ENSA M3 Network Security Concepts Part 1 — Transcript
Full transcript
- 0:03[Music]
- 0:15hi hello there
- 0:17welcome to network security concepts
- 0:20this video lecture are divided into two
- 0:22segments
- 0:23okay so you've got part one and part two
- 0:27on the next video so perhaps you have
- 0:30learned and heard about hundreds of
- 0:32news stories about data security bridge
- 0:36within a large corporation or even a
- 0:39government
- 0:40was your credit card number exposed by a
- 0:42bridge
- 0:44your private health information would
- 0:47you like to know how to prevent these
- 0:49data breaches so the field of network
- 0:52security is growing every day
- 0:55this module provides a detailed
- 0:57landscape
- 0:58of the types of cybercrime and the many
- 1:01ways we have to fight back against cyber
- 1:04criminals
- 1:05let's get started
- 1:08okay so for the part one of this video
- 1:10lecture so
- 1:12we will be talking about these topics
- 1:14here
- 1:15current state of the cyber security
- 1:18threat actors malware common network
- 1:21attacks and ip vulnerabilities in
- 1:23threats
- 1:25okay now for the module objective okay
- 1:28so at the end of this video lecture
- 1:30for part one and part two you should be
- 1:32able to explain
- 1:33how vulnerabilities threats and exploits
- 1:37can be mitigated to enhance network
- 1:39security
- 1:42okay so before we start let's have this
- 1:45ethical hacking statement
- 1:47so in this module learners may be
- 1:49exposed to tools and techniques in a
- 1:51sandbox
- 1:52virtual machine environment to
- 1:54demonstrate various types of cyber
- 1:56attacks
- 1:58experimentation with this tools
- 2:00techniques
- 2:01and resources is at the discretion of
- 2:03the instructor
- 2:04and local institution so if the learner
- 2:08is considering using attack tools for
- 2:10educational purposes
- 2:11they should contact their instructor
- 2:13prior to an experimentation
- 2:16so an authorized process okay or access
- 2:19the data
- 2:20computer and network systems is a crime
- 2:23in many jurisdictions
- 2:25and often is accompanied by severe
- 2:28consequences
- 2:29regardless of the perpetrator's
- 2:31motivations
- 2:33so it is the learner's responsibility as
- 2:35the user of this material
- 2:37to be cognizant of end the complaint
- 2:41with computer use
- 2:42laws
- 2:46okay so let's start with the first
- 2:49section
- 2:50of this part one of the video let's talk
- 2:52about the current state of the cyber
- 2:54security
- 2:55[Music]
- 2:56okay so cyber criminals now have the
- 3:00expertise and tools necessary
- 3:03to take down critical infrastructure and
- 3:05systems
- 3:07so their tools and techniques continue
- 3:09to evolve
- 3:11so cyber criminals are taking malware
- 3:14to unprecedented levels of
- 3:16sophistication and impact
- 3:18okay so they are more adept at using
- 3:22stealth
- 3:23and evasion techniques to hide their
- 3:25activity
- 3:27lastly cyber criminals are exploiting
- 3:30undependent gaps
- 3:31in security so network
- 3:34security bridges can disrupt e-commerce
- 3:38cause the loss of business data threaten
- 3:41people's privacy and compromise the
- 3:43integrity of information
- 3:45so these bridges can result in lost
- 3:48revenue for corporations theft of
- 3:51intellectual property lawsuits and can
- 3:55even threaten public safety
- 3:57[Music]
- 3:58so maintaining a network or a secure
- 4:01network
- 4:02ensures that safety for network users
- 4:04and protects commercial interests
- 4:07so organization need individuals who can
- 4:10recognize the speed and skill
- 4:13at which adversaries are amassing
- 4:17and refining their cyber weak boundary
- 4:20so
- 4:20all the users should be aware of
- 4:22security terms
- 4:24in the table here okay so you've
- 4:27got assets vulnerability threat
- 4:30exploit mitigation and risk
- 4:34so when you say assets assets must be
- 4:37identified
- 4:37and protected okay so
- 4:41this has something to do with anything
- 4:43of value to the organization
- 4:46it indicates or it includes people
- 4:49equipment resources and data
- 4:52so next is vulnerability so
- 4:54vulnerabilities must be addressed before
- 4:56they become a threat
- 4:58and are exploited so a vulnerability is
- 5:02a weakness in a system
- 5:03or its design that could be exploited by
- 5:07a threat
- 5:08okay so next is a threat
- 5:11trapped is a potential danger to a
- 5:13company's assets
- 5:15data and network functionality
- 5:19exploit is a mechanism that takes
- 5:21advantage of the vulnerability
- 5:25next is mitigation so mitigation
- 5:28techniques
- 5:29are required before during and after an
- 5:32attack
- 5:33okay so mitigation is the counter
- 5:36measure that reduces the likelihood
- 5:38of severity of a potential trip
- 5:41or risk so network security involves
- 5:44multiple mitigation techniques
- 5:47okay so the last one is risk
- 5:51risk is the likelihood of a threat to
- 5:53exploit the vulnerability
- 5:56of an asset with an aim of
- 5:59negatively affecting an organization so
- 6:02risk is measured
- 6:04using the probability of occurrence
- 6:07of an event and its consequences
- 6:13okay so next would be vectors of
- 6:17network attacks so an attack
- 6:20is a path by which a threat actor
- 6:24can gain access to a server host
- 6:27or a network okay so attack vectors
- 6:30originate from
- 6:31inside or outside the corporate network
- 6:35as shown in the figure here so we've got
- 6:37external threat
- 6:39and internal threat and this is our
- 6:41compromised
- 6:42host for example threat actors may
- 6:46target a network
- 6:47through the internet to disrupt network
- 6:50operations
- 6:51and create denial of service or dos
- 6:53attack
- 6:55okay so these threats are
- 6:58shown here internal or external
- 7:02so take note that a dos or denial of
- 7:05service attack occurs
- 7:06when a network device or application is
- 7:09incapacitated
- 7:11and no longer capable of supporting
- 7:12requests from a legitimate
- 7:15okay so an internal user such as an
- 7:19employee
- 7:20can accidentally or intentionally steal
- 7:23and copy confidential data
- 7:25to removable media email messaging
- 7:28software
- 7:29and other media so compromise
- 7:32internal servers or network
- 7:34infrastructure devices
- 7:36or disconnect a critical network
- 7:38connection
- 7:39and cause a network outage
- 7:43so it could be connecting an infected
- 7:45usb drive
- 7:46into a corporate computer system
- 7:49okay so internal threats have the
- 7:51potential to cause
- 7:52greater damage than external threats
- 7:55because internal users
- 7:57have direct access to the building and
- 8:00its infrastructure devices
- 8:02so employees students may also have
- 8:05knowledge of the corporate network
- 8:08each resources and its confidential data
- 8:12so network security professionals must
- 8:14implement tools
- 8:15and apply techniques for mitigating both
- 8:18external
- 8:20okay and internal threats
- 8:26okay so the next one is data loss okay
