1
00:00:06,540 --> 00:00:08,790
- In this lesson, 21.2,

2
00:00:08,790 --> 00:00:11,403
we're gonna focus in on incident response.

3
00:00:12,330 --> 00:00:15,300
So let's start with an
incident response flowchart.

4
00:00:15,300 --> 00:00:18,630
First thing that happens
is an incident is detected.

5
00:00:18,630 --> 00:00:20,370
Okay, that's great.

6
00:00:20,370 --> 00:00:22,673
The incident is reported, right?

7
00:00:22,673 --> 00:00:25,020
So whatever your detection
system has, it reports it out.

8
00:00:25,020 --> 00:00:28,140
And then the incident is
probably assigned, right?

9
00:00:28,140 --> 00:00:30,420
So there is an assignment made, okay?

10
00:00:30,420 --> 00:00:32,730
You go figure out that incident.

11
00:00:32,730 --> 00:00:37,260
So the incident investigation,
right, gets assigned.

12
00:00:37,260 --> 00:00:38,970
Then the next thing that has to happen,

13
00:00:38,970 --> 00:00:41,820
is validation and prioritization.

14
00:00:41,820 --> 00:00:44,910
Just because an incident
has been reported,

15
00:00:44,910 --> 00:00:48,180
doesn't really mean an incident
has necessarily occurred,

16
00:00:48,180 --> 00:00:50,040
or maybe it has occurred,

17
00:00:50,040 --> 00:00:52,083
but it really doesn't have much impact.

18
00:00:53,085 --> 00:00:55,421
So you wanna validate that
the incident has occurred.

19
00:00:55,421 --> 00:00:57,640
And then if there's more
than one thing happening,

20
00:00:57,640 --> 00:01:00,270
at a time, we wanna
prioritize our response.

21
00:01:00,270 --> 00:01:03,333
So validation and prioritization.

22
00:01:04,290 --> 00:01:07,077
From there, we're gonna
wanna contain it, right?

23
00:01:07,077 --> 00:01:08,370
We're gonna wanna keep it tight,

24
00:01:08,370 --> 00:01:09,870
we're gonna wanna eradicate it,

25
00:01:09,870 --> 00:01:12,510
get rid of whatever's, you
know, causing the incident.

26
00:01:12,510 --> 00:01:14,670
We're gonna wanna recover from it,

27
00:01:14,670 --> 00:01:16,970
and then we're gonna
wanna do lessons learned.

28
00:01:18,226 --> 00:01:19,830
So those are all of the
components of incident response.

29
00:01:19,830 --> 00:01:22,430
So now let's dive a little
deeper into some of them.

30
00:01:23,880 --> 00:01:24,963
Validation.

31
00:01:25,831 --> 00:01:27,450
Validation is really important.

32
00:01:27,450 --> 00:01:29,760
The focus of validation is determined,

33
00:01:29,760 --> 00:01:31,860
whether an incident has actually occurred.

34
00:01:32,754 --> 00:01:35,067
Now you might have, you
know, indicators of attack,

35
00:01:35,067 --> 00:01:36,710
maybe some indicators of compromise,

36
00:01:36,710 --> 00:01:39,178
but they really need to
be understood, right?

37
00:01:39,178 --> 00:01:40,011
So we wanna determine,

38
00:01:40,011 --> 00:01:41,640
whether an incident has
actually occurred, and if so,

39
00:01:41,640 --> 00:01:45,840
the type, the extent, and
the magnitude of the problem.

40
00:01:45,840 --> 00:01:48,570
Remember, an indicator tells
us that something is happening,

41
00:01:48,570 --> 00:01:52,530
or has happened, but even
if an indicator is accurate,

42
00:01:52,530 --> 00:01:56,560
it doesn't necessarily mean
that an incident has occurred.

43
00:01:56,560 --> 00:01:58,200
It could just be a problem.

44
00:01:58,200 --> 00:02:00,510
The following predefined processes,

45
00:02:00,510 --> 00:02:03,715
the incident response
team should work quickly,

46
00:02:03,715 --> 00:02:06,573
to analyze and validate
potential incidents.

47
00:02:08,280 --> 00:02:10,770
Now, prioritization is
the process of determining

48
00:02:10,770 --> 00:02:13,110
the order of importance or urgency,

49
00:02:13,110 --> 00:02:16,020
and it's one of the most
critical decision points,

50
00:02:16,020 --> 00:02:18,870
in the incident handling process.

51
00:02:18,870 --> 00:02:22,380
So we wanna pre-established
incident prioritization,

52
00:02:22,380 --> 00:02:25,053
and escalation guidance as a component,

53
00:02:25,923 --> 00:02:28,080
of our incident response preparation.

