Man-in-the-Middle

Adversaries may attempt to position themselves between two or more networked devices using a man-in-the-middle (MiTM) technique to support follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation. By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.[1]

Adversaries may leverage the MiTM position to attempt to modify traffic, such as in Transmitted Data Manipulation. Adversaries can also stop traffic from flowing to the appropriate destination, causing denial of service.

ID: T1557
Sub-techniques:  T1557.001
Tactics: Credential Access, Collection
Platforms: Linux, Windows, macOS
Permissions Required: User
Data Sources: File monitoring, Netflow/Enclave netflow, Packet capture
CAPEC ID: CAPEC-94
Contributors: Daniil Yugoslavskiy, @yugoslavskiy, Atomic Threat Coverage project
Version: 1.0
Created: 11 February 2020
Last Modified: 31 March 2020

Mitigations

Mitigation Description
Disable or Remove Feature or Program

Disable legacy network protocols that may be used for MiTM if applicable and they are not needed within an environment.

Filter Network Traffic

Use network appliances and host-based security software to block network traffic that is not necessary within the environment, such as legacy protocols that may be leveraged for MiTM.

Limit Access to Resource Over Network

Limit access to network infrastructure and resources that can be used to reshape traffic or otherwise produce MiTM conditions.

Network Intrusion Prevention

Network intrusion detection and prevention systems that can identify traffic patterns indicative of MiTM activity can be used to mitigate activity at the network level.

Network Segmentation

Network segmentation can be used to isolate infrastructure components that do not require broad network access. This may mitigate, or at least alleviate, the scope of MiTM activity.

Detection

Monitor network traffic for anomalies associated with known MiTM behavior. Consider monitoring for modifications to system configuration files involved in shaping network traffic flow.

References