CyOFTS_II,_Section_L,_Attachment_3_Part_II.pptx
PPTX presentation 3 MB Posted
- Attached to
- Solicitation Notice Federal contract opportunity
- Solicitation number
- FA8773-17-R-8005
About this file
Part II- Teaching Plan
View the file
Other files for this federal contract opportunity
Show all 50
Solicitation Notice has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Vulnerability Management C-1507L
CYBER DEFENSE AND CONTROL OPERATIONS
HURLBURT FIELD, FL
PART II TEACHING PLAN
“The overall classification of this lesson is UNCLASSIFIED//FOR OFFICIAL USE ONLY.”
LESSON AND SELF: Name and background
ATTENTION STATEMENT: Every single day AF network works are hit with countless attacks. While the source of the attacks may be difficult to ascertain, the destination and the means through which the attack was carried out should be investigated and mitigated.
MOTIVATION STATEMENT: We should never get hit by an attack where the vulnerability that was exploited was known by the organization that it was vectored against. This is where the process of identifying vulnerabilities that exist on our current infrastructure aka “known knowns” and remediating them is most important.
TRANSITION: Let’s take a look at what we’re going to cover within this lesson…
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Lesson Overview Vulnerability Management Identification of New Vulnerabilities Vulnerability Notification Procedures Time Compliance Network Orders (TCNO) Vulnerability Scanning
OVERVIEW: (roadmap for the lesson) Read through the slide.
Part II Teaching Plan C-1507L Vulnerability Assessments
Lesson Objectives LO-1: Comprehend the process of conducting vulnerability management (VM) (B) MSB 1.1: Identify the purpose of vulnerability assessments (A) MSB 1.2: Explain procedures used to complete a vulnerability assessment (B)
OVERVIEW: Read them verbatim
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Lesson Objectives LO-2: Comprehend the vulnerability assessment process conducted by AF assets (B) MSB 2.1: Identify the organizations who resolve vulnerability scans (B) MSB 2.2: Explain the AF tools used to perform vulnerability scanning (B)
OVERVIEW: Read them verbatim
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability
Weakness in an Information System, system security procedures, internal controls, or implementation that could be exploited
CNSSI-4009
MP1: Weakness in an IS, system security procedures, internal controls, or implementation that could be exploited.
MP2: Identifying vulnerabilities in your organization assist the vulnerability management process by defining what level of protection is needed to secure the information systems that your organization operates.
TRANSITION: Lets take a look at why we need to manage these vulnerabilities.
Part II Teaching Plan C-1507L Vulnerability Assessments
Why Vulnerability Management Vulnerability Management Guide Fix faults in the software affecting security, performance or functionality Alter functionality or address a new security threat, such as by updating an antivirus signature Change a software configuration to make it less susceptible to attack Use most effective means to thwart attacks by automated malware
MP1: This mode deals with the inherent nature of there always being coding flaws in the software that your organization is using. Its important to keep up to date with the patches to those coding flaws so that your organization is not exploited using buffer overflow type attacks.
MP2: AV is a gift and a curse. The data/signature file for the AV engine that scans your environment is in a state of constant updating. Of course this allows for you to be secure from known attacks but if the virus signature does not exist for a vulnerability in your organization AV will not detect it.
MP3: Lots of software comes with default settings out of the box that make it vulnerable to attack. Certain functions and features may need to be configured differently so that those vulnerabilities are not exploited.
MP4: The propagation of attack is definitely a goal of the adversary; because of this, organizations may need to segment their networks in ways peer communication on the network is at a minimum.
TRANSITION: Now that we understand why we do vulnerability management lets discuss the process.
Part II Teaching Plan C-1507L Vulnerability Assessments
MPTO 00-33A-1109-WA-1
Legacy Scan/Patch Process
MP1: Legacy method is focused on the bases figuring out what is wrong, why patches aren’t being deployed to clients, and report back up directly to 624th on compliance.
TRANSITION: Lets discuss why we should move to a more proactive approach.
Part II Teaching Plan C-1507L Vulnerability Assessments
Current Scan/Patch Process
Needs Improvement
MP1: This is the current cyber operations process for routine pre-approved vulnerability identification and patching connecting previously disconnected processes.
