1 00:00:00,000 --> 00:00:04,229 You found the backup wrap up your go-to podcast for all things 2 00:00:04,229 --> 00:00:06,689 backup recovery and cyber recovery. 3 00:00:07,079 --> 00:00:11,189 In this episode, we'll explore the critical concept of minimizing the 4 00:00:11,189 --> 00:00:13,199 blast radius of a cyber attack. 5 00:00:13,739 --> 00:00:16,319 Once again, we're joined by cybersecurity expert Dr. 6 00:00:16,319 --> 00:00:16,530 Mike Saylor. 7 00:00:18,175 --> 00:00:22,254 We'll talk about implementing lease privilege, access, network segmentation, 8 00:00:22,465 --> 00:00:26,724 controlling outbound traffic, and other ideas on how to reduce the 9 00:00:26,724 --> 00:00:28,884 impact of your next cyber attack. 10 00:00:29,395 --> 00:00:33,325 By the way, if you don't know who I am, I'm w Curtis Preston, AKA, Mr. 11 00:00:33,325 --> 00:00:36,685 Backup, and I've been passionate about backup and recovery for 12 00:00:36,835 --> 00:00:38,634 over 30 years, ever since. 13 00:00:38,634 --> 00:00:42,025 I had to tell my boss that there were no backups of the really 14 00:00:42,025 --> 00:00:43,735 important database we just lost. 15 00:00:44,085 --> 00:00:46,995 I don't want that to happen to you, and that's why I do this. 16 00:00:47,324 --> 00:00:52,935 On this podcast, we turn unappreciated backup admins into Cyber Recovery Heroes. 17 00:00:53,144 --> 00:00:55,365 This is the backup wrap up. 18 00:01:11,493 --> 00:01:12,483 Welcome to the show. 19 00:01:13,683 --> 00:01:18,003 Before I continue, if I could ask you to press that subscribe, like 20 00:01:18,003 --> 00:01:22,743 or follow button so that you will always get our amazing content. 21 00:01:23,433 --> 00:01:26,913 And I am w Curtis Preston, AKA, Mr. 22 00:01:26,913 --> 00:01:27,453 Backup. 23 00:01:27,453 --> 00:01:31,803 And with me, I have my very expensive chair disassembly consultant. 24 00:01:32,313 --> 00:01:33,093 Persona. 25 00:01:33,243 --> 00:01:36,243 Malaiyandi how. 26 00:01:38,943 --> 00:01:42,753 Are you upset that I am returning my very expensive chair? 27 00:01:42,963 --> 00:01:43,683 Are you saddened? 28 00:01:44,673 --> 00:01:49,083 I am not, because chairs are one of those things that are very subjective 29 00:01:49,563 --> 00:01:52,323 and what work, what works for one person may not work for 30 00:01:52,323 --> 00:01:54,813 another person, So I get it. 31 00:01:55,323 --> 00:01:58,593 those, those that listen to the podcast regularly know that I 32 00:01:58,593 --> 00:02:04,293 recently purchased a pretty, for me, pretty expensive office chair. 33 00:02:04,293 --> 00:02:04,353 I. 34 00:02:04,608 --> 00:02:08,178 From Crandall office Furniture, not a sponsor. 35 00:02:08,508 --> 00:02:14,058 Um, and that, uh, as a very nice chair, it was actually a Steelcase chair. 36 00:02:14,238 --> 00:02:18,678 And, um, I think I spent like 800 bucks on it, which was, you know, 37 00:02:18,888 --> 00:02:20,538 a lot of money for me for a chair. 38 00:02:21,168 --> 00:02:22,518 And I did it all 39 00:02:22,758 --> 00:02:25,218 Not, not, but if you think about, 40 00:02:25,698 --> 00:02:26,148 what, 41 00:02:26,238 --> 00:02:26,538 yeah. 42 00:02:26,898 --> 00:02:27,708 Well, two things. 43 00:02:27,708 --> 00:02:27,918 Yeah. 44 00:02:27,918 --> 00:02:30,438 Your existing chair would constantly squeak, especially if 45 00:02:30,438 --> 00:02:31,848 you go left, right, left, right. 46 00:02:32,403 --> 00:02:32,853 like this. 47 00:02:33,168 --> 00:02:34,368 Oh, I can't hear it anymore. 48 00:02:35,313 --> 00:02:37,323 Yeah, well, maybe I better mic placement. 49 00:02:37,323 --> 00:02:37,683 I don't know. 50 00:02:38,258 --> 00:02:39,818 The first is, yeah, the squeak. 51 00:02:40,358 --> 00:02:42,458 And then what was the second one? 52 00:02:42,458 --> 00:02:49,538 Oh, if you think about the cost per hour of buying that $800 chair and 53 00:02:49,538 --> 00:02:52,358 how much time you sit in that chair, 54 00:02:53,123 --> 00:02:53,483 Yeah. 55 00:02:53,663 --> 00:02:53,933 Yeah. 56 00:02:54,203 --> 00:02:54,323 And. 57 00:02:54,488 --> 00:02:54,998 a penny 58 00:02:55,298 --> 00:02:55,388 a 59 00:02:55,418 --> 00:02:57,758 It was a $1,200 chair that I got for 800 bucks. 60 00:02:57,758 --> 00:03:00,908 But, but anyway, Crandle was great in terms of, I'm like, listen, I, 61 00:03:00,908 --> 00:03:02,498 I just really don't like the chair. 62 00:03:02,498 --> 00:03:04,778 They were great with the return policy, so I'm very happy. 63 00:03:04,778 --> 00:03:08,228 But disa assembling it was quite the chore. 64 00:03:08,978 --> 00:03:14,288 Um, so, uh, on, on a completely different note, non-sequitur, 65 00:03:14,288 --> 00:03:15,908 my favorite Latin term. 66 00:03:16,418 --> 00:03:19,778 Uh, we're gonna be talking this week about minimizing the 67 00:03:19,778 --> 00:03:22,208 blast radius of a cyber attack. 68 00:03:22,538 --> 00:03:23,558 And once again. 69 00:03:23,828 --> 00:03:28,178 Fans of the show will recognize our guest today, Mike Sailor. 70 00:03:28,478 --> 00:03:29,498 How's it going, Mike? 71 00:03:30,638 --> 00:03:31,208 It is going well. 72 00:03:31,208 --> 00:03:31,958 How are you guys? 73 00:03:32,948 --> 00:03:34,268 Doing well, doing well. 74 00:03:34,748 --> 00:03:35,558 Doing all right. 75 00:03:35,648 --> 00:03:36,068 I'm back. 76 00:03:36,248 --> 00:03:37,598 would get a bit new chair though. 77 00:03:38,888 --> 00:03:39,308 I'm back. 78 00:03:39,338 --> 00:03:42,668 I'm back to my old chair, which is, which is for me is fine for now. 79 00:03:43,898 --> 00:03:48,218 But, uh, what, what do we, what do we mean, uh, Mike, when we talk about 80 00:03:48,218 --> 00:03:50,053 minimizing the blast radius of an attack? 81 00:03:52,208 --> 00:03:52,448 Sure. 82 00:03:52,448 --> 00:03:55,928 It's also today the new term is called Exposure management. 83 00:03:56,033 --> 00:03:56,633 Ooh. 84 00:03:56,693 --> 00:03:57,383 Exposure 85 00:03:57,593 --> 00:03:57,713 I. 86 00:03:58,043 --> 00:03:58,463 I like it. 87 00:04:00,653 --> 00:04:03,263 You know, it's not a new term, it just means something 88 00:04:03,263 --> 00:04:04,583 different today than it used to. 89 00:04:04,583 --> 00:04:08,183 It used for me, it just, it meant, it meant, uh, knowing who my daughter was 90 00:04:08,183 --> 00:04:09,953 going out with before they left the house. 91 00:04:10,493 --> 00:04:12,623 But, uh, today, 92 00:04:12,688 --> 00:04:13,048 also a. 93 00:04:13,073 --> 00:04:13,643 exposure. 94 00:04:15,378 --> 00:04:15,668 Yeah. 95 00:04:16,463 --> 00:04:16,733 Today. 96 00:04:16,733 --> 00:04:20,963 Exposure Management really encompasses kind of the, the, you know, i 97 00:04:21,053 --> 00:04:25,013 governance, like good controls and policy, and knowing where your stuff is. 98 00:04:25,013 --> 00:04:28,883 It, it, it in it involves good operations, sound operations, 99 00:04:28,883 --> 00:04:30,383 good quality, consistency. 100 00:04:30,623 --> 00:04:32,093 It involves incident response. 