Attack surfaces represent the total sum of potential entry points into an organization, while attack vectors are the specific methods threat actors use to exploit them. This content covers physical, digital, and human attack categories, along with supply chain risks and cloud service models.
Attack Surfaces & Vectors
When a threat actor targets an organization, they're going to start looking for the way into the organization. What can they leverage to get into the organization? They're going to look at the attack surface and they're going to look for attack vectors to get in.
We can think of the attack surface as all of the different ways combined of how we can get into an organization. I'm going to use this building as an example. Let's say we are trying to break into this building. We may be able to get through the front door, or perhaps we can tunnel into the building. Perhaps we can get through one of the windows. Maybe there's a rooftop access, or maybe we're going to break through a wall. The attack surface of this building would be all of this together, all of the different ways that we could actually break into this building.
The attack vector would be the specific way that we chose to break into it. So if we were to access this building through a window, then that would be our attack vector. If it's through the door, that would be the attack vector. Rooftop access, then that would be it.
Since we're talking about cyber security, let's apply this attack surface to our network and see what that looks like. We have a firewall right here and that guards our network, and so what we have is an attack surface that looks a little like this. However, we also have this wireless signal that's right here. This is a wireless access point and it broadcasts out a big signal, and so anything that's within that signal also has access to this network to a certain degree. So that extends our attack surface.
To better understand the concept, I've broken down the attack surfaces into three different categories. We have the physical attack surface, we have the digital, and we have the human.
The physical is what we've already talked about: physically being able to access into the building, or perhaps it's into the network closet, or access to the equipment wherever that equipment might be. And the problem is that if we have access into the building and break into the building, then what we could do is unplug somebody's computer and plug our own equipment into it, and now we have access to the resources on that network.
We also have to consider the digital attack surface. There is information that's flowing in and out of this network, and since information flows in and out of this network, there might be a way to leverage some of that to get into this network. As an example, this wireless network just gets broadcasted out, and there's no way to really secure the waves from being able to reach anyone. And so if we were sitting out here, we'd be able to access, at least from a layer 1 and two standpoint, some of the information that's flowing. And so that's why it's really important to secure our wireless networks.
Then there's the human side of this. People are physically walking in and out of that building and sitting down at these different machines. They're doing things like accessing their email. So if we can send them an email and leverage some social engineering to trick them into installing something on this machine, we now have access to the rest of the network and the resources on that network. And leveraging social engineering by sending an email and tricking somebody into downloading some sort of software onto that computer is an example of an attack vector.
Within each of these attack surfaces, there are many different ways that we can trick, or we can manipulate or change things, as an attack vector to get into this network.
Physically gaining access could be as simple as walking in the front door. Although what I've seen is that buildings have been more secure and more locked down than they ever have been before, so it may require some sort of social engineering, something like tailgating, to be able to gain access into the physical building.
From a digital standpoint, we could leverage the network. One example might be that we could sit outside the building and gain access to the wireless access points in the wireless network to try to leverage it to get into the rest of the network. Or perhaps we leverage some sort of hardware. Laptops might be brought in and out of that network, and when it's outside of the network, something malicious could happen to it that would be brought back into the network. For instance, we could install some sort of software on it. Software also gets installed and people want that on their machines, and so they'll do that. Or perhaps it's some sort of files that are being transferred back and forth.
An attacker may use unsecured networks as a vector to get into the network. Perhaps it's the wireless network or the wired network, or perhaps it's something like a Bluetooth device that is connecting. Or there could be some open service ports. There are times when we open up holes in the firewall so that they can gain access to things like maybe a web server. Well, those are open ports on the firewall to gain access to the server, and there is a level of access to that server that might be able to be leveraged to gain access to the rest of the network.
There's also hardware that gets installed on your network, whether it's a computer or a switch or server or some other device. And are you getting those from the proper vendor? So that could be a problem as well. Or just removable media: people taking flash drives, random flash drives or other flash drives, and then putting it onto their computer, which could carry a virus.
An attacker may use software and files as a vector to gain access into an organization. Perhaps they're using some sort of vulnerability in already existing software, or perhaps there is some malicious software that they're tricking somebody into installing. A client-based would mean that it gets installed on the machine and runs on the machine, and the agent-based doesn't need to be installed for it to be up and running on the machine. We can also take some of this malicious software and embed it into files, whether it's some sort of image or some sort of document. We can embed it so that we can more easily trick somebody into installing that software.
