Internet exposure
Internet-facing devices are visible and routable to anyone on the network, so that any remote threat actor can initiate a connection to these devices.
Threat actors can easily identify devices that have been scanned by Internet scanners and indexed. Once a device is identified, it can even be compromised without hacking. For example, when default and maintenance passwords are used. The Internet Exposure factor only deals with detected traffic initiated from the public Internet and directed to a device on the customer's internal network. This includes:
- Every source IP that is not included within the customer's internal network.
- Every source IP that is not included in the private network's reserved addresses (RFC1918).
For every suspicious internet exposure, Forescout provides an affirmative (Yes) indication.
The Risk scoring algorithm calculation includes all the observations that take place in a sliding window of 24 hours.
minute read