Ace of Repudiation
You’ve invented a new repudiation attack.
Threat |
|
Your central logging server is a single point of failure, and an attacker can use Domain Name Server (DNS) or Address Resolution Protocol (ARP) poisoning to render your centralized log server unreachable. |
|
CAPEC |
CAPEC-571 - Block Logging to Central Repository CAPEC-589 - DNS Blocking CAPEC-598 - DNS Spoofing |
ASVS |
10.3.3 - Ensure your DNS is kept up to date and protected from subdomain takeovers. |
CWE |
N/A |
Mitigations |
|
|