CISCO Cybersecurity Essentials Study Notes
CISCO Cybersecurity Essentials 3.0
Module 1: Cybersecurity Threats, Vulnerabilities, and Attacks
Module Objectives
Module Title: Cybersecurity Threats, Vulnerabilities, and Attacks
Module Objective: Explain how threat actors execute some of the most common types of cyber attacks.
Topic Objectives
Common Threats:
Explain the threats, vulnerabilities, and attacks that occur in various domains.
Deception:
Identify different deception methods used by attackers to deceive their victims.
Cyber Attacks:
Describe common types of network attacks.
Wireless and Mobile Device Attacks:
Describe common types of wireless and mobile device attacks.
Application Attacks:
Describe types of application attacks.
1.1 Common Threats
Threat Domains
A threat domain is an area of control, authority, or protection that attackers can exploit to gain access to a system. Attackers can exploit systems within a domain through:
Direct, physical access to systems and networks.
Wireless networking that extends beyond an organization's boundaries.
Bluetooth or near-field communication (NFC) devices.
Malicious email attachments.
Less secure elements within an organization’s supply chain.
An organization’s social media accounts.
Removable media such as flash drives.
Cloud-based applications.
Types of Cyber Threats
Category Types of Cyber Threats
Software Attacks:
Examples include denial-of-service (DoS) attacks, computer viruses.
Software Errors:
Issues like software bugs, application downtime, cross-site scripting, or illegal file server shares.
Sabotage:
Actions by authorized users to compromise databases or deface websites.
Human Error:
Mistakes such as inadvertent data entry errors or misconfiguration of firewalls.
Theft:
Incidents like stealing laptops or equipment from unsecured locations.
Hardware Failures:
Issues including hard drive crashes.
Utility Interruption:
Events like electrical power outages or water damage from sprinkler failures.
Natural Disasters:
Severe weather events such as hurricanes, earthquakes, floods, and fires.
Internal vs External Threats
Valuable, Sensitive Information: Includes personnel records, intellectual property, financial data.
Internal Threats:
Actions by current/former employees or contractors, often through compromised servers.
External Threats:
Typically arise from independent attackers exploiting vulnerabilities or using social engineering techniques.
User Threats and Vulnerabilities
A user domain consists of individuals accessing an organization’s information systems, including employees, customers, and contractors.
Users represent the weakest link in information security systems, posing significant risks such as:
Lack of awareness regarding security policies.
Poor enforcement of existing security measures.
Data theft, unauthorized activity, and destruction of systems or data.
Threats to Devices
Common device-related threats include:
Unattended powered-on devices.
Downloading from unreliable sources.
Installed software vulnerabilities.
Uses of unauthorized USB drives on network devices.
Lack of policies to protect IT infrastructures.
Use of outdated hardware and software.
Threats to the Local Area Network (LAN)
Typical LAN threats include:
Unauthorized access to wiring closets, data centers, and computer rooms.
Network vulnerabilities and software updates.
Unauthorized access to systems and applications.
Rogue users accessing wireless networks.
Exploitation of data in transit.
Misconfigured firewalls leading to vulnerabilities.
Threats to the Private Cloud
The private cloud domain includes:
Unauthorized probing and port scanning.
Unauthorized access to resources.
OS/software vulnerabilities in routers and network devices.
Configuration errors in network devices.
Remote access to sensitive data by unauthorized users.
Threats to the Public Cloud
The public cloud includes services accessible to the general public, which can be exploited through:
Software as a Service (SaaS): Centralized software accessed via web.
Platform as a Service (PaaS): Development environment for applications hosted externally.
Infrastructure as a Service (IaaS): Virtualized computing resources purchased on demand.
Threats to Applications
Applications are critical for organizational operations and can face:
Unauthorized access to data centers.
Server downtimes.
Vulnerabilities in network operating systems or software.
Potential for data loss in client-server applications.
Threat Complexity
Software vulnerabilities arise from programming errors, protocol weaknesses, or misconfigurations.
