1
00:00:00,000 --> 00:00:01,830
In this lesson, we're going to discuss

2
00:00:01,830 --> 00:00:03,630
hardware vulnerabilities.

3
00:00:03,630 --> 00:00:05,880
Now, hardware vulnerabilities are security flaws

4
00:00:05,880 --> 00:00:07,290
or weaknesses that are inherent

5
00:00:07,290 --> 00:00:09,810
in a device's physical components or design

6
00:00:09,810 --> 00:00:10,643
that can be exploited

7
00:00:10,643 --> 00:00:12,870
to compromise the integrity, confidentiality

8
00:00:12,870 --> 00:00:15,750
or availability of the system and its data.

9
00:00:15,750 --> 00:00:17,760
There are numerous different hardware vulnerabilities

10
00:00:17,760 --> 00:00:18,780
for us to consider,

11
00:00:18,780 --> 00:00:20,400
including the device's firmware,

12
00:00:20,400 --> 00:00:21,630
end of life hardware,

13
00:00:21,630 --> 00:00:23,790
legacy hardware, unsupported systems

14
00:00:23,790 --> 00:00:25,830
and applications, unpatched systems

15
00:00:25,830 --> 00:00:27,840
and hardware misconfigurations.

16
00:00:27,840 --> 00:00:30,030
It's also important to note that these kind of issues

17
00:00:30,030 --> 00:00:32,850
can be present in all kinds of different hardware devices,

18
00:00:32,850 --> 00:00:35,550
including servers, workstations, laptops,

19
00:00:35,550 --> 00:00:38,160
switches, routers, network appliances,

20
00:00:38,160 --> 00:00:39,990
mobile devices, and IOT

21
00:00:39,990 --> 00:00:41,940
or Internet of Things devices.

22
00:00:41,940 --> 00:00:44,700
Now first, let's talk about device firmware.

23
00:00:44,700 --> 00:00:46,830
Firmware is a specialized form of software

24
00:00:46,830 --> 00:00:49,140
that's stored on a hardware device like a router

25
00:00:49,140 --> 00:00:52,140
or a smart thermostat that's going to provide low level control

26
00:00:52,140 --> 00:00:54,330
for the devices specific hardware.

27
00:00:54,330 --> 00:00:55,960
Firmware vulnerabilities can be especially dangerous

28
00:00:55,960 --> 00:00:59,160
because they often provide the attacker with full control

29
00:00:59,160 --> 00:01:00,870
of the device so that they can manipulate

30
00:01:00,870 --> 00:01:03,810
or control the hardware's behavior, which in turn can lead

31
00:01:03,810 --> 00:01:05,880
to unauthorized access, data leaks,

32
00:01:05,880 --> 00:01:08,640
or even a complete takeover of the affected device.

33
00:01:08,640 --> 00:01:10,980
Firmware can be vulnerable for several reasons.

34
00:01:10,980 --> 00:01:12,810
The firmware could have been developed without security

35
00:01:12,810 --> 00:01:14,400
in mind, or it could have used

36
00:01:14,400 --> 00:01:17,220
outdated security practices during its development.

37
00:01:17,220 --> 00:01:20,220
Firmware updates are also overlooked in many organizations

38
00:01:20,220 --> 00:01:21,750
when they're performing their routine maintenance

39
00:01:21,750 --> 00:01:23,730
for their devices, and this, again can lead

40
00:01:23,730 --> 00:01:26,550
to persistent vulnerabilities inside of your systems.

41
00:01:26,550 --> 00:01:29,760
Also, firmware often has privilege access to your system,

42
00:01:29,760 --> 00:01:32,280
which makes firmware exploitation even more dangerous

43
00:01:32,280 --> 00:01:35,910
for defenders, and a great target for malicious attackers.

44
00:01:35,910 --> 00:01:37,890
To help mitigate firmware vulnerabilities,

45
00:01:37,890 --> 00:01:40,560
you should perform regular updates, security auditing

46
00:01:40,560 --> 00:01:42,390
and device hardening to ensure your device

47
00:01:42,390 --> 00:01:43,680
remains up to date and secure

48
00:01:43,680 --> 00:01:46,140
from potential attacks and exploitation.

