CyOFTS_II,_Section_L,_Attachment_3_Pt_IV.docx
DOCX document 1 MB Posted
- Attached to
- Solicitation Notice Federal contract opportunity
- Solicitation number
- FA8773-17-R-8005
About this file
Part IV- Student Guide
View the file
Other files for this federal contract opportunity
Show all 50
Solicitation Notice has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED
UNCLASSIFIED
Vulnerability Management C-1507L
Student Guide
16 June 2016
This Page Intentionally Left Blank
Table of Contents
| C-1507L Vulnerability Management | 5 |
| F3VA | 7 |
| Identification and Notification | 9 |
| Vulnerability Scanning | 10 |
| Summary | 13 |
Acronym List…………………………………………………………………………………….14
This Page Intentionally Left Blank
C-1507L Vulnerability Management
SECTION I – OVERVIEW
LESSON OBJECTIVES:
LO 1 Comprehend the process of conducting vulnerability management (VM) (B) MSB 1.1 Identify the purpose of vulnerability assessments (A) MSB 1.2 Explain procedures used to complete a vulnerability assessment (B)
LO 2 Comprehend the vulnerability assessment process conducted by AF assets (B) MSB 2.1 Identify the organizations who resolve vulnerability scans (B) MSB 2.2 Explain the AF tools used to perform vulnerability scanning (B)
STUDENT PREPARATION/READING ASSIGNMENTS: Students should read all pages in this student guide. Additional reading from the reference material will enhance understanding of the material contained in this student guide.
REFERENCES:
\\FTEV-FS-IOS1V\courseware\CDCO\References (NIPR)
1. NIST 800-53 rev 4 Security and Privacy Controls for Federal Information Systems and Organizations
2. DoD 8500.01 Cybersecurity
3. MPTO 00-33D-2001 Enterprise Service Unit Functions
4. 33 NWS Familiarization Course Handbook
5. Cybersecurity Vulnerability Scanning and Reporting DISA
6. MPTO 00-33A-1109-WA-1 AFIN Vulnerability Management
7. 690th COG Vulnerability Management Concept of Operations
SECTION II – STUDENT OUTLINE
INTRODUCTION
Vulnerability Management (VM) is an on-going cyclical process of identifying, classifying, remediating, and mitigating vulnerabilities, which incorporates security procedures designed to proactively prevent the exploitation of Information Technology vulnerabilities within an organization. Controlling authorities will establish and proactively manage VM programs in order to prevent potential exploitation while adopting a methodology of active involvement that reduces system interruptions while contributing to readiness and overall mission success.
Two types of vulnerabilities exist: known and new. Known vulnerabilities are those that have been previously identified and validated by an official source and have a mechanism available to prevent them (e.g., patch, hot fix or work-around). New vulnerabilities are those that were previously unknown and for which no mechanisms are available to prevent them.
LO 1 Comprehend the process of conducting vulnerability management
The purpose of vulnerability assessments are to improve the security posture of the Air Force Information Network (AFIN), Air Force information systems, and stand-alone computing devices through rapid positive identification and notification in order to mitigate network and information system vulnerabilities. Timely, accurate vulnerability reports are crucial to the success of mitigating the threats posed by identified vulnerabilities.
Organizations conduct vulnerability assessments because they improve security in the following ways:
· Fix faults in the software affecting security, performance or functionality
· Alter functionality or address a new security threat, such as by updating an antivirus signature
· Change a software configuration to make it less susceptible to attack
· Use most effective means to thwart attacks by automated malware
A majority of the previously stated objectives for vulnerability management are race conditions where the network operations information assurance team is in a constant state of battle. The team has to make sure that systems on their terrain have been updated and patched to the appropriate level before the adversary can take action against a known or unknown vulnerability.
It is paramount that these team members not leave it to the vulnerability management system to do all the work in discovering known and unknown vulnerabilities. For unknown vulnerabilities it is important that team members have a process in place that weighs the risk of what is critical on their terrain to the intelligence reporting on what the adversary is most likely going after. For known vulnerabilities the team members will need to leverage their enterprise vulnerability management system in conjunction with the vulnerability management cycle.
FIND
FIX
FINISH
VALIDATE
ANALYZE
F VA
FIND
-ACAS/Retina
-HBSS
-DCM
-Users -Other Creation of potential target lists
FIX
Conduct analysis of raw data into prioritized actionable intelligence utilizing Cyber Readiness brief template.
