1
00:00:00,000 --> 00:00:00,833
In this lesson

2
00:00:00,833 --> 00:00:02,850
we are going to cover the different concepts related

3
00:00:02,850 --> 00:00:04,920
to threat vectors and attack surfaces.

4
00:00:04,920 --> 00:00:07,290
Before we dive into the different threat vectors

5
00:00:07,290 --> 00:00:08,640
that you should be aware of

6
00:00:08,640 --> 00:00:11,395
we need to take a moment to define a threat vector

7
00:00:11,395 --> 00:00:13,140
and an attack surface.

8
00:00:13,140 --> 00:00:15,960
A threat vector refers to the means or pathway

9
00:00:15,960 --> 00:00:18,990
by which an attacker can gain unauthorized access

10
00:00:18,990 --> 00:00:20,850
to a computer or network

11
00:00:20,850 --> 00:00:22,770
to deliver a malicious payload

12
00:00:22,770 --> 00:00:25,140
or carry out an unwanted action.

13
00:00:25,140 --> 00:00:28,050
The attack surface of a system or network on the other hand

14
00:00:28,050 --> 00:00:30,240
encompasses all the various points

15
00:00:30,240 --> 00:00:33,240
where an unauthorized user can try to enter data

16
00:00:33,240 --> 00:00:35,400
or extract data from the environment.

17
00:00:35,400 --> 00:00:38,250
Basically, this attack surface represents the sum

18
00:00:38,250 --> 00:00:39,990
of all potential vulnerabilities

19
00:00:39,990 --> 00:00:42,630
and entry points that an attacker could exploit.

20
00:00:42,630 --> 00:00:44,070
I like to think of the threat vector

21
00:00:44,070 --> 00:00:45,510
as the how of an attack

22
00:00:45,510 --> 00:00:49,020
whereas the attack surface is the aware of the attack.

23
00:00:49,020 --> 00:00:50,820
Now, when it comes to the attack surface

24
00:00:50,820 --> 00:00:53,250
you can consider the whole network at once,

25
00:00:53,250 --> 00:00:55,470
but it's often easier to break down the network

26
00:00:55,470 --> 00:00:57,540
into smaller parts for analysis.

27
00:00:57,540 --> 00:01:00,570
Then each of these attack surfaces can be minimized

28
00:01:00,570 --> 00:01:01,830
by restricting access,

29
00:01:01,830 --> 00:01:03,600
removing unnecessary software,

30
00:01:03,600 --> 00:01:05,610
and disabling unused protocols

31
00:01:05,610 --> 00:01:07,050
on the portion of the network

32
00:01:07,050 --> 00:01:09,420
to significantly increase their security posture

33
00:01:09,420 --> 00:01:10,890
of your networks.

34
00:01:10,890 --> 00:01:13,770
For instance, the use of email and instant messaging

35
00:01:13,770 --> 00:01:16,770
within an organization will expand its attack surface

36
00:01:16,770 --> 00:01:19,620
since this provides additional avenues that could be used

37
00:01:19,620 --> 00:01:21,900
as a part of a phishing campaign.

38
00:01:21,900 --> 00:01:24,060
Similarly, the use of removable devices

39
00:01:24,060 --> 00:01:27,480
or unsecured networks can also increase the attack surface

40
00:01:27,480 --> 00:01:29,760
by introducing additional vulnerabilities

41
00:01:29,760 --> 00:01:31,770
that an attacker could exploit.

42
00:01:31,770 --> 00:01:34,050
So now that we understand some of the basics

43
00:01:34,050 --> 00:01:36,000
of threat actors and attack surfaces,

44
00:01:36,000 --> 00:01:38,430
let's take a look at several different threat vectors

45
00:01:38,430 --> 00:01:40,980
that could be used to attack your enterprise networks,

46
00:01:40,980 --> 00:01:44,580
including messages, images, files, voice calls,

47
00:01:44,580 --> 00:01:45,690
removable devices,

48
00:01:45,690 --> 00:01:47,250
and unsecure networks.

49
00:01:47,250 --> 00:01:48,810
First, we have messages.

50
00:01:48,810 --> 00:01:51,300
Message-based threat vectors include threats delivered

51
00:01:51,300 --> 00:01:55,230
by email, short message service or SMS,

52
00:01:55,230 --> 00:01:57,540
or other forms of instant messaging.

53
00:01:57,540 --> 00:01:59,730
Phishing campaigns are commonly used as a part

54
00:01:59,730 --> 00:02:01,530
of a message-based threat vector

55
00:02:01,530 --> 00:02:04,530
where an attacker impersonates a trusted entity

56
00:02:04,530 --> 00:02:05,520
to trick its victims

57
00:02:05,520 --> 00:02:08,759
into revealing their sensitive information to the attacker.

58
00:02:08,759 --> 00:02:10,949
These messages can also contain malicious links

59
00:02:10,949 --> 00:02:14,010
or attachments to try and install malware, Trojans,

60
00:02:14,010 --> 00:02:16,950
and viruses on a given system or network.

61
00:02:16,950 --> 00:02:19,200
For example, if you receive an email stating

62
00:02:19,200 --> 00:02:20,910
that you want a brand new iPhone,

63
00:02:20,910 --> 00:02:23,430
and all you need to do is click on the link to open a form

64
00:02:23,430 --> 00:02:25,620
so that you can provide your mailing information

65
00:02:25,620 --> 00:02:27,630
for the phone to be shipped out to you,

66
00:02:27,630 --> 00:02:29,010
you should be very wary

67
00:02:29,010 --> 00:02:31,980
that this could be a message-based threat vector being used

68
00:02:31,980 --> 00:02:34,230
as a part of a phishing campaign.

69
00:02:34,230 --> 00:02:35,790
Second, we have images.

70
00:02:35,790 --> 00:02:38,610
Image-based threat vectors involve the embedding

71
00:02:38,610 --> 00:02:40,590
of malicious code inside of an image file

72
00:02:40,590 --> 00:02:42,060
by the threat actor.

73
00:02:42,060 --> 00:02:44,010
When the image is later opened or loaded

74
00:02:44,010 --> 00:02:45,210
by the victim system,

75
00:02:45,210 --> 00:02:47,220
the malicious code is executed

76
00:02:47,220 --> 00:02:50,160
and this can potentially lead to data theft,

77
00:02:50,160 --> 00:02:51,360
a system compromise,

78
00:02:51,360 --> 00:02:54,000
or other types of malicious outcomes.

79
00:02:54,000 --> 00:02:56,400
Back in 2017, cybersecurity researchers

80
00:02:56,400 --> 00:02:58,890
discovered a large scale image-based attack

81
00:02:58,890 --> 00:03:00,390
known as stegano.

82
00:03:00,390 --> 00:03:01,770
In the stegano attack

83
00:03:01,770 --> 00:03:04,620
cyber criminals embedded malicious codes within the pixels

84
00:03:04,620 --> 00:03:07,350
of banner ads on so many popular websites

85
00:03:07,350 --> 00:03:08,880
and the malicious code was designed

86
00:03:08,880 --> 00:03:10,770
to exploit known vulnerabilities

87
00:03:10,770 --> 00:03:13,800
in the older Internet Explorer web browser.

88
00:03:13,800 --> 00:03:16,950
If a user visited a website that contained the banner ad

89
00:03:16,950 --> 00:03:19,800
with the malicious code hitting within the banner ads image,

90
00:03:19,800 --> 00:03:22,860
the code would be executed by the vulnerable web browser

91
00:03:22,860 --> 00:03:24,630
and it would then redirect the user

92
00:03:24,630 --> 00:03:27,600
to a site that hosted an exploit kit.

93
00:03:27,600 --> 00:03:29,910
This exploit kit would then attempt to download

94
00:03:29,910 --> 00:03:32,520
and install malware on the user's system

95
00:03:32,520 --> 00:03:33,900
all without the user's knowledge

96
00:03:33,900 --> 00:03:37,950
or any visible indication that this attack even occurred.

97
00:03:37,950 --> 00:03:39,510
Third, we have files.

98
00:03:39,510 --> 00:03:41,220
File-based threat vectors involve the use

99
00:03:41,220 --> 00:03:43,920
of malicious files to deliver a cyber threat.

100
00:03:43,920 --> 00:03:46,740
The files often disguised as legitimate documents

101
00:03:46,740 --> 00:03:49,920
or software can be transferred as email attachments

102
00:03:49,920 --> 00:03:51,660
through file sharing services

103
00:03:51,660 --> 00:03:54,570
or hosted on a malicious website.

104
00:03:54,570 --> 00:03:57,210
For example, if you try to avoid paying for a new video game

105
00:03:57,210 --> 00:04:00,120
by downloading a cracked or pirated version of the game

106
00:04:00,120 --> 00:04:01,860
from a website you found online,

107
00:04:01,860 --> 00:04:04,770
the files within the downloaded game could potentially

108
00:04:04,770 --> 00:04:07,500
include different types of malwares depending

109
00:04:07,500 --> 00:04:09,420
on the motivations of the threat actor

110
00:04:09,420 --> 00:04:10,920
who uploaded the file.

111
00:04:10,920 --> 00:04:12,510
Fourth, we have voice calls.

112
00:04:12,510 --> 00:04:14,280
Voice call based threat vectors,

113
00:04:14,280 --> 00:04:17,190
also known as vishing, involves the use of voice calls

114
00:04:17,190 --> 00:04:20,040
to trick victims into revealing their sensitive information

115
00:04:20,040 --> 00:04:21,149
to an attacker.

116
00:04:21,149 --> 00:04:24,030
The attacker may try to impersonate a trusted entity,

117
00:04:24,030 --> 00:04:26,220
such as a bank or a service provider

118
00:04:26,220 --> 00:04:28,560
to gain the victim's trust over the call.

119
00:04:28,560 --> 00:04:31,080
For example, you may get unsolicited calls

120
00:04:31,080 --> 00:04:33,120
to your cell phone from someone claiming to be

121
00:04:33,120 --> 00:04:35,190
from the Internal Revenue Service

122
00:04:35,190 --> 00:04:37,080
and if you don't provide them

123
00:04:37,080 --> 00:04:39,900
with your social security number for identification purposes

124
00:04:39,900 --> 00:04:41,970
or credit card information to pay a fine

125
00:04:41,970 --> 00:04:43,740
that they will send agents to your house

126
00:04:43,740 --> 00:04:45,810
to arrest you for non-compliance.

127
00:04:45,810 --> 00:04:48,480
In reality, this is just an attacker trying to scare you

128
00:04:48,480 --> 00:04:50,400
into providing your information

129
00:04:50,400 --> 00:04:52,950
because the IRS does not call people directly

130
00:04:52,950 --> 00:04:56,100
and instead would send you a formal letter in the mail

131
00:04:56,100 --> 00:04:59,370
to collect any information or payments from you

132
00:04:59,370 --> 00:05:02,040
if this was really the IRS.

133
00:05:02,040 --> 00:05:04,440
Fifth, we have removable devices.

134
00:05:04,440 --> 00:05:07,170
Removable device threat vectors refers to the threats

135
00:05:07,170 --> 00:05:09,330
delivered via removable devices,

136
00:05:09,330 --> 00:05:11,010
such as USB thumb drives

137
00:05:11,010 --> 00:05:13,560
and externally connected storage devices

138
00:05:13,560 --> 00:05:16,440
like hard disks and solid state devices.

139
00:05:16,440 --> 00:05:18,990
One common technique used with removable devices

140
00:05:18,990 --> 00:05:20,670
is known as baiting.

141
00:05:20,670 --> 00:05:21,503
With baiting,

142
00:05:21,503 --> 00:05:24,540
an attacker might leave a malware infected USB drive

143
00:05:24,540 --> 00:05:27,330
in a location where their target might find it,

144
00:05:27,330 --> 00:05:29,370
such as in the parking lot or the lobby

145
00:05:29,370 --> 00:05:31,170
of the targeted organization.

146
00:05:31,170 --> 00:05:33,330
If the target finds the device,

147
00:05:33,330 --> 00:05:35,460
connects it to their computer system,

148
00:05:35,460 --> 00:05:38,970
the malware will then be installed and executed.

149
00:05:38,970 --> 00:05:41,250
Alternatively, some attackers may use

150
00:05:41,250 --> 00:05:42,990
social engineering techniques

151
00:05:42,990 --> 00:05:45,030
to get themselves into the office building

152
00:05:45,030 --> 00:05:47,370
where they can then connect the removable device

153
00:05:47,370 --> 00:05:51,000
on the system themselves in order to infect the system.

154
00:05:51,000 --> 00:05:53,880
The exact malware and objectives used for the attack

155
00:05:53,880 --> 00:05:55,590
will really depend on the attacker's

156
00:05:55,590 --> 00:05:57,120
own motivations as well.

157
00:05:57,120 --> 00:05:59,340
Six, we have unsecured networks.

158
00:05:59,340 --> 00:06:02,430
Unsecured networks include wireless, wired,

159
00:06:02,430 --> 00:06:03,540
and Bluetooth networks

160
00:06:03,540 --> 00:06:05,760
that lack the appropriate security measures

161
00:06:05,760 --> 00:06:07,380
to protect these networks.

162
00:06:07,380 --> 00:06:09,270
Since the networks are unsecured

163
00:06:09,270 --> 00:06:11,160
an attacker can exploit these networks

164
00:06:11,160 --> 00:06:13,560
to intercept data to deliver malware

165
00:06:13,560 --> 00:06:16,710
or to gain unauthorized access to connected devices.

166
00:06:16,710 --> 00:06:19,440
Wireless networks such as wifi provide convenient

167
00:06:19,440 --> 00:06:21,240
and flexible connectivity.

168
00:06:21,240 --> 00:06:24,090
However, they also present a significant threat vector

169
00:06:24,090 --> 00:06:25,830
for our enterprise networks.

170
00:06:25,830 --> 00:06:28,770
If these wireless networks are not properly secured,

171
00:06:28,770 --> 00:06:30,180
unauthorized individuals

172
00:06:30,180 --> 00:06:32,400
can intercept the wireless communications

173
00:06:32,400 --> 00:06:34,200
or gain access to the network.

