1
1

00:00:00,360  -->  00:00:01,800
<v Instructor>Containment.</v>
2

2

00:00:01,800  -->  00:00:02,760
In this lesson,
3

3

00:00:02,760  -->  00:00:04,440
we are going to talk about containment,
4

4

00:00:04,440  -->  00:00:07,710
which is our next step in the incident response phases.
5

5

00:00:07,710  -->  00:00:10,110
Now, rapid containment in an incident response
6

6

00:00:10,110  -->  00:00:11,700
is really important,
7

7

00:00:11,700  -->  00:00:14,190
because if we don't contain things quickly,
8

8

00:00:14,190  -->  00:00:15,900
the adversary can get into our network
9

9

00:00:15,900  -->  00:00:17,070
and start pivoting around
10

10

00:00:17,070  -->  00:00:19,200
and laterally spreading across the network
11

11

00:00:19,200  -->  00:00:20,850
and cause more damage.
12

12

00:00:20,850  -->  00:00:22,350
When we talk about containment,
13

13

00:00:22,350  -->  00:00:24,960
our job here is to limit the scope and magnitude
14

14

00:00:24,960  -->  00:00:25,980
of the incident
15

15

00:00:25,980  -->  00:00:28,140
by securing data and limiting the impact
16

16

00:00:28,140  -->  00:00:30,570
to the business operations and our customers.
17

17

00:00:30,570  -->  00:00:33,810
Now, there are five key steps for conducting containment.
18

18

00:00:33,810  -->  00:00:36,180
First, we want to ensure the safety and security
19

19

00:00:36,180  -->  00:00:37,920
of all of our personnel.
20

20

00:00:37,920  -->  00:00:40,230
This is always going to be the first concern
21

21

00:00:40,230  -->  00:00:42,120
for management and executives
22

22

00:00:42,120  -->  00:00:43,800
because we can't replace people
23

23

00:00:43,800  -->  00:00:46,560
but we can replace data and technology.
24

24

00:00:46,560  -->  00:00:49,020
Second, we want to prevent an ongoing intrusion
25

25

00:00:49,020  -->  00:00:50,370
or data breach.
26

26

00:00:50,370  -->  00:00:51,900
Now that we know our people are safe,
27

27

00:00:51,900  -->  00:00:53,670
we want to protect our information
28

28

00:00:53,670  -->  00:00:56,310
and we want to stop any ongoing intrusions
29

29

00:00:56,310  -->  00:00:59,040
to prevent them from further exfiltrating data.
30

30

00:00:59,040  -->  00:01:01,320
The third thing we want to do is identify
31

31

00:01:01,320  -->  00:01:04,860
if the intrusion is the primary or secondary attack.
32

32

00:01:04,860  -->  00:01:06,690
Sometimes as you detect something,
33

33

00:01:06,690  -->  00:01:08,640
you think you found the main cause,
34

34

00:01:08,640  -->  00:01:09,750
but you didn't.
35

35

00:01:09,750  -->  00:01:11,340
You found the secondary attack,
36

36

00:01:11,340  -->  00:01:12,173
and then you have to go back
37

37

00:01:12,173  -->  00:01:13,920
and find out how they initially get in
38

38

00:01:13,920  -->  00:01:15,900
and what other things are they doing.
39

39

00:01:15,900  -->  00:01:17,190
For example, if you see
40

40

00:01:17,190  -->  00:01:18,690
that they've gotten into your network
41

41

00:01:18,690  -->  00:01:21,000
and they're exfiltrating unimportant data,
42

42

00:01:21,000  -->  00:01:22,860
is that really the attack they were going for?
43

43

00:01:22,860  -->  00:01:24,480
Or were they using that
44

44

00:01:24,480  -->  00:01:26,160
as a way to hide their true intentions
45

45

00:01:26,160  -->  00:01:29,310
of going after some important data store instead?
46

46

00:01:29,310  -->  00:01:31,710
Fourth, we want to avoid alerting the attacker
47

