1
00:00:06,510 --> 00:00:09,090
- In 8.4, we're gonna take a closer look

2
00:00:09,090 --> 00:00:11,463
at digital infrastructure attacks.

3
00:00:12,300 --> 00:00:13,133
Now, the objective

4
00:00:13,133 --> 00:00:15,780
of digital infrastructure
attacks is disruption

5
00:00:15,780 --> 00:00:18,300
or manipulation or compromise

6
00:00:18,300 --> 00:00:21,090
of either IT, information technology,

7
00:00:21,090 --> 00:00:24,780
or OT, operational technology systems.

8
00:00:24,780 --> 00:00:26,100
So what's the difference?

9
00:00:26,100 --> 00:00:29,610
Well, IT systems are primarily
concerned with managing data

10
00:00:29,610 --> 00:00:31,590
and information assets,

11
00:00:31,590 --> 00:00:33,840
where OT, operational technologies,

12
00:00:33,840 --> 00:00:36,990
focused on the use of
hardware and software systems

13
00:00:36,990 --> 00:00:39,930
to monitor and control
physical processes generally

14
00:00:39,930 --> 00:00:42,450
in an industrial or factory setting.

15
00:00:42,450 --> 00:00:43,283
So for example,

16
00:00:43,283 --> 00:00:46,653
in a manufacturing plant
or a transportation system.

17
00:00:49,800 --> 00:00:52,680
So here are four cyber
attacks terms to know,

18
00:00:52,680 --> 00:00:55,350
two of which we've already
talked about, two will be new;

19
00:00:55,350 --> 00:01:00,123
targeted, opportunistic
amplification and reflection.

20
00:01:00,990 --> 00:01:04,230
In a targeted attack, the
attacker chooses a target

21
00:01:04,230 --> 00:01:06,090
for a specific objective.

22
00:01:06,090 --> 00:01:07,860
We've already talked about this one,

23
00:01:07,860 --> 00:01:10,590
generally influenced by
the value of the asset

24
00:01:10,590 --> 00:01:12,660
and or the potential outcome.

25
00:01:12,660 --> 00:01:15,270
They don't know what the
target's weaknesses are,

26
00:01:15,270 --> 00:01:18,840
they just know they're
going after that target.

27
00:01:18,840 --> 00:01:20,520
In an opportunistic attack,

28
00:01:20,520 --> 00:01:23,730
the attacker takes advantage
of a vulnerable target.

29
00:01:23,730 --> 00:01:25,740
We talked about this one earlier as well.

30
00:01:25,740 --> 00:01:28,380
This is when the attacker
is looking for a weak

31
00:01:28,380 --> 00:01:32,013
or a vulnerable target, and
that's who they go after.

32
00:01:33,030 --> 00:01:34,950
In an amplification attack,

33
00:01:34,950 --> 00:01:38,010
the attacker uses an amplification factor

34
00:01:38,010 --> 00:01:40,230
in order to multiply its power.

35
00:01:40,230 --> 00:01:42,030
So for example, the use of botnets,

36
00:01:42,030 --> 00:01:44,370
when we talked about bots and zombies,

37
00:01:44,370 --> 00:01:46,530
botnets are just when
we have a lot of bots

38
00:01:46,530 --> 00:01:49,590
that are connected
together to launch a DDoS,

39
00:01:49,590 --> 00:01:53,223
a distributed denial of service
attack or a spam campaign.

40
00:01:54,240 --> 00:01:56,610
And then in a reflection attack,

41
00:01:56,610 --> 00:02:00,540
the attacker sends a large
number of requests to a device

42
00:02:00,540 --> 00:02:04,440
with the victim's IP address
as the source address.

43
00:02:04,440 --> 00:02:07,680
So then it bounces back,
right, to that victim.

44
00:02:07,680 --> 00:02:09,930
Now, that's often used in conjunction

45
00:02:09,930 --> 00:02:12,060
with an amplification attack.

46
00:02:12,060 --> 00:02:15,840
Targeted, opportunistic,
amplification and reflection,

47
00:02:15,840 --> 00:02:18,633
make sure you know these
four cyber attack terms.

48
00:02:20,010 --> 00:02:23,070
So let's look at the primary
digital attack categories;

49
00:02:23,070 --> 00:02:28,070
spoofing, poisoning, hijacking,
and denial of service.

50
00:02:28,560 --> 00:02:32,280
Spoofing is impersonating an
address, a system, or a person,

51
00:02:32,280 --> 00:02:35,430
and it enables the attacker
to act as a trusted source

52
00:02:35,430 --> 00:02:38,223
and either redirect or manipulate actions.

53
00:02:39,210 --> 00:02:43,200
Poisoning is manipulating
the trusted source of data.

54
00:02:43,200 --> 00:02:48,200
So for example, a DNS zone
file or a routing table.

55
00:02:48,210 --> 00:02:49,590
And that enables the attacker

56
00:02:49,590 --> 00:02:51,900
to control the trusted source of data

57
00:02:51,900 --> 00:02:55,650
and redirect or manipulate actions.

58
00:02:55,650 --> 00:02:58,500
Hijacking is intercepting
communication between two

59
00:02:58,500 --> 00:03:01,440
or more systems, and
that enables the attacker

60
00:03:01,440 --> 00:03:04,710
to eavesdrop or to
capture or to manipulate,

61
00:03:04,710 --> 00:03:07,320
and or to reuse data packets.

62
00:03:07,320 --> 00:03:09,570
And then a denial of service attack,

63
00:03:09,570 --> 00:03:11,820
is overwhelming system resources,

64
00:03:11,820 --> 00:03:13,560
and that enables the attacker

65
00:03:13,560 --> 00:03:17,400
to make those services unavailable
for their intended use.

66
00:03:17,400 --> 00:03:19,110
So those are our four broad categories;

67
00:03:19,110 --> 00:03:22,500
spoofing, poisoning, hijacking,
and denial of service.

68
00:03:22,500 --> 00:03:25,053
Now, let's dive into each
one of them individually.

69
00:03:27,120 --> 00:03:29,130
So in the spoofing attack, right,

70
00:03:29,130 --> 00:03:30,600
what we're doing here is,

71
00:03:30,600 --> 00:03:33,360
our adversary is impersonating
an address, a system,

72
00:03:33,360 --> 00:03:34,920
or a person.

73
00:03:34,920 --> 00:03:36,870
The outcome is enabling the attacker

74
00:03:36,870 --> 00:03:38,970
to act as the trusted source

75
00:03:38,970 --> 00:03:41,370
and or redirect or manipulate actions.

76
00:03:41,370 --> 00:03:42,510
And some examples

77
00:03:42,510 --> 00:03:45,420
of a spoofing attack would
be an IP address spoofing,

78
00:03:45,420 --> 00:03:47,820
where using a known trusted IP address

79
00:03:47,820 --> 00:03:49,980
for authentication or response,

80
00:03:49,980 --> 00:03:53,610
or using a fake IP address
to disguise the sender,

81
00:03:53,610 --> 00:03:56,880
or a MAC, a media access
control address spoofing.

82
00:03:56,880 --> 00:03:59,730
Now, every network interface
has a unique address known

83
00:03:59,730 --> 00:04:03,090
as a MAC address or a media
access control address,

84
00:04:03,090 --> 00:04:06,510
and that identifies that
device on the network.

85
00:04:06,510 --> 00:04:08,760
So MAC address spoofing could be used

86
00:04:08,760 --> 00:04:12,660
to using a known trusted
MAC address to get access,

87
00:04:12,660 --> 00:04:16,410
using a known trusted MAC
address to circumvent licensing,

88
00:04:16,410 --> 00:04:19,920
or using a fake MAC address
to mask the identity

89
00:04:19,920 --> 00:04:20,913
of a device.

90
00:04:23,370 --> 00:04:25,590
Now, a poisoning attack is manipulating

91
00:04:25,590 --> 00:04:28,140
or altering a trusted source of data.

92
00:04:28,140 --> 00:04:31,110
And the outcome is and enables
the attacker to control

93
00:04:31,110 --> 00:04:33,330
that trusted source of
data, that routing table,

94
00:04:33,330 --> 00:04:35,730
that DNS zone file, the ARP cache,

95
00:04:35,730 --> 00:04:39,780
and from there, redirect
or manipulate actions.

96
00:04:39,780 --> 00:04:42,690
So two primary type of
attacks you wanna recognize;

97
00:04:42,690 --> 00:04:46,529
an ARP cache poisoning
and a DNS cache poisoning.

98
00:04:46,529 --> 00:04:51,390
So the ARP cache address
resolution protocol is used to map

99
00:04:51,390 --> 00:04:53,430
or resolve a MAC address, right?

100
00:04:53,430 --> 00:04:56,970
That's the unique address that
every network interface has

101
00:04:56,970 --> 00:04:58,140
to an IP address.

102
00:04:58,140 --> 00:05:00,810
So it's used from MAC
to IP address resolution

103
00:05:00,810 --> 00:05:03,270
or back from IP to Mac.

104
00:05:03,270 --> 00:05:05,850
So our attacker can use
a poisoned ARP cache

105
00:05:05,850 --> 00:05:08,370
to redirect traffic to a malicious host,

106
00:05:08,370 --> 00:05:10,080
or using a poison ARP cache,

107
00:05:10,080 --> 00:05:12,123
actually, just to even stop traffic.

108
00:05:13,710 --> 00:05:17,370
DNS caches are used
for domain or host name

109
00:05:17,370 --> 00:05:19,110
to IP resolution.

110
00:05:19,110 --> 00:05:21,120
So DNS cache poisoning,

111
00:05:21,120 --> 00:05:22,920
you know, that set of information,

112
00:05:22,920 --> 00:05:26,490
can be used to divert website
traffic to a malicious site,

113
00:05:26,490 --> 00:05:29,493
or to divert website traffic
to a non-existent site.

114
00:05:31,920 --> 00:05:35,250
Now, a hijacking attack is
intercepting communication,

115
00:05:35,250 --> 00:05:36,390
between two systems,

116
00:05:36,390 --> 00:05:38,970
literally hijacking the communications.

117
00:05:38,970 --> 00:05:41,760
The attacker captures and
or controls communication,

118
00:05:41,760 --> 00:05:44,370
between the two systems.

119
00:05:44,370 --> 00:05:46,470
There are two types of
attacks I want you to know,

120
00:05:46,470 --> 00:05:50,010
an on-path hijacking and
the session hijacking.

121
00:05:50,010 --> 00:05:51,330
Now, on-path hijacking,

122
00:05:51,330 --> 00:05:53,790
is either exploiting
the realtime processing

123
00:05:53,790 --> 00:05:56,940
of transactions, conversations,
or data transfer.

124
00:05:56,940 --> 00:05:58,590
We used to refer to that
as man in the middle.

125
00:05:58,590 --> 00:06:00,690
We're now referring to that as on-path,

126
00:06:00,690 --> 00:06:02,070
or manipulating the browser

127
00:06:02,070 --> 00:06:05,100
to control a session
including what's displayed.

128
00:06:05,100 --> 00:06:07,440
And we used to refer to
that as man in the browser.

129
00:06:07,440 --> 00:06:08,760
But again, we'll now refer to that

130
00:06:08,760 --> 00:06:11,130
as an on-path hijacking attack.

131
00:06:11,130 --> 00:06:12,870
And then we have session hijacking

132
00:06:12,870 --> 00:06:14,520
which is stealing session cookies

133
00:06:14,520 --> 00:06:17,763
to be able to take over
a user's active session.

134
00:06:20,490 --> 00:06:21,540
In the web environment,

135
00:06:21,540 --> 00:06:25,050
we have some specific
types of hijacking attacks.

136
00:06:25,050 --> 00:06:27,210
Generally, what our attacker's doing is,

137
00:06:27,210 --> 00:06:30,783
attempting misdirection
to a fraudulent website.

138
00:06:31,710 --> 00:06:34,380
So the attacker directs
or redirects the victim

139
00:06:34,380 --> 00:06:37,320
to a fraudulent site
for malicious purposes.

140
00:06:37,320 --> 00:06:40,620
Now, there are three web
hijacking attacks you wanna know,

141
00:06:40,620 --> 00:06:45,000
domain hijacking, URL
squatting, and typo squatting.

142
00:06:45,000 --> 00:06:48,150
Now, domain hijacking is the
unauthorized modification

143
00:06:48,150 --> 00:06:50,100
of a domain name registration.

144
00:06:50,100 --> 00:06:54,840
So manipulating DNS settings
is registering or in some way,

145
00:06:54,840 --> 00:06:56,940
using an internet domain name

146
00:06:56,940 --> 00:06:59,460
that actually belongs to somebody else.

147
00:06:59,460 --> 00:07:02,820
And typo squatting is taking
advantage of common typos

148
00:07:02,820 --> 00:07:04,500
to create fraudulent domains.

149
00:07:04,500 --> 00:07:07,950
So Google is G-O-O-G-L-E.

150
00:07:07,950 --> 00:07:12,900
So a typo squat domain
might be G-O-O-O-G-L-E,

151
00:07:12,900 --> 00:07:16,440
adding that extra O, taking
advantage of those typos,

152
00:07:16,440 --> 00:07:17,460
at which point, right,

153
00:07:17,460 --> 00:07:20,493
we have misdirection to
a fraudulent website.

154
00:07:22,320 --> 00:07:24,390
And then we have our
denial of service attack.

155
00:07:24,390 --> 00:07:26,730
And the goal of a denial
of service attack is

156
00:07:26,730 --> 00:07:29,490
to overwhelm system resources.

