Introduction
In this skill we're focusing on Attack Threats & the CIA triad. Attackers have preferred threat methods they use to carry out attacks and they're looking for weak points, or vulnerabilities, they can exploit to gain access. This might be as simple as a phishing email to fool someone into giving up their credentials. Or it could be more complicated by identifying a vulnerability in a web server giving them access to the root of that web server and then harvesting data from that server and trying to move laterally within the network. So let's spend a little time discussing these attack threats and the CIA triad.
Attack Threats Part 1
In this nugget, we're going to start off with some foundational terms to set the stage for our attack threats so let's get started.
Nugget 1:
Nugget 2:
Knowledge Check
Which of the following is a weakness in a system or software?
Attack Threats Part 2
We're continuing with attack threats and moving onto threats such as insecure API's, compromised credentials and post-quantum cryptography
Knowledge Check
When dealing with compromised credentials, this isn't only about passwords, but also tokens. (True or False)?
Attack Threats Part 3
We're wrapping up our list of attack threats by coving threats to Artificial Intelligence and how threats can change based on your location.
Knowledge Check
Which of the following is a type of attack against AI where the attacker gets a copy of the AI model?
The CIA Triad
The CIA Triad is a foundational security model focused on protecting data. It ensures sensitive information is accessed only by authorized users, remains accurate and untampered, and is accessible when needed.
Knowledge Check
What does the "A" in CIA triad stand for?
Validation
Congratulations on making it to the end of this skill. Now it's time for a validation challenge to put that newly acquired knowledge to the test by answering a few review questions. Here we go!
Question 1
Knowledge Check
Which type of malware requires user interaction to spread (such as opening a file)?
Question 2
Knowledge Check
Which attack floods a system with traffic to make it unavailable?
Question 3
Knowledge Check
Which type of attack is social engineering?
Question 4
Knowledge Check
Insecure APIs can expose sensitive data if not properly protected. (True or False)?
Question 5
Knowledge Check
Which CIA Triad principle ensures data is accurate and not altered?
View Transcript
Attack Threats Part 1
0:00In this nugget, we're going to be talking about attack threats because we know in the world of
0:04cybersecurity, there's all kinds of attacks that can be carried out. And these are various threats.
0:09And we're going to start by setting a foundation. We'll talk about what a threat is versus what a
0:13vulnerability is versus what an exploit is. And once we do that, we'll start talking about these
0:18attacks. So let's get started. All right. So here we are setting the foundation. That's what we're
0:24going to do. And that's because we're going to talk about the difference between a threat,
0:28a vulnerability, and an exploit, just so that we're all on the same page here. So a threat,
0:34this is any potential danger. Okay. So it's danger to an asset. So this could be hackers,
0:41malicious employees. Yeah. Because there are such things as insider threats, malware,
0:46phishing, and the list goes on. These are all potential, that's key word there, potential
0:53dangers to assets. So that's what a threat is. Now, vulnerability is a little bit different.
0:58Vulnerability is a weakness, and that is in a system or software. Things like misconfigurations,
1:05poor coding practices, hard-coded passwords, that's a real bad one, or weak passwords, just as bad,
1:11bugs, using weak encryption, all these things are vulnerabilities. And you know what? The good
1:17thing about vulnerabilities is we can fix them. That's right. We can have good coding practices.
1:24We can make sure we're not using weak passwords. We're fixing any bugs that are found. We're not
1:30misconfiguring things. So these are something that we can address. This is something in our
1:35control. Now, a threat, that's not something in our control. So we really don't like those.
1:42All right. Lastly, how about an exploit? So when it comes to exploits, this is any way
1:49that an attacker can take advantage of a vulnerability to bypass the security of that
1:54system. So what they can use as exploits, usually it's some type of software, oftentimes a tool,
2:00and often techniques. So this is how they exploit it. So we've got our bad guys out there
2:06who identify vulnerabilities, and then they try to exploit them to gain access. So these are
2:13the foundational terms you really need to be familiar with, threats, vulnerabilities,
2:17and exploits, and of course what each of them is. All right. Moving on. We're going to now talk
2:23about various types of attack threats. So these are those threats out there. And the first one
2:29is malware. So when it comes to malware, there's different types. The first one is a virus. Now,
2:36we all have heard the term virus, but really what is a virus? Well, it's software designed to cause
2:43harm to a system. All right. That's pretty straightforward there. And it could be something
2:49on the system, like an application or a service that's running. But the thing is, it needs something.
2:55It needs a system to infect, and this is a key part here, human interaction. So this is when somebody
3:03clicks and installs something they shouldn't, or let something run they shouldn't, and it creates
3:07an incident where a virus is unleashed upon a system. Okay. So that is viruses. That's our first
3:14one. A second type of malware, Trojans. Now, Trojans are disguised as legitimate software.
3:22Okay. And they require user interaction. And oftentimes they'll create a backdoor or install
3:28malware, something like that. So we've got our little Trojan horse down there. We've got a virus
3:32over here. Okay. So again, this needs human interaction in order to do what it does. Okay.
3:41But it's disguised as legitimate software. All right. Next up, we have rootkits. Now, this is
3:49software that hides deep in the operating system, and it works to avoid detection. So really what
3:56this is, this is a backdoor that's implanted by a bad guy. Could be done through a Trojan or a virus,
4:02but it gives the attackers persistent control. And that just means they maintain control. And
4:09oftentimes they'll reach out to what we call a C2 server. That's a command and control
4:14for direction. So the idea is if we had a computer down here and it had that rootkit in it, well,
4:21what it would do is if we had out here in the cloud somewhere, we had a C2 server, it's going
4:27to reach out and check in every so often. It might be every 30 minutes or an hour or something
4:33like that. And it's going to say, hey, do you have anything you want me to do? And there might be a
4:38command come back to, yeah, I would like you to create this user account with this password,
4:43with these permissions. And the rootkit can do that on the device. So it's all kinds of things
4:48like that. So rootkits are very, very dangerous. So lastly, as far as malware class of threats,
4:55we've got worms. That's right. So worms are similar to viruses. However, there's a big
5:03differentiator. They can self-replicate between systems with no human interaction.
5:11That's not good, right? Absolutely not. So if a worm is introduced into an environment,
5:16it can then self-replicate between hosts in that environment. So what do we do to protect against
5:24these? Well, we're going to need some type of endpoint protection. All right. That's what's
5:29really going to help us here as one layer. Because really, when it comes to security,
5:35we practice something called defense in depth. So we'll say in depth. And what that means is
5:42you have different layers. So you've got maybe a firewall, an IPS. You could have your endpoint
5:48protection software. You can have email filtering software, web filtering software. But the idea is
5:54with defense in depth, we have all these different layers. And endpoint protection is one of those
6:00layers. And this could be something like the Cisco Secure Endpoint. OK. And that's formerly known as
6:07AMP. Just for reference, if you've heard of AMP before. Well, now Secure Endpoint is what Cisco
6:12uses for their endpoint protection. So there you go. That is our malware and the various types of
6:19malware. OK. Next up, we're talking about malware payloads. So what is a payload? Well, if you think
6:27about it, just think about, well, like a B-52 bomber or something. Well, what we do is we have this
6:34bomber out here. It's going out. And it's going to drop some bombs somewhere. That's what it's supposed
6:39to do. So what happens is they fly along. And when they get there, they drop there. That's right,
6:45the payload, which are the bombs which go boom. OK. So if you think of the aircraft as the hacker
6:53or attacker, well, they've got payloads and those payloads are what go boom, except they don't
6:59actually explode necessarily, but they do things. It could be creating accounts. It could be assigning
7:05permissions. It could be pulling file hashes or pulling password hashes off of systems. But the
7:12idea is when there is a type of virus or it could be a Trojan or even a worm, the idea is what these
7:21do is they carry a payload. So once they are delivered onto a system, it could be a user
7:29interaction or with worms. It doesn't have to be user interaction. Well, you're going to then run
7:34that payload. That's what these viruses and Trojans and worms could do. They use that payload and it
7:40is executed on the endpoint where that malware is installed. OK, so that's the idea of a payload.
7:47Super. Now, here we go. Yes, we're going to talk about TCP, the protocol here, transmission
7:54control protocol, TCP. Now, why on earth are we talking about TCP, Bob? This is security stuff.
8:01What's TCP got to do with anything? Well, I'll tell you, there's a certain type of attack
8:09called denial of service or distributed denial of service, and it helps to understand how TCP works
8:15so you can understand how those attacks work. Now, if you're not familiar with TCP and this is a
8:20layer four or transport layer protocol because you've heard of UDP as well. Well, this is the
8:27TCP and of the TCP UDP dynamic duo. So here we're talking about TCP transmission control protocol.
