Threat DF.C.ACDF-VFS-i.3.6

URI: DF.C.ACDF-VFS-i.3.6

Package: ProcessComms

< prev | next >

Description: Encrypted flow of data Data from FlowsFrom leaked to false client of compromised service Service: if service Service is compromised by an attacker, they can access its cryptographic key to decrypt data and accept a request for it from a false client acting as Client.

Threat Type: Primary Threat

Matching Pattern:

DF.C.ACDF-VFS-i.3.6
MP-ACDF-VFS-i

Finds a data flow not encrypted with keys from a vault flowing from a service to/via a client, plus any data fields, and the associated channel, where the connection is direct.

        (empty)

CSG-EncryptedDataProcessingAtService

Process Service uses homomorphic encryption technology to perform calculations on data Data in an encrypted domain, allowing it to process the data without first decrypting.