DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

Reconciling external attack surface findings with what you already own

Reconciling external attack surface findings with what you already own

An external scan produces a list of addresses, hostnames and certificates. Comparing that list with the asset inventory is where most of the value sits, because the entries that appear in the scan and not in the inventory are either forgotten infrastructure or somebody else's. Both findings are worth an afternoon.

Sources that describe the same thing differently

The inventory is organised by owner and application. Certificate transparency logs are organised by hostname. DNS zones are organised by record. Cloud accounts are organised by resource identifier. None of these agree by default, and none of them is complete on its own. The reconciliation starts by choosing a single key, usually the fully qualified domain name, and mapping everything to it.

The four buckets

  • Present in both the scan and the inventory, with a named owner. This is the majority and needs the least attention.
  • Present in the scan, absent from the inventory. This is where shadow infrastructure lives: a marketing landing page, an acquired company's domain, a developer's test host with a public address.
  • Present in the inventory, absent from the scan. Either the asset is not actually reachable, the scan did not cover that address range, or the inventory entry is stale.
  • Absent from both. This bucket is invisible and is the reason to use more than one discovery source, because two blind spots do not cancel out.

Ownership is the output

A reconciled list without an owner per entry becomes a second inventory that decays at the same rate as the first. The useful artefact assigns each hostname to a team, records how that team was determined, and defines what happens when the assignment is disputed. Anything nobody claims goes to a queue with a deadline rather than being left unassigned.

Certificates as a discovery channel

Certificate transparency records every publicly trusted certificate issued for a name. Watching the stream for the organisation's names and for lookalike names catches new services as they are deployed and typosquatting as it is registered. The signal is public, so the only work is filtering it to something an analyst can read.

References

  • Certificate Transparency, RFC 6962
  • NIST SP 800-53 Revision 5, Asset Management controls
  • CISA Continuous Diagnostics and Mitigation program documentation

Top comments (0)