ORSHIN Attack Defense Framework

Profile switch

Description

Profile switch

CWE

CVE

Attack Surfaces

Controller Implementation (MITRE EMB3D PID-11)

Session (MITRE EMB3D PID-41)

Attack Vectors

Entropy downgrade (MITRE EMB3D TID-411)

Key brute force (MITRE EMB3D TID-317)

Authentication role switch

RCE (MITRE EMB3D TID-310)

Defenses

Mutually authenticated session establishment, Mutually authenticated session establishment