1
1

00:00:00,330  -->  00:00:02,790
<v Instructor>Cloud access security broker.</v>
2

2

00:00:02,790  -->  00:00:05,400
What is a cloud access security broker,
3

3

00:00:05,400  -->  00:00:07,890
also known as a CASB?
4

4

00:00:07,890  -->  00:00:09,990
Well, this is an enterprise management software
5

5

00:00:09,990  -->  00:00:12,660
designed to mediate access to cloud services
6

6

00:00:12,660  -->  00:00:15,510
by users across all types of devices.
7

7

00:00:15,510  -->  00:00:17,550
Essentially, it's going to be a middleman
8

8

00:00:17,550  -->  00:00:19,230
that helps you with your authentication
9

9

00:00:19,230  -->  00:00:21,390
and ensure that people are using the services
10

10

00:00:21,390  -->  00:00:22,620
they're supposed to use.
11

11

00:00:22,620  -->  00:00:24,420
Now, there are many different vendors
12

12

00:00:24,420  -->  00:00:26,160
who sell this type of product.
13

13

00:00:26,160  -->  00:00:27,960
They include people like Symantec
14

14

00:00:27,960  -->  00:00:29,670
which uses the Blue Coat proxy,
15

15

00:00:29,670  -->  00:00:32,010
which I've personally used in a lot of my organizations.
16

16

00:00:32,010  -->  00:00:34,470
There's Skyhigh Networks, which is made by McAfee.
17

17

00:00:34,470  -->  00:00:35,640
There's Forcepoint.
18

18

00:00:35,640  -->  00:00:37,470
There's Microsoft's Cloud App Security
19

19

00:00:37,470  -->  00:00:38,550
which is their version,
20

20

00:00:38,550  -->  00:00:41,100
and Cisco has their version called CloudLock.
21

21

00:00:41,100  -->  00:00:44,040
All of these are different cloud access security brokers
22

22

00:00:44,040  -->  00:00:46,200
and the key term here is security.
23

23

00:00:46,200  -->  00:00:47,160
By being a broker,
24

24

00:00:47,160  -->  00:00:48,600
they're going to make sure that your device
25

25

00:00:48,600  -->  00:00:51,690
is connecting to the right device using the right security.
26

26

00:00:51,690  -->  00:00:52,920
Now, what are some benefits
27

27

00:00:52,920  -->  00:00:56,010
of using these cloud access security brokers?
28

28

00:00:56,010  -->  00:00:58,530
Well, they can enable single sign-on authentication
29

29

00:00:58,530  -->  00:01:00,990
and enforce access controls and authorizations
30

30

00:01:00,990  -->  00:01:03,210
across your entire enterprise network,
31

31

00:01:03,210  -->  00:01:04,950
all the way from your enterprise network
32

32

00:01:04,950  -->  00:01:06,720
up to the cloud provider.
33

33

00:01:06,720  -->  00:01:09,900
They also can help you scan for malware and rogue devices,
34

34

00:01:09,900  -->  00:01:11,460
and be able to find any of these devices
35

35

00:01:11,460  -->  00:01:13,110
that might be on your network.
36

36

00:01:13,110  -->  00:01:14,610
They also can help monitor and audit
37

37

00:01:14,610  -->  00:01:16,200
user and resource activity
38

38

00:01:16,200  -->  00:01:18,540
to know exactly what your users are doing on your network
39

39

00:01:18,540  -->  00:01:19,500
at any time.
40

40

00:01:19,500  -->  00:01:22,590
And finally, they can help you mitigate data exfiltration
41

41

00:01:22,590  -->  00:01:23,790
by performing functions
42

42

00:01:23,790  -->  00:01:26,580
like a data loss prevention system would.
43

43

00:01:26,580  -->  00:01:29,400
Now, when you talk about a cloud access service broker,
44

44

00:01:29,400  -->  00:01:31,440
I want you to remember they provide visibility
45

