1 00:00:00,040 --> 00:00:02,200 I am super excited about this episode. 2 00:00:02,500 --> 00:00:08,280 We have a networking expert coming on and we talk about what to do in your network, 3 00:00:08,280 --> 00:00:12,060 when you get a ransomware attack, I bet you've been wanting to know that answer. 4 00:00:12,240 --> 00:00:13,707 So stay tuned. 5 00:00:34,099 --> 00:00:37,099 W. Curtis Preston: Hi and welcome to Backup Central's Restore All podcast. 6 00:00:37,099 --> 00:00:37,949 I'm your host, W. 7 00:00:37,969 --> 00:00:39,799 Curtis Preston, aka a Mr. 8 00:00:39,804 --> 00:00:45,129 Backup and have with me possibly my Pex consultant Prasanna Malaiyandi. 9 00:00:45,649 --> 00:00:46,249 How's it going? 10 00:00:46,509 --> 00:00:47,189 Prasanna, 11 00:00:47,209 --> 00:00:47,329 Prasanna Malaiyandi: am. 12 00:00:47,539 --> 00:00:48,739 I'm good Curtis. 13 00:00:48,739 --> 00:00:53,839 And just for people that's p e x, not P E C K S. 14 00:00:55,099 --> 00:00:59,719 W. Curtis Preston: Yeah, this is the piping, the, uh, the modern 15 00:00:59,719 --> 00:01:04,939 piping alternative to copper, which I think is far superior. 16 00:01:05,029 --> 00:01:07,624 And, uh, You know what? 17 00:01:07,624 --> 00:01:12,094 Just, just for those that are watching this on on video, which is only a 18 00:01:12,094 --> 00:01:17,404 handful of you, but I'm gonna tilt my camera up and this is what my office 19 00:01:17,404 --> 00:01:25,144 looks like right now because I got yet another pinhole leak in my, um, second 20 00:01:25,144 --> 00:01:29,494 story bathroom water supply, which happens to be right above my office. 21 00:01:29,974 --> 00:01:33,874 And yesterday I was just sitting here at my desk and I get this 22 00:01:33,884 --> 00:01:37,124 drip drip on my face and I'm like, 23 00:01:37,369 --> 00:01:39,319 Prasanna Malaiyandi: you're like, am I sweating profusely? 24 00:01:39,334 --> 00:01:39,964 W. Curtis Preston: Yeah. 25 00:01:39,969 --> 00:01:42,304 And the pipe, the pipe is actually over there. 26 00:01:42,304 --> 00:01:45,454 The, the, the joint that's leaking, it's actually over there, but you know, 27 00:01:45,454 --> 00:01:47,614 the water finds its way, you know, 28 00:01:47,614 --> 00:01:51,214 along a drywall seam and then it just sort of drips 29 00:01:51,214 --> 00:01:52,624 down onto my face. 30 00:01:53,059 --> 00:01:54,679 Prasanna Malaiyandi: you know what though, Curtis, I have to say 31 00:01:54,684 --> 00:01:58,879 congratulations on finally finishing your other project, which we should 32 00:01:58,879 --> 00:01:59,149 tell our 33 00:01:59,269 --> 00:01:59,899 W. Curtis Preston: my other pro. 34 00:02:00,409 --> 00:02:00,829 Yeah. 35 00:02:00,859 --> 00:02:01,099 Yeah. 36 00:02:01,099 --> 00:02:04,189 For those who have been following along my other project is, is, I 37 00:02:04,189 --> 00:02:07,159 mean, it, it's still, you know, at this point it's 98% done. 38 00:02:07,159 --> 00:02:10,189 But, you know, I have put the, the stair, you know, the, the, 39 00:02:10,189 --> 00:02:11,599 the flooring on the stairs. 40 00:02:12,049 --> 00:02:13,969 Um, it looks really good. 41 00:02:14,269 --> 00:02:17,569 Uh, it looks way better than the ceiling in this room, I will say that. 42 00:02:18,019 --> 00:02:22,399 Um, and now there's the official first mess on the new floor 43 00:02:23,149 --> 00:02:24,079 . There's just, as I 44 00:02:24,214 --> 00:02:26,044 Prasanna Malaiyandi: At some point it's gonna happen, you know? 45 00:02:26,239 --> 00:02:26,749 W. Curtis Preston: yeah. 46 00:02:27,079 --> 00:02:29,239 Well, apparently that some point is today. 47 00:02:29,929 --> 00:02:33,979 Uh, but yeah, so the plumber, who is a good guy, uh, he's been here before, 48 00:02:34,309 --> 00:02:39,369 um, he, um, he's talking to me about, he knows a guy that does, uh, PEX repiping 49 00:02:39,384 --> 00:02:39,889 so, we'll, 50 00:02:41,554 --> 00:02:44,344 Prasanna Malaiyandi: Our listeners will learn all about water piping 51 00:02:44,344 --> 00:02:46,594 soon in the next few episodes as we go 52 00:02:46,699 --> 00:02:49,189 W. Curtis Preston: More, more than you ever wanted to know. 53 00:02:49,219 --> 00:02:51,979 Uh, and by the way, I did check they can go through the attic. 54 00:02:52,039 --> 00:02:59,149 So, um, that is a, that is a real possibility for the, um, and, um, yeah, 55 00:02:59,149 --> 00:03:05,959 so anyway, um, and I just realized that, uh, my son-in-law is home today. 56 00:03:05,959 --> 00:03:06,799 He's not normally home. 57 00:03:06,799 --> 00:03:08,149 I just heard him making noise. 58 00:03:08,329 --> 00:03:11,089 I hope he gets his bath out of the way before the plumber gets here. 59 00:03:13,129 --> 00:03:14,179 I didn't, I didn't warn him. 60 00:03:14,839 --> 00:03:18,709 Uh, I actually hear, I hear a bath going on right now, . So, 61 00:03:18,839 --> 00:03:20,329 so that answer's that question. 62 00:03:21,289 --> 00:03:23,959 Way too much information going on at depress pressing 63 00:03:23,959 --> 00:03:24,379 household. 64 00:03:24,379 --> 00:03:24,619 Well, listen. 65 00:03:24,649 --> 00:03:25,049 Prasanna Malaiyandi: okay. 66 00:03:25,654 --> 00:03:27,724 W. Curtis Preston: Yeah, we wanna bring on our guest. 67 00:03:27,784 --> 00:03:31,384 Uh, he is both, I would say, a friend of the pod. 68 00:03:31,384 --> 00:03:33,754 He's also been an enemy of the pod at once. 69 00:03:33,754 --> 00:03:37,654 You may recall that we had an episode where basically we just argued 70 00:03:37,654 --> 00:03:41,614 with Tom without his per, without him being here to defend himself. 71 00:03:42,034 --> 00:03:47,494 Um, that was over a blog post that he said, uh, something about, uh, backup 72 00:03:47,494 --> 00:03:49,084 people reporting to security people. 73 00:03:49,084 --> 00:03:49,624 And, uh, I 74 00:03:49,624 --> 00:03:51,214 think I had an issue with that or something. 75 00:03:51,524 --> 00:03:54,224 Tom has been in the industry about 20 years and he is an 76 00:03:54,224 --> 00:03:56,294 event lead over at Gestalt. 77 00:03:56,474 --> 00:03:59,144 It the, uh, what would you call it? 78 00:03:59,144 --> 00:04:03,884 The makers of the Tech Field Day series, which, uh, uh, my 79 00:04:03,884 --> 00:04:05,294 employer has used quite a bit. 80 00:04:05,654 --> 00:04:09,344 And, um, uh, we're glad to have him on the podcast. 81 00:04:09,344 --> 00:04:11,684 Welcome, Tom Hollingsworth. 82 00:04:12,509 --> 00:04:14,399 Tom Hollingsworth: Well, thank you for having me on Curtis. 83 00:04:14,399 --> 00:04:18,539 It was, uh, it was fascinating to listen to an episode where I was, I was arguing 84 00:04:18,539 --> 00:04:19,919 with somebody and it wasn't even here. 85 00:04:20,309 --> 00:04:25,079 But, uh, I, I, I love, I love listening to you guys, and I've learned quite a bit. 86 00:04:25,079 --> 00:04:28,739 In fact, uh, the very first time that Curtis and I ever met at Tech Field Day 87 00:04:29,009 --> 00:04:32,459 back in 2011, he was teaching me about data de-duplication, and I was trying to 88 00:04:32,459 --> 00:04:34,169 convince him that IP V6 was important. 89 00:04:34,169 --> 00:04:37,039 And I can tell you which one of those things panned out a lot better than the. 90 00:04:38,834 --> 00:04:41,864 W. Curtis Preston: Uh, well, you know, is it, is that the thing where 91 00:04:41,864 --> 00:04:44,054 you do the nat behind the thing? 92 00:04:44,054 --> 00:04:47,354 That's what I recall really learning from you was that you gotta do 93 00:04:47,354 --> 00:04:49,304 Tom Hollingsworth: if you want me to come crashing through your roof 94 00:04:49,304 --> 00:04:50,924 like the Kool-Aid man, just keep 95 00:04:50,924 --> 00:04:51,344 it up my. 96 00:04:54,164 --> 00:04:54,674 W. Curtis Preston: Yeah. 97 00:04:54,674 --> 00:04:55,094 Yeah. 98 00:04:55,144 --> 00:04:58,084 I wanted to bring on somebody that actually understood networking 99 00:04:58,084 --> 00:04:59,794 far better than me, right? 100 00:04:59,794 --> 00:05:02,974 Which, which is basically many people in the world. 101 00:05:03,344 --> 00:05:04,874 With ransomware attacks. 102 00:05:05,999 --> 00:05:10,889 One of the things that we talk about is once you've, um, you 103 00:05:10,889 --> 00:05:14,579 know, figured out that you actually have a ransomware attack, you, 104 00:05:14,579 --> 00:05:16,349 you want to isolate the network. 105 00:05:16,709 --> 00:05:22,559 And there there's a discussion, you know, I've been talking with with CISOs lately 106 00:05:22,559 --> 00:05:28,289 and, and, and what, what appears to be the reality is that that few environments 107 00:05:28,889 --> 00:05:31,469 actually do the, the actual full. 108 00:05:31,469 --> 00:05:33,629 Like we just we're just shutting everything off. 109 00:05:33,689 --> 00:05:34,079 Right. 110 00:05:34,499 --> 00:05:37,259 Prasanna Malaiyandi: Go grab the cable, pull it out quick, quick, 111 00:05:37,589 --> 00:05:38,639 W. Curtis Preston: They're actually, I know. 112 00:05:38,644 --> 00:05:41,429 Tom, did you ever watch, uh, alias when it was on 113 00:05:42,269 --> 00:05:43,199 Tom Hollingsworth: I've seen a couple of 114 00:05:43,529 --> 00:05:43,649 W. Curtis Preston: and. 115 00:05:44,669 --> 00:05:48,929 Okay, well there's an episode in there when they were having a cyber 116 00:05:48,929 --> 00:05:52,229 attack and the, uh, what's his name? 117 00:05:52,229 --> 00:05:57,029 Um, uh, Marshall Flank man comes running into the data center and he just literally 118 00:05:57,034 --> 00:05:59,189 starts flipping, flipping power switches. 119 00:05:59,189 --> 00:06:02,339 He's like, they're downloading all the files off the server and he down. 120 00:06:02,344 --> 00:06:04,139 He just flips all the power switches off. 121 00:06:04,799 --> 00:06:09,349 And so, you know, on one end there is the complete. 122 00:06:10,664 --> 00:06:15,059 like networking, shutdown, like literally both internal and external, right? 123 00:06:15,089 --> 00:06:19,019 Um, because, you know, once the, once the ransomware is inside, it's gonna try to 124 00:06:19,019 --> 00:06:20,909 crawl around and, and make things worse. 125 00:06:21,089 --> 00:06:22,319 So that's one way. 126 00:06:22,589 --> 00:06:26,819 And then there are, you know, and, and then there's the, those that go, well, 127 00:06:27,089 --> 00:06:33,259 well, I'm just going to turn it off, or I'm gonna unplug the cable at the 128 00:06:33,264 --> 00:06:36,839 one server or the three servers that appear to be infected and I'm not gonna 129 00:06:36,839 --> 00:06:38,459 worry about the rest of the network. 130 00:06:39,209 --> 00:06:44,399 And somewhere in the, between those two extremes is what everybody else does. 131 00:06:44,909 --> 00:06:46,529 Prasanna Malaiyandi: And maybe we should also talk about basics 132 00:06:46,529 --> 00:06:50,159 of networking before we jump into this to talk about the detail. 133 00:06:50,369 --> 00:06:51,089 Because just 134 00:06:51,769 --> 00:06:52,239 W. Curtis Preston: Go ahead. 135 00:06:52,239 --> 00:06:52,679 Go ahead. 136 00:06:52,679 --> 00:06:53,309 Prasanna, 137 00:06:53,324 --> 00:06:55,169 what, what do you think we should be talking about first? 138 00:06:55,589 --> 00:06:58,709 Prasanna Malaiyandi: no, I think it's sort of, because what you just 139 00:06:58,739 --> 00:07:01,469 mentioned, Curtis, like everyone might think, oh, all computers 140 00:07:01,474 --> 00:07:03,119 are plugged into the same network. 141 00:07:03,119 --> 00:07:03,389 Right? 142 00:07:03,389 --> 00:07:07,019 I think it's important to talk about some of the best practices from networking, 143 00:07:07,019 --> 00:07:11,399 Tom, if you could, about sort of network isolation, BLANs, other things like that. 144 00:07:11,609 --> 00:07:13,679 Before we get into sort of the other side of things, 145 00:07:13,799 --> 00:07:19,679 W. Curtis Preston: Yeah, so please explain all networking technology, period before 146 00:07:19,754 --> 00:07:20,394 Tom Hollingsworth: the good news. 147 00:07:21,249 --> 00:07:23,084 ,you've already talked a little bit about it because it's just 148 00:07:23,084 --> 00:07:26,384 a series of tubes, pipes, if you will, that we send things through. 149 00:07:27,014 --> 00:07:30,524 Uh, now the, the, the important thing to realize when you're trying to think 150 00:07:30,529 --> 00:07:35,474 about how ransomware propagates through a network is to realize that, um, the 151 00:07:35,474 --> 00:07:38,384 way that networks have traditionally been built is we have this perimeter 152 00:07:38,444 --> 00:07:42,314 on the outside, you know, it's probably bounded by firewalls and a bunch of 153 00:07:42,314 --> 00:07:45,164 other stuff, and it looks really, really imposing on the castle walls, 154 00:07:45,464 --> 00:07:47,624 but inside of the network, it's a whole lot easier to get around. 155 00:07:47,684 --> 00:07:51,164 And that's just due to the nature of the way that that networks operate. 156 00:07:51,164 --> 00:07:54,854 I mean, ethernet is effectively like trying to shout out somebody's order 157 00:07:54,854 --> 00:07:57,794 number at a fast food restaurant and hoping that you get the right one. 158 00:07:57,914 --> 00:08:00,464 Everybody's gonna hear the message, but if it's not meant for you, 159 00:08:00,524 --> 00:08:01,604 we're just gonna ignore it. 160 00:08:01,994 --> 00:08:06,014 But the problem is, is that that allows you to propagate a lot of information 161 00:08:06,014 --> 00:08:10,664 very quickly, and that's what ransomware is trying to take, uh, advantage of 162 00:08:10,664 --> 00:08:14,084 whenever it's, it's trying to, uh, do almost like, you know, reconnaissance 163 00:08:14,089 --> 00:08:15,314 lateral movement in the network. 164 00:08:15,314 --> 00:08:20,699 So I'm, I'm looking for a whole bunch of, um, , potentially vulnerable servers 165 00:08:20,969 --> 00:08:24,359 going all the way back, you know, to the beginning of my professional IT career, 166 00:08:24,359 --> 00:08:28,409 I was actually working on a help desk, uh, when the S SQL slammer worm came out. 167 00:08:28,709 --> 00:08:32,159 And boy, you'd be surprised how many people had that port open to the internet, 168 00:08:32,489 --> 00:08:33,869 uh, because everything shut down. 169 00:08:34,169 --> 00:08:35,489 And it was really weird to see that. 170 00:08:35,489 --> 00:08:38,069 And you're like, well, you know, at the time I'm, I'm kind of 171 00:08:38,069 --> 00:08:39,749 freshly minted in my career. 172 00:08:39,749 --> 00:08:41,489 And I'm like, well, how could that happen? 173 00:08:41,489 --> 00:08:44,459 And, and now all these years later, I look at it and go, oh my God, 174 00:08:44,459 --> 00:08:47,099 these people were stupid because you're not supposed to do that. 175 00:08:47,699 --> 00:08:51,149 But that's one of the things that people want to take advantage of because the, 176 00:08:51,209 --> 00:08:53,069 the systems want to talk to each other. 177 00:08:53,069 --> 00:08:55,109 They want to be able to exchange information. 178 00:08:55,409 --> 00:08:56,999 That's the purpose of a network. 179 00:08:57,119 --> 00:09:01,629 You actually have to do extra work to prevent them from talking to each other. 180 00:09:02,399 --> 00:09:02,789 W. Curtis Preston: Right. 181 00:09:02,789 --> 00:09:02,919 Yeah. 182 00:09:02,939 --> 00:09:07,769 I think that's, you know, I, I, and the, the number of times I went in and out 183 00:09:07,769 --> 00:09:14,999 of data centers, uh, over the years, I remember only one, uh, where they had 184 00:09:15,059 --> 00:09:18,329 very solid internal firewalls, basically. 185 00:09:18,334 --> 00:09:18,629 Right. 186 00:09:18,634 --> 00:09:22,349 That, that it was very difficult to do, to traverse laterally 187 00:09:22,349 --> 00:09:23,699 within the organization. 188 00:09:24,089 --> 00:09:26,939 And that was actually Intuit, uh, right. 189 00:09:27,009 --> 00:09:29,459 And, and it's because of what they felt they had. 190 00:09:29,459 --> 00:09:29,669 Right. 191 00:09:29,669 --> 00:09:34,499 They had all of this very sensitive personal data, thanks to their, you know, 192 00:09:34,499 --> 00:09:37,799 they, they had QuickBooks, they have TurboTax, they have all of that stuff. 193 00:09:38,189 --> 00:09:42,569 And so they had to basically firewall off systems between each other to 194 00:09:42,569 --> 00:09:47,459 prevent that lateral movement that you're right by design in most networks, you 195 00:09:47,459 --> 00:09:51,779 buy a switch, you buy, well, a bunch of switches, you plug everything in. 196 00:09:52,274 --> 00:09:54,944 And everything talk, everything can talk to everything. 197 00:09:55,484 --> 00:10:03,044 Um, and unless you do something to prevent it, a lot of those ports that 198 00:10:03,044 --> 00:10:07,184 you talked about, right, just like the SQL, uh, issue, a lot of those 199 00:10:07,184 --> 00:10:08,984 ports are visible to the internet. 200 00:10:09,014 --> 00:10:09,344 Right. 201 00:10:09,349 --> 00:10:13,094 I, I think a, another one would be a, a vCenter Right. 202 00:10:13,094 --> 00:10:17,264 And Hyper V, the, that, those ports being visible to the internet, I suppose 203 00:10:17,264 --> 00:10:18,584 you hear about that a lot as well. 204 00:10:19,319 --> 00:10:19,769 Tom Hollingsworth: Yeah. 205 00:10:19,769 --> 00:10:20,459 I usually do. 206 00:10:20,799 --> 00:10:23,459 Whenever there's some kind of, uh, a vulnerability that comes out and 207 00:10:23,759 --> 00:10:25,799 everyone's like, I hope you don't have these exposed to the internet, and 208 00:10:25,799 --> 00:10:28,799 you can literally hear the scrabbling as people run into their keyboards 209 00:10:28,799 --> 00:10:30,179 to figure out if that's the case. 210 00:10:30,569 --> 00:10:31,529 But, you know, as, 211 00:10:31,529 --> 00:10:35,099 as Prasanna mentioned, I mean, we have ways to kind of like segment 212 00:10:35,099 --> 00:10:36,449 networks away from each other. 213 00:10:36,629 --> 00:10:39,989 And it's funny that you bring up that, that Intuit had kind of a, a rigorous 214 00:10:40,479 --> 00:10:45,179 internal firewall structure because in my experience, um, companies or organizations 215 00:10:45,179 --> 00:10:47,279 that are very, uh, heavily regulat. 216 00:10:47,639 --> 00:10:50,669 Have much more strict internal structure. 217 00:10:50,969 --> 00:10:54,929 And the reason for that is because they need the ability to say 218 00:10:54,929 --> 00:10:59,189 for a fact, Curtis cannot see anything on this network because he 219 00:10:59,194 --> 00:11:00,659 hasn't been authorized to see it. 220 00:11:01,019 --> 00:11:03,779 Now, you can do that through software constructs. 221 00:11:03,779 --> 00:11:07,979 I mean, VLANs, virtual local area networks are kind of the, the most common 222 00:11:07,979 --> 00:11:12,479 way to do it, where we, we effectively divide some, uh, uh, partition on the 223 00:11:12,479 --> 00:11:16,649 switch and we say, this port belongs to this vlan, so it can only talk to 224 00:11:16,649 --> 00:11:18,239 other ports that are on that vlan. 225 00:11:18,629 --> 00:11:21,359 Uh, but that's not even good enough for some organizations. 226 00:11:21,359 --> 00:11:24,989 And, and the, the one that everybody always thinks of is Mission Impossible, 227 00:11:25,049 --> 00:11:28,709 the Tom Cruise movie with the, the machine that's in a vault that's 228 00:11:28,709 --> 00:11:30,179 not connected to anything else. 229 00:11:30,329 --> 00:11:32,279 We would call that an air gap system. 230 00:11:32,279 --> 00:11:37,229 Or you can have an air gap network a lot of times things like, um, HVAC or 231 00:11:37,229 --> 00:11:40,019 management systems are air gap from the rest of the network because they 232 00:11:40,019 --> 00:11:43,739 have different controls and different needs, but I also don't trust those 233 00:11:43,739 --> 00:11:46,499 people to, um, secure their stuff. 234 00:11:46,499 --> 00:11:50,399 So I'm gonna build a wall in front of that air gap or just completely 235 00:11:50,399 --> 00:11:54,509 isolate it, uh, itself so that I don't have to worry about securing it. 236 00:11:54,719 --> 00:12:00,089 And if, uh, you, you say hvac, you say things like, you know, uh, um, 237 00:12:00,149 --> 00:12:03,869 environmental control systems and any security people listening to this 238 00:12:03,869 --> 00:12:06,479 podcast are immediately thinking, man, those are back doors that I 239 00:12:06,479 --> 00:12:07,799 can use to get into the system. 240 00:12:08,069 --> 00:12:10,829 Because no matter what, they're still gonna have to be connected 241 00:12:10,829 --> 00:12:12,509 to the network somehow. 242 00:12:12,509 --> 00:12:17,459 And that just increases your, um, you know, your threat profile. 243 00:12:18,114 --> 00:12:18,674 W. Curtis Preston: Right. 244 00:12:20,594 --> 00:12:23,864 Prasanna Malaiyandi: Yeah, it's interesting because I think most people 245 00:12:23,864 --> 00:12:25,544 who think about home networks, right? 246 00:12:25,604 --> 00:12:27,914 Everything's typically flat in a home, right? 247 00:12:27,914 --> 00:12:30,974 Everything can talk to everything, every single iot device out there, right? 248 00:12:30,979 --> 00:12:34,754 And they're not always thinking about, Hey, I got this smart light bulb. 249 00:12:34,754 --> 00:12:35,474 Isn't it great? 250 00:12:35,474 --> 00:12:36,314 Isn't it awesome? 251 00:12:36,314 --> 00:12:40,904 And then realizing that's on my network, everything is now exposed and could 252 00:12:40,904 --> 00:12:44,774 be potentially exposed if there's a security issue with that single device, 253 00:12:46,034 --> 00:12:49,544 Tom Hollingsworth: Those devices are, you know, they obviously have an IP address, 254 00:12:49,544 --> 00:12:51,554 they have some kind of a control system. 255 00:12:51,794 --> 00:12:55,094 You would hope that most of them have some kind of a security function that 256 00:12:55,094 --> 00:12:59,234 allows them to, to securely communicate back to whatever controls them. 257 00:12:59,594 --> 00:13:04,454 But multiply that by a factor of 10 for all of the devices that could be 258 00:13:04,454 --> 00:13:06,434 on your average enterprise network. 259 00:13:06,704 --> 00:13:11,564 And when you start saying things like, you know, access controls for those devices, 260 00:13:11,594 --> 00:13:16,694 or port security like network engineering and, and operations folks, like, they 261 00:13:16,694 --> 00:13:18,284 just start breaking out into hives. 262 00:13:18,884 --> 00:13:23,399 because like the, the, just the amount of work that it takes to create that 263 00:13:23,399 --> 00:13:26,819 level of security is its own monster. 264 00:13:26,819 --> 00:13:30,899 I mean, anyone who's ever deployed a technology like 8 0 2 0.1 x, which 265 00:13:30,899 --> 00:13:34,739 is effectively, I am only gonna allow authorized devices to be plugged into 266 00:13:34,739 --> 00:13:39,119 this port, knows that like there's this whole enrollment process and 267 00:13:39,119 --> 00:13:40,769 are you on the authorized users list? 268 00:13:40,769 --> 00:13:42,899 And what happens if you're using a different device today? 269 00:13:43,139 --> 00:13:47,099 And it's just, it's maddening and it, it drives people to insane to the 270 00:13:47,099 --> 00:13:50,159 point where, and that's the normal people who know what they're doing. 271 00:13:50,339 --> 00:13:53,279 Could you imagine an executive plugging their laptop into a network port one 272 00:13:53,279 --> 00:13:54,359 day and going, this doesn't work. 273 00:13:54,809 --> 00:13:57,479 And you tell 'em, oh, it's doing that on purpose because we 274 00:13:57,479 --> 00:13:58,649 want to keep everything secure. 275 00:13:58,799 --> 00:13:59,759 What do you think is gonna happen? 276 00:13:59,759 --> 00:14:01,709 The executive's probably gonna look at you and go, I don't care. 277 00:14:01,859 --> 00:14:02,009 Make 278 00:14:02,024 --> 00:14:02,744 Prasanna Malaiyandi: Turn it off. 279 00:14:02,864 --> 00:14:03,404 Exactly. 280 00:14:04,754 --> 00:14:05,654 . We don't need that. 281 00:14:06,659 --> 00:14:06,959 Tom Hollingsworth: It's getting 282 00:14:06,959 --> 00:14:07,589 in my way. 283 00:14:07,809 --> 00:14:08,249 Prasanna Malaiyandi: Yeah, 284 00:14:08,339 --> 00:14:08,849 W. Curtis Preston: Yeah. 285 00:14:09,149 --> 00:14:15,089 Well, I know that when we, when we had, um, you know, we had a, a, a security 286 00:14:15,149 --> 00:14:19,499 person on and they had a list of things that they wanted people to do that they 287 00:14:19,499 --> 00:14:28,139 felt were common sense, that were, um, ways to prevent basically, sort of, 288 00:14:28,199 --> 00:14:31,739 I, I think the proper thing today when we talk about ransomware is to just 289 00:14:31,739 --> 00:14:36,449 assume something in your, in your world is going to get ransomware, right? 290 00:14:36,449 --> 00:14:40,289 It's just, it is, I think it's just impossible to, to, 291 00:14:40,294 --> 00:14:41,879 to stop it 100% of the time. 292 00:14:41,879 --> 00:14:43,469 So just assume that's going to happen. 293 00:14:43,679 --> 00:14:45,689 So then there's all about. 294 00:14:46,439 --> 00:14:50,939 How to prevent it from activating itself, from talking to the command and control 295 00:14:50,939 --> 00:14:53,489 servers and also the lateral movement. 296 00:14:53,489 --> 00:14:53,729 Right? 297 00:14:53,729 --> 00:14:53,969 So he 298 00:14:53,969 --> 00:14:54,779 Prasanna Malaiyandi: reducing the black 299 00:14:54,899 --> 00:14:56,339 W. Curtis Preston: lateral movement, right? 300 00:14:56,339 --> 00:14:56,849 So what's that? 301 00:14:57,299 --> 00:14:58,079 Prasanna Malaiyandi: Limiting the blast 302 00:14:58,289 --> 00:14:58,739 W. Curtis Preston: radius. 303 00:14:59,249 --> 00:15:03,179 So, so Tom, what, what kinds of things besides VLANs? 304 00:15:03,179 --> 00:15:06,809 Because even VLANs, you know, we have the, we have the VLAN 305 00:15:06,809 --> 00:15:08,189 for this and the VLAN for that. 306 00:15:08,189 --> 00:15:10,919 Still all the servers within that VLAN can talk to each other. 307 00:15:11,369 --> 00:15:17,309 What else can companies do, uh, with modern networking equipment to prevent 308 00:15:17,549 --> 00:15:23,489 lateral movement or to basically prevent it from everything and then, and then, uh, 309 00:15:23,549 --> 00:15:25,589 selectively allow it for certain servers. 310 00:15:26,339 --> 00:15:27,749 Tom Hollingsworth: Well, the first thing you have to do is you have to 311 00:15:27,749 --> 00:15:29,489 realize that a completely flat network. 312 00:15:30,059 --> 00:15:31,769 Is not a stable network. 313 00:15:31,799 --> 00:15:36,539 I mean, there is a limit to the amount of chatter that a network can tolerate 314 00:15:36,539 --> 00:15:38,519 before it starts running into problems. 315 00:15:38,819 --> 00:15:44,519 Um, ethernet is not a, uh, a medium that allows for a large number of hosts because 316 00:15:44,519 --> 00:15:47,609 eventually they're gonna, it, you know, it's like recording a podcast eventually 317 00:15:47,614 --> 00:15:49,319 with too many guests on the podcast. 318 00:15:49,559 --> 00:15:51,239 You're all gonna wanna talk over the top of each other, 319 00:15:51,244 --> 00:15:52,409 and ethernet doesn't like that. 320 00:15:52,739 --> 00:15:55,469 So once you had a certain boundary, you kind of have to divide it 321 00:15:55,469 --> 00:15:56,939 up into these little domains. 322 00:15:56,999 --> 00:15:59,489 Um, collision domains are what we call them, and that's one 323 00:15:59,494 --> 00:16:00,809 of the things that a VLAN is. 324 00:16:01,109 --> 00:16:05,729 But as we've learned over the years about what we really should be doing, 325 00:16:05,729 --> 00:16:07,739 we've kind of built a super set of that. 326 00:16:08,009 --> 00:16:12,029 And anyone out there who has been reading any kind of the tech press recently, or 327 00:16:12,029 --> 00:16:14,939 been to any trade show in the last couple of years, probably heard of something 328 00:16:14,939 --> 00:16:19,349 like Zero Trust Network Architecture or, or, you know, just Zero Trust in general. 329 00:16:19,349 --> 00:16:20,129 It's a buzzword. 330 00:16:20,279 --> 00:16:23,939 I'm, I'll be the first to admit it, but the principles behind it are fairly sound. 331 00:16:24,644 --> 00:16:28,739 what you do is you take the tools that you've already been given, those ones 332 00:16:28,739 --> 00:16:32,279 that I told you, make your network team break out in hives, and you try to 333 00:16:32,279 --> 00:16:36,869 implement them in such a way as to reduce the complexity of the implementation. 334 00:16:37,259 --> 00:16:41,159 And think about like, you know, think about a teenager and they 335 00:16:41,159 --> 00:16:44,939 want a, a list of, uh, things that they can do when they get a car. 336 00:16:45,149 --> 00:16:49,109 Are you gonna tell them you can do anything you want, but 337 00:16:49,109 --> 00:16:51,149 you can't do this and you can't do that and you can't do this? 338 00:16:51,209 --> 00:16:54,089 Or are you gonna be more explicit? 339 00:16:54,209 --> 00:16:59,549 You can only do these things and if it's not on that list, you can't do it. 340 00:17:00,029 --> 00:17:03,119 Well, most people would say, well, I'm only go, I'm gonna do the second 341 00:17:03,119 --> 00:17:06,059 thing because I want to make sure that they're only going to school and to 342 00:17:06,059 --> 00:17:07,829 work into this one friend's house. 343 00:17:08,219 --> 00:17:09,989 But we don't build networks that way. 344 00:17:09,994 --> 00:17:14,039 I mean, we, we typically allow as much as possible because of the 345 00:17:14,039 --> 00:17:17,549 situations we find ourselves in where something doesn't work right. 346 00:17:17,549 --> 00:17:18,569 And we don't know why. 347 00:17:18,749 --> 00:17:21,449 So we will put a little catchall at the bottom of the, the access 348 00:17:21,449 --> 00:17:22,999 list and go permit everything else. 349 00:17:23,939 --> 00:17:24,629 and then we leave it. 350 00:17:25,019 --> 00:17:26,969 And that's the worst thing that you can do. 351 00:17:27,299 --> 00:17:29,939 And what Zero Trust Network architectures try to do is they try 352 00:17:29,939 --> 00:17:32,879 to say, okay, that server over there is running our backup software. 353 00:17:33,269 --> 00:17:36,299 What should it, what should communicate with it? 354 00:17:36,479 --> 00:17:40,169 And how should it be communicated with, you know, maybe it only needs to accept 355 00:17:40,174 --> 00:17:41,849 connections on these three or four ports. 356 00:17:41,854 --> 00:17:45,299 Maybe it only accepts connections from these authorized users. 357 00:17:45,359 --> 00:17:48,389 And you're effectively creating an isolation for that unit. 358 00:17:48,749 --> 00:17:51,569 And if something needs to access it and you're having problems with it, the 359 00:17:52,059 --> 00:17:55,469 software usually allows you to kind of dig into that a little bit and go, oh, it 360 00:17:55,474 --> 00:17:59,099 looks like that this program did an update and it now needs to communicate over this 361 00:17:59,099 --> 00:18:01,859 port, uh, and I need to allow that port. 362 00:18:02,069 --> 00:18:06,329 But you're doing it in a, in a way that allows you to kind of control that access. 363 00:18:06,719 --> 00:18:10,079 But more importantly, what happens is that when something tries to operate 364 00:18:10,079 --> 00:18:15,119 outside of that access control, it slams it shut and hopefully will send 365 00:18:15,124 --> 00:18:18,599 you some kind of a warning, you know, Hey, we just noticed that this server 366 00:18:18,599 --> 00:18:22,709 over here is trying to communicate with the rest of the network on Port 4 45. 367 00:18:23,219 --> 00:18:24,839 and I know it shouldn't be doing that. 368 00:18:25,049 --> 00:18:26,399 You need to take a look at it. 369 00:18:26,819 --> 00:18:31,319 And so limiting that blast radius, that broadcast capability tends 370 00:18:31,319 --> 00:18:33,619 to prevent lateral movement. 371 00:18:33,624 --> 00:18:38,459 And like you said, people who are going to attack you are, are 372 00:18:38,459 --> 00:18:40,229 going to be dedicated in doing it. 373 00:18:40,499 --> 00:18:43,829 Either they're gonna be dedicated to looking for a very specific exploit and 374 00:18:43,829 --> 00:18:47,819 just kind of hauling in whatever they can do, or they're gonna be looking to 375 00:18:47,819 --> 00:18:52,559 attack you, you specifically, however they can get to you that second kind 376 00:18:52,559 --> 00:18:54,959 of attacker, very difficult to block. 377 00:18:54,959 --> 00:18:59,639 It's like a door lock, a dedicated burglar is gonna get into your house. 378 00:18:59,909 --> 00:19:03,149 You're looking to prevent more of the first one where it's like, oh, we were 379 00:19:03,149 --> 00:19:07,019 able to get in through your HVAC system and boy, we're gonna turn this thing loose 380 00:19:07,019 --> 00:19:10,619 and see what open file shares you've got out there and what we can do with them. 381 00:19:10,919 --> 00:19:16,409 You, you need to create structure in the organization that does not allow 382 00:19:16,414 --> 00:19:20,189 people to move laterally that that prevents them from accessing things. 383 00:19:20,189 --> 00:19:25,499 Or worse yet, alerts you when things start doing a lot of scanning across 384 00:19:25,499 --> 00:19:29,549 your network, looking for those kinds of things because the, the rest of the group 385 00:19:29,909 --> 00:19:32,189 that's trying to get into your network doesn't know that stuff's there either. 386 00:19:32,189 --> 00:19:35,639 They're gonna have to go looking and just like the burglars that are casing the 387 00:19:35,639 --> 00:19:37,889 joint, you need to look for those people. 388 00:19:37,994 --> 00:19:39,914 Prasanna Malaiyandi: So multiple things popped up in my head, 389 00:19:39,919 --> 00:19:40,994 Tom, as you were talking. 390 00:19:41,294 --> 00:19:44,714 So the first is, as you're talking about the burglar example, I'm gonna bring this 391 00:19:44,714 --> 00:19:48,404 up again for the second week, but Curtis had recommended reading The Cuckoo's Egg. 392 00:19:48,404 --> 00:19:49,514 I don't know if you've read that book. 393 00:19:49,514 --> 00:19:49,904 Tom. 394 00:19:51,374 --> 00:19:52,554 Highly recommend you read it. 395 00:19:52,574 --> 00:19:57,729 It's basically, 1980s, a hacker gets into a mainframe and starts moving 396 00:19:57,729 --> 00:20:01,779 laterally across all these like military networks and science networks 397 00:20:01,779 --> 00:20:03,279 because everything was connected. 398 00:20:03,309 --> 00:20:07,539 And like you said, that example was go and try all the door locks and he 399 00:20:07,539 --> 00:20:11,499 would try default passwords and some of these systems, like the mainframes, 400 00:20:11,499 --> 00:20:13,009 people would not change the defaults. 401 00:20:13,239 --> 00:20:16,359 And so he got in and it was just that lateral movement across 402 00:20:16,359 --> 00:20:17,289 everything in the environment. 403 00:20:17,289 --> 00:20:20,799 So that's like the first thing that came to mind as you were talking. 404 00:20:21,519 --> 00:20:26,469 Um, the other thing that also came to mind is I totally get the reason to have 405 00:20:26,469 --> 00:20:32,169 like that zero trust and only enables services that, and patterns that are known 406 00:20:32,169 --> 00:20:34,689 to be valid and disable everything else. 407 00:20:35,319 --> 00:20:36,909 Uh, my question. 408 00:20:37,689 --> 00:20:41,529 As a network engineer or operations person, how do 409 00:20:41,529 --> 00:20:42,999 you manage that at the scale? 410 00:20:42,999 --> 00:20:47,229 Because there's so many applications, so many servers, it's hard to predict 411 00:20:47,229 --> 00:20:51,009 what's going to talk with what, um, and coming up with, because 412 00:20:51,009 --> 00:20:52,029 like, everything's all connected. 413 00:20:52,034 --> 00:20:54,459 Like in my mind I think about like Facebook and graphs, right? 414 00:20:54,459 --> 00:20:56,049 Everything is connected in the world, right? 415 00:20:56,319 --> 00:20:58,699 And so everything in your network to some extent is probably 416 00:20:58,704 --> 00:21:00,189 connected in some form or fashion. 417 00:21:00,219 --> 00:21:05,199 So how do you sort of go about even coming up with, okay, these things 418 00:21:05,204 --> 00:21:08,019 are the things that should be talking to the backup server in your example. 419 00:21:09,039 --> 00:21:11,834 Tom Hollingsworth: So it takes a lot of teamwork because as a network person, 420 00:21:12,224 --> 00:21:15,914 I don't care what's running over my network, I just need to make sure that 421 00:21:15,914 --> 00:21:17,804 these two things can talk to each other. 422 00:21:18,194 --> 00:21:22,544 And so in a way, like if you've ever deployed a server, um, you, you have a 423 00:21:22,544 --> 00:21:26,804 list, okay, it needs to communicate, uh, using this protocol over these ports or, 424 00:21:26,804 --> 00:21:31,064 you know, uh, think about, uh, opening something like, I need to open HTTPS to 425 00:21:31,064 --> 00:21:35,834 the server, but not http because I don't want it to ever communicate over http. 426 00:21:35,954 --> 00:21:39,254 And that's actually one of the things that we've noticed a lot recently is that a 427 00:21:39,254 --> 00:21:43,304 lot of protocols that used to have their own dedicated ports have now just started 428 00:21:43,304 --> 00:21:46,695 writing over, uh, HTTP and https s. 429 00:21:47,079 --> 00:21:48,549 Because it's just easier. 430 00:21:48,579 --> 00:21:51,729 Uh, bit Torrent was actually one of the first ones to start doing this because 431 00:21:51,729 --> 00:21:55,239 they're like, well, eighty's gonna be open anyway, which is the port for http. 432 00:21:55,359 --> 00:21:59,149 So we'll just ride on that because most people fire, most people's firewalling 433 00:21:59,154 --> 00:22:02,139 systems just allow that by default, because that's what the web uses. 434 00:22:02,379 --> 00:22:05,889 And so it gets kind of insidious and you almost have to think at a higher level. 435 00:22:05,894 --> 00:22:06,749 So what. 436 00:22:07,464 --> 00:22:10,314 it crack open any networking textbook in the world, and they're gonna 437 00:22:10,314 --> 00:22:12,624 give you this seven layer model. 438 00:22:12,624 --> 00:22:15,624 It's like a seven layer dip from Taco Bell, but there's no refried 439 00:22:15,624 --> 00:22:17,394 beans in the seven layer OSI model. 440 00:22:17,724 --> 00:22:21,624 But we play a lot in the bottom of that, where the physical connections 441 00:22:21,624 --> 00:22:24,834 happen, where the IP addresses allow systems to talk to each other. 442 00:22:25,194 --> 00:22:28,674 Once we get above a certain level, that's where the applications take over. 443 00:22:28,974 --> 00:22:32,904 And as networking people, we're not as concerned about that. 444 00:22:33,084 --> 00:22:36,504 But boy, the server people are because, oh, you know, I need to be able to have 445 00:22:36,504 --> 00:22:37,794 these two devices talking to each other. 446 00:22:37,794 --> 00:22:39,204 I need to make sure this is all un impeded. 447 00:22:39,204 --> 00:22:41,994 And the first thing that happens when two servers can't talk to each other is you 448 00:22:41,994 --> 00:22:43,584 gotta find the network people, people. 449 00:22:43,584 --> 00:22:45,684 And you're like, you need to tell me what's going on here. 450 00:22:45,684 --> 00:22:48,774 And then invariably, like the security team gets drawn in because like, oh no, 451 00:22:48,774 --> 00:22:51,624 we told him that he had to block that because nobody should ever be using that. 452 00:22:52,044 --> 00:22:55,074 And, and you, you really do have to pull those people together. 453 00:22:55,254 --> 00:22:59,064 I mean, think of, you know, think of a book like, uh, gene Kim's Phoenix project. 454 00:22:59,064 --> 00:23:02,694 Like you can't work in isolation anymore. 455 00:23:02,694 --> 00:23:04,014 As much as we might like to. 456 00:23:04,584 --> 00:23:08,304 Because so many things are so inter interdependent now. 457 00:23:08,514 --> 00:23:12,144 It's like, you know, the, the old joke is, is what does the server do? 458 00:23:12,144 --> 00:23:12,654 I don't know. 459 00:23:12,654 --> 00:23:15,174 Unplug the cable and we'll see who screams the loudest. 