1
00:00:00,000 --> 00:00:00,930
In this lesson,

2
00:00:00,930 --> 00:00:03,510
we're going to discuss the cybersecurity best practices

3
00:00:03,510 --> 00:00:05,910
that you need to implement within Linux.

4
00:00:05,910 --> 00:00:08,010
Now, Linux is the operating system that is used

5
00:00:08,010 --> 00:00:09,540
on the most network devices

6
00:00:09,540 --> 00:00:11,550
and security appliances out there.

7
00:00:11,550 --> 00:00:14,100
This includes things like routers, firewalls,

8
00:00:14,100 --> 00:00:16,230
next-generation firewall devices,

9
00:00:16,230 --> 00:00:18,150
unified threat management gateways,

10
00:00:18,150 --> 00:00:19,980
virtual private network concentrators,

11
00:00:19,980 --> 00:00:23,370
intrusion detection systems, intrusion protection systems,

12
00:00:23,370 --> 00:00:26,400
security information and event management appliances,

13
00:00:26,400 --> 00:00:29,760
wireless access point devices, and many others.

14
00:00:29,760 --> 00:00:31,590
Therefore, it's important to understand

15
00:00:31,590 --> 00:00:33,810
how all of this security-related data

16
00:00:33,810 --> 00:00:35,520
can be collected from these devices,

17
00:00:35,520 --> 00:00:37,410
because it's going to give you a lot of areas

18
00:00:37,410 --> 00:00:38,280
that you can look at

19
00:00:38,280 --> 00:00:40,170
when you're trying to secure your network.

20
00:00:40,170 --> 00:00:42,240
Additionally, you also need to understand

21
00:00:42,240 --> 00:00:44,070
what kind of security hardening you can do

22
00:00:44,070 --> 00:00:46,320
on your Linux servers and devices,

23
00:00:46,320 --> 00:00:47,700
because as more and more companies

24
00:00:47,700 --> 00:00:49,680
are moving their data into the cloud,

25
00:00:49,680 --> 00:00:51,540
it's being put onto Linux servers,

26
00:00:51,540 --> 00:00:53,520
and so you have to understand the extent

27
00:00:53,520 --> 00:00:55,710
to which that data could be compromised

28
00:00:55,710 --> 00:00:58,650
if you don't properly secure your network.

29
00:00:58,650 --> 00:01:00,870
So what can you do to protect your server

30
00:01:00,870 --> 00:01:03,000
and increase your Linux security?

31
00:01:03,000 --> 00:01:04,860
Well, this is what we're going to be talking about

32
00:01:04,860 --> 00:01:06,090
in this lesson.

33
00:01:06,090 --> 00:01:07,740
And we're going to talk about all the different techniques

34
00:01:07,740 --> 00:01:11,040
you can do to bolster the security of your Linux systems,

35
00:01:11,040 --> 00:01:13,860
and therefore minimize the risk of your organization

36
00:01:13,860 --> 00:01:16,830
falling victim to a data breach or other attack.

37
00:01:16,830 --> 00:01:19,590
Now, there are lots of best practices that you should follow

38
00:01:19,590 --> 00:01:21,600
to secure your Linux operating systems,

39
00:01:21,600 --> 00:01:23,370
and we're going to cover those as we go through

40
00:01:23,370 --> 00:01:26,670
these cybersecurity best practices in this lesson.

41
00:01:26,670 --> 00:01:28,980
Now, when I talk about the terms cybersecurity

42
00:01:28,980 --> 00:01:30,930
and cybersecurity best practices,

43
00:01:30,930 --> 00:01:32,940
I'm really talking about the ways that you can protect

44
00:01:32,940 --> 00:01:35,430
your computer systems and digital information

45
00:01:35,430 --> 00:01:39,720
against unauthorized access, attack, theft, or data damage.

46
00:01:39,720 --> 00:01:42,210
These days, cybersecurity is truly

47
00:01:42,210 --> 00:01:44,160
an important and necessary thing

48
00:01:44,160 --> 00:01:47,040
for organizations of all shapes and sizes.

49
00:01:47,040 --> 00:01:48,510
It's an essential practice

50
00:01:48,510 --> 00:01:50,430
that individuals also need to have,

51
00:01:50,430 --> 00:01:52,320
because your individual identity

52
00:01:52,320 --> 00:01:54,570
is not separated from the digital space.

53
00:01:54,570 --> 00:01:57,030
These things are all interwoven these days.

54
00:01:57,030 --> 00:01:59,370
So in our world that is highly connected

55
00:01:59,370 --> 00:02:00,510
across the internet,

56
00:02:00,510 --> 00:02:02,430
we really have to be cybersecurity minded,

57
00:02:02,430 --> 00:02:04,530
both at work and at home.

58
00:02:04,530 --> 00:02:06,360
Now, cybersecurity seeks to address

59
00:02:06,360 --> 00:02:08,009
three specific principles.

60
00:02:08,009 --> 00:02:11,460
These are confidentiality, integrity, and availability,

61
00:02:11,460 --> 00:02:14,250
which we refer to as the CIA triad.

62
00:02:14,250 --> 00:02:16,380
Now, if one of these principles is compromised,

63
00:02:16,380 --> 00:02:17,910
the security of the organization

64
00:02:17,910 --> 00:02:20,190
as a whole can be threatened.

65
00:02:20,190 --> 00:02:22,380
Confidentiality is the principle that talks

66
00:02:22,380 --> 00:02:24,570
about keeping information and communications

67
00:02:24,570 --> 00:02:27,540
private and protected from unauthorized access.

68
00:02:27,540 --> 00:02:30,630
Confidential information includes things like trade secrets,

69
00:02:30,630 --> 00:02:33,900
personnel records, health records, tax records,

70
00:02:33,900 --> 00:02:36,000
military secrets, and more.

