1
00:00:06,510 --> 00:00:10,290
- In 8.3, we're gonna focus
in on brute force attacks.

2
00:00:10,290 --> 00:00:14,370
And we'll start by describing
what is a brute force attack.

3
00:00:14,370 --> 00:00:16,410
A brute force approach to a problem

4
00:00:16,410 --> 00:00:18,900
leverages those qualities
of being a brute,

5
00:00:18,900 --> 00:00:20,610
kinda strength and power,

6
00:00:20,610 --> 00:00:22,800
while being bound by its limitations

7
00:00:22,800 --> 00:00:24,870
of resource and discovery.

8
00:00:24,870 --> 00:00:26,760
Now an advantage of brute force

9
00:00:26,760 --> 00:00:28,950
is that it's generally
simple to implement.

10
00:00:28,950 --> 00:00:30,030
Now an advantage, obviously,

11
00:00:30,030 --> 00:00:31,410
from an adversary's perspective,

12
00:00:31,410 --> 00:00:32,250
not ours.

13
00:00:32,250 --> 00:00:36,630
And if unimpeded will eventually succeed.

14
00:00:36,630 --> 00:00:37,463
Now work factor...

15
00:00:37,463 --> 00:00:38,580
That term's gonna come up again.

16
00:00:38,580 --> 00:00:41,280
Work factor is the estimate
of the time, effort,

17
00:00:41,280 --> 00:00:45,183
and resources needed by
an adversary to succeed.

18
00:00:46,800 --> 00:00:48,750
A cyber brute force attack

19
00:00:48,750 --> 00:00:51,330
is just this incredibly
exhaustive approach

20
00:00:51,330 --> 00:00:53,790
to performing an attack against a system,

21
00:00:53,790 --> 00:00:55,590
a service, or a dataset.

22
00:00:55,590 --> 00:00:58,290
Just doing it again and
again and again, right?

23
00:00:58,290 --> 00:00:59,643
It's brute force.

24
00:01:01,890 --> 00:01:03,450
Now a cyber brute force attack,

25
00:01:03,450 --> 00:01:05,280
it's almost always going to be automated

26
00:01:05,280 --> 00:01:08,370
and it's performed via a
script or an executable

27
00:01:08,370 --> 00:01:10,740
that performs a fairly simple operation

28
00:01:10,740 --> 00:01:14,010
or sequence of operations
on a repeating loop.

29
00:01:14,010 --> 00:01:16,650
Now, the attacks can be
performed live online

30
00:01:16,650 --> 00:01:19,320
or offline against an acquired dataset.

31
00:01:19,320 --> 00:01:22,320
And cyber brute force
attacks generally require

32
00:01:22,320 --> 00:01:24,240
a significant amount of time

33
00:01:24,240 --> 00:01:26,700
'cause we're doing it over
and over and over again,

34
00:01:26,700 --> 00:01:28,593
and computing resources.

35
00:01:30,420 --> 00:01:33,330
So let's look at a couple
of brute force approaches.

36
00:01:33,330 --> 00:01:35,490
One approach is known as conduct.

37
00:01:35,490 --> 00:01:37,740
In the conduct brute force approach,

38
00:01:37,740 --> 00:01:39,930
the payload of the attack itself

39
00:01:39,930 --> 00:01:42,660
is the conduct of the attack, right?

40
00:01:42,660 --> 00:01:45,960
So example would be a denial
of service attack, right?

41
00:01:45,960 --> 00:01:49,830
Actually doing the brute
force in and of itself, right?

42
00:01:49,830 --> 00:01:51,840
Requesting access, requesting access,

43
00:01:51,840 --> 00:01:54,360
requesting access, requesting access.

44
00:01:54,360 --> 00:01:56,310
That in and of itself, right?

45
00:01:56,310 --> 00:01:57,513
Is the attack.

46
00:01:58,710 --> 00:02:00,480
The other is discovery,

47
00:02:00,480 --> 00:02:02,520
and that's where the payload of the attack

48
00:02:02,520 --> 00:02:04,770
is used to discover a hidden secret.

