YouTube2Text

Network Control — Transcript

by Santelmo · 3,159 words · 719 segments · language en · Watch on YouTube

Full transcript

  1. 0:04Hi. Hello.
  2. 0:06On this video,
  3. 0:08we'll be talking about network control.
  4. 0:11So, from the last video that we
  5. 0:12discussed,
  6. 0:14so we covered network monitoring.
  7. 0:17So, network management is one of the
  8. 0:19task of a system administrator.
  9. 0:23And we could say that network management
  10. 0:25is
  11. 0:27a product
  12. 0:29of network monitoring
  13. 0:32and network control.
  14. 0:34All right. So, let's get started.
  15. 0:39Now, for the topic outline on this
  16. 0:40video, this includes the introduction
  17. 0:43about network control,
  18. 0:45configuration control,
  19. 0:47and security control.
  20. 0:53Okay. So, let us start with definition
  21. 0:56of
  22. 0:58network control.
  23. 0:59So, basically, network control is
  24. 1:01concerned with modifying parameters
  25. 1:05in and causing actions to be taken by
  26. 1:07the end systems, intermediate systems,
  27. 1:10and sub-networks that made up the
  28. 1:11network to be managed.
  29. 1:13So, when we talked about end systems, so
  30. 1:16from the previous discussion, this
  31. 1:18covers computers, servers,
  32. 1:21fax machines. Okay, so voice over IP,
  33. 1:23these are the end systems.
  34. 1:26Intermediate systems, this includes
  35. 1:27routers, switches, bridges,
  36. 1:29all right, firewalls, and the subnets,
  37. 1:32which includes
  38. 1:33VLANs.
  39. 1:35Okay?
  40. 1:36So, basically, network control is for
  41. 1:40the modification of parameters, and that
  42. 1:42modification would lead or cause an
  43. 1:44action.
  44. 1:45Okay? So, if you still remember, network
  45. 1:48monitoring is concerned more on
  46. 1:50observing and analyzing the status
  47. 1:53and behavior
  48. 1:55of the end systems, intermediate
  49. 1:57systems, and subnets.
  50. 1:59Okay? So, network monitoring is more on
  51. 2:03fault, performance, and accounting.
  52. 2:06Whereas on network control,
  53. 2:09so this is more concerned with
  54. 2:11configuration and security.
  55. 2:15All right?
  56. 2:16So, all five functional areas of network
  57. 2:18management involved monitoring and
  58. 2:21control. So, but configuration and
  59. 2:23security are more concerned with
  60. 2:26control.
  61. 2:27All right?
  62. 2:29Now, what are the issues in network
  63. 2:31control?
  64. 2:33So, first, what do we want to control?
  65. 2:36Okay? So, as administrator, what to
  66. 2:38control on the network?
  67. 2:40So, define what is to be controlled. So,
  68. 2:42definitely, we want to control the usage
  69. 2:45of the resources.
  70. 2:47All right? So, the the access of the end
  71. 2:48users. So, those are just some of the
  72. 2:51examples that needs to be controlled.
  73. 2:54Okay?
  74. 2:55And how do we control it?
  75. 2:57So, basically,
  76. 2:59we are using
  77. 3:01the network management tool, or shall we
  78. 3:04say administrative tool, okay? So, in in
  79. 3:07Windows domain,
  80. 3:09to control
  81. 3:10the actions, okay? Or to control the
  82. 3:12access of the end users, and to control
  83. 3:15the uses of the resources.
  84. 3:18So, basically, we are using an
  85. 3:19application to do this.
  86. 3:22All right?
  87. 3:24Next, let's talk let's talk about
  88. 3:26configuration management.
  89. 3:28So, define configuration information,
  90. 3:31configuration monitoring.
  91. 3:33Okay? So, this includes examining the
  92. 3:35values and relationships.
  93. 3:37Report on configuration status.
  94. 3:41Third is configuration control. So, may
  95. 3:43be required as a result of monitoring or
  96. 3:46event reports.
  97. 3:49Okay? So, this includes initialization
  98. 3:52and termination of network operations.
  99. 3:55So, this is happening during the
  100. 3:56maintenance wherein
  101. 3:58the administrator has to stop.
