4. Research.
5. Execute the attack.
6. Cover tracks.
How to mitigate risk of attack
• Preventive controls (下面详细介绍)
preventive controls – Controls that deter problems before they arise.
o People
o Process
o IT solutions
o Physical security
o Change controls and change management
• Detective controls
detective controls – Controls designed to discover control problems that were not
prevented.
– Detective controls actually monitor preventive controls.
o Log analysis
– The process of examining logs to identify evidence of possible attacks.
o Intrusion detection systems
– A system that creates logs of all network traffic that was permitted to pass the
firewall and then analyzes those logs for signs of attempted or successful intrusions.
o Penetration testing
– An authorized attempt to break into the organization’s information system.
o Continuous monitoring
o Vulnerability scan
– A detective control that identifies weaknesses in devices or software
• Corrective
corrective controls – Controls that identify and correct problems as well as correct and
recover from the resulting errors.
o Computer Incident Response Team (CIRT)
– A team that is responsible for dealing with major security incidents.
o Chief Information Security Officer (CISO)
o Patch management
• The process of regularly applying patches and updates to software.
• Patch management involves replacing flawed code that represents a vulnerability
with corrected code, called a patch.
exploit – A program designed to take advantage of a known vulnerability.
patch – Code released by software developers that fixes a particular vulnerability.
Preventive: People
• Culture of security
o Tone set at the top with management
• Training
o Follow safe computing practices
▪ Never open unsolicited e-mail attachments
▪ Use only approved software
▪ Do not share passwords
▪ Physically protect laptops/cellphones