1
1

00:00:00,731  -->  00:00:01,650
<v Instructor>Honeypots.</v>
2

2

00:00:01,650  -->  00:00:04,290
In this lesson, we're going to start talking about honeypots
3

3

00:00:04,290  -->  00:00:05,820
and active defense.
4

4

00:00:05,820  -->  00:00:07,860
Honeypots are probably the most well-known form
5

5

00:00:07,860  -->  00:00:10,620
of active defense, although there are several other types.
6

6

00:00:10,620  -->  00:00:12,120
Now, when we talk about defense,
7

7

00:00:12,120  -->  00:00:13,567
you probably have heard the old saying,
8

8

00:00:13,567  -->  00:00:15,780
"The best defense is a good offense."
9

9

00:00:15,780  -->  00:00:17,070
Now, what does that mean?
10

10

00:00:17,070  -->  00:00:18,870
Well, this was actually a saying from a boxer
11

11

00:00:18,870  -->  00:00:21,270
back in the 1930s named Jack Dempsey.
12

12

00:00:21,270  -->  00:00:23,820
And his idea was if you have a really good offense
13

13

00:00:23,820  -->  00:00:25,110
and you're hitting the other guy over and over
14

14

00:00:25,110  -->  00:00:27,240
and over again, you're going to bloody him up to the point
15

15

00:00:27,240  -->  00:00:29,340
where he gets tired and gives up on you.
16

16

00:00:29,340  -->  00:00:31,890
That's the idea of the best defense being a good offense.
17

17

00:00:31,890  -->  00:00:33,960
Now, does that really apply to our networks?
18

18

00:00:33,960  -->  00:00:35,850
Well, maybe or maybe not.
19

19

00:00:35,850  -->  00:00:38,700
But in this lesson, we are going to focus on active defense
20

20

00:00:38,700  -->  00:00:40,290
because that is one of the objectives
21

21

00:00:40,290  -->  00:00:42,570
underneath your CYSA+ exam.
22

22

00:00:42,570  -->  00:00:44,160
Now, when we talk about active defense,
23

23

00:00:44,160  -->  00:00:46,650
we're talking about the practice of responding to a threat
24

24

00:00:46,650  -->  00:00:50,010
by destroying or deceiving the threat actor's capabilities.
25

25

00:00:50,010  -->  00:00:51,450
Now, what this really means
26

26

00:00:51,450  -->  00:00:53,700
is that we have an engagement with the adversary.
27

27

00:00:53,700  -->  00:00:55,620
That's what active defense is all about.
28

28

00:00:55,620  -->  00:00:57,660
You're going to hit me, well, I'm going to hit you back
29

29

00:00:57,660  -->  00:00:59,370
or you're going to try breaking into my network,
30

30

00:00:59,370  -->  00:01:00,900
I'm going to let you in but I'm going to put you
31

31

00:01:00,900  -->  00:01:02,640
in this other area that's a decoy.
32

32

00:01:02,640  -->  00:01:04,650
That's the idea of active defense.
33

33

00:01:04,650  -->  00:01:06,900
For instance, I might want to set up something
34

34

00:01:06,900  -->  00:01:08,850
that is essentially bait for an attacker.
35

35

00:01:08,850  -->  00:01:11,310
I set up an area of my network that is exposed
36

36

00:01:11,310  -->  00:01:13,500
to the internet and I don't patch my servers
37

37

00:01:13,500  -->  00:01:15,360
and I put false information on that stuff.
38

38

00:01:15,360  -->  00:01:18,090
That all looks like a very attractive target to an attacker.
39

39

00:01:18,090  -->  00:01:21,360
And so they may go and grab that. And I'm luring them in.
40

40

00:01:21,360  -->  00:01:24,540
Well, that concept is actually called a honeypot.
41

41

00:01:24,540  -->  00:01:27,120
A honeypot is essentially a host or a server
42

42

00:01:27,120  -->  00:01:29,340
that is set up with the purpose of luring attackers
43