45

00:01:31,440  -->  00:01:34,080
into how your clients and other network nodes
46

46

00:01:34,080  -->  00:01:36,120
are using your cloud services.
47

47

00:01:36,120  -->  00:01:38,040
When you start moving everything out to the cloud,
48

48

00:01:38,040  -->  00:01:38,887
you have to think about,
49

49

00:01:38,887  -->  00:01:40,890
"How are my users using those things?
50

50

00:01:40,890  -->  00:01:42,390
How much time are they spending?
51

51

00:01:42,390  -->  00:01:44,010
Are they using it the right way?
52

52

00:01:44,010  -->  00:01:46,410
Are they taking data and putting it where it shouldn't be?"
53

53

00:01:46,410  -->  00:01:49,290
And to do that, we have three different things.
54

54

00:01:49,290  -->  00:01:51,600
We can set it up as either a forward proxy,
55

55

00:01:51,600  -->  00:01:52,830
a reverse proxy,
56

56

00:01:52,830  -->  00:01:54,840
or using API access.
57

57

00:01:54,840  -->  00:01:56,490
Now, when we talk about a forward proxy
58

58

00:01:56,490  -->  00:01:58,800
in terms of a cloud access security broker,
59

59

00:01:58,800  -->  00:02:01,620
we're essentially going to set up a security appliance or host
60

60

00:02:01,620  -->  00:02:03,900
that's positioned at the client network edge,
61

61

00:02:03,900  -->  00:02:05,760
and then it's going to forward the user traffic
62

62

00:02:05,760  -->  00:02:07,020
to the cloud network
63

63

00:02:07,020  -->  00:02:10,020
if the contents of that traffic comply with policy.
64

64

00:02:10,020  -->  00:02:12,060
For example, in my home network,
65

65

00:02:12,060  -->  00:02:15,090
I have my kids set up to use a forward proxy.
66

66

00:02:15,090  -->  00:02:16,860
Now, this means that I went to their browser
67

67

00:02:16,860  -->  00:02:17,693
and I configured it,
68

68

00:02:17,693  -->  00:02:20,400
so they had to go and connect to my proxy server
69

69

00:02:20,400  -->  00:02:21,930
before they went out to the internet.
70

70

00:02:21,930  -->  00:02:23,640
This way, I could see what they were doing,
71

71

00:02:23,640  -->  00:02:25,470
how much time they were spending on sites,
72

72

00:02:25,470  -->  00:02:27,690
and if I needed to block certain things.
73

73

00:02:27,690  -->  00:02:29,100
Now, as my kids got older,
74

74

00:02:29,100  -->  00:02:32,490
my son got smarter and he realized what a proxy server was,
75

75

00:02:32,490  -->  00:02:35,520
and so, he wanted to prevent the use of this forward proxy.
76

76

00:02:35,520  -->  00:02:37,140
So, what did he do?
77

77

00:02:37,140  -->  00:02:38,850
Well, he evaded the proxy
78

78

00:02:38,850  -->  00:02:41,100
and connected directly to the sites he wanted to,
79

79

00:02:41,100  -->  00:02:43,500
and the way he did that was by bypassing the proxy.
80

80

00:02:43,500  -->  00:02:45,420
And so, this is something you have to be concerned with
81

81

00:02:45,420  -->  00:02:47,490
when you're dealing with a forward proxy.
82

82

00:02:47,490  -->  00:02:48,750
Now, if I wanted to prevent that,
83

83

00:02:48,750  -->  00:02:51,960
I might go to the second method, which is a reverse proxy.
84

84

00:02:51,960  -->  00:02:54,450
Now, a reverse proxy is an appliance that's positioned
85

85

00:02:54,450  -->  00:02:56,070
at the cloud network edge
86

86

00:02:56,070  -->  00:02:58,380
and directs the traffic to the cloud services
87

87

00:02:58,380  -->  00:03:01,650
if the contents of that traffic comply with the policy.
88

