July 27, 2026

Stopping Ransomware Lateral Movement Before It Spreads

Stopping Ransomware Lateral Movement Before It Spreads

Ransomware lateral movement is exactly what it sounds like — once an attacker's inside your network, they start crawling around looking for more to encrypt, and stopping that crawl is often the difference between a bad day and a catastrophe. In this encore episode, part four of our seven-episode series pulling the best of the archives back into your feed, W. Curtis Preston and Prasanna Malaiyandi sit down with networking expert Tom Hollingsworth to break down exactly how attackers move once they're in, and what you can actually do about it.

This one's back because listeners didn't just download it — they stuck with it, and a fair number of you came back for a second listen. That kind of engagement told us this conversation was worth surfacing again, especially with ransomware attacks as common as they are right now.

Tom walks through the fundamentals of network segmentation — VLANs, air gaps, and why a "flat" network (where everything can talk to everything) is a gift to any attacker who gets in. From there the conversation moves into Zero Trust Network Architecture, what it actually takes to implement it at scale, and why flipping the switch from "allow everything" to "deny by default" is both the right move and the one that generates a thousand help desk tickets on day one. There's a good stretch on how schools, stadiums, and hotels handle network isolation differently than a typical enterprise, plus a practical rundown of incident response — locking down external access, isolating infected segments, keeping communication running when your own network is down, and why every kill switch needs to actually be wired to something.

If you've ever wondered how much of this is built into your existing networking gear versus something you have to buy separately, or you just want a clearer mental model for how ransomware spreads once it's past the perimeter, this is a great one to revisit.

Chapter Markers:

00:00:00 - Intro and why ransomware lateral movement matters right now

00:01:25 - Welcome back, meet Tom Hollingsworth

00:04:06 - Why isolating the network is step one after a ransomware attack

00:06:07 - Networking basics: how ransomware exploits flat networks

00:09:31 - VLANs, air gaps, and network segmentation

00:14:12 - Zero Trust Network Architecture explained

00:19:02 - Managing zero trust at scale across teams

00:25:48 - Special cases: schools, stadiums, and hotels

00:34:31 - Blocking newly registered domains to stop command and control

00:38:01 - Incident response: locking down the network

00:42:12 - Keeping communication running during an attack

00:44:54 - A real-world story: isolating infected devices

00:50:01 - Building segmentation in from the start

Speaker:

According to CrowdStrike's most recent State of Ransomware

Speaker:

survey, 78% of respondents were attacked by ransomware last year.

Speaker:

With odds like that, we figured it was time to bring on one of our most

Speaker:

popular episodes, and this one's all about stopping ransomware from moving

Speaker:

around once it's already in your network.

Speaker:

I brought on Tom Hollingsworth, who knows networking way better than I do.

Speaker:

Uh, we get into VLANs, zero trust, firewalls, and a few other

Speaker:

things, including some, at least I think, really good war stories.

Speaker:

If this is your first time watching or listening to me, I'm

Speaker:

W. Curtis Preston, AKA Mr. Backup.

Speaker:

I've been obsessing over backup, recovery, and now cyber recovery for over 30 years.

Speaker:

If that's your bag, then I'm your guy.

Speaker:

You're not gonna find anyone that's cares about backups more than me.

Speaker:

Ever since 1993 when I had to tell my boss that there were no backups of

Speaker:

the database that we had just lost.

Speaker:

Now I've written five O'Reilly books, a blog, and a podcast.

Speaker:

Here, we turn unappreciated admins into cyber recovery heroes.

Speaker:

This is the Backup Wrap-Up

Speaker:

Hi and welcome to Backup Central's podcast.

Speaker:

I'm your host, W. Curtis Preston, aka a Mr. Backup and have with me possibly

Speaker:

my Pex consultant Prasanna Malaiyandi.

Speaker:

it going?

Speaker:

Prasanna,

Speaker:

am.

Speaker:

I'm good Curtis.

Speaker:

And just for people that's p e x, not P E C K S.

Speaker:

Yeah, this is the piping, the, the modern piping alternative to copper,

Speaker:

which I think is far superior.

Speaker:

And, You know what?

Speaker:

just for those that are watching this on on video, which is only a handful of

Speaker:

you, but I'm gonna tilt my camera up and this is what my office looks like right

Speaker:

now because I got yet another pinhole leak in my, second story water supply,

Speaker:

which happens to be right above my office.

Speaker:

And yesterday I was just sitting here at my desk and I get this

Speaker:

drip drip on my face and I'm like,

Speaker:

you're like, am I sweating profusely?

Speaker:

Yeah.

Speaker:

And the pipe is actually over there.

Speaker:

the joint that's leaking, it's actually over there, the water finds its way,

Speaker:

down cracks.

Speaker:

Yeah,

Speaker:

it just drips

Speaker:

down onto my face.

Speaker:

Yeah, we wanna bring on our guest.

Speaker:

he is both, I would say, a friend of the pod.

Speaker:

He's also been an enemy of the pod at once.

Speaker:

You may recall that we had an episode where basically we just argued

Speaker:

with Tom without his per, without him being here to defend himself.

Speaker:

that was over a blog post that he said, something about, backup

Speaker:

people reporting to security people.

Speaker:

And, I

Speaker:

Yep.

Speaker:

had an issue with that or something.

Speaker:

Tom has been in the industry about 20 years and he is an

Speaker:

event lead over at Gestalt.

Speaker:

It the, what would you call it?

Speaker:

The makers of the Tech Field Day series,

Speaker:

and, we're glad to have him on the podcast.

Speaker:

Welcome, Tom Hollingsworth.

Speaker:

thank you for having me on Curtis.

Speaker:

It was, it was fascinating to listen to an episode where I was arguing

Speaker:

with somebody and it wasn't even here.

Speaker:

But, I love listening to you guys, and I've learned quite a bit.

Speaker:

In fact, the very first time that Curtis and I ever met at Tech Field Day back

Speaker:

in 2011, he was teaching me about data de-duplication, and I was trying to

Speaker:

convince him that IP V6 was important.

Speaker:

And I can tell you which one of those things panned out a lot better than the.

Speaker:

is it, that the thing where you do the nat behind the thing?

Speaker:

That's what I recall really learning from you was that you gotta do

Speaker:

NAT for I P V C

Speaker:

like the Kool-Aid man, just keep

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

I wanted to bring on somebody that actually understood networking

Speaker:

far better than me, right?

Speaker:

Which, which is basically many people in the world.

Speaker:

With ransomware attacks.

Speaker:

One of the things that we talk about is once you've, figured out that you

Speaker:

actually have a ransomware attack, you want to isolate the network.

Speaker:

And there's a discussion, I've been talking with CISOs lately and what

Speaker:

appears to be the reality is that few environments do the actual full.

Speaker:

Like we just we're just shutting everything off.

Speaker:

Go grab the cable, pull it out

Speaker:

actually, I know.

Speaker:

Tom, did you ever watch, alias when it was on

Speaker:

with Jennifer Garner and.

Speaker:

Okay, there's an episode in there when they were having a cyber

Speaker:

attack and the, what's his name?

Speaker:

Marshall Flank man comes running into the data center and he just literally

Speaker:

starts flipping, flipping power switches.

Speaker:

He's they're downloading all the files off the server and he down.

Speaker:

He just flips all the power switches off.

Speaker:

on one end there is the

Speaker:

like networking, shutdown, like literally both internal and external, right?

Speaker:

because, once the ransomware is inside, it's gonna try to crawl

Speaker:

around and make things worse.

Speaker:

So that's one way.

Speaker:

And then there are, and then there's the, those that go, I'm just going to turn

Speaker:

it off, I'm gonna unplug the cable at the one server or the three servers that

Speaker:

appear to be infected and I'm not gonna worry about the rest of the network.

Speaker:

And somewhere in the, between those two extremes is what everybody else does.

Speaker:

And maybe we should also talk about basics of networking before we jump

Speaker:

into this to talk about the detail.

Speaker:

Because just

Speaker:

Go ahead.

