An attacker reaches root on a file server, stops the audit daemon, and rewrites the access-control configuration so that nothing done afterwards is recorded anywhere. Which class of the classical taxonomy is that?
An attacker reaches root on a file server, stops the audit daemon, and rewrites the access-control configuration so that nothing done afterwards is recorded anywhere. Which class of the classical taxonomy is that?
Answer
Clandestine user
Options - A. Clandestine user - B. Masquerader - C. Misfeasor - D. Mole Why - A. Correct — the defining act is turning the supervisory level against the monitoring, and this is the one class that may be an insider or an outsider. - B. A masquerader is not authorised to use the computer at all; they penetrate the access controls and run somebody else’s account. This attacker holds supervisory power and hides behind that, not behind a borrowed identity. - C. A misfeasor is a legitimate user exceeding or misusing their authority. They have standing on the system already, and they do not need to defeat the auditing to do what they do. - D. Not a member of this taxonomy at all. If it looked plausible, that is the recognition trap: three real terms and one that merely sounds like one. Ask what standing the intruder had before the intrusion: none (masquerader), legitimate (misfeasor), or supervisory (clandestine user).
J. P. Anderson, Computer Security Threat Monitoring and Surveillance (1980), carried by earlier editions of Stallings & Brown — NOT in the 5th edition