54
00:02:28,080 --> 00:02:30,626
There may be some incidents that we say,

55
00:02:30,626 --> 00:02:33,439
we have to respond to
immediately, drop everything.

56
00:02:33,439 --> 00:02:36,836
There's others 30 minutes,
maybe others two hours,

57
00:02:36,836 --> 00:02:40,290
maybe others within a day,
another within 24 hours.

58
00:02:40,290 --> 00:02:42,577
So within a day being a workday,

59
00:02:42,577 --> 00:02:45,000
24 hours could go over to the next day.

60
00:02:45,000 --> 00:02:48,300
But we really want to say, based
on these type of incidents,

61
00:02:48,300 --> 00:02:50,250
right, this is how we're gonna respond.

62
00:02:51,265 --> 00:02:53,629
And then what are those
escalation thresholds,

63
00:02:53,629 --> 00:02:54,750
as well, for those incidents?

64
00:02:54,750 --> 00:02:57,090
So relevant factors include,

65
00:02:57,090 --> 00:02:59,940
what's the functional
impact of the incident?

66
00:02:59,940 --> 00:03:03,300
What is the confidentiality
impact of the incident,

67
00:03:03,300 --> 00:03:06,213
and what's our recovery of the incident?

68
00:03:07,426 --> 00:03:09,818
So it could be that the
longer the incident goes on,

69
00:03:09,818 --> 00:03:11,423
the harder it's gonna
be to recover from it.

70
00:03:12,281 --> 00:03:15,030
Now the escalation process
is initiated at the point

71
00:03:15,030 --> 00:03:17,160
where an incident requires a higher level,

72
00:03:17,160 --> 00:03:19,413
of attention or response.

73
00:03:22,350 --> 00:03:24,400
So now we're focused in on that incident,

74
00:03:25,391 --> 00:03:27,390
and what we wanna really do is contain it.

75
00:03:27,390 --> 00:03:29,940
Containment is a short-term approach,

76
00:03:29,940 --> 00:03:33,780
to limiting or reducing
the impact of an incident.

77
00:03:33,780 --> 00:03:36,727
Now, containment
strategies are gonna vary,

78
00:03:36,727 --> 00:03:38,633
by type of incident, which of course,

79
00:03:38,633 --> 00:03:40,830
should be documented in
your incident playbook.

80
00:03:40,830 --> 00:03:43,530
Relevant stakeholders, like system owners,

81
00:03:43,530 --> 00:03:46,080
should be included in decision making,

82
00:03:46,080 --> 00:03:49,238
and evidence is collected
during containment,

83
00:03:49,238 --> 00:03:52,353
for problem resolution and for
potential legal proceedings.

84
00:03:53,263 --> 00:03:55,211
So if we are going to build a criminal,

85
00:03:55,211 --> 00:03:57,180
or civil case during
this containment phase,

86
00:03:57,180 --> 00:03:58,953
we will be gathering evidence.

87
00:04:01,189 --> 00:04:04,454
The eradication process is
inclusive of all of the steps,

88
00:04:04,454 --> 00:04:07,800
taken to either correct and
or eliminate the root cause,

89
00:04:07,800 --> 00:04:10,140
not just the symptoms, the root cause,

90
00:04:10,140 --> 00:04:11,583
that led to the incident.

91
00:04:13,440 --> 00:04:16,083
Now, a really good practice to get into,

92
00:04:16,083 --> 00:04:18,843
is doing what's known as an
RCA, a root cause analysis.

93
00:04:19,842 --> 00:04:22,470
A root cause analysis is a
method of problem solving,

94
00:04:22,470 --> 00:04:25,950
used to investigate known
problems and identify,

95
00:04:25,950 --> 00:04:29,400
what happened and what's
the underlying cause,

96
00:04:29,400 --> 00:04:32,827
you know, and there's such a tendency,

97
00:04:32,827 --> 00:04:34,777
in instant response to really
look at the symptoms and say,

98
00:04:34,777 --> 00:04:36,600
"okay, I gotta fix those symptoms."

99
00:04:36,600 --> 00:04:37,980
Well, that's good,

100
00:04:37,980 --> 00:04:40,680
but we really always wanna
understand the root cause,

101
00:04:40,680 --> 00:04:43,800
because the main goal of
doing the root cause analysis,

102
00:04:43,800 --> 00:04:46,443
is to prevent the
problem from reoccurring.

103
00:04:47,283 --> 00:04:50,083
And only if we understand the
root cause can we do that.

