3. Continuously grow State capacities to support the development of
information and communication technologies;
4. Promote educational capacity on the Lebanese territory;
5. Promote industrial and technical capacity;
6. Support the export and internationalization of Cyber Security companies;
7. Strengthen collaboration between the public and the private sectors;
8. Promote the role of security and intelligence services and strengthen the
mutual cooperation and coordination with the support and supervision of
the higher authorities.
It is only once the above Pillars are recognized and addressed that we can begin to
develop a Cyber Security Strategy with clear objectives.
3.1 Defend, deter, and reinforce against threats
The Lebanese State shall put in place a deterrence strategy in order to significantly reduce
the number of Cyber Crimes. A deterrence strategy in Cyber Space refers to a set of
actions designed to stop and identify attackers as they make their first malicious
operations on the network, taking as a premise that after gaining access to a network,
attackers always follow a predictable Cyber Kill Chain.
The Cyber Kill Chain is distributed across eight phases: reconnaissance, intrusion,
exploitation, privilege escalation, lateral movement, obfuscation, denial of service, and
exfiltration.
During the reconnaissance phase, the hacker will discover passively the Network in
order to gather all the necessary information. It is absolutely vital to put in action proper
deterrence technologies and tools in order to redirect the actions of the attackers in a
controlled path, which will be easily handled by defenders.
The intrusion phase is then launched based on the information discovered in the
reconnaissance phase. The objective is to enter the system and gain access to the data it
contains.
The exploitation phase employs an active attack, where the hacker uses different types
of vulnerabilities identified on the target victims in order to quickly exploit them, gaining
remote or local access – as regular users or administrators.
Attackers then use privilege escalation technique to get increased access to resources.
The lateral movement phase aims to allow unauthorized access to internal servers and
the data they store and manage. Sometimes such access can also enable attackers in
June 2019
LEBANON NATIONAL CYBER SECURITY STRATEGY
22