Attach 28_Compare Doc.pdf
PDF 749 KB Posted
- Attached to
- National Cyber Range Complex Event Planning, Operations and Support Federal contract opportunity
- Solicitation number
- W900KK-20-R-0011
About this file
This document provides a sample training event scenario and related federal contract opportunity. The sample scenario outlines a proposed one-week cybersecurity training event for Army National Guard blue teams, focusing on incident response, digital forensics, vulnerability analysis, and system hardening. The event objectives, network topology, and red team techniques are to be detailed in an event support plan. The related federal contract opportunity is solicitation number W900KK-20-R-0011 for National Cyber Range Complex event planning, operations, and support services. Key dates include a February 2020 solicitation release, March 2020 question submission and pre-proposal conference, and April 2020 proposal submission with contract award planned for December 2020. The Army Materiel Command Contracting Command Orlando Contracting Center is the issuing agency.
View the file
Other files for this federal contract opportunity
Show all 50
National Cyber Range Complex Event Planning, Operations and Support has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 28 Solicitation #: W900KK-20-R-0011 Rev Date: 7 Feb27 Mar 2020
Sample Training Event Scenario Page 1 of 4
National Cyber Range Complex Event Planning, Operations, and Maintenance
(NCRC EPOS)
Sample Training Event Scenario
I. Event Overview The US Army National Guard (ARNG) contacts the Test Resource Management Center (TRMC) and requests support for an upcoming, intermediate-sized,1, one week cybersecurity training event. The training event will focus on “Blue Team” operations training, which shall include assessing the following skill areas:
Cyber Incident Response Digital Forensic Analysis & Basic Malware Analysis System and Network Vulnerability Analysis
System and Network Hardening/Vulnerability Remediation
The prompt that will be briefed to the training participants on Day 1 of the event reads as follows:
“ARNG Blue Teams are dispatched in response to a possible cyber intrusion at a major maritime port in the Continental United States. The Blue Teams’ mission is to augment the port’s Network Security and Information Technology (IT) teams to assist in the intrusion incident response and investigation and to remediate any vulnerabilities discovered during the investigation.”
ARNG will supply “White Team” personnel to assess the Blue Teams’ performance against their training objectives. The NCRC shall supply “Red Team” personnel that shall execute offensive cyber operations at multiple levels of sophistication (i.e. Low level/”Script Kiddie” and Nation-State level/Advanced Persistent Threat). Further, the NCRC shall supply the entirety of the training event’s network topology to include virtualized workstations, servers, and routers, as well as physical Industrial Control Systems (ICS)/ Supervisory Control and Data Acquisition (SCADA) devices that shall be made accessible to the virtualized hosts.
II. Event Objectives ARNG has identified the following training objectives for each of the given Blue Team skill areas:
Cyber Incident Response
1. Perform volatile memory capture and hard drive imaging from selected endpoint systems.
1 The reference to intermediate-sized event here is the same as the medium sized training event described in attachment
Sample Training Event Scenario Page 2 of 4
2. Deploy a virtual network security device (e.g. virtual machine running Bro, SNORT, Security Onion) to capture and analyze network traffic.
Digital Forensic Analysis & Basic Malware Analysis
1. Analyze SYSLOG files from Linux servers.
2. Analyze Event Logs and Registry entries from Windows servers and workstations.
3. Conduct volatile memory forensics on the captured volatile memory dumps.
System and Network Vulnerability Analysis
1. Conduct network port scans from within the enterprise network.
2. Conduct system vulnerability scans from within the enterprise network.
System and Network Hardening/Vulnerability Remediation
1. Manipulate network and host firewall rules to block suspicious traffic.
2. Disable unnecessary services and user accounts across the enterprise.
3. Restrict access control for critical systems to specific users (i.e. audit and enforce least privilege).
At a minimum, the maritime port’s network shall comprise a Corporate Demilitarized Zone (DMZ), an Enterprise Server Local Area Network (LAN), a user/workstation LAN, a Network & Security Administration (ADMIN) LAN, and an ICS Network (controls the ashore systems responsible for fueling ships).
The maritime port’s network services shall include— but not be limited to— the following:
Domain Name System (DNS) (external and internal resolution) External corporate web server connecting to a sales/shipping database Internal Human Resources Department web server connecting to a personnel database Virtual Private Network (VPN) for remote and teleworking users Microsoft Active Directory Microsoft Exchange Dynamic Host Configuration Protocol (DHCP)
File and Print Services
The overall event network topology shall include a high-fidelity, simulated Internet “gray space” to which the maritime port’s network is connected via (virtualized) commercial perimeter router. Further, the overall event network topology shall include a “red space” network from which the Red Team will operate. The red space network shall be connected to the Internet gray space in a realistic manner, and the maritime port’s external network interface shall be reachable from the red space.
Sample Training Event Scenario Page 3 of 4
The ARNG, acting as the event sponsor, has provided the following notional architecture diagram:
Finally, the network shall appear to the training participants as though it is currently being used by the maritime port’s personnel, as normal business operations have not ceased during the investigation.
III. Training Event Planning Based on the aforementioned information, address the following items:
1. Describe the analysis methodology and approach that will be applied to scope, plan, design and execute the training environment.
2. Develop an Event Support Plan using Attachment 30 (Event Support Plan template) that includes, but is not limited to:
Specification of the event objectives, A detailed network topology suitable for design of the event environment, Range instrumentation details relevant to the event objectives.
3. The Event Support Plan shall include the offensive cyber operations techniques the Red Team will apply to allow the White Team to evaluate Blue Team performance.
Sample Training Event Scenario Page 4 of 4
4. Describe the post-event activities that will be executed at the conclusion of the event execution.
5. Describe any customized content capabilities (e.g. traffic generation, web sites, Tactic, Techniques, and Procedures [TTP’s] etc.) required to conduct this event in a closed-loop, cyber range environment.
6. Describe how the capabilities developed for the environment will be managed following completion of the event.
File details come from the government source that posted it. Updated .