MP2: START:
624 OC Orders Processing Cell sends the patch as an order to the NOS Order Processing Cell
1. Patch management (PM) receives the patch, prepares and distributes it to the test environment
2. PM releases the patch to their test group
3. If successful PM release the patch
4. In the new process remediation management (RM) cell acts as the intermediary between the Scan and patch teams
5. Once the patch is deployed the RM team monitors compliance based on predetermined milestones
a. if milestones reached RM reports compliance back to 624 OC/OPC
6. If the compliance milestones are not met, there are a couple of options
| a. Send the patch back through the patch process |
| b. Run a set of automated tools such as the SCCM client health remediation tool |
7. If the automation tools don't bring compliance to 100% then they issue a cyber order to the CCSD owner at the installation (Base CFP) where the patches are failing. Those applicable Computer Support Techs will perform touch maintenance as an order from the RM
--VM--
1. The next block illustrates the vulnerability management piece. DISA releases the audit scan –
| a. VM verifies scan data verifies the active directory structure |
| b. verifies scanner audits and updates as necessary |
| c. runs the audit scan |
2. The RM team step in to gauge the scan results
| a. If they notice administrative issues with the scan such as low access rates, misconfigured scanners…etc, RM direct VM to restart the process |
| b. If the RM team determines high numbers of machines are not patch compliant, RM begins interaction with patching team to remediate via enterprise automated means (ex. A one off patch or GPO recommendation) |
3. If RM team determines the scan & enterprise remediation efforts cannot reach the client, RM tasks the CCSD/Owner (CFP) with touch mx. (e.g. SCCM client health issues or other items that require touch/mx)
4. RM team receives compliance notice from the CCSD/Owner
| a. RM verifies via SCCM reports |
| b. documents compliance in ACT (for the bases) or submits POA&M in VMS or ACAS for later resolution |
STOP:
5. Process complete
MP3: Take notice to the blue section of tasks. This is where we need improvement and through Find, Fix, Finish, Validate, and Analyze (F3VA) and Defensive Cyber Targeting Cell (DCTC) we will hopefully achieve our goals.
TRANSITION: Let’s discuss why we should move to a more proactive approach.
Part II Teaching Plan C-1507L Vulnerability Assessments
Proactive Scan/Patch Process
MP1: F3VA is a variation of the OODA Loop and a variation of the HVT hunting process developed by LTG McChrystal at JSOC called F3EA. It is intended to show a proactive defensive cyber process which in cyber operates in near-real time. The process is simplified and faster for two reasons. Defensively Blue Force target information is much more readily available, and finishing actions executed with far less oversight and approval. Technology in Cyber has automated processes and future tools such as Tanium will bring near real-time capabilities to even further shrink this OODA Loop cycle.
| SP1: Find - In the Find phase, raw sensor data is collected from all possible sources—a dynamic list. Primary sources include System Center Configuration Management (SCCM), Desired Configuration Manager (DCM), and Assured Compliance Assessment Solution (ACAS). The official reporting source of record is ACAS scan data. This can be tasked as a surveillance mission type by the 624 OC or 690 NSS. |
| SP2: Fix- The Fix phase entails analysis of raw sensor data. The more effectively this phase executes, the more wisely overall resources are expended in characterizing and engaging identified problem sets. Personnel performing Cyberspace Surety actions will review the data to determine the cause of anomalies, the appearance of normal trends and which events correlate with the data provided to explain the reports. The aggregation of like systems or vulnerabilities into target sets for later action vice single machine attacks provides more efficient use of resources. The normal target list is a sorted 1-to-N list of systems in descending order with the largest number of vulnerabilities listed first. Additional analysis can be performed to generate an output of like issues for batch processing and potential automation for remediation can be created or up channeled. The target lists should include a number of relevant data points for discussion in more detail in a later section. The Fix phase time may vary depending on data analysis or defensive cyberspace intelligence expertise. Analytic tools were developed to aid this analysis phase by creating visual trending data and automated target lists. The wing/base also has the ability to inject key cyberspace terrain data for mission assurance, weighting specific targets for prioritization. The Fix phase uses the raw data and applies it into the template of the Cyberspace Readiness Briefing to display standardized information for decisions and action. |
| SP3: Finish- In this phase, actions on the target objectives are accomplished and effects are created. These can include pre-approved actions (PAA) IAW rules of engagement (ROE) for action at the bases, or tasked missions by the 624 OC to be accomplished with enterprise level visibility and priority. Finishing forces may be any personnel with the ability to remediate the issue (PMO FSA, base CSTs, base infrastructure, etc.). Cyberspace Surety is only the inject point to the organizations where operators from any discipline may be required to actually conduct the finishing actions. Finishing actions occur on approved target lists by the designated finishing force utilizing the recommended remediation method. Remediation methods include Group Policy Objects (GPO), scripts, manual patching, re-imaging, port blocking for disconnection, and more. The 624 OC or AMAC would normally task a Secure mission type to conduct these finishing actions under DoDIN operations. |
| SP4: Validate- The Validate phase is operational assessment. The finishing force believes the mission was accomplished and the DCTC must now validate vulnerabilities were remediated. This generally involves a targeted re-scan using ACAS. Whether the issue is STIG compliance, patch configuration, or is physical in nature, re-scan constitutes the outside validation to ensure creation of desired effects. Feedback is then returned to the tasking organization for sortie closure. If validation is incomplete then a re-attack mission is generated. The validation can be tasked as an surveillance/secure mission type. Validation details are an input for the Cyberspace Readiness briefing. |
| SP5: Analysis- In the Analysis phase, a determination is made concerning why vulnerabilities are not remediated with organic automated means. This analysis helps prevent repeat problems and vulnerabilities. The Analysis phase occurs where the most enterprise data is available for understanding large scale trends and enterprise level issues. The AMAC conducts vulnerability management analysis actions for the tactical units at an enterprise level. The wing/base, NOS and COS have smaller Analysis functions, scaled for their AOR, to improve their F3VA processes. The F3VA process allows for the fastest return to service while the Analysis phase allows for longer term problem solving in an ITIL construct. Cyberspace Readiness briefs will be updated and briefed to unit leadership in this phase at unit leadership discretion. |
TRANSITION: Lets revisit the definition of what a vulnerability is in relation to information systems.
Part II Teaching Plan C-1507L Vulnerability Assessments
MPTO 00-33A-1109-WA-1
Defensive Cyber Targeting Cell(DCTC) Simply a Cyber Surety shop made up of the fusion of patching and scanning branches
Why must we adopt this new cell?
Patch deployment is “fire and forget” Scan results are not current No repercussions for noncompliant orders Tracking and reporting lead to compliance Validation of desired effects not occurring Operational rigor introduced with a new cell which binds the complete process
MP1: Simply a Cyber Surety shop made up of the fusion of patching and scanning branches
MP2: Self-Explanatory
| SP1: Patching is fire and forget – bases are expected to follow through and ensure patches are deployed – why? Patches will not be deployed to users who are currently logged on to a system, or if the system is asleep (Power mgt). |
| SP2: Scan results are typically 2+ weeks old by the time it reaches a base/unit. Technicians can still deploy remediation efforts, but have to wait until NEXT scan cycle to verify compliance. Patch may not have applied correctly; therefore, another month will pass before validation (possibly 3+ months old) Focus is always on the new vulnerability and reaching 95+%. No organization re-looks at the <5% still vulnerable. 95 % compliance may not equal the DISA required ratio of 2.5 In that time, computer could reboot, user could log off, network hiccup, wrong scanning audit version…etc |
| SP3: There is no authoritative organization with teeth to tell the bases they are outside of compliance. No repercussions as mentioned before. It doesn’t matter is your client is missing 50 patches. |
| SP4: Self-Explanatory |
| SP5: The results of validation are skewed based on the time gathered and scanned again. There is no current operational picture of vulnerabilities on the AFIN that is 100% accurate. |
| SP6: Self-Explanatory |
TRANSITION: Lets revisit the definition of what a vulnerability is in relation to information systems.
Part II Teaching Plan C-1507L Vulnerability Assessments
Results
Since Jan 2016
• Tracking 77K+ IDs (plug-ins) correlating to ~32K vulnerabilities monthly
| • Identified 7 CVEs correlating 425K CAT I and 1.6 M CAT II in the AF | |
| • 5 of the 7 accounted for 30% of the top vulnerabilities in the AF | |
| • 3 of the 7accounted for 60% of an adversary’s primary TTPs |
Originally priority #13 and #757 based on CCRI weighted criteria
• Nominated 15 targets to DoDIN Forces associated with 6.1M vulnerabilities
• Mitigated 4 CVEs associated to 30% of weighted total of vulnerabilities on AFIN
PVG Brief
MP1: Self-Explanatory
MP2: Self-Explanatory
MP3: Self-Explanatory
MP4: Self-Explanatory
TRANSITION: Lets take a look at why we need to manage these vulnerabilities.
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability Management Lifecycle Identification/Notification Scanning Remediation Reporting
MP1: The purpose of the various vulnerability identification and notification processes is to improve the security posture of the AFIN, Air Force information systems, and stand-alone computing devices through rapid positive identification and notification in order to mitigate network and information system vulnerabilities.
MP2: The practice of vulnerability scanning is an information gathering process for identifying known vulnerabilities of computing resources on a computer network. By DOD and AF policy and directive, all AF networks must be scanned for known vulnerabilities on a monthly basis.
MP3: The goal of the vulnerability remediation/mitigation process is to mitigate risk to the AF-GIG through the implementation of network vulnerability countermeasures. Countermeasures will generally entail configuration changes to systems, installation of software patches, and/or the search for and removal of specific files or tools used for malicious purposes.
MP4: 24 AF is responsible for reporting Air Force compliance with USCYBERCOM directives. Timely, accurate vulnerability reports are crucial to the success of mitigating the threats posed by identified vulnerabilities.
TRANSITION: Lets dive into the identification and notification process.
Part II Teaching Plan C-1507L Vulnerability Assessments
Identification of New Vulnerabilities Reported via Operational Reporting Chain Validated by 33 NWS Air Force Cyber Defense (ACD) validates vulnerability previously not identified Was new vulnerability exploited?
If incident occurred -> ACD starts investigation If configuration issue -> Start TCNO process Once validated, C3MS reports to USCYBERCOM
MP1: Newly discovered vulnerabilities for which no risk mitigation procedure has been established must be reported via operational reporting chains (e.g., User to Client Support Technician (CST), CST/Functional System Administrator (FSA) to Communications Focal Point (CFP), CFP to servicing Network Operations Squadron (NOS)). The servicing NOS will forward to the 33 NWS with a courtesy copy to 624 OC. The CFP is responsible to inform local IA managers of newly discovered vulnerabilities.
MP2: The 33 NWS validates that the vulnerability has not been previously identified and an order to remediate has not been released. The 33 NWS may develop mitigation strategies to immediately protect against exploitation.
MP3: If the newly discovered vulnerability was exploited or an actual incident is suspected, follow the incident handling procedures in CJCSM 6510. For vulnerabilities identified or caused by network configurations directed by 624 OC or DOD guidance (e.g. STIGs), follow the operational reporting chain to notify the distributing organization and 624 OC. In conjunction, contact the source originator to validate the vulnerability and report the findings to the 624 OC for situational awareness.
MP4: Once validated by the 33 NWS, 624 OC communicates newly discovered vulnerabilities with USCYBERCOM for further direction.
TRANSITION: Now that we have identified new vulnerabilities what is the notification process for eventual remediation.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability Notification: General Procedures 690th COG/AMAC releases orders via AF Network Operations Compliance Tracker (ACT) Orders issued to address vulnerabilities include:
Cyber Control Order (CCO) Time Compliance Network Order (TCNO) Maintenance Tasking Order (MTO) Time Compliance Technical Order (TCTO)
MP1: The 624 OC (690th AMAC) releases orders via the ACT in accordance with AFI 10-1701, C2 of the AF-GIG, to direct the remediation and/or mitigation of vulnerabilities that affect the AF-GIG. Three primary orders are issued to address vulnerabilities (in order of criticality): CCOs, TCNOs, MTOs. In addition, 624 OC may release informational reports, such as the C-4 NOTAM, Friendly Forced Information Requirements (FFIR) and Commander’s Critical Information Requirements (CCIR). These reports disseminate information on vulnerabilities for which no mechanisms to prevent exploitation are yet available.
SP1: CCOs are directives to bind or shape the portion of cyberspace to be employed in support of an Air Force or Combatant Commander’s mission assurance objective. A CCO carries the highest precedence or criticality for accomplishment.
SP2: TCNOs are orders issued to direct the immediate patching of information systems to mitigate or eliminate exploitation vulnerabilities. These orders have a significant implication if not accomplished in a timely manner.
SP3: MTOs are routine tasks that enhance network security with a medium to low risk associated with the task.
SP4: For Technical Order (TO)-controlled systems, Program Offices release Time Compliance Technical Orders (TCTO) in response to orders released by 624 OC to address applicable vulnerabilities, per AFI 63-101, in addition to standard system updates.