71
00:02:36,000 --> 00:02:37,920
When you're dealing with confidentiality,

72
00:02:37,920 --> 00:02:40,650
you try to control that data by using encryption

73
00:02:40,650 --> 00:02:44,340
and access controls to protect it from being exposed.

74
00:02:44,340 --> 00:02:46,560
The second principle we have is integrity,

75
00:02:46,560 --> 00:02:48,570
and integrity is the fundamental principle

76
00:02:48,570 --> 00:02:51,300
of keeping the organization's information accurate,

77
00:02:51,300 --> 00:02:54,660
error-free, and without unauthorized modifications.

78
00:02:54,660 --> 00:02:58,050
For example, if I was able to break into a school's system

79
00:02:58,050 --> 00:02:59,700
and go ahead and change the test scores

80
00:02:59,700 --> 00:03:01,050
for a particular student,

81
00:03:01,050 --> 00:03:03,600
that would actually be an integrity violation,

82
00:03:03,600 --> 00:03:05,640
because the integrity of that grade information

83
00:03:05,640 --> 00:03:09,090
was compromised when I changed it from one score to another,

84
00:03:09,090 --> 00:03:11,820
and that was unauthorized in its modification.

85
00:03:11,820 --> 00:03:13,920
Now, typically, to control integrity,

86
00:03:13,920 --> 00:03:17,040
you want to use things like hashing, digital signatures,

87
00:03:17,040 --> 00:03:20,040
certificates, and change control processes.

88
00:03:20,040 --> 00:03:22,890
Now, the third principle we have is known as availability,

89
00:03:22,890 --> 00:03:25,530
and availability refers to the fundamental principle

90
00:03:25,530 --> 00:03:28,470
of ensuring that computer systems operate continuously

91
00:03:28,470 --> 00:03:30,180
and that the authorized people

92
00:03:30,180 --> 00:03:32,760
can access their data whenever they need it.

93
00:03:32,760 --> 00:03:35,490
This is typically controlled by using redundant systems,

94
00:03:35,490 --> 00:03:36,990
installing fault tolerance,

95
00:03:36,990 --> 00:03:39,030
and then doing software patching and updates

96
00:03:39,030 --> 00:03:42,270
to ensure your systems remain online all the time.

97
00:03:42,270 --> 00:03:44,700
Now, a prominent component of cybersecurity

98
00:03:44,700 --> 00:03:46,680
comes down to authentication.

99
00:03:46,680 --> 00:03:49,080
Authentication enables the organization to trust

100
00:03:49,080 --> 00:03:51,480
that the users are who they claim to be.

101
00:03:51,480 --> 00:03:53,550
Now, there are various ways to authenticate a user

102
00:03:53,550 --> 00:03:55,560
when they try to log onto a system.

103
00:03:55,560 --> 00:03:57,750
You can do this using pins, passwords,

104
00:03:57,750 --> 00:03:59,670
and passphrases, for example.

105
00:03:59,670 --> 00:04:01,710
All of these are basically strings of text

106
00:04:01,710 --> 00:04:03,720
that you're going to input along with your username

107
00:04:03,720 --> 00:04:05,760
in order to sign into a system.

108
00:04:05,760 --> 00:04:07,050
Depending on the system,

109
00:04:07,050 --> 00:04:09,600
you may be constrained by the type of characters you use,

110
00:04:09,600 --> 00:04:10,980
the length, either the minimum

111
00:04:10,980 --> 00:04:13,050
or maximum number of characters you can use,

112
00:04:13,050 --> 00:04:14,850
and other things like that.

113
00:04:14,850 --> 00:04:16,890
Now, in addition to using a knowledge factor,

114
00:04:16,890 --> 00:04:19,079
like pins, passwords, or passphrases,

115
00:04:19,079 --> 00:04:21,209
you can also use a possession factor,

116
00:04:21,209 --> 00:04:22,710
something like a token.

117
00:04:22,710 --> 00:04:24,720
Now, a token is any unique object,

118
00:04:24,720 --> 00:04:27,180
whether physical or digital, that you possess,

119
00:04:27,180 --> 00:04:29,610
and then present to verify your identity.

120
00:04:29,610 --> 00:04:31,260
These tokens are usually going to be used

121
00:04:31,260 --> 00:04:35,070
to generate one-time passwords, and these are called OTPs,

122
00:04:35,070 --> 00:04:37,920
and those passwords or pin numbers would then expire

123
00:04:37,920 --> 00:04:41,670
after a certain amount of time, normally 30 to 60 seconds.

124
00:04:41,670 --> 00:04:44,610
These tokens can also be leveraged in digital certificates

125
00:04:44,610 --> 00:04:46,860
as part of their authentication information,

126
00:04:46,860 --> 00:04:48,930
depending on how you configure them.

127
00:04:48,930 --> 00:04:51,180
Another type of authentication we can use

128
00:04:51,180 --> 00:04:53,460
is what we call an inheritance factor,

129
00:04:53,460 --> 00:04:55,740
and this includes things like biometrics.

130
00:04:55,740 --> 00:04:57,990
Now, biometrics is an authentication scheme

131
00:04:57,990 --> 00:04:59,820
that verifies a user's identity

132
00:04:59,820 --> 00:05:01,680
based on their physical characteristics,

133
00:05:01,680 --> 00:05:03,960
like their fingerprint, their iris,

134
00:05:03,960 --> 00:05:06,450
their hand size, or things like that.

135
00:05:06,450 --> 00:05:08,910
We can go ahead and get this information from our users

136
00:05:08,910 --> 00:05:11,880
by using things like fingerprint scanners, iris scanners,

137
00:05:11,880 --> 00:05:14,760
hand geometry scanners, voice recognition devices,

138
00:05:14,760 --> 00:05:16,680
and facial recognition software.

139
00:05:16,680 --> 00:05:19,770
And there's lots of different ways to use biometrics.

140
00:05:19,770 --> 00:05:21,270
Now, this makes it a little bit harder

141
00:05:21,270 --> 00:05:23,130
to compromise than a normal password,

142
00:05:23,130 --> 00:05:25,590
because if you had to present my fingerprint,

143
00:05:25,590 --> 00:05:27,990
that's a lot harder than getting my password,

144
00:05:27,990 --> 00:05:30,720
and so it is considered a higher level of security.

145
00:05:30,720 --> 00:05:32,160
Now, what is more secure, though,

146
00:05:32,160 --> 00:05:34,650
is when you start combining these different things.

147
00:05:34,650 --> 00:05:37,980
For example, if I combine a password with a token,

148
00:05:37,980 --> 00:05:41,130
that now has something I know and something I have,

149
00:05:41,130 --> 00:05:42,630
and putting these two factors together

150
00:05:42,630 --> 00:05:44,610
gives me multifactor authentication,

151
00:05:44,610 --> 00:05:47,970
which is much more secure than any single factor.

152
00:05:47,970 --> 00:05:49,980
The next thing we're going to cover is RADIUS.

153
00:05:49,980 --> 00:05:52,080
Now, RADIUS is the Remote Authentication

154
00:05:52,080 --> 00:05:53,700
Dial-In User Service,

155
00:05:53,700 --> 00:05:55,680
and this is an internet standard protocol

156
00:05:55,680 --> 00:05:58,620
that provides authentication, authorization, and accounting,

157
00:05:58,620 --> 00:06:02,040
which we call AAA, as part of our services.

158
00:06:02,040 --> 00:06:04,980
Now, in addition to RADIUS, we can also use TACACS.

159
00:06:04,980 --> 00:06:07,650
Now, TACACS+ is the Terminal Access Controller

160
00:06:07,650 --> 00:06:08,997
Access-Control System,

161
00:06:08,997 --> 00:06:12,480
and it's actually more secure and more scalable than RADIUS,

162
00:06:12,480 --> 00:06:15,840
but it only works on Cisco devices, and for this reason,

163
00:06:15,840 --> 00:06:16,890
you're going to see a lot of people

164
00:06:16,890 --> 00:06:19,830
still using RADIUS instead of TACACS+.

165
00:06:19,830 --> 00:06:22,950
Now, another thing we have to cover is the idea of LDAP.

166
00:06:22,950 --> 00:06:25,770
LDAP is the Lightweight Directory Access Protocol,

167
00:06:25,770 --> 00:06:27,420
and it's a directory service protocol

168
00:06:27,420 --> 00:06:30,240
that runs over a TCP/IP network.

169
00:06:30,240 --> 00:06:33,810
LDAP allows your clients to authenticate to the LDAP service

170
00:06:33,810 --> 00:06:36,270
and the service's schema then defines the tasks

171
00:06:36,270 --> 00:06:38,970
that that particular client can and cannot perform

172
00:06:38,970 --> 00:06:41,790
once they're accessing a directory database.

173
00:06:41,790 --> 00:06:44,190
Now, in addition to LDAP on Windows systems,

174
00:06:44,190 --> 00:06:46,470
we use something known as Kerberos.

175
00:06:46,470 --> 00:06:48,720
Now, Kerberos is an authentication service

176
00:06:48,720 --> 00:06:52,080
that's based on a time-sensitive ticket-granting system.

177
00:06:52,080 --> 00:06:54,510
It's also used a lot when we use single sign-on

178
00:06:54,510 --> 00:06:56,940
or SSO methods for users to access

179
00:06:56,940 --> 00:06:59,100
different sites and different services.

180
00:06:59,100 --> 00:07:01,170
Now, SSO is a method where the user

181
00:07:01,170 --> 00:07:03,660
can enter their access credentials one time

182
00:07:03,660 --> 00:07:05,910
and they're being passed to the authentication server,

183
00:07:05,910 --> 00:07:08,280
and then, based on that, they get a ticket,

184
00:07:08,280 --> 00:07:10,200
and they can then log into other services

185
00:07:10,200 --> 00:07:12,990
across the network or across the internet.

186
00:07:12,990 --> 00:07:14,640
This gives you a list of what is allowed

187
00:07:14,640 --> 00:07:15,660
and what is not allowed

188
00:07:15,660 --> 00:07:18,240
based on those particular access credentials.

189
00:07:18,240 --> 00:07:21,210
Now, Linux does have an implementation of Kerberos as well,

190
00:07:21,210 --> 00:07:23,070
and there's a few commands that you should know,

191
00:07:23,070 --> 00:07:26,730
including kinit, which is the initialization command

192
00:07:26,730 --> 00:07:28,440
that's used to authenticate Kerberos,

193
00:07:28,440 --> 00:07:30,360
and thereby grant the user a ticket,

194
00:07:30,360 --> 00:07:32,400
granting a ticket if successful;

195
00:07:32,400 --> 00:07:34,500
kpassword, which is a command that's used

196
00:07:34,500 --> 00:07:36,690
to change the user's Kerberos password;

197
00:07:36,690 --> 00:07:38,430
klist, which is a command used

198
00:07:38,430 --> 00:07:40,230
to list the user's ticket cache;

199
00:07:40,230 --> 00:07:42,270
and kdestroy, which is used to clear

200
00:07:42,270 --> 00:07:43,920
the user's ticket cache.

201
00:07:43,920 --> 00:07:45,870
For example, if I issue the command

202
00:07:45,870 --> 00:07:49,380
kinit user@diontraining.com,

203
00:07:49,380 --> 00:07:51,240
this will prompt for the user's password

204
00:07:51,240 --> 00:07:54,000
that's being stored in the directory server's database.

205
00:07:54,000 --> 00:07:55,740
If they enter the correct password,

206
00:07:55,740 --> 00:07:58,740
this user will obtain a ticket from the Kerberos server.

207
00:07:58,740 --> 00:08:01,950
That user can then issue klist -v

208
00:08:01,950 --> 00:08:03,690
to verify that the ticket they've received

209
00:08:03,690 --> 00:08:06,510
was valid and was properly obtained.

210
00:08:06,510 --> 00:08:08,100
Now, the next thing we need to talk about

211
00:08:08,100 --> 00:08:09,510
in terms of cybersecurity

212
00:08:09,510 --> 00:08:11,970
is what's known as privilege escalation.

213
00:08:11,970 --> 00:08:13,470
Now, privilege escalation occurs

214
00:08:13,470 --> 00:08:15,420
when a user's able to obtain access

215
00:08:15,420 --> 00:08:17,640
to additional resources or functionality

216
00:08:17,640 --> 00:08:20,040
that they're normally not allowed access to.

217
00:08:20,040 --> 00:08:22,710
One of the most common scenarios is when a normal user

218
00:08:22,710 --> 00:08:24,840
is able to exploit some kind of vulnerability

219
00:08:24,840 --> 00:08:26,550
in the system or its software

220
00:08:26,550 --> 00:08:28,590
to gain root-level permissions.

221
00:08:28,590 --> 00:08:30,750
One pitfall of this is that that person

222
00:08:30,750 --> 00:08:33,059
now has the ability to run things as root.

223
00:08:33,059 --> 00:08:34,260
And generally, this happens

224
00:08:34,260 --> 00:08:38,610
because of poorly-configured SUID and SGID permissions.

225
00:08:38,610 --> 00:08:40,590
When you change the permissions of a file

226
00:08:40,590 --> 00:08:43,500
to use either SUID or SGID,

227
00:08:43,500 --> 00:08:45,180
always use the lowest level of permissions

228
00:08:45,180 --> 00:08:46,980
needed to accomplish that task.

229
00:08:46,980 --> 00:08:48,120
This means you're adhering

230
00:08:48,120 --> 00:08:50,280
to the principle of least privilege.

231
00:08:50,280 --> 00:08:51,720
Also, you want to make sure

232
00:08:51,720 --> 00:08:53,250
you're looking at your software programs

233
00:08:53,250 --> 00:08:55,590
and ensure you're only installing things that you trust,

234
00:08:55,590 --> 00:08:56,910
because some software programs

235
00:08:56,910 --> 00:08:58,830
can have a backdoor installed into them,

236
00:08:58,830 --> 00:09:00,240
and that can enable an attacker

237
00:09:00,240 --> 00:09:02,970
to get a remote shell into your system.

238
00:09:02,970 --> 00:09:04,290
Now, to help prevent this,

239
00:09:04,290 --> 00:09:07,170
there is something known as chroot jail.

240
00:09:07,170 --> 00:09:10,020
This is spelled C-H-R-O-O-T.

241
00:09:10,020 --> 00:09:12,810
Now, a chroot jail is a way to isolate a process

242
00:09:12,810 --> 00:09:15,300
and its children from the rest of the system.

243
00:09:15,300 --> 00:09:16,710
For chroot jail to work,

244
00:09:16,710 --> 00:09:18,870
you need to make sure it's only used on processes

245
00:09:18,870 --> 00:09:20,790
that don't need to be run as root,

246
00:09:20,790 --> 00:09:23,760
because a root user can easily break out of the jail.

247
00:09:23,760 --> 00:09:25,440
Now, when you're using chroot jail,

248
00:09:25,440 --> 00:09:27,840
it's really a good thing to do, because it separates out

249
00:09:27,840 --> 00:09:30,180
privileged access on the file system

250
00:09:30,180 --> 00:09:32,250
so that a malicious or rogue process

251
00:09:32,250 --> 00:09:35,550
can't cause damage outside of its jailed environment.

252
00:09:35,550 --> 00:09:38,250
The whole idea here is that you can create a directory tree

253
00:09:38,250 --> 00:09:41,220
where you copy or link in all the system files that you need

254
00:09:41,220 --> 00:09:42,900
for that process to run.

255
00:09:42,900 --> 00:09:44,970
For example, if I use the command

256
00:09:44,970 --> 00:09:49,920
chroot /home/user /usr/bin/bash,

257
00:09:49,920 --> 00:09:53,100
this will create a new root directory using the bash shell

258
00:09:53,100 --> 00:09:56,040
as the process inside of this jail.

259
00:09:56,040 --> 00:09:58,530
The chroot command can be run by typing chroot,

260
00:09:58,530 --> 00:10:01,170
the options, the new root directory you're creating,

261
00:10:01,170 --> 00:10:03,450
in my case, it was /home/user,

262
00:10:03,450 --> 00:10:05,760
and then the command you want to link into it.

263
00:10:05,760 --> 00:10:07,200
Now, another thing you need to be aware of

264
00:10:07,200 --> 00:10:09,330
in terms of security is encryption.

265
00:10:09,330 --> 00:10:12,060
Encryption is a cryptographic technique that converts data

266
00:10:12,060 --> 00:10:15,840
from plaintext into coded or encoded ciphertext.

267
00:10:15,840 --> 00:10:17,310
Now, if you want to read that data again

268
00:10:17,310 --> 00:10:18,570
from its ciphertext form,

269
00:10:18,570 --> 00:10:20,340
you need to do the reverse process,

270
00:10:20,340 --> 00:10:21,960
which is known as decryption.

271
00:10:21,960 --> 00:10:23,550
This is the companion technique

272
00:10:23,550 --> 00:10:26,700
that converts your ciphertext back into plaintext.

273
00:10:26,700 --> 00:10:28,680
Now, an algorithm is known as a cipher,

274
00:10:28,680 --> 00:10:30,960
and this is responsible for this whole conversion

275
00:10:30,960 --> 00:10:33,420
of encrypting and decrypting process.

