Milestone 2 1
ISE 620 : Final Project Milestone 2
SNHU
Milestone 2 2
No.
Attack
Phase
Attack Action
Compro
mise
indicato
rs
Detection
point
Defensive
countermeasures
Defense
phase
1
Targeting
Identifying a
vulnerable
device or
system
High
network
traffic
Continuo
us traffic
events
involvin
g less
low
transferr
ed data.
SIEM
platform
reports
Web server
logs (public
systems)
Perimeter
firewall
logs
Keeping check of
malicious or
suspicious log
addresses
Applying
temporary block
on suspicious log
addresses
Documenting
findings and
action taken
Preparation
2
Exploration
or
Reconnaissa
nce
Collecting
maximum
information on
the possible
targets
Applying tools
like Nmap for
scanning
target systems
to identify
open ports or
other
vulnerabilities.
Detectio
n of
external
scans in
traffic
patterns
The rise
in
Social
Engineer
ing
attempts
to collect
more
informati
on from
personne
SIEM
platform or
Intrusion
Detection
and
Prevention
System
(IDPS)
High user
reports
relating to
suspicious
activities
Ensuring SIEM
platform or
Intrusion
Detection and
Prevention
System is updated
Introducing and
implementing
strict physical
access policies
and practices.
Ensuring
outsiders or
visitors are
allowed to enter
into personnel
premise.
Identification
Milestone 2 3
l
The receptionist
has to make sure
that visitors do
not sneak into the
“Employee only”
area.
Documentation
of all the findings
and actions taken
by conducting a
thorough analysis
of the security
incident.
3
Weaponizati
on
Downloading,
or installing a
tool which
unifies an
exploit with
malware and
gives rise to
the deliverable
payload.
Choosing
correct
vulnerabilities
based on the
previous stage.
Abnorma
l issues
and
performa
nce-
related
issues
Detectio
n of
suspiciou
s files
Logged
connecti
ons with
maliciou
s IP
addresse
s.
SIEM logs
that have
identified
connections
with
suspicious
IP
addresses
Endpoint
antivirus
warnings
and alerts
Ensuring anti-
virus is updated
Regularly
assessing log and
file history
Documentation
of all the findings
and actions taken
after conducting
a thorough
analysis of the
security incident.
Identification
4
Exploitation
After the
The anti-
Logs or
Employment of a
Identification
Milestone 2 4
payload is
established
and deployed
to the targeted
system, the
built-in exploit
gets activated
to compromise
the intended
target
virus
detection
of
suspiciou
s files,
especiall
y the
ones that
have
been
blacklist
ed or
reported
by
trustwort
hy
repositor
ies
Observat
ion of
suspiciou
s
activities
in
accounts
of users.
Identific
ation of
maliciou
s or
suspiciou
s files in
common
anti-virus
endpoints
detecting
suspicious
files which
are located
on endpoint
devices. f
SIEM logs
identifying
connections
with
malicious
IP
addresses
Perimeter
firewall
recognizes
outbound
connections
to peculiar
or strange
IP
addresses
new and updated
anti-virus or anti-
malware platform
which will have
the potential to
capture as well as
quarantine
malicious or
suspicious code
executions.
Offer users and
employees with
proper security
awareness
training. They
need to be
updated about the
latest security
threats that are
emerging in the
cyber world. f
Introducing a
strict user access
policy so that
they can carry
out their
responsibilities in
an effective
manner.
Documenting the
findings and
actions taken by
conducting a
Milestone 2 5
locations
.
Detectio
n of
abnormal
behavior
at
endpoint
s
thorough analysis
of the security
incident.
5
Installation
Establishment
of a secure
control over
the target
system by
using specific
malware like
Remote
Access Trojan.
Taking
advantage of
the position to
continue
havening
access into the
system.
Identific
ation of
maliciou
s or
suspiciou
s
processe
s that are
running
on the
system.
Abnorma
l
behavior
identifie
d at
endpoint
s
Performa
nce
issues
SIEM logs
identifying
connections
with
malicious
IP
addresses
Windows
Event log
highlights
activities
and events
at hours
when the
system
should
have been
idle.
Designing a
deploying a
robust audit
process for
identifying
suspicious or
malicious
processes on the
system.
Making sure that
the available
Intrusion
Detection and
Prevention
System (IDPS)
updates are
installed on an
on-going basis on
the system.
