1
00:00:06,570 --> 00:00:07,800
- Welcome to Lesson 7,

2
00:00:07,800 --> 00:00:10,470
Explain Various Types of Vulnerabilities.

3
00:00:10,470 --> 00:00:12,450
In Lesson 7.1, we're gonna start off

4
00:00:12,450 --> 00:00:14,040
with a Vulnerability Primer,

5
00:00:14,040 --> 00:00:15,450
really just getting an understanding

6
00:00:15,450 --> 00:00:17,250
of what a vulnerability is,

7
00:00:17,250 --> 00:00:18,960
and how we manage vulnerabilities.

8
00:00:18,960 --> 00:00:20,280
And then in the next lesson,

9
00:00:20,280 --> 00:00:24,180
we'll dive deeper into specific
types of vulnerabilities.

10
00:00:24,180 --> 00:00:26,940
A vulnerability, which I know
we've defined multiple times,

11
00:00:26,940 --> 00:00:29,790
but we're gonna do it one more
time, is a weakness, right?

12
00:00:29,790 --> 00:00:32,157
It's a weakness in hardware, and software,

13
00:00:32,157 --> 00:00:35,550
and people or processes
can also be a a weakness

14
00:00:35,550 --> 00:00:37,150
in infrastructure or a building.

15
00:00:38,310 --> 00:00:40,890
Now, vulnerability in and of itself

16
00:00:40,890 --> 00:00:43,110
doesn't pose the imminent danger.

17
00:00:43,110 --> 00:00:45,210
Rather, the fact that the vulnerability

18
00:00:45,210 --> 00:00:47,250
is the gateway to an exploit.

19
00:00:47,250 --> 00:00:50,850
The fact that we have a
vulnerability is the gateway

20
00:00:50,850 --> 00:00:54,153
for our threat actor to exploit us.

21
00:00:56,355 --> 00:00:58,240
Now, there are different
types of vulnerabilities,

22
00:00:58,240 --> 00:00:59,073
there are network vulnerabilities,

23
00:00:59,073 --> 00:01:01,860
operating system vulnerabilities,
process vulnerabilities,

24
00:01:01,860 --> 00:01:04,500
and people-oriented vulnerabilities.

25
00:01:04,500 --> 00:01:06,330
Network vulnerabilities are weaknesses

26
00:01:06,330 --> 00:01:10,530
within organization's hardware
or software infrastructure.

27
00:01:10,530 --> 00:01:12,840
Operating system vulnerabilities
are code weaknesses,

28
00:01:12,840 --> 00:01:16,050
sometimes we refer to them as
bugs which can be exploited,

29
00:01:16,050 --> 00:01:19,830
and, or could be operating
system misconfigurations.

30
00:01:19,830 --> 00:01:21,420
Process vulnerabilities occur

31
00:01:21,420 --> 00:01:23,310
when there is a security exposure

32
00:01:23,310 --> 00:01:25,353
within a particular process.

33
00:01:26,460 --> 00:01:29,880
And human vulnerabilities are
the result of human error,

34
00:01:29,880 --> 00:01:33,510
inattention, unintentional,
or accidental actions,

35
00:01:33,510 --> 00:01:35,550
or from an organization's perspective,

36
00:01:35,550 --> 00:01:38,220
it could be the result
of inadequate vetting,

37
00:01:38,220 --> 00:01:40,053
training, and oversight.

38
00:01:43,050 --> 00:01:45,540
Now, we need to know
about vulnerabilities,

39
00:01:45,540 --> 00:01:49,800
and we trust the organizations
that we do business with

40
00:01:49,800 --> 00:01:52,140
that they will in fact let us know

41
00:01:52,140 --> 00:01:54,000
when the hardware, or the software,

42
00:01:54,000 --> 00:01:57,570
or device we're using has vulnerabilities.

43
00:01:57,570 --> 00:01:59,790
And the process of
disclosing vulnerabilities

44
00:01:59,790 --> 00:02:02,190
is referred to as ethical disclosure.