Speaker:

I,

Speaker:

Prasanna,

Speaker:

no, I,

Speaker:

you think we should be talking about first?

Speaker:

no, I think it's because what you just mentioned, Curtis, like everyone

Speaker:

might think, oh, all computers are plugged into the same network.

Speaker:

I think it's important to talk about some of the best practices from networking,

Speaker:

Tom, if you could, about sort of network isolation, BLANs, other things like that.

Speaker:

Before we get into sort of the other side of things,

Speaker:

Yeah, so please explain all networking technology, period before

Speaker:

we get started.

Speaker:

, you've already talked a little bit about it because it's just

Speaker:

a series of tubes, pipes, if you will, that we send things through.

Speaker:

now the important thing to realize when you're trying to think about how

Speaker:

ransomware propagates through a network is to realize that, the way that networks

Speaker:

have traditionally been built is we have this perimeter on the outside, it's

Speaker:

probably bounded by and a bunch of other stuff, and it looks really imposing on the

Speaker:

castle walls, but inside of the network, it's a whole lot easier to get around.

Speaker:

And that's just due to the nature of the way that networks operate.

Speaker:

ethernet is effectively like trying to shout out somebody's order

Speaker:

number at a fast food restaurant and hoping that you get the right one.

Speaker:

Everybody's gonna hear the message, but if it's not meant for you,

Speaker:

we're just gonna ignore it.

Speaker:

But the problem is that allows you to propagate a lot of information very

Speaker:

quickly, and that's what ransomware is trying to take, advantage of whenever

Speaker:

it's trying to, do almost reconnaissance lateral movement in the network.

Speaker:

So I'm looking for a whole bunch of, , potentially vulnerable servers going

Speaker:

all the way back, to the beginning of my professional IT career, I was

Speaker:

actually working on a help desk, when the S SQL slammer worm came out.

Speaker:

And boy, you'd be surprised how many people had that port open to the

Speaker:

internet, because everything shut down.

Speaker:

And it was really weird to see that.

Speaker:

And you're like, at the time I'm freshly minted in my career.

Speaker:

And I'm like, how could that happen?

Speaker:

and now all these years later, I look at it and go, oh my God,

Speaker:

these people were stupid because you're not supposed to do that.

Speaker:

But that's one of the things that people want to take advantage of because the

Speaker:

systems want to talk to each other.

Speaker:

They want to be able to exchange information.

Speaker:

That's the purpose of a network.

Speaker:

Right.

Speaker:

to do extra work to prevent them from talking to each other.

Speaker:

Right.

Speaker:

Yeah.

Speaker:

I think that's, I, and the number of times I went in and out of data centers, over

Speaker:

the years, I remember only one, where they had very solid firewalls, basically.

Speaker:

That, that it was very difficult to do, to traverse laterally

Speaker:

within the organization.

Speaker:

And that was actually Intuit, and it's because of what they felt they had.

Speaker:

They had all of this very sensitive personal data, thanks to their,

Speaker:

they had QuickBooks, they have TurboTax, they have all of that stuff.

Speaker:

And so they had to basically firewall off systems between each other to

Speaker:

prevent that lateral movement that you're right by design in most networks,

Speaker:

you buy a switch, you buy, a bunch of switches, you plug everything in.

Speaker:

And everything talk, everything can talk to everything.

Speaker:

and unless you do something to prevent it, lot of those ports that you talked

Speaker:

about, just like the SQL, issue, a lot of those ports are visible to the internet.

Speaker:

I think a, another one would be a vCenter Right.

Speaker:

And Hyper V, the, that, those ports being visible to the internet, I suppose

Speaker:

you hear about that a lot as well.

Speaker:

Yeah.

Speaker:

I usually do.

Speaker:

Whenever there's some kind of, a vulnerability that comes out and

Speaker:

everyone's I hope you don't have these exposed to the internet, and

Speaker:

you can literally hear the scrabbling as people run into their keyboards

Speaker:

to figure out if that's the case.

Speaker:

But,

Speaker:

as Prasanna mentioned, we have ways to like segment

Speaker:

networks away from each other.

Speaker:

And it's funny that you bring up that, that Intuit had a rigorous internal

Speaker:

firewall structure because in my experience, companies or organizations

Speaker:

that are very, heavily regulat.

Speaker:

Have much more strict structure.

Speaker:

And the reason for that is because they need the ability to say

Speaker:

for a fact, Curtis cannot see anything on this network because he

Speaker:

hasn't been authorized to see it.

Speaker:

Now, you can do that through software constructs.

Speaker:

VLANs, virtual local area networks are the most common way to do it, where we

Speaker:

effectively divide some, partition on the switch and we say, this port belongs

Speaker:

to this vlan, so it can only talk to other ports that are on that vlan.

Speaker:

but that's not even good enough for some organizations.

Speaker:

and the one that everybody always thinks of is Mission Impossible, the Tom Cruise

Speaker:

movie with the machine that's in a vault that's not connected to anything else.

Speaker:

We would call that an air gap system.

Speaker:

Or you can have an air gap network a lot of times things like, HVAC or

Speaker:

management systems are air gap from the rest of the network because they

Speaker:

have different controls and different needs, but I also don't trust those

Speaker:

people to, secure their stuff.

Speaker:

So I'm gonna build a wall in front of that air gap or just completely

Speaker:

isolate it, itself so that I don't have to worry about securing it.

Speaker:

And if, you say hvac, you say things like, environmental control systems

Speaker:

and any security people listening to this podcast are immediately

Speaker:

thinking, man, those are back doors that I can use to get into the system.

Speaker:

Because no matter what, they're still gonna have to be connected

Speaker:

to the network somehow.

Speaker:

And that just increases your, your threat profile.

Speaker:

Yeah, it's interesting because I think most people who think

Speaker:

about home networks, right?

Speaker:

Everything's typically flat in a home, right?

Speaker:

Everything can talk to everything, every single iot device out there, right?

Speaker:

And they're not always thinking about, Hey, I got this smart light bulb.

Speaker:

Isn't it great?

Speaker:

Isn't it awesome?

Speaker:

And then realizing that's on my network, everything is now exposed and could

Speaker:

be potentially exposed if there's a security issue with that single device,

Speaker:

Yeah, Those devices are, they obviously have an IP address, they

Speaker:

have some kind of a control system.

Speaker:

You would hope that most of them have some kind of a security function that

Speaker:

allows them to securely communicate back to whatever controls them.

Speaker:

But multiply that by a factor of 10 for all of the devices that could be

Speaker:

on your average enterprise network.

Speaker:

And when you start saying things like, access controls for those

Speaker:

devices, or port security like network engineering and operations folks, they

Speaker:

just start breaking out into hives.

Speaker:

the, just the amount of work that it takes to create that level

Speaker:

of security is its own monster.

Speaker:

anyone who's ever deployed a technology like 8 0 2 0.1 x, which is effectively,

Speaker:

I am only gonna allow authorized devices to be plugged into this port, knows that

Speaker:

there's this whole enrollment process and are you on the authorized users list?

Speaker:

And what happens if you're using a different device today?

Speaker:

And it's just, it's maddening and it drives people to insane to the

Speaker:

point where, and that's the normal people who know what they're doing.

Speaker:

Could you imagine an executive plugging their laptop into a network port one

Speaker:

day and going, this doesn't work.

Speaker:

And you tell 'em, oh, it's doing that on purpose because we

Speaker:

want to keep everything secure.

Speaker:

What do you think is gonna happen?

Speaker:

The executive's probably gonna look at you and go, I don't care.

Speaker:

Turn it off.

Speaker:

Exactly.

Speaker:

. We don't need that.

Speaker:

It's getting

Speaker:

Yeah.

Speaker:

Yeah,

Speaker:

Yeah.

Speaker:

I know that when we had, we had a security person on and they had a list of things

Speaker:

that they wanted people to do that they felt were common sense, that were, ways

Speaker:

to prevent basically, I think the proper thing today when we talk about ransomware

Speaker:

is to just assume something in your world is going to get ransomware, right?

Speaker:

It's just, it is, I think it's just impossible to stop it 100% of the time.

Speaker:

So just assume that's going to happen.

Speaker:

So then there's all about.

Speaker:

How to prevent it from activating itself, from talking to the command and control

Speaker:

servers and also the lateral movement.

Speaker:

So he

Speaker:

reducing the black

Speaker:

raised,

Speaker:

right?

Speaker:

So what's that?

Speaker:

Limiting the blast

Speaker:

radius.

Speaker:

so Tom, what kinds of things besides VLANs?

Speaker:

Because even VLANs, we have the VLAN for this and the VLAN for that.

Speaker:

Still all the servers within that VLAN can talk to each other.

Speaker:

What else can companies do, with modern networking equipment to prevent

Speaker:

lateral movement or to basically prevent it from everything and then,

Speaker:

selectively allow it for certain servers.

Speaker:

the first thing you have to do is you have to realize that a completely flat network.

Speaker:

not a stable network.

Speaker:

there is a limit to the amount of chatter that a network can tolerate

Speaker:

before it starts running into problems.

Speaker:

ethernet is not a, a medium that allows for a large number of hosts because

Speaker:

eventually they're gonna, it, it's like recording a podcast eventually

Speaker:

with too many guests on the podcast.

Speaker:

You're all gonna wanna talk over the top of each other,

Speaker:

and ethernet doesn't like that.

Speaker:

So once you had a certain boundary, you have to divide it

Speaker:

up into these little domains.

Speaker:

collision domains are what we call them, and that's one

Speaker:

of the things that a VLAN is.

Speaker:

But as we've learned over the years about what we really should be doing,

Speaker:

we've built a super set of that.

Speaker:

And anyone out there who has been reading any kind of the tech press recently, or

Speaker:

been to any trade show in the last couple of years, probably heard of something

Speaker:

like Zero Trust Network Architecture or, just Zero Trust in general.

Speaker:

It's a buzzword.

Speaker:

I'm, I'll be the first to admit it, but the principles behind it are fairly sound.

Speaker:

what you do is you take the tools that you've already been given, those ones

Speaker:

that I told you, make your network team break out in hives, and you try to

Speaker:

implement them in such a way as to reduce the complexity of the implementation.

Speaker:

And think about think about a teenager and they want a list of, things that

Speaker:

they can do when they get a car.

Speaker:

Are you gonna tell them you can do anything you want, but

Speaker:

you can't do this and you can't do that and you can't do this?

Speaker:

Or are you gonna be more explicit?

Speaker:

You can only do these things and if it's not on that list, you can't do it.

Speaker:

most people would say, I'm only go, I'm gonna do the second thing

Speaker:

because I want to make sure that they're only going to school and to

Speaker:

work into this one friend's house.

Speaker:

But we don't build networks that way.

Speaker:

we typically allow as much as possible because of the situations

Speaker:

we find ourselves in where something doesn't work right.

Speaker:

And we don't know why.

Speaker:

So we will put a little catchall at the bottom of the access list

Speaker:

and go permit everything else.

Speaker:

and then we leave it.

Speaker:

And that's the worst thing that you can do.

Speaker:

And what Zero Trust Network architectures try to do is they try

Speaker:

to say, okay, that server over there is running our backup software.

Speaker:

What should it, what should communicate with it?

Speaker:

And how should it be communicated with, maybe it only needs to accept

Speaker:

connections on these three or four ports.

Speaker:

Maybe it only accepts connections from these authorized users.

Speaker:

And you're effectively creating an isolation for that unit.

Speaker:

And if something needs to access it and you're having problems with it, the

Speaker:

software usually allows you to dig into that a little bit and go, oh, it looks

Speaker:

like that this program did an update and it now needs to communicate over this

Speaker:

port, and I need to allow that port.

Speaker:

But you're doing it in a way that allows you to control that access.

Speaker:

But more importantly, what happens is that when something tries to operate outside

Speaker:

of that access control, slams it shut and hopefully will send you some kind of a

Speaker:

warning, Hey, we just noticed that this server over here is trying to communicate

Speaker:

with the rest of the network on Port 4 45.

Speaker:

know it shouldn't be doing that.

Speaker:

You need to take a look at it.

Speaker:

And so limiting that blast radius, that broadcast capability tends

Speaker:

to prevent lateral movement.

Speaker:

And like you said, people who are going to attack you are going

Speaker:

to be dedicated in doing it.

Speaker:

Either they're gonna be dedicated to looking for a very specific exploit

Speaker:

and just hauling in whatever they can do, or they're gonna be looking to

Speaker:

attack you, you specifically, however they can get to you that second kind

Speaker:

of attacker, very difficult to block.

Speaker:

It's like a door lock, a dedicated burglar is gonna get into your house.

Speaker:

You're looking to prevent more of the first one where it's oh, we were able

Speaker:

to get in through your HVAC system and boy, we're gonna turn this thing loose

Speaker:

and see what open file shares you've got out there and what we can do with them.

Speaker:

You, you need to create in the organization that does not allow

Speaker:

people to move laterally that prevents them from accessing things.

Speaker:

Or worse yet, alerts you when things start doing a lot of across your

Speaker:

network, looking for those kinds of things because the rest of the group

Speaker:

that's trying to get into your network doesn't know that stuff's there either.

Speaker:

They're gonna have to go looking and just like the burglars that are casing the

Speaker:

joint, you need to look for those people.

Speaker:

So multiple things popped up in my head, Tom, as you were talking.

Speaker:

So the first is, as you're talking about the burglar example, I'm gonna bring this

Speaker:

up again for the second week, but Curtis had recommended reading The Cuckoo's Egg.

Speaker:

I don't know if you've read that book.

Speaker:

Tom.

Speaker:

Highly recommend you read it.

Speaker:

It's basically, 1980s, a hacker gets into a mainframe and starts moving

Speaker:

laterally across all these like military networks and science networks

Speaker:

because everything was connected.

Speaker:

And

Speaker:

Yeah.

Speaker:

you said, that example was go and try all the door locks and he would

Speaker:

try default passwords and some of these systems, like the mainframes,

Speaker:

people would not change the defaults.

Speaker:

And so he got in and it was just that lateral movement across

Speaker:

everything in the environment.

Speaker:

So that's like the first thing that came to mind as you were talking.

Speaker:

the other thing that also came to mind is I totally get the reason to have that

Speaker:

zero trust and only enables services that, and patterns that are known to

Speaker:

be valid and disable everything else.

Speaker:

my question.

Speaker:

As a network engineer or operations person, how do

Speaker:

you manage that at the scale?

Speaker:

Because there's so many applications, so many servers, it's hard to predict what's

Speaker:

going to talk with what, and coming up with, because everything's all connected.

Speaker:

Like in my mind I think about Facebook and graphs, right?

Speaker:

Everything is connected in the world, right?

Speaker:

And so everything in your network to some extent is probably

Speaker:

connected in some form or fashion.

Speaker:

So how do you go about even coming up with, okay, these things are the

Speaker:

things that should be talking to the backup server in your example.

Speaker:

So it takes a lot of teamwork because as a network person, I don't care

Speaker:

what's running over my network, I just need to make sure that these

Speaker:

two things can talk to each other.

Speaker:

And so in a way, like if you've ever deployed a server, you have a list,

Speaker:

okay, it needs to communicate, using this protocol over these ports or,

Speaker:

think about, opening something like, I need to open HTTPS to the server,

Speaker:

but not http because I don't want it to ever communicate over http.

Speaker:

And that's actually one of the things that we've noticed a lot recently is

Speaker:

that a lot of protocols that used to have their own dedicated ports have

Speaker:

now just started writing over, HTTP and https s. Because it's just easier.

Speaker:

bit Torrent was actually one of the first ones to start doing this because

Speaker:

they're like, eighty's gonna be open anyway, which is the port for http.

Speaker:

So we'll just ride on that because most people fire, most people's firewalling

Speaker:

systems just allow that by default, because that's what the web uses.

Speaker:

And so it gets insidious and you almost have to think at a higher level.

Speaker:

So what.

Speaker:

it crack open any networking textbook in the world, and they're gonna

Speaker:

give you this seven layer model.

Speaker:

It's like a seven layer dip from Taco Bell, but there's no refried

Speaker:

beans in the seven layer OSI model.

Speaker:

But we play a lot in the bottom of that, where the physical connections

Speaker:

happen, where the IP addresses allow systems to talk to each other.

Speaker:

Once we get above a certain level, that's where the applications take over.

Speaker:

And as networking people, we're not as concerned about that.

Speaker:

But boy, the server people are because, oh, I need to be able to have these

Speaker:

two devices talking to each other.

Speaker:

I need to make sure this is all un impeded.

Speaker:

And the first thing that happens when two servers can't talk to each other

Speaker:

is you gotta find the network people.

Speaker:

And you're like, you need to tell me what's going on here.

Speaker:

And then invariably, like the security team gets drawn in because oh no, we

Speaker:

told him that he had to block that because nobody should ever be using that.

Speaker:

and you really do have to pull those people together.

Speaker:

think of, think of a book like, gene Kim's Phoenix project.

Speaker:

Like you can't work in isolation anymore.

Speaker:

As much as we might like to.

Speaker:

Because so many things are so inter interdependent now.

Speaker:

It's the old joke is what does the server do?

Speaker:

I don't know.

Speaker:

Unplug the cable and we'll see who screams the loudest.

Speaker:

You wanna figure out what people, what port is being used.

Speaker:

Let's block it and see who comes to yell at us.

Speaker:

that's the way you have to do some of these things.

Speaker:

Cuz

Speaker:

the other thing, and we all know that nobody ever skips documentation, right?

Speaker:

You brought up an old memory of mine.

Speaker:

Literally like my first months in being a cis admin, we were trying to

Speaker:

decommission, the, the first computer to run Unix was the three BK and the

Speaker:

at and t had a three BK I think it was like a three B And it was their

Speaker:

attempt at a multiprocessor architecture.

Speaker:

And we had this beast and we were trying to decommission it.

Speaker:

And, we had gotten down to, we had fi and we had gotten down to

Speaker:

that phase where it's we're just gonna turn it off and whoever yells

Speaker:

will be the one that we missed.

Speaker:

But I remember the, We had, stripped it, all of its regular networking cable.

Speaker:

I don't exactly remember exactly why, but I remember that there was one cable left

Speaker:

and it was running across the floor and we were doing the last like download of was

Speaker:

off of this server onto something else.

Speaker:

And the manager for that cost center was in there and he

Speaker:

kept stepping on the cable.

Speaker:

we told him that he was slowing down the download whenever

Speaker:

he would step on the cable.

Speaker:

we actually caught him, we left him into data center.

Speaker:

We actually caught him like watching the monitor and like the

Speaker:

throughput speed and stepping on and stepping up and off on the cable.

Speaker:

Bad Curtis.

Speaker:

Yeah.

Speaker:

good stories.

Speaker:

I, so question I want to ask you about, all of the things you just

Speaker:

talked about, this something built into modern networking equipment or

Speaker:

is this, are these extra applications that I'm buying that then configure

Speaker:

that networking equipment for me?

Speaker:

So it can be both.

Speaker:

the basics of being able to isolate hosts and configure systems

Speaker:

has been built in for years.

Speaker:

anyone can write an a c L, right?

Speaker:

The thing is that scaling that across a large organization is

Speaker:

where it typically falls down.

Speaker:

Eventually, your security team can't keep up with all the changes.

Speaker:

They throw their hands up in the air and it lies fallow for as long as

Speaker:

it takes for you to get infected.

Speaker:

So the additional tools that are basically being brought to market and

Speaker:

are popular now, organize that system.

Speaker:

They put a shiny.

Speaker:

UI on it, if you will, to go in and say, okay, I want to enable port

Speaker:

security on these ports because back when I started this port security was,

Speaker:

if it isn't being used, shut it off.

Speaker:

Just shut down the port.

Speaker:

And then if somebody plugs into it and it doesn't work, then now we know

Speaker:

we need to enable that port and we need to know who's trying to use it.

Speaker:

But now you have the ability to have somebody plug in a device, whether

Speaker:

it's an IOT system or what have

Speaker:

you, and this, the device will register with the system.

Speaker:

It'll say, Hey, I need access.

Speaker:

And then the system can come back and say, Hey, it looks like somebody

Speaker:

plugged in an S thermostat over here.

Speaker:

that's actually a bad example cause they don't use wires, a laptop

Speaker:

or some other kind of device, you need to go, check it out.

Speaker:

Or you can even set a policy that says, I'm going to allow you for now, I have the

Speaker:

ability to just cut it off if I need to.

Speaker:

Or if it's one of these recognized device classes or something like that.

Speaker:

So for smaller systems, for smaller organizations, if your IT department

Speaker:

isn't already completely overworked, you can't implement some of this by hand.

Speaker:

It's just a matter of if it works really well, that means you're gonna

Speaker:

be spending a lot of time tuning that system to keep working effectively.

Speaker:

And once you get past a certain point, the, the solutions that do

Speaker:

this are reassuringly expensive because they're worth it.

Speaker:

Oh, I understood cuz that they would help you save the labor.

Speaker:

And is there a category of these types of tools that, that a

Speaker:

category name that we give to them?

Speaker:

there's a bunch of different ones.

Speaker:

access management is typically one that honestly, tools like Aruba

Speaker:

ClearPass or Cisco ice, ise, integrated services engine, or integrated security

Speaker:

engine, I forget which one it is.

Speaker:

But they're not identity and access management, although

Speaker:

they can be integrated that.

Speaker:

There are some smaller ones that have these capabilities.

Speaker:

A lot of it is mostly figuring out what you need because there's different,

Speaker:

some systems are configured so that you're controlling access to devices.

Speaker:

I only wanna authorize people to be able to log into this

Speaker:

device and make changes to it.

Speaker:

that's different than I want to change the way that people in my network are

Speaker:

accessing data like that is a different kind of identity and access management.

Speaker:

So you need to do a little bit of investigative work to make sure that

Speaker:

you are, properly using the right tool.

Speaker:

Cause if you spend a lot of money on one that doesn't give you what you want or

Speaker:

does a terrible job of it, then not only are you gonna be upset, but the people

Speaker:

that are or authorizing your budget are not gonna be very happy with you.

Speaker:

Now a lot of these changes, if I think about an enterprise

Speaker:

environment, things are easier to a fair extent to control, right?

Speaker:

If you're looking at servers or virtualization, other things like that.

Speaker:

But then I go to think about other environments like a school, where you

Speaker:

have students coming and going, right?

Speaker:

Or a stadium or a conference center, right?

Speaker:

Does it get significantly more difficult to do what you talked

Speaker:

about, Tom, in those environments?

Speaker:

Or can the same tools apply there as well?

Speaker:

Yes and no.

Speaker:

I'm the typical IT nerd.

Speaker:

The answer is, it depends for whatever question you ask, but I'll tell

Speaker:

you that in some ways, schools and other places where your user base

Speaker:

is not employed directly by you.

Speaker:

have a slightly easier time if you're willing to, a little bit.

Speaker:

So I know that there are a lot of colleges out there that treat their

Speaker:

student dorm networks like the wild west.

Speaker:

We don't care what goes on out there, but we're not gonna keep an eye on it either.

Speaker:

So if

Speaker:

there's a, a piece of ransomware or something that's running rampant through

Speaker:

the system, all we did is tell you that you had to have your antivirus up to

Speaker:

date to be able to join our network.

Speaker:

Yeah.

Speaker:

the stadiums are actually a really interesting, problem too, because not

Speaker:

only do you have a, a group of users that are outside of your control, they're

Speaker:

very transient, in a lot of those places.

Speaker:

Like they, they actually have, wireless networks that are set

Speaker:

up so that, they can only talk.

Speaker:

, like they block all device to device communication, which

Speaker:

is something that you can do.

Speaker:

It's a little bit more complicated, but it effectively treats, the

Speaker:

stadium itself like a demilitarized zone in a, in a security structure.

