penetration testing
Home > Software Quality Glossary > Definition - penetration testing
EMAIL THIS
Glossary - powered by WhatIs.com
 BROWSE ALPHABETICALLY:    A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #    
Search for: in Full Target Search with Google

penetration testing
Penetration testing is the security-oriented probing of a computer system or network to seek out vulnerabilities that an attacker could exploit. The testing process involves an exploration of the all security features of the system in question, followed by an attempt to breech security and penetrate the system. The tester, sometimes known as an ethical hacker, generally uses the same methods and tools as a real attacker. Afterwards, the penetration testers report on the vulnerabilities and suggest steps that should be taken to make the system more secure.

In his article "Knockin' At Your Backdoor," security expert Thomas Rude lists some of the system components that an ethical hacker might explore: areas that could be compromised in the demilitarized zone (DMZ); the possibility of getting into the intranet; the PBX (the enterprise's internal telephone system); and the database. According to Rude, this is far from an exhaustive list, however, because the main criterion for testing is value: if an element of your system is worthy of safe-keeping, its security should be tested regularly.

Read more about it:
>>  On SearchSecurity.com, Ira Winkler offers an on-demand Webcast, "Audits, assessments, and penetration tests, oh my!"
>>  Reston Communications offers a detailed explanation of penetration testing.
>>  Thomas Rude's article, "Knockin' At Your Backdoor" is available on his Web site.

Last updated on: Jan 13, 2006

WHITE PAPERS  
Implementing a "Smart IPS": IANS Working Knowledge Series™
Sourcefire

A New Affordable Event and Log Management Solution from OpenService to Help with Your Compliance Requirements (Press Release)
OpenService, Inc.

3 Key Components of a Risk-Based Security Plan
Foundstone, Inc.

Exchange Server Disaster Recovery: Planning for the Worst, Hoping for the Best
AppAssure Software

Building Bridges between IT Shops, Legal Teams and Security Staff
Symantec Corporation

>> More White Papers
  WHAT'S NEW
 1. Managing performance in the enterprise
 2. Software testing fundamentals
 3. Learning Guide: Debugging & unit testing
 4. .NET Application Security Learning Guide


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts