1
1

00:00:00,350  -->  00:00:02,420
<v ->Threats and vulnerabilities.</v>
2

2

00:00:02,420  -->  00:00:04,000
In this lesson, we're going to talk
3

3

00:00:04,000  -->  00:00:05,750
about threats and vulnerabilities.
4

4

00:00:05,750  -->  00:00:08,350
After all, where threats and vulnerabilities intersect
5

5

00:00:08,350  -->  00:00:11,180
is where risk exists within our enterprise networks.
6

6

00:00:11,180  -->  00:00:12,830
So if we can understand the different threats
7

7

00:00:12,830  -->  00:00:14,890
and vulnerabilities we may have in our networks,
8

8

00:00:14,890  -->  00:00:16,540
we can then add protection mechanisms
9

9

00:00:16,540  -->  00:00:18,410
to help mitigate that risk.
10

10

00:00:18,410  -->  00:00:20,290
Often, I hear people use the words threats
11

11

00:00:20,290  -->  00:00:22,080
and vulnerability interchangeably,
12

12

00:00:22,080  -->  00:00:24,710
but they're technically not the same thing.
13

13

00:00:24,710  -->  00:00:27,300
A threat is a person or an event that has the potential
14

14

00:00:27,300  -->  00:00:30,350
for impacting a valuable resource in a negative manner.
15

15

00:00:30,350  -->  00:00:32,090
So a hacker will be a threat
16

16

00:00:32,090  -->  00:00:35,010
since they want to steal your data, but so is a hurricane,
17

17

00:00:35,010  -->  00:00:36,400
because it could cause a power outage
18

18

00:00:36,400  -->  00:00:38,400
that takes down your valuable network.
19

19

00:00:38,400  -->  00:00:39,930
Now, a vulnerability on the other,
20

20

00:00:39,930  -->  00:00:42,483
is a quality or characteristic within a given resource
21

21

00:00:42,483  -->  00:00:44,820
or it's environment that might allow the threat
22

22

00:00:44,820  -->  00:00:46,010
to be realized.
23

23

00:00:46,010  -->  00:00:48,150
Now essentially, a vulnerability is any weakness
24

24

00:00:48,150  -->  00:00:50,230
in the system design, implementation,
25

25

00:00:50,230  -->  00:00:52,870
source code or lack of preventive mechanisms
26

26

00:00:52,870  -->  00:00:54,750
that would prevent a threat from occurring.
27

27

00:00:54,750  -->  00:00:57,350
So for example, if you're not running the latest version
28

28

00:00:57,350  -->  00:00:59,140
of Microsoft Windows on your servers,
29

29

00:00:59,140  -->  00:01:01,280
that is considered a vulnerability.
30

30

00:01:01,280  -->  00:01:02,810
If you have a battery back up for your network
31

31

00:01:02,810  -->  00:01:03,897
that only lasts 15 min
32

32

00:01:03,897  -->  00:01:05,700
and you don't have any back up generators,
33

33

00:01:05,700  -->  00:01:07,440
that again, is a vulnerability,
34

34

00:01:07,440  -->  00:01:08,830
because if you loose power,
35

35

00:01:08,830  -->  00:01:12,020
after 15 minutes, the entire network is going to crash on you.
36

36

00:01:12,020  -->  00:01:14,400
Now, it's only going to be when combine a threat
37

37

00:01:14,400  -->  00:01:16,421
with a vulnerability that we actually get risk
38

38

00:01:16,421  -->  00:01:20,030
that's being realized and now something bad will occur.
39

39

00:01:20,030  -->  00:01:21,750
This is an important distinction,
40

40

00:01:21,750  -->  00:01:24,270
because if I have device, like a switch or a router
41

41

00:01:24,270  -->  00:01:26,610
and it has a vulnerability, but there's no threats
42

42

00:01:26,610  -->  00:01:28,270
that would ever go after that vulnerability,
43

43

00:01:28,270  -->  00:01:29,200
then guess what?
44

44

00:01:29,200  -->  00:01:30,920
There's not really a risk there.
45

45

00:01:30,920  -->  00:01:32,540
On the other hand, if I have an asset
46

46

00:01:32,540  -->  00:01:34,210
that doesn't have any vulnerabilities,
47

47

00:01:34,210  -->  00:01:36,190
then it doesn't matter if I have dedicated threat
48

48

00:01:36,190  -->  00:01:38,160
trying to attack me, because they won't ever be able
49

49

00:01:38,160  -->  00:01:39,680
to cause any harm to my network,
50

50

00:01:39,680  -->  00:01:41,650
because there's absolutely not vulnerabilities
51

51

00:01:41,650  -->  00:01:43,030
for them to exploit.
52

52

00:01:43,030  -->  00:01:44,260
Now, in the real world,
53

53

00:01:44,260  -->  00:01:46,060
there's almost always some kind of threat
54

54

00:01:46,060  -->  00:01:47,910
and some kind of vulnerability out there
55

55

00:01:47,910  -->  00:01:49,020
that we're going to be facing,
56

56

00:01:49,020  -->  00:01:50,940
so we almost always have risk.
57

57

00:01:50,940  -->  00:01:52,100
The amount of risk though,
58

58

00:01:52,100  -->  00:01:54,330
is really going to be determined by how big of a threat
59

59

00:01:54,330  -->  00:01:57,070
or how major of a vulnerability we actually have.
60

60

00:01:57,070  -->  00:01:58,981
So let's dive into threats and vulnerabilities
61

61

00:01:58,981  -->  00:02:00,630
a bit deeper here.
62

62

00:02:00,630  -->  00:02:02,610
First, let's cover threats.
63

63

00:02:02,610  -->  00:02:04,670
Threats come in two basic varieties.
64

64

00:02:04,670  -->  00:02:07,270
We have internal threats and external threats.
65

65

00:02:07,270  -->  00:02:08,990
Now, an internal threat is any threat
66

66

00:02:08,990  -->  00:02:11,550
that originates from within the organization itself.
67

67

00:02:11,550  -->  00:02:13,580
Normally, these are conducted by a current
68

68

00:02:13,580  -->  00:02:15,420
or former employee, a contractor
69

69

00:02:15,420  -->  00:02:17,500
or a business partner who's going to cause damage
70

70

00:02:17,500  -->  00:02:19,410
to your systems or steal your data.
71

71

00:02:19,410  -->  00:02:20,830
When we're dealing with internal threats,
72

72

00:02:20,830  -->  00:02:21,990
these can be caused by people
73

73

00:02:21,990  -->  00:02:25,660
who intend to do us harm or those who do it accidentally.
74

74

00:02:25,660  -->  00:02:27,930
For example, if you have insider threat,
75

75

00:02:27,930  -->  00:02:30,790
this could be a person who uses their authorized access
76

76

00:02:30,790  -->  00:02:33,690
to get onto your network and harm your organization.
77

77

00:02:33,690  -->  00:02:35,630
Maybe you had an employee who just got passed over
78

78

00:02:35,630  -->  00:02:38,470
for a promotion and now they're pretty upset.
79

79

00:02:38,470  -->  00:02:39,475
So they decide to download
80

80

00:02:39,475  -->  00:02:41,740
your entire client contact database
81

81

00:02:41,740  -->  00:02:43,860
to their thumb drive and take it home with them,
82

82

00:02:43,860  -->  00:02:46,080
that way, if they decide to quit next week,
83

83

00:02:46,080  -->  00:02:47,910
they can start calling up all of your clients
84

84

00:02:47,910  -->  00:02:49,370
and bring them over to a new company
85

85

00:02:49,370  -->  00:02:50,990
that will end up hiring them.
86

86

00:02:50,990  -->  00:02:53,020
On the other hand, you may also have an end user
87

87

00:02:53,020  -->  00:02:55,490
who unknowingly causes damage to your systems,
88

88

00:02:55,490  -->  00:02:57,320
for example, we may have a sales person
89

89

00:02:57,320  -->  00:02:59,490
who opens up an email that contains malware
90

90

00:02:59,490  -->  00:03:01,950
and this starts infecting your systems and your servers.
91

91

00:03:01,950  -->  00:03:03,670
Now, that person, they weren't being malicious,
92

92

00:03:03,670  -->  00:03:05,150
they didn't do this on purpose.
93

93

00:03:05,150  -->  00:03:06,528
They just opened an email and they didn't think
94

94

00:03:06,528  -->  00:03:08,250
that it would cause any problems.
95

95

00:03:08,250  -->  00:03:11,140
This is an unwitting or unknowing internal threat.
96

96

00:03:11,140  -->  00:03:12,750
Now, in addition to internal threats,
97

97

00:03:12,750  -->  00:03:14,700
we also have external threats.
98

98

00:03:14,700  -->  00:03:16,960
External threats could be people, like a hacker,
99

99

00:03:16,960  -->  00:03:19,430
or it can be an event or environmental condition,
100

100

00:03:19,430  -->  00:03:22,590
for example, if I was going to have a wildfire near my office,
101

101

00:03:22,590  -->  00:03:25,350
that would be an environmental threat against my facility
102

102

00:03:25,350  -->  00:03:27,010
and the network that it contains,
103

103

00:03:27,010  -->  00:03:29,130
or maybe I'm working as the IT director
104

104

00:03:29,130  -->  00:03:30,360
for a large oil company
105

105

00:03:30,360  -->  00:03:32,010
and I have a lot of angry hacktivists
106

106

00:03:32,010  -->  00:03:33,230
who want to take down my network,
107

107

00:03:33,230  -->  00:03:35,280
because they don't agree with our company's policies
108

108

00:03:35,280  -->  00:03:37,570
concerning drilling within the Alaskan wilderness.
109

109

00:03:37,570  -->  00:03:39,760
This would also be considered an external threat,
110

110

00:03:39,760  -->  00:03:41,940
because it's something external to my organization,
111

111

00:03:41,940  -->  00:03:44,910
these hacktivists or hacker who are trying to break in.
112

112

00:03:44,910  -->  00:03:46,620
Now next, we need to talk a little more
113

113

00:03:46,620  -->  00:03:48,070
about the types of vulnerabilities
114

114

00:03:48,070  -->  00:03:50,760
that we can have in our organizations and its networks.
115

115

00:03:50,760  -->  00:03:52,910
Remember, a vulnerability is any weakness
116

116

00:03:52,910  -->  00:03:54,940
in the system design, implementation,
117

117

00:03:54,940  -->  00:03:57,660
software code or a lack of preventive measure
118

118

00:03:57,660  -->  00:03:58,850
in your systems.
119

119

00:03:58,850  -->  00:04:01,140
Now, these can take the form of environmental,
120

120

00:04:01,140  -->  00:04:04,270
physical, operational or technical vulnerabilities.
121

121

00:04:04,270  -->  00:04:06,310
When we talk about environmental vulnerabilities,
122

122

00:04:06,310  -->  00:04:09,020
these are focused on undesirable conditions or weaknesses
123

123

00:04:09,020  -->  00:04:11,220
that are in the general area surrounding your building
124

124

00:04:11,220  -->  00:04:12,980
where you're going to operate your networks.
125

125

00:04:12,980  -->  00:04:16,120
So for example, my company is based out of Puerto Rico,
126

126

00:04:16,120  -->  00:04:18,440
so we have he ever-present threat of hurricanes
127

127

00:04:18,440  -->  00:04:20,800
and earthquakes that could exploit a vulnerability
128

128

00:04:20,800  -->  00:04:22,810
and how we provide services to our office,
129

129

00:04:22,810  -->  00:04:25,950
including our power, water, heating and air-conditioning.
130

130

00:04:25,950  -->  00:04:28,870
So to mitigate this, we actually have four sources of power
131

131

00:04:28,870  -->  00:04:31,020
at our facility, including solar power,
132

132

00:04:31,020  -->  00:04:32,610
a full building battery back-up,
133

133

00:04:32,610  -->  00:04:34,270
a diesel generator and of course,
134

134

00:04:34,270  -->  00:04:36,580
our local power grid from the electric company.
135

135

00:04:36,580  -->  00:04:38,130
Physical vulnerabilities are focused
136

136

00:04:38,130  -->  00:04:40,140
on undesirable conditions or weaknesses
137

137

00:04:40,140  -->  00:04:42,260
in the buildings where you operate your networks.
138

138

00:04:42,260  -->  00:04:44,320
Now, some examples of physical vulnerabilities,
139

