4 ms·
Ok, so this is going to sound crazy, but it's deeper than that. When you put yourself on another port or make yourself invisible on a battlefield you didn't ac
by danielrm26 10y ago
Ok, so this is going to sound crazy, but it's deeper than that.
When you put yourself on another port or make yourself invisible on a battlefield you didn't actually reduce your attack surface. You are equally vulnerable to a bullet or an 0day. If it comes towards you, it will hit you.
What was reduced was their ability to TARGET you. That's not reducing attack surface.
I'm thinking about doing a write-up on risk reduction methods that break all these down, where:
- Obscurity is hiding a secret that reduces your resilience if you are discovered
- Avoidance is limiting the likelihood that you'll be targeted
- Hardening makes you more survivable if you are hit
How does that grab you? You think that's the distinction we need?
Ultimately it's all security because it's reducing risk, i.e. probability and/or impact. But the ways in which that is done are important to understand.
- leepowers 10y agoObscurity, Avoidance, Hardening seem to be useful ways to explore the idea of attack surface and related security concepts. Reducing surface area refers to ways to increase the overall security of a system by restricting the set of features accessible to user groups. Every feature is an attack vector. So limiting access reduces the total number of possible attackers. Surface area is related strongly to the concepts of Obscurity and Avoidance. The other thing to consider is the total risk and any associated costs/tradeoffs. In terms of SSH, changing the port number changes the set of attackers from A) attackers scanning standard ports across many hosts, to B) attackers deep port scanning fewer hosts. The relative risk will decrease if group A is significantly larger than group B. If there are 1,000,000 shallow scanners (group A) and only 100,000 deep scanners (group B) the reduction in relative risk is significant. But what is total risk? Using SSH public-key authentication creates another set of users, group C, that can actually login to the server. Group C is also very small, usually consisting of only 1 member. Whether or not attackers belong to group A or group B isn't particularly significant in total, as the likelihood that a member of A or B is also a member of C is very, very low. This, I think, is the crux of the "security by obscurity" criticism. Such security measures seem to do little to decrease the total risk to a system. So why implement obscure/avoidance measures? The value of changing port numbers or port knocking (and reducing attack surface in general) isn't statistical. The value is completeness, or as a type of insurance. Using alternate port numbers could buy an admin some time if a OpenSSH 0-day occurs. This event isn't very likely, so we might dismiss it. But managing the risk of unlikely events is exactly the point of insurance.