276
00:10:33,420 --> 00:10:36,000
When a message is encrypted, only authorized parties

277
00:10:36,000 --> 00:10:37,800
with the necessary decryption information,

278
00:10:37,800 --> 00:10:41,490
such as the private key, can decode and read that data.

279
00:10:41,490 --> 00:10:43,950
Encryption is therefore one of the more important

280
00:10:43,950 --> 00:10:46,950
fundamental techniques that we're going to use in cybersecurity

281
00:10:46,950 --> 00:10:49,350
for protecting the confidentiality of data,

282
00:10:49,350 --> 00:10:50,790
because when data is encrypted,

283
00:10:50,790 --> 00:10:53,700
no one can read it except those who have the key.

284
00:10:53,700 --> 00:10:56,370
Encryption can be applied to data as it's going in transit

285
00:10:56,370 --> 00:10:57,750
or passing through a network,

286
00:10:57,750 --> 00:10:59,550
it could be done during data in use,

287
00:10:59,550 --> 00:11:01,470
which is when it's being accessed in memory,

288
00:11:01,470 --> 00:11:02,760
or data at rest,

289
00:11:02,760 --> 00:11:05,670
which is when it's stored on a device or hard drive.

290
00:11:05,670 --> 00:11:08,340
There are several subtypes of data-at-rest encryption,

291
00:11:08,340 --> 00:11:10,410
and two of the most prominent are those known

292
00:11:10,410 --> 00:11:14,100
as disk and drive encryption or file encryption.

293
00:11:14,100 --> 00:11:17,430
Now, when you use full disk encryption, known as FDE,

294
00:11:17,430 --> 00:11:19,200
you're going to encrypt the entire storage drive,

295
00:11:19,200 --> 00:11:20,730
partition, or volume

296
00:11:20,730 --> 00:11:23,190
using either hardware or software utilities,

297
00:11:23,190 --> 00:11:24,810
while file encryption encrypts

298
00:11:24,810 --> 00:11:28,200
only individual files and folders on a given file system

299
00:11:28,200 --> 00:11:30,720
using a particular software utility.

300
00:11:30,720 --> 00:11:33,060
Now, if you're looking for a good platform-independent,

301
00:11:33,060 --> 00:11:36,420
full disk encryption solution, you can look to LUKS,

302
00:11:36,420 --> 00:11:40,920
which is the Linux Unified Key Setup, or L-U-K-S.

303
00:11:40,920 --> 00:11:42,900
The LUKS utility has the ability to encrypt

304
00:11:42,900 --> 00:11:46,290
an entire storage device inside of a Linux environment.

305
00:11:46,290 --> 00:11:50,040
Inside Linux, LUKS will use the dm-crypt subsystem

306
00:11:50,040 --> 00:11:52,080
that was incorporated into the Linux kernel

307
00:11:52,080 --> 00:11:54,120
back in version 2.6.

308
00:11:54,120 --> 00:11:55,890
This subsystem will create a mapping

309
00:11:55,890 --> 00:11:58,650
between an encrypted device and a virtual device name

310
00:11:58,650 --> 00:12:01,260
that the user space software can then work with.

311
00:12:01,260 --> 00:12:04,080
LUKS offers a high degree of compatibility with software

312
00:12:04,080 --> 00:12:07,500
because it standardizes the format of the encrypted devices.

313
00:12:07,500 --> 00:12:09,060
Now, before you encrypt a device,

314
00:12:09,060 --> 00:12:11,670
it's always a good idea to override its contents

315
00:12:11,670 --> 00:12:14,160
with random data or all zeros.

316
00:12:14,160 --> 00:12:16,590
This is known as sanitizing the drive.

317
00:12:16,590 --> 00:12:18,723
This ensures that there's no sensitive data from past use

318
00:12:18,723 --> 00:12:21,090
that is remaining on that drive.

319
00:12:21,090 --> 00:12:23,940
To do this, you can use the shred command.

320
00:12:23,940 --> 00:12:25,920
The shred command is used to securely wipe

321
00:12:25,920 --> 00:12:27,630
a storage device in this manner

322
00:12:27,630 --> 00:12:31,290
by overriding it with a series of random data or zeros.

323
00:12:31,290 --> 00:12:33,030
Another command you're going to come across

324
00:12:33,030 --> 00:12:34,860
is known as cryptsetup.

325
00:12:34,860 --> 00:12:37,260
The cryptsetup command is used as the front-end

326
00:12:37,260 --> 00:12:39,810
to the LUKS and dm-crypt modules.

327
00:12:39,810 --> 00:12:43,020
The LUKS extensions to cryptsetup supports various actions,

328
00:12:43,020 --> 00:12:44,370
including luksFormat,

329
00:12:44,370 --> 00:12:46,200
which is used to format a storage device

330
00:12:46,200 --> 00:12:48,450
using the LUKS encryption standard;

331
00:12:48,450 --> 00:12:50,160
isLuks, which is used to identify

332
00:12:50,160 --> 00:12:52,530
if a given device is a LUKS device;

333
00:12:52,530 --> 00:12:55,470
luksOpen, which is used to open a LUKS storage device

334
00:12:55,470 --> 00:12:56,880
and set it up for mapping,

335
00:12:56,880 --> 00:12:59,130
assuming you have provided the right key;

336
00:12:59,130 --> 00:13:01,050
luksClose, which is used to remove

337
00:13:01,050 --> 00:13:03,000
a LUKS storage device from mapping;

338
00:13:03,000 --> 00:13:05,250
luksAddKey, which is used to associate

339
00:13:05,250 --> 00:13:07,740
a new key material with that LUKS device;

340
00:13:07,740 --> 00:13:09,960
and luksDelKey, which is used to remove

341
00:13:09,960 --> 00:13:12,090
the key material from a LUKS device.

342
00:13:12,090 --> 00:13:14,940
To run cryptsetup, simply type in cryptsetup,

343
00:13:14,940 --> 00:13:18,240
options, action, and the action arguments.

344
00:13:18,240 --> 00:13:20,220
The next thing we're going to talk about is hashing,

345
00:13:20,220 --> 00:13:22,830
and I mentioned earlier that hashing is very important

346
00:13:22,830 --> 00:13:24,780
to the integrity of your data.

347
00:13:24,780 --> 00:13:27,300
Hashing is a process or function that transforms

348
00:13:27,300 --> 00:13:31,020
plaintext input into indecipherable, fixed-length output.

349
00:13:31,020 --> 00:13:34,320
It ensures that this process cannot be easily reversed.

350
00:13:34,320 --> 00:13:36,300
The resulting output of the hashing process

351
00:13:36,300 --> 00:13:40,320
is known as a hash, a hash file, or a message digest.

352
00:13:40,320 --> 00:13:42,120
The input data can vary in length,

353
00:13:42,120 --> 00:13:45,210
but that hash length is always going to be fixed.

354
00:13:45,210 --> 00:13:46,890
Hashing is used in a lot of different

355
00:13:46,890 --> 00:13:48,630
password-authentication schemes,

356
00:13:48,630 --> 00:13:50,340
and hash values can also be embedded

357
00:13:50,340 --> 00:13:53,880
into electronic messages to support data integrity.

358
00:13:53,880 --> 00:13:56,490
Finally, you can hash files and then verify

359
00:13:56,490 --> 00:13:58,710
the integrity of that file after you transfer it

360
00:13:58,710 --> 00:14:01,050
by ensuring that the hash you sent also matched

361
00:14:01,050 --> 00:14:03,783
the hash they calculated when they received the file.

362
00:14:03,783 --> 00:14:05,280
Now, in addition to everything

363
00:14:05,280 --> 00:14:06,450
we've covered up to this point,

364
00:14:06,450 --> 00:14:08,910
we also need to talk about how you can protect your data

365
00:14:08,910 --> 00:14:10,860
as it's going across a network.

366
00:14:10,860 --> 00:14:13,170
So when you're configuring your network configurations,

367
00:14:13,170 --> 00:14:14,850
especially for your web servers,

368
00:14:14,850 --> 00:14:17,850
you always want to enable SSL and TLS.

369
00:14:17,850 --> 00:14:21,210
This guarantees confidentiality and authenticity in the data

370
00:14:21,210 --> 00:14:22,680
as it's being sent and received

371
00:14:22,680 --> 00:14:24,810
from the clients to your servers.

372
00:14:24,810 --> 00:14:27,240
When it comes to all of your different Linux servers,

373
00:14:27,240 --> 00:14:30,750
you do want to configure SSH to disable root access.

374
00:14:30,750 --> 00:14:32,550
This will prevent an authorized user from gaining

375
00:14:32,550 --> 00:14:35,970
complete access over a system from a remote location.

376
00:14:35,970 --> 00:14:38,160
Now, whenever you're doing remote access and receiving

377
00:14:38,160 --> 00:14:40,170
other types of network connections from clients,

378
00:14:40,170 --> 00:14:41,880
you should always configure your system

379
00:14:41,880 --> 00:14:44,400
to deny hosts that it doesn't recognize.

380
00:14:44,400 --> 00:14:46,770
To do this, you'll establish an allow list

381
00:14:46,770 --> 00:14:48,120
of the acceptable hosts

382
00:14:48,120 --> 00:14:50,250
so that all the hosts that are not on that list

383
00:14:50,250 --> 00:14:53,580
are automatically considered untrusted, and blocked.

384
00:14:53,580 --> 00:14:55,230
Finally, you should consider changing

385
00:14:55,230 --> 00:14:58,050
the default port associations for certain services,

386
00:14:58,050 --> 00:15:01,517
like SSH or HTTP or HTTPS,

387
00:15:01,517 --> 00:15:04,110
unless you want those to be easily found.

388
00:15:04,110 --> 00:15:06,510
For example, you might set up your SSH server

389
00:15:06,510 --> 00:15:10,740
to only listen on port 2222 instead of port 22.

390
00:15:10,740 --> 00:15:11,880
This will make it a little bit harder

391
00:15:11,880 --> 00:15:12,837
for attackers to find it,

392
00:15:12,837 --> 00:15:14,940
and it could stop some automated attacks

393
00:15:14,940 --> 00:15:16,620
against well-known ports.

394
00:15:16,620 --> 00:15:20,310
Now realize this is what we call security through obscurity,

395
00:15:20,310 --> 00:15:21,780
and this should not be the only thing

396
00:15:21,780 --> 00:15:23,460
you're doing to secure your systems

397
00:15:23,460 --> 00:15:25,620
by hiding services over different ports,

398
00:15:25,620 --> 00:15:27,600
but it is a little something you can do

399
00:15:27,600 --> 00:15:28,890
to try to make it harder for people

400
00:15:28,890 --> 00:15:31,500
to find out where you're running your services.

401
00:15:31,500 --> 00:15:32,970
Now, if you're running a web server,

402
00:15:32,970 --> 00:15:36,840
you need to understand how to set up SSL and TLS.

403
00:15:36,840 --> 00:15:38,400
If you're running an Apache web server,

404
00:15:38,400 --> 00:15:40,800
which is the most commonly used one on Linux,

405
00:15:40,800 --> 00:15:43,230
you're first going to generate a self-signed certificate

406
00:15:43,230 --> 00:15:45,480
using a tool like OpenSSL,

407
00:15:45,480 --> 00:15:47,700
or you're going to request and obtain a certificate

408
00:15:47,700 --> 00:15:49,650
directly from an external authority,

409
00:15:49,650 --> 00:15:51,930
such as Verisign or Entrust.

410
00:15:51,930 --> 00:15:52,950
Once you have that,

411
00:15:52,950 --> 00:15:55,230
you're going to download it onto your system.

412
00:15:55,230 --> 00:15:59,940
Then you're going to download and install the mod_ssl package.

413
00:15:59,940 --> 00:16:01,080
Once you've done that,

414
00:16:01,080 --> 00:16:03,420
open up the configuration file for your web server,

415
00:16:03,420 --> 00:16:08,420
which is located at /etc/httpd/conf.d/ssl.conf,

416
00:16:12,060 --> 00:16:14,700
and you can edit that file and be able to uncomment

417
00:16:14,700 --> 00:16:16,980
the document root and server name lines

418
00:16:16,980 --> 00:16:19,020
and replace them with the values necessary

419
00:16:19,020 --> 00:16:22,170
to ensure that the SSL engine is set to on.

420
00:16:22,170 --> 00:16:23,940
Also, you want to make sure you point

421
00:16:23,940 --> 00:16:26,010
your SSLCertificateFile to the path

422
00:16:26,010 --> 00:16:28,980
where you downloaded your certificate on your system.

423
00:16:28,980 --> 00:16:32,130
You'll also point your SSLCertificateKeyFile to the path

424
00:16:32,130 --> 00:16:34,170
where your private key is going to be located,

425
00:16:34,170 --> 00:16:36,990
and then you'll restart Apache and open a web browser

426
00:16:36,990 --> 00:16:40,230
and verify that your site is presenting a valid certificate

427
00:16:40,230 --> 00:16:43,080
using either SSL or TLS.

428
00:16:43,080 --> 00:16:44,910
Now, let's talk about user access,

429
00:16:44,910 --> 00:16:47,910
and how you can manage this using some best practices.

430
00:16:47,910 --> 00:16:49,440
This includes being able to protect

431
00:16:49,440 --> 00:16:51,780
your boot loader configuration with a password

432
00:16:51,780 --> 00:16:53,430
to prevent unauthorized personnel

433
00:16:53,430 --> 00:16:55,230
from tampering with the boot options

434
00:16:55,230 --> 00:16:58,830
and enabling a password within your system's BIOS or UEFI

435
00:16:58,830 --> 00:17:01,380
to prevent unauthorized personnel from installing

436
00:17:01,380 --> 00:17:03,810
or booting into a new operating system.

437
00:17:03,810 --> 00:17:06,300
If you're trying to figure out what USB storage devices

438
00:17:06,300 --> 00:17:09,450
are connected to your system, you can use the lsmod command

439
00:17:09,450 --> 00:17:12,750
to search for USB storage or any dependent modules.

440
00:17:12,750 --> 00:17:14,880
If you see any modules you need to unload,

441
00:17:14,880 --> 00:17:17,460
you can use the modprobe -r command

442
00:17:17,460 --> 00:17:20,040
to unload the relevant modules from the kernel.

443
00:17:20,040 --> 00:17:22,200
Then you can prevent those relevant modules

444
00:17:22,200 --> 00:17:24,030
from being loaded again at boot

445
00:17:24,030 --> 00:17:25,680
by creating a block list file

446
00:17:25,680 --> 00:17:29,580
in the /etc/modprobe.d/ directory.

447
00:17:29,580 --> 00:17:32,790
Another key thing to set up is auditing for your users.

448
00:17:32,790 --> 00:17:34,770
You want to ensure that all of your user IDs

449
00:17:34,770 --> 00:17:36,720
are not being shared, and instead,

450
00:17:36,720 --> 00:17:40,680
each user is uniquely logging in using their own user ID.

451
00:17:40,680 --> 00:17:41,880
This will make sure you can audit

452
00:17:41,880 --> 00:17:43,740
all the actions a user's performing,

453
00:17:43,740 --> 00:17:45,390
and that way you can maintain accountability

454
00:17:45,390 --> 00:17:47,580
for each individual user.

455
00:17:47,580 --> 00:17:49,800
Also, you may want to consider establishing

456
00:17:49,800 --> 00:17:52,290
a public key infrastructure to enforce the use

457
00:17:52,290 --> 00:17:54,630
of public and private keys for authentication,

458
00:17:54,630 --> 00:17:56,010
because this is much more secure

459
00:17:56,010 --> 00:17:58,200
than using usernames and passwords.

460
00:17:58,200 --> 00:18:01,140
Another best practice is to restrict access to cron,

461
00:18:01,140 --> 00:18:03,180
which is the Linux job scheduler.

462
00:18:03,180 --> 00:18:05,460
By doing this, you can prevent unauthorized users

463
00:18:05,460 --> 00:18:07,590
from configuring the system to automatically run

464
00:18:07,590 --> 00:18:10,650
malicious or unwanted tasks at regular intervals,

465
00:18:10,650 --> 00:18:12,090
and this will actually bypass their need

466
00:18:12,090 --> 00:18:14,160
to log in and issue the command manually,

467
00:18:14,160 --> 00:18:15,630
and so you don't want to do that.

468
00:18:15,630 --> 00:18:17,820
Again, you want to make it harder for attackers

469
00:18:17,820 --> 00:18:20,550
to break into your system and do bad things.

470
00:18:20,550 --> 00:18:23,640
Finally, you should disable the use of Ctrl+Alt+Del

471
00:18:23,640 --> 00:18:25,440
to prevent users from rebooting a system

472
00:18:25,440 --> 00:18:28,200
and disrupting service availability if this is a server

473
00:18:28,200 --> 00:18:31,200
that needs to remain up and online at all times.

474
00:18:31,200 --> 00:18:33,390
All right, a couple of more best practices to cover,

475
00:18:33,390 --> 00:18:35,250
and we'll finish up this lesson.

