YouTube2Text

ENSA M3 Network Security Concepts Part 2 — Transcript

by Santelmo · 7,842 words · 1,603 segments · language en · Watch on YouTube

Full transcript

  1. 0:04hi hello there
  2. 0:05welcome to network security concepts
  3. 0:08part
  4. 0:08two so perhaps you've heard one of the
  5. 0:12hundreds of new stories about
  6. 0:14data security rates within a large
  7. 0:16corporation
  8. 0:18or even government was your credit card
  9. 0:21number exposed by bridge
  10. 0:24how about your private health
  11. 0:25information
  12. 0:27would you like to know how to prevent
  13. 0:29this data breaches
  14. 0:31the field of network security is growing
  15. 0:33every day
  16. 0:35this module provides a detailed
  17. 0:37landscape
  18. 0:38of the types of cyber crime and the many
  19. 0:42ways
  20. 0:42we have to fight back against cyber
  21. 0:44criminals
  22. 0:45let's get started so welcome to part two
  23. 0:52okay so the objectives
  24. 0:56okay so explain how vulnerabilities
  25. 0:58threats
  26. 0:59and exploits can be mitigated to enhance
  27. 1:03network security
  28. 1:05so on this part two of the video lecture
  29. 1:07we will be talking about tcp
  30. 1:09and udp vulnerabilities ip services
  31. 1:13network security best practices and
  32. 1:16cryptography
  33. 1:20so let's start with tcp and udp
  34. 1:24vulnerabilities
  35. 1:26so while some attacks target ip this
  36. 1:29topic discusses attacks
  37. 1:31that target tcp and udp
  38. 1:35tcp segment information appears
  39. 1:37immediately after the ip header
  40. 1:40the fields of the tcp segment and the
  41. 1:42flags for the control bits
  42. 1:44fields are displayed on this figure here
  43. 1:48so the following are the six control
  44. 1:50bits of the tcp segment
  45. 1:52so you've got the urg or urgent pointer
  46. 1:56field significant
  47. 1:58ack or the acknowledgement
  48. 2:01psh or the push function rsd for the
  49. 2:04reset
  50. 2:07syn for the synchronized sequence
  51. 2:08numbers and fin
  52. 2:10no more data from the sender
  53. 2:16tcp provides this services
  54. 2:19so you've got reliability delivery flow
  55. 2:23control
  56. 2:23and stateful communication
  57. 2:27so under the reliability delivery
  58. 2:30tcp incorporates acknowledgements to
  59. 2:33guaranteed delivery
  60. 2:35instead of relying on the upper layer
  61. 2:37protocols to detect and resolve
  62. 2:39errors so if a timely acknowledgement is
  63. 2:43not received
  64. 2:44the sender retransmits the data
  65. 2:48requiring acknowledgement of received
  66. 2:50data
  67. 2:51can cause substantial delays
  68. 2:55examples of application layer protocols
  69. 2:57that make use of tcp
  70. 3:00okay or the reliability of tcp includes
  71. 3:03http
  72. 3:04ssl all right or tls
  73. 3:07ftp dns zone transfers
  74. 3:11and others flow control
  75. 3:15tcp implements flow control to address
  76. 3:17this issue
  77. 3:19rather than acknowledge one segment at a
  78. 3:22time
  79. 3:23multiple segments can be acknowledged
  80. 3:25with a single acknowledgement segment
  81. 3:31stateful communication tcp stateful
  82. 3:34communication between the two parties
  83. 3:36occurs
  84. 3:37during the tcp three-way handshake
  85. 3:40so before data can be transferred using
  86. 3:43tcp
  87. 3:45a three-way handshake opens the tcp
  88. 3:47connection
  89. 3:49and then if both sides agree to the tcp
  90. 3:51connection
  91. 3:52data can be sent and received by both
  92. 3:55parties using tcp
  93. 4:01now a tcp connection is established in
  94. 4:03three steps as shown in the figure
  95. 4:05diagram here okay so the first one would
  96. 4:08be
  97. 4:09the initiating client
  98. 4:12requests a client to server
  99. 4:14communication session
  100. 4:16with the server the server
  101. 4:20then acknowledges the client to server
  102. 4:22communication session
  103. 4:24and requests a server to client
  104. 4:26communication session
  105. 4:29the initiating client acknowledges the
  106. 4:31server to client communication
  107. 4:34this is an example of a three-way
  108. 4:40handshaking
  109. 4:46how about tcp syn flood attacks or the
  110. 4:49tcp attacks
  111. 4:51network applications use tcp or udp
  112. 4:55ports
  113. 4:56threat actors conduct port scans of
  114. 4:59target devices
  115. 5:00to discover which services they offer
  116. 5:05so the tcp syn flood attack exploits the
  117. 5:08tcp
  118. 5:09three-way handshake presented in the
  119. 5:11earlier diagram
  120. 5:13now the figure here shows a threat actor
  121. 5:16continually sending tcp syn session
  122. 5:19request packets
  123. 5:21with a randomly spoofed source ip
  124. 5:23address to target
  125. 5:27okay now the target device replies with
  126. 5:29tcp
  127. 5:30scene acknowledgement packet three
  128. 5:32spoofed ip address and waits for the tcp
  129. 5:35acknowledgement packet
  130. 5:37okay now those responses never arrive
  131. 5:41eventually the target host is
  132. 5:44overwhelmed
  133. 5:45with half open tcp connections
  134. 5:49and tcp services are denied
  135. 5:52to legitimate users
  136. 5:56okay
  137. 6:00how about terminating a tcp connection
  138. 6:04terminating a tcp session uses the
  139. 6:06following four-way exchange process
  140. 6:09first when the client has no more data
  141. 6:12to send in the stream
  142. 6:14it sends a segment with the fin
  143. 6:17plug set okay
  144. 6:20now the server sends an acknowledgement
  145. 6:25to acknowledge the receipt of the fin
  146. 6:28to terminate the session from client to
  147. 6:32server the server
  148. 6:35sends fin or fin
  149. 6:39to the client to terminate the server to
  150. 6:42client session
  151. 6:44and then last would be the client
  152. 6:47responds
  153. 6:47with an ack or acknowledgement to
  154. 6:50acknowledge the fin
  155. 6:51from the server
  156. 7:01so the tcp session hijacking is another
  157. 7:03tcp vulnerability
  158. 7:06although difficult to conduct a threat
  159. 7:08actor takes over
  160. 7:10an already authenticated host as it
  161. 7:12communicates
  162. 7:13with a target the threat actor must
  163. 7:16spoof
  164. 7:17the ip address of one host predict
  165. 7:20the next sequence number and send an ack
  166. 7:24to the other host if successful
  167. 7:28the threat actor could send but not
  168. 7:31receive
  169. 7:31data from the target device
  170. 7:38udp segment header and operation
  171. 7:41so udp is commonly used by dns
  172. 7:44tftp nfs right
  173. 7:47and snmp so it is also used with
  174. 7:51real-time applications such as
  175. 7:53media streaming or voip
  176. 7:56udp is a connectionless transport layer
  177. 7:59protocol
  178. 8:01it has much lower overhead than tcp
  179. 8:03because it is not connected
  180. 8:05or connection oriented and does not
  181. 8:08offer the sophisticated rear
  182. 8:09transmission
  183. 8:10sequencing and flow control mechanisms
  184. 8:14that provides reliability the udp
  185. 8:17segment structure
  186. 8:19shown in this figure here is much
  187. 8:22smaller than tcp segment structure
  188. 8:25although udp is normally called
  189. 8:27unreliable
  190. 8:29in contrast to tcp's reliability this
  191. 8:32does not mean that the application does
  192. 8:34use or that use udp are always
  193. 8:37unreliable
  194. 8:39nor does it mean that udp is an inferior
  195. 8:42protocol
  196. 8:44it means that these functions are not
  197. 8:47provided
  198. 8:47by the transport layer protocol and must
  199. 8:50be implemented elsewhere if
  200. 8:52required so the low overhead of udp
  201. 8:57makes it very desirable for protocols
  202. 8:59that make simple requests
  203. 9:01and reply transactions so for example
  204. 9:05using tcp for dhcp would introduce
  205. 9:08unnecessary network traffic
  206. 9:10so if no response is received the device
  207. 9:14presents the request
  208. 9:20how about udp attacks so udp
  209. 9:24is not protected by any encryption
  210. 9:27you can add encryption to udp but it is
  211. 9:30not available by default
  212. 9:32so the lack of encryption means that
