Attack surface denotes all exposed interfaces, components, and configurations of a system through which an attacker can gain access or cause harm. It includes code, APIs, network endpoints, user interfaces, and operational processes. The concept supports risk identification, prioritisation of hardening efforts, and targeted security planning.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
The attack surface is the set of reachable interfaces, components, configurations, and process paths through which a system can be attacked or influenced.
The term comes from security work on software and networked systems with many reachable entry points. As web, cloud, and supply-chain architectures expanded, teams needed a systematic way to inventory, measure, and prioritize those exposures. OWASP frames this as a practical analysis of in- and out-flow paths, sensitive data, and especially risky areas.
Think of a system like a fortress with doors, windows, service corridors, and switches. The attack surface is not only the openings themselves, but also the paths behind them: which APIs, identities, code paths, and operational functions are reachable and which controls protect them. Analysis means mapping those points, ordering them by risk, and closing or monitoring the most important ones first.
A reachable access point across a trust boundary, such as a UI, API, port, or service.
The route through which data, commands, or requests flow into or out of the system.
Authentication, authorization, validation, logging, and similar controls limit how exposed a path is.
Enabled services, settings, and third-party components can expand or shrink the visible surface.
The concrete path or entry point an attacker actually uses.
The concept is useful in architecture reviews, threat modeling, penetration tests, cloud inventories, and before releases or integration changes. It focuses hardening on exposed areas and reveals when new APIs, third parties, or enabled features change risk. A smaller surface lowers risk, but it does not replace vulnerability management or strong authentication and authorization.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.