1
00:00:06,480 --> 00:00:09,630
- Welcome to Lesson 16:
Explain Various Activities

2
00:00:09,630 --> 00:00:12,510
Associated with Vulnerability Management.

3
00:00:12,510 --> 00:00:14,790
Now, in this lesson, 16.1,

4
00:00:14,790 --> 00:00:16,200
we're gonna start with talking about

5
00:00:16,200 --> 00:00:17,970
vulnerability identification.

6
00:00:17,970 --> 00:00:19,620
We'll review what a vulnerability is,

7
00:00:19,620 --> 00:00:22,170
and we're gonna then
really look closely at

8
00:00:22,170 --> 00:00:25,290
what are all the ways that we
can identify vulnerabilities,

9
00:00:25,290 --> 00:00:26,970
which is certainly the starting point

10
00:00:26,970 --> 00:00:28,473
in vulnerability management.

11
00:00:30,150 --> 00:00:33,060
And just as a review, a
vulnerability is a weakness

12
00:00:33,060 --> 00:00:37,260
in a system, hardware,
software, process, person,

13
00:00:37,260 --> 00:00:41,070
building, infrastructure,
right, that can be exploited.

14
00:00:41,070 --> 00:00:43,890
It's a weakness that can be exploited.

15
00:00:43,890 --> 00:00:45,540
Now, another term that's gonna come up

16
00:00:45,540 --> 00:00:49,140
as we're talking about our
vulnerabilities is exposure.

17
00:00:49,140 --> 00:00:51,210
The term exposure means a system

18
00:00:51,210 --> 00:00:55,320
or software configuration
issue or lack of a control

19
00:00:55,320 --> 00:00:58,923
that could contribute to a
successful exploit or compromise,

20
00:01:01,380 --> 00:01:05,070
and one more refresher about
our zero-day vulnerabilities.

21
00:01:05,070 --> 00:01:07,890
A zero-day vulnerability
refers to a vulnerability

22
00:01:07,890 --> 00:01:11,100
that is actively being
exploited by attackers

23
00:01:11,100 --> 00:01:13,260
before the vendor has an opportunity

24
00:01:13,260 --> 00:01:16,503
to develop or release
a patch or fix for it.

25
00:01:17,760 --> 00:01:20,310
Now, the term zero-day really
is used just to indicate

26
00:01:20,310 --> 00:01:23,130
that there was no notice
or advanced warning given

27
00:01:23,130 --> 00:01:26,490
to the software vendor or the
public about the vulnerability

28
00:01:26,490 --> 00:01:28,920
before it began to be exploited.

29
00:01:28,920 --> 00:01:31,620
Now, our attackers we know
go right after these, right?

30
00:01:31,620 --> 00:01:34,320
The attackers aim to
exploit the vulnerability

31
00:01:34,320 --> 00:01:37,320
before it becomes widely
known and patched,

32
00:01:37,320 --> 00:01:41,160
maximizing their opportunity
to compromise systems,

33
00:01:41,160 --> 00:01:43,680
but as soon as we know about
a zero-day vulnerability,

34
00:01:43,680 --> 00:01:45,090
we need to take action,

35
00:01:45,090 --> 00:01:47,910
and that action will be determining

36
00:01:47,910 --> 00:01:50,310
what the impact might be
to our organization, right,

37
00:01:50,310 --> 00:01:51,810
if that vulnerability was exploited

38
00:01:51,810 --> 00:01:55,080
and what additional
controls we can put in place

39
00:01:55,080 --> 00:01:57,693
until such time that a fix is available.

40
00:01:59,310 --> 00:02:01,890
How are new vulnerabilities discovered?

41
00:02:01,890 --> 00:02:03,780
Well, organizations are, you know,

42
00:02:03,780 --> 00:02:07,050
continually doing research
on their own code,

43
00:02:07,050 --> 00:02:09,330
but many organizations also offer

44
00:02:09,330 --> 00:02:12,330
what's known as a bug bounty problem.

45
00:02:12,330 --> 00:02:13,410
No. (laughing)

46
00:02:13,410 --> 00:02:15,750
Many organizations also offer

47
00:02:15,750 --> 00:02:19,200
what is known as a bug bounty program.