  102. 4:00Okay, so the operation of the
  103. 4:02infrastructure
  104. 4:03so that we could perform some sort of
  105. 4:06configurations or fine-tuning of the
  106. 4:07network.
  107. 4:09Okay? So, this includes initialization
  108. 4:12and termination of the network
  109. 4:14operations, but this should be done
  110. 4:17during a long break. Okay, so that we
  111. 4:20have to ensure
  112. 4:21that this will not hamper the operation
  113. 4:23of the organization.
  114. 4:25All right, so usually this is being
  115. 4:27performed during Holy Week.
  116. 4:28All right.
  117. 4:30Next is also under configuration
  118. 4:33control, we set and modify attribute
  119. 4:35values. So, we will talking about this
  120. 4:37uh attribute values on the next slide.
  121. 4:41Define and modify the relationship.
  122. 4:43Okay?
  123. 4:44Also, we're going to cover this
  124. 4:46on the next slide.
  125. 4:48Define configuration information.
  126. 4:53So, this includes the nature and status
  127. 4:55of the managed resources.
  128. 4:58Okay, so again we say managed resources,
  129. 5:00this are the MOs or the managed object.
  130. 5:03Okay? So, specification and attributes
  131. 5:06of the resources.
  132. 5:09It also includes network resources. So,
  133. 5:12this can be classified as physical
  134. 5:15resource
  135. 5:16or logical resources.
  136. 5:18Okay?
  137. 5:19So, under physical resources, so this
  138. 5:21includes the end systems
  139. 5:23intermediary which includes routers
  140. 5:26bridges, switches, modems, etc.
  141. 5:29Okay?
  142. 5:30So, for the logical resources
  143. 5:32this covers TCP connections, timers,
  144. 5:35counters, virtual circuits, and so on.
  145. 5:39Okay?
  146. 5:41Also, under defining the configuration
  147. 5:43information is attributes. Okay? So,
  148. 5:46attributes includes names,
  149. 5:49address, ID numbers, states, operational
  150. 5:52characteristics, number of connections,
  151. 5:55etc. So, we're we're talking about the
  152. 5:57router names,
  153. 5:58the IP addresses assigned to each
  154. 6:00interfaces, the router ID used by the
  155. 6:02protocols, and so on. So, those are
  156. 6:05attributes.
  157. 6:06Okay?
  158. 6:07So, control functions should be able to
  159. 6:10define new classes and attributes. So,
  160. 6:12mostly, this should be done offline.
  161. 6:16All right? So, in every configuration,
  162. 6:19so we do not do this during the
  163. 6:21operation of the infrastructure. Okay?
  164. 6:24Or, we do not define
  165. 6:27any configuration. Okay? So, on the
  166. 6:30production area. So, usually, we do it
  167. 6:33on our simulation network.
  168. 6:36Okay? So, don't ever perform any
  169. 6:39configurations on the production or live
  170. 6:42network.
  171. 6:43All right?
  172. 6:45Next is define the type and range of the
  173. 6:48attribute values.
  174. 6:50Okay? So, that's under control
  175. 6:51functions.
  176. 6:55Okay? So, set and modify attribute
  177. 6:57values. So, when requesting agents to
  178. 6:59perform set and modify, the manager must
  179. 7:03be authorized. Okay? So, in a network
  180. 7:06environment, Okay? So, every access of
  181. 7:10an individual
  182. 7:11should have a different level. Okay? So,
  183. 7:14the administrators basically has the
  184. 7:16full access. Okay? So, if you are a
  185. 7:18junior engineer, you you'll have
  186. 7:20different level of access.
  187. 7:22Okay? So, if you are the network
  188. 7:25engineer, you'll have different access.
  189. 7:28Okay? So, whenever you are requesting
  190. 7:31agents to perform
  191. 7:33any set or modify values, [music]
  192. 7:35okay? So, the manager the manager must
  193. 7:37be authorized to first. All right? So,
  194. 7:40sort of that
  195. 7:42is not within my level.
  196. 7:45So, I need to obtain that authorization
  197. 7:47so that I may be able to perform.
  198. 7:51Okay, such set and modify.
  199. 7:54Okay?
  200. 7:55So, there is a corresponding level.
  201. 7:58Okay, so for every
  202. 8:00uh position in the organization.
  203. 8:03All right?
  204. 8:04Next. So, some attributes cannot be
  205. 8:07modified like the number of physical
  206. 8:09ports. So, you need to do some
  207. 8:11uh changes, okay, physically.
  208. 8:15Okay, and definitely
  209. 8:18every access to the network
  210. 8:20infrastructure components should be
  211. 8:22restricted, especially if you are not
  212. 8:24part of the authorization,
  213. 8:27okay, or if you're not authorized to do
  214. 8:29it.
  215. 8:30All right?
  216. 8:32Next would be modification categories.
  217. 8:36So, under modification categories, so
  218. 8:37it's either you update the MIB, okay, or
  219. 8:40MIB update only does not require the
  220. 8:43agent to perform any other action.
  221. 8:46So, update of static configuration
  222. 8:48information,
  223. 8:49that's example of the MIB updates only.
  224. 8:52Okay? Or it could be
  225. 8:54an MIB update plus a resource
  226. 8:56modification. So, this requires the
  227. 8:58agent to to modify the resource itself.
  228. 9:02So, something like changing the state of
  229. 9:03the physical port to disabled.
  230. 9:06Okay?
  231. 9:07Next would be
  232. 9:08MIB update plus action. So, perform
  233. 9:11actions
  234. 9:13as a side effect of set operation.
  235. 9:16So, SNMP takes this approach.
  236. 9:19So, we'll be talking about SNMP in the
  237. 9:21succeeding video.
  238. 9:26Okay.
  239. 9:27So, next would be defining and modifying
  240. 9:29the relationship.
  241. 9:31Okay? So, this includes
  242. 9:33the relationship describing an
  243. 9:35association, connection, or condition
  244. 9:39that exists between network resources.
  245. 9:42All right? So, this includes topology.
  246. 9:46So, when you say topology,
  247. 9:48it's either physical or logical
  248. 9:49topology. Okay? So, when you say
  249. 9:52physical topology or physical network
  250. 9:54topology,
  251. 9:55this is the placement of various
  252. 9:57components of a network
  253. 9:59and the different connectors usu-
  254. 10:01usually represent the physical network
  255. 10:03cables
  256. 10:04and the nodes. Okay? So, represents
  257. 10:06usually the physical network devices
  258. 10:08like switches.
  259. 10:10Okay?
  260. 10:11So, when you say logical network
  261. 10:13topology, it illustrates at a higher
  262. 10:15level how data flows within the network.
  263. 10:19Okay? So, again, when we say topology,
  264. 10:22we've talked about the physical or a
  265. 10:24logical topology.
  266. 10:26Okay, so next would be the hierarchy.
  267. 10:29Okay?
  268. 10:30So, take note that in a network, we have
  269. 10:33what you call core, distribution,
  270. 10:36and access.
  271. 10:38It's an example of hierarchy on the
  272. 10:39network.
  273. 10:40Okay?
  274. 10:41Or the use of the group policy objects
  275. 10:44or GPO,
  276. 10:46that is also in hierarchical form.
  277. 10:49Okay? So, on the network,
  278. 10:52we have this core, distribution, and
  279. 10:54aggregation,
  280. 10:55or access. So, I guess you still
  281. 10:57remember this.
  282. 10:58Okay? So, when you say core,
  283. 11:01it is com- it composed of a high speed
  284. 11:05switches.
  285. 11:06Okay? So, with high resiliency and
  286. 11:09usually routing and other high-level
  287. 11:11functions.
  288. 11:13Okay? So, your your
  289. 11:16fast devices,
  290. 11:18okay? Should be placed on the core
  291. 11:21layer.
  292. 11:22Okay?
  293. 11:23Next would be the distribution or
  294. 11:25aggregation. So, composed of high speed
  295. 11:27switches with redundancy and
  296. 11:29availability.
  297. 11:31Okay? And the lowest is of course the
  298. 11:34access. This is where the users are in.
  299. 11:37Okay? So, it comprises of switches to
  300. 11:39which the client devices are connected.
