CAPEC-582: Route Disabling
An adversary disables the network route between two targets. The goal is to completely sever the communications channel between two entities. This is often the result of a major error or the use of an "Internet kill switch" by those in control of critical infrastructure. This attack pattern differs from most other obstruction patterns by targeting the route itself, as opposed to the data passed over the route.
Last updated
Overview
CAPEC-582 (Route Disabling) is a standard-level attack pattern catalogued by MITRE in the Common Attack Pattern Enumeration and Classification (CAPEC). It describes a recurring method attackers use to exploit software weaknesses.
What the attacker needs
Prerequisites
- The adversary requires knowledge of and access to network route.
Consequences
What a successful CAPEC-582 attack can achieve.
Other
Affects: Availability
Disabling a network route denies the availability of a service.
Frequently asked questions
Common questions about CAPEC-582.
- What is CAPEC-582?
- An adversary disables the network route between two targets. The goal is to completely sever the communications channel between two entities. This is often the result of a major error or the use of an "Internet kill switch" by those in control of critical infrastructure. This attack pattern differs from most other obstruction patterns by targeting the route itself, as opposed to the data passed over the route.
- How severe is CAPEC-582?
- MITRE rates CAPEC-582 as High severity with low likelihood of attack.
References
Attack-pattern data is sourced from the MITRE CAPEC catalog (v3.9). Weakness associations link to the corresponding CWE entries on RadicalNotion.AI.
Defend against CAPEC-582
Track the CVEs and weaknesses attackers exploit with this technique, with AI-written analysis and remediation guidance.