ENSA M3 Network Security Concepts Part 2 — Transcript
Full transcript
- 0:04hi hello there
- 0:05welcome to network security concepts
- 0:08part
- 0:08two so perhaps you've heard one of the
- 0:12hundreds of new stories about
- 0:14data security rates within a large
- 0:16corporation
- 0:18or even government was your credit card
- 0:21number exposed by bridge
- 0:24how about your private health
- 0:25information
- 0:27would you like to know how to prevent
- 0:29this data breaches
- 0:31the field of network security is growing
- 0:33every day
- 0:35this module provides a detailed
- 0:37landscape
- 0:38of the types of cyber crime and the many
- 0:42ways
- 0:42we have to fight back against cyber
- 0:44criminals
- 0:45let's get started so welcome to part two
- 0:52okay so the objectives
- 0:56okay so explain how vulnerabilities
- 0:58threats
- 0:59and exploits can be mitigated to enhance
- 1:03network security
- 1:05so on this part two of the video lecture
- 1:07we will be talking about tcp
- 1:09and udp vulnerabilities ip services
- 1:13network security best practices and
- 1:16cryptography
- 1:20so let's start with tcp and udp
- 1:24vulnerabilities
- 1:26so while some attacks target ip this
- 1:29topic discusses attacks
- 1:31that target tcp and udp
- 1:35tcp segment information appears
- 1:37immediately after the ip header
- 1:40the fields of the tcp segment and the
- 1:42flags for the control bits
- 1:44fields are displayed on this figure here
- 1:48so the following are the six control
- 1:50bits of the tcp segment
- 1:52so you've got the urg or urgent pointer
- 1:56field significant
- 1:58ack or the acknowledgement
- 2:01psh or the push function rsd for the
- 2:04reset
- 2:07syn for the synchronized sequence
- 2:08numbers and fin
- 2:10no more data from the sender
- 2:16tcp provides this services
- 2:19so you've got reliability delivery flow
- 2:23control
- 2:23and stateful communication
- 2:27so under the reliability delivery
- 2:30tcp incorporates acknowledgements to
- 2:33guaranteed delivery
- 2:35instead of relying on the upper layer
- 2:37protocols to detect and resolve
- 2:39errors so if a timely acknowledgement is
- 2:43not received
- 2:44the sender retransmits the data
- 2:48requiring acknowledgement of received
- 2:50data
- 2:51can cause substantial delays
- 2:55examples of application layer protocols
- 2:57that make use of tcp
- 3:00okay or the reliability of tcp includes
- 3:03http
- 3:04ssl all right or tls
- 3:07ftp dns zone transfers
- 3:11and others flow control
- 3:15tcp implements flow control to address
- 3:17this issue
- 3:19rather than acknowledge one segment at a
- 3:22time
- 3:23multiple segments can be acknowledged
- 3:25with a single acknowledgement segment
- 3:31stateful communication tcp stateful
- 3:34communication between the two parties
- 3:36occurs
- 3:37during the tcp three-way handshake
- 3:40so before data can be transferred using
- 3:43tcp
- 3:45a three-way handshake opens the tcp
- 3:47connection
- 3:49and then if both sides agree to the tcp
- 3:51connection
- 3:52data can be sent and received by both
- 3:55parties using tcp
- 4:01now a tcp connection is established in
- 4:03three steps as shown in the figure
- 4:05diagram here okay so the first one would
- 4:08be
- 4:09the initiating client
- 4:12requests a client to server
- 4:14communication session
- 4:16with the server the server
- 4:20then acknowledges the client to server
- 4:22communication session
- 4:24and requests a server to client
- 4:26communication session
- 4:29the initiating client acknowledges the
- 4:31server to client communication
- 4:34this is an example of a three-way
- 4:40handshaking
- 4:46how about tcp syn flood attacks or the
- 4:49tcp attacks
- 4:51network applications use tcp or udp
- 4:55ports
- 4:56threat actors conduct port scans of
- 4:59target devices
- 5:00to discover which services they offer
- 5:05so the tcp syn flood attack exploits the
- 5:08tcp
- 5:09three-way handshake presented in the
- 5:11earlier diagram
- 5:13now the figure here shows a threat actor
- 5:16continually sending tcp syn session
- 5:19request packets
- 5:21with a randomly spoofed source ip
- 5:23address to target
- 5:27okay now the target device replies with
- 5:29tcp
- 5:30scene acknowledgement packet three
- 5:32spoofed ip address and waits for the tcp
- 5:35acknowledgement packet
- 5:37okay now those responses never arrive
- 5:41eventually the target host is
- 5:44overwhelmed
- 5:45with half open tcp connections
- 5:49and tcp services are denied
- 5:52to legitimate users
- 5:56okay
- 6:00how about terminating a tcp connection
- 6:04terminating a tcp session uses the
- 6:06following four-way exchange process
- 6:09first when the client has no more data
- 6:12to send in the stream
- 6:14it sends a segment with the fin
- 6:17plug set okay
- 6:20now the server sends an acknowledgement
- 6:25to acknowledge the receipt of the fin
- 6:28to terminate the session from client to
- 6:32server the server
- 6:35sends fin or fin
- 6:39to the client to terminate the server to
- 6:42client session
- 6:44and then last would be the client
- 6:47responds
- 6:47with an ack or acknowledgement to
- 6:50acknowledge the fin
- 6:51from the server
- 7:01so the tcp session hijacking is another
- 7:03tcp vulnerability
- 7:06although difficult to conduct a threat
- 7:08actor takes over
- 7:10an already authenticated host as it
- 7:12communicates
- 7:13with a target the threat actor must
- 7:16spoof
- 7:17the ip address of one host predict
- 7:20the next sequence number and send an ack
- 7:24to the other host if successful
- 7:28the threat actor could send but not
- 7:31receive
- 7:31data from the target device
- 7:38udp segment header and operation
- 7:41so udp is commonly used by dns
- 7:44tftp nfs right
- 7:47and snmp so it is also used with
- 7:51real-time applications such as
- 7:53media streaming or voip
- 7:56udp is a connectionless transport layer
- 7:59protocol
- 8:01it has much lower overhead than tcp
- 8:03because it is not connected
- 8:05or connection oriented and does not
- 8:08offer the sophisticated rear
- 8:09transmission
- 8:10sequencing and flow control mechanisms
- 8:14that provides reliability the udp
- 8:17segment structure
- 8:19shown in this figure here is much
- 8:22smaller than tcp segment structure
- 8:25although udp is normally called
- 8:27unreliable
- 8:29in contrast to tcp's reliability this
- 8:32does not mean that the application does
- 8:34use or that use udp are always
- 8:37unreliable
- 8:39nor does it mean that udp is an inferior
- 8:42protocol
- 8:44it means that these functions are not
- 8:47provided
- 8:47by the transport layer protocol and must
- 8:50be implemented elsewhere if
- 8:52required so the low overhead of udp
- 8:57makes it very desirable for protocols
- 8:59that make simple requests
- 9:01and reply transactions so for example
- 9:05using tcp for dhcp would introduce
- 9:08unnecessary network traffic
- 9:10so if no response is received the device
- 9:14presents the request
- 9:20how about udp attacks so udp
- 9:24is not protected by any encryption
- 9:27you can add encryption to udp but it is
- 9:30not available by default
- 9:32so the lack of encryption means that
- 9:34anyone can see the traffic
- 9:36change it and send it on to each
- 9:39destination
- 9:41so changing the data in the traffic will
- 9:43alter the 16-bit checksum
- 9:46but the checksum is optional and is not
- 9:48always used
- 9:50so when the checksum is used the threat
- 9:52actor can create
- 9:54a new checksum based on the new data
- 9:57payload
- 9:58and then record it in a header
- 10:01as a new checksum so the destination
- 10:04device will find that the checksum
- 10:06matches
- 10:06the data without knowing that the data
- 10:09has been altered
- 10:11so this type of attack is not widely
- 10:14used okay now for the udp flat attacks
- 10:20you are more likely to see a udp flat
- 10:22attack
- 10:23in a udp flat attack all the resources
- 10:26in the network are consumed
- 10:29so if the threat actor must use a tool
- 10:32like udp unicorn or
- 10:34low orbit ion cannon these tools send a
- 10:37flood of udp packets
- 10:39often from a spoofed host to a server on
- 10:43the subset
- 10:44the program will sweep through all the
- 10:47known ports
- 10:48trying to find closed ports
- 10:51this will cause the server to reply with
- 10:54icmp port and reachable message
- 10:57because there are many closed ports on
- 10:59the server this creates a lot of traffic
- 11:01on the segment
- 11:03which uses up most of the bandwidth
- 11:06so the result is similar to the denial
- 11:09of service attack
- 11:15ip services
- 11:19one of the ip services is the arp
- 11:22or the address resolution protocol
- 11:24vulnerabilities
- 11:26so earlier in this module you learned
- 11:28about vulnerabilities with
- 11:30ip tcp and udp
- 11:34so the tcp product called suit was never
- 11:37built for security
- 11:39therefore the services that ip uses for
- 11:42addressing functions such as arp
- 11:45dns and dhcp are also not secure
- 11:49as you will learn in this topic hosts
- 11:53broadcasts and arp requests to other
- 11:55hosts on the segment
- 11:57to determine the mac address of the host
- 11:59with a particular ip address
- 12:02all hosts on the subnet received and
- 12:04processed the arp requests
- 12:07the host where the matching ip address
- 12:10in the erp request
- 12:11sends an arp reply
- 12:16now here's the arp process so any client
- 12:20can send unsolicited arp reply called
- 12:24gratuitous arp this is often done
- 12:28when a device first boot or boot up
- 12:31to inform all other devices on the
- 12:33network or local network
- 12:35of the new device's mac address
- 12:39when a host sends a gratitude's arp
- 12:42other hosts on the subnet to store the
- 12:44mac address
- 12:45and ip address contained in the graph
- 12:48t2s arp and their arp
- 12:50tables so this feature of arp also means
- 12:54that any host can claim to be the owner
- 12:58of any ip or mac address
- 13:01so a threat actor can poison the arp
- 13:04cache
- 13:05of the devices on the local network
- 13:08creating a man in the middle attack
- 13:12to redirect traffic so the goal is
- 13:16to target a victim okay or
- 13:19host and have it change its default
- 13:22gateway
- 13:23to the threat actors device
- 13:26so just positions the threat actor
- 13:30in between the victim and all other
- 13:33systems
- 13:34outside the local subnet
- 13:41next is arp cache poisoning
- 13:45arp cache poisoning can be used to
- 13:47launch various man-in-the-middle attacks
- 13:50okay so in this diagram here
- 13:55we have the arp request the figure
- 13:59shows how arp cache poisoning works
- 14:04so pca requires the mac address
- 14:07of its default k20 which is connected to
- 14:11r1
- 14:12therefore it sends an arp requests
- 14:16for the mac address of 192.168.10.1
- 14:25and then there would be an arp reply
- 14:29in this figure r1 updates
- 14:32each arp cache with the ip address and
- 14:35mac address of
- 14:36pca r1 sends an arp reply to pca
- 14:43which then updates its arp cache with
- 14:45the ip address and mac address of
- 14:48r1
- 14:55alright so how about if there would be a
- 14:57spoofed gratitude's arp replies
- 15:00so in the figure the threat actor
- 15:04sends two spoofed the t2u's arp replies
- 15:07using its own mac address for the
- 15:10indicated destination ip address
- 15:13so pca updates
- 15:17harp cache with its default gateway
- 15:20which is now pointing to the threat
- 15:22actors
- 15:23host mac address so r1 also updates
- 15:27its arp cache with the ip address of pca
- 15:31pointing to the threat actors mac
- 15:34address
- 15:35so the threat actors host is executing
- 15:38an arp poisoning attack
- 15:40so the arp poisoning attack can be
- 15:43passive
- 15:44or active so passive arp
- 15:47poisoning is wear threat act or steal
- 15:50confidential information
- 15:53active arp poisoning is where threat
- 15:56actors modify the data in transit
- 15:59or inject malicious data
- 16:12dns attacks so the domain name service
- 16:16or dns protocol defines an
- 16:17automated service that matches resource
- 16:20names such as
- 16:23www.education.com
- 16:25or any url with the required numeric
- 16:29network address
- 16:30such as ipv4 or ipv6
- 16:33addresses it includes the format
- 16:37for queries responses and data
- 16:40and uses resource records or rr
- 16:44to identify the type of the dns response
- 16:49securing a dns is often overlooked
- 16:52however it is crucial to the operation
- 16:56of the network and should be secured
- 16:57accordingly
- 16:59dns attacks includes the following
- 17:02you'll have the dns op and resolver
- 17:04attacks
- 17:05the dns stealth attacks dns domain
- 17:09shadowing attacks
- 17:10and dns tunneling attacks
- 17:17now let's talk about the dns open
- 17:19resolver attacks
- 17:21many organizations use the services of
- 17:23publicly open dns servers
- 17:25such as google dns which is at 8.8.8.8
- 17:31to provide responses to queries this
- 17:34type of dns server
- 17:35is called an open resolver a dns open
- 17:38resolver
- 17:40answers queries from clients outside of
- 17:42its administrative domain
- 17:44dns open resolvers are vulnerable to
- 17:48multiple malicious activities
- 17:50as described here on this table this
- 17:52includes the dns cache positioning
- 17:54attacks
- 17:56wherein threat actors send spoofed
- 17:59pulsified record resource or rr
- 18:02to a dns resolver to redirect users from
- 18:05legitimate sites to malicious sites
- 18:09so the next one is the dns amplification
- 18:12and reflection attacks this is where the
- 18:14threat actors use the denial of service
- 18:16or the distributed denial of service
- 18:18attacks
- 18:19on dns open resolvers to increase the
- 18:22volume of attacks
- 18:23and to hide the true score or source of
- 18:26an attack
- 18:28so threat actor sends dns messages
- 18:31to the open resolvers using the ip
- 18:34address of a target hosts
- 18:37so the next one is the dns resource
- 18:39utilization attacks
- 18:42so the denial of service attacks that
- 18:44consumes the resources of the dns open
- 18:46resolvers
- 18:47this denial of service attack consumes
- 18:50all the available resources
