Cybersecurity guide for developing countries
Figure II.6 – Typical phases in a cyberattack
Figure IV.1: Phases caractéristiques du déroulement d’une attaque
Social
phase
Phaseengineering
de social engineering
Phase 4
Phase 1
Retreat
Exfiltration
Collecte d’informations
Information
collection
Recherche
de vulnérabilités
Search
for vulnerabilities
Savoir-faire et exploitation
Skills
and exploitation
des informations
ofrecueillies
known weaknesses
et des failles
Intrusion
Phase 2
Technical faults,
Failles technologiques,
faults,de
dedesign
conception,
configuration
faults,
configuration,
etc.etc.
Spoofing
Leurres
Passwordde
Usurpation
mots theft
de passe
Phase 3
Devisingd’une
the attack
Création
attaque
Security
Problèmes
problems
sécuritaires
Direct and indirect losses
Pertes directes et indirectes
Hackers can also look for and exploit known – but not yet repaired (patched) – security vulnerabilities,
using the available means (attack libraries, attack toolkits) to infiltrate the system. The retreat phase is
intended to cover up the traces of the attack, and ensure that such traces as are left do not allow the
hacker to be identified. Hackers increase their anonymity by using aliases, usurping legitimate users’
identities, or covering their tracks by means of multiple intermediate (relay) systems.
Cyberattacks
47