• No results found

Network Security Testing

N/A
N/A
Protected

Academic year: 2021

Share "Network Security Testing"

Copied!
67
0
0

Loading.... (view fulltext now)

Full text

(1)

Network Security Testing—

Are There Really Different Types of Testing?

July 28, 2015

Start Time: 9 am US Pacific / 12 noon US Eastern / 5 pm London Time

Web

CONFERENCES

(2)

Brought to you by:

Title goes here 2

Web

CONFERENCE:

#ISSAWebConf

Network Testing—Are There Really Different Types of Testing?

Network Security Testing—

(3)

Welcome Conference Moderator

July 28, 2015

Start Time: 9 am US Pacific

12 noon US Eastern

5 pm London Time

#ISSAWebConf

Web

CONFERENCES

Jorge Orchilles

Vice President, South Florida ISSA

Network Security Testing—

(4)

John Kindervag

Vice President & Principal Analyst, Forrrester

Research

Eric Raisters

CISSP, CSSLP

Ira Winkler

President, Secure Mentem, CISSP

Donald Shin

Sr. Technical Business Development Manager, IXIA

Speaker Introduction

Title goes here 4

Web

CONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the

Chat

area of your screen.

You may need to click on the double arrows to open this function.

(5)

Network Security Testing—

Are There Really Different Types of Testing?

+1 469.221.5372

[email protected]

@Kindervag

#ISSAWebConf

Web

CONFERENCES

John Kindervag

Vice President, Principal Analyst serving Security & Risk

Professionals at Forrester Research

Materials omitted

due to licensing and

reproduction rights.

(6)
(7)

Network Security Testing—

Are There Really Different Types of Testing?

[email protected]

#ISSAWebConf

Web

CONFERENCES

Eric Raisters

(8)

Approach SUT as an attacker

Process (from SANS Ethical Hacking)

Planning

Scoping

Reconnaissance

Scanning

Exploitation

Documentation/Reporting

Pen Test Basics

(9)

Approach SUT as an attacker

In-house developed apps/services

White-box testing

Deployed systems/purchased products

Includes virtual servers and cloud

deployments

Pen Test Purpose

(10)

SUT object

Network – mis-configs, weak settings

Web apps/services – OWASP Top 10

Mobile apps/services – permissions,

data leakage

Attack methods

Known vulnerability scans - automated

Exploitation proof - manual

Pen Test Types

(11)

Kali Linux

Samurai Web Test Framework

Pwnie Express

Pen Test Toolkits

(12)

Look for known vulnerabilities

Nessus (OpenVAS)

Nexpose

Core Impact

Burp Suite (free and commercial)

Zed Attack Proxy (OWASP)

Vulnerability Scan

(13)

Prove a found vulnerability is

exploitable

Metasploit (freed and commercial)

CANVAS

Network Exploits

(14)

Burp Suite (free and commercial)

Zed Attack Proxy (OWASP)

Paros proxy

w3af

Netsparker

Web App Exploits

(15)

Pwnie Express

zANTI

Hackcode

AndroRAT

Android Exploits

(16)

Standard Linux pentest tools

iNalyser

iPhone Exploits

(17)

Pen testing is important

Vulnerability scans are not enough

Exploit testing proves that a

vulnerability is important enough to fix

Consider contracting experts

Consider a bug bounty program

If you don’t do it, the hackers will

Summary

(18)

sectools.org

n0where.net/directory

OWASP.prg

kali.org

Eric Raisters

[email protected]

Resources

(19)

19

Thank you!

(20)

Eric Raisters

CISSP, CSSLP

[email protected]

Question and Answer

Title goes here 20

Web

CONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the

Chat

area of your screen.

You may need to click on the double arrows to open this function.

(21)

Eric Raisters

CISSP, CSSLP

[email protected]

Thank You

Title goes here 21

Web

CONFERENCE:

#ISSAWebConf

(22)

Network Security Testing—

Are There Really Different Types of Testing?

[email protected]

#ISSAWebConf

Web

CONFERENCES

Ira Winkler

(23)

23 Network Testing—Are There Really Different Types of Testing?

(24)

24 Network Testing—Are There Really Different Types of Testing?

(25)

25 Network Testing—Are There Really Different Types of Testing?

(26)

26 Network Testing—Are There Really Different Types of Testing?

(27)

27 Network Testing—Are There Really Different Types of Testing?

(28)

28 Network Testing—Are There Really Different Types of Testing?

(29)

29 Network Testing—Are There Really Different Types of Testing?

(30)

30 Network Testing—Are There Really Different Types of Testing?

(31)

31 Network Testing—Are There Really Different Types of Testing?

(32)

32 Network Testing—Are There Really Different Types of Testing?

(33)

33 Network Testing—Are There Really Different Types of Testing?

(34)

34 Network Testing—Are There Really Different Types of Testing?

(35)

35 Network Testing—Are There Really Different Types of Testing?

(36)

36 Network Testing—Are There Really Different Types of Testing?

(37)

37 Network Testing—Are There Really Different Types of Testing?

(38)

38 Network Testing—Are There Really Different Types of Testing?

(39)

Ira Winkler

President, Secure Mentem, CISSP

+1-443-603-0200

[email protected]

@irawinkler

Question and Answer

Title goes here 39

Web

CONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the

Chat

area of your screen.