  213. 9:34anyone can see the traffic
  214. 9:36change it and send it on to each
  215. 9:39destination
  216. 9:41so changing the data in the traffic will
  217. 9:43alter the 16-bit checksum
  218. 9:46but the checksum is optional and is not
  219. 9:48always used
  220. 9:50so when the checksum is used the threat
  221. 9:52actor can create
  222. 9:54a new checksum based on the new data
  223. 9:57payload
  224. 9:58and then record it in a header
  225. 10:01as a new checksum so the destination
  226. 10:04device will find that the checksum
  227. 10:06matches
  228. 10:06the data without knowing that the data
  229. 10:09has been altered
  230. 10:11so this type of attack is not widely
  231. 10:14used okay now for the udp flat attacks
  232. 10:20you are more likely to see a udp flat
  233. 10:22attack
  234. 10:23in a udp flat attack all the resources
  235. 10:26in the network are consumed
  236. 10:29so if the threat actor must use a tool
  237. 10:32like udp unicorn or
  238. 10:34low orbit ion cannon these tools send a
  239. 10:37flood of udp packets
  240. 10:39often from a spoofed host to a server on
  241. 10:43the subset
  242. 10:44the program will sweep through all the
  243. 10:47known ports
  244. 10:48trying to find closed ports
  245. 10:51this will cause the server to reply with
  246. 10:54icmp port and reachable message
  247. 10:57because there are many closed ports on
  248. 10:59the server this creates a lot of traffic
  249. 11:01on the segment
  250. 11:03which uses up most of the bandwidth
  251. 11:06so the result is similar to the denial
  252. 11:09of service attack
  253. 11:15ip services
  254. 11:19one of the ip services is the arp
  255. 11:22or the address resolution protocol
  256. 11:24vulnerabilities
  257. 11:26so earlier in this module you learned
  258. 11:28about vulnerabilities with
  259. 11:30ip tcp and udp
  260. 11:34so the tcp product called suit was never
  261. 11:37built for security
  262. 11:39therefore the services that ip uses for
  263. 11:42addressing functions such as arp
  264. 11:45dns and dhcp are also not secure
  265. 11:49as you will learn in this topic hosts
  266. 11:53broadcasts and arp requests to other
  267. 11:55hosts on the segment
  268. 11:57to determine the mac address of the host
  269. 11:59with a particular ip address
  270. 12:02all hosts on the subnet received and
  271. 12:04processed the arp requests
  272. 12:07the host where the matching ip address
  273. 12:10in the erp request
  274. 12:11sends an arp reply
  275. 12:16now here's the arp process so any client
  276. 12:20can send unsolicited arp reply called
  277. 12:24gratuitous arp this is often done
  278. 12:28when a device first boot or boot up
  279. 12:31to inform all other devices on the
  280. 12:33network or local network
  281. 12:35of the new device's mac address
  282. 12:39when a host sends a gratitude's arp
  283. 12:42other hosts on the subnet to store the
  284. 12:44mac address
  285. 12:45and ip address contained in the graph
  286. 12:48t2s arp and their arp
  287. 12:50tables so this feature of arp also means
  288. 12:54that any host can claim to be the owner
  289. 12:58of any ip or mac address
  290. 13:01so a threat actor can poison the arp
  291. 13:04cache
  292. 13:05of the devices on the local network
  293. 13:08creating a man in the middle attack
  294. 13:12to redirect traffic so the goal is
  295. 13:16to target a victim okay or
  296. 13:19host and have it change its default
  297. 13:22gateway
  298. 13:23to the threat actors device
  299. 13:26so just positions the threat actor
  300. 13:30in between the victim and all other
  301. 13:33systems
  302. 13:34outside the local subnet
  303. 13:41next is arp cache poisoning
  304. 13:45arp cache poisoning can be used to
  305. 13:47launch various man-in-the-middle attacks
  306. 13:50okay so in this diagram here
  307. 13:55we have the arp request the figure
  308. 13:59shows how arp cache poisoning works
  309. 14:04so pca requires the mac address
  310. 14:07of its default k20 which is connected to
  311. 14:11r1
  312. 14:12therefore it sends an arp requests
  313. 14:16for the mac address of 192.168.10.1
  314. 14:25and then there would be an arp reply
  315. 14:29in this figure r1 updates
  316. 14:32each arp cache with the ip address and
  317. 14:35mac address of
  318. 14:36pca r1 sends an arp reply to pca
  319. 14:43which then updates its arp cache with
  320. 14:45the ip address and mac address of
  321. 14:48r1
  322. 14:55alright so how about if there would be a
  323. 14:57spoofed gratitude's arp replies
  324. 15:00so in the figure the threat actor
  325. 15:04sends two spoofed the t2u's arp replies
  326. 15:07using its own mac address for the
  327. 15:10indicated destination ip address
  328. 15:13so pca updates
  329. 15:17harp cache with its default gateway
  330. 15:20which is now pointing to the threat
  331. 15:22actors
  332. 15:23host mac address so r1 also updates
  333. 15:27its arp cache with the ip address of pca
  334. 15:31pointing to the threat actors mac
  335. 15:34address
  336. 15:35so the threat actors host is executing
  337. 15:38an arp poisoning attack
  338. 15:40so the arp poisoning attack can be
  339. 15:43passive
  340. 15:44or active so passive arp
  341. 15:47poisoning is wear threat act or steal
  342. 15:50confidential information
  343. 15:53active arp poisoning is where threat
  344. 15:56actors modify the data in transit
  345. 15:59or inject malicious data
  346. 16:12dns attacks so the domain name service
  347. 16:16or dns protocol defines an
  348. 16:17automated service that matches resource
  349. 16:20names such as
  350. 16:23www.education.com
  351. 16:25or any url with the required numeric
  352. 16:29network address
  353. 16:30such as ipv4 or ipv6
  354. 16:33addresses it includes the format
  355. 16:37for queries responses and data
  356. 16:40and uses resource records or rr
  357. 16:44to identify the type of the dns response
  358. 16:49securing a dns is often overlooked
  359. 16:52however it is crucial to the operation
  360. 16:56of the network and should be secured
  361. 16:57accordingly
  362. 16:59dns attacks includes the following
  363. 17:02you'll have the dns op and resolver
  364. 17:04attacks
  365. 17:05the dns stealth attacks dns domain
  366. 17:09shadowing attacks
  367. 17:10and dns tunneling attacks
  368. 17:17now let's talk about the dns open
  369. 17:19resolver attacks
  370. 17:21many organizations use the services of
  371. 17:23publicly open dns servers
  372. 17:25such as google dns which is at 8.8.8.8
  373. 17:31to provide responses to queries this
  374. 17:34type of dns server
  375. 17:35is called an open resolver a dns open
  376. 17:38resolver
  377. 17:40answers queries from clients outside of
  378. 17:42its administrative domain
  379. 17:44dns open resolvers are vulnerable to
  380. 17:48multiple malicious activities
  381. 17:50as described here on this table this
  382. 17:52includes the dns cache positioning
  383. 17:54attacks
  384. 17:56wherein threat actors send spoofed
  385. 17:59pulsified record resource or rr
  386. 18:02to a dns resolver to redirect users from
  387. 18:05legitimate sites to malicious sites
  388. 18:09so the next one is the dns amplification
  389. 18:12and reflection attacks this is where the
  390. 18:14threat actors use the denial of service
  391. 18:16or the distributed denial of service
  392. 18:18attacks
  393. 18:19on dns open resolvers to increase the
  394. 18:22volume of attacks
  395. 18:23and to hide the true score or source of
  396. 18:26an attack
  397. 18:28so threat actor sends dns messages
  398. 18:31to the open resolvers using the ip
  399. 18:34address of a target hosts
  400. 18:37so the next one is the dns resource
  401. 18:39utilization attacks
  402. 18:42so the denial of service attacks that
  403. 18:44consumes the resources of the dns open
  404. 18:46resolvers
  405. 18:47this denial of service attack consumes
  406. 18:50all the available resources
  407. 18:52to negatively affect the operations of
  408. 18:55the dns open resolver
  409. 18:57now the impact of this denial of service
