CAPEC-517: Documentation Alteration to Circumvent Dial-down

Detailed Draft 严重程度: High 攻击可能性: Low

CAPEC版本: 3.9

更新日期: 2023-01-24

攻击模式描述

An attacker with access to a manufacturer's documentation, which include descriptions of advanced technology and/or specific components' criticality, alters the documents to circumvent dial-down functionality requirements. This alteration would change the interpretation of implementation and manufacturing techniques, allowing for advanced technologies to remain in place even though these technologies might be restricted to certain customers, such as nations on the terrorist watch list, giving the attacker on the receiving end of a shipped product access to an advanced technology that might otherwise be restricted.

前提条件

  • Advanced knowledge of internal software and hardware components within manufacturer's development environment.
  • Access to the manufacturer's documentation.

所需技能

High Ability to read, interpret, and subsequently alter manufacturer's documentation to prevent dial-down capabilities.
High Ability to stealthly gain access via remote compromise or physical access to the manufacturer's documentation.

缓解措施

Digitize documents and cryptographically sign them to verify authenticity.

Password protect documents and make them read-only for unauthorized users.

Avoid emailing important documents and configurations.

Ensure deleted files are actually deleted.

Maintain backups of the document for recovery and verification.

示例实例

A product for manufacture exists that contains advanced cryptographic capabilities, including algorithms that are restricted from being shipped to some nations. An attacker from one of the restricted nations alters the documentation to ensure that when the product is manufactured for shipment to a restricted nation, the software compilation steps that normally would prevent the advanced cryptographic capabilities from being included are actually included. When the product is shipped to the attacker's home country, the attacker is able to retrieve and/or use the advanced cryptographic capabilities.

关键信息

CAPEC ID: CAPEC-517

抽象级别: Detailed

状态: Draft

典型严重程度: High

攻击可能性: Low

相关攻击模式