Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryTesting

Attack Surface

The attack surface is every point where an attacker can interact with a system: interfaces, protocols, ports, debug access, people. How to map it and how to shrink it.

Updated This page as Markdown

In short

The attack surface of a system is the set of all points at its boundary through which an attacker can try to enter, influence it or extract data: network services, radio interfaces, physical ports, APIs, update channels, suppliers and people. NIST defines the term in SP 800-53. The Cyber Resilience Act requires products to be designed to limit it. Mapping the attack surface is the first step of every penetration test and every TARA.

What is an attack surface?

The attack surface is the set of all points at the boundary of a system where an attacker can try to get in, cause an effect or get data out. NIST SP 800-53 Rev. 5 defines it exactly that way for a system, a system component or an environment. In plain terms: every interface, every protocol, every input and every person with access is part of it.

For a connected product the attack surface typically includes network services and open ports, wireless interfaces (Wi-Fi, BLE, cellular, proprietary 2.4 GHz radios), physical interfaces (USB, SD card, UART, JTAG, SWD, exposed flash memory), the cloud API and the mobile app, the firmware update channel, third-party components and the supply chain, and the people who administer or use it. For a vehicle it adds CAN, LIN and Ethernet buses, the OBD port, diagnostic services (UDS, DoIP), telematics and charging interfaces.

Where is it defined?

NIST defines the term in SP 800-53 Rev. 5, SP 800-160 and SP 800-172. OWASP’s Attack Surface Analysis Cheat Sheet describes how to identify, map and manage it for applications: entry and exit points, data flows, the valuable assets behind them, and how changes over time affect it.

In EU law the Cyber Resilience Act turns the concept into a product requirement: Annex I Part I point 2(h) requires products with digital elements to be designed, developed and produced to limit attack surfaces, including external interfaces. In automotive engineering the attack surface is captured in the item definition and the attack path analysis of a TARA under ISO/SAE 21434, and IEC 62443 handles it for industrial systems by dividing them into zones and limiting the conduits between them.

What it means in practice

Mapping the attack surface is the first week of every hardware or ECU penetration test we do and the first work product of every TARA. Only when the list is complete can scope, duration and depth be agreed sensibly. The surprises are almost always on the list of things nobody thought of as interfaces:

  • A UART debug port on the production board with a root shell and no password, found on household appliances and communication modules alike.
  • UDS services that respond in the default session without authentication, including routines that were only meant for the production line.
  • Test and staging endpoints that shipped in the production cloud API, or an MQTT broker that accepts anonymous connections.
  • A firmware update mechanism that is itself the largest attack surface: unauthenticated download, unsigned image, writable update server.
  • The supplier’s remote access to a machine, with shared credentials that outlive the service contract.

Reducing the attack surface is the cheapest security measure there is: disable what is not needed, authenticate what is, segment the rest. Every interface that is closed before release is a class of future vulnerabilities that never has to be found, patched or reported. The CRA requirement is a good argument internally: document every exposed interface in the default configuration together with the reason it has to be exposed. Interfaces without a reason get closed.

Common misunderstandings

An attack surface is not a count of vulnerabilities, and a small one is not automatically secure: one unauthenticated service is enough. “Internal only” is not zero attack surface; it is attack surface that becomes reachable after the first compromise. And the attack surface is not static. Every firmware release, every new cloud feature and every new supplier connection changes it, which is why the map must be maintained, not drawn once.

FAQ

Frequently asked questions

What is the difference between attack surface and vulnerability?

The attack surface is where an attacker can touch the system; a vulnerability is a flaw at one of those points that can be exploited. A large attack surface is not a vulnerability by itself, but every point on it is a place where one can exist and has to be tested. Reducing the surface removes whole classes of future vulnerabilities without finding them first.

Does the Cyber Resilience Act require attack surface reduction?

Yes. Annex I Part I point 2(h) requires products with digital elements to be designed, developed and produced to limit attack surfaces, including external interfaces. In practice that means every exposed interface in the default configuration needs a reason, and debug and test interfaces are closed or protected before shipping.

How do you determine the attack surface in a penetration test?

Interface by interface: network scans and service enumeration, radio surveys for BLE, Wi-Fi and proprietary links, inspection of the circuit board for debug ports and memory, enumeration of diagnostic services on vehicle buses, review of the mobile app and cloud API, and a look at the update mechanism. The result is a list that scoping, testing and the report all refer back to.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab