1
00:00:06,630 --> 00:00:09,870
- In this lesson, 16.2,
we're gonna be looking

2
00:00:09,870 --> 00:00:13,320
at vulnerability response and remediation,

3
00:00:13,320 --> 00:00:14,400
starting out with,

4
00:00:14,400 --> 00:00:17,733
how do we find those
vulnerabilities in our environment?

5
00:00:18,600 --> 00:00:20,550
Well, generally,
vulnerabilities are identified

6
00:00:20,550 --> 00:00:22,560
through vulnerability scanning.

7
00:00:22,560 --> 00:00:25,470
Vulnerability scanning
is an automated activity

8
00:00:25,470 --> 00:00:28,260
that relies on a database
of known vulnerabilities,

9
00:00:28,260 --> 00:00:31,170
such as the CVE and the NVD,

10
00:00:31,170 --> 00:00:33,090
the National Vulnerability Database,

11
00:00:33,090 --> 00:00:36,000
designed to identify vulnerabilities

12
00:00:36,000 --> 00:00:37,833
in the target environment.

13
00:00:39,300 --> 00:00:41,250
Now, when you do vulnerability scanning,

14
00:00:41,250 --> 00:00:43,830
they can be internal or external facing

15
00:00:43,830 --> 00:00:46,470
and they can be credentialed
or non-credentialed.

16
00:00:46,470 --> 00:00:47,580
What does that mean?

17
00:00:47,580 --> 00:00:50,670
So internal means that we
do it inside our network.

18
00:00:50,670 --> 00:00:52,170
External facing means we do it

19
00:00:52,170 --> 00:00:54,510
from outside of our network looking in.

20
00:00:54,510 --> 00:00:56,520
And then, credentialed or non-credentialed

21
00:00:56,520 --> 00:00:58,920
is really are we logging in or not?

22
00:00:58,920 --> 00:01:00,780
So usually there are a couple

23
00:01:00,780 --> 00:01:02,490
of different ways to approach this, right?

24
00:01:02,490 --> 00:01:04,410
We could do it non-credentialed.

25
00:01:04,410 --> 00:01:05,820
Now why would you do a non-credentialed

26
00:01:05,820 --> 00:01:07,320
to run a scan in your network?

27
00:01:07,320 --> 00:01:08,820
Because that would tell you what somebody

28
00:01:08,820 --> 00:01:11,280
who didn't have access to authenticate

29
00:01:11,280 --> 00:01:13,410
to your network would see.

30
00:01:13,410 --> 00:01:14,873
You might want to do a credentialed

31
00:01:14,873 --> 00:01:18,457
as an ordinary user or
standard user that would say,

32
00:01:18,457 --> 00:01:20,010
"Okay, someone who just has sort

33
00:01:20,010 --> 00:01:24,180
of standard permissions and
rights, what would they see?"

34
00:01:24,180 --> 00:01:27,840
And then, as an
administrator, or a superuser,

35
00:01:27,840 --> 00:01:29,760
or root user, if you run it,

36
00:01:29,760 --> 00:01:31,920
then you really, really get to dive deep

37
00:01:31,920 --> 00:01:33,660
and get all of the details.

38
00:01:33,660 --> 00:01:35,340
So credentialed or non-credentialed,

39
00:01:35,340 --> 00:01:37,320
or at various levels of credentialed,

40
00:01:37,320 --> 00:01:39,543
internal or external facing.

41
00:01:42,060 --> 00:01:45,060
Now that's what we do on our network,

42
00:01:45,060 --> 00:01:47,190
but we can really apply the same idea

43
00:01:47,190 --> 00:01:49,110
to our web applications.

44
00:01:49,110 --> 00:01:51,360
So web application vulnerability scanners

45
00:01:51,360 --> 00:01:53,640
are specialized automated tools

46
00:01:53,640 --> 00:01:56,880
used to identify
vulnerabilities in websites

47
00:01:56,880 --> 00:01:59,940
and in other web-based applications.

48
00:01:59,940 --> 00:02:01,440
Now web application scanners

49
00:02:01,440 --> 00:02:03,600
are gonna look for common types of flaws,

50
00:02:03,600 --> 00:02:05,340
such as cross-site scripting,

51
00:02:05,340 --> 00:02:07,800
SQL injection, command injection,

52
00:02:07,800 --> 00:02:10,380
and directory path traversal.

53
00:02:10,380 --> 00:02:12,780
Now this category of tools
is frequently referred

54
00:02:12,780 --> 00:02:17,580
to as our Dynamic Application
Security Testing, or DAST.

55
00:02:17,580 --> 00:02:20,400
To learn more about web
app vulnerability scanning,

56
00:02:20,400 --> 00:02:23,610
I suggest that you go out to owasp.org.

57
00:02:23,610 --> 00:02:28,380
Now OWASP is a nonprofit
organization of developers,

58
00:02:28,380 --> 00:02:32,430
and coders, and webmasters who really care

59
00:02:32,430 --> 00:02:34,500
about web and mobile security.

60
00:02:34,500 --> 00:02:38,250
And there's a host of
great information there,

61
00:02:38,250 --> 00:02:40,770
including learning about
vulnerability scanning tools.

62
00:02:40,770 --> 00:02:45,450
So you can go out to owasp.org, owasp.org.

63
00:02:45,450 --> 00:02:46,680
You can just search at that point

64
00:02:46,680 --> 00:02:48,120
for vulnerability scanning tools,

65
00:02:48,120 --> 00:02:50,813
or you can follow the link
that you see on the screen.

66
00:02:53,490 --> 00:02:56,220
Your vulnerability scanners
and your web app scanners

67
00:02:56,220 --> 00:03:00,000
are going to make decisions
about what's normal or abnormal,

68
00:03:00,000 --> 00:03:02,370
what's expected or not expected.

69
00:03:02,370 --> 00:03:04,800
And their decisions are really gonna fall

70
00:03:04,800 --> 00:03:06,030
into one of four buckets,

71
00:03:06,030 --> 00:03:07,890
true positive, false positive,

72
00:03:07,890 --> 00:03:10,230
true negative, or false negative,

73
00:03:10,230 --> 00:03:12,420
just like when we talked about devices.

74
00:03:12,420 --> 00:03:15,930
So as a refresher, a true
positive is when normal

75
00:03:15,930 --> 00:03:19,593
or expected activity is correctly
identified, that's good.

76
00:03:20,430 --> 00:03:23,640
A false positive is when
normal or expected activity

77
00:03:23,640 --> 00:03:28,640
is incorrectly identified
as abnormal or unexpected.

78
00:03:28,770 --> 00:03:31,860
Now that's problematic,
where everything's fine,

79
00:03:31,860 --> 00:03:33,217
but the system comes back and says,

80
00:03:33,217 --> 00:03:35,040
"No, you're missing that patch,"

81
00:03:35,040 --> 00:03:36,480
or "there's abnormal activity,"

82
00:03:36,480 --> 00:03:39,090
and now you have to spend
time researching something

83
00:03:39,090 --> 00:03:41,130
that's really not a problem at all.

84
00:03:41,130 --> 00:03:44,340
So everything's okay, but
there's time and effort

85
00:03:44,340 --> 00:03:47,190
involved in troubleshooting
and resolving that issue,

86
00:03:47,190 --> 00:03:48,543
so it's problematic.

87
00:03:49,710 --> 00:03:52,320
A true negative where abnormal
or unexpected activity

88
00:03:52,320 --> 00:03:54,300
is correctly identified.

89
00:03:54,300 --> 00:03:56,040
That's very good.

90
00:03:56,040 --> 00:04:00,090
And a false negative is when
abnormal or unexpected activity

91
00:04:00,090 --> 00:04:03,540
is incorrectly identified
as normal or expected.

92
00:04:03,540 --> 00:04:05,010
So that's when there's something wrong,

93
00:04:05,010 --> 00:04:06,450
there's something missing.

94
00:04:06,450 --> 00:04:08,820
You know, there's
something going on there,

95
00:04:08,820 --> 00:04:10,177
but the system's coming back and saying,

96
00:04:10,177 --> 00:04:12,000
"Nope, everything's cool."

