 00:03:04,000 +This particular device, when it's hooked up like this is called inline. + +55 +00:03:04,000 --> 00:03:07,000 +What this is doing, all the traffic comes in one port leaves the other. + +56 +00:03:07,000 --> 00:03:11,000 +So it's it's directly in line with the network traffic. + +57 +00:03:11,000 --> 00:03:14,000 +Traffic cannot do any can't go around it. + +58 +00:03:14,000 --> 00:03:16,000 +It must go in the device. + +59 +00:03:16,000 --> 00:03:17,000 +Now. + +60 +00:03:19,000 --> 00:03:21,000 +The other one is a tap device. + +61 +00:03:21,000 --> 00:03:26,000 +This is just a connect a computer plugged off of a switch and it just absorbs it. + +62 +00:03:26,000 --> 00:03:28,000 +Just watching the network traffic. + +63 +00:03:28,000 --> 00:03:35,000 +Now, these particular terms that I have here, uh, is important because when we get in to learning + +64 +00:03:35,000 --> 00:03:42,000 +about appliances such as IDs and firewalls, for example, coming up, uh, in a few minutes, we have + +65 +00:03:42,000 --> 00:03:44,000 +to understand that some of them are inline. + +66 +00:03:44,000 --> 00:03:46,000 +They're going to modify the firewall. + +67 +00:03:46,000 --> 00:03:49,000 +Some of them are just there to watch an observed traffic. + +68 +00:03:49,000 --> 00:03:51,000 +Some of them are interacting with the traffic. + +69 +00:03:51,000 --> 00:03:52,000 +Some of them are just watching it. + +70 +00:03:52,000 --> 00:03:56,000 +So keep that in mind as we learn more about network security. + diff --git a/11 - Security Principles/007 Network Appliances and Sensors OB 3.2_en.srt b/11 - Security Principles/007 Network Appliances and Sensors OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..94a5f37c2c5686762f1ba268c8b7f28b400fd90c --- /dev/null +++ b/11 - Security Principles/007 Network Appliances and Sensors OB 3.2_en.srt @@ -0,0 +1,116 @@ +1 +00:00:00,000 --> 00:00:05,000 +When it comes to setting up an actual network, you're going to be dealing with a lot of different appliances + +2 +00:00:05,000 --> 00:00:06,000 +that are out there. + +3 +00:00:06,000 --> 00:00:12,000 +Appliances such as a load balancer, an intrusion detection system, even proxy servers, and so on. + +4 +00:00:12,000 --> 00:00:17,000 +Now, what exactly do these network appliances accomplish? + +5 +00:00:17,000 --> 00:00:22,000 +Well, they're generally going to be some kind of specialized device designed to do a specific network + +6 +00:00:22,000 --> 00:00:23,000 +function. + +7 +00:00:23,000 --> 00:00:29,000 +Some things, like an intrusion detection system or an IDs, would be designed to capture network traffic + +8 +00:00:29,000 --> 00:00:31,000 +and analyze that traffic further. + +9 +00:00:31,000 --> 00:00:36,000 +They're typically optimized for tasks such as cedar routing, switch and security, load balancing, + +10 +00:00:36,000 --> 00:00:37,000 +and storages. + +11 +00:00:37,000 --> 00:00:43,000 +Now, I do have some of these different appliances that I want to talk about that's specific to your + +12 +00:00:43,000 --> 00:00:43,000 +exam. + +13 +00:00:43,000 --> 00:00:48,000 +Now we're going to be covering these coming up a little bit later such as jump servers, proxy servers + +14 +00:00:48,000 --> 00:00:51,000 +IDs and load balancers coming up a little bit later. + +15 +00:00:51,000 --> 00:00:56,000 +But a lot of these different devices are going to have things like sensors. + +16 +00:00:56,000 --> 00:00:58,000 +Now what exactly is a sensor? + +17 +00:00:58,000 --> 00:01:04,000 +Well, it's a device or software components that collect and analyze data from a network, from a network + +18 +00:01:04,000 --> 00:01:07,000 +system to identify potential security threats. + +19 +00:01:07,000 --> 00:01:11,000 +A lot of these devices are going to have different kinds of sensors that is able to detect the different + +20 +00:01:11,000 --> 00:01:17,000 +kinds of traffic on a network, depending on the traffic and depending on what the device does, it + +21 +00:01:17,000 --> 00:01:20,000 +may stop the traffic, manipulate the traffic. + +22 +00:01:20,000 --> 00:01:24,000 +It may even send you alerts that there's something wrong with the traffic, or just do nothing because + +23 +00:01:24,000 --> 00:01:27,000 +it detects that it's just normal traffic. + +24 +00:01:27,000 --> 00:01:28,000 +So something there to think about. + +25 +00:01:28,000 --> 00:01:33,000 +Now when it comes to your actual questions, just understand that it's