O
OSCF Handbook Accessible cybersecurity standards
Draft v0.1 Repo Framework Docs Overview
← Back to Framework

Framework

Threat Model

Primary threats and mitigations.

Latest version

AGVS Draft v0.1

This section is part of the current public OSCF documentation draft.

Replay attack

Reuse of a previously valid challenge response.

Automation

Bot-generated or scripted interaction attempting to bypass verification.

Shoulder surfing

Observation of a verification flow by a nearby attacker.

Session hijacking

Reuse or theft of an active verification session.

Mitigations

  • unique challenge nonce
  • short expiration time
  • session binding
  • rate limiting
  • risk-based escalation
  • audit logging
Draft section of the OSCF public documentation.