CISCO Cybersecurity Essentials Study Notes

CISCO Cybersecurity Essentials 3.0

Module 1: Cybersecurity Threats, Vulnerabilities, and Attacks

Module Objectives
  • Module Title: Cybersecurity Threats, Vulnerabilities, and Attacks

  • Module Objective: Explain how threat actors execute some of the most common types of cyber attacks.

Topic Objectives
  • Common Threats:

    • Explain the threats, vulnerabilities, and attacks that occur in various domains.

  • Deception:

    • Identify different deception methods used by attackers to deceive their victims.

  • Cyber Attacks:

    • Describe common types of network attacks.

  • Wireless and Mobile Device Attacks:

    • Describe common types of wireless and mobile device attacks.

  • Application Attacks:

    • Describe types of application attacks.

1.1 Common Threats

Threat Domains
  • A threat domain is an area of control, authority, or protection that attackers can exploit to gain access to a system. Attackers can exploit systems within a domain through:

    • Direct, physical access to systems and networks.

    • Wireless networking that extends beyond an organization's boundaries.

    • Bluetooth or near-field communication (NFC) devices.

    • Malicious email attachments.

    • Less secure elements within an organization’s supply chain.

    • An organization’s social media accounts.

    • Removable media such as flash drives.

    • Cloud-based applications.

Types of Cyber Threats
Category Types of Cyber Threats
  • Software Attacks:

    • Examples include denial-of-service (DoS) attacks, computer viruses.

  • Software Errors:

    • Issues like software bugs, application downtime, cross-site scripting, or illegal file server shares.

  • Sabotage:

    • Actions by authorized users to compromise databases or deface websites.

  • Human Error:

    • Mistakes such as inadvertent data entry errors or misconfiguration of firewalls.

  • Theft:

    • Incidents like stealing laptops or equipment from unsecured locations.

  • Hardware Failures:

    • Issues including hard drive crashes.

  • Utility Interruption:

    • Events like electrical power outages or water damage from sprinkler failures.

  • Natural Disasters:

    • Severe weather events such as hurricanes, earthquakes, floods, and fires.

Internal vs External Threats
  • Valuable, Sensitive Information: Includes personnel records, intellectual property, financial data.

  • Internal Threats:

    • Actions by current/former employees or contractors, often through compromised servers.

  • External Threats:

    • Typically arise from independent attackers exploiting vulnerabilities or using social engineering techniques.

User Threats and Vulnerabilities
  • A user domain consists of individuals accessing an organization’s information systems, including employees, customers, and contractors.

  • Users represent the weakest link in information security systems, posing significant risks such as:

    • Lack of awareness regarding security policies.

    • Poor enforcement of existing security measures.

    • Data theft, unauthorized activity, and destruction of systems or data.

Threats to Devices
  • Common device-related threats include:

    • Unattended powered-on devices.

    • Downloading from unreliable sources.

    • Installed software vulnerabilities.

    • Uses of unauthorized USB drives on network devices.

    • Lack of policies to protect IT infrastructures.

    • Use of outdated hardware and software.

Threats to the Local Area Network (LAN)
  • Typical LAN threats include:

    • Unauthorized access to wiring closets, data centers, and computer rooms.

    • Network vulnerabilities and software updates.

    • Unauthorized access to systems and applications.

    • Rogue users accessing wireless networks.

    • Exploitation of data in transit.

    • Misconfigured firewalls leading to vulnerabilities.

Threats to the Private Cloud
  • The private cloud domain includes:

    • Unauthorized probing and port scanning.

    • Unauthorized access to resources.

    • OS/software vulnerabilities in routers and network devices.

    • Configuration errors in network devices.

    • Remote access to sensitive data by unauthorized users.

Threats to the Public Cloud
  • The public cloud includes services accessible to the general public, which can be exploited through:

    • Software as a Service (SaaS): Centralized software accessed via web.

    • Platform as a Service (PaaS): Development environment for applications hosted externally.

    • Infrastructure as a Service (IaaS): Virtualized computing resources purchased on demand.

Threats to Applications
  • Applications are critical for organizational operations and can face:

    • Unauthorized access to data centers.

    • Server downtimes.

    • Vulnerabilities in network operating systems or software.

    • Potential for data loss in client-server applications.

Threat Complexity
  • Software vulnerabilities arise from programming errors, protocol weaknesses, or misconfigurations.

