1
00:00:06,480 --> 00:00:08,050
- In this lesson, 2.5,

2
00:00:08,050 --> 00:00:11,070
which is the last
sub-lesson of lesson two,

3
00:00:11,070 --> 00:00:14,973
we're gonna focus in on
deception and disruption.

4
00:00:16,350 --> 00:00:19,710
Now deception and disruption
technologies and practices

5
00:00:19,710 --> 00:00:23,340
are used to deceive potential
attackers, or adversaries,

6
00:00:23,340 --> 00:00:26,880
with the goal of, one, threat
intelligence collection,

7
00:00:26,880 --> 00:00:30,033
and, two, importantly,
early breach detection.

8
00:00:31,170 --> 00:00:34,380
To accomplish this task,
we're gonna use honey traps.

9
00:00:34,380 --> 00:00:36,900
Honey traps are a deception technique

10
00:00:36,900 --> 00:00:38,940
that allows security defenders

11
00:00:38,940 --> 00:00:41,970
to understand attacker behavior patterns.

12
00:00:41,970 --> 00:00:43,710
Now honey traps will vary

13
00:00:43,710 --> 00:00:46,500
based on design and how
we're deploying them,

14
00:00:46,500 --> 00:00:48,390
but here's what they all have in common,

15
00:00:48,390 --> 00:00:51,630
they're intended to look really legitimate

16
00:00:51,630 --> 00:00:54,540
to attract attackers, because
that's our goal, right?

17
00:00:54,540 --> 00:00:57,180
They're gonna be
non-production systems, right?

18
00:00:57,180 --> 00:00:58,290
We don't want them to really attack

19
00:00:58,290 --> 00:00:59,700
anything we actually have,

20
00:00:59,700 --> 00:01:03,570
but we want to tempt our
adversaries, our attackers,

21
00:01:03,570 --> 00:01:06,450
we wanna understand how
they might attack us,

22
00:01:06,450 --> 00:01:08,280
and then we wanna be able
to apply that knowledge

23
00:01:08,280 --> 00:01:10,710
to early breach detection.

24
00:01:10,710 --> 00:01:12,840
Now there are different
types of honey traps,

25
00:01:12,840 --> 00:01:15,630
including honeypots, honeynets,

26
00:01:15,630 --> 00:01:18,723
honeyfiles, and honeytokens.

27
00:01:20,370 --> 00:01:22,590
A honeypot is going to be a decoy system.

28
00:01:22,590 --> 00:01:25,440
Could be a web server,
could be a database server,

29
00:01:25,440 --> 00:01:28,650
could be a domain controller,
could be an email server,

30
00:01:28,650 --> 00:01:30,000
could be an FTP server.

31
00:01:30,000 --> 00:01:31,890
It's just a decoy system.

32
00:01:31,890 --> 00:01:35,490
I wanna stress, again, it's
one we're using as a honeypot.

33
00:01:35,490 --> 00:01:39,930
It's not being used in our
production environment.

34
00:01:39,930 --> 00:01:41,760
Now there are two types of honeypots.

35
00:01:41,760 --> 00:01:43,800
There are high-interaction honeypots

36
00:01:43,800 --> 00:01:45,900
and low-interaction honeypots.

37
00:01:45,900 --> 00:01:47,730
A high-interaction honeypot

38
00:01:47,730 --> 00:01:51,330
is really running the
application that it says it is.

39
00:01:51,330 --> 00:01:53,640
So if it says that it's a web server,

40
00:01:53,640 --> 00:01:57,000
it's really let's say
running IIS or Apache, right?

41
00:01:57,000 --> 00:01:59,550
If it thinks it's a email server,

42
00:01:59,550 --> 00:02:02,190
it's really running, maybe Exchange.

43
00:02:02,190 --> 00:02:04,650
So that would be a high interaction.

44
00:02:04,650 --> 00:02:08,070
A low-interaction honeypot
isn't actually running

45
00:02:08,070 --> 00:02:10,740
those applications or
providing those services,

46
00:02:10,740 --> 00:02:12,300
but it appears to the attacker

47
00:02:12,300 --> 00:02:14,760
that they are because they're listening

48
00:02:14,760 --> 00:02:16,260
on a particular port.

49
00:02:16,260 --> 00:02:20,310
So we know that there's
communication on port 80

50
00:02:20,310 --> 00:02:24,750
for HTTP or for a web
server, port 21 for FTP,

51
00:02:24,750 --> 00:02:26,700
and so they're listening on those ports.

