risk
Session hijacking and unauthorized-protocol egress
Adversary hijacks established legitimate sessions (externally or internally based) and conducts attacks/exfiltration using unauthorized ports, protocols, and permitted information flows across the perimeter.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Network & Communications Security
- Access Control & Identity Management
- taxonomy
- nist-800-30-threat-event
- inherent_rating
- medium
Details
- risk_id
- net-session-hijacking
- category
- cyber_security
- likelihood
- medium
- impact
- high
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-NET-14 — Enforce policy on cross-domain information exchange mitigates Session hijacking and unauthorized-protocol egress
- strength
- related
- rationale
- Enforcing authorized flow directions/types at cross-domain interconnections constrains the permitted flows abused for egress.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Session hijacking and unauthorized-protocol egress
- strength
- primary
- rationale
- Deny-by-default egress control and monitoring of communications crossing the boundary block exfiltration over unauthorized ports/protocols named in the risk.
- UC-ACCESS-12 — Lock, limit, and terminate user sessions mitigates Session hijacking and unauthorized-protocol egress
- strength
- primary
- rationale
- Inactivity termination, concurrent-session limits, and re-authentication for sensitive operations directly shrink the window and impact of hijacked sessions.
- UC-NET-03 — Provide trusted channels and control session lifecycle mitigates Session hijacking and unauthorized-protocol egress
- strength
- primary
- rationale
- Protecting session authenticity/integrity against hijacking, insertion, and replay and terminating idle sessions is the operative session-hijacking defense.