DefinitionThe attack surface is the set of points through which an intruder can try to enter an environment or extract data from it. ASM is the practice of mapping and reducing it continuously; EASM focuses on what is exposed to the internet.
What makes up the attack surface
The surface includes everything an attacker can reach:
- External: domains, subdomains, IPs, web applications, APIs, VPNs, cloud services and certificates exposed to the internet.
- Internal: servers, workstations, applications and accounts reachable from the corporate network.
- Human: people who can be targeted by phishing and social engineering.
- Third parties: suppliers and integrations with access to your systems or data.
How ASM/EASM works
ASM (Attack Surface Management) treats the surface as something that changes all the time. EASM (External Attack Surface Management) looks at the environment from the outside in, as an attacker would. It continuously discovers assets linked to the organization, including ones nobody remembered, such as legacy systems, forgotten test environments and services contracted without going through IT (shadow IT). It then identifies exposures, such as open ports, vulnerable versions, misconfigurations and expired certificates, and routes them for remediation.
ASM vs vulnerability management
Vulnerability management starts from a known inventory and looks for flaws in it. ASM answers an earlier question: what exists and is exposed? The two practices complement each other. An asset that is not in the inventory is neither scanned nor patched, and that is exactly where many attacks begin. Shrinking the surface by shutting down what is not needed also reduces the number of flaws to manage.
Frequently asked questions
What is the difference between ASM and EASM?
ASM covers the entire attack surface, internal and external. EASM focuses on internet-facing assets, seen from the outside as an attacker would see them.
How do you reduce the attack surface?
By keeping the inventory up to date, shutting down unused services and systems, limiting what is exposed to the internet, requiring MFA and quickly fixing flaws on exposed assets.