Message Spoofing Clause Samples

Message Spoofing. An attacker may forge messages from the client or server. Spoofing may occur at multiple layers in the in the protocol stack. This threat does not include taking over a session, which is described in section 4.3.9 as “Session Hijacking”. By spoofing messages from the client or server, attackers may perform unauthorized operations and avoid detection of their activities. Message spoofing impacts integrity and authorization.
Message Spoofing. As specified in the OpenSecureChannel service in [UA Part 4], OPC UA counters message spoofing threats by the possibility to sign messages. Additionally all messages must contain a valid session id and are assigned to a secure channel.