Speaker:

So for most people that are familiar with it, you've got the outside

Speaker:

internet, which is big and scary.

Speaker:

You've got your inside network, which is soft and you don't want it to get hurt.

Speaker:

And then in the middle you have the dmz, which is basically the moat where

Speaker:

you're like, I'm gonna put everything that I don't care if it gets attacked

Speaker:

out there so that if it breaks, it can't get back into my network.

Speaker:

And but the otherwise, the other thing there is I only allow certain

Speaker:

traffic to come back through.

Speaker:

So if something bad were to happen, can just basically cut it off and

Speaker:

sink it into the moat and I'm done.

Speaker:

Yeah, I think, hotels have a similar model, right?

Speaker:

Where the base, I know having plugged in multiple devices that needed to

Speaker:

talk to each other in hotel networks, they don't like that very much.

Speaker:

and you end up having to bring basically your own router if that's

Speaker:

something that you want to do.

Speaker:

the, so it sounded like, if I understood you correctly, the access management

Speaker:

part is this sort of basic security thing, that there are tools that do

Speaker:

just that, and then there's also this identity access, which is a bigger pain.

Speaker:

I would imagine.

Speaker:

But those that want that, and it sounds like when we put those two together,

Speaker:

that's what we call a SEIM tool, right?

Speaker:

Is identity and access management.

Speaker:

But it sounds like there's just an access management.

Speaker:

That, for those that need just that there, there's smaller and less

Speaker:

expensive than a full SEIM tool.

Speaker:

Yeah.

Speaker:

not inexpensive, but just less expensive.

Speaker:

and it also matters as to what you're spending your resources on, because there

Speaker:

are tools that will do this for free.

Speaker:

But they are not supported at all by anybody other than people on a forum.

Speaker:

And they'll be glad to tell you that you misconfigured something

Speaker:

and go figure it out yourself.

Speaker:

Like we, we've dealt with that.

Speaker:

And I'm not really crapping on the open source community because

Speaker:

they do an amazing job of this.

Speaker:

I'm crapping on the fact that open source communities are not as well supported

Speaker:

as the bigger players in these markets.

Speaker:

And that's the expensive part comes from.

Speaker:

You're not paying for the software, although you are in some ways.

Speaker:

You're paying for somebody to answer the phone when somebody is like breathing

Speaker:

down your neck because something won't work or something won't come online.

Speaker:

And so a and you're also trying to get to that point where not automated

Speaker:

as much as it is as low possible.

Speaker:

Because what you want in situations is people to just

Speaker:

be able to get on the network.

Speaker:

that's the thing.

Speaker:

If you've ever tried to log into a wifi network that has a captive portal

Speaker:

that requires you to accept a whole bunch of licensing agreements and

Speaker:

type your room number in and all the other stuff, you know that it's not

Speaker:

the most frustrating thing, but it's definitely not what you want to hear.

Speaker:

As opposed to oh, this device has already been pre-authorized cuz you logged in

Speaker:

with your active directory username.

Speaker:

we'll just let it on the network.

Speaker:

That's completely frictionless.

Speaker:

But the amount of effort that it takes to make it frictionless is where your time

Speaker:

and resource invests gonna come from.

Speaker:

Tom, I know we started this all out with Curtis asking, how do

Speaker:

you prevent lateral movement in networks right from ransomware?

Speaker:

Just given the fact that ransomware does move laterally in a lot of networks?

Speaker:

Does this mean people are not using these tools or have not

Speaker:

configured the networks correctly?

Speaker:

Because it seems if you did all the things that we just talked about, it

Speaker:

should have prevented a lot of the lateral movement that we see in ransomware today.

Speaker:

Prasanna, I'm gonna tell you something that my dad always tell

Speaker:

me, and you have to understand.

Speaker:

My dad grew up in the country.

Speaker:

If a frog had wings, he wouldn't bump his ass every time he hopped.

Speaker:

yes, if you turn on all of these tools, you will cut down on a lot of this stuff.

Speaker:

But does that mean your network's not working correctly?

Speaker:

No.

Speaker:

It just means that we didn't enable all these extra features that we have

Speaker:

to keep track of because I can get four, four ports on a. and plug four

Speaker:

devices in there and they're gonna work is the best way for them to work.

Speaker:

Absolutely not, but I also don't have to do a whole lot of extra configuration.

Speaker:

A lot of people are looking at this from the perspective of, I need to

Speaker:

make sure that everything is able to communicate with everything else.

Speaker:

They're not looking at it like you, like the example you had earlier, Curtis, when

Speaker:

you log into the hotel wifi and I can't talk to anything else on the hotel wifi.

Speaker:

They're not thinking in a, in an isolation mode.

Speaker:

And we're that ship's turning because a lot of people are now realizing that

Speaker:

traditional idea of having a very stiff, crunchy perimeter with a very soft

Speaker:

internal network doesn't work so well.

Speaker:

Right,

Speaker:

ends up happening is that once people get through the perimeter, they have

Speaker:

free reign to do whatever they want.

Speaker:

You, you do have to build these controls in place to effectively

Speaker:

slow them down or to herd them to places that you want them to go.

Speaker:

And that's what a lot of people have spent time developing and working on.

Speaker:

And there's varying degrees of success to make that work.

Speaker:

It has to shift the mindset though.

Speaker:

application people are just turn on all the ports and I'll turn them off later.

Speaker:

When I tell you which ones I don't need, you won't, because you'll

Speaker:

right.

Speaker:

something else.

Speaker:

It's like developers, they're like, I'm gonna load everything I can possibly

Speaker:

think of in the memory so that I know the library that I need is there.

Speaker:

And then you wonder why your, application is consuming like three terabytes of ram.

Speaker:

It's maybe you need to pa pair back a little bit on that.

Speaker:

Yeah.

Speaker:

So it, it sounds like these tools are there.

Speaker:

I think a lot of people do use them, but you talked about, like in the

Speaker:

very beginning, you said that people's heads are gonna start spinning or

Speaker:

whatever, because there is a lot of work involved in implementing these things.

Speaker:

And the moment you flip that switch from, per, from everything is

Speaker:

permitted to only the things that are permitted or permitted, you're

Speaker:

gonna get 5,000 tickets, right?

Speaker:

I can't do this and I can't do that.

Speaker:

And they see that.

Speaker:

They see that very real worry.

Speaker:

and I think it stops many people from implementing this because they just see

Speaker:

it as the amount of work they're gonna have to do to initially implement it.

Speaker:

they're, and they're not seeing the risk of what's gonna happen when

Speaker:

they get a ransomware infection, and then it just goes crazy.

Speaker:

Most tools that are set up like this.

Speaker:

they have a learning mode where they will, you could put 'em in place and

Speaker:

they just sit there and they watch for at

Speaker:

least the first, week or two.

Speaker:

And they're mapping out all of these application dependencies.

Speaker:

the backup system needs to receive traffic on this port for this

Speaker:

application from this subnet.

Speaker:

And then it allows you to carefully craft that rule so that only devices

Speaker:

from this subnet can talk to that server on these ports and nothing else.

Speaker:

And if you let the tool go long enough, you'll be able to like, suss

Speaker:

out exactly what you need to know.

Speaker:

But yeah, that first day you click the switch to from, allow list to deny

Speaker:

a list is just like you're staring at the ticket queue because you're

Speaker:

like, oh, what happens if I, if this machine hadn't been turned on for a

Speaker:

Yeah.

Speaker:

And this

Speaker:

yeah.

Speaker:

Yeah.

Speaker:

It just, it is, it's maddening because you're always gonna wonder if you didn't

Speaker:

get the right stuff, but like you said, would you rather be worried about one

Speaker:

machine that can't talk to another?

Speaker:

Or would you be worrying about the fact that you're getting a phone call from

Speaker:

the CIO saying, yeah, the database has just got encrypted by this new flavor

Speaker:

of malware that we haven't seen yet.

Speaker:

why did that?

Speaker:

Yeah.

Speaker:

Another thing I want to ask you, I wanna move forward

Speaker:

into the ransomware part here.

Speaker:

Although Prasanna, I'm so glad you basically told us to go backwards.

Speaker:

You always, you're really good at that, you're really good at

Speaker:

I try.

Speaker:

anyway, I wanted, so one of the things, so we talked about

Speaker:

trying to limit lateral movement.

Speaker:

Another thing that was suggested was to not

Speaker:

new either new domains, like domains that just recently were created, or

Speaker:

domains that w got recently active, From a DNS perspective, is that still

Speaker:

fall under the networking purview?

Speaker:

or is that is that another world?

Speaker:

it tend, anything that involves names and not numbers tends to float up towards

Speaker:

the application team or the security

Speaker:

Okay.

Speaker:

and the reason for that is because, like you said, like one of the things

Speaker:

that, that we see a lot in security now is it's this idea that you wanna black

Speaker:

hole things that are relatively new.

Speaker:

Like why is this machine suddenly starting to communicate over a d n

Speaker:

s name that I've never seen before?

Speaker:

But it also

Speaker:

requires that your devices have the intelligence to be able to resolve that

Speaker:

because, application layer firewalls will see, oh, you are trying to access

Speaker:

this service that I don't recognize on a domain that I've never seen before.

Speaker:

Whereas a lower level, almost a packet filtering firewall will say,

Speaker:

oh, that's an IP address connection on this port from here to there.

Speaker:

I don't see a reason why I shouldn't be using that.

Speaker:

Gotcha.

Speaker:

You, have to integrate those two things together because like you said,

Speaker:

something doesn't look right here because why would it be contacting a

Speaker:

brand new DNS name that it should, it has no reason to contact or worse yet?

Speaker:

You can ask the people over at SolarWinds.

Speaker:

Why is this DLL suddenly talking to .ru addresses?

Speaker:

right?

Speaker:

Yeah.

Speaker:

when he says new domain names, he actually means domain names that were

Speaker:

like recently registered, not just domain names that are new to your network.

Speaker:

And then also ones that, that were, they were registered but they hadn't

Speaker:

been active or something like that.

Speaker:

So that sounds like that's a d n s there's a d I world, right?

Speaker:

we had somebody on from that.

Speaker:

I think we need to have some, because this is, I think that's, , if you

Speaker:

can reasonably do that, where you could basically push a button, just

Speaker:

like the deny the allowed deny thing.

Speaker:

If you can reasonably say, I, I don't want, want anybody talking to domain

Speaker:

names that were registered 24 hours ago.

Speaker:

I if you could do something like that, it will of course also

Speaker:

create some trouble, tickets.

Speaker:

But I'm thinking far less.

Speaker:

And if you could do that, it stops to command and control, the ransomware from

Speaker:

reaching out at command and control,

Speaker:

the

Speaker:

down.

Speaker:

But the one thing I will say there though, is that you need to make sure

Speaker:

that your users are expecting that change.

Speaker:

Because if it requires you to go out and check a list or, get some kind of

Speaker:

una authorization to go to this domain name, even if it adds one second to the

Speaker:

resolution time, that's one extra second that people are going to complain about

Speaker:

and you know who they're gonna complain.

Speaker:

mm-hmm.

Speaker:

team, because the network isn't working.

Speaker:

Not the d n s block list checker or the application that has this built into it.

Speaker:

Oh, no.

Speaker:

It's the network's fault because the packets aren't

Speaker:

going where they're supposed to.

Speaker:

we used to say back when I was, when I first said that we would

Speaker:

say the problem's under the floor.

Speaker:

meaning, meaning it was a networking problem.

Speaker:

go ahead, Prasanna.

Speaker:

So moving on.

Speaker:

So we talked about how to prevent lateral movement, how to detect these,

Speaker:

rogue, servers that are coming up.

Speaker:

One thing I wanted to ask is, so say you do get hit by ransomware, right?

Speaker:

They're able to move laterally.

Speaker:

What happens next from a networking perspective?

Speaker:

I guess two questions.

Speaker:

One is how do you, how would you go about bringing down your network or sort

Speaker:

of isolating what needs to be isolated?

Speaker:

Like how do you actually figure out what's going on in your network?

Speaker:

And then the second question is, okay, now that you've identified that, how do

Speaker:

you slowly recover from those situations?

Speaker:

Incident response is never fun because it's a whole lot of cleanup.

Speaker:

And, and the first thing you have to do is you have to get people out

Speaker:

of your network because there's, there's obviously, there's the

Speaker:

tools that kind of run on their own.

Speaker:

And there are tools that kind of have to be piloted by people.

Speaker:

So you have to create, limits on the system to be able to stop that.

Speaker:

And fingers crossed that you're not in a situation where your entire

Speaker:

network has been taken down by whatever is causing the problem.

Speaker:

Because I've seen that before too, where not only does it try to laterally move to

Speaker:

infect systems, it also throws up enough extra garbage that you are, it's Inca,

Speaker:

you're capable of logging into any of your

Speaker:

Oh,

Speaker:

So we're lesson number one.

Speaker:

Make sure all your management networks are isolated so that you

Speaker:

always have the ability to use those.

Speaker:

But the first thing that I would.

Speaker:

As I would cut off outside access immediately, I would

Speaker:

lock the firewall in place.

Speaker:

you don't have to run through the data center screaming with your

Speaker:

hair on fire and start yanking cables out like the alias episode.

Speaker:

But you need to be able to lock all of those connections down.

Speaker:

And specifically you need to look for ones that, could be like, from

Speaker:

really weird external addresses, or worse yet ones that are coming in.

Speaker:

Once you've blocked that external access in and out, you gotta do it

Speaker:

in both directions because obviously you don't want anything getting out

Speaker:

because the two things that I can think of are command and control traffic.

Speaker:

If some kind of tool that's being, orchestrated or data exfiltration

Speaker:

Yep.

Speaker:

and you're like, oh, I can stop those file transfers.

Speaker:

Yeah, look up oil rig.

Speaker:

It was, it was able to exfiltrate data through DNS queries.

Speaker:

that's the kind of crap you have to worry about.

Speaker:

So you've gotta lock it down.

Speaker:

Then you have to isolate because that's

Speaker:

And

Speaker:

too.

Speaker:

before you move on,

Speaker:

yeah.

Speaker:

you there?

Speaker:

so how do you do that, right?

Speaker:

is this something where you have to create.

Speaker:

A button to press up, because this sounds like a lot of little steps you

Speaker:

probably need to do this manually, or is there something I can do

Speaker:

upfront that says, in the event of a ransomware attack, push this button.

Speaker:

Hey, gum.

Speaker:

Shut up.

Speaker:

Anyway, in the event of a ransomware attack, press this button and it

Speaker:

does the 10 things I need to do.

Speaker:

what do you think

Speaker:

Some of them do have a big red button press here to terminate

Speaker:

all firewall connections.

Speaker:

But most of the time you're gonna have to create like a checklist or have

Speaker:

a system of okay, I'm gonna go into these rules and I'm gonna uncheck these

Speaker:

five boxes and then I'm gonna hit the terminate connections button to make

Speaker:

sure that no new connections can be made.

Speaker:

Also, if you have a rule at the bottom of your firewall list that

Speaker:

says Permit ip, any, take it out

Speaker:

now because it's not doing you any good.

Speaker:

but more importantly, you have to, all kill switches have to be wired.

Speaker:

, such thing as a magical switch that you can just hit, even if it's one that the

Speaker:

provider has given you what it does.

Speaker:

Does it dump the rules completely?

Speaker:

Does it just suspend the rules until you go in and manually add them?

Speaker:

Remember that could also cut off your connection to the firewall, so

Speaker:

you need to have another way to get into it just in case that happens.

Speaker:

Another reason for an isolated management network, but the idea is that you need to

Speaker:

investigate what your options are because God help you if you really do have to

Speaker:

run down to the data center and yank the cables out, and if that is a case and

Speaker:

hey, it's just as valid as anything else.

Speaker:

Can you make sure that you have the right keys, that you know which

Speaker:

firewall you're yanking out of?