101 00:04:32,093 --> 00:04:33,803 It involves insurance and. 102 00:04:34,253 --> 00:04:41,153 Risk mitigation and it's, it's very broad, but uh, specific to attack surface stuff, 103 00:04:41,543 --> 00:04:47,183 um, a lot of, a lot of organizations and, and I've been in it for 30 years, 104 00:04:47,273 --> 00:04:52,463 uh, I can count probably on one hand the number of the number of organizations that 105 00:04:52,463 --> 00:04:54,198 have a good handle on their environment. 106 00:04:54,243 --> 00:04:57,633 Like how many in, when I, when I ask how many assets do you have? 107 00:04:57,663 --> 00:05:02,913 Oh, well, I maybe go check the spreadsheet or let me run my scan real quick. 108 00:05:03,243 --> 00:05:04,053 They don't know. 109 00:05:04,383 --> 00:05:07,953 Uh, and that's a problem in certain industries, especially like oil and gas, 110 00:05:07,953 --> 00:05:10,773 where you've got all that stuff out in the field and you don't, I have no idea. 111 00:05:11,103 --> 00:05:14,913 Well, then how can you protect what you don't know and how? 112 00:05:14,913 --> 00:05:18,033 And then there's other implications like licensing and patching and all. 113 00:05:18,033 --> 00:05:19,203 If you don't know what you're. 114 00:05:19,553 --> 00:05:21,833 You're in charge of, then how can you be effective at it? 115 00:05:21,833 --> 00:05:22,553 So there's that. 116 00:05:23,093 --> 00:05:27,473 Uh, but then the exposure management or the, the blast radius is also 117 00:05:27,473 --> 00:05:30,953 all those controls that would be designed or implemented to minimize 118 00:05:30,953 --> 00:05:32,933 the impact of a given situation. 119 00:05:33,323 --> 00:05:35,993 Like, this laptop gets ransomware. 120 00:05:36,143 --> 00:05:38,183 How do I make sure it doesn't go other places? 121 00:05:38,183 --> 00:05:39,983 Or at least not to the critical stuff. 122 00:05:40,013 --> 00:05:43,343 Um, you know, if users get in fact in infected, then, you know, they 123 00:05:43,343 --> 00:05:46,493 get the day off or whatever, but at least it's not taking down my server. 124 00:05:47,048 --> 00:05:47,978 Um, but then other 125 00:05:47,978 --> 00:05:51,068 considerations too, based on how your business operates and the people you 126 00:05:51,068 --> 00:05:57,998 work with, are there ways to limit risk, uh, to, to that scope of, uh, 127 00:05:58,058 --> 00:06:00,068 you know, your, your little ecosystem? 128 00:06:00,068 --> 00:06:03,698 You know, if you're a company that just does business in Texas, then why are you 129 00:06:03,698 --> 00:06:05,558 accepting internet traffic from China? 130 00:06:06,878 --> 00:06:07,358 Yeah, good 131 00:06:07,358 --> 00:06:08,363 Kind of a simple example. 132 00:06:08,813 --> 00:06:12,023 And one thing, Mike, as you were talking about, sort of understanding 133 00:06:12,023 --> 00:06:13,913 like what's in your environment. 134 00:06:14,213 --> 00:06:17,453 I know sometimes we don't think about like companies who are developing 135 00:06:17,453 --> 00:06:21,833 software and they, or even just using a third party software, sometimes 136 00:06:21,833 --> 00:06:23,454 those have vulnerabilities that can. 137 00:06:23,828 --> 00:06:24,698 That get flagged. 138 00:06:24,698 --> 00:06:28,508 And if you don't know what software is running in your environment, how can 139 00:06:28,508 --> 00:06:32,528 you make sure that you don't have any issues or you realize, Hey, I should 140 00:06:32,528 --> 00:06:36,998 really be patching this, or I need to take some mitigation steps to prevent 141 00:06:36,998 --> 00:06:42,218 myself from being attacked and being exploited by a certain ex, uh, exploit. 142 00:06:42,998 --> 00:06:43,628 Absolutely. 143 00:06:43,628 --> 00:06:48,158 And that seems like a very straightforward, uh, conversation to have. 144 00:06:48,368 --> 00:06:52,238 But the moment that we, we start sitting back and talking about changing 145 00:06:52,238 --> 00:06:57,698 our patch management policy and, and what systems get antivirus and what 146 00:06:57,698 --> 00:06:59,883 don't, and for whatever reason I. 147 00:06:59,903 --> 00:07:02,993 It's, it's not just us having this conversation anymore. 148 00:07:02,993 --> 00:07:06,563 We've gotta involve the business and how what we're doing is gonna impact 149 00:07:06,563 --> 00:07:08,753 people's ability to do their job or 150 00:07:09,143 --> 00:07:11,063 watch Netflix on their lunch break. 151 00:07:11,363 --> 00:07:14,933 But then also, uh, is there a cost associated with that? 152 00:07:14,933 --> 00:07:17,153 Now we're gonna be paying more or differently. 153 00:07:17,453 --> 00:07:22,313 Uh, and then at the end of the day, uh, if our policy is what drives an 154 00:07:22,313 --> 00:07:23,873 incident, then, then you're on the hook. 155 00:07:24,233 --> 00:07:28,193 Um, and so I think a lot of it environments kind of. 156 00:07:28,718 --> 00:07:31,298 Take the, the, the risk averse approach. 157 00:07:31,328 --> 00:07:32,828 Let's, let's like be as. 158 00:07:33,938 --> 00:07:36,428 Uh, implement as much coverage as we can without 159 00:07:37,023 --> 00:07:37,688 Hindering the 160 00:07:38,018 --> 00:07:39,008 responsible. 161 00:07:39,338 --> 00:07:42,638 Uh, for, especially when the business doesn't give us the feedback or the 162 00:07:42,638 --> 00:07:44,408 direction we need to be more effective. 163 00:07:44,408 --> 00:07:47,648 We, we become the default, uh, you know, scapegoat. 164 00:07:48,128 --> 00:07:52,178 Uh, I mean, think the CrowdStrike situation, uh, where they, you know, 165 00:07:52,178 --> 00:07:56,888 this update went out, I believe it was an involuntary update, so it doesn't 166 00:07:56,888 --> 00:08:01,928 really apply to patch management, but if we knew about the criticality of the. 167 00:08:02,273 --> 00:08:05,783 Um, or the value or the function of a server or machine 168 00:08:05,783 --> 00:08:06,953 that had CrowdStrike on it. 169 00:08:06,953 --> 00:08:11,003 The moment that problem arose, we would know the impact it was gonna 170 00:08:11,003 --> 00:08:12,743 have over the next day or week. 171 00:08:13,133 --> 00:08:13,943 Uh, and we would be. 172 00:08:15,233 --> 00:08:18,023 I was reading a, a blog, uh, this morning. 173 00:08:18,023 --> 00:08:21,083 I was reading a blog about the over-reliance on 174 00:08:21,083 --> 00:08:22,793 individual vendors, right? 175 00:08:23,213 --> 00:08:29,693 Um, and, uh, the, the funny thing is the blog was on, uh, CrowdStrike's, uh, blog. 176 00:08:30,173 --> 00:08:30,503 Um. 177 00:08:33,068 --> 00:08:37,148 It was a blog that they wrote a little while ago about, you know, 178 00:08:37,178 --> 00:08:38,858 the overreliance on a single vendor. 179 00:08:38,858 --> 00:08:40,958 It's just, it's just, when you think about what happened with 180 00:08:40,958 --> 00:08:42,968 CrowdStrike, it's just rather ironic. 181 00:08:43,568 --> 00:08:48,518 Um, yeah, I, so when we talk about, you know, there, there are things, let's 182 00:08:48,518 --> 00:08:55,178 first talk about the concept when we're trying to minimize that blast radius. 183 00:08:55,298 --> 00:08:59,318 Um, the, one of the first things that comes to my mind is the 184 00:08:59,318 --> 00:09:01,718 concept of least privilege. 