  410. 18:59attack may require the dns open resolver
  411. 19:02to be rebooted or services to be stopped
  412. 19:06and restarted
  413. 19:12the next type of attack is the dns
  414. 19:15stealth attacks
  415. 19:16so to hide their identity threat actors
  416. 19:19also use the dns style techniques
  417. 19:22described in the table to carry out
  418. 19:24their attacks
  419. 19:25so first would be the fast flags
  420. 19:29this is where the threat actors use this
  421. 19:32technique
  422. 19:32to hide their fishing and malware
  423. 19:35okay so that is delivery sites behind a
  424. 19:38quickly changing network
  425. 19:40of compromised okay so which is the dns
  426. 19:44hosts
  427. 19:44now the dns ip addresses are
  428. 19:47continuously changed within minutes
  429. 19:50botnets often employ a fast flux
  430. 19:53technique
  431. 19:54to effectively hide malicious servers
  432. 19:56from being
  433. 19:57detected next would be a double ip flux
  434. 20:02so this is where the threat actors can
  435. 20:05use techniques to rapidly change the
  436. 20:07host name
  437. 20:08to ip address mappings and to also
  438. 20:11change the authoritative name server
  439. 20:14this increases the difficulty to
  440. 20:16identify
  441. 20:18the source of the attack so the last one
  442. 20:22would be a domain generation algorithms
  443. 20:25threat actors use this technique in
  444. 20:27malware to randomly generate
  445. 20:29domain names that can then be used
  446. 20:32and rendezvous points to their command
  447. 20:36and control or the cnc server
  448. 20:42now the dns domain shadowing attacks
  449. 20:45involves a threat after gathering domain
  450. 20:47account credentials
  451. 20:49in order to silently create multiple
  452. 20:52subdomains
  453. 20:53to be used during the attacks so
  454. 20:56these subdomains typically point to
  455. 20:58malicious servers
  456. 21:00without alerting the actual owner of the
  457. 21:02parent domain
  458. 21:08next would be dns tunneling
  459. 21:12so threat actors who use dns tunneling
  460. 21:16place
  461. 21:16non-dns traffic within the dns traffic
  462. 21:20so this method often circumvents
  463. 21:22security solutions
  464. 21:24when a threat actor wishes to
  465. 21:26communicate with bots
  466. 21:28inside a protected network or
  467. 21:31exfiltrate data from the organization
  468. 21:34such as password databases so when the
  469. 21:37threat
  470. 21:38actor uses dns tunneling the different
  471. 21:41types of dns records are altered
  472. 21:44this is how dns tunneling works for
  473. 21:47cnc commands sent to a bootnet
  474. 21:51okay so the command data is split into
  475. 21:54multiple encoded chunks
  476. 21:56each chunk is placed into a lower level
  477. 22:00domain name
  478. 22:01okay or it is placed on the lower level
  479. 22:05domain name label
  480. 22:06of the dns query because there is no
  481. 22:10response from the local
  482. 22:12network dns for the query
  483. 22:15the request is sent to the isbc
  484. 22:17recursive dns servers
  485. 22:19now the recursive dns service will
  486. 22:21forward the query to the threat actors
  487. 22:23authoritative name server
  488. 22:26the process is repeated until all the
  489. 22:28queries containing the chunks of
  490. 22:30data are sent so when the threat
  491. 22:33actors authoritative name server
  492. 22:36receives the dns queries from the
  493. 22:38infected devices it
  494. 22:40sends responses to each dns query
  495. 22:43which contain the encapsulated encoded
  496. 22:46cnc commands
  497. 22:48so the malware on the compromised host
  498. 22:51recombines the chunks okay or the chunks
  499. 22:54of data
  500. 22:55and executes the commands hidden within
  501. 22:58the dns record
  502. 23:00now to stop this dns tunneling the
  503. 23:03network administrator
  504. 23:05must use filter that inspects
  505. 23:08dns traffic so pay close attention to
  506. 23:12dns
  507. 23:13queries that are no longer
  508. 23:17than the average or those that have a
  509. 23:20suspicious
  510. 23:21domain name dns solutions
  511. 23:24like the cisco open dns block match of
  512. 23:27the dns tunneling traffic by identifying
  513. 23:30suspicious
  514. 23:34domain
  515. 23:36next ip services is dhcp
  516. 23:40or the dynamic host configuration
  517. 23:42protocol
  518. 23:44dhep servers dynamically provide
  519. 23:46ipconfiguration information to clients
  520. 23:49now the figure here shows the typical
  521. 23:51sequence of the hcp message exchange
  522. 23:54between the client right and the server
  523. 23:58now in the figure the client broadcasts
  524. 24:02a dhcp discover message the dhep server
  525. 24:06responds
  526. 24:07with a unicast okay
  527. 24:10or unicast offer that includes
  528. 24:12addressing information
  529. 24:14the client can use the client broadcast
  530. 24:17at dhcp requests
  531. 24:19to tell the server that the client
  532. 24:21accepts the offer
  533. 24:24now lastly the server will respond
  534. 24:28with a unicast acknowledgement accepting
  535. 24:30the requests
  536. 24:33now what are the attacks on dhcp
  537. 24:37so the first one is dhep spoofing attack
  538. 24:41this occurs when a rogue dhtp server is
  539. 24:44connected to the network and provides
  540. 24:46false ip configuration parameters to
  541. 24:49legitimate clients
  542. 24:51so a rogue server can provide a variety
  543. 24:53of misleading information
  544. 24:57next is wrong default gateway now threat
  545. 25:00actors
  546. 25:01provide an invalid gateway or ip address
  547. 25:05of each host
  548. 25:06to create a man in the middle attack
  549. 25:09this may go entirely undetected as the
  550. 25:12intruder intercepts the data flow
  551. 25:14through the network next would be
  552. 25:17a wrong dns server so threat actor
  553. 25:20provides an
  554. 25:21incorrect dns server addresses pointing
  555. 25:24the user
  556. 25:25to a malicious website
  557. 25:29okay next would be wrong ip address
  558. 25:33now threat actor provides an invalid ip
  559. 25:35address
  560. 25:36invalid default gateway ip address or
  561. 25:38both
  562. 25:40the threat actor then creates a denial
  563. 25:42of service attack on the daycheep client
  564. 25:45now assume a jet actor has successfully
  565. 25:48connected to a rogue date gp server
  566. 25:50to a switch port on the same subnet as
  567. 25:52the target clients
  568. 25:54so the goal of the rogue server is to
  569. 25:57provide clients with false ip
  570. 25:58configuration
  571. 26:00information
  572. 26:03[Music]
  573. 26:06now in the figure here
  574. 26:07[Music]
  575. 26:09okay so the client broadcasts
  576. 26:12the hcp discovery message okay
  577. 26:15in the figure a legitimate client
  578. 26:18connects to the network
  579. 26:19and requires ip configuration parameters
  580. 26:22now the client broadcasts a dhcp
  581. 26:25discover requests
  582. 26:26looking for a response from the dhcp
  583. 26:30server
  584. 26:31both servers receive the message
  585. 26:36all right
  586. 26:40second dhcp server
  587. 26:43response with offer okay so let's start
  588. 26:47with http server here
  589. 26:48responding with offers
  590. 26:52now the figure shows how to lead or how
  591. 26:54the legitimate
  592. 26:55and the rogue day gp server each
  593. 26:58respond with valid ip configuration
  594. 27:01parameters
  595. 27:02so the dhp server here which is the
  596. 27:04legitimate dhb server
  597. 27:06will respond and so with the rogue dhcp
  598. 27:09server
  599. 27:10of the threat actor now the client
  600. 27:13replies
  601. 27:14to the first offer received
  602. 27:17and this client is not aware whether the
  603. 27:20offer
  604. 27:21came from a rogue the hp server
  605. 27:25[Music]
  606. 27:27next would be the client accepts the
  607. 27:29rogue http requests
  608. 27:31now in this scenario the client received
  609. 27:34the rogue
  610. 27:35offers first it broadcasts a dhcp
  611. 27:39request
  612. 27:40accepting the parameters which is from
