EVALUATION OF NETWORK AND SYSTEMS SECURITY USING PENETRATION TESTING IN A SIMULATION ENVIRONMENT.

Autor: Fashoto, S. G., Ogunleye, G. O., Adabara, I.
Zdroj: Computer Science & Telecommunications; 2018, Vol. 55 Issue 3, p3-12, 10p, 2 Diagrams, 2 Charts, 3 Graphs
Abstrakt: Penetration testing can provide Network and System Administrators with a realistic assessment of security posture by identifying the vulnerabilities and exploits that exist within the computer network infrastructure. Penetration testing uses the same principles as crackers or hackers to penetrate computer network infrastructure, thereby verify the presence of flaws and vulnerabilities, and help to confirm the security measures. The aim of this paper is to explore the use of penetration testing in the assessment of network infrastructure in a simulation environment, and to demonstrate attacks and intrusion into the network infrastructure. Vulnerability assessment is presented as a part of the penetration test also classifications and phases of a penetration test are described. Some free and open source tools (Nessus, OpenVAS), techniques are used to simulate possible attacks. After the theoretical part, these tools are used to exploit and discovered vulnerabilities in the Network Infrastructure by using appropriate publicly known exploits. This paper shows that if penetration testing is conducted in a methodological manner it could assist Systems and Network administrators improve the security of their network infrastructure. [ABSTRACT FROM AUTHOR]
Databáze: Supplemental Index