Information Exposure Through Behavioral Discrepancy |
Weakness ID: 205 (Weakness Base) | Status: Incomplete |
Description Summary
The product's actions indicate important differences based on (1) the internal state of the product or (2) differences from other products in the same class.
Extended Description
For example, attacks such as OS fingerprinting rely heavily on both behavioral and response discrepancies.
Compartmentalize your system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 203 | Information Exposure Through Discrepancy | Development Concepts (primary)699 Research Concepts (primary)1000 |
ParentOf | ![]() | 206 | Internal Behavioral Inconsistency Information Leak | Development Concepts (primary)699 Research Concepts (primary)1000 |
ParentOf | ![]() | 207 | Information Exposure Through an External Behavioral Inconsistency | Development Concepts (primary)699 Research Concepts (primary)1000 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
PLOVER | Behavioral Discrepancy Infoleak | ||
WASC | 45 | Fingerprinting |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
PLOVER | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Relationships, Taxonomy Mappings | ||||
2008-10-14 | CWE Content Team | MITRE | Internal | |
updated Description | ||||
2009-12-28 | CWE Content Team | MITRE | Internal | |
updated Description, Name | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2009-12-28 | Behavioral Discrepancy Information Leak | |||