1
00:00:06,360 --> 00:00:09,210
- Welcome to Lesson 18, Given a scenario,

2
00:00:09,210 --> 00:00:12,780
modify enterprise capabilities
to enhance security.

3
00:00:12,780 --> 00:00:15,540
In our first lesson,
18.1, we're gonna talk

4
00:00:15,540 --> 00:00:19,620
about enhancing security
with network devices.

5
00:00:19,620 --> 00:00:21,780
In this lesson, we're going to be looking

6
00:00:21,780 --> 00:00:26,730
at how we can use network
devices to enhance our security.

7
00:00:26,730 --> 00:00:28,320
But a number of these devices,

8
00:00:28,320 --> 00:00:29,820
we've already talked about.

9
00:00:29,820 --> 00:00:34,497
Firewalls, IDS/IPS, DLP, NAC, and UEBA.

10
00:00:36,150 --> 00:00:38,100
So let's do a refresher on those.

11
00:00:38,100 --> 00:00:40,590
And then we'll talk about some new devices

12
00:00:40,590 --> 00:00:42,240
that we haven't talked about yet.

13
00:00:42,240 --> 00:00:47,240
Web filters, file integrity
monitoring, and EDR/XDR.

14
00:00:47,940 --> 00:00:52,650
As a refresher, we use firewalls
to enforce security policy

15
00:00:52,650 --> 00:00:57,060
by controlling ingress incoming
and egress outgoing traffic,

16
00:00:57,060 --> 00:00:59,670
using rules and access controllers.

17
00:00:59,670 --> 00:01:02,850
We use our IDSs and our IPSs to analyze

18
00:01:02,850 --> 00:01:05,130
and monitor for suspicious traffic.

19
00:01:05,130 --> 00:01:08,970
And then the IPS can
also deny traffic access.

20
00:01:08,970 --> 00:01:11,340
DLP, our data loss prevention,

21
00:01:11,340 --> 00:01:15,000
we use to detect and prevent
unauthorized transfer

22
00:01:15,000 --> 00:01:17,460
and exfiltration of data.

23
00:01:17,460 --> 00:01:20,070
Our NAC, network access control,

24
00:01:20,070 --> 00:01:22,860
we use to enforce
endpoint access privileges

25
00:01:22,860 --> 00:01:26,700
based on pre-admission and
post admission policies.

26
00:01:26,700 --> 00:01:29,460
And UEBA is our automation tool

27
00:01:29,460 --> 00:01:32,310
that models the behavior
of humans and machines

28
00:01:32,310 --> 00:01:36,000
to identify normal and abnormal behavior.

29
00:01:36,000 --> 00:01:39,270
So again, all of those were
covered in previous lessons.

30
00:01:39,270 --> 00:01:41,970
In this lesson, we're gonna
talk about web filters

31
00:01:41,970 --> 00:01:44,370
that we use to enforce
restrictions to websites

32
00:01:44,370 --> 00:01:46,341
based on predefined criteria,

33
00:01:46,341 --> 00:01:49,020
file integrity monitoring to detect

34
00:01:49,020 --> 00:01:52,410
and report on changes
made to system application

35
00:01:52,410 --> 00:01:57,030
and configuration files,
and then EDR and XDR,

36
00:01:57,030 --> 00:02:00,430
which are advanced integrated
platforms that monitor,

37
00:02:00,430 --> 00:02:04,113
report on, and respond
to security threats.

38
00:02:05,790 --> 00:02:07,380
So starting with web filters.

39
00:02:07,380 --> 00:02:10,440
Web filters are used to
enforce content restrictions

40
00:02:10,440 --> 00:02:14,670
to websites based on
a predefined criteria.

41
00:02:14,670 --> 00:02:17,100
Now web filters are often used to enforce

42
00:02:17,100 --> 00:02:18,330
an acceptable use policy.

43
00:02:18,330 --> 00:02:20,700
We haven't talked about
that yet, but we will.

44
00:02:20,700 --> 00:02:23,070
Also, to protect against
malicious websites

45
00:02:23,070 --> 00:02:25,740
and to regulate internet access.

46
00:02:25,740 --> 00:02:27,819
Now web filters can set limits on sites

47
00:02:27,819 --> 00:02:29,820
that consume bandwidth,

48
00:02:29,820 --> 00:02:33,030
and web filters can reduce shadow IT

49
00:02:33,030 --> 00:02:36,270
by monitoring and blocking
the uncontrolled use

50
00:02:36,270 --> 00:02:37,893
of cloud applications.

