Threat CC.AuC.HuDFTCS.3

URI: CC.AuC.HuDFTCS.3

Package: ProcessComms

< prev | next >

Description: Unauthentic flow of data Data from FlowsFrom directs Client to a fake service impersonating Service: an attacker who provides malicious input to client Client via FlowsFrom (e.g. via phishing), can induce the client to access a fake version of service Service, a one-off deception that may allow subsequent impersonation of the client through capture of its password.

Threat Type: Primary Threat

Matching Pattern:

CC.AuC.HuDFTCS.3
MP-HuDFTCS

Finds a Human using a Web Browser that accesses via at least one IP subnet a Service that does not use a separate authenticator service, where the browser consumes a data flow viewed but not updated by the user, plus the data access and client channel assets associated with the data use and client-service commnication.

        (empty)

        (empty)

CSG-ClientOneTimeKeyAuthentication

Access to service Service is controlled, by authenticating authorised users using a one time key created using a client-side authentication device provided to them.

CSG-ClientOutOfBandKeyAuthentication

Access to service Service is controlled, by authenticating authorised users using a password and a separate key sent to them via a separate (out of band) means.