43

00:01:29,340  -->  00:01:31,050
away from your actual network components
44

44

00:01:31,050  -->  00:01:33,360
that you care about and instead allowing them
45

45

00:01:33,360  -->  00:01:35,100
to start attacking this other area.
46

46

00:01:35,100  -->  00:01:36,960
When they do this, it allows you to discover
47

47

00:01:36,960  -->  00:01:38,880
attack strategies and weaknesses
48

48

00:01:38,880  -->  00:01:40,620
in different security configurations
49

49

00:01:40,620  -->  00:01:42,420
and learn from their attack methods
50

50

00:01:42,420  -->  00:01:44,670
because as you watch them doing things, you're going to see,
51

51

00:01:44,670  -->  00:01:47,160
oh, when they first break in, then they try to pivot
52

52

00:01:47,160  -->  00:01:48,870
or then they try to escalate privileges
53

53

00:01:48,870  -->  00:01:50,940
or then they try to do X, Y, Z.
54

54

00:01:50,940  -->  00:01:52,440
And by being able to gather that information,
55

55

00:01:52,440  -->  00:01:54,030
you can learn about your adversary.
56

56

00:01:54,030  -->  00:01:56,220
Now, in addition to a honeypot, which is a single host
57

57

00:01:56,220  -->  00:01:58,440
or server, you might have a honeynet.
58

58

00:01:58,440  -->  00:02:00,630
And this is an entire network that's set up to entice
59

59

00:02:00,630  -->  00:02:02,400
an attacker and it looks really juicy,
60

60

00:02:02,400  -->  00:02:04,200
like it's a real company's network.
61

61

00:02:04,200  -->  00:02:05,700
Now, often these honeynets are set up
62

62

00:02:05,700  -->  00:02:07,350
by internet security companies
63

63

00:02:07,350  -->  00:02:08,820
because they want to use that to allow
64

64

00:02:08,820  -->  00:02:11,940
their security teams to analyze an attacker's behavior.
65

65

00:02:11,940  -->  00:02:13,800
Now, what's a good example of this?
66

66

00:02:13,800  -->  00:02:14,947
Let's say I went ahead and said,
67

67

00:02:14,947  -->  00:02:16,980
"I have this wonderful database."
68

68

00:02:16,980  -->  00:02:18,540
So then set up a database server.
69

69

00:02:18,540  -->  00:02:21,300
I'm going to put some fake information in the database server
70

70

00:02:21,300  -->  00:02:23,370
and I'm going to expose it to the internet.
71

71

00:02:23,370  -->  00:02:26,160
Now, inside of that database, I have a lot of meaningless
72

72

00:02:26,160  -->  00:02:29,010
or unhelpful information but the attacker doesn't know that.
73

73

00:02:29,010  -->  00:02:30,630
They just see there's a database with a lot
74

74

00:02:30,630  -->  00:02:31,950
of important financial records
75

75

00:02:31,950  -->  00:02:33,390
because that's what I made it look like.
76

76

00:02:33,390  -->  00:02:35,340
And so as they go in there and they start attacking
77

77

00:02:35,340  -->  00:02:37,710
that database and they start getting into there,
78

78

00:02:37,710  -->  00:02:39,780
I can start seeing what they're doing and figure out
79

79

00:02:39,780  -->  00:02:42,900
what their techniques are and then use that to better harden
80

80

00:02:42,900  -->  00:02:45,480
the rest of my network against that type of an attack.
81

81

00:02:45,480  -->  00:02:48,210
That's the idea of using a honeypot or a honeynet.
82

82

00:02:48,210  -->  00:02:50,370
Now, one of the reasons why security researchers
83

83

00:02:50,370  -->  00:02:53,580
set up these big honeynets is to learn about new techniques
84

84

00:02:53,580  -->  00:02:54,930
because when they learn about techniques,
85

85

00:02:54,930  -->  00:02:57,570
they can try to attribute them back to the actor.
86

86

00:02:57,570  -->  00:02:58,800
When we talk about attribution,
87

87

00:02:58,800  -->  00:03:00,960
we're talking about the ability to do identification
88

88

00:03:00,960  -->  00:03:03,630
and publication of an attacker's methods, techniques,
89

89

00:03:03,630  -->  00:03:06,270
and tactics as useful threat intelligence.
90

90

00:03:06,270  -->  00:03:07,950
For instance, if you look at FireEye,
91

91

00:03:07,950  -->  00:03:09,570
they do this all the time.
92

92

00:03:09,570  -->  00:03:12,270
You can go look in a report on a APT 28 for instance
93

