CAPEC - Common Attack Pattern Enumeration and Classification (A Community of Knowledge Resource for Building Secure Software)
Home > CAPEC List > VIEW GRAPH: CAPEC-1000: Mechanism of Attack (Release 1.4)  

CAPEC-1000: Mechanism of Attack

 
Mechanism of Attack
Definition in a New Window Definition in a New Window
View ID: 1000 (View: Graph)Status: Draft
+ View Data

View Structure: Graph

View Objective

+ Relationships
NatureTypeIDNameDescriptionView(s) this relationship pertains toView(s)
HasMemberCategoryCategory118Data Leakage Attacks 
Mechanism of Attack1000
HasMemberCategoryCategory119Resource Depletion 
Mechanism of Attack1000
HasMemberCategoryCategory152Injection (Injecting Control Plane content through the Data Plane) 
Mechanism of Attack1000
HasMemberCategoryCategory156Spoofing 
Mechanism of Attack1000
HasMemberCategoryCategory172Time and State Attacks 
Mechanism of Attack1000
HasMemberCategoryCategory210Abuse of Functionality 
Mechanism of Attack1000
HasMemberCategoryCategory223Probabilistic Techniques 
Mechanism of Attack1000
HasMemberCategoryCategory225Exploitation of Authentication 
Mechanism of Attack1000
HasMemberCategoryCategory232Exploitation of Privilege/Trust 
Mechanism of Attack1000
HasMemberCategoryCategory255Data Structure Attacks 
Mechanism of Attack1000
HasMemberCategoryCategory262Resource Manipulation 
Mechanism of Attack1000
HasMemberAttack PatternAttack Pattern286Network Reconnaissance 
Mechanism of Attack1000
CAPECs in this viewTotal CAPECs
Total298out of310
Views0out of5
Categories18out of18
Attack Patterns287out of287
1000 - Mechanism of Attack
+CategoryCategoryData Leakage Attacks - (118)Data Leakage Attacks - (118)
+Attack PatternAttack PatternData Excavation Attacks - (116)Data Excavation Attacks - (116)
+Attack PatternAttack PatternData Interception Attacks - (117)Data Interception Attacks - (117)
+CategoryCategoryResource Depletion - (119)Resource Depletion - (119)
+CategoryCategoryInjection (Injecting Control Plane content through the Data Plane) - (152)Injection (Injecting Control Plane content through the Data Plane) - (152)
*Attack PatternAttack PatternLDAP Injection - (136)LDAP Injection - (136)
*Attack PatternAttack PatternReflection Injection - (138)Reflection Injection - (138)
+Attack PatternAttack PatternResource Injection - (240)Resource Injection - (240)
+Attack PatternAttack PatternScript Injection - (242)Script Injection - (242)
+Attack PatternAttack PatternEmbedding Scripts in Nonscript Elements - (18)Embedding Scripts in Nonscript Elements - (18)
+Attack PatternAttack PatternSimple Script Injection - (63)Simple Script Injection - (63)
+Attack PatternAttack PatternEmbedding Scripts in Nonscript Elements - (18)Embedding Scripts in Nonscript Elements - (18)
+Attack PatternAttack PatternXML Injection - (250)XML Injection - (250)
*Attack PatternAttack PatternXPath Injection - (83)XPath Injection - (83)
*Attack PatternAttack PatternXQuery Injection - (84)XQuery Injection - (84)
+CategoryCategorySpoofing - (156)Spoofing - (156)
+Attack PatternAttack PatternIdentity Spoofing (Impersonation) - (151)Identity Spoofing (Impersonation) - (151)
*Attack PatternAttack PatternPharming - (89)Pharming - (89)
+Attack PatternAttack PatternPhishing - (98)Phishing - (98)
*Attack PatternAttack PatternPrincipal Spoofing - (195)Principal Spoofing - (195)
+Attack PatternAttack PatternClient-Server Protocol Manipulation - (220)Client-Server Protocol Manipulation - (220)
*Attack PatternAttack PatternExternal Entity Attack - (221)External Entity Attack - (221)
+Attack PatternAttack PatternAction Spoofing - (173)Action Spoofing - (173)
+Attack PatternAttack PatternClickjacking - (103)Clickjacking - (103)
*Attack PatternAttack PatternFlash File Overlay - (181)Flash File Overlay - (181)
*Attack PatternAttack PatterniFrame Overlay - (222)iFrame Overlay - (222)
+CategoryCategoryTime and State Attacks - (172)Time and State Attacks - (172)
+CategoryCategoryAbuse of Functionality - (210)Abuse of Functionality - (210)
*Attack PatternAttack PatternWSDL Scanning - (95)WSDL Scanning - (95)
*Attack PatternAttack PatternCache Poisoning - (141)Cache Poisoning - (141)
*Attack PatternAttack PatternDirectory Traversal - (213)Directory Traversal - (213)
+Attack PatternAttack PatternAnalytic Attacks - (281)Analytic Attacks - (281)
*Attack PatternAttack PatternCryptanalysis - (97)Cryptanalysis - (97)
+Attack PatternAttack PatternLifting Sensitive Data from the Client - (167)Lifting Sensitive Data from the Client - (167)
+CategoryCategoryProbabilistic Techniques - (223)Probabilistic Techniques - (223)
+CategoryCategoryExploitation of Authentication - (225)Exploitation of Authentication - (225)
+CategoryCategoryExploitation of Privilege/Trust - (232)Exploitation of Privilege/Trust - (232)
+Attack PatternAttack PatternExploiting Trust in Client (aka Make the Client Invisible) - (22)Exploiting Trust in Client (aka Make the Client Invisible) - (22)
+Attack PatternAttack PatternManipulating User-Controlled Variables - (77)Manipulating User-Controlled Variables - (77)
+Attack PatternAttack PatternLifting Sensitive Data from the Client - (167)Lifting Sensitive Data from the Client - (167)
+Attack PatternAttack PatternClient-Server Protocol Manipulation - (220)Client-Server Protocol Manipulation - (220)
+CategoryCategoryData Structure Attacks - (255)Data Structure Attacks - (255)
+Attack PatternAttack PatternBuffer Attacks - (123)Buffer Attacks - (123)
+Attack PatternAttack PatternOverflow Buffers - (100)Overflow Buffers - (100)
*Attack PatternAttack PatternMIME Conversion - (42)MIME Conversion - (42)
*Attack PatternAttack PatternSOAP Array Overflow - (256)SOAP Array Overflow - (256)
+Attack PatternAttack PatternInteger Attacks - (128)Integer Attacks - (128)
*Attack PatternAttack PatternPointer Attack - (129)Pointer Attack - (129)
+CategoryCategoryResource Manipulation - (262)Resource Manipulation - (262)
+Attack PatternAttack PatternInput Data Manipulation - (153)Input Data Manipulation - (153)
+Attack PatternAttack PatternLeverage Alternate Encoding - (267)Leverage Alternate Encoding - (267)
*Attack PatternAttack PatternDouble Encoding - (120)Double Encoding - (120)
+Attack PatternAttack PatternResource Location Attacks - (154)Resource Location Attacks - (154)
+Attack PatternAttack PatternInfrastructure Manipulation - (161)Infrastructure Manipulation - (161)
*Attack PatternAttack PatternPharming - (89)Pharming - (89)
*Attack PatternAttack PatternDNS Cache Poisoning - (142)DNS Cache Poisoning - (142)
+Attack PatternAttack PatternFile Manipulation - (165)File Manipulation - (165)
+Attack PatternAttack PatternVariable Manipulation - (171)Variable Manipulation - (171)
+Attack PatternAttack PatternGlobal variable manipulation - (265)Global variable manipulation - (265)
+Attack PatternAttack PatternSchema Poisoning - (271)Schema Poisoning - (271)
*Attack PatternAttack PatternXML Schema Poisoning - (146)XML Schema Poisoning - (146)
+Attack PatternAttack PatternProtocol Manipulation - (272)Protocol Manipulation - (272)
+Attack PatternAttack PatternClient-Server Protocol Manipulation - (220)Client-Server Protocol Manipulation - (220)
*Attack PatternAttack PatternDNS Rebinding - (275)DNS Rebinding - (275)
+Attack PatternAttack PatternNetwork Reconnaissance - (286)Network Reconnaissance - (286)
*Attack PatternAttack PatternICMP Echo Request Ping - (285)ICMP Echo Request Ping - (285)
*Attack PatternAttack PatternTCP SYN Scan - (287)TCP SYN Scan - (287)
*Attack PatternAttack PatternICMP Echo Request Ping - (288)ICMP Echo Request Ping - (288)
*Attack PatternAttack PatternDNS Zone Transfers - (291)DNS Zone Transfers - (291)
*Attack PatternAttack PatternHost Discovery - (292)Host Discovery - (292)
*Attack PatternAttack PatternICMP Timestamp Request - (295)ICMP Timestamp Request - (295)
*Attack PatternAttack PatternTCP ACK Ping - (297)TCP ACK Ping - (297)
*Attack PatternAttack PatternUDP Ping - (298)UDP Ping - (298)
*Attack PatternAttack PatternTCP SYN Ping - (299)TCP SYN Ping - (299)
*Attack PatternAttack PatternPort Scanning - (300)Port Scanning - (300)
*Attack PatternAttack PatternTCP Connect Scan - (301)TCP Connect Scan - (301)
*Attack PatternAttack PatternTCP FIN scan - (302)TCP FIN scan - (302)
*Attack PatternAttack PatternTCP Xmas Scan - (303)TCP Xmas Scan - (303)
*Attack PatternAttack PatternTCP Null Scan - (304)TCP Null Scan - (304)
*Attack PatternAttack PatternTCP ACK Scan - (305)TCP ACK Scan - (305)
*Attack PatternAttack PatternTCP Window Scan - (306)TCP Window Scan - (306)
*Attack PatternAttack PatternTCP RPC Scan - (307)TCP RPC Scan - (307)
*Attack PatternAttack PatternUDP Scan - (308)UDP Scan - (308)
Page Last Updated: September 22, 2009