49
00:01:46,140 --> 00:01:49,020
Second, we need to discuss end of life, legacy

50
00:01:49,020 --> 00:01:50,760
and unsupported systems.

51
00:01:50,760 --> 00:01:52,770
Now, end of life systems refer to hardware

52
00:01:52,770 --> 00:01:54,720
or software products that have reached the end

53
00:01:54,720 --> 00:01:56,700
of their lifecycle so that their manufacturer

54
00:01:56,700 --> 00:01:58,950
or developer is no longer providing updates,

55
00:01:58,950 --> 00:02:01,140
support, or enhancements for them.

56
00:02:01,140 --> 00:02:04,440
Legacy systems are outdated computing software, hardware,

57
00:02:04,440 --> 00:02:06,960
or technologies that while they're still in use,

58
00:02:06,960 --> 00:02:08,850
have been largely superseded by newer

59
00:02:08,850 --> 00:02:10,710
or more efficient alternatives

60
00:02:10,710 --> 00:02:12,720
and unsupported systems are hardware

61
00:02:12,720 --> 00:02:14,850
or software products that no longer receive

62
00:02:14,850 --> 00:02:17,130
official technical support, security updates

63
00:02:17,130 --> 00:02:20,400
or patches from their respective vendors or developers.

64
00:02:20,400 --> 00:02:22,860
These three concepts are very similar to each other,

65
00:02:22,860 --> 00:02:24,420
and often you're going to see people

66
00:02:24,420 --> 00:02:25,830
use these terms interchangeably

67
00:02:25,830 --> 00:02:28,020
when they're discussing end of life, legacy

68
00:02:28,020 --> 00:02:30,600
and unsupported systems and applications.

69
00:02:30,600 --> 00:02:32,430
These kinds of systems and applications

70
00:02:32,430 --> 00:02:33,660
are particularly vulnerable

71
00:02:33,660 --> 00:02:35,310
because any existing security flaws

72
00:02:35,310 --> 00:02:37,440
will not be addressed with patches or updates,

73
00:02:37,440 --> 00:02:39,180
and this leaves that system exposed

74
00:02:39,180 --> 00:02:41,070
to those known vulnerabilities.

75
00:02:41,070 --> 00:02:43,074
Third, we have unpatched systems.

76
00:02:43,074 --> 00:02:45,930
Now, an unpatched system is a device, application

77
00:02:45,930 --> 00:02:48,030
or piece of software that has not been updated

78
00:02:48,030 --> 00:02:49,560
with the latest security patches,

79
00:02:49,560 --> 00:02:52,710
so it now remains vulnerable to known exploits and attacks.

80
00:02:52,710 --> 00:02:55,560
This usually happens because of an oversight, negligence

81
00:02:55,560 --> 00:02:57,360
or challenges in deploying updates

82
00:02:57,360 --> 00:02:59,190
in a timely manner to all of your devices

83
00:02:59,190 --> 00:03:00,990
across your enterprise network.

84
00:03:00,990 --> 00:03:03,660
If you do not patch your systems in a timely manner though,

85
00:03:03,660 --> 00:03:06,210
your organization is going to be exposed to a wide range

86
00:03:06,210 --> 00:03:07,920
of security risks because an attacker

87
00:03:07,920 --> 00:03:10,230
can easily exploit these known vulnerabilities

88
00:03:10,230 --> 00:03:12,630
to gain unauthorized access into your systems,

89
00:03:12,630 --> 00:03:15,750
compromise your data, or to disrupt your services.

90
00:03:15,750 --> 00:03:18,090
To help mitigate the risk of unpatched systems,

91
00:03:18,090 --> 00:03:19,530
it's going to be essential to establish

92
00:03:19,530 --> 00:03:20,970
a patch management process

93
00:03:20,970 --> 00:03:23,040
that involves regularly monitoring for updates,

94
00:03:23,040 --> 00:03:25,377
assessing the relevance and impact of the patches,

95
00:03:25,377 --> 00:03:27,810
and deploying your patches in a timely manner

96
00:03:27,810 --> 00:03:29,310
to ensure the security and integrity

97
00:03:29,310 --> 00:03:31,830
of all of your systems remains intact.

98
00:03:31,830 --> 00:03:34,118
Fourth, we have hardware misconfigurations.

99
00:03:34,118 --> 00:03:36,060
Now, a hardware misconfiguration

100
00:03:36,060 --> 00:03:38,070
occurs when a device's settings, parameters

101
00:03:38,070 --> 00:03:40,320
or options are not optimally set up,

102
00:03:40,320 --> 00:03:42,300
and this can cause vulnerabilities to exist,

103
00:03:42,300 --> 00:03:43,560
a decrease in performance

104
00:03:43,560 --> 00:03:46,680
or unintended behavior of your devices or systems.

105
00:03:46,680 --> 00:03:49,380
These misconfigurations can happen due to oversight,

106
00:03:49,380 --> 00:03:52,110
a lack of understanding of your industry best practices

107
00:03:52,110 --> 00:03:53,790
or errors that occurred during this setup

108
00:03:53,790 --> 00:03:55,380
and deployment process.

109
00:03:55,380 --> 00:03:57,870
These misconfigurations can inadvertently open up

110
00:03:57,870 --> 00:04:00,120
security holes that would make your system susceptible

111
00:04:00,120 --> 00:04:02,610
to unauthorized access and data breaches.

112
00:04:02,610 --> 00:04:03,510
To mitigate the risks

113
00:04:03,510 --> 00:04:05,670
associated with hardware misconfigurations,

114
00:04:05,670 --> 00:04:08,100
it's also recommended that you conduct regular audits,

115
00:04:08,100 --> 00:04:10,320
enforce good configuration management practices,

116
00:04:10,320 --> 00:04:11,730
and implement automated tools

117
00:04:11,730 --> 00:04:14,070
for detecting and rectifying misconfigurations,

118
00:04:14,070 --> 00:04:15,990
as well as providing training to your personnel

119
00:04:15,990 --> 00:04:18,480
so that they're aware of the correct configuration protocols

120
00:04:18,480 --> 00:04:20,010
and security best practices

121
00:04:20,010 --> 00:04:22,500
that should be implemented across your devices.

122
00:04:22,500 --> 00:04:24,570
Now, when it comes to hardware vulnerabilities,

123
00:04:24,570 --> 00:04:27,030
including those that exist in the devices, firmware,

124
00:04:27,030 --> 00:04:29,400
end of life hardware, legacy hardware,

125
00:04:29,400 --> 00:04:31,320
unsupported systems and applications,

126
00:04:31,320 --> 00:04:32,340
unpatched systems

127
00:04:32,340 --> 00:04:35,010
and hardware misconfigurations, you need to be conducting

128
00:04:35,010 --> 00:04:37,132
hardening, patching,

129
00:04:37,132 --> 00:04:39,030
configuration enforcement, decommissioning, isolation

130
00:04:39,030 --> 00:04:41,820
and segmentation to mitigate any known vulnerabilities

131
00:04:41,820 --> 00:04:43,740
in your devices and systems.

132
00:04:43,740 --> 00:04:45,540
Now, hardening involves tightening the security

133
00:04:45,540 --> 00:04:48,000
of your system by closing unnecessary ports,

134
00:04:48,000 --> 00:04:49,770
disabling unnecessary services,

135
00:04:49,770 --> 00:04:51,690
and setting up proper permissions.

136
00:04:51,690 --> 00:04:52,590
Hardening can be applied

137
00:04:52,590 --> 00:04:55,200
to firmware, applications and various hardware

138
00:04:55,200 --> 00:04:57,900
to make them more resistant to attacks as well.

