CAPEC™ 151: Identity Spoofing
Description
Identity Spoofing refers to the action of assuming (i.e., taking on) the identity of some other entity (human or non-human) and then using that identity to accomplish a goal. An adversary may craft messages that appear to come from a different principle or use stolen / spoofed authentication credentials.
Source: CAPEC™ 151
Related ASVS Requirements
ASVS (5.0): 10.4.2, 10.4.3, 10.4.5, 10.4.9, 13.2.3, 13.3.4, 16.1.1, 16.2.1, 16.2.2, 16.2.3, 16.2.4, 16.2.5, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.4.3, 16.5.1, 16.5.2, 16.5.3, 16.5.4, 6.1.1, 6.1.3, 6.2.10, 6.2.11, 6.2.12, 6.2.4, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.8.3, 7.5.1, 7.5.2, 7.5.3, 8.1.3, 8.1.4, 8.4.2, 9.2.1