Misbehaviour LossOfAnonUserTW

URI: LossOfAnonUserTW

Package: ProcessComms

< prev | next >

Description: Untrustworthy users are able to send messages to a service from the direction of a specific client. This relates to any message so it includes messages sent anonymously, prior to authentication. It is not related to which users can access the service. Consequently, a high likelihood is not in itself a cause for concern, so the impact level should never be raised for this behaviour.

This misbehaviour affects the trustworthiness attribute AnonUserTW

ClientChannel

Represents a trust relationship between a Client and a Service. Exists where the two communicate directly, or where the Service may need to know the identity of the Client.

        (empty)