Comprehensive Study Guide to Cybersecurity Threats and Attack Vectors

Cybersecurity Lesson Objectives

  • The primary objectives of cyber threat analysis are to:

    • Describe cybersecurity threats and list specific examples.

    • Categorize the main cyber threats into distinct groups.

    • Define and describe the profile of attack vectors.

Defining Cybersecurity Threats and Bad Actors

  • A cybersecurity threat is defined as an action that exploits a vulnerability, which subsequently results in harm to a computer system or network.

  • Bad actors are the primary instigators of cybersecurity threats, actively seeking vulnerabilities to exploit.

  • Bad actors utilize various attack vectors to achieve their specific goals, such as illegal system access or inhibiting network functionality.

  • Cybersecurity threats represent a specific subset of attack vectors.

  • In this context, "method" refers to the specific way in which a vulnerability is exploited by a bad actor.

Attack Vectors and Their Components

  • An attack vector is the method a bad actor uses to illegally access or inhibit a network, facility, or system.

  • There are 33 fundamental components that comprise an attack vector:

    • The Vulnerability: The specific weakness in a system, process, or person.

    • The Mechanism or Object: The tool or method (such as malware or a psychological tactic) used to exploit the identified vulnerability.

    • The Pathway: The route or medium (such as an email or a physical entrance) taken to reach the vulnerability.

Case Studies in Attack Vectors

  • Scenario A: Email Exploitation

    • Diego receives an email appearing to be from a colleague, requesting a review of an attached document.

    • Diego saves the document to his hard drive and opens it, resulting in the installation of malware.

    • Analysis of elements:

      • Vulnerability: The user (Diego).

      • Mechanism: The malware and the socially engineered message used to deceive the user.

      • Pathway: The email conduit.

  • Scenario B: Physical and Facility Access

    • An authorized individual enters a restricted server room and encounters a technician loitering outside with heavy boxes.

    • The technician claims to have forgotten her access pass while performing equipment upgrades.

    • The authorized individual allows her entry; while inside, she connects a USB device to a server to install malware.

    • Analysis of elements:

      • Vulnerability: The authorized person and the existence of an unprotected server.

      • Mechanism: The malware and the fabricated situation used to manipulate the individual.

      • Pathway: The physical door into the server room and the USB device used to release the malware.

Classification of Cyber Threats

  • Attack vectors are categorized into three primary types:

    • Electronic social engineering.

    • Physical social engineering.

    • Technical vulnerabilities, such as computer misconfiguration.

  • Cybersecurity threats are broadly divided into 44 main categories:

    • Social Engineering: The use of psychological manipulation to trick individuals into performing actions contrary to their interests, such as disclosing confidential data. Success is dependent on gaining the victim's trust and compelling them to act.

    • Malicious Software (Malware): Software specifically designed to damage, disrupt, or gain unauthorized access to a system.

    • Unauthorized Access: Can be physical or digital.

      • Tailgating: Following an authorized person through a secure door after they have used their credentials.

      • Shoulder Surfing: Looking over a person's shoulder while they type credentials to gain digital access.

    • System Design Failure: Security flaws or bugs in a computer system or application that bad actors exploit to gain access.

Systemic Error Data

  • During the analysis of cyber threats, the following system data was processed:

    • Code: AccessDenied

    • Message: Access Denied

    • RequestId: 1ABK4DSBTSMZYEV41ABK4DSBTSMZYEV4

    • HostId: NuBPpqU+QCjkslr1mrwIpZpdtZYzoz+xEXL7kHy04mGSuypDrGdAVlDQYPsMTvb25H+qmxJAXUBZwAzwJIORIDKa3/iVCQVvNuBPpqU+QCjkslr1mrwIpZpdtZYzoz+xEXL7kHy04mGSuypDrGdAVlDQYPsMTvb25H+qmxJAXUBZwAzwJIORIDKa3/iVCQVv

Methodologies of Common Cyber Attacks

  • Attack Path: The preparation of an attack campaign, representing the chain of events that occurs when various attack vectors are exploited across multiple stages.

  • Distributed Denial of Service (DDoS): An attack involving a Command and Control (CNC) server that signals to thousands of already-infected computers to send requests to a single targeted server simultaneously. This overload inhibits the target's ability to function.

  • Phishing: A common method used to build a network of infected computers (a botnet) for attacks like DDoS. Bad actors send emails to millions\text{millions} of unsuspecting users; if a link is clicked, malware is installed.

High-Target Attacks and Multi-Stage Logic

  • Whale Phishing: A targeted phishing attack aimed at high-level executives such as a CEO or CFO. These targets are selected because of their high-level access privileges to databases and servers.

  • Spear Phishing: Targeted phishing aimed at specific individuals, though not necessarily high-level executives, to install ransomware or Trojan horses.

  • Trojan Horse: Malware hidden behind an apparently harmless document or link. Once opened, it installs itself and can leverage the victim's network privileges to infect other computers.

  • Multi-Staged Attacks: An initial infection is often just the access point to a network. Subsequent stages may include reconnaissance and the exfiltration of data.

Vulnerabilities and Countermeasures

  • Attack vectors can exploit human nature (trust), computer technology, or both.

  • Pre-exploit stage: Vulnerabilities like phishing exploit human nature's default trait to trust official or known sources.

  • Birthday Attack: A pre-exploit technical attack that targets weaknesses in hashing algorithms used to protect passwords.

  • Brute Force Attack: A method of stealing credentials by attempting every possible combination of characters until the correct one is guessed. This relies on human fallibility, specifically the use of weak passwords.

  • Counteractions: Network administrators can neutralize brute force attacks by implementing a strong password policy. Other attack vectors require specific technical or procedural countermeasures to mitigate risk.