  301. 11:41All right? So, on the core, we have the
  302. 11:44resiliency.
  303. 11:46On the distribution,
  304. 11:47we have the redundancy and availability.
  305. 11:51And on the access, that is where the
  306. 11:52users are.
  307. 11:55All right?
  308. 11:57So, the next one would be containment.
  309. 12:00So, containment, an example of this is
  310. 12:02the organizational units.
  311. 12:04Okay? So, in the active directory, one
  312. 12:07of your experiment at the lab will be
  313. 12:08dealing with
  314. 12:10organizational units.
  315. 12:12Okay?
  316. 12:13And the last one would be
  317. 12:17the management domain.
  318. 12:20Okay? So, the management domain,
  319. 12:22okay?
  320. 12:24Is an active directory itself. Okay?
  321. 12:27So,
  322. 12:29that is where we manage the entire
  323. 12:31network. That is where the systems
  324. 12:34administrator performs its duties.
  325. 12:38Okay? So, we've talked about physical
  326. 12:40and logical connections already.
  327. 12:43Okay? So, a configuration control should
  328. 12:45allow online modification of resources
  329. 12:48without taking all part of the network
  330. 12:50down.
  331. 12:51But, beware of providing an access
  332. 12:55via online modifications. All right? So,
  333. 12:58it should be equipped with proper
  334. 13:02uh security configurations and
  335. 13:04authorization, as always.
  336. 13:06Okay?
  337. 13:09All right? So, next is security
  338. 13:11management. Okay? So, take note that
  339. 13:13security management is part of the
  340. 13:15FCAPS.
  341. 13:17Okay?
  342. 13:18So,
  343. 13:20under security management, so what
  344. 13:22should be secured in the network?
  345. 13:25So, basically, if you're talking about
  346. 13:27being a systems administrator or a
  347. 13:30network administrator,
  348. 13:31what should you secure in a network?
  349. 13:35Okay?
  350. 13:36So, we might consider ourselves as the
  351. 13:39security guard of data or information.
  352. 13:41And what do we need to secure?
  353. 13:43First is information.
  354. 13:45Right? So, we'll be talking about
  355. 13:47information security.
  356. 13:49You know, or infosec, okay? So,
  357. 13:52information security primarily refers to
  358. 13:55protecting the confidentiality,
  359. 13:58all right,
  360. 13:59integrity, and ability uh availability
  361. 14:02of data.
  362. 14:03So, no matter its form, information
  363. 14:06security can just as easily be about
  364. 14:10protecting a filing cabinet of important
  365. 14:13documents
  366. 14:14as it is about protecting your
  367. 14:15organization's database.
  368. 14:17So, that's information security.
  369. 14:20This encompasses
  370. 14:22almost all
  371. 14:24or almost everything on the
  372. 14:25infrastructure.
  373. 14:27All right?
  374. 14:28So, information security,
  375. 14:31this is the protection of information
  376. 14:33and information systems from
  377. 14:35unauthorized access,
  378. 14:38unauthorized use, disclosure,
  379. 14:41disruption, modification, or destruction
  380. 14:45in order to provide confidentiality,
  381. 14:48integrity, and availability.
  382. 14:51Okay?
  383. 14:53Next would be
  384. 14:54another
  385. 14:56definition of information security might
  386. 14:58be
  387. 14:59it ensures that both the physical
  388. 15:02and digital data is protected from
  389. 15:04unauthorized access, use, disclosure,
  390. 15:07disruption, modification, inspection,
  391. 15:09recording, or destruction.
  392. 15:12Okay? So, information security differs
  393. 15:15from cybersecurity
  394. 15:16in that infosec aims to keep data in any
  395. 15:21form secure, whereas cybersecurity
  396. 15:24protects only digital data.
  397. 15:27Okay? So, don't be confused with
  398. 15:28information security and cybersecurity.
  399. 15:32Okay? So, cybersecurity is just one of
  400. 15:35the element of information security. So,
  401. 15:38if your business is starting to develop
  402. 15:39a security program,
  403. 15:41information security is where you will
  404. 15:43should first begin
  405. 15:45as it is the foundation of data
  406. 15:47security.
  407. 15:49All right? So, again, cybersecurity is
  408. 15:52just a subset of information security.