51
00:02:39,420 --> 00:02:41,550
Now there are different approaches

52
00:02:41,550 --> 00:02:43,590
and techniques to web filtering.

53
00:02:43,590 --> 00:02:46,080
URL filtering, keyword filtering,

54
00:02:46,080 --> 00:02:49,410
allow and block lists, content analysis,

55
00:02:49,410 --> 00:02:53,620
category filtering, and
time-based filtering.

56
00:02:53,620 --> 00:02:57,570
In URL filtering, what we're
doing is controlling access

57
00:02:57,570 --> 00:03:00,198
to websites based on their URLs

58
00:03:00,198 --> 00:03:05,190
by comparing their URL with a
database of categorized URLs.

59
00:03:05,190 --> 00:03:07,593
These are ones you can
go to or you can't go to.

60
00:03:08,549 --> 00:03:11,316
Keyword filtering controls
access to websites

61
00:03:11,316 --> 00:03:16,230
and content based on
specific words, phrases,

62
00:03:16,230 --> 00:03:18,720
or patterns that are found in the URL

63
00:03:18,720 --> 00:03:20,463
or in the webpage itself.

64
00:03:21,690 --> 00:03:25,800
Allow and block list control
access based on a maintain list

65
00:03:25,800 --> 00:03:28,230
of allowed sites and or block sites.

66
00:03:28,230 --> 00:03:29,850
Here are the only sites
we're gonna let you go to

67
00:03:29,850 --> 00:03:32,839
or here are the sites
that we're gonna block.

68
00:03:32,839 --> 00:03:36,090
Content analysis is how we control access

69
00:03:36,090 --> 00:03:38,460
based on an analysis of the site,

70
00:03:38,460 --> 00:03:42,330
including text, images,
and programming language.

71
00:03:42,330 --> 00:03:44,940
So it's really a maturity
of the keyword filtering.

72
00:03:44,940 --> 00:03:47,130
Keyword filtering was
just looking for keywords.

73
00:03:47,130 --> 00:03:49,800
In content analysis, we're
also looking at the text,

74
00:03:49,800 --> 00:03:52,893
the images, and even underlying
programming language.

75
00:03:54,240 --> 00:03:57,060
Category filtering is
controls based on a category.

76
00:03:57,060 --> 00:04:00,690
So for example, you can't
access adult content

77
00:04:00,690 --> 00:04:02,160
or based on media type.

78
00:04:02,160 --> 00:04:04,380
You can't access streaming media.

79
00:04:04,380 --> 00:04:06,946
And time filtering controls access

80
00:04:06,946 --> 00:04:10,173
during times of the day
or days of the week.

81
00:04:12,780 --> 00:04:15,450
There are different ways
to implement filtering.

82
00:04:15,450 --> 00:04:17,280
We can have, on the client side,

83
00:04:17,280 --> 00:04:20,070
browser extensions or local software,

84
00:04:20,070 --> 00:04:23,280
or we could have a centralized
network proxy server

85
00:04:23,280 --> 00:04:26,640
or we could do it in the cloud,
have a cloud-based service.

86
00:04:26,640 --> 00:04:27,810
The browser extensions,

87
00:04:27,810 --> 00:04:30,600
sometimes referred to
as plugins or add-ons,

88
00:04:30,600 --> 00:04:34,710
are used on an individual device
to filter internet access.

89
00:04:34,710 --> 00:04:36,840
That's gonna be effective for personal use

90
00:04:36,840 --> 00:04:39,513
or for really small scale use.

91
00:04:40,470 --> 00:04:43,331
We can also have, on the
client side, local software

92
00:04:43,331 --> 00:04:45,660
and that is software that's installed

93
00:04:45,660 --> 00:04:49,020
on the individual devices
for internet filtering.

94
00:04:49,020 --> 00:04:51,480
Once again, effective for personal use

95
00:04:51,480 --> 00:04:53,313
or on a very small scale.

96
00:04:54,240 --> 00:04:56,580
Now a centralized network proxy server

97
00:04:56,580 --> 00:04:59,250
will process all requests
that the user makes

98
00:04:59,250 --> 00:05:01,950
and that gives the
proxy server the ability

99
00:05:01,950 --> 00:05:05,160
to filter the content
or block or allow access

100
00:05:05,160 --> 00:05:06,303
to the websites.

101
00:05:07,650 --> 00:05:09,780
And then we have cloud-based solutions.

102
00:05:09,780 --> 00:05:12,120
A cloud-based SaaS web filter

103
00:05:12,120 --> 00:05:14,501
processes the internet
request in the cloud.

104
00:05:14,501 --> 00:05:18,180
Now DNS servers are configured to point

105
00:05:18,180 --> 00:05:20,451
to the web filtering provider

106
00:05:20,451 --> 00:05:22,650
and that's where the decisions are made.

107
00:05:22,650 --> 00:05:25,560
Now of course, if we're not
going through a proxy server,

108
00:05:25,560 --> 00:05:26,730
maybe we're working at home

109
00:05:26,730 --> 00:05:28,320
so we don't go through the proxy server,

110
00:05:28,320 --> 00:05:30,180
it may require an agent

111
00:05:30,180 --> 00:05:32,763
on those remote devices
for remote workers.

112
00:05:35,130 --> 00:05:36,390
Next up is FIM.

113
00:05:36,390 --> 00:05:39,180
FIM stands for file integrity monitoring.

114
00:05:39,180 --> 00:05:41,700
Now FIM tools are used
to detect and report

115
00:05:41,700 --> 00:05:44,550
on changes made to a
system and application

116
00:05:44,550 --> 00:05:46,470
or a configuration file.

117
00:05:46,470 --> 00:05:50,940
And FIM can monitor just a
really wide range of attributes,

118
00:05:50,940 --> 00:05:55,020
including file size,
permissions, modification,

119
00:05:55,020 --> 00:05:57,273
access, and ownership.

120
00:05:58,620 --> 00:06:00,690
So what does the FIM process look like?

121
00:06:00,690 --> 00:06:04,230
Well, a baseline creation
of the file is created.

122
00:06:04,230 --> 00:06:06,000
Really, what we're doing
is we're creating a hash.

123
00:06:06,000 --> 00:06:09,240
Remember, a hash is just
a visual representation.

124
00:06:09,240 --> 00:06:11,340
We talked about how we
created hashes early on.

125
00:06:11,340 --> 00:06:12,990
We're gonna use a a hash calculator.

126
00:06:12,990 --> 00:06:14,970
It could be online or local.

127
00:06:14,970 --> 00:06:17,340
And we're going to take
a variable length input

128
00:06:17,340 --> 00:06:20,760
and we're gonna end up with a unique

129
00:06:20,760 --> 00:06:23,940
one-way fixed length output called a hash

130
00:06:23,940 --> 00:06:26,040
or a message digest.

131
00:06:26,040 --> 00:06:28,800
So we're gonna create a hash of the file.

132
00:06:28,800 --> 00:06:32,210
And then the FIM software
who has created the hash

133
00:06:32,210 --> 00:06:35,850
will monitor, either real-time monitoring

134
00:06:35,850 --> 00:06:39,840
or periodic checks to see
if anything has changed

135
00:06:39,840 --> 00:06:43,713
in that file by looking at
the hash, right, rehashing.

136
00:06:45,000 --> 00:06:47,220
Doing a comparison, did anything change

137
00:06:47,220 --> 00:06:48,750
or are they same, right?

138
00:06:48,750 --> 00:06:50,040
If anything changed in the hash,

139
00:06:50,040 --> 00:06:52,170
we know that that file was modified.

140
00:06:52,170 --> 00:06:54,030
But if nothing's changed in the hash,

141
00:06:54,030 --> 00:06:57,000
we know the file has not been modified.

142
00:06:57,000 --> 00:06:58,410
But if there is a change,

143
00:06:58,410 --> 00:07:00,960
then the FIM software will
be able to send an alert.

144
00:07:00,960 --> 00:07:02,435
This file has changed.

145
00:07:02,435 --> 00:07:04,830
Could be a data file,
could be a database file,

146
00:07:04,830 --> 00:07:07,280
could be a registry file,
could be a system file.

147
00:07:10,890 --> 00:07:14,700
Next, we have endpoint detection
and response known as EDR.

148
00:07:14,700 --> 00:07:17,130
The endpoint detection
and response solutions

149
00:07:17,130 --> 00:07:19,740
continually monitor our endpoint devices,

150
00:07:19,740 --> 00:07:22,530
or host devices, right,
to detect and respond

151
00:07:22,530 --> 00:07:24,123
to suspicious activity.

152
00:07:25,110 --> 00:07:27,480
The EDR tools identify threats

153
00:07:27,480 --> 00:07:29,220
using a variety of techniques,

154
00:07:29,220 --> 00:07:30,990
including pattern recognition,

155
00:07:30,990 --> 00:07:34,200
anomaly detection, and
behavioral analytics.

156
00:07:34,200 --> 00:07:36,600
And when a potential threat is detected,

157
00:07:36,600 --> 00:07:38,520
then an alert can be sent.

158
00:07:38,520 --> 00:07:41,520
The EDR tools can be configured to respond

159
00:07:41,520 --> 00:07:43,590
to the event by isolating the endpoint.

160
00:07:43,590 --> 00:07:48,120
So something's wrong, the
EDR tool can be instructed

161
00:07:48,120 --> 00:07:50,580
to isolate that device, right,

162
00:07:50,580 --> 00:07:52,500
that endpoint from the network

163
00:07:52,500 --> 00:07:54,573
or from any other surrounding systems.

164
00:07:55,590 --> 00:07:58,500
Extended detection and response, XDR,

165
00:07:58,500 --> 00:08:01,620
really takes EDR to the next level.

166
00:08:01,620 --> 00:08:04,770
Extended detection and response, XDR,

167
00:08:04,770 --> 00:08:08,550
is a unified platform that
continuously monitors activity

168
00:08:08,550 --> 00:08:10,050
across the enterprise.

169
00:08:10,050 --> 00:08:13,170
Network traffic, cloud workloads, email,

170
00:08:13,170 --> 00:08:17,204
and any other relevant security
data for security threats.

171
00:08:17,204 --> 00:08:20,940
The XDR tools collect and correlate data

172
00:08:20,940 --> 00:08:22,680
across different security layers,

173
00:08:22,680 --> 00:08:25,113
creating this really holistic view.

174
00:08:25,113 --> 00:08:28,830
XDR systems also incorporate
advanced analytics

175
00:08:28,830 --> 00:08:31,710
and AI, artificial intelligence.

176
00:08:31,710 --> 00:08:35,130
And our XDR tools can
be configured to respond

177
00:08:35,130 --> 00:08:38,990
to detected threats on multiple
levels, isolate a system,

178
00:08:38,990 --> 00:08:43,320
block malicious traffic,
or disable a user account.

179
00:08:43,320 --> 00:08:45,300
So this is really the way
we're kind of heading.

180
00:08:45,300 --> 00:08:49,200
This is an emerging technology and tool.

181
00:08:49,200 --> 00:08:51,390
A little bit complex,
a little bit expensive,

182
00:08:51,390 --> 00:08:53,610
but really think about what it does.

183
00:08:53,610 --> 00:08:56,160
This unified look, right,

184
00:08:56,160 --> 00:08:59,940
at activity across our entire platform.

185
00:08:59,940 --> 00:09:02,910
And that, my friends, brings
us to a three-second challenge.

186
00:09:02,910 --> 00:09:05,100
Five challenge questions,
three seconds each.

187
00:09:05,100 --> 00:09:06,720
You know how to do it.

188
00:09:06,720 --> 00:09:08,310
Detects and reports on changes made

189
00:09:08,310 --> 00:09:11,790
to system application
and configuration files.

190
00:09:11,790 --> 00:09:13,173
One, two, three.

191
00:09:14,280 --> 00:09:17,013
It's gonna be file
integrity monitor or FIM.

192
00:09:18,090 --> 00:09:21,690
Number two, enforces content
restrictions to websites

193
00:09:21,690 --> 00:09:24,570
based on predefined criteria.

194
00:09:24,570 --> 00:09:26,493
One, two, three.

195
00:09:27,510 --> 00:09:28,910
It's gonna be web filtering.

196
00:09:30,030 --> 00:09:33,180
Number three, solution
that continuously monitors

197
00:09:33,180 --> 00:09:35,310
endpoint devices to detect

198
00:09:35,310 --> 00:09:37,353
and respond to suspicious activity.

199
00:09:38,460 --> 00:09:40,350
One, two, three.

200
00:09:40,350 --> 00:09:43,863
It's gonna be EDR, or endpoint
detection and response.

201
00:09:44,790 --> 00:09:47,280
Number four, unified platform

202
00:09:47,280 --> 00:09:51,570
that continuously monitors
activity across the enterprise.

203
00:09:51,570 --> 00:09:53,467
One, two, three.

204
00:09:53,467 --> 00:09:58,200
It's gonna be XDR, extended
detection and response.

205
00:09:58,200 --> 00:10:00,210
And lastly, number five.

206
00:10:00,210 --> 00:10:05,210
Controls internet access during
times of the day or week.

207
00:10:05,370 --> 00:10:06,840
And this would be a type of web filtering.

208
00:10:06,840 --> 00:10:07,673
What is it?