There's also unsupported systems and applications that get set up on a network. I've had people set up equipment. I've had people install software that cause problems on the network, because they think that they want these extra services and don't want to go through it, so they just install it and then that will cause problems. One of the problems is when this stuff gets installed, a lot of people will leave the default credentials. Well, that can mean that anybody can get onto that device and easily look up these default credentials to be able to gain access, therefore gaining access to the rest of the network and other resources.
Then we have the human aspect of it, or the social engineering. Humans behave in certain patterns, and attackers know how to leverage those patterns to get what they want. Of course, to carry out a social engineering attack, there's got to be some sort of contact. And that contact could come in the form of some sort of message-based contact like email or text messages or instant messaging, or it could be over the phone, some sort of voice conversation, or it could actually be in person.
Now, I've included supply chain as its own category, but it really has roots in all of the other categories. It's just one other aspect we need to keep in mind.
So what is a supply chain? A supply chain is all the goods and resources and everything that goes into creating a product. That's the general idea of what a supply chain is. But what does it look like when it comes to IT? When it comes to IT, supply chain is where we get our resources to provide our services. So we are buying hardware, we're buying software, we're buying cloud resources, we're buying services from other entities. We're buying this stuff so that we can provide resources to our users.
What we need to do is keep that in mind, because if we're buying hardware then there could actually be flaws in that hardware, vulnerabilities in that hardware, or even malicious stuff already installed in that hardware, or even the software, and utilizing the clouds. It's just one other aspect we need to consider because it can be a vector for the attackers.
Just a few things to call out. One of the things is a managed service provider. A managed service provider provides some sort of services for us. For instance, maybe that service is help desk, and so they're providing our help desk services for it. Well, if they have problems within their organization and they're not being secure in the way that they're providing those services, that could be devastating to the rest of our organization. So when we're talking about supply chains, we're talking about the vendors and suppliers and cloud providers that are providing services for us.
There are many different types of cloud providers that are out there. One example would be if you have a Gmail account, or maybe some sort of web mail up in the cloud, then that is what's known as a software as a service, or SaaS. You really don't have to worry about managing hardly anything. It is really just your inbox that you're managing. The rest is all managed up in the cloud. And so that's considered software as a service.
But there are other models as well. There is the model where we have something that's on premise. Of course, that's not in the cloud. In that model right there, we're in charge of everything.
There are also other models in between those. One example is infrastructure as a service. Infrastructure as a service is that they take care of all of the infrastructure, but then you take care of all the virtual machines on top of that. So in this case right here, they are in charge of the data center, networking, storage, servers, all the virtualization, and then on top of that you would turn up a virtual machine, but from you it would just be like a regular machine that you're logging into. Then you would install all the applications and install everything on it to run as if you wanted to run it as if it was installed on your equipment, but it's running on somebody else's infrastructure.
You also have things like platform as a service, which is in between a software as a service and infrastructure as a service. This is an example where they pretty much manage most of it, but there are a few things that you need to manage, like the application and the data behind it. A good example of this is maybe some sort of web hosting where they don't provide just a plug-and-play where you create your web page, but maybe it's somewhere where you're not actually managing the machine itself. It's somewhere in between, where they provide the services but you turn up maybe WordPress on there, or maybe some sort of web instance on there, and you manage the back end of that.
So there are variations of this when it comes to cloud services and how you manage it. Of course, there's also hybrids as well, where we have hybrids in between these or using multiple. For instance, maybe we have some on-premise equipment but also some things like in an infrastructure as a service, and they do some collaborating, they do some communicating, they do some replication, they use some services. So that way we have both on premise and in the cloud. And so there's these hybrid models as well.
Why this is important from a security perspective is that many times there's a shared responsibility when it comes to security. You don't have a lot of control with some of these models of the back-end systems, so you're relying on the other provider in order to make sure that they do security correctly. So there's this shared responsibility when it comes to security. In fact, this is called the shared responsibility model. And depending on which one you're choosing, there's going to be a variation of responsibilities and where those responsibilities fall into who's responsible for it.
So what an attacker is going to do is they're going to look for their attack vector to get into the organization, and all those attack vectors combined makes the attack surface of the different ways they could get in. We talked about some of those common attack vectors, and we categorized them into physical, digital, and human. And then we also talked about the supply chain, because we could have different vendors out there supplying different aspects that could be categorized in the physical, digital, or human as creating some sort of vulnerabilities for us. So it's one of those things that we need to make sure we keep in mind as we're analyzing our vendors and choosing our vendors.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →