Explain how adversary could use the exploited intelligence

Assignment Help Computer Network Security
Reference no: EM131365758

Assignment

You are a cybersecurity analyst on a security team at Red Cell 637 Defense, a DoD contractor specializing in cyber operations and defensive strategies.

High-ranking federal government officials informed your team that recent intelligence shows an advanced persistent threat (APT) is looking at exploiting supply chain vulnerabilities against the computers that operate the Western Interconnection power grid. You are to assume that this APT originates from either a well-funded nation state or terrorist group. The APT has been able to probe and map the network over the course of several months. The officials have given your team access to classified intelligence indicating that the currently unidentified group may be planning to install malicious malware within the grid's computer network that will disrupt power to eleven states.

Your team has been asked to work closely with the DoD, Department of Homeland Security (DHS), and other federal stakeholders to strengthen the security and safety of the power grid and its related computer information systems.

The federal agencies responsible for critical infrastructure protection want to ensure that the Western Interconnection power grid computer network has the strongest possible defense while ensuring continued operation. They formally request that your team analyze common vulnerabilities in SCADA networks such as the western power connection grid, and then apply the Cyber Kill Chain to determine how this adversary could have exploited the vulnerabilities to attack the network. In addition, you will utilize the NSA's information assurance-based "Defense in Depth" strategy as it relates to the power grid's computer networks to make recommendations for implementing stronger information assurance measures and actions. You will compose a report with graphics, detailing your recommendations for securing the network against future cyberattacks.

Requirements:

Your submission must be your original work. No more than a combined total of 30% of the submission and no more than a 10% match to any one individual source can be directly quoted or closely paraphrased from sources, even if cited correctly. Use the Turnitin Originality Report available in Taskstream as a guide for this measure of originality.

You must use the rubric to direct the creation of your submission because it provides detailed criteria that will be used to evaluate your work. Each requirement below may be evaluated by more than one rubric aspect. The rubric aspect titles may contain hyperlinks to relevant portions of the course.

A. ICS Vulnerabilities and Cyber Kill Chain

1. Reconnaissance - Summarize plausible active gathering, passive gathering, and active reconnaissance techniques that the adversary could have executed to gain intelligence on the target in the scenario.

2. Weaponization and Delivery - Explain how the adversary could use the exploited intelligence to create a malicious payload, including plausible delivery methods of the payload to the target.

3. Exploitation and Installation - Describe the series of events that could occur during the exploitation and installation of a malicious payload, including where the payload could be delivered on the network to accomplish the adversary's goals as described in the scenario.

4. Command & Control - Create a visual representation of channels through which an adversary could use tools to exploit a compromised network and create an "at will" entry point for sending and receiving information. Be sure to clearly indicate each component represented in your visual.

5. Actions - Describe how the adversary is likely collecting and exfiltrating information from the Western Interconnection power grid, including how that information could be used to successfully execute an attack.

B. "Defense in Depth" Recommendations

1. People - Recommend information assurance policies or procedures specific to the facilities and personnel security that control and monitor access to facilities and critical infrastructures for the Western Interconnection power grid. Be sure to explain how each policy and procedure will raise information assurance levels.

2. Technology - Recommend technology acquisition policies or procedures that the Western Interconnection power grid should use to detect and protect against cyberattacks. Be sure to explain how these policies or procedures will raise information assurance levels.

3. Operations - Recommend policies or procedures to sustain security posture for the Western Interconnection power grid on a day-to-day basis. Be sure to explain how these policies or procedures will raise information assurance levels.

C. Acknowledge sources, using APA-formatted in-text citations and references, for content that is quoted, paraphrased, or summarized.

Reference no: EM131365758

Questions Cloud

Write an essay about deborahs life : Write a 600 word essay about Deborah's life, she was a Judge in the bible.- Somehow be related to something covered in the lectures or text, BUT not talked about specifically in our lectures.
Describ elements to include in psychiatric interviews : The psychiatric nurse stressed that a process recording, or written analysis of the interaction between the client and nurse, is essential for nurses to recognize the effects of their communication style in the assessment process. A review of the..
Write an essay about an event : Write an essay about an event. - Be before 922BC, when Solomon died, and where our semester ends which is Ecclesiastes
Describing the numerators and denominators : Summarize the prevalence & incidence rates by describing the numerators & denominators (how was the numerator defined? What was the denominator that was used or the population that you are referring to)
Explain how adversary could use the exploited intelligence : Explain how the adversary could use the exploited intelligence to create a malicious payload, including plausible delivery methods of the payload to the target.
How can the student nurses convey the essential elements : How can the student nurses convey the essential elements of a therapeutic relationship in talking to clients?How can the student nurses maintain a professional relationship and avoid a social one for clients in psychiatric settings?List the key ingre..
Discuss the role of multidisciplinary team in care of client : A multidisciplinary team meeting is in progress for Cindy, a 21-year-old college student who has recently been diagnosed with schizophrenia. Cindy had been an excellent student on the dean's list until 2 weeks ago, when she stopped attending clas..
What types of system requirements will you focus on : Use the Internet to find a site that contains current IT industry news, information, and links. Write a brief description of what you liked and didnt like.
How has my motivation changed or not changed : How has my motivation changed, or not changed, as I progressed in college? What persons external to the college environment have helped and supported me?

Reviews

Write a Review

Computer Network Security Questions & Answers

  Develop detailed plan to approach and secure incident scene

Discuss the initial steps you would take for the investigation, depending on whether or not the attack is still in progress. Include how your actions would differ based on the current status of the incident.

  Design a logical and topographical layout of planned network

Design a logical and physical topographical layout of the current and planned network through the use of graphical tools in Microsoft Word or Visio, or an open source alternative such as Dia.

  Describe the triple data encryption standards

Describe the Triple Data Encryption Standards

  What are ddos attacks

Focus on detection, prevention, and mitigation techniques for DoS or DDoS attacks?

  What is the plain text m

We assume that Oscar is able to observe all messages sent from Alice to Bob and vice versa. Oscar has no knowledge of any keys but the public one in case of DS - Will Bob detect this

  A friend is interested in installing a wireless lan in her

a friend is interested in installing a wireless lan in her small business. she has about a dozen employees. she is

  What is cryptanalysis

What is cryptanalysis. Give an example of a cryptanalytic problem. Describe the components of a digital stream cipher.

  Draw network diagram of this network including ip addresses

Draw a network diagram of this network including IP addresses - Describe how the attack may have occurred with sufficient information to explain how a hacker could carry out the attack. Ensure you include references.

  Write =on various type of utility and its use to secure data

Write a paper about various types of Utility and its use to secure the data. 8 pages start with executive summary, introduction, examples, its use in data security and conclusion.

  Examine the contents of the security and privacy tabs

Using a Microsoft Windows XP, Vista, or 7, open Internet Explorer. Click Internet Options on the Tools menu. Examine the contents of the Security and Privacy tabs. How can these tabs be configured to provide: (a) content filtering and (b) protecti..

  Incident and crime scene procedures

Determine the purpose of creating a digital hash. Explain in detail the need for this procedure and the potential damage if this critical step is not taken.

  Why people participate in bug bounties

What are the core components of a PKI - Explain the problems with key management.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd