Title: RaptorX Attacks!
Scenario:
The notorious hacker RaptorX is looking to make a splash by targeting your organization for an attack. He is currently looking for weaknesses in your organization's security as you begin this assignment.
RaptorX typically takes two approaches to attacking a network:
1. Going through the "front door" using network-based attacks.
2. Finding a shortcut to the inside of the network using social engineering.
Once he has a foothold on an internal network, he installs malicious software designed to search the network for valuable information and send it to a series of IP addresses in Eastern Europe.
You have done your homework and convinced your organization to implement the following three security components:
1. Active IDS (also called an IPS)
2. Stateful Packet Inspection Firewall
3. Virus scanner
Determinations:
Briefly describe how each security component could play a role in stopping each of the two attack approaches.
Active IDS (4 points):
Stateful Packet Inspection Firewall (4 points):
Virus scanner (4 points):
Can any one of the security components alone stop either of the approaches RaptorX will take to attack the network? (3 points)
If so, which one(s)?
If not, why not?
Write a brief memo to the management team of your organization stating the importance of using a layered security approach with security components. (5 points)