  409. 15:56So, it is the practice of the
  410. 18:07>> hacker attacks
  411. 18:08the denial of service
  412. 18:10spyware and maybe adware.
  413. 18:14All right?
  414. 18:15So, information assurance measure
  415. 18:18that the protect and defend information
  416. 18:21and information systems
  417. 18:23by ensuring their availability,
  418. 18:25integrity, authentication,
  419. 18:26confidentiality, and non-repudiation.
  420. 18:30Okay? So, these measures include
  421. 18:32providing for restoration of information
  422. 18:34system
  423. 18:35by incorporating protection, detection
  424. 18:38and reaction capabilities.
  425. 18:42Okay? So, these are the three
  426. 18:46important
  427. 18:48um
  428. 18:49components that needs to be secured in
  429. 18:51the network. So, information, computer,
  430. 18:53and network.
  431. 18:55All right? So, basically, the main
  432. 18:57target of the attacker is the
  433. 18:59information.
  434. 19:01And the first line of uh defense would
  435. 19:03be
  436. 19:04through network security.
  437. 19:06Okay?
  438. 19:07When the attacker gets and penetrated
  439. 19:10the network, so the next target is the
  440. 19:12computer. So, your computer should be
  441. 19:14secure.
  442. 19:15Because your information is basically
  443. 19:17residing on the computer.
  444. 19:19Okay?
  445. 19:21Next,
  446. 19:22security requirements.
  447. 19:25Okay?
  448. 19:26So, we kept on mentioning
  449. 19:28confidentiality.
  450. 19:30Okay? Or secrecy.
  451. 19:32So, making information accessible to
  452. 19:34only authorized users.
  453. 19:37Okay? So, this includes hiding of the
  454. 19:41existence of information.
  455. 19:43Confidentiality or secrecy, which means
  456. 19:46preserving authorized restrictions on
  457. 19:48access
  458. 19:49and disclosure,
  459. 19:51including means of protecting personal
  460. 19:54privacy
  461. 19:55and proprietary information. That's
  462. 19:58secrecy or confidentiality.
  463. 20:01All right? So, next would be integrity.
  464. 20:05Making information modifiable only to
  465. 20:08authorized
  466. 20:10user. So, which means guarding against
  467. 20:13improper
  468. 20:14information modification or destruction.
  469. 20:17And includes ensuring information
  470. 20:19non-repudiation
  471. 20:21and authenticity.
  472. 20:23Okay?
  473. 20:24And
  474. 20:25availability.
  475. 20:27Okay? Making resources available only to
  476. 20:31authorized users.
  477. 20:34So, which means ensuring timely and
  478. 20:36reliable access to and use of
  479. 20:40information. So, this is network
  480. 20:43management.
  481. 20:45All right?
  482. 20:48Next, since we're talking about
  483. 20:49security,
  484. 20:52so, what are the threats?
  485. 20:55Number one is interruption.
  486. 20:57Okay?
  487. 20:58Interruption destroyed or becomes
  488. 21:02unavailable or unusable.
  489. 21:04Okay? So, in an interruption, an asset
  490. 21:07of the system becomes lost,
  491. 21:10unavailable,
  492. 21:12or unusable. For example,
  493. 21:15a malicious destruction of a hardware
  494. 21:17device, erasure of program or data file,
  495. 21:21or malfunction of an operating system
  496. 21:23file manager so that it cannot find a
  497. 21:26particular disk file. That is an example
  498. 21:29of an interruption.
  499. 21:31Okay?
  500. 21:33So, the next one would be
  501. 21:36interception.
  502. 21:38Okay? So, interception means that
  503. 21:41some unauthorized party has gained
  504. 21:43access to an asset.
  505. 21:46Okay? The outside party can be a person,
  506. 21:49a program,
  507. 21:51or a computing system.
  508. 21:53So, examples of this type of failure are
  509. 21:56illicit copying of programs or data
  510. 21:59files, or wiretapping to obtain data in
  511. 22:03a network.
  512. 22:04Although a loss may be discovered fairly
  513. 22:07quickly, a silent interceptor may leave
  514. 22:10no traces by which the interception can
  515. 22:13readily detected.
