1 / 10100%
Milestone 2 1
ISE 620 : Final Project Milestone 2
Carlos Delapaz
SNHU
September 22,2019
Milestone 2 2
No. Attack
Phase
Attack Action Compro
mise
indicato
rs
Detection
point
Defensive
countermeasure
s
Defense
phase
1 Targeting Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web server
logs (public
systems)
Perimeter
firewall
logs
Keeping check of
malicious or
suspicious log
addresses
Applying
temporary block
on suspicious log
addresses
Documenting
findings and
action taken
Preparation
2 Exploration
or
Reconnaissa
nce
Collecting
maximum
information on
the possible
targets
Applying tools
like Nmap for
scanning target
systems to
identify open
ports or other
vulnerabilities.
Detectio
n of
external
scans in
traffic
patterns
The rise
in Social
Engineer
ing
attempts
to collect
more
informati
on from
personne
SIEM
platform or
Intrusion
Detection
and
Prevention
System
(IDPS)
High user
reports
relating to
suspicious
Students also viewed