-
Objectives
- Pick a date
-
Choose Objectives
- Interdependencies: Examine network interdependencies during a cyber disruption
- Cyber Response Plan: Assess the sufficiency of response plans, policies and procedures
- Public / Private Relationships: Examine public / private sector relationships during a cyber disruption
- Allocation of Resources: Assess the allocation of limited technical resources during a cyber disruption
- Communications: Identify communication challenges and paths among organizations
-
Participants
-
Emergency Services
-
Computer aided dispatch (CAD) attack
- Automated Vehicle Location system fails
- CAD server infected with rootkit
- Police dispatch wondering if CAD is trustworthy
-
EOC data corruption
- Numerous event reports in EOC data system cannot be validated
- Event reports are not real, EOC requesting guidance
- Vendor identifies EOC software vulnerability
-
Law Enforcement
-
Criminal database corruption
- CJIS queries not responding
- Officers report responses to IAFIS queries are wrong
- CJIS back on line, police chief requests briefing
-
Offender registry corruption
- Media reports that Mayor and Legislators have been mistakenly included in offender registry
- Sex crime registry contains the names of many public figures
- Mayor's office requests briefing by IT department
-
Cyber crime criminal investigation
- Cybercrime unit asked to investigate fraud complaint at City IT
- Phishing scam - site pretending to be City tax collection web site is based in Europe
- Citizens call City Help Desk concerned that their SSNs have been compromised
-
Government IT
-
Government website defacement
- Citizen complaints about website
- Website corruption confirmed, enabled by unauthorized external access
- Executive office asks for damage assessment
-
Taxpayer data exfiltration
- Credit card processing interruption
- Taxpayer SSN data posted on website in Eastern Europe
- Media inquiry about possibility of identity theft
-
DMV records
- Help Desk calls from Law Enforcement reporting large call volume of revoked licences
- DMV confirms database corruption
- Recovery plan
-
Public Utilities / Manufacturing
-
SCADA worm
- CERT report of a new control system worm like Sxutnet
- Local utilities and manufacturing are infected with the worm
- Worm signature and payload identified
-
Insider threat to control systems
- Power substation failure
- Utility employee arrested for software sabotage
- Media inquiry into insider threat
-
Health Care
-
Patient data disclosure
- Three identify theft cases have been traced to leaking hospital records
- A total of 2000 patient records were illegally disclosed from a hospital server
- Hospital CEO requests HIPAA impact statement
-
Prescription database availability
- Hospital prescription database is down
- Pharmacy says hundreds of prescription records have been deleted, rootkit found on server
- Can records be trusted after intrusion
-
Banking / Finance
-
ATM fraud
- Bank customers complain that ATMs are out of cash
- FBI calls asking for forensic data involving fraudulent cards
- Investigation shows that in less than one hour 30 ATMs were accessed using fraudulent cards
-
Account transfer failure
- Escrow company complains that it is missing $400K due to unauthorized bank transfers
- Bank employee admits to opening email claiming to be a shipping receipt. IT says it was a Trojan.
- Escrow company wants to know what kind of security improvements will be made
-
Telecommunications
-
DNS poisoning
- Customers complain about phishing scam involving Federal Tax refunds
- Phishing scam linked to DNS attack
- DNS servers have been poisoned
-
Botnet
- Customers request blocking port 6667
- Bot armies discovered in college campuses served by local ISP
- DDOS attack against US government sites
-
Transportation
-
Control systems corruption
- Traffic informations signs post unauthorized messages
- Rail signals inoperative
- Governor's office concerned about rail safety after attacks
-
Bus / train scheduling system
- Customers complain that bus schedule page is not available
- Transit schedule page defaced
- Transit employee names leaked on website