139

00:04:44,320  -->  00:04:46,090
might be things like unlocked doors,
140

140

00:04:46,090  -->  00:04:48,940
unmonitored hallways, misconfigured sprinkler systems
141

141

00:04:48,940  -->  00:04:51,020
or cables that are running across the floor.
142

142

00:04:51,020  -->  00:04:52,710
These things could lead to a threat actor
143

143

00:04:52,710  -->  00:04:54,040
being able to get into your building
144

144

00:04:54,040  -->  00:04:56,248
and stealing all your data or a fire could break out
145

145

00:04:56,248  -->  00:04:58,450
and cause massive amounts of damage,
146

146

00:04:58,450  -->  00:05:00,950
or maybe somebody will trip over a misplaced cable
147

147

00:05:00,950  -->  00:05:04,190
and that will cause damage to themselves or to your network.
148

148

00:05:04,190  -->  00:05:06,248
Operational vulnerabilities are focused on how the network
149

149

00:05:06,248  -->  00:05:07,860
and its systems are being run
150

150

00:05:07,860  -->  00:05:10,220
from a policy and procedure perspective.
151

151

00:05:10,220  -->  00:05:12,580
These vulnerabilities or weaknesses usually result
152

152

00:05:12,580  -->  00:05:15,090
from either poorly worded or unenforceable policies
153

153

00:05:15,090  -->  00:05:16,740
within your organization.
154

154

00:05:16,740  -->  00:05:18,910
This can allow a threat actor to exploit weaknesses
155

155

00:05:18,910  -->  00:05:21,230
in these policies to their own advantage.
156

156

00:05:21,230  -->  00:05:22,610
Now, technical vulnerabilities
157

157

00:05:22,610  -->  00:05:24,240
are system-specific conditions
158

158

00:05:24,240  -->  00:05:26,120
that create a weakness in our security.
159

159

00:05:26,120  -->  00:05:27,790
This includes misconfigurations,
160

160

00:05:27,790  -->  00:05:29,810
outdated hardware, malicious software
161

161

00:05:29,810  -->  00:05:31,350
and other technical weaknesses
162

162

00:05:31,350  -->  00:05:33,650
in the implementation or operation of our networks
163

163

00:05:33,650  -->  00:05:34,850
and its devices.
164

164

00:05:34,850  -->  00:05:36,560
When it comes to technical vulnerabilities
165

165

00:05:36,560  -->  00:05:38,920
that focus on network or system exploitation,
166

166

00:05:38,920  -->  00:05:41,580
we normally are going to classify these as a CVE
167

167

00:05:41,580  -->  00:05:43,390
or a zero-day vulnerability.
168

168

00:05:43,390  -->  00:05:46,260
Now, CVE or the common vulnerabilities and exposures
169

169

00:05:46,260  -->  00:05:48,230
are going to be a list of publicly disclosed
170

170

00:05:48,230  -->  00:05:50,610
computer security weaknesses or flaws.
171

171

00:05:50,610  -->  00:05:52,028
Basically, it's an official list
172

172

00:05:52,028  -->  00:05:54,060
of all the known technical vulnerabilities
173

173

00:05:54,060  -->  00:05:55,600
for each and every piece of software
174

174

00:05:55,600  -->  00:05:57,080
that's publicly available.
175

175

00:05:57,080  -->  00:05:58,960
When you look up a CVE, for example,
176

176

00:05:58,960  -->  00:06:01,100
you might see something like CVE-2017-0144
177

177

00:06:04,340  -->  00:06:05,280
and then you can look at that
178

178

00:06:05,280  -->  00:06:07,240
and read all about that vulnerability,
179

179

00:06:07,240  -->  00:06:09,250
what it is, what software it affects
180

180

00:06:09,250  -->  00:06:11,850
and a list of references, so you can learn more about it.
181

181

00:06:11,850  -->  00:06:15,350
Now, in the case of CVE-2017-0144,
182

182

00:06:15,350  -->  00:06:17,430
this was the 144th vulnerability
183

183

00:06:17,430  -->  00:06:19,790
that was disclosed in the year 2017.
184

184

00:06:19,790  -->  00:06:22,650
This particular CVE was actually a really serious one
185

185

00:06:22,650  -->  00:06:25,170
and it was one that was exploited by the WannaCry ransomware
186

186

00:06:25,170  -->  00:06:27,180
that spread rapidly across the globe.
187

187

00:06:27,180  -->  00:06:28,900
Due to its widespread exploitation,
188

188

00:06:28,900  -->  00:06:29,879
it also received a codename
189

189

00:06:29,879  -->  00:06:31,820
and became knows as EternalBlue.
190

190

00:06:31,820  -->  00:06:34,087
Now, EternalBlue affected Windows Vista,
191

191

00:06:34,087  -->  00:06:36,670
Windows 7, Windows 8, Windows 10
192

192

00:06:36,670  -->  00:06:38,200
on desktop and laptop computers
193

193

00:06:38,200  -->  00:06:39,820
and then also, Windows server 2008,
194

194

00:06:39,820  -->  00:06:43,560
2012 and 2016 on servers.
195

195

00:06:43,560  -->  00:06:45,670
This vulnerability allowed an attacker
196

196

00:06:45,670  -->  00:06:47,890
to be able to remotely execute arbitrate code
197

197

00:06:47,890  -->  00:06:50,030
via well-crafted packets over the network
198

198

00:06:50,030  -->  00:06:52,800
that could lead to a remote code execution vulnerability.
199

199

00:06:52,800  -->  00:06:54,570
Now, for the network plus exam,
200

200

00:06:54,570  -->  00:06:57,360
you don't need to know specifics of the EternalBlue exploit,
201

201

00:06:57,360  -->  00:06:59,690
but you should be aware of what a CVE is
202

202

00:06:59,690  -->  00:07:01,390
and the kind of information it can give you
203

203

00:07:01,390  -->  00:07:02,950
as a network administrator.
204

204

00:07:02,950  -->  00:07:04,790
So while CVEs provide us with a list
205

205

00:07:04,790  -->  00:07:06,170
of all the known vulnerabilities,
206

206

00:07:06,170  -->  00:07:07,707
there's also a lot of unknown vulnerabilities
207

207

00:07:07,707  -->  00:07:09,480
that may be out there too.
208

208

00:07:09,480  -->  00:07:11,830
These are known as zero-day vulnerabilities.
209

209

00:07:11,830  -->  00:07:14,090
Now, a zero-day vulnerability is any weakness
210

210

00:07:14,090  -->  00:07:16,060
in the system design, implementation,
211

211

00:07:16,060  -->  00:07:18,470
software code or a lack of preventive mechanisms
212

212

00:07:18,470  -->  00:07:20,100
within a given system or network
213

213

00:07:20,100  -->  00:07:22,700
that is unknown at the time of publication.
214

214

00:07:22,700  -->  00:07:24,620
Now, basically a zero-day vulnerability
215

215

00:07:24,620  -->  00:07:27,600
is a new vulnerability that not everyone is aware of.
216

216

00:07:27,600  -->  00:07:29,430
Once cybersecurity professionals become aware
217

217

00:07:29,430  -->  00:07:31,530
of this vulnerability, they're going to report it
218

218

00:07:31,530  -->  00:07:34,110
and a CVE will be created for that zero-day,
219

219

00:07:34,110  -->  00:07:36,250
making it no longer a zero-day
220

220

00:07:36,250  -->  00:07:38,630
and now it's going to be called a CVE.
221

221

00:07:38,630  -->  00:07:42,040
So remember, CVEs are a list of known vulnerabilities,
222

222

00:07:42,040  -->  00:07:44,370
while a zero-day is a brand new vulnerability
223

223

00:07:44,370  -->  00:07:47,020
that no one else has discovered or reported yet.
224

224

00:07:47,020  -->  00:07:50,340
Finally, let's talk about how a vulnerability is attacked.
225

225

00:07:50,340  -->  00:07:52,840
After all, a vulnerability is just a weakness,
226

226

00:07:52,840  -->  00:07:54,980
but until it's attacked or exploited,
227

227

00:07:54,980  -->  00:07:56,750
as we like to call it in the cybersecurity world,
228

228

00:07:56,750  -->  00:07:57,610
it's just sitting there
229

229

00:07:57,610  -->  00:07:59,400
and it's really not hurting anyone.
230

230

00:07:59,400  -->  00:08:00,650
When you take advantage of a vulnerability
231

231

00:08:00,650  -->  00:08:02,340
as a threat actor, this is called,
232

232

00:08:02,340  -->  00:08:03,940
exploiting the vulnerability.
233

233

00:08:03,940  -->  00:08:06,110
We do this using an exploit.
234

234

00:08:06,110  -->  00:08:08,050
Now, an exploit is a piece of software code
235

235

00:08:08,050  -->  00:08:09,620
that takes advantage of a security flaw
236

236

00:08:09,620  -->  00:08:11,860
or vulnerability within a system or network.
237

237

00:08:11,860  -->  00:08:13,950
Because CVEs are known vulnerabilities,
238

238

00:08:13,950  -->  00:08:16,090
most of them have a matching exploit.
239

239

00:08:16,090  -->  00:08:17,590
This is because when a new vulnerability
240

240

00:08:17,590  -->  00:08:18,890
is discovered and reported,
241

241

00:08:18,890  -->  00:08:21,070
a patch is created by the software's creators.
242

242

00:08:21,070  -->  00:08:23,253
For example, if a new zero-day vulnerability was discovered
243

243

00:08:23,253  -->  00:08:26,250
in Windows 10, then Microsoft will create a software patch
244

244

00:08:26,250  -->  00:08:28,240
to fix this vulnerability and they will release
245

245

00:08:28,240  -->  00:08:30,620
that software patch and a CVE to the public
246

246

00:08:30,620  -->  00:08:32,100
so we can all know about it.
247

247

00:08:32,100  -->  00:08:34,370
Now at the same time, attackers are going to reverse engineer
248

248

00:08:34,370  -->  00:08:36,660
that software patch and research the CVE
249

249

00:08:36,660  -->  00:08:37,693
to determine what vulnerability
250

250

00:08:37,693  -->  00:08:39,610
that patch is trying to solve.
251

251

00:08:39,610  -->  00:08:41,260
Then they can create some code
252

252

00:08:41,260  -->  00:08:43,040
that will take advantage of that vulnerability
253

253

00:08:43,040  -->  00:08:45,490
if a system isn't properly patched and updated.
254

254

00:08:45,490  -->  00:08:47,550
Since many people don't patch their systems right away
255

255

00:08:47,550  -->  00:08:49,260
using the latest security patches,
256

256

00:08:49,260  -->  00:08:50,696
this means, there's a period of time
257

257

00:08:50,696  -->  00:08:53,680
where a lot of Windows systems may still be vulnerable
258

258

00:08:53,680  -->  00:08:55,800
and so, we can actually use this exploit
259

259

00:08:55,800  -->  00:08:57,500
to attack those vulnerable systems
260

260

00:08:57,500  -->  00:09:00,320
for weeks or months after the release of a patch.
261

261

00:09:00,320  -->  00:09:02,440
So now the attackers have a working exploit
262

262

00:09:02,440  -->  00:09:04,360
for this vulnerability and they can find
263

263

00:09:04,360  -->  00:09:06,330
any unpatched Windows 10 machines out there
264

264

00:09:06,330  -->  00:09:08,510
and exploit them by running their new software code
265

265

00:09:08,510  -->  00:09:10,410
against those unpatched systems.
266

266

00:09:10,410  -->  00:09:12,290
This exploit code is often incorporated
267

267

00:09:12,290  -->  00:09:14,173
into malware and this allows it to propagate
268

268

00:09:14,173  -->  00:09:17,270
and run intricate scripts against vulnerable computers,
269

269

00:09:17,270  -->  00:09:18,403
therefore, increasing the damage
270

270

00:09:18,403  -->  00:09:21,170
that these attackers can do with this exploit.
271

271

00:09:21,170  -->  00:09:22,520
To prevent this, you need to ensure
272

272

00:09:22,520  -->  00:09:23,710
your systems remain up to date
273

273

00:09:23,710  -->  00:09:25,560
and patched with the latest security releases
274

274

00:09:25,560  -->  00:09:26,500
and ensure that your systems
275

275

00:09:26,500  -->  00:09:28,080
have an up-to-date anti-malware
276

276

00:09:28,080  -->  00:09:30,340
or anti-virus software installed to protect them
277

277

00:09:30,340  -->  00:09:31,990
from these known vulnerabilities.