- 18:52to negatively affect the operations of
- 18:55the dns open resolver
- 18:57now the impact of this denial of service
- 18:59attack may require the dns open resolver
- 19:02to be rebooted or services to be stopped
- 19:06and restarted
- 19:12the next type of attack is the dns
- 19:15stealth attacks
- 19:16so to hide their identity threat actors
- 19:19also use the dns style techniques
- 19:22described in the table to carry out
- 19:24their attacks
- 19:25so first would be the fast flags
- 19:29this is where the threat actors use this
- 19:32technique
- 19:32to hide their fishing and malware
- 19:35okay so that is delivery sites behind a
- 19:38quickly changing network
- 19:40of compromised okay so which is the dns
- 19:44hosts
- 19:44now the dns ip addresses are
- 19:47continuously changed within minutes
- 19:50botnets often employ a fast flux
- 19:53technique
- 19:54to effectively hide malicious servers
- 19:56from being
- 19:57detected next would be a double ip flux
- 20:02so this is where the threat actors can
- 20:05use techniques to rapidly change the
- 20:07host name
- 20:08to ip address mappings and to also
- 20:11change the authoritative name server
- 20:14this increases the difficulty to
- 20:16identify
- 20:18the source of the attack so the last one
- 20:22would be a domain generation algorithms
- 20:25threat actors use this technique in
- 20:27malware to randomly generate
- 20:29domain names that can then be used
- 20:32and rendezvous points to their command
- 20:36and control or the cnc server
- 20:42now the dns domain shadowing attacks
- 20:45involves a threat after gathering domain
- 20:47account credentials
- 20:49in order to silently create multiple
- 20:52subdomains
- 20:53to be used during the attacks so
- 20:56these subdomains typically point to
- 20:58malicious servers
- 21:00without alerting the actual owner of the
- 21:02parent domain
- 21:08next would be dns tunneling
- 21:12so threat actors who use dns tunneling
- 21:16place
- 21:16non-dns traffic within the dns traffic
- 21:20so this method often circumvents
- 21:22security solutions
- 21:24when a threat actor wishes to
- 21:26communicate with bots
- 21:28inside a protected network or
- 21:31exfiltrate data from the organization
- 21:34such as password databases so when the
- 21:37threat
- 21:38actor uses dns tunneling the different
- 21:41types of dns records are altered
- 21:44this is how dns tunneling works for
- 21:47cnc commands sent to a bootnet
- 21:51okay so the command data is split into
- 21:54multiple encoded chunks
- 21:56each chunk is placed into a lower level
- 22:00domain name
- 22:01okay or it is placed on the lower level
- 22:05domain name label
- 22:06of the dns query because there is no
- 22:10response from the local
- 22:12network dns for the query
- 22:15the request is sent to the isbc
- 22:17recursive dns servers
- 22:19now the recursive dns service will
- 22:21forward the query to the threat actors
- 22:23authoritative name server
- 22:26the process is repeated until all the
- 22:28queries containing the chunks of
- 22:30data are sent so when the threat
- 22:33actors authoritative name server
- 22:36receives the dns queries from the
- 22:38infected devices it
- 22:40sends responses to each dns query
- 22:43which contain the encapsulated encoded
- 22:46cnc commands
- 22:48so the malware on the compromised host
- 22:51recombines the chunks okay or the chunks
- 22:54of data
- 22:55and executes the commands hidden within
- 22:58the dns record
- 23:00now to stop this dns tunneling the
- 23:03network administrator
- 23:05must use filter that inspects
- 23:08dns traffic so pay close attention to
- 23:12dns
- 23:13queries that are no longer
- 23:17than the average or those that have a
- 23:20suspicious
- 23:21domain name dns solutions
- 23:24like the cisco open dns block match of
- 23:27the dns tunneling traffic by identifying
- 23:30suspicious
- 23:34domain
- 23:36next ip services is dhcp
- 23:40or the dynamic host configuration
- 23:42protocol
- 23:44dhep servers dynamically provide
- 23:46ipconfiguration information to clients
- 23:49now the figure here shows the typical
- 23:51sequence of the hcp message exchange
- 23:54between the client right and the server
- 23:58now in the figure the client broadcasts
- 24:02a dhcp discover message the dhep server
- 24:06responds
- 24:07with a unicast okay
- 24:10or unicast offer that includes
- 24:12addressing information
- 24:14the client can use the client broadcast
- 24:17at dhcp requests
- 24:19to tell the server that the client
- 24:21accepts the offer
- 24:24now lastly the server will respond
- 24:28with a unicast acknowledgement accepting
- 24:30the requests
- 24:33now what are the attacks on dhcp
- 24:37so the first one is dhep spoofing attack
- 24:41this occurs when a rogue dhtp server is
- 24:44connected to the network and provides
- 24:46false ip configuration parameters to
- 24:49legitimate clients
- 24:51so a rogue server can provide a variety
- 24:53of misleading information
- 24:57next is wrong default gateway now threat
- 25:00actors
- 25:01provide an invalid gateway or ip address
- 25:05of each host
- 25:06to create a man in the middle attack
- 25:09this may go entirely undetected as the
- 25:12intruder intercepts the data flow
- 25:14through the network next would be
- 25:17a wrong dns server so threat actor
- 25:20provides an
- 25:21incorrect dns server addresses pointing
- 25:24the user
- 25:25to a malicious website
- 25:29okay next would be wrong ip address
- 25:33now threat actor provides an invalid ip
- 25:35address
- 25:36invalid default gateway ip address or
- 25:38both
- 25:40the threat actor then creates a denial
- 25:42of service attack on the daycheep client
- 25:45now assume a jet actor has successfully
- 25:48connected to a rogue date gp server
- 25:50to a switch port on the same subnet as
- 25:52the target clients
- 25:54so the goal of the rogue server is to
- 25:57provide clients with false ip
- 25:58configuration
- 26:00information
- 26:03[Music]
- 26:06now in the figure here
- 26:07[Music]
- 26:09okay so the client broadcasts
- 26:12the hcp discovery message okay
- 26:15in the figure a legitimate client
- 26:18connects to the network
- 26:19and requires ip configuration parameters
- 26:22now the client broadcasts a dhcp
- 26:25discover requests
- 26:26looking for a response from the dhcp
- 26:30server
- 26:31both servers receive the message
- 26:36all right
- 26:40second dhcp server
- 26:43response with offer okay so let's start
- 26:47with http server here
- 26:48responding with offers
- 26:52now the figure shows how to lead or how
- 26:54the legitimate
- 26:55and the rogue day gp server each
- 26:58respond with valid ip configuration
- 27:01parameters
- 27:02so the dhp server here which is the
- 27:04legitimate dhb server
- 27:06will respond and so with the rogue dhcp
- 27:09server
- 27:10of the threat actor now the client
- 27:13replies
- 27:14to the first offer received
- 27:17and this client is not aware whether the
- 27:20offer
- 27:21came from a rogue the hp server
- 27:25[Music]
- 27:27next would be the client accepts the
- 27:29rogue http requests