Speaker:

Are there any other exits off of your network?

Speaker:

Because that's another problem that you may run into.

Speaker:

What happens if someone has created another exit off of your network,

Speaker:

either accidentally or on purpose?

Speaker:

And what happens then?

Speaker:

Because you know it's just as easy for me to plug something into your network.

Speaker:

And if there's another way off of it, I'm gonna find it.

Speaker:

Yeah.

Speaker:

The one other thing though, I know you talked about, and it totally makes

Speaker:

sense to kill all incoming and outcoming traffic, but just thinking a step forward,

Speaker:

like when you're dealing with incident response, doesn't that also take out like

Speaker:

your chat channels, your slack channels, your video conferencing, everything

Speaker:

else, like what do you do at that point?

Speaker:

Is it just hope you have everyone's cell phone numbers?

Speaker:

you need to have a plan for out of band incident response because y

Speaker:

it's, it's just like any crime scene.

Speaker:

I need to figure out what's been hit and I need to figure out how

Speaker:

much of it is going to spread.

Speaker:

And you're thinking to yourself like, I can't shut my network down

Speaker:

permanently because you know it's gonna cost me X amount of dollars.

Speaker:

Yes, but it's also gonna cost you x plus whatever amount of

Speaker:

dollars when the next system gets

Speaker:

If you don't

Speaker:

a device that no, nobody's patched it in years.

Speaker:

I'm not gonna lie.

Speaker:

Incident response can work over iMessage text threads for a good couple of

Speaker:

hours while you try to figure that out.

Speaker:

Or, buy your incident response team like those little, hotspots or enable the

Speaker:

data plans on their phone so that they can join their laptop there and join a

Speaker:

Slack instance outside of your network.

Speaker:

Yep.

Speaker:

way nothing is working internal to your network.

Speaker:

Because that's the other thing too.

Speaker:

If you, if this is something that's particularly insidious on a window

Speaker:

system and your incident responders are using Windows systems and they

Speaker:

join the network to be able to do incident response and their laptops get

Speaker:

compromised because they join the network again, you're gonna feel really dumb.

Speaker:

It's the professional, when they blew up the bomb squad truck, it's come

Speaker:

on guys, what were you expecting?

Speaker:

You just reminded me of the, there's a series of commercials and there's

Speaker:

one where the commercial is it's like a horror movie and the, there's a

Speaker:

bunch of kid, it's like the, I got the guy with the ax murderers looking

Speaker:

for the group of kids, and they're like, why don't we go hang out?

Speaker:

Why don't we go hide in that shed over there with all the, with all

Speaker:

the, machetes or something like

Speaker:

that, so we talked about blocking external traffic.

Speaker:

What about blocking internal traffic?

Speaker:

basically the lateral traffic, be due to the, we know we have ransomware

Speaker:

and we know it's gonna try to crawl.

Speaker:

What about blocking that, access?

Speaker:

So that's where you hope that your management networks are, isolated

Speaker:

because the first thing I would do going into a router is shut down the route.

Speaker:

Tables prevent, traffic from being passed across network boundaries.

Speaker:

what you're effectively doing in there is you are containing the damage to one area.

Speaker:

Now, yeah, you're gonna take things down, but if you can isolate that network as

Speaker:

the location for wherever the problem is, you can then bring other networks

Speaker:

back online be relatively certain that they're not gonna be infected.

Speaker:

I really hope that you're not using just regular routing, that you have

Speaker:

some kind of a security boundary there, because that makes it a whole lot.

Speaker:

But you've got to think in, in phases.

Speaker:

Obviously, using the kill switch is gonna take everything down, but then you have

Speaker:

to start, can I bring this back online?

Speaker:

Is this going to be infected?

Speaker:

What would I be looking for?

Speaker:

so I actually have a story about this, this happened last year to my children.

Speaker:

one of 'em goes to the public high school here, and I got a rocket text

Speaker:

message from their IT department saying, please turn off all public school

Speaker:

issue devices until further notice.

Speaker:

And I'm like, uhoh, somebody got hit with something fun.

Speaker:

And this was like the last day before Christmas break or something.

Speaker:

So we went in and we turned off my kid's MacBook, right?

Speaker:

So now, immediately I, because I know what the thing was, I don't want anybody to

Speaker:

like phone home and get infected and then infect the parents networks or whatever.

Speaker:

Okay, no problem.

Speaker:

We just shut it off.

Speaker:

But then I'm like, I wonder what it could.

Speaker:

like I, I'm curious and they've, to this day, they've never disclosed what

Speaker:

it was, but you would get an email like the next week, oh, if you're using like

Speaker:

a corporate phone or if you're using a MacBook, you can turn it back on.

Speaker:

that automatically lowers the horizon of, it has to be something that's focused

Speaker:

on Windows or something like that.

Speaker:

So then you start running through your head of what it could possibly be.

Speaker:

an incident response, you have to do the same thing.

Speaker:

What server got hit?

Speaker:

Oh, it was the database server and it was running this version

Speaker:

of, windows or SQL server.

Speaker:

Okay.

Speaker:

Does that mean that Max can get on the network?

Speaker:

Do I want them on the network?

Speaker:

Is it a situation where even though they can't be infected, they could

Speaker:

propagate something to another location?

Speaker:

there's a lot that you have to go into because obviously the executives are

Speaker:

gonna be like, when can we do back up and.

Speaker:

and if you're a publicly traded company, oh God, the stockholders are like outdoors

Speaker:

with pitchforks and torches and they wanna know when they can get their dividends.

Speaker:

And you're like, when I figure out how much of this data got encrypted

Speaker:

or stolen, and you're always gonna be fighting that tension and you can't

Speaker:

just shut everything off forever.

Speaker:

So that's part of incident response is you've got one team working on figuring

Speaker:

out how to stop whatever infected you, but you've got another team figuring

Speaker:

out how to bring things back online.

Speaker:

That's why we call it business continuity now.

Speaker:

It is interesting about the incident response.

Speaker:

How have you seen cases?

Speaker:

Like how do you actually, two questions I have.

Speaker:

How do you figure out like that, this segment, going back to what

Speaker:

you said, you kill all the routes.

Speaker:

How do you figure out that this segment is safe or not?

Speaker:

And then I guess that, yeah, that's actually only one question.

Speaker:

so typically what, and you're effectively, when you create these

Speaker:

boundaries, it's like looking for the hot potato effectively, because

Speaker:

unless you, like in the alias episode, just go click all the switches off.

Speaker:

Those devices can still communicate to each other at layer two.

Speaker:

Now, where you don't wanna have a problem is that it's in the data.

Speaker:

because if you isolate the layer two data center, now you've got a real problem.

Speaker:

Because if those servers, if it's looking for servers, those

Speaker:

servers can still get infected.

Speaker:

That's why it's actually better to have a, a host route or something

Speaker:

like that, or something that, that kind of isolates that per unit thing.

Speaker:

honestly, like a V switch is perfect for this because if it's not bound for that

Speaker:

host, I'm not gonna let it go any further.

Speaker:

But effectively what you have to do is you have to look for chatter

Speaker:

that's still going on in the network.

Speaker:

Like you, I've shut all this down.

Speaker:

I told my users to disable their machines or turn them off or

Speaker:

whatever, what's still trying to talk.

Speaker:

And then you go take that on a case by case basis.

Speaker:

Oh, this device is still sending traffic that it's, but

Speaker:

it's looking for this server.

Speaker:

Okay, I'm, I can shut it off because I know that it's probably safe.

Speaker:

But then you run into something like, oh, this thing is chattering

Speaker:

an awful lot and it's chattering on a way that it shouldn't be chattering.

Speaker:

that's how I've gone and found hosts that have been infected, but not

Speaker:

by ransomware, but by early malware because they just kept hammering the

Speaker:

firewall with these outbound requests.

Speaker:

And I'm like, you shouldn't

Speaker:

be doing that.

Speaker:

So it's almost like a little bit of detective work.

