Threat Modeling and Internetworking - Kill Chains
In 2014, a committee report to the U.S. Senate offered an operationally realistic model that applied classical military doctrine to cybersecurity attacks.
4 slides · 2 min read · Domain 4
This was one of the first highly visible demonstrations of applying the kill chain, long used in military campaign planning, to cybersecurity.
This kill chain's major operational phases are shown in this figure.
Kill Chain Phases
Reconnaissance
Weaponization
Delivery
Attack Operations
- OSINT, Scanning,
Early Intrusion Social Engineering
Select access technique
EMAIL, USBs, URLs
Possible Indicators
Increase in phishing, vishing; IDS alerts on aggressive scanning; unusual access attempts; default user ID attempts; user ID replay attacks
Software allowed list alerts; email scanning; antimalware; attempts to access unusual URLs; IP address ranges
Exploitation
Installation
Command
and Control
Actions on Objective
- Malware, Rootkit Exploit or "Live-Offthe-Land"
- Install backdoors
for continued stealth access, C3
- Attacker now has
"hands-on access" inside target
- Exfiltration, data corruption, springboard to other targets. Hide in plain sight; erase tracks.
Antimalware, allowed list alerts; AAA or privilege elevation anomalies; behavioral anomalies
Configuration control / allowed list alerts of unauthorized changes; systems behavioral anomalies
Anomalies detected by apps, platforms, database servers; data traffic / flow anomalies; user activity anomalies
This model forces the security team to recognize that on any given day, potentially suspicious actions against their organization's information systems or its people can be part of one or more APTs' agenda. It emphasizes that seemingly isolated actions, such as a new phishing attempt or indications of a previously unseen malware attempting to load, may in fact be connected.
And, as the Target 2013 attack and others since then have demonstrated, when many businesses, organizations, and individuals allow their information and information systems to be compromised, they may unwittingly provide support to an APT in the pursuit of its larger objectives.
Reference: United States Senate, Committee on Commerce, Science, and Transportation. A "Kill Chain" analysis of the 2013 Target Data Breach. https://www.commerce.senate.gov/public/?a=Files. Serve&File_id=24d3c229-4f2f-405d-b8db-a3a67f183883
