Information security drill of Vietnam Academy of Science and Technology, theme: "Investigation and handling of information security incidents through application vulnerabilities"

05/01/2023
Implementing Directive 60/CT-BTTTT dated September 16, 2021 of the Ministry of Information and Communications on organizing the implementation of practical combat drills to ensure cyberinformation security, Decision 360/QD-VHL dated March 18, 2022, the President of the Vietnam Academy of Science and Technology (VAST) issued the plan to develop the Digital Government/Digital Government and ensure cyber security in 2022, on November 25, 2022, the Center for Informatics and Computing organized a practical information security training session of the Vietnam Academy of Science and Technology, with the topic "Investigating and dealing with information security incidents through application vulnerabilities" for information system operators and staff in charge of information technology at units under VAST. The drill takes place in two forms of live online.

Overview of the drill

The purpose of the drill is to: (1) Foster and improve knowledge of cyberinformation security for staff who manage and operate information systems of the VAST; (2) Help the incident response team, the cyberinformation security officers of the VAST promptly detect gaps in technology, people and processes, thereby improving high handling capacity, ensuring readiness to respond when incidents occur right on the operating system.

MSc. Pham Thanh Mai, Director of the Center for Informatics and Computing, gave the opening speech

During the drill, participants were divided into two teams: the Red Team from the 3rd party will participate in the attack on the rehearsal target; the Blue Team includes the system operator, members of the incident response team of the VAST. This force is tasked with monitoring, detecting and timely preventing attack actions by the Red Team.

The content of the drill is divided into 3 phases, including:

  • Stage 1 (Warning Phase): The monitoring team detects that application access is slow and stabilizes after a short period of time. This is the warning phase. At this stage, the attacker will perform small DDoS attacks to probe the system. The early warning detection system has detected anomalies of small DDoS attacks to provide prevention plans. In addition, with this stage, the monitoring team detects scans and tries to attack the system.
  • Stage 2 (Attacking phase): This is the stage when an attack occurs, exploits a security hole, and the system warnings related to the application appear. The internal incident response team analyzes, investigates and handles incidents, then assesses the level of impact.
  • Stage 3 (Treatment phase): Provide mitigation measures to limit the risks of information insecurity, and discuss the process of handling and responding to information security incidents.

At the drill, the staff operated the information system; Information technology officers at affiliated units were disseminated and trained on the types of attacks used, as well as the principles of compliance during actual combat exercises such as attack principles, defensive principles.

Some more pictures from the drill:

 

Translated by Phuong Huyen
Link to Vietnamese version



Tags:
Related news
ADVERTISMENTS
LINKS