You may need to click on the double arrows to open this function.

(40)

Ira Winkler

President, Secure Mentem, CISSP

+1-443-603-02500

[email protected]

@irawinkler

Thank You

Title goes here 40

Web

CONFERENCE:

#ISSAWebConf

(41)

Network Security Testing—

Are There Really Different Types of Testing?

www.ixiacom.com

#ISSAWebConf

Web

CONFERENCES

Donald Shin

(42)

42 Network Testing—Are There Really Different Types of Testing?

(43)

43 Network Testing—Are There Really Different Types of Testing?

(44)

44 Network Testing—Are There Really Different Types of Testing?

(45)

45 Network Testing—Are There Really Different Types of Testing?

(46)

46 Network Testing—Are There Really Different Types of Testing?

(47)

47 Network Testing—Are There Really Different Types of Testing?

(48)

48 Network Testing—Are There Really Different Types of Testing?

(49)

49 Network Testing—Are There Really Different Types of Testing?

(50)

50 Network Testing—Are There Really Different Types of Testing?

(51)

51 Network Testing—Are There Really Different Types of Testing?

(52)

52 Network Testing—Are There Really Different Types of Testing?

(53)

53 Network Testing—Are There Really Different Types of Testing?

(54)

54 Network Testing—Are There Really Different Types of Testing?

(55)

55 Network Testing—Are There Really Different Types of Testing?

(56)

56 Network Testing—Are There Really Different Types of Testing?

(57)

57 Network Testing—Are There Really Different Types of Testing?

(58)

58 Network Testing—Are There Really Different Types of Testing?

(59)

59 Network Testing—Are There Really Different Types of Testing?

(60)

60 Network Testing—Are There Really Different Types of Testing?

(61)

61 Network Testing—Are There Really Different Types of Testing?

(62)

62 Network Testing—Are There Really Different Types of Testing?

(63)

Donald Shin

Sr. Technical Business Development Manager

IXIA

www.ixiacom.com

Question and Answer

Title goes here 63

Web

CONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the

Chat

area of your screen.

You may need to click on the double arrows to open this function.

(64)

Donald Shin

Sr. Technical Business Development Manager

IXIA

www.ixiacom.com

Thank You

Title goes here 64

Web

CONFERENCE:

#ISSAWebConf

(65)

John Kindervag

Vice President & Principal Analyst, Forrester

Research

Eric Raisters

CISSP, CSSLP

Ira Winkler

President, Secure Mentem, CISSP

Donald Shin

Sr. Technical Business Development Manager, IXIA

Open Panel with Audience Q&A

Title goes here 65

Web

CONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the

Chat

area of your screen.

You may need to click on the double arrows to open this function.

(66)

Thank you Citrix for donating

the Webcast service

Closing Remarks

Title goes here 66

Web

CONFERENCE:

#ISSAWebConf

Thank You

(67)

Within

24 hours of the conclusion

of this webcast, you

will receive a link via email to a post Web Conference

quiz.

After the successful completion of the quiz you will be

given an opportunity to

PRINT

a certificate of attendance

to use for the submission of CPE credits.

On-Demand Viewers Quiz Link:

http://www.surveygizmo.com/s3/2241426/ISSA-Web-

Conference-July-28-2015-Network-Security-Testing-Are-There-Really-Different-Types-of-Testing

CPE Credit

Title goes here 67

Web

CONFERENCE:

#ISSAWebConf

http://www.surveygizmo.com/s3/2241426/ISSA-Web- Conference-July-28-2015-Network-Security-Testing-Are-There-Really-Different-Types-of-Testing

References

Related documents

Writing Secure Code, Microsoft Press, 2003... Consider

Preventative maintenance (PM) processes should be performed for a wide variety of items used in endoscopy, such as the endoscopes themselves, equipment on the tower, and automated

strategies as well as operations carried out by the organisation. Values from a culture would definitely have an effect on the values towards sustainability. In this research, in

Types of Penetration Testing Network Network Application Application Social Engineering Social Engineering.. Wardialing: It is a technique used to identify

Pursuant to the Allocation Agreement among the United States of America, the Metropolitan Water District of Southern California, Coachella Valley Water District, Imperial

Product Name: Security Testing Market by Network Security Testing, Application Security Testing, SAST, DAST, Security Testing Tools, Penetration Testing Tools, Automated Testing

Individual variables that remained associated with regular gambling after adjustment for all other child vari- ables were lower childhood IQ in both males and females aged 17

Penetration Testing: Communication Media Testing covers Wireless Network Penetration Testing, Advanced Wireless Testing, VoIP Penetration Testing, VPN Penetration Testing,