1 / 10100%
Milestone 2 1
ISE 620 Final Project Milestone : 2
Milestone 2 2
No.
Attack
Phase
Attack
Action
Compro
mise
indicato
rs
Detection
point
Defensive
countermeasures
Defense
phase
1
Targeting
Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us
traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web
server
logs
(public
systems)
Perimeter
firewall
logs
Keeping check
of malicious or
suspicious log
addresses
Applying
temporary block
on suspicious
log addresses
Documenting
findings and
action taken
Preparation
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information
on the
possible
targets
Applying
tools like
Nmap for
scanning
target
systems to
identify open
ports or
other
vulnerabilities.
aa
Detectio
n of
external
scans
in
traffic
patterns
The
rise in
Students also viewed