47

00:01:31,710  -->  00:01:33,690
that the attack has been discovered.
48

48

00:01:33,690  -->  00:01:34,650
Now, this is important
49

49

00:01:34,650  -->  00:01:36,960
because some attackers, when they're discovered,
50

50

00:01:36,960  -->  00:01:38,970
will actually destroy your systems.
51

51

00:01:38,970  -->  00:01:39,803
There is one APT
52

52

00:01:39,803  -->  00:01:43,380
that is known for doing what we call burning down the house.
53

53

00:01:43,380  -->  00:01:45,330
If they're discovered, they will actually go
54

54

00:01:45,330  -->  00:01:47,070
and start formatting all your systems
55

55

00:01:47,070  -->  00:01:49,260
and destroying everything.
56

56

00:01:49,260  -->  00:01:50,730
This is burning down the house,
57

57

00:01:50,730  -->  00:01:52,860
and we don't want them to do that to our systems.
58

58

00:01:52,860  -->  00:01:54,480
So we don't want to tip our hand
59

59

00:01:54,480  -->  00:01:56,640
and let the adversary know that we've detected them.
60

60

00:01:56,640  -->  00:01:58,920
Instead, we want to make sure we've cut off their ability
61

61

00:01:58,920  -->  00:02:00,150
to do any harm to us
62

62

00:02:00,150  -->  00:02:02,790
before they figure out that we know they're there.
63

63

00:02:02,790  -->  00:02:05,550
And then fifth, we want to preserve any forensic evidence
64

64

00:02:05,550  -->  00:02:07,170
of the intrusion and attack
65

65

00:02:07,170  -->  00:02:09,420
because that evidence could be useful
66

66

00:02:09,420  -->  00:02:11,880
for law enforcement and for other things.
67

67

00:02:11,880  -->  00:02:15,180
Now notice, these five steps are in priority order.
68

68

00:02:15,180  -->  00:02:16,920
We want to make sure we are safe.
69

69

00:02:16,920  -->  00:02:18,270
We stop the ongoing breach,
70

70

00:02:18,270  -->  00:02:20,670
we identify the primary or secondary attack
71

71

00:02:20,670  -->  00:02:22,530
and then we want to avoid alerting the attacker,
72

72

00:02:22,530  -->  00:02:25,920
and finally, preserving evidence is our last thing.
73

73

00:02:25,920  -->  00:02:27,060
Now, as we go forward
74

74

00:02:27,060  -->  00:02:28,710
and we start thinking about containment,
75

75

00:02:28,710  -->  00:02:31,200
there's really two categories of containment we can do.
76

76

00:02:31,200  -->  00:02:33,960
There is isolation and segmentation.
77

77

00:02:33,960  -->  00:02:35,940
Now, when we talk about isolation,
78

78

00:02:35,940  -->  00:02:37,620
this is a mitigation strategy
79

79

00:02:37,620  -->  00:02:39,600
that involves removing an effective component
80

80

00:02:39,600  -->  00:02:42,270
from whatever larger environment it's a part of.
81

81

00:02:42,270  -->  00:02:44,940
So if I have a server and I think it's been compromised,
82

82

00:02:44,940  -->  00:02:47,280
I can physically take it out of the environment
83

83

00:02:47,280  -->  00:02:48,450
and cut it off.
84

84

00:02:48,450  -->  00:02:50,340
That way, the attacker can't access it
85

85

00:02:50,340  -->  00:02:52,650
but neither can my employees.
86

86

00:02:52,650  -->  00:02:53,820
Now, when you're doing this,
87

87

00:02:53,820  -->  00:02:56,340
you need to ensure that there is no longer an interface
88

88

00:02:56,340  -->  00:02:57,780
between the affected component
89

89

00:02:57,780  -->  00:03:00,120
and your production network or the internet.
90

90

00:03:00,120  -->  00:03:01,680
One of the most common ways of doing this
91

91

00:03:01,680  -->  00:03:03,450
is by creating an air gap.
92

92

00:03:03,450  -->  00:03:05,520
You can do this by turning off a switch port
93

93

00:03:05,520  -->  00:03:08,460
or unplugging the cable directly from the switch port
94

