Stopping Ransomware Lateral Movement Before It Spreads
Ransomware lateral movement is exactly what it sounds like — once an attacker's inside your network, they start crawling around looking for more to encrypt, and stopping that crawl is often the difference between a bad day and a catastrophe. In this encore episode, part four of our seven-episode series pulling the best of the archives back into your feed, W. Curtis Preston and Prasanna Malaiyandi sit down with networking expert Tom Hollingsworth to break down exactly how attackers move once they're in, and what you can actually do about it.
This one's back because listeners didn't just download it — they stuck with it, and a fair number of you came back for a second listen. That kind of engagement told us this conversation was worth surfacing again, especially with ransomware attacks as common as they are right now.
Tom walks through the fundamentals of network segmentation — VLANs, air gaps, and why a "flat" network (where everything can talk to everything) is a gift to any attacker who gets in. From there the conversation moves into Zero Trust Network Architecture, what it actually takes to implement it at scale, and why flipping the switch from "allow everything" to "deny by default" is both the right move and the one that generates a thousand help desk tickets on day one. There's a good stretch on how schools, stadiums, and hotels handle network isolation differently than a typical enterprise, plus a practical rundown of incident response — locking down external access, isolating infected segments, keeping communication running when your own network is down, and why every kill switch needs to actually be wired to something.
If you've ever wondered how much of this is built into your existing networking gear versus something you have to buy separately, or you just want a clearer mental model for how ransomware spreads once it's past the perimeter, this is a great one to revisit.
Chapter Markers:
00:00:00 - Intro and why ransomware lateral movement matters right now
00:01:25 - Welcome back, meet Tom Hollingsworth
00:04:06 - Why isolating the network is step one after a ransomware attack
00:06:07 - Networking basics: how ransomware exploits flat networks
00:09:31 - VLANs, air gaps, and network segmentation
00:14:12 - Zero Trust Network Architecture explained
00:19:02 - Managing zero trust at scale across teams
00:25:48 - Special cases: schools, stadiums, and hotels
00:34:31 - Blocking newly registered domains to stop command and control
00:38:01 - Incident response: locking down the network
00:42:12 - Keeping communication running during an attack
00:44:54 - A real-world story: isolating infected devices
00:50:01 - Building segmentation in from the start
According to CrowdStrike's most recent State of Ransomware
Speaker:survey, 78% of respondents were attacked by ransomware last year.
Speaker:With odds like that, we figured it was time to bring on one of our most
Speaker:popular episodes, and this one's all about stopping ransomware from moving
Speaker:around once it's already in your network.
Speaker:I brought on Tom Hollingsworth, who knows networking way better than I do.
Speaker:Uh, we get into VLANs, zero trust, firewalls, and a few other
Speaker:things, including some, at least I think, really good war stories.
Speaker:If this is your first time watching or listening to me, I'm
Speaker:W. Curtis Preston, AKA Mr. Backup.
Speaker:I've been obsessing over backup, recovery, and now cyber recovery for over 30 years.
Speaker:If that's your bag, then I'm your guy.
Speaker:You're not gonna find anyone that's cares about backups more than me.
Speaker:Ever since 1993 when I had to tell my boss that there were no backups of
Speaker:the database that we had just lost.
Speaker:Now I've written five O'Reilly books, a blog, and a podcast.
Speaker:Here, we turn unappreciated admins into cyber recovery heroes.
Speaker:This is the Backup Wrap-Up
Speaker:Hi and welcome to Backup Central's podcast.
Speaker:I'm your host, W. Curtis Preston, aka a Mr. Backup and have with me possibly
Speaker:my Pex consultant Prasanna Malaiyandi.
Speaker:it going?
Speaker:Prasanna,
Speaker:am.
Speaker:I'm good Curtis.
Speaker:And just for people that's p e x, not P E C K S.
Speaker:Yeah, this is the piping, the, the modern piping alternative to copper,
Speaker:which I think is far superior.
Speaker:And, You know what?
Speaker:just for those that are watching this on on video, which is only a handful of
Speaker:you, but I'm gonna tilt my camera up and this is what my office looks like right
Speaker:now because I got yet another pinhole leak in my, second story water supply,
Speaker:which happens to be right above my office.
Speaker:And yesterday I was just sitting here at my desk and I get this
Speaker:drip drip on my face and I'm like,
Speaker:you're like, am I sweating profusely?
Speaker:Yeah.
Speaker:And the pipe is actually over there.
Speaker:the joint that's leaking, it's actually over there, the water finds its way,
Speaker:down cracks.
Speaker:Yeah,
Speaker:it just drips
Speaker:down onto my face.
Speaker:Yeah, we wanna bring on our guest.
Speaker:he is both, I would say, a friend of the pod.
Speaker:He's also been an enemy of the pod at once.
Speaker:You may recall that we had an episode where basically we just argued
Speaker:with Tom without his per, without him being here to defend himself.
Speaker:that was over a blog post that he said, something about, backup
Speaker:people reporting to security people.
Speaker:And, I
Speaker:Yep.
Speaker:had an issue with that or something.
Speaker:Tom has been in the industry about 20 years and he is an
Speaker:event lead over at Gestalt.
Speaker:It the, what would you call it?
Speaker:The makers of the Tech Field Day series,
Speaker:and, we're glad to have him on the podcast.
Speaker:Welcome, Tom Hollingsworth.
Speaker:thank you for having me on Curtis.
Speaker:It was, it was fascinating to listen to an episode where I was arguing
Speaker:with somebody and it wasn't even here.
Speaker:But, I love listening to you guys, and I've learned quite a bit.
Speaker:In fact, the very first time that Curtis and I ever met at Tech Field Day back
Speaker:in 2011, he was teaching me about data de-duplication, and I was trying to
Speaker:convince him that IP V6 was important.
Speaker:And I can tell you which one of those things panned out a lot better than the.
Speaker:is it, that the thing where you do the nat behind the thing?
Speaker:That's what I recall really learning from you was that you gotta do
Speaker:NAT for I P V C
Speaker:like the Kool-Aid man, just keep
Speaker:Yeah.
Speaker:Yeah.
Speaker:Yeah.
Speaker:I wanted to bring on somebody that actually understood networking
Speaker:far better than me, right?
Speaker:Which, which is basically many people in the world.
Speaker:With ransomware attacks.
Speaker:One of the things that we talk about is once you've, figured out that you
Speaker:actually have a ransomware attack, you want to isolate the network.
Speaker:And there's a discussion, I've been talking with CISOs lately and what
Speaker:appears to be the reality is that few environments do the actual full.
Speaker:Like we just we're just shutting everything off.
Speaker:Go grab the cable, pull it out
Speaker:actually, I know.
Speaker:Tom, did you ever watch, alias when it was on
Speaker:with Jennifer Garner and.
Speaker:Okay, there's an episode in there when they were having a cyber
Speaker:attack and the, what's his name?
Speaker:Marshall Flank man comes running into the data center and he just literally
Speaker:starts flipping, flipping power switches.
Speaker:He's they're downloading all the files off the server and he down.
Speaker:He just flips all the power switches off.
Speaker:on one end there is the
Speaker:like networking, shutdown, like literally both internal and external, right?
Speaker:because, once the ransomware is inside, it's gonna try to crawl
Speaker:around and make things worse.
Speaker:So that's one way.
Speaker:And then there are, and then there's the, those that go, I'm just going to turn
Speaker:it off, I'm gonna unplug the cable at the one server or the three servers that
Speaker:appear to be infected and I'm not gonna worry about the rest of the network.
Speaker:And somewhere in the, between those two extremes is what everybody else does.
Speaker:And maybe we should also talk about basics of networking before we jump
Speaker:into this to talk about the detail.
Speaker:Because just
Speaker:Go ahead.
Speaker:I,
Speaker:Prasanna,
Speaker:no, I,
Speaker:you think we should be talking about first?
Speaker:no, I think it's because what you just mentioned, Curtis, like everyone
Speaker:might think, oh, all computers are plugged into the same network.
Speaker:I think it's important to talk about some of the best practices from networking,
Speaker:Tom, if you could, about sort of network isolation, BLANs, other things like that.
Speaker:Before we get into sort of the other side of things,
Speaker:Yeah, so please explain all networking technology, period before
Speaker:we get started.
Speaker:, you've already talked a little bit about it because it's just
Speaker:a series of tubes, pipes, if you will, that we send things through.
Speaker:now the important thing to realize when you're trying to think about how
Speaker:ransomware propagates through a network is to realize that, the way that networks
Speaker:have traditionally been built is we have this perimeter on the outside, it's
Speaker:probably bounded by and a bunch of other stuff, and it looks really imposing on the
Speaker:castle walls, but inside of the network, it's a whole lot easier to get around.
Speaker:And that's just due to the nature of the way that networks operate.
Speaker:ethernet is effectively like trying to shout out somebody's order
Speaker:number at a fast food restaurant and hoping that you get the right one.
Speaker:Everybody's gonna hear the message, but if it's not meant for you,
Speaker:we're just gonna ignore it.
Speaker:But the problem is that allows you to propagate a lot of information very
Speaker:quickly, and that's what ransomware is trying to take, advantage of whenever
Speaker:it's trying to, do almost reconnaissance lateral movement in the network.
Speaker:So I'm looking for a whole bunch of, , potentially vulnerable servers going
Speaker:all the way back, to the beginning of my professional IT career, I was
Speaker:actually working on a help desk, when the S SQL slammer worm came out.
Speaker:And boy, you'd be surprised how many people had that port open to the
Speaker:internet, because everything shut down.
Speaker:And it was really weird to see that.
Speaker:And you're like, at the time I'm freshly minted in my career.
Speaker:And I'm like, how could that happen?
Speaker:and now all these years later, I look at it and go, oh my God,
Speaker:these people were stupid because you're not supposed to do that.
Speaker:But that's one of the things that people want to take advantage of because the
Speaker:systems want to talk to each other.
Speaker:They want to be able to exchange information.
Speaker:That's the purpose of a network.
Speaker:Right.
Speaker:to do extra work to prevent them from talking to each other.
Speaker:Right.
Speaker:Yeah.
Speaker:I think that's, I, and the number of times I went in and out of data centers, over
Speaker:the years, I remember only one, where they had very solid firewalls, basically.
Speaker:That, that it was very difficult to do, to traverse laterally
Speaker:within the organization.
Speaker:And that was actually Intuit, and it's because of what they felt they had.
Speaker:They had all of this very sensitive personal data, thanks to their,
Speaker:they had QuickBooks, they have TurboTax, they have all of that stuff.
Speaker:And so they had to basically firewall off systems between each other to
Speaker:prevent that lateral movement that you're right by design in most networks,
Speaker:you buy a switch, you buy, a bunch of switches, you plug everything in.
Speaker:And everything talk, everything can talk to everything.
Speaker:and unless you do something to prevent it, lot of those ports that you talked
Speaker:about, just like the SQL, issue, a lot of those ports are visible to the internet.
Speaker:I think a, another one would be a vCenter Right.
Speaker:And Hyper V, the, that, those ports being visible to the internet, I suppose
Speaker:you hear about that a lot as well.
Speaker:Yeah.
Speaker:I usually do.
Speaker:Whenever there's some kind of, a vulnerability that comes out and
Speaker:everyone's I hope you don't have these exposed to the internet, and
Speaker:you can literally hear the scrabbling as people run into their keyboards
Speaker:to figure out if that's the case.
Speaker:But,
Speaker:as Prasanna mentioned, we have ways to like segment
Speaker:networks away from each other.
Speaker:And it's funny that you bring up that, that Intuit had a rigorous internal
Speaker:firewall structure because in my experience, companies or organizations
Speaker:that are very, heavily regulat.
Speaker:Have much more strict structure.
Speaker:And the reason for that is because they need the ability to say
Speaker:for a fact, Curtis cannot see anything on this network because he
Speaker:hasn't been authorized to see it.
Speaker:Now, you can do that through software constructs.
Speaker:VLANs, virtual local area networks are the most common way to do it, where we
Speaker:effectively divide some, partition on the switch and we say, this port belongs
Speaker:to this vlan, so it can only talk to other ports that are on that vlan.
Speaker:but that's not even good enough for some organizations.
Speaker:and the one that everybody always thinks of is Mission Impossible, the Tom Cruise
Speaker:movie with the machine that's in a vault that's not connected to anything else.
Speaker:We would call that an air gap system.
Speaker:Or you can have an air gap network a lot of times things like, HVAC or
Speaker:management systems are air gap from the rest of the network because they
Speaker:have different controls and different needs, but I also don't trust those
Speaker:people to, secure their stuff.
Speaker:So I'm gonna build a wall in front of that air gap or just completely
Speaker:isolate it, itself so that I don't have to worry about securing it.
Speaker:And if, you say hvac, you say things like, environmental control systems
Speaker:and any security people listening to this podcast are immediately
Speaker:thinking, man, those are back doors that I can use to get into the system.
Speaker:Because no matter what, they're still gonna have to be connected
Speaker:to the network somehow.
Speaker:And that just increases your, your threat profile.
Speaker:Yeah, it's interesting because I think most people who think
Speaker:about home networks, right?
Speaker:Everything's typically flat in a home, right?
Speaker:Everything can talk to everything, every single iot device out there, right?
Speaker:And they're not always thinking about, Hey, I got this smart light bulb.
Speaker:Isn't it great?
Speaker:Isn't it awesome?
Speaker:And then realizing that's on my network, everything is now exposed and could
Speaker:be potentially exposed if there's a security issue with that single device,
Speaker:Yeah, Those devices are, they obviously have an IP address, they
Speaker:have some kind of a control system.
Speaker:You would hope that most of them have some kind of a security function that
Speaker:allows them to securely communicate back to whatever controls them.
Speaker:But multiply that by a factor of 10 for all of the devices that could be
Speaker:on your average enterprise network.
Speaker:And when you start saying things like, access controls for those
Speaker:devices, or port security like network engineering and operations folks, they
Speaker:just start breaking out into hives.
Speaker:the, just the amount of work that it takes to create that level
Speaker:of security is its own monster.
Speaker:anyone who's ever deployed a technology like 8 0 2 0.1 x, which is effectively,
Speaker:I am only gonna allow authorized devices to be plugged into this port, knows that
Speaker:there's this whole enrollment process and are you on the authorized users list?
Speaker:And what happens if you're using a different device today?
Speaker:And it's just, it's maddening and it drives people to insane to the
Speaker:point where, and that's the normal people who know what they're doing.
Speaker:Could you imagine an executive plugging their laptop into a network port one
Speaker:day and going, this doesn't work.
Speaker:And you tell 'em, oh, it's doing that on purpose because we
Speaker:want to keep everything secure.
Speaker:What do you think is gonna happen?
Speaker:The executive's probably gonna look at you and go, I don't care.
Speaker:Turn it off.
Speaker:Exactly.
Speaker:. We don't need that.
Speaker:It's getting
Speaker:Yeah.
Speaker:Yeah,
Speaker:Yeah.
Speaker:I know that when we had, we had a security person on and they had a list of things
Speaker:that they wanted people to do that they felt were common sense, that were, ways
Speaker:to prevent basically, I think the proper thing today when we talk about ransomware
Speaker:is to just assume something in your world is going to get ransomware, right?
Speaker:It's just, it is, I think it's just impossible to stop it 100% of the time.
Speaker:So just assume that's going to happen.
Speaker:So then there's all about.
Speaker:How to prevent it from activating itself, from talking to the command and control
Speaker:servers and also the lateral movement.
Speaker:So he
Speaker:reducing the black
Speaker:raised,
Speaker:right?
Speaker:So what's that?
Speaker:Limiting the blast
Speaker:radius.
Speaker:so Tom, what kinds of things besides VLANs?
Speaker:Because even VLANs, we have the VLAN for this and the VLAN for that.
Speaker:Still all the servers within that VLAN can talk to each other.
Speaker:What else can companies do, with modern networking equipment to prevent
Speaker:lateral movement or to basically prevent it from everything and then,
Speaker:selectively allow it for certain servers.
Speaker:the first thing you have to do is you have to realize that a completely flat network.
Speaker:not a stable network.
Speaker:there is a limit to the amount of chatter that a network can tolerate
Speaker:before it starts running into problems.
Speaker:ethernet is not a, a medium that allows for a large number of hosts because
Speaker:eventually they're gonna, it, it's like recording a podcast eventually
Speaker:with too many guests on the podcast.
Speaker:You're all gonna wanna talk over the top of each other,
Speaker:and ethernet doesn't like that.
Speaker:So once you had a certain boundary, you have to divide it
Speaker:up into these little domains.
Speaker:collision domains are what we call them, and that's one
Speaker:of the things that a VLAN is.
Speaker:But as we've learned over the years about what we really should be doing,
Speaker:we've built a super set of that.
Speaker:And anyone out there who has been reading any kind of the tech press recently, or
Speaker:been to any trade show in the last couple of years, probably heard of something
Speaker:like Zero Trust Network Architecture or, just Zero Trust in general.
Speaker:It's a buzzword.
Speaker:I'm, I'll be the first to admit it, but the principles behind it are fairly sound.
Speaker:what you do is you take the tools that you've already been given, those ones
Speaker:that I told you, make your network team break out in hives, and you try to
Speaker:implement them in such a way as to reduce the complexity of the implementation.
Speaker:And think about think about a teenager and they want a list of, things that
Speaker:they can do when they get a car.
Speaker:Are you gonna tell them you can do anything you want, but
Speaker:you can't do this and you can't do that and you can't do this?
Speaker:Or are you gonna be more explicit?
Speaker:You can only do these things and if it's not on that list, you can't do it.
Speaker:most people would say, I'm only go, I'm gonna do the second thing
Speaker:because I want to make sure that they're only going to school and to
Speaker:work into this one friend's house.
Speaker:But we don't build networks that way.
Speaker:we typically allow as much as possible because of the situations
Speaker:we find ourselves in where something doesn't work right.
Speaker:And we don't know why.
Speaker:So we will put a little catchall at the bottom of the access list
Speaker:and go permit everything else.
Speaker:and then we leave it.
Speaker:And that's the worst thing that you can do.
Speaker:And what Zero Trust Network architectures try to do is they try
Speaker:to say, okay, that server over there is running our backup software.
Speaker:What should it, what should communicate with it?
Speaker:And how should it be communicated with, maybe it only needs to accept
Speaker:connections on these three or four ports.
Speaker:Maybe it only accepts connections from these authorized users.
Speaker:And you're effectively creating an isolation for that unit.
Speaker:And if something needs to access it and you're having problems with it, the
Speaker:software usually allows you to dig into that a little bit and go, oh, it looks
Speaker:like that this program did an update and it now needs to communicate over this
Speaker:port, and I need to allow that port.
Speaker:But you're doing it in a way that allows you to control that access.
Speaker:But more importantly, what happens is that when something tries to operate outside
Speaker:of that access control, slams it shut and hopefully will send you some kind of a
Speaker:warning, Hey, we just noticed that this server over here is trying to communicate
Speaker:with the rest of the network on Port 4 45.
Speaker:know it shouldn't be doing that.
Speaker:You need to take a look at it.
Speaker:And so limiting that blast radius, that broadcast capability tends
Speaker:to prevent lateral movement.
Speaker:And like you said, people who are going to attack you are going
Speaker:to be dedicated in doing it.
Speaker:Either they're gonna be dedicated to looking for a very specific exploit
Speaker:and just hauling in whatever they can do, or they're gonna be looking to
Speaker:attack you, you specifically, however they can get to you that second kind
Speaker:of attacker, very difficult to block.
Speaker:It's like a door lock, a dedicated burglar is gonna get into your house.
Speaker:You're looking to prevent more of the first one where it's oh, we were able
Speaker:to get in through your HVAC system and boy, we're gonna turn this thing loose
Speaker:and see what open file shares you've got out there and what we can do with them.
Speaker:You, you need to create in the organization that does not allow
Speaker:people to move laterally that prevents them from accessing things.
Speaker:Or worse yet, alerts you when things start doing a lot of across your
Speaker:network, looking for those kinds of things because the rest of the group
Speaker:that's trying to get into your network doesn't know that stuff's there either.
Speaker:They're gonna have to go looking and just like the burglars that are casing the
Speaker:joint, you need to look for those people.
Speaker:So multiple things popped up in my head, Tom, as you were talking.
Speaker:So the first is, as you're talking about the burglar example, I'm gonna bring this
Speaker:up again for the second week, but Curtis had recommended reading The Cuckoo's Egg.
Speaker:I don't know if you've read that book.
Speaker:Tom.
Speaker:Highly recommend you read it.
Speaker:It's basically, 1980s, a hacker gets into a mainframe and starts moving
Speaker:laterally across all these like military networks and science networks
Speaker:because everything was connected.
Speaker:And
Speaker:Yeah.
Speaker:you said, that example was go and try all the door locks and he would
Speaker:try default passwords and some of these systems, like the mainframes,
Speaker:people would not change the defaults.
Speaker:And so he got in and it was just that lateral movement across
Speaker:everything in the environment.
Speaker:So that's like the first thing that came to mind as you were talking.
Speaker:the other thing that also came to mind is I totally get the reason to have that
Speaker:zero trust and only enables services that, and patterns that are known to
Speaker:be valid and disable everything else.
Speaker:my question.
Speaker:As a network engineer or operations person, how do
Speaker:you manage that at the scale?
Speaker:Because there's so many applications, so many servers, it's hard to predict what's
Speaker:going to talk with what, and coming up with, because everything's all connected.
Speaker:Like in my mind I think about Facebook and graphs, right?
Speaker:Everything is connected in the world, right?
Speaker:And so everything in your network to some extent is probably
Speaker:connected in some form or fashion.
Speaker:So how do you go about even coming up with, okay, these things are the
Speaker:things that should be talking to the backup server in your example.
Speaker:So it takes a lot of teamwork because as a network person, I don't care
Speaker:what's running over my network, I just need to make sure that these
Speaker:two things can talk to each other.
Speaker:And so in a way, like if you've ever deployed a server, you have a list,
Speaker:okay, it needs to communicate, using this protocol over these ports or,
Speaker:think about, opening something like, I need to open HTTPS to the server,
Speaker:but not http because I don't want it to ever communicate over http.
Speaker:And that's actually one of the things that we've noticed a lot recently is
Speaker:that a lot of protocols that used to have their own dedicated ports have
Speaker:now just started writing over, HTTP and https s. Because it's just easier.
Speaker:bit Torrent was actually one of the first ones to start doing this because
Speaker:they're like, eighty's gonna be open anyway, which is the port for http.
Speaker:So we'll just ride on that because most people fire, most people's firewalling
Speaker:systems just allow that by default, because that's what the web uses.
Speaker:And so it gets insidious and you almost have to think at a higher level.
Speaker:So what.
Speaker:it crack open any networking textbook in the world, and they're gonna
Speaker:give you this seven layer model.
Speaker:It's like a seven layer dip from Taco Bell, but there's no refried
Speaker:beans in the seven layer OSI model.
Speaker:But we play a lot in the bottom of that, where the physical connections
Speaker:happen, where the IP addresses allow systems to talk to each other.
Speaker:Once we get above a certain level, that's where the applications take over.
Speaker:And as networking people, we're not as concerned about that.
Speaker:But boy, the server people are because, oh, I need to be able to have these
Speaker:two devices talking to each other.
Speaker:I need to make sure this is all un impeded.
Speaker:And the first thing that happens when two servers can't talk to each other
Speaker:is you gotta find the network people.
Speaker:And you're like, you need to tell me what's going on here.
Speaker:And then invariably, like the security team gets drawn in because oh no, we
Speaker:told him that he had to block that because nobody should ever be using that.
Speaker:and you really do have to pull those people together.
Speaker:think of, think of a book like, gene Kim's Phoenix project.
Speaker:Like you can't work in isolation anymore.
Speaker:As much as we might like to.
Speaker:Because so many things are so inter interdependent now.
Speaker:It's the old joke is what does the server do?
Speaker:I don't know.
Speaker:Unplug the cable and we'll see who screams the loudest.
Speaker:You wanna figure out what people, what port is being used.
Speaker:Let's block it and see who comes to yell at us.
Speaker:that's the way you have to do some of these things.
Speaker:Cuz
Speaker:the other thing, and we all know that nobody ever skips documentation, right?
Speaker:You brought up an old memory of mine.
Speaker:Literally like my first months in being a cis admin, we were trying to
Speaker:decommission, the, the first computer to run Unix was the three BK and the
Speaker:at and t had a three BK I think it was like a three B And it was their
Speaker:attempt at a multiprocessor architecture.
Speaker:And we had this beast and we were trying to decommission it.
Speaker:And, we had gotten down to, we had fi and we had gotten down to
Speaker:that phase where it's we're just gonna turn it off and whoever yells
Speaker:will be the one that we missed.
Speaker:But I remember the, We had, stripped it, all of its regular networking cable.
Speaker:I don't exactly remember exactly why, but I remember that there was one cable left
Speaker:and it was running across the floor and we were doing the last like download of was
Speaker:off of this server onto something else.
Speaker:And the manager for that cost center was in there and he
Speaker:kept stepping on the cable.
Speaker:we told him that he was slowing down the download whenever
Speaker:he would step on the cable.
Speaker:we actually caught him, we left him into data center.
Speaker:We actually caught him like watching the monitor and like the
Speaker:throughput speed and stepping on and stepping up and off on the cable.
Speaker:Bad Curtis.
Speaker:Yeah.
Speaker:good stories.
Speaker:I, so question I want to ask you about, all of the things you just
Speaker:talked about, this something built into modern networking equipment or
Speaker:is this, are these extra applications that I'm buying that then configure
Speaker:that networking equipment for me?
Speaker:So it can be both.
Speaker:the basics of being able to isolate hosts and configure systems
Speaker:has been built in for years.
Speaker:anyone can write an a c L, right?
Speaker:The thing is that scaling that across a large organization is
Speaker:where it typically falls down.
Speaker:Eventually, your security team can't keep up with all the changes.
Speaker:They throw their hands up in the air and it lies fallow for as long as
Speaker:it takes for you to get infected.
Speaker:So the additional tools that are basically being brought to market and
Speaker:are popular now, organize that system.
Speaker:They put a shiny.
Speaker:UI on it, if you will, to go in and say, okay, I want to enable port
Speaker:security on these ports because back when I started this port security was,
Speaker:if it isn't being used, shut it off.
Speaker:Just shut down the port.
Speaker:And then if somebody plugs into it and it doesn't work, then now we know
Speaker:we need to enable that port and we need to know who's trying to use it.
Speaker:But now you have the ability to have somebody plug in a device, whether
Speaker:it's an IOT system or what have
Speaker:you, and this, the device will register with the system.
Speaker:It'll say, Hey, I need access.
Speaker:And then the system can come back and say, Hey, it looks like somebody
Speaker:plugged in an S thermostat over here.
Speaker:that's actually a bad example cause they don't use wires, a laptop
Speaker:or some other kind of device, you need to go, check it out.
Speaker:Or you can even set a policy that says, I'm going to allow you for now, I have the
Speaker:ability to just cut it off if I need to.
Speaker:Or if it's one of these recognized device classes or something like that.
Speaker:So for smaller systems, for smaller organizations, if your IT department
Speaker:isn't already completely overworked, you can't implement some of this by hand.
Speaker:It's just a matter of if it works really well, that means you're gonna
Speaker:be spending a lot of time tuning that system to keep working effectively.
Speaker:And once you get past a certain point, the, the solutions that do
Speaker:this are reassuringly expensive because they're worth it.
Speaker:Oh, I understood cuz that they would help you save the labor.
Speaker:And is there a category of these types of tools that, that a
Speaker:category name that we give to them?
Speaker:there's a bunch of different ones.
Speaker:access management is typically one that honestly, tools like Aruba
Speaker:ClearPass or Cisco ice, ise, integrated services engine, or integrated security
Speaker:engine, I forget which one it is.
Speaker:But they're not identity and access management, although
Speaker:they can be integrated that.
Speaker:There are some smaller ones that have these capabilities.
Speaker:A lot of it is mostly figuring out what you need because there's different,
Speaker:some systems are configured so that you're controlling access to devices.
Speaker:I only wanna authorize people to be able to log into this
Speaker:device and make changes to it.
Speaker:that's different than I want to change the way that people in my network are
Speaker:accessing data like that is a different kind of identity and access management.
Speaker:So you need to do a little bit of investigative work to make sure that
Speaker:you are, properly using the right tool.
Speaker:Cause if you spend a lot of money on one that doesn't give you what you want or
Speaker:does a terrible job of it, then not only are you gonna be upset, but the people
Speaker:that are or authorizing your budget are not gonna be very happy with you.
Speaker:Now a lot of these changes, if I think about an enterprise
Speaker:environment, things are easier to a fair extent to control, right?
Speaker:If you're looking at servers or virtualization, other things like that.
Speaker:But then I go to think about other environments like a school, where you
Speaker:have students coming and going, right?
Speaker:Or a stadium or a conference center, right?
Speaker:Does it get significantly more difficult to do what you talked
Speaker:about, Tom, in those environments?
Speaker:Or can the same tools apply there as well?
Speaker:Yes and no.
Speaker:I'm the typical IT nerd.
Speaker:The answer is, it depends for whatever question you ask, but I'll tell
Speaker:you that in some ways, schools and other places where your user base
Speaker:is not employed directly by you.
Speaker:have a slightly easier time if you're willing to, a little bit.
Speaker:So I know that there are a lot of colleges out there that treat their
Speaker:student dorm networks like the wild west.
Speaker:We don't care what goes on out there, but we're not gonna keep an eye on it either.
Speaker:So if
Speaker:there's a, a piece of ransomware or something that's running rampant through
Speaker:the system, all we did is tell you that you had to have your antivirus up to
Speaker:date to be able to join our network.
Speaker:Yeah.
Speaker:the stadiums are actually a really interesting, problem too, because not
Speaker:only do you have a, a group of users that are outside of your control, they're
Speaker:very transient, in a lot of those places.
Speaker:Like they, they actually have, wireless networks that are set
Speaker:up so that, they can only talk.
Speaker:, like they block all device to device communication, which
Speaker:is something that you can do.
