attack surface
ründepind
olemus
kaitstava objekti (seadme, tarkvara, süsteemi, võrgu)
täielik nõrkuste hulk või
täielik ründevektorite hulk
NIST SP 800-53 Rev. 5:
the set of points on the boundary of a system, a system component, or an environment where an attacker can try to enter, cause an effect on, or extract data from, that system, component, or environment
ülevaateid
https://en.wikipedia.org/wiki/Attack_surface
https://www.youtube.com/watch?v=nqpCqSVVWuw
https://cheatsheetseries.owasp.org/cheatsheets/Attack_Surface_Analysis_Cheat_Sheet.html
http://www.cs.cmu.edu/afs/cs/usr/wing/www/publications/ManadhataWing04.pdf
http://reports-archive.adm.cs.cmu.edu/anon/2008/CMU-CS-08-152.pdf
https://security.netenrich.com/blog/attack-surface-discovery/
https://irtf.org/raim-2015-papers/raim-2015-paper44.pdf
https://mlsec.info/pdf/phdthesis.pdf
http://resources.infosecinstitute.com/attack-surface-reduction/
vt ka
- dünaamiline ründepind
- füüsiline ründepind
- manipuleerimise ründepind
- tarkvara ründepind
- võrguründepind