Threat DF.Auth.CCCSDF-VCCS-i.3

URI: DF.Auth.CCCSDF-VCCS-i.3

Package: ProcessComms

< prev | next >

Description: Flow of data from/via Process forged by compromised client Client via confused deputy Service: if client Client does not send data Data to its service Service, it is still possible to inject false content into the data flow via service Service using a confused deputy attack. The attack itself is responsible for the upstream loss of DeputyUserTW (see threat causes).

Threat Type: Primary Threat

Matching Pattern:

DF.Auth.CCCSDF-VCCS-i.3
MP-CCCSDF-VCCS-i

Finds a client accessing a service that uses another service, via the associated client channels, where indirect access by the client is not authenticated by the second service, plus a data flow and any data fields not encrypted with keys from a vault flowing to the second service from the first but not from the client.

        (empty)

        (empty)

CSG-DataFlowEncryption

The data Data flowing between processes FlowsFrom and FlowsTo is encrypted by the two processes (i.e. not relying on transport level encryption).