these sensors that's going to + +26 +00:01:33,000 --> 00:01:36,000 +able to grab the traffic on the network. + +27 +00:01:37,000 --> 00:01:43,000 +It's going to able to detect and prevent security breaches, uh, by reporting it to things such as + +28 +00:01:43,000 --> 00:01:47,000 +Ids's and Ips's on our particular network. + +29 +00:01:47,000 --> 00:01:52,000 +So let's go in and take a look at all the different network devices that we need to know for our exam. + diff --git a/11 - Security Principles/008 Jump Server OB 3.2_en.srt b/11 - Security Principles/008 Jump Server OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..ffa65b8aad62351ddfdcd07c6701c9743bd0dc48 --- /dev/null +++ b/11 - Security Principles/008 Jump Server OB 3.2_en.srt @@ -0,0 +1,156 @@ +1 +00:00:00,000 --> 00:00:05,000 +When you're working on a large network with multiple segments within the network, sometimes there's + +2 +00:00:05,000 --> 00:00:11,000 +different kinds of administrative tasks that you have to get done within those particular systems. + +3 +00:00:11,000 --> 00:00:17,000 +One thing that is incredibly useful, that you should be setting up when you have like, multiple segments + +4 +00:00:17,000 --> 00:00:20,000 +on a network, is generally going to be what's called a jump server. + +5 +00:00:20,000 --> 00:00:27,000 +Jump servers are really important because it helps to have a centralized box that you can use in order + +6 +00:00:27,000 --> 00:00:30,000 +to get to different segments and administer different segments. + +7 +00:00:30,000 --> 00:00:37,000 +So it's basically a gateway between two networks, often used by administrators and IT professionals + +8 +00:00:37,000 --> 00:00:39,000 +to manage and access device in separate zones. + +9 +00:00:39,000 --> 00:00:41,000 +So look at his diagram that I have here. + +10 +00:00:41,000 --> 00:00:48,000 +So if you can access the jump server by just gaining access to this device, you can then access servers + +11 +00:00:48,000 --> 00:00:49,000 +in this security zone. + +12 +00:00:49,000 --> 00:00:51,000 +This could be like something like in finance. + +13 +00:00:51,000 --> 00:00:54,000 +And then this one here can be something like an accountant. + +14 +00:00:54,000 --> 00:01:01,000 +So by accessing the jump server you then gain access to it, the jump server, its main point is going + +15 +00:01:01,000 --> 00:01:06,000 +to be that central point to which administrators can connect before launching and administering other + +16 +00:01:06,000 --> 00:01:07,000 +remote servers here. + +17 +00:01:07,000 --> 00:01:10,000 +So from here, let's say you get access to this. + +18 +00:01:10,000 --> 00:01:12,000 +Let's say you get a type of remote desktop from there. + +19 +00:01:12,000 --> 00:01:16,000 +Then you can remote desktop all the servers in this segment and or this segment. + +20 +00:01:17,000 --> 00:01:19,000 +The question is why do you do this? + +21 +00:01:19,000 --> 00:01:22,000 +Well imagine you didn't have this jump server. + +22 +00:01:22,000 --> 00:01:23,000 +Then what are you going to do? + +23 +00:01:23,000 --> 00:01:23,000 +Then? + +24 +00:01:23,000 --> 00:01:28,000 +You actually have to get a direct connection into this network, get a direct connection into this network. + +25 +00:01:28,000 --> 00:01:30,000 +That would just take. + +26 +00:01:31,000 --> 00:01:34,000 +A lot of different connections and too much points of entry. + +27 +00:01:34,000 --> 00:01:39,000 +Your attack surface would grow because you would have points, and you would have a point of entry here. + +28 +00:01:39,000 --> 00:01:42,000 +And another point of entry here versus here. + +29 +00:01:42,000 --> 00:01:45,000 +You just have one point entry just to that particular machine. + +30 +00:01:45,000 --> 00:01:47,000 +So hopefully that makes sense, right. + +31 +00:01:47,000 --> 00:01:50,000 +Because if not you would have a branch from the firewall coming out here. + +32 +00:01:50,000 --> 00:01:53,000 +And let me just draw it here and make it easy. + +33 +00:01:53,000 --> 00:01:57,000 +You would have a far you would have a branch coming off of the firewall into this server, and a branch + +34 +00:01:57,000 --> 00:02:02,000 +coming off of its two extra connections you don't need versus now you just need one connection one. + +35 +00:02:02,000 --> 00:02:06,000 +And it could be a secure remote connection here and then branch it off from there. + +36 +00:02:06,000 --> 00:02:15,000 +This really helps to enhance your security function by limiting, uh, administrative tasks to a certain + +37 +00:02:15,000 --> 00:02:17,000 +box and of course, limited access. + +38 +00:02:17,000 --> 00:02:22,000 +If you work in a complex network that has many kinds of segments all over the place, the best thing + +39 +00:02:22,000 --> 00:02:26,000 +you can do to limit access and to centralize the administration of them is to get a jump server. + diff --git a/11 - Security Principles/009 Proxy Servers OB 3.2_en.srt b/11 - Security Principles/009 Proxy Servers OB 3.2_en.srt new file mode 100644 index 0000000000000000000000000000000000000000..2d6fca1c0d35318e839c4b01e1b27c6ecdfb6907 --- /dev/null +++ b/11 - Security Principles/009 Proxy Servers OB 3.2_en.srt @@ -0,0 +1,332 @@ +1 +00:00:00,000 --> 00:00:05,000 +If you have ever been to a university or you worked in a large corporate network and you try to go to + +2 +00:00:05,000 --> 00:00:09,000 +like a specific website that maybe the organization doesn't want you to go to. + +3 +00:00:09,000 --> 00:00:14,000 +So maybe you were sitting at work and you wanted to go to Facebook and you type facebook.com and boom, + +4 +00:00:14,000 --> 00:00:19,000 +it redirected you to another site, or it puts you to a page that says, this company policy doesn't + +5 +00:00:19,000 --> 00:00:20,000 +allow this site. + +6 +00:00:20,000 --> 00:00:24,000 +Maybe you were in your university one time and you were in college, and you try to access a site and + +7 +00:00:24,000 --> 00:00:28,000 +it says university campus has blocked us more than likely. + +8 +00:00:28,000 --> 00:00:28,000 +What's doing that? + +9 +00:00:28,000 --> 00:00:30,000 +What's filtering that? + +10 +00:00:30,000 --> 00:00:33,000 +Web traffic is a kind of a proxy server. + +11 +00:00:33,000 --> 00:00:39,000 +So proxy servers are incredibly popular, especially in corporate America. + +12 +00:00:39,000 --> 00:00:45,000 +And the reason for that is because my mother once told me, the more choices, the more mistakes. + +13 +00:00:45,000 --> 00:00:51,000 +Proxy servers allows us to filter out content coming into our organization and given users access to. + +14 +00:00:51,000 --> 00:00:52,000 +So that's what makes it great. + +15 +00:00:52,000 --> 00:00:58,000 +What a proxy server does is that before you can get to the internet, that proxy sits between you and + +16 +00:00:58,000 --> 00:01:00,000 +that internet connection. + +17 +00:01:00,000 --> 00:01:02,000 +Now this is the general type of proxy. + +18 +00:01:02,000 --> 00:01:06,000 +And generally when people say proxy, this is the one that corporate America is going to implement. + +19 +00:01:07,000 --> 00:01:08,000 +What is a proxy doing. + +20 +00:01:08,000 --> 00:01:11,000 +Well, it's that it's that intermediate. + +21 +00:01:12,000 --> 00:01:18,000 +Uh, place in between you and the internet, between a user's computer and the internet. + +22 +00:01:18,000 --> 00:01:23,000 +It requests resources such as web page files or services on behalf of a user. + +23 +00:01:23,000 --> 00:01:27,000 +So let's say you want Facebook, so you type facebook.com. + +24 +00:01:27,000 --> 00:01:28,000 +The request goes to the proxy. + +25 +00:01:28,000 --> 00:01:30,000 +What does the proxy do. + +26 +00:01:30,000 --> 00:01:34,000 +So let's say you send a request that you want facebook.com to the proxy. + +27 +00:01:34,000 --> 00:01:36,000 +The proxy then analyzes the request. + +28 +00:01:36,000 --> 00:01:40,000 +And the proxy can even say, hmm, I don't think this guy should get that. + +29 +00:01:40,000 --> 00:01:41,000 +And it checks. + +30 +00:01:41,000 --> 00:01:42,000 +Sometimes it has permissions. + +31 +00:01:42,000 --> 00:01:44,000 +Should I allow him or should I not? + +32 +00:01:44,000 --> 00:01:47,000 +If it does allow you, it'll go to the internet, grab Facebook and come back. + +33 +00:01:47,000 --> 00:01:51,000 +Now if it has policies it says you can't. + +34 +00:01:51,000 --> 00:01:53,000 +It may tell you, it may just give you a blank page. + +35 +00:01:53,000 --> 00:01:55,000 +It may redirect you to another site. + +36 +00:01:55,000 --> 00:01:58,000 +It may even display the company policies. + +37 +00:01:59,000 --> 00:02:00,000 +So what is he doing? + +38 +00:02:00,000 --> 00:02:05,000 +Well, the biggest thing here is that it's content filter, and it's often used to control internet + +39 +00:02:05,000 --> 00:02:08,000 +usage in the organization by blocking websites. + +40 +00:02:08,000 --> 00:02:08,000 +Now. + +41 +00:02:09,000 --> 00:02:15,000 +Another thing that a proxy is going to do is that it's going to anonymize it, mask the user's IP address, + +42 +00:02:15,000 --> 00:02:21,000 +enhancing security in certain parts of the world, certain people utilize these proxies. + +43 +00:02:21,000 --> 00:02:27,000 +So when they go to place different internet's internet sites, no one knows that they were there. + +44 +00:02:27,000 --> 00:02:31,000 +There's a wide variety of open proxies that I'll talk about coming up a little bit later, that you + +45 +00:02:31,000 --> 00:02:34,000 +can use to anonymize yourself when browsing the internet. + +46 +00:02:35,000 --> 00:02:38,000 +Another thing proxies can do is cache the internet traffic. + +47 +00:02:38,000 --> 00:02:40,000 +Let me explain how this one works for you. + +48 +00:02:41,000 --> 00:02:44,000 +So let's say you want to go to Facebook. + +49 +00:02:44,000 --> 00:02:47,000 +So let's say the internet the site is Facebook. + +50 +00:02:47,000 --> 00:02:50,000 +So you tell the proxy, hey, I want to go to Facebook. + +51 +00:02:50,000 --> 00:02:55,000 +The proxy goes out, grabs the Facebook website, comes back in and gives it to you. + +52 +00:02:55,000 --> 00:03:02,000 +But what the proxy does is that it then caches a copy of Facebook on its server on its hard drive. + +53 +00:03:02,000 --> 00:03:08,000 +So then when Bob, another user comes in and says, tells the proxy, can I get Facebook instead of + +54 +00:03:08,000 --> 00:03:11,000 +going out and get it, it just gives Facebook directly to it. + +55 +00:03:11,000 --> 00:03:18,000 +This is called caching proxies, and a lot of times it was combined with content filtering to really + +56 +00:03:18,000 --> 00:03:20,000 +make the internet secure and make it quick. + +57 +00:03:20,000 --> 00:03:22,000 +Now I have to set up. + +58 +00:03:22,000 --> 00:03:26,000 +I'm old and I have set up Microsoft Isa server. + +59 +00:03:26,000 --> 00:03:32,000 +Uh, it's a really old server that we used to use caching proxy modern day proxies that does content + +60 +00:03:32,000 --> 00:03:33,000 +filtering and things like blue coat. + +61 +00:03:33,000 --> 00:03:35,000 +I think that's run by Google now. + +62 +00:03:35,000 --> 00:03:39,000 +Now, when it comes to proxies, there is a few different proxies we're probably going to be familiar + +63 +00:03:39,000 --> 00:03:40,000 +with. + +64 +00:03:40,000 --> 00:03:43,000 +For example, like a forward proxy, this one sits in front of a client. + +65 +00:03:43,000 --> 00:03:45,000 +No direct connection is made. + +66 +00:03:45,000 --> 00:03:50,000 +When we think proxies, we're thinking generally of forward proxy caches, the content. + +67 +00:03:50,000 --> 00:03:52,000 +It can even filter requests. + +68 +00:03:52,000 --> 00:03:55,000 +There is a kind of a proxy we call a reverse proxy. + +69 +00:03:55,000 --> 00:04:01,000 +This one sits in front of a web server and traffic coming into the web server, it can filter out. + +70 +00:04:02,000 --> 00:04:05,000 +Malicious traffic that's going to hit a web server. + +71 +00:04:06,000 --> 00:04:10,000 +So it's commonly used for load balance caching or SSL encryption. + +72 +00:04:10,000 --> 00:04:15,000 +Now, open proxies conceal your IP address from websites that you visit. + +73 +00:04:15,000 --> 00:04:18,000 +I'm not going to, you know, go in and show you guys open proxies. + +74 +00:04:18,000 --> 00:04:24,000 +But if you guys just Google open proxies, there's these different sites that you can go to and you + +75 +00:04:24,000 --> 00:04:29,000 +can use them as a launching pad to go and surf the internet. + +76 +00:04:29,000 --> 00:04:31,000 +And basically you're going through their systems. + +77 +00:04:31,000 --> 00:04:34,000 +So whatever website you go to, they don't know it's you. + +78 +00:04:34,000 --> 00:04:37,000 +They just know it's that proxy that's been there. + +79 +00:04:37,000 --> 00:04:40,000 +So if you look into anonymize yourself, you may want to check one of those out. + +80 +00:04:40,000 --> 00:04:44,000 +But when it comes to IT security, I think proxies are super important. + +81 +00:04:44,000 --> 00:04:49,000 +I used to set these things up a whole lot because like my mother said, more choices, more mistakes, + +82 +00:04:49,000 --> 00:04:51,000 +and it's a good network admin. + +83 +00:04:51,000 --> 00:04:55,000 +We want to remove choices from what people do on our networks to keep our networks safe. +