CAPEC-474: Signature Spoofing by Key Theft |
Description An attacker obtains an authoritative or reputable signer's private signature key by theft and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker. Likelihood Of Attack Typical Severity Prerequisites
| An authoritative or reputable signer is storing their private signature key with insufficient protection. |
Skills Required
[Level: Low] Knowledge of common location methods and access methods to sensitive data |
[Level: High] Ability to compromise systems containing sensitive data |
Mitigations
| Restrict access to private keys from non-supervisory accounts |
| Restrict access to administrative personnel and processes only |
| Ensure all remote methods are secured |
| Ensure all services are patched and up to date |
Taxonomy Mappings CAPEC mappings to ATT&CK techniques leverage an inheritance model to streamline and minimize direct CAPEC/ATT&CK mappings. Inheritance of a mapping is indicated by text stating that the parent CAPEC has relevant ATT&CK mappings. Note that the ATT&CK Enterprise Framework does not use an inheritance model as part of the mapping to CAPEC.Relevant to the ATT&CK taxonomy mapping (also see parent) | Entry ID | Entry Name |
|---|
| 1552.004 | Unsecured Credentials: Private Keys |
References
[REF-411] Sigbjørn Vik. "Security breach stopped". http://my.opera.com/securitygroup/blog/2013/06/26/opera-infrastructure-attack. 2013-06-26.
|
[REF-412] Patrick Morley. "Bit9 and Our Customers’ Security". https://blog.bit9.com/2013/02/08/bit9-and-our-customers-security/. 2013-02-08.
|
[REF-413] Brad Arkin. "Inappropriate Use of Adobe Code Signing Certificate". http://blogs.adobe.com/asset/2012/09/inappropriate-use-of-adobe-code-signing-certificate.html. 2012-09-27.
|
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization |
|---|
| 2014-06-23 (Version 2.6) | CAPEC Content Team | The MITRE Corporation | | | Modifications |
|---|
| Modification Date | Modifier | Organization |
|---|
| 2019-04-04 (Version 3.1) | CAPEC Content Team | The MITRE Corporation | | Updated Related_Weaknesses | | 2020-12-17 (Version 3.4) | CAPEC Content Team | The MITRE Corporation | | Updated Mitigations | | 2022-09-29 (Version 3.8) | CAPEC Content Team | The MITRE Corporation | | Updated Taxonomy_Mappings |
More information is available — Please select a different filter.
|