1
00:00:00,000 --> 00:00:00,930
In this lesson,

2
00:00:00,930 --> 00:00:02,370
we'll discuss four ways you

3
00:00:02,370 --> 00:00:05,580
can begin to outsmart threat actors.

4
00:00:05,580 --> 00:00:07,230
Attackers are everywhere

5
00:00:07,230 --> 00:00:08,850
and they're always out to get you,

6
00:00:08,850 --> 00:00:11,640
especially if you or your organization

7
00:00:11,640 --> 00:00:13,320
have something of interest

8
00:00:13,320 --> 00:00:15,399
like sensitive information, digital assets,

9
00:00:15,399 --> 00:00:18,930
or simply resources that can be stolen.

10
00:00:18,930 --> 00:00:21,000
If you find that you are always reacting

11
00:00:21,000 --> 00:00:23,568
instead of focusing on a proactive defense,

12
00:00:23,568 --> 00:00:26,880
you'll be missing out on a lot of valuable information

13
00:00:26,880 --> 00:00:30,270
and always be operating in a reactionary mode.

14
00:00:30,270 --> 00:00:33,140
Instead, to really increase your cyber resilience,

15
00:00:33,140 --> 00:00:35,400
you must be more proactive

16
00:00:35,400 --> 00:00:37,779
by understanding countering threat actors

17
00:00:37,779 --> 00:00:40,380
through a continuous process.

18
00:00:40,380 --> 00:00:41,839
One of the most effective ways to learn

19
00:00:41,839 --> 00:00:44,010
from the different threat actors that are

20
00:00:44,010 --> 00:00:46,200
attacking your network is to set up

21
00:00:46,200 --> 00:00:49,720
and utilize deception and disruption technologies

22
00:00:50,742 --> 00:00:54,390
like honeypots, honeynets, honeyfiles, and honeytokens

23
00:00:54,390 --> 00:00:57,390
to log, monitor and track threat actors

24
00:00:57,390 --> 00:00:58,260
so that we can learn

25
00:00:58,260 --> 00:01:01,590
about their tactics, techniques, and procedures.

26
00:01:01,590 --> 00:01:03,450
Now, the collection of tactics,

27
00:01:03,450 --> 00:01:05,370
techniques and procedures used

28
00:01:05,370 --> 00:01:07,560
by giving threat actor are usually referred

29
00:01:07,560 --> 00:01:12,060
to as a type of adversary or a threat actor's TTPs.

30
00:01:12,060 --> 00:01:14,280
Tactics, techniques, and procedures

31
00:01:14,280 --> 00:01:17,460
or TTPs refer to the specific methods

32
00:01:17,460 --> 00:01:20,940
and patterns of activities or behaviors associated

33
00:01:20,940 --> 00:01:24,630
with a particular threat actor or group of threat actors.

34
00:01:24,630 --> 00:01:28,166
These TTPs present how a given adversary operates

35
00:01:28,166 --> 00:01:31,578
can be used by your cybersecurity professionals

36
00:01:31,578 --> 00:01:34,320
to detect, mitigate and counter

37
00:01:34,320 --> 00:01:36,360
the attacker's cyber threats.

38
00:01:36,360 --> 00:01:38,820
But how can cybersecurity researchers

39
00:01:38,820 --> 00:01:40,464
and professionals learn the different

40
00:01:40,464 --> 00:01:42,454
tactics, techniques and procedures

41
00:01:42,454 --> 00:01:45,630
used by each different type of threat actor?

42
00:01:45,630 --> 00:01:46,860
That is where deception

43
00:01:46,860 --> 00:01:48,927
and disruption technologies get implemented

44
00:01:48,927 --> 00:01:51,450
within our enterprise networks.

45
00:01:51,450 --> 00:01:53,091
Deception and disruption technologies

46
00:01:53,091 --> 00:01:56,280
are designed to mislead, confuse

47
00:01:56,280 --> 00:01:59,111
and divert attackers away from critical assets

48
00:01:59,111 --> 00:02:02,790
while simultaneously detecting and neutralizing threats.

49
00:02:02,790 --> 00:02:04,950
By creating a dynamic environment

50
00:02:04,950 --> 00:02:06,783
or presenting false information.

51
00:02:07,951 --> 00:02:09,471
these technologies can delay

52
00:02:09,471 --> 00:02:10,304
and deter adversaries

53
00:02:10,304 --> 00:02:11,599
giving organizations an upper hand

54
00:02:11,599 --> 00:02:15,600
in identifying countering malicious activities.

55
00:02:15,600 --> 00:02:18,060
The four commonly used deception and disruption

56
00:02:18,060 --> 00:02:20,622
technologies are honeypots, honeynets,

57
00:02:20,622 --> 00:02:23,340
honeyfiles, and honeytokens.

58
00:02:23,340 --> 00:02:24,900
First, we have honeypots.

59
00:02:24,900 --> 00:02:27,450
A honeypot is a decoy system or network set up

60
00:02:27,450 --> 00:02:28,790
to attract potential hackers.

61
00:02:28,790 --> 00:02:31,740
Honeypots are used to mimic a real system

62
00:02:31,740 --> 00:02:34,860
with vulnerabilities that seem attractive to attackers.

63
00:02:34,860 --> 00:02:37,590
The primary purpose of a honeypot is not to block

64
00:02:37,590 --> 00:02:40,260
or prevent attacks, but is instead focused

65
00:02:40,260 --> 00:02:42,259
on gathering information about the attacker's

66
00:02:42,259 --> 00:02:46,380
methods, motives, and TTPs.

67
00:02:46,380 --> 00:02:49,830
These honeypots can also be used against insider threats

68
00:02:49,830 --> 00:02:53,970
to detect internal fraud, snooping, and malpractice

69
00:02:53,970 --> 00:02:55,620
and they can be configured to work

70
00:02:55,620 --> 00:02:58,140
as an actual network or simulated network

71
00:02:58,140 --> 00:03:00,780
using an emulation application.

72
00:03:00,780 --> 00:03:03,990
Our honeypots are designed to log all interactions

73
00:03:03,990 --> 00:03:06,723
and transactions in order to provide valuable insights

74
00:03:06,723 --> 00:03:09,030
into the threat landscape.

75
00:03:09,030 --> 00:03:10,830
These honeypots are critical

76
00:03:10,830 --> 00:03:13,908
to helping cybersecurity researchers identify the new types

77
00:03:13,908 --> 00:03:17,430
of attacks, malware and other threats being seen

78
00:03:17,430 --> 00:03:20,970
on the internet before they become a widespread problem

79
00:03:20,970 --> 00:03:22,511
for our enterprise networks.

80
00:03:22,511 --> 00:03:24,540
If you are going to install a honeypot

81
00:03:24,540 --> 00:03:25,950
on your enterprise network,

82
00:03:25,950 --> 00:03:26,820
you should locate it

83
00:03:26,820 --> 00:03:30,450
within a screen subnet of the network or an isolated segment

84
00:03:30,450 --> 00:03:32,940
of the network that can be easily accessed

85
00:03:32,940 --> 00:03:35,530
over the internet by a potential attacker.

86
00:03:35,530 --> 00:03:37,633
Second, we have honeynets.

87
00:03:37,633 --> 00:03:39,570
A honeynet is essentially a network

88
00:03:39,570 --> 00:03:41,830
of honeypots to create a more complex system

89
00:03:41,830 --> 00:03:45,450
that is designed to mimic an entire network of systems

90
00:03:45,450 --> 00:03:48,780
including servers, routers, and switches.

91
00:03:48,780 --> 00:03:51,189
Honeynets are often used by a large organizations

92
00:03:51,189 --> 00:03:54,780
and research institutions to study the behavior

93
00:03:54,780 --> 00:03:55,613
of threat actors

94
00:03:55,613 --> 00:03:59,190
in a more controlled environment like a honeypot.

95
00:03:59,190 --> 00:04:01,980
A honeynet logs all activities to provide us

96
00:04:01,980 --> 00:04:04,230
with a wealth of data about both the successful

97
00:04:04,230 --> 00:04:07,850
and unsuccessful attacks being attempted against our network

98
00:04:07,850 --> 00:04:09,702
so that we can reveal patterns in the attack

99
00:04:09,702 --> 00:04:13,260
vectors to help our security teams develop a more

100
00:04:13,260 --> 00:04:15,971
effective defense to counteract new TTPs

101
00:04:15,971 --> 00:04:18,120
being observed in the honeynet.

102
00:04:18,120 --> 00:04:19,889
When you think about honeypots and honeynets,

103
00:04:19,889 --> 00:04:22,680
I want you to remember that while they can both be

104
00:04:22,680 --> 00:04:24,840
used to help your organization improve

105
00:04:24,840 --> 00:04:25,673
its security systems,

106
00:04:25,673 --> 00:04:28,860
there is a risk that the attacker could use the honeynet

107
00:04:28,860 --> 00:04:31,560
and its honeypots to learn how your production

108
00:04:31,560 --> 00:04:33,059
systems are also configured,

109
00:04:33,059 --> 00:04:36,330
which make this a double-edged sword when implemented

110
00:04:36,330 --> 00:04:39,090
as a part of your security architecture.

111
00:04:39,090 --> 00:04:40,740
Third, we have honeyfiles.

112
00:04:40,740 --> 00:04:43,110
A honeyfile is a decoy file placed

113
00:04:43,110 --> 00:04:45,510
within a system to lure in potential attackers.

114
00:04:45,510 --> 00:04:48,270
A honeyfile should appear to contain valuable

115
00:04:48,270 --> 00:04:51,300
or sensitive information that will entice a threat

116
00:04:51,300 --> 00:04:53,150
actor to go after the data,

117
00:04:53,150 --> 00:04:56,400
but in reality, it serves as a trap

118
00:04:56,400 --> 00:04:58,020
and contains fake data

119
00:04:58,020 --> 00:05:01,134
and hidden metadata or digital watermarks in the file

120
00:05:01,134 --> 00:05:05,160
to attempt to enumerate the attacker's own network.

121
00:05:05,160 --> 00:05:07,202
When an attacker accesses the honeyfile,

122
00:05:07,202 --> 00:05:11,100
an alert is triggered that notifies the security team

123
00:05:11,100 --> 00:05:12,270
of the intrusion,

124
00:05:12,270 --> 00:05:14,069
and some honeyfiles have embedded code

125
00:05:14,069 --> 00:05:17,100
that allows them to begin enumerating the attacker's network

126
00:05:17,100 --> 00:05:18,780
once the file is open

127
00:05:18,780 --> 00:05:22,320
on a computer connected to their attack network.

128
00:05:22,320 --> 00:05:23,153
When it comes to honeyfiles,

129
00:05:23,153 --> 00:05:25,649
these can be created using any type of file you want

130
00:05:25,649 --> 00:05:28,961
including word processing documents, spreadsheets,

131
00:05:28,961 --> 00:05:32,310
presentation files, images, database files,

132
00:05:32,310 --> 00:05:33,960
or even executables.

133
00:05:33,960 --> 00:05:35,589
These honeyfiles are typically embedded

134
00:05:35,589 --> 00:05:38,280
with unique identifiers or watermarks

135
00:05:38,280 --> 00:05:39,971
to help track the file

136
00:05:39,971 --> 00:05:42,149
if it is stolen or copied,

137
00:05:42,149 --> 00:05:43,367
and are usually placed

138
00:05:43,367 --> 00:05:46,929
under loose or less strict defenses that files

139
00:05:46,929 --> 00:05:50,176
that contain actual sensitive data might have.

140
00:05:50,176 --> 00:05:52,873
Fourth and finally, we have honeytokens.

141
00:05:52,873 --> 00:05:54,540
A honeytoken is a piece of data

142
00:05:54,540 --> 00:05:57,600
or a resource that has no legitimate value or use,

143
00:05:57,600 --> 00:05:59,970
but is monitored for access or use.

144
00:05:59,970 --> 00:06:02,490
A honeytoken could be a fake user account,

145
00:06:02,490 --> 00:06:05,730
a bogus URL, or a dummy database record.

146
00:06:05,730 --> 00:06:07,710
If the honeytoken is accessed or used,

147
00:06:07,710 --> 00:06:08,829
this is a clear indication

148
00:06:08,829 --> 00:06:11,346
that a security breach is likely occurring.

149
00:06:11,346 --> 00:06:13,860
Honeytokens are particularly useful

150
00:06:13,860 --> 00:06:15,349
for detecting insider threats.

151
00:06:15,349 --> 00:06:17,850
Since they have no legitimate use,

152
00:06:17,850 --> 00:06:20,460
any interaction with them is suspicious.

