YouTube2Text

ENSA M3 Network Security Concepts Part 1 — Transcript

by Santelmo · 7,665 words · 1,591 segments · language en · Watch on YouTube

Full transcript

  1. 0:03[Music]
  2. 0:15hi hello there
  3. 0:17welcome to network security concepts
  4. 0:20this video lecture are divided into two
  5. 0:22segments
  6. 0:23okay so you've got part one and part two
  7. 0:27on the next video so perhaps you have
  8. 0:30learned and heard about hundreds of
  9. 0:32news stories about data security bridge
  10. 0:36within a large corporation or even a
  11. 0:39government
  12. 0:40was your credit card number exposed by a
  13. 0:42bridge
  14. 0:44your private health information would
  15. 0:47you like to know how to prevent these
  16. 0:49data breaches so the field of network
  17. 0:52security is growing every day
  18. 0:55this module provides a detailed
  19. 0:57landscape
  20. 0:58of the types of cybercrime and the many
  21. 1:01ways we have to fight back against cyber
  22. 1:04criminals
  23. 1:05let's get started
  24. 1:08okay so for the part one of this video
  25. 1:10lecture so
  26. 1:12we will be talking about these topics
  27. 1:14here
  28. 1:15current state of the cyber security
  29. 1:18threat actors malware common network
  30. 1:21attacks and ip vulnerabilities in
  31. 1:23threats
  32. 1:25okay now for the module objective okay
  33. 1:28so at the end of this video lecture
  34. 1:30for part one and part two you should be
  35. 1:32able to explain
  36. 1:33how vulnerabilities threats and exploits
  37. 1:37can be mitigated to enhance network
  38. 1:39security
  39. 1:42okay so before we start let's have this
  40. 1:45ethical hacking statement
  41. 1:47so in this module learners may be
  42. 1:49exposed to tools and techniques in a
  43. 1:51sandbox
  44. 1:52virtual machine environment to
  45. 1:54demonstrate various types of cyber
  46. 1:56attacks
  47. 1:58experimentation with this tools
  48. 2:00techniques
  49. 2:01and resources is at the discretion of
  50. 2:03the instructor
  51. 2:04and local institution so if the learner
  52. 2:08is considering using attack tools for
  53. 2:10educational purposes
  54. 2:11they should contact their instructor
  55. 2:13prior to an experimentation
  56. 2:16so an authorized process okay or access
  57. 2:19the data
  58. 2:20computer and network systems is a crime
  59. 2:23in many jurisdictions
  60. 2:25and often is accompanied by severe
  61. 2:28consequences
  62. 2:29regardless of the perpetrator's
  63. 2:31motivations
  64. 2:33so it is the learner's responsibility as
  65. 2:35the user of this material
  66. 2:37to be cognizant of end the complaint
  67. 2:41with computer use
  68. 2:42laws
  69. 2:46okay so let's start with the first
  70. 2:49section
  71. 2:50of this part one of the video let's talk
  72. 2:52about the current state of the cyber
  73. 2:54security
  74. 2:55[Music]
  75. 2:56okay so cyber criminals now have the
  76. 3:00expertise and tools necessary
  77. 3:03to take down critical infrastructure and
  78. 3:05systems
  79. 3:07so their tools and techniques continue
  80. 3:09to evolve
  81. 3:11so cyber criminals are taking malware
  82. 3:14to unprecedented levels of
  83. 3:16sophistication and impact
  84. 3:18okay so they are more adept at using
  85. 3:22stealth
  86. 3:23and evasion techniques to hide their
  87. 3:25activity
  88. 3:27lastly cyber criminals are exploiting
  89. 3:30undependent gaps
  90. 3:31in security so network
  91. 3:34security bridges can disrupt e-commerce
  92. 3:38cause the loss of business data threaten
  93. 3:41people's privacy and compromise the
  94. 3:43integrity of information
  95. 3:45so these bridges can result in lost
  96. 3:48revenue for corporations theft of
  97. 3:51intellectual property lawsuits and can
  98. 3:55even threaten public safety
  99. 3:57[Music]
  100. 3:58so maintaining a network or a secure
  101. 4:01network
  102. 4:02ensures that safety for network users
  103. 4:04and protects commercial interests
  104. 4:07so organization need individuals who can
  105. 4:10recognize the speed and skill
  106. 4:13at which adversaries are amassing
  107. 4:17and refining their cyber weak boundary
  108. 4:20so
  109. 4:20all the users should be aware of
  110. 4:22security terms
  111. 4:24in the table here okay so you've
  112. 4:27got assets vulnerability threat
  113. 4:30exploit mitigation and risk
  114. 4:34so when you say assets assets must be
  115. 4:37identified
  116. 4:37and protected okay so
  117. 4:41this has something to do with anything
  118. 4:43of value to the organization
  119. 4:46it indicates or it includes people
  120. 4:49equipment resources and data
  121. 4:52so next is vulnerability so
  122. 4:54vulnerabilities must be addressed before
  123. 4:56they become a threat
  124. 4:58and are exploited so a vulnerability is
  125. 5:02a weakness in a system
  126. 5:03or its design that could be exploited by
  127. 5:07a threat
  128. 5:08okay so next is a threat
  129. 5:11trapped is a potential danger to a
  130. 5:13company's assets
  131. 5:15data and network functionality
  132. 5:19exploit is a mechanism that takes
  133. 5:21advantage of the vulnerability
  134. 5:25next is mitigation so mitigation
  135. 5:28techniques
  136. 5:29are required before during and after an
  137. 5:32attack
  138. 5:33okay so mitigation is the counter
  139. 5:36measure that reduces the likelihood
  140. 5:38of severity of a potential trip
  141. 5:41or risk so network security involves
  142. 5:44multiple mitigation techniques
  143. 5:47okay so the last one is risk
  144. 5:51risk is the likelihood of a threat to
  145. 5:53exploit the vulnerability
  146. 5:56of an asset with an aim of
  147. 5:59negatively affecting an organization so
  148. 6:02risk is measured
  149. 6:04using the probability of occurrence
  150. 6:07of an event and its consequences
  151. 6:13okay so next would be vectors of
  152. 6:17network attacks so an attack
  153. 6:20is a path by which a threat actor
  154. 6:24can gain access to a server host
  155. 6:27or a network okay so attack vectors
  156. 6:30originate from
  157. 6:31inside or outside the corporate network
  158. 6:35as shown in the figure here so we've got
  159. 6:37external threat
  160. 6:39and internal threat and this is our
  161. 6:41compromised
  162. 6:42host for example threat actors may
  163. 6:46target a network
  164. 6:47through the internet to disrupt network
  165. 6:50operations
  166. 6:51and create denial of service or dos
  167. 6:53attack
  168. 6:55okay so these threats are
  169. 6:58shown here internal or external
  170. 7:02so take note that a dos or denial of
  171. 7:05service attack occurs
  172. 7:06when a network device or application is
  173. 7:09incapacitated
  174. 7:11and no longer capable of supporting
  175. 7:12requests from a legitimate
  176. 7:15okay so an internal user such as an
  177. 7:19employee
  178. 7:20can accidentally or intentionally steal
  179. 7:23and copy confidential data
  180. 7:25to removable media email messaging
  181. 7:28software
  182. 7:29and other media so compromise
  183. 7:32internal servers or network
  184. 7:34infrastructure devices
  185. 7:36or disconnect a critical network
  186. 7:38connection
  187. 7:39and cause a network outage
  188. 7:43so it could be connecting an infected
  189. 7:45usb drive
  190. 7:46into a corporate computer system
  191. 7:49okay so internal threats have the
  192. 7:51potential to cause
  193. 7:52greater damage than external threats
  194. 7:55because internal users
  195. 7:57have direct access to the building and
  196. 8:00its infrastructure devices
  197. 8:02so employees students may also have
  198. 8:05knowledge of the corporate network
  199. 8:08each resources and its confidential data
  200. 8:12so network security professionals must
  201. 8:14implement tools
  202. 8:15and apply techniques for mitigating both
  203. 8:18external
  204. 8:20okay and internal threats
  205. 8:26okay so the next one is data loss okay
  206. 8:29so data is likely to be an
  207. 8:31organization's most
  208. 8:32valuable asset so organizational data
  209. 8:35can include research and development
  210. 8:37data
  211. 8:38sales data financial data human resource
  212. 8:42and
  213. 8:42legal data employee data contractor data
  214. 8:45and customer data so data loss or
  215. 8:49data exfiltration is when data is
  216. 8:53intentionally
  217. 8:54or unintentionally lost stolen
  218. 8:57or leaked to the outside world so the
  219. 9:00data loss can result in
  220. 9:02brand damage and loss of reputation
  221. 9:06loss of competitive advantage loss of
  222. 9:09customers
  223. 9:10loss of revenue okay litigation
  224. 9:14or legal action resulting in fines and
  225. 9:17civil penalties
  226. 9:19or significant cost and effort to notify
  227. 9:22affected parties
  228. 9:23and recover from the bridge
  229. 9:28so network security professionals must
  230. 9:30protect organizations data
  231. 9:33so various data loss prevention or dlp
  232. 9:36controls must be implemented which
  233. 9:38combines strategic
  234. 9:40operational and tactical measures
  235. 9:46okay now these are the common data loss
  236. 9:48of vectors
  237. 9:50okay so which displays on this table so
  238. 9:52this includes
  239. 9:53email or social networking unencrypted
  240. 9:56devices
  241. 9:57cloud storage devices removable media
  242. 10:01hard copy and improper access control
  243. 10:05okay
  244. 10:08okay so on the next section we will be
  245. 10:10talking about the threat upwards so what
  246. 10:12are these
  247. 10:12threat actors in security
  248. 10:15okay now in the previous topic you
  249. 10:18gained a high level look
  250. 10:20at the current landscape of cyber
  251. 10:22security
  252. 10:24so including the types of threats and
  253. 10:26vulnerabilities that
  254. 10:27block all network administrators and
  255. 10:30architects okay
  256. 10:32now in this topic you will learn more
  257. 10:35details about particular types of
  258. 10:37threat actors okay so hacker
  259. 10:41is a common term used to describe
  260. 10:44attractor
  261. 10:46so as shown in this table here the terms
  262. 10:49white hot hacker okay you've got the
  263. 10:52black hat hacker
  264. 10:53and the gray hat hacker are often used
  265. 10:56to describe
  266. 10:57a type of hacker okay so when you say
  267. 11:00white hat hacker
  268. 11:02these are ethical hackers who use their
  269. 11:04programming skills for good
  270. 11:06ethical and legal purposes
  271. 11:10okay so security vulnerabilities are
  272. 11:12reported to
  273. 11:13developers for them to fix before the
  274. 11:16vulnerabilities
  275. 11:17can be exploited okay
  276. 11:20so the next one are the great uh gray
  277. 11:23hat hackers
  278. 11:24who are they okay so these are
  279. 11:26individuals
  280. 11:27who commit crimes and do arguably
  281. 11:30unethical things
  282. 11:32okay but not for personal gain or
  283. 11:35to cause damage gray hat hackers may
  284. 11:38disclose a vulnerability
  285. 11:40to the affected organization after
  286. 11:42having compromised their system
  287. 11:45okay and the last one is a black hat
  288. 11:48hackers
  289. 11:49so these are an ethical criminals who
  290. 11:51compromise
  291. 11:53computer and network security for
  292. 11:54personal gain or
  293. 11:56for malicious reasons such as attacking
  294. 11:59the networks
  295. 12:01okay now in this course we will use them
  296. 12:05okay the term hacker outside of this
  297. 12:08module okay
  298. 12:10so we will use the term chat actor
  299. 12:13so the term threat actor includes
  300. 12:15hackers
  301. 12:16okay but that actor also includes any
  302. 12:19device
  303. 12:20person group or nation state
  304. 12:23that is intentionally or unintentionally
  305. 12:26the source of an attack
  306. 12:28okay
  307. 12:32all right so let's take a look at the
  308. 12:35evolution of a hacker
  309. 12:37or hackers so hacking started the 1960s
  310. 12:40with prone freaking or breaking
  311. 12:44okay which refers to using audio
  312. 12:46frequencies to manipulate phone systems
  313. 12:49so at that time telephone switches used
  314. 12:52various tones to indicate different
  315. 12:54functions
  316. 12:55early hackers realized that by mimicking
  317. 12:58a tone
  318. 12:59using a whistle they could exploit the
  319. 13:01phone switches to make three long
  320. 13:03distance calls
  321. 13:04right now in the mid 1980s
  322. 13:07computer dial up modems were used to
  323. 13:09connect computers to the networks
  324. 13:12so hackers wrote word dialing programs
  325. 13:15which dialed each number or telephone
  326. 13:18number
  327. 13:18in a given area in search for computers
  328. 13:22so when a computer was found password
  329. 13:24cracking programs were used to gain
  330. 13:26access
  331. 13:28so this table here displays the modern
  332. 13:30hacking terms
  333. 13:31and brief description of it so this
  334. 13:34includes script kiddies
  335. 13:36so when you say script kitties these are
  336. 13:38teenagers or inexperienced hackers
  337. 13:41running existing scripts tools and
  338. 13:44exploits to
  339. 13:45cause harm but typically not for profit
  340. 13:49okay so sort of okay starters
  341. 13:52so our script kit is okay so the next
  342. 13:55one
  343. 13:56are vulnerability brokers
  344. 13:59okay so these are usually gray hat
  345. 14:02hackers
  346. 14:03who attempt to discover exploits
  347. 14:06and report them to vendors sometimes for
  348. 14:09prizes or
  349. 14:10rewards okay so the next term
  350. 14:13would be activists so these are grey hat
  351. 14:17hackers who publicly protests
  352. 14:19organizations or governments
  353. 14:21by posting articles videos leaking
  354. 14:24sensitive information
  355. 14:25and performing network attacks okay
  356. 14:29so the next hacking term is cyber
  357. 14:30criminals
  358. 14:32these are black uh hot hoppers
  359. 14:35who are either self-employed or working
  360. 14:37for large cyber crime organization
  361. 14:40okay and the next one would be the state
  362. 14:43sponsored
  363. 14:44so these are either white hat or black
  364. 14:47hat hackers
  365. 14:48who still government secrets gather
  366. 14:51intelligence and sabotage networks
  367. 14:54so their targets are foreign governments
  368. 14:57terrorist groups and corporations
  369. 15:00so most countries in the world
  370. 15:02participate to some degree
  371. 15:04in state-sponsored hacking
  372. 15:08okay so the next term would be cyber
  373. 15:11criminals
  374. 15:13so it is estimated that cyber criminals
  375. 15:15steal billions of dollars from consumers
  376. 15:17and businesses
  377. 15:19okay cyber criminals operate in an
  378. 15:22underground economy
  379. 15:24where they buy sell and trade attack
  380. 15:26toolkits
  381. 15:27zero day exploit code okay botnet
  382. 15:30services
  383. 15:31banking trojans key bloggers
  384. 15:36or key lagers and much more so they also
  385. 15:39buy and sell the private information
  386. 15:41and intellectual property they can still
  387. 15:43or they still
  388. 15:45so cyber criminals target small
  389. 15:47businesses and consumers
  390. 15:48as well as large enterprises and entire
  391. 15:52industries okay so
  392. 15:55activists two examples of activist
  393. 15:58groups are anonymous and the syrian
  394. 16:02electronic army
  395. 16:04okay although most hacktivist groups are
  396. 16:07not well organized
  397. 16:08they can cause significant problems for
  398. 16:10governments and
  399. 16:11businesses so activists tend to rely
  400. 16:16on fairly basic freely available
  401. 16:19tools okay
  402. 16:22so next would be the state-sponsored
  403. 16:25hackers
  404. 16:26so state-sponsored hackers create
  405. 16:29advanced
  406. 16:29customized attack code often using
  407. 16:32previously undiscovered software
  408. 16:35is called the zero-day vulnerabilities