139
00:04:57,900 --> 00:05:00,360
Patching involves the regular updating of your software,

140
00:05:00,360 --> 00:05:03,360
firmware and applications with the latest security patches

141
00:05:03,360 --> 00:05:04,740
to ensure that known vulnerabilities

142
00:05:04,740 --> 00:05:07,620
are being fixed in order to prevent exploitation.

143
00:05:07,620 --> 00:05:09,600
Configuration enforcement is going to be used

144
00:05:09,600 --> 00:05:11,460
to ensure that all devices and systems

145
00:05:11,460 --> 00:05:12,995
adhere to a standard secure configuration

146
00:05:12,995 --> 00:05:15,180
to help prevent any misconfiguration

147
00:05:15,180 --> 00:05:17,160
and vulnerabilities from occurring.

148
00:05:17,160 --> 00:05:18,540
If you're dealing with end of life,

149
00:05:18,540 --> 00:05:20,670
legacy or unsupported systems,

150
00:05:20,670 --> 00:05:22,079
then you might want to use decommissioning.

151
00:05:22,079 --> 00:05:24,750
Decommissioning might be your best course of action

152
00:05:24,750 --> 00:05:26,387
because this means that the system is going to be retired

153
00:05:26,387 --> 00:05:29,130
and removed from your network, and this is usually done

154
00:05:29,130 --> 00:05:30,450
because an older end of life

155
00:05:30,450 --> 00:05:32,310
or legacy system would pose too great

156
00:05:32,310 --> 00:05:34,170
of a security risk if we leave it connected

157
00:05:34,170 --> 00:05:35,820
to our enterprise network.

158
00:05:35,820 --> 00:05:38,460
Now, if decommissioning is not immediately possible,

159
00:05:38,460 --> 00:05:41,460
you may instead isolate your legacy or vulnerable systems

160
00:05:41,460 --> 00:05:42,870
from your enterprise network

161
00:05:42,870 --> 00:05:44,040
to limit the potential damage

162
00:05:44,040 --> 00:05:46,860
that could occur from a potential security breach.

163
00:05:46,860 --> 00:05:48,810
Finally, we can also use segmentation

164
00:05:48,810 --> 00:05:50,169
to divide our network into segments,

165
00:05:50,169 --> 00:05:52,050
to ensure that even if one section

166
00:05:52,050 --> 00:05:53,370
of our network is compromised,

167
00:05:53,370 --> 00:05:55,050
that breach will not necessarily

168
00:05:55,050 --> 00:05:58,290
compromise the entire enterprise network on our behalf.

169
00:05:58,290 --> 00:06:01,110
So remember, hardware vulnerabilities are security flaws

170
00:06:01,110 --> 00:06:02,520
or weaknesses that are inherent

171
00:06:02,520 --> 00:06:04,020
in a device's physical components

172
00:06:04,020 --> 00:06:05,670
or design that can be exploited

173
00:06:05,670 --> 00:06:07,890
to compromise the integrity, confidentiality

174
00:06:07,890 --> 00:06:10,560
or availability of the system and its data.

175
00:06:10,560 --> 00:06:12,480
There are numerous different hardware vulnerabilities

176
00:06:12,480 --> 00:06:15,150
for us to consider, including the device's firmware,

177
00:06:15,150 --> 00:06:18,480
end of life hardware, legacy hardware, unsupported systems

178
00:06:18,480 --> 00:06:20,520
and applications, unpatched systems

179
00:06:20,520 --> 00:06:22,470
and hardware misconfigurations.

180
00:06:22,470 --> 00:06:24,102
To mitigate these types of hardware vulnerabilities

181
00:06:24,102 --> 00:06:26,640
you should conduct hardening, patching,

182
00:06:26,640 --> 00:06:29,460
configuration enforcement, decommissioning, isolation,

183
00:06:29,460 --> 00:06:32,160
and segmentation to mitigate any known vulnerabilities

184
00:06:32,160 --> 00:06:33,633
in your devices and systems.

