Identifying the Attack Surface
Joxean Koret, Elias Bachaalany · 2015
The attack surface of any software is the exposed surface, which can be used by unauthorized users to discover and exploit vulnerabilities. The attack surface can be divided into two groups: local and remote. This chapter discusses how to identify the attack surface of antivirus software. To some extent, we can apply the techniques and tools described in the chapter to any software when determining where to aim attack against chosen Goliath. The chapter illustrates how to use tools provided by the operating system, as well as specialized tools that will aid us in identifying the local and remote attack surface and techniques to determine the odds of discovering "gold." The tools and techniques vary, depending on the components we are analyzing and the target operating systems. Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP) exploit mitigations that are implemented in recent operating systems.