0% found this document useful (0 votes)
21 views26 pages

Security Baselines and Hardening Techniques

The document outlines best practices for securing application environments, including establishing and maintaining secure baselines, hardening various targets like servers and mobile devices, and implementing effective wireless security measures. It emphasizes the importance of constant updates, input validation, and secure coding practices, as well as asset management strategies such as tracking and data retention. Additionally, it discusses the significance of using proper authentication methods and monitoring for vulnerabilities in applications.

Uploaded by

asgv1997
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views26 pages

Security Baselines and Hardening Techniques

The document outlines best practices for securing application environments, including establishing and maintaining secure baselines, hardening various targets like servers and mobile devices, and implementing effective wireless security measures. It emphasizes the importance of constant updates, input validation, and secure coding practices, as well as asset management strategies such as tracking and data retention. Additionally, it discusses the significance of using proper authentication methods and monitoring for vulnerabilities in applications.

Uploaded by

asgv1997
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

4.

1 - Secure Baselines
Secure baselines Deploy baselines
• The security of an application environment should be • We now have established detailed security baselines
well defined – How do we put those baselines into action?
– All application instances must follow this baseline • Deploy the baselines
– Firewall settings, patch levels, OS file versions – Usually managed through a centrally
– May require constant updates administered console
• Integrity measurements check for the secure baseline • May require multiple deployment mechanisms
– These should be performed often – Active Directory group policy, MDM, etc.
– Check against well-documented baselines • Automation is the key
– Failure requires an immediate correction – Deploy to hundreds or thousands of devices
Establish baselines Maintain baselines
• Create a series of baselines • Many of these are best practices
– Foundational security policies – They rarely change
• Security baselines are often available from the • Other baselines may require ongoing updates
manufacturer – A new vulnerability is discovered
– Application developer – An updated application has been deployed
– Operating system manufacturer – A new operating system is installed
– Appliance manufacturer
• Test and measure to avoid conflicts
• Many operating systems have extensive options – Some baselines may contradict others
– There are over 3,000 group policy settings in Windows 10 – Enterprise environments are complex
– Only some of those are associated with security

4.1 - Hardening Targets


Hardening targets Network infrastructure devices
• No system is secure with the default configurations • Switches, routers, etc.
– You need some guidelines to keep everything safe – You never see them, but they’re always there
• Hardening guides are specific to the software or • Purpose-built devices
platform – Embedded OS, limited OS access
– Get feedback from the manufacturer or • Configure authentication
Internet interest group – Don’t use the defaults
– They’ll have the best details • Check with the manufacturer
• Other general-purpose guides are available online – Security updates
Mobile devices – Not usually updated frequently
• Always-connected mobile technologies – Updates are usually important
– Phones, tablets, etc. Cloud infrastructure
– Hardening checklists are available from manufacturers • Secure the cloud management workstation
• Updates are critical – The keys to the kingdom
– Bug fixes and security patches • Least privilege
– Prevent any known vulnerabilities – All services, network settings, application rights
• Segmentation can protect data and permissions
– Company and user data are separated • Configure Endpoint Detection and Response (EDR)
• Control with an MDM - Mobile Device Manager – All devices accessing the cloud should be secure
Workstations • Always have backups
• User desktops and laptops - Windows, macOS, Linux, etc. – Cloud to Cloud (C2C)
• Constant monitoring and updates
– Operating systems, applications, firmware, etc.
• Automate the monthly patches
– There’s likely an existing process
• Connect to a policy management system
– Active Directory group policy
• Remove unnecessary software - Limit the threats
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 59 [Link]
4.1 - Hardening Targets (continued)
Servers • Can be difficult to upgrade
• Many and varied – Watches and televisions are relatively easy
– Windows, Linux, iOS, Android, etc. – Other devices may not be easily modified
• Updates • Correct vulnerabilities
– Operating system updates/service packs, – Security patches remove potential threats
security patches • Segment and firewall
• User accounts – Prevent access from unauthorized users
– Minimum password lengths and complexity RTOS (Real-Time Operating System)
– Account limitations • An operating system with a deterministic processing
• Network access and security schedule
– Limit network access – No time to wait for other processes
• Monitor and secure – Industrial equipment, automobiles, military
– Anti-virus, anti-malware environments
SCADA / ICS • Isolate the system
• Supervisory Control and Data Acquisition System – Prevent access from other areas
– Large-scale, multi-site Industrial Control Systems (ICS) • Run with the minimum services
• PC manages equipment – Prevent the potential for exploit
– Power generation, refining, manufacturing equipment • Use secure communication
– Facilities, industrial, energy, logistics – Protect with a host-based firewall
• Distributed control systems IoT devices
– Real-time information • Heating and cooling, lighting, home automation,
– System control wearable technology, etc.
• Requires extensive segmentation • Weak defaults
– No access from the outside – IOT manufacturers are not security professionals
Embedded systems – Change those passwords
• Hardware and software designed for a • Deploy updates quickly
specific function – Can be a significant security concern
– Or to operate as part of a larger system • Segmentation - Put IoT devices on their own VLAN

4.1 - Securing Wireless and Mobile


Site surveys Mobile Device Management (MDM)
• Determine existing wireless landscape • Manage company-owned and user-owned mobile devices
– Sample the existing wireless spectrum – BYOD - Bring Your Own Device
• Identify existing access points • Centralized management of the mobile devices
– You may not control all of them – Specialized functionality
• Work around existing frequencies • Set policies on apps, data, camera, etc.
– Layout and plan for interference – Control the remote device
• Plan for ongoing site surveys – The entire device or a “partition”
– Things will certainly change • Manage access control
• Heat maps – Force screen locks and PINs on these single user devices
– Identify wireless signal strengths BYOD
Wireless survey tools • Bring Your Own Device
• Signal coverage – Bring Your Own Technology
• Potential interference • Employee owns the device
• Built-in tools – Need to meet the company’s requirements
• 3rd-party tools • Difficult to secure
– It’s both a home device and a work device
• Spectrum analyzer
– How is data protected?
– What happens to the data when a device is sold or
traded in?
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 60 [Link]
4.1 - Securing Wireless and Mobile (continued)
COPE Wi-Fi
• Corporate owned, personally enabled • Local network access
– Company buys the device – Local security problems
– Used as both a corporate device and a personal device • Same security concerns as other Wi-Fi devices
• Organization keeps full control of the device • Data capture
– Similar to company-owned laptops and desktops – Encrypt your data!
– Information is protected using corporate policies • On-path attack
– Information can be deleted at any time – Modify and/or monitor data
• CYOD - Choose Your Own Device • Denial of service
– Similar to COPE, but with the user’s choice of device – Frequency interference
Cellular networks Bluetooth
• Mobile devices • High speed communication over short distances
– “Cell” phones – PAN (Personal Area Network)
– 4G, 5G • Connects our mobile devices
• Separate land into “cells” – Smartphones
– Antenna coverages a cell with certain frequencies – Tethering
• Security concerns – Headsets and headphones
– Traffic monitoring – Health monitors
– Location tracking – Automobile and phone integration
– Worldwide access to a mobile device – Smartwatches
– External speakers
4.1 - Wireless Security Settings
Securing a wireless network WPA3 and GCMP
• An organization’s wireless network can contain • Wi-Fi Protected Access 3 (WPA3)
confidential information – Introduced in 2018
– Not everyone is allowed access • GCMP block cipher mode
• Authenticate the users before granting access – Galois/Counter Mode Protocol
– Who gets access to the wireless network? – A stronger encryption than WPA2
– Username, password, multi-factor authentication • GCMP security services
• Ensure that all communication is confidential – Data confidentiality with AES
– Encrypt the wireless data – Message Integrity Check (MIC) with
• Verify the integrity of all communication – Galois Message Authentication Code (GMAC)
– The received data should be identical to the original SAE
sent data • WPA3 changes the PSK authentication process
– A message integrity check (MIC) – Includes mutual authentication
The WPA2 PSK problem – Creates a shared session key without sending that
• WPA2 has a PSK brute-force problem key across the network
– Listen to the four-way handshake – No more four-way handshakes, no hashes, no
– Some methods can derive the PSK hash without the brute force attacks
handshake • Simultaneous Authentication of Equals (SAE)
– Capture the hash – A Diffie-Hellman derived key exchange with an
• With the hash, attackers can brute force the authentication component
pre-shared key (PSK) – Everyone uses a different session key, even with
• This has become easier as technology improves the same PSK
– A weak PSK is easier to brute force – An IEEE standard - the dragonfly handshake
– GPU processing speeds
– Cloud-based password cracking
• Once you have the PSK, you have everyone’s wireless
key
– There’s no forward secrecy

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 61 [Link]
4.1 - Wireless Security Settings (continued)
Wireless authentication methods RADIUS (Remote Authentication Dial-in User Service)
• Gain access to a wireless network • One of the more common AAA protocols
– Mobile users, temporary users – Supported on a wide variety of platforms and devices
• Credentials – Not just for dial-in
– Shared password / pre-shared key (PSK) • Centralize authentication for users
– Centralized authentication (802.1X) – Routers, switches, firewalls
• Configuration – Server authentication
– Part of the wireless network connection – Remote VPN access
– Prompted during the connection process – 802.1X network access
Wireless security modes • RADIUS services available on almost any server
• Configure the authentication on your wireless access operating system
point / wireless router IEEE 802.1X
• Open System • Port-based Network Access Control (NAC)
– No authentication password is required – You don’t get access to the network until you
• WPA3-Personal / WPA3-PSK authenticate
– WPA2 or WPA3 with a pre-shared key • Used in conjunction with an access database
– Everyone uses the same 256-bit key – RADIUS, LDAP, TACACS+
• WPA3-Enterprise / WPA3-802.1X EAP
– Authenticates users individually with an • Extensible Authentication Protocol (EAP)
authentication server (i.e., RADIUS) – An authentication framework
AAA framework • Many different ways to authenticate based on
• Identification RFC standards
– This is who you claim to be - Usually your username – Manufacturers can build their own EAP methods
• Authentication • EAP integrates with 802.1X
– Prove you are who you say you are – Prevents access to the network until the
– Password and other authentication factors authentication succeeds
• Authorization IEEE 802.1X and EAP
– Based on your identification and authentication, • Supplicant - the client
what access do you have? • Authenticator - The device that provides access
• Accounting • Authentication server - Validates the client credentials
– Resources used: Login time, data sent and received,
logout time

4.1 - Application Security


Secure coding concepts Secure cookies
• A balance between time and quality • Information stored on your computer by the browser
– Programming with security in mind is often secondary • Used for tracking, personalization, session management
• Testing, testing, testing – Not executable, not generally a security risk
– The Quality Assurance (QA) process – Unless someone gets access to them
• Vulnerabilities will eventually be found • Secure cookies have a Secure attribute set
– And exploited – Browser will only send it over HTTPS
Input validation • Sensitive information should not be saved in a cookie
• What is the expected input? – This isn’t designed to be secure storage
– Validate actual vs. expected
• Document all input methods - Forms, fields, type
• Check and correct all input (normalization)
– A zip code should be only X characters long with a
letter in the X column
– Fix any data with improper input
• The fuzzers will find what you missed
– Don’t give them an opening
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 62 [Link]
4.1 - Application Security (continued)
Static code analyzers Sandboxing
• Static Application Security Testing (SAST) • Applications cannot access unrelated resources
– Help to identify security flaws – They play in their own sandbox
• Many security vulnerabilities found easily • Commonly used during development
– Buffer overflows, database injections, etc. – Can be a useful production technique
• Not everything can be identified through analysis • Used in many different deployments
– Authentication security, insecure cryptography, etc. – Virtual machines
– Don’t rely on automation for everything – Mobile devices
• Still have to verify each finding – Browser iframes (Inline Frames)
– False positives are an issue – Windows User Account Control (UAC)
Code signing Application security monitoring
• An application is deployed • Real-time information
– Users run application executable or scripts – Application usage, access demographics
• So many security questions • View blocked attacks
– Has the application been modified in any way? – SQL injection attempts, patched vulnerabilities
– Can you confirm that the application was written by a • Audit the logs
specific developer? – Find the information gathering and hidden attacks
• The application code can be digitally signed by the • Anomaly detection
developer – Unusual file transfers
– Asymmetric encryption – Increase in client access
– A trusted CA signs the developer’s public key
– Developer signs the code with their private key
– For internal apps, use your own CA

4.2 - Asset Management


Acquisition/procurement process Monitoring / asset tracking
• The purchasing process • Inventory every asset
– Multi-step process for requesting and obtaining – Laptops, desktops, servers, routers, switches, cables,
goods and services fiber modules, tablets, etc.
• Start with a request from the user • Associate a support ticket with a device make and model
– Usually includes budgeting information and formal – Can be more detailed than a user’s description
approvals • Enumeration
• Negotiate with suppliers – List all parts of an asset
– Terms and conditions – CPU, memory, storage drive, keyboard, mouse
• Purchase, invoice, and payment • Add an asset tag
– The money part – Barcode, RFID, visible tracking number, organization name
Assignment/accounting – Media sanitization
• A central asset tracking system • System disposal or decommissioning
– Used by different parts of the organization – Completely remove data
• Ownership – No usable information remains
– Associate a person with an asset • Different use cases
– Useful for tracking a system – Clean a hard drive for future use
• Classification – Permanently delete a single file
– Type of asset • A one-way trip
– Hardware (capital expenditure) – Once it’s gone, it’s really gone
– Software (operating expenditure) – No recovery with forensics tools
• Reuse the storage media
– Ensure nothing is left behind

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 63 [Link]
4.2 - Asset Management (continued)
Physical destruction Data retention
• Shredder / pulverizer • Backup your data
– Heavy machinery - complete destruction – How much and where?
• Drill / Hammer – Copies, versions of copies, lifecycle of data,
– Quick and easy purging old data
– Platters, all the way through • Regulatory compliance
• Electromagnetic (degaussing) – A certain amount of data backup may be required
– Remove the magnetic field – Emails, corporate financial data
– Destroys the drive data and renders the drive unusable • Operational needs
• Incineration – Accidental deletion
– Fire hot. – Disaster recovery
Certificate of destruction • Differentiate by type and application
• Destruction is often done by a 3rd party – Recover the data you need when you need it
– How many drills and degaussers do you have?
• Need confirmation that your data is destroyed
– Service should include a certificate
• A paper trail of broken data
– You know exactly what happened

4.3 - Vulnerability Scanning


Vulnerability scanning Fuzzing engines and frameworks
• Usually minimally invasive • Many different fuzzing options
– Unlike a penetration test – Platform specific, language specific, etc.
• Port scan • Very time and processor resource heavy
– Poke around and see what’s open – Many, many different iterations to try
• Identify systems – Many fuzzing engines use high-probability tests
– And security devices • Carnegie Mellon Computer
• Test from the outside and inside – Emergency Response Team (CERT)
– Don’t dismiss insider threats – CERT Basic Fuzzing Framework (BFF)
• Gather as much information as possible – [Link]
– We’ll separate wheat from chaff later Package monitoring
Static code analyzers • Some applications are distributed in a package
– Especially open source
• Static Application Security Testing (SAST)
– Supply chain integrity
– Help to identify security flaws
• Confirm the package is legitimate
• Many security vulnerabilities found easily
– Trusted source
– Buffer overflows, database injections, etc.
– No added malware
• Not everything can be identified through analysis – No embedded vulnerabilities
– Authentication security, insecure cryptography, etc.
• Confirm a safe package before deployment
– Don’t rely on automation for everything
– Verify the contents
• Still have to verify each finding
– False positives are an issue
Dynamic analysis (fuzzing)
• Send random input to an application
– Fault-injecting, robustness testing, syntax testing,
negative testing
• Looking for something out of the ordinary
– Application crash, server error, exception
• 1988 class project at the University of Wisconsin
– “Operating System Utility Program Reliability”
– Professor Barton Miller
– The Fuzz Generator
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 64 [Link]
4.3 - Threat Intelligence
Threat intelligence Information-sharing organization
• Research the threats • Public threat intelligence
– And the threat actors – Often classified information
• Data is everywhere • Private threat intelligence
– Hacker group profiles, tools used by the attackers, – Private companies have extensive resources
and much more • Need to share critical security details
• Make decisions based on this intelligence – Real-time, high-quality cyber threat information sharing
– Invest in the best prevention • Cyber Threat Alliance (CTA)
• Used by researchers, security operations teams, – Members upload specifically formatted
and others threat intelligence
Open-source intelligence (OSINT) – CTA scores each submission and validates across
• Open-source other submissions
– Publicly available sources - A good place to start – Other members can extract the validated data
• Internet - Discussion groups, social media Dark web intelligence
• Government data • Dark web
– Mostly public hearings, reports, websites, etc. – Overlay networks that use the Internet
– Requires specific software and configurations to access
• Commercial data
– Maps, financial reports, databases • Hacking groups and services
– Activities
Proprietary/third-party intelligence – Tools and techniques
• Someone else has already compiled the threat – Credit card sales
information - You can buy it – Accounts and passwords
• Threat intelligence services • Monitor forums for activity
– Threat analytics – Company names, executive names
– Correlation across different data sources
• Constant threat monitoring
– Identify new threats
– Create automated prevention workflows

4.3 - Penetration Testing


Penetration testing Exploiting vulnerabilities
• Pentest - Simulate an attack • Try to break into the system
• Similar to vulnerability scanning – Be careful; this can cause a denial of service or
– Except we actually try to exploit the vulnerabilities loss of data
• Often a compliance mandate – Buffer overflows can cause instability
– Regular penetration testing by a 3rd-party – Gain privilege escalation
• National Institute of Standards and Technology • You may need to try many different vulnerability types
– Technical Guide to Information Security – Password brute-force
– Testing and Assessment – Social engineering
– [Link] (PDF download) – Database injections
– Buffer overflows
Rules of engagement
• You’ll only be sure you’re vulnerable if you
• An important document
can bypass security
– Defines purpose and scope
– If you can get through, the attackers can get through
– Makes everyone aware of the test parameters
• Type of testing and schedule
– On-site physical breach, internal test, external test
– Normal working hours, after 6 PM only, etc.
• The rules
– IP address ranges
– Emergency contacts
– How to handle sensitive information
– In-scope and out-of-scope devices or applications
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 65 [Link]
4.3 - Penetration Testing
The process Responsible disclosure program
• Initial exploitation • It takes time to fix a vulnerability
– Get into the network – Software changes, testing, deployment, etc.
• Lateral movement • Bug bounty programs
– Move from system to system – A reward for discovering vulnerabilities
– The inside of the network is relatively unprotected – Earn money for hacking a system
• Persistence – Document the vulnerability to earn cash
– Once you’re there, you need to make sure there’s a way back in • A controlled information release
– Set up a backdoor, build user accounts, change or verify – Researcher reports the vulnerability
default passwords – Manufacturer creates a fix
• The pivot – The vulnerability is announced publicly
– Gain access to systems that would normally not be accessible
– Use a vulnerable system as a proxy or relay

4.3 - Analyzing Vulnerabilities


Dealing with false information CVE
• False positives • The vulnerabilities can be cross-referenced online
– A vulnerability is identified that doesn’t really exist – Almost all scanners give you a place to go
• This is different than a low-severity vulnerability • National Vulnerability Database: [Link]
– It’s real, but it may not be your highest priority – Common Vulnerabilities and Exposures (CVE):
• False negatives – [Link]
– A vulnerability exists, but you didn’t detect it • Microsoft Security Bulletins:
• Update to the latest signatures – [Link]
– If you don’t know about it, you can’t see it [Link]
• Work with the vulnerability detection manufacturer • Some vulnerabilities cannot be definitively identified
– They may need to update their signatures for your – You’ll have to check manually to see if a system is
environment vulnerable
– The scanner gives you a heads-up
Prioritizing vulnerabilities
• Not every vulnerability shares the same priority Vulnerability classification
– Some may not be significant • The scanner looks for everything
– Others may be critical – Well, not everything - The signatures are the key
• This may be difficult to determine • Application scans
– The research has probably already been done – Desktop, mobile apps
• Refer to public disclosures and vulnerability databases • Web application scans
– The industry is well versed – Software on a web server
– Online discussion groups, public disclosure mailing lists • Network scans
CVSS – Misconfigured firewalls, open ports, vulnerable
• National Vulnerability Database: [Link] devices
– Synchronized with the CVE list Exposure factor
– Enhanced search functionality • Loss of value or business activity if the
• Common Vulnerability Scoring System (CVSS) vulnerability is exploited
– Quantitative scoring of a vulnerability - 0 to 10 – Usually expressed as a percentage
– The scoring standards change over time • A small DDoS may limit access to a service
– Different scoring for CVSS 2.0 vs CVSS 3.x – 50% exposure factor
• Industry collaboration • A buffer overflow may completely disable a service
– Enhanced feed sharing and automation – 100% exposure factor
• A consideration when prioritizing
– Worst possible outcome probably gets priority

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 66 [Link]
4.3 - Analyzing Vulnerabilities (continued)
Environmental variables Risk tolerance
• What type of environment is associated with this • The amount of risk acceptable to an organization
vulnerability? – It’s impractical to remove all risk
– Internal server, public cloud, test lab • The timing of security patches
• Prioritization and patching frequency – Patching immediately doesn’t allow for proper
– A device in an isolated test lab testing
– A database server in the public cloud • Testing takes time
– Which environment gets priority? – While you’re testing, you’re also vulnerable
• Every environment is different • There’s a middle ground
– Number and type of users (internal, external) – May change based on the severity
– Revenue generating application
– Potential for exploit
Industry/organizational impact
• Some exploits have significant consequences
– The type of organization is an important consideration
• Tallahassee Memorial HealthCare - February 2023
– Ransomware - closed for two weeks
– Diverted emergency cases, surgeries canceled
• Power utilities - Salt Lake City, LA County CA - March 2019
– DDoS attacks from an unpatched known vulnerability

4.3 - Vulnerability Remediation


Patching Segmentation
• The most common mitigation technique • Limit the scope of an exploit
– We know the vulnerability exists – Separate devices into their own networks/VLANs
– We have a patch file to install • A breach would have limited scope
• Scheduled vulnerability/patch notices – It’s not as bad as it could be
– Monthly, quarterly • Can’t patch?
• Unscheduled patches – Disconnect from the world
– Zero day, often urgent – Air gaps may be required
• This is an ongoing process • Use internal NGFWs
– The patches keep coming – Block unwanted/unnecessary traffic between VLANs
– An easy way to prevent most exploits – Identify malicious traffic on the inside
Insurance Physical segmentation
• Cybersecurity insurance coverage • Separate devices - Multiple units, separate infrastructure
– Lost revenue Logical segmentation with VLANs
– Data recovery costs • Virtual Local Area Networks (VLANs)
– Money lost to phishing – Separated logically instead of physically
– Privacy lawsuit costs – Cannot communicate between VLANs without a
• Doesn’t cover everything Layer 3 device / router
– Intentional acts, funds transfers, etc.
Compensating controls
• Ransomware has increased popularity of • Optimal security methods may not be available
cybersecurity liability insurance – Can’t deploy a patch right now
– Applies to every organization – No internal firewalls
• Compensate in other ways
– Disable the problematic service
– Revoke access to the application
– Limit external access
– Modify internal security controls and software firewalls
• Provide coverage until a patch is deployed
– Or similar optimal security response
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 67 [Link]
4.3 - Vulnerability Remediation (continued)
Exceptions and exemptions • Audit
• Removing the vulnerability is optimal – Check remediated systems to ensure the patch
– But not everything can be patched was successfully deployed
• A balancing act • Verification
– Provide the service, but also protect the data and – Manually confirm the security of the system
systems Reporting
• Not all vulnerabilities share the same severity • Ongoing checks are required
– May require local login, physical access, or other criteria – New vulnerabilities are continuously discovered
• An exception may be an option • Difficult (or impossible) to manage without
– Usually a formal process to approve automation
Validation of remediation – Manual checks would be time consuming
• The vulnerability is now patched • Continuous reporting
– Does the patch really stop the exploit? – Number of identified vulnerabilities
– Did you patch all vulnerable systems? – Systems patched vs. unpatched
• Rescanning – New threat notifications
– Perform an extensive vulnerability scan – Errors, exceptions, and exemptions

