07.11.2014 Views

Enterprise Library Test Guide - Willy .Net

Enterprise Library Test Guide - Willy .Net

Enterprise Library Test Guide - Willy .Net

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

138<br />

<strong>Enterprise</strong> <strong>Library</strong> <strong>Test</strong> <strong>Guide</strong><br />

Table 22 lists the DREAD rating for threat 8.<br />

Table 22: Threat 8 DREAD Rating<br />

D R E A D Total Rating<br />

3 3 2 3 3 14 High<br />

Table 23 lists details about threat 9.<br />

Table 23: Logging Application Block Threat 9<br />

Threat 9<br />

Name<br />

Entry points<br />

Threat<br />

description<br />

Countermeasures<br />

STRIDE<br />

classification<br />

Risk<br />

Mitigation<br />

Attackers can flood WMI event instrumentation with false events.<br />

Flooding WMI events<br />

Public classes and static methods<br />

The Logging Application Block exposes interfaces that allow you to raise<br />

WMI events. An attacker can use these interfaces to raise false instrumentation<br />

events. This can constitute a denial of service attack.<br />

Validate the input.<br />

Denial of Services, Elevation of Privileges<br />

High<br />

No

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!