  613. 27:43the rogue server now the legitimate
  614. 27:47and the rogue server is receive the
  615. 27:50request
  616. 27:55and next would be the rogue dhcp
  617. 27:58acknowledges
  618. 27:59the request all right
  619. 28:06network security best practices
  620. 28:12now on this segment we will be talking
  621. 28:14about the
  622. 28:15network security best practices so this
  623. 28:18includes the cia or the confidentiality
  624. 28:22availability and integrity now it is
  625. 28:25true that the list of network attack
  626. 28:27types is long
  627. 28:29but there are many best practices that
  628. 28:31you can use
  629. 28:32to defend your network as you will learn
  630. 28:35in this topic now network security
  631. 28:39consists of protecting information
  632. 28:42and information systems from authorized
  633. 28:44access
  634. 28:45use disclosure disruption modification
  635. 28:50or destruction most organizations follow
  636. 28:54the cia
  637. 28:55information security trial or
  638. 28:58confidentiality
  639. 28:59integrity and availability
  640. 29:04now let us define confidentiality so
  641. 29:06what is confidentiality
  642. 29:08so this means only authorized
  643. 29:10individuals or users
  644. 29:12entities or processes can access
  645. 29:15sensitive information
  646. 29:17it may require using cryptographic
  647. 29:19encryption algorithms such as
  648. 29:21aes to encrypt and decrypt data
  649. 29:25when you say integrity this refers to
  650. 29:27protecting data from an
  651. 29:29authorized alteration it requires the
  652. 29:32use of
  653. 29:33cryptographic hashing algorithms such as
  654. 29:36ssh or sha
  655. 29:39and a availability
  656. 29:42authorized users must have uninterrupted
  657. 29:45access
  658. 29:46to important resources and data it
  659. 29:49requires implementing redundant services
  660. 29:52gateways and links
  661. 29:59okay so how about the defense in-depth
  662. 30:01approach
  663. 30:02now to ensure a secure communication
  664. 30:05across
  665. 30:05both private and public networks
  666. 30:08you must secure devices including
  667. 30:10routers
  668. 30:11okay switches servers and hosts
  669. 30:17this is because known as or this is also
  670. 30:20known as the layered approach
  671. 30:22okay so it requires a combination of
  672. 30:24networking devices
  673. 30:26and services working together now
  674. 30:29consider the network here
  675. 30:30in the given diagram
  676. 30:36so several security devices and services
  677. 30:38are implemented
  678. 30:39to protect an organization's users and
  679. 30:42assets against
  680. 30:43tcp threats so
  681. 30:47it includes vpn what is a vpn so vpn
  682. 30:50is a router used to provide secure vpn
  683. 30:55services
  684. 30:56with corporate sites and remote access
  685. 30:58support for remote users
  686. 31:01using a secure encrypted tunnels
  687. 31:05you can also have the asa firewall so
  688. 31:08this
  689. 31:09is a dedicated device which provides
  690. 31:12stateful firewall services
  691. 31:14it ensures that internal traffic can go
  692. 31:16out and come back
  693. 31:18but external traffic cannot initiate
  694. 31:20connections
  695. 31:21to inside hosts next is ips
  696. 31:26an intrusion prevention system ips
  697. 31:29monitors incoming and outgoing traffic
  698. 31:31looking for malware
  699. 31:33network attack signatures and more
  700. 31:38if it is recognized as a threat it can
  701. 31:40immediately stop it
  702. 31:43okay next is essa
  703. 31:46or wsa the email service or email
  704. 31:50security appliance essa
  705. 31:52filters spam and suspicious emails
  706. 31:55the web security appliance or wsa
  707. 31:58filters
  708. 31:59known and suspicious internet malware
  709. 32:02sites next
  710. 32:05is aaa server so this server contains a
  711. 32:09secure database
  712. 32:11of who is authorized to access and
  713. 32:14manage network devices
  714. 32:16network devices authenticate
  715. 32:18administrative users
  716. 32:20using their databases
  717. 32:23so all network devices including the
  718. 32:25router and switches
  719. 32:27are hardened which means that they have
  720. 32:30been secured
  721. 32:31to prevent threat actors from gaining
  722. 32:33access and tampering with
  723. 32:35the devices so next
  724. 32:38you must secure the data as it travels
  725. 32:41across
  726. 32:42various links so this may include
  727. 32:45internal traffic
  728. 32:47but it's more important to protect the
  729. 32:48data that travels
  730. 32:50outside of the organization to broad
  731. 32:53sites
  732. 32:54telecommuter sites and partner sites
  733. 33:02firewall so a firewall is a system
  734. 33:06or group of systems that enforces an
  735. 33:08access control policy
  736. 33:10between networks okay
  737. 33:14now all firewalls share some common
  738. 33:17properties
  739. 33:19so firewalls are resistant to network
  740. 33:21attacks
  741. 33:23firewalls are the only transit points
  742. 33:26between internal corporate networks and
  743. 33:28external networks
  744. 33:29because all traffic flows through the
  745. 33:31firewall
  746. 33:33so firewalls enforce the access control
  747. 33:37policy
  748. 33:39there are several benefits of using
  749. 33:41firewall in a network
  750. 33:43so first they prevent exposure of
  751. 33:46sensitive
  752. 33:47hosts resources and applications to
  753. 33:50untrusted users
  754. 33:52they sanitize protocol flow which
  755. 33:56prevents the exploitation of protocol
  756. 33:58flaws
  757. 33:59they block malicious data from servers
  758. 34:01and clients
  759. 34:03they reduce security management
  760. 34:05complexity by offloading most of the
  761. 34:07network access control
  762. 34:09to a few firewalls in the network
  763. 34:12so firewalls also present some
  764. 34:14limitations
  765. 34:16okay a misconfigured firewall can
  766. 34:20have serious consequences for the
  767. 34:22network
  768. 34:23such as becoming a single point of
  769. 34:24failure
  770. 34:26so the data from many applications
  771. 34:29cannot be passed through the firewall
  772. 34:31security
  773. 34:33users might proactively search four ways
  774. 34:35around the firewall
  775. 34:37to receive blocked material which
  776. 34:40exposes the network
  777. 34:41to potential attack network performance
  778. 34:45can slow down traffic can be tunneled
  779. 34:49or hidden so that it appears as
  780. 34:52legitimate traffic
  781. 34:53through the firewall
  782. 35:00next is ips or intrusion prevention
  783. 35:03system
  784. 35:04so to prevent data or to defend
  785. 35:08okay so against the fast moving and
  786. 35:10evolving attacks
  787. 35:12you may need cost effective detection
  788. 35:14and prevention systems such
  789. 35:16as intrusion detection systems or ids
  790. 35:19or the most scalable intrusion
  791. 35:22prevention system
  792. 35:23or ips now the network architecture
  793. 35:27integrates these solutions into the
  794. 35:29entry and exit points of the network
  795. 35:32so the ips and ids technologies
  796. 35:36share several characteristics okay
  797. 35:39so ideas and ips technologies are both
  798. 35:42deployed as sensors
  799. 35:44an ids or ips sensor can be
  800. 35:48in the form of several
  801. 35:51different devices it could be in a form
  802. 35:54of a router configured with cisco ios
  803. 35:56ips software
  804. 35:58a device is specifically designed to
  805. 36:00provide a dedicated
  806. 36:01ids or ips services a network module
  807. 36:05installed
  808. 36:06in an adaptive security appliance or asa
  809. 36:09switch or router
  810. 36:13now the figure shows how an ips handles
  811. 36:16denied traffic so the threat actor here
  812. 36:21sends a packet distinct to the target
  813. 36:24laptop
  814. 36:24so here's our target so the ips
  815. 36:28intercepts the traffic okay
  816. 36:31and evaluates it against known threats
  817. 36:35and the configured policies so the ips
  818. 36:39sends a log message to the management
  819. 36:41console
  820. 36:42and then the ips drops the packet
  821. 36:47now ideas and ips technologies detect
  822. 36:49patterns in network traffic using
  823. 36:51signatures
  824. 36:52a signature is a set of rules that an
  825. 36:55ids or ips uses to detect malicious
  826. 36:58activity
  827. 36:59signatures can be used to detect severe
  828. 37:02breaches of security
  829. 37:04to detect common network attacks and to
  830. 37:07gather information
  831. 37:09so ids and ips technologies can detect
  832. 37:13atomic signature patterns or single
  833. 37:15packet or
  834. 37:16the composite signature patterns we call
  835. 37:19it the multi-packet
  836. 37:25content security devices
  837. 37:29so content security appliances include
  838. 37:33fine grained control over email and web
  839. 37:35browsing
  840. 37:36for an organization's users
  841. 37:40so this includes the cisco email
  842. 37:42security appliance or essa
  843. 37:44now this email security appliance
  844. 37:48is a special device designed to monitor
  845. 37:51simple mail transfer protocol or smtp
  846. 37:55so the esa is constantly updated by
  847. 37:58real-time
  848. 37:59feds from the cisco talos
  849. 38:02which detects and correlates threats and
  850. 38:05solutions
  851. 38:06by using a worldwide database monitoring
  852. 38:08system
  853. 38:10now this threat intelligence data is
  854. 38:13pulled by the cisco esa
  855. 38:16every three to five minutes
  856. 38:19now referring to the figure here okay
  857. 38:23so in here the threat actor sends a
  858. 38:25piecing attack to an important host on
  859. 38:28the network
  860. 38:30and then the firewall forwards all email
  861. 38:33to the esa now the esa
  862. 38:36analyzes the email logs it and discard
  863. 38:44it
  864. 38:46the next component would be the cisco
  865. 38:48web security appliance
  866. 38:49or the wsa now the cisco web security
  867. 38:53appliance
  868. 38:54is a mitigation technology for web-based
  869. 38:57threats
  870. 38:58it helps organization address the
  871. 39:01challenges of securing and controlling
  872. 39:03web traffic now this wsa
  873. 39:07combines advanced malware protection
  874. 39:10application visibility and control
  875. 39:12acceptable use policy control and
  876. 39:14reporting
  877. 39:16wsa provides complete control over
  878. 39:20how users access the internet certain
  879. 39:23features and applications such as
  880. 39:25chat messaging video
  881. 39:28and audio can be allowed restricted with
  882. 39:32time and bandwidth limits or
  883. 39:34blocked according to the organization's
  884. 39:36requirements
  885. 39:37the wsa can perform block listing
  886. 39:40okay that includes the url filtering
  887. 39:43malware scanning
  888. 39:45url categorization web application
  889. 39:48filtering
  890. 39:49and encryption and decryption of the web
  891. 39:51traffic
  892. 39:54now from the figure here a user
  893. 39:58attempts to connect a website
  894. 40:01okay the firewall forwards the website
  895. 40:03request
  896. 40:04to the wsa now the wsa
  897. 40:09evaluates the url and determines
  898. 40:12that it is non-blacklisted site
  899. 40:15so the wsa disregards or discards the
  900. 40:19packet
  901. 40:20and sends an access denied message to
  902. 40:22the user
  903. 40:30on this section we will be talking about
  904. 40:33cryptography
  905. 40:35early in the previous topic cryptography
  906. 40:37is mentioned as part of the cia
  907. 40:40or the confidentiality integrity
  908. 40:43and availability information security
  909. 40:45triad
  910. 40:46in this topic we will get deeper dive
  911. 40:49into many types of cryptography
  912. 40:53and how they are used to secure the
  913. 40:55network
  914. 41:00securing communications organization
  915. 41:04must have uh provide or must provide
  916. 41:07supports to secure the data
  917. 41:10as it travels across the links so this
  918. 41:13may include
  919. 41:14internal traffic but it is even more
  920. 41:17important to protect the data that
  921. 41:18travels
  922. 41:19outside organization to broad sites
  923. 41:22telecommuter sites
  924. 41:23and partner sites now these are the four
  925. 41:27elements
  926. 41:28of a secure communication first
  927. 41:32there should be data integrity so data
  928. 41:35integrity guarantees that the message
  929. 41:37was not altered
  930. 41:38any changes to data in transit will be
  931. 41:41detected
  932. 41:42integrity is ensured by implementing
  933. 41:45either message digest
  934. 41:46version 5 or md5 or the secure hash
  935. 41:50algorithm or sha hash generating
  936. 41:53algorithms
  937. 41:55second is attend origin authentication
  938. 41:59it guarantees that the message is not
  939. 42:02forgery
  940. 42:04right or is not first and that's
  941. 42:06actually come from whom
  942. 42:08it states many modern networks ensure
  943. 42:11authentication with protocols such as
  944. 42:13hash message authentication code or the
  945. 42:17hmap
  946. 42:20next would be data confidentiality
  947. 42:24so guarantees that the only authorized
  948. 42:26users
  949. 42:27can read the message if the message is
  950. 42:31intercepted
  951. 42:32it cannot be deciphered within a
  952. 42:34reasonable amount of time
  953. 42:36so data confidentiality is implemented
  954. 42:38using symmetric and asymmetric
  955. 42:40encryption algorithm
  956. 42:44so the last one be data non-reputation
  957. 42:49it guarantees that the sender cannot
  958. 42:50repudiate or refute
  959. 42:53the validity of the message sent
  960. 42:56non-repugation
  961. 42:57relies on the fact that only the sender
  962. 42:59has the unique characteristics
  963. 43:01or signature for how that message
  964. 43:05is treated so cryptography
  965. 43:08can be used almost anywhere that there
  966. 43:12is data communication
  967. 43:14in fact the trend is towards
  968. 43:17all communications being encrypted
  969. 43:24okay so let's focus on data integrity
  970. 43:28hash functions are used to ensure the
  971. 43:30integrity of a message
  972. 43:32so they guarantee the message data has
  973. 43:34not changed accidentally or
  974. 43:38intentionally now in the figure here
  975. 43:42the sender is sending one hundred
  976. 43:44dollars of money
  977. 43:46okay and then it transferred to
  978. 43:50the other uh or the the recipient
  979. 43:54okay in here if you will observe from
  980. 43:57100
  981. 43:58okay paid to alex
  982. 44:02okay and then you've got there paid to
  983. 44:05jeremy
  984. 44:06it was changed or altered from the one
  985. 44:09hundred dollars
  986. 44:11to one thousand dollars okay
  987. 44:14so the sender wants to ensure that the
  988. 44:16message is not altered on its way
  989. 44:18to the receiver or recipient
  990. 44:22now the sending device inputs the
  991. 44:24message into a hashing algorithm
  992. 44:27and computes its fixed length hash
  993. 44:30okay so which is this 4e h
  994. 44:34i d x 67 and m op9
  995. 44:38alright now this hash is then attached
  996. 44:42to the message
  997. 44:43and send it to the receiver both the
  998. 44:46message and the hash
  999. 44:48are in plain text now the receiving
  1000. 44:51device removes the hash from the message
  1001. 44:54and inputs the message into the same
  1002. 44:56hashing algorithm
  1003. 44:58if the computed hash is equal to the one
  1004. 45:01that is attached to the message
  1005. 45:03then the message has not been altered
  1006. 45:06while in transit
  1007. 45:08if the hashes are not equal as shown in
  1008. 45:11the figure
  1009. 45:12all right so they are not the same okay
  1010. 45:15so then the integrity of the message can
  1011. 45:17no longer be trusted
  1012. 45:18so it was altered while in transit
  1013. 45:24okay so hash function
  1014. 45:27there are three well known hash
  1015. 45:28functions you've got the md5 with 128
  1016. 45:31bit digest
  1017. 45:33sha hashing algorithm and the sha2
  1018. 45:36okay now the md5 with a 128-bit digest
  1019. 45:41is a one-way function that produces
  1020. 45:43128-bit hash message md5
