Name the attack from the log line

short · 35 min · Objective 2.5

Task

Build a reference card that maps log evidence to attack names, then test it against synthetic log lines you generate. This is the exact skill objective 4.8 will drill when you read logs in an investigation, and building the card yourself is what makes it stick.

Steps

  1. Write /tmp/indicators.csv with the columns evidence,attack,layer,first_control, and fill at least twelve rows using these attack names: spraying, brute force, directory traversal, sql injection, buffer overflow, ssrf, dns tunnelling, cache poisoning, protocol downgrade, arp poisoning, reflected ddos, tailgating, privilege escalation.
  2. Now write /tmp/samples.log: one synthetic log line for each row, in the format that log source would really use -- an access log, a DNS log, an auth log, a door controller. Do not label them.
  3. Shuffle the file and set it aside for an hour, or a day.
  4. Come back and classify each line, writing your answers to /tmp/answers.csv as line_number,attack.
  5. Score yourself against the original mapping and record which ones you got wrong.
  6. For every mistake, write the distinguishing feature you missed into /tmp/missed.md -- the rate, direction, character class, group membership or count that was the anomaly. Those are your revision list.

Verify

awk -F, 'NR>1 && NF>=4 {n++} END {print n" indicator row(s)"}' /tmp/indicators.csv
wc -l < /tmp/samples.log
python3 - <<'PY'
import csv
ind=list(csv.DictReader(open('/tmp/indicators.csv')))
attacks=[r['attack'].strip().lower() for r in ind]
assert len(set(attacks))==len(attacks), 'two rows name the same attack'
assert len(attacks)>=12, 'fewer than twelve indicators'
missing={'spraying','ssrf','directory traversal','protocol downgrade'} - set(attacks)
print('rows:',len(attacks),'| missing key attacks:',missing or 'none')
assert not missing, 'the four most-tested indicators must all be present'
PY

The assertions require twelve distinct attacks including four that appear most often, so the card cannot be padded with variations of the same thing. The scoring step has no command because it is the part only you can do -- and the file that matters afterwards is /tmp/missed.md, not the score.

Notes

The delay in step 3 is deliberate and it is the only part of this lab people skip. Classifying lines you wrote ten minutes ago tests your memory of writing them; classifying them tomorrow tests what the exam will test.

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.