Milestone 2 1
ISE 620 : Final Project Milestone 2
Milestone 2 2
No.
Attack
Phase
Attack
Action
Compro
mise
indicato
rs
Detection
point
Defensive
countermeasures
Defense
phase
1
Targeting
Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us
traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web
server
logs
(public
systems)
Perimeter
firewall
logs
Keeping check
of malicious or
suspicious log
addresses
Applying
temporary block
on suspicious
log addresses
Documenting
findings and
action taken
Preparation
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information
on the
possible
targets
Applying
tools like
Nmap for
scanning
target
systems to
identify open
ports or
other
vulnerabilities.
ac
Detectio
n of
external
scans in
traffic
patterns
The
rise in
Social
Engineer
ing
attempts
to
collect
more
informati
on from
SIEM
platform
or
Intrusion
Detection
and
Prevention
System
(IDPS)
High user
reports
relating to
suspicious
activities
Ensuring SIEM
platform or
Intrusion
Detection and
Prevention
System is
updated
Introducing and
implementing
strict physical
access policies
and practices.
Ensuring
outsiders or
visitors are
allowed to enter
Identification
Milestone 2 3
personne
l
into personnel
premise.
The receptionist
has to make
sure that
visitors do not
sneak into the
“Employee
only” area.
Documentation
of all the
findings and
actions taken
by conducting a
thorough
analysis of the
security
incident.
3
Weaponizati
on
Downloading,
or installing
a tool which
unifies an
exploit with
malware and
gives rise to
the
deliverable
payload.
Choosing
correct
vulnerabilities
based on the
previous
Abnorma
l issues
and
performa
nce-
related
issues
Detectio
n of
suspiciou
s files
Logged
connecti
ons
SIEM logs
that have
identified
connections
with
suspicious
IP
addresses
Endpoint
antivirus
warnings
and alerts
Ensuring anti-
virus is updated
Regularly
assessing log
and file history
Documentation
of all the
findings and
actions taken
after conducting
a thorough
analysis of the
security incident.
Identification
Milestone 2 4
stage.
with
maliciou
s IP
addresse
s.
4
Exploitation
After the
payload is
established
and deployed
to the
targeted
system, the
built-in
exploit gets
activated to
compromise
the intended
target
The
anti-
virus
detection
of
suspiciou
s files,
especiall
y the
ones
that
have
been
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
Logs or
anti-virus
endpoints
detecting
suspicious
files
which are
located on
endpoint
devices. ac
SIEM logs
identifying
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to
peculiar or
strange IP
addresses
Employment of
a new and
updated anti-
virus or anti-
malware
platform which
will have the
potential to
capture as well
as quarantine
malicious or
suspicious code
executions.
Offer users and
employees with
proper security
awareness
training. They
need to be
updated about
the latest
security threats
that are
emerging in the
cyber world. ac
Introducing a
strict user
access policy so
Identification
Milestone 2 5
of
users.
Identific
ation of
maliciou
s or
suspiciou
s files
in
common
locations
.
Detectio
n of
abnormal
behavior
at
endpoint
s
that they can
carry out their
responsibilities
in an effective
manner.
Documenting
the findings and
actions taken
by conducting a
thorough
analysis of the
security incident.
5
Installation
Establishment
of a secure
control over
the target
system by
using specific
malware like
Remote
Access
Trojan.
Taking
advantage of
the position
Identific
ation of
maliciou
s or
suspiciou
s
processe
s that
are
running
on the
system.
Abnorma
SIEM logs
identifying
connections
with
malicious
IP
addresses
Windows
Event log
highlights
activities
and events
at hours
Designing a
deploying a
robust audit
process for
identifying
suspicious or
malicious
processes on
the system.
Making sure
that the
available
Intrusion
Containment
Milestone 2 6
to continue
havening
access into
the system.
l
behavior
identifie
d at
endpoint
s
Performa
nce
issues
when the
system
should
have been
idle.
Detection and
Prevention
System (IDPS)
updates are
installed on an
on-going basis
on the system.
Hardening the
organization’s
network by
closing all the
ports that are
not needed to
carry out the
legal activities
of the business.
Documenting
all the findings
and actions
relating to the
security incident.
6
Command
and Control
Building a
communicatio
n network
between the
target system
and the
attacker
system to
access the
functional
aspects of
Identific
ation of
abnormal
behavior
at the
endpoint
Performa
nce
issues
Running
SIEM logs
identifying
connections
with
suspicious
IP
addresses.
Windows
Event log
shows
Employment of
proxy servers
for varying
kinds of access.
Analysis of
logs Command
and Control to
tailor the
blocking
mechanism.
Containment
Milestone 2 7
the target
system.
The ports for
social media
and cloud
applications
work fine as
they have
high
bandwidth
which is
because they
are left open.
This makes
it difficult to
identify
suspicious
activities.
of
suspiciou
s
processe
s on
the
system.
Logs
revealing
a
connecti
on to
maliciou
s IP
addresse
s.
activities
at hours
when the
system
should
have been
idle.
Large data
transfers
revealed
by logs
Perimeter
firewall logs
show outbound
connections.
Documentation
of all the
findings and
actions taken
by conducting
thorough
analysis of the
security incident.
7
Achieving
the objective
Using proper
controls over
the target
system for
accomplishing
the chief
target
objective.
Creation
of
unauthor
ized
accounts
at the
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnorma
Abnormal
endpoint
behavior
Windows
Event log
reveals
activities
at hours
when it
should not
be used
SIEM logs
recognizing
malicious
IP
Tracing the
mobility of files
that were
copied, moved
or deleted.
Identification of
whether the
compromised
data contained
sensitive
information or
not.
Creating
effective
process relating
Eradication
Milestone 2 8
l file
activity
Corrupte
d or
destroye
d data
found
on the
system
Complet
e denial
of
access
to
system
resources
ac
addresses.
to incidence
response.
Documentation
of all the
findings and
actions taken
by conducting a
thorough
analysis of the
security incident.
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is extremely vital
to maintain the quality of the security infrastructure. After making sure that a proper
remedy is in place, it is necessary for the security professionals to make sure that a
proper documentation approach is followed which captures all the details relating to
the incident. In fact, it would assist to devise suitable policies and practices in the
organizational setting so that similar kinds of security incidents could be avoided in
the future. The existence of proper documentation of the entire event would also help
to critically evaluate the security incident and arrive at the findings which can help to
strengthen the overall effectiveness of the security framework of the business entity
that is highlighted in the Cybersecurity Incident Response Plan.
Milestone 2 9
The comprehensive assessment of the entire security incident can enable the
security professionals to get an in-depth insight into the vulnerabilities that were
exploited. They will be empowered to take robust decisions relating to incidence
response. The documentation of appropriate findings will act as the guideline which
will help the professionals to take suitable measures to prevent similar security breach
incidents.
Communications plan
The careful and accurate documentation of the actions and steps is necessary
as it can assist to devise proper strategies, policies, and protocols or the business
undertaking. In addition to this, it is necessary to effectively articulate and
communicate about the security incident to the key stakeholders. Their knowledge on
the sensitive subject matter is of paramount importance and this will be possible by
making sure a robust documentation process is in place. On the basis of the nature
and type of the cybersecurity incident that took place, the involved stakeholders must
be given necessary information that will be relevant for them.
For example, in case a security incident compromises private and sensitive
information, it is necessary to take into consideration legislation and regulations so
that it can identify who are the parties that must be notified about the security
incident. According to the Federal Trade Commission, good communication is
necessary so that the concern and frustration of the customers can be limited to a
certain degree (Data Breach Response: A Guide for Business, 2019). In the
organizational setting, it is necessary to intimate the suitable personnel about the
security breach incident. The information sharing would help to take necessary
measures so that the degree of vulnerability could be contained. As the information
relating to the security incident might have a different degree of relevance for the
Milestone 2 10
involved parties, a thorough documentation would enable the personnel to get a
comprehensive idea about the incident and associated implications.
References
Data Breach Response: A Guide for Business. (2019). Federal Trade Commission.
Retrieved 23 September 2019, from https://www.ftc.gov/tips-advice/business-
center/guidance/data-breach-response-guide-business