...
首页> 外文期刊>Internet Research: Electronic Networking Applications and Policy >Employing penetration testing as an audit methodology for the security review of VoIP: Tests and examples
【24h】

Employing penetration testing as an audit methodology for the security review of VoIP: Tests and examples

机译:使用渗透测试作为VoIP安全审查的审核方法:测试和示例

获取原文
获取原文并翻译 | 示例

摘要

Purpose - The purpose of this paper is to discuss and amalgamate information security principles, and legal and ethical concerns that surround security testing and components of generic security testing methodologies that can be applied to Voice over Internet Protocol (VoIP), in order to form an audit methodology that specifically addresses the needs of this technology. Design/methodology/approach - Information security principles, legal and ethical concerns are amalgamated that surround security testing and components of generic security testing methodologies that can be applied to VoIP. A simple model is created of a business infrastructure (core network) for the delivery of enterprise VoIP services and the selected tests are applied through a methodically structured action plan. Findings - The main output of this paper is a, documented in detail, testing plan (audit programme) for the security review of a core VoIP enterprise network infrastructure. Also, a list of recommendations for good testing practice based on the testing experience and derived through the phase of the methodology evaluation stage. Research limitations/implications - The methodology in the paper does not extend at the moment to the testing of the business operation issues of VoIP telephony, such as revenue assurance or toll fraud detection. Practical implications - This approach facilitates the conduct or security reviews and auditing in a VoIP infrastructure. Originality/value - VoIP requires appropriate security testing before its deployment in a commercial environment. A key factor is the security of the underlying data network. If the business value of adopting VoIP is considered then the potential impact of a related security incident becomes clear. This highlights the need for a coherent security framework that includes means for security reviews, risk assessments, and influencing design and deployment. In this respect, this approach can meet this requirement.
机译:目的-本文的目的是讨论和融合信息安全原理,以及围绕安全测试和可应用于Internet协议语音(VoIP)的通用安全测试方法的组成部分的法律和道德问题,以便形成一个专门解决该技术需求的审核方法。设计/方法/方法-信息安全原则,法律和道德问题被合并在一起,围绕着安全测试以及可应用于VoIP的通用安全测试方法论的组成部分。创建用于交付企业VoIP服务的业务基础架构(核心网络)的简单模型,并通过系统地构造行动计划来应用选定的测试。调查结果-本文的主要输出是详细记录在案的测试计划(审核计划),用于对核心VoIP企业网络基础结构进行安全性审查。此外,还应根据测试经验并在方法论评估阶段中得出有关良好测试实践的建议列表。研究的局限性/意义-本文中的方法目前尚未扩展到VoIP电话业务运营问题的测试,例如收入保证或通行费欺诈检测。实际意义-这种方法有助于VoIP基础结构中的行为或安全性检查和审核。原创性/价值-VoIP在商业环境中部署之前需要进行适当的安全测试。一个关键因素是基础数据网络的安全性。如果考虑采用VoIP的商业价值,那么相关安全事件的潜在影响就变得显而易见。这凸显了对一个统一的安全框架的需求,该框架包括用于安全审查,风险评估以及影响设计和部署的方法。在这方面,这种方法可以满足这一要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号