  516. 22:16Okay?
  517. 22:18Next,
  518. 22:19modification.
  519. 22:22So, modification, that is where an
  520. 22:25authorized party makes modification to
  521. 22:27the data.
  522. 22:28Okay? It could be while in transit.
  523. 22:31So, if an authorized party not only
  524. 22:34accesses but tampers with an asset,
  525. 22:38that threat is a modification. So, for
  526. 22:41example, someone might change the values
  527. 22:43in a database
  528. 22:45after a program so that it performs an
  529. 22:47additional computations, or modify data
  530. 22:50being transmitted electronically,
  531. 22:53or while the data is in transit.
  532. 22:55So, it is even possible to modify
  533. 22:57hardware.
  534. 22:58Some cases of modification can be
  535. 23:00detected with simple measures,
  536. 23:03but other more subtle
  537. 23:06changes may be almost impossible to
  538. 23:08detect.
  539. 23:09Okay? So, this security threats
  540. 23:12interruption is a threat to
  541. 23:13availability.
  542. 23:15Interception is a threat to
  543. 23:17confidentiality
  544. 23:18or secrecy, and modification is a threat
  545. 23:21to integrity.
  546. 23:23All right?
  547. 23:25So, aside from this,
  548. 23:26we also have fabrication.
  549. 23:29Okay? Fabrication is an authorized party
  550. 23:32inserts false information.
  551. 23:35Okay? An authorized party might create a
  552. 23:38fabrication of a counterfeit objects
  553. 23:42on a computer system. So, the intruder
  554. 23:44may insert spurious transactions through
  555. 23:47a network communication system or add
  556. 23:50records on existing database.
  557. 23:52So, sometimes this additions can be
  558. 23:55detected as
  559. 23:57forgeries,
  560. 23:58but if it's skillfully done,
  561. 24:00they are virtually indistinguishable
  562. 24:03from the real thing.
  563. 24:05Okay? And it's a challenge for us
  564. 24:07systems administrator.
  565. 24:10Okay?
  566. 24:11Next is masquerade.
  567. 24:13Okay? An entity pretending to be a
  568. 24:15different entity.
  569. 24:17So, in general,
  570. 24:18a masquerade is a disguise.
  571. 24:21Okay? In terms of communications
  572. 24:23security issues, masquerade is a type of
  573. 24:26attack
  574. 24:27where the attacker pretends to be
  575. 24:30the authorized user of a system in order
  576. 24:33to gain access to it
  577. 24:34or
  578. 24:36to gain greater privileges
  579. 24:38than they are authorized for.
  580. 24:40All right? So, a masquerade may be
  581. 24:42attempted
  582. 24:44through
  583. 26:53>> Okay.
  584. 26:55So, next is fabrication. Fabrication
  585. 26:58basically
  586. 27:00the receiver received information, but
  587. 27:04it was not came from the sender.
  588. 27:07So, something like, "Thank you for
  589. 27:09sending me flowers. I didn't send you
  590. 27:11any." All right? So, that's fabrication.
  591. 27:15Okay? So, it was came from someone.
  592. 27:18Okay? But, not or definitely not from
  593. 27:21the legitimate source.
  594. 27:23Okay? So, next.
  595. 27:26Security threats and network assets.
  596. 27:29So, what are the network assets?
  597. 27:32So, basically, these are the data,
  598. 27:34communication lines, hardware, and
  599. 27:36software.
  600. 27:37So, these are the asset of the
  601. 27:39organization, and we need to protect
  602. 27:42any of this or all of this.
  603. 27:45Okay? Just like protecting your data
  604. 27:47from masquerade, modification,
  605. 27:51interception, and interruption.
  606. 27:54Okay?
  607. 27:55So, your communication lines is also
  608. 27:57prone to masquerade, modification,
  609. 28:00interception,
  610. 28:02and interruption. So, imagine
  611. 28:03interruption in what sense?
  612. 28:05Maybe your your your access point was
  613. 28:08stolen, the router was stolen, okay?
  614. 28:11So, the communication line itself was
  615. 28:13stolen.
  616. 28:15Okay? So, that's an interruption.
  617. 28:17All right?
