Question

Select a recent, within ten years, cybersecurity case in which security broke down, or were security...

Select a recent, within ten years, cybersecurity case in which security broke down, or were security was breached.   Target, Equifax, Home Depot, Sony, the OPM are common topics, and one may chose one of these, but I would prefer if one found a less common, but equally challenging case to evaluate.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

In June 2013, Edward Snowden, who was working for United States government as an employee of the NSA contractor Booz Allen Hamilton, revealed thousands of classified NSA documents that eventually appeared in The Guardian and The Washington Post. Snowden was a System Administrator in NSA with official authority to access thousands of classified documents. Nevertheless, the scope and number of the documents disclosed by him suggested Snowden had wider access than would be consistent with his authority in NSA. Furthermore, he even breached the security of the sites under allied federal agencies and even the agencies of allied countries and made classified documents from those sites open to public. He probably breached the websites by stealing crednetials. Nonetheless, there is no direct evidence of how he had done it.

Stealing credentials from NSA and other federal agency websites are easier said than done. Particularly NSA follows a high end security protocol that is impossible to breach for anyone even with highest level of security access.  National Security Agency (NSA) of United States of America is always obsessive with log-watching its site access at different security levels and NSA also uses extensive psychometric analysis to predict any discrepancies in its contractual employees' behavioral pattaren. Furthermore, US federal agencies pioneered the idea that only hardware can be trusted, so they designed in the last decade a version of Linux Operating System that is called Security-Enhanced Linux (SELinux). This specially designed Operating System reduces the role of the systems administrator from the unlimited "root" superuser of standard linux/unix to a much more nuanced set of permissions that did not allow disabling logging (or modifying the logs), altering certain key system files and configuration settings, and so forth. Thus any attempt to access credentials stored by his users should have been logged, and on audit of those logs, an explanation would need to be forthcoming or that user will face punitive actions. This also implies that the security manager will know in triplicate exactly which files Snowden had accessed, where he had copied them to, and where that copy was supposed to be now for each and every file he accessed.

Snowden could have breached the system only in the following ways --

  1. By fabricating the digital certificates or other types of cryptographic keys such as those used for SSH access. Such self-signed certificates are common part of the cybercriminals toolkit to enable the exfiltration of data.
  2. Snowden reportedly obtained usernames and passwords from dozens of colleagues. When logging in with his colleagues credentials, he would also have access to their SSH keys and digital certificates. Since unlike passwords that are frequently required to be changed, SSH keys and digital certificates have much longer life span. Snowden could also have taken “fabricated” SSH keys and establish them as trusted against the colleagues credentials.

Using military Kill Chain analysis model, we can following interpretation about this cybersecurity breach case:

  1. Researching the target—Snowden used his valid access (such as CAC with keys and certificates and SSH keys for system administration) to determine what information was available and where it was stored—even if he didn’t immediately have full access to that information.
  2. Initial intrusion—Snowden gained unauthorized access to other administrative SSH keys and inserted his own to gain trusted status to information he was not authorized to access. He also took care not to set off alarms and covered his tracks.
  3. Exfiltration—To get data off the NSAnet, he could not simply save it to a flash drive. Instead data needed to be moved across networks and under the radar to evade detection. Just like common cybercriminals, Snowden used Command and Control servers to receive encrypted data sessions. These sessions were authenticated with self-signed certificates.
Add a comment
Know the answer?
Add Answer to:
Select a recent, within ten years, cybersecurity case in which security broke down, or were security...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

  • Please read case article, "Attention Kmart Shoppers? Into and out of Bankruptcy" and help me come...

    Please read case article, "Attention Kmart Shoppers? Into and out of Bankruptcy" and help me come up with a solution for the case as well as action steps to implement the solution! Thank you!! ATTENTION KMART SHOPPERS? Former Kmart CEO, Charles C. Conaway, failed in his 19-month effort to revive the iconic firm, resulting in the largest retailing bankruptcy filing in history on January 22, 2002 (Davies, et al., 2002). On March 11, 2002, bankrupt Kmart named James B. Adamson...