FINISH
Execution of remediation action by tasked finishing force AMAC Tasked NOS -Patch
-GPO
-Script -Manual change -Other
VALIDATE
<DCTC CELL>
-Loopback to “FIND” source -Verify target remediated “Battle Damage Assessment” If target persists --Re-attack or --Pass to Problem Management
ANALYZE
-Root Cause Analysis -Effectiveness of remediation assessment -Lessons Learned -Proactive prevention steps <Proposed at AMAC>
Figure 1. F3VA Process
Find – In the Find phase, raw sensor data is collected from all possible sources – a dynamic list. Primary sources include System Center Configuration Management (SCCM), Desired Configuration Manager (DCM), and Assured Compliance Assessment Solution (ACAS). The official reporting source of record is ACAS scan data.
Fix – The Fix phase entails analysis of raw sensor data. The more effectively this phase executes, the more wisely overall resources are expended in characterizing and engaging identified problem sets. Personnel performing Cyberspace Surety actions will review the data to determine the cause of anomalies, the appearance of normal trends and which events correlate with the data provided to explain the reports. The Fix phase uses the raw data and applies it into the template of the Cyberspace Readiness Briefing to display standardized information for decisions and action.
Finish – In this phase, actions on the target objectives are accomplished and effects are created. Finishing forces may be any personnel with the ability to remediate the issue (PMO FSA, base CSTs, base infrastructure, etc.). Remediation methods include Group Policy Objects, scripts, manual patching, re-imaging, port blocking for disconnection, and more.
Validate – The Validate phase is operational assessment. The finishing force believes the mission was accomplished and the DCTC must now validate vulnerabilities were remediated. This generally involves a re-scan using ACAS. Whether the issue is STIG compliance, patch configuration, or is physical in nature, re-scan constitutes the outside validation to ensure creation of desired effects. Feedback is then returned to the tasking organization for sortie closure. If validation is incomplete, then a re-attack mission is generated.
Analysis – In the Analysis phase, a determination is made concerning why vulnerabilities are not remediated with organic automated means. This analysis helps prevent repeat problems and vulnerabilities. The Analysis phase occurs where the most enterprise data is available for understanding large scale trends and enterprise level issues. The AMAC conducts vulnerability management analysis actions for the tactical units at an enterprise level. The wing/base, NOS and COS have smaller Analysis functions, scaled for their AOR, to improve their F3VA processes. The F3VA process allows for the fastest return to service while the Analysis phase allows for longer term problem solving in an ITIL construct.
Figure 2. Vulnerability Management Cycle
Vulnerability Identification & Notification involves using a system or checklist in the detection of new weaknesses across your infrastructure and who should be alerted when found. Many times the system used to discover flaws will need to re-accomplish the scanning of the infrastructure due to unforeseen circumstances. Scanning allows the VM team to determine if an identified vulnerability exists on the AFIN. It is important that the scanning of the AFIN is reported to those organizations that are conducting computer network defense support operations so that scans are not mistaken for probes of our network by the adversary. Also scanning should be done in accordance to mission systems still having network access for completion of automated and manual tasks. Remediation & Mitigation are the goals of the VM process. Timely identification of the vulnerabilities within our network will lead to the mitigation of them that much faster. Reporting is how we track the compliance of organizations to remediate weaknesses across our network. Some programs may be exempt from the normal scanning and patching process but that doesn’t mean that their system owners are not liable for the vulnerabilities identified in their systems. Finally, vulnerabilities that cannot be remediated must have a Plan of Actions & Milestones (POA&M) in place to state when it will be remediated.
Identification and Notification
Newly discovered vulnerabilities for which no risk mitigation procedure has been established must be reported via operational reporting chains (e.g., User to Client Support Technician (CST), CST/Functional System Administrator (FSA) to Communications Focal Point (CFP), and CFP to servicing Network Operations Squadron (NOS)). The servicing NOS will forward to the 33 NWS with a courtesy copy to 624 OC. The CFP is responsible to inform local Information Assurance (IA) managers of newly discovered vulnerabilities.
The 33 NWS validates that the vulnerability has not been previously identified and an order to remediate has not been released. The 33 NWS may develop mitigation strategies to immediately protect against exploitation.
If the newly discovered vulnerability was exploited or an actual incident is suspected, follow the incident handling procedures in CJCSM 6510. For vulnerabilities identified or caused by network configurations directed by 624 OC or DOD guidance (e.g. STIG), follow the operational reporting chain to notify the distributing organization and 624 OC.
The 624 OC (690th AMAC) releases orders via AFNet OPS Compliance Tracker (ACT) in accordance with AFI 10-1701, Command and Control (C2) of the Air Force-Global Information Grid (AF-GIG), to direct the remediation and/or mitigation of vulnerabilities that affect the AF-GIG. Three primary orders are issued to address vulnerabilities (in order of criticality): CCOs, Time Compliance Network Order (TCNO), and Maintenance Tasking Orders (MTO). In addition, 624 OC may release informational reports, such as the C-4 NOTAM, Friendly Forced Information Requirements (FFIR) and Commander’s Critical Information Requirements (CCIR). These reports disseminate information on vulnerabilities for which no mechanisms to prevent exploitation are yet available.
