1 / 13100%
Cyber Resiliency: Ability to anticipate, withstand, recognize, etc attacks/stress on
cyber resources. Focuses on APT, but also addresses all threats, even non cyber
(kinetic) ones. Not the same as cyber security
Threat: Human or natural event that could affect the system
Vulnerability: Weakness that could be exploited
Risk: Likelihood/probability of event and its impact
Hacker: Enjoys learning about computers (pen testers, not malicious)
Cracker: Hostile Intent
Brute-force password attack: the attacker tries different passwords on a system
until one of them is successful.
Dictionary password attack: hackers try simpler and shorter combinations,
including actual words (hence the name of attack) because such passwords are
so common.
Spoofing: is a type of attack in which one person, program, or computer
disguises itself as another person, program, or computer.
Man-in-the-Middle Attack: attacker intercepts messages between two parties
before transferring them to their intended destinations
Social Engineering: is the art of one human attempting to coerce or deceive
another human into divulging information.
Spear phishing: Targeted Phishing
Hacktivists: someone who breaks into a service or anything with the intent of civil
disobedience (i.e. breaking into a social media account or website and changing
it or putting bad messages or offensive things on it because they do not like what
the person or company has been saying or posting on it)
Cyber Criminals:
Zero-day Vulnerability: a computer-software vulnerability either unknown to those who
should be interested in its mitigation or known, and a patch has not been developed.
State Sponsored Cyber Spies: form of warfare in which one nation or state
attacks another's government agencies and systems known to store valuable
information.
Malware: Malicious Software, designed to infiltrate/hijack code
Phishing: tricking others into taking an action that can be profited from.
Deepfakes: Synthetic media. Manipulated video usually used to smear someone.
Firewall: Hardware and/or software that controls incoming and outgoing network
traffic.
Cyber Resources: Separately manageable resources in cyber, including data?
Information Assurance (IA): focuses on protecting information during process
and use.
Five Pillars of the Information Assurance (IA) model:
- Confidentiality: Only authorized individuals can access it
- Integrity: Information has not been improperly changed
- Availability: Information is available to authorized users and devices
- Authentication: Ability to verify identity of user or device
- Nonrepudiation: Individual cannot deny doing something; proving that a
user did something (esignature)
CIA Triad: Confidentiality, Integrity, Availability
·
Confidentially Only authorized users can access and view its information
·
Integrity Only authorized users can change information
·
Availability Information is accessible by authorized users whenever they request their
information
Obfuscation: a programming technique used to make source code exceedingly
difficult to read and so prevent reverse engineering or detection of malware.
Governance: Is both a concept and a set of specific actions an organization takes
to ensure compliance with its policies, processes, standards, and
guidelines. Checkpoints that perform either QA or QC
Security Documents:
Principle: Sets the tone and authority
- Policy: How to document
- Standard: Industry Norm
- Procedure: The actual steps
- Guideline: Optional
Open System Interconnection Reference Model (OSI)
Application Layer (Layer 7): This layer is responsible for interacting with end
users
Presentation Layer (Layer 6): This layer is responsible for the coding of data
Session Layer (Layer 5): This layer is responsible for maintaining communication
sessions between computers
Transport Layer (Layer 4): The layer responsible for breaking data into packets
and properly transmitting it over the network c
Network Layer (Layer 3): The layer responsible for logical implementations of the
network. One of the key features of this layer is
logical addressing which takes the form of TCP/IP addresses
Data Link Layer (Layer 2): This layer is responsible for connecting computers to
computers in a basic network (LAN, WAN, Network Topology Physical/Logical).
Physical Layer (Layer 1): This layer is responsible for the physical connection of
computers to the network using a network medium (can use Wi/Fi).
LAN Local Area Network
WAN Wide Area Network (a group of LANs that are all interconnected within a
certain area)
Session when two different computers talk together effectively at the same
time
ARPANET: First instance of the Internet. Developed by the Defense Department to
promote networking research.
Gateways: Regulate traffic between two dissimilar networks. Special type of
node?
Routers: Regulate traffic between similar networks
·
Border Routers: a border router is subject to direct attack from an
outside source.
·
Internal Routers: help keep subnet traffic separate. They can keep
traffic out of a subnet and keep traffic in a subnet.
Node: an electronic device that is attached to a network, and can create, receive,
or transmit information over a communications channel (end-point devices,
routers, gateways).
Host: a server offering information, resources, services, and
·
File Server (FTP): a computer that stores and manages files for
multiple users on a network.
·
Web Server (HTTP): A computer dedicated
to responding to requests (from the browser client) for web pages
Internet Backbone: Set of high-speed networks that carry internet traffic,
provided by companies like Verizon, IBM, etc.
Internet Service Provider (ISP): A company that provides other companies or
individuals with access to the Internet
Packet Switching
·
Packet (box or envelope): A unit of data sent across a network
·
Router: network device that directs
a packet between networks toward its final destination
·
Packet Switching: Messages are divided into fixed-
sized, numbered packers; packets are individually
routed to their destination, then reassembled
·
Packet Filtering: done by both routers and firewalls. Compares the
packet to a list of rules configured by the network administrator. The
rules tell the device whether to allow the packet into the network.
Components of IP Packets
Network Addresses
·
Hostname: a name made up of words separated by dots that
uniquely identifies a computer on the Internet
·
IP address: an address made up of four one-
byte numeric values separated by dots that uniquely identifies a
computer on the internet
·
MAC Address: defines the devices identity, but IP address describes
how the devices are connected to the network.
Lan Devices: Hubs and Switches
·
Hubs: simple network devices. Receives a packet on any port, it
automatically retransmits that packet to all the other ports.
·
Switches: a much better alternative to hubs. Performs same basic
functions as a hub, but they also perform intelligent packet
filtering. Using the MAC address, the switch sends data packets to only
the device that it is addressed to.
Firewall Types/Encryption/Security
·
Stateful Inspection: firewall remembers that communication session
until it is closed. Does not have to check its rules each time if it receives
a packet.
·
Border Firewall: firewalls that separate the protected networks from
the internet
·
Virtual Private Network (VPNs): normally use encryption to protect all
the data they send between a user and the organization's network.
·
Network Access Control (NAC): systems enable you to add more
security requirements before allowing a device to connect to your
network.
·
Posture Checking: Optional second use of NAC. When used, the
NAC device checks the configuration of the user’s computer to ensure
that it meets security standards before allowing it to access the
network.
·
Wireless Access Point (WAP): the connection between a wired and
wireless network
Internet of Things (IoT)
·
Internet of Things (IoT): used to refer to the large number of
networked devices (e.g., personal items, home appliances, cloud
services, vehicles, etc.) that can now connect to the Internet.
·
IoT 5 Critical Challenges:
o Security
o Privacy Whose data, are they? Who owns
the intellectual property of personal information, data, and media,
what is a privacy statement and why is it important to you?
Privacy vs. Security
Shades vs. Bars
Appropriate use of data vs. Protecting data
o Interoperability - How do we define standards and protocols
such that all IoT-connected devices can communicate and be
accessible.
o Legal and regulatory compliance The IoT vision presents
legal and regulatory compliance issues that typically have not
always kept pace with the speed of IoT implementations.
o Emerging social and economic issues The countries of the
world and their citizens must quickly learn to understand and
overcome any political, environmental, and economic issues
presented by the IoT vision.
Radio Frequency Identification (RFID): implemented within supply chain
management processes to track the movement of goods and their delivery.
Cloud Service Models
·
Infrastructure as a Service (IaaS): is a cloud computing offering in
which a vendor provides users access to computing resources such as
servers, storage, and networking.
o Microsoft Azure
·
Platform as a Service (PaaS): is a cloud computing offering that
provides users with a cloud environment in which they can develop,
manage, and deliver applications.
o RedHat open shift, Microsoft Azure
·
Software as a Service (SaaS): is a cloud computing offering that
provides users with access to a vendor’s cloud-based software. Users
do not install applications on their local devices.
o DropBox, Office 365
Real-Time Communicatons: Synchronous communication; phone calls, instant
messaging, etc.
Store-and-forward communication: Asynchronous communication. Email, texts
that aren’t read for a while, etc.
Business-to-consumer (B2C): amazon.com, etc
Business-to-business: For sales between companies, like parts for
manufacturing/raw materials. Computers talking to computers
BYOD: Bring Your Own Devices
Web Applications
·
Data Leakage: unauthorized transmission of data from within an
organization to an external destination or recipient
Data Breaches
·
Data breach: an event in which an individual’s name and a medical
record and/or a financial record or debit card is potentially put at risk,
either in electronic or paper format.
·
Data Breach Life Cycle: The time between when a data breach
incident occurred and when the breach is finally contained
Three types of breaches
·
Malicious cyber-attack: attacks with malicious intent
·
Human error: breaches caused by something a human does to the
system or not being smart (phishing, downloading or infected
with malware, or having their devices lost/stolen
·
System glitches: hardware or software error that cannot be linked
directly to human error
Cost Amplifier: a situation that causes the data breach to become much worse
than it already is
Cost Mitigators: Put money into the breach security which will in turn reduce the
costs.
DevSecOps: development, security, and operations automate the integration of
security at every phase of the software development lifecycle.
CVE-2017-0144 (Vulnerability) -> EternalBlue (Exploit) -> WannaCry (Attack)
EternalBlue: an NSA-Developed Exploit that just won't die
WannaCry
·
Worm: beneficial type of software search services
·
Wormable: characteristics of a worm
·
Cryptoworm: encrypting worm WannaCry
·
Caused by an exploit in the EternalBlue system that was used to
infect over 28,000 computers and servers
·
Buffer overflow: data overflows the buffers boundaries
Clouds
·
Hybrid Clouds: non-critical and less sensitive resources
·
Private Clouds: dedicated to a single client and can be secured by
private network settings and management.
·
Public Clouds: share common access
·
Cloud Security: is the set of policies, procedures and tools used to
protect data, applications and networks in cloud environments.
·
Cloud environments: highly distributed and dynamic. They are more
susceptible to unauthorized access, data exposure, cyber-attack and
other threats. Same practices used to secure on-
premises environments.
·
Data protection: encryption and encryption keys where data is
encoded and can only be decoded with a key.
·
Monitoring: provides greater visibility through access trails and audit
logs that track activity and incidents.
·
Compliance: data owner must fully comply, but cloud provider may
not have specific regulatory responsibilities
·
Micro segmentation: enables security architects to logically divide
the data center into distinct security segments down to the individual
workload level, and then define security controls and deliver
services for each unique segment.
·
Identity and Access Management: verifies and authenticates the
identity
·
Network Security: isolates network resources
·
Application security or web application security: augments
perimeter-based approaches models like network security. Application-
level firewalls and vulnerability testing and scanning.
·
Data protection: encryption and encryption keys where data is
encoded and can only be decoded with a key.
·
Monitoring: provides greater visibility through access trails and audit
logs that track activity and incidents.
·
Compliance: data owner must fully comply, but cloud provider may
not have specific regulatory responsibilities
Threat Hunting
·
Hunting: process of proactively and iteratively searching through
networks to detect and isolate advanced threats that evade existing
security solutions.
·
Hunting Maturity Model (HMM): good hunting infrastructure;
routinely collects from its IT environment, determining their level of
Hunting Maturity.
Levels of Threat Hunting
Level 0: Initial
·
Relies primarily on automated learning
·
Little to no routine
Level 1: Minimal
·
Incorporates threat intelligence
·
Moderate to high level of routine data collection
Level 2: Procedural
·
High or very high level of routine data collection
·
Follows data analysis procedures created by others
Level 3: Innovative
·
Creates new data analysis procedures
·
Understands what needs to be done but is just getting started
Level 4: Leading
The Hunting Loop
1) Create hypothesis
2) Investigate Via tools and Techniques
3) Uncover New Patterns and TTPs
4) Inform and Enrich Analytics
Kill Chain: specifies the phases of an attack from the attacker’s perspective.
By Understanding the attack phases, you can anticipate the sequential actions of
an attacker.
Visualizations: graphic/visual representation of linked data.
Linked data analysis evaluates relationships (connections) between objects,
including organizations and people.
Tactics, Techniques, and Procedures (TTPs): how threat agents orchestrate and
manage attacks. TTP can be used to profile the attacks for identification.