93

00:03:12,270  -->  00:03:14,640
and they'll tell you they believe this is attributed
94

94

00:03:14,640  -->  00:03:16,830
to APT 28, these types of malware
95

95

00:03:16,830  -->  00:03:18,450
and these are the common techniques they use
96

96

00:03:18,450  -->  00:03:20,220
and these are the common tactics they use
97

97

00:03:20,220  -->  00:03:21,360
and this is who we think they are.
98

98

00:03:21,360  -->  00:03:23,760
We think they are part of the Russian Federation
99

99

00:03:23,760  -->  00:03:26,040
or we think they are part of China or we think they are part
100

100

00:03:26,040  -->  00:03:28,170
of the US or whoever it is they think they are.
101

101

00:03:28,170  -->  00:03:30,060
That is what attribution does.
102

102

00:03:30,060  -->  00:03:31,560
Now, in addition to dealing with things
103

103

00:03:31,560  -->  00:03:33,990
like honeynets and honeypots and attribution,
104

104

00:03:33,990  -->  00:03:37,080
we also can do other strategies like annoyance strategies.
105

105

00:03:37,080  -->  00:03:38,970
Now, annoyance strategies often will rely
106

106

00:03:38,970  -->  00:03:40,830
on obfuscation techniques.
107

107

00:03:40,830  -->  00:03:42,660
These are things where we're basically trying to annoy
108

108

00:03:42,660  -->  00:03:44,610
our attacker and waste their time.
109

109

00:03:44,610  -->  00:03:47,340
So for instance, we might put in bogus DNS entries
110

110

00:03:47,340  -->  00:03:48,750
so when they look at our DNS records,
111

111

00:03:48,750  -->  00:03:51,300
they see that we have a mail server and a SharePoint server
112

112

00:03:51,300  -->  00:03:53,190
and a file server and a web server.
113

113

00:03:53,190  -->  00:03:54,990
And we may not have any of those servers up
114

114

00:03:54,990  -->  00:03:56,490
but we can give bogus DNS entries
115

115

00:03:56,490  -->  00:03:57,780
so they think there's something else there
116

116

00:03:57,780  -->  00:03:59,760
and so they'll waste their time trying to find it.
117

117

00:03:59,760  -->  00:04:01,320
Then we can also have things like web servers
118

118

00:04:01,320  -->  00:04:02,550
with decoy directories.
119

119

00:04:02,550  -->  00:04:03,720
So I have a web server up
120

120

00:04:03,720  -->  00:04:05,310
and I have all my juicy information
121

121

00:04:05,310  -->  00:04:07,260
in a file called Confidential.
122

122

00:04:07,260  -->  00:04:08,730
No, I don't because I don't want somebody
123

123

00:04:08,730  -->  00:04:09,930
to see that 'cause they see confidential,
124

124

00:04:09,930  -->  00:04:11,520
they're going to try to get into it, right?
125

125

00:04:11,520  -->  00:04:14,160
But I might put decoy directories like confidential,
126

126

00:04:14,160  -->  00:04:16,620
important, financial, and that way attackers
127

127

00:04:16,620  -->  00:04:18,630
might try to go for those and waste their time
128

128

00:04:18,630  -->  00:04:19,800
'cause if they're wasting their time on stuff
129

129

00:04:19,800  -->  00:04:21,810
I don't care about, hopefully they're not using their time
130

130

00:04:21,810  -->  00:04:23,790
against stuff I actually do care about.
131

131

00:04:23,790  -->  00:04:24,720
And then the other thing we can do
132

132

00:04:24,720  -->  00:04:26,550
is we can use port triggering and spoofing.
133

133

00:04:26,550  -->  00:04:28,200
There's a lot of techniques out there
134

134

00:04:28,200  -->  00:04:31,080
where when you see traffic come in on port X,
135

135

00:04:31,080  -->  00:04:32,610
have this action occur.
136

136

00:04:32,610  -->  00:04:35,250
And so you might have something like they connect on port 25
137

137

00:04:35,250  -->  00:04:37,170
to try to get into your SMTP server
138

138

00:04:37,170  -->  00:04:39,150
and you're not really running an SMTP server.
139

139

00:04:39,150  -->  00:04:41,340
Instead, you're going to send that over to port 80
140