460 00:23:15,474 --> 00:23:18,504 You wanna figure out what people, uh, what port is being used. 461 00:23:18,654 --> 00:23:21,114 Let's block it and see who comes to yell at us. 462 00:23:21,504 --> 00:23:23,964 Like, that's kind of the way you have to do some of these things. 463 00:23:23,964 --> 00:23:24,264 Cuz 464 00:23:24,444 --> 00:23:27,294 the other thing, and we, we all know that nobody, nobody ever 465 00:23:27,299 --> 00:23:28,704 skips documentation, right? 466 00:23:29,419 --> 00:23:33,259 I realized while editing this episode, that we forgot to 467 00:23:33,529 --> 00:23:34,879 throw out our disclaimer. 468 00:23:35,179 --> 00:23:37,279 Uh, Prasanna and I work for different companies. 469 00:23:37,279 --> 00:23:38,059 He works for zoom. 470 00:23:38,059 --> 00:23:38,899 I work for Druva. 471 00:23:39,199 --> 00:23:41,749 This is not a podcast of either company. 472 00:23:41,749 --> 00:23:43,759 It is an independent podcast. 473 00:23:44,029 --> 00:23:46,639 So the opinions that you hear are ours. 474 00:23:46,999 --> 00:23:50,059 Also, if you'd like to join the podcast, please reach out to me 475 00:23:50,329 --> 00:23:55,609 at w Curtis Preston on, uh, at Gmail or at WC Preston on Twitter. 476 00:23:55,969 --> 00:23:59,809 Or linkedin.com/i N slash Mr. 477 00:23:59,809 --> 00:24:00,319 Backup. 478 00:24:00,589 --> 00:24:04,969 And you'll find me, uh, we'd love to have you join and also be sure to 479 00:24:04,969 --> 00:24:06,529 rate us at your favorite podcatcher. 480 00:24:06,739 --> 00:24:07,219 Thanks a lot. 481 00:24:07,819 --> 00:24:09,649 Now onto my silly story. 482 00:24:10,407 --> 00:24:11,757 W. Curtis Preston: You brought up an old memory of mine. 483 00:24:11,787 --> 00:24:18,417 Literally like my first months in being a cis admin, we were trying to decommission, 484 00:24:18,717 --> 00:24:23,457 um, uh, the, you know, the, the, the first computer designed to run Unix was the 485 00:24:23,457 --> 00:24:29,297 three BK and the at and t had a three BK I think it was like a three B 1000. 486 00:24:29,302 --> 00:24:31,947 And it was their attempt at a multiprocessor architecture. 487 00:24:32,337 --> 00:24:34,827 And we had this beast and we were trying to decommission it. 488 00:24:35,397 --> 00:24:39,837 And, uh, we had gotten down to, we had fi you know, and, and we had gotten down 489 00:24:39,837 --> 00:24:43,077 to that phase where it's like, well, we're just gonna turn it off and whoever 490 00:24:43,077 --> 00:24:45,297 yells will be the one that we missed. 491 00:24:45,297 --> 00:24:45,567 Right. 492 00:24:45,957 --> 00:24:50,577 But I remember the, um, We had, uh, stripped it, all of, all of 493 00:24:50,577 --> 00:24:51,927 its regular networking cable. 494 00:24:51,927 --> 00:24:55,587 I don't exactly remember exactly why, but I remember that there was one cable 495 00:24:55,587 --> 00:25:00,177 left and it was running across the floor and we were doing the last like 496 00:25:00,267 --> 00:25:05,817 download of, of whatever it was off of this server onto something else. 497 00:25:06,177 --> 00:25:09,927 And the manager for that cost center was in there and he 498 00:25:09,927 --> 00:25:11,667 kept stepping on the cable. 499 00:25:12,237 --> 00:25:15,897 And, um, we told him that he was slowing down the download whenever 500 00:25:15,897 --> 00:25:17,157 he would step on the cable. 501 00:25:17,667 --> 00:25:21,567 And, um, we actually caught him, we left him into data center. 502 00:25:21,567 --> 00:25:26,457 We actually caught him like watching the monitor and like the throughput speed 503 00:25:26,457 --> 00:25:30,087 and sort of stepping on and stepping up and off and off on the cable. 504 00:25:31,827 --> 00:25:32,427 Anyway. 505 00:25:32,847 --> 00:25:33,267 Yeah. 506 00:25:33,297 --> 00:25:34,467 Good, good stories. 507 00:25:34,557 --> 00:25:38,877 I, so the question I want to ask you about, all of the things you just talked 508 00:25:38,877 --> 00:25:46,797 about, is this something built into modern networking equipment or is this, um, 509 00:25:46,827 --> 00:25:51,747 you know, are these extra applications that I'm buying that then configure 510 00:25:51,747 --> 00:25:53,307 that networking equipment for me? 511 00:25:54,172 --> 00:25:55,282 Tom Hollingsworth: So it can be both. 512 00:25:55,372 --> 00:26:01,852 The, the basics of being able to isolate hosts and configure systems 513 00:26:02,182 --> 00:26:03,382 has been built in for years. 514 00:26:03,382 --> 00:26:05,992 I mean, anyone can write an a c L, right? 515 00:26:06,382 --> 00:26:10,672 The thing is, is that scaling that across a large organization 516 00:26:10,672 --> 00:26:12,202 is where it typically falls down. 517 00:26:12,202 --> 00:26:15,292 Eventually, your security team can't keep up with all the changes. 518 00:26:15,292 --> 00:26:18,352 They throw their hands up in the air and it lies fallow for as long as 519 00:26:18,352 --> 00:26:19,732 it takes for you to get infected. 520 00:26:20,062 --> 00:26:24,382 So the additional tools that are basically being brought to market and are, are 521 00:26:24,382 --> 00:26:27,622 popular now, kind of organize that system. 522 00:26:27,622 --> 00:26:30,082 They put a, a, a shiny. 523 00:26:31,017 --> 00:26:35,097 UI on it, if you will, to, to go in and say, okay, I, I want to enable port 524 00:26:35,097 --> 00:26:39,207 security on these ports because back when I started this port security was, 525 00:26:39,212 --> 00:26:40,617 if it isn't being used, shut it off. 526 00:26:40,917 --> 00:26:42,477 Just like shut down the port. 527 00:26:42,477 --> 00:26:45,777 And then if somebody plugs into it and it doesn't work, well then now we know 528 00:26:45,777 --> 00:26:48,267 we need to enable that port and we need to know who's trying to use it. 529 00:26:48,627 --> 00:26:52,647 But now you have the ability to like have somebody plug in a device, 530 00:26:52,647 --> 00:26:55,227 whether it's an IOT system or what have 531 00:26:55,227 --> 00:26:58,947 you, and this, the device will like register with the system. 532 00:26:58,947 --> 00:27:00,267 It'll say, Hey, I need access. 533 00:27:00,537 --> 00:27:02,817 And then the system can come back and say, Hey, it looks like somebody 534 00:27:02,817 --> 00:27:04,617 plugged in an S thermostat over here. 535 00:27:04,857 --> 00:27:08,277 Well, that's actually a bad example cause they don't use wires, but you know, a 536 00:27:08,277 --> 00:27:11,877 laptop or some other kind of device, you need to go, like check it out. 537 00:27:11,877 --> 00:27:15,807 Or you can even set a policy that says, I'm going to allow you for 538 00:27:15,812 --> 00:27:20,157 now, but I have the ability to just cut it off if I need to. 539 00:27:20,697 --> 00:27:24,207 Or if it's one of these recognized device classes or something like that. 540 00:27:24,447 --> 00:27:30,102 So for smaller systems, , you know, for, for smaller organizations, if 541 00:27:30,102 --> 00:27:33,672 your IT department isn't already completely overworked, you can't 542 00:27:33,672 --> 00:27:36,222 implement some of this by hand. 543 00:27:36,222 --> 00:27:40,722 It's just a matter of if it works really well, that means you're gonna 544 00:27:40,727 --> 00:27:45,192 be spending a lot of time tuning that system to keep working effectively. 545 00:27:45,432 --> 00:27:48,822 And once you get past a certain point, the, uh, the solutions 546 00:27:48,822 --> 00:27:53,022 that do this are reassuringly expensive because they're worth it. 547 00:27:53,927 --> 00:27:54,487 W. Curtis Preston: Right. 548 00:27:54,487 --> 00:27:58,287 Oh, I understood cuz that, that they would help you save the, the, the labor. 549 00:27:58,377 --> 00:28:01,767 And is there a category of these types of tools that, that a 550 00:28:01,767 --> 00:28:03,357 category name that we give to them? 551 00:28:04,122 --> 00:28:06,252 Tom Hollingsworth: Uh, there's, there's a bunch of different ones. 552 00:28:06,282 --> 00:28:10,362 Uh, access management is typically one that you, you see, um, honestly, 553 00:28:10,362 --> 00:28:15,762 tools like Aruba ClearPass or uh, Cisco ice, uh, ise, uh, integrated 554 00:28:15,762 --> 00:28:19,032 services engine, or integrated security engine, I forget which one it is. 555 00:28:19,362 --> 00:28:22,602 But they're, they're, they're not identity and access management, 556 00:28:22,952 --> 00:28:24,042 although they can be integrated that. 557 00:28:25,152 --> 00:28:27,972 There are some smaller ones that, that have these capabilities. 558 00:28:28,182 --> 00:28:31,602 A lot of it is, is mostly figuring out what you need because there's 559 00:28:31,602 --> 00:28:34,692 different, you know, some systems are, are configured so that you're 560 00:28:34,692 --> 00:28:36,522 controlling access to devices. 561 00:28:36,702 --> 00:28:39,222 I only wanna authorize people to be able to log into this 562 00:28:39,222 --> 00:28:40,512 device and make changes to it. 563 00:28:40,782 --> 00:28:45,342 Well, that's different than I want to change the way that people 564 00:28:45,342 --> 00:28:50,832 in my network are accessing data like that is a different kind of 565 00:28:50,892 --> 00:28:52,542 identity and access management. 566 00:28:52,692 --> 00:28:55,752 So you need to do a little bit of investigative work to make sure that you 567 00:28:55,757 --> 00:28:58,512 are, uh, properly using the right tool. 568 00:28:58,512 --> 00:29:01,602 Cause if you spend a lot of money on one that doesn't give you what you want or 569 00:29:01,602 --> 00:29:05,982 does a, a, a terrible job of it, then not only are you gonna be upset, but the 570 00:29:05,982 --> 00:29:09,312 people that are or authorizing your budget are not gonna be very happy with you. 571 00:29:10,137 --> 00:29:12,747 Prasanna Malaiyandi: Now a lot of these changes, if I think about an 572 00:29:12,747 --> 00:29:17,997 enterprise environment, things are easier to a fair extent to control, right? 573 00:29:18,002 --> 00:29:20,817 If you're looking at servers or virtualization, other things like that. 574 00:29:21,477 --> 00:29:26,907 But then I go to think about other environments like a school, right, where 575 00:29:26,907 --> 00:29:29,067 you have students coming and going, right? 576 00:29:29,067 --> 00:29:32,637 Or a stadium or a conference center, right? 577 00:29:33,267 --> 00:29:38,877 Does it get significantly more difficult to do what you talked 578 00:29:38,877 --> 00:29:40,197 about, Tom, in those environments? 579 00:29:40,197 --> 00:29:42,567 Or can the same tools apply there as well? 580 00:29:43,327 --> 00:29:44,257 Tom Hollingsworth: Yes and no. 581 00:29:44,347 --> 00:29:47,287 Um, I, I, I'm, I'm the typical IT nerd. 582 00:29:47,287 --> 00:29:50,407 The answer is, it depends for whatever question you ask, but I'll tell you 583 00:29:50,407 --> 00:29:54,967 that in some ways, um, schools and other places where your user base 584 00:29:54,967 --> 00:29:56,827 is not employed directly by you. 585 00:29:57,352 --> 00:30:03,202 Can have a slightly easier time if you're willing to, um, sacrifice a little bit. 586 00:30:03,382 --> 00:30:07,102 So I know that there are a lot of colleges out there that treat their student 587 00:30:07,132 --> 00:30:09,862 dorm networks like the wild, wild west. 588 00:30:10,342 --> 00:30:14,092 We don't care what goes on out there, but we're not gonna keep an eye on it either. 589 00:30:14,362 --> 00:30:15,142 So like, if 590 00:30:15,142 --> 00:30:17,962 there's a, you know, a piece of ransomware or something that's running rampant 591 00:30:17,962 --> 00:30:21,202 through the system, all we did is tell you that you had to have your antivirus 592 00:30:21,202 --> 00:30:22,822 up to date to be able to join our network. 593 00:30:22,822 --> 00:30:23,212 So, 594 00:30:24,142 --> 00:30:29,062 so what, uh, the stadiums are actually a, a really interesting, uh, problem 595 00:30:29,062 --> 00:30:32,422 too, because not only do you have a a, a group of users that are outside of 596 00:30:32,422 --> 00:30:35,752 your control, they're very transient, um, in a lot of those places. 597 00:30:35,752 --> 00:30:40,432 Like they, they actually have, uh, wireless networks that are set up 598 00:30:40,432 --> 00:30:42,592 so that, um, they can only talk. 599 00:30:43,512 --> 00:30:46,327 , like they block all device to device communication, which 600 00:30:46,327 --> 00:30:47,317 is something that you can do. 601 00:30:47,317 --> 00:30:51,967 It's a little bit more complicated, but it effectively treats, um, the stadium 602 00:30:51,967 --> 00:30:56,167 itself like a demilitarized zone in a, uh, in a, in a security structure. 603 00:30:56,347 --> 00:30:58,867 So for most people that are, that are familiar with it, you know, you've got the 604 00:30:58,872 --> 00:31:00,607 outside internet, which is big and scary. 605 00:31:00,757 --> 00:31:03,577 You've got your inside network, which is soft and, and you know, 606 00:31:03,907 --> 00:31:05,707 uh, you don't want it to get hurt. 607 00:31:05,707 --> 00:31:09,397 And then in the middle you have the dmz, which is basically the moat where 608 00:31:09,402 --> 00:31:12,097 you're like, I'm gonna put everything that I don't care if it gets attacked 609 00:31:12,097 --> 00:31:16,387 out there so that if it breaks, it can't get back into my network. 