- 8:29so data is likely to be an
- 8:31organization's most
- 8:32valuable asset so organizational data
- 8:35can include research and development
- 8:37data
- 8:38sales data financial data human resource
- 8:42and
- 8:42legal data employee data contractor data
- 8:45and customer data so data loss or
- 8:49data exfiltration is when data is
- 8:53intentionally
- 8:54or unintentionally lost stolen
- 8:57or leaked to the outside world so the
- 9:00data loss can result in
- 9:02brand damage and loss of reputation
- 9:06loss of competitive advantage loss of
- 9:09customers
- 9:10loss of revenue okay litigation
- 9:14or legal action resulting in fines and
- 9:17civil penalties
- 9:19or significant cost and effort to notify
- 9:22affected parties
- 9:23and recover from the bridge
- 9:28so network security professionals must
- 9:30protect organizations data
- 9:33so various data loss prevention or dlp
- 9:36controls must be implemented which
- 9:38combines strategic
- 9:40operational and tactical measures
- 9:46okay now these are the common data loss
- 9:48of vectors
- 9:50okay so which displays on this table so
- 9:52this includes
- 9:53email or social networking unencrypted
- 9:56devices
- 9:57cloud storage devices removable media
- 10:01hard copy and improper access control
- 10:05okay
- 10:08okay so on the next section we will be
- 10:10talking about the threat upwards so what
- 10:12are these
- 10:12threat actors in security
- 10:15okay now in the previous topic you
- 10:18gained a high level look
- 10:20at the current landscape of cyber
- 10:22security
- 10:24so including the types of threats and
- 10:26vulnerabilities that
- 10:27block all network administrators and
- 10:30architects okay
- 10:32now in this topic you will learn more
- 10:35details about particular types of
- 10:37threat actors okay so hacker
- 10:41is a common term used to describe
- 10:44attractor
- 10:46so as shown in this table here the terms
- 10:49white hot hacker okay you've got the
- 10:52black hat hacker
- 10:53and the gray hat hacker are often used
- 10:56to describe
- 10:57a type of hacker okay so when you say
- 11:00white hat hacker
- 11:02these are ethical hackers who use their
- 11:04programming skills for good
- 11:06ethical and legal purposes
- 11:10okay so security vulnerabilities are
- 11:12reported to
- 11:13developers for them to fix before the
- 11:16vulnerabilities
- 11:17can be exploited okay
- 11:20so the next one are the great uh gray
- 11:23hat hackers
- 11:24who are they okay so these are
- 11:26individuals
- 11:27who commit crimes and do arguably
- 11:30unethical things
- 11:32okay but not for personal gain or
- 11:35to cause damage gray hat hackers may
- 11:38disclose a vulnerability
- 11:40to the affected organization after
- 11:42having compromised their system
- 11:45okay and the last one is a black hat
- 11:48hackers
- 11:49so these are an ethical criminals who
- 11:51compromise
- 11:53computer and network security for
- 11:54personal gain or
- 11:56for malicious reasons such as attacking
- 11:59the networks
- 12:01okay now in this course we will use them
- 12:05okay the term hacker outside of this
- 12:08module okay
- 12:10so we will use the term chat actor
- 12:13so the term threat actor includes
- 12:15hackers
- 12:16okay but that actor also includes any
- 12:19device
- 12:20person group or nation state
- 12:23that is intentionally or unintentionally
- 12:26the source of an attack
- 12:28okay
- 12:32all right so let's take a look at the
- 12:35evolution of a hacker
- 12:37or hackers so hacking started the 1960s
- 12:40with prone freaking or breaking
- 12:44okay which refers to using audio
- 12:46frequencies to manipulate phone systems
- 12:49so at that time telephone switches used
- 12:52various tones to indicate different
- 12:54functions
- 12:55early hackers realized that by mimicking
- 12:58a tone
- 12:59using a whistle they could exploit the
- 13:01phone switches to make three long
- 13:03distance calls
- 13:04right now in the mid 1980s
- 13:07computer dial up modems were used to
- 13:09connect computers to the networks
- 13:12so hackers wrote word dialing programs
- 13:15which dialed each number or telephone
- 13:18number
- 13:18in a given area in search for computers
- 13:22so when a computer was found password
- 13:24cracking programs were used to gain
- 13:26access
- 13:28so this table here displays the modern
- 13:30hacking terms
- 13:31and brief description of it so this
- 13:34includes script kiddies
- 13:36so when you say script kitties these are
- 13:38teenagers or inexperienced hackers
- 13:41running existing scripts tools and
- 13:44exploits to
- 13:45cause harm but typically not for profit
- 13:49okay so sort of okay starters
- 13:52so our script kit is okay so the next
- 13:55one
- 13:56are vulnerability brokers
- 13:59okay so these are usually gray hat
- 14:02hackers
- 14:03who attempt to discover exploits
- 14:06and report them to vendors sometimes for
- 14:09prizes or
- 14:10rewards okay so the next term
- 14:13would be activists so these are grey hat
- 14:17hackers who publicly protests
- 14:19organizations or governments
- 14:21by posting articles videos leaking
- 14:24sensitive information
- 14:25and performing network attacks okay
- 14:29so the next hacking term is cyber
- 14:30criminals
- 14:32these are black uh hot hoppers
- 14:35who are either self-employed or working
- 14:37for large cyber crime organization
- 14:40okay and the next one would be the state
- 14:43sponsored
- 14:44so these are either white hat or black
- 14:47hat hackers
- 14:48who still government secrets gather
- 14:51intelligence and sabotage networks
- 14:54so their targets are foreign governments
- 14:57terrorist groups and corporations
- 15:00so most countries in the world
- 15:02participate to some degree
- 15:04in state-sponsored hacking
- 15:08okay so the next term would be cyber
- 15:11criminals
- 15:13so it is estimated that cyber criminals
- 15:15steal billions of dollars from consumers
- 15:17and businesses
- 15:19okay cyber criminals operate in an
- 15:22underground economy
- 15:24where they buy sell and trade attack
- 15:26toolkits
- 15:27zero day exploit code okay botnet
- 15:30services
- 15:31banking trojans key bloggers
- 15:36or key lagers and much more so they also
- 15:39buy and sell the private information
- 15:41and intellectual property they can still
- 15:43or they still
- 15:45so cyber criminals target small
- 15:47businesses and consumers
- 15:48as well as large enterprises and entire
- 15:52industries okay so
- 15:55activists two examples of activist
- 15:58groups are anonymous and the syrian
- 16:02electronic army
- 16:04okay although most hacktivist groups are
- 16:07not well organized
- 16:08they can cause significant problems for
- 16:10governments and
- 16:11businesses so activists tend to rely
- 16:16on fairly basic freely available
- 16:19tools okay
- 16:22so next would be the state-sponsored
- 16:25hackers
- 16:26so state-sponsored hackers create
- 16:29advanced
- 16:29customized attack code often using
- 16:32previously undiscovered software
- 16:35is called the zero-day vulnerabilities
- 16:38so an example of the state-sponsored
- 16:40attack involves
- 16:42the stuxnet malware okay so that was
- 16:45created to damage iran's
- 16:46nuclear enrichment capabilities
- 16:50all right okay so next section
- 16:54will cover threat actor tools so what
- 16:57are the different tools
- 16:58used by these threat actors okay
- 17:02so introduction to attack tools so to
- 17:06exploit vulnerability
- 17:07a threat actor must have a technique or
- 17:10tool
- 17:11so over the years attack tools have
- 17:13become more sophisticated and highly
- 17:15automated
- 17:17so these new tools require less
- 17:19technical knowledge
- 17:20to implement okay now referring on the
- 17:23table or diagram here
- 17:25okay so we can see that
- 17:29it shows a bar with sophistication of
- 17:33attack tools okay on the left
- 17:36and a bar with technical knowledge on
- 17:39the right
- 17:40okay so in 1985
- 17:43as time passed by so the sophistication
- 17:46of attack grow
- 17:47into a required technical knowledge
- 17:49diminished
- 17:58okay
- 18:00okay so next would be the evolution of
- 18:03the security tools
- 18:04okay so ethical hacking involves many
- 18:08different types of tools
- 18:09used to test the network and keep its
- 18:12data secure so
- 18:14to validate the security of a network
- 18:16and its systems
- 18:18many network penetration testing tools
- 18:21have been developed
- 18:22so it is unfortunate that many of these
- 18:26tools can be used by black hot
- 18:28hackers for expectation okay
- 18:31so black hat hackers can also have
- 18:33created many hacking tools
- 18:37so these tools are created explicitly
- 18:40for nefarious reasons so white hat
- 18:43hackers
- 18:44must also know how to use these tools
- 18:47when performing network penetration
- 18:49testing
- 18:51okay now this includes password trackers
- 18:55okay the wireless hacking tools the
- 18:58network scanning and hacking tools
- 19:00packet crafting tools and packet
- 19:03sniffers
- 19:04okay now this table highlights the
- 19:07categories of common penetration testing
- 19:09tools
- 19:10notice that okay how some tools are used
- 19:14by white hats
- 19:15and black hats so keep in mind that the
- 19:18list
- 19:19is not exhaustive as new tools
- 19:22are always being developed okay
- 19:25so password crackers example includes
- 19:29uh lovecraft okay thc hydra
- 19:33the rainbow crack medusa gender reaper
- 19:36okay so those are all password trackers
- 19:40so password tracking tools are often
- 19:42referred to as
- 19:43a password recovery tools and can be
- 19:46used to crack or recover the password
- 19:49so password crackers repeatedly make
- 19:52guesses
- 19:52in order to crack the passwords okay
- 19:55so the next one is wireless hacking
- 19:58tools
- 20:00so the wireless hacking tools are used
- 20:02intentionally hacked
- 20:03into a wireless okay to detect
- 20:07security vulnerabilities so example
- 20:10of wireless hacking tools include the
- 20:12aircracking
- 20:14kismet the in ssider
- 20:17his mac fire chip and the buy stumbler
- 20:22okay so the next penetration testing
- 20:24tool is
- 20:25network scanning and hacking tools so
- 20:28network scanning tools are used to prove
- 20:30network devices servers and hosts
- 20:34for open tcp or udp
- 20:37okay so examples of scanning tools
- 20:39include nmap
- 20:40super scan angry ip scanner and
- 20:44net scan tools okay so
- 20:47next tool would be a packet crafting
- 20:49tools
- 20:50these tools are used to probe and test a
- 20:53firewall robustness
- 20:54using specifically crafted first packets
- 20:58examples includes hping scapi
- 21:02socat okay garcinia
- 21:05netcat and ping and nemesis
- 21:09you also have the packet sniffers so
- 21:12these tools are used to capture and
- 21:13analyze
- 21:14packets with traditional internet lands
- 21:16or wireless lands
- 21:18so tools include wireshark okay so tc
- 21:21dump
- 21:21easter cup dsnif okay so easter ape
- 21:26arrows fiddler flat proxy
- 21:30and ssl strip
- 21:33right so also
- 21:37take note that many of these tools are
- 21:39unix or linux based
- 21:41so therefore a security professional
- 21:43should have a strong unix and linux
- 21:45background
- 21:46okay so also included are the rootkit
- 21:49detectors
- 21:51so this is a directory and file
- 21:52integrity checker
- 21:54used by white hats to detect installed
- 21:57root kits
- 21:58so example tools includes the aide
- 22:03net filter and pf open bsd packet filter
- 22:08so next would be the fuzzers okay to
- 22:11search vulnerabilities
- 22:12so fuzzers are tools used by threat
- 22:16actors
- 22:17to discover a computer security
- 22:19vulnerabilities
- 22:20examples of others include skip fish
- 22:24pt and w3af
- 22:27okay you also have forensic tools these
- 22:30tools
- 22:30are used by white hat hackers to sniff
- 22:33out any trace of evidence existing in a
- 22:37computer
- 22:38so example of tools include this luth
- 22:41kit
- 22:42helix multago and
- 22:45in case all right so debugger tools or
- 22:48debugger penetration tools are also
- 22:50available so these tools are used
- 22:52by black hat hackers okay
- 22:55to reverse engineer binary files when
- 22:58writing exploits
- 23:00so they are also used by white hat when
- 23:03analyzing malwares
- 23:05so debugging tools include gdb
- 23:08win dbg ida pro
- 23:12and immunity debugger so hacking
- 23:15operating systems
- 23:17so these are specially designed
- 23:19operating systems reloaded with tools
- 23:22optimized for hacking so examples of
- 23:26specially designed hacking operating
- 23:27systems includes kali linux and
- 23:29blackbox linux okay
- 23:33so next would be the encryption tools so
- 23:35encryption tools use algorithm schemes
- 23:38to encode the data to prevent
- 23:40unauthorized access
- 23:42to the encrypted data so examples of
- 23:44these tools includes
- 23:46veracrypt a cybershed open ssh open ssl
- 23:51tor open vpn and stunner
- 23:55okay you also have the vulnerability
- 23:57explicit exploitation tools
- 24:00these tools identify whether a remote
- 24:03host is
- 24:04vulnerable to security attack so
- 24:06examples of vulnerability exploitation
- 24:08tools include the metal exploit
- 24:12core impact sql map social engineer
- 24:15toolkit
- 24:16and netsparker
- 24:20next would be vulnerability scanners so
- 24:23these tools can
- 24:25scan a network or system to identify
- 24:28open ports so they can also be used to
- 24:31scan
- 24:32for known vulnerabilities and scan vms
- 24:36byod devices and client databases
- 24:39so examples of tools includes nipper
- 24:42or impact nexus or nesus
- 24:46saint and open pass right so again
- 24:51take note that many of these tools here
- 24:53are unix or linux based systems so
- 24:56therefore
- 24:56a security professional should have a
- 24:58strong unix
- 25:00and linux background
- 25:04all right so next would be
- 25:07attack types okay so threat actors can
- 25:11use
- 25:11the previously mentioned attack tools or
- 25:14a combination of tools
- 25:16to create attacks so the table displays
- 25:19common types of attacks
- 25:21however the list of attacks is not
- 25:23exhaustive
- 25:25as new attack vulnerabilities are
- 25:27constantly being discovered
- 25:29okay so this includes if dropping attack
- 25:32data modification attack ip address
- 25:35proofing attack
- 25:36password based attacks denial of service
- 25:39attack
- 25:40man in the middle attack compromised ski
- 25:42attack and sniffer attack
- 25:44okay so it's dropping this is when a
- 25:48trap
- 25:48actor captures and listens to network
- 25:51traffic
- 25:52so this attack is referred to as
- 25:54sniffing
- 25:55or snooping okay so next one would be
- 25:59the data modification attack
- 26:01so if threat actors have captured
- 26:04enterprise traffic
- 26:06they can alter the data in the packet
- 26:08without the knowledge of the sender or
- 26:10the receiver
- 26:13so ip address spoofing attack is a chat
- 26:15actor constructs
- 26:17an ip packet that appears to originate
- 26:20from a valid address
- 26:21inside the corporate internet okay
- 26:24when you say password-based attacks so
- 26:27if
- 26:28threat actors discover a valid user
- 26:30account
- 26:31the threat actors have the same rights
- 26:34as the real
- 26:34user so threat actors could use that
- 26:38valid account to obtain
- 26:40list of other users network information
- 26:44change server and network configurations
- 26:47and modify reroute or delete data
- 26:51okay the denial of service attack
- 26:54a dos attack prevents normal use of a
- 26:57computer
- 26:58or network by valid users so a dos
- 27:02attack can flood the computer or the
- 27:04entire network with traffic
- 27:06until a shutdown occurs because of the
- 27:09overloading
- 27:11so a dos or denial of service attack can
- 27:14also block traffic
- 27:16which results in a loss of access
- 27:19to network resources by authorized users
- 27:23okay now man in the middle attack this
- 27:26attack
- 27:27occurs when threat actors have
- 27:30positioned themselves between the source
- 27:32and destination
- 27:34okay so they can now actively monitor
- 27:36capture
- 27:38and control the communication
- 27:40transparently
- 27:43next would be the compromised key attack
- 27:46so if a chat actor obtains a secret key
- 27:50that key is referred to as an
- 27:51accomplished or compromised key
- 27:54okay a compromise key can be used to
- 27:57gain access
- 27:58to a secured communication without the
- 28:00sender or receiver
- 28:02being aware of the attack okay
- 28:05so next would be sniffing attack
- 28:08so a sniffer is an application or device
- 28:11that can read
- 28:12monitor and capture network data
- 28:14exchanges and read network packets
- 28:18so if the packets are not encrypted a
- 28:20sniffer provides a full view
- 28:23of the data inside the packet
- 28:30all right so on this section we will be
- 28:32talking about
- 28:33malwares okay what is a malware
- 28:37so now that you know about the tools
- 28:40that hacker use
- 28:41this topic introduces you to different
- 28:44types of malware
- 28:45that hackers use to gain access to end
- 28:48devices
- 28:50okay so end devices are particularly
- 28:53prone to malware attacks
- 28:54so it is important to know about malware
- 28:57because threat actors rely on users to
- 29:00install malware
- 29:01to help exploit the security gaps okay
- 29:05so the primary vulnerabilities for an
- 29:08end-user workstations
- 29:09are viruses okay a worm
- 29:13and trojan horses okay so as shown on
- 29:16this
- 29:17diagram here okay so when you say virus
- 29:21virus is a malicious software which
- 29:23executes a specific unwanted
- 29:26and often harmful function on a computer
- 29:30so the next one would be worm okay
- 29:33worm executes arbitrary codes and
- 29:36install copies of itself in the memory
- 29:38of the infected computers so the main
- 29:41purpose of worm
- 29:42is to automatically replicate itself and
- 29:45spread across the network from system to
- 29:46system
- 29:48so the next one is a trojan horse okay
- 29:52this is a non-self replicating type of
- 29:55malware
- 29:56it often contains malicious code that is
- 29:59designed to look like something else
- 30:01such as legitimate application or file
- 30:04okay
- 30:05so when an infected application or file
- 30:07is downloaded and opened
- 30:09the trojan horse can attack the end
- 30:12device
- 30:12from within okay
- 30:18all right so viruses and trojan horses
- 30:22so the first and most common type of
- 30:24computer malware is a virus
- 30:26so viruses requires human action to
- 30:29propagate
- 30:30and infect other computers for example
- 30:33a virus can infect a computer when a
- 30:35victim opens an email attachment
- 30:38opens a file on a usb drive or downloads
- 30:41a file
- 30:43all right so the virus has
- 30:46by attacking or attaching itself to a
- 30:48computer code
- 30:50software or documents on the computer
- 30:53so when opened the virus executes and
- 30:56infects
- 30:57the entire computer systems okay so
- 31:00viruses can alter corrupt delete files
- 31:04or erase the enter drives okay
- 31:07it can cause computer booting issues and
- 31:09corrupt applications
- 31:11it can capture and send sensitive
- 31:13information to threat actors
- 31:16access and use email accounts to spread
- 31:19and lay dormant until someone by attract
- 31:22actor
- 31:24all right
- 31:28okay so modern viruses are developed for
- 31:31specific intent such as those listed in
- 31:33the table here
- 31:34okay so you've got the boot sector virus
- 31:36the firmware viruses
- 31:38macro virus program viruses and script
- 31:41viruses okay now a boot sector virus
- 31:45a virus attacks the boot sector
- 31:48partition or file partition table
- 31:50or the file system of the hard drives
- 31:53okay
- 31:53when you say firmware viruses this virus
- 31:56attacks the device
- 31:59okay macro viruses uses the ms office
- 32:04macro feature maliciously
- 32:06so program viruses virus inserts itself
- 32:09in another executable program so this is
- 32:11the most common type of
- 32:13virus okay you also have script viruses
- 32:17virus attacks the os interpreter
- 32:20which is used to execute scripts
- 32:28okay so chat actors use trojan horses to
- 32:31compromise
- 32:32hosts so a trojan horse is a program
- 32:36that looks useful but also carries
- 32:39malicious code
- 32:40so trojan horses are often provided with
- 32:43free online programs such as computer
- 32:45games
- 32:46okay so unsuspecting users download and
- 32:49install the game
- 32:50along with the trojan course
- 32:53right now there are several types of
- 32:56trojan horses as described in this table
- 32:58so this includes remote access data
- 33:01sending
- 33:01destructive proxy ftp security software
- 33:05disabler
- 33:06the denial of service and the key logger
- 33:10okay so trojan
- 33:14okay or trojan horse enables
- 33:15unauthorized remote access
- 33:17that is remote access type of trojan
- 33:19horse
- 33:20now data sending trojan horse provides
- 33:23the threat actor with sensitive data
- 33:26such as passwords
- 33:27okay destructive trojan horse corrupts
- 33:31or deletes
- 33:32files proxy trojan horse
- 33:35will use the victim's computer as the
- 33:38source device
- 33:39to launch attacks and perform other
- 33:41illegal activities
- 33:44okay ftp trojan horse trojan horse
- 33:47enables unauthorized file transfer
- 33:50services
- 33:50and end devices so security software
- 33:54disabler
- 33:55trojan horses stops antivirus programs
- 33:58or firewalls
- 33:59from functioning okay so denial of
- 34:03service
- 34:04trojan horse slows or halt network
- 34:06activity
- 34:08and the last one is key lager trojan
- 34:10horse actively attempts to steal
- 34:12confidential information such as credit
- 34:14card numbers
- 34:15or credit card information by recording
- 34:18keystrokes entered
- 34:20into a web form okay so viruses and
- 34:23trojan horses
- 34:24are the only two types of malware that
- 34:27actors use
- 34:29there are many other types of malware
- 34:30that can have been designed
- 34:33for specific purposes
- 34:36all right
- 34:39okay so other types of malware so this
- 34:42includes adware
- 34:43ransomware rootkit spyware and
- 34:46worm okay now adware
- 34:50is usually distributed by downloading
- 34:52online software
- 34:53so adware can display unsolicited
- 34:55advertising
- 34:57using pop-up web browsers windows
- 34:59neutral bars
- 35:00or unexpectedly redirect web page to a
- 35:04different website
- 35:05okay so ransomware typically denies a
- 35:09user access
- 35:10to their files by encrypting the files
- 35:12and then displaying a message
- 35:14demanding for a ransom for the
- 35:16decryption key
- 35:18so users without up-to-date backup must
- 35:21pay the ransom to decrypt the files
- 35:24okay so payment is usually made using
- 35:26wire transfer or the cryptocurrency such
- 35:29as a bitcoin
- 35:31okay so the next one is rootkit
- 35:34so rootkits are used by threat actors to
- 35:37gain administrators account level access
- 35:39to their computer
- 35:40so there are or they are very difficult
- 35:44to detect because they can alter
- 35:46firewall
- 35:47antivirus protection system files or
- 35:50even the os commands
- 35:52to conceal their presence okay
- 35:55so spyware like adwire but
- 35:58used to gather information about the
- 36:01user
- 36:02and send to threat actors without the
- 36:05user's consent
- 36:07so spyware can be low threat gathering
- 36:10browsing data
- 36:11or it can be a high threat capturing
- 36:13personal or financial information
- 36:17so the last one would be worm so worm is
- 36:20a self-replicating program that
- 36:22propagates
- 36:23automatically without the user's actions
- 36:25by exploiting vulnerabilities in
- 36:27legitimate software
- 36:29so it uses the network to search other
- 36:32victims
- 36:33with the same vulnerability so the
- 36:36intent of warm
- 36:37is usually to slow or disrupt network
- 36:40operations
- 36:46okay so let's talk about the common
- 36:48network attacks
- 36:54so let's start with an overview of the
- 36:57common network attacks
- 36:58so as you have learned there are many
- 37:00types of malware
- 37:02that hackers can use okay so but these
- 37:05are not the only ways that they can
- 37:07attack a network
- 37:08or even an organization so when malware
- 37:12is delivered and installed
- 37:14so the payload can be used to cause a
- 37:16variety of network related attacks
- 37:18so to mitigate attacks it is useful to
- 37:21understand
- 37:22the types of attacks okay so that is by
- 37:25categorizing network attacks
- 37:28it is possible to address types of
- 37:30attacks rather than individual attacks
- 37:33okay so networks are susceptible to the
- 37:36following types of attacks
- 37:37so you've got the reconnaissance attacks
- 37:40access attacks
- 37:41and dos or denial of service attacks
- 37:46okay so for the reconnaissance attack
- 37:50so reconnaissance is simply information
- 37:52gathering
- 37:53okay so it is analogous to achieve
- 37:57surveying a neighborhood by going door
- 38:00to door
- 38:01pretending to sell something okay so
- 38:04what the tif is actually doing is
- 38:06looking for vulnerable homes
- 38:09okay so to break into such us and
- 38:11occupied residences
- 38:13residences with easy to open doors or
- 38:16windows
- 38:17and those residences without security
- 38:19systems or security cameras
- 38:21okay now trap actors use
- 38:24reconnaissance or recon attacks to do an
- 38:28authorized discovery and mapping of
- 38:30systems
- 38:30services and vulnerabilities so recon
- 38:34attacks
- 38:34precede access attacks or the denial of
- 38:38service attack
- 38:41okay so some of the techniques
- 38:44used by malicious threat actors to
- 38:46conduct reconnaissance attacks are
- 38:48described in this table
- 38:49okay so perform information query
- 38:53of a target so with this one the threat
- 38:56actor is looking for initial information
- 38:58about
- 38:59target so various tools can be used
- 39:02including google search organization
- 39:05websites
- 39:06who is and more okay so the second
- 39:09technique is to initiate a ping sweep
- 39:12of the target network so the information
- 39:15query usually reveals the target network
- 39:18address
- 39:18okay the threat actors can now initiate
- 39:22a ping sweep to determine which ip
- 39:25addresses
- 39:26are active okay so
- 39:29next technique would be initiate a port
- 39:31scan
- 39:32of active ip address okay so this is
- 39:35used to determine
- 39:37which ports or services are available so
- 39:41of port scanners include nmap super scan
- 39:44angry ip scanner and net scan tools
- 39:48okay so the next one of the run
- 39:51vulnerability scanners
- 39:53so this is the query the identified
- 39:55ports
- 39:56to determine the type and version of the
- 39:58application and operating system
- 40:01that is running on the host so examples
- 40:03of tools
- 40:05includes a nipper a core impact
- 40:10nasus saint and open
- 40:13bas okay so
- 40:16the last one would be run exploitation
- 40:18tools
- 40:20so the threat actors now attempts to
- 40:22discover vulnerable services
- 40:24that can be exploited so a variety of
- 40:27vulnerability exploitation tools
- 40:30exist including you've got the
- 40:32metasploit
- 40:34core core impact the sql map
- 40:38social engineer toolkit and not spara
- 40:41not sparker
- 40:46all right so some of the techniques used
- 40:49by malicious threat actors to conduct
- 40:51reconnaissance
- 40:52attacks are described on this table here
- 40:54okay
- 40:55so let's have the first one which is
- 40:57perform an initial
- 40:59or information query of a target
- 41:02okay now in the figure here
- 41:06it shows a threat actor using the
- 41:08application
- 41:09who is okay or who is command to find
- 41:12information about the target
- 41:15all right so the next technique that was
- 41:19mentioned earlier was to initiate a ping
- 41:22sweep
- 41:22to the target network okay this is
- 41:26performing being
- 41:27swept so the figure here okay
- 41:30shows a threat actor doing a pink sweep
- 41:34of the target's network address to
- 41:37determine or discover
- 41:39live and active ip addresses
- 41:43all right okay
- 41:46so the next one would be initiate a port
- 41:49scan
- 41:50of active ip addresses now
- 41:53take note that from the diagram or from
- 41:54the figure here it shows a threat actor
- 41:57performing a port scan onto discovered
- 42:01active ip
- 42:02address using nmap right so
- 42:05nmap is the tool that is used by this
- 42:08um threat actor all right
- 42:13okay so next thing is the
- 42:16access attacks right so access attacks
- 42:20exploits known vulnerabilities in
- 42:22authentication services
- 42:24ftp services and web services
- 42:27so the purpose of this types of attack
- 42:29is to gain entry
- 42:31to web accounts confidential databases
- 42:34and other sensitive information
- 42:36so threat actors use access attacks
- 42:40on network devices and computers to
- 42:43retrieve
- 42:43data gain access or to escalate access
- 42:47privileges
- 42:48to administrator status okay
- 42:52so this includes password attack
- 42:56okay spoofing attack okay and other
- 42:59attacks
- 42:59all right so like uh trust exploitations
- 43:04port redirections man in the middle
- 43:06attacks and
- 43:07buffer flow or buffer overflow attacks
- 43:12all right so in the password attacks
- 43:14okay in a password attack
- 43:16the threat actor attempts to discover
- 43:18critical system passwords
- 43:19using various methods so password
- 43:22attacks are very common
- 43:24and can be launched using a variety of
- 43:26password tracking tools
- 43:28okay now for spoofing attack
- 43:31so in spoofing attacks the threat actor
- 43:33device attempts to pose
- 43:35as another device by falsifying data
- 43:39so common spoofing attacks includes ip
- 43:42spoofing
- 43:43mac address spoofing and dcp spoofing
- 43:48so this spoofing attacks will be
- 43:50discussed in more detail
- 43:52later on this video lecture
- 43:58okay so let's take
- 44:02the other attacks okay so which includes
- 44:05trust exploitations okay
- 44:09now trust exploitation in this diagram
- 44:12here
- 44:13in a trust exploitation attack attract
- 44:16actor uses unauthorized privileges
- 44:20to gain access to the system okay
- 44:23possibly compromising the target
- 44:26all right so take note that in this
- 44:29diagram
- 44:30okay our figure so refer to the figure
- 44:34to view an example of trust exploitation
- 44:36here
- 44:38okay so take a look at this threat actor
- 44:40trying to access
- 44:42devices all right they're compromised
- 44:44devices
- 44:46using the username
- 44:49all right and he's trying to attack
- 44:52systems a
- 44:53right so and systems b
- 44:57take note that systems a trust systems b
- 45:00and system b here trusts everyone
- 45:04okay so we call it the trust
- 45:06exploitation
- 45:08all right so we're in the user or the
- 45:11attacker or that actor uses an
- 45:13authorized privileges
- 45:14to gain access to the system okay
- 45:18so the next one would be port
- 45:20exploitation
- 45:21okay now in a port exploitation or port
- 45:24redirection
- 45:26okay so we call it port redirection
- 45:28attack
- 45:29a threat actor uses a compromised system
- 45:33as base for attacks against other
- 45:35targets
- 45:37so the example in the figure shows a
- 45:39threat actor
- 45:40using ssh or the secure
- 45:43shell port 22 to connect to the
- 45:46compromised
- 45:47host a okay now host a is trusted by
- 45:51host b
- 45:52and therefore all right the threat actor
- 45:56can use
- 45:56telnet port 23 to access it
- 46:00so we call it port redirection
- 46:03okay so next would be
- 46:07money in the medial attacks or the mitm
- 46:11okay now money in the middle attack
- 46:14the threat actor is positioned between
- 46:17the two legitimate
- 46:19entities in order to read or modify the
- 46:22data
- 46:23that passes between the two parties so
- 46:26the figure here displays an example
- 46:28of the mitm or the man in the middle
- 46:30attack
- 46:32all right okay
- 46:36so the next one would be a buffer
- 46:38overflow attacks
- 46:40okay now in a buffer overflow attack the
- 46:43threat
- 46:43actor exploits the buffer memory
- 46:46and overwhelms it with unexpected values
- 46:50so this is or usually
- 46:53okay renders the system inoperable for
- 46:56creating a denial of service or dos
- 46:59attack
- 47:00okay now the figure here shows
- 47:03that the threat actor is sending
- 47:06many packets to the victim in an attempt
- 47:09to overflow the victim's
- 47:11buffer okay so we call it buffer
- 47:14overflow
- 47:15attacks
- 47:19all right so next one would be
- 47:22social engineering attacks
- 47:26so social engineering is a process
- 47:30or is an access attack that attempts to
- 47:32manipulate individuals into performing
- 47:35actions
- 47:36or divulging confidential information
- 47:39so some social engineering techniques
- 47:43okay are performed in person
- 47:47right while others may use telephone or
- 47:51the internet so social engineers
- 47:54often rely on people's willingness to be
- 47:57helpful
- 47:58right they also prey on people's
- 48:01weaknesses for example so a threat actor
- 48:05could call
- 48:06an authorized employee okay with an
- 48:09urgent problem that requires immediate
- 48:11network access
- 48:13so the threat actor would appeal to the
- 48:15employee's
- 48:16vanity okay so
- 48:20invoking the authority using name
- 48:23dropping techniques
- 48:25or appeal to the employee's grid
- 48:29all right so that is social engineering
- 48:32attacks
- 48:34now information about social engineering
- 48:35techniques is shown in this table
- 48:38so this includes pre-texting
- 48:41okay so attract actor pretends to need
- 48:44personal or financial data
- 48:46to confirm the identity of the recipient
- 48:49so we call it
- 48:50pre-texting okay you also have pissing
- 48:54a threat actor sends a fraudulent email
- 48:57which is disguised as being from a
- 49:00legitimate
- 49:01trusted source to trick the recipient
- 49:04into installing malware on their device
- 49:07or to share personal or financial
- 49:10information
- 49:12okay you also have a spearfishing
- 49:16a threat actor creates a targeted vision
- 49:19attack
- 49:20tailored for the specific individual or
- 49:23organization
- 49:24okay so this one is common spam
- 49:28okay so also known as junk mail this
- 49:31is unsolicited email which often
- 49:34contains harmful links
- 49:36malware or deceptive content
- 49:40okay so something for something
- 49:43sometimes called kid pulco
- 49:46right so kid pro this
- 49:49is when a chat actor requests
- 49:53personal information from a party in
- 49:55exchange of
