1
00:00:00,090 --> 00:00:00,930
In this lesson,

2
00:00:00,930 --> 00:00:03,360
we'll discuss Restricting Applications.

3
00:00:03,360 --> 00:00:05,670
Now let me take a moment here and ask you a question.

4
00:00:05,670 --> 00:00:07,350
How many applications do you have installed

5
00:00:07,350 --> 00:00:08,970
on your computer right now?

6
00:00:08,970 --> 00:00:10,860
Now, I don't mean how many are you currently running,

7
00:00:10,860 --> 00:00:12,990
like your web browser or your email client,

8
00:00:12,990 --> 00:00:15,810
but exactly how many exist on your computer in total?

9
00:00:15,810 --> 00:00:19,350
Do you have 5, 50, 500, or maybe even more?

10
00:00:19,350 --> 00:00:21,180
Each application that's installing your device

11
00:00:21,180 --> 00:00:23,520
will take up valuable disk space, but more importantly,

12
00:00:23,520 --> 00:00:25,050
it's going to introduce additional code,

13
00:00:25,050 --> 00:00:27,840
and therefore, additional vulnerabilities to your system.

14
00:00:27,840 --> 00:00:29,640
To combat this, system administrators

15
00:00:29,640 --> 00:00:31,020
will attempt to practice a concept

16
00:00:31,020 --> 00:00:32,670
known as least functionality.

17
00:00:32,670 --> 00:00:34,380
Least functionality is the process

18
00:00:34,380 --> 00:00:36,300
of configuring a workstation or a server

19
00:00:36,300 --> 00:00:38,760
to provide only essential applications and services

20
00:00:38,760 --> 00:00:41,070
that are going to be required by that user.

21
00:00:41,070 --> 00:00:43,230
To create an environment of least functionality,

22
00:00:43,230 --> 00:00:45,930
your administrators need to restrict unneeded applications,

23
00:00:45,930 --> 00:00:48,960
services, ports, and protocols on that system.

24
00:00:48,960 --> 00:00:50,310
Now, another method of doing this

25
00:00:50,310 --> 00:00:53,250
is to start uninstalling any unneeded applications.

26
00:00:53,250 --> 00:00:56,280
After all, every application that's installed on a computer

27
00:00:56,280 --> 00:00:59,220
has to be managed, updated, and patched for security,

28
00:00:59,220 --> 00:01:01,590
and it provides yet another chance for a vulnerability

29
00:01:01,590 --> 00:01:03,540
to be introduced into our systems.

30
00:01:03,540 --> 00:01:05,129
Now at work, most of our computers

31
00:01:05,129 --> 00:01:06,630
are going to be placed under a process

32
00:01:06,630 --> 00:01:08,010
known as configuration management

33
00:01:08,010 --> 00:01:09,840
to help us oversee this process.

34
00:01:09,840 --> 00:01:11,670
But for our personal computers at home,

35
00:01:11,670 --> 00:01:14,070
they become a mess with unnecessary programs

36
00:01:14,070 --> 00:01:16,830
being installed and accumulated over time.

37
00:01:16,830 --> 00:01:19,830
For example, if you go into your Program area of Windows,

38
00:01:19,830 --> 00:01:20,670
you can open it up

39
00:01:20,670 --> 00:01:23,460
and see all the different programs that you have installed.

40
00:01:23,460 --> 00:01:24,390
You might be surprised

41
00:01:24,390 --> 00:01:26,490
at just how many there are on your computer.

42
00:01:26,490 --> 00:01:28,440
For this example, I have a computer here

43
00:01:28,440 --> 00:01:30,900
with 132 different programs installed

44
00:01:30,900 --> 00:01:33,600
that took over 400 gigabytes of disk space.

45
00:01:33,600 --> 00:01:34,650
Now, looking through this list,

46
00:01:34,650 --> 00:01:36,033
there's a lot of unnecessary programs

47
00:01:36,033 --> 00:01:38,610
that user could have uninstalled.

48
00:01:38,610 --> 00:01:39,990
As I previously mentioned,

49
00:01:39,990 --> 00:01:41,790
it's really important to keep all your programs

50
00:01:41,790 --> 00:01:43,260
and your software up to date.

51
00:01:43,260 --> 00:01:45,300
And sometimes though, these new programs

52
00:01:45,300 --> 00:01:48,630
will also be installed and leave the old version intact.

53
00:01:48,630 --> 00:01:49,620
Now, for example,

54
00:01:49,620 --> 00:01:51,510
I used to use a software called Adobe Premier

55
00:01:51,510 --> 00:01:53,250
as a video editing software,

56
00:01:53,250 --> 00:01:55,170
and every year they put out a new version

57
00:01:55,170 --> 00:01:59,310
like Adobe Premier 2018, 2019, 2020, and so on.

58
00:01:59,310 --> 00:02:03,450
And if I went from 2018 to 2019 or 2019 to 2020,

59
00:02:03,450 --> 00:02:05,100
after the installation was complete,

60
00:02:05,100 --> 00:02:06,480
we saw that both versions,

61
00:02:06,480 --> 00:02:07,950
the old one and the new one

62
00:02:07,950 --> 00:02:10,139
were both still installed on the computer.

63
00:02:10,139 --> 00:02:13,170
So to eliminate the vulnerabilities with the older version,

64
00:02:13,170 --> 00:02:14,003
we had to go back

65
00:02:14,003 --> 00:02:16,230
and manually uninstall it from our systems.

66
00:02:16,230 --> 00:02:17,760
Now, this may be very easy to do

67
00:02:17,760 --> 00:02:20,070
if you have a small network of just a few machines,

68
00:02:20,070 --> 00:02:21,120
but how do you do this

69
00:02:21,120 --> 00:02:23,400
when you're managing a huge enterprise network?

70
00:02:23,400 --> 00:02:25,560
For example, one network I used to manage

71
00:02:25,560 --> 00:02:28,830
had over 10,000 computers spread across four countries.

72
00:02:28,830 --> 00:02:30,750
It would've been nearly impossible for me

73
00:02:30,750 --> 00:02:32,190
to send my system administrators out

74
00:02:32,190 --> 00:02:33,540
to each of those computers

75
00:02:33,540 --> 00:02:35,610
and check which ones had the programs installed

76
00:02:35,610 --> 00:02:36,990
and which ones didn't.

77
00:02:36,990 --> 00:02:38,490
In large networks like this,

78
00:02:38,490 --> 00:02:40,020
preventing excessive installations

79
00:02:40,020 --> 00:02:42,060
is going to be your best solution.

80
00:02:42,060 --> 00:02:43,500
In most of our corporate networks,

81
00:02:43,500 --> 00:02:44,520
it's going to be common for us

82
00:02:44,520 --> 00:02:46,050
to create a secure baseline image

83
00:02:46,050 --> 00:02:47,670
that we're going to use for all the workstations

84
00:02:47,670 --> 00:02:49,620
that are getting installed in our company

85
00:02:49,620 --> 00:02:51,900
from when they're first installed at your desk.

86
00:02:51,900 --> 00:02:53,820
Now, this image will have the operating system,

87
00:02:53,820 --> 00:02:56,520
the minimum applications required for that organization,

88
00:02:56,520 --> 00:02:58,350
and a strict configuration policy

89
00:02:58,350 --> 00:03:00,900
that's all set up for all of those machines.

90
00:03:00,900 --> 00:03:02,100
Now, these policies

91
00:03:02,100 --> 00:03:03,870
will have to be updated and changed over time

92
00:03:03,870 --> 00:03:05,880
based on our changing business requirements.

93
00:03:05,880 --> 00:03:06,720
And to do that,

94
00:03:06,720 --> 00:03:08,910
we're going to be pushing out group policies and other things

95
00:03:08,910 --> 00:03:11,430
across our organization using those.

96
00:03:11,430 --> 00:03:12,390
So now that we've discussed

97
00:03:12,390 --> 00:03:14,340
why we should be using a secure baseline

98
00:03:14,340 --> 00:03:17,040
with the minimum level of functionality for our systems,

99
00:03:17,040 --> 00:03:18,930
we have to figure out how are we going to stop Gary

100
00:03:18,930 --> 00:03:21,090
down in accounting from downloading and installing

101
00:03:21,090 --> 00:03:24,510
his own piece of software on our organization's computers.

102
00:03:24,510 --> 00:03:25,343
To do this,

103
00:03:25,343 --> 00:03:27,330
what we want to do is restrict which applications

104
00:03:27,330 --> 00:03:29,460
can be run on a given workstation.

105
00:03:29,460 --> 00:03:31,110
Now, let me give you an example of this.

106
00:03:31,110 --> 00:03:32,100
Let's say you and I

107
00:03:32,100 --> 00:03:34,470
wanted to go to a trendy nightclub this Friday night.

108
00:03:34,470 --> 00:03:36,900
We show up at the door and were greeted by the bouncer.

109
00:03:36,900 --> 00:03:38,010
Now the bouncer looks at us

110
00:03:38,010 --> 00:03:39,270
and he asks, "If we're on the list?"

111
00:03:39,270 --> 00:03:41,730
So I give him my name and I say, "Hey, I'm Jason Dion,"

112
00:03:41,730 --> 00:03:43,440
and he looks at the list and realizes

113
00:03:43,440 --> 00:03:45,690
I'm not on his list because I'm not that trendy.

114
00:03:45,690 --> 00:03:48,240
Now this means he's not going to let me get into that club.

115
00:03:48,240 --> 00:03:49,590
Now maybe you're cooler than I am

116
00:03:49,590 --> 00:03:50,850
and your name was on the list,

117
00:03:50,850 --> 00:03:51,720
and if that's the case,

118
00:03:51,720 --> 00:03:53,340
they're going to let you into the club.

119
00:03:53,340 --> 00:03:54,600
Now, if each of us was considered

120
00:03:54,600 --> 00:03:56,280
to be an application on a computer,

121
00:03:56,280 --> 00:03:57,630
this nightclub example

122
00:03:57,630 --> 00:03:58,920
shows you what we're talking about

123
00:03:58,920 --> 00:04:01,620
when we talk about a concept known as allowlisting.

124
00:04:01,620 --> 00:04:02,850
Based on allowlisting,

125
00:04:02,850 --> 00:04:05,490
I'm going to be denied because my name isn't on the list.

126
00:04:05,490 --> 00:04:07,290
With application allowlisting,

127
00:04:07,290 --> 00:04:09,330
only applications that are on the approved list

128
00:04:09,330 --> 00:04:12,090
are going to be allowed to be run on that operating system,

129
00:04:12,090 --> 00:04:13,530
and all the other applications

130
00:04:13,530 --> 00:04:15,120
will get blocked from running.

131
00:04:15,120 --> 00:04:17,310
This is the most secure way of doing this,

132
00:04:17,310 --> 00:04:18,240
and this is what we want to do

133
00:04:18,240 --> 00:04:19,769
to prevent Gary down in accounting

134
00:04:19,769 --> 00:04:21,750
from installing things on our systems.

135
00:04:21,750 --> 00:04:23,880
Now, if you think back to your Network+ studies,

136
00:04:23,880 --> 00:04:25,290
you are probably familiar with the concept

137
00:04:25,290 --> 00:04:27,000
of an access control list.

138
00:04:27,000 --> 00:04:28,020
And this is essentially,

139
00:04:28,020 --> 00:04:30,900
an explicit allow statement in an access control list,

140
00:04:30,900 --> 00:04:32,550
but at an application level,

141
00:04:32,550 --> 00:04:34,200
instead of at a network level.

142
00:04:34,200 --> 00:04:35,640
Now, for my next example,

143
00:04:35,640 --> 00:04:36,840
let's say that my friend and I

144
00:04:36,840 --> 00:04:38,280
are going to head to the airport.

145
00:04:38,280 --> 00:04:39,330
We arrive at the airport

146
00:04:39,330 --> 00:04:40,650
and we walk up to the ticket counter

147
00:04:40,650 --> 00:04:42,540
and we try to check in with the agent at the counter,

148
00:04:42,540 --> 00:04:45,210
so we hand her our passports and she looks at our names.

149
00:04:45,210 --> 00:04:46,680
After consulting her computer,

150
00:04:46,680 --> 00:04:49,050
she sees that my friend is apparently a bad guy

151
00:04:49,050 --> 00:04:50,970
because he's on the no-fly list.

152
00:04:50,970 --> 00:04:52,770
Now because his name's on that list,

153
00:04:52,770 --> 00:04:54,510
he has denied the ability to check in

154
00:04:54,510 --> 00:04:56,460
and he's not able to take the flight.

155
00:04:56,460 --> 00:04:57,780
Now, my name on the other hand,

156
00:04:57,780 --> 00:04:59,040
is not on that list,

157
00:04:59,040 --> 00:05:01,740
and therefore, I'm allowed to go and board the airplane.

158
00:05:01,740 --> 00:05:04,410
This is an example of how blocklisting works,

159
00:05:04,410 --> 00:05:06,060
With application blocklisting,

160
00:05:06,060 --> 00:05:07,980
any application that's placed on the list

161
00:05:07,980 --> 00:05:09,480
is going to be prevented from running

162
00:05:09,480 --> 00:05:12,420
while all other applications will be permitted to run.

163
00:05:12,420 --> 00:05:14,520
This is considered to be a less secure method

164
00:05:14,520 --> 00:05:16,320
than using allowlisting, though,

165
00:05:16,320 --> 00:05:17,490
because if you're an application

166
00:05:17,490 --> 00:05:18,810
whose name shows up on the block list,

167
00:05:18,810 --> 00:05:19,860
you're going to be denied,

168
00:05:19,860 --> 00:05:22,470
but anything else, will be allowed to proceed.

169
00:05:22,470 --> 00:05:23,437
Now, you may be wondering,

170
00:05:23,437 --> 00:05:25,740
"Why do we have these two different types of lists?"

171
00:05:25,740 --> 00:05:28,890
Well, using application allowlisting is much more secure,

172
00:05:28,890 --> 00:05:31,620
as I said, because everything is denied by default

173
00:05:31,620 --> 00:05:33,540
and only the things we specifically list

174
00:05:33,540 --> 00:05:35,190
are going to be allowed to run.

175
00:05:35,190 --> 00:05:37,470
Unfortunately, though, this is much more difficult

176
00:05:37,470 --> 00:05:38,550
to set up and manage

177
00:05:38,550 --> 00:05:40,770
because every time an application is updated,

178
00:05:40,770 --> 00:05:43,230
you're going to have to update your allowlist too.

179
00:05:43,230 --> 00:05:45,900
After all, Microsoft Word 2016

180
00:05:45,900 --> 00:05:49,080
is not the exact same code as Version 2 or Version 3

181
00:05:49,080 --> 00:05:52,290
or the current version of Office 365.

182
00:05:52,290 --> 00:05:54,270
For this reason, many companies have chosen

183
00:05:54,270 --> 00:05:56,250
to use blocklist approaches instead,

184
00:05:56,250 --> 00:05:58,050
but there's a problem with this approach too

185
00:05:58,050 --> 00:05:59,250
because everything is allowed

186
00:05:59,250 --> 00:06:01,920
except what you explicitly deny in that list.

187
00:06:01,920 --> 00:06:03,840
And so every new variation of malware

188
00:06:03,840 --> 00:06:06,240
or a new program that comes out is going to be allowed

189
00:06:06,240 --> 00:06:08,640
until you create a blocklist rule for it.

190
00:06:08,640 --> 00:06:09,840
This becomes a big challenge

191
00:06:09,840 --> 00:06:11,880
when you're dealing with allowlisting and blocklisting

192
00:06:11,880 --> 00:06:13,170
because you have to manage that list

193
00:06:13,170 --> 00:06:15,540
across all the workstations in your network.

194
00:06:15,540 --> 00:06:16,890
Thankfully, though, if you're using

195
00:06:16,890 --> 00:06:18,840
a Microsoft Windows Domain environment,

196
00:06:18,840 --> 00:06:19,673
you can use

197
00:06:19,673 --> 00:06:21,816
your Microsoft Active Directory Domain Controller

198
00:06:21,816 --> 00:06:23,250
to be able to essentially manage all your lists

199
00:06:23,250 --> 00:06:25,440
and deploy them through your group policies.

200
00:06:25,440 --> 00:06:28,290
So remember, when it comes to restricting applications,

201
00:06:28,290 --> 00:06:29,910
you can do this one of two ways.

202
00:06:29,910 --> 00:06:32,640
You can use an allowlist or a blocklist.

203
00:06:32,640 --> 00:06:33,870
If you use an allowlist,

204
00:06:33,870 --> 00:06:35,100
everything is going to be blocked

205
00:06:35,100 --> 00:06:36,840
except what is on the list.

206
00:06:36,840 --> 00:06:38,700
If you use a blocklist, on the other hand,

207
00:06:38,700 --> 00:06:41,460
everything will be allowed except what's on that list.

208
00:06:41,460 --> 00:06:43,380
This is the way you have to think about these things,

209
00:06:43,380 --> 00:06:44,550
and which one you're going to use

210
00:06:44,550 --> 00:06:45,900
is going to depend on how secure

211
00:06:45,900 --> 00:06:47,490
you want your organization to be.

212
00:06:47,490 --> 00:06:48,900
For higher levels of security,

213
00:06:48,900 --> 00:06:50,310
you should use an allowlist,

214
00:06:50,310 --> 00:06:52,830
but at a minimum, you should be using a blocklist

215
00:06:52,830 --> 00:06:55,020
to block any applications you know are malicious

216
00:06:55,020 --> 00:06:56,340
or to block any applications

217
00:06:56,340 --> 00:06:58,540
that you don't want running on your network.

