Showing posts with label Testing. Show all posts
Showing posts with label Testing. Show all posts

Security Testing: Who, What, Why and How?


Who really needs to have their network security tested? If a computer is used "online" and is used to store sensitive data, it should be tested for security. While it is tempting to rely on patches, updates or an application to secure the network, it is never that simple. Every company that has been hacked has thought their network was secure.

What might tempt hackers to attack a computer, a network or websites? There are a variety of reasons. First, hackers might be after personal customer information including credit card information. A hacker might also be looking for any proprietary software application, trade secrets or company tax information. In some cases a computer will be attacked and information destroyed for revenge if the attacker feels he was wronged by the company or any individual at the company that owns the computer. There are also some hackers who will compromise a computer to try extorting the company, "pay up or all company info will be destroyed or made public."

Why else might security testing be important? Peace of mind. With proper security testing the company has less chance for loss of customer personal or credit information leading to identity or monetary theft for which the company could be held liable. Liability in these cases is a tricky thing, as it depends on an interpretation of liability based upon how well a company tried to protect their users information.

How does security testing work? In many cases testing your software applications, computer systems or network for vulnerabilities does not require physical access and can be done from off site. This can be advantageous as it keeps anyone, such as clients, employees or competitors from knowing anything is happening and allowing them to draw erroneous conclusions. The tester, working from off site, will connect to the network, with the client's permission, then begin using various applications designed for penetration testing. Through the course of testing, the tester will check the network hardware and software for any known or theoretical vulnerabilities. The tester will then pass on all results, with possible recommendations, and known fixes to the hiring company.

So for the reasons listed above and others that are not listed here application security testing makes sense for all companies that have anything sensitive stored on the network computers. No matter how secure a system seems, there is no way to know for sure unless it has been through a thorough security assessment.




Author is a freelance copywriter. For more information about Application security, please visit http://www.plynt.com/.




Evaluation of Penetration Testing in Security


Penetration testing is also known as a pen test. It is used for evaluating the security of a computer system or network that suffers from the attack of malicious outsider and insiders. In this process, we use an active analysis of the system for any potential vulnerability.

The penetration testing is valuable because of following reasons:

1. It determines the feasibility of a particular set of attack vectors.

2. It identifies the vulnerabilities from the higher to lower sequence.

3. It identifies the vulnerabilities which is not detected by the automated network or scanning software.

4. It provides evidence to support increased investment in personal security and technology.

The penetration testing is a component of security audit. It has several ways to conduct the testing like black box testing and white box testing. In black box testing there is no any prior knowledge of the infrastructure to be tested. It is necessary for the tester to first determine the location and then extend the system for commencing their analysis. The white box testing provides the full information about the infrastructure to be tested and sometime also provides the network diagrams, source code and IP addressing information. There are some variations between black and white box testing which is known as gray box testing. The black box testing, white box testing and gray box testing are also known as blind, full disclosures and partial disclosure test accordingly.

The penetration testing should be carried out on any computer which is to be deployed in any hostile environment, in any internet facing site, before the system is deployed. By this we provide the level of practical assurance for that the system will not be penetrate by any malicious user. The penetration testing is an invaluable technique for any organization for the information security program. Basically white box penetration testing is often ally used as a fully automated inexpensive process. The black box penetrating testing is a labor intensive activity that is why it is required expertise to minimize the risk of targeted system. The black box penetration testing may slow the organization network response time due to network scanning and vulnerability scanning. It is possible that system may be damaged in the course of penetration testing and may be inoperable. This risk may be minimizing by the use of experienced penetration testers but it can never be fully eliminated.

The web applications of penetration testing are as follows:

� It is used for the knowing vulnerabilities in Commercial off the Shelf (COTS) application.

� For the technical vulnerabilities like URL manipulation, SQL injection, cross-site scripting, back-end authentication, password in memory, session hijacking, buffer overflow, web server configuration, credential management, etc.

� For knowing business logic errors like day-to-day threat analysis, unauthorized logins, personnel information modification, price-list modification, unauthorized fund transfer, etc.




Torrid Networks is a global leader in the information security services. Our strong leadership and passion for information security helped us build unique onsite-offshore service delivery model combined with unparalleled culture of customer satisfaction. We bring cutting-edge information security products in association with our global partners and early adoption of best practices and quality standards (closely emulating CMM Level 4 practices) helps us deliver excellence.

http://www.torridnetworks.com/




 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Information Computer and Technology - All Rights Reserved
Template Modify by Creating Website
Proudly powered by Blogger