1
00:00:06,540 --> 00:00:07,950
- Welcome to Lesson 11:

2
00:00:07,950 --> 00:00:10,410
Given a Scenario, Apply
Security Principles

3
00:00:10,410 --> 00:00:13,410
to Secure Enterprise Infrastructure.

4
00:00:13,410 --> 00:00:15,570
In 11.1, we're gonna talk about

5
00:00:15,570 --> 00:00:17,670
network devices fairly generically

6
00:00:17,670 --> 00:00:19,200
but getting an understanding

7
00:00:19,200 --> 00:00:22,140
of what network devices
are, what they can do,

8
00:00:22,140 --> 00:00:23,823
and how they make decisions.

9
00:00:26,490 --> 00:00:28,410
So let's define different types

10
00:00:28,410 --> 00:00:30,030
of network devices first,

11
00:00:30,030 --> 00:00:31,350
starting with an appliance.

12
00:00:31,350 --> 00:00:33,990
An appliance is a self-contained resource

13
00:00:33,990 --> 00:00:36,243
that provides a specific function.

14
00:00:37,320 --> 00:00:39,060
Now, other types of network devices,

15
00:00:39,060 --> 00:00:40,980
appliance being the most popular,

16
00:00:40,980 --> 00:00:43,050
are sensors and collectors.

17
00:00:43,050 --> 00:00:45,630
A sensor is a device
that collects information

18
00:00:45,630 --> 00:00:47,100
about a network or host.

19
00:00:47,100 --> 00:00:49,020
And a sensor can report,

20
00:00:49,020 --> 00:00:51,480
but it can also take some action.

21
00:00:51,480 --> 00:00:52,770
A collector is a device

22
00:00:52,770 --> 00:00:55,320
that performs targeted collection,

23
00:00:55,320 --> 00:00:57,900
which ultimately feeds into an aggregation

24
00:00:57,900 --> 00:00:59,943
or into a correlation engine.

25
00:01:01,980 --> 00:01:04,500
Let's talk about some device attributes.

26
00:01:04,500 --> 00:01:07,620
Devices can be passive,
they can be active,

27
00:01:07,620 --> 00:01:08,880
they can be in line,

28
00:01:08,880 --> 00:01:10,713
or they can be what's known as tap.

29
00:01:11,910 --> 00:01:14,640
The passive devices simply allow data

30
00:01:14,640 --> 00:01:16,230
to pass through, right?

31
00:01:16,230 --> 00:01:18,810
So an example would be
things like a patch panel,

32
00:01:18,810 --> 00:01:20,673
or a coupler, or a splitter.

33
00:01:21,660 --> 00:01:24,030
An active network device can control

34
00:01:24,030 --> 00:01:27,660
or modify data as it
passes through the network.

35
00:01:27,660 --> 00:01:30,090
So examples include things like switches,

36
00:01:30,090 --> 00:01:32,910
and routers, and firewalls.

37
00:01:32,910 --> 00:01:35,490
When we say that a device is inline,

38
00:01:35,490 --> 00:01:37,590
what we're saying is that it sits directly

39
00:01:37,590 --> 00:01:39,630
in the path of network traffic,

40
00:01:39,630 --> 00:01:42,930
and it can actively process data packets

41
00:01:42,930 --> 00:01:44,610
as they pass through it.

42
00:01:44,610 --> 00:01:48,270
So our examples include IPSs, firewalls,

43
00:01:48,270 --> 00:01:49,653
and load balancers.

44
00:01:52,050 --> 00:01:54,690
Now a network tap is a passive device

45
00:01:54,690 --> 00:01:57,150
that's used to monitor network traffic

46
00:01:57,150 --> 00:01:59,190
by copying all the packets

47
00:01:59,190 --> 00:02:02,430
that actually pass through
a network connection.

48
00:02:02,430 --> 00:02:05,943
So passive, active, inline, or tap.

49
00:02:08,610 --> 00:02:11,070
Now, devices have to
make decisions, right?

50
00:02:11,070 --> 00:02:12,900
Is this good traffic, is this bad traffic?

51
00:02:12,900 --> 00:02:14,730
Or should I report on this?

52
00:02:14,730 --> 00:02:17,100
Or should I not report on this?

53
00:02:17,100 --> 00:02:19,920
So devices will have decision states.

54
00:02:19,920 --> 00:02:21,270
Now, software does the same thing.

55
00:02:21,270 --> 00:02:22,770
Software will have decision states

56
00:02:22,770 --> 00:02:24,960
or when you're running a
vulnerability scan, right?

57
00:02:24,960 --> 00:02:27,480
That vulnerability scanner
will have decision states.

58
00:02:27,480 --> 00:02:29,490
It has to tell you is
this good, is this bad?

59
00:02:29,490 --> 00:02:31,380
Is this right or is this wrong?

60
00:02:31,380 --> 00:02:34,860
So I wanna go through four
basic decision states.

61
00:02:34,860 --> 00:02:37,980
True positive, false
positive, true negative,

62
00:02:37,980 --> 00:02:39,183
and false negative.

63
00:02:40,470 --> 00:02:42,180
Now, I want to give you a little caveat.

64
00:02:42,180 --> 00:02:43,207
As we're going through
this, you might say,

65
00:02:43,207 --> 00:02:44,910
"Well, that's not the way my vendor

66
00:02:44,910 --> 00:02:46,470
actually uses those terms."

67
00:02:46,470 --> 00:02:48,570
And that's true, like, different vendors

68
00:02:48,570 --> 00:02:51,060
seem to, like, weirdly use
these terms differently.

69
00:02:51,060 --> 00:02:53,510
But this is how you need
to know it for the exam.

70
00:02:54,960 --> 00:02:57,210
In a true positive, the normal

71
00:02:57,210 --> 00:03:00,180
or expected activity is
correctly identified.

72
00:03:00,180 --> 00:03:02,100
Now, you see I say normal or expected.

73
00:03:02,100 --> 00:03:03,900
So it could be either what's normal

74
00:03:03,900 --> 00:03:06,510
or expected in cases of
what I'm looking for,

75
00:03:06,510 --> 00:03:10,470
what I expect to find
is correctly identified.

76
00:03:10,470 --> 00:03:11,310
Well, that's good, right?

77
00:03:11,310 --> 00:03:12,273
That's really good.

78
00:03:13,920 --> 00:03:16,410
A false positive is where normal

79
00:03:16,410 --> 00:03:20,670
or expected activity is
incorrectly identified

80
00:03:20,670 --> 00:03:23,220
as abnormal or unexpected.

81
00:03:23,220 --> 00:03:25,050
And that's problematic.

82
00:03:25,050 --> 00:03:27,060
Everything's really okay, right?

83
00:03:27,060 --> 00:03:28,980
Everything's fine, right?

84
00:03:28,980 --> 00:03:30,690
It's the activity is normal

85
00:03:30,690 --> 00:03:32,760
or expected what you're looking for,

86
00:03:32,760 --> 00:03:34,980
but it's not being tagged that way.

87
00:03:34,980 --> 00:03:37,650
It's being identified as
abnormal or unexpected.

88
00:03:37,650 --> 00:03:39,510
It would be like if you
did a vulnerability scan,

89
00:03:39,510 --> 00:03:41,047
and the system came back and said,

90
00:03:41,047 --> 00:03:42,450
"You're missing a bunch of patches."

91
00:03:42,450 --> 00:03:44,970
And you're like, "I know I
installed those patches."

92
00:03:44,970 --> 00:03:46,170
Well, it turns out those patches

93
00:03:46,170 --> 00:03:48,300
were installed as part of a security patch

94
00:03:48,300 --> 00:03:49,560
or a bigger update.

95
00:03:49,560 --> 00:03:52,080
And so the vulnerability
scanner didn't know to look,

96
00:03:52,080 --> 00:03:55,560
you know, there for that
piece of information.

97
00:03:55,560 --> 00:03:57,420
So it comes back, and it's not there.

98
00:03:57,420 --> 00:04:00,360
And so it's problematic in the sense

99
00:04:00,360 --> 00:04:02,250
that now you've gotta just spend time

100
00:04:02,250 --> 00:04:04,440
and energy kinda researching why

101
00:04:04,440 --> 00:04:07,623
you're getting this response,
this false positive.

102
00:04:09,060 --> 00:04:10,680
A true negative is when abnormal

103
00:04:10,680 --> 00:04:14,100
or unexpected activity
is correctly identified.

