1
00:00:06,589 --> 00:00:08,190
- In this lesson, 17.2,

2
00:00:08,190 --> 00:00:11,160
we're gonna focus in on
three tools, specifically:

3
00:00:11,160 --> 00:00:14,637
SNMP, NetFlow, and SCAP.

4
00:00:14,637 --> 00:00:17,340
Are you ready? All right, let's do it.

5
00:00:17,340 --> 00:00:19,290
So starting with SNMP,

6
00:00:19,290 --> 00:00:23,340
which stands for Simple
Network Management Protocol.

7
00:00:23,340 --> 00:00:26,520
Now, Simple Network
Management Protocol, or SNMP,

8
00:00:26,520 --> 00:00:29,340
is a widely used network
management protocol

9
00:00:29,340 --> 00:00:34,340
that allows administrators to
monitor and to manage devices.

10
00:00:34,830 --> 00:00:36,450
Now, what does SNMP do for us?

11
00:00:36,450 --> 00:00:39,480
Well, SNMP provides a
standardized framework

12
00:00:39,480 --> 00:00:42,210
for collecting and organizing information

13
00:00:42,210 --> 00:00:45,930
about our network devices
and their performance.

14
00:00:45,930 --> 00:00:48,810
Now, the most current
version is version three.

15
00:00:48,810 --> 00:00:50,040
It's not just the most current,

16
00:00:50,040 --> 00:00:52,875
but it's also the most secure version.

17
00:00:52,875 --> 00:00:55,560
SNMPv3 incorporates features

18
00:00:55,560 --> 00:00:59,250
like authentication,
encryption, and access control,

19
00:00:59,250 --> 00:01:01,200
which we didn't have in earlier versions,

20
00:01:01,200 --> 00:01:05,550
providing a much more
robust security platform

21
00:01:05,550 --> 00:01:07,923
for SNMP communications.

22
00:01:09,330 --> 00:01:12,300
Now, there are three
primary SNMP components:

23
00:01:12,300 --> 00:01:15,540
the managed devices, the
devices we wanna manage,

24
00:01:15,540 --> 00:01:19,590
SNMP agents, and SNMP managers.

25
00:01:19,590 --> 00:01:22,200
Now, managed devices
are the network devices

26
00:01:22,200 --> 00:01:25,710
that are being monitored
and managed using SNMP.

27
00:01:25,710 --> 00:01:29,790
So for example, a router, a
switch, a server, a printer,

28
00:01:29,790 --> 00:01:31,623
or other network appliances.

29
00:01:32,850 --> 00:01:35,160
An Agent are software modules

30
00:01:35,160 --> 00:01:37,710
that we install on the managed devices.

31
00:01:37,710 --> 00:01:39,570
Now, those Agents are responsible

32
00:01:39,570 --> 00:01:42,150
for collecting and storing information

33
00:01:42,150 --> 00:01:44,190
about the device's performance

34
00:01:44,190 --> 00:01:46,860
and responding to queries or questions

35
00:01:46,860 --> 00:01:50,370
from the SNMP management systems.

36
00:01:50,370 --> 00:01:53,460
And then we have the SNMP managers

37
00:01:53,460 --> 00:01:56,190
and they're really part of
the management system, right?

38
00:01:56,190 --> 00:02:00,720
They send SNMP queries to
agents to retrieve information

39
00:02:00,720 --> 00:02:03,780
and they can also issue
configuration commands

40
00:02:03,780 --> 00:02:05,010
to the device.

41
00:02:05,010 --> 00:02:05,910
So three pieces:

42
00:02:05,910 --> 00:02:09,723
our device, our agents, and
our managers or management.

43
00:02:11,100 --> 00:02:14,070
Lemme walk you through an
example of network monitoring

44
00:02:14,070 --> 00:02:16,200
with SNMP.

45
00:02:16,200 --> 00:02:19,290
So a network administrator
sets up SNMP agents

46
00:02:19,290 --> 00:02:21,903
on router, switches, and
other network devices.

47
00:02:22,920 --> 00:02:25,170
SNMP management systems are configured

48
00:02:25,170 --> 00:02:28,860
to send periodic queries,
in this case, GET requests,

49
00:02:28,860 --> 00:02:30,630
to the SNMP agents.

50
00:02:30,630 --> 00:02:32,790
And the GET request is asking

51
00:02:32,790 --> 00:02:36,783
to retrieve network performance
data and device status.

52
00:02:38,040 --> 00:02:41,430
The management system will
collect that SNMP data,

53
00:02:41,430 --> 00:02:46,320
such as interface utilization,
error rates, CPU usage

54
00:02:46,320 --> 00:02:48,000
and memory usage, right,

55
00:02:48,000 --> 00:02:50,820
to really monitor that the
health and the performance

56
00:02:50,820 --> 00:02:51,963
of the network.

57
00:02:52,980 --> 00:02:55,110
Thresholds and alarms can then be set

58
00:02:55,110 --> 00:02:56,460
to trigger notifications,

59
00:02:56,460 --> 00:02:58,470
those are known as SNMP traps,

60
00:02:58,470 --> 00:03:00,720
when certain conditions are met,

61
00:03:00,720 --> 00:03:04,620
such as excessive bandwidth
usage or device failures.

62
00:03:04,620 --> 00:03:06,870
So that's how we're gonna
do network monitoring

63
00:03:06,870 --> 00:03:08,283
with SNMP.

64
00:03:09,300 --> 00:03:10,650
Next up is NetFlow.

65
00:03:10,650 --> 00:03:12,960
NetFlow is a network protocol

66
00:03:12,960 --> 00:03:15,900
developed by Cisco Systems
that allow the collection

67
00:03:15,900 --> 00:03:19,260
and analysis of network traffic data.

68
00:03:19,260 --> 00:03:22,230
NetFlow enables the
monitoring of network traffic

69
00:03:22,230 --> 00:03:25,020
by capturing and analyzing flow data.

70
00:03:25,020 --> 00:03:26,310
So what's flow?

71
00:03:26,310 --> 00:03:29,130
Well, a flow represents
a sequence of packets

72
00:03:29,130 --> 00:03:30,840
that share common characteristics,

73
00:03:30,840 --> 00:03:35,100
such as source and destination
IP address, port, protocol,

74
00:03:35,100 --> 00:03:37,050
or other attributes.

75
00:03:37,050 --> 00:03:40,710
NetFlow-capable devices, such
as a router and a switch,

76
00:03:40,710 --> 00:03:43,620
generate flow records
containing information

77
00:03:43,620 --> 00:03:45,780
about those network flows.

78
00:03:45,780 --> 00:03:48,720
IPFIX is an industry-standard protocol

79
00:03:48,720 --> 00:03:51,000
based on NetFlow version nine

80
00:03:51,000 --> 00:03:53,823
that does provide vendor-agnostic format.

81
00:03:55,650 --> 00:03:57,630
So let's look at some NetFlow use cases.

82
00:03:57,630 --> 00:04:00,960
We can use it for traffic
analysis, capacity planning,

83
00:04:00,960 --> 00:04:04,290
bandwidth utilization, malicious sources,

84
00:04:04,290 --> 00:04:06,660
and to detect anomalies.

85
00:04:06,660 --> 00:04:07,770
So traffic analysis,

86
00:04:07,770 --> 00:04:11,700
giving us visibility into
network traffic patterns.

87
00:04:11,700 --> 00:04:14,880
Capacity planning, insights
into source volume,

88
00:04:14,880 --> 00:04:17,760
and help us identify bottlenecks.

89
00:04:17,760 --> 00:04:19,650
Bandwidth utilization to track

90
00:04:19,650 --> 00:04:22,470
and trend bandwidth utilization.

91
00:04:22,470 --> 00:04:25,350
Malicious sources to identify sources

92
00:04:25,350 --> 00:04:28,650
of malicious traffic,
as well as DDoS attempts

93
00:04:28,650 --> 00:04:31,050
and any unauthorized access,

94
00:04:31,050 --> 00:04:35,223
and to detect anomalies or
suspicious network activities.

95
00:04:37,080 --> 00:04:40,260
So let me give you an
example of using NetFlow

96
00:04:40,260 --> 00:04:43,443
and SNMP together for capacity planning.

97
00:04:44,490 --> 00:04:46,890
An organization wants
to assess its current

98
00:04:46,890 --> 00:04:48,843
and future capacity.

