Browse Definitions :
Definition

offensive security

Offensive security is a proactive and adversarial approach to protecting computer systems, networks and individuals from attacks. Conventional security -- sometimes referred to as "defensive security" -- focuses on reactive measures, such as patching software and finding and fixing system vulnerabilities. In contrast, offensive security measures are focused on seeking out the perpetrators and in some cases attempting to disable or at least disrupt their operations.

At the RSA 2012 conference, Paul Asadoorian and John Strand presented methods that companies can use to frustrate would-be attackers, gather information about them, and cautiously retaliate without illegal actions. The men, both instructors at the SANS Institute, thought that their offensive methods for penetration testing could be used defensively.

Asadoorian and Strand recommend that companies place statements in likely network entrance points warning that anyone attempting to gain access will be subjected to an NAC-like check, which would inform the attacker that their machine data, IP and MAC addresses would be gathered.

The three components of Asadoorian and Strand's method are annoyance, attribution and attack. The annoyance component consists of frustrating the attacker's attempt through tools that establish false ports, services and directories. Once the attacker is lured into the false system, he ends up looping endlessly through it.

Attribution -- accurately identifying the attacker -- is important. One method, as Asadoorian explained, is to put a Web bug in sensitive documents. If the document is accessed, the Web bug sends back information about the system that accessed it.

According to Asadoorian, the attack component should only be an enhancement of the annoyance and attribution capabilities, rather than a truly malicious -- and illegal -- assault on the attacker. 

 

This was last updated in November 2012

Continue Reading About offensive security

SearchCompliance

  • information governance

    Information governance is a holistic approach to managing corporate information by implementing processes, roles, controls and ...

  • enterprise document management (EDM)

    Enterprise document management (EDM) is a strategy for overseeing an organization's paper and electronic documents so they can be...

  • risk assessment

    Risk assessment is the identification of hazards that could negatively impact an organization's ability to conduct business.

SearchSecurity

  • spam trap

    A spam trap is an email address that is used to identify and monitor spam email.

  • honeypot (computing)

    A honeypot is a network-attached system set up as a decoy to lure cyber attackers and detect, deflect and study hacking attempts ...

  • cracker

    A cracker is someone who breaks into someone else's computer system, often on a network; bypasses passwords or licenses in ...

SearchHealthIT

SearchDisasterRecovery

  • risk mitigation

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • call tree

    A call tree is a layered hierarchical communication model that is used to notify specific individuals of an event and coordinate ...

  • Disaster Recovery as a Service (DRaaS)

    Disaster recovery as a service (DRaaS) is the replication and hosting of physical or virtual servers by a third party to provide ...

SearchStorage

  • cloud testing

    Cloud testing is the process of using the cloud computing resources of a third-party service provider to test software ...

  • storage virtualization

    Storage virtualization is the pooling of physical storage from multiple storage devices into what appears to be a single storage ...

  • erasure coding

    Erasure coding (EC) is a method of data protection in which data is broken into fragments, expanded and encoded with redundant ...

Close