185 00:09:02,708 --> 00:09:02,738 I. 186 00:09:02,738 --> 00:09:05,063 Um, you want, you want to talk about that a little bit? 187 00:09:06,503 --> 00:09:06,953 Sure. 188 00:09:08,438 --> 00:09:12,128 That that lends itself to some comments I've already made. 189 00:09:12,638 --> 00:09:15,668 And so let's just take you gentlemen, for example, Curtis, if you're just 190 00:09:15,668 --> 00:09:19,568 a normal user, I'm just gonna give you the ability to do your job. 191 00:09:19,628 --> 00:09:22,958 And so that's internet access, the ability to print, maybe access your, 192 00:09:22,958 --> 00:09:28,148 you know, your email and maybe access, you know, some role specific server 193 00:09:28,148 --> 00:09:29,738 or application within the environment. 194 00:09:30,338 --> 00:09:34,418 Well, that takes time on the operations side for me to develop. 195 00:09:35,603 --> 00:09:37,763 Who has access to what, based on job role, 196 00:09:38,063 --> 00:09:39,293 which is called what role? 197 00:09:39,298 --> 00:09:39,538 Role 198 00:09:39,543 --> 00:09:39,773 based 199 00:09:39,908 --> 00:09:41,318 based access control, right? 200 00:09:41,318 --> 00:09:41,648 Or RA. 201 00:09:41,948 --> 00:09:42,128 Yeah. 202 00:09:43,103 --> 00:09:49,223 so that's a, that's a, that's a mature version of, uh, of, of just having the 203 00:09:49,223 --> 00:09:52,044 questions a asked, uh, when new users get. 204 00:09:53,078 --> 00:09:55,778 Uh, new user access, uh, is requested. 205 00:09:55,783 --> 00:09:55,953 And, 206 00:09:55,958 --> 00:10:00,728 and so in a small shop that's, that's not so somewhat of a problem, but even in a 207 00:10:00,728 --> 00:10:04,898 small shop that has a lot of turnover, where you've got these large enterprise, 208 00:10:05,018 --> 00:10:08,798 you know, small, medium, large, you know, and then enterprise, the different sizes 209 00:10:08,798 --> 00:10:14,018 of organization may dictate the need for better, uh, more mature approaches to. 210 00:10:14,423 --> 00:10:16,343 Allocating or provisioning access. 211 00:10:16,763 --> 00:10:20,543 So if we can reduce what a user has access to, we're reducing their 212 00:10:20,543 --> 00:10:23,213 exposure of that asset and that user. 213 00:10:23,723 --> 00:10:27,443 Um, when, if, if they're compromised, their credentials are compromised, their 214 00:10:27,443 --> 00:10:33,323 assets compromised, whatever it is, that user profile, the limit of, of that user's 215 00:10:33,323 --> 00:10:38,543 profiles, that the access to do other stuff, uh, should mitigate the risk. 216 00:10:39,113 --> 00:10:42,053 And a good example of that is in some environments. 217 00:10:43,103 --> 00:10:47,573 When it resources are limited and we don't have the ability to go fix all 218 00:10:47,573 --> 00:10:53,303 these problems at people's desks, we're giving users, normal users, local 219 00:10:53,303 --> 00:10:55,163 administrator, access to their machine. 220 00:10:55,703 --> 00:10:59,813 Um, and if we're not looking at stuff on the network, like network shares 221 00:10:59,873 --> 00:11:06,143 and who has the ability to do whatever, uh, the exposure there, the risk, uh, 222 00:11:06,143 --> 00:11:09,713 is much greater because you've given those users, those profiles, those 223 00:11:09,713 --> 00:11:11,428 assets, more access than they need. 224 00:11:12,233 --> 00:11:16,283 Well, I think when we start talking about least privilege and and RBAC. 225 00:11:17,228 --> 00:11:23,648 Where this really comes to play is the more privileges that you have as part of 226 00:11:23,648 --> 00:11:28,838 your job, the more RAC and the concept, the least privilege applies, right? 227 00:11:29,108 --> 00:11:33,218 So if you are, you know, back in the day again, you and I have been around a 228 00:11:33,218 --> 00:11:39,458 minute, and back in the day if you, if you were part of the IT team, you got root. 229 00:11:40,058 --> 00:11:40,478 Right. 230 00:11:40,658 --> 00:11:44,138 You got root on all the systems and you could do all the things. 231 00:11:44,258 --> 00:11:48,158 And if you wanted to, if you wanted to blow up Oracle, you logged in as root. 232 00:11:48,338 --> 00:11:49,598 You sued Oracle. 233 00:11:50,258 --> 00:11:52,118 You did stuff in Oracle, right? 234 00:11:52,268 --> 00:11:55,418 You basically were all powerful in the data center. 235 00:11:56,048 --> 00:12:00,188 And I guess what, what I'd like to recommend here is that. 236 00:12:00,668 --> 00:12:05,948 The more power that you're giving to someone and the more powerful that 237 00:12:05,948 --> 00:12:11,438 their role is, the more you should think about this concept of limiting 238 00:12:11,438 --> 00:12:13,388 the privilege that, that they have. 239 00:12:13,658 --> 00:12:14,048 Right? 240 00:12:14,168 --> 00:12:15,878 So you don't give root to everybody. 241 00:12:15,878 --> 00:12:19,118 You don't give the Oracle like, like again, back in the day, you 242 00:12:19,118 --> 00:12:20,918 just gave the Oracle password. 243 00:12:21,443 --> 00:12:24,593 To the person that was going to be in charge of Oracle rather than 244 00:12:24,593 --> 00:12:27,383 forcing them to become themselves. 245 00:12:27,383 --> 00:12:32,303 And then su to, and again, I'm using very eunuchs terms, but, um, you 246 00:12:32,303 --> 00:12:34,283 know, I'm old and that's what we did. 247 00:12:34,673 --> 00:12:37,133 Um, although that still applies. 248 00:12:37,193 --> 00:12:38,993 great responsibility, right? 249 00:12:39,173 --> 00:12:40,253 Yeah, exactly. 250 00:12:40,643 --> 00:12:44,888 Um, persona, I mean, you, you, you, you've dealt with this as well, right? 251 00:12:45,488 --> 00:12:46,418 Oh yeah, yeah. 252 00:12:46,568 --> 00:12:51,158 No, and that's always the case is how do you make sure? 253 00:12:51,158 --> 00:12:53,048 Well, I think it's the trade-off, right? 254 00:12:53,078 --> 00:12:58,118 Because people want easy, seamless access to do things they have to 255 00:12:58,118 --> 00:13:02,198 get done, and they don't always do those operations over and over. 256 00:13:02,198 --> 00:13:06,098 So if you introduce some of these hurdles, it becomes 257 00:13:06,098 --> 00:13:07,598 difficult for them to do things. 258 00:13:08,398 --> 00:13:11,038 At the same time, I totally agree a hundred percent that, 259 00:13:11,038 --> 00:13:14,278 hey, I can't do this anymore. 260 00:13:14,278 --> 00:13:17,398 Like our, I wanna restrict access because it's just too much exposure. 261 00:13:17,998 --> 00:13:22,798 And so really only what you need access to, you should have, so an example 262 00:13:22,798 --> 00:13:25,228 is in the CrowdStrike case, right? 263 00:13:25,288 --> 00:13:27,898 If you look at what the recovery step was, right? 264 00:13:27,898 --> 00:13:31,618 You had to go sort of go to each individual machine, enter their 265 00:13:31,618 --> 00:13:35,818 recovery key before the user could even get to safe mode in order to be 266 00:13:35,818 --> 00:13:37,108 able to try to recover their machine. 267 00:13:37,748 --> 00:13:42,188 And this was, you had to go to every single endpoint and do that, right? 268 00:13:42,698 --> 00:13:47,348 If you said least privilege, and you said, look, as an end user, you should 269 00:13:47,348 --> 00:13:50,678 never have access to this key, right? 270 00:13:50,678 --> 00:13:52,538 Because you never need access to it. 271 00:13:52,598 --> 00:13:56,828 Now you're kind of stuck having an IT person manually go to every 272 00:13:56,828 --> 00:13:58,358 single desk, and there's no sort of 273 00:13:58,748 --> 00:13:59,618 self-help 274 00:14:00,218 --> 00:14:02,198 mitigation, right? 275 00:14:02,198 --> 00:14:04,238 So I think that's why there needs to be a balance, right? 276 00:14:04,238 --> 00:14:06,008 It can't just be one or the other. 277 00:14:06,758 --> 00:14:08,798 It's just like everything else in it. 278 00:14:09,548 --> 00:14:09,968 Right? 279 00:14:09,998 --> 00:14:13,898 It's easier to do it, you know, like you said, it's easier 280 00:14:13,898 --> 00:14:18,338 to give everybody, everybody administrator on their laptop, right? 281 00:14:18,758 --> 00:14:21,578 Um, it's easier to give everybody the recovery key. 282 00:14:21,878 --> 00:14:23,738 It's also riskier to do all of that. 283 00:14:24,578 --> 00:14:25,508 What were you gonna say, Mike? 284 00:14:25,578 --> 00:14:27,623 I, I'll add a couple things. 285 00:14:27,623 --> 00:14:28,733 You're right, it is a balance. 286 00:14:28,733 --> 00:14:31,913 The more security you have, the less usable things are. 287 00:14:32,393 --> 00:14:33,773 Uh, and that's, that's just a. 288 00:14:35,813 --> 00:14:38,663 Balancing act between operations or usability and security. 289 00:14:38,663 --> 00:14:43,373 But, uh, a couple things I'll add and, and this kind of, uh, continues the, 290 00:14:43,373 --> 00:14:45,408 the threads that both of you mentioned. 291 00:14:46,268 --> 00:14:46,488 Um. 292 00:14:47,528 --> 00:14:52,058 Even, even administrators should have a normal non-ad administrator account 293 00:14:52,358 --> 00:14:56,258 for doing normal non-administrative things like checking my email 294 00:14:56,258 --> 00:14:58,448 and writing reports or whatever. 295 00:14:58,448 --> 00:15:00,638 I don't need to be logged in as admin for that. 296 00:15:01,148 --> 00:15:05,258 And it could still be Mike admin, but also have a Mike normal user account. 297 00:15:05,258 --> 00:15:08,768 We want that accountability that, that, that I can attribute 298 00:15:09,218 --> 00:15:11,168 network activity to a user 299 00:15:11,453 --> 00:15:11,663 Yeah. 300 00:15:11,663 --> 00:15:11,933 Can can 301 00:15:12,293 --> 00:15:13,673 I add, can I add on that? 302 00:15:13,763 --> 00:15:14,843 Can I add on that, Mike? 303 00:15:15,263 --> 00:15:20,243 Um, and you should, as a matter of policy and a matter of logging 304 00:15:20,243 --> 00:15:21,773 and monitoring and enforcement, I. 305 00:15:22,688 --> 00:15:28,418 Enforce the idea that you do, you do not ever log in as 306 00:15:28,418 --> 00:15:30,818 administrator or log in as root. 307 00:15:30,968 --> 00:15:36,788 You log in as you, and you become the role that you need that creates logs, 308 00:15:37,058 --> 00:15:38,768 that creates all of these things. 309 00:15:38,978 --> 00:15:42,908 Uh, and that, and that way if anyone ever does log in as administrator 310 00:15:43,088 --> 00:15:47,948 directly, that should be setting off the, the CLS on alerts everywhere, right? 311 00:15:49,208 --> 00:15:51,308 So that goes back to the logging and alerting part. 312 00:15:51,338 --> 00:15:51,818 Um. 313 00:15:52,778 --> 00:15:54,398 And you're right, that's policy. 314 00:15:54,398 --> 00:15:58,778 So you need to have a policy that dictates that privileged users have normal user 315 00:15:58,778 --> 00:16:03,278 accounts and that they, they use those accounts to then gain administrator what, 316 00:16:03,338 --> 00:16:08,138 whether it's their own administrator account or it's pseudo or su to, to 317 00:16:08,138 --> 00:16:10,478 a, uh, an a router admin account. 318 00:16:11,048 --> 00:16:14,798 Uh, the other thing I'll, I'll, I'll contribute is 319 00:16:15,008 --> 00:16:17,798 privileged, privileged access. 320 00:16:18,278 --> 00:16:18,878 Um. 321 00:16:19,253 --> 00:16:21,353 Is often applied to more than just users. 322 00:16:21,353 --> 00:16:23,963 There are service accounts that get privilege. 323 00:16:24,593 --> 00:16:27,053 And so you've really gotta assess whether service accounts 324 00:16:27,053 --> 00:16:28,253 really need that privilege. 325 00:16:28,253 --> 00:16:32,273 And I know a lot of vendors in IT shops will give it that privilege for, for the 326 00:16:32,273 --> 00:16:34,133 ease of deployment and troubleshooting. 327 00:16:34,403 --> 00:16:36,713 Like, it's not gonna be a problem if it's, if it's an admin. 328 00:16:37,223 --> 00:16:40,433 Uh, unfortunately, even, even security tools. 329 00:16:40,493 --> 00:16:45,923 Um, and I think we, we, we, we may have mentioned red teaming at some point when 330 00:16:45,923 --> 00:16:48,053 we, when we red team an organization. 331 00:16:48,398 --> 00:16:52,358 We look at service accounts, and in a lot of cases, those security tools that 332 00:16:52,358 --> 00:16:56,168 are supposed to protect you are also running as a privileged service account. 333 00:16:56,168 --> 00:16:58,808 And in a lot of cases, we're able to actually compromise those 334 00:16:58,808 --> 00:17:02,558 security service accounts in order to compromise the network. 335 00:17:02,688 --> 00:17:04,518 Yeah, we talked, we talked about that. 336 00:17:04,848 --> 00:17:08,418 We talked about those service accounts quite a bit a, a couple episodes ago. 337 00:17:08,868 --> 00:17:09,558 Um, 338 00:17:09,638 --> 00:17:10,868 but that's policy. 339 00:17:10,868 --> 00:17:15,428 Policy needs to dictate that least privilege is, is something that, uh, 340 00:17:15,428 --> 00:17:16,538 needs to be applied to everything. 341 00:17:16,733 --> 00:17:17,903 Yeah, absolutely. 342 00:17:18,323 --> 00:17:20,633 Uh, let's move on to another topic. 343 00:17:20,933 --> 00:17:22,313 Um, least privilege. 344 00:17:22,313 --> 00:17:23,273 Really important. 345 00:17:23,633 --> 00:17:27,203 You know, implement it wherever you can, as much as you can. 346 00:17:27,353 --> 00:17:29,603 There is a balance that you have to have, right? 347 00:17:29,993 --> 00:17:35,093 Um, and I do think that idea of like, you know, administrators need to 348 00:17:35,093 --> 00:17:37,763 have administrator, but they should not be logging in as administrator. 349 00:17:37,763 --> 00:17:39,863 They should have to become administrator. 350 00:17:40,043 --> 00:17:40,643 And I do. 351 00:17:41,243 --> 00:17:47,993 Um, I do very much prefer pseudo to su, uh, because you, you use your password, 352 00:17:47,993 --> 00:17:50,063 right, rather than the, the root password. 353 00:17:50,063 --> 00:17:50,453 Anyway. 354 00:17:50,963 --> 00:17:55,013 Um, let's talk a little bit about network segmentation. 355 00:17:55,403 --> 00:17:57,983 You talked a little bit about laptops. 356 00:17:58,103 --> 00:18:03,173 Um, one of the things, you know, a laptop we can limit to a certain degree 357 00:18:03,173 --> 00:18:05,483 what servers a laptop has access to. 358 00:18:06,008 --> 00:18:13,058 But I think that in, in almost every case, we can put laptops on a 359 00:18:13,058 --> 00:18:17,108 separate network that should never be able to talk to each other. 360 00:18:18,518 --> 00:18:22,148 does a laptop ever need to talk to another laptop directly? 361 00:18:23,483 --> 00:18:25,883 Well, it's it, because it's running windows, first of all. 362 00:18:25,883 --> 00:18:30,383 But, um, their their windows is so chatty when you look at network 363 00:18:30,653 --> 00:18:32,483 analyzers, it's, it's crazy. 364 00:18:32,843 --> 00:18:37,013 But, uh, absolutely you should have a, a, a, like your core 365 00:18:37,013 --> 00:18:38,573 network should be on its own 366 00:18:39,113 --> 00:18:39,773 segment. 367 00:18:40,073 --> 00:18:42,683 Your if, if you have a voiceover IP network that 368 00:18:42,683 --> 00:18:44,123 needs to be on its own segment. 369 00:18:44,513 --> 00:18:47,363 Uh, your backup network, your administration, uh, there's, there are 370 00:18:47,363 --> 00:18:51,863 so many different ways to, to architect your network that can reduce exposure when 371 00:18:51,863 --> 00:18:58,613 there is a problem, because deploying, uh, access control, uh, creating rules around 372 00:18:58,613 --> 00:19:02,933 segments, all that stuff is one console today with the virtual, you know, the, the 373 00:19:02,938 --> 00:19:06,113 interface and a lot of these switches, it's so much, it's so intuitive. 374 00:19:06,533 --> 00:19:08,453 Creating VLANs and all that stuff. 375 00:19:08,453 --> 00:19:14,393 It's, that is one of the best and most timely ways of mitigating 376 00:19:14,423 --> 00:19:19,583 network, uh, network layer, uh, intrusions and, and incidents is se 377 00:19:19,763 --> 00:19:21,683 being able to, you've already got it. 378 00:19:21,743 --> 00:19:22,943 You've already got it set up. 379 00:19:22,973 --> 00:19:25,613 If there's a problem with the, the, the user environment, just 380 00:19:25,613 --> 00:19:27,593 go to your switch and tell it. 381 00:19:27,593 --> 00:19:30,023 They can't talk to anything else for a while until you figure this out. 382 00:19:30,728 --> 00:19:35,648 Uh, so there's a lot of, a lot of very effective and, and, um, timely, uh, 383 00:19:35,648 --> 00:19:39,038 things you can do, uh, once you've implemented, once you've architected 384 00:19:39,038 --> 00:19:40,778 segmentation, the tools are out there. 385 00:19:41,183 --> 00:19:45,318 And Mike, I think, and wanna get your take on this, I guess so. 386 00:19:46,133 --> 00:19:49,793 Segmentation is great, and firewall rules are great only 387 00:19:49,793 --> 00:19:52,973 if you use 'em correctly, right? 388 00:19:52,973 --> 00:19:56,993 Because there are a lot of times where people might say, have a trunk port 389 00:19:56,993 --> 00:20:02,873 passing all the BAN tags across it, which basically defeats the purpose of having 390 00:20:02,873 --> 00:20:06,623 segmentation, especially for end users because you can automatically switch 391 00:20:06,623 --> 00:20:10,163 between different VLANs and now you have access to networks, which you should not. 392 00:20:10,163 --> 00:20:14,603 So just making sure you are using the switches and. 393 00:20:14,973 --> 00:20:18,213 The network configuration and also your firewall rules correctly 394 00:20:18,453 --> 00:20:20,253 is also a big thing as well. 395 00:20:21,053 --> 00:20:23,513 Yeah, you've gotta have a strategy for your architecture. 396 00:20:23,513 --> 00:20:27,353 Implementing parts of this are better than not in most cases, but 397 00:20:27,443 --> 00:20:31,343 implementing segmentation can actually create more overhead if you don't do. 398 00:20:32,228 --> 00:20:35,018 Um, and then, I mean, there's, I, I, I listed a couple. 399 00:20:35,018 --> 00:20:38,588 You could also create a, a segment for your remote access, uh, 400 00:20:38,618 --> 00:20:41,978 users that are calling in over, you know, VPN or what have you. 401 00:20:42,398 --> 00:20:46,748 But, um, the, the idea though, and even other locations, if you've 402 00:20:46,748 --> 00:20:50,948 got different buildings, that those buildings should be on their own segment. 403 00:20:51,428 --> 00:20:54,728 Uh, if, if you're running like an MPLS or internal, uh. 404 00:20:55,838 --> 00:20:57,158 Networking scheme for that, 405 00:20:57,458 --> 00:21:02,258 but the idea then is making sure you have a good understanding of how your network 406 00:21:02,258 --> 00:21:05,408 operates and how it supports the business so that you can configure that right. 407 00:21:05,723 --> 00:21:09,473 On a previous episode, actually, I think it's the one that went live just 408 00:21:09,473 --> 00:21:12,503 this week, um, in recording World. 409 00:21:12,503 --> 00:21:13,973 It's, it's, it's different. 410 00:21:14,273 --> 00:21:15,533 It's different on the episode world. 411 00:21:15,863 --> 00:21:21,293 But, um, you know, one of the things that I harp against a lot is RDP, right? 412 00:21:21,623 --> 00:21:24,323 Uh, which I call the ransomware deployment Protocol. 413 00:21:24,683 --> 00:21:30,713 Um, and if, if you are going to enable RDP, I think RDP should be on its own 414 00:21:30,713 --> 00:21:36,533 segment, that in order to use RDP, you must be either physically present. 415 00:21:36,908 --> 00:21:41,828 In a particular place, or you need to be VPNing in, uh, to that, that you should 416 00:21:41,828 --> 00:21:46,148 not be able, you should not have RDP on, on every server and have that rd have 417 00:21:46,148 --> 00:21:48,458 those RDP ports accessible everywhere. 418 00:21:48,788 --> 00:21:49,178 Right. 419 00:21:49,268 --> 00:21:52,448 Um, that's another, can you think of anything else like that, that 420 00:21:52,448 --> 00:21:54,518 we would really wanna segment off? 421 00:21:59,768 --> 00:22:03,068 man, I can, I can, I can probably spend the, the rest of the 422 00:22:03,068 --> 00:22:05,018 day, uh, talking scenarios. 423 00:22:05,018 --> 00:22:08,498 But the important thing, the important thing to do is assess the 424 00:22:08,498 --> 00:22:12,368 way your environment operates, the things that you use to support your 425 00:22:12,368 --> 00:22:14,318 environment, your users and the company. 426 00:22:14,678 --> 00:22:19,298 And then what, what I'm gonna say, what risks are associated with that? 427 00:22:19,298 --> 00:22:23,318 Like RDP, if you don't have it configured well, all that traffic is unencrypted. 428 00:22:23,858 --> 00:22:27,938 Uh, if, if, you know, so are there other tools you're using? 429 00:22:28,508 --> 00:22:30,308 Uh, and, and how are those configured? 430 00:22:30,308 --> 00:22:36,278 Like Service Desk or, uh, ninja, RAMM or, or some of these others if those 431 00:22:36,278 --> 00:22:41,048 are great tools, but if the endpoints are con, are configured to auto answer 432 00:22:41,288 --> 00:22:45,008 without user interaction and putting in a token and all that stuff, that's a risk. 433 00:22:45,668 --> 00:22:51,308 And that's, so that's an example of look at the tools you're using and. 434 00:22:51,938 --> 00:22:53,798 Can we use, can we use them secure? 435 00:22:53,798 --> 00:22:55,598 And if not, are there, is there an alternative? 436 00:22:55,628 --> 00:22:59,708 And like there are alternatives to RDP that are low or no cost, that 437 00:22:59,708 --> 00:23:01,508 are more secure and effective. 438 00:23:01,898 --> 00:23:04,208 They're just not as, they're not easy. 439 00:23:04,268 --> 00:23:06,188 They're, they don't come with the operating system. 440 00:23:06,188 --> 00:23:06,548 So there's 441 00:23:06,548 --> 00:23:08,948 a, there's a, there's a list there of there deployment 442 00:23:08,948 --> 00:23:10,388 and configuration to use it. 443 00:23:10,928 --> 00:23:13,778 Uh, that, you know, maybe some organizations don't have 444 00:23:13,778 --> 00:23:15,218 the time or resources to, 445 00:23:15,263 --> 00:23:15,503 Yeah. 446 00:23:15,503 --> 00:23:16,943 Or, or once again, money. 447 00:23:17,033 --> 00:23:20,453 It's like everything else that, you know, the good tools cost money, right? 448 00:23:21,083 --> 00:23:21,623 Um. 449 00:23:22,583 --> 00:23:25,643 One other thing I was gonna add to what you were saying, Mike, is for some of 450 00:23:25,643 --> 00:23:29,273 these vendors, maybe it's worthwhile to see, do they have like white papers 451 00:23:29,273 --> 00:23:35,243 or knowledge, uh, based articles on how to actually set these up securely, 452 00:23:35,668 --> 00:23:36,088 Mm-Hmm. 453 00:23:36,413 --> 00:23:36,713 right. 454 00:23:36,713 --> 00:23:38,693 Or best practices to 455 00:23:39,053 --> 00:23:39,443 and I, I 456 00:23:39,443 --> 00:23:42,503 know, and, and you're right there usually is because that's just 457 00:23:42,503 --> 00:23:46,193 gonna help them, uh, you know, distribute and market their product. 458 00:23:46,703 --> 00:23:51,983 I know a lot of organizations that are using AI to ask those questions, like, 459 00:23:51,983 --> 00:23:55,253 how, what's a good way to, what's a good alternative to RDP or what have you? 460 00:23:55,883 --> 00:24:00,533 And I'm gonna, I'm gonna, uh, suggest that people be conscious that when 461 00:24:00,533 --> 00:24:03,833 you ask the questions in a public domain, they become public knowledge. 462 00:24:03,863 --> 00:24:06,893 And if I can trace that back to who asked the question, now I know the 463 00:24:06,893 --> 00:24:08,363 technologies you might be using. 464 00:24:08,903 --> 00:24:11,933 Um, and, but also not to trust AI on face value. 465 00:24:11,933 --> 00:24:13,283 Still do your own research. 466 00:24:13,283 --> 00:24:14,813 In fact, finding all that good stuff. 467 00:24:15,238 --> 00:24:18,243 Are you saying AI's not perfect, Mike? 468 00:24:18,308 --> 00:24:19,058 is not perfect. 469 00:24:20,468 --> 00:24:21,038 It's almo. 470 00:24:21,038 --> 00:24:22,688 AI is almost intelligent. 471 00:24:23,968 --> 00:24:24,898 Almost intelligent. 472 00:24:25,048 --> 00:24:25,708 I like that. 473 00:24:26,278 --> 00:24:30,478 The key, the key is the board of artificial, um, that I saw 474 00:24:30,478 --> 00:24:33,178 a meme yesterday and it was a, it was a picture of, um. 475 00:24:34,268 --> 00:24:38,918 What's the, what's the, the, the guy, the young man that comes back 476 00:24:38,918 --> 00:24:40,628 in time to stop the Terminator? 477 00:24:40,628 --> 00:24:41,108 What's his name? 478 00:24:41,198 --> 00:24:43,898 Um, what's the character's name? 479 00:24:45,908 --> 00:24:47,918 No, the, the, the guy that comes back. 480 00:24:47,918 --> 00:24:52,028 The son, the guy that battles all the terminators. 481 00:24:53,483 --> 00:24:54,463 Why can't I think of him? 482 00:24:54,933 --> 00:24:56,738 Yeah, we know who you're talking about though. 483 00:24:56,943 --> 00:24:57,873 Mike Connors. 484 00:24:57,878 --> 00:25:00,368 Mike, Mike Connors and that his name Mike Connors. 485 00:25:01,568 --> 00:25:04,388 Anyway, and he is like, it's like it's a picture of him, like giving 486 00:25:04,388 --> 00:25:09,428 side eye and it's like Mike Connor's watching all of you people befriend ai. 487 00:25:12,088 --> 00:25:12,378 Nice. 488 00:25:13,538 --> 00:25:17,498 Um, all right, so let's talk about a third topic, and that 489 00:25:17,558 --> 00:25:21,488 is, again, this is all under the concept of minimizing blast radius. 490 00:25:22,163 --> 00:25:26,153 One of the things, so, you know, we, we talk on this, on this podcast, we talk 491 00:25:26,153 --> 00:25:28,433 a lot about backup and recovery and DR. 492 00:25:28,433 --> 00:25:32,303 And making sure that you, you have a copy of your data and having it 493 00:25:32,303 --> 00:25:37,913 in a place that is, is blocked from, from, um, uh, you know, access. 494 00:25:37,973 --> 00:25:40,583 You know, so that if, if you do get attacked or when you get 495 00:25:40,583 --> 00:25:44,693 attacked, the, the hackers won't be able to also delete your backups. 496 00:25:45,923 --> 00:25:48,863 Having said that, none of that will help you. 497 00:25:49,343 --> 00:25:53,783 If your data is stolen, right, if your data is exfiltrated. 498 00:25:53,813 --> 00:26:01,343 So the thing that I think people are not spending enough time on is doing what 499 00:26:01,343 --> 00:26:08,033 they can to stop the uploading of their data, um, you know, to, uh, the world. 500 00:26:08,363 --> 00:26:14,783 And we, we, there's a really good episode, uh, of ours back when we had, um, uh, 501 00:26:14,813 --> 00:26:18,053 Dwayne from, uh, the red teaming group. 502 00:26:18,413 --> 00:26:22,223 That where, where he talked a lot about, you know, he talked about 503 00:26:22,223 --> 00:26:27,833 how that actually generally people aren't, the hackers aren't using like 504 00:26:28,133 --> 00:26:30,653 the web, they're just going directly. 505 00:26:30,953 --> 00:26:34,943 They're just, you know, copying the data directly to where they want to 506 00:26:34,943 --> 00:26:40,883 store it because, and this is the crazy thing, no one is stopping them right. 507 00:26:41,828 --> 00:26:46,028 They know that the web traffic is being monitored, and so they don't use that. 508 00:26:46,448 --> 00:26:50,528 And, and he had this analogy, he goes, it's like we're in this wide open field 509 00:26:50,978 --> 00:26:55,688 and the web is like a door in the middle of this field and that door is locked. 510 00:26:55,958 --> 00:26:58,988 So it's like, oh, darn, there's a door here. 511 00:26:59,108 --> 00:27:00,218 We can't use it. 512 00:27:00,788 --> 00:27:03,188 Oh, maybe we'll just go around the door. 513 00:27:03,368 --> 00:27:03,668 Right? 514 00:27:03,668 --> 00:27:05,078 We'll, all these other ways. 515 00:27:05,258 --> 00:27:08,918 So it, it came as a surprise to me, and I guess it shouldn't. 516 00:27:09,398 --> 00:27:13,538 Because historically we didn't limit outgoing traffic. 517 00:27:14,108 --> 00:27:20,228 Uh, and so, you know, what do you think about this idea of basically blocking 518 00:27:20,228 --> 00:27:25,988 everything that's going out and only limiting what should be going out, which 519 00:27:25,988 --> 00:27:30,848 is the, the complete opposite of the way most networks currently are configured. 520 00:27:30,848 --> 00:27:31,763 What do you think about that idea? 521 00:27:33,773 --> 00:27:37,778 I think it's a beautiful idea, but it would take a lot of analysis. 