Misuse pattern

Jaime Muñoz Arteaga, Eduardo B. Fernández, Héctor Caudel-García · 2011

We present here a misuse pattern, Spoofing Web Services. A misuse pattern describes how a misuse is performed from the point of view of the attacker, what system units it uses and how, provides ways of stopping the attack by enumerating possible security patterns that can be applied for this purpose, and provides forensic information. This pattern is useful for designers and developers of web services, who can then avoid these situations following the prescriptions of the pattern. This pattern could also be a guide to know what happened and to correct the corresponding vulnerabilities that led to the attack. A web service spoofing misuse tries to impersonate the identity of a user, and then with the user's credentials makes requests in his name, with the intention of accessing a specific web service.

Read the paper · More papers on PaperTik