Unit content
Attack surfaces and exposed interfaces
A system's attack surface is the set of interfaces through which an adversary can influence or observe it.
Examples include
- network endpoints;
- file and document formats;
- command-line arguments and environment variables;
- device inputs;
- parsers and decoders;
- privileged APIs;
- browser-facing forms and application protocols.
An interface matters because it accepts potentially adversarial data, triggers work or exposes information.
Adding features can enlarge the attack surface even when each feature is legitimate. A new parser, protocol endpoint or plugin mechanism creates additional behavior that must safely handle adversarial inputs.
Reducing attack surface means removing unnecessary exposure or narrowing the operations and inputs an interface accepts. It does not mean that every exposed interface is vulnerable; it means each one is another place where the threat model must be enforced.