arrow
Return

Attack Surface Score for Software Systems

delete2025-08-22
delete0
PRE
AI
Y
Yudeep Rajbhandari *
R
Rokin Maharjan *
S
Sakshi Shrestha
T
Tomáš Černý *
DOI:10.3390-fi17070305delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Software attack surfaces define the external boundaries—entry points, communication channels, and sensitive data stores through which adversaries may compromise a system. This paper introduces a scoring mechanism that produces a normalized attack-surface metric in the range of 0–1. Building on the established Damage-Potential-to-Effort ratio, our approach further incorporates real-world vulnerability intelligence drawn from MITRE’s CVE and CWE repositories. We compute each application’s score by ingesting preliminary findings from a static-analysis tool and processing them through our unified model. To assess effectiveness, we validate the scoring system across a spectrum of scenarios, from a simple Java application to complex enterprise applications. The resulting metric offers development and security teams a concise, objective measure to monitor an application’s attack surface and hence proactively identify vulnerabilities in their applications. This tool can also be used to benchmark various third-party or dependent applications, enabling both developers and security practitioners to better manage risk.
Keywords:
attack surface
vulnerability intelligence
static analysis
security scoring
risk management

Journal

Future Internet cover
Future Internet
IF:
3.6
Papers:
1.2K
Citations:
6.5K

Organization

B
Baylor University
Scholars:
6.3K
Papers: 5.4K
Citations: 5.2K
U
University of Arizona
Scholars:
3.6W
Papers: 3.2W
Citations: 980
E
East Tennessee State University
Scholars:
2.7K
Papers: 2.0K
Citations: 8
researcher View more organizations