  • Attack methods by cybercriminals include:

    • Advanced Persistent Threat (APT): Continuous spying efforts utilizing multiple actors and complex malware.

    • Algorithm Attacks: Exploiting software algorithms for unintended harmful results.

Backdoors and Rootkits
  • Backdoors: Programs providing unauthorized access to systems bypassing normal authentication. E.g., Remote Administrative Tool (RAT).

  • Rootkits: Modify operating systems for gaining administrative control and exploiting access via privilege escalation.

Threat Intelligence and Research Sources
  • The United States Computer Emergency Readiness Team (US-CERT) and Department of Homeland Security maintain a dictionary of common vulnerabilities and exposures (CVE).

  • Other sources include:

    • Dark Web: A part of the Internet requiring special configurations to access.

    • Indicator of Compromise (IOC): Evidence like malware signatures signaling security breaches.

    • Automated Indicator Sharing (AIS): An initiative enabling real-time cybersecurity indicator exchanges.

1.2 Deception

Social Engineering
  • Social Engineering: A strategy that manipulates individuals into revealing confidential information through deceitful means.

  • Common attack types:

    • Pretexting: Using lies to obtain confidential info.

    • Quid Pro Quo: Offering something in exchange for personal information.

    • Identity Fraud: Using stolen identities to obtain goods/services.

Social Engineering Tactics
  • Tactics used to gain sensitive information include:

    • Authority

    • Intimidation

    • Consensus

    • Scarcity (implying limited availability)

    • Urgency

    • Familiarity & Trust

Shoulder Surfing and Dumpster Diving
  • Shoulder Surfing: Observing over someone's shoulder to obtain sensitive data (e.g., PINs).

  • Dumpster Diving: Going through trash to find discarded sensitive information. Shred important documents before disposal.

Impersonation and Hoaxes
  • Impersonation: Pretending to be someone to manipulate others into actions they wouldn’t typically take.

  • Hoaxes: Deceptive acts causing disruption, akin to an actual security breach.

Piggybacking and Tailgating
  • Occurs when someone unauthorized follows an authorized person into a secure area. Methods of prevention include utilizing a mantrap to limit access through dual-locked doors.

Other Methods of Deception
  • Common methods include:

    • Invoice Scam: Sending fake invoices for payment.

    • Watering Hole Attack: Compromising a frequently visited site to infect target devices.

    • Typosquatting: Using mistyped URLs to redirect users to malicious sites.

    • Prepending: Adding deceptive prefixes to emails to make them appear legitimate.

    • Influence campaigns.

Defending Against Deception
  • Increase awareness of social engineering and educate employees on measures:

    • Never share confidential information with unknown parties.

    • Avoid clicking on suspicious emails and web links.

    • Implement security policies with regular updates.

    • Encourage vigilance against unknown pressures.

1.3 Cyber Attacks

What's the Difference?
Types of Malware
  • Virus: Codes that replicate by attaching to other files.

  • Worms: Exploit vulnerabilities independently to replicate.

  • Trojan Horse: Malware disguised as a legitimate program.

Logic Bombs
  • A dormant piece of malicious code activated by a specific event, capable of damaging data or system integrity upon activation.

Ransomware
  • Restricts access to data until a ransom is paid, often done via encryption, with many victims finding no resolution even after payment.

Denial of Service (DoS) Attacks
  • A straightforward attack resulting in network service interruptions, characterized by:

    • Overwhelming data traffic causing delay/crashes.

    • Sending maliciously formatted packets that crash service responses.

Domain Name System (DNS) Attacks
  • DNS Vulnerabilities: Exploitable due to critical operational requirements like routing, addressing, and domain naming. Attack types include:

    • DNS Spoofing: Introducing false data into DNS caches.

    • Domain Hijacking: Gaining unauthorized control over DNS information leading to illicit changes.

Layer 2 Attacks
  • Types include:

    • Spoofing (MAC, ARP, IP)

    • MAC Flooding: Compromises data through the generation of fake MAC addresses.

Man-in-the-Middle (MitM) Attacks
  • Interception of communications between two devices for data theft or impersonation.

    • MitMO (Man-in-the-Mobile): Taking control of mobile devices for exfiltration of sensitive information.

Zero-Day Attacks
  • Exploiting software weaknesses unknown to the vendor, highly vulnerable period exists until patches are released.