99
00:04:50,340 --> 00:04:54,120
NetFlow data provides insights
into traffic patterns,

100
00:04:54,120 --> 00:04:57,960
peak usage periods, and
application usage trends,

101
00:04:57,960 --> 00:05:00,090
allowing the company to identify

102
00:05:00,090 --> 00:05:02,970
potential bandwidth bottlenecks.

103
00:05:02,970 --> 00:05:05,580
The SNMP monitoring tracks the performance

104
00:05:05,580 --> 00:05:09,330
and the utilization of
network devices such as CPU,

105
00:05:09,330 --> 00:05:11,490
memory and interface statistics

106
00:05:11,490 --> 00:05:13,200
to determine if upgrades

107
00:05:13,200 --> 00:05:16,410
or additional resources
are going to be needed.

108
00:05:16,410 --> 00:05:19,950
Now, by analyzing the
NetFlow and the SNMP data,

109
00:05:19,950 --> 00:05:21,990
the company can make informed decisions

110
00:05:21,990 --> 00:05:25,080
about network updates,
equipment provisioning,

111
00:05:25,080 --> 00:05:26,943
and resource utilization.

112
00:05:29,700 --> 00:05:31,710
A third tool we're gonna look at is SCAP,

113
00:05:31,710 --> 00:05:34,860
Security Content Automation Protocol.

114
00:05:34,860 --> 00:05:37,230
SCAP is a collection of open standards

115
00:05:37,230 --> 00:05:39,120
developed by the National Institute

116
00:05:39,120 --> 00:05:41,310
of Standards and Technology, or NIST,

117
00:05:41,310 --> 00:05:44,070
to help organizations automate the process

118
00:05:44,070 --> 00:05:47,970
of managing and evaluating
security configurations

119
00:05:47,970 --> 00:05:50,853
and vulnerabilities in computer systems.

120
00:05:52,020 --> 00:05:54,750
The SCAP provides a standardized approach

121
00:05:54,750 --> 00:05:58,320
for expressing and sharing
security-related information,

122
00:05:58,320 --> 00:06:00,390
including configuration settings,

123
00:06:00,390 --> 00:06:03,450
vulnerability data, and patch management.

124
00:06:03,450 --> 00:06:05,490
It consists of several
components standards

125
00:06:05,490 --> 00:06:06,600
that work together.

126
00:06:06,600 --> 00:06:08,790
I'm gonna show you those in just a sec.

127
00:06:08,790 --> 00:06:10,590
Now, if you're really interested in SCAP,

128
00:06:10,590 --> 00:06:14,640
you can learn much more about
it at the NIST SCAP project.

129
00:06:14,640 --> 00:06:17,760
So you can go out to nist.gov,
you can search for SCAP,

130
00:06:17,760 --> 00:06:19,320
or you can follow the link that you see

131
00:06:19,320 --> 00:06:20,770
on the bottom of your screen.

132
00:06:22,680 --> 00:06:25,920
So what are all the components
that feed into SCAP?

133
00:06:25,920 --> 00:06:28,410
Well, we have the Common
Vulnerabilities & Exposures,

134
00:06:28,410 --> 00:06:32,013
CVEs, Common Configuration
Enumeration, CCE,

135
00:06:33,180 --> 00:06:36,570
Common Platform Enumeration, CPE,

136
00:06:36,570 --> 00:06:40,230
the Common Vulnerability
Scoring System, the CVSS,

137
00:06:40,230 --> 00:06:43,380
and Open Vulnerability and
Assessment Language, OVAL.

138
00:06:43,380 --> 00:06:45,030
Now, we've already talked
about two of them, right?

139
00:06:45,030 --> 00:06:47,370
We've talked about Common
Vulnerabilities & Exposures,

140
00:06:47,370 --> 00:06:51,840
CVE, and the Common Vulnerability
Scoring System, CVSS.

141
00:06:51,840 --> 00:06:53,640
So we will do a refresh on those

142
00:06:53,640 --> 00:06:55,890
but then we've got three
new ones to look at.

143
00:06:56,760 --> 00:06:59,400
Remember that the CVEs
are common identifiers

144
00:06:59,400 --> 00:07:01,803
for publicly known
security vulnerabilities.

145
00:07:02,820 --> 00:07:05,670
Common Configuration Enumeration, CCE,

146
00:07:05,670 --> 00:07:10,110
is common identifiers for
system configurations.

147
00:07:10,110 --> 00:07:14,580
CPE, Common Platform Enumeration,
is a naming convention

148
00:07:14,580 --> 00:07:17,190
for identifying software applications,

149
00:07:17,190 --> 00:07:20,760
operating systems and hardware devices.

150
00:07:20,760 --> 00:07:23,100
The CVSS, which we looked at earlier,

151
00:07:23,100 --> 00:07:24,390
is a framework for assessing

152
00:07:24,390 --> 00:07:26,790
the severity of software vulnerabilities.

153
00:07:26,790 --> 00:07:30,030
And lastly, Open Vulnerability
and Assessment Language,

154
00:07:30,030 --> 00:07:32,250
or OVAL, is a standardized language

155
00:07:32,250 --> 00:07:34,860
for expressing vulnerability assessments

156
00:07:34,860 --> 00:07:36,813
and configuration checks.

157
00:07:39,000 --> 00:07:41,460
So let's take a look
at how we can use SCAP

158
00:07:41,460 --> 00:07:43,920
in our vulnerability management.

159
00:07:43,920 --> 00:07:46,500
An organization uses a SCAP-compliant

160
00:07:46,500 --> 00:07:48,150
vulnerability scanning tool

161
00:07:48,150 --> 00:07:52,140
to periodically scan their
network devices and systems.

162
00:07:52,140 --> 00:07:54,540
The tools leverage SCAP's standardized

163
00:07:54,540 --> 00:07:57,090
vulnerability definitions, the CVEs,

164
00:07:57,090 --> 00:07:59,580
and the scoring system, the CVSS,

165
00:07:59,580 --> 00:08:01,350
to identify vulnerabilities

166
00:08:01,350 --> 00:08:03,393
and assign severity levels.

167
00:08:04,530 --> 00:08:08,100
The scan results are
presented in a unified format,

168
00:08:08,100 --> 00:08:10,590
allowing administrators to prioritize

169
00:08:10,590 --> 00:08:14,520
and remediate vulnerabilities
based on their severity.

170
00:08:14,520 --> 00:08:16,200
And then SCAP content,

171
00:08:16,200 --> 00:08:19,260
such as security
benchmarks and checklists,

172
00:08:19,260 --> 00:08:21,570
is used to assess the compliance

173
00:08:21,570 --> 00:08:25,290
of the system configuration
with industry standards

174
00:08:25,290 --> 00:08:27,630
and best practices.

175
00:08:27,630 --> 00:08:29,610
So three really interesting tools, right,

176
00:08:29,610 --> 00:08:32,913
SNMP, NetFlow, and SCAP.

177
00:08:34,650 --> 00:08:37,320
And that, my friends, brings
us to a three-second challenge.

178
00:08:37,320 --> 00:08:39,390
Five challenge questions,
three seconds each.

179
00:08:39,390 --> 00:08:40,390
You know what to do?

180
00:08:41,640 --> 00:08:44,040
Network management protocol
that allows administrators

181
00:08:44,040 --> 00:08:47,070
to monitor and manage network devices.

182
00:08:47,070 --> 00:08:48,633
One, two, three.

183
00:08:49,800 --> 00:08:51,000
It's gonna be SNMP,

184
00:08:51,000 --> 00:08:53,820
Simple Network Management Protocol.

185
00:08:53,820 --> 00:08:57,660
Number two, SNMP software
modules that are installed

186
00:08:57,660 --> 00:09:00,180
on a managed device.

187
00:09:00,180 --> 00:09:02,550
One, two, three.

188
00:09:02,550 --> 00:09:04,743
That's an agent. SNMP Agent.

189
00:09:06,000 --> 00:09:08,370
Number three, industry-standard protocol

190
00:09:08,370 --> 00:09:10,590
based on NetFlow version nine

191
00:09:10,590 --> 00:09:13,293
that provides a vendor-agnostic format.

192
00:09:14,550 --> 00:09:17,220
One, two, three.

193
00:09:17,220 --> 00:09:18,573
That's IPFIX.

194
00:09:19,980 --> 00:09:22,230
Number four, a standardized approach

195
00:09:22,230 --> 00:09:26,894
for expressing and sharing
security-related information.

196
00:09:26,894 --> 00:09:29,013
One, two, three.

197
00:09:30,030 --> 00:09:33,120
That's gonna be our Security
Content Automation Protocol,

198
00:09:33,120 --> 00:09:34,290
or SCAP.

199
00:09:34,290 --> 00:09:37,470
And lastly, number five,
a standardized language

200
00:09:37,470 --> 00:09:39,600
for expressing vulnerability assessments

201
00:09:39,600 --> 00:09:42,060
and configuration checks.

202
00:09:42,060 --> 00:09:43,500
One, two, three.

203
00:09:43,500 --> 00:09:45,273
You gonna get it? I hope so.

204
00:09:46,260 --> 00:09:49,713
That's OVAL, or Open Vulnerability
and Assessment Language.

205
00:09:51,270 --> 00:09:53,220
So that brings us to a security in action.

206
00:09:53,220 --> 00:09:55,500
And this one's about monitoring tools.

207
00:09:55,500 --> 00:10:00,500
Now, your company employs
SNMP, NetFlow and SCAP.

208
00:10:00,780 --> 00:10:04,080
But you are convinced that the
company isn't using the tools

209
00:10:04,080 --> 00:10:05,280
to their full potential,

210
00:10:05,280 --> 00:10:07,680
and you're exploring
ways to integrate them

211
00:10:07,680 --> 00:10:09,750
with management processes.

212
00:10:09,750 --> 00:10:12,990
Your first initiative
is incident response.

213
00:10:12,990 --> 00:10:15,060
So I want you to explain to me

214
00:10:15,060 --> 00:10:17,820
or actually to your colleagues, right,

215
00:10:17,820 --> 00:10:22,820
how SNMP, NetFlow, and SCAP
can be practically be applied

216
00:10:24,120 --> 00:10:26,220
for incident response.

217
00:10:26,220 --> 00:10:27,150
So put me on pause.

218
00:10:27,150 --> 00:10:29,550
This definitely, this might
take a little bit of time.

219
00:10:29,550 --> 00:10:32,220
Think about how you're going
to use those three tools

220
00:10:32,220 --> 00:10:34,293
in an incident response scenario.

221
00:10:37,290 --> 00:10:39,150
Well, during a security incident,

222
00:10:39,150 --> 00:10:40,740
the NetFlow data can be used

223
00:10:40,740 --> 00:10:43,080
to reconstruct network activities,

224
00:10:43,080 --> 00:10:45,720
trace the source and the
spread of the attack,

225
00:10:45,720 --> 00:10:47,523
and understand the impact.

226
00:10:48,600 --> 00:10:52,260
SCAP can be employed to
assess affected systems

227
00:10:52,260 --> 00:10:55,140
for vulnerabilities, check configurations,

228
00:10:55,140 --> 00:10:57,660
and identify potential security weaknesses

229
00:10:57,660 --> 00:10:59,880
that might've been exploited.

230
00:10:59,880 --> 00:11:04,080
And SNMP traps and SNMP
management systems play a role

231
00:11:04,080 --> 00:11:07,950
in the actual real-time
incident detection and alerting,

232
00:11:07,950 --> 00:11:12,000
providing notification for
critical security events.

233
00:11:12,000 --> 00:11:14,700
So all three of them
really have a role to play

234
00:11:14,700 --> 00:11:15,810
in incident response.

235
00:11:15,810 --> 00:11:18,030
And you were right on
target when you thought,

236
00:11:18,030 --> 00:11:18,863
you know what,

237
00:11:18,863 --> 00:11:20,940
we could probably make
better use of these tools

238
00:11:20,940 --> 00:11:23,250
rather than looking at
them each discreetly,

239
00:11:23,250 --> 00:11:26,280
how can we use all of
them together, right,

240
00:11:26,280 --> 00:11:29,730
to really address some
management processes.

241
00:11:29,730 --> 00:11:32,970
Being able to do that,
definitely security in action.

242
00:11:32,970 --> 00:11:34,050
There's your word cloud.

243
00:11:34,050 --> 00:11:35,190
You know what to do.

244
00:11:35,190 --> 00:11:36,390
And when you're ready,

245
00:11:36,390 --> 00:11:38,763
I'm gonna see you at
our next deep dive quiz.
