Check: SRG-APP-000215-MAPP-NA
Mobile Application SRG:
SRG-APP-000215-MAPP-NA
(in version v1 r1)
Title
The application must perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources when requested by client systems. (Cat II impact)
Discussion
A recursive resolving or caching Domain Name System (DNS) server is an example of an information system providing name/address resolution service for local clients. Authoritative DNS servers are examples of authoritative sources. Information systems using technologies other than the DNS to map between host/service names and network addresses provide other means to enable clients to verify the authenticity and integrity of response data. Rationale for non-applicability: The mobile operating system is responsible for name/address resolution services. If a mobile application were granted the OS privileges necessary to provide name services to other applications, this would enable the name service application to launch a number of IA attacks against other applications.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46840r1_rule
Vulnerability ID: V-35553
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001663 |
The information system, when operating as part of a distributed, hierarchical namespace, provides the means to enable verification of a chain of trust among parent and child domains (if the child supports secure resolution services). |
Controls
Number | Title |
---|---|
SC-20 |
Secure Name / Address Resolution Service (authoritative Source) |