Browse Definitions :
Definition

network attack surface

The network attack surface is the totality of all vulnerabilities in connected hardware and software that are accessible to unauthenticated users.

Every point of network interaction is a part of the network attack surface. Hackers, industrial spies and malware such as worms and advanced persistent threats (APTs) target these points for potential entry to a network they wish to disrupt or capture data from.

A network’s attack surface is most often exploited through remote access and intrusion but Wi-Fi and even local area networks (LANs) must also be considered in a complete view of the attack surface.  Technologies that rely on tunneling such as virtual private networks (VPNs), peer-to-peer (P2P) and Teredo constitute a threat to networks, as they circumvent intrusion prevention and other security measures.

The network attack surface can be reduced by closing unnecessary ports and limiting resources available to untrusted users and the Internet in general with techniques like MAC address filtering. Any forms of tunneling should be limited to those that are necessary, and access should be stringently controlled. Limiting some network attack vectors can also limit exposure of existing software vulnerabilities by blocking access to them.

 A complete attack surface analysis is crucial to proper set up of breach detection systems (BDS), firewall, intrusion prevention systems, data policy and other security measures. Many attack approaches exploit a combination of attack surface types to gain access to desired resources.

See also: software attack surface, physical attack surface, social engineering attack surface

This was last updated in January 2015

Continue Reading About network attack surface

SearchCompliance
  • compliance risk

    Compliance risk is an organization's potential exposure to legal penalties, financial forfeiture and material loss, resulting ...

  • information governance

    Information governance is a holistic approach to managing corporate information by implementing processes, roles, controls and ...

  • enterprise document management (EDM)

    Enterprise document management (EDM) is a strategy for overseeing an organization's paper and electronic documents so they can be...

SearchSecurity
  • session key

    A session key is an encryption and decryption key that is randomly generated to ensure the security of a communications session ...

  • computer forensics (cyber forensics)

    Computer forensics is the application of investigation and analysis techniques to gather and preserve evidence from a particular ...

  • multifactor authentication (MFA)

    Multifactor authentication (MFA) is a security technology that requires more than one method of authentication from independent ...

SearchHealthIT
SearchDisasterRecovery
  • risk mitigation

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • call tree

    A call tree is a layered hierarchical communication model that is used to notify specific individuals of an event and coordinate ...

  • Disaster Recovery as a Service (DRaaS)

    Disaster recovery as a service (DRaaS) is the replication and hosting of physical or virtual servers by a third party to provide ...

SearchStorage
  • cloud storage

    Cloud storage is a service model in which data is transmitted and stored on remote storage systems, where it is maintained, ...

  • cloud testing

    Cloud testing is the process of using the cloud computing resources of a third-party service provider to test software ...

  • storage virtualization

    Storage virtualization is the pooling of physical storage from multiple storage devices into what appears to be a single storage ...

Close