8:35Now, this is what's called a connection oriented protocol. And what that means is before data is
8:43passed, there's a handshake that takes place. A connection is established or oriented before data
8:50is sent. So if Bob wants to talk to Lois, what he's going to do, well, his system is going to
8:55do this. He's not personally. All right. But when he clicks on something that wants to communicate
8:59with Lois's server over here, well, it's going to go out and it's going to send what we call
9:05a SYN packet. OK. And that's basically saying, hey, I'd like to talk to you. OK. And Lois's
9:12server is going to send back something called a SYN AC packet. All right. So Lois's server is
9:20then saying, OK, yeah, sure, we can talk. Let's get started. And so then Bob's system is going
9:26to send back to Lois's server a final acknowledgment packet saying, all right, we have established this
9:34what's called a three way handshake because we have three actions that took place here.
9:41And at this point, we have what's called a session and we can start to pass data back and forth.
9:46OK. So that's how TCP works.
Attack Threats Part 1
0:00Now we're going to talk about a certain type of attack that I had alluded to just a minute ago,
0:07and that is denial of service and distributed denial of service. So let's talk about how
0:13these work. Now there's multiple ways that these can work, but one of the most common types is
0:18called a TCP SIN flood. So if I do TCP SIN flood, that's what that's called, and this is just one
0:26example of a type of denial of service or distributed denial of service. So let's talk
0:31about how this works. So you've got the attacker over here and his target over here. So what will
0:36happen is they'll send a SIN packet across, all right, and the server sends back, of course, a SIN
0:45ACK, but the attacker never sends the final ACK. That does not happen. So what this does is it,
0:54when this server over here, the target sends that SIN ACK, it leaves that open and listening,
1:01so it's got this ear over here, it's listening for that final ACK to come back. And the
1:05idea of this being open and listening, guess what it's doing? It's using resources,
1:12and we're talking about is like CPU and memory, more specifically. Okay. So the idea is in a TCP
1:21SIN flood scenario, the attacker here is going to send maybe, who knows, like 100,000 SINs,
1:28all within a very, very, very short period of time. We're talking just a few seconds.
1:33So it's going to flood this target full of SINs, and it's going to respond to them all with SIN ACKs,
1:39and everyone is going to use up a little tiny bit of resources. But when you've got 100,000
1:45tiny little resources being used up, you might max out their CPU and memory, which is going to
1:51cause that server to not be available for service. At that point, there's no resources left. So it's
1:58basically, at this point, just kind of stuck. It can't respond to anything. It has no resources
2:03available to use. Well, this is one example of a denial of service. The idea here with a DOS
2:09attack or denial of service is an attacker is going to try to use up as much resources on a
2:13target as it can so they can no longer respond to valid service requests. Okay. Now, a distributed
2:21denial of service, the only difference is when you have a standard denial of service, it's usually
2:26one attacker in one point going to a target. So let's say our target could be right over here.
2:33Here's our target. Okay. And our attacker is over here. Well, it's one attacker to one target.
2:40And there is a limit on how many SINs that one device can send within a short period of time,
2:45of course. But the distributed part means there are multiple attackers. Okay. So we've got some
2:52over here, some over here, some over here. I'll put them all over the place. And guess what?
2:55They're all attacking multiple from a distributed attack source. Okay. And a lot of times,
3:02this is using something called a botnet. And a botnet is basically where an attacker will go out
3:09and infect several machines with malware. And they're going out and connecting to the C2 server,
3:14like we talked about. And it's going to say, hey, I want everybody at noon Greenwich Mean Time. So
3:21at noon GMT, I want you to go attack this host, this target over here. So what's going to happen
3:27at noon? They're all going to strike out and try to use up all the resources on this target
3:32so that it can no longer respond to valid session requests. So that's denial of service
3:37and distributed denial of service. All right. Super. Let's move on. Next up, we have a man in
3:44the middle attack. So MITM, as it's abbreviated, or it's also known as an on path attack. And that's
3:52because the attacker is on the same path or trajectory as that data flowing through the
3:57network environment. So this is where an attacker places themselves in the middle of a conversation
4:03between a target and whatever resource that target is trying to access. So there's different ways that
4:10this can happen. One of the ways is something called ARP spoofing. Okay. So if this attacker
4:18could get on the same local network as the target over here, his machine can send out spoofed ARP
4:25messages so that this attacker's computer to the rest of the network appears to be the default
4:34gateway. Okay. So that all traffic's going to be routed through it. And then the attacker's
4:38machine will route it through the actual, you know, router or firewall or whatever.
4:42And the attacker becomes basically a proxy, which can then see all that data. You got it.
4:51Okay. So that is an on path attack or man in the middle attack. But you say, what do you mean you
4:57can see the traffic? What if we're talking about HTTPS traffic? It's secure, right? Well, yes,
5:03it is. Except there's an attack called SSL stripping. And that's where, let me change colors
5:08here. That's where this all takes place like we see here, except when the attacker forwards this
5:15traffic, the original request is going out to HTTPS dot dot slash slash some website. Okay.
5:24All right. So what happens is during the SSL stripping process, the S gets removed from the
5:31request before it's forwarded. Then it's forwarded as an HTTP request. Okay. So that's called SSL
5:39stripping. And that way we've got that eyeball down here seeing all the traffic coming across.
5:44So this is a man in the middle attack. Now there's several different ways this can happen.
5:49Using ARP spoofing and SSL strip is just one of the techniques used to do that. All right. Now
5:56let's talk about data breaches because we just need to really make sure we're all on the same
6:02page as far as some certain terms. Now, a data breach is unauthorized access to sensitive data
6:10and not just sensitive data, really any data. And again, the key here is unauthorized. So this
6:17would be a data breach, especially when it comes to things like, you know, your customer records.
6:22Yeah, that's a lot of personal or private or sensitive information. Could be credit card
6:29numbers. It could be medical data, things like that. But there's also other types of breaches
6:36because this here is known as a data breach, but there's other types of breaches such as
6:44account compromise. That's a type of breach where an account is breached itself or the identity that
6:51users credentials. Okay. Also a system breach. And this is just where an attacker's gain access
6:58to any system or even security breach. And this is basically just a generic term for any kind of
7:08security related breach. So a data breach, an account compromise system breach, they could
7:12all be called a security breach, but a breach is just something we really don't want to happen.
7:17All right. At this point, we're going to go ahead and take a break and we will continue
7:21in the next nugget with insecure APIs. So I'll see you there shortly.
Attack Threats Part 2
0:00All right. Welcome back. And now we're continuing with our attack threats and we're looking at
0:05insecure APIs. And an API is an application programming interface. And if you're not
0:10familiar with what an API actually is or what it does, it basically allows you to use web traffic
0:17or web commands in order to interact with some type of program or service. Okay. So you don't
0:26have to use a web UI or PowerShell. You could use something called an API. And this is used a lot
0:32between applications. So if you had this app over here, app one, and your business uses that all
0:38the time, and maybe they use it for inventory and you had a sales system over here, and this is used
0:43by the company. There we go. Sales. And you might configure these to use APIs in order for the sales
0:51to talk to the app one to identify how much inventory is available. And then you might have
0:57a separate system that's used for purchasing. Okay. And so the sales API goes out and checks
1:04the inventory because somebody just sold a thousand widgets. Okay. We're big on widgets.
1:11Okay. But we only have 900 in inventory. Well, then what we need to do is sales could use an API
1:18to talk to the purchasing software platform and say, hey, we need to make sure we have enough
1:24material on hand. So go purchase this material for a hundred more widgets. That way we can go
1:29ahead and make this sale complete and we can provide the customer with the resources, their
1:34widgets. So that's what an API is. And here's an example of one right here. So it's really simple.
1:40Get. Get just gets data. Put is another command. So put, well, as you can imagine, it puts data.
1:47So here, for example, with the sales to the app one, this is a get. We're getting some information
1:54here. Here, we're doing a put. We're putting information into that database. So we know we
1:59need to purchase material for a hundred more widgets. All right. So this is an example of
2:04what an API does. Okay. So we're talking about insecure APIs. Well, these APIs run as code
2:11on these various applications or systems. And if proper secure coding isn't being used,
2:17then there can be weaknesses. For example, authentication. We want authentication to
2:23happen. So when the sales goes over to request information to do a get from app one, how does
2:30app one know that it's actually the sales application we use and not something else?
2:36Well, that's where we need authentication. So weaknesses or insecure APIs often have
2:41no authentication, and that is a big no-no. Okay. Or these APIs might be a little loose. Okay. And
2:48what I mean by that is they return more data than needed. Okay. For example, when our sales down
2:57here goes across and talks here to our app one to get that inventory count, well, instead of just
3:04returning 900 because that's what we need to find out what's our inventory of widgets, it not only
3:10returns 900, but maybe it also returns a bunch of other information along with it. So it's being a
3:16little chatty, if you know what I mean. All right. And then lastly is poor input validation.