49
00:02:04,770 --> 00:02:07,770
So for example, trying
to discover a password.

50
00:02:07,770 --> 00:02:09,690
Try an option one, try an option two

51
00:02:09,690 --> 00:02:11,640
try an option three, try an option four

52
00:02:11,640 --> 00:02:15,210
try an option five until
you get the answer.

53
00:02:15,210 --> 00:02:16,770
So it could either be conduct.

54
00:02:16,770 --> 00:02:18,240
Meaning, the payload of the attack

55
00:02:18,240 --> 00:02:20,580
is the conduct of the attack itself

56
00:02:20,580 --> 00:02:22,770
or discovery where the
payload of the attack

57
00:02:22,770 --> 00:02:25,083
is used to discover a hidden secret.

58
00:02:27,390 --> 00:02:29,970
So let's look at that second
one a little bit more closely.

59
00:02:29,970 --> 00:02:32,220
The common types of
these discovery attacks

60
00:02:32,220 --> 00:02:34,350
where we're trying to get a secret, right?

61
00:02:34,350 --> 00:02:36,420
We're trying to discover something.

62
00:02:36,420 --> 00:02:41,420
There are basic, dictionary,
informed, and rainbow table.

63
00:02:41,460 --> 00:02:43,530
In a basic, we're just really attempting

64
00:02:43,530 --> 00:02:44,670
every single solution,

65
00:02:44,670 --> 00:02:46,830
trying everything we can do to discover

66
00:02:46,830 --> 00:02:48,990
whatever the secret is.

67
00:02:48,990 --> 00:02:50,580
In a dictionary attack,

68
00:02:50,580 --> 00:02:55,580
the adversary will use a finite
reference list or dataset.

69
00:02:55,650 --> 00:02:57,570
Maybe it's a common password list

70
00:02:57,570 --> 00:03:00,690
because they're looking
to discover a password.

71
00:03:00,690 --> 00:03:02,430
So the most common passwords

72
00:03:02,430 --> 00:03:05,550
or the most common words ever
used in a password, right?

73
00:03:05,550 --> 00:03:08,070
It's going to be a finite reference.

74
00:03:08,070 --> 00:03:10,980
Where in a basic, we're not
narrowing it down like that

75
00:03:10,980 --> 00:03:13,020
or the adversary isn't
narrowing it down like that.

76
00:03:13,020 --> 00:03:13,860
Just trying everything,

77
00:03:13,860 --> 00:03:14,693
trying everything,

78
00:03:14,693 --> 00:03:15,526
trying everything.

79
00:03:16,830 --> 00:03:21,360
An informed attack uses a
known good reference list

80
00:03:21,360 --> 00:03:22,830
or dataset.

81
00:03:22,830 --> 00:03:24,870
A really good example
is credential stuffing.

82
00:03:24,870 --> 00:03:26,850
Now credential stuffing is when usernames

83
00:03:26,850 --> 00:03:28,740
and passwords have been obtained.

84
00:03:28,740 --> 00:03:29,820
Generally, they've been obtained

85
00:03:29,820 --> 00:03:31,440
because a site's been compromised

86
00:03:31,440 --> 00:03:33,780
and that information has been published

87
00:03:33,780 --> 00:03:36,270
or sold out on the dark web.

88
00:03:36,270 --> 00:03:38,017
So now I'm the adversary and I say,

89
00:03:38,017 --> 00:03:41,760
"Okay, I've got sarah@greengroup.com

90
00:03:41,760 --> 00:03:44,070
and I've got XYZ password."

91
00:03:44,070 --> 00:03:47,160
I wonder if Sarah uses that username

92
00:03:47,160 --> 00:03:49,650
and password anywhere else.

93
00:03:49,650 --> 00:03:51,240
And so an informed attack,

94
00:03:51,240 --> 00:03:53,850
they'd be using that
known good list, right?

