1
00:00:06,210 --> 00:00:07,380
- [Instructor] In this segment,

2
00:00:07,380 --> 00:00:10,143
we're gonna talk about
Zero-day Vulnerabilities.

3
00:00:11,520 --> 00:00:13,590
You know, zero-day vulnerabilities

4
00:00:13,590 --> 00:00:16,410
are really, really dangerous.

5
00:00:16,410 --> 00:00:19,680
Now, by the strictest definition
of zero-day vulnerability

6
00:00:19,680 --> 00:00:22,800
is one that is not yet publicly disclosed

7
00:00:22,800 --> 00:00:26,160
or one that's been discovered
as a result of an attack.

8
00:00:26,160 --> 00:00:29,370
But in reality, we use the term "zero-day"

9
00:00:29,370 --> 00:00:33,210
to describe an exploit that
does not yet have a fix.

10
00:00:33,210 --> 00:00:34,860
Now, the term "zero-day" stems

11
00:00:34,860 --> 00:00:37,410
from the time the
vulnerability is discovered,

12
00:00:37,410 --> 00:00:39,690
often referred to as day zero.

13
00:00:39,690 --> 00:00:42,420
And the subsequent race that we have

14
00:00:42,420 --> 00:00:46,080
between our security
teams and our attackers,

15
00:00:46,080 --> 00:00:49,710
and the race is to either fix
or patch the vulnerability

16
00:00:49,710 --> 00:00:52,650
or to successfully exploit it.

17
00:00:52,650 --> 00:00:56,730
Let's take a look at the
timeline of a zero-day attack.

18
00:00:56,730 --> 00:00:58,980
Now, the first thing
that has to happen is,

19
00:00:58,980 --> 00:01:02,010
the vulnerabilities have to be identified.

20
00:01:02,010 --> 00:01:04,260
So how are the vulnerabilities identified?

21
00:01:04,260 --> 00:01:05,850
Well, you know, our criminals invest

22
00:01:05,850 --> 00:01:08,790
an awful lot of time
and resources and effort

23
00:01:08,790 --> 00:01:11,190
in R&D, research and development,

24
00:01:11,190 --> 00:01:15,270
testing open source code and
proprietary applications,

25
00:01:15,270 --> 00:01:16,950
looking for vulnerabilities

26
00:01:16,950 --> 00:01:20,103
that have not yet been
identified or reported.

27
00:01:21,420 --> 00:01:24,120
Alternately, they may
turn to the black market

28
00:01:24,120 --> 00:01:27,300
and purchase information
about vulnerabilities.

29
00:01:27,300 --> 00:01:29,850
So once they've got that information,

30
00:01:29,850 --> 00:01:31,260
now they have to decide

31
00:01:31,260 --> 00:01:33,990
how valuable that information is to them.

32
00:01:33,990 --> 00:01:35,190
So they're going to go out

33
00:01:35,190 --> 00:01:39,090
and they're going to look
for vulnerable systems.

34
00:01:39,090 --> 00:01:42,750
They're going to do that
by using automated scanners

35
00:01:42,750 --> 00:01:45,270
or bots, or even manual probing,

36
00:01:45,270 --> 00:01:49,320
but they want to understand
what the market is, if you will,

37
00:01:49,320 --> 00:01:51,630
for those vulnerabilities.

38
00:01:51,630 --> 00:01:53,190
If they decide to go ahead,

39
00:01:53,190 --> 00:01:56,160
because that vulnerability
is gonna be valuable to them,

40
00:01:56,160 --> 00:01:59,640
then they're going to
work on the dual tasks

41
00:01:59,640 --> 00:02:02,340
of creating the appropriate exploits

42
00:02:02,340 --> 00:02:04,680
and planning the attack.

43
00:02:04,680 --> 00:02:08,460
Now, those exploits might be
a kit or a script or a process

44
00:02:08,460 --> 00:02:09,750
that's going to enable them

45
00:02:09,750 --> 00:02:12,750
to exploit the discovered vulnerability.

