1
00:00:00,000 --> 00:00:00,990
In this lesson,

2
00:00:00,990 --> 00:00:04,260
we're going to take a look at an IPS or IDS log,

3
00:00:04,260 --> 00:00:06,630
and we're basically going to do that by using a sample question

4
00:00:06,630 --> 00:00:09,120
to see if you can understand how to take apart one

5
00:00:09,120 --> 00:00:11,550
of these questions during your exam.

6
00:00:11,550 --> 00:00:13,470
Now, in this question we're going to be asked which

7
00:00:13,470 --> 00:00:16,230
of the following event IDs represents the biggest threat

8
00:00:16,230 --> 00:00:18,330
to your organization's enterprise network

9
00:00:18,330 --> 00:00:20,100
and should be investigate immediately

10
00:00:20,100 --> 00:00:23,130
by the organization's cybersecurity analysts.

11
00:00:23,130 --> 00:00:25,740
Then we see a whole bunch of different events here,

12
00:00:25,740 --> 00:00:28,890
and we see the date, the time, the severity, the event ID,

13
00:00:28,890 --> 00:00:31,230
the description, and the action taken.

14
00:00:31,230 --> 00:00:32,220
Based on all of this,

15
00:00:32,220 --> 00:00:34,140
you would get a multiple choice question

16
00:00:34,140 --> 00:00:36,180
with four different event IDs,

17
00:00:36,180 --> 00:00:38,190
and you would then select out of those event IDs,

18
00:00:38,190 --> 00:00:41,310
which one is the most severe for your organization.

19
00:00:41,310 --> 00:00:43,440
But to make this a little bit more challenging,

20
00:00:43,440 --> 00:00:45,630
we're not going to give you four choices here.

21
00:00:45,630 --> 00:00:47,640
I'm actually going to let you choose from any

22
00:00:47,640 --> 00:00:49,980
of these event IDs to see if you're correct.

23
00:00:49,980 --> 00:00:52,110
So what I'd like you to do here is pause the video

24
00:00:52,110 --> 00:00:55,170
for a moment and then come back when you have the event ID

25
00:00:55,170 --> 00:00:57,300
that you think is the most severe,

26
00:00:57,300 --> 00:00:58,710
and then I'm going to give you the right answer

27
00:00:58,710 --> 00:01:00,900
and explain why it was right.

28
00:01:00,900 --> 00:01:02,670
Alright, are you back with me now?

29
00:01:02,670 --> 00:01:04,170
You ready to see the right answer?

30
00:01:04,170 --> 00:01:06,840
Well, the right answer here is actually going to be one

31
00:01:06,840 --> 00:01:09,810
of the high severity ones, but which one?

32
00:01:09,810 --> 00:01:12,543
There's actually six different high severity alerts here

33
00:01:12,543 --> 00:01:15,630
that were detected by this IDS or IPS.

34
00:01:15,630 --> 00:01:17,640
And in this case, because it is blocking action,

35
00:01:17,640 --> 00:01:21,240
we know this is an IPS or an intrusion prevention system

36
00:01:21,240 --> 00:01:24,450
and not an IDS an intrusion detection system.

37
00:01:24,450 --> 00:01:27,270
So which of our six highs is going to be the one

38
00:01:27,270 --> 00:01:29,400
that is the most dangerous for us?

39
00:01:29,400 --> 00:01:31,500
Well, in this case, it's actually going

40
00:01:31,500 --> 00:01:36,500
to be the data exfiltration detection at line 4130.

41
00:01:36,690 --> 00:01:39,060
Now it's not just because this was a high severity though,

42
00:01:39,060 --> 00:01:41,310
because we had six different high severities.

43
00:01:41,310 --> 00:01:42,840
So let's take a look at each of those six

44
00:01:42,840 --> 00:01:44,730
and then we could talk about why data exfiltration

45
00:01:44,730 --> 00:01:46,110
was the right answer.

46
00:01:46,110 --> 00:01:48,750
Now, the first high we had was up at the second line,

47
00:01:48,750 --> 00:01:51,000
which is line 4105,

48
00:01:51,000 --> 00:01:51,960
and you see the description

49
00:01:51,960 --> 00:01:54,450
as an SQL injection attack detected.

50
00:01:54,450 --> 00:01:56,370
Now, normally that would be a very severe thing

51
00:01:56,370 --> 00:01:57,870
because it has to do with our database

52
00:01:57,870 --> 00:01:59,670
and people could try to attack our database

53
00:01:59,670 --> 00:02:02,670
through an SQL injection and then take our data out of it.

54
00:02:02,670 --> 00:02:04,440
But this was actually blocked,

55
00:02:04,440 --> 00:02:06,270
and since it was blocked by the IPS,

56
00:02:06,270 --> 00:02:07,290
it's really not a big deal

57
00:02:07,290 --> 00:02:10,199
because the IPS protected us like it was supposed to.

58
00:02:10,199 --> 00:02:12,510
So we can say that one is not that dangerous

59
00:02:12,510 --> 00:02:14,100
and we'll move it down the list.

60
00:02:14,100 --> 00:02:15,510
Let's go to the next high.

61
00:02:15,510 --> 00:02:17,970
The next high we have is 4110,

62
00:02:17,970 --> 00:02:20,130
which is a buffer overflow attack, which again,

63
00:02:20,130 --> 00:02:21,510
is another serious issue,

64
00:02:21,510 --> 00:02:23,490
but again, it was blocked by the IPS

65
00:02:23,490 --> 00:02:25,770
and therefore it's not an issue for our systems.

66
00:02:25,770 --> 00:02:27,360
It wasn't successful in running

67
00:02:27,360 --> 00:02:29,940
that attack even though the attack was attempted.

68
00:02:29,940 --> 00:02:33,030
The next one we have is another high at 4115,

69
00:02:33,030 --> 00:02:35,490
and it was anomalous privilege escalation detected.

70
00:02:35,490 --> 00:02:36,360
This means somebody was able

71
00:02:36,360 --> 00:02:39,360
to go from a regular account into a administrative account

72
00:02:39,360 --> 00:02:42,600
or from a guest user into an authenticated user.

73
00:02:42,600 --> 00:02:45,570
But again, either way, this was blocked by the IPS.

74
00:02:45,570 --> 00:02:47,880
So once again, it doesn't affect our systems

75
00:02:47,880 --> 00:02:49,560
and we can then push that to the side

76
00:02:49,560 --> 00:02:51,180
and look at the next high.

77
00:02:51,180 --> 00:02:53,700
The next high we have is 4120,

78
00:02:53,700 --> 00:02:55,650
which was an external brute force attack,

79
00:02:55,650 --> 00:02:56,760
and again, it was blocked.

80
00:02:56,760 --> 00:02:58,470
And so you're seeing the pattern here.

81
00:02:58,470 --> 00:03:00,930
If it was blocked, it's not as big of a deal for us

82
00:03:00,930 --> 00:03:03,540
because that was stopped by our defenses.

83
00:03:03,540 --> 00:03:05,430
Now, one of the things you do want to keep in mind though is

84
00:03:05,430 --> 00:03:07,290
even though these things are being blocked,

85
00:03:07,290 --> 00:03:09,690
you would want to see who is doing these attacks.

86
00:03:09,690 --> 00:03:11,670
And if it's the same person, you may want to go ahead

87
00:03:11,670 --> 00:03:14,070
and add in something like blocking their IP address

88
00:03:14,070 --> 00:03:15,390
or doing other things to prevent them

89
00:03:15,390 --> 00:03:17,070
from even getting to your IPS.

90
00:03:17,070 --> 00:03:19,320
But again, the IPS was doing its job here

91
00:03:19,320 --> 00:03:21,060
by blocking those issues.

92
00:03:21,060 --> 00:03:23,490
The next high we have is 4125,

93
00:03:23,490 --> 00:03:25,170
which was a network scan being conducted

94
00:03:25,170 --> 00:03:26,460
from an internal IP.

95
00:03:26,460 --> 00:03:29,370
Honestly, a network scan is not really that big of a deal.

96
00:03:29,370 --> 00:03:31,590
It can be an indication that somebody is going to attack you

97
00:03:31,590 --> 00:03:33,270
because they're performing reconnaissance,

98
00:03:33,270 --> 00:03:35,370
but the scan itself is not that dangerous.

99
00:03:35,370 --> 00:03:38,400
And again, here the IPS was able to contain that for us,

100
00:03:38,400 --> 00:03:40,380
so it wasn't really affecting our systems.

101
00:03:40,380 --> 00:03:43,080
And then finally we get to the high of 4130,

102
00:03:43,080 --> 00:03:45,360
which was the data exfiltration detected.

103
00:03:45,360 --> 00:03:48,930
It was an alert, not a block, and the admin was notified.

104
00:03:48,930 --> 00:03:50,970
So at this point, because it alerted on it,

105
00:03:50,970 --> 00:03:52,890
we need to go take action on it.

106
00:03:52,890 --> 00:03:54,150
If you look through some of the other ones,

107
00:03:54,150 --> 00:03:57,090
you do see some others that were alerted or monitored.

108
00:03:57,090 --> 00:04:00,300
In the case of the medium severity incident at 3301

109
00:04:00,300 --> 00:04:01,860
in the middle of this page,

110
00:04:01,860 --> 00:04:05,100
you could see there was an ICMP Echo (Ping) Request Flood,

111
00:04:05,100 --> 00:04:06,360
and that was monitored.

112
00:04:06,360 --> 00:04:07,860
So this is something that was happening

113
00:04:07,860 --> 00:04:10,410
and we saw it happen, but we didn't stop it.

114
00:04:10,410 --> 00:04:12,690
Now again, this is just an echo request,

115
00:04:12,690 --> 00:04:14,220
which basically means they're trying to flood you

116
00:04:14,220 --> 00:04:16,290
with echo requests and it would be an issue,

117
00:04:16,290 --> 00:04:18,839
but it's not a major issue like a data breach is.

118
00:04:18,839 --> 00:04:21,510
So again, the data breach will be much more important.

119
00:04:21,510 --> 00:04:23,370
And then as we look at some of the other ones that alerted.

120
00:04:23,370 --> 00:04:25,440
We had unusual outbound traffic patterns.

121
00:04:25,440 --> 00:04:27,180
We had excessive login attempts.

122
00:04:27,180 --> 00:04:29,460
We had suspicious file download activity.

123
00:04:29,460 --> 00:04:32,460
We had things like insecure protocols being detected,

124
00:04:32,460 --> 00:04:35,310
like maybe somebody was using Telnet instead of SSH,

125
00:04:35,310 --> 00:04:37,470
and we had ARP spoofing attempts detected,

126
00:04:37,470 --> 00:04:39,600
and we had unusual inbound traffic patterns

127
00:04:39,600 --> 00:04:41,940
and we had multiple insecure login attempts.

128
00:04:41,940 --> 00:04:44,940
All of those were issues, but they were either medium or low

129
00:04:44,940 --> 00:04:47,040
and they were alerted on, but they weren't blocked.

130
00:04:47,040 --> 00:04:49,230
But because we had that high data exfiltration

131
00:04:49,230 --> 00:04:50,880
and it was an alert and not a block,

132
00:04:50,880 --> 00:04:52,650
that becomes our most significant one

133
00:04:52,650 --> 00:04:53,483
and the one that we need to

134
00:04:53,483 --> 00:04:55,380
focus our investigations on first

135
00:04:55,380 --> 00:04:56,820
with our cybersecurity analysts to be able

136
00:04:56,820 --> 00:04:58,830
to determine was it successful?

137
00:04:58,830 --> 00:05:00,390
Were they able to exfiltrate data?

138
00:05:00,390 --> 00:05:03,360
And if so, how much data, and what kind of data?

139
00:05:03,360 --> 00:05:05,310
Because now we'll be in the middle of an incident response

140
00:05:05,310 --> 00:05:07,500
and try to clean up from this data exfiltration

141
00:05:07,500 --> 00:05:09,180
that happened and that was actually able to go

142
00:05:09,180 --> 00:05:10,440
through our IPS.

143
00:05:10,440 --> 00:05:12,360
So we're going to want to retune our IDS to block

144
00:05:12,360 --> 00:05:13,740
that in the future and not allow

145
00:05:13,740 --> 00:05:15,540
those kind of things from happening.

146
00:05:15,540 --> 00:05:17,640
All right. If you get something like this on the exam,

147
00:05:17,640 --> 00:05:19,890
remember they're going to give you four choices

148
00:05:19,890 --> 00:05:21,480
and out of those four choices,

149
00:05:21,480 --> 00:05:23,340
you might get four highs here.

150
00:05:23,340 --> 00:05:25,350
And what you want to look for is were these blocked?

151
00:05:25,350 --> 00:05:27,120
If they were blocked, it's already been mitigated

152
00:05:27,120 --> 00:05:29,070
and it didn't have an effect on your network.

153
00:05:29,070 --> 00:05:30,990
But if it was an alert or a monitor,

154
00:05:30,990 --> 00:05:31,823
that means it made it through

155
00:05:31,823 --> 00:05:33,240
that network security appliance

156
00:05:33,240 --> 00:05:34,740
and it actually had an effect on your network,

157
00:05:34,740 --> 00:05:37,050
so you need to investigate it and figure out what they took

158
00:05:37,050 --> 00:05:38,160
and what they're able to steal

159
00:05:38,160 --> 00:05:39,660
during that data exfiltration.