- 27:31now in this scenario the client received
- 27:34the rogue
- 27:35offers first it broadcasts a dhcp
- 27:39request
- 27:40accepting the parameters which is from
- 27:43the rogue server now the legitimate
- 27:47and the rogue server is receive the
- 27:50request
- 27:55and next would be the rogue dhcp
- 27:58acknowledges
- 27:59the request all right
- 28:06network security best practices
- 28:12now on this segment we will be talking
- 28:14about the
- 28:15network security best practices so this
- 28:18includes the cia or the confidentiality
- 28:22availability and integrity now it is
- 28:25true that the list of network attack
- 28:27types is long
- 28:29but there are many best practices that
- 28:31you can use
- 28:32to defend your network as you will learn
- 28:35in this topic now network security
- 28:39consists of protecting information
- 28:42and information systems from authorized
- 28:44access
- 28:45use disclosure disruption modification
- 28:50or destruction most organizations follow
- 28:54the cia
- 28:55information security trial or
- 28:58confidentiality
- 28:59integrity and availability
- 29:04now let us define confidentiality so
- 29:06what is confidentiality
- 29:08so this means only authorized
- 29:10individuals or users
- 29:12entities or processes can access
- 29:15sensitive information
- 29:17it may require using cryptographic
- 29:19encryption algorithms such as
- 29:21aes to encrypt and decrypt data
- 29:25when you say integrity this refers to
- 29:27protecting data from an
- 29:29authorized alteration it requires the
- 29:32use of
- 29:33cryptographic hashing algorithms such as
- 29:36ssh or sha
- 29:39and a availability
- 29:42authorized users must have uninterrupted
- 29:45access
- 29:46to important resources and data it
- 29:49requires implementing redundant services
- 29:52gateways and links
- 29:59okay so how about the defense in-depth
- 30:01approach
- 30:02now to ensure a secure communication
- 30:05across
- 30:05both private and public networks
- 30:08you must secure devices including
- 30:10routers
- 30:11okay switches servers and hosts
- 30:17this is because known as or this is also
- 30:20known as the layered approach
- 30:22okay so it requires a combination of
- 30:24networking devices
- 30:26and services working together now
- 30:29consider the network here
- 30:30in the given diagram
- 30:36so several security devices and services
- 30:38are implemented
- 30:39to protect an organization's users and
- 30:42assets against
- 30:43tcp threats so
- 30:47it includes vpn what is a vpn so vpn
- 30:50is a router used to provide secure vpn
- 30:55services
- 30:56with corporate sites and remote access
- 30:58support for remote users
- 31:01using a secure encrypted tunnels
- 31:05you can also have the asa firewall so
- 31:08this
- 31:09is a dedicated device which provides
- 31:12stateful firewall services
- 31:14it ensures that internal traffic can go
- 31:16out and come back
- 31:18but external traffic cannot initiate
- 31:20connections
- 31:21to inside hosts next is ips
- 31:26an intrusion prevention system ips
- 31:29monitors incoming and outgoing traffic
- 31:31looking for malware
- 31:33network attack signatures and more
- 31:38if it is recognized as a threat it can
- 31:40immediately stop it
- 31:43okay next is essa
- 31:46or wsa the email service or email
- 31:50security appliance essa
- 31:52filters spam and suspicious emails
- 31:55the web security appliance or wsa
- 31:58filters
- 31:59known and suspicious internet malware
- 32:02sites next
- 32:05is aaa server so this server contains a
- 32:09secure database
- 32:11of who is authorized to access and
- 32:14manage network devices
- 32:16network devices authenticate
- 32:18administrative users
- 32:20using their databases
- 32:23so all network devices including the
- 32:25router and switches
- 32:27are hardened which means that they have
- 32:30been secured
- 32:31to prevent threat actors from gaining
- 32:33access and tampering with
- 32:35the devices so next
- 32:38you must secure the data as it travels
- 32:41across
- 32:42various links so this may include
- 32:45internal traffic
- 32:47but it's more important to protect the
- 32:48data that travels
- 32:50outside of the organization to broad
- 32:53sites
- 32:54telecommuter sites and partner sites
- 33:02firewall so a firewall is a system
- 33:06or group of systems that enforces an
- 33:08access control policy
- 33:10between networks okay
- 33:14now all firewalls share some common
- 33:17properties
- 33:19so firewalls are resistant to network
- 33:21attacks
- 33:23firewalls are the only transit points
- 33:26between internal corporate networks and
- 33:28external networks
- 33:29because all traffic flows through the
- 33:31firewall
- 33:33so firewalls enforce the access control
- 33:37policy
- 33:39there are several benefits of using
- 33:41firewall in a network
- 33:43so first they prevent exposure of
- 33:46sensitive
- 33:47hosts resources and applications to
- 33:50untrusted users
- 33:52they sanitize protocol flow which
- 33:56prevents the exploitation of protocol
- 33:58flaws
- 33:59they block malicious data from servers
- 34:01and clients
- 34:03they reduce security management
- 34:05complexity by offloading most of the
- 34:07network access control
- 34:09to a few firewalls in the network
- 34:12so firewalls also present some
- 34:14limitations
- 34:16okay a misconfigured firewall can
- 34:20have serious consequences for the
- 34:22network
- 34:23such as becoming a single point of
- 34:24failure
- 34:26so the data from many applications
- 34:29cannot be passed through the firewall
- 34:31security
- 34:33users might proactively search four ways
- 34:35around the firewall
- 34:37to receive blocked material which
- 34:40exposes the network
- 34:41to potential attack network performance
- 34:45can slow down traffic can be tunneled
- 34:49or hidden so that it appears as
- 34:52legitimate traffic
- 34:53through the firewall
- 35:00next is ips or intrusion prevention
- 35:03system
- 35:04so to prevent data or to defend
- 35:08okay so against the fast moving and
- 35:10evolving attacks
- 35:12you may need cost effective detection
- 35:14and prevention systems such
- 35:16as intrusion detection systems or ids
- 35:19or the most scalable intrusion
- 35:22prevention system
- 35:23or ips now the network architecture
- 35:27integrates these solutions into the
- 35:29entry and exit points of the network
- 35:32so the ips and ids technologies
- 35:36share several characteristics okay
- 35:39so ideas and ips technologies are both
- 35:42deployed as sensors
- 35:44an ids or ips sensor can be
- 35:48in the form of several
- 35:51different devices it could be in a form
- 35:54of a router configured with cisco ios
- 35:56ips software
- 35:58a device is specifically designed to
- 36:00provide a dedicated
- 36:01ids or ips services a network module
- 36:05installed
- 36:06in an adaptive security appliance or asa
- 36:09switch or router
- 36:13now the figure shows how an ips handles
- 36:16denied traffic so the threat actor here
- 36:21sends a packet distinct to the target
- 36:24laptop
