various devices and equipment connected to data networks have made a great impact on
daily life, on the economy, and on the functioning of the State. In addition, the Internet is
becoming increasingly accessible, the number of users continues to grow, and new
technological services and solutions such as Internet of Things (IoT), Industrial Internet
of Things (IIoT) and cloud services are on the rise. All the above result in a wider threat
landscape and in a growth of attack vectors that have increased complexity,
sophistication, and damages when successful.
The number of State Actors involved in Cyber Space and engaged in Cyber
Espionage activities targeting computers connected to the Internet as well as closed
networks continues to grow. This reality is due to the fact that collecting information on
national security as well as economic assets represents an important resource in the
regional and international arena. The number and activeness of Nations capable to
perform State-sponsored Cyber Attacks are increasing, posing unknown and unexpected
critical threats and risks to Lebanon.
In addition to the activeness of State actors, politically-motivated individuals and
groups with limited financial means have a growing ability to organize their activities
using social networks and carry out Denial of Service and other types of attacks.
Moreover, the recent but fast-growing diffusion and implementation of encryption
standards by governmental institutions and private companies – such as the SSL or the
SSH protocols, just to mention a couple – revealed an unexpected side effect: They
rendered real-time detection, post-incident analysis, defense, and investigation much
more complex. Under some specific circumstances and ICT architectures, such as very
large and complex data centers, it is becoming nearly impossible to perform real-time
detection successfully.
Nowadays, such scenarios are allowing different Threat Actors massively to exfiltrate
sensitive and critical information using the very same encryption protocols that the
victims use to enhance their Cyber Security.
Very often this causes previously used detection and data protection solutions, such
as DLP (Data Leakage Prevention), to fail in their core scope, usually greatly broadening
the so-called “attack window” and resulting in increased and long-lasting data breaches,
instead of the previously totally undetected, shorter breaches. The rapid evolution in the
profile and capabilities of attackers makes tracing and attributing the attack drastically
more complex.
1.4 Challenges
The main Cyber Security risks arise from the extensive and growing dependence on ICT
infrastructure and e-services by the Lebanese State, economy, and population.
June 2019
LEBANON NATIONAL CYBER SECURITY STRATEGY
15