【24h】

Towards a Unified Penetration Testing Taxonomy

机译:朝向统一的渗透测试分类

获取原文

摘要

Penetration testing is a time consuming process which combines different mechanisms (security standards, protocols, best practices, vulnerability databases, techniques and guidelines) to evaluate computer systems and network vulnerabilities. It's main goal is to identify security weaknesses by using methods and procedures that are commonly used by malicious attackers. Furthermore, the best companies have certificated penetration testers to increase the quality and efficiency of their work. However, the rapid technology evolution increases the complexity and decreases security, and it raises the question if these support mechanisms are adequate and up-to-date. To provide an efficient widespread quality assessment of penetration testing process and mechanisms. Our work is formed to use developed framework to depict an efficient taxonomy over widespread technical and non-technical aspects that cover penetration testing process.
机译:渗透测试是一个耗时的过程,它结合了不同的机制(安全标准,协议,最佳实践,漏洞数据库,技术和指南)来评估计算机系统和网络漏洞。 主要目标是通过使用恶意攻击者通常使用的方法和程序来识别安全弱点。 此外,最好的公司拥有认证的渗透测试人员,以提高其工作的质量和效率。 然而,快速的技术进化会增加复杂性并降低安全性,并且如果这些支持机制足够和最新,则会提出问题。 为渗透测试过程和机制提供有效的广泛质量评估。 我们的作品是使用开发的框架来描述覆盖渗透测试过程的广泛技术和非技术方面的有效分类物。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号