52
00:02:26,700 --> 00:02:28,087
And so when the attacker says,

53
00:02:28,087 --> 00:02:31,500
"Let me see what ports
are open on that device,"

54
00:02:31,500 --> 00:02:34,470
they might see the HTTP, or HTTPS,

55
00:02:34,470 --> 00:02:37,897
port 80 or 443 is open
and they're gonna think,

56
00:02:37,897 --> 00:02:40,890
"Aha, that must be a web server or FTP.

57
00:02:40,890 --> 00:02:43,257
Oh, that must be an FTP server."

58
00:02:44,610 --> 00:02:46,320
Hard to find, but if you can find it,

59
00:02:46,320 --> 00:02:49,110
there is a nice, little
low-interaction honeypot

60
00:02:49,110 --> 00:02:51,330
called BackOfficer Friendly.

61
00:02:51,330 --> 00:02:52,680
If you can still find it out there,

62
00:02:52,680 --> 00:02:54,480
it's worth bringing that into your lab.

63
00:02:54,480 --> 00:02:55,650
It's a really fun one.

64
00:02:55,650 --> 00:02:58,230
You can have BackOfficer Friendly listen

65
00:02:58,230 --> 00:03:03,063
on port 80 or 443 for HTTP and HTTPS.

66
00:03:03,063 --> 00:03:06,450
They can listen on FTP, it
can listen on Telnet ports.

67
00:03:06,450 --> 00:03:08,430
It can also even do some fake responses.

68
00:03:08,430 --> 00:03:09,540
It's just a fun thing to play

69
00:03:09,540 --> 00:03:11,010
around with in your
lab if you can find it.

70
00:03:11,010 --> 00:03:13,593
It's called BOF, BackOfficer Friendly.

71
00:03:14,430 --> 00:03:17,130
Now a honeynet is just
multiple linked honeypots

72
00:03:17,130 --> 00:03:19,233
that simulate a network environment.

73
00:03:20,460 --> 00:03:22,530
A honeyfile is a decoy file

74
00:03:22,530 --> 00:03:24,240
located on a network file share,

75
00:03:24,240 --> 00:03:28,590
and they're really
designed to tempt access,

76
00:03:28,590 --> 00:03:32,340
then detect access and
exfiltration attempts.

77
00:03:32,340 --> 00:03:35,490
So it'll often have a
really, really tempting name,

78
00:03:35,490 --> 00:03:39,397
like CEO payroll type of
thing so that they can say,

79
00:03:39,397 --> 00:03:41,250
"Oh, I wanna see what that is,"

80
00:03:41,250 --> 00:03:43,440
you know, let's see who's going after it.

81
00:03:43,440 --> 00:03:45,480
And then, lastly, we have a honeytoken.

82
00:03:45,480 --> 00:03:49,230
A honeytoken is a beacon
that's actually embedded

83
00:03:49,230 --> 00:03:51,270
into either a document or a database.

84
00:03:51,270 --> 00:03:55,200
It can be embedded in an image,
in a directory, in a folder.

85
00:03:55,200 --> 00:03:56,970
But the key about a honeytoken

86
00:03:56,970 --> 00:03:59,250
is that it goes with the attacker,

87
00:03:59,250 --> 00:04:02,190
and it can ultimately be used to tell us

88
00:04:02,190 --> 00:04:03,900
about what the attacker's doing

89
00:04:03,900 --> 00:04:06,693
and maybe even who the attacker is.

90
00:04:08,460 --> 00:04:11,790
So these honeytokens are used
to track malicious actors

91
00:04:11,790 --> 00:04:15,090
revealing critical information
about their identity,

92
00:04:15,090 --> 00:04:19,080
as well as the methods that
they use to exploit a system.

93
00:04:19,080 --> 00:04:21,600
So they can be a really,
really effective tool

94
00:04:21,600 --> 00:04:25,470
in identifying our cyber
attackers, or our adversaries,

95
00:04:25,470 --> 00:04:27,900
because they can send specific information

96
00:04:27,900 --> 00:04:29,700
back to us about an attacker

97
00:04:29,700 --> 00:04:33,750
that we might not otherwise
ever be able to glean or get.

98
00:04:33,750 --> 00:04:35,790
Now honeytokens, as I
mentioned a moment ago,

99
00:04:35,790 --> 00:04:38,400
can really be embedded in
a variety of locations.

100
00:04:38,400 --> 00:04:39,960
They can be in executable files,

101
00:04:39,960 --> 00:04:41,640
they can be in database records,

102
00:04:41,640 --> 00:04:43,140
they can be in browser cookies,

103
00:04:43,140 --> 00:04:45,870
they can be in images,
they can even be in APIs,

104
00:04:45,870 --> 00:04:48,090
application programming interfaces.

105
00:04:48,090 --> 00:04:48,930
Really interesting.

106
00:04:48,930 --> 00:04:50,700
You should read up more about honeytokens.

107
00:04:50,700 --> 00:04:53,103
I think they're a
fascinating, fascinating tool.

108
00:04:54,600 --> 00:04:55,980
Now there are some other types of traps

109
00:04:55,980 --> 00:04:57,330
you wanna be familiar with.

110
00:04:57,330 --> 00:04:58,500
There are spam traps,

111
00:04:58,500 --> 00:05:01,110
which are just fake email addresses

112
00:05:01,110 --> 00:05:04,770
that are used to identify
and to block spammers.

113
00:05:04,770 --> 00:05:06,500
Now legitimate email is really unlikely

114
00:05:06,500 --> 00:05:08,460
to be sent to the fake address,

115
00:05:08,460 --> 00:05:12,210
so when the email is received,
it is most likely spam.

116
00:05:12,210 --> 00:05:14,400
And then, we have DNS sinkholes.

117
00:05:14,400 --> 00:05:17,160
A DNS sinkhole is a DNS server

118
00:05:17,160 --> 00:05:20,280
that is going to respond
with false results.

119
00:05:20,280 --> 00:05:21,990
Now DNS sinkholes can be used

120
00:05:21,990 --> 00:05:24,210
to redirect malicious internet traffic

121
00:05:24,210 --> 00:05:27,600
so it can be captured and
analyzed by security analysts.

122
00:05:27,600 --> 00:05:29,850
And those sinkholes are most often used

123
00:05:29,850 --> 00:05:32,190
to seize control of a botnet

124
00:05:32,190 --> 00:05:34,830
by interrupting the
DNS names of the botnet

125
00:05:34,830 --> 00:05:36,483
that's used by the malware.

126
00:05:39,360 --> 00:05:41,220
And that, my friends, brings us to the end

127
00:05:41,220 --> 00:05:43,230
of deception and disruption.

128
00:05:43,230 --> 00:05:44,910
So let's do a three-second
challenge together.

129
00:05:44,910 --> 00:05:46,170
You know how to do these.

130
00:05:46,170 --> 00:05:47,580
You ready to shout 'em out?

131
00:05:47,580 --> 00:05:49,140
Let's do it.

132
00:05:49,140 --> 00:05:52,530
Decoy file located on
a network file share.

133
00:05:52,530 --> 00:05:53,580
What is that?

134
00:05:53,580 --> 00:05:55,383
One, two, three.

135
00:05:56,610 --> 00:05:58,410
That's a honeyfile.

136
00:05:58,410 --> 00:06:00,480
These are kind of gimmes, aren't they?

137
00:06:00,480 --> 00:06:02,340
Number two, multiple linked honeypots

138
00:06:02,340 --> 00:06:04,710
that simulate a network environment.

139
00:06:04,710 --> 00:06:06,183
One, two, three.

140
00:06:07,140 --> 00:06:08,073
A honeynet.

141
00:06:09,480 --> 00:06:14,460
Number three, type of honeypot
that imitates services.

142
00:06:14,460 --> 00:06:17,493
A type of honeypot that imitates services.

143
00:06:18,330 --> 00:06:20,673
One, two, three.

144
00:06:21,720 --> 00:06:23,910
That's a low-interaction honeypot, right?

145
00:06:23,910 --> 00:06:25,410
It pretends, it's listening.

146
00:06:25,410 --> 00:06:27,633
It's not really offering those services.

147
00:06:29,430 --> 00:06:31,680
Number four, type of honey trap

148
00:06:31,680 --> 00:06:34,293
that incorporates an embedded beacon.

149
00:06:35,850 --> 00:06:38,193
One, two, three.

150
00:06:39,150 --> 00:06:41,280
That's called a honeytoken.

151
00:06:41,280 --> 00:06:43,320
And lastly, number five, the type of trap

152
00:06:43,320 --> 00:06:46,923
that responds with false
domain names or URLs.

