extending offensive actions towards external third parties, i.e. digital assets that are physically or logically located out of the victim’s network perimeter. Following this stage, obfuscation is being used to mask the activity and evade any forensic analysis. The Denial of Service Phase then stops the attack from being tracked or blocked by disrupting the normal activity of the users and servers. The last phase, exfiltration, represents the real and most important goal of the attackers, especially when dealing with the most experienced and skilled among them. It aims to remotely transfer different information and data through different exfiltration techniques, which could range from simple to very complex, and often using dedicated network infrastructures. Once Lebanon has complied with basic Cyber Security standards and has applied this Strategy, the Government and the National Cyber Security Information System Agency (NCISA) shall be able to assess vulnerabilities; to alert with recommendations on preventative measures against the main consequences; to identify threats; to respond promptly and efficiently to attacks; and to maintain the Lebanese cyber environment secure. Several tools and technologies can be used in order to create a functional cyber deterrence framework. Before implementing them, however, it is mandatory to develop defense-specific technical and judicial capabilities. A commonly agreed upon definition of deterrence in Cyber Space involves two elements: defense capabilities (deterrence by denial) and offensive capabilities (deterrence by punishment). Defensive capabilities are here understood to be Cyber Defense, i.e. the protection of a State's essential Information Systems (IS) and their ability to withstand constant and varied attacks. On the other hand, under an ongoing attack, deterrence is achieved by initiating the appropriate actions leading to stop the attack and to pursue the offenders. Another component of deterrence is Cyber Dissuasion which involves the threat of retaliating with intolerable consequences in Cyber Space, designed to convince an opponent not to attack in the first place. It is about putting enough force on display for the purpose of eliminating the need of using it. Developing defensive capabilities must follow the below course of actions:  Create an active Lebanese Cyber Defense Model, which must include best practices and incorporate low-level and high-level technical actions, such as blocks, filters, white and black lists, etc., against phishing attacks, malicious domains and related command & control takedowns, malware-based attacks, 0day based attacks and exploitation frameworks, email spoofing, IP reputation services, etc. June 2019 LEBANON NATIONAL CYBER SECURITY STRATEGY 23

Select target paragraph3