A security analyst is investigating a suspected man-in-the-middle attack against an internal TLS-secured web application. The analyst reviews the certificate chain and notices that the leaf certificate's public key modulus matches an unauthorized external entity. Which fundamental security property of asymmetric cryptography was compromised in this scenario?
Trap 1: Data confidentiality
Data confidentiality ensures that intercepted information cannot be read by unauthorized parties through robust encryption mechanisms. A substitute certificate still allows encrypted sessions, meaning confidentiality technically remains intact while authenticity fails.
Trap 2: System availability
System availability guarantees that network resources and applications remain accessible to authorized users without disruption. Certificate manipulation targets trust and identity validation rather than rendering the web server unreachable or unresponsive.
Trap 3: Message non-repudiation
Non-repudiation prevents a sender from denying the authenticity of their transmitted signature using private key validation. While related to signatures, the primary failure in a fraudulent certificate deployment is establishing correct endpoint identity.
- A
Data confidentiality
Why it fails: Data confidentiality ensures that intercepted information cannot be read by unauthorized parties through robust encryption mechanisms. A substitute certificate still allows encrypted sessions, meaning confidentiality technically remains intact while authenticity fails.
- B
System availability
Why it fails: System availability guarantees that network resources and applications remain accessible to authorized users without disruption. Certificate manipulation targets trust and identity validation rather than rendering the web server unreachable or unresponsive.
- C
Message non-repudiation
Why it fails: Non-repudiation prevents a sender from denying the authenticity of their transmitted signature using private key validation. While related to signatures, the primary failure in a fraudulent certificate deployment is establishing correct endpoint identity.
- D
Entity authenticity
Why it fails: Entity authenticity relies on trusted certificates to prove that the communicating server is indeed who it claims to be. A forged or compromised certificate chain subverts this verification process, allowing malicious actors to impersonate legitimate services.