157
00:07:29,490 --> 00:07:30,600
Now, at that point,

158
00:07:30,600 --> 00:07:34,380
the resources become unavailable
for their intended use.

159
00:07:34,380 --> 00:07:36,030
So two types of attacks to know

160
00:07:36,030 --> 00:07:38,220
for denial of service, a DoS,

161
00:07:38,220 --> 00:07:40,530
which is just a plain
denial of service attack

162
00:07:40,530 --> 00:07:44,913
and a DDoS, which stands for
distributed denial of service.

163
00:07:44,913 --> 00:07:46,500
In a denial of service attack,

164
00:07:46,500 --> 00:07:49,710
the attackers generally
transmitting malformed packets

165
00:07:49,710 --> 00:07:53,580
or unusual requests
from point A to point B,

166
00:07:53,580 --> 00:07:57,090
so that point B eventually
becomes overwhelmed.

167
00:07:57,090 --> 00:07:59,250
In a distributed denial of service,

168
00:07:59,250 --> 00:08:01,920
there's a massive volume
of service requests come

169
00:08:01,920 --> 00:08:03,330
from multiple sources.

170
00:08:03,330 --> 00:08:06,240
A lot of times, those instructions
were from bots or zombies

171
00:08:06,240 --> 00:08:09,150
and it often uses the amplification

172
00:08:09,150 --> 00:08:12,240
and the reflection techniques
that we talked about earlier.

173
00:08:12,240 --> 00:08:14,850
So make sure that you know
these different types of attacks

174
00:08:14,850 --> 00:08:18,483
so you can recognize them
if you're given a scenario.

175
00:08:19,920 --> 00:08:22,710
And that my friends, brings us
to a three-second challenge.

176
00:08:22,710 --> 00:08:24,570
Five challenge questions,
three seconds each,

177
00:08:24,570 --> 00:08:25,403
let's do it.

178
00:08:26,700 --> 00:08:31,170
Manipulating a trusted source
of data, what's that called?

179
00:08:31,170 --> 00:08:33,273
One, two, three.

180
00:08:35,520 --> 00:08:37,620
That's gonna be poisoning.

181
00:08:37,620 --> 00:08:42,180
Number two, impersonating an
address system or purpose.

182
00:08:42,180 --> 00:08:44,223
One, two, three.

183
00:08:45,810 --> 00:08:47,060
That's gonna be spoofing.

184
00:08:48,570 --> 00:08:53,370
Number three, attack designed
to overwhelm system resources.

185
00:08:53,370 --> 00:08:55,413
One, two, three.

186
00:08:56,940 --> 00:08:58,380
That's a denial of service

187
00:08:58,380 --> 00:09:00,813
or a distributed denial of service attack.

188
00:09:02,400 --> 00:09:05,010
Number four, manipulating the browser

189
00:09:05,010 --> 00:09:08,400
to control a session
including what's displayed.

190
00:09:08,400 --> 00:09:10,380
This is the one we said had a new name.

191
00:09:10,380 --> 00:09:12,660
One, two, three.

192
00:09:12,660 --> 00:09:14,100
This is an on-path attack.

193
00:09:14,100 --> 00:09:16,890
We used to refer to it as
a man in the browser attack

194
00:09:16,890 --> 00:09:18,180
or a MitB.

195
00:09:18,180 --> 00:09:20,010
And lastly, number five,

196
00:09:20,010 --> 00:09:21,780
use of hardware and software systems

197
00:09:21,780 --> 00:09:24,600
to monitor and control physical processes

198
00:09:24,600 --> 00:09:26,160
in industrial settings.

199
00:09:26,160 --> 00:09:27,363
What does that refer to?

200
00:09:28,331 --> 00:09:30,960
One, two, three.

201
00:09:30,960 --> 00:09:34,353
And that is gonna be OT
or operational technology.

202
00:09:35,370 --> 00:09:37,890
Right, that brings us
to a security-in-action.

203
00:09:37,890 --> 00:09:40,200
This one is about a cyber attack.

204
00:09:40,200 --> 00:09:43,740
We have a hacktivist group
initiated a poisoning attack

205
00:09:43,740 --> 00:09:45,750
on your regional DNS servers,

206
00:09:45,750 --> 00:09:47,730
which resulted in traffic being redirected

207
00:09:47,730 --> 00:09:49,800
to a much smaller competitor.

208
00:09:49,800 --> 00:09:52,680
The competitor site was
unable to handle the traffic,

209
00:09:52,680 --> 00:09:55,020
and subsequently crashed.

210
00:09:55,020 --> 00:09:57,420
Now, post-incident, you're
writing up an assessment

211
00:09:57,420 --> 00:09:58,920
and you wanna include a preface

212
00:09:58,920 --> 00:10:01,320
that includes a brief incident synopsis.

213
00:10:01,320 --> 00:10:03,870
And because your audience isn't technical,

214
00:10:03,870 --> 00:10:06,240
you know, you really want to explain

215
00:10:06,240 --> 00:10:09,360
what went on in non-technical terms.

216
00:10:09,360 --> 00:10:11,280
So a couple of key things here, right?

217
00:10:11,280 --> 00:10:13,140
We have a hacktivist group.

218
00:10:13,140 --> 00:10:17,400
We have a poisoning
attack on our DNS servers.

219
00:10:17,400 --> 00:10:21,930
Our competitor site subsequently crashed.

220
00:10:21,930 --> 00:10:24,720
So, let's write up our assessment

221
00:10:24,720 --> 00:10:27,180
and what we wanna include in the preface,

222
00:10:27,180 --> 00:10:30,270
which includes that
brief incident synopsis

223
00:10:30,270 --> 00:10:32,430
in a non-technical way.

224
00:10:32,430 --> 00:10:34,800
So go ahead and put me on
pause while you work on that.

225
00:10:34,800 --> 00:10:37,350
Come on back, and we'll do
an explanation together.

226
00:10:40,500 --> 00:10:42,690
Well, let's start with
defining what a hacktivist is.

227
00:10:42,690 --> 00:10:44,610
Hacktivists are cyber adversaries,

228
00:10:44,610 --> 00:10:47,853
whose motivation is generally political.

229
00:10:49,440 --> 00:10:52,650
Poisoning is the
manipulation of trusted data.

230
00:10:52,650 --> 00:10:53,730
Now, in this case,

231
00:10:53,730 --> 00:10:56,610
the DNS internet locator
record was changed

232
00:10:56,610 --> 00:11:00,300
to point from www.ourrcompany.com site

233
00:11:00,300 --> 00:11:03,723
to www.competitorcompany.com site.

234
00:11:05,940 --> 00:11:07,980
Now, the increase in traffic was intended

235
00:11:07,980 --> 00:11:12,243
to consume resources and
cause a denial of service.

236
00:11:13,980 --> 00:11:17,160
And in the end, really both
companies were victimized.

237
00:11:17,160 --> 00:11:18,960
The smaller company crashed,

238
00:11:18,960 --> 00:11:21,450
the larger company lost their customers,

239
00:11:21,450 --> 00:11:23,280
they went somewhere else.

240
00:11:23,280 --> 00:11:24,750
Why would a hacktivist do this?

241
00:11:24,750 --> 00:11:27,030
Again, a hacktivist is
trying to make a statement.

242
00:11:27,030 --> 00:11:30,240
So maybe the hacktivist
really had some issue

243
00:11:30,240 --> 00:11:31,650
with the competitor.

244
00:11:31,650 --> 00:11:34,080
Now, hacktivist will tend
to see one of two things,

245
00:11:34,080 --> 00:11:36,870
either defacement or denial of service,

246
00:11:36,870 --> 00:11:40,410
but explaining what's a
hacktivist, what's poisoning?

247
00:11:40,410 --> 00:11:42,000
How is DNS used?

248
00:11:42,000 --> 00:11:42,990
In simple terms,

249
00:11:42,990 --> 00:11:46,530
how did this attack occur
and who was the victim?

250
00:11:46,530 --> 00:11:49,923
And doing all that is
definitely security and action.

251
00:11:51,810 --> 00:11:52,920
There's your word cloud.

252
00:11:52,920 --> 00:11:55,140
There's a lot in this word cloud, a lot.

253
00:11:55,140 --> 00:11:56,400
We just went through a lot of material.

254
00:11:56,400 --> 00:11:58,440
So please take your time,

255
00:11:58,440 --> 00:12:00,210
you know, go through all of these terms,

256
00:12:00,210 --> 00:12:02,130
and make sure you can speak to them all,

257
00:12:02,130 --> 00:12:03,900
that you have clarity and
that you're confident.

258
00:12:03,900 --> 00:12:06,180
And if not, go back in the lesson, right?

259
00:12:06,180 --> 00:12:09,030
And find out what it
is that you don't know.

260
00:12:09,030 --> 00:12:10,440
Do that before you move on.

261
00:12:10,440 --> 00:12:11,610
But when you're ready, move on,

262
00:12:11,610 --> 00:12:13,410
and I'll see you in the next lesson.
