1
00:00:06,480 --> 00:00:09,120
- So welcome to lesson
10, Compare and Contrast

2
00:00:09,120 --> 00:00:12,330
Security Implications of
Different Architecture Models.

3
00:00:12,330 --> 00:00:14,700
In lesson 10.1, we're gonna talk about

4
00:00:14,700 --> 00:00:17,880
a variety of computing
architecture models.

5
00:00:17,880 --> 00:00:21,300
A computing architecture model
is a conceptual framework.

6
00:00:21,300 --> 00:00:23,550
It's what we use to describe the design

7
00:00:23,550 --> 00:00:25,350
and the organization of a network.

8
00:00:25,350 --> 00:00:26,730
And what it provides for us

9
00:00:26,730 --> 00:00:30,450
is this high level view of the
components, the interfaces,

10
00:00:30,450 --> 00:00:34,410
and the relationships between
different parts of the system.

11
00:00:34,410 --> 00:00:37,860
Now, examples of computing
architecture include centralized,

12
00:00:37,860 --> 00:00:41,790
decentralized client server,
industrial control systems,

13
00:00:41,790 --> 00:00:44,490
cloud, and microservices.

14
00:00:44,490 --> 00:00:46,440
I'm sure that you are
familiar with some of these

15
00:00:46,440 --> 00:00:48,540
but probably not all of these.

16
00:00:48,540 --> 00:00:50,790
So we're gonna go
through each one of them.

17
00:00:50,790 --> 00:00:52,800
But before we do that, I
wanna talk a little bit about

18
00:00:52,800 --> 00:00:55,260
some cybersecurity considerations

19
00:00:55,260 --> 00:00:57,333
for each of the different architectures.

20
00:00:59,130 --> 00:01:01,260
So here are cybersecurity considerations.

21
00:01:01,260 --> 00:01:02,430
They're not in priority order,

22
00:01:02,430 --> 00:01:04,560
they're actually in alphabetical order.

23
00:01:04,560 --> 00:01:05,910
But when we're thinking about

24
00:01:05,910 --> 00:01:07,590
what's the appropriate architecture

25
00:01:07,590 --> 00:01:09,540
for whatever it's we're trying to do,

26
00:01:09,540 --> 00:01:10,890
we wanna be thinking about

27
00:01:10,890 --> 00:01:13,080
what are the access control options?

28
00:01:13,080 --> 00:01:15,660
What is our availability or uptime?

29
00:01:15,660 --> 00:01:18,275
Will it be in compliance
with any regulations

30
00:01:18,275 --> 00:01:21,240
that we are obligated to follow?

31
00:01:21,240 --> 00:01:24,660
Can we implement configuration management?

32
00:01:24,660 --> 00:01:25,950
What is the cost?

33
00:01:25,950 --> 00:01:28,590
The cost of implementing,
the cost of managing,

34
00:01:28,590 --> 00:01:30,390
the cost of maintaining,

35
00:01:30,390 --> 00:01:33,780
the cost of refreshing
and replacing over time?

36
00:01:33,780 --> 00:01:36,663
What is the ease of recovery
if we have a failure?

37
00:01:37,800 --> 00:01:39,330
How well can we do provisioning

38
00:01:39,330 --> 00:01:41,550
and can we automate our provisioning?

39
00:01:41,550 --> 00:01:43,290
How resilient is it?

40
00:01:43,290 --> 00:01:46,173
So again, if there's failures,
how well can we recover?

41
00:01:47,100 --> 00:01:48,780
What is the risk transference?

42
00:01:48,780 --> 00:01:51,450
Meaning who can assume the risk here.

43
00:01:51,450 --> 00:01:52,350
Is it scalable?

44
00:01:52,350 --> 00:01:54,660
Meaning, will it grow with us?

45
00:01:54,660 --> 00:01:56,730
Does it strategically align

46
00:01:56,730 --> 00:01:59,130
with the needs of the organization?

47
00:01:59,130 --> 00:02:02,820
And do we have really robust
vulnerability management?

48
00:02:02,820 --> 00:02:04,860
Because we know in every architecture

49
00:02:04,860 --> 00:02:06,570
there are vulnerabilities.

50
00:02:06,570 --> 00:02:08,340
So we need to be able to implement

51
00:02:08,340 --> 00:02:12,240
a very robust vulnerability
management program.

52
00:02:12,240 --> 00:02:13,920
So if you are assessing

53
00:02:13,920 --> 00:02:15,240
these various different architectures,

54
00:02:15,240 --> 00:02:18,483
you wanna be thinking about
all of these considerations.

55
00:02:20,190 --> 00:02:22,440
So let's start going
through them one by one.

56
00:02:22,440 --> 00:02:24,570
In a centralized computing environment,

57
00:02:24,570 --> 00:02:26,700
all processing and data storage

58
00:02:26,700 --> 00:02:30,090
is gonna be managed and
controlled by a central server,

59
00:02:30,090 --> 00:02:32,760
or generally speaking by a mainframe

60
00:02:32,760 --> 00:02:35,133
rather than on an individual device.

61
00:02:36,180 --> 00:02:39,120
So users are going to
access applications and data

62
00:02:39,120 --> 00:02:41,970
through dumb terminals or thin clients.

63
00:02:41,970 --> 00:02:45,420
But the processing, the
data storage, the security,

64
00:02:45,420 --> 00:02:48,420
and the resiliency
services are all managed

65
00:02:48,420 --> 00:02:51,063
and controlled by the central server.

66
00:02:52,020 --> 00:02:53,880
Advantages and disadvantages, right?

67
00:02:53,880 --> 00:02:55,020
Everything's in one place,

68
00:02:55,020 --> 00:02:58,500
but if we lose that central
server, that mainframe,

69
00:02:58,500 --> 00:03:00,000
we're dead in the water, right?

70
00:03:00,000 --> 00:03:01,443
We really can't do anything.

71
00:03:03,510 --> 00:03:05,520
In a client server architecture,

72
00:03:05,520 --> 00:03:08,250
what we have is a
decentralized computing model.

73
00:03:08,250 --> 00:03:10,950
Now it's the one that you
and I generally work in.

74
00:03:10,950 --> 00:03:12,990
It's in which a client device communicates

75
00:03:12,990 --> 00:03:16,170
with a server to request services or data.

76
00:03:16,170 --> 00:03:18,840
Probably one of the most
common configurations now.

77
00:03:18,840 --> 00:03:21,870
Now the client server model is
based on a division of labor

78
00:03:21,870 --> 00:03:24,330
between the client and the server.

79
00:03:24,330 --> 00:03:27,450
The client typically
handles the user interface,

80
00:03:27,450 --> 00:03:30,870
the application logic,
and local data storage

81
00:03:30,870 --> 00:03:34,200
where the server is going
to manage data storage,

82
00:03:34,200 --> 00:03:38,520
processing, and the management
of our shared resources.

83
00:03:38,520 --> 00:03:40,920
So we've got a good division of labor,

84
00:03:40,920 --> 00:03:44,070
but because all these
clients talk to the server,

85
00:03:44,070 --> 00:03:47,583
we have lots of conduits
for malicious behavior.

86
00:03:49,800 --> 00:03:52,830
We could also have some
vulnerable operating systems

87
00:03:52,830 --> 00:03:56,070
and applications, malware distribution,

88
00:03:56,070 --> 00:03:58,260
and if we have any
unprotected or weak links

89
00:03:58,260 --> 00:04:00,723
it could impact the other systems.

90
00:04:04,200 --> 00:04:07,260
Now, Industrial Control
Systems are network devices

91
00:04:07,260 --> 00:04:10,320
and software used to monitor and control

92
00:04:10,320 --> 00:04:13,200
industrial processes such as manufacturing

93
00:04:13,200 --> 00:04:16,353
or power generation, and water treatment.

94
00:04:17,220 --> 00:04:19,440
The components of an ICS system,

95
00:04:19,440 --> 00:04:20,910
an Industrial Control System

96
00:04:20,910 --> 00:04:23,190
are gonna include hardware
devices such as sensors,

97
00:04:23,190 --> 00:04:24,990
actuators, and controllers,

98
00:04:24,990 --> 00:04:28,650
and some very customized
software applications.