Lockheed Martin’s cyber kill chain:
·
Reconnaissance: Intruder picks a target - Look for known
weaknesses
·
Weaponization: Intruder develops malware - EternalBlue
·
Delivery: Intruder transmits the malware via a phishing email or
another medium - Wormability of WannaCry
·
Exploitation: The malware begins executing on the target system -
crypto-side of WannaCry
·
Installation: The malware installs a backdoor or other ingress
accessible to the attacker - DoublePulsar
·
Command and Control: Intruder gains persistent access to victim’s
network - APT
·
Actions on Objective: Intruder initiates end goal actions such as data
theft, data corruption, or data destruction - Ransomware
· Break the chain to break the attack
BeyondTrust Cyber-Attack Chain Model
·
Step One: Perimeter Exploitation early attempts to gain access to
gain access to an IT organization system
o Exploit known vulnerabilities
o Social engineering
o Direct hacking
Limiting access to sensitive assets, Pen testing, and
removing admin rights whenever possible for extremely
sensitive material are three ways that one can dismantle an
attack at this stage
Pen testing: authorized simulated cyber-attack
performed to evaluate the security of the system.
·
Step Two: Privilege Hijacking and Escalation -
o Monitor and audit
·
Step Three: Lateral Movement and Exfiltration
o Correlate and analyze
Security Operations Center (SOC)
o Security Operations Center: is a centralized function within
an organization employing people, processes, and technology to
continuously monitor and improve an organization’s security posture
while preventing, detecting, analyzing, and responding to
cybersecurity incidents.
Endpoint Detection and Response (EDR): security provides an
integrated hub for the collection, correlation, and analysis of endpoint
data, as well as for coordinating alerts and responses to immediate
threats.
o Endpoint data collection agents: Software agents conduct
endpoint monitoring and collecting data such as processes,
connections, volume of activity, and data transfers into a central
database.
o Automated response: pre-configured rules in an EDR solution
can recognize when incoming data indicates a known type of
security breach and triggers an automatic response, such as to
log off the end user or send an alert to a staff member.
o Analysis and forensics: AN endpoint detection and response
system may incorporate both real-time analytics, for
rapid diagnosis of threats that do not quite fit the pre-configured
rules, and forensics tools for threat hunting or conducting a post-
mortem analysis of an attack.
10 Key Functions of SOC
a. Security Roadmap:
i. Conduct IT and Risk Assessment
ii. Create a Security Policy and Strategy
iii. Plan for Implementation, Security Testing, and Risk
Management
4. Alert Ranking and Management
a. Triage: can wait, immediate attention, pass along.
Network Operations Center (NOC): Used to handle challenges related to
managing, monitoring, and controlling the networks in customer IT ecosystem.
Chief Information Security Officer (CISO): responsible for the larger picture of risk
and compliance.
IRT
·
Incident Response Team (IRT): is a specialized group of people
whose purpose is to respond to major incidents.
·
Infractions: handled by an individual’s manager
·
Incident vs infraction vs event = vehicle on fire vs fender bender vs
warning ticket.
·
Incident Classification Scheme: is developed before
something happens.
·
Due Care (Due Diligence): refers to the effort made to avoid harm to
another party.
·
IRT Charter: organizational document that outlines the mission,
goals, and authority of a team or committee.
·
Cross-functional team: IRT members are from several departments
and bring together multiple disciplines.
Compliance Laws
·
Critical Infrastructure: key elements of the country’s transportation,
energy communications, and banking systems.
·
Consumer rights: in ecommerce broadly deal with creating rules on
how to handle a consumer’s transaction
·
·
Federal Information Security Management Act (FISMA): Must always
understand the range of authority of a range of authority of a law.
FISMA Compliance Process
1. Congress -> Law FISMA
2. NIST (National Institute of Standards and Technology) -> Standard -
(SP) 800-series
3. Agencies -> Policies, procedures
4. Contractors -> Compliance records to agency
5. OMB -> Audit M-10-15 w
Full disclosure: The concept that individuals should know what information about
them is being collected. A company must give written notice on how it plans to
use your information.
Limited use of personal data: The key idea is that the company can use the
information collected only for the immediate service provided, or transaction
made, such as a purchase.
Opt-in/opt-out: The practice of asking permission on how personal information
can be used beyond its original purpose.
Data Privacy: A company must tell an individual how personal information will be
protected and limits placed on how the data will be shared.
Informed Consent: The concept that someone is of legal age, has the necessary
facts, and is without undue pressure to make an informed judgement.
Health Insurance Portability and Accountability Act (HIPPA)
·
The law protects a person’s privacy.
·
If you handle someone’s health records, you must adhere to HIPPA.
·
This includes doctor’s offices, hospitals, clinics, and
insurance companies.
Family Education Rights and Privacy Act (FERPA)
Students also viewed