1 / 10100%
Milestone 2 1
ISE 620 : Final Project Milestone 2
SNHU
Milestone 2 2
No.
Attack
Phase
Attack Action
Compro
mise
indicato
rs
Detection
point
Defensive
countermeasures
Defense
phase
1
Targeting
Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us
traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web server
logs
(public
systems)
Perimeter
firewall
logs
Keeping check
of malicious or
suspicious log
addresses
Applying
temporary block
on suspicious
log addresses
Documenting
findings and
action taken
Preparation
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information
on the
possible
targets
Applying
tools like
Nmap for
scanning
target systems
to identify
open ports or
other
vulnerabilities.
Detectio
n of
external
scans in
traffic
patterns
The rise
in
Social
Engineer
ing
attempts
to
collect
more
informati
on from
SIEM
platform or
Intrusion
Detection
and
Prevention
System
(IDPS)
High user
reports
relating to
suspicious
activities
Ensuring SIEM
platform or
Intrusion
Detection and
Prevention
System is
updated
Introducing and
implementing
strict physical
access policies
and practices.
Ensuring
outsiders or
visitors are
allowed to enter
Identification
Milestone 2 3
personne
l
into personnel
premise.
The receptionist
has to make
sure that visitors
do not sneak
into the
“Employee
only” area.
Documentation
of all the
findings and
actions taken by
conducting a
thorough
analysis of the
security incident.
3
Weaponizati
on
Downloading,
or installing a
tool which
unifies an
exploit with
malware and
gives rise to
the
deliverable
payload.
Choosing
correct
vulnerabilities
based on the
previous
Abnorma
l issues
and
performa
nce-
related
issues
Detectio
n of
suspiciou
s files
Logged
connecti
ons with
maliciou
SIEM logs
that have
identified
connections
with
suspicious
IP
addresses
Endpoint
antivirus
warnings
and alerts
Ensuring anti-
virus is updated
Regularly
assessing log
and file history
Documentation
of all the
findings and
actions taken
after conducting
a thorough
analysis of the
security incident.
Identification
Milestone 2 4
stage.
s IP
addresse
s.
4
Exploitation
After the
payload is
established
and deployed
to the
targeted
system, the
built-in
exploit gets
activated to
compromise
the intended
target
The anti-
virus
detection
of
suspiciou
s files,
especiall
y the
ones
that
have
been
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
of users.
Identific
ation of
Logs or
anti-virus
endpoints
detecting
suspicious
files which
are located
on
endpoint
devices. c
SIEM logs
identifying
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to
peculiar or
strange IP
addresses
Employment of
a new and
updated anti-
virus or anti-
malware
platform which
will have the
potential to
capture as well
as quarantine
malicious or
suspicious code
executions.
Offer users and
employees with
proper security
awareness
training. They
need to be
updated about
the latest
security threats
that are
emerging in the
cyber world. c
Introducing a
strict user access
policy so that
they can carry
out their
Identification
Milestone 2 5
maliciou
s or
suspiciou
s files
in
common
locations
.
Detectio
n of
abnormal
behavior
at
endpoint
s
responsibilities
in an effective
manner.
Documenting the
findings and
actions taken by
conducting a
thorough
analysis of the
security incident.
5
Installation
Establishment
of a secure
control over
the target
system by
using specific
malware like
Remote
Access
Trojan.
Taking
advantage of
the position
to continue
havening
access into
the system.
Identific
ation of
maliciou
s or
suspiciou
s
processe
s that
are
running
on the
system.
Abnorma
l
behavior
identifie
d at
SIEM logs
identifying
connections
with
malicious
IP
addresses
Windows
Event log
highlights
activities
and events
at hours
when the
system
should
have been
Designing a
deploying a
robust audit
process for
identifying
suspicious or
malicious
processes on the
system.
Making sure that
the available
Intrusion
Detection and
Prevention
System (IDPS)
updates are
installed on an
Containment
Milestone 2 6
endpoint
s
Performa
nce
issues
idle.
on-going basis
on the system.
Hardening the
organization’s
network by
closing all the
ports that are
not needed to
carry out the
legal activities
of the business.
Documenting all
the findings and
actions relating
to the security
incident.
6
Command
and Control
Building a
communicatio
n network
between the
target system
and the
attacker
system to
access the
functional
aspects of the
target system.
The ports for
social media
and cloud
Identific
ation of
abnormal
behavior
at the
endpoint
Performa
nce
issues
Running
of
suspiciou
s
processe
s on the
SIEM logs
identifying
connections
with
suspicious
IP
addresses.
Windows
Event log
shows
activities at
hours
when the
system
should
Employment of
proxy servers
for varying
kinds of access.
Analysis of logs
Command and
Control to tailor
the blocking
mechanism.
Perimeter
firewall logs
show outbound
connections.
Documentation
of all the
Containment
Milestone 2 7
applications
work fine as
they have
high
bandwidth
which is
because they
are left open.
This makes it
difficult to
identify
suspicious
activities.
system.
Logs
revealing
a
connecti
on to
maliciou
s IP
addresse
s.
have been
idle.
Large data
transfers
revealed
by logs
findings and
actions taken by
conducting
thorough
analysis of the
security incident.
7
Achieving
the objective
Using proper
controls over
the target
system for
accomplishing
the chief
target
objective.
Creation
of
unauthor
ized
accounts
at the
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnorma
l file
activity
Corrupte
d or
destroye
Abnormal
endpoint
behavior
Windows
Event log
reveals
activities at
hours
when it
should not
be used
SIEM logs
recognizing
malicious
IP
addresses.
Tracing the
mobility of files
that were
copied, moved
or deleted.
Identification of
whether the
compromised
data contained
sensitive
information or
not.
Creating
effective process
relating to
incidence
response.
Documentation
of all the
findings and
Eradication
Milestone 2 8
d data
found
on the
system
Complet
e denial
of
access
to
system
resources
c
actions taken by
conducting a
thorough
analysis of the
security incident.
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is extremely vital to
maintain the quality of the security infrastructure. After making sure that a proper
remedy is in place, it is necessary for the security professionals to make sure that a
proper documentation approach is followed which captures all the details relating to the
incident. In fact, it would assist to devise suitable policies and practices in the
organizational setting so that similar kinds of security incidents could be avoided in the
future. The existence of proper documentation of the entire event would also help to
critically evaluate the security incident and arrive at the findings which can help to
strengthen the overall effectiveness of the security framework of the business entity that
is highlighted in the Cybersecurity Incident Response Plan.
The comprehensive assessment of the entire security incident can enable the
security professionals to get an in-depth insight into the vulnerabilities that were
exploited. They will be empowered to take robust decisions relating to incidence
response. The documentation of appropriate findings will act as the guideline which will
Milestone 2 9
help the professionals to take suitable measures to prevent similar security breach
incidents.
Communications plan
The careful and accurate documentation of the actions and steps is necessary as
it can assist to devise proper strategies, policies, and protocols or the business
undertaking. In addition to this, it is necessary to effectively articulate and communicate
about the security incident to the key stakeholders. Their knowledge on the sensitive
subject matter is of paramount importance and this will be possible by making sure a
robust documentation process is in place. On the basis of the nature and type of the
cybersecurity incident that took place, the involved stakeholders must be given necessary
information that will be relevant for them.
For example, in case a security incident compromises private and sensitive
information, it is necessary to take into consideration legislation and regulations so that
it can identify who are the parties that must be notified about the security incident.
According to the Federal Trade Commission, good communication is necessary so that
the concern and frustration of the customers can be limited to a certain degree (Data
Breach Response: A Guide for Business, 2019). In the organizational setting, it is
necessary to intimate the suitable personnel about the security breach incident. The
information sharing would help to take necessary measures so that the degree of
vulnerability could be contained. As the information relating to the security incident
might have a different degree of relevance for the involved parties, a thorough
documentation would enable the personnel to get a comprehensive idea about the
incident and associated implications.
Milestone 2 10
References
Data Breach Response: A Guide for Business. (2019). Federal Trade Commission.
Retrieved 23 September 2019, from https://www.ftc.gov/tips-advice/business-
center/guidance/data-breach-response-guide-business
Students also viewed