97
00:04:12,000 --> 00:04:13,650
That's dangerous.

98
00:04:13,650 --> 00:04:15,390
So true positive, good.

99
00:04:15,390 --> 00:04:17,280
False positive, problematic.

100
00:04:17,280 --> 00:04:18,780
True negative, good.

101
00:04:18,780 --> 00:04:21,393
And a false negative,
very, very dangerous.

102
00:04:22,800 --> 00:04:24,870
Now in addition to just doing plain old

103
00:04:24,870 --> 00:04:26,880
vulnerability scanning,

104
00:04:26,880 --> 00:04:28,980
we may also do assessments.

105
00:04:28,980 --> 00:04:30,600
And in those assessments

106
00:04:30,600 --> 00:04:33,060
we will be looking for vulnerabilities.

107
00:04:33,060 --> 00:04:35,310
There are three primary
types of assessments,

108
00:04:35,310 --> 00:04:37,290
system configuration assessments,

109
00:04:37,290 --> 00:04:40,680
vulnerability assessments,
and penetration testing,

110
00:04:40,680 --> 00:04:44,340
all of these actually incorporate
vulnerability scanning.

111
00:04:44,340 --> 00:04:47,520
Now the objective of a system
configuration assessment

112
00:04:47,520 --> 00:04:51,540
is to identify issues related
to security configurations,

113
00:04:51,540 --> 00:04:56,130
baseline variations,
compliance, and nonconformance

114
00:04:56,130 --> 00:04:58,770
with industry standards
and recommendations.

115
00:04:58,770 --> 00:05:02,190
So very often here we're
looking for exposures, right?

116
00:05:02,190 --> 00:05:05,763
And the goal is to find
them and report them out.

117
00:05:07,770 --> 00:05:10,380
A vulnerability assessment
is used to identify

118
00:05:10,380 --> 00:05:14,880
host attributes and common
vulnerabilities and exposures.

119
00:05:14,880 --> 00:05:17,553
Again, find and report.

120
00:05:19,050 --> 00:05:21,270
And the objective of a penetration test

121
00:05:21,270 --> 00:05:23,910
is to evaluate the security of a target

122
00:05:23,910 --> 00:05:27,300
by identifying and providing
either proof of concept

123
00:05:27,300 --> 00:05:28,950
of the flaws and vulnerabilities

124
00:05:28,950 --> 00:05:31,800
or by performing compromise exploitation.

125
00:05:31,800 --> 00:05:34,320
And later on, we'll have a
whole lesson, actually two,

126
00:05:34,320 --> 00:05:36,180
on penetration testing.

127
00:05:36,180 --> 00:05:39,000
But the goal here is find,

128
00:05:39,000 --> 00:05:41,793
exploit, and report.

129
00:05:43,350 --> 00:05:47,670
Now vulnerability analysis
focuses on analyzing the results

130
00:05:47,670 --> 00:05:51,240
of our vulnerability scans,
our vulnerability assessments,

131
00:05:51,240 --> 00:05:53,850
and the curated threat intelligence

132
00:05:53,850 --> 00:05:56,040
to assess the risks associated

133
00:05:56,040 --> 00:05:58,470
with identified vulnerabilities.

134
00:05:58,470 --> 00:06:01,830
Now the process includes
determining the potential impact,

135
00:06:01,830 --> 00:06:03,600
the likelihood of exploitation,

136
00:06:03,600 --> 00:06:07,800
and the overall risk posed
by each vulnerability.

137
00:06:07,800 --> 00:06:09,270
'Cause a vulnerability,
remember, is a weakness,

138
00:06:09,270 --> 00:06:11,070
but not all weaknesses are equal

139
00:06:11,070 --> 00:06:14,640
and won't all have the same
impact in your organization.

140
00:06:14,640 --> 00:06:18,060
So vulnerability severity
levels are used to classify

141
00:06:18,060 --> 00:06:20,250
and prioritize vulnerabilities

142
00:06:20,250 --> 00:06:23,280
based on their potential impact and risk.

143
00:06:23,280 --> 00:06:25,080
Now vulnerability analysis helps

144
00:06:25,080 --> 00:06:30,080
us to prioritize our remediation
efforts based on severity

145
00:06:30,540 --> 00:06:33,033
and the criticality of
the vulnerabilities.

146
00:06:35,280 --> 00:06:37,110
Now, generally, we put vulnerabilities

147
00:06:37,110 --> 00:06:40,890
into three severity levels,
critical high severity,

148
00:06:40,890 --> 00:06:43,620
medium severity, and low severity.

149
00:06:43,620 --> 00:06:45,720
So how do we define those?

150
00:06:45,720 --> 00:06:47,460
Well, high severity vulnerabilities

151
00:06:47,460 --> 00:06:52,460
have the potential to create
significant harm or damage.

152
00:06:52,650 --> 00:06:54,510
Now high severity vulnerabilities

153
00:06:54,510 --> 00:06:56,820
generally require immediate attention

154
00:06:56,820 --> 00:06:59,940
and remediation to prevent exploitation

155
00:06:59,940 --> 00:07:02,313
and minimize potential impact.

156
00:07:03,630 --> 00:07:05,880
Medium severity vulnerabilities

157
00:07:05,880 --> 00:07:08,820
could result in adverse consequence.

158
00:07:08,820 --> 00:07:11,580
Now remediation of medium
severity vulnerabilities

159
00:07:11,580 --> 00:07:12,870
should be prioritized

160
00:07:12,870 --> 00:07:15,900
based on the potential
impact to the organization.

161
00:07:15,900 --> 00:07:18,630
And then, lastly, we have
low severity vulnerabilities.

162
00:07:18,630 --> 00:07:22,410
Now low severity vulnerabilities
may have limited impact

163
00:07:22,410 --> 00:07:24,720
or maybe they're just harder to exploit.

164
00:07:24,720 --> 00:07:27,900
Low severity vulnerabilities
should be remediated

165
00:07:27,900 --> 00:07:31,410
as part of your ongoing
vulnerability management efforts.

166
00:07:31,410 --> 00:07:34,290
So critical or high, let's
get on them right away.

167
00:07:34,290 --> 00:07:37,650
Medium, we're gonna prioritize
'em based on impact.

168
00:07:37,650 --> 00:07:41,040
Low, as we go through our
vulnerability management program

169
00:07:41,040 --> 00:07:42,393
we will be addressing them.

170
00:07:43,890 --> 00:07:45,390
Now one of the primary ways

171
00:07:45,390 --> 00:07:48,540
we address a vulnerability is by patching.

172
00:07:48,540 --> 00:07:51,210
Patch management is the
process of identifying,

173
00:07:51,210 --> 00:07:54,390
acquiring, installing,
and verifying patches,

174
00:07:54,390 --> 00:07:56,940
also referred to as updates.

175
00:07:56,940 --> 00:07:58,710
Security patches are designed

176
00:07:58,710 --> 00:08:01,110
to correct security vulnerabilities.

177
00:08:01,110 --> 00:08:03,510
And timely deployment of a security patch

178
00:08:03,510 --> 00:08:06,900
reduces the likelihood of exploitation.

179
00:08:06,900 --> 00:08:10,620
Now the time from when an
exploit first becomes active

180
00:08:10,620 --> 00:08:12,750
to when the number of vulnerable systems,

181
00:08:12,750 --> 00:08:13,920
because they've been patched,

182
00:08:13,920 --> 00:08:16,290
shrink to an insignificant number

183
00:08:16,290 --> 00:08:19,170
is known as the Window of Vulnerability.

184
00:08:19,170 --> 00:08:21,510
But you can bet during that window

185
00:08:21,510 --> 00:08:24,870
our adversaries are looking
hard for those systems

186
00:08:24,870 --> 00:08:28,260
to exploit any of them
that have not been patched.

187
00:08:28,260 --> 00:08:31,563
So we wanna get on patching
just as soon as we can.

188
00:08:32,970 --> 00:08:35,760
Now there are different
classifications of patching.

189
00:08:35,760 --> 00:08:38,190
Again, not all patches are equal.

190
00:08:38,190 --> 00:08:40,620
We have critical updates,
definition updates,

191
00:08:40,620 --> 00:08:44,130
driver updates, feature
packs, security updates,

192
00:08:44,130 --> 00:08:47,583
service packs, update rollups and updates.

193
00:08:48,540 --> 00:08:51,390
A critical update
provides fixes that target

194
00:08:51,390 --> 00:08:54,363
critical non-security related.

195
00:08:56,010 --> 00:08:58,860
A definition update provides updates

196
00:08:58,860 --> 00:09:02,190
to viruses and definition files.

197
00:09:02,190 --> 00:09:04,650
A driver update provides
software components

198
00:09:04,650 --> 00:09:07,020
that control or regulate a device.

199
00:09:07,020 --> 00:09:09,930
Feature packs provide new
product or functionality

200
00:09:09,930 --> 00:09:12,060
for the next product release.

201
00:09:12,060 --> 00:09:14,160
Our security updates provide a fix

202
00:09:14,160 --> 00:09:17,460
for product-specific,
security-related vulnerabilities.

203
00:09:17,460 --> 00:09:19,800
Now that will be by classification,

204
00:09:19,800 --> 00:09:21,600
so in inside security updates

205
00:09:21,600 --> 00:09:23,640
you will see that critical,

206
00:09:23,640 --> 00:09:26,040
you know, high, medium, low severity.

207
00:09:26,040 --> 00:09:27,750
But I just don't want you to confuse

208
00:09:27,750 --> 00:09:30,750
that between our critical
update and our security update.

209
00:09:30,750 --> 00:09:34,860
A critical update, generally
that term when you see it used,

210
00:09:34,860 --> 00:09:38,730
is providing a fix for
a critical non-security.

211
00:09:38,730 --> 00:09:40,860
But inside security updates,

212
00:09:40,860 --> 00:09:43,020
you may once again see the term critical,

213
00:09:43,020 --> 00:09:45,120
because that's how the security updates

214
00:09:45,120 --> 00:09:46,413
are being classified.

215
00:09:47,400 --> 00:09:48,870
And then, we have service packs,

216
00:09:48,870 --> 00:09:51,900
provides a cumulative
set of security updates,

217
00:09:51,900 --> 00:09:55,653
hot fixes, critical updates,
and design change features.

218
00:09:56,640 --> 00:09:59,700
Update rollups provide a
cumulative set of security updates,

219
00:09:59,700 --> 00:10:01,770
critical updates, and hot fixes,

220
00:10:01,770 --> 00:10:04,500
and other updates in one package.

221
00:10:04,500 --> 00:10:06,570
And, lastly, updates,
which seems to be a term

222
00:10:06,570 --> 00:10:08,100
we keep using over and over again,

223
00:10:08,100 --> 00:10:10,740
provides fixes that address non-critical,

224
00:10:10,740 --> 00:10:12,840
non-security related bugs.

225
00:10:12,840 --> 00:10:16,353
So lots of different patch
or update classifications.

226
00:10:18,420 --> 00:10:19,920
There are several challenges

227
00:10:19,920 --> 00:10:22,890
inherent in the patch management process.

228
00:10:22,890 --> 00:10:24,900
Maybe for some reason
you can't get a patch

229
00:10:24,900 --> 00:10:26,220
installed right away.

230
00:10:26,220 --> 00:10:28,890
Maybe you haven't reached
a maintenance window yet.

231
00:10:28,890 --> 00:10:30,360
Maybe there's a system

232
00:10:30,360 --> 00:10:32,610
that really needs a patch
in your environment,

233
00:10:32,610 --> 00:10:33,690
but you don't manage it,

234
00:10:33,690 --> 00:10:35,910
it's managed by a vendor.

235
00:10:35,910 --> 00:10:37,860
So in all of those situations

236
00:10:37,860 --> 00:10:39,660
if there is going to be a delay,

237
00:10:39,660 --> 00:10:41,730
particularly a delay of a critical patch,

238
00:10:41,730 --> 00:10:43,740
a critical security patch,

239
00:10:43,740 --> 00:10:45,360
that should be a evaluated

240
00:10:45,360 --> 00:10:47,670
considering the
organization's risk tolerance

241
00:10:47,670 --> 00:10:50,160
and definitely brought to
management's attention.

242
00:10:50,160 --> 00:10:51,910
You don't wanna keep that a secret.

243
00:10:53,610 --> 00:10:55,320
So what are some of the activities

244
00:10:55,320 --> 00:10:57,270
that we engage in in patch management?

245
00:10:57,270 --> 00:10:59,190
Well, we have to think
about confirmation, right?

246
00:10:59,190 --> 00:11:00,360
Is this patch applicable?

247
00:11:00,360 --> 00:11:01,680
Do we really need it?

248
00:11:01,680 --> 00:11:03,960
We have to determine the prioritization

249
00:11:03,960 --> 00:11:05,370
of applying that patch.

250
00:11:05,370 --> 00:11:07,410
And then, what the timing's going to be,

251
00:11:07,410 --> 00:11:10,350
when we're going to apply
it, as well as testing.

252
00:11:10,350 --> 00:11:12,450
Do we wanna test it in a lab first?

253
00:11:12,450 --> 00:11:15,180
Do we wanna test it on a subset of users?

254
00:11:15,180 --> 00:11:16,920
Or do we just wanna blast it out

255
00:11:16,920 --> 00:11:19,740
because it's such a significant patch?

256
00:11:19,740 --> 00:11:22,380
What is gonna be our
patch management approach?

257
00:11:22,380 --> 00:11:23,730
Are we gonna do an automated,

258
00:11:23,730 --> 00:11:26,850
or manual, or a hybrid approach?

259
00:11:26,850 --> 00:11:30,870
How are we going to get access
to either unmanaged devices,

260
00:11:30,870 --> 00:11:33,090
meaning the ones that
we don't manage perhaps,

261
00:11:33,090 --> 00:11:35,370
or we don't own in our environment,

262
00:11:35,370 --> 00:11:37,800
or mobile devices, those are on the road,

263
00:11:37,800 --> 00:11:38,970
or remote devices,

264
00:11:38,970 --> 00:11:42,750
those that might be at
a work-at-home location

265
00:11:42,750 --> 00:11:44,403
or in remote locations?

266
00:11:45,390 --> 00:11:46,830
We always have to be mindful

267
00:11:46,830 --> 00:11:49,800
of potential unintended consequences.

268
00:11:49,800 --> 00:11:51,270
There certainly have been patches

269
00:11:51,270 --> 00:11:54,120
that have been put on that
have caused corruption,

270
00:11:54,120 --> 00:11:57,660
or have caused, you
know, a system to fail,

271
00:11:57,660 --> 00:12:00,270
or get, you know, a blue screen of death.

272
00:12:00,270 --> 00:12:01,590
Certainly that happens,

273
00:12:01,590 --> 00:12:05,790
so we also wanna make sure
that we know how to roll back

274
00:12:05,790 --> 00:12:09,270
in case we have any
unintentional consequences

275
00:12:09,270 --> 00:12:12,060
how we could possibly remove or roll back.

276
00:12:12,060 --> 00:12:14,220
But, you know, inherent
sometimes in rolling back

277
00:12:14,220 --> 00:12:15,900
there are some issues as well.

278
00:12:15,900 --> 00:12:17,190
So, you know, patch management

279
00:12:17,190 --> 00:12:18,630
isn't as easy as it sounds, right?

280
00:12:18,630 --> 00:12:19,980
It's not like, "Okay, put that patch.

281
00:12:19,980 --> 00:12:21,300
One and done, you're good."

282
00:12:21,300 --> 00:12:24,393
There's a lot to consider
in doing patch management.

283
00:12:25,410 --> 00:12:28,650
And that, my friends, brings
us to a three-second challenge.

284
00:12:28,650 --> 00:12:30,960
Five challenge questions,
three seconds each.

