| Home > CAPEC List > CAPEC-668: Key Negotiation of Bluetooth Attack (KNOB) (Version 3.9) |
|
Low
High
| Nature | Type | ID | Name |
|---|---|---|---|
| ChildOf | Meta Attack PatternMeta Attack Pattern - A meta level attack pattern in CAPEC is a decidedly abstract characterization of a specific methodology or technique used in an attack. A meta attack pattern is often void of a specific technology or implementation and is meant to provide an understanding of a high level approach. A meta level attack pattern is a generalization of related group of standard level attack patterns. Meta level attack patterns are particularly useful for architecture and design level threat modeling exercises. | 115 | Authentication Bypass |
| CanFollow | Standard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern. | 20 | Encryption Brute Forcing |
| CanFollow | Meta Attack PatternMeta Attack Pattern - A meta level attack pattern in CAPEC is a decidedly abstract characterization of a specific methodology or technique used in an attack. A meta attack pattern is often void of a specific technology or implementation and is meant to provide an understanding of a high level approach. A meta level attack pattern is a generalization of related group of standard level attack patterns. Meta level attack patterns are particularly useful for architecture and design level threat modeling exercises. | 94 | Adversary in the Middle (AiTM) |
| CanPrecede | Meta Attack PatternMeta Attack Pattern - A meta level attack pattern in CAPEC is a decidedly abstract characterization of a specific methodology or technique used in an attack. A meta attack pattern is often void of a specific technology or implementation and is meant to provide an understanding of a high level approach. A meta level attack pattern is a generalization of related group of standard level attack patterns. Meta level attack patterns are particularly useful for architecture and design level threat modeling exercises. | 148 | Content Spoofing |
| View Name | Top Level Categories |
|---|---|
| Domains of Attack | Software |
| Mechanisms of Attack | Subvert Access Control |
Discovery: Using an established Person in the Middle setup, search for Bluetooth devices beginning the authentication process.
| Techniques |
|---|
| Use packet capture tools. |
Change the entropy bits: Upon recieving the initial key negotiation packet from the master, the adversary modifies the entropy bits requested to 1 to allow for easy decryption before it is forwarded.
Capture and decrypt data: Once the entropy of encryption is known, the adversary can capture data and then decrypt on their device.
| Scope | Impact | Likelihood |
|---|---|---|
Confidentiality | Read Data | |
Confidentiality Access Control Authorization | Bypass Protection Mechanism | |
Integrity | Modify Data |
| CWE-ID | Weakness Name |
|---|---|
| 425 | Direct Request ('Forced Browsing') |
| 285 | Improper Authorization |
| 693 | Protection Mechanism Failure |
| Entry ID | Entry Name |
|---|---|
| 1565.002 | Data Manipulation: Transmitted Data Manipulation |
| Submissions | ||
|---|---|---|
| Submission Date | Submitter | Organization |
| 2021年06月24日 (Version 3.5) | CAPEC Content Team | The MITRE Corporation |
| Modifications | ||
| Modification Date | Modifier | Organization |
| 2022年09月29日 (Version 3.8) | CAPEC Content Team | The MITRE Corporation |
| Updated Taxonomy_Mappings | ||
|
Use of the Common Attack Pattern Enumeration and Classification (CAPEC), and the associated references from this website are subject to the Terms of Use. Copyright © 2007–2025, The MITRE Corporation. CAPEC and the CAPEC logo are trademarks of The MITRE Corporation. |
||