174
00:06:34,200 --> 00:06:37,140
For instance, attackers can set up rogue access points

175
00:06:37,140 --> 00:06:40,620
known as evil twins to create fake wifi networks

176
00:06:40,620 --> 00:06:43,260
that mimic an organization's legitimate ones.

177
00:06:43,260 --> 00:06:46,170
When users connect to these fake wifi networks

178
00:06:46,170 --> 00:06:48,630
their data can be intercepted, captured,

179
00:06:48,630 --> 00:06:50,730
and modified based on the objectives

180
00:06:50,730 --> 00:06:52,080
when conducting the attack.

181
00:06:52,080 --> 00:06:54,120
Wired networks tend to be more secure

182
00:06:54,120 --> 00:06:55,650
than their wireless counterparts,

183
00:06:55,650 --> 00:06:57,870
but they are still not immune to threats.

184
00:06:57,870 --> 00:06:59,940
Physical access to the network infrastructure can lead

185
00:06:59,940 --> 00:07:01,110
to various attacks,

186
00:07:01,110 --> 00:07:03,480
such as tapping into the network cables to intercept

187
00:07:03,480 --> 00:07:06,900
and manipulate the data or connecting unauthorized devices

188
00:07:06,900 --> 00:07:10,500
to the network by using Mac address cloning or VLAN hopping.

189
00:07:10,500 --> 00:07:12,900
Bluetooth networks are widely used

190
00:07:12,900 --> 00:07:15,390
for short range communications between devices

191
00:07:15,390 --> 00:07:16,320
and they present us

192
00:07:16,320 --> 00:07:20,130
with yet another threat vector that an attacker can exploit.

193
00:07:20,130 --> 00:07:23,850
By exploiting vulnerabilities within the Bluetooth protocol

194
00:07:23,850 --> 00:07:26,790
an attacker can carry out their attacks using techniques

195
00:07:26,790 --> 00:07:29,400
like the BlueBorne or the BlueSmack exploits.

196
00:07:29,400 --> 00:07:32,310
BlueBorne, for example, refers to a set of vulnerabilities

197
00:07:32,310 --> 00:07:34,860
in the Bluetooth technology can allow an attacker

198
00:07:34,860 --> 00:07:37,230
to take over devices, spread malware,

199
00:07:37,230 --> 00:07:39,570
or even establish an on-path attack

200
00:07:39,570 --> 00:07:41,220
to intercept communications

201
00:07:41,220 --> 00:07:43,320
without any user interaction.

202
00:07:43,320 --> 00:07:44,550
BlueSmack, on the other hand,

203
00:07:44,550 --> 00:07:46,470
is a type of denial service attack

204
00:07:46,470 --> 00:07:48,690
that targets Bluetooth enabled devices

205
00:07:48,690 --> 00:07:52,170
by sending especially crafted logical link control

206
00:07:52,170 --> 00:07:55,230
adaptation protocol packet to a target device

207
00:07:55,230 --> 00:07:58,770
which can then consume all the available resources

208
00:07:58,770 --> 00:08:00,240
on a targeted device

209
00:08:00,240 --> 00:08:03,780
and causes it to crash or become inoperable.

210
00:08:03,780 --> 00:08:06,420
So remember, a threat vector refers to the means

211
00:08:06,420 --> 00:08:09,030
or pathway by which an attacker can gain unauthorized access

212
00:08:09,030 --> 00:08:12,360
to a computer or network to deliver a malicious payload

213
00:08:12,360 --> 00:08:14,850
or carry out an unwanted action.

214
00:08:14,850 --> 00:08:16,290
The attack surface of the system

215
00:08:16,290 --> 00:08:17,640
or network on the other hand

216
00:08:17,640 --> 00:08:19,290
encompasses all the various points

217
00:08:19,290 --> 00:08:22,290
where an unauthorized user can try to enter data

218
00:08:22,290 --> 00:08:24,690
or extract data from an environment.

219
00:08:24,690 --> 00:08:26,160
There are many different threat vectors

220
00:08:26,160 --> 00:08:28,860
that an attacker could use against your enterprise networks,

221
00:08:28,860 --> 00:08:32,610
including messages, images, files, voice calls,

222
00:08:32,610 --> 00:08:33,750
removable devices,

223
00:08:33,750 --> 00:08:35,520
and unsecured networks.

224
00:08:35,520 --> 00:08:37,890
By better understanding the various paths used

225
00:08:37,890 --> 00:08:41,220
by threat actors to infiltrate your enterprise network

226
00:08:41,220 --> 00:08:44,310
you can help to develop a more effective defense,

227
00:08:44,310 --> 00:08:46,860
implement the appropriate security policies,

228
00:08:46,860 --> 00:08:50,670
and ultimately protect your organization's valuable data

229
00:08:50,670 --> 00:08:52,173
and resources.