The 33 NWS receives information on vulnerabilities from numerous sources; assesses the threat to AF systems; drafts a TCNO (common on the CTO) or a Command, Control, Communications, and Computer Notice to Airmen (C4-NOTAM) and sends to the Integrated-Network Operations and Security Centers (I-NOSC) and 624 OC for pre-coordination.
The 624 OC assigns a TCNO priority based on an assessment of the scope and potential impact of the vulnerability to the AF-GIG and supported operations and, where applicable, to comply with USCYBERCOM implementation and reporting requirements.
| Priority |
| Description |
| Critical |
| Widespread and imminent/ongoing threat to the AF-GIG and supported operations. |
| Serious |
| Widespread threat to the AF-GIG and supported operations is expected. |
| Medium |
| Threat to the AG-GIG is possible but may be mitigated by such factors as difficulty of exploitation, limited deployment of vulnerable operating system, etc. |
Figure 3. TCNO Priority Categories
Scanning
The practice of vulnerability scanning is an information gathering process for identifying known vulnerabilities of computing resources on a computer network. By DoD and AF policy and directive, all AF networks must be scanned for known vulnerabilities on a monthly basis.
Before performing a cybersecurity vulnerability scan, it is important to understand the objective of the scan. By understanding the objective of the cybersecurity vulnerability scan, the Scan Content Assessor (SCA), individual conducting the scan, will be able to ensure that the preliminary information required to perform the scan is received, as well as being able to establish a plan for performing a scan that will provide the desired output for reporting purposes. The majority of scans fall into one of the following categories:
· Command Cyber Readiness Inspection (CCRI) Scan- Used to perform a cybersecurity vulnerability scan for a site or Program of Record (POR) in order to validate compliance readiness. The results of the scan will be used to report the site compliance status and provide the site with results in order to mitigate any deficiencies.
· Certification & Accreditation (C&A) Scan- Used to perform a cybersecurity vulnerability scan for a site or POR that will be utilized to generate a recommendation for C&A. The results of the scans can be used to conduct a risk assessment for the site or asset that will be included in the C&A package.
· Cyberspace Security Provider (CNDSP) Scan- Used to perform an external cybersecurity vulnerability scan to test a site’s perimeter security and determine the potential security vulnerabilities that may exist. The results of this scan will be used to report a site’s vulnerability status and shared with the subscriber site for corrective actions to be taken.
As you can probably imagine most of the scans we conduct using AF cyber weapon systems are for CCRIs and CNDSP scans. These scans involve both time and effort on the squadron initiating the scans and those tasking them. Some of these scans can take as little as an hour to complete and some can take up to two weeks dependent on the scope of the scan needed.
In further preparing for a scan the SCA will need to determine the scope of the scan. If the scan is internally focused, they run against assets operating on a customer’s network inside a premise router. This may include remote offices connected via Wide Area Network (WAN) links, providing intranet connectivity, if those links are inside the perimeter or the point of demarcation of the site being evaluated. Internal scans are performed on both the NIPRNet and Secure Internet Protocol Router Network (SIPRNet) to query systems utilizing predefined audits to examine a system’s security compliance. These scans are usually credentialed scans to allow internal access to the system to obtain detailed information concerning the configuration and compliance validation of the scanned system. If the scan is externally focused, scans are conducted by remote scanning teams and consist of scans on assets inside a customer’s premise router from an Internet Protocol (IP) source address outside the customer’s network. These scans are most commonly non-credentialed scans which are port scans of networks and assets (like public facing webservers) to determine potential security weaknesses which could be exploitable from the outside.
Finally the SCA will make sure they have correctly identified the key terrain upon which the scan will take place, the system conducting the scan, and a memorandum in place giving them the authority to scan.
LO 2 Summarize vulnerability assessment process conduct by AF assets
Figure 4. Vulnerability Scans
Cyber Security and Control System (CSCS) will resolve scheduled monthly vulnerability scans of all devices connected to the AFIN on both NIPRNET and SIPRNET. All IP addressable devices are eligible for scanning to include, but not limited to servers, routers, switches, firewalls, printers, workstations, and access points. CSCS and associated Detachments will coordinate within their Area of Responsibility (AOR) to identify IP addresses that must be exempt from scanning for various reasons such as mission impact and utilization overload caused by the scan.