3:24And I want to spend a couple minutes talking about input validation and what that is. And that's
3:29because any time you have a system or application that is ingesting data from a user like here,
3:39it's not from a user, but it's from another system. If that data being put into that field,
3:45so if we had a field here for let's say username and one for password, if we're not checking to
3:51make sure that malicious code isn't being entered into here, then an attacker could actually put
3:57commands in here. And once they press the enter button down here to submit their username,
4:03password, which is actually malicious code in these fields. If the program doesn't validate
4:10that input and make sure it's not malicious, then you could actually run commands against systems.
4:16Okay. So yeah, that's really bad. And you're going to see as we go and talk about code and insecurities
4:22and applications and such, one of the biggest problems is that developers aren't using
4:30input validation. So they have poor input validations, which allows attackers to inject
4:35malicious code into systems and applications. Not a good thing, right? Absolutely not. Because within
4:42this API call here, maybe I included some extra commands after this, and it's going to go ahead
4:48and run them. Well, that could be a possibility. So this is just another threat we need to be aware
4:54of. All right. Next up is compromised credentials. Well, well, well. So this is when an account is
5:01compromised. The attacker gets the password basically for this username. So we'll have our
5:09username and password. And guess who got that? That's right. Our bad guy. Okay. Now, how did
5:16this happen? Well, the most common type is phishing. So a phishing email with a link that goes to,
5:23you know, msonline dot, dot, dot, dot, dot. At least that's what it looks like. The user clicks
5:29on it. They get what looks to be a valid, maybe Microsoft website. They put in their credentials
5:35and bada bing, bada boom, bad guy gets it. Okay. So that's one way phishing and actually probably
5:42the second most common way. The first most common way is simply weak passwords. Okay.
5:49So an attacker, they can go out and get your username. And that's just because it's probably
5:54the same as your email address. So they can pull that off of anything. Okay. And then they find
5:59your company's portal or something, and they begin to try to log in with your account. So you've got
6:05your username over here and the bad guy is then going to try a list of well-known passwords,
6:14things like, you know, summer 2024 exclamation point. And then in 2025, that gets to change 25
6:22and in 26, they changed it to 26. You know, this is a very weak password and very common,
6:28unfortunately. So the attackers out there know that they have like the top 10 or 20 or a hundred
6:34most commonly used passwords. And what they'll do is just use code or an application to go try
6:40to log in with your username and a password off this list. Right. And that is a type of brute
6:47force password attack. Now they'll only do it like once every 10 minutes or 15 minutes. So as to not
6:53lock your account out. Now it takes time, but you know what? It is effective. Now, another way,
6:59actually, I'm going to make some room here. So grab a screenshot if you want to, before I go
7:03erasing here, I'm going to grab this and we're going to get rid of that. All right. I need to
7:07make room for something because we're going to talk about another type of compromise credentials.
7:12And this is known as token theft. All right. So how this works is when you sign into an online
7:22portal or something, oftentimes you get what's called a token and it goes into your browser
7:27and it allows you to maintain authentication. So you don't have to log in every 15 minutes or
7:33something. Right. So you get this token on your system. Well, what happens is bad guys can use
7:37tools. One of them is called evil jinx. I'll put that in here. Evil G I N X evil jinx. And basically
7:45they send a fish to a user and it contains a link to an evil jinx server. All right. Now what this
7:55is, is basically this will look like an authentic website. So let's just go again with our Microsoft
8:01login. It's so super common. So we've got our, our login page here where the user's going to
8:06enter their credentials. So what happens is when they fall victim to this, they go to the website
8:12and you know what? It looks absolutely authentic. Well, that's because you can just clone a website,
8:17not difficult. Okay. So when they do that and they send their username and password over here to this
8:23website, well, evil jinx then forwards that to the real website. So we'll say real Microsoft website
8:31and then becomes a proxy at this point. So then the results come back and then it goes like that.
8:37Okay. But here's the thing. What about multi-factor authentication? Well, since evil jinx is the proxy,
8:44it can pass that information to this website. So it is actually going to allow the MFA to take place
8:53and once that happens, the token, remember our token we're talking about here, we've got a little
8:58token right here, is sent through evil jinx back over to the user. And guess what? The evil jinx
9:04user now have your token, which means they can authenticate without using MFA to your account.
9:12What? Yeah, it's pretty darn dangerous. So this is just another type of compromised credentials.
9:20Super duper. Let's keep rolling on. Here we go. PQC, post quantum cryptography. Yeah. So we're
9:28talking here, post quantum crypto. So what is this? Well, if you think about quantum computing,
9:34the idea is that we're going to have these computers over here that can perform absolutely
9:39mind-blowing equations and solve problems at just unheard of speeds, just things we've dreamt about.
9:46Well, the problem with this is if it's that good, it's going to be able to break
9:54our encryption that we use today within a few seconds, if that long. So that means if quantum
10:02computing is actually realized at this point in time, well, we would have no data privacy.
10:09You couldn't protect your data. There's no such thing as confidentiality anymore,
10:14because all crypto has been broken. So what we're talking about is post quantum.
10:19So the idea is we need some type of cryptography that will survive quantum computing. And there's
10:28a few different types here. One is called lattice-based cryptography. Another one is
10:34hash-based signatures. Another is multivariate quadratic equations. And finally, code-based
10:43schemes. We're not going to go into each one of these. The idea is you need to be aware of this
10:47situation. This is a threat, absolutely. And now it's not an attack per se, but it's a threat
10:56that if quantum computing is realized before we have something like this in production and
11:01available to us to use on our systems and devices, well, that's a threat. Okay. So that is post
11:08quantum cryptography. All right. At this point, we're going to go ahead and take another break,
11:12and we'll be back with some more attack threats. See you there shortly.
Attack Threats Part 3
0:00All right, we're back and it's time to go ahead and finish up our attack threats. I've got a
0:04couple more to go through. The first one is attack threats that AI faces. Pretty interesting. All
0:11right, let's get to work here. So what do we have? Well, one of the threats is called data poisoning
0:18and this is where an attacker poisons the training data used to train that AI model.
0:24Okay, so if you're not familiar with AI and different models and such, the idea is that it's
0:30not a simple program that knows all this information. That program that was created has to
0:36be trained. So what happens is you have various training models that are used to train the AI,
0:45just like you would train a new employee on how to do something. The same thing. These AI models
0:51are trained for something specific. Okay, so if an attacker could gain access to the training
0:57models, well, guess what? It could modify those model behavior to make that model actually bias
1:05and make incorrect predictions. Yep, so that's a bad thing, right? It sure is. And that's known as a
1:11targeted data poisoning attack. There's also an exploratory data poisoning attack and that just
1:18looks to degrade the model's performance so that it's just really not usable. So when it comes to
1:25the targeted here, let's focus on that for a minute because I want you to think about this.
1:29What if you could gain access to a company's training models for their AI that is used
1:37in their endpoint protection software? Well, if you could do that, you could actually tell it
1:44or train it to realize that XYZ type of piece of software is actually safe. In reality,
1:54since you as the attacker are changing this training model, you the attacker could then use
2:00XYZ software to attack an endpoint. And this AI model over here used in the endpoint protection
2:08software is going to think that our XYZ software down here is safe, when in reality it's not.
2:16So yeah, that's a pretty bad thing as you can imagine. So okay, let's go ahead and wrap up this
2:22here. We got four more to look at here and we have your adversarial attack and that's where you're
2:28tricking the model into making incorrect decisions just like we talked about with our targeted data
2:35poisoning attack. You've also got model inversion attack and this uses the outputs from an AI model
2:41to infer details about the training data. So here we're trying to figure out what training data is
2:48being used and also is that training data public or is it private? Because if it's public we can
2:56kind of figure out how it's learning and maybe figure out ways around it or how to trick it.
3:02Okay, there's also model stealing and that's basically just creating a copy or a clone of that
3:08model, so the AI itself. So again you'd be able to study it in depth and figure out ways to get around
3:15the rails it has put in place for safety. And then lastly an AI trojan attack, also known as a back
3:22door attack. This is where the attacker will inject malicious behavior into the model and the attacker
3:28can trigger that at will. So that's why it's a back door because it sits there and until the
3:33attacker provides a certain input to that AI model and then it will go ahead and trigger that to do
3:41whatever the attacker has designed that attack to do. So there you go, those are attack threats
3:46that our AI faces. Okay, let's go ahead and wrap this up with common threats against location types.
