1 / 10100%
Milestone 2 1
ISE 620 : Final Project Milestone 2
Milestone 2 2
No.
Attack
Phase
Attack Action
Compro
mise
indicato
rs
Detection
point
Defensive
countermeasures
Defense
phase
1
Targeting
Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us
traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web server
logs
(public
systems)
Perimeter
firewall
logs
Keeping check
of malicious or
suspicious log
addresses
Applying
temporary block
on suspicious log
addresses
Documenting
findings and
action taken
Preparation
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information
on the
possible
targets
Applying
tools like
Nmap for
scanning
target systems
to identify
open ports or
other
vulnerabilities.
Detectio
n of
external
scans in
traffic
patterns
The rise
in
Social
Engineer
ing
attempts
to
collect
more
informati
on from
SIEM
platform or
Intrusion
Detection
and
Prevention
System
(IDPS)
High user
reports
relating to
suspicious
activities
Ensuring SIEM
platform or
Intrusion
Detection and
Prevention
System is
updated
Introducing and
implementing
strict physical
access policies
and practices.
Ensuring
outsiders or
visitors are
allowed to enter
Identification
Milestone 2 3
personne
l
into personnel
premise.
The receptionist
has to make sure
that visitors do
not sneak into
the “Employee
only” area.
Documentation
of all the
findings and
actions taken by
conducting a
thorough
analysis of the
security incident.
3
Weaponizati
on
Downloading,
or installing a
tool which
unifies an
exploit with
malware and
gives rise to
the deliverable
payload.
Choosing
correct
vulnerabilities
based on the
previous
stage.
Abnorma
l issues
and
performa
nce-
related
issues
Detectio
n of
suspiciou
s files
Logged
connecti
ons with
maliciou
s IP
SIEM logs
that have
identified
connections
with
suspicious
IP
addresses
Endpoint
antivirus
warnings
and alerts
Ensuring anti-
virus is updated
Regularly
assessing log and
file history
Documentation
of all the
findings and
actions taken
after conducting
a thorough
analysis of the
security incident.
Identification
Milestone 2 4
addresse
s.
4
Exploitation
After the
payload is
established
and deployed
to the targeted
system, the
built-in
exploit gets
activated to
compromise
the intended
target
The anti-
virus
detection
of
suspiciou
s files,
especiall
y the
ones
that
have
been
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
of users.
Identific
ation of
maliciou
Logs or
anti-virus
endpoints
detecting
suspicious
files which
are located
on
endpoint
devices. g
SIEM logs
identifying
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to peculiar
or strange
IP
addresses
Employment of a
new and updated
anti-virus or anti-
malware
platform which
will have the
potential to
capture as well
as quarantine
malicious or
suspicious code
executions.
Offer users and
employees with
proper security
awareness
training. They
need to be
updated about
the latest
security threats
that are
emerging in the
cyber world. g
Introducing a
strict user access
policy so that
they can carry
out their
responsibilities
in an effective
Identification
Milestone 2 5
s or
suspiciou
s files in
common
locations
.
Detectio
n of
abnormal
behavior
at
endpoint
s
manner.
Documenting the
findings and
actions taken by
conducting a
thorough
analysis of the
security incident.
5
Installation
Establishment
of a secure
control over
the target
system by
using specific
malware like
Remote
Access
Trojan.
Taking
advantage of
the position to
continue
havening
access into the
system.
Identific
ation of
maliciou
s or
suspiciou
s
processe
s that
are
running
on the
system.
Abnorma
l
behavior
identifie
d at
endpoint
s
SIEM logs
identifying
connections
with
malicious
IP
addresses
Windows
Event log
highlights
activities
and events
at hours
when the
system
should
have been
idle.
Designing a
deploying a
robust audit
process for
identifying
suspicious or
malicious
processes on the
system.
Making sure that
the available
Intrusion
Detection and
Prevention
System (IDPS)
updates are
installed on an
on-going basis
on the system.
Containment
Milestone 2 6
Performa
nce
issues
Hardening the
organization’s
network by
closing all the
ports that are not
needed to carry
out the legal
activities of the
business.
Documenting all
the findings and
actions relating
to the security
incident.
6
Command
and Control
Building a
communicatio
n network
between the
target system
and the
attacker
system to
access the
functional
aspects of the
target system.
The ports for
social media
and cloud
applications
work fine as
they have
Identific
ation of
abnormal
behavior
at the
endpoint
Performa
nce
issues
Running
of
suspiciou
s
processe
s on the
system.
Logs
SIEM logs
identifying
connections
with
suspicious
IP
addresses.
Windows
Event log
shows
activities at
hours when
the system
should
have been
idle.
Large data
Employment of
proxy servers for
varying kinds of
access.
Analysis of logs
Command and
Control to tailor
the blocking
mechanism.
Perimeter
firewall logs
show outbound
connections.
Documentation
of all the
findings and
actions taken by
Containment
Milestone 2 7
high
bandwidth
which is
because they
are left open.
This makes it
difficult to
identify
suspicious
activities.
revealing
a
connecti
on to
maliciou
s IP
addresse
s.
transfers
revealed by
logs
conducting
thorough
analysis of the
security incident.
7
Achieving
the objective
Using proper
controls over
the target
system for
accomplishing
the chief
target
objective.
Creation
of
unauthor
ized
accounts
at the
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnorma
l file
activity
Corrupte
d or
destroye
d data
found
on the
Abnormal
endpoint
behavior
Windows
Event log
reveals
activities at
hours when
it should
not be used
SIEM logs
recognizing
malicious
IP
addresses.
Tracing the
mobility of files
that were copied,
moved or
deleted.
Identification of
whether the
compromised
data contained
sensitive
information or
not.
Creating
effective process
relating to
incidence
response.
Documentation
of all the
findings and
actions taken by
conducting a
thorough
Eradication
Milestone 2 8
system
Complet
e denial
of
access
to
system
resources
g
analysis of the
security incident.
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is extremely vital to
maintain the quality of the security infrastructure. After making sure that a proper remedy
is in place, it is necessary for the security professionals to make sure that a proper
documentation approach is followed which captures all the details relating to the incident.
In fact, it would assist to devise suitable policies and practices in the organizational setting
so that similar kinds of security incidents could be avoided in the future. The existence of
proper documentation of the entire event would also help to critically evaluate the security
incident and arrive at the findings which can help to strengthen the overall effectiveness of
the security framework of the business entity that is highlighted in the Cybersecurity
Incident Response Plan.
The comprehensive assessment of the entire security incident can enable the
security professionals to get an in-depth insight into the vulnerabilities that were exploited.
They will be empowered to take robust decisions relating to incidence response. The
documentation of appropriate findings will act as the guideline which will help the
professionals to take suitable measures to prevent similar security breach incidents.
Communications plan
Milestone 2 9
The careful and accurate documentation of the actions and steps is necessary as it
can assist to devise proper strategies, policies, and protocols or the business undertaking.
In addition to this, it is necessary to effectively articulate and communicate about the
security incident to the key stakeholders. Their knowledge on the sensitive subject matter
is of paramount importance and this will be possible by making sure a robust
documentation process is in place. g On the basis of the nature and type of the cybersecurity
incident that took place, the involved stakeholders must be given necessary information
that will be relevant for them.
For example, in case a security incident compromises private and sensitive
information, it is necessary to take into consideration legislation and regulations so that it
can identify who are the parties that must be notified about the security incident.
According to the Federal Trade Commission, good communication is necessary so that the
concern and frustration of the customers can be limited to a certain degree (Data Breach
Response: A Guide for Business, 2019). In the organizational setting, it is necessary to
intimate the suitable personnel about the security breach incident. The information sharing
would help to take necessary measures so that the degree of vulnerability could be
contained. As the information relating to the security incident might have a different
degree of relevance for the involved parties, a thorough documentation would enable the
personnel to get a comprehensive idea about the incident and associated implications.
Milestone 2 10
References
Data Breach Response: A Guide for Business. (2019). Federal Trade Commission.
Retrieved 23 September 2019, from https://www.ftc.gov/tips-advice/business-
center/guidance/data-breach-response-guide-business
Students also viewed