Device Security Analysis
Warehouse handheld scanner: a guessed PIN and a flashlight app that phones home
- Units 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, a handheld barcode scanner, scanner-12, at the Summit Freight warehouse (IP address 192.0.2.150), and were gathered during a security review. The scanner is a small handheld computer that runs Linux. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | 192.0.2.5 | 192.0.2.150 | Inbound | 22 | SSH |
| 2 | Deny | ALL | ALL | Inbound | ALL | ALL |
| 3 | Allow | 192.0.2.150 | 192.0.2.10 | Outbound | 443 | HTTPS |
| 4 | Allow | 192.0.2.150 | ALL | Outbound | 8080 | HTTP-alt |
| 5 | Deny | ALL | ALL | Outbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Rule 4 was left over from the vendor's testing. On July 14 at 13:00 the warehouse moved its inventory system from 192.0.2.10 to 192.0.2.11
Source 2: Scanner system log (sudo tail -n 17 /var/log/syslog)
| Line | Entry |
|---|---|
| 1 | Jul 14 06:01:12 scanner-12 lockscreen: user worker7 unlocked the screen (PIN ok) |
| 2 | Jul 14 12:31:05 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 1) |
| 3 | Jul 14 12:31:09 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 2) |
| 4 | Jul 14 12:31:13 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 3) |
| 5 | Jul 14 12:31:17 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 4) |
| 6 | Jul 14 12:31:21 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 5) |
| 7 | Jul 14 12:31:25 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 6) |
| 8 | Jul 14 12:31:31 scanner-12 lockscreen: user supervisor unlocked the screen (PIN ok) |
| 9 | Jul 14 12:32:10 scanner-12 pkg: supervisor installed flashlight-plus 1.0 from /media/usb0/flashlight-plus.pkg (unsigned; not on the approved app list) |
| 10 | Jul 14 12:32:40 scanner-12 flashlight-plus: requested access to camera, location and contacts; access granted |
| 11 | Jul 14 12:33:00 scanner-12 audit: process flplus-agent opened /var/lib/scanner/location.db |
| 12 | Jul 14 12:40:00 scanner-12 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.150 DST=203.0.113.150 PROTO=TCP DPT=443 |
| 13 | Jul 14 12:40:02 scanner-12 conntrack: NEW tcp src=192.0.2.150 dst=203.0.113.150 dport=8080 (2.1 MB sent) |
| 14 | Jul 14 12:50:02 scanner-12 conntrack: NEW tcp src=192.0.2.150 dst=203.0.113.150 dport=8080 (2.1 MB sent) |
| 15 | Jul 14 13:00:02 scanner-12 conntrack: NEW tcp src=192.0.2.150 dst=203.0.113.150 dport=8080 (2.2 MB sent) |
| 16 | Jul 14 13:05:40 scanner-12 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.150 DST=192.0.2.11 PROTO=TCP DPT=443 |
| 17 | Jul 14 13:05:41 scanner-12 inventory-app: cannot reach inventory server 192.0.2.11 |
Source: Hypothetical device records written for this practice question. Scanners use a 4-digit PIN. Workers start their shifts at 6:00 a.m.
Source 3: File listing
$ ls -l /var/lib/scanner
-rw-rw-rw- 1 scanner scanner 1048576 Jul 14 13:00 location.db
-rw-rw-r-- 1 scanner warehouse 524288 Jul 14 12:58 inventory_cache.db
-rw-r--r-- 1 scanner scanner 214 Jun 02 08:00 wifi.conf
-rwxrwxrwx 1 scanner scanner 940 Jun 02 08:05 sync.sh
-rw-rw-r-- 1 scanner warehouse 380 Jun 30 15:20 approved_apps.list
Source: Hypothetical device records written for this practice question
Source 4: Summit Freight handheld device policy
Required:
• Scanners must lock after 2 minutes without use and unlock with a 4-digit PIN.
• Only apps on the company's approved app list may be installed.
Permitted:
• Workers may use the scanner's camera to photograph damaged pallets.
Prohibited:
• Scanners may not leave the warehouse.
• Workers may not plug USB drives or personal devices into scanners.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the handheld device policy in Source 4 protects the device from a specific threat. (ii) Explain how one rule that is already in the handheld device policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence that someone guessed their way into the scanner. (i) Describe the evidence in the log. Cite specific line numbers and entries. (ii) Identify one login setting that would have stopped or slowed this attack, and explain how.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /var/lib/scanner (Source 3). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 3 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt in Source 2 was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) The warehouse has moved its inventory system to 192.0.2.11. Other than allowing all traffic, describe a change to one existing rule in Source 1 that would let the connection on line 16 through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, Source 2 shows evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.