153
00:06:20,460 --> 00:06:22,800
For example, you may create a user account

154
00:06:22,800 --> 00:06:25,560
called Admin or Route on a window system,

155
00:06:25,560 --> 00:06:28,020
and if someone tries to log in with that account,

156
00:06:28,020 --> 00:06:29,640
you know that they're attacking you

157
00:06:29,640 --> 00:06:32,361
since no legitimate user would ever log into that account

158
00:06:32,361 --> 00:06:35,620
since it was only created to be used as a honeytoken.

159
00:06:35,620 --> 00:06:39,060
These honeytokens can also help with the identification

160
00:06:39,060 --> 00:06:41,190
of any data leak pathways

161
00:06:41,190 --> 00:06:42,023
and provide us

162
00:06:42,023 --> 00:06:45,480
with an early warning of a potential data breach.

163
00:06:45,480 --> 00:06:47,940
In addition to the deceptive technologies we covered

164
00:06:47,940 --> 00:06:50,459
of honeypots honeynets, honeyfiles and honeytokens,

165
00:06:50,459 --> 00:06:52,729
we also could use some disruption technologies

166
00:06:52,729 --> 00:06:56,190
and strategies to help secure our enterprise networks

167
00:06:56,190 --> 00:07:00,030
like using bogus DNS entries, creating decoy directories,

168
00:07:00,030 --> 00:07:02,891
generating dynamic pages to slow down web crawlers,

169
00:07:02,891 --> 00:07:05,820
using port triggering to hype services,

170
00:07:05,820 --> 00:07:07,379
and spoofing fake telemetry data

171
00:07:07,379 --> 00:07:10,332
during a detected network scan.

172
00:07:10,332 --> 00:07:13,260
First, we have bogus DNS entries.

173
00:07:13,260 --> 00:07:15,900
Bogus DNS entries are fake domain name system

174
00:07:15,900 --> 00:07:19,230
entries introduced into your system DNS server.

175
00:07:19,230 --> 00:07:20,890
By adding these deceptive entries,

176
00:07:20,890 --> 00:07:23,640
administrators can mislead attackers

177
00:07:23,640 --> 00:07:25,430
into accessing non-existent domains

178
00:07:25,430 --> 00:07:28,159
or trap systems to waste the attacker's time

179
00:07:28,159 --> 00:07:32,117
and resources while simultaneously alerting the defenders

180
00:07:32,117 --> 00:07:34,890
about potential malicious activities.

181
00:07:34,890 --> 00:07:36,990
Second, we can create decoy directories

182
00:07:36,990 --> 00:07:38,430
to disrupt the attackers.

183
00:07:38,430 --> 00:07:40,279
Decoy directories are fake folders

184
00:07:40,279 --> 00:07:43,680
and files placed within a system storage.

185
00:07:43,680 --> 00:07:45,759
When unauthorized user attempts to access or modify

186
00:07:45,759 --> 00:07:49,380
these directories, the system can raise an alert

187
00:07:49,380 --> 00:07:51,510
and the attacker is misled by false data

188
00:07:51,510 --> 00:07:54,480
and made to think that they have successfully gained access

189
00:07:54,480 --> 00:07:57,750
to your organization's genuine resources.

190
00:07:57,750 --> 00:08:00,690
Third, we have dynamic page generation.

191
00:08:00,690 --> 00:08:02,580
By generating dynamic pages,

192
00:08:02,580 --> 00:08:04,839
websites can present ever-changing content

193
00:08:04,839 --> 00:08:06,710
to web crawlers to confuse

194
00:08:06,710 --> 00:08:09,450
and slow down the threat actor.

195
00:08:09,450 --> 00:08:11,231
This tactic can be especially effective

196
00:08:11,231 --> 00:08:15,420
against automated scrubbing tools or bots trying to index,

197
00:08:15,420 --> 00:08:18,690
or steal content from your organization's website.

198
00:08:18,690 --> 00:08:21,627
Fourth, we have the use of port triggering to hide services.

199
00:08:21,627 --> 00:08:24,210
Port triggering is a security mechanism where

200
00:08:24,210 --> 00:08:27,960
specific services or ports on a network device remain closed

201
00:08:27,960 --> 00:08:31,650
until a specific outbound traffic pattern is detected.

202
00:08:31,650 --> 00:08:33,210
Once the pattern is observed,

203
00:08:33,210 --> 00:08:36,539
the service or port is opened temporarily.

