Insider Attack Model Against HSM-Based Architecture
Marc Dib, Samuel Pierre · IEEE Access · 2023
In this paper, we propose a combinatory attack model for insider attacks against HSM-based security architectures. Our model is based on the study of attack vectors in the security architecture and the conduction of all possible attacks on those vectors. It shows that these typical architectures are vulnerable to private key theft and replacement, as well as data theft, alteration, swapping, nullification, and deletion. Results show that each of those attacks was successfully conducted on an HSM-based security architecture with relative ease. They prove the essential need for a security architecture that also considers insider threats.