Attack Vectors
An attack vector is the route an attacker takes to reach a target — the specific path, not the motive or the outcome. Mapping vectors is how a defender moves from listing threats to deciding where controls actually go, and in identity verification the useful map is unusual: the most damaging vectors bypass the sensor entirely rather than trying to fool it.
| Definition | The route or method by which an attacker reaches a target |
| Distinct from attack surface | The surface is everything exposed; a vector is one path across it |
| Distinct from payload | The vector is how access is obtained; the payload is what is done with it |
| General categories | Human, credential, software, network, supply chain, physical |
| In identity verification | Document, presentation, injection, enrollment, and recovery |
| Displacement effect | Closing one vector moves attackers to the next cheapest, rather than stopping them |
| Consequence | Coverage is about the weakest path, not the average control |
The vectors that matter in identity verification
Generic security taxonomies list phishing, malware and misconfiguration. That framing does not help someone building a verification flow, because it describes the enterprise rather than the check. The relevant map is narrower:
| Vector | What the attacker does | What closes it |
|---|---|---|
| Document | Presents a forged, altered or borrowed document | Authentication of security features, and tamper analysis |
| Presentation | Shows the camera a photo, screen, mask or replay | Liveness detection |
| Injection | Bypasses the camera and feeds media directly to the application | Device and stream integrity signals |
| Enrollment | Passes verification using a real but stolen or fabricated identity | Document authentication plus biometric binding |
| Recovery | Skips verification entirely by claiming lost credentials | Re-proofing with evidence rather than questions |
Two things stand out from reading down that table. The first three attack the check; the last two go around it. And the last two are usually the least defended, because they were designed as convenience paths rather than as security surfaces.
Injection is the vector that changed the shape of the problem
Worth isolating, because it breaks an assumption most verification flows were built on.
A liveness check assumes the image it evaluates came from the camera it asked. A presentation attack accepts that assumption and tries to fool the camera with a printed photo, a screen or a mask — and it can be defended by analyzing the image for the signs of a replica.
An injection attack denies the assumption. Using a virtual camera, an emulator, a modified client or an intercepted API call, the attacker supplies media the camera never saw. The image may be flawless and entirely synthetic, and no amount of analysis of its content will reveal that it was never captured — because the evidence of the attack is not in the image. It is in the device, the client integrity and the transport.
That is why injection attack detection is a separate control rather than a better liveness model, and why a vendor answering “how do you handle injection?” with a description of image analysis has answered a different question.
Why mapping vectors matters
The practical value of the concept is that it forces the right question. Not “is this control good?” but “which path does it close, and what is now the cheapest path that is still open?”
Attackers are economically rational. Chip cards did not reduce card fraud; they moved it to card-not-present channels. Tokenization did not stop mobile payment fraud; it moved it to provisioning. Strong authentication did not end account takeover; it moved it to recovery. In each case a control worked exactly as designed and the attack relocated.
The conclusion for identity verification is that coverage is determined by the weakest path rather than the strongest control. A flow with excellent document authentication, strong liveness and an account recovery process built on security questions has one vector defended to a high standard and one wide open — and the attacker will choose. Identity document verification closes the document and enrollment vectors; whether the recovery path is closed is a separate decision that is frequently never made.
What vector mapping can’t do
It cannot enumerate the unknown. A map covers the paths someone thought of, and novel vectors are by definition absent from it.
It does not rank by likelihood. Listing a path says nothing about how often it is used or what it costs an attacker, and treating a list as a priority order is a common error.
It does not account for combinations. Real attacks chain vectors — smishing to obtain a code, then provisioning, then payment — and each link may look tolerable alone.
Closing a vector displaces rather than removes. The activity relocates to the next cheapest path, which is a reason to map continuously rather than once.
Frequently asked questions
What is an attack vector?
The route or method an attacker uses to reach a target — the path rather than the motive or the result. Attack surface describes everything exposed; a vector is one specific way across it; the payload is what the attacker does once through.
What are the main attack vectors in identity verification?
Five: the document itself, presentation attacks against the camera, injection attacks that bypass the camera, enrollment using a real but stolen or fabricated identity, and account recovery. The first three attack the check; the last two go around it, and they are usually the least defended.
What is the difference between a presentation attack and an injection attack?
A presentation attack shows the camera something fake — a printed photo, a screen, a mask — and can be caught by analyzing the captured image. An injection attack bypasses the camera entirely and supplies media directly, so the image may be flawless and no analysis of its content will reveal it was never captured.
Why does closing one attack vector not reduce fraud?
Because attackers relocate rather than stop. Chip cards moved fraud to card-not-present channels; tokenization moved it to wallet provisioning; strong authentication moved account takeover to recovery. Each control worked as designed, and the activity found the next cheapest path.
Related reading
- Liveness detection — the control closing the presentation vector, and the assumption it makes
- Digital tampering — the document vector, and how an edited file betrays itself
- New account fraud — what the enrollment vector produces
- Account takeover fraud — where the recovery vector leads