476
00:18:35,250 --> 00:18:38,100
Next, we need to talk about the auditd service.

477
00:18:38,100 --> 00:18:40,320
The auditd service is an audit daemon,

478
00:18:40,320 --> 00:18:42,030
and it enables records to be used

479
00:18:42,030 --> 00:18:43,920
to audit what is being written to storage

480
00:18:43,920 --> 00:18:45,780
and what actions are happening.

481
00:18:45,780 --> 00:18:47,880
Another thing you can do is you can modify

482
00:18:47,880 --> 00:18:51,240
the /etc/issue file to add a banner message

483
00:18:51,240 --> 00:18:52,890
that will display useful information

484
00:18:52,890 --> 00:18:55,410
every time a user logs into the system.

485
00:18:55,410 --> 00:18:57,540
We can also separate out our operating system

486
00:18:57,540 --> 00:18:59,970
and our other data, like application files,

487
00:18:59,970 --> 00:19:01,290
into different partitions,

488
00:19:01,290 --> 00:19:03,030
and this will give us a little more segmentation

489
00:19:03,030 --> 00:19:05,100
and a little bit more security.

490
00:19:05,100 --> 00:19:06,630
Additionally, you want to make sure

491
00:19:06,630 --> 00:19:08,970
you're regularly monitoring for common vulnerabilities

492
00:19:08,970 --> 00:19:13,323
and exposures in the CVE database at cve.mitre.org,

493
00:19:14,400 --> 00:19:17,370
which is the MITRE database called CVE.

494
00:19:17,370 --> 00:19:19,860
This is a website that contains all of the vulnerabilities

495
00:19:19,860 --> 00:19:22,530
for every software application and operating system

496
00:19:22,530 --> 00:19:23,550
that they know about.

497
00:19:23,550 --> 00:19:25,290
And so, if you do that, you'll be able to figure out,

498
00:19:25,290 --> 00:19:27,180
is there anything vulnerable on your system

499
00:19:27,180 --> 00:19:29,340
that you might need to patch and fix.

500
00:19:29,340 --> 00:19:30,750
And finally, you want to make sure

501
00:19:30,750 --> 00:19:33,720
you're hardening your system by disabling or uninstalling

502
00:19:33,720 --> 00:19:36,240
any unused or insecure services.

503
00:19:36,240 --> 00:19:38,400
Remember, services are things that are running

504
00:19:38,400 --> 00:19:39,957
in the background of your Linux system,

505
00:19:39,957 --> 00:19:41,700
and if there's a vulnerability in it,

506
00:19:41,700 --> 00:19:43,620
it means an attacker can attack that

507
00:19:43,620 --> 00:19:46,260
and take control of your system at any time.

508
00:19:46,260 --> 00:19:48,780
There's lots of popular attacks for different services,

509
00:19:48,780 --> 00:19:52,890
like FTP, Telnet, Finger, Sendmail, and Postfix,

510
00:19:52,890 --> 00:19:54,480
just to name a few.

511
00:19:54,480 --> 00:19:55,920
All right, when it comes to implementing

512
00:19:55,920 --> 00:19:57,870
your cybersecurity best practices,

513
00:19:57,870 --> 00:20:00,660
your goal is to protect the confidentiality, integrity,

514
00:20:00,660 --> 00:20:03,810
and availability of the information on your system.

515
00:20:03,810 --> 00:20:05,760
To help with this, you should consider using

516
00:20:05,760 --> 00:20:09,210
advanced authentication mechanisms like LDAP and Kerberos

517
00:20:09,210 --> 00:20:11,790
to centralize your authentication for your users.

518
00:20:11,790 --> 00:20:13,530
Additionally, you might want to consider

519
00:20:13,530 --> 00:20:15,480
using multifactor authentication,

520
00:20:15,480 --> 00:20:18,300
so that way people have to use a username and a password

521
00:20:18,300 --> 00:20:19,410
as well as something like

522
00:20:19,410 --> 00:20:22,320
a biometric fingerprint or a token.

523
00:20:22,320 --> 00:20:24,090
You also want to make sure that you're not granting

524
00:20:24,090 --> 00:20:25,830
more access than is necessary

525
00:20:25,830 --> 00:20:28,350
for any particular file or user.

526
00:20:28,350 --> 00:20:30,360
You can do this by verifying you have the right

527
00:20:30,360 --> 00:20:33,600
SUID and SGID properties set.

528
00:20:33,600 --> 00:20:34,890
You also want to make sure you're placing

529
00:20:34,890 --> 00:20:37,860
any unprivileged processes into chroot jails

530
00:20:37,860 --> 00:20:39,030
to prevent them from accessing

531
00:20:39,030 --> 00:20:41,040
other parts of the file system.

532
00:20:41,040 --> 00:20:42,360
Anytime you're dealing with data,

533
00:20:42,360 --> 00:20:44,010
it's always best to encrypt it,

534
00:20:44,010 --> 00:20:45,480
so you want to encrypt sensitive data

535
00:20:45,480 --> 00:20:47,970
while it's in transit, in use, or at rest,

536
00:20:47,970 --> 00:20:49,680
and you can do this using LUKS

537
00:20:49,680 --> 00:20:52,020
to fully encrypt your storage devices.

538
00:20:52,020 --> 00:20:54,480
When it comes to networking, make sure you're doing things

539
00:20:54,480 --> 00:20:56,760
like limiting root access over SSH,

540
00:20:56,760 --> 00:20:58,830
implement user access best practices

541
00:20:58,830 --> 00:21:00,540
to make sure people aren't sharing IDs,

542
00:21:00,540 --> 00:21:02,910
and implement the best practices like separating

543
00:21:02,910 --> 00:21:05,610
your operating system data and your application data

544
00:21:05,610 --> 00:21:08,163
by placing them on different partitions or volumes.

