Threat DF.C.ACDF-VSC-i.3.2

URI: DF.C.ACDF-VSC-i.3.2

Package: ProcessComms

< prev | next >

Description: Flow of data Data from FlowsFrom to FlowsTo leaked to false client of compromised service Service: if service Service is compromised by an attacker, they can allow a false client to request data by acting as Client.

Threat Type: Primary Threat

Matching Pattern:

DF.C.ACDF-VSC-i.3.2
MP-ACDF-VSC-i

Finds a data flow not encrypted with keys from a vault, that goes via a service and thence a client, and the related channel and any data fields, where the connection is direct and not via any credential-sharing intermediaries.

        (empty)

        (empty)

CSG-DataFlowEncryption

The data Data flowing between processes FlowsFrom and FlowsTo is encrypted by the two processes (i.e. not relying on transport level encryption).