610 00:31:16,537 --> 00:31:19,507 And so, but the otherwise, the other thing there is I only allow 611 00:31:19,507 --> 00:31:21,277 certain traffic to come back through. 612 00:31:21,427 --> 00:31:25,267 So if something bad were to happen, I can just basically cut it off and 613 00:31:25,267 --> 00:31:26,587 sink it into the moat and I'm done. 614 00:31:27,877 --> 00:31:30,517 W. Curtis Preston: Yeah, I think, uh, hotels have a similar model, right? 615 00:31:30,517 --> 00:31:35,287 Where the base, uh, I know having, having plugged in multiple devices that 616 00:31:35,287 --> 00:31:38,977 needed to talk to each other in hotel networks, they don't like that very much. 617 00:31:39,277 --> 00:31:42,877 Uh, and you end up having to bring basically your own router if, if 618 00:31:42,877 --> 00:31:44,047 that's something that you want to do. 619 00:31:44,197 --> 00:31:44,527 Right? 620 00:31:45,007 --> 00:31:50,947 Um, so the, so it sounded like, um, if I understood you correctly, 621 00:31:51,127 --> 00:31:55,777 the access management part is this sort of basic security thing, that 622 00:31:55,777 --> 00:31:58,927 there are tools that do just that, and then there's also this identity 623 00:31:58,927 --> 00:32:02,527 access, which is a, a bigger pain. 624 00:32:02,557 --> 00:32:03,727 I would, I would imagine. 625 00:32:03,727 --> 00:32:07,507 But those that want that, and it sounds like when we put those 626 00:32:07,507 --> 00:32:10,027 two together, that's what, what we call a SEIM tool, right? 627 00:32:10,027 --> 00:32:12,787 Is uh, uh, identity and access management. 628 00:32:13,027 --> 00:32:16,117 But it sounds like there's just an access management. 629 00:32:16,912 --> 00:32:21,622 That, for those that need just that there, there's smaller and less 630 00:32:21,622 --> 00:32:24,052 expensive than a full SEIM tool. 631 00:32:24,862 --> 00:32:25,192 Yeah. 632 00:32:25,522 --> 00:32:28,342 Not, not inexpensive, but just less expensive. 633 00:32:28,867 --> 00:32:31,387 Tom Hollingsworth: Well, and it, it also matters as to what you're spending 634 00:32:31,392 --> 00:32:33,847 your resources on, because there are tools that will do this for free. 635 00:32:34,612 --> 00:32:38,902 But they are not supported at all by anybody other than people on a forum. 636 00:32:39,202 --> 00:32:42,712 And they'll be glad to tell you that you misconfigured something 637 00:32:42,717 --> 00:32:43,912 and go figure it out yourself. 638 00:32:44,212 --> 00:32:45,382 Like we, we've dealt with that. 639 00:32:45,387 --> 00:32:48,802 And I'm not really crapping on the open source community because 640 00:32:48,802 --> 00:32:50,752 they do an amazing job of this. 641 00:32:50,842 --> 00:32:55,162 I'm crapping on the fact that open source communities are not as well supported 642 00:32:55,162 --> 00:32:57,322 as the bigger players in these markets. 643 00:32:57,472 --> 00:33:01,042 And that's honestly where the expensive part comes from. 644 00:33:01,252 --> 00:33:03,352 You're not paying for the software, although you, you 645 00:33:03,352 --> 00:33:04,102 kind of are in some ways. 646 00:33:04,282 --> 00:33:08,422 You're paying for somebody to answer the phone when somebody is like breathing 647 00:33:08,427 --> 00:33:12,262 down your neck because something won't work or something won't come online. 648 00:33:12,712 --> 00:33:16,432 And so a and a and you're also trying to get to that point where 649 00:33:16,432 --> 00:33:21,402 it's, it's not automated as much as it is as low friction as possible. 650 00:33:21,532 --> 00:33:24,142 Because what you want in situations is people to just 651 00:33:24,142 --> 00:33:26,002 be able to get on the network. 652 00:33:26,487 --> 00:33:27,577 That's, that's the thing. 653 00:33:27,577 --> 00:33:30,847 If you've ever tried to log into a wifi network that has a captive portal 654 00:33:31,057 --> 00:33:33,757 that requires you to like accept a whole bunch of licensing agreements 655 00:33:33,757 --> 00:33:36,727 and type your room number in and all the other stuff, you know that it's not 656 00:33:36,727 --> 00:33:40,357 the most frustrating thing, but it's definitely not what you want to hear. 657 00:33:41,407 --> 00:33:44,437 As opposed to like, oh, this device has already been pre-authorized cuz you logged 658 00:33:44,437 --> 00:33:45,787 in with your active directory username. 659 00:33:45,792 --> 00:33:46,867 Well, we'll just let it on the network. 660 00:33:47,287 --> 00:33:48,817 That's completely frictionless. 661 00:33:48,822 --> 00:33:52,717 But the amount of effort that it takes to make it frictionless is where your time 662 00:33:52,717 --> 00:33:54,517 and resource invests gonna come from. 663 00:33:54,822 --> 00:33:57,702 Prasanna Malaiyandi: Tom, I know we started this all out with Curtis asking, 664 00:33:58,032 --> 00:34:02,142 how do you prevent lateral movement in networks right from ransomware? 665 00:34:02,982 --> 00:34:07,302 Just given the fact that ransomware does move laterally in a lot of networks? 666 00:34:07,362 --> 00:34:10,722 Does this mean people are not using these tools or have not 667 00:34:10,722 --> 00:34:12,222 configured the networks correctly? 668 00:34:12,222 --> 00:34:15,912 Because it seems like if you did all the things that we just talked about, it 669 00:34:15,912 --> 00:34:19,812 should have prevented a lot of the lateral movement that we see in ransomware today. 670 00:34:20,487 --> 00:34:21,897 Tom Hollingsworth: Well, Prasanna, I'm gonna tell you something 671 00:34:21,897 --> 00:34:24,117 that my dad always tell me, and you have to understand. 672 00:34:24,117 --> 00:34:25,197 My dad grew up in the country. 673 00:34:25,197 --> 00:34:28,467 If a frog had wings, he wouldn't bump his ass every time he hopped. 674 00:34:29,007 --> 00:34:34,737 So yes, if you turn on all of these tools, you will cut down on a lot of this stuff. 675 00:34:34,742 --> 00:34:37,707 But does that mean your network's not working correctly? 676 00:34:37,977 --> 00:34:38,307 No. 677 00:34:38,307 --> 00:34:40,887 It just means that we didn't enable all these extra features that we have 678 00:34:40,887 --> 00:34:45,867 to keep track of because I can get four, uh, four network ports on a. 679 00:34:46,872 --> 00:34:49,497 and plug four devices in there and they're gonna work is the 680 00:34:49,497 --> 00:34:50,547 best way for them to work. 681 00:34:50,547 --> 00:34:54,087 Absolutely not, but I also don't have to do a whole lot of extra configuration. 682 00:34:54,417 --> 00:34:58,317 A lot of people are looking at this from the perspective of, I need to 683 00:34:58,322 --> 00:35:01,647 make sure that everything is, is able to communicate with everything else. 684 00:35:01,827 --> 00:35:05,187 They're not looking at it like you, like the example you had earlier, Curtis, when 685 00:35:05,192 --> 00:35:08,217 you log into the hotel wifi and I can't talk to anything else on the hotel wifi. 686 00:35:08,547 --> 00:35:11,397 They're not thinking in a, in an isolation mode. 687 00:35:11,757 --> 00:35:15,327 And we're, we're that ship's turning because a lot of people are now 688 00:35:15,327 --> 00:35:20,277 realizing that, that that traditional idea of having a very stiff, crunchy 689 00:35:20,282 --> 00:35:24,187 perimeter with a very soft internal network doesn't work so well. 690 00:35:24,807 --> 00:35:27,867 Because what ends up happening is, is that once people get through 691 00:35:27,867 --> 00:35:30,807 the perimeter, they have free reign to do whatever they want. 692 00:35:30,807 --> 00:35:35,487 You, you do have to build these controls in place to effectively 693 00:35:35,487 --> 00:35:39,867 slow them down or to herd them to places that you want them to go. 694 00:35:39,957 --> 00:35:44,037 And that's what a lot of people have spent time developing and working on. 695 00:35:44,337 --> 00:35:47,937 And there's varying degrees of success to make that work. 696 00:35:48,747 --> 00:35:51,087 It has to shift the mindset though. 697 00:35:51,447 --> 00:35:55,827 Um, you know, application people are just turn on all the ports 698 00:35:55,827 --> 00:35:56,817 and I'll turn them off later. 699 00:35:56,822 --> 00:36:00,057 When I tell you which ones I don't need, you won't, because you'll 700 00:36:00,062 --> 00:36:01,347 get busy doing something else. 701 00:36:01,467 --> 00:36:04,257 It's like developers, they're like, I'm gonna load everything I can possibly 702 00:36:04,257 --> 00:36:07,887 think of in the memory so that I know the library that I need is there. 703 00:36:08,187 --> 00:36:11,907 And then you wonder why your, your, uh, application is consuming 704 00:36:11,907 --> 00:36:13,797 like three terabytes of ram. 705 00:36:13,797 --> 00:36:16,827 It's like, uh, maybe you need to pa pair back a little bit on that. 706 00:36:17,742 --> 00:36:17,922 W. Curtis Preston: Yeah. 707 00:36:17,922 --> 00:36:20,502 So it, it sounds like these tools are there. 708 00:36:20,742 --> 00:36:25,482 Uh, I think a lot of people do use them, but you talked about, like in the very 709 00:36:25,482 --> 00:36:28,782 beginning, you, you said that people's heads are gonna start spinning or 710 00:36:28,782 --> 00:36:33,792 whatever, because there is a lot of work involved in implementing these things. 711 00:36:33,792 --> 00:36:38,442 And the moment you flip that switch from, you know, per, you know, from 712 00:36:38,682 --> 00:36:43,392 everything is permitted to only the things that are permitted or permitted, uh, 713 00:36:43,462 --> 00:36:46,182 you're gonna get 5,000 tickets, right? 714 00:36:46,182 --> 00:36:47,832 I can't do this and I can't do that. 715 00:36:47,832 --> 00:36:49,542 And they, they see that. 716 00:36:49,947 --> 00:36:52,527 They see that very real worry. 717 00:36:52,827 --> 00:36:56,007 Uh, and I, and I think it stops many people from implementing this 718 00:36:56,007 --> 00:36:59,097 because they just see it as the amount of work they're gonna have 719 00:36:59,097 --> 00:37:01,347 to do to initially implement it. 720 00:37:01,767 --> 00:37:06,927 Um, they're, and they're not seeing the risk of what's gonna happen when 721 00:37:07,017 --> 00:37:10,197 they get a ransomware infection, and then it just goes crazy. 722 00:37:12,187 --> 00:37:14,857 Tom Hollingsworth: Most tools that are, are set up like this. 723 00:37:14,887 --> 00:37:18,667 Uh, they have a learning mode where they will, you could put 'em in place and 724 00:37:18,667 --> 00:37:20,467 they just sit there and they watch for at 725 00:37:20,472 --> 00:37:22,447 least the first, you know, week or two. 726 00:37:22,687 --> 00:37:25,867 And they're mapping out all of these application dependencies. 727 00:37:26,077 --> 00:37:30,517 So, you know, the backup system needs to receive traffic on this port for 728 00:37:30,517 --> 00:37:32,347 this application from this subnet. 729 00:37:32,617 --> 00:37:37,297 And then it allows you to carefully craft that rule so that only devices 730 00:37:37,297 --> 00:37:40,957 from this subnet can talk to that server on these ports and nothing else. 731 00:37:41,257 --> 00:37:44,827 And if you let the tool go long enough, you'll be able to like, suss 732 00:37:44,827 --> 00:37:46,567 out exactly what you need to know. 733 00:37:46,837 --> 00:37:52,447 But yeah, that first day you click the switch to from, you know, allow list to 734 00:37:52,447 --> 00:37:56,767 deny a list is just like you're, you're staring at the ticket queue because 735 00:37:56,772 --> 00:38:00,337 you're like, oh, what happens if I, if this machine hadn't been turned on for a 736 00:38:00,337 --> 00:38:01,837 week or what, you know? 737 00:38:02,222 --> 00:38:02,712 W. Curtis Preston: yeah. 738 00:38:03,532 --> 00:38:03,742 Tom Hollingsworth: Yeah. 739 00:38:03,742 --> 00:38:08,122 It just, it, it, it is, it's maddening because you're always gonna wonder if you 740 00:38:08,122 --> 00:38:13,492 didn't get the right stuff, but like you said, would you rather be worried about 741 00:38:13,497 --> 00:38:15,442 one machine that can't talk to another? 742 00:38:15,592 --> 00:38:19,192 Or would you be worrying about the fact that you're getting a phone call from 743 00:38:19,402 --> 00:38:24,292 the CIO saying, uh, yeah, the database has just got encrypted by this new flavor 744 00:38:24,292 --> 00:38:26,062 of malware that we haven't seen yet. 745 00:38:26,362 --> 00:38:27,442 Uh, why did that? 746 00:38:28,747 --> 00:38:29,227 W. Curtis Preston: Yeah. 747 00:38:29,917 --> 00:38:32,767 Another thing I want to ask you, I wanna sort of move forward into 748 00:38:32,767 --> 00:38:34,747 the, the ransomware part here. 749 00:38:35,017 --> 00:38:39,097 Although Prasanna, I'm so glad you basically told us to go backwards. 750 00:38:39,097 --> 00:38:42,097 You always, you're really good at that, you know, you're really good at 751 00:38:42,097 --> 00:38:43,117 making me go backwards. 752 00:38:43,507 --> 00:38:47,617 Uh, anyway, uh, I wanted, so one of the things, so we talked about 753 00:38:47,617 --> 00:38:49,117 trying to limit lateral movement. 754 00:38:49,147 --> 00:38:57,787 Another thing that was suggested was to not permit, uh, new, new either 755 00:38:57,847 --> 00:39:04,747 new domains, like domains that just recently were created, or domains 756 00:39:04,747 --> 00:39:07,507 that w got recently active, right. 757 00:39:07,717 --> 00:39:13,357 From a DNS perspective, is that, is that still fall under the networking purview? 758 00:39:13,447 --> 00:39:16,027 Um, or is that like, is that another world? 759 00:39:16,612 --> 00:39:19,552 Tom Hollingsworth: It, it tend, anything that involves names and not 760 00:39:19,552 --> 00:39:22,882 numbers tends to float up towards the application team or the security 761 00:39:22,882 --> 00:39:23,302 team. 762 00:39:23,602 --> 00:39:27,712 Uh, and the reason for that is because, like you said, like one of the things 763 00:39:27,782 --> 00:39:31,492 that, that we see a lot in security now is it's this idea that you wanna black hole 764 00:39:31,497 --> 00:39:33,682 things that are, that are relatively new. 765 00:39:33,687 --> 00:39:36,832 Like why is this machine suddenly starting to communicate over a d n 766 00:39:36,832 --> 00:39:38,392 s name that I've never seen before? 767 00:39:38,632 --> 00:39:39,172 But it also 768 00:39:39,172 --> 00:39:42,892 requires that your devices have the intelligence to be able to resolve that 769 00:39:43,132 --> 00:39:48,112 because, you know, application layer firewalls will see, oh, you are trying to 770 00:39:48,112 --> 00:39:52,372 access this service that I don't recognize on a domain that I've never seen before. 771 00:39:52,582 --> 00:39:56,782 Whereas a, a lower level, almost like a packet filtering firewall will say, 772 00:39:56,842 --> 00:40:00,592 oh, well that's an IP address connection on this port from here to there. 773 00:40:00,652 --> 00:40:03,382 Uh, I don't see a reason why I shouldn't be using that. 774 00:40:03,712 --> 00:40:07,282 And so, You, You, kind of have to integrate those two things together 775 00:40:07,522 --> 00:40:10,222 because like you said, you know, something doesn't look right here 776 00:40:10,222 --> 00:40:14,902 because why would it be contacting a brand new DNS name that it should, it 777 00:40:14,902 --> 00:40:17,002 has no reason to contact or worse yet? 778 00:40:17,242 --> 00:40:17,632 Uh uh. 779 00:40:17,632 --> 00:40:19,042 You can ask the people over at SolarWinds. 780 00:40:19,042 --> 00:40:22,282 Why is this DLL suddenly talking to .ru addresses? 781 00:40:22,972 --> 00:40:23,422 W. Curtis Preston: right? 782 00:40:23,422 --> 00:40:23,692 Yeah. 783 00:40:23,692 --> 00:40:28,522 Well, when he says new domain names, he actually means domain names that were 784 00:40:28,522 --> 00:40:33,202 like recently registered, not just domain names that are new to your network. 785 00:40:33,502 --> 00:40:37,432 And then also ones that, that were, they were registered but they had, they hadn't 786 00:40:37,552 --> 00:40:39,382 been active or something like that. 787 00:40:39,532 --> 00:40:44,362 So that sounds like that's a d n s uh, you know, there's a d I world, right? 788 00:40:44,422 --> 00:40:46,582 Um, we had, we had somebody on from that. 789 00:40:46,582 --> 00:40:51,142 I think we need to have some, because this is, I think that's, , if you can 790 00:40:51,142 --> 00:40:55,582 reasonably do that, where you could basically push a button, just sort of like 791 00:40:55,582 --> 00:40:57,952 the, the, the deny the allowed deny thing. 792 00:40:58,222 --> 00:41:03,232 If you can reasonably say, I, I don't want, I don't want anybody 793 00:41:03,232 --> 00:41:06,562 talking to domain names that were registered 24 hours ago. 794 00:41:06,682 --> 00:41:07,042 Right. 795 00:41:07,162 --> 00:41:10,882 I, I If you could, if you could do something like that, it will of course 796 00:41:10,882 --> 00:41:13,402 also create some trouble, uh, tickets. 797 00:41:13,732 --> 00:41:15,052 But I'm thinking far less. 798 00:41:15,052 --> 00:41:19,402 And if you could do that, it stops to command and control, uh, you 799 00:41:19,402 --> 00:41:22,222 know, the, the ransomware from reaching out at command and control, 800 00:41:22,852 --> 00:41:23,572 um, 801 00:41:23,857 --> 00:41:24,247 Tom Hollingsworth: slows the 802 00:41:24,247 --> 00:41:24,907 process down. 803 00:41:24,907 --> 00:41:27,757 But the one thing I will say there though, is that you need to make sure 804 00:41:27,757 --> 00:41:29,617 that your users are expecting that change. 805 00:41:29,622 --> 00:41:34,237 Because if it requires you to go out and check a list or, uh, get some kind of 806 00:41:34,487 --> 00:41:38,077 una authorization to go to this domain name, even if it adds one second to the 807 00:41:38,077 --> 00:41:42,547 resolution time, that's one extra second that people are going to complain about 808 00:41:42,547 --> 00:41:43,807 and you know who they're gonna complain. 809 00:41:44,582 --> 00:41:46,912 the networking team, because the network isn't working. 810 00:41:47,152 --> 00:41:52,372 Not the d n s block list checker or the application that has this built into it. 811 00:41:52,402 --> 00:41:52,942 Oh, no, no. 812 00:41:52,942 --> 00:41:54,772 It's the network's fault because the packets aren't 813 00:41:54,772 --> 00:41:55,732 going where they're supposed to. 814 00:41:56,407 --> 00:41:59,497 W. Curtis Preston: As we used to say back, back when I was, you know, 815 00:41:59,497 --> 00:42:02,767 when I first said that we, we would say the problem's under the floor. 816 00:42:03,187 --> 00:42:03,577 Right? 817 00:42:03,637 --> 00:42:05,797 Uh, meaning, meaning it was a networking problem. 818 00:42:06,427 --> 00:42:08,637 Um, go ahead, Prasanna. 819 00:42:09,262 --> 00:42:10,312 Prasanna Malaiyandi: So moving on. 820 00:42:10,312 --> 00:42:14,212 So we talked about how to prevent lateral movement, how to detect these, uh, 821 00:42:14,452 --> 00:42:17,422 rogue, uh, servers that are coming up. 822 00:42:18,592 --> 00:42:23,032 One thing I wanted to ask is, so say you do get hit by ransomware, right? 823 00:42:23,062 --> 00:42:24,412 They're able to move laterally. 824 00:42:24,862 --> 00:42:27,472 What happens next from a networking perspective? 825 00:42:27,712 --> 00:42:28,872 Well, I guess two questions. 826 00:42:29,092 --> 00:42:32,722 One is how do you, how would you go about bringing down your network or sort 827 00:42:32,722 --> 00:42:34,732 of isolating what needs to be isolated? 828 00:42:34,732 --> 00:42:37,042 Like how do you actually figure out what's going on in your network? 829 00:42:37,312 --> 00:42:39,502 And then the second question is, okay, now that you've sort of 830 00:42:39,952 --> 00:42:44,092 identified that, how do you slowly recover from those situations? 831 00:42:45,067 --> 00:42:46,867 Tom Hollingsworth: Incident response is never fun because 832 00:42:46,867 --> 00:42:48,067 it's a whole lot of cleanup. 833 00:42:48,157 --> 00:42:51,487 And, uh, and, and the first thing you have to do is you have to, 834 00:42:51,697 --> 00:42:55,087 you have to get people out of your network because there's, you know, 835 00:42:55,087 --> 00:42:57,667 there's obviously, there's the tools that kind of run on their own. 836 00:42:57,967 --> 00:43:00,757 And there are tools that kind of have to be piloted by people. 837 00:43:00,967 --> 00:43:06,997 So you have to create, uh, limits on the, on the system to be able to stop that. 838 00:43:06,997 --> 00:43:11,317 And fingers crossed that you're not in a situation where your entire 839 00:43:11,317 --> 00:43:14,257 network has been taken down by whatever is causing the problem. 840 00:43:14,257 --> 00:43:17,887 Because I've seen that before too, where not only does it try to laterally move to 841 00:43:17,887 --> 00:43:22,477 infect systems, it also throws up enough extra garbage that you are, it's Inca, 842 00:43:22,477 --> 00:43:23,947 you're capable of logging into any of your 843 00:43:23,947 --> 00:43:24,637 management networks. 844 00:43:24,637 --> 00:43:25,507 So we're lesson number one. 845 00:43:25,507 --> 00:43:28,177 Make sure all your management networks are kind of isolated so that you 846 00:43:28,177 --> 00:43:29,857 always have the ability to use those. 847 00:43:30,187 --> 00:43:31,387 But the first thing that I would. 848 00:43:32,347 --> 00:43:34,957 As I would cut off outside access immediately, I would 849 00:43:35,107 --> 00:43:36,787 lock the firewall in place. 850 00:43:36,787 --> 00:43:39,217 I mean, you don't have to like run through the data center screaming with 851 00:43:39,217 --> 00:43:42,517 your hair on fire and start yanking cables out like the alias episode. 852 00:43:42,727 --> 00:43:45,637 But you need to be able to lock all of those connections down. 853 00:43:45,877 --> 00:43:50,437 And specifically you need to look for ones that, you know, could be like, you know, 854 00:43:50,557 --> 00:43:54,427 from really weird external addresses, or worse yet ones that are coming in. 855 00:43:54,787 --> 00:43:58,387 Once you've blocked that external access in and out, you gotta do it 856 00:43:58,387 --> 00:44:01,687 in both directions because obviously you don't want anything getting out 857 00:44:01,687 --> 00:44:04,237 because the two things that I can think of are command and control traffic. 858 00:44:04,237 --> 00:44:09,697 If some kind of tool that's being, uh, um, orchestrated or data exfiltration 859 00:44:10,297 --> 00:44:13,057 and, and you're like, oh, well I can stop those file transfers. 860 00:44:13,062 --> 00:44:14,227 Yeah, look up oil rig. 861 00:44:14,257 --> 00:44:17,467 It was, uh, it was able to exfiltrate data through DNS queries. 862 00:44:18,037 --> 00:44:20,287 Like that's the kind of crap you have to worry about. 863 00:44:20,287 --> 00:44:21,787 So you've gotta lock it down. 864 00:44:22,057 --> 00:44:24,007 Then you have to isolate because that's 865 00:44:24,007 --> 00:44:24,967 the other thing too. 866 00:44:25,267 --> 00:44:26,497 Prasanna Malaiyandi: But, but before you move on, 867 00:44:26,647 --> 00:44:27,367 W. Curtis Preston: I stop you there? 868 00:44:27,547 --> 00:44:30,697 Uh, so how, how do you do that, right? 869 00:44:30,697 --> 00:44:34,237 Is this, is this something where you have to create. 870 00:44:35,107 --> 00:44:39,637 A button to press up, you know, because this sounds like a lot of little steps 871 00:44:39,637 --> 00:44:42,997 you probably need to do to do this manually, or is there something I can 872 00:44:42,997 --> 00:44:47,107 do upfront that says, in the event of a ransomware attack, push this button. 873 00:44:47,587 --> 00:44:48,097 Hey, gum. 874 00:44:48,517 --> 00:44:49,357 Shut up. 875 00:44:49,687 --> 00:44:53,887 Anyway, uh, in the event of a ransomware attack, press this button and it 876 00:44:53,887 --> 00:44:56,377 does the 10 things I need to do. 877 00:44:56,827 --> 00:44:58,897 Uh, what, what do you think 878 00:44:59,322 --> 00:45:02,422 Tom Hollingsworth: Some of them do have a big red button press here to, to like 879 00:45:02,422 --> 00:45:04,162 terminate all firewall connections. 880 00:45:04,162 --> 00:45:07,042 But most of the time you're gonna have to create like a checklist or, or have 881 00:45:07,042 --> 00:45:09,622 a system of like, okay, I'm gonna go into these rules and I'm gonna uncheck 882 00:45:09,622 --> 00:45:12,592 these five boxes and then I'm gonna hit the terminate connections button to make 883 00:45:12,592 --> 00:45:14,122 sure that no new connections can be made. 884 00:45:14,272 --> 00:45:16,372 Also, if you have a rule at the bottom of your firewall list that 885 00:45:16,372 --> 00:45:17,932 says Permit ip, any, any, take it out 886 00:45:17,932 --> 00:45:19,942 now because it's not doing you any good. 887 00:45:20,392 --> 00:45:24,622 But, but more importantly, you, you have to, you know, uh, all 888 00:45:24,627 --> 00:45:26,512 kill switches have to be wired. 889 00:45:27,182 --> 00:45:30,697 , there's no such thing as a magical switch that you can just hit, even if it's one 890 00:45:30,697 --> 00:45:35,197 that the, that the provider has given you investigate what it actually does. 891 00:45:35,227 --> 00:45:37,327 Does it dump the rules completely? 892 00:45:37,537 --> 00:45:41,137 Does it just like suspend the rules until you go in and manually add them? 893 00:45:41,617 --> 00:45:45,247 Remember that that could also cut off your connection to the firewall, so 894 00:45:45,247 --> 00:45:47,887 you need to have another way to get into it just in case that happens. 895 00:45:48,127 --> 00:45:52,297 Another reason for an isolated management network, but the, the idea is, is that 896 00:45:52,297 --> 00:45:57,517 you, you, you need to investigate what your options are because God help you 897 00:45:57,517 --> 00:46:01,117 if you really do have to run down to the data center and yank the cables 898 00:46:01,117 --> 00:46:05,337 out, and if that is a case and, and hey, it's just as valid as anything else. 899 00:46:06,067 --> 00:46:09,307 Can you make sure that you have the right keys, that you know which 900 00:46:09,307 --> 00:46:10,597 firewall you're yanking out of? 901 00:46:10,837 --> 00:46:13,117 Are there any other exits off of your network? 902 00:46:13,117 --> 00:46:15,877 Because that's another problem that you may run into. 903 00:46:16,057 --> 00:46:19,537 What happens if someone has created another exit off of your network, 904 00:46:19,537 --> 00:46:21,457 either accidentally or on purpose? 905 00:46:21,907 --> 00:46:23,737 And what happens then? 906 00:46:23,737 --> 00:46:27,277 Because you know it's just as easy for me to plug something into your network. 