95
00:03:53,850 --> 00:03:55,140
Username and password.

96
00:03:55,140 --> 00:03:58,177
And trying it on lots of
different other sites saying,

97
00:03:58,177 --> 00:04:00,900
"I bet that she might reuse her password."

98
00:04:00,900 --> 00:04:03,210
Because we know that
people have a tendency

99
00:04:03,210 --> 00:04:05,130
to reuse their passwords.

100
00:04:05,130 --> 00:04:06,780
So that would be an example of informed,

101
00:04:06,780 --> 00:04:09,783
using that known good
reference list or dataset.

102
00:04:10,920 --> 00:04:12,660
And then lastly, a rainbow table.

103
00:04:12,660 --> 00:04:14,370
Now a rainbow table attack uses

104
00:04:14,370 --> 00:04:16,920
a pre-computed table of hashes

105
00:04:16,920 --> 00:04:19,290
to find the original plain text.

106
00:04:19,290 --> 00:04:21,870
It's often used in password cracking

107
00:04:21,870 --> 00:04:23,580
because in a number of systems,

108
00:04:23,580 --> 00:04:27,090
passwords are transmitted
not in clear text, hopefully,

109
00:04:27,090 --> 00:04:28,170
not encrypted,

110
00:04:28,170 --> 00:04:31,680
but the hash or the visual representation.

111
00:04:31,680 --> 00:04:33,840
And when we talked about hashing earlier,

112
00:04:33,840 --> 00:04:37,410
we said that we can go from
our plain text to our hash

113
00:04:37,410 --> 00:04:39,600
but we can never go back, right?

114
00:04:39,600 --> 00:04:40,980
It's a one-way process.

115
00:04:40,980 --> 00:04:43,140
I gave you the example of
we make chicken nuggets

116
00:04:43,140 --> 00:04:43,973
from chicken,

117
00:04:43,973 --> 00:04:46,350
but we can never make a
chicken from chicken nuggets.

118
00:04:46,350 --> 00:04:48,960
So we can't reverse a hash.

119
00:04:48,960 --> 00:04:50,640
But what we can do, right?

120
00:04:50,640 --> 00:04:54,420
Is have a list of common
words and their hashes

121
00:04:54,420 --> 00:04:56,640
and compare them and do a comparison.

122
00:04:56,640 --> 00:04:59,850
'Cause remember, every time we
put that word through a hash,

123
00:04:59,850 --> 00:05:03,180
it's going to come up with
the exact same answer,

124
00:05:03,180 --> 00:05:04,650
the same result.

125
00:05:04,650 --> 00:05:06,510
So we can use the rainbow table

126
00:05:06,510 --> 00:05:08,400
which is a pre-computed table of hashes.

127
00:05:08,400 --> 00:05:10,957
So if I capture a hash,
I can look and say,

128
00:05:10,957 --> 00:05:12,510
"Okay, let me look down that list.

129
00:05:12,510 --> 00:05:13,890
Oh, that hash is here.

130
00:05:13,890 --> 00:05:15,990
Oh look, here's the reverse.

131
00:05:15,990 --> 00:05:17,517
It's XYZ."

132
00:05:20,150 --> 00:05:22,830
Now the most effective detective control

133
00:05:22,830 --> 00:05:27,830
for identifying a brute force
attack is going to be logging

134
00:05:28,260 --> 00:05:32,280
and monitoring and
alerting of both successful

135
00:05:32,280 --> 00:05:34,590
and unsuccessful events.

136
00:05:34,590 --> 00:05:35,910
So, you really wanna make sure

137
00:05:35,910 --> 00:05:37,237
that your logs are set up to say,

138
00:05:37,237 --> 00:05:39,990
"Okay, tell me when there's
been a successful event."

139
00:05:39,990 --> 00:05:40,980
But tell me when,

140
00:05:40,980 --> 00:05:42,870
and probably more importantly here,

141
00:05:42,870 --> 00:05:44,820
there's been an unsuccessful attempt.

142
00:05:44,820 --> 00:05:46,560
Because in a brute force attack,

143
00:05:46,560 --> 00:05:48,060
particularly in a discovery attack,

144
00:05:48,060 --> 00:05:51,000
there will be a lot of
unsuccessful attempts

145
00:05:51,000 --> 00:05:53,103
before there's a successful attempt.

146
00:05:54,750 --> 00:05:56,550
Now, what are some
mitigation techniques we have

147
00:05:56,550 --> 00:05:58,410
for brute force attacks?

148
00:05:58,410 --> 00:05:59,730
We can do rate limiting

149
00:05:59,730 --> 00:06:02,310
which is a technique to
limit network traffic.

150
00:06:02,310 --> 00:06:03,630
We can have account lockouts.

151
00:06:03,630 --> 00:06:05,550
So let's say if the brute force attack

152
00:06:05,550 --> 00:06:06,600
is against the password,

153
00:06:06,600 --> 00:06:08,040
we can say, "Okay, you've got three tries

154
00:06:08,040 --> 00:06:09,630
or four tries or five tries."

155
00:06:09,630 --> 00:06:10,740
And then that's it, right?

156
00:06:10,740 --> 00:06:12,480
The account is locked up.

157
00:06:12,480 --> 00:06:14,640
We could require
multi-factor authentication.

158
00:06:14,640 --> 00:06:17,070
So, let's say we're trying
to discover a password.

159
00:06:17,070 --> 00:06:18,390
Well, if you have multifactor,

160
00:06:18,390 --> 00:06:20,760
just knowing the password
isn't gonna be enough.

161
00:06:20,760 --> 00:06:23,040
And having intrusion prevention systems

162
00:06:23,040 --> 00:06:26,430
so that we can see this
malicious activity taking place

163
00:06:26,430 --> 00:06:27,663
and put a stop to it.

164
00:06:30,270 --> 00:06:33,630
And that, my friends, takes us
to a three-second challenge.

165
00:06:33,630 --> 00:06:34,463
Are you ready?

166
00:06:34,463 --> 00:06:35,760
Five questions, three seconds each.

167
00:06:35,760 --> 00:06:36,593
Let's do it.

168
00:06:37,710 --> 00:06:39,780
This type of brute force attack attempts

169
00:06:39,780 --> 00:06:42,120
every single solution.

170
00:06:42,120 --> 00:06:44,043
1, 2, 3.

171
00:06:45,150 --> 00:06:46,053
That's basic.

172
00:06:47,580 --> 00:06:50,970
Number two, this type of attack
uses a finite reference list

173
00:06:50,970 --> 00:06:51,963
or data set.

174
00:06:52,950 --> 00:06:55,710
1, 2, 3.

175
00:06:55,710 --> 00:06:56,973
It's gonna be dictionary.

176
00:06:58,320 --> 00:07:01,200
Number three, credential
stuffing is an example

177
00:07:01,200 --> 00:07:03,243
of this type of brute force attack.

178
00:07:04,200 --> 00:07:06,870
1, 2, 3.

179
00:07:06,870 --> 00:07:08,313
It's gonna be informed.

180
00:07:09,600 --> 00:07:13,620
Number four, the estimate of
time, effort, and resources

181
00:07:13,620 --> 00:07:15,930
needed by an adversary to succeed.

182
00:07:15,930 --> 00:07:17,910
What does that refer to as?

183
00:07:17,910 --> 00:07:20,880
1, 2, 3.

184
00:07:20,880 --> 00:07:23,370
And that's gonna be our work factor.

185
00:07:23,370 --> 00:07:25,500
And lastly, number five.

186
00:07:25,500 --> 00:07:28,080
The objective of this
type of brute force attack

187
00:07:28,080 --> 00:07:30,273
is a disruption of a resource.

188
00:07:31,530 --> 00:07:34,350
1, 2, 3.

189
00:07:34,350 --> 00:07:37,080
And that's gonna be a
denial of service attack.

190
00:07:37,080 --> 00:07:39,243
That's our disruption of a resource.

191
00:07:40,560 --> 00:07:41,393
Good work.

192
00:07:41,393 --> 00:07:42,753
I hope you did great on those.

193
00:07:44,190 --> 00:07:45,600
All right, let's do a security-in-action

194
00:07:45,600 --> 00:07:48,723
so we can apply our knowledge
about brute force detection.

195
00:07:49,800 --> 00:07:51,270
Your boss has requested

196
00:07:51,270 --> 00:07:53,340
that your team enhance their brute force

197
00:07:53,340 --> 00:07:56,640
authentication attack
detection capabilities.

198
00:07:56,640 --> 00:07:58,590
One of your colleagues responds

199
00:07:58,590 --> 00:08:02,340
that the current logging of
successful login attempts

200
00:08:02,340 --> 00:08:03,510
is sufficient.

201
00:08:03,510 --> 00:08:04,380
It's like, "We're good.

202
00:08:04,380 --> 00:08:06,960
We don't need to do anything more."

203
00:08:06,960 --> 00:08:08,430
My question to you is,

204
00:08:08,430 --> 00:08:09,840
do you agree?

205
00:08:09,840 --> 00:08:11,520
So once again, our bosses has requested

206
00:08:11,520 --> 00:08:13,140
our team enhance their brute force

207
00:08:13,140 --> 00:08:16,170
authentication attack
detection capabilities.

208
00:08:16,170 --> 00:08:18,330
And our colleague says,
"Listen, we're logging.

209
00:08:18,330 --> 00:08:20,670
We're logging successful login attempts.

210
00:08:20,670 --> 00:08:22,080
We're good."

211
00:08:22,080 --> 00:08:23,790
And my question to you,

212
00:08:23,790 --> 00:08:24,900
do you agree?

213
00:08:24,900 --> 00:08:26,250
Go ahead and put me on pause if you want

214
00:08:26,250 --> 00:08:27,510
while you think about that.

215
00:08:27,510 --> 00:08:29,810
Go on back and we'll do
our response together.

216
00:08:32,250 --> 00:08:34,560
So hopefully, you didn't agree

217
00:08:34,560 --> 00:08:38,220
because logging of successful
attempts is not sufficient.

218
00:08:38,220 --> 00:08:41,520
By the time a successful
attempt is identified,

219
00:08:41,520 --> 00:08:43,533
the intruder's already in our system.

220
00:08:45,750 --> 00:08:49,020
So logging should always be
set to report both successful

221
00:08:49,020 --> 00:08:51,300
and unsuccessful attempts.

222
00:08:51,300 --> 00:08:55,830
And in addition, high priority
alerts should be configured

223
00:08:55,830 --> 00:08:59,343
if we see a pattern of
unsuccessful attempts.

224
00:09:00,810 --> 00:09:01,950
That make sense?

225
00:09:01,950 --> 00:09:06,950
So we wanna just respectfully
tell our colleague that,

226
00:09:07,297 --> 00:09:11,940
"Nope, it's not sufficient and
this is what we should do."

227
00:09:11,940 --> 00:09:13,680
And importantly, we wanna
educate our colleagues.

228
00:09:13,680 --> 00:09:17,160
So explain why we're going
to do both successful

229
00:09:17,160 --> 00:09:18,480
and unsuccessful.

230
00:09:18,480 --> 00:09:21,330
Doing that, my friends, is
definitely security-in-action.

231
00:09:22,890 --> 00:09:23,723
There you go.

232
00:09:23,723 --> 00:09:24,556
There's your word cloud.

233
00:09:24,556 --> 00:09:25,389
You know what to do.

234
00:09:25,389 --> 00:09:28,410
No moving on until you can
identify all of these terms.

235
00:09:28,410 --> 00:09:30,330
When you're ready, head
to the next lesson.

236
00:09:30,330 --> 00:09:32,130
I'll be waiting for you right there.