45
00:02:02,190 --> 00:02:05,100
Ethical disclosure is a practice
of publishing information

46
00:02:05,100 --> 00:02:08,310
related to a vulnerability or a finding.

47
00:02:08,310 --> 00:02:11,280
Now, the purpose of
vulnerability disclosure

48
00:02:11,280 --> 00:02:13,530
is to inform others of potential risks,

49
00:02:13,530 --> 00:02:15,900
so that they can make informed decisions,

50
00:02:15,900 --> 00:02:17,670
and take appropriate action,

51
00:02:17,670 --> 00:02:19,980
and there's really two different ways

52
00:02:19,980 --> 00:02:21,990
to approach ethical disclosure,

53
00:02:21,990 --> 00:02:25,350
full disclosure and
responsible disclosure.

54
00:02:25,350 --> 00:02:27,960
Full disclosure is
making all details public

55
00:02:27,960 --> 00:02:31,200
without regard to harm that
may be caused to others,

56
00:02:31,200 --> 00:02:33,690
including exploited by adversaries,

57
00:02:33,690 --> 00:02:35,490
where responsible disclosure

58
00:02:35,490 --> 00:02:38,430
is making just enough information known

59
00:02:38,430 --> 00:02:40,650
so informed decisions can be made

60
00:02:40,650 --> 00:02:42,450
while not releasing details

61
00:02:42,450 --> 00:02:45,150
that could be useful to an adversary.

62
00:02:45,150 --> 00:02:47,130
But there's really a fine
line between the two,

63
00:02:47,130 --> 00:02:49,560
because when you're doing
responsible disclosure,

64
00:02:49,560 --> 00:02:50,460
which at first sounds like,

65
00:02:50,460 --> 00:02:52,320
well, that must be the way to go,

66
00:02:52,320 --> 00:02:55,140
what if you aren't
releasing all the details

67
00:02:55,140 --> 00:02:57,120
or enough details I should say.

68
00:02:57,120 --> 00:02:58,470
Enough details so that someone

69
00:02:58,470 --> 00:03:00,390
really can make a good decision.

70
00:03:00,390 --> 00:03:02,010
So fine line,

71
00:03:02,010 --> 00:03:04,020
a lot of discussion in the industry

72
00:03:04,020 --> 00:03:07,263
about full disclosure versus
responsible disclosure.

73
00:03:08,880 --> 00:03:10,350
Now, vulnerability management

74
00:03:10,350 --> 00:03:12,630
is the process of
identifying vulnerabilities,

75
00:03:12,630 --> 00:03:14,220
assessing vulnerabilities,

76
00:03:14,220 --> 00:03:17,430
reporting non-vulnerabilities,
prioritizing vulnerabilities,

77
00:03:17,430 --> 00:03:20,670
and then ultimately
mitigating vulnerabilities.

78
00:03:20,670 --> 00:03:22,680
The goal of vulnerability management

79
00:03:22,680 --> 00:03:25,260
is to reduce the risk of
our security breaches,

80
00:03:25,260 --> 00:03:28,620
and minimize the potential
impact of any vulnerabilities

81
00:03:28,620 --> 00:03:30,240
that have been identified.

82
00:03:30,240 --> 00:03:33,570
The vulnerability management
is not a set and forget,

83
00:03:33,570 --> 00:03:36,270
it is absolutely an ongoing process

84
00:03:36,270 --> 00:03:38,850
that requires continuous monitoring

85
00:03:38,850 --> 00:03:42,390
and updating as new
vulnerabilities are discovered

86
00:03:42,390 --> 00:03:44,280
or new threats emerge.

87
00:03:44,280 --> 00:03:46,230
And those are both happening all the time.

88
00:03:46,230 --> 00:03:48,870
New vulnerabilities are
continually being discovered,

89
00:03:48,870 --> 00:03:51,933
and new threats or potential
dangers are emerging.

90
00:03:54,540 --> 00:03:56,640
Now, there is a particular
type of vulnerability

91
00:03:56,640 --> 00:03:57,690
that we need to be aware of

92
00:03:57,690 --> 00:04:00,210
known as a zero-day vulnerability.

93
00:04:00,210 --> 00:04:02,460
A zero-day vulnerability is a flaw

94
00:04:02,460 --> 00:04:06,750
in hardware or software
that's been discovered,

95
00:04:06,750 --> 00:04:09,483
but a fix is not yet available.

96
00:04:10,560 --> 00:04:12,870
Now, a zero-day exploit is a method

97
00:04:12,870 --> 00:04:15,510
that really weaponizes that
discovered vulnerability.

98
00:04:15,510 --> 00:04:16,380
And very often,

99
00:04:16,380 --> 00:04:19,080
that vulnerability is
not gonna be discovered

100
00:04:19,080 --> 00:04:20,190
by the good guys,

101
00:04:20,190 --> 00:04:22,170
it has been discovered by the bad guys,

102
00:04:22,170 --> 00:04:25,170
and we don't even know that
that vulnerability is out there,

103
00:04:25,170 --> 00:04:27,840
but they can develop their exploits.

104
00:04:27,840 --> 00:04:29,850
So the term zero-day really implies

105
00:04:29,850 --> 00:04:32,610
that there's no time between
when the vulnerability

106
00:04:32,610 --> 00:04:33,750
is known to developers,

107
00:04:33,750 --> 00:04:35,700
and when it's exploited
by the adversaries,

108
00:04:35,700 --> 00:04:38,370
because it's probably
already being exploited.

109
00:04:38,370 --> 00:04:41,010
The time from when an
exploit first becomes active

110
00:04:41,010 --> 00:04:43,110
to when the number of
vulnerable systems shrink

111
00:04:43,110 --> 00:04:44,760
to a really insignificant number

112
00:04:44,760 --> 00:04:47,220
is known as the Window of Vulnerability.

113
00:04:47,220 --> 00:04:48,630
Now, what would make that shrink?

114
00:04:48,630 --> 00:04:50,670
Well, it would be once our developer

115
00:04:50,670 --> 00:04:53,670
or manufacturer can release a patch,

116
00:04:53,670 --> 00:04:56,670
but zero-day vulnerabilities
are very, very dangerous.

117
00:04:56,670 --> 00:04:59,520
And oftentimes while we're waiting

118
00:04:59,520 --> 00:05:02,460
for a patch to be released,

119
00:05:02,460 --> 00:05:04,740
we have to make some
really serious decisions,

120
00:05:04,740 --> 00:05:06,540
like shutting the system down,

121
00:05:06,540 --> 00:05:10,560
or what other compensating
controls we can put in place.

122
00:05:10,560 --> 00:05:14,460
So let's look at a timeline
for a zero-day vulnerability.

123
00:05:14,460 --> 00:05:17,220
The weakness or the
vulnerability is discovered.

124
00:05:17,220 --> 00:05:18,180
More often than not,

125
00:05:18,180 --> 00:05:20,490
it's gonna be discovered
by our adversaries.

126
00:05:20,490 --> 00:05:23,940
Now, it could be discovered
by a security researcher,

127
00:05:23,940 --> 00:05:27,480
or maybe a part of a, you
know, a bug bounty program.

128
00:05:27,480 --> 00:05:30,510
But generally speaking,
it's really our adversaries

129
00:05:30,510 --> 00:05:32,360
who are discovering these weaknesses.

130
00:05:34,110 --> 00:05:37,620
The adversary or the attacker
will create the exploit code.

131
00:05:37,620 --> 00:05:40,140
We still don't know that it's happening.

132
00:05:40,140 --> 00:05:42,300
The exploit code becomes available.