907 00:46:27,277 --> 00:46:29,527 And if there's another way off of it, I'm gonna find it. 908 00:46:29,737 --> 00:46:29,977 Prasanna Malaiyandi: Yeah. 909 00:46:30,277 --> 00:46:33,397 The one other thing though, I know you talked about, and it totally 910 00:46:33,397 --> 00:46:38,257 makes sense to kill all incoming and outcoming traffic, but just thinking a 911 00:46:38,257 --> 00:46:41,287 step forward, like when you're dealing with incident response, like doesn't 912 00:46:41,287 --> 00:46:44,617 that also take out like your chat channels, your slack channels, your 913 00:46:44,617 --> 00:46:48,937 video conferencing, everything else, like what do you do at that point? 914 00:46:48,937 --> 00:46:51,487 Is it just hope you have everyone's cell phone numbers? 915 00:46:52,612 --> 00:46:56,262 Tom Hollingsworth: you need to have a plan for out of band incident 916 00:46:56,662 --> 00:46:59,602 response because y it's, it, it's just like any crime scene. 917 00:46:59,722 --> 00:47:03,022 I need to figure out what's, what's been hit and I need to figure out 918 00:47:03,172 --> 00:47:05,422 how much of it is going to spread. 919 00:47:05,692 --> 00:47:08,602 And you're thinking to yourself like, I can't shut my network down 920 00:47:08,602 --> 00:47:12,532 permanently because you know it's gonna cost me X amount of dollars. 921 00:47:12,922 --> 00:47:16,102 Yes, but it's also gonna cost you x plus whatever amount of 922 00:47:16,102 --> 00:47:17,872 dollars when the next system gets 923 00:47:17,872 --> 00:47:22,012 hit, when it uncovers a device that no, nobody's patched it in years. 924 00:47:22,342 --> 00:47:24,052 Um, I'm not gonna lie. 925 00:47:24,502 --> 00:47:29,392 Incident response can work over iMessage text threads for a good couple of 926 00:47:29,392 --> 00:47:31,642 hours while you try to figure that out. 927 00:47:31,642 --> 00:47:35,032 Or, you know, buy your incident response team like those little, you 928 00:47:35,032 --> 00:47:38,092 know, hotspots or enable the data plans on their phone so that they can join 929 00:47:38,097 --> 00:47:42,322 their laptop there and join a Slack instance outside of your network. 930 00:47:42,997 --> 00:47:46,852 because that way nothing is working internal to your network. 931 00:47:47,062 --> 00:47:48,562 Because that's the other thing too. 932 00:47:48,802 --> 00:47:51,712 If you, if this is something that's particularly insidious on a window 933 00:47:51,712 --> 00:47:55,402 system and your incident responders are using Windows systems and they join 934 00:47:55,402 --> 00:47:58,492 the network to be able to do incident response and their laptops get compromised 935 00:47:58,492 --> 00:48:02,432 because they join the network again, you're gonna feel really, really dumb. 936 00:48:02,712 --> 00:48:06,022 It's like, uh, the professional, when they blew up the bomb squad truck, it's like, 937 00:48:06,022 --> 00:48:08,002 come on guys, what were you expecting? 938 00:48:09,352 --> 00:48:11,782 W. Curtis Preston: You just reminded me of the, there's a, there's a series 939 00:48:11,787 --> 00:48:15,862 of commercials and there's one where the commercial is like, it's like a 940 00:48:15,867 --> 00:48:20,992 horror movie and the, there's a bunch of kid, it's like the, you know, I got 941 00:48:20,992 --> 00:48:24,382 the guy with the, the, the ax murderers looking for the group of kids, and 942 00:48:24,382 --> 00:48:25,912 they're like, why don't we go hang out? 943 00:48:25,912 --> 00:48:29,482 Why don't we go hide in that shed over there with all the, uh, with all 944 00:48:29,487 --> 00:48:31,342 the, uh, machetes or something like 945 00:48:31,462 --> 00:48:31,792 Tom Hollingsworth: Yeah. 946 00:48:32,512 --> 00:48:36,292 W. Curtis Preston: Um, so, so we talked about blocking external traffic. 947 00:48:36,292 --> 00:48:38,632 What about blocking internal traffic? 948 00:48:38,812 --> 00:48:44,362 You know, uh, basically the lateral traffic, uh, be due to the, we 949 00:48:44,367 --> 00:48:46,972 know we have ransomware and we know it's gonna try to crawl. 950 00:48:47,212 --> 00:48:49,822 What about blocking that, uh, access? 951 00:48:50,512 --> 00:48:52,177 Tom Hollingsworth: So that's where you hope that your management 952 00:48:52,177 --> 00:48:56,467 networks are, um, isolated because the first thing I would do going 953 00:48:56,467 --> 00:48:59,167 into a router is shut down the route. 954 00:48:59,167 --> 00:49:05,227 Tables prevent, um, traffic from being passed across network boundaries. 955 00:49:05,497 --> 00:49:07,627 Um, what you're effectively doing in there is you are 956 00:49:07,627 --> 00:49:10,117 containing the damage to one area. 957 00:49:10,327 --> 00:49:15,667 Now, yeah, you're gonna take things down, but if you can isolate that network as 958 00:49:15,667 --> 00:49:20,107 the location for wherever the problem is, you can then bring other networks 959 00:49:20,107 --> 00:49:25,027 back online and be relatively certain that they're not gonna be infected. 960 00:49:25,507 --> 00:49:28,897 I really hope that you're not using like, just regular routing, that you 961 00:49:28,897 --> 00:49:31,957 have some kind of a security boundary there, because that makes it a whole lot. 962 00:49:32,782 --> 00:49:35,482 But you, you've got to think in, in phases. 963 00:49:35,482 --> 00:49:38,902 Obviously, you know, using the kill switch is gonna take everything 964 00:49:38,902 --> 00:49:42,292 down, but then you have to start, you know, can I bring this back online? 965 00:49:42,322 --> 00:49:43,822 Is this going to be infected? 966 00:49:43,852 --> 00:49:45,712 What would I be looking for? 967 00:49:46,282 --> 00:49:49,492 Um, so I actually have a, a story about this, uh, this happened 968 00:49:49,492 --> 00:49:50,872 last year to my children. 969 00:49:51,172 --> 00:49:55,402 Uh, one of 'em goes to the public high school here, uh, and I got a rocket 970 00:49:55,402 --> 00:50:00,652 text message from their IT department saying, please turn off all public school 971 00:50:00,652 --> 00:50:03,802 issue devices until further notice. 972 00:50:03,802 --> 00:50:06,172 And I'm like, uhoh, somebody got hit with something fun. 973 00:50:06,442 --> 00:50:09,052 And this was like the last day before Christmas break or something. 974 00:50:09,052 --> 00:50:11,692 So we went in and we turned off my kid's MacBook, right? 975 00:50:11,932 --> 00:50:15,742 So now, immediately I, because I know what the, the thing was, I don't 976 00:50:15,742 --> 00:50:19,042 want anybody to like phone home and get infected and then like infect 977 00:50:19,042 --> 00:50:20,392 the parents networks or whatever. 978 00:50:20,692 --> 00:50:21,442 Okay, no problem. 979 00:50:21,442 --> 00:50:22,132 We just shut it off. 980 00:50:22,132 --> 00:50:23,362 But then I'm like, I wonder what it could. 981 00:50:24,242 --> 00:50:26,962 like I, I'm kind of curious and, and they've, to this day, they've never 982 00:50:26,962 --> 00:50:30,052 disclosed what it was, but you would get an email like the next week, 983 00:50:30,112 --> 00:50:33,802 oh, if you're using like a, a, a, a corporate phone or if you're using 984 00:50:33,802 --> 00:50:35,422 a MacBook, you can turn it back on. 985 00:50:35,422 --> 00:50:39,112 Well, that automatically kind of lowers the horizon of, it has to 986 00:50:39,112 --> 00:50:41,512 be something that's focused on Windows or something like that. 987 00:50:41,722 --> 00:50:44,242 So then you start running through your head of what it could possibly be. 988 00:50:44,392 --> 00:50:46,282 Well, an incident response, you have to do the same thing. 989 00:50:46,282 --> 00:50:47,212 What server got hit? 990 00:50:47,272 --> 00:50:49,942 Oh, well, it was the database server and it was running this version of, 991 00:50:50,002 --> 00:50:51,682 uh, you know, windows or SQL server. 992 00:50:51,892 --> 00:50:52,372 Okay. 993 00:50:52,372 --> 00:50:54,202 Does that mean that Max can get on the network? 994 00:50:54,202 --> 00:50:55,552 Do I want them on the network? 995 00:50:55,882 --> 00:50:58,342 Is it a situation where even though they can't be infected, they could 996 00:50:58,342 --> 00:51:00,562 propagate something to another location? 997 00:51:00,742 --> 00:51:04,222 Like there's a lot that you have to go into because obviously the executives are 998 00:51:04,222 --> 00:51:05,632 gonna be like, when can we do back up and. 999 00:51:06,537 --> 00:51:09,907 and if you're a publicly traded company, oh God, the stockholders are like outdoors 1000 00:51:09,907 --> 00:51:13,057 with pitchforks and torches and they wanna know when they can get their dividends. 1001 00:51:13,237 --> 00:51:16,357 And you're like, uh, when I figure out how much of this data got encrypted 1002 00:51:16,357 --> 00:51:20,497 or stolen, and you're always gonna be fighting that tension and you can't 1003 00:51:20,502 --> 00:51:22,147 just shut everything off forever. 1004 00:51:22,417 --> 00:51:25,987 So that's part of incident response is you've got one team working on figuring 1005 00:51:25,987 --> 00:51:28,507 out how to stop whatever infected you, but you've got another team figuring 1006 00:51:28,507 --> 00:51:30,217 out how to bring things back online. 1007 00:51:30,457 --> 00:51:32,587 That's why we call it business continuity now. 1008 00:51:32,587 --> 00:51:32,917 Right. 1009 00:51:33,116 --> 00:51:35,716 Prasanna Malaiyandi: It is interesting about the incident response. 1010 00:51:35,716 --> 00:51:37,096 How have you seen cases? 1011 00:51:37,096 --> 00:51:40,066 Like how do you actually, well, two questions I have. 1012 00:51:40,456 --> 00:51:43,546 How do you figure out like that, this segment, going back to what 1013 00:51:43,546 --> 00:51:44,836 you said, you kill all the routes. 1014 00:51:45,016 --> 00:51:47,566 How do you figure out that this segment is safe or not? 1015 00:51:47,626 --> 00:51:51,046 And then I guess that, yeah, that's actually only one question. 1016 00:51:51,691 --> 00:51:54,241 Tom Hollingsworth: Well, so typically what, and, and you're, you're 1017 00:51:54,241 --> 00:51:57,721 effectively, when you create these boundaries, it's, it's like looking 1018 00:51:57,721 --> 00:52:02,221 for the hot potato effectively, because unless you, like in the alias episode, 1019 00:52:02,221 --> 00:52:03,811 just go click all the switches off. 1020 00:52:04,081 --> 00:52:07,471 Those devices can still communicate to each other at layer two. 1021 00:52:07,741 --> 00:52:10,861 Now, where you don't wanna have a problem is, is that it's in the data. 1022 00:52:11,851 --> 00:52:16,006 because if you isolate the layer two data center, now you've got a real problem. 1023 00:52:16,036 --> 00:52:19,546 Because if those servers, if if it's looking for servers, those 1024 00:52:19,546 --> 00:52:20,896 servers can still get infected. 1025 00:52:21,166 --> 00:52:24,016 That's why it's actually better to have like a, you know, a host route or 1026 00:52:24,016 --> 00:52:28,936 something like that, or something that, that kind of isolates that per unit thing. 1027 00:52:28,941 --> 00:52:31,756 I mean, honestly, like a V switch is perfect for this because like, 1028 00:52:31,786 --> 00:52:34,996 if it's not bound for that host, I'm not gonna let it go any further. 1029 00:52:35,266 --> 00:52:38,266 But effectively what you have to do is you have to look for chatter 1030 00:52:38,266 --> 00:52:39,946 that's still going on in the network. 1031 00:52:40,366 --> 00:52:42,616 Like you, you, I've shut all this down. 1032 00:52:43,266 --> 00:52:47,161 and I told my users to like disable their machines or, or turn them off or 1033 00:52:47,161 --> 00:52:49,501 whatever, what's still trying to talk. 1034 00:52:49,951 --> 00:52:52,531 And then you go take that on a case by case basis. 1035 00:52:52,861 --> 00:52:55,381 Oh, this device is still sending traffic that it's, but 1036 00:52:55,381 --> 00:52:56,551 it's looking for this server. 1037 00:52:56,551 --> 00:52:59,611 Okay, well I'm, I, I can shut it off because I know that it's probably safe. 1038 00:52:59,881 --> 00:53:02,671 But then you run into something like, oh, this thing is chattering 1039 00:53:02,671 --> 00:53:06,031 an awful lot and it's chattering on a way that it shouldn't be chattering. 1040 00:53:06,241 --> 00:53:09,361 Like that's how I've gone and found hosts that have been infected, but not 1041 00:53:09,366 --> 00:53:12,841 by ransomware, but by early malware because they just kept hammering the 1042 00:53:12,841 --> 00:53:14,671 firewall with these outbound requests. 1043 00:53:14,671 --> 00:53:16,231 And I'm like, you shouldn't 1044 00:53:16,236 --> 00:53:16,981 be doing that. 1045 00:53:17,191 --> 00:53:19,351 So it's, it's almost like a little bit of detective work. 1046 00:53:19,381 --> 00:53:23,281 The good news is, is that even though the network devices are kind of like 1047 00:53:23,281 --> 00:53:27,841 dumb from the perspective of I don't care what application is trying to talk, 1048 00:53:27,841 --> 00:53:31,651 where they're really good at telling you that things are still generating traffic. 1049 00:53:31,656 --> 00:53:35,311 It's like, oh, this port is still sending a ton of packets f bound 1050 00:53:35,311 --> 00:53:37,171 for this address on this location. 1051 00:53:37,561 --> 00:53:40,081 And so then you're like, oh, I think something might be up here. 1052 00:53:40,411 --> 00:53:42,811 Prasanna Malaiyandi: Do you ever see cases where people. 