104
00:04:53,045 --> 00:04:55,440
So looking at the root
cause analysis process,

105
00:04:55,440 --> 00:04:57,810
we start with defining the incident,

106
00:04:57,810 --> 00:05:00,360
gathering data and input,

107
00:05:00,360 --> 00:05:03,810
and then identifying
possible causal factors.

108
00:05:03,810 --> 00:05:06,033
Now, there could be a lot of factors.

109
00:05:06,033 --> 00:05:08,229
So we wanna whiteboard this
and throw them all up there.

110
00:05:08,229 --> 00:05:10,260
It's not just that the
symptoms, we wanna think back,

111
00:05:10,260 --> 00:05:11,970
what could have possibly caused this,

112
00:05:11,970 --> 00:05:13,713
what are the possible factors?

113
00:05:15,000 --> 00:05:17,610
And we'll go through looking
at those possible factors,

114
00:05:17,610 --> 00:05:18,990
over and over again, and we might even go

115
00:05:18,990 --> 00:05:20,460
through a process called the five why's,

116
00:05:20,460 --> 00:05:22,590
where you ask the question why five times,

117
00:05:22,590 --> 00:05:24,840
each time you come up with a new answer.

118
00:05:24,840 --> 00:05:28,800
But ultimately we should
be answering the question,

119
00:05:28,800 --> 00:05:30,990
what was the root cause?

120
00:05:30,990 --> 00:05:31,950
Identifying the root cause.

121
00:05:31,950 --> 00:05:33,840
Once we know the root cause,

122
00:05:33,840 --> 00:05:36,810
then we can look to find solutions.

123
00:05:36,810 --> 00:05:38,703
And once we've found solutions,

124
00:05:39,603 --> 00:05:41,295
we can implement the solutions.

125
00:05:41,295 --> 00:05:43,410
So we're defining the incident,
gathering data and input,

126
00:05:43,410 --> 00:05:47,015
identifying the possible
factors, you know,

127
00:05:47,015 --> 00:05:48,390
coming up with what the root causes are,

128
00:05:48,390 --> 00:05:51,390
finding the solutions
based on those root causes,

129
00:05:51,390 --> 00:05:53,523
and then implementing those solutions.

130
00:05:55,410 --> 00:05:59,430
Now recovery is the process of
restoring normal operations,

131
00:05:59,430 --> 00:06:00,990
confirming that all of our systems,

132
00:06:00,990 --> 00:06:03,240
are back functioning properly again.

133
00:06:03,240 --> 00:06:04,860
And if applicable,

134
00:06:04,860 --> 00:06:07,743
remediating any associated
vulnerabilities.

135
00:06:09,674 --> 00:06:11,430
The recovery activities
can include things like,

136
00:06:11,430 --> 00:06:13,740
restoring and or rebuilding systems,

137
00:06:13,740 --> 00:06:16,980
replacing compromised
files with a clean version,

138
00:06:16,980 --> 00:06:19,710
installing patches, changing passwords,

139
00:06:19,710 --> 00:06:21,891
and tightening, you know,

140
00:06:21,891 --> 00:06:24,630
network perimeter security
or hardening our systems.

141
00:06:24,630 --> 00:06:27,300
That implementing enhanced monitoring,

142
00:06:27,300 --> 00:06:29,883
is often a part of the
recovery process, right?

143
00:06:30,835 --> 00:06:34,183
Once a resource is successfully
attacked, you know,

144
00:06:34,183 --> 00:06:37,068
it's not that unusual to
have it attacked again.

145
00:06:37,068 --> 00:06:39,870
So having that resource attacked
again, or another resource

146
00:06:39,870 --> 00:06:43,413
within the organization being
attacked in a similar manner.

147
00:06:44,320 --> 00:06:46,294
So we really wanted to up our game,

148
00:06:46,294 --> 00:06:47,744
and have enhanced monitoring.

149
00:06:49,140 --> 00:06:52,903
And then at the end of
this process, we wanna say,

150
00:06:52,903 --> 00:06:54,567
what can we learn from this?

151
00:06:54,567 --> 00:06:56,204
What are our lessons learned?

152
00:06:56,204 --> 00:06:58,290
So post-incident lessons
learned should be evaluated,

153
00:06:58,290 --> 00:07:03,290
and integrated into organizational
processes and controls.

154
00:07:03,330 --> 00:07:05,980
So what's part of our lesson learned?

155
00:07:05,980 --> 00:07:07,620
Well, we wanna say exactly what happened,

156
00:07:07,620 --> 00:07:09,870
and really when did it happen?

