Technical Article / Cybersecurity

HVV Cybersecurity Exercise: Detection Focus

This article discusses the detection side of a large-scale cybersecurity attack-and-defense exercise.

IT Knowledge Detection and hardening
HVV Cybersecurity Exercise: Detection Focus technical article image
Back to All Articles

Key takeaways

Start with three anchors, then read the full article

These points are derived from the current article sections. The complete technical material remains below.

01

Overall Security Remediation

An organization-wide remediation view—inventorying assets, identifying related risks and carrying out the corresponding work—can help teams conduct early security.

02

Asset Inventory

As the foundation of overall security, asset inventory should be comprehensive: its coverage directly affects whether subsequent risk checks are thorough.

03

Reduce Internet Exposure

The internet-facing perimeter is an entry point for traffic, a key target for adversaries to discover, and an important attack surface.

Security Dog

Beijing Yidengyi Technology Consulting Co., Ltd.

This article reflects material published in March 2021. Its vulnerability examples and recommendations are historical references, not a statement of current prevalence or current best practice. Validate exposure against a dated asset inventory, current vendor advisories and support lifecycles, approved testing, and the organization's current security policy.

The HVV exercise is a major national-level cybersecurity exercise that tests an organization's ability to protect its networks and information infrastructure, respond to incidents, and coordinate command and dispatch. Its purpose is to improve the overall defensive capability of information systems. A strong defense begins by remediating the organization's own weaknesses, using an organization-wide view.

This article reviews the detection topics and key points in the first, preparation phase of an HVV exercise and provides corresponding hardening recommendations.

01

Overall Security Remediation

An organization-wide remediation view—inventorying assets, identifying related risks and carrying out the corresponding work—can help teams conduct early security hardening in a comprehensive and orderly way, laying a solid foundation for the HVV exercise.

Technical diagram for the HVV cybersecurity exercise detection article

02

Asset Inventory

As the foundation of overall security, asset inventory should be comprehensive: its coverage directly affects whether subsequent risk checks are thorough. Review assets across internal and external networks, software and hardware, staffing, and security-management policies. Cross-check assets from multiple perspectives, following the principle of “check more rather than miss anything.” Categories may include internet-exposed assets, business assets, hardware assets, software assets and office assets.

Technical diagram for the HVV cybersecurity exercise detection article (Figure 2)

03

Reduce Internet Exposure

The internet-facing perimeter is an entry point for traffic, a key target for adversaries to discover, and an important attack surface. Reducing risk to internet-facing assets is therefore a major task for the blue team. Relevant risks include vulnerabilities in public-facing services such as official websites, apps and other application systems; exposed test environments; VPN systems; systems hosted in public clouds; and code shared in public repositories or file-sharing services such as GitHub and Baidu Netdisk.

Collect information about external-facing assets.

Discover subdomains.

Check for sensitive-information leaks.

Check for source-code leaks.

Fix issues found by vulnerability scanning and penetration testing at the code level.

Close external port mappings for test systems.

Close high-risk service ports and mapped addresses that are directly exposed to the internet.

Route all externally facing business services through security controls such as firewalls, web application firewalls (WAFs), intrusion detection and anti-malware gateways.

Upgrade VPN systems to the latest version, restrict access to their administrative pages to selected IP addresses, and require multi-factor authentication for VPN sign-in.

For systems whose issues cannot be fixed in code, shut down the system or remove its external mapping. If neither is possible, isolate it from other systems.

Apply security groups to public-cloud assets and use cloud security controls, such as cloud firewalls, together with host security software.

04

Patch Remediation

Patch review should start with a current inventory of operating systems, middleware, applications and externally reachable services. Check each finding against the affected product and version, the vendor's current advisory and support status, and the organization's authorized test results. The 2021 source material emphasized unpatched vulnerabilities, weak credentials and insufficient isolation; those categories remain useful prompts for assessment, but the old examples do not establish present-day exposure.

