The Wayback Machine - https://web.archive.org/web/20190701124440/https://whatis.techtarget.com/definition/attack-surface
Browse Definitions :
Definition

attack surface

Contributor(s): Matthew Haughn

An attack surface is the total sum of vulnerabilities that can be exploited to carry out a security attack. Attack surfaces can be physical or digital. The term attack surface is often confused with the term attack vector, but they are not the same thing. The surface is what is being attacked; the vector is the means by which an intruder gains access. 

Both physical and digital attack surfaces should be limited in size to protect surfaces from anonymous, public access. Organization can analyze and reduce its physical and digital attack surfaces by taking the following measures:

  • Identify physical and digital assets.
  • Conduct an attack surface analysis.
  • Review asset management policies.
  • Eliminate complexity by reducing unused, redundant or overly permissive rules.
  • Prioritize strengthening most vulnerable attack points first.
  • Continually seek ways to make attack surfaces smaller.

Digital attack surfaces

In a computing , a network attack surface is the totality of all vulnerabilities in connected hardware and software. In order to keep the network secure, network administrators must proactively seek ways reduce the number and size of attack surfaces. There is a law of computing that states that the more code you have running on a system, the greater the chance that the system will have an exploitable security vulnerability. This means that one of the most important steps information technology (IT) administrators can take to secure a system is to reduce the amount of code being executed, which helps reduce the software attack surface.

One popular approach to limiting the size of attack surfaces is a strategy called microsegmentation . With microsegmentation , the data center is divided into logical units, each of which has its own unique security policies. The idea is to significantly reduce the surface available for malicious activity and restrict unwanted lateral (east-west) traffic once the perimeter has been penetrated. Policies are tied to logical segments, so any workload migration will also move the security policies.

Network microsegmentation isn't new, but its adoption has been sparked by software-defined networking (SDN) and software-defined data center (SDDC) technologies. Traditional firewalls remain in place to maintain north-south defenses, while microsegmentation significantly limits unwanted communication between east-west workloads within the enterprise.

Physical attack surfaces

In computing, a physical attack surface includes access to all endpoint devices, including desktop systems, laptops, mobile devices, USB ports and improperly discarded hard drives. Once an attacker has accessed a computing device physically, the intruder will look for digital attack surfaces left vulnerable by poor coding, default security setting or poorly-maintained software that has not been updated or patched. The physical attack surface is exploitable through inside threats such as rogue employees, social engineering ploys and intruders posing as service workers, especially in public companies. External threats include password retrieval from carelessly discarded hardware, passwords on sticky notes and physical break-ins.

Physical security has three important components: access control, surveillance and testing. Obstacles should be placed in the way of potential attackers and physical sites should be hardened against accidents, attacks or environmental disasters. Such hardening measures include fencing, locks, access control cards, biometric access control systems and fire suppression systems. Second, physical locations should be monitored using surveillance cameras and notification systems, such as intrusion detection sensors, heat sensors and smoke detectors. Third, disaster recovery policies and procedures should be tested regularly to ensure safety and to reduce the time it takes to recover from disruptive man-made or natural disasters.

 

 

This was last updated in February 2019

Continue Reading About attack surface

Start the conversation

Please create a username to comment.

-ADS BY GOOGLE

Dateiendungen und Dateiformate

Gesponsert von:

SearchCompliance

SearchSecurity

  • incident response

    Incident response is an organized approach to addressing and managing the aftermath of a security breach or cyberattack, also ...

  • Security Operations Center (SOC)

    A security operations center (SOC) is a command center facility for a team of IT professionals with expertise in information ...

  • incident response team

    An incident response team is a group of IT professionals in charge of preparing for and reacting to any type of organizational ...

SearchHealthIT

SearchDisasterRecovery

  • disaster recovery team

    A disaster recovery team is a group of individuals focused on planning, implementing, maintaining, auditing and testing an ...

  • cloud insurance

    Cloud insurance is any type of financial or data protection obtained by a cloud service provider. 

  • business continuity software

    Business continuity software is an application or suite designed to make business continuity planning/business continuity ...

SearchStorage

  • storage class memory (SCM)

    Storage class memory (SCM) is a type of NAND flash that includes a power source to ensure that data won't be lost due to a system...

  • Hadoop as a service (HaaS)

    Hadoop as a service (HaaS), also known as Hadoop in the cloud, is a big data analytics framework that stores and analyzes data in...

  • blockchain storage

    Blockchain storage is a way of saving data in a decentralized network which utilizes the unused hard disk space of users across ...

Close