4.4 - Security Monitoring


Security monitoring Scanning
• The attackers never sleep - 24/7/365 • A constantly changing threat landscape
• Monitor all entry points – New vulnerabilities discovered daily
– Logins, publicly available services, data storage – Many different business applications and services
locations, remote access – Systems and people are always moving
• React to security events • Actively check systems and devices
– Account access, firewall rulebase, additional scanning – Operating system types and versions
• Status dashboards – Device driver versions
– Get the status of all systems at a glance – Installed applications
– Potential anomalies
Monitoring computing resources
• Gather the raw details
• Systems
– A valuable database of information
– Authentication - logins from strange places
– Server monitoring - Service activity, backups, software Reporting
versions • Analyze the collected data
• Applications – Create “actionable” reports
– Availability - Uptime and response times • Status information
– Data transfers - increases or decreases in rates – Number of devices up to date/in compliance
– Security notifications - From the developer/ – Devices running older operating systems
manufacturer • Determine best next steps
• Infrastructure – A new vulnerability is announced
– Remote access systems - Employees, vendors, guests – How many systems are vulnerable?
– Firewall and IPS reports - Increase or type of attack • Ad hoc information summaries
Log aggregation – Prepare for the unknown
• SIEM or SEM (Security Information and Event Manager) Archiving
– Consolidate many different logs to a central database • It takes an average of about 9 months for a
– Servers, firewalls, VPN concentrators, SANs, cloud company to identify and contain a breach
services – IBM security report, 2022
• Centralized reporting • Access to data is critical
– All information in one place – Archive over an extended period
• Correlation between diverse systems • May have a mandate
– View authentication and access – State or federal law
– Track application access – Or organizational requirements
– Measure and report on data transfers
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 68 [Link]
4.4 - Security Monitoring (continued)
Alerting Alert response and remediation
• Real-time notification of security events • Quarantine
– Increase in authentication errors – A foundational security response
– Large file transfers – Prevent a potential security issue from spreading
• Actionable data • Alert tuning
– Keep the right people informed – A balancing act
– Enable quick response and status information – Prevent false positives and false negatives
• Notification methods • An alert should be accurate
– SMS/text – This is an ongoing process
– Email – The tuning gets better as time goes on
– Security console / SOC

4.4 - Security Tools


Security Content Automation Protocol (SCAP) Agents/agentless
• Many different security tools on the market • Check to see if the device is in compliance
– NGFWs, IPS, vulnerability scanners, etc. – Install a software agent onto the device
– They all have their own way of evaluating a threat – Run an on-demand agentless check
• Managed by National Institute of • Agents can usually provide more detail
– Standards and Technology (NIST) [Link] – Always monitoring for real-time notifications
• Allows tools to identify and act on the same criteria – Must be maintained and updated
– Validate the security configuration • Agentless runs without a formal install
– Confirm patch installs – Performs the check, then disappears
– Scan for a security breach – Does not require ongoing updates to an agent
Using SCAP – Will not inform or alert if not running
• SCAP content can be shared between tools SIEM
– Focused on configuration compliance • Security Information and Event Management
– Easily detect applications with known vulnerabilities – Logging of security events and information
• Especially useful in large environments • Log collection of security alerts
– Many different operating systems and applications – Real-time information
• This specification standard enables automation • Log aggregation and long-term storage
– Even between different tools – Usually includes advanced reporting features
• Automation types • Data correlation
– Ongoing monitoring – Link diverse data types
– Notification and alerting • Forensic analysis
– Remediation of noncompliant systems – Gather details after an event
Benchmarks Anti-virus and anti-malware
• Apply security best-practices to everything • Anti-virus is the popular term
– Operating systems, cloud providers, mobile devices, etc. – Refers specifically to a type of malware
– The bare minimum for security settings – Trojans, worms, macro viruses
• Example: Mobile device • Malware refers to the broad malicious
– Disable screenshots, disable screen recordings, prevent software category
voice calls when locked, force encryption backups, – Anti-malware stops spyware, ransomware,
disable additional VPN profiles, configure a “lost phone” fileless malware
message, etc. • The terms are effectively the same these days
• Popular benchmarks - Center for Internet Security (CIS) – The names are more of a marketing tool
– [Link] – Anti-virus software is also anti-malware
software now
– Make sure your system is using a
comprehensive solution

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 69 [Link]
4.4 - Security Tools (continued)
Data Loss Prevention (DLP) NetFlow
• Where’s your data? • Gather traffic statistics from all traffic flows
– Social Security numbers, credit card numbers, – Shared communication between devices
medical records • NetFlow
• Stop the data before the attacker gets it – Standard collection method
– Data “leakage” – Many products and options
• So many sources, so many destinations • Probe and collector
– Often requires multiple solutions – Probe watches network communication
– Endpoint clients – Summary records are sent to the collector
– Cloud-based systems • Usually a separate reporting app
– Email, cloud storage, collaboration tools – Closely tied to the collector
SNMP Vulnerability scanners
• Simple Network Management Protocol • Usually minimally invasive
– A database of data (MIB) - Management Information Base – Unlike a penetration test
– The database contains OIDs - Object Identifiers • Port scan
– Poll devices over udp/161 – Poke around and see what’s open
• Request statistics from a device • Identify systems
– Server, firewall, workstation, switch, router, etc. – And security devices
• Poll devices at fixed intervals • Test from the outside and inside
– Create historical performance graphs – Don’t dismiss insider threats
SNMP traps • Gather as much information as possible
• Most SNMP operations expect a poll – We’ll separate wheat from chaff later
– Devices then respond to the SNMP request
– This requires constant polling
• SNMP traps can be configured on the monitored device
– Communicates over udp/162
• Set a threshold for alerts
– If the number of CRC errors increases by 5, send a trap
– Monitoring station can react immediately

4.5 - Firewalls
Network-based firewalls Ports and protocols
• Filter traffic by port number or application • Make forwarding decisions based on protocol
– Traditional vs. NGFW (TCP or UDP) and port number
• Encrypt traffic – Traditional port-based firewalls
– VPN between sites – Add to an NGFW for additional security
• Most firewalls can be layer 3 devices (routers) policy options
– Often sits on the ingress/egress of the network • Based on destination protocol and port
– Network Address Translation (NAT) – Web server: tcp/80, tcp/443
– Dynamic routing – SSH server: tcp/22
– Microsoft RDP: tcp/3389
Next-generation Firewalls (NGFW)
– DNS query: udp/53
• The OSI Application Layer
– NTP: udp/123
– Layer 7 firewall
• Can be called different names
– Application layer gateway
– Stateful multilayer inspection
– Deep packet inspection
• Requires some advanced decodes
– Every packet must be analyzed, categorized, and
a security decision determined

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 70 [Link]
4.5 - Firewalls (continued)
Firewall rules IPS rules
• A logical path • Intrusion Prevention System
– Usually top-to-bottom – Usually integrated into an NGFW
• Can be very general or very specific • Different ways to find malicious traffic
– Specific rules are usually at the top – Look at traffic as it passes by
• Implicit deny • Signature-based - Look for a perfect match
– Most firewalls include a deny at the bottom • Anomaly-based
– Even if you didn’t put one – Build a baseline of what’s “normal”
• Access control lists (ACLs) – Unusual traffic patterns are flagged
– Allow or disallow traffic • You determine what happens when unwanted
– Groupings of categories - traffic appears
– Source IP, Destination IP, port number, time of day, – Block, allow, send an alert, etc.
application, etc. • Thousands of rules - Or more
Screened subnet • Rules can be customized by group
• An additional layer of security between the you and – Or as individual rules
the Internet • This can take time to find the right balance
– Public access to public resources – Security / alert “noise” / false positives
– Private data remains inaccessible

4.5 - Web Filtering


Content filtering Proxies
• Control traffic based on data within the content • Sits between the users and the external network
– URL filtering, website category filtering • Receives the user requests and sends the request
• Corporate control of outbound and inbound data on their behalf (the proxy)
– Sensitive materials • Useful for caching information, access control,
• Control of inappropriate content URL filtering, content scanning
– Not safe for work • Applications may need to know how to use
– Parental controls the proxy (explicit)
• Protection against evil • Some proxies are invisible (transparent)
– Anti-virus, anti-malware
Forward proxy
URL scanning • A centralized “internal proxy”
• Allow or restrict based on Uniform Resource Locator – Commonly used to protect and control user
– Also called a Uniform Resource Identifier (URI) access to the Internet
– Allow list / Block list
Block rules
• Managed by category
• Based on specific URL
– Auction, Hacking, Malware,
– *.[Link]: Allow
– Travel, Recreation, etc.
• Category of site content
• Can have limited control
– Usually divided into over 50 different topics
– URLs aren’t the only way to surf
– Adult, Educational, Gambling, Government,
• Often integrated into an NGFW Home and Garden, Legal, Malware, News, etc.
– Filters traffic based on category or specific URL
• Different dispositions
Agent based – Educational: Allow
• Install client software on the user’s device – Home and Garden: Allow and Alert
– Usually managed from a central console – Gambling: Block
• Users can be located anywhere
– The local agent makes the filtering decisions
– Always-on, always filtering
• Updates must be distributed to all agents
– Cloud-based updates
– Update status shown at the console

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 71 [Link]
4.5 - Web Filtering (continued)
Reputation DNS filtering
• Filter URLs based on perceived risk • Before connecting to a website, get the IP address
– A good reputation is allowed – Perform a DNS lookup
– A bad reputation is blocked • DNS is updated with real-time threat intelligence
– Risk: Trustworthy, Low risk, Medium risk, Suspicious, – Both commercial and public lists
High risk • Harmful sites are not resolved
• Automated reputation – No IP address, no connection
– Sites are scanned and assigned a reputation • This works for any DNS lookup
• Manual reputation – Not just web filtering
– Managers can administratively assign a rep
• Add these dispositions to the URL filter
– High risk: Block, Trustworthy: Allow

4.5 - Operating System Security


Active Directory • A central console
• A database of everything on the network – Login scripts
– Computers, user accounts, file shares, printers, groups, – Network configurations (QoS)
and more – Security parameters
– Primarily Windows-based • Comprehensive control
• Manage authentication – Hundreds of configuration options
– Users login using their AD credentials Security-Enhanced Linux (SELinux)
• Centralized access control • Security patches for the Linux kernel
– Determine which users can access resources – Adds mandatory access control (MAC) to Linux
• Commonly used by the help desk – Linux traditionally uses
– Reset passwords, add and remove accounts – Discretionary Access Control (DAC)
Group Policy • Limits application access
• Manage the computers or users with Group Policies – Least privilege
– Local and Domain policies – A potential breach will have limited scope
– Group Policy Management Editor • Open source
– Already included as an option with many Linux
distributions

4.5 - Secure Protocols


Unencrypted network data • HTTP and HTTPS
• Network traffic is important data – In-the-clear and encrypted web browsing
– Everything must be protected – HTTP: Port 80
• Some protocols aren’t encrypted – HTTPS: Port 443
– All traffic sent in the clear • The port number does not guarantee security
– Telnet, FTP, SMTP, IMAP – Confirm the security features are enabled
• Verify with a packet capture – Packet captures may be necessary
– View everything sent over the network
Protocol selection
• Use a secure application protocol
– Built-in encryption
• A secure protocol may not be available
– This may be a deal-breaker
Port selection
• Secure and insecure application connections may be
available
– It’s common to run secure and insecure on different ports

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 72 [Link]
4.5 - Secure Protocols (continued)
Transport method • Virtual Private Network (VPN)
• Don’t rely on the application – Create an encrypted tunnel
– Encrypt everything over the current – All traffic is encrypted and protected
network transport – Often requires third-party services and software
• 802.11 Wireless
– Open access point: No transport-level encryption
– WPA3: All user data is encrypted

4.5 - Email Security


Email security challenges • List of authorized mail servers are added to a
• The protocols used to transfer emails include DNS TXT record
relatively few security checks – Receiving mail servers perform a check to see if
– It’s very easy to spoof an email incoming mail really did come from an authorized host
• Spoofing happens all the time Domain Keys Identified Mail (DKIM)
– Check your spam folder • A mail server digitally signs all outgoing mail
• The email looks as if it originated from – The public key is in the DKIM TXT record
james@[Link] • The signature is validated by the receiving mail servers
– But did it? How can you tell? – Not usually seen by the end user
• A reputable sender will configure email validation DMARC
– Publicly available on the sender’s DNS server • Domain-based Message Authentication,
Mail gateway Reporting, and Conformance (DMARC)
• The gatekeeper – An extension of SPF and DKIM
– Evaluates the source of inbound email messages • The domain owner decides what receiving email servers
– Blocks it at the gateway before it reaches the user should do with emails not validating using SPF and DKIM
– On-site or cloud-based – That policy is written into a DNS TXT record
Sender Policy Framework (SPF) – Accept all, send to spam, or reject the email
• SPF protocol • Compliance reports are sent to the email administrator
– Sender configures a list of all servers authorized to – The domain owner can see how emails are received
send emails for a domain
4.5 - Monitoring Data
FIM (File Integrity Monitoring) Data Loss Prevention (DLP) systems
• Some files change all the time • On your computer
– Some files should NEVER change – Data in use
• Monitor important operating system and application files – Endpoint DLP
– Identify when changes occur • On your network
• Windows - SFC (System File Checker) – Data in motion
• Linux - Tripwire • On your server
• Many host-based IPS options – Data at rest
Data Loss Prevention (DLP) USB blocking
• Where’s your data? • DLP on a workstation
– Social Security numbers, credit card numbers, – Allow or deny certain tasks
medical records • November 2008 - U.S. Department of Defense
• Stop the data before the attackers get it – Worm virus “[Link]” replicates
– Data “leakage” using USB storage
– Bans removable flash media and
• So many sources, so many destinations
storage devices
– Often requires multiple solutions in different places
• All devices had to be updated
– Local DLP agent handled USB blocking
• Ban was lifted in February 2010
– Replaced with strict guidelines

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 73 [Link]
4.5 - Monitoring Data (continued)
Cloud-based DLP • Inbound
• Located between users and the Internet – Block keywords, identify impostors, quarantine email messages
– Watch every byte of network traffic • Outbound
– No hardware, no software – Fake wire transfers, W-2 transmissions, employee information
• Block custom defined data strings Emailing a spreadsheet template
– Unique data for your organization • November 2016
• Manage access to URLs • Boeing employee emails spouse a spreadsheet to use as a
– Prevent file transfers to cloud storage template
• Block viruses and malware • Contained the personal information of 36,000
– Anything traversing the network Boeing employees
DLP and email – In hidden columns
• Email continues to be the most critical risk vector – Social security numbers, date of birth, etc.
– Inbound threats, outbound data loss • Boeing sells its own DLP software
• Check every email inbound and outbound – But only uses it for classified work
– Internal system or cloud-based

4.5 - Endpoint Security


The endpoint Health checks/posture assessment
• The user’s access • Persistent agents
– Applications and data – Permanently installed onto a system
• Stop the attackers – Periodic updates may be required
– Inbound attacks • Dissolvable agents
– Outbound attacks – No installation is required
• Many different platforms – Runs during the posture assessment
– Mobile, desktop – Terminates when no longer required
• Protection is multi-faceted • Agentless NAC
– Defense in depth – Integrated with Active Directory
– Checks are made during login and logoff
Edge vs. access control
– Can’t be scheduled
• Control at the edge
– Your Internet link Failing your assessment
– Managed primarily through firewall rules • What happens when a posture assessment fails?
– Firewall rules rarely change – Too dangerous to allow access
• Access control • Quarantine network, notify administrators
– Control from wherever you are – Just enough network access to fix the issue
– Inside or outside • Once resolved, try again
– Access can be based on many rules – May require additional fixes
– By user, group, location, application, etc. Endpoint detection and response (EDR)
– Access can be easily revoked or changed • A different method of threat protection
– Change your security posture at any time – Scale to meet the increasing number of threats
Posture assessment • Detect a threat
• You can’t trust everyone’s computer – Signatures aren’t the only detection tool
– BYOD (Bring Your Own Device) – Behavioral analysis, machine learning, process
– Malware infections / missing anti-malware monitoring
– Unauthorized applications – Lightweight agent on the endpoint
• Before connecting to the network, perform a health • Investigate the threat
check – Root cause analysis
– Is it a trusted device? • Respond to the threat
– Is it running anti-virus? Which one? Is it updated? – Isolate the system, quarantine the threat,
– Are the corporate applications installed? rollback to a previous config
– Is it a mobile device? Is the disk encrypted? – API driven, no user or technician intervention required
– The type of device doesn’t matter - Windows, Mac,
Linux, iOS, Android
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 74 [Link]
4.5 - Endpoint Security (continued)
Extended Detection and Response (XDR) User behavior analytics
• An evolution of EDR • XDR commonly includes user behavior analytics
– Improve missed detections, false positives, and – Extend the scope of anomaly detection
long investigation times • Watch users, hosts, network traffic, data repositories, etc.
– Attacks involve more than just the endpoint – Create a baseline or normal activity
• Add network-based detection – Requires data analysis over an extended period
– Investigate and respond to network anomalies • Watch for anything unusual
• Correlate endpoint, network, and cloud data – Use a set of rules, pattern matching, statistical analysis
– Improve detection rates • Real-time detection of unusual activity
– Simplify security event investigations – Catch the threat early

4.6 - Identity and Access Management


Identity and Access Management (IAM) Permission assignments
• Applications are available anywhere • Each entity gets limited permissions
– Desktop, browser, mobile device, etc. – Just enough to do their job
• Data can be located anywhere – Group assignments are common
– Cloud storage, private data centers, etc. • Storage and files can be private to that user
• Many different application users – Even if another person is using the same computer
– Employees, vendors, contractors, customers • No privileged access to the operating system
• Give the right permissions to the right people at – Specifically not allowed on a user account
the right time Identity proofing
– Prevent unauthorized access • I could be anyone
• Identify lifecycle management – The IAM process should confirm who I am
– Every entity (human and non-human) gets a • Resolution
digital identity – Who the system thinks you are
• Access control • Validation
– An entity only gets access to what they need – Gathering information from the user
• Authentication and authorization (password, security questions, etc.)
– Entities must prove they are who they claim to be • Verification / Attestation
• Identity governance – Passport, in-person meeting, etc.
– Track an entity’s resource access – Automated verification is also an option
– May be a regulatory requirement Single sign-on (SSO)
• Provisioning/de-provisioning user accounts • Provide credentials one time
• The user account creation process – Get access to all available or assigned resources
– And the account removal process – No additional authentication required
• Provisioning and de-provisioning occurs for certain events • Usually limited by time
– Hiring, transfers, promotions, job separation – A single authentication can work for 24 hours
• Account details – Authenticate again after the timer expires
– Name, attributes, group permissions, other permissions • The underlying authentication infrastructure must
• An important part of the IAM process support SSO
– An initial checkpoint to limit access – Not always an option
– Nobody gets Administrator access

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 75 [Link]
4.6 - Identity and Access Management (continued)
LDAP (Lightweight Directory Access Protocol) Federation
• Protocol for reading and writing directories over • Provide network access to others
an IP network – Not just employees - Partners, suppliers,
– An organized set of records, like a phone directory customers, etc.
• X.500 specification was written by the International – Provides SSO and more
Telecommunications Union (ITU) • Third-parties can establish a federated network
– They know directories! – Authenticate and authorize between the two
• DAP ran on the OSI protocol stack organizations
– LDAP is lightweight – Login with your Facebook credentials
• LDAP is the protocol used to query and update an • The third-parties must establish a trust relationship
X.500 directory – And the degree of the trust
– Used in Windows Active Directory, Apple OpenDirectory, Interoperability
Novell eDirectory, etc. • Many different ways to communicate with an
X.500 Directory Information Tree authentication server
• Hierarchical structure – More than a simple login process
– Builds a tree • Often determined by what is at hand
• Container objects – VPN concentrator can talk to a LDAP server
– Country, organization, organizational units – We have an LDAP server
• Leaf objects • A new app uses OAuth
– Users, computers, printers, files – Need to allow authentication API access
Security Assertion Markup Language (SAML) • The interoperability is dependent on the
• Open standard for authentication and authorization environment
– You can authenticate through a third-party to – This is often part of a much larger IAM strategy
gain access
– One standard does it all, sort of
• Not originally designed for mobile apps
– This has been SAML’s largest roadblock
OAuth
• Authorization framework
– Determines what resources a user will be able to access
• Created by Twitter, Google, and many others
– Significant industry support
• Not an authentication protocol
– OpenID Connect handles the single sign-on
authentication
– OAuth provides authorization between applications
• Relatively popular
– Used by Twitter, Google, Facebook, LinkedIn, and more

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 76 [Link]
4.6 - Access Controls
Access control Role-based access control (RBAC)
• Authorization • You have a role in your organization
– The process of ensuring only authorized rights are – Manager, director, team lead, project manager
exercised • Administrators provide access based on the role of the
– Policy enforcement user
– The process of determining rights – Rights are gained implicitly instead of explicitly
– Policy definition • In Windows, use Groups to provide role-based access
• Users receive rights based on control
– Access Control models – You are in shipping and receiving, so you can use the
– Different business needs or mission requirements shipping software
Least privilege – You are the manager, so you can review shipping logs
• Rights and permissions should be set to the bare Rule-based access control
minimum • Generic term for following rules
– You only get exactly what’s needed to complete your – Conditions other than who you are
objective • Access is determined through system-enforced rules
• All user accounts must be limited – System administrators, not users
– Applications should run with minimal privileges • The rule is associated with the object
• Don’t allow users to run with administrative privileges – System checks the ACLs for that object
– Limits the scope of malicious behavior • Rule examples
Mandatory Access Control (MAC) – Lab network access is only available between 9 AM
• The operating system limits the operation on an object and 5 PM
– Based on security clearance levels – Only Chrome browsers may complete this web form
• Every object gets a label Attribute-based access control (ABAC)
– Confidential, secret, top secret, etc. • Users can have complex relationships to applications
• Labeling of objects uses predefined rules and data
– The administrator decides who gets access to what – Access may be based on many different criteria
security level • ABAC can consider many parameters
– Users cannot change these settings – A “next generation” authorization model
Discretionary Access Control (DAC) – Aware of context
• Used in most operating systems • Combine and evaluate multiple parameters
– A familiar access control model – Resource information, IP address, time of day, desired
• You create a spreadsheet action, relationship to the data, etc.
– As the owner, you control who has access Time-of-day restrictions
– You can modify access at any time • Almost all security devices include a time-of-day option
• Very flexible access control – Restrict access during certain times or days of the
– And very weak security week
– Usually not the only access control
• Can be difficult to implement
– Especially in a 24-hour environment
• Time-of-day restrictions
– Training room network is inaccessible between
midnight and 6 AM
– Conference room access is limited after 8 PM
– R&D databases are only after between 8 AM and 6 PM