  • Review middleware and application components for known, version-specific vulnerabilities, including historical deserialization and file-read issues.
  • Check administrative interfaces and data services for unintended exposure or access without authorization.
  • Assess operating-system patch status and confirm that identified fixes have been installed and verified.
  • Review upload paths, validation and execution controls for risks that could allow an uploaded file to become executable.

05

Middleware and Third-Party Component Security

Middleware and third-party components can be missed during inventory and maintenance. The source's historical examples include Redis, ActiveMQ, Memcached, RabbitMQ, AppServ, XAMPP, BaoTa, PhpStudy, DedeCMS, ThinkPHP, PHPCMS, ECShop, MetInfo, Discuz!, Empire CMS, WordPress, Joomla and Drupal. Verify each product's current version, exposure and support status rather than assuming an old example is still applicable.

Common issues with these components include:

Default passwords or direct access without authorization.

Known vulnerabilities in outdated releases. The source cites historical examples such as ThinkPHP injection and file-operation issues, Apache ActiveMQ remote code execution (CVE-2020-13920), WordPress File Manager file upload, Apache Shiro authorization bypass (CVE-2020-13933), a PHPCMS v9 front-end remote-code-execution issue, and ThinkAdmin v6 arbitrary file read (CVE-2020-25540). These examples are dated; verify applicability and remediation in the relevant vendor advisories.

Administrative pages exposed directly to the internet.

Upgrade to a supported release after checking compatibility and the vendor's current guidance.

Change default or blank passwords.

Restrict access to these resources.

06

Application Systems

The main risks in application systems arise during the use of applications and software, particularly in networked environments. They include:

Application-system security weaknesses.

Unauthorized access to or alteration of data.

Unauthorized remote access.

Inaccurate information.

Erroneous or fabricated input.

Abuse by authorized end users.

Incomplete processing.

Duplicate data processing.

Delayed processing.

Communications-system failures.

Insufficient testing.

Classify application systems according to the importance of their business functions.

Scan all application systems for vulnerabilities and remediate the findings.

Conduct penetration tests on important systems and remediate the findings.

Restrict access to important systems that cannot yet be modified.

Temporarily take non-critical systems offline if their issues cannot yet be fixed.

07

Weak Passwords

Weak or reused credentials can expose administrative consoles and other systems to guessing, credential stuffing and unauthorized access. The source includes an old list of common passwords, but it should not be treated as a current prevalence ranking. A defensible review uses approved credential-assessment methods: inventory authentication paths and privileged accounts, check for default or blank credentials, review sign-in and lockout telemetry, confirm multi-factor authentication coverage, and compare password controls with current organizational policy without collecting clear-text passwords.

Use both technical controls and administrative measures. Set current requirements through the organization's approved policy and applicable guidance; the numerical thresholds in the 2021 source should not be reused as present-day defaults.

  • Use an approved password policy, block known-compromised or commonly guessed passwords where supported, and avoid storing or handling clear-text credentials.
  • Apply rate limits and appropriate lockout or step-up controls to repeated failed sign-ins; assess bot protections against current attack methods.
  • Require multi-factor authentication for privileged and remote access according to the current access-control policy.
  • Review credential-change and recovery workflows, password reuse protections, and account lifecycle processes as part of an authorized identity assessment.

  • Provide regular security-awareness guidance on phishing, password reuse and reporting suspected compromise.
  • Coordinate credential resets when an incident, exposure or approved policy change requires them, and verify that recovery channels are protected.

08

Network Devices

Many organizations have large, complex networks with ad hoc topologies. This can leave network and security devices without effective policy controls. Poorly managed policies may lead to device failures, lost configurations, unauthorized external or internal connections, east-west internet penetration, north-south lateral movement within the internal network, and risks from device zero-day vulnerabilities.

1. Draw a network topology that reflects current operations and maintain an asset register for network devices, including their connections, interface details and administrative credentials.

2. Back up configurations for network and security devices on a cadence based on change rate and recovery objectives, and test that the backup files are usable.