Attack methods by cybercriminals include:
Advanced Persistent Threat (APT): Continuous spying efforts utilizing multiple actors and complex malware.
Algorithm Attacks: Exploiting software algorithms for unintended harmful results.
Backdoors and Rootkits
Backdoors: Programs providing unauthorized access to systems bypassing normal authentication. E.g., Remote Administrative Tool (RAT).
Rootkits: Modify operating systems for gaining administrative control and exploiting access via privilege escalation.
Threat Intelligence and Research Sources
The United States Computer Emergency Readiness Team (US-CERT) and Department of Homeland Security maintain a dictionary of common vulnerabilities and exposures (CVE).
Other sources include:
Dark Web: A part of the Internet requiring special configurations to access.
Indicator of Compromise (IOC): Evidence like malware signatures signaling security breaches.
Automated Indicator Sharing (AIS): An initiative enabling real-time cybersecurity indicator exchanges.
1.2 Deception
Social Engineering
Social Engineering: A strategy that manipulates individuals into revealing confidential information through deceitful means.
Common attack types:
Pretexting: Using lies to obtain confidential info.
Quid Pro Quo: Offering something in exchange for personal information.
Identity Fraud: Using stolen identities to obtain goods/services.
Social Engineering Tactics
Tactics used to gain sensitive information include:
Authority
Intimidation
Consensus
Scarcity (implying limited availability)
Urgency
Familiarity & Trust
Shoulder Surfing and Dumpster Diving
Shoulder Surfing: Observing over someone's shoulder to obtain sensitive data (e.g., PINs).
Dumpster Diving: Going through trash to find discarded sensitive information. Shred important documents before disposal.
Impersonation and Hoaxes
Impersonation: Pretending to be someone to manipulate others into actions they wouldn’t typically take.
Hoaxes: Deceptive acts causing disruption, akin to an actual security breach.
Piggybacking and Tailgating
Occurs when someone unauthorized follows an authorized person into a secure area. Methods of prevention include utilizing a mantrap to limit access through dual-locked doors.
Other Methods of Deception
Common methods include:
Invoice Scam: Sending fake invoices for payment.
Watering Hole Attack: Compromising a frequently visited site to infect target devices.
Typosquatting: Using mistyped URLs to redirect users to malicious sites.
Prepending: Adding deceptive prefixes to emails to make them appear legitimate.
Influence campaigns.
Defending Against Deception
Increase awareness of social engineering and educate employees on measures:
Never share confidential information with unknown parties.
Avoid clicking on suspicious emails and web links.
Implement security policies with regular updates.
Encourage vigilance against unknown pressures.
1.3 Cyber Attacks
What's the Difference?
Types of Malware
Virus: Codes that replicate by attaching to other files.
Worms: Exploit vulnerabilities independently to replicate.
Trojan Horse: Malware disguised as a legitimate program.
Logic Bombs
A dormant piece of malicious code activated by a specific event, capable of damaging data or system integrity upon activation.
Ransomware
Restricts access to data until a ransom is paid, often done via encryption, with many victims finding no resolution even after payment.
Denial of Service (DoS) Attacks
A straightforward attack resulting in network service interruptions, characterized by:
Overwhelming data traffic causing delay/crashes.
Sending maliciously formatted packets that crash service responses.
Domain Name System (DNS) Attacks
DNS Vulnerabilities: Exploitable due to critical operational requirements like routing, addressing, and domain naming. Attack types include:
DNS Spoofing: Introducing false data into DNS caches.
Domain Hijacking: Gaining unauthorized control over DNS information leading to illicit changes.
Layer 2 Attacks
Types include:
Spoofing (MAC, ARP, IP)
MAC Flooding: Compromises data through the generation of fake MAC addresses.
Man-in-the-Middle (MitM) Attacks
Interception of communications between two devices for data theft or impersonation.
MitMO (Man-in-the-Mobile): Taking control of mobile devices for exfiltration of sensitive information.
Zero-Day Attacks
Exploiting software weaknesses unknown to the vendor, highly vulnerable period exists until patches are released.