140

00:04:41,340  -->  00:04:42,780
and give them some other kind of message back.
141

141

00:04:42,780  -->  00:04:44,670
So again, you're wasting their time.
142

142

00:04:44,670  -->  00:04:47,790
Now, another thing you can do is what's known as hack back.
143

143

00:04:47,790  -->  00:04:50,370
And this is something I don't really encourage you to do.
144

144

00:04:50,370  -->  00:04:52,860
Most organizations are not going to allow you to do hack back
145

145

00:04:52,860  -->  00:04:55,530
unless you work for maybe a three-letter agency
146

146

00:04:55,530  -->  00:04:58,320
or a military component or some other nation-state
147

147

00:04:58,320  -->  00:04:59,550
because when you're hacking back,
148

148

00:04:59,550  -->  00:05:01,890
you are conducting offensive attacks.
149

149

00:05:01,890  -->  00:05:03,750
Hack back is essentially using offensive
150

150

00:05:03,750  -->  00:05:06,510
or counterattacking techniques to identify the attacker
151

151

00:05:06,510  -->  00:05:08,430
and degrade their capabilities.
152

152

00:05:08,430  -->  00:05:10,710
The idea here with hack back is maybe you have somebody
153

153

00:05:10,710  -->  00:05:12,900
who is attacking your network and you identify
154

154

00:05:12,900  -->  00:05:16,380
that their command and control is at this particular IP.
155

155

00:05:16,380  -->  00:05:18,240
Well, you can start doing a denial of service
156

156

00:05:18,240  -->  00:05:20,310
against their IP to get them to stop
157

157

00:05:20,310  -->  00:05:21,900
doing the attack against you.
158

158

00:05:21,900  -->  00:05:23,820
That's the idea of a hack back.
159

159

00:05:23,820  -->  00:05:26,100
Now, can you do this legally?
160

160

00:05:26,100  -->  00:05:29,580
Mm, maybe, it depends where you live because these things
161

161

00:05:29,580  -->  00:05:32,190
all are in different laws based on the city, the state,
162

162

00:05:32,190  -->  00:05:34,800
the country, or the region of the world that you live in.
163

163

00:05:34,800  -->  00:05:36,960
And so you have to look into that because there are many
164

164

00:05:36,960  -->  00:05:38,850
legal and reputational implications
165

165

00:05:38,850  -->  00:05:40,620
that you have to consider and mitigate
166

166

00:05:40,620  -->  00:05:43,080
before you can use some of these active defense strategies,
167

167

00:05:43,080  -->  00:05:44,910
especially hack back.
168

168

00:05:44,910  -->  00:05:47,970
For instance, hack back is considered an offensive maneuver.
169

169

00:05:47,970  -->  00:05:50,250
As I said, you are attacking somebody.
170

170

00:05:50,250  -->  00:05:52,770
So in the United States, you could actually go to jail
171

171

00:05:52,770  -->  00:05:54,870
for that because you are breaking the law.
172

172

00:05:54,870  -->  00:05:56,520
It is illegal to do hacking.
173

173

00:05:56,520  -->  00:05:58,320
And so if you are hacking back against somebody
174

174

00:05:58,320  -->  00:06:00,090
who is hacking you, that doesn't make
175

175

00:06:00,090  -->  00:06:01,260
two wrongs make a right here.
176

176

00:06:01,260  -->  00:06:02,700
You could still go to jail for that.
177

177

00:06:02,700  -->  00:06:03,810
So keep that in mind.
178

178

00:06:03,810  -->  00:06:06,510
Remember where you are and the laws in your area
179

179

00:06:06,510  -->  00:06:09,270
and the laws of the server that you're actually attacking
180

180

00:06:09,270  -->  00:06:11,190
because just 'cause you're in the United States,
181

181

00:06:11,190  -->  00:06:13,080
that server may be someplace else
182

182

00:06:13,080  -->  00:06:15,600
and then it's affected by those laws and regulations.
183

183

00:06:15,600  -->  00:06:18,420
So again, the best practice is really not to do hack back.
184

184

00:06:18,420  -->  00:06:19,980
But again, it is one of those things that's covered
185

185

00:06:19,980  -->  00:06:22,403
in your textbook so I wanted to bring it up here.