Speaker:

The good news is that even though the network devices are like dumb from

Speaker:

the perspective of I don't care what application is trying to talk, where

Speaker:

they're really good at telling you that things are still generating traffic.

Speaker:

It's oh, this port is still sending a ton of packets bound

Speaker:

for this address on this location.

Speaker:

And so then you're like, oh, I think something might be up here.

Speaker:

Do you ever see cases where people.

Speaker:

, almost do a, create a black hole on the device itself sync the packets there so

Speaker:

it doesn't go out, rather than having to necessarily do it on the switch.

Speaker:

you can, that's actually a really great way to determine what it's

Speaker:

trying to contact is to create like a null route on the system.

Speaker:

going all the way back three or four years.

Speaker:

Like Mark Marcus Hutchins, that's how he actually stopped a major outbreak

Speaker:

of malware, for all the good it did, and he got arrested by the FBI later.

Speaker:

But he basically black hole the dns.

Speaker:

yeah.

Speaker:

He bought the domain black hole it because if that domain name was

Speaker:

active, then it would stop propagating.

Speaker:

And so he figured that out by saying, oh, I wonder where this is

Speaker:

going and I wonder what it's doing.

Speaker:

You can do that.

Speaker:

And it's actually the next step in incident response, which you've isolated

Speaker:

the system, is I wanna see how it behaves and what it's trying to do.

Speaker:

Cuz that could give me a clue as to what I got hit with and

Speaker:

what they could be looking for.

Speaker:

And that gives you, a little bit of opportunity, but that's

Speaker:

a little bit more of an advanced tool that you would want to use.

Speaker:

just because black holding traffic on a device takes a little bit of setup,

Speaker:

especially if you're fighting against people who don't want you to do that.

Speaker:

Yeah.

Speaker:

Yeah, so it sounds a lot of the things that you talked about in the last

Speaker:

couple of minutes, would be a lot easier to do again, if we segmented

Speaker:

the network in the first place,

Speaker:

Mm-hmm.

Speaker:

We put people with Windows laptops on one network.

Speaker:

We put people with Mac laptops on a network, another network.

Speaker:

We put the phones right?

Speaker:

That are doing the wifi.

Speaker:

We put them on another network.

Speaker:

and we put servers on a different network.

Speaker:

We put, maybe we put servers of a different type on a different network.

Speaker:

So that way you could basically say you don't have to tell

Speaker:

the users to not do anything.

Speaker:

You can just say shut off the laptop, network.

Speaker:

and you shut off the laptop network and so on.

Speaker:

and all the networks that where we don't currently, what we're not looking at.

Speaker:

And then, okay, who's trying to talk?

Speaker:

Who's trying to talk?

Speaker:

Why is this server surfing?

Speaker:

The web

Speaker:

Yeah.

Speaker:

There's nobody over there.

Speaker:

Why is this server going over report 80?

Speaker:

a lot of places already have this by default, even if they didn't realize

Speaker:

they were doing it because you have different classes of devices that

Speaker:

you wanna treat them differently.

Speaker:

Like for example, the the server network, we want to have a little

Speaker:

bit more security in there.

Speaker:

Maybe a little less host to host East to west traffic kind of thing.

Speaker:

The wireless network where all the laptops and the devices connect.

Speaker:

I'm a little less careful about that because I actually have identity

Speaker:

management in place that validates the users when they try to log in.

Speaker:

Maybe I have a guest wireless network for my, for people that come into the lobby.

Speaker:

That one's wide open to the internet outbound only.

Speaker:

So I don't need to worry about that quite as much.

Speaker:

And then, like phones and printers and things like that, that have very specific

Speaker:

things like, I wouldn't enable Bonura in my internal network, but maybe for

Speaker:

the printer vlan I would, because I want people to be able to find a printer.

Speaker:

Open up their laptop.

Speaker:

So they've already created these segments.

Speaker:

You just have to know where the buttons are to shut them off.

Speaker:

So maybe the example is I wanna isolate the servers from the rest

Speaker:

of the network, cuz I think there's something in there, but I can still

Speaker:

leave the wireless network up.

Speaker:

Maybe have everybody join the guest access network and force them all out

Speaker:

to the internet to do, incident response or chat channels or something like that

Speaker:

where I'm, but I'm creating these bounds so that traffic flows one direction

Speaker:

only, or it prevents certain things inside of other areas because, there's

Speaker:

nothing to say like the, the, s IDs that are on printers that are like, set up,

Speaker:

Yeah,

Speaker:

up or something like that can't be compromised.

Speaker:

And then if they can get into your printer network, it's oh

Speaker:

crap, where can they go from?

Speaker:

Yeah.

Speaker:

and Bonjour of course would be the, I don't know how would

Speaker:

apple file sharing.

Speaker:

it is, it's almost like an auto configuration announcement, setting where,

Speaker:

it, and you can thank Steve Jobs for this.

Speaker:

He's I hate setting up printers.

Speaker:

And so basically what he did is he set up a system so that the printers

Speaker:

can announce that they exist.

Speaker:

And your laptop is constantly listening for these.

Speaker:

Bonura is another one of those protocols that is extra chatty and you kinda

Speaker:

wanna put bounds on it so that like you don't have the Apple TV four hallways

Speaker:

down announcing itself to the people in accounting because one, it's annoying.

Speaker:

And two, you never know when you're gonna do something you're not supposed to.

Speaker:

Interesting.

Speaker:

So yeah, I guess a lot of these are really around setting up

Speaker:

that initial network properly.

Speaker:

So then when you do have these issues, you can recover quickly and

Speaker:

identify and then recover quickly.

Speaker:

But if you don't have that initial setup done, then you're in for a world of hurt,

Speaker:

and not just initial setup.

Speaker:

You actually do have to treat the network like a living, breathing organism.

Speaker:

I can't think of a single server admin out there that installs,

Speaker:

windows What are we up now?

Speaker:

20 20, 20 23 Windows, server X, I don't know, installs it

Speaker:

and then never patches it.

Speaker:

Never

Speaker:

Yeah.

Speaker:

it again.

Speaker:

like you people are probably just shaking, even thinking.

Speaker:

, you cannot configure a network and then just leave it alone.

Speaker:

You do have to go in and tweak things and move things and change things.

Speaker:

And, not just when you're trying to fix a broken thing,

Speaker:

Yeah.

Speaker:

have to like, okay, is this subnet big enough for the

Speaker:

number of hosts that are in it?

Speaker:

Should I create routes over here?

Speaker:

It looks like there's a lot of extra traffic going on over this direction.

Speaker:

Maybe I need to disallow that because it looks like it's something

Speaker:

that shouldn't be happening.

Speaker:

if you're not pruning back what you are working on then, and that's the

Speaker:

problem that a lot of the, ransomware writers have figured out, like a lot of

Speaker:

their secrets, if you wanna call them, that are just inadequate it support.

Speaker:

we're gonna hope that you had left this on by default and we're gonna

Speaker:

take advantage of it and use it.

Speaker:

And if you did, sorry, but if best practices guide out there says, shut

Speaker:

that off, and you didn't shut it off, are you in that big of a hurry?

Speaker:

Yeah, we're living in a world where, people don't even

Speaker:

change their default password.

Speaker:

listen, here's the thing, Tom, my plumber's here, I, I got a tradesman that

Speaker:

actually showed up at two o'clock when he said he was gonna be here at two o'clock.

Speaker:

So I gotta , we gotta shut this baby down.

Speaker:

Tom, this has been a great conversation.

Speaker:

so thanks a lot.

Speaker:

thanks for having me.

Speaker:

it's been fun to talk about networking with, with some folks that coming at it

Speaker:

from a slightly different perspective and understanding, what are we trying

Speaker:

to accomplish with it, and in some cases, what are we trying to disallow?

Speaker:

Absolutely.

Speaker:

Thanks again, Prasanna, once again, making me go backwards,

Speaker:

I, you know me, I try, you take one step back, two steps forward

Speaker:

or something like that, right?

Speaker:

something like that.

Speaker:

I

Speaker:

like that.

Speaker:

All right.

Speaker:

And thanks again to our listeners