1
1

00:00:00,000  -->  00:00:00,990
<v Instructor>In this lesson,</v>
2

2

00:00:00,990  -->  00:00:03,960
we're going to cover a tool known as AbuseIPDB,
3

3

00:00:03,960  -->  00:00:06,210
or the Abuse IP database.
4

4

00:00:06,210  -->  00:00:09,240
Now, the AbuseIPDB is a community driven database
5

5

00:00:09,240  -->  00:00:11,880
that keeps track of IP addresses that have been reported
6

6

00:00:11,880  -->  00:00:13,440
for abusive behavior.
7

7

00:00:13,440  -->  00:00:15,990
This database is built and maintained by a global community
8

8

00:00:15,990  -->  00:00:18,360
of users who actively report IP addresses
9

9

00:00:18,360  -->  00:00:20,580
that they suspect to be involved in cyber attacks
10

10

00:00:20,580  -->  00:00:23,070
such as hacking, phishing, and spamming.
11

11

00:00:23,070  -->  00:00:25,560
This information is then made available to the public,
12

12

00:00:25,560  -->  00:00:28,290
allowing others to check if an IP address has been reported
13

13

00:00:28,290  -->  00:00:30,360
and take the appropriate actions.
14

14

00:00:30,360  -->  00:00:31,620
Now, one of the key benefits
15

15

00:00:31,620  -->  00:00:35,130
of the Abuse IP Database is that it enables the organization
16

16

00:00:35,130  -->  00:00:38,040
to take a proactive approach to its cybersecurity
17

17

00:00:38,040  -->  00:00:40,080
by monitoring for IP addresses that have been flagged
18

18

00:00:40,080  -->  00:00:41,040
as malicious,
19

19

00:00:41,040  -->  00:00:42,570
organizations can block traffic
20

20

00:00:42,570  -->  00:00:43,950
from those IP addresses,
21

21

00:00:43,950  -->  00:00:44,970
preventing cyber attacks
22

22

00:00:44,970  -->  00:00:47,160
before they can even cause any damage.
23

23

00:00:47,160  -->  00:00:49,140
This is especially important in today's world
24

24

00:00:49,140  -->  00:00:51,480
where cyber attacks are becoming increasingly sophisticated
25

25

00:00:51,480  -->  00:00:53,100
and difficult to detect.
26

26

00:00:53,100  -->  00:00:55,410
By using a tool like AbuseIPDB,
27

27

00:00:55,410  -->  00:00:57,210
an organization can stay one step ahead
28

28

00:00:57,210  -->  00:01:00,570
of the attackers and reduce the risk of a successful attack.
29

29

00:01:00,570  -->  00:01:02,670
The abuse IP database is not limited
30

30

00:01:02,670  -->  00:01:04,560
to just organizational use, though,
31

31

00:01:04,560  -->  00:01:07,950
because individuals can also benefit by using this database.
32

32

00:01:07,950  -->  00:01:11,190
For example, if you receive an email from an unknown sender,
33

33

00:01:11,190  -->  00:01:12,390
you can check the IP address
34

34

00:01:12,390  -->  00:01:15,300
that it came from against the Abuse IP Database.
35

35

00:01:15,300  -->  00:01:16,560
This can then help you to determine
36

36

00:01:16,560  -->  00:01:19,230
if the email is legitimate or if it's likely
37

37

00:01:19,230  -->  00:01:20,640
to be a phishing attempt.
38

38

00:01:20,640  -->  00:01:21,510
By doing this,
39

39

00:01:21,510  -->  00:01:23,220
you can protect yourself from falling victim
40

40

00:01:23,220  -->  00:01:24,270
to a phishing attack,
41

41

00:01:24,270  -->  00:01:25,680
which is a really common method used
42

42

00:01:25,680  -->  00:01:29,190
by cyber criminals to gain access to sensitive information.
43

43

00:01:29,190  -->  00:01:31,830
Another benefit of using the Abuse IP Database
44

44

00:01:31,830  -->  00:01:33,810
is that the database is constantly being updated
45

45

00:01:33,810  -->  00:01:36,870
with new information from a global community of users.
46

46

00:01:36,870  -->  00:01:38,760
This allows the database to stay current
47

47

00:01:38,760  -->  00:01:40,050
and provides a valuable resource
48

48

00:01:40,050  -->  00:01:41,820
for cybersecurity professionals.
49

49

00:01:41,820  -->  00:01:44,010
This is especially useful for organizations
50

50

00:01:44,010  -->  00:01:46,950
that need to quickly identify and respond to new threats.
51

51

00:01:46,950  -->  00:01:49,560
With the ability to track the latest IP addresses associated
52

52

00:01:49,560  -->  00:01:50,910
with malicious activity,
53

53

00:01:50,910  -->  00:01:52,200
organizations can now quickly
54

54

00:01:52,200  -->  00:01:55,050
and effectively block those IP addresses and reduce the risk
55

55

00:01:55,050  -->  00:01:56,670
of a successful attack.
56

56

00:01:56,670  -->  00:01:59,010
For example, if an organization suspects
57

57

00:01:59,010  -->  00:02:00,360
that they're under a DDOS,
58

58

00:02:00,360  -->  00:02:02,430
or distributed denial of service attack,
59

59

00:02:02,430  -->  00:02:05,280
that organization could use the Abuse IP Database
60

60

00:02:05,280  -->  00:02:08,010
to identify the IP addresses that are being used to launch
61

61

00:02:08,010  -->  00:02:09,840
that DDOS attack.
62

62

00:02:09,840  -->  00:02:11,760
The organization can then use this information
63

63

00:02:11,760  -->  00:02:14,400
to block traffic from all of those different IP addresses
64

64

00:02:14,400  -->  00:02:16,170
and this will effectively stop the attack
65

65

00:02:16,170  -->  00:02:19,170
and protect their servers from any kind of further damage.
66

66

00:02:19,170  -->  00:02:21,870
The organization can also use the Abuse IP Database
67

67

00:02:21,870  -->  00:02:24,240
to monitor their logs for any suspicious activity,
68

68

00:02:24,240  -->  00:02:26,310
such as a large number of failed login attempts
69

69

00:02:26,310  -->  00:02:29,460
or unusual traffic from specific IP addresses
70

70

00:02:29,460  -->  00:02:30,510
which could be indications
71

71

00:02:30,510  -->  00:02:33,060
that the organization is currently under attack.
72

72

00:02:33,060  -->  00:02:35,700
By using the Abuse IP database to check the IP addresses
73

73

00:02:35,700  -->  00:02:37,110
associated with that activity,
74

74

00:02:37,110  -->  00:02:38,640
the organization can quickly determine
75

75

00:02:38,640  -->  00:02:40,230
if that traffic was malicious
76

76

00:02:40,230  -->  00:02:42,720
and then take appropriate actions to block it.
77

77

00:02:42,720  -->  00:02:44,550
It is worth noting that the information
78

78

00:02:44,550  -->  00:02:46,920
in the Abuse IP Database is not considered
79

79

00:02:46,920  -->  00:02:48,720
to be a hundred percent reliable though,
80

80

00:02:48,720  -->  00:02:50,430
because it is based on reports submitted
81

81

00:02:50,430  -->  00:02:51,660
by the community members.
82

82

00:02:51,660  -->  00:02:53,640
And this can actually give us a lot of false positives
83

83

00:02:53,640  -->  00:02:55,410
or malicious reports.
84

84

00:02:55,410  -->  00:02:56,400
This is why it's important
85

85

00:02:56,400  -->  00:02:58,230
that you use the Abuse IP Database
86

86

00:02:58,230  -->  00:02:59,670
as one of the the security measures
87

87

00:02:59,670  -->  00:03:01,800
and then you combine it with other security measures
88

88

00:03:01,800  -->  00:03:05,130
as you're making decisions on your cybersecurity posture.
89

89

00:03:05,130  -->  00:03:08,220
So remember, when it comes to the Abuse IP Database,
90

90

00:03:08,220  -->  00:03:11,100
it is an essential tool for organizations to be looking at
91

91

00:03:11,100  -->  00:03:12,420
when they're trying to protect their networks
92

92

00:03:12,420  -->  00:03:14,040
from cyber attacks by monitoring
93

93

00:03:14,040  -->  00:03:15,720
for IP addresses that have been reported
94

94

00:03:15,720  -->  00:03:16,980
for abusive behavior.
95

95

00:03:16,980  -->  00:03:19,110
And this way organizations can be more proactive
96

96

00:03:19,110  -->  00:03:20,640
in their approach to cybersecurity
97

97

00:03:20,640  -->  00:03:23,370
and reduce their overall risk of a successful attack.
98

98

00:03:23,370  -->  00:03:25,800
Remember, this database is constantly being updated
99

99

00:03:25,800  -->  00:03:26,820
with new information,
100

100

00:03:26,820  -->  00:03:28,920
and therefore it's a really valuable resource
101

101

00:03:28,920  -->  00:03:30,813
for you as a cybersecurity analyst.
