1
1

00:00:00,330  -->  00:00:02,850
<v Instructor>Defensive capabilities.</v>
2

2

00:00:02,850  -->  00:00:04,410
In this lesson, we are going to talk
3

3

00:00:04,410  -->  00:00:07,230
about the different types of defensive capabilities.
4

4

00:00:07,230  -->  00:00:10,350
Now, every organization has different defensive capabilities
5

5

00:00:10,350  -->  00:00:11,520
so you have to ask yourself,
6

6

00:00:11,520  -->  00:00:15,090
what defensive capabilities does your organization have?
7

7

00:00:15,090  -->  00:00:17,250
Now, when we talk about defensive capabilities,
8

8

00:00:17,250  -->  00:00:18,240
these are outlined
9

9

00:00:18,240  -->  00:00:20,940
inside the intelligence-driven computer network defense
10

10

00:00:20,940  -->  00:00:23,400
informed by analysis and adversary campaigns
11

11

00:00:23,400  -->  00:00:25,080
and intrusion kill chains.
12

12

00:00:25,080  -->  00:00:27,900
This is a document that came from Lockheed Martin.
13

13

00:00:27,900  -->  00:00:29,430
And it is a very popular one to use
14

14

00:00:29,430  -->  00:00:31,560
inside the cybersecurity world.
15

15

00:00:31,560  -->  00:00:34,140
This document is only about 14 pages long,
16

16

00:00:34,140  -->  00:00:36,060
so if you want to read it, you can Google
17

17

00:00:36,060  -->  00:00:38,250
intelligence-driven computer network defense,
18

18

00:00:38,250  -->  00:00:39,300
Lockheed Martin,
19

19

00:00:39,300  -->  00:00:42,030
and it will come up immediately in your browser.
20

20

00:00:42,030  -->  00:00:44,040
Now, I would recommend going through and reading this
21

21

00:00:44,040  -->  00:00:46,950
not necessarily for the exam, but just for the fact
22

22

00:00:46,950  -->  00:00:49,650
that it's going to be helpful to you in the real world.
23

23

00:00:49,650  -->  00:00:50,760
We're going to cover what you need to know
24

24

00:00:50,760  -->  00:00:53,070
for the exam in this lesson though.
25

25

00:00:53,070  -->  00:00:54,870
Now, when we talk about these different things
26

26

00:00:54,870  -->  00:00:56,670
that we can do as defensive capabilities,
27

27

00:00:56,670  -->  00:00:58,170
there are a handful of them.
28

28

00:00:58,170  -->  00:00:59,130
We have things like:
29

29

00:00:59,130  -->  00:01:04,130
detect, destroy, degrade, disrupt, deny, and deceive.
30

30

00:01:04,320  -->  00:01:06,150
Let's talk about what each of those mean.
31

31

00:01:06,150  -->  00:01:07,920
First, we have detect,
32

32

00:01:07,920  -->  00:01:09,510
and this is going to identify the presence
33

33

00:01:09,510  -->  00:01:13,050
of an adversary or the resources at their disposal.
34

34

00:01:13,050  -->  00:01:14,640
Essentially, when you go through your SIEM
35

35

00:01:14,640  -->  00:01:15,930
and you look at the alerts
36

36

00:01:15,930  -->  00:01:18,750
that's your ability to detect an adversary in your network.
37

37

00:01:18,750  -->  00:01:20,490
That is a defensive capability,
38

38

00:01:20,490  -->  00:01:22,860
and usually the first one you're going to use.
39

39

00:01:22,860  -->  00:01:24,780
Then we have destroy.
40

40

00:01:24,780  -->  00:01:27,270
Now, destroy is going to render an adversary's resources
41

41

00:01:27,270  -->  00:01:29,610
permanently useless or ineffective.
42

42

00:01:29,610  -->  00:01:31,710
For most of us in a commercial organization,
43

43

00:01:31,710  -->  00:01:33,780
we are not going to be using destroy,
44

44

00:01:33,780  -->  00:01:35,520
but if you happen to work for the government
45

45

00:01:35,520  -->  00:01:36,960
or you work for the military,
46

46

00:01:36,960  -->  00:01:38,790
they have the ability to destroy,
47

47

00:01:38,790  -->  00:01:40,770
which essentially would be a hack-back,
48

48

00:01:40,770  -->  00:01:41,880
and they'd be able to take down
49

49

00:01:41,880  -->  00:01:44,790
somebody else's system who is attacking them.
50

50

00:01:44,790  -->  00:01:46,770
Next, we have degrade.
51

51

00:01:46,770  -->  00:01:47,790
Degrade is going to reduce
52

52

00:01:47,790  -->  00:01:50,190
an adversary's capabilities or functionality,
53

53

00:01:50,190  -->  00:01:51,720
perhaps temporarily.
54

54

00:01:51,720  -->  00:01:53,820
For example, maybe you've identified
55

55

00:01:53,820  -->  00:01:56,220
that a particular adversary is attacking you
56

56

00:01:56,220  -->  00:01:59,640
from a virtual private network with a certain IP range.
57

57

00:01:59,640  -->  00:02:00,870
You could block that range,
58

58

00:02:00,870  -->  00:02:02,700
and that would degrade their ability,
59

59

00:02:02,700  -->  00:02:04,860
but it's only going to do that temporarily
60

60

00:02:04,860  -->  00:02:07,200
because they're going to be able to go and get new services
61

61

00:02:07,200  -->  00:02:09,753
from another IP range and then re-attack you again.
62

62

00:02:10,770  -->  00:02:13,890
The next defensive capability we have is disruption.
63

63

00:02:13,890  -->  00:02:15,090
When you disrupt something,
64

64

00:02:15,090  -->  00:02:17,520
you're trying to interrupt an adversary's communications
65

65

00:02:17,520  -->  00:02:19,950
or frustrate or confuse their efforts.
66

66

00:02:19,950  -->  00:02:23,160
Again, you can do this by blocking their IP address.
67

67

00:02:23,160  -->  00:02:25,620
You might add a second factor of authentication
68

68

00:02:25,620  -->  00:02:26,550
or something else.
69

69

00:02:26,550  -->  00:02:29,460
Anything you do that is going to interrupt their ability
70

70

00:02:29,460  -->  00:02:32,130
to communicate or frustrate or confuse their efforts
71

71

00:02:32,130  -->  00:02:34,380
would be considered disruption.
72

72

00:02:34,380  -->  00:02:36,450
After that, we have deny.
73

73

00:02:36,450  -->  00:02:38,640
When we deny, we are preventing an adversary
74

74

00:02:38,640  -->  00:02:40,260
from learning about your capabilities
75

75

00:02:40,260  -->  00:02:42,750
or accessing your information assets.
76

76

00:02:42,750  -->  00:02:44,100
Deny is the best thing.
77

77

00:02:44,100  -->  00:02:46,500
We want to make sure we keep the bad guy out,
78

78

00:02:46,500  -->  00:02:48,480
and that is what deny is all about.
79

79

00:02:48,480  -->  00:02:50,220
In addition to keeping them out of our systems,
80

80

00:02:50,220  -->  00:02:53,010
we also want to keep them from knowing about our systems.
81

81

00:02:53,010  -->  00:02:54,390
And if we can deny their ability
82

82

00:02:54,390  -->  00:02:56,640
to learn what IP ranges we're using,
83

83

00:02:56,640  -->  00:02:58,860
what type of servers or software we're using,
84

84

00:02:58,860  -->  00:03:01,710
that is going to help us in defending our networks.
85

85

00:03:01,710  -->  00:03:03,780
And finally, we have deceive.
86

86

00:03:03,780  -->  00:03:06,150
Deceive is where we're going to supply false information
87

87

00:03:06,150  -->  00:03:09,330
to distort the adversary's understanding and awareness.
88

88

00:03:09,330  -->  00:03:11,130
If you use something like a honeypot
89

89

00:03:11,130  -->  00:03:12,810
or you start sending out false documents
90

90

00:03:12,810  -->  00:03:14,160
for them to steal from you,
91

91

00:03:14,160  -->  00:03:16,080
that would be a deception mechanism
92

92

00:03:16,080  -->  00:03:18,000
under the deceive category.
93

93

00:03:18,000  -->  00:03:19,170
Now, as you go through
94

94

00:03:19,170  -->  00:03:21,120
and you look at the Lockheed Martin white paper,
95

95

00:03:21,120  -->  00:03:22,860
there's a chart that looks like this,
96

96

00:03:22,860  -->  00:03:24,420
and they show you the different phases
97

97

00:03:24,420  -->  00:03:26,670
going down the left side based on the kill chain,
98

98

00:03:26,670  -->  00:03:29,970
such as reconnaissance, weaponization, delivery,
99

99

00:03:29,970  -->  00:03:34,140
exploitation, installation, C2, and action on objectives.
100

100

00:03:34,140  -->  00:03:36,450
And then going across to the right, you'll see:
101

101

00:03:36,450  -->  00:03:41,070
detect, deny, disrupt, degrade, deceive, and destroy,
102

102

00:03:41,070  -->  00:03:42,270
and then you can map out
103

103

00:03:42,270  -->  00:03:45,450
which technologies you have in each of these categories.
104

104

00:03:45,450  -->  00:03:47,730
For example, if I'm using web analytics,
105

105

00:03:47,730  -->  00:03:49,440
that is a detection technology
106

106

00:03:49,440  -->  00:03:52,050
that's going to be focused on the reconnaissance phase.
107

107

00:03:52,050  -->  00:03:54,480
If I have a network intrusion detection system,
108

108

00:03:54,480  -->  00:03:57,690
that might detect things in the weaponization phase.
109

109

00:03:57,690  -->  00:03:59,790
If I'm using something like a vigilant user,
110

110

00:03:59,790  -->  00:04:01,560
that would be something where we're going to detect things
111

111

00:04:01,560  -->  00:04:03,090
in the delivery phase.
112

112

00:04:03,090  -->  00:04:05,010
And you can see how this chart starts filling out
113

113

00:04:05,010  -->  00:04:07,530
based on the different technologies we're going to use.
114

114

00:04:07,530  -->  00:04:10,860
Now, this is particularly set up for your organization,
115

115

00:04:10,860  -->  00:04:12,540
so you can use this as a template,
116

116

00:04:12,540  -->  00:04:15,930
and then modify it based on your own defensive capabilities.
117

117

00:04:15,930  -->  00:04:18,030
Again, notice the destroy column.
118

118

00:04:18,030  -->  00:04:19,800
It is completely empty here.
119

119

00:04:19,800  -->  00:04:22,020
That's because I'm a commercial organization.
120

120

00:04:22,020  -->  00:04:23,550
I don't have the legal authority
121

121

00:04:23,550  -->  00:04:25,530
to hack-back against an adversary,
122

122

00:04:25,530  -->  00:04:27,780
so therefore I cannot destroy them.
123

123

00:04:27,780  -->  00:04:32,580
I can only detect, deny, disrupt, degrade, and deceive them.
124

124

00:04:32,580  -->  00:04:34,170
If you work for the military though,
125

125

00:04:34,170  -->  00:04:36,480
you might have the legal authority to hack-back,
126

126

00:04:36,480  -->  00:04:38,970
and that would allow you to have some destroy options.
127

127

00:04:38,970  -->  00:04:40,590
But for me, I don't have those,
128

128

00:04:40,590  -->  00:04:42,590
and that's why my chart looks like this.
