Hardentechnique

D3-TBAToken-based Authentication

Token-based Authentication

Definition

Token-based authentication is an authentication protocol where users verify their identity in exchange for a unique access token. Users can then access the website, application, or resource for the life of the token without having to re-enter their credentials.

Defends against24

TypeTargetConfidenceTier
SubTechniqueLocal Accountt1087.001100%live
SubTechniqueAdditional Cloud Rolest1098.003100%live
SubTechniqueLocal Accountst1078.003100%live
SubTechniqueLocal Accountt1136.001100%live
SubTechniqueCloud Accountt1136.003100%live
SubTechniqueCloud Accountt1087.004100%live
SubTechniqueCreate Process with Tokent1134.002100%live
SubTechniqueAdditional Email Delegate Permissionst1098.002100%live
SubTechniqueDefault Accountst1078.001100%live
SubTechniqueTemporary Elevated Cloud Accesst1548.005100%live
TechniqueAccount Manipulationt1098100%live
SubTechniqueDomain Accountt1136.002100%live
TechniqueCreate Accountt1136100%live
SubTechniqueToken Impersonation/Theftt1134.001100%live
SubTechniqueDomain Accountt1087.002100%live
TechniqueAccount Access Removalt1531100%live
SubTechniqueDomain Accountst1078.002100%live
SubTechniqueApplication Access Tokent1550.001100%live
SubTechniqueMake and Impersonate Tokent1134.003100%live
TechniqueValid Accountst1078100%live
SubTechniqueCloud Accountst1078.004100%live
TechniqueSteal Application Access Tokent1528100%live
TechniqueSteal or Forge Kerberos Ticketst1558100%live
SubTechniqueGolden Tickett1558.001100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Token Binding
Defence
Password Authentication
Defence
Certificate-based Authentication
Defence
Multi-factor Authentication
Defence
One-time Password
Defence
Biometric Authentication
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.