Hardening the
organization’s
network by
closing all the
Containment
Milestone 2 6
ports that are not
needed to carry
out the legal
activities of the
business.
Documenting all
the findings and
actions relating
to the security
incident.
6
Command
and Control
Building a
communicatio
n network
between the
target system
and the
attacker
system to
access the
functional
aspects of the
target system.
The ports for
social media
and cloud
applications
work fine as
they have high
bandwidth
which is
because they
are left open.
Identific
ation of
abnormal
behavior
at the
endpoint
Performa
nce
issues
Running
of
suspiciou
s
processe
s on the
system.
Logs
revealing
a
connecti
on to
SIEM logs
identifying
connections
with
suspicious
IP
addresses.
Windows
Event log
shows
activities at
hours when
the system
should
have been
idle.
Large data
transfers
revealed by
logs
Employment of
proxy servers for
varying kinds of
access.
Analysis of logs
Command and
Control to tailor
the blocking
mechanism.
Perimeter
firewall logs
show outbound
connections.
Documentation
of all the findings
and actions taken
by conducting
thorough analysis
of the security
incident.
Containment
Milestone 2 7
This makes it
difficult to
identify
suspicious
activities.
maliciou
s IP
addresse
s.
7
Achieving
the objective
Using proper
controls over
the target
system for
accomplishing
the chief target
objective.
Creation
of
unauthor
ized
accounts
at the
endpoint
s with
administr
ator
rights
and
privilege
s.
Abnorma
l file
activity
Corrupte
d or
destroye
d data
found on
the
system
Complet
e denial
of access
to
Abnormal
endpoint
behavior
Windows
Event log
reveals
activities at
hours when
it should
not be used
SIEM logs
recognizing
malicious
IP
addresses.
Tracing the
mobility of files
that were copied,
moved or deleted.
Identification of
whether the
compromised
data contained
sensitive
information or
not.
Creating
effective process
relating to
incidence
response.
Documentation
of all the findings
and actions taken
by conducting a
thorough analysis
of the security
incident.
Eradication
Milestone 2 8
system
resources
f
After actions or lessons learned
Finding an appropriate remedy for the cybersecurity incident is extremely vital to
maintain the quality of the security infrastructure. After making sure that a proper remedy is
in place, it is necessary for the security professionals to make sure that a proper
documentation approach is followed which captures all the details relating to the incident. In
fact, it would assist to devise suitable policies and practices in the organizational setting so
that similar kinds of security incidents could be avoided in the future. The existence of proper
documentation of the entire event would also help to critically evaluate the security incident
and arrive at the findings which can help to strengthen the overall effectiveness of the
security framework of the business entity that is highlighted in the Cybersecurity Incident
Response Plan.
The comprehensive assessment of the entire security incident can enable the security
professionals to get an in-depth insight into the vulnerabilities that were exploited. They will
be empowered to take robust decisions relating to incidence response. The documentation of
appropriate findings will act as the guideline which will help the professionals to take
suitable measures to prevent similar security breach incidents.
Communications plan
The careful and accurate documentation of the actions and steps is necessary as it can
assist to devise proper strategies, policies, and protocols or the business undertaking. In
addition to this, it is necessary to effectively articulate and communicate about the security
incident to the key stakeholders. Their knowledge on the sensitive subject matter is of
paramount importance and this will be possible by making sure a robust documentation
Milestone 2 9
process is in place. f On the basis of the nature and type of the cybersecurity incident that took
place, the involved stakeholders must be given necessary information that will be relevant for
them.
For example, in case a security incident compromises private and sensitive
information, it is necessary to take into consideration legislation and regulations so that it can
identify who are the parties that must be notified about the security incident. According to the
Federal Trade Commission, good communication is necessary so that the concern and
frustration of the customers can be limited to a certain degree (Data Breach Response: A
Guide for Business, 2019). In the organizational setting, it is necessary to intimate the
suitable personnel about the security breach incident. The information sharing would help to
take necessary measures so that the degree of vulnerability could be contained. As the
information relating to the security incident might have a different degree of relevance for the
involved parties, a thorough documentation would enable the personnel to get a
comprehensive idea about the incident and associated implications.
Milestone 2 10
References
Data Breach Response: A Guide for Business. (2019). Federal Trade Commission. Retrieved
23 September 2019, from https://www.ftc.gov/tips-advice/business-
center/guidance/data-breach-response-guide-business