  618. 28:18Next is hardware. So, what are the
  619. 28:20threats
  620. 28:21on hardware?
  621. 28:23Theft of the hardware itself, all right?
  622. 28:26So, denial of service.
  623. 28:29Okay? So, these are examples of an
  624. 28:31interruption.
  625. 28:33Okay? So, how about a software?
  626. 28:35On software, someone can modify,
  627. 28:38interrupt, through deletion. Okay? So,
  628. 28:41they have deleted your files,
  629. 28:43or interception. So, when you forwarded
  630. 28:46a data,
  631. 28:47it can be intercepted along the way.
  632. 28:49Okay? So, basically, these are the
  633. 28:52security threats
  634. 28:53on your network assets.
  635. 28:57All right?
  636. 28:59Next, security management function.
  637. 29:02So, how do we manage security? So, we
  638. 29:06have to maintain security information.
  639. 29:09Okay? So, there should be event logs,
  640. 29:12monitoring of uses of security-related
  641. 29:14resources.
  642. 29:16Okay?
  643. 29:17There should be receiving notification
  644. 29:19and reporting security violations.
  645. 29:23All right? And maintaining and examining
  646. 29:26security logs.
  647. 29:28All right? So, you should have this
  648. 29:30facility
  649. 29:31on your network.
  650. 29:33Okay?
  651. 29:34So, also, maintaining backup copies of
  652. 29:37security-related
  653. 29:39files.
  654. 29:41Okay, so next is the control resource
  655. 29:43access service.
  656. 29:45Okay?
  657. 29:46So, use access control, authentication,
  658. 29:49and authorization. We already have
  659. 29:51defined authentication and
  660. 29:53authorization. Authentication is the
  661. 29:55first
  662. 29:57security, okay?
  663. 29:59on the infrastructure
  664. 30:01by asking username and password.
  665. 30:04Okay? So, if you were able to get in,
  666. 30:06authorization are the type of access
  667. 30:08given to you.
  668. 30:10Okay? So, what are you authorized to do
  669. 30:13when you're able to get in?
  670. 30:15But, authorization.
  671. 30:17All right?
  672. 30:18So,
  673. 30:20for authentication, so this includes
  674. 30:22username and passwords.
  675. 30:24Okay? For authorization,
  676. 30:27are you authorized to view or generate a
  677. 30:29routing table or the accounting tables,
  678. 30:32etc.?
  679. 30:34Okay? What are you allowed to perform?
  680. 30:37It's authorization.
  681. 30:39Okay?
  682. 30:41The last one would be control the
  683. 30:43encryption process.
  684. 30:45Okay?
  685. 30:47So, we must be able to encrypt messages
  686. 30:50between managers and agents. And we do
  687. 30:52that by integrating and incorporating
  688. 30:56a different encryption algorithm. So,
  689. 30:59maybe you're familiar with
  690. 31:01uh 3 DES, all right? The Blowfish
  691. 31:03encryption,
  692. 31:05the two-phase encryption, Advanced
  693. 31:07Encryption Standard or the AES.
  694. 31:10We use that in Cisco.
  695. 31:12IDEA
  696. 31:13encryption,
  697. 31:15MD5,
  698. 31:16the HMAC, and RSA.
  699. 31:19So, these are just some of the examples
  700. 31:21of the encryption algorithm that we can
  701. 31:23use to protect the data. All right?
  702. 31:30All right. So, we have reached the end
  703. 31:33of the presentation.
  704. 31:35So, to summarize,
  705. 31:36so we've talked about network control,
  706. 31:38okay? And network control is concerned
  707. 31:40with setting and changing parameters of
  708. 31:42various parts of the network resources
  709. 31:44as a consequence of network monitoring
  710. 31:47and analysis.
  711. 31:48Okay?
  712. 31:50Also, we've talked about configuration
  713. 31:52control and security control. These are
  714. 31:54the two essential aspects of network
  715. 31:56control.
  716. 31:58All right?
  717. 31:59So, thank you for sticking around, and
  718. 32:01thank you for watching. Have a great
  719. 32:03day.

About this transcript

This page contains the full transcript of Network Control by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 3,159 words across 719 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.