99
00:04:28,650 --> 00:04:31,650
An ICS, Industrial Control
System architecture,

100
00:04:31,650 --> 00:04:34,440
can be centralized or
it can be decentralized

101
00:04:34,440 --> 00:04:37,800
depending on the specific
design and implementation.

102
00:04:37,800 --> 00:04:40,560
Now, a SCADA system, Supervisory Control

103
00:04:40,560 --> 00:04:44,580
and Data Acquisition is really
a specialized ICS system

104
00:04:44,580 --> 00:04:48,540
that is designed specifically
for monitoring and controlling

105
00:04:48,540 --> 00:04:53,070
large scale industrial
processes like a gas pipeline,

106
00:04:53,070 --> 00:04:55,920
or an electrical grid, or a water system.

107
00:04:55,920 --> 00:04:57,930
So what are some of our
security considerations

108
00:04:57,930 --> 00:04:59,370
here when we talk about ICS

109
00:04:59,370 --> 00:05:02,910
and really even more
specifically about SCADA?

110
00:05:02,910 --> 00:05:06,360
Is that many of these systems
have to have a very long life.

111
00:05:06,360 --> 00:05:08,670
They're designed for 20 plus years.

112
00:05:08,670 --> 00:05:11,670
So if you think about how
often components change,

113
00:05:11,670 --> 00:05:14,858
how often hardware is updated,
and more importantly right,

114
00:05:14,858 --> 00:05:18,510
what the end of life is
on operating systems,

115
00:05:18,510 --> 00:05:20,670
we can see that, you
know going out 20 years

116
00:05:20,670 --> 00:05:23,340
can potentially introduce
a lot of vulnerabilities.

117
00:05:23,340 --> 00:05:26,850
'Cause we'll be way past end
of life and end of support.

118
00:05:26,850 --> 00:05:28,920
There's also very limited
maintenance windows

119
00:05:28,920 --> 00:05:30,210
in a lot of these systems.

120
00:05:30,210 --> 00:05:33,510
Most of 'em are operating seven
days a week, 24 hours a day,

121
00:05:33,510 --> 00:05:38,510
365 days a year, and there
may be minimal visibility.

122
00:05:38,580 --> 00:05:40,308
Again, these distributed systems,

123
00:05:40,308 --> 00:05:42,750
Industrial Control Systems, particular,

124
00:05:42,750 --> 00:05:44,010
you may not be able to see everything

125
00:05:44,010 --> 00:05:45,183
that's that's going on.

126
00:05:48,150 --> 00:05:49,410
Next we have cloud computing.

127
00:05:49,410 --> 00:05:51,810
And this is one that I'm sure
you're all very familiar with.

128
00:05:51,810 --> 00:05:54,450
Cloud computing is the
delivery of computing services

129
00:05:54,450 --> 00:05:57,090
over the internet, a.k.a, "the cloud",

130
00:05:57,090 --> 00:05:59,010
right, that scale to business needs.

131
00:05:59,010 --> 00:06:00,000
And scale to business needs

132
00:06:00,000 --> 00:06:01,560
is an important part of that sentence.

133
00:06:01,560 --> 00:06:04,680
It's not just that we're
delivering services over the cloud,

134
00:06:04,680 --> 00:06:06,930
so delivering services over the cloud

135
00:06:06,930 --> 00:06:10,410
that scale to business needs.

136
00:06:10,410 --> 00:06:13,440
Now, cloud computing can be
considered a hybrid architecture

137
00:06:13,440 --> 00:06:15,210
because it does involve a combination

138
00:06:15,210 --> 00:06:16,380
of centralized management

139
00:06:16,380 --> 00:06:19,170
and decentralized
distribution of resources.

140
00:06:19,170 --> 00:06:21,090
And we've got two full lessons coming up

141
00:06:21,090 --> 00:06:22,380
about cloud computing.

142
00:06:22,380 --> 00:06:24,090
One from a user perspective

143
00:06:24,090 --> 00:06:26,910
and the other from a architecture

144
00:06:26,910 --> 00:06:28,413
or data center perspective.

145
00:06:30,540 --> 00:06:32,520
And then we have microservices.

146
00:06:32,520 --> 00:06:34,050
Microservices architecture

147
00:06:34,050 --> 00:06:36,870
is composed of these
small independent services

148
00:06:36,870 --> 00:06:39,540
that communicate with
each other over a network

149
00:06:39,540 --> 00:06:42,960
enabling greater
scalability and flexibility.

150
00:06:42,960 --> 00:06:45,330
Now, each microservice is in itself

151
00:06:45,330 --> 00:06:49,380
a self-contained component
that can be deployed, updated,

152
00:06:49,380 --> 00:06:51,600
and scaled independently.

153
00:06:51,600 --> 00:06:54,900
So microservices architecture
is generally considered to be

154
00:06:54,900 --> 00:06:57,990
a decentralized computing model.

155
00:06:57,990 --> 00:06:59,280
So now that we've gone through all these

156
00:06:59,280 --> 00:07:02,730
as we're thinking about various
threats and vulnerabilities,

157
00:07:02,730 --> 00:07:04,500
I want you to be applying those

158
00:07:04,500 --> 00:07:08,370
to what you now know about
these different architectures.

159
00:07:08,370 --> 00:07:10,860
And that brings us to a
three second challenge.

160
00:07:10,860 --> 00:07:12,540
Five questions, three seconds each.

161
00:07:12,540 --> 00:07:13,373
Let's do it.

162
00:07:14,287 --> 00:07:17,607
"An example of this architecture
is mainframe computing."

163
00:07:18,480 --> 00:07:20,703
One, two, three.

164
00:07:21,690 --> 00:07:23,253
That's gonna be centralized.

165
00:07:24,780 --> 00:07:27,330
Question two, "Microsoft Windows networks

166
00:07:27,330 --> 00:07:29,680
are an example of this
computing architecture."

167
00:07:30,840 --> 00:07:33,033
One, two, three.

168
00:07:34,080 --> 00:07:36,963
That's gonna be client,
server or decentralized.

169
00:07:38,640 --> 00:07:42,660
Question three, "Delivery of
services over the internet

170
00:07:42,660 --> 00:07:44,880
that scale to business needs."

171
00:07:44,880 --> 00:07:46,030
What's that considered?

172
00:07:47,310 --> 00:07:48,963
One, two, three.

173
00:07:50,280 --> 00:07:51,753
That's cloud computing.

174
00:07:53,310 --> 00:07:57,270
Number four, "Small independent
services that communicate

175
00:07:57,270 --> 00:08:00,240
with each other over a network."

176
00:08:00,240 --> 00:08:02,370
This is the one you might
be least familiar with.

177
00:08:02,370 --> 00:08:04,083
One, two, three.

178
00:08:04,920 --> 00:08:08,250
It's referred to as microservices.

179
00:08:08,250 --> 00:08:10,117
And lastly, number five,

180
00:08:10,117 --> 00:08:12,687
"Widely used in factory automation."

181
00:08:13,770 --> 00:08:15,063
One, two, three.

182
00:08:15,930 --> 00:08:19,563
That's gonna be Industrial
Control Systems or ICS.

183
00:08:21,570 --> 00:08:23,880
Alright, let's do a
security in action about,

184
00:08:23,880 --> 00:08:25,410
well a boomer of all things.

185
00:08:25,410 --> 00:08:29,070
So, okay, boomer, "Your
almost retired coworker

186
00:08:29,070 --> 00:08:31,560
is reminiscing about the 'good old days'

187
00:08:31,560 --> 00:08:34,620
when computing was centrally
controlled and managed

188
00:08:34,620 --> 00:08:37,500
and security was just
easier to implement."

189
00:08:37,500 --> 00:08:40,920
Well, "You respectfully disagree
and you'd like to respond

190
00:08:40,920 --> 00:08:44,610
with the benefits of a client
server and cloud architecture.

191
00:08:44,610 --> 00:08:46,530
So what might you say?"

192
00:08:46,530 --> 00:08:49,500
So we've got this almost retired coworker.

193
00:08:49,500 --> 00:08:52,140
He's talking about those
"good old days", right?

194
00:08:52,140 --> 00:08:55,920
When computing was centrally
controlled, meaning a mainframe

195
00:08:55,920 --> 00:08:58,590
or a mid-frame and it was managed,

196
00:08:58,590 --> 00:09:01,380
and boy security was just
easier in those days.

197
00:09:01,380 --> 00:09:02,213
And you're thinking, well

198
00:09:02,213 --> 00:09:04,620
"Not really, you know, not necessarily.

199
00:09:04,620 --> 00:09:06,210
There's an awful lot of benefits

200
00:09:06,210 --> 00:09:09,510
to the client server
and cloud architecture."

201
00:09:09,510 --> 00:09:12,000
So what are you gonna say when you compare

202
00:09:12,000 --> 00:09:15,840
kind of old versus current
or emerging architecture?

203
00:09:15,840 --> 00:09:16,860
Go ahead and put me on pause

204
00:09:16,860 --> 00:09:19,193
and write down some notes
and then come on back.

205
00:09:21,540 --> 00:09:22,860
We may wanna talk about

206
00:09:22,860 --> 00:09:26,040
the client server division
of labor often results

207
00:09:26,040 --> 00:09:29,430
in enhanced collaboration
and productivity.

208
00:09:29,430 --> 00:09:31,140
And that the client server model

209
00:09:31,140 --> 00:09:33,960
is a really efficient
use of resources, right?

210
00:09:33,960 --> 00:09:36,420
We get to use processing power
of the client and server.

211
00:09:36,420 --> 00:09:38,100
We get to use memory of
the client and server.

212
00:09:38,100 --> 00:09:40,800
We get to use local storage
of the client and server,

213
00:09:40,800 --> 00:09:42,660
opposed to in the mainframe environment

214
00:09:42,660 --> 00:09:44,457
everything was on a central server,

215
00:09:44,457 --> 00:09:47,520
a very, very, very
expensive central server.

216
00:09:47,520 --> 00:09:50,130
And really our end user devices

217
00:09:50,130 --> 00:09:53,100
are thin clients or dumb terminals
were effectively useless.

218
00:09:53,100 --> 00:09:54,450
They didn't do anything, right?

219
00:09:54,450 --> 00:09:56,643
Other than communicate with the end user.

220
00:09:58,620 --> 00:10:00,630
Now, client computing allows businesses

221
00:10:00,630 --> 00:10:02,490
to easily scale, so to grow,

222
00:10:02,490 --> 00:10:05,940
and often makes resources
and applications available

223
00:10:05,940 --> 00:10:08,643
that otherwise wouldn't
be available to us.

224
00:10:10,020 --> 00:10:11,640
So in some cases, you know,

225
00:10:11,640 --> 00:10:14,220
security may be more
challenging to implement

226
00:10:14,220 --> 00:10:16,290
in a client server or
in a cloud environment

227
00:10:16,290 --> 00:10:19,980
opposed to a centralized
mainframe environment.

228
00:10:19,980 --> 00:10:22,110
But generally speaking, the trade-off

229
00:10:22,110 --> 00:10:23,490
is going to be worth it.

230
00:10:23,490 --> 00:10:26,190
We get so many benefits
from both our client server

231
00:10:26,190 --> 00:10:28,410
and our cloud computing environment.

232
00:10:28,410 --> 00:10:30,120
So respectfully, boomer,

233
00:10:30,120 --> 00:10:32,400
that's a discussion you wanna have.

234
00:10:32,400 --> 00:10:34,713
Doing so, security and action.

235
00:10:36,270 --> 00:10:39,210
All right, that brings
you to our word cloud,

236
00:10:39,210 --> 00:10:41,850
fairly small, but you just
wanna be able to recognize

237
00:10:41,850 --> 00:10:43,950
these different types of architectures

238
00:10:43,950 --> 00:10:45,899
and then apply those
security considerations

239
00:10:45,899 --> 00:10:47,490
that I introduced to you

240
00:10:47,490 --> 00:10:49,890
right at the very beginning of the lesson.

241
00:10:49,890 --> 00:10:51,450
All right, you know what
to do when you're ready.

242
00:10:51,450 --> 00:10:53,050
I'll see you at the next lesson.