88

00:03:01,650  -->  00:03:04,380
So, instead of having to go through the proxy
89

89

00:03:04,380  -->  00:03:05,700
to leave the network,
90

90

00:03:05,700  -->  00:03:06,630
you can leave the network,
91

91

00:03:06,630  -->  00:03:08,670
but you can't get into the cloud network
92

92

00:03:08,670  -->  00:03:10,110
until you hit the proxy.
93

93

00:03:10,110  -->  00:03:11,820
That's the idea of the reverse proxy.
94

94

00:03:11,820  -->  00:03:14,280
Now, the big problem with this is it only works
95

95

00:03:14,280  -->  00:03:16,410
if the cloud application you're trying to connect to
96

96

00:03:16,410  -->  00:03:17,850
supports proxies.
97

97

00:03:17,850  -->  00:03:19,200
If they don't have proxy support,
98

98

00:03:19,200  -->  00:03:20,907
you can't do a reverse proxy.
99

99

00:03:20,907  -->  00:03:22,920
And so, this brings us to our third method
100

100

00:03:22,920  -->  00:03:26,130
which is an application programming interface or API.
101

101

00:03:26,130  -->  00:03:28,290
This is a method that uses the broker's connections
102

102

00:03:28,290  -->  00:03:30,930
between the cloud service and the cloud consumer
103

103

00:03:30,930  -->  00:03:32,310
to make changes.
104

104

00:03:32,310  -->  00:03:33,390
Now, essentially when we're using
105

105

00:03:33,390  -->  00:03:35,100
the application programming interface,
106

106

00:03:35,100  -->  00:03:37,350
we're sending data between the cloud service
107

107

00:03:37,350  -->  00:03:38,760
and the cloud consumer,
108

108

00:03:38,760  -->  00:03:39,750
and what we're doing here
109

109

00:03:39,750  -->  00:03:42,450
is we're being able to send information about those users.
110

110

00:03:42,450  -->  00:03:45,090
So, if I had a user account that's now been disabled,
111

111

00:03:45,090  -->  00:03:47,250
or authorization's been revoked from the local network
112

112

00:03:47,250  -->  00:03:49,080
because they were doing bad things,
113

113

00:03:49,080  -->  00:03:52,200
I can send that using the cloud broker over the API
114

114

00:03:52,200  -->  00:03:53,257
to the cloud service and say,
115

115

00:03:53,257  -->  00:03:55,290
"Hey, don't let Jason in.
116

116

00:03:55,290  -->  00:03:57,720
We just fired that guy and his account's been disabled,"
117

117

00:03:57,720  -->  00:04:00,540
and so, they can now know not to give him access.
118

118

00:04:00,540  -->  00:04:02,610
Now, the problem with this, the big warning here,
119

119

00:04:02,610  -->  00:04:03,450
is that it's dependent
120

120

00:04:03,450  -->  00:04:06,480
on the API supporting the functions your policies demand.
121

121

00:04:06,480  -->  00:04:08,250
So, as you start thinking about your policies
122

122

00:04:08,250  -->  00:04:10,170
and you start saying, "Well, I want people
123

123

00:04:10,170  -->  00:04:12,990
to be denied or allowed access to everything,"
124

124

00:04:12,990  -->  00:04:14,280
that's probably going to be supported.
125

125

00:04:14,280  -->  00:04:16,650
But if you start having very detailed requirements,
126

126

00:04:16,650  -->  00:04:18,390
those things may not be supported
127

127

00:04:18,390  -->  00:04:19,890
depending on the service that you're using.
128

128

00:04:19,890  -->  00:04:21,570
And if they don't support those policies,
129

129

00:04:21,570  -->  00:04:22,800
the API doesn't have 'em,
130

130

00:04:22,800  -->  00:04:24,683
and you're not going to be able to use this method.
