An attack on a secure communication protocol where the attacker transmits data to the claimant, Credential Service Provider (CSP), verifier, or Relying Party (RP). Examples of active attacks include man-in- the middle (MitM), impersonation, and session hijacking. Note: NIST SP 800-30 Rev. 1, Appendix E provides a representative list of threat events, including attacks. Active and passive attacks may include: Denial of Service (DoS); Distributed Denial of Service (DDoS); Cross-site Request Forgery (CSRF); Cross- site Scripting (XSS); manipulative communications deception; phishing; laboratory attacks; side channel attacks; spear phishing; whaling; and Trojan Horses.
Sources:
CNSSI 4009-2022