Device Security Analysis
Esports club game server: an officer password and a flood of replies
- Units 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the game server run by the Lakeside High School esports club (IP address 192.0.2.200), and were gathered during a security review. The school network is 192.0.2.0/24. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | ALL | 192.0.2.200 | Inbound | 25565 | Game server |
| 2 | Allow | 192.0.2.0/24 | 192.0.2.200 | Inbound | 22 | SSH |
| 3 | Allow | 192.0.2.0/24 | 192.0.2.200 | Inbound | 8080 | HTTP-alt |
| 4 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Port 8080 is the club's web dashboard
Source 2: Authentication log (sudo tail -n 12 /var/log/auth.log)
| Line | Entry |
|---|---|
| 1 | Mar 21 15:05:44 esports-srv sshd[4410]: Accepted password for captain from 192.0.2.30 port 51022 ssh2 |
| 2 | Mar 21 15:42:06 esports-srv sshd[4520]: Failed password for captain from 192.0.2.150 port 53100 ssh2 |
| 3 | Mar 21 15:42:09 esports-srv sshd[4521]: Failed password for captain from 192.0.2.150 port 53102 ssh2 |
| 4 | Mar 21 15:42:12 esports-srv sshd[4522]: Failed password for captain from 192.0.2.150 port 53104 ssh2 |
| 5 | Mar 21 15:42:15 esports-srv sshd[4523]: Failed password for captain from 192.0.2.150 port 53106 ssh2 |
| 6 | Mar 21 15:42:18 esports-srv sshd[4524]: Failed password for captain from 192.0.2.150 port 53108 ssh2 |
| 7 | Mar 21 15:42:21 esports-srv sshd[4525]: Failed password for captain from 192.0.2.150 port 53110 ssh2 |
| 8 | Mar 21 15:42:24 esports-srv sshd[4526]: Failed password for captain from 192.0.2.150 port 53112 ssh2 |
| 9 | Mar 21 15:42:27 esports-srv sshd[4527]: Failed password for captain from 192.0.2.150 port 53114 ssh2 |
| 10 | Mar 21 15:42:30 esports-srv sshd[4528]: Failed password for captain from 192.0.2.150 port 53116 ssh2 |
| 11 | Mar 21 18:12:09 esports-srv kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.33 DST=192.0.2.200 PROTO=TCP DPT=8080 |
| 12 | Mar 21 18:30:51 esports-srv kernel: [UFW BLOCK] IN=eth0 OUT= SRC=203.0.113.7 DST=192.0.2.200 PROTO=TCP DPT=23 |
Source: Hypothetical device records written for this practice question. 198.51.100.33 is the club coach's home internet address
Source 3: Network monitor and game server log (sudo tail -n 7 /var/log/netmon.log)
| Line | Entry |
|---|---|
| 1 | Mar 21 19:00:00 esports-srv netmon: ICMP echo replies in: 3 per second; players online: 41 |
| 2 | Mar 21 19:30:00 esports-srv netmon: ICMP echo replies in: 2 per second; players online: 44 |
| 3 | Mar 21 20:14:00 esports-srv netmon: ICMP echo replies in: 52,400 per second from 186 different addresses in 203.0.113.0/24; echo requests sent by this server: 0 |
| 4 | Mar 21 20:14:05 esports-srv game-srv: server tick took 4,850 ms (normal is 50 ms) |
| 5 | Mar 21 20:14:30 esports-srv game-srv: 37 players timed out |
| 6 | Mar 21 20:15:00 esports-srv netmon: ICMP echo replies in: 55,100 per second from 191 different addresses in 203.0.113.0/24; inbound link 98% full |
| 7 | Mar 21 20:31:00 esports-srv netmon: ICMP echo replies in: 4 per second; players online: 3 |
Source: Hypothetical device records written for this practice question
Source 4: File listing
$ ls -l /srv/game
-rw-rw-rw- 1 gamesrv officers 412 Mar 20 17:02 ops.json
-rw-rw-r-- 1 gamesrv officers 2208 Mar 18 16:45 whitelist.json
-rw-r--r-- 1 gamesrv gamesrv 1630 Feb 27 15:10 server.properties
-rwxrwxrwx 1 gamesrv gamesrv 388 Feb 27 15:12 start.sh
-rw-r--r-- 1 gamesrv gamesrv 33 Feb 27 15:15 rcon.secret
Source: Hypothetical device records written for this practice question
Source 5: Lakeside esports club server rules
Required:
• Club officers' server passwords must be at least 12 characters long.
• The game server software must be updated every Sunday.
Permitted:
• Members may join the game server from home.
• The coach may manage the club dashboard from the school network.
Prohibited:
• Members may not run bots, scripts or traffic generators against the server.
• Officers may not share admin passwords with other members.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the club server rules in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the club server rules could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/game (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, Source 3 shows evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.