CAPEC-548: Contaminate Resource
Also known as: Data Spill
An adversary contaminates organizational information systems (including devices and networks) by causing them to handle information of a classification/sensitivity for which they have not been authorized. When this happens, the contaminated information system, device, or network must be brought offline to investigate and mitigate the data spill, which denies availability of the system until the investigation is complete.
Last updated
Overview
Contamination through email is a very common attack vector. Systems with email servers or personal work systems using email are susceptible to this attack simply by receiving an email that contains a classified document or information. A fake classified document could even be used that is mistaken as true classified material. This would still cause the system to be taken offline until the validity of the classified material is confirmed.
What the attacker needs
Prerequisites
- The adversary needs to have real or fake classified/sensitive information to place on a system
Skills required
- Low skill: Knowledge of classification levels of systems
- High skill: The ability to obtain a classified document or information
- Low skill: The ability to fake a classified document
Consequences
What a successful CAPEC-548 attack can achieve.
Resource Consumption
Affects: Availability
Denial of Service
Read Data
Affects: Confidentiality
Victims of the attack can be exposed to classified materials
How to mitigate it
Defenses that reduce the risk of CAPEC-548.
- Properly safeguard classified/sensitive data. This includes training cleared individuals to ensure they are handling and disposing of this data properly, as well as ensuring systems only handle information of the classification level they are designed for.
- Design systems with redundancy in mind. This could mean creating backing servers that could be switched over to in the event that a server has to be taken down for investigation.
- Have a planned and efficient response plan to limit the amount of time a system is offline while the contamination is investigated.
Examples
An insider threat was able to obtain a classified document. They have knowledge that a backend server which provides access to a website also runs a mail server. The adversary creates a throwaway email address and sends the classified document to the mail server. When an administrator checks the mail server they notice that it has processed an email with a classified document and the server has to be taken offline while they investigate the contamination. In the meantime, the website has to be taken down as well and access to the website is denied until the backend can be migrated to another server or the investigation is complete.
Terminology & mappings
Alternate terms
- Data Spill
- When information is handled by an information system of a classification/sensitivity for which the system has not been authorized to handle.
Frequently asked questions
Common questions about CAPEC-548.
- What is CAPEC-548?
- An adversary contaminates organizational information systems (including devices and networks) by causing them to handle information of a classification/sensitivity for which they have not been authorized. When this happens, the contaminated information system, device, or network must be brought offline to investigate and mitigate the data spill, which denies availability of the system until the investigation is complete.
- How do you prevent CAPEC-548?
- Properly safeguard classified/sensitive data. This includes training cleared individuals to ensure they are handling and disposing of this data properly, as well as ensuring systems only handle information of the classification level they are designed for.
- How severe is CAPEC-548?
- MITRE rates CAPEC-548 as High severity with low likelihood of attack.
References
Attack-pattern data is sourced from the MITRE CAPEC catalog (v3.9). Weakness associations link to the corresponding CWE entries on RadicalNotion.AI.
Defend against CAPEC-548
Track the CVEs and weaknesses attackers exploit with this technique, with AI-written analysis and remediation guidance.