Principles of Information Security (MindTap Course List)
Principles of Information Security (MindTap Course List)
6th Edition
ISBN: 9781337102063
Author: Michael E. Whitman, Herbert J. Mattord
Publisher: Cengage Learning
Expert Solution & Answer
Book Icon
Chapter 7, Problem 3CEDQ

Explanation of Solution

Miller’s hacking attempt:

  • Miller is required to attach tools such as fully explained network diagram of the SLS company with all the required files along with the access code that are required in attacking the network.
  • The attack is made to the network using client VPN (Virtual Private Network) and was identified that front door was closed.
  • Since, it is found closed doors at the front, the connection was tried to establish using a dial-up connection and it was again redirected to same authentication server that is used by the Virtual Private Network which made first attempt failure.
  • The next option that miller preferred is installing the Zombie program at the company’s extranet quality assurance server and this approach also directed towards the failure because of the firewall and control policies defined in it...

Blurred answer
Students have asked these similar questions
Discussion Questions Do you think Miller is out of options as he pursues his vendetta? If you think he could take additional actions in his effort to damage the SLS network, what are they? Suppose a system administrator at SLS read the details of this case. What steps should he or she take to improve the company's information security program? Consider Miller's hacking attempt in light of the intrusion kill chain described earlier and shown in Figure 7-1. At which phase in the kill chain has SLS countered his vendetta? Ethical Decision Making It seems obvious that Miller is breaking at least a few laws in his attempt at revenge. Suppose that when his scanning efforts had been detected, SLS not only added his IP address to the list of sites banned from connecting to the SLS network, the system also triggered a response to seek out his computer and delete key files on it to disable his operating system. Would such action by SLS be ethical? Do you think action would be legal? Suppose…
Consider a newsworthy authentication or access control breach. How did it influence everyday operations? Are there specific corporate losses?
“The Diamond Model of Intrusion Analysis Summarize the diamond model and how does each section work together? Do you feel that this module is effective? If not, what do you feel is missing?? How could this be used by cybersecurity teams in private organizations? How does the Diamond Model compare to the Kill Chain? Which do you feel is the most effective and why?
Knowledge Booster
Background pattern image
Similar questions
SEE MORE QUESTIONS
Recommended textbooks for you
Text book image
Principles of Information Security (MindTap Cours...
Computer Science
ISBN:9781337102063
Author:Michael E. Whitman, Herbert J. Mattord
Publisher:Cengage Learning