204
00:08:36,539 --> 00:08:37,620
This method ensures

205
00:08:37,620 --> 00:08:40,530
that certain services remain invisible and inaccessible

206
00:08:40,530 --> 00:08:43,950
to potential attackers scanning for open ports,

207
00:08:43,950 --> 00:08:47,400
but become available for legitimate users when needed.

208
00:08:47,400 --> 00:08:50,280
Fifth, we have spoofing fake telemetry data.

209
00:08:50,280 --> 00:08:52,800
When a system detects a network scan is being attempted

210
00:08:52,800 --> 00:08:55,440
by an attacker, it can be configured to respond

211
00:08:55,440 --> 00:08:58,860
by sending out fake telemetry or network data.

212
00:08:58,860 --> 00:09:01,530
This data can be used to confuse an attacker

213
00:09:01,530 --> 00:09:02,760
and make it more challenging

214
00:09:02,760 --> 00:09:05,820
for them to understand the network's real layout,

215
00:09:05,820 --> 00:09:06,660
and prevent them

216
00:09:06,660 --> 00:09:09,480
from being able to identify genuine vulnerabilities

217
00:09:09,480 --> 00:09:10,399
in your systems.

218
00:09:10,399 --> 00:09:12,761
For example, if my system detected

219
00:09:12,761 --> 00:09:14,552
that you are running a network against it,

220
00:09:14,552 --> 00:09:15,720
it might report

221
00:09:15,720 --> 00:09:18,540
that I'm using Windows 11 instead of the macOS system

222
00:09:18,540 --> 00:09:19,890
I'm really using.

223
00:09:19,890 --> 00:09:22,470
This way, if you're trying to use a Windows 11 exploit

224
00:09:22,470 --> 00:09:24,160
against my system, it would fail

225
00:09:24,160 --> 00:09:26,520
because I'm not actually running Windows

226
00:09:26,520 --> 00:09:29,122
by your scan was tricked into believing I was

227
00:09:29,122 --> 00:09:32,820
since I sent back the fake telemetric data.

228
00:09:32,820 --> 00:09:35,850
So remember, deceptive and disruptive technologies refer

229
00:09:35,850 --> 00:09:36,720
to a set of tools

230
00:09:36,720 --> 00:09:39,580
and strategies designed to mislead potential attackers,

231
00:09:39,580 --> 00:09:41,880
and hinder their malicious activities

232
00:09:41,880 --> 00:09:43,340
within a system or network

233
00:09:43,340 --> 00:09:46,203
such as honeypots honeynets, honeyfiles, honeytokens.

234
00:09:47,370 --> 00:09:49,230
A honeypot is a decoy system set

235
00:09:49,230 --> 00:09:50,820
up to lure cyber attackers,

236
00:09:50,820 --> 00:09:53,160
allowing defenders to study their actions

237
00:09:53,160 --> 00:09:55,710
without any real world consequences.

238
00:09:55,710 --> 00:09:58,380
Similarly, a honeynet is an entire network

239
00:09:58,380 --> 00:10:01,530
of such deceptive systems that mimic a real world

240
00:10:01,530 --> 00:10:05,550
environment to attract analyze attackers behaviors.

241
00:10:05,550 --> 00:10:07,980
A honeyfile is a decoy file that appears

242
00:10:07,980 --> 00:10:09,360
to be genuine data,

243
00:10:09,360 --> 00:10:10,830
but it's really just a watermarked

244
00:10:10,830 --> 00:10:14,820
file that can be used to detect unauthorized access.

245
00:10:14,820 --> 00:10:18,270
Lastly, a honeytoken is a digital entity such

246
00:10:18,270 --> 00:10:19,380
as the fake password

247
00:10:19,380 --> 00:10:21,850
or user credential that when used triggers

248
00:10:21,850 --> 00:10:25,088
an alarm signaling a potential security breach.

249
00:10:25,088 --> 00:10:28,320
These technologies allow organizations to lure

250
00:10:28,320 --> 00:10:31,140
and threat actors, learn their TTPs,

251
00:10:31,140 --> 00:10:33,359
and then develop more effective countermeasures.

252
00:10:33,359 --> 00:10:35,730
While these tools do not replace traditional

253
00:10:35,730 --> 00:10:38,100
security measures, they add an extra layer

254
00:10:38,100 --> 00:10:40,110
of defense by turning the tables

255
00:10:40,110 --> 00:10:42,341
on attackers and allowing us to hunt them

256
00:10:42,341 --> 00:10:45,933
and remove them from our networks.