- 49:57or in exchange for something such as
- 49:58gift or favor
- 50:00all right so next is baiting
- 50:04a threat actor leaves a malware infected
- 50:07flash
- 50:08drive in a public location so a victim
- 50:11finds the drive and unsuspectingly
- 50:14inserts
- 50:15it into their laptop unintentionally
- 50:17installing malware
- 50:19all right so that's upbeating so next
- 50:22would be
- 50:23impersonation okay so this type of
- 50:26attack is
- 50:27where the threat actor pretends to be
- 50:29someone
- 50:30they are not to gain the trust of a
- 50:33victim
- 50:34okay so tailgating this is where the
- 50:37threat actor quickly follows an
- 50:39authorized person okay into a secure
- 50:43location to gain access to a secure
- 50:45area tailgating okay so the next one is
- 50:48shoulder surfing okay so shoulder
- 50:52surfing
- 50:52this is where the threat actor can
- 50:55conspicuously look or looks over
- 50:58someone's shoulder
- 51:00to steal their passwords or other
- 51:02information
- 51:03okay and the last one would be dumpster
- 51:06diving
- 51:07this is where a threat actor
- 51:10rummages to trust beans to discover
- 51:14confidential documents
- 51:16all right
- 51:20okay so what are the recommended social
- 51:24engineering protection practices
- 51:27okay so the social engineering toolkit
- 51:30or set was designed to help white
- 51:33hackers or white hot hackers
- 51:35and other network security professionals
- 51:38create a social engineering attacks
- 51:40to test their own networks okay
- 51:43so enterprises must educate their users
- 51:47about the risk of social engineering and
- 51:50develop strategies
- 51:51to validate identities over the phone
- 51:54via email
- 51:55or in person so the figure here shows a
- 51:59recommended practices
- 52:00that should be followed by all the users
- 52:04okay so this includes
- 52:08okay so like always destroy confidential
- 52:11information
- 52:12according to organization policy
- 52:15never give user name or password
- 52:18credentials to anyone
- 52:20all right so never leave your username
- 52:23password credentials
- 52:25where they can easily be found never
- 52:29open
- 52:29emails from untrusted sources
- 52:32okay never release work related
- 52:35information
- 52:36on the social media sites never reuse
- 52:40work related passwords okay
- 52:43always lock and sign out
- 52:47of your computer when unattended
- 52:50and always report suspicious individuals
- 52:53so these are just some of the
- 52:55recommendations okay
- 52:58and protection against a social
- 53:01engineering
- 53:02attacks
- 53:06okay so the next one would be dos or
- 53:08denial of service
- 53:10and you've got the ddos or the
- 53:12distributed denial of service
- 53:15so a denial of service or u.s attack
- 53:18creates
- 53:18some sort of interruption of network
- 53:21services to the users
- 53:22devices or applications so these are the
- 53:25two major types of the dos attack
- 53:28you've got overwhelming quantity of
- 53:30traffic and
- 53:31maliciously formatted packets okay
- 53:35now overwhelming quantity of traffic the
- 53:38threat actor sends an enormous quantity
- 53:41of data
- 53:42at a rate that the network host or
- 53:44application cannot handle
- 53:46so this causes transmission response
- 53:49okay
- 53:50to slow down so it can also crash
- 53:53a device or a service so the next one
- 53:57is maliciously formatted packets so the
- 54:00threat actor
- 54:01sends a maliciously formatted packet to
- 54:03a host or application
- 54:05and the receiver is unable to handle
- 54:10to handle that okay so this causes the
- 54:12receiving device
- 54:14to run very slowly or crash
- 54:19okay now for the
- 54:23dos attack so dos attacks are the major
- 54:26risk
- 54:27okay because they interrupt
- 54:30communication and cause significant loss
- 54:33of time and money
- 54:34so these attacks are relatively simple
- 54:37okay so to conduct
- 54:39even if by unskilled chat actor
- 54:43okay so something like this threat actor
- 54:46here
- 54:46sends so many pings to the server okay
- 54:50and the server can respond to anyone
- 54:52else
- 54:53all right so you are flooding the server
- 54:56with inquiries or ping so that they
- 54:58cannot respond
- 55:00to other inquiries from the hosts or
- 55:02from other uh
- 55:03clients here okay
- 55:07now when you say distributed denial of
- 55:10service attack or ddos
- 55:12this is similar to the os attack okay so
- 55:14but it originates
- 55:16from multiple coordinated sources
- 55:19so for example okay so a threat
- 55:23actor builds a network of infected uh
- 55:26hosts
- 55:27known as zombies right so the threat
- 55:30actor uses the command and controller
- 55:33cnc
- 55:34to send control messages to the zombies
- 55:37now the zombies constantly scan
- 55:40and infect more hosts with both
- 55:44malware now the bot malware
- 55:48okay is designed to infect a host
- 55:51making it a zombie that can communicate
- 55:54with the cnc or the command and control
- 55:57now the collection of zombies is called
- 55:59botnet
- 56:00all right so when ready the threat actor
- 56:04instructs the cnc
- 56:06or the command and control to make the
- 56:09botnet of
- 56:10zombies carry out the distributed denial
- 56:13of service
- 56:15all right
- 56:19okay so on this section we will be
- 56:21talking about
- 56:22ip vulnerabilities and trends
- 56:27okay now ipb4 and ipv6
- 56:30so ip does not validate whether the
- 56:32source ip address contained in a packet
- 56:35actually came from that source
- 56:38for this reason threat actors can send
- 56:41packets using a spoofed source ip
- 56:43address
- 56:45threat actors can also tamper with other
- 56:48fields
- 56:48in the ip header to carry out their
- 56:51attacks
- 56:52so security analysts most
- 56:55understand or must understand the
- 56:56different fields in both the ipb4 and
- 56:59ipv6 headers
- 57:01okay now some of the more common ip
- 57:05related attacks
- 57:06are shown on this table so you've got
- 57:08icmp attacks
- 57:11amplification and reflection attacks
- 57:14address proofing attacks money in the
- 57:17middle attacks
- 57:18and session hijacking okay
- 57:22now for icmp attacks threat actors use
- 57:25the icmp
- 57:27or the internet control message protocol
- 57:30echo packets or pings to discover
- 57:33subnets and hosts
- 57:34on a protected network so that is to
- 57:36generate the denial of service of floods
- 57:38attacks
- 57:40and to alter host routing tables
- 57:44so next would be amplification and
- 57:47reflection attacks
- 57:48so trap actors attempts to prevent
- 57:51legitimate users
- 57:53from accessing information or services
- 57:56using the denial
- 57:57and denial or distributed denial of
- 58:00service attacks
- 58:02okay so next would be address spoofing
- 58:05attacks
- 58:06now threat actors poof the source ip
- 58:09address
- 58:10in an ip packet to perform blind
- 58:12spoofing
- 58:13or non-blind spoofing
- 58:16man in the middle as mentioned earlier
- 58:18in the previous slides
- 58:20threat actors positioned themselves
- 58:22between the source
- 58:23and the destination to transparently
- 58:26monitor
- 58:27capture and control the communication
- 58:30so they could absorb by inspecting
- 58:33captured packets or
- 58:35alter packets and forward them to their
- 58:38original destination
- 58:41all right so the last one would be the
- 58:43session hijacking
- 58:45threat actors gain access to the
- 58:48physical network
- 58:50and then use the mit-m or the man in the
- 58:53middle attack
- 58:54to hijack a session
- 59:00all right so for the icmp attacks so
- 59:02trap actors use icmb
- 59:04or icmp for reconnaissance and scanning
- 59:08attacks
- 59:09so they can launch information gathering
- 59:11attacks to map
- 59:12out a network topology discover
- 59:16which hosts are active or reachable
- 59:19identify the host operating system or os
- 59:22fingerprinting
- 59:23and determine the state of the firewall
- 59:26so threat actors
- 59:27also use icmp for the denial of service
- 59:31attacks
- 59:32okay so take note that icmp for ipv4 or
- 59:36icmp
- 59:37version 4 and icmp for version 6 or ipv6
- 59:43or the known as the icmp b6
- 59:46are susceptible to similar types of
- 59:48attack
- 59:49so networks should have a strict icmp
- 59:53access control list or acl filtering
- 59:57on the network edge to avoid icmp
- 1:00:00probing
- 1:00:01from the internet okay so security
- 1:00:05analysts
- 1:00:06should be able to detect icmp related
- 1:00:09attacks
- 1:00:10by looking at captured traffic and lag
- 1:00:12piles
- 1:00:15right so in the case of the large
- 1:00:17network
- 1:00:18security devices such as a firewall and
- 1:00:21intrusion detection systems or ids
- 1:00:24detect such attacks and generate alerts
- 1:00:27to the security
- 1:00:29analysts
- 1:00:32all right so this table here
- 1:00:36shows the common icmp messages of
- 1:00:38interest
- 1:00:39to threat actors all right and this
- 1:00:42includes
- 1:00:43icmp echo request and echo reply
- 1:00:46which is used to perform host
- 1:00:48verification and
- 1:00:50denial of service attacks okay
- 1:00:53you also have the icmp unreachable this
- 1:00:56is used to perform network
- 1:00:57reconnaissance and scanning attacks
- 1:01:01icmp mask reply this is used to map an
- 1:01:04internal ip network
- 1:01:07icmp redirects right so this is used to
- 1:01:10lure
- 1:01:11a target host into ascending
- 1:01:14all traffic to a compromised device
- 1:01:18and create a man in the middle attack
- 1:01:22okay so the last one would be icmp
- 1:01:24router discovery
- 1:01:27so this is used to inject bogus route
- 1:01:30entries
- 1:01:30into the routing table of a target hosts
- 1:01:36okay now let's focus on the
- 1:01:40amplification and reflection attacks
- 1:01:43okay now trap actors often use
- 1:01:46amplification and reflection techniques
- 1:01:49to create dos attacks
- 1:01:52now the example in the figure right so
- 1:01:55illustrates
- 1:01:56how an amplification and reflection
- 1:01:59technique
- 1:02:00called smurf attack is used to overwhelm
- 1:02:03a target host
- 1:02:05okay so this um amplification and
- 1:02:08reflection technique
- 1:02:10is also known as the smurf attack okay
- 1:02:13now let us define the amplification okay
- 1:02:16so amplification the threat actor
- 1:02:19forwards icmp
- 1:02:21echo request messages to many hosts
- 1:02:25okay this messages contains the source
- 1:02:28ip address of the victim
- 1:02:31reflection this hosts reply
- 1:02:34to the spoofed ip address of the victim
- 1:02:38to overwhelm it okay so these are the
- 1:02:41replies here
- 1:02:43okay so take note that newer forms of
- 1:02:46amplification
- 1:02:47and reflection attacks such as dns based
- 1:02:51reflection and amplification attacks and
- 1:02:53network time
- 1:02:54protocol or ntp amplification attacks
- 1:02:57are now being used
- 1:02:59okay so threat actors also use resource
- 1:03:02exhaustion attacks
- 1:03:04these attacks consume the resources of
- 1:03:07the target host to either
- 1:03:09the grassroot or to consume the
- 1:03:11resources
- 1:03:12of a network
- 1:03:15okay so next would be address spoofing
- 1:03:19attack
- 1:03:20so ip address boofing attack occurs
- 1:03:23when a chat actor creates a packet with
- 1:03:26full source ip address information
- 1:03:29to either hide the identity of the
- 1:03:31sender or
- 1:03:32to pose as another legitimate user
- 1:03:36okay so the threat actor can then gain
- 1:03:39access
- 1:03:40to otherwise inaccessible data
- 1:03:43or circumvent security configuration
- 1:03:47spoofing is usually incorporated into
- 1:03:49another attack
- 1:03:51such as the smurf attack
- 1:03:56okay now spoofing attacks can be
- 1:03:59non-blind or blind
- 1:04:02okay so non-blind spoofing
- 1:04:06the threat actor can see the traffic
- 1:04:08that is being sent
- 1:04:10between the host and the target
- 1:04:13so the threat actor uses non-blind
- 1:04:15spoofing
- 1:04:16to inspect the reply packet from the
- 1:04:18target victim
- 1:04:20so non-blind spoofing determines the
- 1:04:23state of a firewall
- 1:04:25and sequence number prediction so it can
- 1:04:28also hijack
- 1:04:29an authorized session okay
- 1:04:33now when you say blind spoofing the
- 1:04:36threat actor cannot see the traffic that
- 1:04:38is being sent
- 1:04:39between the host and the target so blind
- 1:04:42spoofing is used
- 1:04:44in the os attack so mac address spoofing
- 1:04:47attacks
- 1:04:48are used when target or threat actors
- 1:04:51have access to the internal network okay
- 1:04:55now trap actors alter the mac address of
- 1:04:58their host
- 1:04:59to match another known mac address of a
- 1:05:02target host
- 1:05:04so the attacking host then sends a frame
- 1:05:08throughout the network with the newly
- 1:05:10configured mac address
- 1:05:12so when the switch receives the frame it
- 1:05:15examines the source
- 1:05:17mac address alright
- 1:05:23okay so we have here an example threat
- 1:05:26actors
- 1:05:26poof a server's mac address okay
- 1:05:30now the switch here overrides the
- 1:05:33current cam table entry
- 1:05:35and assigns the mac address to the new
- 1:05:38port
- 1:05:39okay now it then forward the frames
- 1:05:42this thing for the target host to the
- 1:05:45attacking host
- 1:05:48all right next the switch
- 1:05:51updates the cam table with spoofed
- 1:05:54address
- 1:05:55so application or service spoofing is
- 1:05:58another spoofing example
- 1:06:00so a threat actor can connect
- 1:06:04a rogue hip server okay
- 1:06:08to create the man in the middle attack
- 1:06:11or the mitm condition
- 1:06:17so thanks for watching and listening
- 1:06:20so this would be the end of part one
- 1:06:24of this module see you on part two
About this transcript
This page contains the full transcript of ENSA M3 Network Security Concepts Part 1 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 7,665 words across 1,591 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.