Device Security Analysis
Water plant operator workstation: a guessed remote login that stayed
- Units 2, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, an operator workstation (HMI) at the Millbrook Water Authority treatment plant (IP address 192.0.2.110), and were gathered during a security review. Operators use it to watch and adjust the plant's chemical pumps. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | 192.0.2.100 | 192.0.2.110 | Inbound | 22 | SSH |
| 2 | Allow | ALL | 192.0.2.110 | Inbound | 5900 | VNC |
| 3 | Deny | ALL | ALL | Inbound | ALL | ALL |
| 4 | Allow | 192.0.2.110 | 192.0.2.0/24 | Outbound | 502 | Modbus |
| 5 | Allow | 192.0.2.110 | ALL | Outbound | 443 | HTTPS |
| 6 | Deny | ALL | ALL | Outbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Rule 2 was added for a vendor's remote support visit
Source 2: System log (sudo tail -n 19 /var/log/syslog)
| Line | Entry |
|---|---|
| 1 | Apr 09 18:02:41 hmi-02 gdm: session opened for user operator2 on console |
| 2 | Apr 10 02:31:10 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 3 | Apr 10 02:31:15 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 4 | Apr 10 02:31:20 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 5 | Apr 10 02:31:25 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 6 | Apr 10 02:31:30 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 7 | Apr 10 02:31:35 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 8 | Apr 10 02:31:40 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 9 | Apr 10 02:31:45 hmi-02 x11vnc[1880]: authentication failed for operator1 from 203.0.113.200 |
| 10 | Apr 10 02:31:52 hmi-02 x11vnc[1880]: authentication succeeded for operator1 from 203.0.113.200 |
| 11 | Apr 10 02:33:12 hmi-02 useradd[2014]: new user: name=svc_maint, UID=1004, home=/home/svc_maint |
| 12 | Apr 10 02:33:15 hmi-02 usermod[2016]: add 'svc_maint' to group 'sudo' |
| 13 | Apr 10 02:34:02 hmi-02 crontab[2031]: (operator1) new job: every 5 minutes run /var/tmp/.sysupd |
| 14 | Apr 10 02:35:01 hmi-02 conntrack: NEW tcp src=192.0.2.110 dst=203.0.113.200 dport=443 |
| 15 | Apr 10 02:36:30 hmi-02 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.110 DST=203.0.113.200 PROTO=TCP DPT=8080 |
| 16 | Apr 10 02:40:01 hmi-02 conntrack: NEW tcp src=192.0.2.110 dst=203.0.113.200 dport=443 |
| 17 | Apr 10 02:45:01 hmi-02 conntrack: NEW tcp src=192.0.2.110 dst=203.0.113.200 dport=443 |
| 18 | Apr 10 06:00:14 hmi-02 conntrack: NEW tcp src=192.0.2.110 dst=198.51.100.30 dport=443 |
| 19 | Apr 10 06:58:03 hmi-02 gdm: session opened for user operator2 on console |
Source: Hypothetical device records written for this practice question. 198.51.100.30 is the HMI vendor's update server
Source 3: File listing
$ ls -l /opt/hmi
-rw-rw-rw- 1 hmi operators 4210 Apr 02 13:20 setpoints.cfg
-rw-rw-r-- 1 hmi operators 15004 Apr 09 22:10 shift_notes.txt
-rw-r--r-- 1 hmi hmi 7342 Mar 15 09:44 pump_map.csv
-rwxr-xr-x 1 hmi hmi 2056 Feb 27 16:31 export_logs.sh
-rw-r--r-- 1 hmi hmi 1675 Jan 30 10:02 vendor_vpn.key
Source: Hypothetical device records written for this practice question
Source 4: Millbrook Water Authority operator workstation policy
Required:
• Remote access must be approved by the plant manager and turned off when the approved work is finished.
• Accounts on operator workstations must be reviewed every 6 months.
Permitted:
• Operators may adjust chemical dosing within the ranges set by the plant engineer.
Prohibited:
• Operators may not browse the web or read email on operator workstations.
• USB storage devices may not be connected to operator workstations.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the operator workstation policy in Source 4 protects the device from a specific threat. (ii) Explain how one rule that is already in the operator workstation policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /opt/hmi (Source 3). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 3 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain how the outbound connection on line 14 of Source 2 got through the device's firewall. Cite the firewall rule involved. (ii) The workstation only needs outbound HTTPS to reach the vendor's update server at 198.51.100.30. Describe a change to one existing rule in Source 1 that would block the connection on line 14 while still allowing updates. (iii) Besides blocking that connection, describe one other effect your change in part D (ii) would have on network traffic from the device.
0 / 2,500 characters
Part (E)
4 pointsAfter the password attack in part B, lines 11–17 of Source 2 show what the adversary did next. (i) Identify the phase of an attack that these lines show. (ii) Describe the specific information in these lines that indicates this phase. Cite line numbers. (iii) Describe one way an automated system could stop this activity while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this activity.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.