The Software Attack Surface Analysis Report documents the results of attack surface analysis activities, identifying the points where unauthorized users could enter or extract data from a software environment.
The Software Attack Surface Analysis Report (SASAR) documents the results of the attack surface analysis activities. The attack surface of a software environment is the sum of the different points of attack vectors where unauthorized users enter data to, or extract data from, software an environment. Keeping the attack surface as small as possible is a key Software Assurance (SwA) objective. The SASAR involves the following:
a. Updating the Software Threat Assessment Report (STAR), DI-IPSC-82251A, with all attack surfaces enumerated and documented in the SASAR.
b. Identifying directly or by reference in the Software Development Plan (SDP), Firmware Development Plan (FDP), Program Protection Implementation Plan (PPIP), or equivalent documents, that design or modification of the software attack surface areas defined by the SASAR, require formal cybersecurity and software assurance review, assessment, and documented within the system test plan.
c. The SASAR is used as input to the risk assessments completed in the Software Vulnerability Assessment Report (SVAR), DI-IPSC-82252, and the Software Assurance Evaluation Report (SAER), DI-IPSC-82249.
This DID contains the format, content, and intended use information for the data deliverable resulting from the work task described in the contract. This DID can be used in conjunction with DI-IPSC-82251A; DI-IPSC-82252A; DI-IPSC-82249A; DI-ADMIN-81306; Program Protection Implementation Plan (PPIP); DI-IPSC-81427, Software Development Plan (SDP); and DI-SESS-82045, Firmware Development Plan (FDP). This DID supersedes DI-IPSC-82250.
DoD Developer's Guidebook for Software Assurance https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=539177
Program Manager's Guidebook for Software Assurance https://resources.sei.cmu.edu/library/asset-view.cfm?assetid=538771
Open Web Application Security Program (OWASP), Cheat Sheets, Attack Surface Analysis https://cheatsheetseries.owasp.org/cheatsheets/Attack_Surface_Analysis_Cheat_Sheet.html
A Threat-Driven Approach to Cyber Security https://www.lockheedmartin.com/content/dam/lockheedmartin/rms/documents/cyber/LM-White-Paper-Threat-Driven-Approach.pdf