  409. 16:38so an example of the state-sponsored
  410. 16:40attack involves
  411. 16:42the stuxnet malware okay so that was
  412. 16:45created to damage iran's
  413. 16:46nuclear enrichment capabilities
  414. 16:50all right okay so next section
  415. 16:54will cover threat actor tools so what
  416. 16:57are the different tools
  417. 16:58used by these threat actors okay
  418. 17:02so introduction to attack tools so to
  419. 17:06exploit vulnerability
  420. 17:07a threat actor must have a technique or
  421. 17:10tool
  422. 17:11so over the years attack tools have
  423. 17:13become more sophisticated and highly
  424. 17:15automated
  425. 17:17so these new tools require less
  426. 17:19technical knowledge
  427. 17:20to implement okay now referring on the
  428. 17:23table or diagram here
  429. 17:25okay so we can see that
  430. 17:29it shows a bar with sophistication of
  431. 17:33attack tools okay on the left
  432. 17:36and a bar with technical knowledge on
  433. 17:39the right
  434. 17:40okay so in 1985
  435. 17:43as time passed by so the sophistication
  436. 17:46of attack grow
  437. 17:47into a required technical knowledge
  438. 17:49diminished
  439. 17:58okay
  440. 18:00okay so next would be the evolution of
  441. 18:03the security tools
  442. 18:04okay so ethical hacking involves many
  443. 18:08different types of tools
  444. 18:09used to test the network and keep its
  445. 18:12data secure so
  446. 18:14to validate the security of a network
  447. 18:16and its systems
  448. 18:18many network penetration testing tools
  449. 18:21have been developed
  450. 18:22so it is unfortunate that many of these
  451. 18:26tools can be used by black hot
  452. 18:28hackers for expectation okay
  453. 18:31so black hat hackers can also have
  454. 18:33created many hacking tools
  455. 18:37so these tools are created explicitly
  456. 18:40for nefarious reasons so white hat
  457. 18:43hackers
  458. 18:44must also know how to use these tools
  459. 18:47when performing network penetration
  460. 18:49testing
  461. 18:51okay now this includes password trackers
  462. 18:55okay the wireless hacking tools the
  463. 18:58network scanning and hacking tools
  464. 19:00packet crafting tools and packet
  465. 19:03sniffers
  466. 19:04okay now this table highlights the
  467. 19:07categories of common penetration testing
  468. 19:09tools
  469. 19:10notice that okay how some tools are used
  470. 19:14by white hats
  471. 19:15and black hats so keep in mind that the
  472. 19:18list
  473. 19:19is not exhaustive as new tools
  474. 19:22are always being developed okay
  475. 19:25so password crackers example includes
  476. 19:29uh lovecraft okay thc hydra
  477. 19:33the rainbow crack medusa gender reaper
  478. 19:36okay so those are all password trackers
  479. 19:40so password tracking tools are often
  480. 19:42referred to as
  481. 19:43a password recovery tools and can be
  482. 19:46used to crack or recover the password
  483. 19:49so password crackers repeatedly make
  484. 19:52guesses
  485. 19:52in order to crack the passwords okay
  486. 19:55so the next one is wireless hacking
  487. 19:58tools
  488. 20:00so the wireless hacking tools are used
  489. 20:02intentionally hacked
  490. 20:03into a wireless okay to detect
  491. 20:07security vulnerabilities so example
  492. 20:10of wireless hacking tools include the
  493. 20:12aircracking
  494. 20:14kismet the in ssider
  495. 20:17his mac fire chip and the buy stumbler
  496. 20:22okay so the next penetration testing
  497. 20:24tool is
  498. 20:25network scanning and hacking tools so
  499. 20:28network scanning tools are used to prove
  500. 20:30network devices servers and hosts
  501. 20:34for open tcp or udp
  502. 20:37okay so examples of scanning tools
  503. 20:39include nmap
  504. 20:40super scan angry ip scanner and
  505. 20:44net scan tools okay so
  506. 20:47next tool would be a packet crafting
  507. 20:49tools
  508. 20:50these tools are used to probe and test a
  509. 20:53firewall robustness
  510. 20:54using specifically crafted first packets
  511. 20:58examples includes hping scapi
  512. 21:02socat okay garcinia
  513. 21:05netcat and ping and nemesis
  514. 21:09you also have the packet sniffers so
  515. 21:12these tools are used to capture and
  516. 21:13analyze
  517. 21:14packets with traditional internet lands
  518. 21:16or wireless lands
  519. 21:18so tools include wireshark okay so tc
  520. 21:21dump
  521. 21:21easter cup dsnif okay so easter ape
  522. 21:26arrows fiddler flat proxy
  523. 21:30and ssl strip
  524. 21:33right so also
  525. 21:37take note that many of these tools are
  526. 21:39unix or linux based
  527. 21:41so therefore a security professional
  528. 21:43should have a strong unix and linux
  529. 21:45background
  530. 21:46okay so also included are the rootkit
  531. 21:49detectors
  532. 21:51so this is a directory and file
  533. 21:52integrity checker
  534. 21:54used by white hats to detect installed
  535. 21:57root kits
  536. 21:58so example tools includes the aide
  537. 22:03net filter and pf open bsd packet filter
  538. 22:08so next would be the fuzzers okay to
  539. 22:11search vulnerabilities
  540. 22:12so fuzzers are tools used by threat
  541. 22:16actors
  542. 22:17to discover a computer security
  543. 22:19vulnerabilities
  544. 22:20examples of others include skip fish
  545. 22:24pt and w3af
  546. 22:27okay you also have forensic tools these
  547. 22:30tools
  548. 22:30are used by white hat hackers to sniff
  549. 22:33out any trace of evidence existing in a
  550. 22:37computer
  551. 22:38so example of tools include this luth
  552. 22:41kit
  553. 22:42helix multago and
  554. 22:45in case all right so debugger tools or
  555. 22:48debugger penetration tools are also
  556. 22:50available so these tools are used
  557. 22:52by black hat hackers okay
  558. 22:55to reverse engineer binary files when
  559. 22:58writing exploits
  560. 23:00so they are also used by white hat when
  561. 23:03analyzing malwares
  562. 23:05so debugging tools include gdb
  563. 23:08win dbg ida pro
  564. 23:12and immunity debugger so hacking
  565. 23:15operating systems
  566. 23:17so these are specially designed
  567. 23:19operating systems reloaded with tools
  568. 23:22optimized for hacking so examples of
  569. 23:26specially designed hacking operating
  570. 23:27systems includes kali linux and
  571. 23:29blackbox linux okay
  572. 23:33so next would be the encryption tools so
  573. 23:35encryption tools use algorithm schemes
  574. 23:38to encode the data to prevent
  575. 23:40unauthorized access
  576. 23:42to the encrypted data so examples of
  577. 23:44these tools includes
  578. 23:46veracrypt a cybershed open ssh open ssl
  579. 23:51tor open vpn and stunner
  580. 23:55okay you also have the vulnerability
  581. 23:57explicit exploitation tools
  582. 24:00these tools identify whether a remote
  583. 24:03host is
  584. 24:04vulnerable to security attack so
  585. 24:06examples of vulnerability exploitation
  586. 24:08tools include the metal exploit
  587. 24:12core impact sql map social engineer
  588. 24:15toolkit
  589. 24:16and netsparker
  590. 24:20next would be vulnerability scanners so
  591. 24:23these tools can
  592. 24:25scan a network or system to identify
  593. 24:28open ports so they can also be used to
  594. 24:31scan
  595. 24:32for known vulnerabilities and scan vms
  596. 24:36byod devices and client databases
  597. 24:39so examples of tools includes nipper
  598. 24:42or impact nexus or nesus
  599. 24:46saint and open pass right so again
  600. 24:51take note that many of these tools here
  601. 24:53are unix or linux based systems so
  602. 24:56therefore
  603. 24:56a security professional should have a
  604. 24:58strong unix
  605. 25:00and linux background
  606. 25:04all right so next would be
  607. 25:07attack types okay so threat actors can
  608. 25:11use
  609. 25:11the previously mentioned attack tools or
  610. 25:14a combination of tools
  611. 25:16to create attacks so the table displays
  612. 25:19common types of attacks
  613. 25:21however the list of attacks is not
  614. 25:23exhaustive
  615. 25:25as new attack vulnerabilities are
  616. 25:27constantly being discovered
  617. 25:29okay so this includes if dropping attack
  618. 25:32data modification attack ip address
  619. 25:35proofing attack
  620. 25:36password based attacks denial of service
  621. 25:39attack
  622. 25:40man in the middle attack compromised ski
  623. 25:42attack and sniffer attack
  624. 25:44okay so it's dropping this is when a
  625. 25:48trap
  626. 25:48actor captures and listens to network
  627. 25:51traffic
  628. 25:52so this attack is referred to as
  629. 25:54sniffing
  630. 25:55or snooping okay so next one would be
  631. 25:59the data modification attack
  632. 26:01so if threat actors have captured
  633. 26:04enterprise traffic
  634. 26:06they can alter the data in the packet
  635. 26:08without the knowledge of the sender or
  636. 26:10the receiver
  637. 26:13so ip address spoofing attack is a chat
  638. 26:15actor constructs
  639. 26:17an ip packet that appears to originate
  640. 26:20from a valid address
  641. 26:21inside the corporate internet okay
  642. 26:24when you say password-based attacks so
  643. 26:27if
  644. 26:28threat actors discover a valid user
  645. 26:30account
  646. 26:31the threat actors have the same rights
  647. 26:34as the real
  648. 26:34user so threat actors could use that
  649. 26:38valid account to obtain
  650. 26:40list of other users network information
  651. 26:44change server and network configurations
  652. 26:47and modify reroute or delete data
  653. 26:51okay the denial of service attack
  654. 26:54a dos attack prevents normal use of a
  655. 26:57computer
  656. 26:58or network by valid users so a dos
  657. 27:02attack can flood the computer or the
  658. 27:04entire network with traffic
  659. 27:06until a shutdown occurs because of the
  660. 27:09overloading
  661. 27:11so a dos or denial of service attack can
  662. 27:14also block traffic
  663. 27:16which results in a loss of access
  664. 27:19to network resources by authorized users
  665. 27:23okay now man in the middle attack this
  666. 27:26attack
  667. 27:27occurs when threat actors have
  668. 27:30positioned themselves between the source
  669. 27:32and destination
  670. 27:34okay so they can now actively monitor
  671. 27:36capture
  672. 27:38and control the communication
  673. 27:40transparently
  674. 27:43next would be the compromised key attack
  675. 27:46so if a chat actor obtains a secret key
  676. 27:50that key is referred to as an
  677. 27:51accomplished or compromised key
  678. 27:54okay a compromise key can be used to
  679. 27:57gain access
  680. 27:58to a secured communication without the
  681. 28:00sender or receiver
  682. 28:02being aware of the attack okay
  683. 28:05so next would be sniffing attack
  684. 28:08so a sniffer is an application or device
  685. 28:11that can read
  686. 28:12monitor and capture network data
  687. 28:14exchanges and read network packets
  688. 28:18so if the packets are not encrypted a
  689. 28:20sniffer provides a full view
  690. 28:23of the data inside the packet
  691. 28:30all right so on this section we will be
  692. 28:32talking about
  693. 28:33malwares okay what is a malware
  694. 28:37so now that you know about the tools
  695. 28:40that hacker use
  696. 28:41this topic introduces you to different
  697. 28:44types of malware
  698. 28:45that hackers use to gain access to end
  699. 28:48devices
  700. 28:50okay so end devices are particularly
  701. 28:53prone to malware attacks
  702. 28:54so it is important to know about malware
  703. 28:57because threat actors rely on users to
  704. 29:00install malware
  705. 29:01to help exploit the security gaps okay
  706. 29:05so the primary vulnerabilities for an
  707. 29:08end-user workstations
  708. 29:09are viruses okay a worm
  709. 29:13and trojan horses okay so as shown on
  710. 29:16this
  711. 29:17diagram here okay so when you say virus
  712. 29:21virus is a malicious software which
  713. 29:23executes a specific unwanted
  714. 29:26and often harmful function on a computer
  715. 29:30so the next one would be worm okay
  716. 29:33worm executes arbitrary codes and
  717. 29:36install copies of itself in the memory
  718. 29:38of the infected computers so the main
  719. 29:41purpose of worm
  720. 29:42is to automatically replicate itself and
  721. 29:45spread across the network from system to
  722. 29:46system
  723. 29:48so the next one is a trojan horse okay
  724. 29:52this is a non-self replicating type of
  725. 29:55malware
  726. 29:56it often contains malicious code that is
  727. 29:59designed to look like something else
  728. 30:01such as legitimate application or file
  729. 30:04okay
  730. 30:05so when an infected application or file
  731. 30:07is downloaded and opened
  732. 30:09the trojan horse can attack the end
  733. 30:12device
  734. 30:12from within okay
  735. 30:18all right so viruses and trojan horses
  736. 30:22so the first and most common type of
  737. 30:24computer malware is a virus
  738. 30:26so viruses requires human action to
  739. 30:29propagate
  740. 30:30and infect other computers for example
  741. 30:33a virus can infect a computer when a
  742. 30:35victim opens an email attachment
  743. 30:38opens a file on a usb drive or downloads
  744. 30:41a file
  745. 30:43all right so the virus has
  746. 30:46by attacking or attaching itself to a
  747. 30:48computer code
  748. 30:50software or documents on the computer
  749. 30:53so when opened the virus executes and
  750. 30:56infects
  751. 30:57the entire computer systems okay so
  752. 31:00viruses can alter corrupt delete files
  753. 31:04or erase the enter drives okay
  754. 31:07it can cause computer booting issues and
  755. 31:09corrupt applications
  756. 31:11it can capture and send sensitive
  757. 31:13information to threat actors
  758. 31:16access and use email accounts to spread
  759. 31:19and lay dormant until someone by attract
  760. 31:22actor
  761. 31:24all right
  762. 31:28okay so modern viruses are developed for
  763. 31:31specific intent such as those listed in
  764. 31:33the table here
  765. 31:34okay so you've got the boot sector virus
  766. 31:36the firmware viruses
  767. 31:38macro virus program viruses and script
  768. 31:41viruses okay now a boot sector virus
  769. 31:45a virus attacks the boot sector
  770. 31:48partition or file partition table
  771. 31:50or the file system of the hard drives
  772. 31:53okay
  773. 31:53when you say firmware viruses this virus
  774. 31:56attacks the device
  775. 31:59okay macro viruses uses the ms office
  776. 32:04macro feature maliciously
  777. 32:06so program viruses virus inserts itself
  778. 32:09in another executable program so this is
  779. 32:11the most common type of
  780. 32:13virus okay you also have script viruses
  781. 32:17virus attacks the os interpreter
  782. 32:20which is used to execute scripts
  783. 32:28okay so chat actors use trojan horses to
  784. 32:31compromise
  785. 32:32hosts so a trojan horse is a program
  786. 32:36that looks useful but also carries
  787. 32:39malicious code
  788. 32:40so trojan horses are often provided with
  789. 32:43free online programs such as computer
  790. 32:45games
  791. 32:46okay so unsuspecting users download and
  792. 32:49install the game
  793. 32:50along with the trojan course
  794. 32:53right now there are several types of
  795. 32:56trojan horses as described in this table
  796. 32:58so this includes remote access data
  797. 33:01sending
  798. 33:01destructive proxy ftp security software
  799. 33:05disabler
  800. 33:06the denial of service and the key logger
  801. 33:10okay so trojan
  802. 33:14okay or trojan horse enables
  803. 33:15unauthorized remote access
  804. 33:17that is remote access type of trojan
  805. 33:19horse
  806. 33:20now data sending trojan horse provides
  807. 33:23the threat actor with sensitive data
  808. 33:26such as passwords