Keyboard Logging
  • Involves recording keystrokes to capture sensitive information like passwords, using either software or hardware.

Defending Against Attacks
  • Tasks to prevent cyber attacks include:

    • Configuring firewalls to prevent unwarranted traffic.

    • Keeping patches & upgrades current.

    • Distributing workloads across server systems effectively.

    • Blocking external ICMP packets to protect against DoS attacks.

1.4 Wireless and Mobile Device Attacks

Grayware and Smishing
  • Grayware: Unwanted applications that can track locations or deliver unwanted advertising.

  • Smishing: Phishing via SMS to deceive users into visiting malicious sites.

Rogue Access Points
  • Unauthorized access points may be set up within secure networks, potentially allowing for data capture or MitM attacks.

Radio Frequency Jamming
  • Disruption of wireless signals through electromagnetic interference, necessitating equal jamming specifications to be effective.

Bluejacking and Bluesnarfing
  • Bluejacking: Sending unsolicited messages using Bluetooth.

  • Bluesnarfing: Unauthorized data transactions using Bluetooth connections, like accessing emails and contacts.

Attacks Against Wi-Fi Protocols
  • WEP and WPA: Security protocols for wireless networks, with WEP lacking proper key management making it vulnerable. WPA2 is more secure against traffic observation.

Wi-Fi and Mobile Defense
  • Strategies include:

    • Enabling authentication and encryption features; modifying default settings.

    • Properly placing access points for security.

    • Deploying WLAN detection tools for rogue networks.

    • Establishing guest access policies.

    • Utilizing remote access VPNs for secure connections.

1.5 Application Attacks

Cross-Site Scripting (XSS)
  • Exploits vulnerabilities in web applications by injecting malicious scripts that affect user browsers.

Code Injection
  • Various attacks include:

    • SQL Injection: Exploiting unfiltered user inputs to manipulate databases.

    • XML Injection: Affecting XML databases through corrupted data inputs.

    • DLL Injection: Deceiving applications into executing malicious code.

    • LDAP Injection: Manipulating directory services through weak inputs.

Buffer Overflow
  • Occurs when buffer data exceeds its designated limits, threatening system stability and security.

Remote Code Executions
  • Allows attackers to run commands via vulnerabilities, often leading to privilege escalation.

Other Application Attacks
  • Types include:

    • Cross-Site Request Forgery (CSRF): Forcing unauthorized commands through authenticated requests.

    • Race Condition Attacks: Compromising task sequences by forcing simultaneous operations.

    • Improper Input Handling Attacks: Compromising applications through unvalidated user input.

    • Error Handling Attacks: Exploiting error messages for valuable internal information.

    • API Attacks: Exploiting APIs for systemic abuses.

    • Replay Attacks: Manipulation of valid data transmissions by resubmission.

    • Directory Traversal Attacks: Gaining unauthorized access to system files.

    • Resource Exhaustion Attacks: Overloading server resources beyond limits.

1.6 Additional Insights

Spam and Phishing Attacks
  • Spam: Unsolicited emails often containing malware or malicious links. Indicators include unclear subject lines, requests for account updates, and weird formatting.

  • Phishing: Attempts to extract personal information by masquerading as a legitimate source; includes spear phishing targeted at individuals, vishing over voice calls, and whaling against high-profile individuals.

Defending Against Email and Browser Attacks
  • Strategies include:

    • ISP filtering of spam.

    • Antivirus and software filters for security against malicious emails.

    • Educating employees about unsolicited email risks.

    • Regular scanning of attachments for malware.

Other Common Attacks
  • Physical Attacks: Direct assaults on infrastructure or hardware.

  • Adversarial AI Attacks: Exploiting vulnerabilities within AI algorithms.

  • Supply Chain Attacks: Threats originating from third-party vendors.

  • Cloud-Based Attacks: Exploiting cloud-stored data and applications across platforms.

Summary of Key Concepts

  • A threat domain is an area of exploitability for attackers.

  • Cyber threats can be categorized as internal or external.

  • Social engineering manipulates individuals for sensitive data extraction.

  • Malware encompasses any harmful code designed to compromise systems.

  • Grayware represents unwanted applications potentially compromising user privacy.

  • Ensuring secure coding and data management is pivotal for safeguarding against threats.