Attack surface analysis identifies every possible entry point into a system—physical, digital, social, and through third-party connections—giving security professionals a complete picture of where a network is exposed. Modern networks are more accurately modeled as layered but permeable structures, not hardened perimeters, making comprehensive surface mapping essential.
Attack Surface Analysis
By doing all this reconnaissance, we start developing an idea of what the attack surface is.
If I was looking to break into a castle here, I'd start looking at all of the ways that I could get into it. Maybe I'd approach it from this bridge right here. Maybe I approach it from the water. And maybe I approach it from this backside somehow, if there's a way I could get to the backside and approach it from here. As I start looking at this, I start looking at the surface of this castle. Well, that's the attack surface right there. That is what I'm able to see, what I'm able to access, what I might be able to leverage to get into this castle.
The attack surface is the total of all possible entry points into a system. When we're looking at a network, we're going to start looking at where are all the possible ways we could attack this network. We're going to look at the surface area of this and where it's exposed. What we can see is that there's a firewall right here that's guarding the rest of the network. But that's not the only attack surface. We need to start opening up our minds that the attack surface is much greater than just that outside barrier.
We used to think the attack surface was just like this onion, that you would have this really strong perimeter on the outside and it would be very difficult to get to the inside because you couldn't even penetrate this outside right here. And we wanted still to have some sort of defense in depth, so we put extra barriers all the way on to the inside so that no one could ever get to our valuable assets.
But now security is being looked at more like something like an artichoke, where you do have different layers, but these layers definitely have weaknesses to them. So if we can find a way through one layer, we can weave our way through these different layers here to get to the inside core, to get to the assets. One reason why we figured this out is because so many networks continually get broken into despite feeling like they have good security.
So when we're looking at the attack surface here, we're not just looking at this perimeter. Well, it's got a firewall, but what else does it have? It's got a hole in the firewall so that people can access the web server. So now that we can access this web server, maybe somehow we can leverage that to get to the rest of the network. We also have this wireless access point right here — maybe somehow we can gain access to this wireless network to get into this network. Or we have a user over here that's using this system; maybe we can access through this user to get into this system. These are all viable routes. So our attack surface is really this whole area here and ways that we can get in. Maybe we can even break into the building and plug into the switch itself and gain access to this network.
So how would we carry out our attack? We could carry out some sort of physical attack — that is, we could show up and plug in the equipment into it. Or maybe it's some sort of digital attack, where we have some sort of network, software or data files that we can use to access the network. We can do some sort of social engineering attack using humans. We can do some sort of outside entity: maybe we have access to a supply chain, maybe we have access to the cloud provider, maybe it's some other vendors, and through those vendors gain access into the network.
From the physical perspective, maybe we have physical access to this equipment. Could we break into this area and plug our equipment into it, or trick somebody into plugging certain equipment into it? Maybe we sell them some sort of equipment that they plug into the network, somehow gaining physical access to this equipment. Or there's also removable media devices that can come in and out of that physical location and be plugged into this network.
There are also ways where we don't have to physically be available, but somehow digitally we get into this. One of the ways is through the network right here. Maybe they've not secured the wireless network and we can get through there. Or maybe there's some sort of Bluetooth that we can get in through. And even the wired network here — somehow get through this wired network because they left something undone.
We could also scan things like maybe this web server for open service ports. So we can start scanning this network and figuring out digitally how we can get in through that network.
But there is also software. People install software on the machines. We can get our software inside this network, and now we have access to the network. The other thing we could have is some sort of data files, maybe delivering a virus to a person and getting them to click and install that on a machine. So data files is another example.
If we're doing the social engineering attack, maybe we're doing that in person, or maybe it's by video, or a voice call, or message based like email, SMS and text messages, or instant messaging.
And here again we have outside entities. Businesses don't operate alone nowadays. They have customers, and maybe the customers are accessing this network somehow. Maybe there's some sort of network services that we can find an entry point through. They partner with other partners, and in doing so a lot of times they share connections with different resources, and so maybe we can leverage that. There's also a lot of people using cloud vendors nowadays, and managed service providers, and there's a lot of other vendors that we can do some sort of supply chain attack through, because the connectivity is more so than it ever has been in the past.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →