Endpoint Attacks
Roger A. Grimes · 2020
This chapter explores specific endpoint attacks that are capable of bypassing multifactor authentication (MFA) solutions. Endpoint attacks can be broken down into two main categories of compromises: programming attacks and physical access. Programming attacks are code-level assaults where the attacker exploits a software or hardware vulnerability to gain unauthorized logical access to the device and/or involved software. Physical access attacks are when an attacker has local, physical possession and control of a device. The chapter discusses some specific endpoint attack examples, including bancos trojans, transaction attacks, mobile attacks, and compromised MFA keys. Endpoint attack defenses break down into two different categories: developer defense and end-user defense. The chapter also suggests many proactive steps for MFA developers and MFA end-users to limit or slow down physical and logical endpoint attacks.