- 36:24so here's our target so the ips
- 36:28intercepts the traffic okay
- 36:31and evaluates it against known threats
- 36:35and the configured policies so the ips
- 36:39sends a log message to the management
- 36:41console
- 36:42and then the ips drops the packet
- 36:47now ideas and ips technologies detect
- 36:49patterns in network traffic using
- 36:51signatures
- 36:52a signature is a set of rules that an
- 36:55ids or ips uses to detect malicious
- 36:58activity
- 36:59signatures can be used to detect severe
- 37:02breaches of security
- 37:04to detect common network attacks and to
- 37:07gather information
- 37:09so ids and ips technologies can detect
- 37:13atomic signature patterns or single
- 37:15packet or
- 37:16the composite signature patterns we call
- 37:19it the multi-packet
- 37:25content security devices
- 37:29so content security appliances include
- 37:33fine grained control over email and web
- 37:35browsing
- 37:36for an organization's users
- 37:40so this includes the cisco email
- 37:42security appliance or essa
- 37:44now this email security appliance
- 37:48is a special device designed to monitor
- 37:51simple mail transfer protocol or smtp
- 37:55so the esa is constantly updated by
- 37:58real-time
- 37:59feds from the cisco talos
- 38:02which detects and correlates threats and
- 38:05solutions
- 38:06by using a worldwide database monitoring
- 38:08system
- 38:10now this threat intelligence data is
- 38:13pulled by the cisco esa
- 38:16every three to five minutes
- 38:19now referring to the figure here okay
- 38:23so in here the threat actor sends a
- 38:25piecing attack to an important host on
- 38:28the network
- 38:30and then the firewall forwards all email
- 38:33to the esa now the esa
- 38:36analyzes the email logs it and discard
- 38:44it
- 38:46the next component would be the cisco
- 38:48web security appliance
- 38:49or the wsa now the cisco web security
- 38:53appliance
- 38:54is a mitigation technology for web-based
- 38:57threats
- 38:58it helps organization address the
- 39:01challenges of securing and controlling
- 39:03web traffic now this wsa
- 39:07combines advanced malware protection
- 39:10application visibility and control
- 39:12acceptable use policy control and
- 39:14reporting
- 39:16wsa provides complete control over
- 39:20how users access the internet certain
- 39:23features and applications such as
- 39:25chat messaging video
- 39:28and audio can be allowed restricted with
- 39:32time and bandwidth limits or
- 39:34blocked according to the organization's
- 39:36requirements
- 39:37the wsa can perform block listing
- 39:40okay that includes the url filtering
- 39:43malware scanning
- 39:45url categorization web application
- 39:48filtering
- 39:49and encryption and decryption of the web
- 39:51traffic
- 39:54now from the figure here a user
- 39:58attempts to connect a website
- 40:01okay the firewall forwards the website
- 40:03request
- 40:04to the wsa now the wsa
- 40:09evaluates the url and determines
- 40:12that it is non-blacklisted site
- 40:15so the wsa disregards or discards the
- 40:19packet
- 40:20and sends an access denied message to
- 40:22the user
- 40:30on this section we will be talking about
- 40:33cryptography
- 40:35early in the previous topic cryptography
- 40:37is mentioned as part of the cia
- 40:40or the confidentiality integrity
- 40:43and availability information security
- 40:45triad
- 40:46in this topic we will get deeper dive
- 40:49into many types of cryptography
- 40:53and how they are used to secure the
- 40:55network
- 41:00securing communications organization
- 41:04must have uh provide or must provide
- 41:07supports to secure the data
- 41:10as it travels across the links so this
- 41:13may include
- 41:14internal traffic but it is even more
- 41:17important to protect the data that
- 41:18travels
- 41:19outside organization to broad sites
- 41:22telecommuter sites
- 41:23and partner sites now these are the four
- 41:27elements
- 41:28of a secure communication first
- 41:32there should be data integrity so data
- 41:35integrity guarantees that the message
- 41:37was not altered
- 41:38any changes to data in transit will be
- 41:41detected
- 41:42integrity is ensured by implementing
- 41:45either message digest
- 41:46version 5 or md5 or the secure hash
- 41:50algorithm or sha hash generating
- 41:53algorithms
- 41:55second is attend origin authentication
- 41:59it guarantees that the message is not
- 42:02forgery
- 42:04right or is not first and that's
- 42:06actually come from whom
- 42:08it states many modern networks ensure
- 42:11authentication with protocols such as
- 42:13hash message authentication code or the
- 42:17hmap
- 42:20next would be data confidentiality
- 42:24so guarantees that the only authorized
- 42:26users
- 42:27can read the message if the message is
- 42:31intercepted
- 42:32it cannot be deciphered within a
- 42:34reasonable amount of time
- 42:36so data confidentiality is implemented
- 42:38using symmetric and asymmetric
- 42:40encryption algorithm
- 42:44so the last one be data non-reputation
- 42:49it guarantees that the sender cannot
- 42:50repudiate or refute
- 42:53the validity of the message sent
- 42:56non-repugation
- 42:57relies on the fact that only the sender
- 42:59has the unique characteristics
- 43:01or signature for how that message
- 43:05is treated so cryptography
- 43:08can be used almost anywhere that there
- 43:12is data communication
- 43:14in fact the trend is towards
- 43:17all communications being encrypted
- 43:24okay so let's focus on data integrity
- 43:28hash functions are used to ensure the
- 43:30integrity of a message
- 43:32so they guarantee the message data has
- 43:34not changed accidentally or
- 43:38intentionally now in the figure here
- 43:42the sender is sending one hundred
- 43:44dollars of money
- 43:46okay and then it transferred to
- 43:50the other uh or the the recipient
- 43:54okay in here if you will observe from
- 43:57100
- 43:58okay paid to alex
- 44:02okay and then you've got there paid to
- 44:05jeremy
- 44:06it was changed or altered from the one
- 44:09hundred dollars
- 44:11to one thousand dollars okay
- 44:14so the sender wants to ensure that the
- 44:16message is not altered on its way
- 44:18to the receiver or recipient
- 44:22now the sending device inputs the
- 44:24message into a hashing algorithm
- 44:27and computes its fixed length hash
- 44:30okay so which is this 4e h
- 44:34i d x 67 and m op9
- 44:38alright now this hash is then attached
- 44:42to the message
- 44:43and send it to the receiver both the
- 44:46message and the hash
- 44:48are in plain text now the receiving
- 44:51device removes the hash from the message
- 44:54and inputs the message into the same
- 44:56hashing algorithm
- 44:58if the computed hash is equal to the one
- 45:01that is attached to the message
- 45:03then the message has not been altered
- 45:06while in transit
- 45:08if the hashes are not equal as shown in
- 45:11the figure
- 45:12all right so they are not the same okay
- 45:15so then the integrity of the message can
- 45:17no longer be trusted
- 45:18so it was altered while in transit
- 45:24okay so hash function
- 45:27there are three well known hash
- 45:28functions you've got the md5 with 128
- 45:31bit digest
- 45:33sha hashing algorithm and the sha2
- 45:36okay now the md5 with a 128-bit digest
- 45:41is a one-way function that produces
- 45:43128-bit hash message md5
- 45:46is a legacy algorithm that should only
- 45:50be used
- 45:50when no better alternatives are
- 45:52available so use
- 45:54xiatu instead okay now
- 45:57sha hashing algorithm or shell 1 is very
- 46:00similar to the md5 hash functions
- 46:03so xiao 1 creates a 160 bit hashed
- 46:06message and is slightly slower than md5
- 46:10xiaowan has the known flaws and is a
- 46:13legacy algorithm
- 46:15that's why we are recommending the use
- 46:17of sha
- 46:182 okay now shot 2 includes
- 46:22shia 224 or 224 bit
- 46:25256 bit 384 bit
- 46:29512 bit okay
- 46:32so shot 256 384 and 512
- 46:36are the next generation algorithm and
- 46:38should be used
- 46:39whenever possible now while hashing can
- 46:43be used to detect accidental changes
- 46:46it cannot be used to guard against
- 46:47deliberate changes
- 46:49this means that anyone can compute a
- 46:52hash
- 46:52for any data if they have the correct
- 46:55hash function
- 46:56therefore hashing is vulnerable to men
- 47:00in the middle or mitm attacks and does
- 47:03not provide
- 47:04security to transmitted data
- 47:09okay now i have here an example sorry so
- 47:12these are the three well-known hash
- 47:14functions
- 47:16so let's start with the md5 128-bit
- 47:19digest
- 47:21so md5 is a one-way function that
- 47:24produces 128-bit
- 47:25hash message as shown in the figure
- 47:29all right now mg5 is a legacy algorithm
- 47:32as mentioned earlier that should only be
- 47:34used
- 47:35when no better alternatives are
- 47:37available
- 47:38so we are recommending the use of xia2
- 47:42so in the figure a plain text message is
- 47:45passed through md5 hash function
- 47:49okay the result is bit
- 47:52hashed message
- 47:56next is the hashing algorithm sha1
- 48:00is very similar to md5
- 48:03okay so several version exists you've
- 48:06got xiao one creates 160 bit hash
- 48:08message and it's slightly slower than
- 48:11md5
- 48:12so xiao one has known flaws and
- 48:15is also a legacy algorithm
- 48:18so again we are recommending the use of
- 48:22chat too now in the figure
- 48:25a plain text message is passed through
- 48:27the shah hash
- 48:28function so the result is a hashed
- 48:32message
- 48:35third would be xia2 this includes sha224
- 48:39as discussed earlier 256 384
- 48:43and 512 so this are the next generation
- 48:47of algorithms and should be used
- 48:51whenever possible okay now while hashing
- 48:54can be used to detect accidental changes
- 48:58it cannot be used to guard against
- 48:59deliberate changes
- 49:01there is no unique identifying
- 49:04information from the sender
- 49:06in the hashing procedures this means
- 49:09that anyone can compute a hash for
- 49:12any data if they have the correct hash
- 49:15function
- 49:17for example when the message traverses
- 49:21the network
- 49:22a potential threat actor could intercept
- 49:24the message right
- 49:25so change it recalculate the hash
- 49:28and append it to the message the
- 49:31receiving device will only validate
- 49:33against
- 49:34whatever has is appended so take note so
- 49:37therefore
- 49:38hashing is vulnerable to man in the
- 49:41middle attack
- 49:42and does not provide security to
- 49:45transmitted data
- 49:47so to provide integrity and origin
- 49:49authentication
- 49:51something more is required right
- 49:56so next would be origin authentication
- 50:00so to add authentication to the
- 50:02integrity assurance
- 50:04use a keyed hash message authentication
- 50:07code
- 50:08or the hmac okay hmac uses
- 50:12an additional secret key as input to the
- 50:15hash function
- 50:18so only parties who have access to the
- 50:20secret key
- 50:21can compute the digest of an hmac
- 50:23function
- 50:24this defeats the man in the middle
- 50:26attack and provides authentication
- 50:29of the origin or data origin
- 50:35okay now as shown in the figure
- 50:39the hmac is calculated using any
- 50:41cryptographic algorithm
- 50:44that combines cryptographic hash
- 50:45function with a secret key
- 50:48hash functions are the basis of the
- 50:50protection mechanism for each map
- 50:53only the sender and the receiver know
- 50:55the secret key
- 50:57and the output of the hash function now
- 50:59depends on the input data
- 51:01and the secret key so only parties who
- 51:05have access to the secret key
- 51:07can compute the digest of an hmac
- 51:10function
- 51:12okay so as mentioned earlier this will
- 51:14defeat
- 51:16right the man in the middle attacks and
- 51:18provides authentication
- 51:21of the data origin okay
- 51:25so also mentioned earlier if two parties
- 51:27share a secret key
- 51:29and use the hmac functions for
- 51:31authentication
- 51:32a properly constructed hmac digest of a
- 51:35message
- 51:36that the party has received indicates
- 51:38that the only the other party
- 51:40was the originator of the message so
- 51:43this is because the other party
- 51:45who says the secret key
- 51:54now how do we create the hmac value now
- 51:57as shown here in the diagram
- 51:59the sending device inputs data such as
- 52:03uh
- 52:04jerry smith pay uh
- 52:07100 and the secret key
- 52:10okay we've got a secret key there
- 52:13now this has been into the hashing
- 52:15algorithm
- 52:17and calculates the fixed length hmac
- 52:19digest
- 52:20so this authenticated digest is then
- 52:23attached to the message
- 52:25and sent to the receiver
- 52:32verifying the hmac value now again in
- 52:35the figure
- 52:36the receiving device removes the digest
- 52:40from the message and uses the plain text
- 52:43message
- 52:44with its secret key as input
- 52:47into the same hashing function now if
- 52:50the digest that is calculated by the
- 52:52receiving device is equal
- 52:54to the digest that was sent the message
- 52:56has not been
- 52:57altered okay so additionally
- 53:01the origin of the message is
- 53:02authenticated because only the sender
- 53:05possesses a copy of the shared secret
- 53:07key
- 53:08now the hmac function has to ensure
- 53:11the authenticity of the message
- 53:19so next would be the cisco router hmac
- 53:22example here now the figure
- 53:26shows how hmacs are used by cisco
- 53:28routers
- 53:29that are configured to use the open
- 53:31shortest path first or ospf routing
- 53:33protocol
- 53:35routing authentication okay
- 53:38now in here r1 is sending a link state
- 53:41updates or lsu
- 53:43regarding a route to network 10.2.0.0
- 53:4916. okay so r1 calculates the hash value
- 53:53using the lsu message
- 53:56and the secret key okay
- 53:59now the resulting hash value is sent
- 54:02with lsu to
- 54:03router 2. now router 2 calculates the
- 54:07hash value
- 54:09using the lsu and its secret key so r2
- 54:13accepts the update
- 54:15if the hash value matched if they do not
- 54:18match
- 54:19then r2 discards the update
- 54:25data confidentiality so there are two
- 54:28classes
- 54:28of encryption used to provide data
- 54:30confidentiality
- 54:32so these are or these two classes differ
- 54:36in how they use
- 54:37keys okay so you've got symmetric
- 54:40such as this 3ds and
- 54:44aes or the advanced encryption standard
- 54:50okay so these are based on the premise
- 54:53that
- 54:53its communicating party shows the
- 54:55pre-shared key
- 54:57so data confidentiality can also be
- 54:59ensured
- 55:00using asymmetric algorithms
- 55:03including okay so the rivers
- 55:06shamir and adelman or the lrsa
- 55:10and the public key infrastructure or the
- 55:12pki
- 55:14okay now the figure here highlights some
- 55:17differences between
- 55:18each encryption algorithm method
- 55:22so one of the most notable difference is
- 55:25of course
- 55:26symmetrical uses the same key and
- 55:30asymmetric uses different keys
- 55:34all right so symmetric
- 55:37key lengths are short 40 bits to 256
- 55:41well for asymmetric it's 512 to 4096
- 55:45bits
- 55:46okay so symmetric is faster than
- 55:48asymmetric encryption
- 55:51asymmetric computationally
- 55:54tasking okay therefore slower than
- 55:58symmetrical so symmetric is commonly
- 56:01used
- 56:02for encrypting bulk data such as in the
- 56:04vpn traffic
- 56:06and asymmetric is commonly used in a
- 56:09quick data transaction such as https
- 56:12when accessing your bank data
- 56:20let's dig in into symmetric encryption
- 56:23so symmetric algorithms use the same
- 56:27pre-shared key to encrypt and decrypt
- 56:30data so a pre-shared key also called
- 56:33secret key
- 56:35is known by the sender and the receiver
- 56:37before any encrypted
- 56:38communication can take place
- 56:41so to help illustrate how symmetric
- 56:43encryption works
- 56:45consider an example here okay so
- 56:48assuming that we have
- 56:49here alice and bob live on different
- 56:52location
- 56:53and want to exchange secret messages
- 56:55with one another
- 56:57through the email system now in this
- 57:00example
- 57:01alice wants to send a secret message to
- 57:04bob
- 57:05okay now in the figure alice and bob
- 57:08have identical keys okay
- 57:11to a single padlock these keys
- 57:14were exchanged prior to sending any
- 57:17secret
- 57:18messages so alice writes a secret
- 57:22message
- 57:23and put it in a small box that she likes
- 57:26using the padlock with her key
- 57:29okay now she mails the box to bob
- 57:33the message is safely locked inside the
- 57:35box
- 57:36as the box makes its way through the
- 57:38post office system
- 57:40now when bob receives the box he uses
- 57:44his key to unlock the padlock
- 57:46and retrieve the message bob can use the
- 57:49same box and padlock to send secret
- 57:52reply
- 57:52to alice okay now
- 57:56today symmetric encryption algorithms
- 57:59are commonly used with vpn traffic
- 58:02this is because symmetric algorithms use
- 58:04less cpu resources
- 58:06than asymmetric encryption algorithms so
- 58:10encryption and decryption of data is
- 58:12fast when using a vpn
- 58:15when using symmetric encryption
- 58:16algorithms like any other type of
- 58:18encryption
- 58:19the longer the key the longer it will
- 58:21take for someone
- 58:23to discover the key so most
- 58:26encryption keys are between 112
- 58:29and 256 bits so to ensure that the
- 58:33encryption is safe
- 58:35use a minimum key length of 128 bits
- 58:39so use a longer key for
- 58:43more secure communication
- 58:48well symmetric encryption algorithms are
- 58:50described in the table so you've got
- 58:52this okay 3ds aes
- 58:56seal and you've got the rifles cyber or
- 58:59rc
- 59:00okay now this is a legacy symmetric
- 59:04encryption algorithm 3ds is the newer
- 59:08version of this
- 59:09but it repeats the dash algorithm
- 59:11process three times
- 59:13okay aes or the advanced encryption
- 59:16standard
- 59:17is a secure and more efficient algorithm
- 59:19than 3ds
- 59:20it is popular and recommended symmetric
- 59:23encryption algorithm
- 59:26so next is seal or the software
- 59:28optimized encryption algorithm
- 59:30this is faster alternative symmetric
- 59:32encryption algorithm to 3ds
- 59:35des and aes
- 59:39the last one would be the right for a
- 59:40rybast cypress or rc series algorithm
- 59:44this algorithm was developed by ron
- 59:46rivest
- 59:48so several variations have been
- 59:50developed
- 59:51but rc4 is the most prevalent
- 59:54in use so rc4 is a stream cyber
- 59:58and is used to secure web traffic in
- 1:00:01ssl and tls
- 1:00:07let's get deeper into asymmetric
- 1:00:10encryption
- 1:00:12so algorithms also called public key
- 1:00:16algorithms are designed so that the key
- 1:00:18that is used for encryption
- 1:00:20is different from the key that is used
- 1:00:22for decryption
- 1:00:24okay so as shown on this diagram here
- 1:00:27now the decryption key
- 1:00:29cannot uh in any reasonable amount of
- 1:00:32time
- 1:00:33be calculated from the encryption key
- 1:00:35and vice versa
- 1:00:37so asymmetric algorithms use a public
- 1:00:41key
- 1:00:42and a private key so both keys
- 1:00:45are capable of encryption process but
- 1:00:48the complementary paired key
- 1:00:50is required for decryption
- 1:00:54so the process is also reversible so
- 1:00:57data encryption with a public key
- 1:00:58requires the private key
- 1:01:00to decrypt so asymmetric algorithms
- 1:01:04achieve confidentiality authentication
- 1:01:08and integrity by using this process
- 1:01:12okay now because neither party
- 1:01:15has a shared secret very long key
- 1:01:18lengths
- 1:01:19must be used so asymmetric encryption
- 1:01:23can use key lengths between 512
- 1:01:27to 4096 bits
- 1:01:30so key lengths greater than or equal to
- 1:01:331024 bits
- 1:01:34can be trusted while shorter okay
- 1:01:38key lengths are considered unreliable
- 1:01:48all right so what are the examples okay
- 1:01:51of protocols that
- 1:01:52use asymmetric key algorithms so this
- 1:01:55includes the ike okay or the internet
- 1:01:58key exchange this is a fundamental
- 1:02:01component of
- 1:02:02ipsec vpns so the next one is
- 1:02:06ssl or the secure socket layer
- 1:02:09so this protocol provides a secure
- 1:02:11remote access connection
- 1:02:13to network devices okay
- 1:02:18next is ssh or the secure shell
- 1:02:21this protocol provides a secure remote
- 1:02:23access connection to network devices
- 1:02:27you also have this uh pretty good
- 1:02:30privacy or pgp
- 1:02:32this computer program provides a
- 1:02:33cryptographic privacy and authentication
- 1:02:36it is often used to increase the
- 1:02:39security of email communications
- 1:02:42so asymmetric algorithms are
- 1:02:44substantially slower than symmetric
- 1:02:46algorithms their design
- 1:02:49is based on computational problems such
- 1:02:52as
- 1:02:53factoring extremely large numbers or
- 1:02:55computing discrete
- 1:02:56logarithms of extremely large numbers
- 1:03:01so because they are slow asymmetric
- 1:03:03algorithms are typically used in low
- 1:03:05volume cryptographic
- 1:03:07mechanisms such as digital signatures
- 1:03:10and key exchange okay however
- 1:03:15the key management for asymmetric
- 1:03:17algorithms
- 1:03:19tends to be simpler than asymmetric or
- 1:03:22than symmetric algorithms
- 1:03:24because usually one of the two
- 1:03:27encryption or decryption keys can be
- 1:03:30made
- 1:03:31public
- 1:03:35so common examples of asymmetric
- 1:03:37encryption algorithms
- 1:03:39includes also daffy helman or the dh
- 1:03:43right you've got dss or the digital
- 1:03:46signature standard
- 1:03:48and digital signature algorithms you'll
- 1:03:51have the rsa
- 1:03:52reversed shamir and adelman encryption
- 1:03:54algorithm
- 1:03:55you've got the ei gamal and the
- 1:03:58elliptical curve
- 1:03:59techniques okay now the daffy helmet
- 1:04:03algorithm allows two parties to agree
- 1:04:05on a key that they can use to encrypt
- 1:04:08messages
- 1:04:09they want to send to each other so the
- 1:04:12security of this algorithm depends on
- 1:04:15the assumption that
- 1:04:16it is easy to raise number of certain
- 1:04:19power but
- 1:04:20difficult to compute which power was
- 1:04:22used
- 1:04:23given the number and the outcome
- 1:04:27now dss dsa dss specifies dsa
- 1:04:32okay as the algorithm for digital
- 1:04:33signatures so dsa
- 1:04:35is a public key algorithm based on the
- 1:04:39ei gamal
- 1:04:41signature scheme so signature creation
- 1:04:44speed is
- 1:04:45similar to rsa but is 10 to 40 times
- 1:04:49lower for verification
- 1:04:52okay next is rsa
- 1:04:55rsa is for public key cryptography that
- 1:04:58is based on the current difficulty of
- 1:05:00factoring very large numbers
- 1:05:03so it is the first algorithm known
- 1:05:06to be a suitable for signing as well as
- 1:05:09encryption okay it is widely used in
- 1:05:12electronic commerce protocols
- 1:05:14and is believed to be the secure given
- 1:05:17sufficiently long keys and the use of
- 1:05:21up-to-date implementations
- 1:05:24right so next would be the ea gamal
- 1:05:28okay this is an asymmetric key
- 1:05:30encryption algorithm for public
- 1:05:33cryptography which is based on the
- 1:05:35deputy helmonkey
- 1:05:36agreement so the disadvantage of the
- 1:05:39eigamal system is that
- 1:05:40the encryption message becomes very big
- 1:05:43about twice the size of the original
- 1:05:45message
- 1:05:46and for this reason it is only used for
- 1:05:49small messages such as secret keys
- 1:05:53all right so the larger the length the
- 1:05:56secure
- 1:05:57okay the more secure it is so
- 1:06:00the last one would be elliptical curve
- 1:06:02techniques
- 1:06:03so elliptic curve cryptography can be
- 1:06:06used to adapt
- 1:06:07many cryptographic algorithms such as
- 1:06:09the epi helmand
- 1:06:10or ei gamal so the main advantage of
- 1:06:13elliptic
- 1:06:14curve cryptography is that the keys
- 1:06:18can be much smaller
- 1:06:24now deputy helman is an asymmetric
- 1:06:27mathematical algorithms
- 1:06:29where two computers generate an
- 1:06:30identical shared key
- 1:06:32without having communicated before okay
- 1:06:35so the new shared key is never actually
- 1:06:38exchanged between the sender and the
- 1:06:40receiver
- 1:06:41however because both parties know it
- 1:06:44they can be used by an encryption
- 1:06:47algorithm to encrypt traffic
- 1:06:49between the two systems right
- 1:06:52so here are the three examples of
- 1:06:55instances
- 1:06:56when dh is commonly used
- 1:06:59first data is exchanged using ipsec vpn
- 1:07:05okay second data is encrypted on the
- 1:07:08internet using either ssl
- 1:07:11or tls
- 1:07:14third ssh data is exchanged
- 1:07:18okay now the daffy helman
- 1:07:21uses unbelievably large number of
- 1:07:25in its calculations unfortunately
- 1:07:28asymmetric key systems are extremely
- 1:07:30slow
- 1:07:31for any sort of bulk encryption so
- 1:07:33therefore
- 1:07:35it is common to encrypt the bulk of
- 1:07:38the traffic using symmetric algorithm
- 1:07:40such as 3ds
- 1:07:42aes and then use daffy helmet or dh
- 1:07:45algorithm to create keys
- 1:07:48that will be used by encryption
- 1:07:50algorithms
- 1:07:55now to help illustrate how dh operates
- 1:07:58so refer to the figure here all right
- 1:08:02now the colors in the figure will be
- 1:08:05used instead of complex
- 1:08:06long numbers to simplify the dh key
- 1:08:09agreement process
- 1:08:11okay now the dhk exchange begins with
- 1:08:15alice and bob
- 1:08:16agreeing on an arbitrary common color
- 1:08:19that does not need to be kept secret
- 1:08:23okay now
- 1:08:27the agreed on color okay in our example
- 1:08:30is yellow
- 1:08:31for instance right next alice and bob
- 1:08:34will each select a secret color
- 1:08:38okay so alice chooses red
- 1:08:41and bob chooses blue here
- 1:08:45now these secret colors will never be
- 1:08:47shared with anyone
- 1:08:49the secret color represents the chosen
- 1:08:52secret private right
- 1:08:56so
- 1:09:00what will happen next is that alice and
- 1:09:03bob
- 1:09:03now makes the shirt common color okay
- 1:09:08so yellow with the respective secret
- 1:09:10color to produce a private color
- 1:09:14so therefore alice will mix the yellow
- 1:09:17one
- 1:09:18with her red color to produce a private
- 1:09:21color of
- 1:09:22orange all right now
- 1:09:25bob will mix the yellow and the blue to
- 1:09:28produce
- 1:09:30a private color green now ali sends her
- 1:09:34private color orange
- 1:09:38to bob and bob sends her private or his
- 1:09:41private
- 1:09:42color green to alice
- 1:09:46all right now alice and bob
- 1:09:49each mix the color they received very
- 1:09:52own
- 1:09:54so original secret color red for alice
- 1:09:58and blue for bob the result is the final
- 1:10:01brown mixture
- 1:10:03all right that is identical to the
- 1:10:06others
- 1:10:07final color mixture so the brown color
- 1:10:10represents the resulting shared
- 1:10:13secret key between bob and alice
- 1:10:16so dh or deputy helmand security uses
- 1:10:19unbelievably large number in this
- 1:10:21calculations for example
- 1:10:24a dh 10 24 bit number is roughly equal
- 1:10:27to a decimal number of
- 1:10:30309 digits all right so considering that
- 1:10:34a billion is 10 decimal digits
- 1:10:37one can easily imagine the complexity of
- 1:10:40working
- 1:10:41with not one but many 309
- 1:10:45digit decimal numbers now
- 1:10:48unfortunately asymmetric key systems are
- 1:10:51extremely slow
- 1:10:52for any sort of bulk encryption so
- 1:10:55therefore
- 1:10:56it is common to encrypt the bulk of the
- 1:10:59traffic
- 1:11:00using the symmetric algorithm okay so
- 1:11:03as mentioned earlier 3ds or aes
- 1:11:06and then use dh algorithm to create keys
- 1:11:09that will be used by an encryption
- 1:11:11algorithm
- 1:11:15so that's the end of this video lecture
- 1:11:17thank you for watching and listening
- 1:11:19have a great day
- 1:11:27[Music]
- 1:11:31you
About this transcript
This page contains the full transcript of ENSA M3 Network Security Concepts Part 2 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 7,842 words across 1,603 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.