TRANSITION: The order most used in the vulnerability management process is the TCNO, lets take a look at its associated procedures and processes.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
TCNO General Procedures Conditional Issuance Implement due to Information Assurance Vulnerability Alert/Bulletin (IAVA/IAVB) ACD receives information on vulnerabilities affecting AFIN assets Releasing Authority 24 AF, through 624 OC, and delegated to the AMAC is the only organization authorized to release Air Force-wide TCNOs CSCS is responsible for assigning released TCNOs to units within their AOR
MP1: To implement an IAVA or IAVB as applicable at the direction of USCYBERCOM as well as other identified vulnerabilities. TCNO-As are associated with USCYBERCOM IAVAs. TCNO-Bs (common on the CTO) are associated with USCYBERCOM IAVBs. TCNO-Cs are associated with all other AF-identified vulnerabilities. TCNO timelines are set to ensure higher headquarters timelines are met or are based on an internal analysis of the scope of effort necessary for units to achieve compliance and the potential impact on planned and ongoing operations.
MP2: The 33 NWS receives information on vulnerabilities from numerous sources and assesses the threat to AF systems and drafts either a TCNO (common on the CTO) or a Command, Control, Communications, and Computer Notice to Airmen (C4-NOTAM) and sends to the Integrated-Network Operations and Security Centers (I-NOSC) and 624 OC for pre-coordination. Upon release of a USCYBERCOM IAVA or IAVB, 33 NWS submits the draft TCNO/NOTAM to 624 OC for release consideration. Once the 624 releases the order via ACT, the 33 NWS will post the TCNOs/NOTAMs to their NIPRNET and SIPRNET websites to ensure widest dissemination to Air Force organizations.
MP3: 24 AF, through 624 OC, is the only organization authorized to release an Air Force-wide TCNO
MP4: Network Operating Squadrons (NOS) are responsible for assigning released TCNOs to units within their area of responsibility (AOR)
TRANSITION: What priorities do these TCNOs take.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
TCNO Priority Categories
| Priority | Description |
| Critical | Widespread and imminent/ongoing threat to the AF-GIG and supported operations. |
| Serious | Widespread threat to the AF-GIG and supported operations is expected. |
| Medium | Threat to the AG-GIG is possible but may be mitigated by such factors as difficulty of exploitation, limited deployment of vulnerable operating system, etc. |
MP1: The 624 OC assigns a TCNO priority based on an assessment of the scope and potential impact of the vulnerability to the AF-GIG and supported operations and, where applicable, to comply with USCYBERCOM implementation and reporting requirements.
SP1: Critical - this priority is reserved for those vulnerabilities that are going to affect a high percentage of systems in the AFIN.
SP2: Serious - this priority is for those vulnerabilities that based off of intel have a high chance of being exploited if left unchanged.
SP3: Medium - lowest priority reserved for a small number of systems that may be affected by a vulnerability.
SP4: There is also a high category from the old AFI that has since been rescinded but is related to the serious category.
TRANSITION: Dependent on its priority level C3MS will assign a corresponding suspense date.
Part II Teaching Plan C-1507L Vulnerability Assessments
Determining TCNO Suspense Dates
Within 24 hours of the first duty day following TCNO release Within 7 calendar days of TCNO release and every 7 days until compliant
MP1: For each TCNO generated, the 624 OC will assign several key suspense dates to help prioritize work by tasked organizations and to ensure information exchange reporting requirements are met.
SP1: Receipt Acknowledgment Date. The date by which tasked organizations will acknowledge receipt of the TCNO in ACT
SP2: First Report Date. The date by which tasked organizations will provide their first initial statistics update in ACT
SP3: Plan of Action and Milestones (POA&M) Mitigation Date. The date by which tasked organizations must achieve full compliance with the implementation actions mandated by the TCNO or have a finalized POA&M submitted to the servicing NOS
TRANSITION: Now that we have talked about managing these vulnerabilities lets switch gears and discuss the process through which we identify that vulnerabilities are present.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability Scanning
The practice of vulnerability scanning is an information gathering process for identifying known vulnerabilities of computing resources on a computer network. By DOD and AF policy and directive, all AF networks must be scanned for known vulnerabilities on a monthly basis
MP1: The practice of vulnerability scanning is an information gathering process for identifying known vulnerabilities of computing resources on a computer network. By DOD and AF policy and directive, all AF networks must be scanned for known vulnerabilities on a monthly basis.
SP1: Why do we accomplish enterprise wide vulnerability scanning? Well it started off with JTF-GNO WARNORD 08-006 directive which called for the completion of automated vulnerability scans, remediation, and the reporting of network vulnerabilities throughout the DoD-GiG. In the CJCSM 6510 its states under the CND Framework that vulnerability scanning will be a part of the protection measures taken to secure federal assets. And most recently TASKORD 13-0670 which mandated the implementation of ACAS (vulnerability management framework) which we will discuss in the next lesson.