48
00:02:19,200 --> 00:02:21,330
It's also known as a VRP,

49
00:02:21,330 --> 00:02:23,550
which is a vulnerability rewards program,

50
00:02:23,550 --> 00:02:27,330
and that's an incentive program
that compensates individuals

51
00:02:27,330 --> 00:02:32,330
for identifying and reporting
vulnerabilities, aka bugs.

52
00:02:32,910 --> 00:02:35,220
Now, there are two types
of bug bounty programs.

53
00:02:35,220 --> 00:02:38,310
There are open bug bounties
and closed bug bounties.

54
00:02:38,310 --> 00:02:40,200
Open bug bounty programs are offered

55
00:02:40,200 --> 00:02:41,520
by hundreds of companies,

56
00:02:41,520 --> 00:02:45,150
including Google and
Microsoft and Facebook.

57
00:02:45,150 --> 00:02:49,143
A closed bug bounty program
is by invitation only.

58
00:02:52,050 --> 00:02:54,450
Now, if a vulnerability is discovered

59
00:02:54,450 --> 00:02:57,420
in third-party software or hardware

60
00:02:57,420 --> 00:03:00,030
by you or by someone in your organization

61
00:03:00,030 --> 00:03:02,100
or by someone who you hired to come in

62
00:03:02,100 --> 00:03:04,710
and do a vulnerability
assessment or a pen test,

63
00:03:04,710 --> 00:03:09,153
best practices dictate
notifying the vendor directly.

64
00:03:10,560 --> 00:03:12,000
So you've reached out to the vendor.

65
00:03:12,000 --> 00:03:13,860
You've said, "We found
this vulnerability,"

66
00:03:13,860 --> 00:03:16,320
or this issue, this exposure,

67
00:03:16,320 --> 00:03:18,217
and hopefully they respond and say,

68
00:03:18,217 --> 00:03:21,030
"Great. We're on it and
we'll keep you updated."

69
00:03:21,030 --> 00:03:24,990
And maybe they'll even give
you a little reward or,

70
00:03:24,990 --> 00:03:27,510
you know, at least an acknowledgement,

71
00:03:27,510 --> 00:03:30,870
but if you don't hear from them,
so if you have no response,

72
00:03:30,870 --> 00:03:33,990
or you have an inadequate
response is forthcoming,

73
00:03:33,990 --> 00:03:36,390
here in the US,
vulnerabilities can be sent

74
00:03:36,390 --> 00:03:38,610
to U.S. CERT Coordination Center,

75
00:03:38,610 --> 00:03:43,110
and CERT/CC will then forward
the report to the vendor,

76
00:03:43,110 --> 00:03:44,400
and this is from their policy.

77
00:03:44,400 --> 00:03:47,070
They say, "Vulnerabilities
reported to CERT/CC

78
00:03:47,070 --> 00:03:48,720
will be disclosed to the public

79
00:03:48,720 --> 00:03:51,660
45 days after the initial report

80
00:03:51,660 --> 00:03:54,450
regardless of the existence
or availability of patches

81
00:03:54,450 --> 00:03:57,930
or workarounds from affected vendors."

82
00:03:57,930 --> 00:03:59,437
Then they go on to say,

83
00:03:59,437 --> 00:04:02,347
"Extenuating circumstances,"
kind of dot, dot, dot,

84
00:04:02,347 --> 00:04:06,870
"may result in either
earlier or later disclosure,"

85
00:04:06,870 --> 00:04:10,110
and you can read more about the policy

86
00:04:10,110 --> 00:04:12,810
by just going to the link
that you see on your screen.

87
00:04:14,430 --> 00:04:17,070
Now, we really should let everybody know,

88
00:04:17,070 --> 00:04:18,420
right, about vulnerabilities.

89
00:04:18,420 --> 00:04:21,570
It shouldn't be a secret, but, you know,

90
00:04:21,570 --> 00:04:26,220
sometimes it's a little
disconcerting for an organization

91
00:04:26,220 --> 00:04:28,380
to release information
about a vulnerability

92
00:04:28,380 --> 00:04:31,320
because they don't wanna
take the reputation hit,

93
00:04:31,320 --> 00:04:34,470
but our good organizations,
our ethical organizations know

94
00:04:34,470 --> 00:04:36,870
that this is really the right thing to do.

95
00:04:36,870 --> 00:04:39,660
So ethical disclosure, which
we've talked about earlier,

96
00:04:39,660 --> 00:04:42,240
is the practice of publishing
information related

97
00:04:42,240 --> 00:04:44,160
to a vulnerability or finding,

98
00:04:44,160 --> 00:04:47,940
and the purpose is to inform
others of potential risks

99
00:04:47,940 --> 00:04:50,040
so they can make informed decisions

100
00:04:50,040 --> 00:04:51,933
and take appropriate action.

101
00:04:52,980 --> 00:04:55,230
Now, full disclosure about a vulnerability

102
00:04:55,230 --> 00:04:57,960
is making all details
public without regard

103
00:04:57,960 --> 00:05:01,290
to the additional harm that
may be caused to others,

104
00:05:01,290 --> 00:05:03,900
including exploits by adversaries.

105
00:05:03,900 --> 00:05:04,927
At first blush, it's like,

106
00:05:04,927 --> 00:05:07,560
"Oh, no, we should never
do full disclosure,"

107
00:05:07,560 --> 00:05:10,653
but there may be valid
reasons for full disclosure.

108
00:05:11,520 --> 00:05:13,650
The second is responsible disclosure,

109
00:05:13,650 --> 00:05:16,170
and responsible disclosure is making

110
00:05:16,170 --> 00:05:19,830
just enough information known
so that informed decisions

111
00:05:19,830 --> 00:05:22,650
can be made without releasing details

112
00:05:22,650 --> 00:05:25,500
that could be useful to an adversary,

113
00:05:25,500 --> 00:05:27,390
but, you know, the discussion
that comes up a lot

114
00:05:27,390 --> 00:05:29,790
about responsible disclosure is,

115
00:05:29,790 --> 00:05:31,980
who's really making that decision,

116
00:05:31,980 --> 00:05:34,230
you know, about what should be disclosed

117
00:05:34,230 --> 00:05:37,170
and are they truly
disclosing the right thing?

118
00:05:37,170 --> 00:05:40,350
So there's a lot of
conversation in our industry

119
00:05:40,350 --> 00:05:44,313
about full disclosure versus
responsible disclosure.

120
00:05:47,250 --> 00:05:50,520
Now, where can you go to find
out about vulnerabilities?

121
00:05:50,520 --> 00:05:52,110
Well, there's this fantastic program

122
00:05:52,110 --> 00:05:54,390
known as the CVE Program.

123
00:05:54,390 --> 00:05:59,040
The CVE Program is an international,
community-driven effort

124
00:05:59,040 --> 00:06:01,890
to catalog hardware and
software vulnerabilities

125
00:06:01,890 --> 00:06:04,470
for public access.

126
00:06:04,470 --> 00:06:08,430
Now, a CVE, Common
Vulnerabilities and Exposure,

127
00:06:08,430 --> 00:06:10,620
is a standardized identifier

128
00:06:10,620 --> 00:06:13,710
for a given vulnerability or exposure.

129
00:06:13,710 --> 00:06:15,870
Now, the CVE records are maintained

130
00:06:15,870 --> 00:06:20,400
in the CVE Program catalog,
and as of May 2023,

131
00:06:20,400 --> 00:06:24,480
there were 202,679 records.

132
00:06:24,480 --> 00:06:28,230
Now, the use of a CVE ensures
that two or more parties

133
00:06:28,230 --> 00:06:31,590
can confidently refer to a CVE identifier

134
00:06:31,590 --> 00:06:33,570
when discussing or sharing information

135
00:06:33,570 --> 00:06:34,710
about a unique vulnerability,

136
00:06:34,710 --> 00:06:37,623
and they know they're
talking about the same thing.

137
00:06:38,730 --> 00:06:41,130
So where do you go to
get this information?

138
00:06:41,130 --> 00:06:44,250
You're gonna go out to cve.org.

139
00:06:44,250 --> 00:06:47,040
Now, it used to be mitre.cve.org.

140
00:06:47,040 --> 00:06:49,770
They've recently brought
it over to a new website,

141
00:06:49,770 --> 00:06:51,750
so cve.org.

142
00:06:51,750 --> 00:06:53,340
If you have not been there before,

143
00:06:53,340 --> 00:06:56,280
you definitely, definitely wanna go there.

144
00:06:56,280 --> 00:06:57,720
That's where you can get information

145
00:06:57,720 --> 00:07:00,720
about all current and past CVEs,

146
00:07:00,720 --> 00:07:03,150
but they also have some
other great publications

147
00:07:03,150 --> 00:07:05,730
and a full tutorial,

148
00:07:05,730 --> 00:07:09,030
both in video form and in written form,

149
00:07:09,030 --> 00:07:12,690
to really understand, you know,
how the CVE Program works,

150
00:07:12,690 --> 00:07:16,410
how to understand CVE documentation,

151
00:07:16,410 --> 00:07:18,933
and just how to make best
use of the information.

152
00:07:21,300 --> 00:07:25,530
So when you're looking
at a CVE at cve.org,

153
00:07:25,530 --> 00:07:26,790
one of the things you're gonna notice

154
00:07:26,790 --> 00:07:28,110
is that there's a score,

155
00:07:28,110 --> 00:07:31,710
and that score is noted as a CVSS score.

156
00:07:31,710 --> 00:07:35,520
CVSS stands for Common
Vulnerability Scoring System.

157
00:07:35,520 --> 00:07:37,380
Now, the Common
Vulnerability Scoring System

158
00:07:37,380 --> 00:07:41,010
is an open framework for
communicating the characteristics

159
00:07:41,010 --> 00:07:45,960
and the severity of hardware
and software vulnerabilities.

160
00:07:45,960 --> 00:07:47,430
There are five ratings:

161
00:07:47,430 --> 00:07:51,030
none, low, medium, high, and critical.

162
00:07:51,030 --> 00:07:55,710
The two common uses of CVSS
are calculating the severity

163
00:07:55,710 --> 00:07:58,860
of vulnerabilities
discovered on your own system

164
00:07:58,860 --> 00:08:02,040
and as a factor in the prioritization

165
00:08:02,040 --> 00:08:05,040
of your vulnerability
remediation activities.

166
00:08:05,040 --> 00:08:08,490
Now, the National
Vulnerability Database, NVD,

167
00:08:08,490 --> 00:08:10,560
provides the CVSS scores

168
00:08:10,560 --> 00:08:12,510
for almost all known vulnerabilities,

169
00:08:12,510 --> 00:08:14,070
and you can learn more about

170
00:08:14,070 --> 00:08:16,020
the National Vulnerability Database at,

171
00:08:16,020 --> 00:08:17,940
well, one of our favorite places, NIST,

172
00:08:17,940 --> 00:08:20,280
National Institute of
Standards and Technology,

173
00:08:20,280 --> 00:08:24,390
by going to nvd.nist.gov,

174
00:08:24,390 --> 00:08:26,430
and this is what a CVSS description

175
00:08:26,430 --> 00:08:27,750
is gonna look like, right?

176
00:08:27,750 --> 00:08:29,880
You'll go out there, you'll see the CVE,

177
00:08:29,880 --> 00:08:33,150
and then you can note
where it says severity.

178
00:08:33,150 --> 00:08:35,040
Right over here, you can see severity,

179
00:08:35,040 --> 00:08:36,630
and then it's going to give you

180
00:08:36,630 --> 00:08:38,460
the various severity ratings,

181
00:08:38,460 --> 00:08:42,480
as well as information
about characteristics.

182
00:08:42,480 --> 00:08:46,470
So this is going out to nvd.nist.gov,

183
00:08:46,470 --> 00:08:49,560
but you can link directly
to this from cve.org.

184
00:08:49,560 --> 00:08:51,150
So when you bring up a CVE,

185
00:08:51,150 --> 00:08:53,130
there'll be a hyperlink that will take you

186
00:08:53,130 --> 00:08:56,580
right to the NVD, the National
Vulnerability Database,

187
00:08:56,580 --> 00:08:58,713
to give you the scoring information.

188
00:09:00,240 --> 00:09:02,280
Now, once you're there,
I want you to look around

189
00:09:02,280 --> 00:09:05,910
because the NVD is also a really,

190
00:09:05,910 --> 00:09:08,253
really great source of information.

191
00:09:09,600 --> 00:09:11,250
One of the things they
have is this dashboard,

192
00:09:11,250 --> 00:09:13,050
the NVD dashboard that tells you about

193
00:09:13,050 --> 00:09:16,530
CVEs received and
processed and status count

194
00:09:16,530 --> 00:09:21,300
and scoring distribution and
just so many other things

195
00:09:21,300 --> 00:09:24,390
that really you're gonna
find really interesting,

196
00:09:24,390 --> 00:09:26,880
truly interesting, and of course,

197
00:09:26,880 --> 00:09:29,460
just like there was in the cve.org site,

198
00:09:29,460 --> 00:09:30,750
there's a great tutorial.

199
00:09:30,750 --> 00:09:33,930
So go there. You know, just look around.

200
00:09:33,930 --> 00:09:37,050
Get familiar with it, and
definitely take the tutorial

201
00:09:37,050 --> 00:09:39,630
so you become more
familiar with how to use

202
00:09:39,630 --> 00:09:41,523
the National Vulnerability Database.

203
00:09:42,390 --> 00:09:45,360
And that, my friends, brings
us to a three-second challenge.

204
00:09:45,360 --> 00:09:47,310
Five challenge questions,
three seconds each.

205
00:09:47,310 --> 00:09:48,143
Let's do it.

206
00:09:49,350 --> 00:09:50,610
Hardware or software weakness

207
00:09:50,610 --> 00:09:52,260
that can potentially be exploited.

208
00:09:52,260 --> 00:09:54,660
This is an easy one. One, two, three.

209
00:09:54,660 --> 00:09:55,810
That's a vulnerability.

210
00:09:57,120 --> 00:09:58,740
When there's no notice or advance warning

211
00:09:58,740 --> 00:10:02,280
about a vulnerability before
it begins to be exploited.

212
00:10:02,280 --> 00:10:04,410
What do we call that
type of vulnerability?

213
00:10:04,410 --> 00:10:08,100
One, two, three. It's very dangerous type.

214
00:10:08,100 --> 00:10:09,783
That's gonna be our zero-day.

215
00:10:11,130 --> 00:10:14,040
Number 3, a standardized identifier

216
00:10:14,040 --> 00:10:16,980
for a given vulnerability or exposure.

217
00:10:16,980 --> 00:10:18,333
One, two, three.

218
00:10:19,530 --> 00:10:21,333
That's gonna be the CVE.

219
00:10:22,350 --> 00:10:25,470
Number 4, scoring system
used to communicate

220
00:10:25,470 --> 00:10:28,290
the severity of vulnerabilities.

221
00:10:28,290 --> 00:10:30,123
One, two, three,

222
00:10:31,560 --> 00:10:36,210
and that's gonna be the
CVSS, and lastly, number 5,

223
00:10:36,210 --> 00:10:38,760
an incentive program that
compensates individuals

224
00:10:38,760 --> 00:10:42,600
for identifying and
reporting vulnerabilities.

225
00:10:42,600 --> 00:10:46,683
One, two, three, and that's
gonna be a bug bounty.

226
00:10:47,940 --> 00:10:50,010
That brings us to a Security-in-Action

227
00:10:50,010 --> 00:10:51,753
about a vulnerability discovery.

228
00:10:52,860 --> 00:10:54,990
During a routine penetration test,

229
00:10:54,990 --> 00:10:57,780
a serious vulnerability
was discovered in the COTS,

230
00:10:57,780 --> 00:11:00,900
that stands for
commercial-off-the-shelf, application.

231
00:11:00,900 --> 00:11:02,190
You researched the issue,

232
00:11:02,190 --> 00:11:06,540
and you found no related
CVE or CVSS entry.

233
00:11:06,540 --> 00:11:08,970
You reached out to the
vendor multiple times

234
00:11:08,970 --> 00:11:11,700
by phone and by email to report it,

235
00:11:11,700 --> 00:11:15,300
but they haven't responded
at all or even acknowledged,

236
00:11:15,300 --> 00:11:18,150
right, in any form that there's an issue.

237
00:11:18,150 --> 00:11:20,200
So my question to you is, what do you do?

238
00:11:21,210 --> 00:11:23,700
Should you do nothing?
Should you do something?

239
00:11:23,700 --> 00:11:25,560
What are you gonna do? Put me on pause.

240
00:11:25,560 --> 00:11:28,110
Think about it, how you might take action

241
00:11:28,110 --> 00:11:29,710
or who you might report this to.

242
00:11:33,360 --> 00:11:34,440
Well, if no response

243
00:11:34,440 --> 00:11:36,870
or an inadequate response is forthcoming,

244
00:11:36,870 --> 00:11:38,220
vulnerabilities can be sent

245
00:11:38,220 --> 00:11:40,320
to the U.S. CERT Coordination Center.

246
00:11:40,320 --> 00:11:43,980
CERT/CC will forward the
report to the vendor.

247
00:11:43,980 --> 00:11:46,680
Now, if CERT/CC doesn't
get an adequate response,

248
00:11:46,680 --> 00:11:48,843
they will publish a notification.

249
00:11:49,680 --> 00:11:51,600
Now, if you belong to an ISAC,

250
00:11:51,600 --> 00:11:53,370
that's an information sharing group,

251
00:11:53,370 --> 00:11:55,380
or any other industry group,

252
00:11:55,380 --> 00:11:59,040
you may wanna share the information
on a confidential basis.

253
00:11:59,040 --> 00:12:00,450
So perhaps you're part of

254
00:12:00,450 --> 00:12:02,700
a banking group or a hospital group,

255
00:12:02,700 --> 00:12:05,700
and this vulnerability was
in your banking software

256
00:12:05,700 --> 00:12:07,530
or in your hospital software.

257
00:12:07,530 --> 00:12:09,750
You may wanna share it
on a confidential basis,

258
00:12:09,750 --> 00:12:11,703
again, inside that group.

259
00:12:12,990 --> 00:12:16,650
And in the meantime, right,
management needs to determine

260
00:12:16,650 --> 00:12:19,140
if there are adequate
compensating controls,

261
00:12:19,140 --> 00:12:22,560
and if not, is this
vulnerability so severe

262
00:12:22,560 --> 00:12:25,050
that we should discontinue
using the software?

263
00:12:25,050 --> 00:12:26,970
Because you found this vulnerability,

264
00:12:26,970 --> 00:12:28,530
obviously there's no patch for it

265
00:12:28,530 --> 00:12:30,810
because they haven't even
acknowledged that it exists.

266
00:12:30,810 --> 00:12:32,610
So now you have to say,
what other controls,

267
00:12:32,610 --> 00:12:35,400
what compensating controls do
we also have to put in place,

268
00:12:35,400 --> 00:12:37,770
right, because of this vulnerability

269
00:12:37,770 --> 00:12:39,960
or is it just so significant

270
00:12:39,960 --> 00:12:41,820
that maybe we really have to think about

271
00:12:41,820 --> 00:12:44,640
not using this software?

272
00:12:44,640 --> 00:12:48,333
Those decisions, those
conversations, Security-in-Action.

273
00:12:49,380 --> 00:12:51,150
There's your word cloud.

274
00:12:51,150 --> 00:12:53,010
Make sure that you know
all of these terms,

275
00:12:53,010 --> 00:12:55,200
you can speak to them,
and I would suggest,

276
00:12:55,200 --> 00:12:58,380
before you move on, go out to cve.org

277
00:12:58,380 --> 00:13:00,990
and go out to the National
Vulnerability Database.

278
00:13:00,990 --> 00:13:01,950
Take a look around.

279
00:13:01,950 --> 00:13:05,160
It's a good time to do it,
right now so you don't forget,

280
00:13:05,160 --> 00:13:07,380
and then when you're ready,
head on over to the next lesson.

281
00:13:07,380 --> 00:13:09,180
I'll be waiting for you right there.