3:52So here as far as location types, you've got on-premise, cloud, and hybrid. Now I do want to say
4:00really this comes down to where do the services reside. Because if it's a service on-prem
4:08then any type of attacks that are against that service, it doesn't matter where it's at, it's
4:13going to be there. If it's on-prem, it's in the cloud, if it's hybrid, it doesn't matter. So this is just
4:17kind of your rule of thumb right here. It's where that service resides. So let's take a look at this.
4:23For on-prem, these are some of the common types of attacks. You've got viruses, malware, denial of
4:30service, distributed denial of services, phishing, rootkits, man-in-the-middle, SQL injection, cross-site
4:36scripting, which we haven't got to yet. We will get to those, don't worry. Okay, so those are some common
4:41types of attacks. But in reality, if you think about it, if you're a SQL, because here we're
4:46talking about SQL injection, so it's an attack against a SQL database server. Well, if your SQL
4:52server is on-prem, then yeah, it's on-prem. But what if it's in the cloud? Well, then obviously it's going
4:56to be attacked in the cloud. So again, it just goes back to where your services reside. So here with
5:01the cloud, we see data breaches, insecure APIs, because yeah, cloud uses a lot of APIs, and you got
5:08your DOS and DDoS, and of course, compromised credentials. Could you have compromised credentials
5:12on-premise? Yeah, if you're AD servers, you're using Active Directory for your identity service
5:18provider. Well, if it's on-site, well, then your compromised credential is going to be part of
5:23on-site as well. But if your SQL injection is on the SQL server in the cloud, then yeah, your SQL
5:27injection is going to be in cloud. So this is not by any means an exact science as to what type of
5:34attacks take place where, because you could have API attacks on-prem. It's possible, yeah, absolutely,
5:40if your systems are talking back and forth via API and somebody gets in there and starts
5:44intercepting traffic and figures out what's going on, absolutely. All right, let's wrap this up with
5:48hybrid. So there's your answer. Pretty simple and straightforward. It's a combination of both. Well,
5:54of course it is, because you have a combination of on-prem and the cloud. So it's your combo pack.
5:59There you go. All right, that wraps up our attack threats. Awesome, we got through that. All right,
6:05next up, we're going to talk about one of the most important things you should understand
6:09in cybersecurity. I'm telling you, this is foundational and it's called the CIA triad.
6:15So I'll see you there shortly.
The CIA Triad
0:00Now we're talking about the CIA triad. So tri, meaning three, there are three sides to this
0:08triangle or triad, and they are confidentiality, that's our C, integrity, that's our I,
0:15and availability, that's our A. And I mentioned at the end of the last nugget that the CIA triad
0:20is one of the most important things you should know in cybersecurity. It's basically a foundational
0:29cybersecurity model, and it's designed to guide security policies within an organization. So it
0:34really focuses on three core pillars. And again, that's our confidentiality, our integrity,
0:40and our availability. So let's jump into each one of these. Okay. So when it comes to confidentiality,
0:46this ensures that sensitive data is only accessible to authorized individuals. So
0:52here we're looking for authorized access. We want to make sure that there is no unauthorized access.
0:59We need authorized access. Now, what does this mean? Well, when it comes to confidentiality,
1:05it means that when we have data, so let's put our server over here, here's our server,
1:10and we've got some data on that server right here, there we go, that we need to protect it
1:16accordingly. What does that mean? Well, authorized access. How do we authorize folks to access
1:23data on our servers? Well, oftentimes we have roles or permissions, and that's how we control
1:30who can access what. Because we've got our users up here, and it's also known as an identity,
1:38the user account that is. So they will be assigned roles and or permissions to access what they need
1:45access to. And in this instance, we need to make sure that they only have access to what they need
1:51in order to perform their job. That's called the Rule of Least Privilege. Okay. And we need to
1:58practice the Rule of Least Privilege. Okay. So that's one way we can focus on confidentiality.
2:06But what about, let's put a server over here, and this is maybe somewhere up in the cloud,
2:11and we're going to send data from our on-prem, so let's put on-prem here, up to the cloud.
2:18So when we do so, that data is going to transmit across the internet. So the internet up here is
2:26unsecure. There is no permissions on the internet. Okay. So your roles and permissions stay on-prem,
2:35and they can reside in your cloud as well. But in transit, so this is what we call
2:40data in transit, meaning it's in motion, it needs to be kept confidential. How do we do that?