94

00:03:08,460  -->  00:03:09,810
because this will make sure
95

95

00:03:09,810  -->  00:03:12,270
that nobody can talk to that device anymore.
96

96

00:03:12,270  -->  00:03:15,450
Now, creating an air gap is the least stealthy option though
97

97

00:03:15,450  -->  00:03:17,070
and it will reduce your opportunities
98

98

00:03:17,070  -->  00:03:19,290
to analyze the attack or the malware
99

99

00:03:19,290  -->  00:03:20,790
because you are essentially cutting off
100

100

00:03:20,790  -->  00:03:22,740
the connection completely.
101

101

00:03:22,740  -->  00:03:24,810
So should you use isolation?
102

102

00:03:24,810  -->  00:03:26,850
Well, if you have a high enough priority
103

103

00:03:26,850  -->  00:03:28,350
that can really do some damage,
104

104

00:03:28,350  -->  00:03:30,480
you may want to isolate immediately
105

105

00:03:30,480  -->  00:03:32,610
to prevent that damage from spreading.
106

106

00:03:32,610  -->  00:03:34,170
Now, another way to do isolation
107

107

00:03:34,170  -->  00:03:36,210
besides unplugging the network cable
108

108

00:03:36,210  -->  00:03:38,100
is you can actually take away the permissions
109

109

00:03:38,100  -->  00:03:40,170
from an account or a service.
110

110

00:03:40,170  -->  00:03:41,003
For example,
111

111

00:03:41,003  -->  00:03:43,230
if somebody has compromised your administrator account,
112

112

00:03:43,230  -->  00:03:45,540
you can go in and disable that account.
113

113

00:03:45,540  -->  00:03:48,360
That, again, is an isolation mechanism.
114

114

00:03:48,360  -->  00:03:50,010
Now, the other way we can do things
115

115

00:03:50,010  -->  00:03:51,900
is we can use segmentation.
116

116

00:03:51,900  -->  00:03:54,300
Now, segmentation is a mitigation strategy
117

117

00:03:54,300  -->  00:03:57,270
that achieves isolation of a host or group of hosts
118

118

00:03:57,270  -->  00:03:59,940
using network technologies and architecture.
119

119

00:03:59,940  -->  00:04:03,270
Segmentation is going to use VLANs, routing and subnets,
120

120

00:04:03,270  -->  00:04:04,800
and firewall ACLs
121

121

00:04:04,800  -->  00:04:08,130
to prevent communications outside the protected segment.
122

122

00:04:08,130  -->  00:04:11,310
Now, this is also sometimes termed as sandboxing.
123

123

00:04:11,310  -->  00:04:13,590
Sandboxing is a security mechanism
124

124

00:04:13,590  -->  00:04:14,820
for separating a system
125

125

00:04:14,820  -->  00:04:17,640
from other critical system resources and programs.
126

126

00:04:17,640  -->  00:04:19,440
This often can be used to test malware
127

127

00:04:19,440  -->  00:04:21,030
or other harmful applications
128

128

00:04:21,030  -->  00:04:23,790
without subjecting the rest of the network to the attack.
129

129

00:04:23,790  -->  00:04:26,430
Again, this is a form of segmentation.
130

130

00:04:26,430  -->  00:04:28,470
This can be accomplished during an instant response
131

131

00:04:28,470  -->  00:04:31,080
by redirecting all of your attackers activity
132

132

00:04:31,080  -->  00:04:32,340
to a workstation
133

133

00:04:32,340  -->  00:04:34,590
that can then be used to gather evidence and information
134

134

00:04:34,590  -->  00:04:36,570
about the attacker's methods.
135

135

00:04:36,570  -->  00:04:38,010
So when we do this,
136

136

00:04:38,010  -->  00:04:39,270
we actually can have
137

137

00:04:39,270  -->  00:04:41,130
something like a honeypot, for instance,
138

138

00:04:41,130  -->  00:04:42,660
and if we think there is some attacker
139

139

00:04:42,660  -->  00:04:44,580
from the internet trying to access us,
140

140

00:04:44,580  -->  00:04:46,470
we can use things like a proxy
141

141

00:04:46,470  -->  00:04:49,320
to proxy the information either into the LAN honeypot
142

142

00:04:49,320  -->  00:04:50,880
or the DMZ honeypot,
143

143

00:04:50,880  -->  00:04:53,880
and that way, we can research what this person is doing.
144

144

00:04:53,880  -->  00:04:55,800
This type of segmentation is often used
145

145

00:04:55,800  -->  00:04:57,330
by security researchers
146

146

00:04:57,330  -->  00:04:59,670
as they start creating honeypots and honeynets
147

147

00:04:59,670  -->  00:05:01,830
that are designed to be attacked by hackers.
148

148

00:05:01,830  -->  00:05:04,110
This way, they can capture their techniques
149

149

00:05:04,110  -->  00:05:05,820
and create indicators of compromise
150

150

00:05:05,820  -->  00:05:08,100
for us to add to our detection systems.
151

151

00:05:08,100  -->  00:05:10,920
If you plan to use sandboxing as a technique in this way
152

152

00:05:10,920  -->  00:05:12,390
during an instant response,
153

153

00:05:12,390  -->  00:05:15,210
you need to consult your organization's legal counsel though
154

154

00:05:15,210  -->  00:05:17,700
to ensure you're not breaking any laws when doing so
155

155

00:05:17,700  -->  00:05:20,370
because laws do vary from place to place.
156

156

00:05:20,370  -->  00:05:23,010
Some countries consider setting these type of honeypots up
157

157

00:05:23,010  -->  00:05:25,320
in a law enforcement activity as entrapment,
158

158

00:05:25,320  -->  00:05:26,580
and it wouldn't be allowed.
159

159

00:05:26,580  -->  00:05:29,820
So you have to consider that and work with your legal team.
160

160

00:05:29,820  -->  00:05:32,550
Now, when you do this segmentation or sandboxing,
161

161

00:05:32,550  -->  00:05:34,530
you can reroute the adversary traffic
162

162

00:05:34,530  -->  00:05:37,230
as part of a deception defensive capability,
163

163

00:05:37,230  -->  00:05:40,170
something like a honeypot as we were just talking about.
164

164

00:05:40,170  -->  00:05:41,670
Now, again, I want you to consult
165

165

00:05:41,670  -->  00:05:42,990
with your senior leadership
166

166

00:05:42,990  -->  00:05:46,590
whenever you have plans for doing isolation or segmentation
167

167

00:05:46,590  -->  00:05:48,540
as part of your containment strategy.
168

168

00:05:48,540  -->  00:05:51,030
Now, one of these two is what you're going to have to do
169

169

00:05:51,030  -->  00:05:53,010
but which one you're going to do is going to depend
170

170

00:05:53,010  -->  00:05:54,420
on senior leadership.
171

171

00:05:54,420  -->  00:05:56,190
This is because there are a lot of factors
172

172

00:05:56,190  -->  00:05:57,330
that we discussed here,
173

173

00:05:57,330  -->  00:05:59,580
and these are only really scratching the surface.
174

174

00:05:59,580  -->  00:06:01,950
You always want to consider the impact to the business
175

175

00:06:01,950  -->  00:06:03,210
and the risk you're taking
176

176

00:06:03,210  -->  00:06:05,460
by choosing one strategy over another
177

177

00:06:05,460  -->  00:06:07,260
for your overall containment strategy
178

178

00:06:07,260  -->  00:06:09,120
during the incident response.
179

179

00:06:09,120  -->  00:06:12,090
Now, this will have larger business impacts as well
180

180

00:06:12,090  -->  00:06:13,290
and so you always need to make sure
181

181

00:06:13,290  -->  00:06:15,030
you're consulting senior leadership
182

182

00:06:15,030  -->  00:06:16,980
and provide them with your recommendations
183

183

00:06:16,980  -->  00:06:18,870
based on your technical expertise,
184

184

00:06:18,870  -->  00:06:20,250
and then they can make a decision
185

185

00:06:20,250  -->  00:06:22,000
based on their business experience.