46
00:02:12,750 --> 00:02:14,130
What's the attack gonna look like?

47
00:02:14,130 --> 00:02:15,030
Well, it really depends

48
00:02:15,030 --> 00:02:17,610
on what they're attempting to accomplish.

49
00:02:17,610 --> 00:02:19,650
If it's a targeted attack,

50
00:02:19,650 --> 00:02:22,410
well, the attackers are
probably gonna carry out

51
00:02:22,410 --> 00:02:25,290
reconnaissance, right,
on their intended victim

52
00:02:25,290 --> 00:02:27,480
because they wanna reduce
the chance of being caught

53
00:02:27,480 --> 00:02:30,060
and increase the chance of success.

54
00:02:30,060 --> 00:02:31,110
But if it's going to be

55
00:02:31,110 --> 00:02:34,980
a more general broad-based
opportunistic attack,

56
00:02:34,980 --> 00:02:38,460
then they're more likely to
use phishing campaigns or bots

57
00:02:38,460 --> 00:02:42,423
to try to hit as many targets
as quickly as possible.

58
00:02:43,377 --> 00:02:46,830
In either case, once they're
ready, they're going to attack.

59
00:02:46,830 --> 00:02:48,540
And here's where the race is on,

60
00:02:48,540 --> 00:02:52,350
because they wanna attack
before a patch is available,

61
00:02:52,350 --> 00:02:57,300
right, when systems are at
their absolute most vulnerable.

62
00:02:57,300 --> 00:02:59,010
So what's an organization to do

63
00:02:59,010 --> 00:03:00,960
while they're waiting for a fix?

64
00:03:00,960 --> 00:03:02,490
Well, whenever possible,

65
00:03:02,490 --> 00:03:06,420
organizations should be
implementing compensating controls.

66
00:03:06,420 --> 00:03:07,950
Now, if that's not possible,

67
00:03:07,950 --> 00:03:09,735
they'll need to make risk-based

68
00:03:09,735 --> 00:03:11,790
(indistinct) operational decisions

69
00:03:11,790 --> 00:03:14,910
which may include pausing or stopping

70
00:03:14,910 --> 00:03:17,430
whatever the affected target is,

71
00:03:17,430 --> 00:03:19,860
and of course be ready to patch

72
00:03:19,860 --> 00:03:23,163
as soon as a patch or
an update is available.

73
00:03:24,030 --> 00:03:26,970
Now, one would think that as
soon as a patch is available,

74
00:03:26,970 --> 00:03:30,120
that a zero-day attack
is no longer viable.

75
00:03:30,120 --> 00:03:32,670
Unfortunately, that's not true

76
00:03:32,670 --> 00:03:36,630
because so many organizations
are very lax about patching

77
00:03:36,630 --> 00:03:38,190
or they're slow to patch

78
00:03:38,190 --> 00:03:41,700
that even after a patch
or a fix is available,

79
00:03:41,700 --> 00:03:44,280
often there's a window of opportunity

80
00:03:44,280 --> 00:03:47,340
for the attackers to still take advantage

81
00:03:47,340 --> 00:03:50,610
of that zero-day vulnerability
to still exploit it,

82
00:03:50,610 --> 00:03:52,893
to still cause havoc.

83
00:03:53,880 --> 00:03:55,230
So it's really important

84
00:03:55,230 --> 00:03:57,600
that you stay up on your
threat intelligence,

85
00:03:57,600 --> 00:04:00,240
that you know about
zero-day vulnerabilities,

86
00:04:00,240 --> 00:04:03,150
and that you're really,
really looking for that patch

87
00:04:03,150 --> 00:04:06,630
and getting that patch
implemented absolutely

88
00:04:06,630 --> 00:04:08,460
as soon as possible.

89
00:04:08,460 --> 00:04:10,713
And that, my friend, is a closer look.