  1021. 45:46is a legacy algorithm that should only
  1022. 45:50be used
  1023. 45:50when no better alternatives are
  1024. 45:52available so use
  1025. 45:54xiatu instead okay now
  1026. 45:57sha hashing algorithm or shell 1 is very
  1027. 46:00similar to the md5 hash functions
  1028. 46:03so xiao 1 creates a 160 bit hashed
  1029. 46:06message and is slightly slower than md5
  1030. 46:10xiaowan has the known flaws and is a
  1031. 46:13legacy algorithm
  1032. 46:15that's why we are recommending the use
  1033. 46:17of sha
  1034. 46:182 okay now shot 2 includes
  1035. 46:22shia 224 or 224 bit
  1036. 46:25256 bit 384 bit
  1037. 46:29512 bit okay
  1038. 46:32so shot 256 384 and 512
  1039. 46:36are the next generation algorithm and
  1040. 46:38should be used
  1041. 46:39whenever possible now while hashing can
  1042. 46:43be used to detect accidental changes
  1043. 46:46it cannot be used to guard against
  1044. 46:47deliberate changes
  1045. 46:49this means that anyone can compute a
  1046. 46:52hash
  1047. 46:52for any data if they have the correct
  1048. 46:55hash function
  1049. 46:56therefore hashing is vulnerable to men
  1050. 47:00in the middle or mitm attacks and does
  1051. 47:03not provide
  1052. 47:04security to transmitted data
  1053. 47:09okay now i have here an example sorry so
  1054. 47:12these are the three well-known hash
  1055. 47:14functions
  1056. 47:16so let's start with the md5 128-bit
  1057. 47:19digest
  1058. 47:21so md5 is a one-way function that
  1059. 47:24produces 128-bit
  1060. 47:25hash message as shown in the figure
  1061. 47:29all right now mg5 is a legacy algorithm
  1062. 47:32as mentioned earlier that should only be
  1063. 47:34used
  1064. 47:35when no better alternatives are
  1065. 47:37available
  1066. 47:38so we are recommending the use of xia2
  1067. 47:42so in the figure a plain text message is
  1068. 47:45passed through md5 hash function
  1069. 47:49okay the result is bit
  1070. 47:52hashed message
  1071. 47:56next is the hashing algorithm sha1
  1072. 48:00is very similar to md5
  1073. 48:03okay so several version exists you've
  1074. 48:06got xiao one creates 160 bit hash
  1075. 48:08message and it's slightly slower than
  1076. 48:11md5
  1077. 48:12so xiao one has known flaws and
  1078. 48:15is also a legacy algorithm
  1079. 48:18so again we are recommending the use of
  1080. 48:22chat too now in the figure
  1081. 48:25a plain text message is passed through
  1082. 48:27the shah hash
  1083. 48:28function so the result is a hashed
  1084. 48:32message
  1085. 48:35third would be xia2 this includes sha224
  1086. 48:39as discussed earlier 256 384
  1087. 48:43and 512 so this are the next generation
  1088. 48:47of algorithms and should be used
  1089. 48:51whenever possible okay now while hashing
  1090. 48:54can be used to detect accidental changes
  1091. 48:58it cannot be used to guard against
  1092. 48:59deliberate changes
  1093. 49:01there is no unique identifying
  1094. 49:04information from the sender
  1095. 49:06in the hashing procedures this means
  1096. 49:09that anyone can compute a hash for
  1097. 49:12any data if they have the correct hash
  1098. 49:15function
  1099. 49:17for example when the message traverses
  1100. 49:21the network
  1101. 49:22a potential threat actor could intercept
  1102. 49:24the message right
  1103. 49:25so change it recalculate the hash
  1104. 49:28and append it to the message the
  1105. 49:31receiving device will only validate
  1106. 49:33against
  1107. 49:34whatever has is appended so take note so
  1108. 49:37therefore
  1109. 49:38hashing is vulnerable to man in the
  1110. 49:41middle attack
  1111. 49:42and does not provide security to
  1112. 49:45transmitted data
  1113. 49:47so to provide integrity and origin
  1114. 49:49authentication
  1115. 49:51something more is required right
  1116. 49:56so next would be origin authentication
  1117. 50:00so to add authentication to the
  1118. 50:02integrity assurance
  1119. 50:04use a keyed hash message authentication
  1120. 50:07code
  1121. 50:08or the hmac okay hmac uses
  1122. 50:12an additional secret key as input to the
  1123. 50:15hash function
  1124. 50:18so only parties who have access to the
  1125. 50:20secret key
  1126. 50:21can compute the digest of an hmac
  1127. 50:23function
  1128. 50:24this defeats the man in the middle
  1129. 50:26attack and provides authentication
  1130. 50:29of the origin or data origin
  1131. 50:35okay now as shown in the figure
  1132. 50:39the hmac is calculated using any
  1133. 50:41cryptographic algorithm
  1134. 50:44that combines cryptographic hash
  1135. 50:45function with a secret key
  1136. 50:48hash functions are the basis of the
  1137. 50:50protection mechanism for each map
  1138. 50:53only the sender and the receiver know
  1139. 50:55the secret key
  1140. 50:57and the output of the hash function now
  1141. 50:59depends on the input data
  1142. 51:01and the secret key so only parties who
  1143. 51:05have access to the secret key
  1144. 51:07can compute the digest of an hmac
  1145. 51:10function
  1146. 51:12okay so as mentioned earlier this will
  1147. 51:14defeat
  1148. 51:16right the man in the middle attacks and
  1149. 51:18provides authentication
  1150. 51:21of the data origin okay
  1151. 51:25so also mentioned earlier if two parties
  1152. 51:27share a secret key
  1153. 51:29and use the hmac functions for
  1154. 51:31authentication
  1155. 51:32a properly constructed hmac digest of a
  1156. 51:35message
  1157. 51:36that the party has received indicates
  1158. 51:38that the only the other party
  1159. 51:40was the originator of the message so
  1160. 51:43this is because the other party
  1161. 51:45who says the secret key
  1162. 51:54now how do we create the hmac value now
  1163. 51:57as shown here in the diagram
  1164. 51:59the sending device inputs data such as
  1165. 52:03uh
  1166. 52:04jerry smith pay uh
  1167. 52:07100 and the secret key
  1168. 52:10okay we've got a secret key there
  1169. 52:13now this has been into the hashing
  1170. 52:15algorithm
  1171. 52:17and calculates the fixed length hmac
  1172. 52:19digest
  1173. 52:20so this authenticated digest is then
  1174. 52:23attached to the message
  1175. 52:25and sent to the receiver
  1176. 52:32verifying the hmac value now again in
  1177. 52:35the figure
  1178. 52:36the receiving device removes the digest
  1179. 52:40from the message and uses the plain text
  1180. 52:43message
  1181. 52:44with its secret key as input
  1182. 52:47into the same hashing function now if
  1183. 52:50the digest that is calculated by the
  1184. 52:52receiving device is equal
  1185. 52:54to the digest that was sent the message
  1186. 52:56has not been
  1187. 52:57altered okay so additionally
  1188. 53:01the origin of the message is
  1189. 53:02authenticated because only the sender
  1190. 53:05possesses a copy of the shared secret
  1191. 53:07key
  1192. 53:08now the hmac function has to ensure
  1193. 53:11the authenticity of the message
  1194. 53:19so next would be the cisco router hmac
  1195. 53:22example here now the figure
  1196. 53:26shows how hmacs are used by cisco
  1197. 53:28routers
  1198. 53:29that are configured to use the open
  1199. 53:31shortest path first or ospf routing
  1200. 53:33protocol
  1201. 53:35routing authentication okay
  1202. 53:38now in here r1 is sending a link state
  1203. 53:41updates or lsu
  1204. 53:43regarding a route to network 10.2.0.0
  1205. 53:4916. okay so r1 calculates the hash value
  1206. 53:53using the lsu message
  1207. 53:56and the secret key okay
  1208. 53:59now the resulting hash value is sent
  1209. 54:02with lsu to
  1210. 54:03router 2. now router 2 calculates the
  1211. 54:07hash value
  1212. 54:09using the lsu and its secret key so r2
  1213. 54:13accepts the update
  1214. 54:15if the hash value matched if they do not
  1215. 54:18match
  1216. 54:19then r2 discards the update
  1217. 54:25data confidentiality so there are two
  1218. 54:28classes
  1219. 54:28of encryption used to provide data
  1220. 54:30confidentiality
  1221. 54:32so these are or these two classes differ
  1222. 54:36in how they use
  1223. 54:37keys okay so you've got symmetric
  1224. 54:40such as this 3ds and
  1225. 54:44aes or the advanced encryption standard
  1226. 54:50okay so these are based on the premise
  1227. 54:53that
  1228. 54:53its communicating party shows the
  1229. 54:55pre-shared key
  1230. 54:57so data confidentiality can also be
  1231. 54:59ensured
  1232. 55:00using asymmetric algorithms
  1233. 55:03including okay so the rivers
  1234. 55:06shamir and adelman or the lrsa
  1235. 55:10and the public key infrastructure or the
  1236. 55:12pki
  1237. 55:14okay now the figure here highlights some
  1238. 55:17differences between
  1239. 55:18each encryption algorithm method
  1240. 55:22so one of the most notable difference is
  1241. 55:25of course
  1242. 55:26symmetrical uses the same key and
  1243. 55:30asymmetric uses different keys
  1244. 55:34all right so symmetric
  1245. 55:37key lengths are short 40 bits to 256
  1246. 55:41well for asymmetric it's 512 to 4096
  1247. 55:45bits
  1248. 55:46okay so symmetric is faster than
  1249. 55:48asymmetric encryption
  1250. 55:51asymmetric computationally
  1251. 55:54tasking okay therefore slower than
  1252. 55:58symmetrical so symmetric is commonly
  1253. 56:01used
  1254. 56:02for encrypting bulk data such as in the
  1255. 56:04vpn traffic
  1256. 56:06and asymmetric is commonly used in a
  1257. 56:09quick data transaction such as https
  1258. 56:12when accessing your bank data
  1259. 56:20let's dig in into symmetric encryption
  1260. 56:23so symmetric algorithms use the same
  1261. 56:27pre-shared key to encrypt and decrypt
  1262. 56:30data so a pre-shared key also called
  1263. 56:33secret key
  1264. 56:35is known by the sender and the receiver
  1265. 56:37before any encrypted
  1266. 56:38communication can take place
  1267. 56:41so to help illustrate how symmetric
  1268. 56:43encryption works
  1269. 56:45consider an example here okay so
  1270. 56:48assuming that we have
  1271. 56:49here alice and bob live on different
  1272. 56:52location
  1273. 56:53and want to exchange secret messages
  1274. 56:55with one another
  1275. 56:57through the email system now in this
  1276. 57:00example
  1277. 57:01alice wants to send a secret message to
  1278. 57:04bob
  1279. 57:05okay now in the figure alice and bob
  1280. 57:08have identical keys okay
  1281. 57:11to a single padlock these keys
  1282. 57:14were exchanged prior to sending any
  1283. 57:17secret
  1284. 57:18messages so alice writes a secret
  1285. 57:22message
  1286. 57:23and put it in a small box that she likes
  1287. 57:26using the padlock with her key
  1288. 57:29okay now she mails the box to bob
  1289. 57:33the message is safely locked inside the
  1290. 57:35box
  1291. 57:36as the box makes its way through the
  1292. 57:38post office system
  1293. 57:40now when bob receives the box he uses
  1294. 57:44his key to unlock the padlock
  1295. 57:46and retrieve the message bob can use the
  1296. 57:49same box and padlock to send secret
  1297. 57:52reply
  1298. 57:52to alice okay now
  1299. 57:56today symmetric encryption algorithms
  1300. 57:59are commonly used with vpn traffic
  1301. 58:02this is because symmetric algorithms use
  1302. 58:04less cpu resources
  1303. 58:06than asymmetric encryption algorithms so
  1304. 58:10encryption and decryption of data is
  1305. 58:12fast when using a vpn
  1306. 58:15when using symmetric encryption
  1307. 58:16algorithms like any other type of
  1308. 58:18encryption
  1309. 58:19the longer the key the longer it will
  1310. 58:21take for someone
  1311. 58:23to discover the key so most
  1312. 58:26encryption keys are between 112
  1313. 58:29and 256 bits so to ensure that the
  1314. 58:33encryption is safe
  1315. 58:35use a minimum key length of 128 bits
  1316. 58:39so use a longer key for
  1317. 58:43more secure communication
  1318. 58:48well symmetric encryption algorithms are
  1319. 58:50described in the table so you've got
  1320. 58:52this okay 3ds aes
  1321. 58:56seal and you've got the rifles cyber or
  1322. 58:59rc
  1323. 59:00okay now this is a legacy symmetric
  1324. 59:04encryption algorithm 3ds is the newer
  1325. 59:08version of this
  1326. 59:09but it repeats the dash algorithm
  1327. 59:11process three times
  1328. 59:13okay aes or the advanced encryption
  1329. 59:16standard
  1330. 59:17is a secure and more efficient algorithm
  1331. 59:19than 3ds
  1332. 59:20it is popular and recommended symmetric
  1333. 59:23encryption algorithm
  1334. 59:26so next is seal or the software
  1335. 59:28optimized encryption algorithm
  1336. 59:30this is faster alternative symmetric
  1337. 59:32encryption algorithm to 3ds
  1338. 59:35des and aes
  1339. 59:39the last one would be the right for a
  1340. 59:40rybast cypress or rc series algorithm
  1341. 59:44this algorithm was developed by ron
  1342. 59:46rivest
  1343. 59:48so several variations have been
  1344. 59:50developed
  1345. 59:51but rc4 is the most prevalent
  1346. 59:54in use so rc4 is a stream cyber
  1347. 59:58and is used to secure web traffic in
  1348. 1:00:01ssl and tls
  1349. 1:00:07let's get deeper into asymmetric
  1350. 1:00:10encryption
  1351. 1:00:12so algorithms also called public key
  1352. 1:00:16algorithms are designed so that the key
  1353. 1:00:18that is used for encryption
  1354. 1:00:20is different from the key that is used
  1355. 1:00:22for decryption
  1356. 1:00:24okay so as shown on this diagram here
  1357. 1:00:27now the decryption key
  1358. 1:00:29cannot uh in any reasonable amount of
  1359. 1:00:32time
  1360. 1:00:33be calculated from the encryption key
  1361. 1:00:35and vice versa
  1362. 1:00:37so asymmetric algorithms use a public
  1363. 1:00:41key
  1364. 1:00:42and a private key so both keys
  1365. 1:00:45are capable of encryption process but
  1366. 1:00:48the complementary paired key
  1367. 1:00:50is required for decryption
  1368. 1:00:54so the process is also reversible so
  1369. 1:00:57data encryption with a public key
  1370. 1:00:58requires the private key
  1371. 1:01:00to decrypt so asymmetric algorithms
  1372. 1:01:04achieve confidentiality authentication
  1373. 1:01:08and integrity by using this process
  1374. 1:01:12okay now because neither party
  1375. 1:01:15has a shared secret very long key
  1376. 1:01:18lengths
  1377. 1:01:19must be used so asymmetric encryption
  1378. 1:01:23can use key lengths between 512
  1379. 1:01:27to 4096 bits
  1380. 1:01:30so key lengths greater than or equal to
  1381. 1:01:331024 bits
  1382. 1:01:34can be trusted while shorter okay
  1383. 1:01:38key lengths are considered unreliable
  1384. 1:01:48all right so what are the examples okay
  1385. 1:01:51of protocols that
  1386. 1:01:52use asymmetric key algorithms so this
  1387. 1:01:55includes the ike okay or the internet
  1388. 1:01:58key exchange this is a fundamental
  1389. 1:02:01component of
  1390. 1:02:02ipsec vpns so the next one is
  1391. 1:02:06ssl or the secure socket layer
  1392. 1:02:09so this protocol provides a secure
  1393. 1:02:11remote access connection
  1394. 1:02:13to network devices okay
  1395. 1:02:18next is ssh or the secure shell
  1396. 1:02:21this protocol provides a secure remote
  1397. 1:02:23access connection to network devices
  1398. 1:02:27you also have this uh pretty good
  1399. 1:02:30privacy or pgp
  1400. 1:02:32this computer program provides a
  1401. 1:02:33cryptographic privacy and authentication
  1402. 1:02:36it is often used to increase the
  1403. 1:02:39security of email communications
  1404. 1:02:42so asymmetric algorithms are
  1405. 1:02:44substantially slower than symmetric
  1406. 1:02:46algorithms their design
  1407. 1:02:49is based on computational problems such
  1408. 1:02:52as
  1409. 1:02:53factoring extremely large numbers or
  1410. 1:02:55computing discrete
  1411. 1:02:56logarithms of extremely large numbers
  1412. 1:03:01so because they are slow asymmetric
  1413. 1:03:03algorithms are typically used in low
  1414. 1:03:05volume cryptographic
  1415. 1:03:07mechanisms such as digital signatures
  1416. 1:03:10and key exchange okay however
  1417. 1:03:15the key management for asymmetric
  1418. 1:03:17algorithms
  1419. 1:03:19tends to be simpler than asymmetric or
  1420. 1:03:22than symmetric algorithms
  1421. 1:03:24because usually one of the two
  1422. 1:03:27encryption or decryption keys can be
  1423. 1:03:30made
  1424. 1:03:31public
  1425. 1:03:35so common examples of asymmetric
  1426. 1:03:37encryption algorithms
  1427. 1:03:39includes also daffy helman or the dh
  1428. 1:03:43right you've got dss or the digital
  1429. 1:03:46signature standard
  1430. 1:03:48and digital signature algorithms you'll
  1431. 1:03:51have the rsa
  1432. 1:03:52reversed shamir and adelman encryption
  1433. 1:03:54algorithm
  1434. 1:03:55you've got the ei gamal and the
  1435. 1:03:58elliptical curve
  1436. 1:03:59techniques okay now the daffy helmet
  1437. 1:04:03algorithm allows two parties to agree
  1438. 1:04:05on a key that they can use to encrypt
  1439. 1:04:08messages
  1440. 1:04:09they want to send to each other so the
  1441. 1:04:12security of this algorithm depends on
  1442. 1:04:15the assumption that
  1443. 1:04:16it is easy to raise number of certain
  1444. 1:04:19power but
  1445. 1:04:20difficult to compute which power was
  1446. 1:04:22used
  1447. 1:04:23given the number and the outcome
  1448. 1:04:27now dss dsa dss specifies dsa
  1449. 1:04:32okay as the algorithm for digital
  1450. 1:04:33signatures so dsa
  1451. 1:04:35is a public key algorithm based on the
  1452. 1:04:39ei gamal
  1453. 1:04:41signature scheme so signature creation
  1454. 1:04:44speed is
  1455. 1:04:45similar to rsa but is 10 to 40 times
  1456. 1:04:49lower for verification
  1457. 1:04:52okay next is rsa
  1458. 1:04:55rsa is for public key cryptography that
  1459. 1:04:58is based on the current difficulty of
  1460. 1:05:00factoring very large numbers
  1461. 1:05:03so it is the first algorithm known
  1462. 1:05:06to be a suitable for signing as well as
  1463. 1:05:09encryption okay it is widely used in
  1464. 1:05:12electronic commerce protocols
  1465. 1:05:14and is believed to be the secure given
  1466. 1:05:17sufficiently long keys and the use of
  1467. 1:05:21up-to-date implementations
  1468. 1:05:24right so next would be the ea gamal
  1469. 1:05:28okay this is an asymmetric key
  1470. 1:05:30encryption algorithm for public
  1471. 1:05:33cryptography which is based on the
  1472. 1:05:35deputy helmonkey
  1473. 1:05:36agreement so the disadvantage of the
  1474. 1:05:39eigamal system is that
  1475. 1:05:40the encryption message becomes very big
  1476. 1:05:43about twice the size of the original
  1477. 1:05:45message
  1478. 1:05:46and for this reason it is only used for
  1479. 1:05:49small messages such as secret keys
  1480. 1:05:53all right so the larger the length the
  1481. 1:05:56secure
  1482. 1:05:57okay the more secure it is so
  1483. 1:06:00the last one would be elliptical curve
  1484. 1:06:02techniques
  1485. 1:06:03so elliptic curve cryptography can be
  1486. 1:06:06used to adapt
  1487. 1:06:07many cryptographic algorithms such as
  1488. 1:06:09the epi helmand
  1489. 1:06:10or ei gamal so the main advantage of
  1490. 1:06:13elliptic
  1491. 1:06:14curve cryptography is that the keys
  1492. 1:06:18can be much smaller
  1493. 1:06:24now deputy helman is an asymmetric
  1494. 1:06:27mathematical algorithms
  1495. 1:06:29where two computers generate an
  1496. 1:06:30identical shared key
  1497. 1:06:32without having communicated before okay
  1498. 1:06:35so the new shared key is never actually
  1499. 1:06:38exchanged between the sender and the
  1500. 1:06:40receiver
  1501. 1:06:41however because both parties know it
  1502. 1:06:44they can be used by an encryption
  1503. 1:06:47algorithm to encrypt traffic
  1504. 1:06:49between the two systems right
  1505. 1:06:52so here are the three examples of
  1506. 1:06:55instances
  1507. 1:06:56when dh is commonly used
  1508. 1:06:59first data is exchanged using ipsec vpn
  1509. 1:07:05okay second data is encrypted on the
  1510. 1:07:08internet using either ssl
  1511. 1:07:11or tls
  1512. 1:07:14third ssh data is exchanged
  1513. 1:07:18okay now the daffy helman
  1514. 1:07:21uses unbelievably large number of
  1515. 1:07:25in its calculations unfortunately
  1516. 1:07:28asymmetric key systems are extremely
  1517. 1:07:30slow
  1518. 1:07:31for any sort of bulk encryption so
  1519. 1:07:33therefore
  1520. 1:07:35it is common to encrypt the bulk of
  1521. 1:07:38the traffic using symmetric algorithm
  1522. 1:07:40such as 3ds
  1523. 1:07:42aes and then use daffy helmet or dh
  1524. 1:07:45algorithm to create keys
  1525. 1:07:48that will be used by encryption
  1526. 1:07:50algorithms
  1527. 1:07:55now to help illustrate how dh operates
  1528. 1:07:58so refer to the figure here all right
  1529. 1:08:02now the colors in the figure will be
  1530. 1:08:05used instead of complex
  1531. 1:08:06long numbers to simplify the dh key
  1532. 1:08:09agreement process
  1533. 1:08:11okay now the dhk exchange begins with
  1534. 1:08:15alice and bob
  1535. 1:08:16agreeing on an arbitrary common color
  1536. 1:08:19that does not need to be kept secret
  1537. 1:08:23okay now
  1538. 1:08:27the agreed on color okay in our example
  1539. 1:08:30is yellow
  1540. 1:08:31for instance right next alice and bob
  1541. 1:08:34will each select a secret color
  1542. 1:08:38okay so alice chooses red
  1543. 1:08:41and bob chooses blue here
  1544. 1:08:45now these secret colors will never be
  1545. 1:08:47shared with anyone
  1546. 1:08:49the secret color represents the chosen
  1547. 1:08:52secret private right
  1548. 1:08:56so
  1549. 1:09:00what will happen next is that alice and
  1550. 1:09:03bob
  1551. 1:09:03now makes the shirt common color okay
  1552. 1:09:08so yellow with the respective secret
  1553. 1:09:10color to produce a private color
  1554. 1:09:14so therefore alice will mix the yellow
  1555. 1:09:17one
  1556. 1:09:18with her red color to produce a private
  1557. 1:09:21color of
  1558. 1:09:22orange all right now
  1559. 1:09:25bob will mix the yellow and the blue to
  1560. 1:09:28produce
  1561. 1:09:30a private color green now ali sends her
  1562. 1:09:34private color orange
  1563. 1:09:38to bob and bob sends her private or his
  1564. 1:09:41private
  1565. 1:09:42color green to alice
  1566. 1:09:46all right now alice and bob
  1567. 1:09:49each mix the color they received very
  1568. 1:09:52own
  1569. 1:09:54so original secret color red for alice
  1570. 1:09:58and blue for bob the result is the final
  1571. 1:10:01brown mixture
  1572. 1:10:03all right that is identical to the
  1573. 1:10:06others
  1574. 1:10:07final color mixture so the brown color
  1575. 1:10:10represents the resulting shared
  1576. 1:10:13secret key between bob and alice
  1577. 1:10:16so dh or deputy helmand security uses
  1578. 1:10:19unbelievably large number in this
  1579. 1:10:21calculations for example
  1580. 1:10:24a dh 10 24 bit number is roughly equal
  1581. 1:10:27to a decimal number of
  1582. 1:10:30309 digits all right so considering that
  1583. 1:10:34a billion is 10 decimal digits
  1584. 1:10:37one can easily imagine the complexity of
  1585. 1:10:40working
  1586. 1:10:41with not one but many 309
  1587. 1:10:45digit decimal numbers now
  1588. 1:10:48unfortunately asymmetric key systems are
  1589. 1:10:51extremely slow
  1590. 1:10:52for any sort of bulk encryption so
  1591. 1:10:55therefore
  1592. 1:10:56it is common to encrypt the bulk of the
  1593. 1:10:59traffic
  1594. 1:11:00using the symmetric algorithm okay so
  1595. 1:11:03as mentioned earlier 3ds or aes
  1596. 1:11:06and then use dh algorithm to create keys
  1597. 1:11:09that will be used by an encryption
  1598. 1:11:11algorithm
  1599. 1:11:15so that's the end of this video lecture
  1600. 1:11:17thank you for watching and listening
  1601. 1:11:19have a great day
  1602. 1:11:27[Music]
  1603. 1:11:31you

About this transcript

This page contains the full transcript of ENSA M3 Network Security Concepts Part 2 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 7,842 words across 1,603 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.