3. Telnet transmits data in clear text, so an attacker may obtain device passwords through ARP attacks or packet capture. Unless there is a special requirement, disable Telnet on network and security devices (port 23) and use the more secure SSH method for remote management.

4. Enable management-host restrictions on all network devices, including IoT devices, and security devices. Allow only trusted IP addresses to reach management ports such as 22, 80 and 443, including interfaces for video-conference systems, cameras and device sign-in.

5. Enable password-complexity rules, account lockout after repeated failed sign-ins, and session timeouts on network and security devices. Require two-factor authentication using two or more methods, such as one-time passwords, digital certificates, biometrics or device fingerprints.

6. Review the effectiveness of policies on all network and security devices regularly and assign permissions according to the principle of least privilege.

7. Bind IP and MAC addresses for network and security devices connected to the network to support reliable operation.

8. Optimize edge-firewall rules. Except for servers that must connect externally for business purposes, restrict other devices from accessing the internet and prohibit unsolicited outbound connections. Alert and investigate immediately if an outbound connection is detected; exceptions may be needed for special servers such as DNS or patch servers.

9. Remove redundant or invalid firewall access-control rules and minimize the access-control list. Place a rule near the top to block communication over high-risk ports commonly used by ransomware, including 135, 137, 138, 139 and 445. By default, controlled interfaces should deny all traffic other than explicitly allowed communication.

10. Remove redundant or invalid edge-firewall NAT rules and retain only the port mappings required by business services. Never map high-risk ports, such as management or database ports, to the internet. Where remote management is needed, prefer VPN, a dedicated line or a 4A access-management system to secure access.

11. Enable log auditing at network boundaries and important network nodes for privileged activity and significant security events so that actions and incidents can be traced. Set retention and access controls according to current policy, legal requirements and investigation needs.

12. Update security-device rule databases to the latest version so they can detect and block new attacks in a timely way and protect business services.

13. Maintain network- and security-device software within vendor support, review current advisories, and prioritize fixes using validated exposure and impact. The source describes zero-day findings from past exercises; those historical examples do not establish the current status of any device.

09

Network Segmentation and Security Zones

For historical reasons related to funding, network size and ease of management, security zones are often poorly designed. A single zone may mix traffic from multiple services, allowing an attack on one service to affect others. As the environment grows, this becomes a hidden risk. Administrators may spend significant effort just understanding traffic flows; staff changes can leave no one who understands the relationships between them, increasing future operations costs. When a failure occurs, troubleshooting can take a long time.

Requirements for network-security segmentation, combined with analysis of the service-layer relationships between application servers, have led to a new layered model for network-security zones. It describes a method of dividing zones using vertical layers and horizontal segments.

Several related definitions should be clarified when dividing security zones. Otherwise, concepts may be confused, leaving the resulting zones logically unclear, security policies ambiguous and defense in depth difficult to establish.

Common definitions used when dividing security zones include:

(1) Physical network zone

A physical network zone is a data-network area defined by a shared physical location, such as an office area, remote-office area or floor-level switching area.

(2) Network functional zone

A functional zone is a logical network area divided by function, such as an internet zone, production-network zone or office-network zone.

(3) Network security zone

A network security zone is an area in a network system whose assets have the same security requirements and protection level. A zone generally needs a unified security-management organization, protection framework and policies. Communication between different zones requires corresponding boundary-security policies.

(4) Network security layer

Using a layered analysis, network-security zones are organized into layers with different security levels. Each layer contains multiple zones of the same level, and zones within the same layer are logically or physically isolated from one another.

Organizations may understand zone design differently, but common design principles can still be used as a reference. Typical network segments include a DMZ, an internet-access zone, an internal office network, a server zone and a security-management center. Firewalls, security gateways, access-control lists (ACLs) and VLANs can provide logical or physical isolation between zones, forming a vertically layered and horizontally segmented network-security model.

When historical constraints make immediate physical segmentation of the entire environment impractical, microsegmentation products can provide software-based isolation to improve the security posture. They divide servers within a security domain into small groups according to defined rules, allowing relatively free communication within a group while strictly controlling traffic between groups. This can reduce internal-network exposure and improve internal security.

10

Office Network Security

The source identifies malicious attacks and Trojan-horse malware as the main risks to office networks.

1. Remediate vulnerabilities promptly.

2. Close unused internet entry and exit points.

3. Update firewall and antivirus signatures and rule databases promptly.

4. Establish centralized desktop-management and network-antivirus systems. Require both client applications on all office computers, and have department heads confirm installation or enable the relevant system-admission controls. Once all office computers are covered, manage them jointly through the desktop-management and antivirus systems.

5. Enable desktop-admission controls for the relevant office network segments. Every device connecting to an office segment should have both the desktop-management and antivirus clients installed.

6. Restrict the IP addresses that can access the back ends of the desktop-management and antivirus systems.

7. Apply policies to groups of office computers. Unless there is a specific need, restrict USB-port use for all users.

8. Schedule regular health checks and scans. The source recommends daily, group-based scans around midday, followed by remediation of affected computers based on the results.

11

Wi-Fi Network Security

The source lists the main Wi-Fi risks as unauthorized use, eavesdropping, device compromise and phishing attacks.

1. Hide the service set identifier (SSID).

2. Use user-authentication equipment.

3. Improve confidentiality protections.

4. Check how many Wi-Fi signals are present in the office, whether any are unknown, and whether any use weak encryption.

5. Check for Wi-Fi networks with blank passwords.

6. Use an approved wireless-security assessment within an explicitly authorized scope. Verify access-point identity, authentication and encryption settings, segment boundaries and reachable resources; do not rely on a third-party shared-password service as a security test.

7. After connecting to a Wi-Fi network, try its management interface and check for weak passwords.

8. Do not allow unauthorized Wi-Fi access points. Strictly manage all Wi-Fi signals and apply device admission and access controls, such as wireless admission controls and a firewall for the wireless zone. If admission control is unavailable, use IP/MAC binding to restrict access and set strong device passwords.

12

Security of Security Products

Risks to security products mainly arise during deployment and operations, particularly in complex network environments. They include:

1. Security products may be aging or running outdated versions.

2. Operational configuration risks may affect any type of security product, including weak passwords, no limit on sign-in attempts, no multi-factor authentication, and failure to update system versions or rule databases regularly.

3. Gateway security products may have overly permissive rules, such as an allow-all policy, or policies that are not reviewed and hardened regularly.

4. Audit and monitoring products may not have their mirrored traffic checked regularly for anomalies, or uploaded log files may be invalid or incomplete.

5. Security products may lack out-of-band management or may not be connected to a centralized security-management platform, making effective control difficult.

1. User authentication: authenticate users at least once when they request access to system resources.

2. Access restrictions: only an authorized user may access resources assigned to that user; users must not access resources that have not been assigned to them.

3. Tiered user management: security products should support multiple user levels, allowing accounts with different permissions and different resource-access rights for different users.

4. Administrator authentication: ensure that only authorized administrators and trusted hosts can use product-management functions, and authenticate both authorized administrators and trusted hosts.

5. Administrator permissions: review administrator attributes regularly, including changing passwords, and establish or update access-control policies.

6. Authentication timing and failed sign-ins: detect when a user exceeds the permitted number of failed sign-in attempts and block further attempts until an authorized administrator restores the user's ability to authenticate.

7. Carefully choose where security products are deployed. Manage them in separate zones to reduce the risk that an attacker could exploit a zero-day vulnerability in a security product to enter the business network and cause damage or take further action.

Related solutions

Connect this topic to an implementation path

IT Managed Services

Connect infrastructure maintenance and incident-management articles with a sustainable enterprise operating model.

View solution →

Industry Software Development

Connect business-process, data, interface and enterprise-application articles with an industry-software delivery plan.

View solution →

Enterprise Hybrid Cloud Management Platform

Connect cloud-resource, migration, network and cost-governance articles with a practical hybrid-cloud delivery approach.

View solution →

Related Articles

Related reading