153
00:06:48,450 --> 00:06:50,730
One, two, three, what do you got?

154
00:06:50,730 --> 00:06:53,580
It's gonna be a DNS sinkhole, good work.

155
00:06:53,580 --> 00:06:55,770
All right, let's go into our
security in action case study.

156
00:06:55,770 --> 00:06:58,710
This one's about
identifying cyber criminals.

157
00:06:58,710 --> 00:07:00,990
At a staff meeting, your boss noted

158
00:07:00,990 --> 00:07:03,990
that the European Union
Agency for Cybersecurity,

159
00:07:03,990 --> 00:07:08,790
or ENISA, has specifically
recommended the use of honeypots

160
00:07:08,790 --> 00:07:12,570
and honeytokens to trap or
ensnare cyber criminals.

161
00:07:12,570 --> 00:07:14,700
You've been assigned
the task of researching

162
00:07:14,700 --> 00:07:16,800
the difference between the two,

163
00:07:16,800 --> 00:07:20,343
honeypots and honeytokens,
and reporting back.

164
00:07:21,270 --> 00:07:23,430
So I want you to summarize your research.

165
00:07:23,430 --> 00:07:28,020
You have to report back the
difference between the two,

166
00:07:28,020 --> 00:07:30,900
between the honeypot and a honeytoken.

167
00:07:30,900 --> 00:07:32,340
So go ahead, put me on pause,

168
00:07:32,340 --> 00:07:34,140
write down a couple of notes.

169
00:07:34,140 --> 00:07:35,760
What's the difference between the two?

170
00:07:35,760 --> 00:07:37,140
And summarize them,

171
00:07:37,140 --> 00:07:39,323
and then you're gonna
report right back on it.

172
00:07:42,240 --> 00:07:45,450
Well, first off, both
honeypots and honeynets

173
00:07:45,450 --> 00:07:47,580
are decoy-based tools, right?

174
00:07:47,580 --> 00:07:49,050
So no difference there,

175
00:07:49,050 --> 00:07:51,333
they're both decoy-based tools.

176
00:07:52,380 --> 00:07:56,340
But honeypots are passive
network detection systems.

177
00:07:56,340 --> 00:07:57,900
The objective of a honeypot

178
00:07:57,900 --> 00:08:01,350
is to gather attack strategy for analysis.

179
00:08:01,350 --> 00:08:03,840
We're seeing how we might be attacked

180
00:08:03,840 --> 00:08:05,460
so that we can better understand

181
00:08:05,460 --> 00:08:07,590
the attacker's strategy, right?

182
00:08:07,590 --> 00:08:10,950
We might use that to put
more controls in place,

183
00:08:10,950 --> 00:08:13,290
maybe deterrent controls,
preventative controls,

184
00:08:13,290 --> 00:08:16,050
detective controls, corrective controls.

185
00:08:16,050 --> 00:08:18,663
We also might use it for
early breach detection.

186
00:08:21,120 --> 00:08:22,890
Honeytokens are like honeypots

187
00:08:22,890 --> 00:08:25,830
as they're designed to
attract our attackers,

188
00:08:25,830 --> 00:08:28,770
but they have the added
benefit of being able

189
00:08:28,770 --> 00:08:32,550
to track and capture
adversarial activities,

190
00:08:32,550 --> 00:08:35,370
identity, and location,

191
00:08:35,370 --> 00:08:38,640
and there are a whole variety
of types of honeytokens.

192
00:08:38,640 --> 00:08:40,800
So think of honeypots as passive,

193
00:08:40,800 --> 00:08:42,630
honeytokens are active

194
00:08:42,630 --> 00:08:46,050
and allow us to really,
really get information

195
00:08:46,050 --> 00:08:49,530
about our adversaries,
who they are potentially,

196
00:08:49,530 --> 00:08:52,860
how they're doing whatever
bad stuff they're doing,

197
00:08:52,860 --> 00:08:54,300
and where they are.

198
00:08:54,300 --> 00:08:56,250
And being able to explain these two,

199
00:08:56,250 --> 00:08:58,893
well, definitely that's
security in action.

200
00:09:00,090 --> 00:09:01,650
That brings us to our word cloud.

201
00:09:01,650 --> 00:09:03,090
Not a lot there,

202
00:09:03,090 --> 00:09:07,080
but make sure that you know
what all of these terms mean.

203
00:09:07,080 --> 00:09:08,980
All right, see you at the next lesson.
