penetration testing
Home > Software Quality Glossary > Definition - penetration testing
EMAIL THIS
Glossary - powered by WhatIs.com
 BROWSE ALPHABETICALLY:    A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #    
Search for: in Full Target Search with Google

penetration testing
Penetration testing is the security-oriented probing of a computer system or network to seek out vulnerabilities that an attacker could exploit. The testing process involves an exploration of the all security features of the system in question, followed by an attempt to breech security and penetrate the system. The tester, sometimes known as an ethical hacker, generally uses the same methods and tools as a real attacker. Afterwards, the penetration testers report on the vulnerabilities and suggest steps that should be taken to make the system more secure.

In his article "Knockin' At Your Backdoor," security expert Thomas Rude lists some of the system components that an ethical hacker might explore: areas that could be compromised in the demilitarized zone (DMZ); the possibility of getting into the intranet; the PBX (the enterprise's internal telephone system); and the database. According to Rude, this is far from an exhaustive list, however, because the main criterion for testing is value: if an element of your system is worthy of safe-keeping, its security should be tested regularly.

Read more about it:
>>  On SearchSecurity.com, Ira Winkler offers an on-demand Webcast, "Audits, assessments, and penetration tests, oh my!"
>>  Reston Communications offers a detailed explanation of penetration testing.
>>  Thomas Rude's article, "Knockin' At Your Backdoor" is available on his Web site.

Last updated on: Jan 13, 2006

WHITE PAPERS  
IDC: Lumension Is Top "Patching & Remediation Vendor
Lumension Security

The Essentials Series: PCI Compliance
Alert Logic

Technology Brief: Achieving Comprehensive Protection with IPS and ETM
Sourcefire

Integrating Vulnerability Assessment and Remediation
Lumension Security

Implementing a "Smart IPS": IANS Working Knowledge Series™
Sourcefire

>> More White Papers
  WHAT'S NEW
 1. Scrum and requirements gathering
 2. Managing performance in the enterprise
 3. Software testing fundamentals
 4. Debugging and unit testing


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts