1
1

00:00:00,360  -->  00:00:03,180
<v Instructor>Eradication. In this lesson</v>
2

2

00:00:03,180  -->  00:00:06,780
we're going to move into the eradication and recovery phase.
3

3

00:00:06,780  -->  00:00:08,940
When we talk about eradication recovery
4

4

00:00:08,940  -->  00:00:10,950
this is going to remove the cause of the incident
5

5

00:00:10,950  -->  00:00:13,830
and bring the system back to a secure state.
6

6

00:00:13,830  -->  00:00:15,390
When we start with the first part of this
7

7

00:00:15,390  -->  00:00:17,220
we're dealing with eradication.
8

8

00:00:17,220  -->  00:00:19,740
And eradication is focused on the complete removal
9

9

00:00:19,740  -->  00:00:22,290
and destruction of the cause of the incident.
10

10

00:00:22,290  -->  00:00:25,260
For example, if your server's been infected with malware
11

11

00:00:25,260  -->  00:00:27,090
the eradication is going to be focused
12

12

00:00:27,090  -->  00:00:28,560
on methods to remove it
13

13

00:00:28,560  -->  00:00:31,650
and suppress its ability to do any further damage.
14

14

00:00:31,650  -->  00:00:33,690
Now, the exact method of eradication
15

15

00:00:33,690  -->  00:00:36,090
is going to depend on the source of the infection
16

16

00:00:36,090  -->  00:00:38,490
or what the specific incident was,
17

17

00:00:38,490  -->  00:00:40,830
but for our purposes in our generic planning,
18

18

00:00:40,830  -->  00:00:42,900
it really doesn't matter that much.
19

19

00:00:42,900  -->  00:00:44,850
Now, later on, when you start dealing with
20

20

00:00:44,850  -->  00:00:47,070
a specific situation or an incident that's caused
21

21

00:00:47,070  -->  00:00:50,040
by an attacker, that is when the specifics will matter,
22

22

00:00:50,040  -->  00:00:52,020
and your team will have to develop a plan
23

23

00:00:52,020  -->  00:00:54,300
that will adequately eliminate that threat.
24

24

00:00:54,300  -->  00:00:55,320
It's important to make sure
25

25

00:00:55,320  -->  00:00:57,330
that you fully have identified the threat,
26

26

00:00:57,330  -->  00:01:00,120
and this way you don't miss any signs of the infection
27

27

00:01:00,120  -->  00:01:03,090
and you root it out all the way throughout the system.
28

28

00:01:03,090  -->  00:01:04,140
There is nothing worse
29

29

00:01:04,140  -->  00:01:06,720
than going through all the effort in an instant response
30

30

00:01:06,720  -->  00:01:08,760
and then finding out that you had three systems
31

31

00:01:08,760  -->  00:01:10,620
that were infected not just one
32

32

00:01:10,620  -->  00:01:12,480
with that particular piece of malware.
33

33

00:01:12,480  -->  00:01:14,820
And now you have to start all over again
34

34

00:01:14,820  -->  00:01:16,620
because it's moving throughout your network
35

35

00:01:16,620  -->  00:01:19,620
and the systems are continually getting infected.
36

36

00:01:19,620  -->  00:01:23,070
So, the simplest option when you try to eradicate a system
37

37

00:01:23,070  -->  00:01:26,430
is to replace it with a clean image from a trusted source.
38

38

00:01:26,430  -->  00:01:28,890
If I know this server has an infection on it
39

39

00:01:28,890  -->  00:01:30,420
and I can just format it
40

40

00:01:30,420  -->  00:01:33,180
and then reinstall a brand new operating system on it
41

41

00:01:33,180  -->  00:01:34,590
from a known good image,
42

42

00:01:34,590  -->  00:01:37,320
that is going to be the simplest way to eradicate it.
43

43

00:01:37,320  -->  00:01:39,690
But, that's not always possible.
44

44

00:01:39,690  -->  00:01:42,600
A lot of times you can't just format the hard drive,
45

45

00:01:42,600  -->  00:01:45,660
because some malware can actually hide itself
46

46

00:01:45,660  -->  00:01:48,570
and bypass itself through a format stage.
47

47

00:01:48,570  -->  00:01:51,420
Instead, we don't want to rely on just a quick format.
48

48

00:01:51,420  -->  00:01:54,240
We want to make sure we are doing proper sanitization
49

49

00:01:54,240  -->  00:01:55,830
and secure disposal.
50

50

00:01:55,830  -->  00:01:57,870
Now, when I talk about sanitization,
51

51

00:01:57,870  -->  00:02:00,630
this is a group of procedures that organization uses
52

52

00:02:00,630  -->  00:02:03,000
to govern the disposal of obsolete information
53

53

00:02:03,000  -->  00:02:05,520
and equipment, including storage devices,
54

54

00:02:05,520  -->  00:02:07,710
devices with internal data storage capabilities
55

55

00:02:07,710  -->  00:02:09,630
or paper records.
56

56

00:02:09,630  -->  00:02:11,190
When you're dealing with standardization,
57

57

00:02:11,190  -->  00:02:14,370
there are lots of different ways of destroying this data,
58

58

00:02:14,370  -->  00:02:15,390
and as I said,
59

59

00:02:15,390  -->  00:02:18,210
it's not just as easy as doing a quick format.
60

60

00:02:18,210  -->  00:02:21,690
Instead, you have to use one of the more secure methods.
61

61

00:02:21,690  -->  00:02:23,700
If you're using a solid state device
62

62

00:02:23,700  -->  00:02:26,670
you might have the ability to do a cryptographic erase.
63

63

00:02:26,670  -->  00:02:28,950
This is also abbreviated as CE.
64

64

00:02:28,950  -->  00:02:30,330
Now, a cryptographic erase
65

65

00:02:30,330  -->  00:02:33,090
is a method of sanitizing a self encrypting drive
66

66

00:02:33,090  -->  00:02:35,340
by erasing the media encryption key.
67

67

00:02:35,340  -->  00:02:36,480
Now, most of the time
68

68

00:02:36,480  -->  00:02:39,240
when you're dealing with cryptographic erase, or CE,
69

69

00:02:39,240  -->  00:02:42,030
this is going to be a feature of self encrypting drives,
70

70

00:02:42,030  -->  00:02:43,530
and these self encrypting drives
71

71

00:02:43,530  -->  00:02:45,720
tend to be solid state drives.
72

72

00:02:45,720  -->  00:02:47,070
Now, if you're going to be dealing with
73

73

00:02:47,070  -->  00:02:48,810
a regular type of hard drive,
74

74

00:02:48,810  -->  00:02:51,930
you might have to do what's known as a zero-fill.
75

75

00:02:51,930  -->  00:02:54,780
A zero-fill is a method of sanitizing a drive
76

76

00:02:54,780  -->  00:02:58,830
by overriding every single bit on that drive with zeros.
77

77

00:02:58,830  -->  00:03:01,170
To do this inside of a window system
78

78

00:03:01,170  -->  00:03:03,570
you can do a zero-fill using the command prompt
79

79

00:03:03,570  -->  00:03:05,190
and the format command.
80

80

00:03:05,190  -->  00:03:07,230
You'll type in something like format,
81

81

00:03:07,230  -->  00:03:11,610
the drive letter you want to format/fs:NTFS
82

82

00:03:11,610  -->  00:03:14,040
to say that you want an NTFS file system
83

83

00:03:14,040  -->  00:03:19,040
and then /p:1, which tells it how many passes you want to do
84

84

00:03:19,260  -->  00:03:21,570
with the number of zeros over that drive.
85

85

00:03:21,570  -->  00:03:24,300
In this example, I'm doing one set of zeros
86

86

00:03:24,300  -->  00:03:26,580
across every bit on that drive.
87

87

00:03:26,580  -->  00:03:28,530
If I want to do something a little bit more secure
88

88

00:03:28,530  -->  00:03:32,160
I might do three sets of zeros, or seven sets of zeros.
89

89

00:03:32,160  -->  00:03:34,920
This way I can overrate the drive multiple times
90

90

00:03:34,920  -->  00:03:37,350
to make sure I got all that information off.
91

91

00:03:37,350  -->  00:03:39,540
Depending on the level of data you have on that
92

92

00:03:39,540  -->  00:03:41,370
and the different classification level,
93

93

00:03:41,370  -->  00:03:44,340
that's going to determine how many passes you need to do.
94

94

00:03:44,340  -->  00:03:46,800
Now, the big problem that we have with a zero-fill though
95

95

00:03:46,800  -->  00:03:48,990
is it's really only reliable when you're dealing
96

96

00:03:48,990  -->  00:03:50,430
with magnetic media.
97

97

00:03:50,430  -->  00:03:52,410
If you're dealing with something like an SSD
98

98

00:03:52,410  -->  00:03:55,320
or a hybrid drive, these zero-fill procedures
99

99

00:03:55,320  -->  00:03:57,480
are not going to be very useful to you.
100

100

00:03:57,480  -->  00:03:59,940
Now, the reason for this is that solid state drives
101

101

00:03:59,940  -->  00:04:02,640
and hybrid drives have a wear leveling routine
102

102

00:04:02,640  -->  00:04:04,410
built into the drive controller,
103

103

00:04:04,410  -->  00:04:06,480
and this helps them communicate which locations
104

104

00:04:06,480  -->  00:04:08,760
are available for use by the software.
105

105

00:04:08,760  -->  00:04:10,050
So even though you're telling it to do
106

106

00:04:10,050  -->  00:04:13,800
a zero across every single bit on that solid state drive,
107

107

00:04:13,800  -->  00:04:15,240
if you're using a solid state drive,
108

108

00:04:15,240  -->  00:04:17,880
that wear leveling routine might miss some places
109

109

00:04:17,880  -->  00:04:21,180
and that means there could be data that could be recovered.
110

110

00:04:21,180  -->  00:04:22,560
Now, another thing you can use
111

111

00:04:22,560  -->  00:04:24,780
is what's known as a secure erase.
112

112

00:04:24,780  -->  00:04:26,910
A secure erase is a method of sanitizing
113

113

00:04:26,910  -->  00:04:30,870
a solid state device using manufacturer provided software.
114

114

00:04:30,870  -->  00:04:33,270
Again, because of that wear leveling routine
115

115

00:04:33,270  -->  00:04:35,610
using this specific secure erase software
116

116

00:04:35,610  -->  00:04:38,310
can override that ability of using that wear leveling
117

117

00:04:38,310  -->  00:04:40,890
and make sure you get all the data sanitized.
118

118

00:04:40,890  -->  00:04:43,050
Now, I mentioned earlier that it's going to depend
119

119

00:04:43,050  -->  00:04:45,360
on the type of data you have on a drive
120

120

00:04:45,360  -->  00:04:48,180
of which method you're going to use to sanitize it.
121

121

00:04:48,180  -->  00:04:50,130
Now, if you have something that is top secret,
122

122

00:04:50,130  -->  00:04:51,720
or highly confidential,
123

123

00:04:51,720  -->  00:04:53,340
you want to make sure you're sanitizing it
124

124

00:04:53,340  -->  00:04:55,320
using secure disposal.
125

125

00:04:55,320  -->  00:04:57,420
Now, what is secure disposal?
126

126

00:04:57,420  -->  00:05:00,240
Well, secure disposal is a method of sanitizing
127

127

00:05:00,240  -->  00:05:02,760
that utilizes physical destruction of the media
128

128

00:05:02,760  -->  00:05:06,450
by mechanical shredding, incineration or degaussing.
129

129

00:05:06,450  -->  00:05:07,650
Yes, that's right.
130

130

00:05:07,650  -->  00:05:09,960
You can actually shred a metal hard drive
131

131

00:05:09,960  -->  00:05:12,240
into smaller pieces, and by doing this,
132

132

00:05:12,240  -->  00:05:14,340
you can ensure nobody will ever get the data
133

133

00:05:14,340  -->  00:05:15,690
off of that drive.
134

134

00:05:15,690  -->  00:05:17,460
This level of physical destruction
135

135

00:05:17,460  -->  00:05:21,210
is reserved for things that have a very high classification,
136

136

00:05:21,210  -->  00:05:24,630
such as proprietary data, top secret government information
137

137

00:05:24,630  -->  00:05:27,090
or confidential business transactions.
138

138

00:05:27,090  -->  00:05:29,550
Now, most of us aren't going to use secure disposal
139

139

00:05:29,550  -->  00:05:32,160
because we don't want to destroy the physical hardware.
140

140

00:05:32,160  -->  00:05:34,380
We want to be able to reuse that hardware in our servers
141

141

00:05:34,380  -->  00:05:36,810
or in our workstations, and so in those cases,
142

142

00:05:36,810  -->  00:05:39,090
we would have to use something like cryptographic erase
143

143

00:05:39,090  -->  00:05:41,190
if you're using a self encrypting drive,
144

144

00:05:41,190  -->  00:05:43,950
zero-fill if you're going to be using a magnetic drive,
145

145

00:05:43,950  -->  00:05:45,570
like the one shown here,
146

146

00:05:45,570  -->  00:05:48,990
or secure erase if you're using a solid state device.
147

147

00:05:48,990  -->  00:05:50,190
It's important for you to know
148

148

00:05:50,190  -->  00:05:52,680
which of these three methods you are going to use
149

149

00:05:52,680  -->  00:05:55,920
based on the type of device that you're trying to sanitize.
150

150

00:05:55,920  -->  00:05:57,810
Finally, if you want to learn more information
151

151

00:05:57,810  -->  00:05:59,550
about sanitizing your media,
152

152

00:05:59,550  -->  00:06:00,840
I do recommend you look at the
153

153

00:06:00,840  -->  00:06:03,930
NIST Special Publication 800-88.
154

154

00:06:03,930  -->  00:06:06,720
This has all the guidelines for media sanitation,
155

155

00:06:06,720  -->  00:06:08,940
and it's going to cover all of the different topics
156

156

00:06:08,940  -->  00:06:10,980
that you might use in the real world,
157

157

00:06:10,980  -->  00:06:12,690
depending on where your organization is
158

158

00:06:12,690  -->  00:06:14,640
and what type of business you're doing.
