Metalikelihood: Lowseverity: MediumStable

CAPEC-117Interception

Abstraction
Meta
Status
Stable
Likelihood
Low
Severity
Medium

Description

An adversary monitors data streams to or from the target for information gathering purposes. This attack may be undertaken to solely gather sensitive information or to support a further attack against the target. This attack pattern can involve sniffing network traffic as well as other types of data streams (e.g. radio). The adversary can attempt to initiate the establishment of a data stream or passively observe the communications as they unfold. In all variants of this attack, the adversary is not the intended recipient of the data stream. In contrast to other means of gathering information (e.g., targeting data leaks), the adversary must actively position themself so as to observe explicit data channels (e.g. network traffic) and read the content. However, this attack differs from a Adversary-In-the-Middle (CAPEC-94) attack, as the adversary does not alter the content of the communications nor forward data to the intended recipient.

Related weaknesses· 1

CWE-319

Exploits1

TypeTargetConfidenceTier
WeaknessCleartext Transmission of Sensitive Informationcwe-319100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Sniffing Attacks
CAPEC
Sniffing Network Traffic
CAPEC
Eavesdropping
CAPEC
Protocol Analysis
CAPEC
Cellular Traffic Intercept
CAPEC
Traffic Injection
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.