157
00:07:09,870 --> 00:07:12,540
How well did we respond to this incident?

158
00:07:12,540 --> 00:07:14,070
What would we do different,

159
00:07:14,070 --> 00:07:17,220
next time a similar incident occurred?

160
00:07:17,220 --> 00:07:20,940
What actions can prevent
similar incidents in the future?

161
00:07:20,940 --> 00:07:24,526
What precursors or indicators
should be watched for,

162
00:07:24,526 --> 00:07:26,676
in the future to detect
a similar incident?

163
00:07:27,639 --> 00:07:29,172
And what additional tools,

164
00:07:29,172 --> 00:07:32,100
or resources are needed
to detect, analyze,

165
00:07:32,100 --> 00:07:34,350
or mitigate future incidents?

166
00:07:34,350 --> 00:07:38,130
So the whole goal of lessons
learned is improvement.

167
00:07:38,130 --> 00:07:40,020
It's never to assign blame,

168
00:07:40,020 --> 00:07:42,303
it's always organizational improvement.

169
00:07:43,560 --> 00:07:46,890
And now my friends, brings us
to a three second challenge.

170
00:07:46,890 --> 00:07:48,990
Five challenge questions,
three seconds each.

171
00:07:48,990 --> 00:07:50,390
Oh, you know how to do this.

172
00:07:51,360 --> 00:07:55,260
Incident response process
that focuses on improvement.

173
00:07:55,260 --> 00:07:56,910
It's the one we just talked about.

174
00:07:56,910 --> 00:07:58,800
1, 2, 3,

175
00:07:58,800 --> 00:07:59,703
lessons learned.

176
00:08:00,660 --> 00:08:03,305
Number two, incident response process,

177
00:08:03,305 --> 00:08:06,030
that focuses on eliminating the threat.

178
00:08:06,030 --> 00:08:07,743
1, 2, 3,

179
00:08:08,670 --> 00:08:10,263
that is eradication.

180
00:08:11,580 --> 00:08:12,450
Number three,

181
00:08:12,450 --> 00:08:16,263
incident response process that
focuses on minimizing damage.

182
00:08:17,190 --> 00:08:18,663
1, 2, 3,

183
00:08:19,650 --> 00:08:21,423
it's gonna be containment.

184
00:08:22,320 --> 00:08:23,373
Number four,

185
00:08:24,300 --> 00:08:28,413
problem solving method used
to identify underlying causes.

186
00:08:29,400 --> 00:08:30,663
1, 2, 3,

187
00:08:32,260 --> 00:08:34,653
it's gonna be a root
cause analysis or an RCA.

188
00:08:36,216 --> 00:08:37,049
Lastly, number five,

189
00:08:37,049 --> 00:08:40,682
the point at which an incident
requires a higher level,

190
00:08:40,682 --> 00:08:41,932
of attention or response.

191
00:08:42,780 --> 00:08:44,733
1, 2, 3,

192
00:08:46,313 --> 00:08:48,185
it's your escalation threshold,

193
00:08:48,185 --> 00:08:50,280
or just escalation
would work as an answer.

194
00:08:50,280 --> 00:08:53,157
All right, let's do a security and action.

195
00:08:53,157 --> 00:08:55,950
And this is about incident
response activity.

196
00:08:55,950 --> 00:08:58,983
The help desk receives
three calls right in a row,

197
00:08:59,916 --> 00:09:01,620
from users on the same
floor of a building,

198
00:09:01,620 --> 00:09:03,270
who state that they're having problems,

199
00:09:03,270 --> 00:09:05,580
with their wireless access.

200
00:09:05,580 --> 00:09:08,550
The network admin goes to
the floor and picks up,

201
00:09:08,550 --> 00:09:13,020
an unauthorized WAP, wireless
access point, signal.

202
00:09:13,020 --> 00:09:16,680
You're being kept
apprised of the situation.

203
00:09:16,680 --> 00:09:18,270
So here's what I want you to tell me.

204
00:09:18,270 --> 00:09:21,554
What incident response phase is currently

205
00:09:21,554 --> 00:09:24,180
in process and what should happen next?

206
00:09:24,180 --> 00:09:26,370
So the help desk gets three
calls, boom, boom, boom,

207
00:09:26,370 --> 00:09:29,022
right in a row, right?

208
00:09:29,022 --> 00:09:31,025
So three calls right in a row from users.