All vulnerability scan results will be uploaded into the appropriate instance of DISA’s Vulnerability Management System (VMS) and notification sent to the local site POC for distribution to appropriate remediation teams and to 24 AF/A3 for compliance validation. CSCS will coordinate with local site personnel as to how information gathered during the scan is to be stored in the VMS database. Vulnerability scan results for both NIPRNET and SIPRNET assets must be kept for a minimum of 90 days to maintain a historical record.
Network vulnerability scans of assets residing in the Demilitarized Zone (DMZ) (e.g., assets operating outside of the CSCS controlled firewalls) will be conducted monthly by the Air Force Cyber Defense (ACD), and findings will be provided to the applicable CSCS organization via the ACD SIPRNET Enterprise Vulnerability Assessment website. CSCS and NOS Detachments will review the reports, identify appropriate organization(s) for corrective actions to include timelines and mitigations, and submit the vulnerability reports to the applicable Tier 3 location (CFPs/PMOs) for action within 48 hours of receipt.
In addition to utilizing the DMZ whitelist (maintained by 26 NOS), ACD resolves a discovery scan, IPs are sought out and recorded. The recorded IPs become the target IPs for the vulnerability scan phase. The two types of discovery scans are: web-server and network server. During the web server discovery scans, the IPs recorded are AFIN websites. IPs are not exclusive to a discovery method, some IPs are web servers and network servers based on DMZ whitelisting. Across all MAJCOM IP ranges, approximately 9.3 million AF IPs are scanned each month for servers during the discovery phase. Approximately 50K IPs will be discovered and then scanned for vulnerabilities each month.
Web server scanning is conducted with COTS tool named Acunetix, which provides in-depth vulnerability scanning of web-servers and includes verification tools that give Vulnerability Assessments the capability to validate its vulnerability findings. Network scans are conducted using the Nessus scanner component of Assured Compliance Assessment Solution (ACAS), which is the DoD replacement for eEye Retina for conducting vulnerability and compliance scanning.
Figure 5. Acunetix Interface
AFINC resolves all audit scans and specialized scans on the 16 Air Force NIPRNet Gateways, 15 SIPRNet Gateways, and the Integrated Management System (IMS). They ensure that all of the systems that are reporting to IMS for centralized services have a manageable security posture. In the past they used Retina to satisfy this requirement but like CSCS have migrated to using ACAS.
Lastly, some base locations may have devices that are approved for the “exempted” scan list. This list is reserved for systems that are deemed mission critical where enterprise wide scans could have an adverse reaction on their operation. NCC/Tier 3 VM Team will still be required to scan the device. PMO systems also fall into this category and require their system owners to deploy local scans against their systems using the same information assurance alert and bulletins.
Summary The practice of vulnerability management is extremely important because it allows us to further standardize and baseline our networks. If we can’t identify known exposures to our network and remediate them using an automated process how we will ever be able to identify the APT who uses non-traditional means and at times zero-day attacks.
ACRONYM LIST
ACAS: Assured Compliance Assessment Solution ACD: Air Force Cyber Defense ACT: Air Force Network Operations Compliance Tracker AMAC: Air Force Information Network Mission Assurance Center AF-GIG: Air Force Global Information Grid AFIN: Air Force Information Network AFTO: Air Force Technical Order AOR: Area of Responsibility C2: Command and Control C4 NOTAM: Command, Control, Communications and Computers Notice to Airmen CAB: Change Advisory Board CCB: Configuration Control Board CC/S/A: Combatant Command, Service, and Agency CERT: Computer Emergency Response Team CFP: Communications Focal Point CND: Computer Network Defense CPE: Common Platform Enumeration CSCS: Cyber Security and Control System CTO: Communications Tasking Order CVE: Common Vulnerabilities & Exposures DISA: Defense Information Systems Agency FDCC: Federal Desktop Core Configuration FRAGO: Fragmentary Order GATES: Global Air Transport Execution System GSU: Geographically Separated Unit HBSS: Host Base Security System IA: Information Assurance IP: Internet Protocol MAJCOM: Major Command MP: Mission Partner MPTO: Methods and Procedures Technical Order MTO: Maintenance Tasking Orders NVD: National Vulnerability Database PA: Policy Auditor POA&M: Plan of Action and Milestones PVS: Passive Vulnerability System RAP: Run Advertised Programs RMF: Risk Management Framework SCAP: Security Content Automation Protocol SCCM: System Center Configuration Management SMB: Server Message Block STIG: Security Technical Implementation Guides SQL: Structured Query Language TCNO: Time Compliance Network Order VM: Vulnerability Management
UNCLASSIFIED
UNCLASSIFIED C-1507L 14
image3.jpeg image4.png image1.png image2.png
File details come from the government source that posted it. Updated .