  809. 33:27okay destructive trojan horse corrupts
  810. 33:31or deletes
  811. 33:32files proxy trojan horse
  812. 33:35will use the victim's computer as the
  813. 33:38source device
  814. 33:39to launch attacks and perform other
  815. 33:41illegal activities
  816. 33:44okay ftp trojan horse trojan horse
  817. 33:47enables unauthorized file transfer
  818. 33:50services
  819. 33:50and end devices so security software
  820. 33:54disabler
  821. 33:55trojan horses stops antivirus programs
  822. 33:58or firewalls
  823. 33:59from functioning okay so denial of
  824. 34:03service
  825. 34:04trojan horse slows or halt network
  826. 34:06activity
  827. 34:08and the last one is key lager trojan
  828. 34:10horse actively attempts to steal
  829. 34:12confidential information such as credit
  830. 34:14card numbers
  831. 34:15or credit card information by recording
  832. 34:18keystrokes entered
  833. 34:20into a web form okay so viruses and
  834. 34:23trojan horses
  835. 34:24are the only two types of malware that
  836. 34:27actors use
  837. 34:29there are many other types of malware
  838. 34:30that can have been designed
  839. 34:33for specific purposes
  840. 34:36all right
  841. 34:39okay so other types of malware so this
  842. 34:42includes adware
  843. 34:43ransomware rootkit spyware and
  844. 34:46worm okay now adware
  845. 34:50is usually distributed by downloading
  846. 34:52online software
  847. 34:53so adware can display unsolicited
  848. 34:55advertising
  849. 34:57using pop-up web browsers windows
  850. 34:59neutral bars
  851. 35:00or unexpectedly redirect web page to a
  852. 35:04different website
  853. 35:05okay so ransomware typically denies a
  854. 35:09user access
  855. 35:10to their files by encrypting the files
  856. 35:12and then displaying a message
  857. 35:14demanding for a ransom for the
  858. 35:16decryption key
  859. 35:18so users without up-to-date backup must
  860. 35:21pay the ransom to decrypt the files
  861. 35:24okay so payment is usually made using
  862. 35:26wire transfer or the cryptocurrency such
  863. 35:29as a bitcoin
  864. 35:31okay so the next one is rootkit
  865. 35:34so rootkits are used by threat actors to
  866. 35:37gain administrators account level access
  867. 35:39to their computer
  868. 35:40so there are or they are very difficult
  869. 35:44to detect because they can alter
  870. 35:46firewall
  871. 35:47antivirus protection system files or
  872. 35:50even the os commands
  873. 35:52to conceal their presence okay
  874. 35:55so spyware like adwire but
  875. 35:58used to gather information about the
  876. 36:01user
  877. 36:02and send to threat actors without the
  878. 36:05user's consent
  879. 36:07so spyware can be low threat gathering
  880. 36:10browsing data
  881. 36:11or it can be a high threat capturing
  882. 36:13personal or financial information
  883. 36:17so the last one would be worm so worm is
  884. 36:20a self-replicating program that
  885. 36:22propagates
  886. 36:23automatically without the user's actions
  887. 36:25by exploiting vulnerabilities in
  888. 36:27legitimate software
  889. 36:29so it uses the network to search other
  890. 36:32victims
  891. 36:33with the same vulnerability so the
  892. 36:36intent of warm
  893. 36:37is usually to slow or disrupt network
  894. 36:40operations
  895. 36:46okay so let's talk about the common
  896. 36:48network attacks
  897. 36:54so let's start with an overview of the
  898. 36:57common network attacks
  899. 36:58so as you have learned there are many
  900. 37:00types of malware
  901. 37:02that hackers can use okay so but these
  902. 37:05are not the only ways that they can
  903. 37:07attack a network
  904. 37:08or even an organization so when malware
  905. 37:12is delivered and installed
  906. 37:14so the payload can be used to cause a
  907. 37:16variety of network related attacks
  908. 37:18so to mitigate attacks it is useful to
  909. 37:21understand
  910. 37:22the types of attacks okay so that is by
  911. 37:25categorizing network attacks
  912. 37:28it is possible to address types of
  913. 37:30attacks rather than individual attacks
  914. 37:33okay so networks are susceptible to the
  915. 37:36following types of attacks
  916. 37:37so you've got the reconnaissance attacks
  917. 37:40access attacks
  918. 37:41and dos or denial of service attacks
  919. 37:46okay so for the reconnaissance attack
  920. 37:50so reconnaissance is simply information
  921. 37:52gathering
  922. 37:53okay so it is analogous to achieve
  923. 37:57surveying a neighborhood by going door
  924. 38:00to door
  925. 38:01pretending to sell something okay so
  926. 38:04what the tif is actually doing is
  927. 38:06looking for vulnerable homes
  928. 38:09okay so to break into such us and
  929. 38:11occupied residences
  930. 38:13residences with easy to open doors or
  931. 38:16windows
  932. 38:17and those residences without security
  933. 38:19systems or security cameras
  934. 38:21okay now trap actors use
  935. 38:24reconnaissance or recon attacks to do an
  936. 38:28authorized discovery and mapping of
  937. 38:30systems
  938. 38:30services and vulnerabilities so recon
  939. 38:34attacks
  940. 38:34precede access attacks or the denial of
  941. 38:38service attack
  942. 38:41okay so some of the techniques
  943. 38:44used by malicious threat actors to
  944. 38:46conduct reconnaissance attacks are
  945. 38:48described in this table
  946. 38:49okay so perform information query
  947. 38:53of a target so with this one the threat
  948. 38:56actor is looking for initial information
  949. 38:58about
  950. 38:59target so various tools can be used
  951. 39:02including google search organization
  952. 39:05websites
  953. 39:06who is and more okay so the second
  954. 39:09technique is to initiate a ping sweep
  955. 39:12of the target network so the information
  956. 39:15query usually reveals the target network
  957. 39:18address
  958. 39:18okay the threat actors can now initiate
  959. 39:22a ping sweep to determine which ip
  960. 39:25addresses
  961. 39:26are active okay so
  962. 39:29next technique would be initiate a port
  963. 39:31scan
  964. 39:32of active ip address okay so this is
  965. 39:35used to determine
  966. 39:37which ports or services are available so
  967. 39:41of port scanners include nmap super scan
  968. 39:44angry ip scanner and net scan tools
  969. 39:48okay so the next one of the run
  970. 39:51vulnerability scanners
  971. 39:53so this is the query the identified
  972. 39:55ports
  973. 39:56to determine the type and version of the
  974. 39:58application and operating system
  975. 40:01that is running on the host so examples
  976. 40:03of tools
  977. 40:05includes a nipper a core impact
  978. 40:10nasus saint and open
  979. 40:13bas okay so
  980. 40:16the last one would be run exploitation
  981. 40:18tools
  982. 40:20so the threat actors now attempts to
  983. 40:22discover vulnerable services
  984. 40:24that can be exploited so a variety of
  985. 40:27vulnerability exploitation tools
  986. 40:30exist including you've got the
  987. 40:32metasploit
  988. 40:34core core impact the sql map
  989. 40:38social engineer toolkit and not spara
  990. 40:41not sparker
  991. 40:46all right so some of the techniques used
  992. 40:49by malicious threat actors to conduct
  993. 40:51reconnaissance
  994. 40:52attacks are described on this table here
  995. 40:54okay
  996. 40:55so let's have the first one which is
  997. 40:57perform an initial
  998. 40:59or information query of a target
  999. 41:02okay now in the figure here
  1000. 41:06it shows a threat actor using the
  1001. 41:08application
  1002. 41:09who is okay or who is command to find
  1003. 41:12information about the target
  1004. 41:15all right so the next technique that was
  1005. 41:19mentioned earlier was to initiate a ping
  1006. 41:22sweep
  1007. 41:22to the target network okay this is
  1008. 41:26performing being
  1009. 41:27swept so the figure here okay
  1010. 41:30shows a threat actor doing a pink sweep
  1011. 41:34of the target's network address to
  1012. 41:37determine or discover
  1013. 41:39live and active ip addresses
  1014. 41:43all right okay
  1015. 41:46so the next one would be initiate a port
  1016. 41:49scan
  1017. 41:50of active ip addresses now
  1018. 41:53take note that from the diagram or from
  1019. 41:54the figure here it shows a threat actor
  1020. 41:57performing a port scan onto discovered
  1021. 42:01active ip
  1022. 42:02address using nmap right so
  1023. 42:05nmap is the tool that is used by this
  1024. 42:08um threat actor all right
  1025. 42:13okay so next thing is the
  1026. 42:16access attacks right so access attacks
  1027. 42:20exploits known vulnerabilities in
  1028. 42:22authentication services
  1029. 42:24ftp services and web services
  1030. 42:27so the purpose of this types of attack
  1031. 42:29is to gain entry
  1032. 42:31to web accounts confidential databases
  1033. 42:34and other sensitive information
  1034. 42:36so threat actors use access attacks
  1035. 42:40on network devices and computers to
  1036. 42:43retrieve
  1037. 42:43data gain access or to escalate access
  1038. 42:47privileges
  1039. 42:48to administrator status okay
  1040. 42:52so this includes password attack
  1041. 42:56okay spoofing attack okay and other
  1042. 42:59attacks
  1043. 42:59all right so like uh trust exploitations
  1044. 43:04port redirections man in the middle
  1045. 43:06attacks and
  1046. 43:07buffer flow or buffer overflow attacks
  1047. 43:12all right so in the password attacks
  1048. 43:14okay in a password attack
  1049. 43:16the threat actor attempts to discover
  1050. 43:18critical system passwords
  1051. 43:19using various methods so password
  1052. 43:22attacks are very common
  1053. 43:24and can be launched using a variety of
  1054. 43:26password tracking tools
  1055. 43:28okay now for spoofing attack
  1056. 43:31so in spoofing attacks the threat actor
  1057. 43:33device attempts to pose
  1058. 43:35as another device by falsifying data
  1059. 43:39so common spoofing attacks includes ip
  1060. 43:42spoofing
  1061. 43:43mac address spoofing and dcp spoofing
  1062. 43:48so this spoofing attacks will be
  1063. 43:50discussed in more detail
  1064. 43:52later on this video lecture
  1065. 43:58okay so let's take
  1066. 44:02the other attacks okay so which includes
  1067. 44:05trust exploitations okay
  1068. 44:09now trust exploitation in this diagram
  1069. 44:12here
  1070. 44:13in a trust exploitation attack attract
  1071. 44:16actor uses unauthorized privileges
  1072. 44:20to gain access to the system okay
  1073. 44:23possibly compromising the target
  1074. 44:26all right so take note that in this
  1075. 44:29diagram
  1076. 44:30okay our figure so refer to the figure
  1077. 44:34to view an example of trust exploitation
  1078. 44:36here
  1079. 44:38okay so take a look at this threat actor
  1080. 44:40trying to access
  1081. 44:42devices all right they're compromised
  1082. 44:44devices
  1083. 44:46using the username
  1084. 44:49all right and he's trying to attack
  1085. 44:52systems a
  1086. 44:53right so and systems b
  1087. 44:57take note that systems a trust systems b
  1088. 45:00and system b here trusts everyone
  1089. 45:04okay so we call it the trust
  1090. 45:06exploitation
  1091. 45:08all right so we're in the user or the
  1092. 45:11attacker or that actor uses an
  1093. 45:13authorized privileges
  1094. 45:14to gain access to the system okay
  1095. 45:18so the next one would be port
  1096. 45:20exploitation
  1097. 45:21okay now in a port exploitation or port
  1098. 45:24redirection
  1099. 45:26okay so we call it port redirection
  1100. 45:28attack
  1101. 45:29a threat actor uses a compromised system
  1102. 45:33as base for attacks against other
  1103. 45:35targets
  1104. 45:37so the example in the figure shows a
  1105. 45:39threat actor
  1106. 45:40using ssh or the secure
  1107. 45:43shell port 22 to connect to the
  1108. 45:46compromised
  1109. 45:47host a okay now host a is trusted by
  1110. 45:51host b
  1111. 45:52and therefore all right the threat actor
  1112. 45:56can use
  1113. 45:56telnet port 23 to access it
  1114. 46:00so we call it port redirection
  1115. 46:03okay so next would be
  1116. 46:07money in the medial attacks or the mitm
  1117. 46:11okay now money in the middle attack
  1118. 46:14the threat actor is positioned between
  1119. 46:17the two legitimate
  1120. 46:19entities in order to read or modify the
  1121. 46:22data
  1122. 46:23that passes between the two parties so
  1123. 46:26the figure here displays an example
  1124. 46:28of the mitm or the man in the middle
  1125. 46:30attack
  1126. 46:32all right okay
  1127. 46:36so the next one would be a buffer
  1128. 46:38overflow attacks
  1129. 46:40okay now in a buffer overflow attack the
  1130. 46:43threat
  1131. 46:43actor exploits the buffer memory
  1132. 46:46and overwhelms it with unexpected values
  1133. 46:50so this is or usually
  1134. 46:53okay renders the system inoperable for
  1135. 46:56creating a denial of service or dos
  1136. 46:59attack
  1137. 47:00okay now the figure here shows
  1138. 47:03that the threat actor is sending
  1139. 47:06many packets to the victim in an attempt
  1140. 47:09to overflow the victim's
  1141. 47:11buffer okay so we call it buffer
  1142. 47:14overflow
  1143. 47:15attacks
  1144. 47:19all right so next one would be
  1145. 47:22social engineering attacks
  1146. 47:26so social engineering is a process
  1147. 47:30or is an access attack that attempts to
  1148. 47:32manipulate individuals into performing
  1149. 47:35actions
  1150. 47:36or divulging confidential information
  1151. 47:39so some social engineering techniques
  1152. 47:43okay are performed in person
  1153. 47:47right while others may use telephone or
  1154. 47:51the internet so social engineers
  1155. 47:54often rely on people's willingness to be
  1156. 47:57helpful
  1157. 47:58right they also prey on people's
  1158. 48:01weaknesses for example so a threat actor
  1159. 48:05could call
  1160. 48:06an authorized employee okay with an
  1161. 48:09urgent problem that requires immediate
  1162. 48:11network access
  1163. 48:13so the threat actor would appeal to the
  1164. 48:15employee's
  1165. 48:16vanity okay so
  1166. 48:20invoking the authority using name
  1167. 48:23dropping techniques
  1168. 48:25or appeal to the employee's grid
  1169. 48:29all right so that is social engineering
  1170. 48:32attacks
  1171. 48:34now information about social engineering
  1172. 48:35techniques is shown in this table
  1173. 48:38so this includes pre-texting
  1174. 48:41okay so attract actor pretends to need
  1175. 48:44personal or financial data
  1176. 48:46to confirm the identity of the recipient
  1177. 48:49so we call it
  1178. 48:50pre-texting okay you also have pissing
  1179. 48:54a threat actor sends a fraudulent email
  1180. 48:57which is disguised as being from a
  1181. 49:00legitimate
  1182. 49:01trusted source to trick the recipient
  1183. 49:04into installing malware on their device
  1184. 49:07or to share personal or financial
  1185. 49:10information
  1186. 49:12okay you also have a spearfishing
  1187. 49:16a threat actor creates a targeted vision
  1188. 49:19attack
  1189. 49:20tailored for the specific individual or
  1190. 49:23organization
  1191. 49:24okay so this one is common spam
  1192. 49:28okay so also known as junk mail this
  1193. 49:31is unsolicited email which often
  1194. 49:34contains harmful links
  1195. 49:36malware or deceptive content
  1196. 49:40okay so something for something
  1197. 49:43sometimes called kid pulco
  1198. 49:46right so kid pro this
  1199. 49:49is when a chat actor requests
  1200. 49:53personal information from a party in
  1201. 49:55exchange of
  1202. 49:57or in exchange for something such as
  1203. 49:58gift or favor
  1204. 50:00all right so next is baiting
  1205. 50:04a threat actor leaves a malware infected
  1206. 50:07flash