209
00:09:31,025 --> 00:09:31,950
They're on the same floor of the building,

210
00:09:31,950 --> 00:09:34,957
and they're having real
problems, you know,

211
00:09:34,957 --> 00:09:36,690
with their wireless access,
perhaps they get, you know,

212
00:09:36,690 --> 00:09:39,660
they're being, you know,
taken off, de-authenticated.

213
00:09:39,660 --> 00:09:42,690
So your network admin goes
up to the floor, you know,

214
00:09:42,690 --> 00:09:44,400
doing some investigation,

215
00:09:44,400 --> 00:09:49,290
picks up an unauthorized WAP
signal, maybe an evil twin.

216
00:09:49,290 --> 00:09:51,600
You're being apprised of the situation.

217
00:09:51,600 --> 00:09:53,610
So what I wanna know from you is,

218
00:09:53,610 --> 00:09:57,630
what incident response phase
is currently in process,

219
00:09:57,630 --> 00:09:59,400
and then what should happen next.

220
00:09:59,400 --> 00:10:02,253
So definitely put me on
pause, write down some notes.

221
00:10:05,190 --> 00:10:07,500
So let's talk about the IR phases.

222
00:10:07,500 --> 00:10:10,920
The response is currently
in the validation phase,

223
00:10:10,920 --> 00:10:15,840
the expected actions are
confirmation and prioritization.

224
00:10:15,840 --> 00:10:19,290
So we need to validate that
having that unauthorized

225
00:10:19,290 --> 00:10:23,061
access point is really what
was causing the problems.

226
00:10:23,061 --> 00:10:25,529
Now having an unauthorized
access point might be a problem,

227
00:10:25,529 --> 00:10:28,770
in and of its own, but just
because we have a symptom,

228
00:10:28,770 --> 00:10:30,060
right, or something happening,

229
00:10:30,060 --> 00:10:32,910
doesn't mean it was necessarily
the cause of the problem.

230
00:10:33,810 --> 00:10:36,060
Now, if an incident is detected,

231
00:10:36,060 --> 00:10:39,153
the next stage is containment, right?

232
00:10:39,153 --> 00:10:41,910
Now, in this case the WAP would
need to be physically found,

233
00:10:41,910 --> 00:10:44,430
and disabled, 'cause all he's
found so far is the signal,

234
00:10:44,430 --> 00:10:48,723
he has to go find the that WAP
and disable our de-power it.

235
00:10:50,277 --> 00:10:52,577
Now, after that, so we
had containment, right?

236
00:10:53,429 --> 00:10:55,696
'Cause we are now in the,
we already had detection.

237
00:10:55,696 --> 00:10:58,002
That was what our users did, right?

238
00:10:58,002 --> 00:11:02,610
We have this validation going
on by the IT guy, right?

239
00:11:02,610 --> 00:11:05,490
If the incident is declared
our next stage containment,

240
00:11:05,490 --> 00:11:09,369
and then after that we
would do eradication, right?

241
00:11:09,369 --> 00:11:12,000
Eradication being the removal
of the wireless access point,

242
00:11:12,000 --> 00:11:15,090
reconfiguration of impacted systems,

243
00:11:15,090 --> 00:11:16,680
and also figuring out,

244
00:11:16,680 --> 00:11:19,740
how the unauthorized device was installed.

245
00:11:19,740 --> 00:11:21,003
That's a root cause.

246
00:11:22,470 --> 00:11:25,110
Now recovery would be
ensuring that all users

247
00:11:25,110 --> 00:11:27,513
can properly connect to
the wireless network.

248
00:11:28,561 --> 00:11:30,720
And lastly, lessons learned
would include your findings,

249
00:11:30,720 --> 00:11:33,033
and post-incident recommendations.

250
00:11:34,524 --> 00:11:36,810
So being able to go through
all of these phases,

251
00:11:36,810 --> 00:11:38,136
you don't ever wanna skip a phase.

252
00:11:38,136 --> 00:11:39,870
You always wanna make sure
that you are validating,

253
00:11:39,870 --> 00:11:44,160
and you never wanna mistake
a symptom for a root cause.

254
00:11:44,160 --> 00:11:46,910
Doing all that, my friends,
that's security and action.

255
00:11:47,820 --> 00:11:50,838
There is your word cloud.

256
00:11:50,838 --> 00:11:52,585
Make sure that you know what happens,

257
00:11:52,585 --> 00:11:55,260
in all of these different
phases and that you can speak

258
00:11:55,260 --> 00:11:58,560
to every term and concept
that is on this word cloud.

259
00:11:58,560 --> 00:12:00,330
When you're ready, head on
over to the next lesson.

260
00:12:00,330 --> 00:12:01,830
I'll be waiting for you there.
