Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks. (Citation: Gabriel Sanchez October 2017) This type of attack allows the adversary to intercept traffic to and/or from a particular device on the network. If a AiTM attack is established, then the adversary has the ability to block, log, modify, or inject traffic into the communication stream. There are several ways to accomplish this attack, but some of the most-common are Address Resolution Protocol (ARP) poisoning and the use of a proxy. (Citation: Bonnie Zhu, Anthony Joseph, Shankar Sastry 2011) An AiTM attack may allow an adversary to perform the following attacks: [Block Reporting Message](https://attack.mitre.org/techniques/T0804), [Spoof Reporting Message](https://attack.mitre.org/techniques/T0856), [Modify Parameter](https://attack.mitre.org/techniques/T0836), [Unauthorized Command Message](https://attack.mitre.org/techniques/T0855)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Intelligent Electronic Device (IED)
is related to Routers
is related to Jump Host
is related to Distributed Control System (DCS) Controller
is related to Data Historian
is related to Firewall
is related to Switch
is related to Application Server
is related to Human-Machine Interface (HMI)
is related to Safety Controller
is related to Virtual Private Network (VPN) Server
is related to Programmable Automation Controller (PAC)
is related to Workstation
is related to Data Gateway
is related to Control Server
is related to Programmable Logic Controller (PLC)
is related to Field I/O
is related to Remote Terminal Unit (RTU)
is blocked by Detection of Adversary-in-the-Middle
is blocked by Network Segmentation
is blocked by Out-of-Band Communications Channel
is blocked by Software Process and Device Authentication
is blocked by Static Network Configuration
is blocked by Network Intrusion Prevention
is blocked by Audit
is blocked by Disable or Remove Feature or Program
is blocked by Communication Authenticity
Impressum German English