  • I have this case study to solve. i want to ask which type of case study...

    I have this case study to solve. i want to ask which type of case study in this like problem, evaluation or decision? if its decision then what are the criterias and all? Stardust Petroleum Sendirian Berhad: how to inculcate the pro-active safety culture? Farzana Quoquab, Nomahaza Mahadi, Taram Satiraksa Wan Abdullah and Jihad Mohammad Coming together is a beginning; keeping together is progress; working together is success. - Henry Ford The beginning Stardust was established in 2013 as a...

  • Select two of the discussion questions and analyze the case study using project management principles. Apply...

    Select two of the discussion questions and analyze the case study using project management principles. Apply your knowledge of project management to the facts presented in the case study to describe how you would proceed. We only need to answer one of the questions. A thorough answer will probably require 300 to 500 words for each question.   Feel free to use text bullets, tables, or graphics to summarize your points. Questions Q1: Make or Buy decision – Describe the make...

  • Please use own words. Thank you. CASE QUESTIONS AND DISCUSSION > Analyze and discuss the questions...

    Please use own words. Thank you. CASE QUESTIONS AND DISCUSSION > Analyze and discuss the questions listed below in specific detail. A minimum of 4 pages is required; ensure that you answer all questions completely Case Questions Who are the main players (name and position)? What business (es) and industry or industries is the company in? What are the issues and problems facing the company? (Sort them by importance and urgency.) What are the characteristics of the environment in which...

  • this is all the information given Personal Financial Planning Mini-Case Jeff and Mary Douglas, a couple...

    this is all the information given Personal Financial Planning Mini-Case Jeff and Mary Douglas, a couple in their mid-30s, have two children - Paul age 6 and Marcy age 7. The Douglas' do not have substantial assets and have not yet reached their peak earning years. Jeff is a general manager of a jewelry manufacturer in Providence, RI while Mary teaches at the local elementary school in the town of Tiverton, RI. The family needs both incomes to meet their...

  • CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male...

    CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male San Bernardino suspect's iPhone 5c. Cook stated: Antiterrorism We are challenging the FBI's demands with the deepes respect for American democracy and a love of our country. We believe it would be in the best interest of everyone to step back and consider the implications While we believe the FBI's intentions are good, if would be wrong for the w e nt to force...

  • THE CASE Sameer Arkell and Marcy Haddow had worked for Crowdsite, an international computer repair service,...

    THE CASE Sameer Arkell and Marcy Haddow had worked for Crowdsite, an international computer repair service, for ten years. It therefore came as a surprise when they both received lay-off notices on a Friday afternoon early January 2015. Both were given severance packages that matched their seniority so they decided that this might be the catalyst to launch their own business repairing computers and related equipment for businesses in their community. Both were single and had no children, so no...

  • Write down your analysis of this case on factors like the interests involved, context and power...

    Write down your analysis of this case on factors like the interests involved, context and power PACIFIC OIL COMPANY (A)* "Look, you asked for my advice, and I gave it to you," Frank Kelsey said. "If I were you, I wouldn't make any more concessions! I really don't think you ought to agree to their last demand! But you're the one who has to live with the contract, not me!" Static on the transatlantic telephone connection obscured Jean Fontaine's reply....

  • Write down your analysis of this case on factors like 1. the negotiation process, strategy and...

    Write down your analysis of this case on factors like 1. the negotiation process, strategy and tactics PACIFIC OIL COMPANY (A)* "Look, you asked for my advice, and I gave it to you," Frank Kelsey said. "If I were you, I wouldn't make any more concessions! I really don't think you ought to agree to their last demand! But you're the one who has to live with the contract, not me!" Static on the transatlantic telephone connection obscured Jean Fontaine's...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT