Device Security Analysis
Dorm heating controller: factory accounts and a scan of every port
- Units 2, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the heating and cooling controller for Cedar Hall, a dormitory at Ridgeview College (IP address 192.0.2.70), and were gathered during a security review. The controller is an embedded computer with a small web page for managing it. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | 192.0.2.0/24 | 192.0.2.70 | Inbound | 443 | HTTPS |
| 2 | Allow | ALL | 192.0.2.70 | Inbound | 80 | HTTP |
| 3 | Allow | 192.0.2.0/24 | 192.0.2.70 | Inbound | 1883 | MQTT |
| 4 | Allow | 192.0.2.5 | 192.0.2.70 | Inbound | 22 | SSH |
| 5 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question
Source 2: Controller web admin log (sudo tail -n 10 /var/log/hvac/webadmin.log)
| Line | Entry |
|---|---|
| 1 | Jan 21 16:40:11 hvac-ctl webadmin[402]: login ok user=facilities1 ip=192.0.2.44 port=443 |
| 2 | Jan 22 03:07:20 hvac-ctl webadmin[402]: login failed user=admin ip=203.0.113.61 port=80 |
| 3 | Jan 22 03:07:22 hvac-ctl webadmin[402]: login failed user=root ip=203.0.113.61 port=80 |
| 4 | Jan 22 03:07:24 hvac-ctl webadmin[402]: login failed user=administrator ip=203.0.113.61 port=80 |
| 5 | Jan 22 03:07:26 hvac-ctl webadmin[402]: login failed user=user ip=203.0.113.61 port=80 |
| 6 | Jan 22 03:07:28 hvac-ctl webadmin[402]: login failed user=guest ip=203.0.113.61 port=80 |
| 7 | Jan 22 03:07:30 hvac-ctl webadmin[402]: login ok user=support ip=203.0.113.61 port=80 |
| 8 | Jan 22 03:08:12 hvac-ctl webadmin[402]: user=support changed setpoint floors=1-6 heat=95F |
| 9 | Jan 22 03:08:40 hvac-ctl webadmin[402]: user=support disabled alarm notifications |
| 10 | Jan 22 07:45:19 hvac-ctl mqtt[388]: client connected sensor-floor3 ip=192.0.2.83 |
Source: Hypothetical device records written for this practice question
Source 3: Kernel firewall log (sudo tail -n 13 /var/log/kern.log)
| Line | Entry |
|---|---|
| 1 | Jan 22 01:12:40 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=192.0.2.91 DST=192.0.2.70 PROTO=TCP DPT=8080 |
| 2 | Jan 22 02:55:10 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=21 |
| 3 | Jan 22 02:55:10 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=23 |
| 4 | Jan 22 02:55:10 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=25 |
| 5 | Jan 22 02:55:10 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=110 |
| 6 | Jan 22 02:55:10 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=139 |
| 7 | Jan 22 02:55:11 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=445 |
| 8 | Jan 22 02:55:11 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=3389 |
| 9 | Jan 22 02:55:11 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=5900 |
| 10 | Jan 22 02:55:11 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=8080 |
| 11 | Jan 22 02:55:11 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.150 DST=192.0.2.70 PROTO=TCP DPT=8443 |
| 12 | Jan 22 06:00:02 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.5 DST=192.0.2.70 PROTO=TCP DPT=1883 |
| 13 | Jan 22 06:05:02 hvac-ctl kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.5 DST=192.0.2.70 PROTO=TCP DPT=1883 |
Source: Hypothetical device records written for this practice question. 198.51.100.5 is the address of the college's approved heating vendor
Source 4: File listing
$ ls -l /etc/hvac
-rw-r--r-- 1 hvac hvac 2204 Jan 03 10:15 controller.conf
-rw-rw-rw- 1 hvac hvac 8192 Jan 22 03:07 users.db
-rwxrwxrwx 1 hvac hvac 3112 Nov 18 08:40 firmware_update.sh
-rw-rw-r-- 1 hvac facilities 1530 Jan 21 16:02 schedule.json
-rw-r--r-- 1 hvac hvac 64 Nov 18 08:41 vendor_api.key
Source: Hypothetical device records written for this practice question
Source 5: Ridgeview College smart building device policy
Required:
• Factory-default passwords must be changed before a device is connected to the campus network.
• Device firmware must be updated at least every 6 months.
Permitted:
• Facilities staff may manage devices from the campus network.
• Approved vendors may monitor devices remotely.
Prohibited:
• Devices may not be managed from the internet over unencrypted protocols such as HTTP or Telnet.
• Staff may not share device logins.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the smart building device policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the smart building device policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the username of the account the adversary was able to log in to.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /etc/hvac (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why the connection attempt on line 12 of Source 3 was blocked. Cite the firewall rule involved. (ii) The college wants the approved vendor to reach the controller's MQTT service. Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let this connection through. (iii) Besides letting the vendor connect, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, Source 3 shows evidence of another kind of hostile activity. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.