Verifier Impersonation
Term · Cybersecurity · MLC-T-CYB-004562
1. Tricking individuals into disclosing sensitive personal information by claiming to be a trustworthy entity in an electronic communication (e.g., internet web sites).
2. An attack in which the subscriber is lured (usually through an email) to interact with a counterfeit verifier/RP and tricked into revealing information that can be used to masquerade as that subscriber to the real verifier/RP.
3. A technique for attempting to acquire sensitive data, such as bank account numbers, through a fraudulent solicitation in email or on a web site, in which the perpetrator masquerades as a legitimate business or reputable person.
4. A scenario where the attacker impersonates the verifier in an authentication protocol, usually to capture information that can be used to masquerade as a subscriber to the real verifier. In previous editions of SP 800-63, authentication protocols that are resistant to verifier impersonation have been described as “strongly MitM resistant”.
| Identifier | MLC-T-CYB-004562 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | phishing |
| References | NIST SP 800-82r3; NIST SP 800-63-4; CNSSI 4009-2015 from IETF RFC 4949 Ver 2; NIST SP 800-63-3 [Superseded]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-004562",
"term": "Verifier Impersonation",
"field": "Cybersecurity",
"definition": "1. Tricking individuals into disclosing sensitive personal information by claiming to be a trustworthy entity in an electronic communication (e.g., internet web sites).\n\n2. An attack in which the subscriber is lured (usually through an email) to interact with a counterfeit verifier/RP and tricked into revealing information that can be used to masquerade as that subscriber to the real verifier/RP.\n\n3. A technique for attempting to acquire sensitive data, such as bank account numbers, through a fraudulent solicitation in email or on a web site, in which the perpetrator masquerades as a legitimate business or reputable person.\n\n4. A scenario where the attacker impersonates the verifier in an authentication protocol, usually to capture information that can be used to masquerade as a subscriber to the real verifier. In previous editions of SP 800-63, authentication protocols that are resistant to verifier impersonation have been described as “strongly MitM resistant”.",
"abbreviation": "phishing",
"references": [
"NIST SP 800-82r3",
"NIST SP 800-63-4",
"CNSSI 4009-2015 from IETF RFC 4949 Ver 2",
"NIST SP 800-63-3 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/verifier-impersonation/"
}
Record 4,562 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.