G
G
Gudsaf2018-05-12 20:23:00
Information Security
Gudsaf, 2018-05-12 20:23:00

How to read security threats in the Threat Data Bank (UBI FSTEC)?

Here is an example of a threat from the FSTEC BDU:
UBI No. 8 : Threat to restore authentication information
The threat consists in the possibility of selecting (for example, by exhaustive enumeration or enumeration in a dictionary) the authentication information of a compromised user account in the system.
Source: Low potential external intruder Target
#1: System software
Target #2: Firmware
Target #3: User credentials
How to read it? I guess it should read something like this:

if the object of influence 1 is attacked in accordance with threat 1, then the following properties of the protected information will be violated: conf, integrity, availability

What will be the protected information in the case of each target: authentication information or protected data (letters, prices, etc.)?

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question