extending offensive actions towards external third parties, i.e. digital assets that are
physically or logically located out of the victim’s network perimeter.
Following this stage, obfuscation is being used to mask the activity and evade any
forensic analysis.
The Denial of Service Phase then stops the attack from being tracked or blocked by
disrupting the normal activity of the users and servers.
The last phase, exfiltration, represents the real and most important goal of the
attackers, especially when dealing with the most experienced and skilled among them. It
aims to remotely transfer different information and data through different exfiltration
techniques, which could range from simple to very complex, and often using dedicated
network infrastructures.
Once Lebanon has complied with basic Cyber Security standards and has applied this
Strategy, the Government and the National Cyber Security Information System
Agency (NCISA) shall be able to assess vulnerabilities; to alert with recommendations
on preventative measures against the main consequences; to identify threats; to respond
promptly and efficiently to attacks; and to maintain the Lebanese cyber environment
secure. Several tools and technologies can be used in order to create a functional cyber
deterrence framework. Before implementing them, however, it is mandatory to develop
defense-specific technical and judicial capabilities.
A commonly agreed upon definition of deterrence in Cyber Space involves two
elements: defense capabilities (deterrence by denial) and offensive capabilities (deterrence
by punishment). Defensive capabilities are here understood to be Cyber Defense, i.e. the
protection of a State's essential Information Systems (IS) and their ability to withstand
constant and varied attacks. On the other hand, under an ongoing attack, deterrence is
achieved by initiating the appropriate actions leading to stop the attack and to pursue the
offenders.
Another component of deterrence is Cyber Dissuasion which involves the threat of
retaliating with intolerable consequences in Cyber Space, designed to convince an
opponent not to attack in the first place. It is about putting enough force on display for
the purpose of eliminating the need of using it.
Developing defensive capabilities must follow the below course of actions:
Create an active Lebanese Cyber Defense Model, which must include best
practices and incorporate low-level and high-level technical actions, such as
blocks, filters, white and black lists, etc., against phishing attacks, malicious
domains and related command & control takedowns, malware-based attacks, 0day based attacks and exploitation frameworks, email spoofing, IP reputation
services, etc.
June 2019
LEBANON NATIONAL CYBER SECURITY STRATEGY
23