2:46Well, I'll tell you. We use encryption. That's right. Encryption is how we achieve confidentiality
2:53when sending data across unsecured networks. Now, when our data is sitting here on our server,
2:59it's called data at rest. Okay. And this is data in transit. A couple different states that data
3:07can be in. So confidentiality, we need to make sure that only authorized access to the data
3:14is happening. We need to make sure it's secure. So when we're encrypting it in transit,
3:19any peeking eyes that might be out there who might have the ability to perform network captures,
3:26well, guess what? They're not going to see the data because it's encrypted. They can't read it.
3:29They don't have the keys. All right. So that is confidentiality. Next up is integrity.
3:35So integrity guarantees that the information is accurate, super important, and trustworthy.
3:44Okay. So when data is used or transmitted, we need to know that it was not altered in any way
3:55during its transition or use of that data. So we need to make sure it's accurate and trustworthy.
4:01That is the integrity of our data. And because if our data is not trustworthy and maybe it was
4:08altered, well, then what good is it? It's not true anymore. It's not accurate. So any work that we do
4:15off of that data is wasted time. That's not good. So how does integrity really work? Well, we can,
4:23again, we can use our permissions, file permissions to make sure that only authorized
4:28individuals have access to the data. Okay. While it's being used, we can also use version control.
4:35Okay. And that's so that we keep various versions. Every time a file is changed or a change made to
4:40a database, we track that. So we know that if something was done at one point, we can kind
4:45of go back to before that happened and have trustworthy data. And then lastly, we can use
4:51checksums. And these are simply basically like a cryptographic hash. And we're going to talk
4:56about those a little later on. But the idea is we take the fingerprint basically of that data
5:02and we store it. And we say on this date, we'll say on February 4th of 26, the data looked like
5:13this. That's the fingerprint. Okay. And then when we go to use it on February 7th of 26, before we
5:21actually use it, we take a checksum or basically a hash again, the fingerprint of it. So I get that
5:27fingerprint. And if this fingerprint and that fingerprint match, then we know the data has not
5:33been altered. Okay. So that's how we can verify data integrity. Super. All right, let's move on to
5:38our final. And this is availability. Yeah, it's got to be available. So when we're talking about
5:43availability, it means that our data and our resources are accessible to authorized users.
5:49That's what availability is. So for instance, if I had my sales application over here on our company,
5:59and something happened to the server and it's no longer available, well, how can we sell anything?
6:05I mean, I can't get into the sales accounts. I can't access the information about my clients. I
6:13need that information. Well, that's where we come up with some ways to make sure our data and our
6:19systems are accessible to our authorized users, because when they're down, that's not good because
6:25we lose money when our services are down. We're not able to use them. So what we can do is, well,
6:31we maintain our hardware and systems. So basically we're doing maintenance. Okay. For example, we're
6:39doing software updates. We're making sure we have a spare hard drive or something in case we need it,
6:44or we're making sure that we have backup power. So our systems don't crash when the power goes out,
6:49lots of things, but we can maintain our hardware and our software and systems there. Okay. So
6:55maintaining them, making sure that they're being taken care of is very important. Also,
7:01we need to have backups as you can imagine, because if this server did crash and go down,
7:07well, maybe we could spin up a virtual over here, a virtual machine and restore from backup and be
7:12back up and running in 30 minutes. Hey, that's great. Instead of maybe being down for days,
7:17we also use something called high availability. And there's simply where, let's say I had this
7:23sales server. I wouldn't have just one. I might have two. Okay. So if one goes down, I have another
7:28one that can be used. And that goes down into the hardware. As we talk about hard drives and using
7:35RAID for hard drives where it provides redundancy. So we have multiple and they work in kind of a
7:41cluster so that if one device goes bad, the other two can carry on and we can replace this and it'll
7:48rebuild the cluster. So we're good there. Also backup power so that if our power goes out,
7:54we can run off batteries or a generator or something. It's all about making sure that our
7:58systems and data are available and accessible to authorized users. So as we jump back up to the top
8:05confidentiality, we've got to keep that data confidential. Okay. Only authorized users can
8:10access it. Integrity, making sure our data is trustworthy so that we can use it. Availability.
8:16Well, we can't use it if it's not available, making sure our services and systems and data
8:21are up and running and available. That is the CIA triad. That's what information security and
8:26cybersecurity is all about. Protecting these three key pillars. All right. Well, that wraps
8:31up this skill. I hope it's been informative for you and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year