133
00:05:42,300 --> 00:05:45,210
So it may be that the attacker sells it,

134
00:05:45,210 --> 00:05:48,060
or maybe puts it out there in the dark web

135
00:05:48,060 --> 00:05:51,123
or decides to use it themselves.

136
00:05:53,220 --> 00:05:55,380
And then they've been exploiting us.

137
00:05:55,380 --> 00:05:58,200
So now that exploit,
it's in the wild, right?

138
00:05:58,200 --> 00:06:00,900
It's out there happening,
is identified, right?

139
00:06:00,900 --> 00:06:02,460
We know that we're being attacked,

140
00:06:02,460 --> 00:06:04,863
and so that exploit is identified,

141
00:06:05,760 --> 00:06:07,920
but there's still no fix available.

142
00:06:07,920 --> 00:06:09,150
So that's when we're going to have

143
00:06:09,150 --> 00:06:10,830
to make some tough decisions

144
00:06:10,830 --> 00:06:12,840
about do we keep our system active?

145
00:06:12,840 --> 00:06:14,700
Should we shut it down, right?

146
00:06:14,700 --> 00:06:16,560
Or are there compensating controls

147
00:06:16,560 --> 00:06:18,000
generally in a temporary basis

148
00:06:18,000 --> 00:06:21,810
that we can implement to
help protect our systems?

149
00:06:21,810 --> 00:06:23,160
And then ultimately,

150
00:06:23,160 --> 00:06:26,280
the developer will
release a patch or a fix,

151
00:06:26,280 --> 00:06:28,560
or the manufacturer
release a patch or fix,

152
00:06:28,560 --> 00:06:31,440
and we can then repair our system,

153
00:06:31,440 --> 00:06:35,223
so that we are no longer
vulnerable to that zero-day attack.

154
00:06:37,260 --> 00:06:39,600
And that, my friends, brings
us to a 3-Second Challenge.

155
00:06:39,600 --> 00:06:40,433
You know how to do it.

156
00:06:40,433 --> 00:06:43,173
Five questions, three
seconds each, let's do it.

157
00:06:44,610 --> 00:06:48,120
A weakness in a hardware,
software, people or processes.

158
00:06:48,120 --> 00:06:49,863
One, two, three.

159
00:06:50,850 --> 00:06:53,220
That is a vulnerability.

160
00:06:53,220 --> 00:06:55,500
Number two, an exploit that's know,

161
00:06:55,500 --> 00:06:57,990
but does not yet have a fix.

162
00:06:57,990 --> 00:07:00,420
One, two, three.

163
00:07:00,420 --> 00:07:02,850
That's gonna be our zero-day.

164
00:07:02,850 --> 00:07:04,170
Number three,

165
00:07:04,170 --> 00:07:06,990
the time from when an
exploit first becomes active

166
00:07:06,990 --> 00:07:09,330
to when the number of
vulnerable systems shrink

167
00:07:09,330 --> 00:07:10,863
to an insignificant number.

168
00:07:12,300 --> 00:07:14,820
One, two, three.

169
00:07:14,820 --> 00:07:17,043
that's gonna be the
Window of Vulnerability.

170
00:07:18,630 --> 00:07:21,390
Number four, the practice
of publishing information

171
00:07:21,390 --> 00:07:24,033
related to a vulnerability
to assist others.

172
00:07:25,350 --> 00:07:27,570
One, two, three.

173
00:07:27,570 --> 00:07:29,790
That is ethical disclosure.

174
00:07:29,790 --> 00:07:31,530
And lastly, number five,

175
00:07:31,530 --> 00:07:34,383
the process of taking
advantage of a vulnerability.

176
00:07:35,280 --> 00:07:36,990
That's known as a?

177
00:07:36,990 --> 00:07:38,910
One, two, three.

178
00:07:38,910 --> 00:07:41,313
That's exploitation or an exploit.

