Cybersecurity guide for developing countries Figure II.6 – Typical phases in a cyberattack Figure IV.1: Phases caractéristiques du déroulement d’une attaque Social phase Phaseengineering de social engineering Phase 4 Phase 1 Retreat Exfiltration Collecte d’informations Information collection Recherche de vulnérabilités Search for vulnerabilities Savoir-faire et exploitation Skills and exploitation des informations ofrecueillies known weaknesses et des failles Intrusion Phase 2 Technical faults, Failles technologiques, faults,de dedesign conception, configuration faults, configuration, etc.etc. Spoofing Leurres Passwordde Usurpation mots theft de passe Phase 3 Devisingd’une the attack Création attaque Security Problèmes problems sécuritaires Direct and indirect losses Pertes directes et indirectes Hackers can also look for and exploit known – but not yet repaired (patched) – security vulnerabilities, using the available means (attack libraries, attack toolkits) to infiltrate the system. The retreat phase is intended to cover up the traces of the attack, and ensure that such traces as are left do not allow the hacker to be identified. Hackers increase their anonymity by using aliases, usurping legitimate users’ identities, or covering their tracks by means of multiple intermediate (relay) systems. Cyberattacks 47

Select target paragraph3