Skip to main content

Attack Surface

An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.

What is Attack Surface?

An attack surface is the set of points on the boundary of a system, component, or environment where an attacker can try to enter, cause an effect, or extract data. It includes reachable interfaces and trust transitions within the defined scope. It is a set, not only a count of internet-facing ports. Reducing it removes or restricts unnecessary paths, but it does not prove that the remaining paths are secure.

Why it matters

A clear attack-surface inventory shows where security controls and testing have the most value. It also helps a team find an unintended path before an attacker uses it.

How it works

  1. Define the system boundary, protected assets, users, services, dependencies, and trust relationships.
  2. List the points where an attacker could enter, change behavior, or extract data, including interfaces, credentials, administration paths, and physical access.
  3. Remove unnecessary points, restrict the required points, test the controls, and repeat the review when the system changes.

Example

A database administration service accepts direct internet traffic. The operator removes the public listener, permits access only through an identity-aware proxy, patches the service, and monitors the remaining route.

Pomerium boundary

A Pomerium route can expose a named path to an upstream service and apply identity-aware policy before it forwards a request. The network must also prevent direct access to the upstream service. Pomerium can reduce direct application reachability, but the route, Pomerium deployment, and upstream service remain part of the attack surface.

Limits and non-claims

  • An attack-surface inventory is valid only for its stated scope and point in time.
  • A smaller attack surface can still contain a serious exploitable weakness.
  • A gateway adds its own configuration, software, credentials, and bypass risks to the system.

Evaluation checklist

  • Which entry points, identities, protocols, parsers, dependencies, and trust boundaries can reach the asset?
  • Which adversary can use each path, and which precondition or authority is required?
  • Does the inventory change when routes, tools, credentials, software, or recovery paths change?

Sources and further reading

Keep learning

Network and Infrastructure

Perimeter

A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo