Esc
Adversary-in-the-Middle - T0830
(ICS Technique)
Definition
Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks. This type of attack allows the adversary to intercept traffic to and/or from a particular device on the network. If a AiTM attack is established, then the adversary has the ability to block, log, modify, or inject traffic into the communication stream. There are several ways to accomplish this attack, but some of the most-common are Address Resolution Protocol (ARP) poisoning and the use of a proxy.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.