have fun in a fundamental number. Two
external and internal threats exist
on the network at all times.
this is based on threat models that have been created over time.
You know some common threat models air stride that is created by Microsoft. Dread
past the trike and bust,
so lots to choose from that help you understand who you're likely Attackers will be.
Threat models can also help with categorizing your attack, starting with script kiddies,
targeted Attackers, insider threats, trusted insider threats and state level actors.
But the zero trust model generally all those are up c 3552 which is the Internet's threat model, according to the book zero Trust networks. Building secure systems and untrusting networks by even Guillen and Doug Breath
And that's the reason why I have The decisions around. Security are created when dealing with zero trust network model.
So in the next lad we we see a progression of an attack that leads to pivot on the network.
So number one we could see a phishing attack that is deployed and targets employees
number two Ah, computer on the network is compromised. A reverse shell is established,
and then three additional reconnaissance can occur that leads to enumeration of user names and neighboring computers.
Four. We see a lateral movement that begins on the network and a privilege computer identified.
Step five. Local administrative privileges are achieved and a key logger installed.
and HR directors. Password is stolen.
Seven. Compromise production payroll system or or from a privilege HR account Right
on and Step eight. We see the HR account used to change bank and information.
Then we moved to Step nine, where paychecks are deposited into a hacker's account
and maybe Step 10 which isn't on the sly. We could continue to go further here. In our thinking, a hacker could use those same credentials. The HR count that Clear Law was on the HR system that was compromised to cover their tracks,
so there's a lot of reasons why an attack like this is successful.
But if we treated all zones the same and place the same amount of security
and have the same amount of monitoring,
could things have turned out differently in the scenario that I just kinda came up with and spoke to?
So if the payroll system was an untrusted zone. The operator will likely have multi factor authentication deployed, maybe device posture configured.
If this is true, then it should be true. No matter what zone the HR system is in
a user name and password should never be enough to trust a user or device.
An example of how the zero trust concept can help here is in step number five. No, we read that the local administrator privileges
now. A solution like Microsoft laps
that allow a different local administrative password that also expires and rotates would be a great zero dress model
or concept to implement that would reduce or completely mitigate and Attackers ability to pivot on the network.
So continue to think about other security tools
that you think would fit in removing trust from the different zones, accounts, devices and applications. In this scenario, you know, write it down, make it a quick exercise for you just to kind of think about if you were minimised and trust.
are currently available that would allow you to get to that zero trust model.
So let's review what we covered in this section.
We focused on fundamental number one and fundamental number two of the zero trust model, which are the network is always assumed to be hostile and external and internal threats exist on the network at all times.
We also discussed how Attackers stepped through a chain of events on traditional networks, helped create a distinction between traditional networks and zero trust networks. Thank you for your time. Stay tuned.
So I'm back with another pop quiz. This is in reference to the section that we just covered and we talked about a lot. So we've got a quick learning check here. First question for you is is the threat model stride created by Google or Microsoft
number two? What is pivot in
on a network mean and number three? What the right model does he would trust Follow. All of this was covered in our last section. And again, I learned check for you here before we move on.
So now we move on to the answers for these three questions.
So number one what we have is is the threat model stride created by Google or Microsoft. And the answer is Microsoft
on stride stands for spoof any tampering, repudiation, information, disclosure, denial of service in elevation of privilege. There are many threat models out there, several that we briefly touched on, but in the supplemental material section, you have much more
and read at your leisure.
Number two. We have what is pivot in on a network mean, and that's simply the ability to move from one note to the next.
Hacker has the ability to pivot, he's able to move east or west on your network,
and it means that they're able to jump from one computer to the next actor performing additional reconnaissance on your network
once one computer or nodes been happy.
Ah, the next question. What threat model does zero trust follow? And we talked about this briefly as well in the last section, and that is the Internet threat model Rxc 3552
Thanks so much for staying with me. I'll see you soon