  1207. 50:08drive in a public location so a victim
  1208. 50:11finds the drive and unsuspectingly
  1209. 50:14inserts
  1210. 50:15it into their laptop unintentionally
  1211. 50:17installing malware
  1212. 50:19all right so that's upbeating so next
  1213. 50:22would be
  1214. 50:23impersonation okay so this type of
  1215. 50:26attack is
  1216. 50:27where the threat actor pretends to be
  1217. 50:29someone
  1218. 50:30they are not to gain the trust of a
  1219. 50:33victim
  1220. 50:34okay so tailgating this is where the
  1221. 50:37threat actor quickly follows an
  1222. 50:39authorized person okay into a secure
  1223. 50:43location to gain access to a secure
  1224. 50:45area tailgating okay so the next one is
  1225. 50:48shoulder surfing okay so shoulder
  1226. 50:52surfing
  1227. 50:52this is where the threat actor can
  1228. 50:55conspicuously look or looks over
  1229. 50:58someone's shoulder
  1230. 51:00to steal their passwords or other
  1231. 51:02information
  1232. 51:03okay and the last one would be dumpster
  1233. 51:06diving
  1234. 51:07this is where a threat actor
  1235. 51:10rummages to trust beans to discover
  1236. 51:14confidential documents
  1237. 51:16all right
  1238. 51:20okay so what are the recommended social
  1239. 51:24engineering protection practices
  1240. 51:27okay so the social engineering toolkit
  1241. 51:30or set was designed to help white
  1242. 51:33hackers or white hot hackers
  1243. 51:35and other network security professionals
  1244. 51:38create a social engineering attacks
  1245. 51:40to test their own networks okay
  1246. 51:43so enterprises must educate their users
  1247. 51:47about the risk of social engineering and
  1248. 51:50develop strategies
  1249. 51:51to validate identities over the phone
  1250. 51:54via email
  1251. 51:55or in person so the figure here shows a
  1252. 51:59recommended practices
  1253. 52:00that should be followed by all the users
  1254. 52:04okay so this includes
  1255. 52:08okay so like always destroy confidential
  1256. 52:11information
  1257. 52:12according to organization policy
  1258. 52:15never give user name or password
  1259. 52:18credentials to anyone
  1260. 52:20all right so never leave your username
  1261. 52:23password credentials
  1262. 52:25where they can easily be found never
  1263. 52:29open
  1264. 52:29emails from untrusted sources
  1265. 52:32okay never release work related
  1266. 52:35information
  1267. 52:36on the social media sites never reuse
  1268. 52:40work related passwords okay
  1269. 52:43always lock and sign out
  1270. 52:47of your computer when unattended
  1271. 52:50and always report suspicious individuals
  1272. 52:53so these are just some of the
  1273. 52:55recommendations okay
  1274. 52:58and protection against a social
  1275. 53:01engineering
  1276. 53:02attacks
  1277. 53:06okay so the next one would be dos or
  1278. 53:08denial of service
  1279. 53:10and you've got the ddos or the
  1280. 53:12distributed denial of service
  1281. 53:15so a denial of service or u.s attack
  1282. 53:18creates
  1283. 53:18some sort of interruption of network
  1284. 53:21services to the users
  1285. 53:22devices or applications so these are the
  1286. 53:25two major types of the dos attack
  1287. 53:28you've got overwhelming quantity of
  1288. 53:30traffic and
  1289. 53:31maliciously formatted packets okay
  1290. 53:35now overwhelming quantity of traffic the
  1291. 53:38threat actor sends an enormous quantity
  1292. 53:41of data
  1293. 53:42at a rate that the network host or
  1294. 53:44application cannot handle
  1295. 53:46so this causes transmission response
  1296. 53:49okay
  1297. 53:50to slow down so it can also crash
  1298. 53:53a device or a service so the next one
  1299. 53:57is maliciously formatted packets so the
  1300. 54:00threat actor
  1301. 54:01sends a maliciously formatted packet to
  1302. 54:03a host or application
  1303. 54:05and the receiver is unable to handle
  1304. 54:10to handle that okay so this causes the
  1305. 54:12receiving device
  1306. 54:14to run very slowly or crash
  1307. 54:19okay now for the
  1308. 54:23dos attack so dos attacks are the major
  1309. 54:26risk
  1310. 54:27okay because they interrupt
  1311. 54:30communication and cause significant loss
  1312. 54:33of time and money
  1313. 54:34so these attacks are relatively simple
  1314. 54:37okay so to conduct
  1315. 54:39even if by unskilled chat actor
  1316. 54:43okay so something like this threat actor
  1317. 54:46here
  1318. 54:46sends so many pings to the server okay
  1319. 54:50and the server can respond to anyone
  1320. 54:52else
  1321. 54:53all right so you are flooding the server
  1322. 54:56with inquiries or ping so that they
  1323. 54:58cannot respond
  1324. 55:00to other inquiries from the hosts or
  1325. 55:02from other uh
  1326. 55:03clients here okay
  1327. 55:07now when you say distributed denial of
  1328. 55:10service attack or ddos
  1329. 55:12this is similar to the os attack okay so
  1330. 55:14but it originates
  1331. 55:16from multiple coordinated sources
  1332. 55:19so for example okay so a threat
  1333. 55:23actor builds a network of infected uh
  1334. 55:26hosts
  1335. 55:27known as zombies right so the threat
  1336. 55:30actor uses the command and controller
  1337. 55:33cnc
  1338. 55:34to send control messages to the zombies
  1339. 55:37now the zombies constantly scan
  1340. 55:40and infect more hosts with both
  1341. 55:44malware now the bot malware
  1342. 55:48okay is designed to infect a host
  1343. 55:51making it a zombie that can communicate
  1344. 55:54with the cnc or the command and control
  1345. 55:57now the collection of zombies is called
  1346. 55:59botnet
  1347. 56:00all right so when ready the threat actor
  1348. 56:04instructs the cnc
  1349. 56:06or the command and control to make the
  1350. 56:09botnet of
  1351. 56:10zombies carry out the distributed denial
  1352. 56:13of service
  1353. 56:15all right
  1354. 56:19okay so on this section we will be
  1355. 56:21talking about
  1356. 56:22ip vulnerabilities and trends
  1357. 56:27okay now ipb4 and ipv6
  1358. 56:30so ip does not validate whether the
  1359. 56:32source ip address contained in a packet
  1360. 56:35actually came from that source
  1361. 56:38for this reason threat actors can send
  1362. 56:41packets using a spoofed source ip
  1363. 56:43address
  1364. 56:45threat actors can also tamper with other
  1365. 56:48fields
  1366. 56:48in the ip header to carry out their
  1367. 56:51attacks
  1368. 56:52so security analysts most
  1369. 56:55understand or must understand the
  1370. 56:56different fields in both the ipb4 and
  1371. 56:59ipv6 headers
  1372. 57:01okay now some of the more common ip
  1373. 57:05related attacks
  1374. 57:06are shown on this table so you've got
  1375. 57:08icmp attacks
  1376. 57:11amplification and reflection attacks
  1377. 57:14address proofing attacks money in the
  1378. 57:17middle attacks
  1379. 57:18and session hijacking okay
  1380. 57:22now for icmp attacks threat actors use
  1381. 57:25the icmp
  1382. 57:27or the internet control message protocol
  1383. 57:30echo packets or pings to discover
  1384. 57:33subnets and hosts
  1385. 57:34on a protected network so that is to
  1386. 57:36generate the denial of service of floods
  1387. 57:38attacks
  1388. 57:40and to alter host routing tables
  1389. 57:44so next would be amplification and
  1390. 57:47reflection attacks
  1391. 57:48so trap actors attempts to prevent
  1392. 57:51legitimate users
  1393. 57:53from accessing information or services
  1394. 57:56using the denial
  1395. 57:57and denial or distributed denial of
  1396. 58:00service attacks
  1397. 58:02okay so next would be address spoofing
  1398. 58:05attacks
  1399. 58:06now threat actors poof the source ip
  1400. 58:09address
  1401. 58:10in an ip packet to perform blind
  1402. 58:12spoofing
  1403. 58:13or non-blind spoofing
  1404. 58:16man in the middle as mentioned earlier
  1405. 58:18in the previous slides