Speaker:It's a little bit more complicated, but it effectively treats, the
Speaker:stadium itself like a demilitarized zone in a, in a security structure.
Speaker:So for most people that are familiar with it, you've got the outside
Speaker:internet, which is big and scary.
Speaker:You've got your inside network, which is soft and you don't want it to get hurt.
Speaker:And then in the middle you have the dmz, which is basically the moat where
Speaker:you're like, I'm gonna put everything that I don't care if it gets attacked
Speaker:out there so that if it breaks, it can't get back into my network.
Speaker:And but the otherwise, the other thing there is I only allow certain
Speaker:traffic to come back through.
Speaker:So if something bad were to happen, can just basically cut it off and
Speaker:sink it into the moat and I'm done.
Speaker:Yeah, I think, hotels have a similar model, right?
Speaker:Where the base, I know having plugged in multiple devices that needed to
Speaker:talk to each other in hotel networks, they don't like that very much.
Speaker:and you end up having to bring basically your own router if that's
Speaker:something that you want to do.
Speaker:the, so it sounded like, if I understood you correctly, the access management
Speaker:part is this sort of basic security thing, that there are tools that do
Speaker:just that, and then there's also this identity access, which is a bigger pain.
Speaker:I would imagine.
Speaker:But those that want that, and it sounds like when we put those two together,
Speaker:that's what we call a SEIM tool, right?
Speaker:Is identity and access management.
Speaker:But it sounds like there's just an access management.
Speaker:That, for those that need just that there, there's smaller and less
Speaker:expensive than a full SEIM tool.
Speaker:Yeah.
Speaker:not inexpensive, but just less expensive.
Speaker:and it also matters as to what you're spending your resources on, because there
Speaker:are tools that will do this for free.
Speaker:But they are not supported at all by anybody other than people on a forum.
Speaker:And they'll be glad to tell you that you misconfigured something
Speaker:and go figure it out yourself.
Speaker:Like we, we've dealt with that.
Speaker:And I'm not really crapping on the open source community because
Speaker:they do an amazing job of this.
Speaker:I'm crapping on the fact that open source communities are not as well supported
Speaker:as the bigger players in these markets.
Speaker:And that's the expensive part comes from.
Speaker:You're not paying for the software, although you are in some ways.
Speaker:You're paying for somebody to answer the phone when somebody is like breathing
Speaker:down your neck because something won't work or something won't come online.
Speaker:And so a and you're also trying to get to that point where not automated
Speaker:as much as it is as low possible.
Speaker:Because what you want in situations is people to just
Speaker:be able to get on the network.
Speaker:that's the thing.
Speaker:If you've ever tried to log into a wifi network that has a captive portal
Speaker:that requires you to accept a whole bunch of licensing agreements and
Speaker:type your room number in and all the other stuff, you know that it's not
Speaker:the most frustrating thing, but it's definitely not what you want to hear.
Speaker:As opposed to oh, this device has already been pre-authorized cuz you logged in
Speaker:with your active directory username.
Speaker:we'll just let it on the network.
Speaker:That's completely frictionless.
Speaker:But the amount of effort that it takes to make it frictionless is where your time
Speaker:and resource invests gonna come from.
Speaker:Tom, I know we started this all out with Curtis asking, how do
Speaker:you prevent lateral movement in networks right from ransomware?
Speaker:Just given the fact that ransomware does move laterally in a lot of networks?
Speaker:Does this mean people are not using these tools or have not
Speaker:configured the networks correctly?
Speaker:Because it seems if you did all the things that we just talked about, it
Speaker:should have prevented a lot of the lateral movement that we see in ransomware today.
Speaker:Prasanna, I'm gonna tell you something that my dad always tell
Speaker:me, and you have to understand.
Speaker:My dad grew up in the country.
Speaker:If a frog had wings, he wouldn't bump his ass every time he hopped.
Speaker:yes, if you turn on all of these tools, you will cut down on a lot of this stuff.
Speaker:But does that mean your network's not working correctly?
Speaker:No.
Speaker:It just means that we didn't enable all these extra features that we have
Speaker:to keep track of because I can get four, four ports on a. and plug four
Speaker:devices in there and they're gonna work is the best way for them to work.
Speaker:Absolutely not, but I also don't have to do a whole lot of extra configuration.
Speaker:A lot of people are looking at this from the perspective of, I need to
Speaker:make sure that everything is able to communicate with everything else.
Speaker:They're not looking at it like you, like the example you had earlier, Curtis, when
Speaker:you log into the hotel wifi and I can't talk to anything else on the hotel wifi.
Speaker:They're not thinking in a, in an isolation mode.
Speaker:And we're that ship's turning because a lot of people are now realizing that
Speaker:traditional idea of having a very stiff, crunchy perimeter with a very soft
Speaker:internal network doesn't work so well.
Speaker:Right,
Speaker:ends up happening is that once people get through the perimeter, they have
Speaker:free reign to do whatever they want.
Speaker:You, you do have to build these controls in place to effectively
Speaker:slow them down or to herd them to places that you want them to go.
Speaker:And that's what a lot of people have spent time developing and working on.
Speaker:And there's varying degrees of success to make that work.
Speaker:It has to shift the mindset though.
Speaker:application people are just turn on all the ports and I'll turn them off later.
Speaker:When I tell you which ones I don't need, you won't, because you'll
Speaker:right.
Speaker:something else.
Speaker:It's like developers, they're like, I'm gonna load everything I can possibly
Speaker:think of in the memory so that I know the library that I need is there.
Speaker:And then you wonder why your, application is consuming like three terabytes of ram.
Speaker:It's maybe you need to pa pair back a little bit on that.
Speaker:Yeah.
Speaker:So it, it sounds like these tools are there.
Speaker:I think a lot of people do use them, but you talked about, like in the
Speaker:very beginning, you said that people's heads are gonna start spinning or
Speaker:whatever, because there is a lot of work involved in implementing these things.
Speaker:And the moment you flip that switch from, per, from everything is
Speaker:permitted to only the things that are permitted or permitted, you're
Speaker:gonna get 5,000 tickets, right?
Speaker:I can't do this and I can't do that.
Speaker:And they see that.
Speaker:They see that very real worry.
Speaker:and I think it stops many people from implementing this because they just see
Speaker:it as the amount of work they're gonna have to do to initially implement it.
Speaker:they're, and they're not seeing the risk of what's gonna happen when
Speaker:they get a ransomware infection, and then it just goes crazy.
Speaker:Most tools that are set up like this.
Speaker:they have a learning mode where they will, you could put 'em in place and
Speaker:they just sit there and they watch for at
Speaker:least the first, week or two.
Speaker:And they're mapping out all of these application dependencies.
Speaker:the backup system needs to receive traffic on this port for this
Speaker:application from this subnet.
Speaker:And then it allows you to carefully craft that rule so that only devices
Speaker:from this subnet can talk to that server on these ports and nothing else.
Speaker:And if you let the tool go long enough, you'll be able to like, suss
Speaker:out exactly what you need to know.
Speaker:But yeah, that first day you click the switch to from, allow list to deny
Speaker:a list is just like you're staring at the ticket queue because you're
Speaker:like, oh, what happens if I, if this machine hadn't been turned on for a
Speaker:Yeah.
Speaker:And this
Speaker:yeah.
Speaker:Yeah.
Speaker:It just, it is, it's maddening because you're always gonna wonder if you didn't
Speaker:get the right stuff, but like you said, would you rather be worried about one
Speaker:machine that can't talk to another?
Speaker:Or would you be worrying about the fact that you're getting a phone call from
Speaker:the CIO saying, yeah, the database has just got encrypted by this new flavor
Speaker:of malware that we haven't seen yet.
Speaker:why did that?
Speaker:Yeah.
Speaker:Another thing I want to ask you, I wanna move forward
Speaker:into the ransomware part here.
Speaker:Although Prasanna, I'm so glad you basically told us to go backwards.
Speaker:You always, you're really good at that, you're really good at
Speaker:I try.
Speaker:anyway, I wanted, so one of the things, so we talked about
Speaker:trying to limit lateral movement.
Speaker:Another thing that was suggested was to not
Speaker:new either new domains, like domains that just recently were created, or
Speaker:domains that w got recently active, From a DNS perspective, is that still
Speaker:fall under the networking purview?
Speaker:or is that is that another world?
Speaker:it tend, anything that involves names and not numbers tends to float up towards
Speaker:the application team or the security
Speaker:Okay.
Speaker:and the reason for that is because, like you said, like one of the things
Speaker:that, that we see a lot in security now is it's this idea that you wanna black
Speaker:hole things that are relatively new.
Speaker:Like why is this machine suddenly starting to communicate over a d n
Speaker:s name that I've never seen before?
Speaker:But it also
Speaker:requires that your devices have the intelligence to be able to resolve that
Speaker:because, application layer firewalls will see, oh, you are trying to access
Speaker:this service that I don't recognize on a domain that I've never seen before.
Speaker:Whereas a lower level, almost a packet filtering firewall will say,
Speaker:oh, that's an IP address connection on this port from here to there.
Speaker:I don't see a reason why I shouldn't be using that.
Speaker:Gotcha.
Speaker:You, have to integrate those two things together because like you said,
Speaker:something doesn't look right here because why would it be contacting a
Speaker:brand new DNS name that it should, it has no reason to contact or worse yet?
Speaker:You can ask the people over at SolarWinds.
Speaker:Why is this DLL suddenly talking to .ru addresses?
Speaker:right?
Speaker:Yeah.
Speaker:when he says new domain names, he actually means domain names that were
Speaker:like recently registered, not just domain names that are new to your network.
Speaker:And then also ones that, that were, they were registered but they hadn't
Speaker:been active or something like that.
Speaker:So that sounds like that's a d n s there's a d I world, right?
Speaker:we had somebody on from that.
Speaker:I think we need to have some, because this is, I think that's, , if you
Speaker:can reasonably do that, where you could basically push a button, just
Speaker:like the deny the allowed deny thing.
Speaker:If you can reasonably say, I, I don't want, want anybody talking to domain
Speaker:names that were registered 24 hours ago.
Speaker:I if you could do something like that, it will of course also
Speaker:create some trouble, tickets.
Speaker:But I'm thinking far less.
Speaker:And if you could do that, it stops to command and control, the ransomware from
Speaker:reaching out at command and control,
Speaker:the
Speaker:down.
Speaker:But the one thing I will say there though, is that you need to make sure
Speaker:that your users are expecting that change.
Speaker:Because if it requires you to go out and check a list or, get some kind of
Speaker:una authorization to go to this domain name, even if it adds one second to the
Speaker:resolution time, that's one extra second that people are going to complain about
Speaker:and you know who they're gonna complain.
Speaker:mm-hmm.
Speaker:team, because the network isn't working.
Speaker:Not the d n s block list checker or the application that has this built into it.
Speaker:Oh, no.
Speaker:It's the network's fault because the packets aren't
Speaker:going where they're supposed to.
Speaker:we used to say back when I was, when I first said that we would
Speaker:say the problem's under the floor.
Speaker:meaning, meaning it was a networking problem.
Speaker:go ahead, Prasanna.
Speaker:So moving on.
Speaker:So we talked about how to prevent lateral movement, how to detect these,
Speaker:rogue, servers that are coming up.
Speaker:One thing I wanted to ask is, so say you do get hit by ransomware, right?
Speaker:They're able to move laterally.
Speaker:What happens next from a networking perspective?
Speaker:I guess two questions.
Speaker:One is how do you, how would you go about bringing down your network or sort
Speaker:of isolating what needs to be isolated?
Speaker:Like how do you actually figure out what's going on in your network?
Speaker:And then the second question is, okay, now that you've identified that, how do
Speaker:you slowly recover from those situations?
Speaker:Incident response is never fun because it's a whole lot of cleanup.
Speaker:And, and the first thing you have to do is you have to get people out
Speaker:of your network because there's, there's obviously, there's the
Speaker:tools that kind of run on their own.
Speaker:And there are tools that kind of have to be piloted by people.
Speaker:So you have to create, limits on the system to be able to stop that.
Speaker:And fingers crossed that you're not in a situation where your entire
Speaker:network has been taken down by whatever is causing the problem.
Speaker:Because I've seen that before too, where not only does it try to laterally move to
Speaker:infect systems, it also throws up enough extra garbage that you are, it's Inca,
Speaker:you're capable of logging into any of your
Speaker:Oh,
Speaker:So we're lesson number one.
Speaker:Make sure all your management networks are isolated so that you
Speaker:always have the ability to use those.
Speaker:But the first thing that I would.
Speaker:As I would cut off outside access immediately, I would
Speaker:lock the firewall in place.
Speaker:you don't have to run through the data center screaming with your
Speaker:hair on fire and start yanking cables out like the alias episode.
Speaker:But you need to be able to lock all of those connections down.
Speaker:And specifically you need to look for ones that, could be like, from
Speaker:really weird external addresses, or worse yet ones that are coming in.
Speaker:Once you've blocked that external access in and out, you gotta do it
Speaker:in both directions because obviously you don't want anything getting out
Speaker:because the two things that I can think of are command and control traffic.
Speaker:If some kind of tool that's being, orchestrated or data exfiltration
Speaker:Yep.
Speaker:and you're like, oh, I can stop those file transfers.
Speaker:Yeah, look up oil rig.
Speaker:It was, it was able to exfiltrate data through DNS queries.
Speaker:that's the kind of crap you have to worry about.
Speaker:So you've gotta lock it down.
Speaker:Then you have to isolate because that's
Speaker:And
Speaker:too.
Speaker:before you move on,
Speaker:yeah.
Speaker:you there?
Speaker:so how do you do that, right?
Speaker:is this something where you have to create.
Speaker:A button to press up, because this sounds like a lot of little steps you
Speaker:probably need to do this manually, or is there something I can do
Speaker:upfront that says, in the event of a ransomware attack, push this button.
Speaker:Hey, gum.
Speaker:Shut up.
Speaker:Anyway, in the event of a ransomware attack, press this button and it
Speaker:does the 10 things I need to do.
Speaker:what do you think
Speaker:Some of them do have a big red button press here to terminate
Speaker:all firewall connections.
Speaker:But most of the time you're gonna have to create like a checklist or have
Speaker:a system of okay, I'm gonna go into these rules and I'm gonna uncheck these
Speaker:five boxes and then I'm gonna hit the terminate connections button to make
Speaker:sure that no new connections can be made.
Speaker:Also, if you have a rule at the bottom of your firewall list that
Speaker:says Permit ip, any, take it out
Speaker:now because it's not doing you any good.
Speaker:but more importantly, you have to, all kill switches have to be wired.
Speaker:, such thing as a magical switch that you can just hit, even if it's one that the
Speaker:provider has given you what it does.
Speaker:Does it dump the rules completely?
Speaker:Does it just suspend the rules until you go in and manually add them?
Speaker:Remember that could also cut off your connection to the firewall, so
Speaker:you need to have another way to get into it just in case that happens.
Speaker:Another reason for an isolated management network, but the idea is that you need to
Speaker:investigate what your options are because God help you if you really do have to
Speaker:run down to the data center and yank the cables out, and if that is a case and
Speaker:hey, it's just as valid as anything else.
Speaker:Can you make sure that you have the right keys, that you know which
Speaker:firewall you're yanking out of?
Speaker:Are there any other exits off of your network?
Speaker:Because that's another problem that you may run into.
Speaker:What happens if someone has created another exit off of your network,
Speaker:either accidentally or on purpose?
Speaker:And what happens then?
Speaker:Because you know it's just as easy for me to plug something into your network.
Speaker:And if there's another way off of it, I'm gonna find it.
Speaker:Yeah.
Speaker:The one other thing though, I know you talked about, and it totally makes
Speaker:sense to kill all incoming and outcoming traffic, but just thinking a step forward,
Speaker:like when you're dealing with incident response, doesn't that also take out like
Speaker:your chat channels, your slack channels, your video conferencing, everything
Speaker:else, like what do you do at that point?
Speaker:Is it just hope you have everyone's cell phone numbers?
Speaker:you need to have a plan for out of band incident response because y
Speaker:it's, it's just like any crime scene.
Speaker:I need to figure out what's been hit and I need to figure out how
Speaker:much of it is going to spread.
Speaker:And you're thinking to yourself like, I can't shut my network down
Speaker:permanently because you know it's gonna cost me X amount of dollars.
Speaker:Yes, but it's also gonna cost you x plus whatever amount of
Speaker:dollars when the next system gets
Speaker:If you don't
Speaker:a device that no, nobody's patched it in years.
Speaker:I'm not gonna lie.
Speaker:Incident response can work over iMessage text threads for a good couple of
Speaker:hours while you try to figure that out.
Speaker:Or, buy your incident response team like those little, hotspots or enable the
Speaker:data plans on their phone so that they can join their laptop there and join a
Speaker:Slack instance outside of your network.
Speaker:Yep.
Speaker:way nothing is working internal to your network.
Speaker:Because that's the other thing too.
Speaker:If you, if this is something that's particularly insidious on a window
Speaker:system and your incident responders are using Windows systems and they
Speaker:join the network to be able to do incident response and their laptops get
Speaker:compromised because they join the network again, you're gonna feel really dumb.
Speaker:It's the professional, when they blew up the bomb squad truck, it's come
Speaker:on guys, what were you expecting?
Speaker:You just reminded me of the, there's a series of commercials and there's
Speaker:one where the commercial is it's like a horror movie and the, there's a
Speaker:bunch of kid, it's like the, I got the guy with the ax murderers looking
Speaker:for the group of kids, and they're like, why don't we go hang out?
Speaker:Why don't we go hide in that shed over there with all the, with all
Speaker:the, machetes or something like
Speaker:that, so we talked about blocking external traffic.
Speaker:What about blocking internal traffic?
Speaker:basically the lateral traffic, be due to the, we know we have ransomware
Speaker:and we know it's gonna try to crawl.
Speaker:What about blocking that, access?
Speaker:So that's where you hope that your management networks are, isolated
Speaker:because the first thing I would do going into a router is shut down the route.
Speaker:Tables prevent, traffic from being passed across network boundaries.
Speaker:what you're effectively doing in there is you are containing the damage to one area.
Speaker:Now, yeah, you're gonna take things down, but if you can isolate that network as
Speaker:the location for wherever the problem is, you can then bring other networks
Speaker:back online be relatively certain that they're not gonna be infected.
Speaker:I really hope that you're not using just regular routing, that you have
Speaker:some kind of a security boundary there, because that makes it a whole lot.
Speaker:But you've got to think in, in phases.
Speaker:Obviously, using the kill switch is gonna take everything down, but then you have
Speaker:to start, can I bring this back online?
Speaker:Is this going to be infected?
Speaker:What would I be looking for?
Speaker:so I actually have a story about this, this happened last year to my children.
Speaker:one of 'em goes to the public high school here, and I got a rocket text
Speaker:message from their IT department saying, please turn off all public school
Speaker:issue devices until further notice.
Speaker:And I'm like, uhoh, somebody got hit with something fun.
Speaker:And this was like the last day before Christmas break or something.
Speaker:So we went in and we turned off my kid's MacBook, right?
Speaker:So now, immediately I, because I know what the thing was, I don't want anybody to
Speaker:like phone home and get infected and then infect the parents networks or whatever.
Speaker:Okay, no problem.
Speaker:We just shut it off.
Speaker:But then I'm like, I wonder what it could.
Speaker:like I, I'm curious and they've, to this day, they've never disclosed what
Speaker:it was, but you would get an email like the next week, oh, if you're using like
Speaker:a corporate phone or if you're using a MacBook, you can turn it back on.
Speaker:that automatically lowers the horizon of, it has to be something that's focused
Speaker:on Windows or something like that.
Speaker:So then you start running through your head of what it could possibly be.
Speaker:an incident response, you have to do the same thing.
Speaker:What server got hit?
Speaker:Oh, it was the database server and it was running this version
Speaker:of, windows or SQL server.
Speaker:Okay.
Speaker:Does that mean that Max can get on the network?
Speaker:Do I want them on the network?
Speaker:Is it a situation where even though they can't be infected, they could
Speaker:propagate something to another location?
Speaker:there's a lot that you have to go into because obviously the executives are
Speaker:gonna be like, when can we do back up and.
Speaker:and if you're a publicly traded company, oh God, the stockholders are like outdoors
Speaker:with pitchforks and torches and they wanna know when they can get their dividends.
Speaker:And you're like, when I figure out how much of this data got encrypted
Speaker:or stolen, and you're always gonna be fighting that tension and you can't
Speaker:just shut everything off forever.
Speaker:So that's part of incident response is you've got one team working on figuring
Speaker:out how to stop whatever infected you, but you've got another team figuring
Speaker:out how to bring things back online.
Speaker:That's why we call it business continuity now.
Speaker:It is interesting about the incident response.
Speaker:How have you seen cases?
Speaker:Like how do you actually, two questions I have.
Speaker:How do you figure out like that, this segment, going back to what
Speaker:you said, you kill all the routes.
Speaker:How do you figure out that this segment is safe or not?
Speaker:And then I guess that, yeah, that's actually only one question.
Speaker:so typically what, and you're effectively, when you create these
Speaker:boundaries, it's like looking for the hot potato effectively, because
Speaker:unless you, like in the alias episode, just go click all the switches off.
Speaker:Those devices can still communicate to each other at layer two.
Speaker:Now, where you don't wanna have a problem is that it's in the data.
Speaker:because if you isolate the layer two data center, now you've got a real problem.
Speaker:Because if those servers, if it's looking for servers, those
Speaker:servers can still get infected.
Speaker:That's why it's actually better to have a, a host route or something
Speaker:like that, or something that, that kind of isolates that per unit thing.
Speaker:honestly, like a V switch is perfect for this because if it's not bound for that
Speaker:host, I'm not gonna let it go any further.
Speaker:But effectively what you have to do is you have to look for chatter
Speaker:that's still going on in the network.
Speaker:Like you, I've shut all this down.
Speaker:I told my users to disable their machines or turn them off or
Speaker:whatever, what's still trying to talk.
Speaker:And then you go take that on a case by case basis.
Speaker:Oh, this device is still sending traffic that it's, but
Speaker:it's looking for this server.
Speaker:Okay, I'm, I can shut it off because I know that it's probably safe.
Speaker:But then you run into something like, oh, this thing is chattering
Speaker:an awful lot and it's chattering on a way that it shouldn't be chattering.
Speaker:that's how I've gone and found hosts that have been infected, but not
Speaker:by ransomware, but by early malware because they just kept hammering the
Speaker:firewall with these outbound requests.
Speaker:And I'm like, you shouldn't
Speaker:be doing that.
Speaker:So it's almost like a little bit of detective work.
Speaker:The good news is that even though the network devices are like dumb from
Speaker:the perspective of I don't care what application is trying to talk, where
Speaker:they're really good at telling you that things are still generating traffic.
Speaker:It's oh, this port is still sending a ton of packets bound
Speaker:for this address on this location.
Speaker:And so then you're like, oh, I think something might be up here.
Speaker:Do you ever see cases where people.
Speaker:, almost do a, create a black hole on the device itself sync the packets there so
Speaker:it doesn't go out, rather than having to necessarily do it on the switch.
Speaker:you can, that's actually a really great way to determine what it's
Speaker:trying to contact is to create like a null route on the system.
Speaker:going all the way back three or four years.
Speaker:Like Mark Marcus Hutchins, that's how he actually stopped a major outbreak
Speaker:of malware, for all the good it did, and he got arrested by the FBI later.
Speaker:But he basically black hole the dns.
Speaker:yeah.
Speaker:He bought the domain black hole it because if that domain name was
Speaker:active, then it would stop propagating.
Speaker:And so he figured that out by saying, oh, I wonder where this is
Speaker:going and I wonder what it's doing.
Speaker:You can do that.
Speaker:And it's actually the next step in incident response, which you've isolated
Speaker:the system, is I wanna see how it behaves and what it's trying to do.
Speaker:Cuz that could give me a clue as to what I got hit with and
Speaker:what they could be looking for.
Speaker:And that gives you, a little bit of opportunity, but that's
Speaker:a little bit more of an advanced tool that you would want to use.
Speaker:just because black holding traffic on a device takes a little bit of setup,
Speaker:especially if you're fighting against people who don't want you to do that.
Speaker:Yeah.
Speaker:Yeah, so it sounds a lot of the things that you talked about in the last
Speaker:couple of minutes, would be a lot easier to do again, if we segmented
Speaker:the network in the first place,
Speaker:Mm-hmm.
Speaker:We put people with Windows laptops on one network.
Speaker:We put people with Mac laptops on a network, another network.
Speaker:We put the phones right?
Speaker:That are doing the wifi.
Speaker:We put them on another network.
Speaker:and we put servers on a different network.
Speaker:We put, maybe we put servers of a different type on a different network.
Speaker:So that way you could basically say you don't have to tell
Speaker:the users to not do anything.
Speaker:You can just say shut off the laptop, network.
Speaker:and you shut off the laptop network and so on.
Speaker:and all the networks that where we don't currently, what we're not looking at.
Speaker:And then, okay, who's trying to talk?
Speaker:Who's trying to talk?
Speaker:Why is this server surfing?
Speaker:The web
Speaker:Yeah.
Speaker:There's nobody over there.
Speaker:Why is this server going over report 80?
Speaker:a lot of places already have this by default, even if they didn't realize
Speaker:they were doing it because you have different classes of devices that
Speaker:you wanna treat them differently.
Speaker:Like for example, the the server network, we want to have a little
Speaker:bit more security in there.
Speaker:Maybe a little less host to host East to west traffic kind of thing.
Speaker:The wireless network where all the laptops and the devices connect.
Speaker:I'm a little less careful about that because I actually have identity
Speaker:management in place that validates the users when they try to log in.
Speaker:Maybe I have a guest wireless network for my, for people that come into the lobby.
Speaker:That one's wide open to the internet outbound only.
Speaker:So I don't need to worry about that quite as much.
Speaker:And then, like phones and printers and things like that, that have very specific
Speaker:things like, I wouldn't enable Bonura in my internal network, but maybe for
Speaker:the printer vlan I would, because I want people to be able to find a printer.
Speaker:Open up their laptop.
Speaker:So they've already created these segments.
Speaker:You just have to know where the buttons are to shut them off.
Speaker:So maybe the example is I wanna isolate the servers from the rest
Speaker:of the network, cuz I think there's something in there, but I can still
Speaker:leave the wireless network up.
Speaker:Maybe have everybody join the guest access network and force them all out
Speaker:to the internet to do, incident response or chat channels or something like that
Speaker:where I'm, but I'm creating these bounds so that traffic flows one direction
Speaker:only, or it prevents certain things inside of other areas because, there's
Speaker:nothing to say like the, the, s IDs that are on printers that are like, set up,
Speaker:Yeah,
Speaker:up or something like that can't be compromised.
Speaker:And then if they can get into your printer network, it's oh
Speaker:crap, where can they go from?
Speaker:Yeah.
Speaker:and Bonjour of course would be the, I don't know how would
Speaker:apple file sharing.
Speaker:it is, it's almost like an auto configuration announcement, setting where,
Speaker:it, and you can thank Steve Jobs for this.
Speaker:He's I hate setting up printers.
Speaker:And so basically what he did is he set up a system so that the printers
Speaker:can announce that they exist.
Speaker:And your laptop is constantly listening for these.
Speaker:Bonura is another one of those protocols that is extra chatty and you kinda
Speaker:wanna put bounds on it so that like you don't have the Apple TV four hallways
Speaker:down announcing itself to the people in accounting because one, it's annoying.
Speaker:And two, you never know when you're gonna do something you're not supposed to.
Speaker:Interesting.
Speaker:So yeah, I guess a lot of these are really around setting up
Speaker:that initial network properly.
Speaker:So then when you do have these issues, you can recover quickly and
Speaker:identify and then recover quickly.
Speaker:But if you don't have that initial setup done, then you're in for a world of hurt,
Speaker:and not just initial setup.
Speaker:You actually do have to treat the network like a living, breathing organism.
Speaker:I can't think of a single server admin out there that installs,
Speaker:windows What are we up now?
Speaker:20 20, 20 23 Windows, server X, I don't know, installs it
Speaker:and then never patches it.
Speaker:Never
Speaker:Yeah.
Speaker:it again.
Speaker:like you people are probably just shaking, even thinking.
Speaker:, you cannot configure a network and then just leave it alone.
Speaker:You do have to go in and tweak things and move things and change things.
Speaker:And, not just when you're trying to fix a broken thing,
Speaker:Yeah.
Speaker:have to like, okay, is this subnet big enough for the
Speaker:number of hosts that are in it?
Speaker:Should I create routes over here?
Speaker:It looks like there's a lot of extra traffic going on over this direction.
Speaker:Maybe I need to disallow that because it looks like it's something
Speaker:that shouldn't be happening.
Speaker:if you're not pruning back what you are working on then, and that's the
Speaker:problem that a lot of the, ransomware writers have figured out, like a lot of
Speaker:their secrets, if you wanna call them, that are just inadequate it support.
Speaker:we're gonna hope that you had left this on by default and we're gonna
Speaker:take advantage of it and use it.
Speaker:And if you did, sorry, but if best practices guide out there says, shut
Speaker:that off, and you didn't shut it off, are you in that big of a hurry?
Speaker:Yeah, we're living in a world where, people don't even
Speaker:change their default password.
Speaker:listen, here's the thing, Tom, my plumber's here, I, I got a tradesman that
Speaker:actually showed up at two o'clock when he said he was gonna be here at two o'clock.
Speaker:So I gotta , we gotta shut this baby down.
Speaker:Tom, this has been a great conversation.
Speaker:so thanks a lot.
Speaker:thanks for having me.
Speaker:it's been fun to talk about networking with, with some folks that coming at it
Speaker:from a slightly different perspective and understanding, what are we trying
Speaker:to accomplish with it, and in some cases, what are we trying to disallow?
Speaker:Absolutely.
Speaker:Thanks again, Prasanna, once again, making me go backwards,
Speaker:I, you know me, I try, you take one step back, two steps forward
Speaker:or something like that, right?
Speaker:something like that.
Speaker:I
Speaker:like that.
Speaker:All right.
Speaker:And thanks again to our listeners