3. Continuously grow State capacities to support the development of information and communication technologies; 4. Promote educational capacity on the Lebanese territory; 5. Promote industrial and technical capacity; 6. Support the export and internationalization of Cyber Security companies; 7. Strengthen collaboration between the public and the private sectors; 8. Promote the role of security and intelligence services and strengthen the mutual cooperation and coordination with the support and supervision of the higher authorities. It is only once the above Pillars are recognized and addressed that we can begin to develop a Cyber Security Strategy with clear objectives. 3.1 Defend, deter, and reinforce against threats The Lebanese State shall put in place a deterrence strategy in order to significantly reduce the number of Cyber Crimes. A deterrence strategy in Cyber Space refers to a set of actions designed to stop and identify attackers as they make their first malicious operations on the network, taking as a premise that after gaining access to a network, attackers always follow a predictable Cyber Kill Chain. The Cyber Kill Chain is distributed across eight phases: reconnaissance, intrusion, exploitation, privilege escalation, lateral movement, obfuscation, denial of service, and exfiltration. During the reconnaissance phase, the hacker will discover passively the Network in order to gather all the necessary information. It is absolutely vital to put in action proper deterrence technologies and tools in order to redirect the actions of the attackers in a controlled path, which will be easily handled by defenders. The intrusion phase is then launched based on the information discovered in the reconnaissance phase. The objective is to enter the system and gain access to the data it contains. The exploitation phase employs an active attack, where the hacker uses different types of vulnerabilities identified on the target victims in order to quickly exploit them, gaining remote or local access – as regular users or administrators. Attackers then use privilege escalation technique to get increased access to resources. The lateral movement phase aims to allow unauthorized access to internal servers and the data they store and manage. Sometimes such access can also enable attackers in June 2019 LEBANON NATIONAL CYBER SECURITY STRATEGY 22

Select target paragraph3