Browse Definitions:
Definition

offensive security

Contributor(s): Ivy Wigmore

Offensive security is a proactive and adversarial approach to protecting computer systems, networks and individuals from attacks. Conventional security -- sometimes referred to as "defensive security" -- focuses on reactive measures, such as patching software and finding and fixing system vulnerabilities. In contrast, offensive security measures are focused on seeking out the perpetrators and in some cases attempting to disable or at least disrupt their operations.

At the RSA 2012 conference, Paul Asadoorian and John Strand presented methods that companies can use to frustrate would-be attackers, gather information about them, and cautiously retaliate without illegal actions. The men, both instructors at the SANS Institute, thought that their offensive methods for penetration testing could be used defensively.

Asadoorian and Strand recommend that companies place statements in likely network entrance points warning that anyone attempting to gain access will be subjected to an NAC-like check, which would inform the attacker that their machine data, IP and MAC addresses would be gathered.

The three components of Asadoorian and Strand's method are annoyance, attribution and attack. The annoyance component consists of frustrating the attacker's attempt through tools that establish false ports, services and directories. Once the attacker is lured into the false system, he ends up looping endlessly through it.

Attribution -- accurately identifying the attacker -- is important. One method, as Asadoorian explained, is to put a Web bug in sensitive documents. If the document is accessed, the Web bug sends back information about the system that accessed it.

According to Asadoorian, the attack component should only be an enhancement of the annoyance and attribution capabilities, rather than a truly malicious -- and illegal -- assault on the attacker. 

 

This was last updated in November 2012

Continue Reading About offensive security

Join the conversation

1 comment

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

I've got to say every time I read something that someone has put a "buzz" word to doing your job it becomes rather offensive. The idea "Offensive Security" is nothing new in fact it's just plain & simple called DOING YOUR JOB. But for those that just have picked up the "Information Assurance" buzz because it might actually get them a income, might need to know that being in front of the mess is called doing your job and it's what you are paid to do. CISO KS
Cancel

-ADS BY GOOGLE

File Extensions and File Formats

SearchCompliance

SearchSecurity

  • black hat

    Black hat refers to a hacker who breaks into a computer system or network with malicious intent.

  • copyright

    Copyright is a legal term describing ownership of control of the rights to the use and distribution of certain works of creative ...

  • keylogger (keystroke logger or system monitor)

    A keylogger, sometimes called a keystroke logger or system monitor, is a type of surveillance technology used to monitor and ...

SearchHealthIT

  • population health management (PHM)

    Population health management (PHM) is a discipline within the healthcare industry that studies and facilitates care delivery ...

  • ICD-10-PCS

    The International Classification of Diseases, 10th Revision, Procedure Coding System (ICD-10-PCS) is a U.S. cataloging system for...

  • U.S. National Library of Medicine (NLM)

    The U.S. National Library of Medicine (NLM) is the largest biomedical library in the world.

SearchDisasterRecovery

  • business continuity plan (BCP)

    A business continuity plan (BCP) is a document that consists of the critical information an organization needs to continue ...

  • call tree

    A call tree -- sometimes referred to as a phone tree -- is a telecommunications chain for notifying specific individuals of an ...

  • mass notification system (MNS)

    A mass notification system is a platform that sends one-way messages to inform employees and the public of an emergency.

SearchStorage

  • open source storage

    Open source storage is data storage software developed in a public, collaborative manner that permits the free use, distribution ...

  • CompactFlash card (CF card)

    A CompactFlash card (CF card) is a memory card format developed by SanDisk in 1994 that uses flash memory technology to store ...

  • email archiving

    Email archiving (also spelled e-mail archiving) is a systematic approach to saving and protecting the data contained in email ...

SearchSolidStateStorage

  • RRAM or ReRAM (resistive RAM)

    RRAM or ReRAM (resistive random access memory) is a form of nonvolatile storage that operates by changing the resistance of a ...

  • JEDEC

    JEDEC is a global industry group that develops open standards for microelectronics.

  • M.2 SSD

    An M.2 SSD is a solid-state drive (SSD) that conforms to a computer industry specification written for internally mounted storage...

SearchCloudStorage

  • RESTful API

    A RESTful application program interface breaks down a transaction to create a series of small modules, each of which addresses an...

  • cloud storage infrastructure

    Cloud storage infrastructure is the hardware and software framework that supports the computing requirements of a private or ...

  • Zadara VPSA and ZIOS

    Zadara Storage provides block, file or object storage with varying levels of compute and capacity through its ZIOS and VPSA ...

Close