Browse Definitions :
Definition

network attack surface

Contributor(s): Matthew Haughn

The network attack surface is the totality of all vulnerabilities in connected hardware and software that are accessible to unauthenticated users.

Every point of network interaction is a part of the network attack surface. Hackers, industrial spies and malware such as worms and advanced persistent threats (APTs) target these points for potential entry to a network they wish to disrupt or capture data from.

A network’s attack surface is most often exploited through remote access and intrusion but Wi-Fi and even local area networks (LANs) must also be considered in a complete view of the attack surface.  Technologies that rely on tunneling such as virtual private networks (VPNs), peer-to-peer (P2P) and Teredo constitute a threat to networks, as they circumvent intrusion prevention and other security measures.

The network attack surface can be reduced by closing unnecessary ports and limiting resources available to untrusted users and the Internet in general with techniques like MAC address filtering. Any forms of tunneling should be limited to those that are necessary, and access should be stringently controlled. Limiting some network attack vectors can also limit exposure of existing software vulnerabilities by blocking access to them.

 A complete attack surface analysis is crucial to proper set up of breach detection systems (BDS), firewall, intrusion prevention systems, data policy and other security measures. Many attack approaches exploit a combination of attack surface types to gain access to desired resources.

See also: software attack surface, physical attack surface, social engineering attack surface

This was last updated in January 2015

Continue Reading About network attack surface

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • compliance audit

    A compliance audit is a comprehensive review of an organization's adherence to regulatory guidelines.

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

  • Whistleblower Protection Act

    The Whistleblower Protection Act of 1989 is a law that protects federal government employees in the United States from ...

SearchSecurity

  • orphan account

    An orphan account, also referred to as an orphaned account, is a user account that can provide access to corporate systems, ...

  • voice squatting (skill squatting)

    Voice squatting is an attack vector for voice user interfaces (VUIs) that exploits homonyms (words that sound the same but are ...

  • WPA3

    WPA3, also known as Wi-Fi Protected Access 3, is the third version of the security certification program developed by the Wi-Fi ...

SearchHealthIT

SearchDisasterRecovery

  • business continuity policy

    Business continuity policy is the set of standards and guidelines an organization enforces to ensure resilience and proper risk ...

  • business continuity and disaster recovery (BCDR)

    Business continuity and disaster recovery (BCDR) are closely related practices that describe an organization's preparation for ...

  • warm site

    A warm site is a type of facility an organization uses to recover its technology infrastructure when its primary data center goes...

SearchStorage

  • cache memory

    Cache memory, also called CPU memory, is high-speed static random access memory (SRAM) that a computer microprocessor can access ...

  • enterprise storage

    Enterprise storage is a centralized repository for business information that provides common data management, protection and data...

  • disk array

    A disk array, also called a storage array, is a data storage system used for block-based storage, file-based storage or object ...

Close