Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Instructor: Before we can dive deeply
into the world of penetration testing,
it's important for us to take a few minutes
and talk about risk.
Good risk management skills are incredibly important
in the world of penetration testing, because without them,
you're gonna cause some horrific accidents
that could cost you your job, your company its contract,
or at least some serious downtime for the network
that you're conducting a penetration test against.
So let's start with two basic questions:
What is risk, and where does risk exist?
Now, risk at its core is the probability
that a threat will be realized.
Risk is a continual balancing act between vulnerabilities
and the threats that try to exploit them.
If you're a cybersecurity professional
working on the defensive side of the industry,
like a cybersecurity analyst would,
then your job is to minimize vulnerabilities.
But when we're working as a penetration tester,
our job is to find vulnerabilities in a system
and then exploit them to prove
that the network is truly vulnerable to an outside attack.
Now, when you hear the term vulnerability,
you should remember that it simply means any weakness
in the system design or implementation.
Vulnerabilities come from internal factors,
things like software bugs, misconfigured software,
improperly protected network devices,
lacking physical security, and other issues like this.
Vulnerabilities are within the control
of the system owner to correct.
So if you're conducting a penetration test
against an organization,
it is within their ability to mitigate
or fix most of those vulnerabilities that you find.
Conversely, however, as cybersecurity professionals,
we can't fully control threats,
but instead, we attempt to minimize or mitigate them.
Now, when you're conducting a penetration test,
you are technically the threat actor in that situation,
and so you are the enemy
of the cyber security analyst who are charged
with defending their organizational networks.
In general, though, a threat is anything
or anyone that could cause harm, loss, damage,
or compromise to our information technology systems.
These threats come from external sources,
things like natural disasters, cyber attacks,
data integrity breaches,
disclosure of confidential information,
and numerous other issues that may arise
during our daily operations.
But those threats can also come from internal sources,
such as an insider threat
who's trying to steal corporate secrets
or an employee who mistakenly leaves the back door unlocked
after taking out the trash before going home at night.
So now that we've covered the concept of vulnerabilities
and threats, let's answer our second question:
Where does risk exist?
Well, risk exists in the intersection area
between threats and vulnerabilities when we diagram them
with two overlapping circles in a Venn diagram.
Now, this is a key point to understand.
If you have a threat, but there is no vulnerability,
then there is no risk.
The same holds true that if you have a vulnerability
but there's no threat against it, there's also no risk.
Let's consider the example of trying to get
to work on time in the morning.
Your alarm clock goes off just after 6:00 AM
and you hop out of bed, you get dressed,
you eat breakfast, and now you have to get
from your house to your office across town,
but there are many vulnerabilities
and threats all around you that could cause a bad outcome,
like you arriving late for work.
This is an everyday example that most of us live with
in the world of risk management.
Let's consider a few possible vulnerabilities.
One might be that you forgot to put gas
in your car the night before,
so let's call this the vulnerability
of a lack of preparation.
Another might be that you forgot it was your day
to drop the kids off at school before driving to work.
There are a lot of possible vulnerabilities to your plan
of getting to work on time, but you can control these
because vulnerabilities are internal factors.
But there are several other threats
to your arriving on time that are outside of your control.
What if there is a traffic jam this morning?
That would certainly cause a delay to your commute
and you would arrive late to work,
which is a realization of that threat.
Another threat could be a natural disaster that's occurring,
like a flood or an earthquake that causes the road
between your home and your office to become unusable.
Now, I know that's a little dramatic,
but you're getting the idea hopefully.
You can't stop a flood or an earthquake.
It's an external factor, and it's a threat
to you arriving to work on time if they were to happen.
Now, we have several threats
and several vulnerabilities that we just identified
in this simple example, but what can we do about them?
Well, if we're worried about being late for work,
one thing we could do is wake up a little bit earlier.
That way, even if an external threat like a traffic jam
or a flooded or destroyed road was in the way,
we can actually find an alternate route
and still get to the office on time.
This is what is referred to as risk management.
