← Back to Framework
Framework
Threat Model
Primary threats and mitigations.
Latest version
AGVS Draft v0.1This section is part of the current public OSCF documentation draft.
Replay attack
Reuse of a previously valid challenge response.
Automation
Bot-generated or scripted interaction attempting to bypass verification.
Shoulder surfing
Observation of a verification flow by a nearby attacker.
Session hijacking
Reuse or theft of an active verification session.
Mitigations
- unique challenge nonce
- short expiration time
- session binding
- rate limiting
- risk-based escalation
- audit logging