Device Security Analysis
Research lab workstation: a scary email and a 2.3 GB upload
- Units 1, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, a workstation in the Ashford University genomics lab (IP address 192.0.2.140), and were gathered during a security review. The lab's real login page is login.ashford.example.org. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | 192.0.2.0/24 | 192.0.2.140 | Inbound | 22 | SSH |
| 2 | Deny | ALL | ALL | Inbound | ALL | ALL |
| 3 | Allow | 192.0.2.140 | ALL | Outbound | 443 | HTTPS |
| 4 | Allow | 192.0.2.140 | ALL | Outbound | 21 | FTP |
| 5 | Allow | 192.0.2.140 | 192.0.2.0/24 | Outbound | 445 | SMB |
| 6 | Deny | ALL | ALL | Outbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Rule 4 was added so the lab can send data to its partner lab at 198.51.100.60
Source 2: Mail and web proxy log (sudo tail -n 6 /var/log/mail-proxy.log)
| Line | Entry |
|---|---|
| 1 | Sep 08 15:02:11 lab-ws7 mail: delivered from=<pi-office@ashford.example.org> to=<rpatel@ashford.example.org> subject="Lab meeting moved to Thursday" |
| 2 | Sep 08 16:44:05 lab-ws7 mail: delivered from=<it-support@ashford-helpdesk.example.net> to=<rpatel@ashford.example.org> subject="URGENT: your research storage will be DELETED in 2 hours unless you verify your account" |
| 3 | Sep 08 16:44:05 lab-ws7 mail: message contains link to https://login.ashford-helpdesk.example.net/verify |
| 4 | Sep 08 16:47:30 lab-ws7 proxy: rpatel GET https://login.ashford-helpdesk.example.net/verify 200 |
| 5 | Sep 08 16:48:02 lab-ws7 proxy: rpatel POST https://login.ashford-helpdesk.example.net/verify 302 (form fields: username, password) |
| 6 | Sep 08 16:50:14 lab-ws7 proxy: rpatel GET https://login.ashford.example.org/ 200 |
Source: Hypothetical device records written for this practice question
Source 3: System log (sudo tail -n 8 /var/log/syslog)
| Line | Entry |
|---|---|
| 1 | Sep 08 09:01:40 lab-ws7 sshd[1402]: Accepted password for rpatel from 192.0.2.141 port 50211 ssh2 |
| 2 | Sep 09 02:39:55 lab-ws7 vpn: user rpatel connected from 203.0.113.88, assigned address 192.0.2.201 |
| 3 | Sep 09 02:41:12 lab-ws7 sshd[2877]: Accepted password for rpatel from 192.0.2.201 port 50980 ssh2 |
| 4 | Sep 09 02:43:30 lab-ws7 audit: user=rpatel created /tmp/out/genome_set_A.tar (2.3 GB) from /data/genomics |
| 5 | Sep 09 02:47:02 lab-ws7 ftp-client: user=rpatel upload /tmp/out/genome_set_A.tar to 203.0.113.88 port 21 started |
| 6 | Sep 09 03:19:48 lab-ws7 ftp-client: user=rpatel upload to 203.0.113.88 finished (2.3 GB in 32 minutes) |
| 7 | Sep 09 03:20:15 lab-ws7 audit: user=rpatel deleted /tmp/out/genome_set_A.tar |
| 8 | Sep 09 09:05:21 lab-ws7 ftp-client: user=kwong upload /data/genomics/shared/run_118.csv to 198.51.100.60 port 21 finished (48 MB) |
Source: Hypothetical device records written for this practice question. 198.51.100.60 is the partner lab's FTP server
Source 4: File listing
$ ls -l /data/genomics
-rw-rw-r-- 1 labadmin genomics 2469606195 Sep 01 12:00 genome_set_A.tar
-rw-r--r-- 1 labadmin genomics 884736 Aug 20 10:31 consent_forms.pdf
-rwxrwxr-x 1 labadmin genomics 15022 Aug 28 17:45 analysis.py
-rw-r--r-- 1 labadmin genomics 96 Jul 14 09:00 partner_ftp.cred
-rw-rw---- 1 labadmin genomics 40210 Sep 07 16:12 lab_notebook.md
Source: Hypothetical device records written for this practice question
Source 5: Ashford genomics lab computer use policy
Required:
• Lab members must report suspicious emails to the IT help desk.
• Sending research data to anyone outside the university must be approved by the lab's principal investigator.
Permitted:
• Lab members may connect from off campus through the university VPN with their university password.
Prohibited:
• Lab members may not enter their university password on any site other than login.ashford.example.org.
• Lab members may not store research data in personal cloud accounts.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the lab computer use policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the lab computer use policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 shows how the adversary got rpatel's password. (i) Describe the evidence in Source 2 that the email on line 2 was a phishing attack and that it worked. Cite specific line numbers and entries. (ii) Identify one social engineering tactic used in the subject line of that email.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /data/genomics (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain how the upload on line 5 of Source 3 got through the device's firewall. Cite the firewall rule involved. (ii) The lab only needs to send files by FTP to its partner lab at 198.51.100.60. Describe a change to one existing rule in Source 1 that would have blocked the upload on line 5 while still allowing transfers to the partner lab. (iii) Besides blocking that upload, describe one other effect your change in part D (ii) would have on network traffic from the device.
0 / 2,500 characters
Part (E)
4 pointsAfter stealing rpatel's password, the adversary carried out a second attack, shown in Source 3. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.