179
00:07:42,660 --> 00:07:43,800
Let's do a Security-in-Action

180
00:07:43,800 --> 00:07:44,940
so you can apply your knowledge

181
00:07:44,940 --> 00:07:47,280
about a zero-day vulnerability.

182
00:07:47,280 --> 00:07:48,960
Your organization has just learned

183
00:07:48,960 --> 00:07:52,650
that one of your applications
has a zero-day vulnerability.

184
00:07:52,650 --> 00:07:54,720
A patch is not yet available,

185
00:07:54,720 --> 00:07:57,333
and publication day is
still to be determined.

186
00:07:58,260 --> 00:08:00,030
So here's the question for you.

187
00:08:00,030 --> 00:08:03,030
In the meantime, are there
any steps you can take

188
00:08:03,030 --> 00:08:05,703
to mitigate the impact
of the vulnerability?

189
00:08:06,540 --> 00:08:09,510
So there's a zero-day
vulnerability, it impacts you.

190
00:08:09,510 --> 00:08:11,430
We assume it's probably pretty serious.

191
00:08:11,430 --> 00:08:13,170
A patch isn't available yet,

192
00:08:13,170 --> 00:08:15,360
and we don't know when a patch is coming.

193
00:08:15,360 --> 00:08:17,940
So anything we can do
to mitigate the impact

194
00:08:17,940 --> 00:08:19,140
of that vulnerability.

195
00:08:19,140 --> 00:08:21,420
Go ahead and put me on
pause, jot down some notes,

196
00:08:21,420 --> 00:08:24,053
and then come back, and we'll
do the response together.

197
00:08:25,770 --> 00:08:26,940
First thing we wanna do

198
00:08:26,940 --> 00:08:28,680
is we wanna notify relevant stakeholders.

199
00:08:28,680 --> 00:08:30,900
So anybody who's potentially
impacted by this,

200
00:08:30,900 --> 00:08:32,343
we wanna put them on notice.

201
00:08:33,840 --> 00:08:37,080
Then we wanna determine the
severity of the vulnerability,

202
00:08:37,080 --> 00:08:39,330
and we're gonna prioritize our response

203
00:08:39,330 --> 00:08:42,030
based on the risk and
the potential damage.

204
00:08:42,030 --> 00:08:45,420
It may be really, really
significant, it may not be,

205
00:08:45,420 --> 00:08:48,663
but we need to really do our
analysis to determine that.

206
00:08:49,710 --> 00:08:52,200
And then we can implement
temporary measures

207
00:08:52,200 --> 00:08:54,030
to mitigate the vulnerabilities.

208
00:08:54,030 --> 00:08:54,863
So for example,

209
00:08:54,863 --> 00:08:58,200
we may decide to isolate the
affected system or service,

210
00:08:58,200 --> 00:09:01,440
maybe disable any unnecessary
features or services,

211
00:09:01,440 --> 00:09:05,403
or we might wanna implement
temporary compensating controls.

212
00:09:07,440 --> 00:09:10,440
And then up until the
time we get that patch,

213
00:09:10,440 --> 00:09:13,740
we're gonna continuously,
really laser-focused,

214
00:09:13,740 --> 00:09:16,950
monitor the system for
any suspicious activity

215
00:09:16,950 --> 00:09:18,540
that could indicate an attack

216
00:09:18,540 --> 00:09:21,720
or exploitation of the vulnerability.

217
00:09:21,720 --> 00:09:24,723
Doing that, my friends,
is Security-in-Action.

218
00:09:25,980 --> 00:09:27,660
There's your word cloud,
there's a lot there,

219
00:09:27,660 --> 00:09:29,190
make sure that you can really speak

220
00:09:29,190 --> 00:09:31,710
to all of these terms before you go on.

221
00:09:31,710 --> 00:09:33,420
If you're struggling with
any of them, go back,

222
00:09:33,420 --> 00:09:34,980
they're all in the lesson.

223
00:09:34,980 --> 00:09:37,380
When you're ready, I'll
see you the next lesson.