It's all about finding ways to minimize the likelihood
of a certain outcome from occurring
and achieving the outcomes that you really wanna achieve.
Now, let's circle back to the world of penetration testing.
As you look at a system,
you need to identify the vulnerabilities that it has
so that you as the threat can go and exploit them.
Going back to my earlier statement,
if there is no vulnerability,
then the threat cannot put that system at risk.
For example, let's say I have a laptop here
that has top secret information on it
but I never connected it to the internet.
You're gonna have a really hard time
conducting a remote exploitation of that laptop system
because it's not online.
By choosing to eliminate the vulnerability
of a remote connection, I have effectively stopped
all remote exploits against that laptop.
It's no longer at risk for those.
Now, unfortunately, this also means
that laptop is no longer useful if I wanted to use it
to do my online banking or something else
that requires an internet connection.
And so you have to think about the pros and the cons
for each mitigation that you apply
against a known vulnerability.
Now, in general, a risk is any vulnerability
that exists that has a threat that could exploit it.
So if I have a server connected to the internet,
it has some vulnerabilities
that we're gonna need to mitigate
as cyber security professionals and defenders,
while a threat actor or penetration tester
is on the other side of things trying to break into it.
To properly manage risk in the world of cyber security,
we first are gonna categorize each risk.
Now, risk is identified
by the different risk types that exist,
things like inherent, residual, and exceptions.
Inherent risk is gonna occur when a risk is identified
but no mitigation factors have been applied.
For example, if I'm gonna drive to work,
there is an inherent risk that I could get
into a car accident and injure myself.
In everything we do in cyber security
as well as the real world, there is some inherent risk.
If I'm gonna install a software patch
to my domain controller, then there's gonna be a risk
that that patch might be faulty
and it could prevent the domain controller
from working as designed.
If my office is located in the area of the world is prone
to hurricanes like Puerto Rico, then guess what?
There's an inherent risk that we could lose power
because there's a hurricane that hits the island.
Essentially, inherent risk is the level of risk in place
prior to us taking any mitigating actions
to reduce the impact or likelihood
of that risk being realized.
Now, if you have a server that's connected to the internet,
there is an inherent risk that it could be attacked.
For example, if an advanced persistent threat,
or APT, wants to target your network,
it really is only a matter of time and resources
before they're ultimately gonna be successful
in exploiting your network.
Now, this doesn't mean we can throw up our hands and give up
on applying controls to make our organization more secure,
but there is always gonna be some level of inherent risk
in all the operations we do,
and a cyber attacker is gonna try to exploit those
to be able to gain access to our systems.
The second type of risk is known as residual risk.
Residual risk occurs when we calculate the risk
after we apply our mitigations and security controls.
So going back to the advanced persistent threat example,
we may decide to create operational policies
to secure our network.
We're then gonna ensure
that every system is fully patched and compliant,
and we're also gonna make sure
that they're as secure as they can be.
Now, there's still a residual risk there,
that there could be a zero day vulnerability
that we didn't know about, and it's gonna be discovered
by an advanced persistent threat.
Now, they're gonna be able to exploit that vulnerability
to gain access to our networks.
That is a residual risk, that amount left over
after we applied all of our security controls.
It's important to understand this
when you're conducting risk management.
Now, the final type of risk we have
is one known as a risk exception.
A risk exception is any risk that is created
due to an exemption being granted
or a failure to comply with corporate policy.
Essentially, think about it this way.
Your organization is implement a cyber security policy,
and it says that all users have to change their passwords
once a quarter, which is every 90 days,
to help prevent brute force attacks.
Well, your CEO decides
that they don't wanna follow this policy
because they hate having to remember new passwords.
So they have the IT department put in an exception
on their user account that lets them change their password
once a year instead of once every 90 days.
This exception to policy
now creates a risk to the organization,
and this risk is known as a risk exception.
In general, risk exception should be avoided
in your organization, but if you do need to use one,
you should always have a process to track these exceptions,
measure the potential impact of allowing these exceptions,
and implement compensating controls
to help mitigate these risks.
(light upbeat music)
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.