TRANSITION: Lets discuss preparing for the vulnerability scanning process.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability Scanning Preparation Process
DISA CVSR TTP
Scan categories Command Cyber Readiness Inspection (CCRI) Scan Certification & Accreditation (C&A) Scan Cyberspace Security Provider Scan Weapon systems usually fall into one of the following CCRI for compliance Cyberspace Security Provider scan for Cyberspace Security Provider (CNDSP)
MP1: Before performing a cybersecurity vulnerability scan, it is important to understand the objective of the scan. By understanding the objective of the cybersecurity vulnerability scan, the scan technician will be able to ensure that the preliminary information required to perform the scan is received, as well as being able to establish a plan for performing a scan that will provide the desired output for reporting purposes.
SP1: Used to perform a cybersecurity vulnerability scan for a site or program of record (POR) in order to validate compliance readiness. The results of the scan will be used to report the site compliance status and provide the site with results in order to mitigate any deficiencies.
SP2: Used to perform a cybersecurity vulnerability scan for a site or POR that will be utilized to generate a recommendation for C&A. The results of the scans can be used to conduct a risk assessment for the site or asset that will be included in the C&A package.
SP3: Used to perform an external cybersecurity vulnerability scan to test a site’s perimeter security and determine the potential security vulnerabilities that may exist. The results of this scan will be used to report a site’s vulnerability status and shared with the subscriber site for corrective actions to be taken.
MP2: The weapon systems usually fall into category 1 and 3. 1 more for compliance sake and 3 because each of the weapon systems are apart of the computer network defense support program.
TRANSITION: Lets continue to illustrate this process.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability Scanning Preparation Process (cont.)
DISA CVSR TTP
Before initiating the previous slides scans the Security Content Assessor (SCA) will determine which of the following scans will help check for vulnerabilities and validate for compliance:
Internal CSCS, AFINC, NCC/Tier 3 VM Team External
ACD/EVA
MP1: When initiating any of these scans the SCA TL will determine the type of vulnerability scan that will be conducted to obtain the desired results. There are two (2) types of scans that can be performed for each of the above categories to check for vulnerabilities and validate compliance.
SP1: Scans are run against assets operating on a customer’s network inside a premise router. This may include remote offices connected via Wide Area Network (WAN) links, providing intranet connectivity, if those links are inside the perimeter or the point of demarcation of the site being evaluated. Internal scans are performed on both the NIPRNet and Secure Internet Protocol Router Network (SIPRNet) to query systems utilizing predefined audits to examine a system’s security compliance. These scans are usually credentialed scans to allow internal access to the system to obtain detailed information concerning the configuration and compliance validation of the scanned system. In most cases, CCRI and C&A will conduct these types of vulnerability scans.
SP2: Scans are conducted by remote scanning teams and consist of scans on assets inside a customer’s premise router from an Internet Protocol (IP) source address outside the customer’s network. These scans are most commonly non-credentialed scans which are port scans of networks and assets to determine potential security weaknesses which could be exploitable from the outside. This is the primary type of vulnerability scan performed by Cybersecurity Service Providers.
TRANSITION: Lets continue to illustrate this process.
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability Scanning Preparation Process (cont.)
DISA CVSR TTP
Before initiating the vulnerability scan the SCA will work with the network owners to determine that relevant information in the scan request will ensure a successful scan such as:
Key Terrain Scanning Infrastructure Scan Coordination Memo
MP1: In preparation for coordinating the cybersecurity vulnerability scan, the SCA TL works with the SCA to validate the vulnerability scan request. This validation will ensure that the SCA has the relevant information to allow for a successful scan.
SP1: All IPs provide as part of the site’s IP scanning range are potential assets for scanning. The SCA will need to scan a representative sample of all device types as time permits with the overall objective of scanning all assets on the network. The SCA should abide with the sites' cybersecurity vulnerability scanning process regarding after hours or unattended scans. Scanning “thin clients” or terminal server-based PCs can have merit if the thin client has a local operating system (OS) (i.e., stored in: flash memory, solid state drive, hard drive) and is doing local processing. It should be scanned along with other devices to ensure that image is compliant with the appropriate Security Technical Implementation Guide (STIG) and other security processes. When scanning private IP addresses and closed networks such as Security Test and Evaluation (ST&E) labs or closed baselines, completion of all pre-scan requirements and documentation is required by the vulnerability scanning team.
SP2: Different deployment options of ACAS which are usually an instance of Security Center or just the Nessus Scanner.
SP3: A Cybersecurity Vulnerability Scan Coordination Memorandum would be a document that outlines the information that would be used to conduct a cybersecurity vulnerability scan. The SCA TL would provide a signed Vulnerability Scan Coordination Memorandum to the SCA which would authorize the SCA to conduct vulnerability scans of the named site’s network(s), but only the network(s) specified in the memorandum.
TRANSITION: Now that we have prepped for conducting a scan lets take a look at the types of scans the vulnerability management systems will complete.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Vulnerability Scans
MPTO 00-33A-1109-WA-1
“All Audits” Discovery Credentialed
Specialized scans DMZs Standalone Assets
MP1: Scans are the downward-directed scans required monthly per USCYBERCOM’s CTO 08-005 (legacy order given back in 2008)
SP1: If the terrain is not known the organization will complete a discovery scan to locate assets; will then follow up with a more specific scan based on vulnerabilities that have been published.
SP2: Credentialed all audit scans are more invasive because you are able to authenticate with the actual client using domain credentials.
MP2: Ad hoc scans performed in response to a newly issued TCNO or identified threat or to validate compliance with an order.
SP1: Organizations that have the capability to scan public facing DMZs will do so from non-attributable IPs (33rd)
SP2: Tier 3 organizations will need to scan systems that are exempt from the all audits lists to stay in compliance with DoD regulations.
TRANSITION: Lets discuss the types of scans you will encounter when completing vulnerability scans.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Cyber Security and Control System (CSCS) Scanning 690th COG VM CONOPS
Responsible for conducting both All Audit and Specialized Scans
Ensures access to the VM tool for base, site, and organizations
Assists in the development of TTPs for VM
MP1: CSCS will conduct scheduled monthly vulnerability scans of all assets/devices connected to the AF-GIG on both NIPRNET and SIPRNET. All internet protocol (IP) addressable devices are eligible for scanning to include, but not limited to servers, routers, switches, firewalls, printers, workstations, and access points. CSCS and associated Detachments will coordinate within their AOR to identify IP addresses that must be exempt from scanning for various reasons such as mission impact and utilization overload caused by the scan.
MP2: Self-explanatory
MP3: Self-explanatory
TRANSITION: Lets next discuss the actual scanning process that CSCS takes.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
ACD Scanning
Responsible for conducting specialized scans of base DMZs (assets not in control of CSCS)
Ensures that all systems within DMZ are found by running a full discovery scan of subnet provided
Scan systems that were previously part of an incident to clear for production operations
MP1: Network vulnerability scans of assets residing in the Demilitarized Zone (DMZ) (e.g., assets operating outside of the I-NOSC controlled firewalls) will be conducted monthly by the 33NWS,also known as the AF Computer Emergency Response Team (AFCERT), and findings will be provided to the applicable I-NOSC via the 33 NWS SIPRNET Blue Assessment website. I-NOSCs and NOS Detachments will review the reports, identify appropriate organization(s) for corrective actions to include timelines and mitigations, and submit the vulnerability reports to the applicable Tier 3 location (CFPs/PMOs) for action within 48 hours of receipt.
MP2: Self-explanatory.
MP3: Self-explanatory.
MP4: In addition to utilizing the DMZ whitelist (maintained by 26 NOS), ACD conducts a discovery scan, IPs are sought out and recorded. The recorded IPs become the target IPs for the vulnerability scan phase. The two types of discovery scans: web-server and network server. During the web server discovery scans, the IPs recorded are AFIN websites. IPs are not exclusive to a discovery method, some IPs are web servers and network servers based on DMZ whitelisting. Across all MAJCOM IP ranges, approximately 9.3 million AF IPs are scanned each month for servers during the discovery phase. Approximately 50K IPs will be discovered and then scanned for vulnerabilities each month.
TRANSITION: Lets next discuss ACDs process for conducting scans.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
ACD Scanning Web Server ACD Familiarization Guide
MP1: Web server scanning is conducted with COTS tool named Acunetix, which provides in-depth vulnerability scanning of web-servers and includes verification tools that give Vulnerability Assessments the capability to validate its vulnerability findings.
TRANSITION: Lets next discuss ACDs process for conducting scans.
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
ACD Scanning Network Server ACD Familiarization Guide
MP1: Network scans are conducted using the Nessus scanner component of Assured Compliance Assessment Solution (ACAS) is the DoD replacement for eEye Retina for conducting vulnerability and compliance scanning. ACD does not leverage the full capabilities of ACAS at this time, although they are looking to engineer that in the coming future.
TRANSITION: Now that we have discussed ways in which ACD completes the VM mission lets see how the AFINC weapon system accomplishes the same tasks.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
AFINC Scanning
26 NOS CNDSP C&A
Responsible for conducting all audit scans and specialized scans on the 16 Air Force NIPRNet Gateways, 15 SIPRNet Gateways, and the Integrated Management System
Ensures all internal information systems that interact with gateway appliances are scanned as well
Reports findings to AMAC/DISA/USCYBERCOM
MP1: These scans are completed on a monthly basis just as the scans are on the rest of the enterprise. The IAO at the 26 NOS provides the findings internally to patch management for remediation and reports findings to AMAC, DISA and USCYBERCOM.
MP2: Self-explanatory.
MP3: Self-explanatory.
TRANSITION: Now that we have discussed ways in which AFINC completes the VM mission lets see how base assets augment the mission as well.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
NCC/Tier 3 VM Scanning 690th COG VM CONOPS
Responsible for maintaining situational awareness of VM posture while scans are being conducted
Assist CSCS in completion of vulnerability scans when access to some networks are limited
Manage the VM program for standalone enclaves
MP1: Self-explanatory
MP2: At some base locations there may be devices that are approved for the “exempted” scan list. This list is reserved for systems that are deemed mission critical where enterprise wide base scans will have an adverse reaction on its operation. NCC/Tier 3 VM Team will still be required to scan the device.
MP3: Enclaves that cannot be reached by enterprise VM tools will be managed by the NCC/Tier 3 VM team. They will scan the device and report their findings to CSCS to be upchanelled to DISA and USCYBERCOM.
TRANSITION: Lets review.
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Lesson Review
Part II Teaching Plan C-1507L Vulnerability Assessments
What is one reason why we conduct vulnerability management?
Answer:
Alter functionality or to address a new security threat, such as by updating an antivirus signature Vulnerability Management Guide
Question 1
REVIEW QUESTIONS
LO-1: Comprehend the process of conducting vulnerability management (B) MSB 1.1: Identify the purpose of vulnerability assessments (A)
<SLIDE BUILD>
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
After comparing the results of a recent monthly audit scan to a commercial vulnerability database you notice that many AFIN servers are configured to allow an attack to propagate unfettered. What order will need to be issued to ensure the systems have been appropriately hardened?
Answer:
TCNO
Question 2
LO-1: Comprehend the purpose of the Assured Compliance Assessment Solution (ACAS) (B) MSB 1.2Explain procedures used to complete a vulnerability assessment (B)
<SLIDE BUILD>
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
Which weapon system is responsible for conducting enterprise wide all audit scans on the AFIN?
Answer:
CSCS
Question 3
LO-2: Summarize the vulnerability assessment process conducted by AF assets (B) MSB 1.2: Explain the components of ACAS (B)
<SLIDE BUILD>
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
What scanning tool does the Enterprise Vulnerability Assessments team use to interrogate web servers?
Answer:
Acunetix 33 NWS Familiarization Guide Question 4
LO-2: Summarize the vulnerability assessment process conducted by AF assets (B) MSB 2.2: Explain the AF tools used to perform vulnerability scanning (B)
<SLIDE BUILD>
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments
QUESTIONS?
QUESTIONS: _________________________.
Part II Teaching Plan C-1507L Vulnerability Assessments
Lesson Summary Vulnerability Management Identification of New Vulnerabilities Vulnerability Notification Procedures Time Compliance Network Orders (TCNOs) Vulnerability Scanning
Summary (main points and questions)
Remotivation: The first step in Cyber Defense is inventorying the hardware and software that we have and then identifying the risks and vulnerabilities that exist for mitigation. This lesson covered the primary tools you will use in the field to assess vuls in AF systems.
Closure: See ya!
UNCLASSIFIED
UNCLASSIFIED
Part II Teaching Plan C-1507L Vulnerability Assessments image2.png image6.png image7.png image8.png image9.jpg image10.png image11.png image12.jpg image13.jpeg image14.png image15.png image3.png image1.png
File details come from the government source that posted it. Updated .