104
00:04:14,100 --> 00:04:15,690
That's really good.

105
00:04:15,690 --> 00:04:18,360
And then we have our very,
very dangerous state,

106
00:04:18,360 --> 00:04:19,770
our false negative.

107
00:04:19,770 --> 00:04:21,480
Our false negative is when abnormal

108
00:04:21,480 --> 00:04:25,080
or unexpected activity
is incorrectly identified

109
00:04:25,080 --> 00:04:27,960
as being just fine, as
being normal or expected.

110
00:04:27,960 --> 00:04:31,800
And that is a really,
really dangerous state

111
00:04:31,800 --> 00:04:33,150
because that's when the system

112
00:04:33,150 --> 00:04:35,730
or the device is saying,
"Everything's fine,"

113
00:04:35,730 --> 00:04:37,440
but it's not.

114
00:04:37,440 --> 00:04:39,630
So true positive, everything's good.

115
00:04:39,630 --> 00:04:42,180
And if the system tells us, "We're okay,"

116
00:04:42,180 --> 00:04:43,230
that's good, right?

117
00:04:43,230 --> 00:04:44,730
False positive, everything's okay.

118
00:04:44,730 --> 00:04:47,130
But the system says, "Not really."

119
00:04:47,130 --> 00:04:48,930
That's problematic 'cause
we now have to spend

120
00:04:48,930 --> 00:04:51,030
time figuring it out and researching it.

121
00:04:51,030 --> 00:04:52,500
True negative telling us

122
00:04:52,500 --> 00:04:55,470
that something's wrong,
abnormal or unexpected,

123
00:04:55,470 --> 00:04:57,330
and that's good, we wanna know that.

124
00:04:57,330 --> 00:04:59,700
False negative, that's the dangerous one.

125
00:04:59,700 --> 00:05:02,070
That's when that abnormal
or unexpected activity

126
00:05:02,070 --> 00:05:05,070
is incorrectly identified
as either being normal

127
00:05:05,070 --> 00:05:07,080
or what you were expecting to find.

128
00:05:07,080 --> 00:05:10,593
So good, problematic, good, dangerous.

129
00:05:13,290 --> 00:05:15,660
Now, devices also have failure modes.

130
00:05:15,660 --> 00:05:17,610
So when they fail, what can happen?

131
00:05:17,610 --> 00:05:19,650
And the two failure modes in devices

132
00:05:19,650 --> 00:05:22,290
are gonna be fail-open and fail-closed.

133
00:05:22,290 --> 00:05:25,320
Now, fail-open means
that the network device

134
00:05:25,320 --> 00:05:27,570
allows the network traffic
to continue to flow

135
00:05:27,570 --> 00:05:29,580
even if the device fails.

136
00:05:29,580 --> 00:05:31,290
Now the setting is really intended

137
00:05:31,290 --> 00:05:33,630
to prevent disruptions
to network connectivity

138
00:05:33,630 --> 00:05:36,090
and minimize the impact of a hardware

139
00:05:36,090 --> 00:05:39,120
or software failure on network operations.

140
00:05:39,120 --> 00:05:41,370
So for example, in a
fail-open in a firewall,

141
00:05:41,370 --> 00:05:43,230
if the firewall failed, you know,

142
00:05:43,230 --> 00:05:45,330
ingress and egress traffic to the internet

143
00:05:45,330 --> 00:05:47,730
would still be allowed, that's fail-open.

144
00:05:47,730 --> 00:05:49,770
It's also referred to as fail-safe.

145
00:05:49,770 --> 00:05:51,780
When we talked about physical security,

146
00:05:51,780 --> 00:05:53,940
we talked about in a building, let's say,

147
00:05:53,940 --> 00:05:57,270
if all of the doors
defaulted to unlocked, right,

148
00:05:57,270 --> 00:05:59,883
or open, that would be fail-safe.

149
00:06:01,320 --> 00:06:03,390
Fail-close means that the network device

150
00:06:03,390 --> 00:06:07,080
blocks network traffic
even if the device fails.

151
00:06:07,080 --> 00:06:08,250
So that setting is intended

152
00:06:08,250 --> 00:06:10,380
to ensure network security

153
00:06:10,380 --> 00:06:12,600
by preventing any unauthorized access

154
00:06:12,600 --> 00:06:15,090
to network resources in the event

155
00:06:15,090 --> 00:06:16,800
of a hardware or software failure.

156
00:06:16,800 --> 00:06:19,020
So going back to our
example at the firewall,

157
00:06:19,020 --> 00:06:20,880
if the firewall failed,
you wouldn't be able

158
00:06:20,880 --> 00:06:22,290
to get to the internet.

159
00:06:22,290 --> 00:06:25,440
Now, that's also referred
to as fail-secure.

160
00:06:25,440 --> 00:06:27,840
Remember back when we talked
about physical security,

161
00:06:27,840 --> 00:06:30,090
and we talked about if
all the doors locked

162
00:06:30,090 --> 00:06:32,700
or closed, that would be fail-secure.

163
00:06:32,700 --> 00:06:35,430
So we used the term fail-open
or sometimes fail-safe,

164
00:06:35,430 --> 00:06:37,803
fail-closed, sometimes fail-secure.

165
00:06:38,940 --> 00:06:41,520
And that brings us to a
three-second challenge.

166
00:06:41,520 --> 00:06:43,680
Five challenge questions,
three seconds each,

167
00:06:43,680 --> 00:06:46,173
all about just devices in general.

168
00:06:47,670 --> 00:06:50,010
The device type that can
control or modify data

169
00:06:50,010 --> 00:06:52,380
as it passes through the network.

170
00:06:52,380 --> 00:06:54,273
One, two, three.

171
00:06:55,800 --> 00:06:57,483
It's gonna be an active device.

172
00:06:58,770 --> 00:07:00,510
Number two, a passive device

173
00:07:00,510 --> 00:07:02,340
used to monitor network traffic

174
00:07:02,340 --> 00:07:05,190
by copying all of its packets.

175
00:07:05,190 --> 00:07:09,033
One, two, three, that's a tap.

176
00:07:10,440 --> 00:07:13,800
Number three, the decision
state where normal

177
00:07:13,800 --> 00:07:16,680
or expected activity is incorrectly

178
00:07:16,680 --> 00:07:19,263
identified as abnormal or unexpected.

179
00:07:20,850 --> 00:07:22,893
One, two, three.

180
00:07:24,120 --> 00:07:26,163
That's gonna be a false positive.

181
00:07:28,530 --> 00:07:31,110
Number four, another decision state.

182
00:07:31,110 --> 00:07:32,940
The decision state when abnormal

183
00:07:32,940 --> 00:07:35,970
or unexpected activity is incorrectly

184
00:07:35,970 --> 00:07:38,490
identified as normal or expected.

185
00:07:38,490 --> 00:07:40,770
This is the one I said
was really dangerous.

186
00:07:40,770 --> 00:07:43,020
One, two, three.

187
00:07:43,020 --> 00:07:44,313
That's a false negative.

188
00:07:47,010 --> 00:07:49,530
And number five, in this failure mode,

189
00:07:49,530 --> 00:07:51,783
network traffic continues to flow.

190
00:07:53,190 --> 00:07:55,950
One, two, three.

191
00:07:55,950 --> 00:07:59,490
And that would be fail-open or fail-safe.

192
00:07:59,490 --> 00:08:03,060
Awesome, let's go into
our Security-in-Action.

193
00:08:03,060 --> 00:08:05,490
This one's about decision states.

194
00:08:05,490 --> 00:08:07,650
Your company recently installed an inline

195
00:08:07,650 --> 00:08:09,540
intrusion prevention system, an IPS,

196
00:08:09,540 --> 00:08:11,220
and we'll be talking about IPSs shortly

197
00:08:11,220 --> 00:08:12,423
in an upcoming lesson.

198
00:08:13,500 --> 00:08:15,900
Now, it's become obvious to everyone

199
00:08:15,900 --> 00:08:18,270
that the device needs to be fine-tuned.

200
00:08:18,270 --> 00:08:21,360
However, there's an internal
debate about tuning.

201
00:08:21,360 --> 00:08:24,210
Specifically, which is worse?

202
00:08:24,210 --> 00:08:26,020
A false positive

203
00:08:27,240 --> 00:08:29,163
or a false negative?

204
00:08:30,270 --> 00:08:31,950
Now, there's a concurrent debate

205
00:08:31,950 --> 00:08:33,933
about the best configuration,

206
00:08:34,800 --> 00:08:39,800
which we're debating,
fail-open or fail-closed?

207
00:08:40,080 --> 00:08:41,970
So how do you respond to this debate?

208
00:08:41,970 --> 00:08:42,930
All right, internal debate,

209
00:08:42,930 --> 00:08:45,660
doesn't really matter
that it's an IPS, right?

210
00:08:45,660 --> 00:08:47,520
That's almost irrelevant to our

211
00:08:47,520 --> 00:08:49,440
Security-in-Action case study here.

212
00:08:49,440 --> 00:08:51,900
Really the question is what's worse?

213
00:08:51,900 --> 00:08:54,480
False positives or false negatives?

214
00:08:54,480 --> 00:08:57,750
And what would be the best configuration?

215
00:08:57,750 --> 00:09:01,203
A fail-open or a fail-closed?

216
00:09:02,040 --> 00:09:03,990
Go ahead and put me on pause.

217
00:09:03,990 --> 00:09:05,580
Take a moment, write down your response,

218
00:09:05,580 --> 00:09:06,680
and then come on back.

219
00:09:09,780 --> 00:09:11,700
A false positive means
that normal activity

220
00:09:11,700 --> 00:09:15,360
is incorrectly identified as abnormal.

221
00:09:15,360 --> 00:09:18,390
So this decision state
really results in time spent

222
00:09:18,390 --> 00:09:20,010
diagnosing a moot issue, right?

223
00:09:20,010 --> 00:09:21,360
Nothing's really wrong but we're busy

224
00:09:21,360 --> 00:09:23,310
trying to troubleshoot and diagnose it.

225
00:09:24,360 --> 00:09:27,600
But a false negative means
that the abnormal activity

226
00:09:27,600 --> 00:09:30,540
is incorrectly identified as normal.

227
00:09:30,540 --> 00:09:31,770
So this decision state

228
00:09:31,770 --> 00:09:35,190
often results in a problem
not being identified,

229
00:09:35,190 --> 00:09:38,040
which could result in a successful attack.

230
00:09:38,040 --> 00:09:41,613
So this is arguably the more
dangerous decision state.

231
00:09:43,320 --> 00:09:46,410
The fail-open allows
traffic to continue to flow,

232
00:09:46,410 --> 00:09:49,173
whereas fail-closed would stop traffic.

233
00:09:50,670 --> 00:09:52,440
We don't really have
an answer for them yet

234
00:09:52,440 --> 00:09:53,280
in this one, right?

235
00:09:53,280 --> 00:09:55,800
Several factors really need to be weighed

236
00:09:55,800 --> 00:09:57,540
to make that decision.

237
00:09:57,540 --> 00:09:59,220
It's not just cut and dry.

238
00:09:59,220 --> 00:10:00,300
We always want a fail-open

239
00:10:00,300 --> 00:10:01,620
or always want a fail-closed.

240
00:10:01,620 --> 00:10:04,140
We really need to look at the device

241
00:10:04,140 --> 00:10:08,643
and what the impact would be
of fail-open or fail-closed.

242
00:10:09,660 --> 00:10:11,310
So being part of this discussion,

243
00:10:11,310 --> 00:10:12,480
understanding what we mean

244
00:10:12,480 --> 00:10:14,190
by false positives and false negatives

245
00:10:14,190 --> 00:10:15,813
and fail-open and fail-closed,

246
00:10:16,680 --> 00:10:19,290
that is the job of a
security practitioner,

247
00:10:19,290 --> 00:10:21,633
and it's obviously security in action.

248
00:10:22,980 --> 00:10:24,720
All right, there you go,
there's your word cloud.

249
00:10:24,720 --> 00:10:27,120
Make sure that you can
speak to all of these terms

250
00:10:27,120 --> 00:10:29,490
and concepts before you move on.

251
00:10:29,490 --> 00:10:30,510
And when you're ready,

252
00:10:30,510 --> 00:10:31,890
come on over to the next lesson.

253
00:10:31,890 --> 00:10:33,690
I'll be waiting for you right there.