  1406. 58:20threat actors positioned themselves
  1407. 58:22between the source
  1408. 58:23and the destination to transparently
  1409. 58:26monitor
  1410. 58:27capture and control the communication
  1411. 58:30so they could absorb by inspecting
  1412. 58:33captured packets or
  1413. 58:35alter packets and forward them to their
  1414. 58:38original destination
  1415. 58:41all right so the last one would be the
  1416. 58:43session hijacking
  1417. 58:45threat actors gain access to the
  1418. 58:48physical network
  1419. 58:50and then use the mit-m or the man in the
  1420. 58:53middle attack
  1421. 58:54to hijack a session
  1422. 59:00all right so for the icmp attacks so
  1423. 59:02trap actors use icmb
  1424. 59:04or icmp for reconnaissance and scanning
  1425. 59:08attacks
  1426. 59:09so they can launch information gathering
  1427. 59:11attacks to map
  1428. 59:12out a network topology discover
  1429. 59:16which hosts are active or reachable
  1430. 59:19identify the host operating system or os
  1431. 59:22fingerprinting
  1432. 59:23and determine the state of the firewall
  1433. 59:26so threat actors
  1434. 59:27also use icmp for the denial of service
  1435. 59:31attacks
  1436. 59:32okay so take note that icmp for ipv4 or
  1437. 59:36icmp
  1438. 59:37version 4 and icmp for version 6 or ipv6
  1439. 59:43or the known as the icmp b6
  1440. 59:46are susceptible to similar types of
  1441. 59:48attack
  1442. 59:49so networks should have a strict icmp
  1443. 59:53access control list or acl filtering
  1444. 59:57on the network edge to avoid icmp
  1445. 1:00:00probing
  1446. 1:00:01from the internet okay so security
  1447. 1:00:05analysts
  1448. 1:00:06should be able to detect icmp related
  1449. 1:00:09attacks
  1450. 1:00:10by looking at captured traffic and lag
  1451. 1:00:12piles
  1452. 1:00:15right so in the case of the large
  1453. 1:00:17network
  1454. 1:00:18security devices such as a firewall and
  1455. 1:00:21intrusion detection systems or ids
  1456. 1:00:24detect such attacks and generate alerts
  1457. 1:00:27to the security
  1458. 1:00:29analysts
  1459. 1:00:32all right so this table here
  1460. 1:00:36shows the common icmp messages of
  1461. 1:00:38interest
  1462. 1:00:39to threat actors all right and this
  1463. 1:00:42includes
  1464. 1:00:43icmp echo request and echo reply
  1465. 1:00:46which is used to perform host
  1466. 1:00:48verification and
  1467. 1:00:50denial of service attacks okay
  1468. 1:00:53you also have the icmp unreachable this
  1469. 1:00:56is used to perform network
  1470. 1:00:57reconnaissance and scanning attacks
  1471. 1:01:01icmp mask reply this is used to map an
  1472. 1:01:04internal ip network
  1473. 1:01:07icmp redirects right so this is used to
  1474. 1:01:10lure
  1475. 1:01:11a target host into ascending
  1476. 1:01:14all traffic to a compromised device
  1477. 1:01:18and create a man in the middle attack
  1478. 1:01:22okay so the last one would be icmp
  1479. 1:01:24router discovery
  1480. 1:01:27so this is used to inject bogus route
  1481. 1:01:30entries
  1482. 1:01:30into the routing table of a target hosts
  1483. 1:01:36okay now let's focus on the
  1484. 1:01:40amplification and reflection attacks
  1485. 1:01:43okay now trap actors often use
  1486. 1:01:46amplification and reflection techniques
  1487. 1:01:49to create dos attacks
  1488. 1:01:52now the example in the figure right so
  1489. 1:01:55illustrates
  1490. 1:01:56how an amplification and reflection
  1491. 1:01:59technique
  1492. 1:02:00called smurf attack is used to overwhelm
  1493. 1:02:03a target host
  1494. 1:02:05okay so this um amplification and
  1495. 1:02:08reflection technique
  1496. 1:02:10is also known as the smurf attack okay
  1497. 1:02:13now let us define the amplification okay
  1498. 1:02:16so amplification the threat actor
  1499. 1:02:19forwards icmp
  1500. 1:02:21echo request messages to many hosts
  1501. 1:02:25okay this messages contains the source
  1502. 1:02:28ip address of the victim
  1503. 1:02:31reflection this hosts reply
  1504. 1:02:34to the spoofed ip address of the victim
  1505. 1:02:38to overwhelm it okay so these are the
  1506. 1:02:41replies here
  1507. 1:02:43okay so take note that newer forms of
  1508. 1:02:46amplification
  1509. 1:02:47and reflection attacks such as dns based
  1510. 1:02:51reflection and amplification attacks and
  1511. 1:02:53network time
  1512. 1:02:54protocol or ntp amplification attacks
  1513. 1:02:57are now being used
  1514. 1:02:59okay so threat actors also use resource
  1515. 1:03:02exhaustion attacks
  1516. 1:03:04these attacks consume the resources of
  1517. 1:03:07the target host to either
  1518. 1:03:09the grassroot or to consume the
  1519. 1:03:11resources
  1520. 1:03:12of a network
  1521. 1:03:15okay so next would be address spoofing
  1522. 1:03:19attack
  1523. 1:03:20so ip address boofing attack occurs
  1524. 1:03:23when a chat actor creates a packet with
  1525. 1:03:26full source ip address information
  1526. 1:03:29to either hide the identity of the
  1527. 1:03:31sender or
  1528. 1:03:32to pose as another legitimate user
  1529. 1:03:36okay so the threat actor can then gain
  1530. 1:03:39access
  1531. 1:03:40to otherwise inaccessible data
  1532. 1:03:43or circumvent security configuration
  1533. 1:03:47spoofing is usually incorporated into
  1534. 1:03:49another attack
  1535. 1:03:51such as the smurf attack
  1536. 1:03:56okay now spoofing attacks can be
  1537. 1:03:59non-blind or blind
  1538. 1:04:02okay so non-blind spoofing
  1539. 1:04:06the threat actor can see the traffic
  1540. 1:04:08that is being sent
  1541. 1:04:10between the host and the target
  1542. 1:04:13so the threat actor uses non-blind
  1543. 1:04:15spoofing
  1544. 1:04:16to inspect the reply packet from the
  1545. 1:04:18target victim
  1546. 1:04:20so non-blind spoofing determines the
  1547. 1:04:23state of a firewall
  1548. 1:04:25and sequence number prediction so it can
  1549. 1:04:28also hijack
  1550. 1:04:29an authorized session okay
  1551. 1:04:33now when you say blind spoofing the
  1552. 1:04:36threat actor cannot see the traffic that
  1553. 1:04:38is being sent
  1554. 1:04:39between the host and the target so blind
  1555. 1:04:42spoofing is used
  1556. 1:04:44in the os attack so mac address spoofing
  1557. 1:04:47attacks
  1558. 1:04:48are used when target or threat actors
  1559. 1:04:51have access to the internal network okay
  1560. 1:04:55now trap actors alter the mac address of
  1561. 1:04:58their host
  1562. 1:04:59to match another known mac address of a
  1563. 1:05:02target host
  1564. 1:05:04so the attacking host then sends a frame
  1565. 1:05:08throughout the network with the newly
  1566. 1:05:10configured mac address
  1567. 1:05:12so when the switch receives the frame it
  1568. 1:05:15examines the source
  1569. 1:05:17mac address alright
  1570. 1:05:23okay so we have here an example threat
  1571. 1:05:26actors
  1572. 1:05:26poof a server's mac address okay
  1573. 1:05:30now the switch here overrides the
  1574. 1:05:33current cam table entry
  1575. 1:05:35and assigns the mac address to the new
  1576. 1:05:38port
  1577. 1:05:39okay now it then forward the frames
  1578. 1:05:42this thing for the target host to the
  1579. 1:05:45attacking host
  1580. 1:05:48all right next the switch
  1581. 1:05:51updates the cam table with spoofed
  1582. 1:05:54address
  1583. 1:05:55so application or service spoofing is
  1584. 1:05:58another spoofing example
  1585. 1:06:00so a threat actor can connect
  1586. 1:06:04a rogue hip server okay
  1587. 1:06:08to create the man in the middle attack
  1588. 1:06:11or the mitm condition
  1589. 1:06:17so thanks for watching and listening
  1590. 1:06:20so this would be the end of part one
  1591. 1:06:24of this module see you on part two

About this transcript

This page contains the full transcript of ENSA M3 Network Security Concepts Part 1 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 7,665 words across 1,591 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.