1053 00:53:43,491 --> 00:53:48,376 , almost do a, like, create a black hole on the device itself to sort 1054 00:53:48,376 --> 00:53:52,036 of sync the packets there so it doesn't go out, rather than having 1055 00:53:52,036 --> 00:53:53,366 to necessarily do it on the switch. 1056 00:53:53,806 --> 00:53:56,416 Tom Hollingsworth: Um, you can, uh, that's actually a really great way to 1057 00:53:56,416 --> 00:54:00,376 determine what it's trying to contact is to create like a null route on the system. 1058 00:54:00,766 --> 00:54:03,256 Uh, uh, going all the way back like three or four years. 1059 00:54:03,261 --> 00:54:06,766 Like Mark Marcus Hutchins, that's how he actually stopped a major outbreak of 1060 00:54:06,766 --> 00:54:09,916 malware, uh, for all the good it did, and he got arrested by the FBI later. 1061 00:54:10,066 --> 00:54:11,746 But he basically black hole the dns. 1062 00:54:12,721 --> 00:54:15,781 He bought the domain black hole it because if that domain name was 1063 00:54:15,781 --> 00:54:17,551 active, then it would stop propagating. 1064 00:54:17,701 --> 00:54:21,001 And so he figured that out by saying, oh, I wonder where this is 1065 00:54:21,001 --> 00:54:22,201 going and I wonder what it's doing. 1066 00:54:22,351 --> 00:54:23,191 You can do that. 1067 00:54:23,191 --> 00:54:25,831 And it's actually the next step in incident response, which you've isolated 1068 00:54:25,831 --> 00:54:29,311 the system, is I wanna see how it behaves and what it's trying to do. 1069 00:54:29,311 --> 00:54:32,041 Cuz that could give me a clue as to what I got hit with and 1070 00:54:32,041 --> 00:54:33,301 what they could be looking for. 1071 00:54:33,481 --> 00:54:36,181 And that gives you, you know, a, a little bit of opportunity, but that's 1072 00:54:36,181 --> 00:54:39,031 a little bit more of an advanced tool that you would, you would want to use. 1073 00:54:39,331 --> 00:54:42,961 Uh, just because black holding traffic on a, on a device takes 1074 00:54:42,961 --> 00:54:45,391 a little bit of setup, especially if you're fighting against people 1075 00:54:45,391 --> 00:54:46,621 who don't want you to do that. 1076 00:54:46,981 --> 00:54:47,221 Prasanna Malaiyandi: Yeah. 1077 00:54:48,076 --> 00:54:49,846 W. Curtis Preston: Yeah, so it sounds like. 1078 00:54:50,716 --> 00:54:55,366 A, a lot of the things that you talked about in the last couple of minutes, they 1079 00:54:55,366 --> 00:54:59,656 would be a lot easier to do again, if we segmented the network in the first place, 1080 00:54:59,956 --> 00:55:00,346 right? 1081 00:55:00,586 --> 00:55:03,136 We put people with Windows laptops on one network. 1082 00:55:03,136 --> 00:55:05,836 We put people with Mac laptops on a network, another network. 1083 00:55:05,841 --> 00:55:08,496 We put the, the, the phones right? 1084 00:55:08,686 --> 00:55:09,766 That are doing the wifi. 1085 00:55:09,766 --> 00:55:11,206 We put them on another network. 1086 00:55:11,596 --> 00:55:14,386 Um, and we put servers on a different network. 1087 00:55:14,386 --> 00:55:17,416 We put, maybe we put servers of a different type on, on a different network. 1088 00:55:17,686 --> 00:55:22,066 So that way you could basically say you don't have to tell the, 1089 00:55:22,126 --> 00:55:24,616 the, the users to not do anything. 1090 00:55:24,616 --> 00:55:28,066 You can just say shut off the, the laptop, uh, network. 1091 00:55:28,066 --> 00:55:28,396 Right? 1092 00:55:28,846 --> 00:55:31,996 Um, and you, you shut off the laptop network and so on. 1093 00:55:32,206 --> 00:55:34,756 And, and all the networks that where we don't currently, 1094 00:55:34,846 --> 00:55:35,836 what we're not looking at. 1095 00:55:36,046 --> 00:55:38,356 And then, okay, who's trying to talk? 1096 00:55:38,356 --> 00:55:39,226 Who's trying to talk? 1097 00:55:39,346 --> 00:55:40,816 Why is this server surfing? 1098 00:55:40,816 --> 00:55:41,266 The web 1099 00:55:42,086 --> 00:55:42,576 Tom Hollingsworth: Yeah. 1100 00:55:42,736 --> 00:55:44,056 W. Curtis Preston: There's nobody over there. 1101 00:55:44,266 --> 00:55:46,156 Why is this server going over report 80? 1102 00:55:47,026 --> 00:55:48,886 Tom Hollingsworth: Well, a lot of places already kind of have this by 1103 00:55:48,886 --> 00:55:51,586 default, even if they didn't realize they were doing it because you have 1104 00:55:51,586 --> 00:55:54,136 different classes of devices that you wanna treat them differently. 1105 00:55:54,406 --> 00:55:58,246 Like for example, the uh, um, the server network, we want to have a 1106 00:55:58,246 --> 00:55:59,506 little bit more security in there. 1107 00:55:59,506 --> 00:56:02,236 Maybe a little less host to host East to west traffic kind of thing. 1108 00:56:02,506 --> 00:56:05,596 The wireless network where all the laptops and the devices connect. 1109 00:56:05,596 --> 00:56:08,416 I'm a little less careful about that because I actually have identity 1110 00:56:08,416 --> 00:56:10,996 management in place that validates the users when they try to log in. 1111 00:56:11,206 --> 00:56:14,566 Maybe I have a guest wireless network for my, for people that come into the lobby. 1112 00:56:14,806 --> 00:56:17,656 That one's wide open to the internet outbound only. 1113 00:56:17,806 --> 00:56:19,816 So I don't need to worry about that quite as much. 1114 00:56:19,816 --> 00:56:22,336 And then, you know, like phones and printers and things like that, that 1115 00:56:22,336 --> 00:56:25,906 have very specific things like, you know, I wouldn't enable Bonura in my 1116 00:56:25,906 --> 00:56:28,846 internal network, but maybe for the printer vlan I would, because I want 1117 00:56:28,846 --> 00:56:30,226 people to be able to find a printer. 1118 00:56:31,081 --> 00:56:32,071 Open up their laptop. 1119 00:56:32,311 --> 00:56:34,771 So they've already created these segments. 1120 00:56:34,951 --> 00:56:37,561 You just have to know where the buttons are to shut them off. 1121 00:56:37,561 --> 00:56:40,561 So maybe the example is I wanna isolate the servers from the rest 1122 00:56:40,561 --> 00:56:43,441 of the network, cuz I think there's something in there, but I can still 1123 00:56:43,441 --> 00:56:45,091 leave the wireless network up. 1124 00:56:45,091 --> 00:56:48,061 Maybe have everybody join the guest access network and force them all 1125 00:56:48,061 --> 00:56:51,541 out to the internet to do, you know, incident response or chat channels 1126 00:56:51,541 --> 00:56:55,021 or something like that where I'm, you know, but I'm creating these bounds so 1127 00:56:55,021 --> 00:57:00,121 that traffic flows one direction only, or it prevents certain things inside 1128 00:57:00,121 --> 00:57:03,421 of other areas because, you know, there's nothing to say like the, you 1129 00:57:03,421 --> 00:57:07,501 know, the, the, uh, s IDs that are on printers that are like, you know, set up, 1130 00:57:07,921 --> 00:57:10,711 uh, set me up or something like that can't be compromised. 1131 00:57:10,711 --> 00:57:12,631 And then if they can get into your printer network, it's like, 1132 00:57:12,631 --> 00:57:13,951 oh crap, where can they go from? 1133 00:57:15,516 --> 00:57:16,006 W. Curtis Preston: Yeah. 1134 00:57:16,011 --> 00:57:19,876 And, and Bonjour of course would be the, um, I, I don't know how would 1135 00:57:19,876 --> 00:57:20,386 I define 1136 00:57:20,496 --> 00:57:21,286 Prasanna Malaiyandi: file sharing. 1137 00:57:22,701 --> 00:57:25,621 Tom Hollingsworth: It, it is, it's almost like an auto configuration announcement, 1138 00:57:25,651 --> 00:57:29,491 uh, setting where, uh, it, it, and you can thank Steve Jobs for this. 1139 00:57:29,491 --> 00:57:30,841 He's like, I hate setting up printers. 1140 00:57:31,081 --> 00:57:33,451 And so basically what he did is he set up a system so that the printers 1141 00:57:33,451 --> 00:57:34,651 can announce that they exist. 1142 00:57:34,651 --> 00:57:36,631 And your laptop is constantly listening for these. 1143 00:57:36,871 --> 00:57:40,561 Bonura is another one of those protocols that is extra chatty and you kinda 1144 00:57:40,561 --> 00:57:44,221 wanna put bounds on it so that like you don't have the Apple TV four hallways 1145 00:57:44,221 --> 00:57:48,421 down announcing itself to the people in accounting because one, it's annoying. 1146 00:57:48,426 --> 00:57:50,611 And two, you never know when you're gonna do something you're not supposed to. 1147 00:57:53,571 --> 00:57:53,931 Prasanna Malaiyandi: Interesting. 1148 00:57:56,211 --> 00:58:02,701 So yeah, I guess a lot of these are really around setting up 1149 00:58:02,701 --> 00:58:04,381 that initial network properly. 1150 00:58:04,441 --> 00:58:08,791 So then when you do have these issues, you can recover quickly and 1151 00:58:08,941 --> 00:58:10,711 identify and then recover quickly. 1152 00:58:10,951 --> 00:58:11,161 Right? 1153 00:58:11,161 --> 00:58:13,801 But if you don't have that initial setup done, then you're 1154 00:58:13,801 --> 00:58:15,571 in for a world of hurt, I guess. 1155 00:58:16,306 --> 00:58:17,806 Tom Hollingsworth: and not just initial setup. 1156 00:58:17,806 --> 00:58:22,426 You actually do have to treat the network like a living, breathing organism. 1157 00:58:22,431 --> 00:58:25,546 I can't think of a single server admin out there that installs, 1158 00:58:25,756 --> 00:58:28,036 you know, windows server. 1159 00:58:28,036 --> 00:58:28,876 What are we up now? 1160 00:58:28,906 --> 00:58:33,106 20 20, 20 23 Windows, server X, I don't know, installs it 1161 00:58:33,106 --> 00:58:34,186 and then never patches it. 1162 00:58:34,246 --> 00:58:34,576 Never 1163 00:58:34,576 --> 00:58:35,386 touches it again. 1164 00:58:35,416 --> 00:58:38,516 Like, like you people are probably just shaking, even thinking. 1165 00:58:39,271 --> 00:58:42,271 , you cannot configure a network and then just leave it alone. 1166 00:58:42,541 --> 00:58:47,161 You do have to go in and, and tweak things and move things and change things. 1167 00:58:47,161 --> 00:58:50,041 And, you know, not just when you're trying to fix a broken thing, 1168 00:58:50,311 --> 00:58:53,461 either, you have to like, okay, is this subnet big enough for the 1169 00:58:53,461 --> 00:58:54,601 number of hosts that are in it? 1170 00:58:54,601 --> 00:58:56,281 Should I create routes over here? 1171 00:58:56,521 --> 00:58:59,641 It looks like there's a lot of extra traffic going on over this direction. 1172 00:58:59,641 --> 00:59:02,461 Maybe I need to disallow that because it looks like it's something 1173 00:59:02,461 --> 00:59:03,481 that shouldn't be happening. 1174 00:59:03,721 --> 00:59:09,181 Like, if you're not constantly pruning back what you are working on then, 1175 00:59:09,301 --> 00:59:12,751 and that's the problem that a lot of the, the, uh, ransomware writers have 1176 00:59:12,751 --> 00:59:16,711 figured out, like a lot of, a lot of their secrets, if you wanna call them, 1177 00:59:16,711 --> 00:59:19,141 that are just inadequate it support. 1178 00:59:19,381 --> 00:59:22,651 Like, we're gonna hope that you had left this on by default and we're 1179 00:59:22,651 --> 00:59:24,931 gonna take advantage of it and use it. 1180 00:59:24,991 --> 00:59:30,471 And if you did, I'm sorry, but like, you know, if any best practices 1181 00:59:30,476 --> 00:59:32,971 guide out there says, shut that off, and you didn't shut it off, 1182 00:59:33,181 --> 00:59:34,561 are you in that big of a hurry? 1183 00:59:35,956 --> 00:59:37,936 W. Curtis Preston: Yeah, well we're, we're living in a world 1184 00:59:37,936 --> 00:59:41,436 where, uh, you know, people don't even change their default password. 1185 00:59:41,441 --> 00:59:48,226 So, um, listen, here's the thing, Tom, my plumber's here, so, uh, I, I, you 1186 00:59:48,226 --> 00:59:51,196 know, I got a tradesman that actually showed up at two o'clock when he said 1187 00:59:51,196 --> 00:59:52,426 he was gonna be here at two o'clock. 1188 00:59:52,426 --> 00:59:54,976 So I gotta , we gotta shut this baby down. 1189 00:59:55,486 --> 00:59:58,156 Uh, Tom, this has been, this has been a great conversation. 1190 00:59:58,396 --> 01:00:00,596 Um, so thanks, thanks a lot. 1191 01:00:01,591 --> 01:00:02,431 Tom Hollingsworth: Well, thanks for having me. 1192 01:00:02,431 --> 01:00:05,461 It's, it's been fun to talk about networking with, uh, with some folks 1193 01:00:05,461 --> 01:00:09,031 that coming at it from a slightly different perspective and understanding, 1194 01:00:09,151 --> 01:00:11,521 you know, what are we trying to accomplish with it, and in some 1195 01:00:11,521 --> 01:00:13,291 cases, what are we trying to disallow? 1196 01:00:13,786 --> 01:00:13,906 Prasanna Malaiyandi: Hmm, 1197 01:00:14,596 --> 01:00:15,106 W. Curtis Preston: Absolutely. 1198 01:00:15,106 --> 01:00:17,776 Thanks again, Prasanna, once again, making me go backwards, 1199 01:00:18,286 --> 01:00:21,886 Prasanna Malaiyandi: I, you know me, I try, you take one step back, two steps 1200 01:00:21,891 --> 01:00:23,266 forward or something like that, right? 1201 01:00:23,446 --> 01:00:24,346 W. Curtis Preston: something like that. 1202 01:00:24,351 --> 01:00:24,506 I 1203 01:00:24,506 --> 01:00:24,826 like that. 1204 01:00:24,946 --> 01:00:25,426 All right. 1205 01:00:25,636 --> 01:00:27,166 And thanks again to our listeners. 1206 01:00:27,786 --> 01:00:30,706 Remember to subscribe so that you can restore it all.