209
00:10:08,520 --> 00:10:10,320
One, two, three.

210
00:10:10,320 --> 00:10:11,823
Time-based filtering.

211
00:10:12,930 --> 00:10:15,510
So that brings us to a security in action.

212
00:10:15,510 --> 00:10:18,480
And this one is about
internet access issues.

213
00:10:18,480 --> 00:10:20,790
Now your organization's
experiencing challenges

214
00:10:20,790 --> 00:10:23,430
related to internet use in the workplace.

215
00:10:23,430 --> 00:10:25,860
As workers have continued
to work from home,

216
00:10:25,860 --> 00:10:27,660
there's been an uptick in the amount

217
00:10:27,660 --> 00:10:30,150
of non-work-related browsing.

218
00:10:30,150 --> 00:10:32,760
Concurrently, there's
been an increase in visits

219
00:10:32,760 --> 00:10:35,640
to suspected malware distribution sites.

220
00:10:35,640 --> 00:10:38,430
So your boss has called a
meeting to discuss this issue

221
00:10:38,430 --> 00:10:40,470
and he's asked you to be prepared

222
00:10:40,470 --> 00:10:43,230
to share suggestions and recommendations.

223
00:10:43,230 --> 00:10:46,020
Now he's also concerned
about staffing shortage,

224
00:10:46,020 --> 00:10:49,110
so he doesn't wanna have to
put any additional burden

225
00:10:49,110 --> 00:10:53,194
or minimal additional burden,
at best, on our current staff.

226
00:10:53,194 --> 00:10:56,010
So again, what's going on here, right?

227
00:10:56,010 --> 00:10:59,580
We've got problems related to
internet use in the workplace.

228
00:10:59,580 --> 00:11:01,350
We've got an uptick in the amount

229
00:11:01,350 --> 00:11:03,480
of non-work related browsing.

230
00:11:03,480 --> 00:11:06,630
And concurrently, we've
got an increase in visits

231
00:11:06,630 --> 00:11:10,020
to suspected malware distribution sites.

232
00:11:10,020 --> 00:11:11,430
So go ahead and put me on pause.

233
00:11:11,430 --> 00:11:14,153
Think about what your
recommendations are to your boss.

234
00:11:16,230 --> 00:11:18,660
Well, web filtering would
be a great recommendation

235
00:11:18,660 --> 00:11:20,100
because web filtering can be used

236
00:11:20,100 --> 00:11:22,710
to block access to
websites and categories,

237
00:11:22,710 --> 00:11:26,730
such as adult content,
social media, personal email,

238
00:11:26,730 --> 00:11:28,950
and online shopping during work hours,

239
00:11:28,950 --> 00:11:31,290
as well as to streaming services.

240
00:11:31,290 --> 00:11:34,800
It can also be configured to
block known malicious websites

241
00:11:34,800 --> 00:11:37,530
and those websites that are uncategorized,

242
00:11:37,530 --> 00:11:40,533
as those could potentially
pose a security risk.

243
00:11:41,670 --> 00:11:43,500
Now if we're worried
about staffing, right,

244
00:11:43,500 --> 00:11:45,660
increasing their burden or their workload,

245
00:11:45,660 --> 00:11:47,430
a cloud-based solution could be used

246
00:11:47,430 --> 00:11:50,580
for both our on-premises
and remote workers.

247
00:11:50,580 --> 00:11:52,740
Our DNS servers would
need to be configured

248
00:11:52,740 --> 00:11:55,170
to point to the SaaS provider

249
00:11:55,170 --> 00:11:58,413
and an agent installed
on the remote devices.

250
00:11:59,700 --> 00:12:01,590
That cloud-based SaaS solution, again,

251
00:12:01,590 --> 00:12:04,620
offloads the work from
the on-premise staff

252
00:12:04,620 --> 00:12:07,200
while still allowing
you to put in a solution

253
00:12:07,200 --> 00:12:09,420
that's gonna specifically
address the issues

254
00:12:09,420 --> 00:12:10,923
that your company is facing.

255
00:12:11,970 --> 00:12:13,260
Great recommendation to make.

256
00:12:13,260 --> 00:12:14,610
I bet your boss is thrilled

257
00:12:14,610 --> 00:12:16,833
and thinking that's security in action.

258
00:12:17,970 --> 00:12:19,410
All right, there's your word cloud.

259
00:12:19,410 --> 00:12:20,760
You know what to do.

260
00:12:20,760 --> 00:12:22,360
I'll see you at the next lesson.