285
00:12:30,960 --> 00:12:31,793
Here it goes.

286
00:12:32,730 --> 00:12:34,440
Automated tools used to look

287
00:12:34,440 --> 00:12:37,080
for vulnerabilities and exposures.

288
00:12:37,080 --> 00:12:38,943
One, two, three.

289
00:12:39,840 --> 00:12:42,510
That's gonna be a vulnerability scanner.

290
00:12:42,510 --> 00:12:46,650
Number two, when abnormal
or unexpected activity

291
00:12:46,650 --> 00:12:49,143
is incorrectly identified,

292
00:12:50,040 --> 00:12:51,810
this is that dangerous state.

293
00:12:51,810 --> 00:12:53,973
One, two, three.

294
00:12:55,410 --> 00:12:57,213
That's gonna be a false negative.

295
00:12:58,650 --> 00:13:01,140
Number three, testing
that can be described

296
00:13:01,140 --> 00:13:03,690
as fine, exploit,

297
00:13:03,690 --> 00:13:07,920
and proof of concept or
compromise exploit, and report.

298
00:13:07,920 --> 00:13:09,750
What kind of testing is that?

299
00:13:09,750 --> 00:13:11,103
One, two, three.

300
00:13:12,130 --> 00:13:13,830
It's gonna be penetration testing.

301
00:13:14,880 --> 00:13:19,230
Number four, severity level
that indicates the potential

302
00:13:19,230 --> 00:13:21,903
to cause significant harm or damage.

303
00:13:23,310 --> 00:13:25,770
One, two, three.

304
00:13:25,770 --> 00:13:28,203
That's high severity or critical.

305
00:13:29,280 --> 00:13:32,010
And number five, provides a cumulative set

306
00:13:32,010 --> 00:13:35,460
of security updates, hot
fixes, critical updates,

307
00:13:35,460 --> 00:13:38,343
updates and design changes or features.

308
00:13:39,600 --> 00:13:41,403
One, two, three.

309
00:13:42,450 --> 00:13:43,923
And that's a service pack.

310
00:13:45,330 --> 00:13:47,130
That brings us to a security in action,

311
00:13:47,130 --> 00:13:49,980
and this one's about
vulnerability scanning.

312
00:13:49,980 --> 00:13:51,870
Your organization hired a third party

313
00:13:51,870 --> 00:13:53,760
to conduct authenticated

314
00:13:53,760 --> 00:13:56,760
and non-authenticated
vulnerability scanning,

315
00:13:56,760 --> 00:13:58,860
authenticated and non-authenticated.

316
00:13:58,860 --> 00:14:02,850
There are several discrepancies
between the two scans.

317
00:14:02,850 --> 00:14:04,080
Now the consultant noted

318
00:14:04,080 --> 00:14:06,150
that there were several false positives

319
00:14:06,150 --> 00:14:08,790
and false negatives in both scans.

320
00:14:08,790 --> 00:14:09,817
But she commented that,

321
00:14:09,817 --> 00:14:13,440
"Well, since they're false,
nothing to worry about."

322
00:14:13,440 --> 00:14:15,360
Well, you've been asked
to explain the difference

323
00:14:15,360 --> 00:14:18,480
between the scan approaches
and how to interpret

324
00:14:18,480 --> 00:14:22,140
the false positives and
the false negatives.

325
00:14:22,140 --> 00:14:24,090
So authenticated and non-authenticated,

326
00:14:24,090 --> 00:14:25,950
which is just really another way,

327
00:14:25,950 --> 00:14:28,860
so authenticated and non-authenticated,

328
00:14:28,860 --> 00:14:30,030
which is just another way of saying

329
00:14:30,030 --> 00:14:32,010
credentialed and non-credentialed.

330
00:14:32,010 --> 00:14:34,290
So two different ways to do the scan.

331
00:14:34,290 --> 00:14:36,480
And it turns out that
there's a whole bunch

332
00:14:36,480 --> 00:14:39,090
of false positives and false negatives,

333
00:14:39,090 --> 00:14:41,190
but your consultant
says, "Eh, they're false.

334
00:14:41,190 --> 00:14:42,480
Don't worry about them.

335
00:14:42,480 --> 00:14:44,310
Nothing to worry about."

336
00:14:44,310 --> 00:14:46,170
You've been asked to
explain the difference

337
00:14:46,170 --> 00:14:47,850
between those two scan approaches

338
00:14:47,850 --> 00:14:51,630
and how to interpret false
positives and false negatives.

339
00:14:51,630 --> 00:14:52,830
So go ahead and put me on pause,

340
00:14:52,830 --> 00:14:55,323
write down your explanation
and come on back.

341
00:14:57,600 --> 00:15:00,300
The difference is, is
that unauthenticated scans

342
00:15:00,300 --> 00:15:02,040
allow for access

343
00:15:02,040 --> 00:15:05,670
based on the logged-in user's
rights and permissions.

344
00:15:05,670 --> 00:15:07,890
An unauthenticated scan can examine

345
00:15:07,890 --> 00:15:10,170
only publicly visible information

346
00:15:10,170 --> 00:15:14,070
and is unable to provide
more detailed information

347
00:15:14,070 --> 00:15:15,600
about the assets.

348
00:15:15,600 --> 00:15:18,360
And we talked about
doing a unauthenticated

349
00:15:18,360 --> 00:15:19,890
or non-credentialed scan,

350
00:15:19,890 --> 00:15:22,710
because that would be what
maybe a stranger would see,

351
00:15:22,710 --> 00:15:24,960
someone who's not authorized
to be on your network would see

352
00:15:24,960 --> 00:15:28,830
if they were able to
connect and run that scan.

353
00:15:28,830 --> 00:15:31,050
Where an authenticated
or credentialed scan

354
00:15:31,050 --> 00:15:33,750
is based on the user's
rights and permissions

355
00:15:33,750 --> 00:15:35,553
what will be reported back.

356
00:15:37,740 --> 00:15:42,180
Now false reporting should
always be taken seriously.

357
00:15:42,180 --> 00:15:44,610
False positives, remember,
are when normal activity

358
00:15:44,610 --> 00:15:48,180
is incorrectly identified as abnormal.

359
00:15:48,180 --> 00:15:51,750
But, you know, we still have
to figure it out, right?

360
00:15:51,750 --> 00:15:53,580
Why did we get that response?

361
00:15:53,580 --> 00:15:57,120
Now false negatives is
when abnormal activity

362
00:15:57,120 --> 00:15:59,520
is incorrectly identified as normal,

363
00:15:59,520 --> 00:16:01,170
and that should never be ignored

364
00:16:01,170 --> 00:16:03,780
because that's going to be dangerous.

365
00:16:03,780 --> 00:16:05,250
Now here's one of the problems,

366
00:16:05,250 --> 00:16:07,680
how do you know you have a false negative,

367
00:16:07,680 --> 00:16:09,870
because the system hasn't come back

368
00:16:09,870 --> 00:16:12,270
and said this is a false negative?

369
00:16:12,270 --> 00:16:13,800
So it's really a matter

370
00:16:13,800 --> 00:16:16,710
of also looking at your
threat intelligence

371
00:16:16,710 --> 00:16:19,950
and other information that
you might have to figure out,

372
00:16:19,950 --> 00:16:22,950
does that vulnerability actually exist?

373
00:16:22,950 --> 00:16:24,270
And being able to do that, my friends,

374
00:16:24,270 --> 00:16:26,163
is definitely security in action.

375
00:16:27,420 --> 00:16:28,590
It's a big word cloud.

376
00:16:28,590 --> 00:16:29,550
You know what to do.

377
00:16:29,550 --> 00:16:31,380
Make sure that you're
comfortable and confident

378
00:16:31,380 --> 00:16:33,300
with all of these terms, right?

379
00:16:33,300 --> 00:16:36,930
You understand what they
mean and how to apply them.

380
00:16:36,930 --> 00:16:39,840
And when you're ready,
head on over to our quiz.

381
00:16:39,840 --> 00:16:40,790
I'll see you there.