Keyboard Logging
Involves recording keystrokes to capture sensitive information like passwords, using either software or hardware.
Defending Against Attacks
Tasks to prevent cyber attacks include:
Configuring firewalls to prevent unwarranted traffic.
Keeping patches & upgrades current.
Distributing workloads across server systems effectively.
Blocking external ICMP packets to protect against DoS attacks.
1.4 Wireless and Mobile Device Attacks
Grayware and Smishing
Grayware: Unwanted applications that can track locations or deliver unwanted advertising.
Smishing: Phishing via SMS to deceive users into visiting malicious sites.
Rogue Access Points
Unauthorized access points may be set up within secure networks, potentially allowing for data capture or MitM attacks.
Radio Frequency Jamming
Disruption of wireless signals through electromagnetic interference, necessitating equal jamming specifications to be effective.
Bluejacking and Bluesnarfing
Bluejacking: Sending unsolicited messages using Bluetooth.
Bluesnarfing: Unauthorized data transactions using Bluetooth connections, like accessing emails and contacts.
Attacks Against Wi-Fi Protocols
WEP and WPA: Security protocols for wireless networks, with WEP lacking proper key management making it vulnerable. WPA2 is more secure against traffic observation.
Wi-Fi and Mobile Defense
Strategies include:
Enabling authentication and encryption features; modifying default settings.
Properly placing access points for security.
Deploying WLAN detection tools for rogue networks.
Establishing guest access policies.
Utilizing remote access VPNs for secure connections.
1.5 Application Attacks
Cross-Site Scripting (XSS)
Exploits vulnerabilities in web applications by injecting malicious scripts that affect user browsers.
Code Injection
Various attacks include:
SQL Injection: Exploiting unfiltered user inputs to manipulate databases.
XML Injection: Affecting XML databases through corrupted data inputs.
DLL Injection: Deceiving applications into executing malicious code.
LDAP Injection: Manipulating directory services through weak inputs.
Buffer Overflow
Occurs when buffer data exceeds its designated limits, threatening system stability and security.
Remote Code Executions
Allows attackers to run commands via vulnerabilities, often leading to privilege escalation.
Other Application Attacks
Types include:
Cross-Site Request Forgery (CSRF): Forcing unauthorized commands through authenticated requests.
Race Condition Attacks: Compromising task sequences by forcing simultaneous operations.
Improper Input Handling Attacks: Compromising applications through unvalidated user input.
Error Handling Attacks: Exploiting error messages for valuable internal information.
API Attacks: Exploiting APIs for systemic abuses.
Replay Attacks: Manipulation of valid data transmissions by resubmission.
Directory Traversal Attacks: Gaining unauthorized access to system files.
Resource Exhaustion Attacks: Overloading server resources beyond limits.
1.6 Additional Insights
Spam and Phishing Attacks
Spam: Unsolicited emails often containing malware or malicious links. Indicators include unclear subject lines, requests for account updates, and weird formatting.
Phishing: Attempts to extract personal information by masquerading as a legitimate source; includes spear phishing targeted at individuals, vishing over voice calls, and whaling against high-profile individuals.
Defending Against Email and Browser Attacks
Strategies include:
ISP filtering of spam.
Antivirus and software filters for security against malicious emails.
Educating employees about unsolicited email risks.
Regular scanning of attachments for malware.
Other Common Attacks
Physical Attacks: Direct assaults on infrastructure or hardware.
Adversarial AI Attacks: Exploiting vulnerabilities within AI algorithms.
Supply Chain Attacks: Threats originating from third-party vendors.
Cloud-Based Attacks: Exploiting cloud-stored data and applications across platforms.
Summary of Key Concepts
A threat domain is an area of exploitability for attackers.
Cyber threats can be categorized as internal or external.
Social engineering manipulates individuals for sensitive data extraction.
Malware encompasses any harmful code designed to compromise systems.
Grayware represents unwanted applications potentially compromising user privacy.
Ensuring secure coding and data management is pivotal for safeguarding against threats.