Device Security Analysis
Software download server: a guessed upload account and a swapped installer
- Units 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the download server for Quillsoft, a small company that makes a free note-taking app (IP address 192.0.2.220), and were gathered during a security review. Users download the app's installers from this server. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | ALL | 192.0.2.220 | Inbound | 443 | HTTPS |
| 2 | Allow | ALL | 192.0.2.220 | Inbound | 80 | HTTP |
| 3 | Allow | ALL | 192.0.2.220 | Inbound | 21 | FTP |
| 4 | Allow | 192.0.2.0/24 | 192.0.2.220 | Inbound | 22 | SSH |
| 5 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Rule 3 lets developers upload new builds
Source 2: Authentication and upload log (sudo tail -n 14 /var/log/vsftpd.log)
| Line | Entry |
|---|---|
| 1 | Apr 01 16:20:41 downloads vsftpd[901]: Accepted login for user builder from 192.0.2.60 port 21 ftp |
| 2 | Apr 01 16:21:30 downloads vsftpd[901]: builder uploaded /srv/downloads/quillnote-setup-4.2.exe (8,654,112 bytes) |
| 3 | Apr 09 03:01:10 downloads vsftpd[1201]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 4 | Apr 09 03:01:13 downloads vsftpd[1203]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 5 | Apr 09 03:01:16 downloads vsftpd[1205]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 6 | Apr 09 03:01:19 downloads vsftpd[1207]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 7 | Apr 09 03:01:22 downloads vsftpd[1209]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 8 | Apr 09 03:01:25 downloads vsftpd[1211]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 9 | Apr 09 03:01:28 downloads vsftpd[1213]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 10 | Apr 09 03:01:31 downloads vsftpd[1215]: Failed login for user builder from 203.0.113.19 port 21 ftp |
| 11 | Apr 09 03:01:40 downloads vsftpd[1217]: Accepted login for user builder from 203.0.113.19 port 21 ftp |
| 12 | Apr 09 03:02:15 downloads vsftpd[1217]: builder uploaded /srv/downloads/quillnote-setup-4.2.exe (8,912,384 bytes; replaced existing file) |
| 13 | Apr 09 10:14:03 downloads kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.70 DST=192.0.2.220 PROTO=TCP DPT=22 |
| 14 | Apr 09 10:20:47 downloads kernel: [UFW BLOCK] IN=eth0 OUT= SRC=203.0.113.19 DST=192.0.2.220 PROTO=TCP DPT=3306 |
Source: Hypothetical device records written for this practice question. 198.51.100.70 is the home internet address of a Quillsoft developer
Source 3: Integrity check by the IT team (integrity-check /srv/downloads)
| Line | Entry |
|---|---|
| 1 | checksums.txt (published Apr 01): 135325d69bfbde972a1e9e3c395ce22a0019268b quillnote-setup-4.2.exe |
| 2 | checksums.txt (published Apr 01): a74dab8e4646aa5a5af88500bbeb298bc59efd6a quillnote-4.2.dmg |
| 3 | sha1sum on Apr 09 at 11:00: 72f06f3ef0c39b929df69e3cab94feceb358c4e6 quillnote-setup-4.2.exe |
| 4 | sha1sum on Apr 09 at 11:00: a74dab8e4646aa5a5af88500bbeb298bc59efd6a quillnote-4.2.dmg |
| 5 | anti-malware scan on Apr 09 at 11:02: quillnote-setup-4.2.exe matches signature Trojan.Downloader (file is still being served) |
| 6 | web server summary: quillnote-setup-4.2.exe downloaded 1,240 times between Apr 09 03:02 and 11:00 |
Source: Hypothetical device records written for this practice question
Source 4: File listing
$ ls -l /srv/downloads
-rw-rw-rw- 1 builder web 8912384 Apr 09 03:02 quillnote-setup-4.2.exe
-rw-rw-r-- 1 builder web 9441280 Apr 01 16:24 quillnote-4.2.dmg
-rw-rw-rw- 1 builder web 132 Apr 01 16:25 checksums.txt
-rw-r--r-- 1 builder builder 2459 Mar 30 09:00 release_signing.key
-rwxr-xr-x 1 builder web 820 Feb 11 14:10 mirror_sync.sh
Source: Hypothetical device records written for this practice question
Source 5: Quillsoft release policy
Required:
• Every release must be published with a SHA-1 checksum so users can check their download.
• Installers must be signed with the company's RSA signing key, which must be at least 2048 bits long.
Permitted:
• Developers may upload new builds to the download server.
Prohibited:
• The private signing key may not be stored on any server that can be reached from the internet.
• Developers may not share upload accounts.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the release policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the release policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/downloads (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, the sources show evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.