522 00:27:38,303 --> 00:27:41,933 That, uh, most organizations don't, don't go through. 523 00:27:41,963 --> 00:27:43,943 So what, what is normal? 524 00:27:43,943 --> 00:27:45,023 What is allowed? 525 00:27:45,533 --> 00:27:46,613 Uh, where's it coming from? 526 00:27:46,613 --> 00:27:47,723 Where's it going to? 527 00:27:47,783 --> 00:27:51,503 How much volume should I be, uh, considering as normal? 528 00:27:52,043 --> 00:27:54,743 Uh, what ports do, does that data go out? 529 00:27:54,773 --> 00:27:55,703 Uh, what protocol? 530 00:27:55,763 --> 00:27:56,723 All those things, 531 00:27:57,143 --> 00:27:57,653 uh, 532 00:27:57,773 --> 00:27:58,103 talked 533 00:27:58,193 --> 00:27:58,793 can be done. 534 00:27:58,883 --> 00:28:01,613 on your firewalls on observe mode. 535 00:28:02,333 --> 00:28:07,433 Um, first for like a month just to see what actual outgoing traffic. 536 00:28:07,763 --> 00:28:12,383 Uh, and he did tell the story that when they were advising a customer of 537 00:28:12,383 --> 00:28:15,713 this and they turned on their firewall and observe mode, they found out 538 00:28:15,713 --> 00:28:19,733 they were in the middle of an actual attack, um, during the observe mode. 539 00:28:20,273 --> 00:28:23,123 Um, but yeah, that you definitely have to. 540 00:28:24,398 --> 00:28:25,748 You can do a lot of damage. 541 00:28:25,748 --> 00:28:28,538 And I, you know, and I have a story that I've told a lot of times on the 542 00:28:28,538 --> 00:28:32,888 podcast of me working in an environment where they, they blocked everything 543 00:28:32,948 --> 00:28:38,108 and the, the amount of hassle that was to me as a, so here I was, I was the 544 00:28:38,108 --> 00:28:43,748 o they had a very segmented network that server A could not talk to server 545 00:28:43,748 --> 00:28:46,178 B it was, it's, it was properly done. 546 00:28:46,268 --> 00:28:49,988 And this is 25 years ago, so this is really impressive, but. 547 00:28:50,588 --> 00:28:54,158 When me, the crazy man came in and I wanted to do this thing 548 00:28:54,158 --> 00:28:57,818 called backups, and I needed a server to be able to talk to every 549 00:28:57,818 --> 00:28:59,438 other server that blew their mind. 550 00:28:59,438 --> 00:29:03,458 And, and they hated me from day one, and they did a lot of damage to my 551 00:29:03,458 --> 00:29:05,918 ability to do my job, uh, in the process. 552 00:29:05,918 --> 00:29:10,628 So, you know, it has to get their job done, but I, I do think this is 553 00:29:10,628 --> 00:29:12,248 something that you should entertain. 554 00:29:12,848 --> 00:29:16,868 Uh, and I do like this idea of turning on the, the firewall and, and observe mode. 555 00:29:16,868 --> 00:29:17,768 What do you think persona. 556 00:29:18,968 --> 00:29:20,678 I think that's worthwhile. 557 00:29:20,678 --> 00:29:25,988 I think also with sort of some of the, uh, blacklists that are out there, 558 00:29:25,988 --> 00:29:30,788 for instance, you could also be using DNS blacklists and other things like 559 00:29:30,788 --> 00:29:37,598 that to also help filter out some of the common websites or IP addresses, 560 00:29:37,598 --> 00:29:39,608 which have a bad reputation, right? 561 00:29:39,608 --> 00:29:42,608 There's also the reputation score out there, right? 562 00:29:42,608 --> 00:29:45,403 So you can look at some of these and apply them and. 563 00:29:46,373 --> 00:29:50,393 Not necessarily gonna prevent every anyone from trying to get to legitimate 564 00:29:50,393 --> 00:29:53,873 websites, because even in those 30 days when you're running firewall and observe 565 00:29:53,873 --> 00:29:58,763 mode, maybe it's seasonality and I don't go look at certain websites or do certain 566 00:29:58,763 --> 00:30:00,413 things until like the quarter end. 567 00:30:00,413 --> 00:30:03,863 So you're not impacting the business, but at least you're trying to prevent 568 00:30:03,863 --> 00:30:06,293 a lot of the malicious traffic. 569 00:30:06,943 --> 00:30:12,373 He, he did also talk about blocking, uh, things like S-S-H-S-C-P. 570 00:30:12,823 --> 00:30:18,613 Um, he's like, ask yourself, when would we ever, is there a scenario in which 571 00:30:18,613 --> 00:30:24,973 we as admins would ever need to SSH to the outside, outside of our network? 572 00:30:25,303 --> 00:30:29,143 And if the answer is, we can't think of one, then turn SSH off 573 00:30:29,578 --> 00:30:30,503 Or FTT. 574 00:30:30,943 --> 00:30:33,763 or ftp, similar protocols, right. 575 00:30:34,163 --> 00:30:37,013 Um, outgoing, specifically outgoing, FTP. 576 00:30:37,013 --> 00:30:37,373 Right. 577 00:30:37,943 --> 00:30:42,023 Um, can you think of other things like that, Mike, that, that we 578 00:30:42,023 --> 00:30:43,403 might wanna block going out? 579 00:30:45,148 --> 00:30:47,638 Uh, encrypted traffic over your DNS port. 580 00:30:48,998 --> 00:30:50,108 That did come up, I think. 581 00:30:50,378 --> 00:30:50,738 Yep. 582 00:30:51,413 --> 00:30:51,683 Yeah. 583 00:30:51,688 --> 00:30:54,958 that's a good exfil, that's a good xFi port and tactic. 584 00:30:55,108 --> 00:30:55,648 Um, 585 00:30:56,008 --> 00:30:56,488 but then 586 00:30:56,573 --> 00:30:57,323 wanna, explain that? 587 00:30:57,323 --> 00:30:59,363 I know what you mean, uh, Mike, but do you wanna explain that 588 00:31:00,893 --> 00:31:03,143 So it's a port that's usually not monitored. 589 00:31:03,293 --> 00:31:05,483 Uh, it's never, it's never blocked. 590 00:31:05,488 --> 00:31:07,193 You, you, you, you have to have it. 591 00:31:07,673 --> 00:31:10,823 Um, so we don't monitor the DNS port on the firewall. 592 00:31:10,913 --> 00:31:17,153 Um, and bad guys know this, so we're, to your point about web traffic and encrypted 593 00:31:17,153 --> 00:31:22,673 traffic and these other services like SSH and FTP, those run on specific ports. 594 00:31:22,673 --> 00:31:25,703 And so if, if I'm concerned about someone. 595 00:31:26,738 --> 00:31:29,858 Uh, creating a connection outbound that can upload files. 596 00:31:29,858 --> 00:31:33,968 I'm looking at Port 21 and the SSH port SSH port. 597 00:31:33,968 --> 00:31:38,588 But very rarely do we monitor the DNS port and so back and, and 598 00:31:38,588 --> 00:31:39,608 there's a couple things there. 599 00:31:39,608 --> 00:31:42,578 One, uh, very low traffic on that port. 600 00:31:43,253 --> 00:31:48,173 And so we could simply look for any increase, you know, abnormal 601 00:31:48,173 --> 00:31:49,763 traffic volume on that port. 602 00:31:49,763 --> 00:31:51,113 That should be clue number one. 603 00:31:51,443 --> 00:31:53,663 And then clue number two, uh, bad guys. 604 00:31:53,693 --> 00:31:56,423 You know, when we, when we expel data off, uh, through that 605 00:31:56,423 --> 00:31:57,713 port, we typically encrypt it. 606 00:31:57,713 --> 00:32:00,713 So you don't know what we're, what we're stealing. 607 00:32:00,953 --> 00:32:05,723 And so encrypted traffic over that port at, at, at any level should be suspicious. 608 00:32:06,323 --> 00:32:07,583 Um, so yeah. 609 00:32:07,613 --> 00:32:10,223 And this goes back to understanding your business, what, and 610 00:32:10,223 --> 00:32:11,963 whether it's the, the firewall. 611 00:32:12,308 --> 00:32:16,718 Uh, you know, observe mode, uh, or just simple understanding of the different 612 00:32:16,718 --> 00:32:20,348 applications and ways that users interact and data flow and all that 613 00:32:20,348 --> 00:32:24,398 stuff that'll help you determine what can be turned off, blocked, uninstalled, 614 00:32:24,488 --> 00:32:27,038 monitored, uh, that kind of thing. 615 00:32:27,458 --> 00:32:31,118 Uh, and along those lines, and, and, and persona touched on this 616 00:32:31,118 --> 00:32:34,868 with the, the known bad IP lists. 617 00:32:35,423 --> 00:32:39,983 Um, so those are good, but you know, you might have a handful of bad ips 618 00:32:39,983 --> 00:32:41,873 in a geographic area of the world. 619 00:32:42,203 --> 00:32:46,043 Well, if your, again, if your business doesn't do, if, if your 620 00:32:46,043 --> 00:32:48,743 business doesn't care about traffic from that part of the world, just 621 00:32:48,743 --> 00:32:51,413 block that entire geo IP subnet. 622 00:32:52,013 --> 00:32:53,603 Uh, and that'll do two things. 623 00:32:53,603 --> 00:32:55,793 One, uh, or several things. 624 00:32:55,793 --> 00:33:00,083 One, uh, you're not gonna get direct traffic from that part of the world. 625 00:33:00,083 --> 00:33:02,513 You don't care about whether it's malicious or unintentional, 626 00:33:02,513 --> 00:33:03,593 and that should reduce. 627 00:33:04,058 --> 00:33:08,378 Overhead on your firewall, but it'll also limit, um, at least 628 00:33:08,378 --> 00:33:12,038 the direct attack exposure, uh, from, from that part of the world. 629 00:33:12,168 --> 00:33:12,468 Yeah. 630 00:33:12,468 --> 00:33:16,638 I remember a long time ago me deciding that I didn't need any web browsers 631 00:33:16,638 --> 00:33:19,218 from, uh, customers from uh, Russia. 632 00:33:19,608 --> 00:33:20,623 I remember deciding that. 633 00:33:21,288 --> 00:33:22,218 A long time ago. 634 00:33:22,608 --> 00:33:26,178 Um, yeah, this, this reminds me, you know, I'm gonna draw an 635 00:33:26,178 --> 00:33:28,788 analogy to pre nine 11, right? 636 00:33:28,878 --> 00:33:36,618 Um, the idea of the idea that the attackers used the planes. 637 00:33:37,103 --> 00:33:42,233 As the weapons themselves was a new idea at the time. 638 00:33:42,533 --> 00:33:47,843 This is a new idea that we never really had to think about exfiltration 639 00:33:47,843 --> 00:33:50,543 really as the problem itself. 640 00:33:50,543 --> 00:33:55,433 And so I'm just saying to me it's the one problem that you can't. 641 00:33:56,258 --> 00:33:56,918 Stop. 642 00:33:56,948 --> 00:33:57,278 Right? 643 00:33:57,278 --> 00:33:58,568 I'm not, let me rephrase that. 644 00:33:58,988 --> 00:34:02,378 If you, if you experience it, if they download your data, 645 00:34:02,678 --> 00:34:03,938 there's nothing you can do. 646 00:34:03,938 --> 00:34:08,288 You're going to either pay the ransom or take the hit the pr hit of whatever it 647 00:34:08,288 --> 00:34:09,788 is that's gonna happen to your company. 648 00:34:10,328 --> 00:34:14,348 And which is why I remember asking you, um, you know, the, the degree 649 00:34:14,348 --> 00:34:16,958 of people that, or the percentage of people that pay the ransom. 650 00:34:16,958 --> 00:34:20,323 And one of the first things you said was if they did exfiltration. 651 00:34:21,203 --> 00:34:23,393 Generally speaking, they're gonna end up paying the ransom. 652 00:34:23,753 --> 00:34:27,683 And so I guess all I'm saying is it's time to have that conversation. 653 00:34:28,043 --> 00:34:32,933 Maybe you do some of these things, maybe you block known bad IP addresses. 654 00:34:32,933 --> 00:34:38,843 Maybe you, maybe you start blocking, um, you know, uh, outgoing, uh, 655 00:34:39,023 --> 00:34:44,333 SSH and SCP and FDP, uh, any of the file transfer type protocols. 656 00:34:45,023 --> 00:34:49,613 Um, and maybe you consider, at least consider, run your firewall and observe 657 00:34:49,613 --> 00:34:54,083 mode to see what kind of outgoing traffic that you normally have, and 658 00:34:54,083 --> 00:34:57,623 then maybe if you want to take it to the next level, do the, the best thing 659 00:34:57,683 --> 00:34:59,393 again, good, better, best, right? 660 00:34:59,783 --> 00:35:03,443 The best thing would be to block all outgoing traffic, except for 661 00:35:03,773 --> 00:35:05,843 the, you know, the stuff, but yes. 662 00:35:05,993 --> 00:35:08,813 You know, your initial response to that is a hundred percent true. 663 00:35:09,503 --> 00:35:12,233 It's gonna take you a minute to accomplish that, 664 00:35:12,923 --> 00:35:13,253 right? 665 00:35:13,328 --> 00:35:14,558 Well, and just imagine 666 00:35:14,588 --> 00:35:16,358 piss off some people in the process. 667 00:35:16,418 --> 00:35:16,928 What's that? 668 00:35:17,138 --> 00:35:19,028 And just imagine the end users like Curtis. 669 00:35:19,058 --> 00:35:22,658 Imagine if at home you blocked all outgoing traffic, 670 00:35:23,348 --> 00:35:23,738 Yeah, 671 00:35:24,548 --> 00:35:24,938 right? 672 00:35:25,298 --> 00:35:26,858 Imagine what? 673 00:35:26,873 --> 00:35:27,473 Help desk. 674 00:35:28,538 --> 00:35:29,078 Yes. 675 00:35:29,078 --> 00:35:29,138 I. 676 00:35:31,253 --> 00:35:31,743 exactly. 677 00:35:32,483 --> 00:35:33,158 Uh, the um. 678 00:35:36,218 --> 00:35:38,678 Uh, I can imagine that very much. 679 00:35:39,128 --> 00:35:42,698 Um, well, it's been another great conversation. 680 00:35:42,788 --> 00:35:46,508 Um, I, I hope that folks got some ideas about ways that they 681 00:35:46,508 --> 00:35:48,338 can minimize the blast radius. 682 00:35:48,488 --> 00:35:52,988 And, um, this is our part of our continuing, uh, series here 683 00:35:52,988 --> 00:35:55,418 about, uh, defeating ransomware. 684 00:35:55,658 --> 00:35:57,038 Thanks again, Mike. 685 00:35:58,808 --> 00:35:59,228 You are welcome. 686 00:36:00,218 --> 00:36:01,628 And, uh, thanks again, prana. 687 00:36:02,528 --> 00:36:03,638 No, this was fun. 688 00:36:03,638 --> 00:36:07,388 And Mike, I'm glad that there's someone who understands networking because 689 00:36:07,388 --> 00:36:09,938 whenever I talk about networking with Curtis, it sort of just like 690 00:36:10,508 --> 00:36:11,288 goes over his head. 691 00:36:11,303 --> 00:36:12,173 stop. 692 00:36:13,073 --> 00:36:13,343 you're 693 00:36:13,568 --> 00:36:14,323 But I love you, Curtis. 694 00:36:14,603 --> 00:36:15,503 sometimes. 695 00:36:15,503 --> 00:36:16,523 You're mean pana. 696 00:36:17,093 --> 00:36:18,353 Thank goodness for me. 697 00:36:18,413 --> 00:36:20,303 I have our lovely listeners. 698 00:36:20,573 --> 00:36:21,413 We love you guys. 699 00:36:21,713 --> 00:36:22,103 Thanks. 700 00:36:22,103 --> 00:36:23,243 Uh, thanks. 701 00:36:23,483 --> 00:36:24,143 Uh. 702 00:36:24,458 --> 00:36:27,368 For, uh, being there at least I think you're there. 703 00:36:27,518 --> 00:36:28,868 The numbers say you're there. 704 00:36:29,108 --> 00:36:30,788 So, uh, thanks for being there. 705 00:36:30,968 --> 00:36:31,933 That is a wrap.