Umbra Wiki attack-pattern attack-pattern/CAPEC-528
Back to wiki

CAPEC-528 — XML Flood

provenance: imported · ATT&CK: T1498.001 T1499.002 · CWE: CWE-770

CAPEC-528: XML Flood

MITRE CAPEC attack pattern

Status Draft
Typical severity Medium
Likelihood of attack Low
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary may execute a flooding attack using XML messages with the intent to deny legitimate users access to a web service. These attacks are accomplished by sending a large number of XML based requests and letting the service attempt to parse each one. In many cases this type of an attack will result in a XML Denial of Service (XDoS) due to an application becoming unstable, freezing, or crashing.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-770

ATT&CK techniques: T1498.001, T1499.002

Prerequisites

  • The target must receive and process XML transactions.
  • An adverssary must possess the ability to generate a large amount of XML based messages to send to the target service.

Skills required

  • Low: Denial of service

Consequences

  • Availability: Resource Consumption

Mitigations

  • Design: Build throttling mechanism into the resource allocation. Provide for a timeout mechanism for allocated resources whose transaction does not complete within a specified interval.
  • Implementation: Provide for network flow control and traffic shaping to control access to the resources.

Source