Project: Problem Identification
Segments of the network must be assessed, such as all local node connections in the LAN (e.g. local processes, local devices, local data storage), as well as other connections to the LAN (e.g. network gateways, WANs, wireless APs, network control resources, network databases, cloud integrations). The environment and architecture must justify the analysis of the coinciding threats. A few of the many network threats you could analyze (but are certainly not limited to) are DDS, session hijacking, parameter modification, server-side includes, addressing errors, message integrity, protocol flaws, reconnaissance, impersonation, wiretapping, malicious active code, connection flooding, man-in-the-middle, spoofing, misdelivery, redirection, and/or other transmission failures. The analysis in the latter example must identify any targets such as confidentiality, integrity, or availability and the coinciding vulnerability such as impersonation, protocol flaw, or misdelivery.
This is just an example given for a network security project and in no way limits the outcomes. The review of literature and detailed analysis of the system or application will determine the primary deliverables. Each requires objective justification for credit.
It is critical to identify the proper targets and vulnerabilities to ensure the final fault tolerant security design includes the appropriate correlated controls. For example, if the target is confidentiality, and the vulnerability is misdelivery, an appropriate control solution to design could be encryption. If the target is availability, and the target is a DNS attack, an appropriate control solution to design could be an intrusion detection system (IDS), access control list, and honeypot.
II. Methodology (must be supported by relevant and current research from scholarly, peer-reviewed journals)
a. Approach(es) for the information security analyses and design
i. Organizational security structure
ii. System, computing, network, or application architecture
iii. Security models that will be utilized
b. How the data will be gathered to objectively analyze the solution
i. System evaluation method
c. Limitations of the analysis
i. Security threats and risks inside the scope that need to be addressed
ii. Security threats and risks outside the scope
III. Synthesis review of literature to support analysis decisions
a. Analysis of the proper solution
i. Targets of the attack