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 77 [Link]
4.6 - Multifactor Authentication
Multifactor authentication • Hardware or software tokens
• Prove who you are – Generates pseudo-random authentication codes
– Use different methods • Your phone
– A memorized password – SMS a code to your phone
– A mobile app
Something you are
– Your GPS location
• Biometric authentication
• Factors – Fingerprint, iris scan, voice print
– Something you know
• Usually stores a mathematical representation of your
– Something you have
biometric
– Something you are
– Your actual fingerprint isn’t usually saved
– Somewhere you are
• Difficult to change
• There are other factors as well
– You can change your password
Something you know – You can’t change your fingerprint
• Password • Used in very specific situations
– Secret word/phrase, string of characters – Not foolproof
– Very common authentication factor
Somewhere you are
• PIN
• Provide a factor based on your location
– Personal identification number
– The transaction only completes if you are in a
– Not typically contained anywhere on a smart card
particular geography
or ATM card
• IP address
• Pattern
– Not perfect, but can help provide more info
– Complete a series of patterns
– Works with IPv4, not so much with IPv6
– Only you know the right format
• Mobile device location services
Something you have – Geolocation to a very specific area
• Smart card – Must be in a location that can receive GPS information
– Integrates with devices or near an identified mobile or 802.11 network
– May require a PIN – Still not a perfect identifier of location
• USB security key - Certificate is on the USB device

4.6 - Password Security


Password complexity and length Password managers
• Make your password strong • Important to use different passwords for each account
– Resist guessing or brute-force attack – Remembering all of them would be impractical
• Increase password entropy • Store all of your passwords in a single database
– No single words, no obvious passwords – Encrypted, protected
– Mix upper and lower case, letters, and special characters – Can include multifactor tokens
• Stronger passwords are commonly at least 8 characters • Built-in to many operating systems
– These requirements change as processing – And some browsers
speed gets faster • Enterprise password managers
– Consider a phrase or set of words – Centralized management and recovery options
Password age and expiration Passwordless authentication
• Password age • Many breaches are due to poor password control
– How long since a password was modified – Weak passwords, insecure implementation
• Password expiration • Authenticate without a password
– Password works for a certain amount of time – This solves many password management issues
– 30 days, 60 days, 90 days, etc. • You may already be passwordless
– After the expiration date, the password does not work – Facial recognition, security key, etc.
– System remembers password history, requires
• Passwordless may not be the primary
unique passwords
authentication method
• Critical systems might change more frequently – Used with a password or additional factors
– Every 15 days or every week
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 78 [Link]
4.6 - Password Security (continued)
Just-in-time permissions • Password vaulting
• In many organizations, the IT team is assigned – Primary credentials are stored in a password vault
administrator/root elevated account rights – The vault controls who gets access to credentials
– This would be a great account to attack • Accounts are temporary
• Grant admin access for a limited time – Just-in-time process creates a time-limited account
– No permanent administrator rights – Administrator receives ephemeral credentials
– The principle of least privilege – Primary passwords are never released
• A breached user account never has elevated rights – Credentials are used for one session then deleted
– Narrow the scope of a breach
• Request access from a central clearinghouse
– Grants or denies based on predefined security policies

4.7 - Scripting and Automation


Scripting and automation Cases for automation
• Automate and orchestrate • User and resource provisioning
– You don’t have to be there – On-boarding and off-boarding
– Solve problems in your sleep – Assign access to specific resources
– Monitor and resolve problems before they happen • Guard rails
• The need for speed – A set of automated validations
– The script is as fast as the computer – Limit behaviors and responses
– No typing or delays – Constantly check to ensure proper implementation
– No human error – Reduce errors
• Automate mundane tasks Cases for automation
– You can do something more creative • Security groups
Automation benefits – Assign (or remove) group access
• Save time - No typing required – Constant audits without human intervention
– Run multiple times, over and over • Ticket creation
• Enforce baselines – Automatically identify issues
– Missing an important security patch – Script email submissions into a ticket
– Automatically install when identified • Escalation
• Standard infrastructure configurations – Correct issues before involving a human
– Use a script to build a default router configuration – If issue isn’t resolved, contact the on-call tech
– Add firewall rules to a new security appliance • Controlling services and access
– IP configurations, security rules, standard – Automatically enable and disable services
configuration options – No set and forget
• Secure scaling • Continuous integration and testing
– Orchestrate cloud resources – Constant development and code updates
– Quickly scale up and down – Securely test and deploy
– Automation ensures proper security also scales • Integrations and application programming interfaces (APIs)
• Employee retention – Interact with third-party devices and services
– Automate the boring stuff – Cloud services, firewalls, operating systems
– Ease the workload – Talk their language
– Minimize the mundane tasks
– Employees work is rewarding instead of repetitive
• Reaction time
– The computer is much faster than you
– An event can be addressed immediately
– A script doesn’t need a wake-up call
• Workforce multiplier
– Scripting works 24/7
– Allows the smart people to do smarter work
somewhere else
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 79 [Link]
4.7 - Scripting and Automation (continued)
Scripting considerations • Technical debt
• Complexity – Patching problems may push the issue down the road
– Many moving parts – It’s going to be more expensive to fix later
– All of the parts have to reliably work together • Ongoing supportability
• Cost – The script works great today
– It takes money to create the script – The script may not work great tomorrow
– It takes money to implement the automation – Plan for changes and updates
• Single point of failure
– What happens if the script stops working?
– This could be a significant deal-breaker

4.8 - Incident Response


Security incidents The challenge of detection
• User clicks an email attachment and executes malware • Many different detection sources
– Malware then communicates with external servers – Different levels of detail, different levels of perception
• DDoS • A large amount of “volume”
– Botnet attack – Attacks are incoming all the time
• Confidential information is stolen – How do you identify the legitimate threats?
– Thief wants money or it goes public • Incidents are almost always complex
• User installs peer-to-peer software and allows – Extensive knowledge needed
external access to internal servers – Analysis
NIST SP800-61 • An incident might occur in the future
• National Institute of Standards and Technology – This is your heads-up
– NIST Special Publication 800-61 Revision 2 • Web server log
– Computer Security Incident – Vulnerability scanner in use
– Handling Guide • Exploit announcement
• The incident response lifecycle: – Monthly Microsoft patch release,
– Preparation – Adobe Flash update
– Detection and Analysis • Direct threats - A hacking group doesn’t like you
– Containment, Eradication, and Recovery Analysis
– Post-incident Activity • An attack is underway - Or an exploit is successful
Preparing for an incident • Buffer overflow attempt
• Communication methods – Identified by an intrusion detection/prevention system
– Phones and contact information • Anti-virus software identifies malware
• Incident handling hardware and software – Deletes from OS and notifies administrator
– Laptops, removable media, forensic software, • Host-based monitor detects a configuration change
digital cameras, etc. – Constantly monitors system files
• Incident analysis resources • Network traffic flows deviate from the norm
– Documentation, network diagrams, baselines, – Requires constant monitoring
critical file hash values
Isolation and containment
• Incident mitigation software
• Generally a bad idea to let things run their course
– Clean OS and application images
– An incident can spread quickly
• Policies needed for incident handling – It’s your fault at that point
– Everyone knows what to do
• Sandboxes
– An isolated operating system
– Run malware and analyze the results
– Clean out the sandbox when done
• Isolation can be sometimes be problematic
– Malware or infections can monitor connectivity
– When connectivity is lost, everything could be
deleted/encrypted/damaged

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 80 [Link]
4.8 - Incident Response (continued)
Recovery after an incident Answer the tough questions
• Get things back to normal • What happened, exactly?
– Remove the bad, keep the good – Timestamp of the events
• Eradicate the bug • How did your incident plans work?
– Remove malware – Did the process operate successfully?
– Disable breached user accounts • What would you do differently next time?
– Fix vulnerabilities – Retrospective views provide context
• Recover the system • Which indicators would you watch next time?
– Restore from backups – Different precursors may give you better alerts
– Rebuild from scratch
Training for an incident
– Replace compromised files
• There’s limited on-the-job training when a security event occurs
– Tighten down the perimeter
– Be ready when an incident is identified
Lessons learned • Train the team prior to an incident
• Learn and improve – Initial response
– No system is perfect – Investigation plans
• Post-incident meeting – Incident reporting
– Invite everyone affected by the incident – And more
• Don’t wait too long • This can be an expensive endeavor
– Memories fade over time – Especially with larger response teams
– Some recommendations can be applied to
the next event

4.8 - Incident Planning


Exercising Root cause analysis
• Test yourselves before an actual event • Determine the ultimate cause of an incident
– Scheduled update sessions (annual, semi-annual, etc.) – Find the root cause by asking “why”
• Use well-defined rules of engagement • Create a set of conclusions regarding the incident
– Do not touch the production systems – Backed up by the facts
• Very specific scenario • Don’t get tunnel vision
– Limited time to run the event – There can be more than a single root cause
• Evaluate response • Mistakes happen
– Document and discuss – The response to the mistake is the difference
Tabletop exercises Threat hunting
• Performing a full-scale disaster drill can be costly • The constant game of cat and mouse
– And time consuming – Find the attacker before they find you
• Many of the logistics can be determined through analysis • Strategies are constantly changing
– You don’t physically have to go through a disaster or drill – Firewalls get stronger, so phishing gets better
• Get key players together for a tabletop exercise • Intelligence data is reactive
– Talk through a simulated disaster – You can’t see the attack until it happens
Simulation • Speed up the reaction time
• Test with a simulated event – Use technology to fight
– Phishing attack, password requests, data breaches
• Going phishing
– Create a phishing email attack
– Send to your actual user community
– See who bites
• Test internal security
– Did the phishing get past the filter?
• Test the users
– Who clicked?
– Additional training may be required
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 81 [Link]
4.8 - Digital Forensics
Digital forensics Reporting
• Collect and protect information relating to an intrusion • Document the findings
– Many different data sources and – For Internal use, legal proceedings, etc.
protection mechanisms • Summary information
• RFC 3227 - Guidelines for – Overview of the security event
– Evidence Collection and Archiving • Detailed explanation of data acquisition
– A good set of best practices – Step-by-step method of the process
• Standard digital forensic process • The findings
– Acquisition, analysis, and reporting – An analysis of the data
• Must be detail oriented • Conclusion
– Take extensive notes – Professional results, given the analysis
Legal hold Preservation
• A legal technique to preserve relevant information • Handling evidence
– Prepare for impending litigation – Isolate and protect the data
– Initiated by legal counsel – Analyze the data later without any alterations
• Hold notification • Manage the collection process
– Custodians are instructed to preserve data – Work from copies
• Separate repository for electronically stored information – Manage the data collection from mobile devices
(ESI) • Live collection has become an important skill
– Many different data sources and types – Data may be encrypted or difficult to collect after
– Unique workflow and retention requirements powering down
• Ongoing preservation • Follow best practices to ensure admissibility of data in
– Once notified, there’s an ongoing obligation to court
preserve data – What happens now affects the future
Chain of custody E-discovery
• Control evidence • Electronic discovery
– Maintain integrity – Collect, prepare, review, interpret, and produce
• Everyone who contacts the evidence electronic documents
– Use hashes and digital signatures • E-discovery gathers data required by the legal process
– Avoid tampering – Does not generally involve analysis
• Label and catalog everything – There’s no consideration of intent
– Digitally tag all items for ongoing documentation • Works together with digital forensics
– Seal and store – The e-discovery process obtains a storage drive
Acquisition – Data on the drive is smaller than expected
• Obtain the data – Forensics experts determine that data was deleted and
– Disk, RAM, firmware, OS files, etc. attempt to recover the data
• Some of the data may not be on a single system
– Servers, network data, firewall logs
• For virtual systems, get a snapshot
– Contains all files and information about a VM
• Look for any left-behind digital items
– Artifacts
– Log information, recycle bins, browser bookmarks,
saved logins, etc.

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 82 [Link]
4.9 - Log Data
Security log files IPS/IDS logs
• Detailed security-related information • Intrusion prevention system/Intrusion detection system
– Blocked and allowed traffic flows – Usually integrated into an NGFW
– Exploit attempts • Logs contain information about predefined
– Blocked URL categories vulnerabilities
– DNS sinkhole traffic – Known OS vulnerabilities, generic security events
• Critical security information • Common data points
– Documentation of every traffic flow – Timestamp
– Summary of attack info – Type or class of attack
– Correlate with other logs – Source and destination IP
Firewall logs – Source and destination port
• Traffic flows through the firewall Network logs
– Source/destination IP, port numbers, disposition • Switches, routers, access points, VPN concentrators
• Next Generation Firewalls (NGFW) – And other infrastructure devices
– Logs the application used, • Network changes
– URL filtering categories, anomalies and suspicious data – Routing updates
Application logs – Authentication issues
• Specific to the application – Network security issues
– Information varies widely Metadata
• Windows • Metadata
– Event Viewer / Application Log – Data that describes other data sources
• Linux / macOS/ • Email
– var/log – Header details, sending servers, destination address
• Parse the log details on the SIEM • Mobile
– Filter out unneeded info – Type of phone, GPS location
Endpoint logs • Web
• Attackers often gain access to endpoints – Operating system, browser type, IP address
– Phones, laptops, tablets, desktops, servers, etc. • Files
• There’s a lot of data on the endpoint – Name, address, phone number, title
– Logon events, policy changes, system events, Vulnerability scans
processes, account management, directory services, • Lack of security controls
etc. – No firewall
• Everything rolls up to the SIEM – No anti-virus
– Security Information and Event Manager – No anti-spyware
• Use with correlation of security events • Misconfigurations
– Combine IPS events with endpoint status – Open shares
OS-specific security logs – Guest access
• OS security events • Real vulnerabilities
– Monitoring apps – Especially newer ones
– Brute force, file changes – Occasionally the old ones
– Authentication details
• Find problems before they happen
– Brute force attacks
– Disabled services
• May require filtering
– Don’t forward everything

© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 83 [Link]
4.9 - Log Data (continued)
Automated reports Dashboards
• Most SIEMs include a report generator • Real-time status information
– Automate common security reports – Get summaries on a single screen
• May be easy or complex to create • Add or remove information
– The SIEM may have its own report generator – Most SIEMs and reporting systems allow for customization
– Third-party report generators may be able to • Shows the most important data
access the database – Not designed for long-term analysis
• Requires human intervention Packet captures
– Someone has to read the reports • Solve complex application issues
• These can be involved to create – Get into the details
– Huge data storage and extensive processing time • Gathers packets on the network
– Or in the air
– Sometimes built into the device
• View detailed traffic information
– Identify unknown traffic
– Verify packet filtering and security controls
– View a plain-language description of the application data

5.1 - Security Policies


Security policy guidelines Business continuity
• What rules are you following to provide CIA? • Not everything goes according to plan
– Confidentiality, Integrity, and Availability – Disasters can cause a disruption to the norm
• High level strategies • We rely on our computer systems
– Data storage requirements, security event procedures – Technology is pervasive
• Detailed security goals • There needs to be an alternative
– Appropriate Wi-Fi usage, requirements for remote – Manual transactions
access – Paper receipts
• Security policies answer the “what” and “why” – Phone calls for transaction approvals
– Technical security controls answer the “how” • These must be documented and tested before a
Information security policies problem occurs
• The big list of all security-related policies Disaster recovery plan
– A centralized resource for processes • If a disaster happens, IT should be ready
• Compliance requirements – Part of business continuity planning
– Can be critical to an organization – Keep the organization up and running
– Detailed security procedures • Disasters are many and varied
– What happens when…? – Natural disasters
• A list of roles and responsibilities – Technology or system failures
– You got this – Human-created disasters
• This is just words and letters • A comprehensive plan
– An organization must enforce the policy – Recovery location
– Data recovery method
Acceptable use policies (AUP)
– Application restoration
• What is acceptable use of company assets?
– IT team and employee availability
– Detailed documentation
– May be documented in the Rules of Behavior Security incidents
• Covers many topics • User clicks an email attachment and executes malware
– Internet use, telephones, computers, – Malware then communicates with external servers
mobile devices, etc. • DDoS - Botnet attack
• Used by an organization to limit legal liability • Confidential information is stolen
– If someone is dismissed, these are the well- – Thief wants money or it goes public
documented reasons why • User installs peer-to-peer software and allows external
access to internal servers
© 2023 Messer Studios, LLC Professor Messer’s CompTIA SY0-701 Security+ Course Notes - Page 84 [Link]

You might also like