AA05 Spoofing Of Remote Service
Context | Cloud application uses a remote service |
Problem | Spoofing of the remote service |
Solution | Apply certificate-based validation of the remote service; Apply TLS-based encryption of the network connection; |
References | |
Type | ns:type_ThreatPattern |
Victim | su:comp_CloudApplication |
Aggressor | su:comp_ExternalService |
Aggr. role | ns:role_Server |
STRIDE | ns:STRIDE_Spoofing |
Threat | ns:threat_txIdentitySpoofing; ns:threat_txMessageAuthenticityViolation; ns:threat_txSessionHijacking |