Top Banner
Network Security Testing Are There Really Different Types of Testing? July 28, 2015 Start Time: 9 am US Pacific / 12 noon US Eastern / 5 pm London Time Web CONFERENCES #ISSAWebConf
67

Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Aug 20, 2018

Download

Documents

doannguyet
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Network Security Testing—Are There Really Different Types of Testing?

July 28, 2015Start Time: 9 am US Pacific / 12 noon US Eastern / 5 pm London Time

WebCONFERENCES

#ISSAWebConf

Page 2: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Brought to you by:

Title goes here 2WebCONFERENCE:

#ISSAWebConf

Network Testing—Are There Really Different Types of Testing?

Network Security Testing—Are There Really Different Types of Testing?

Page 3: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Welcome Conference Moderator

July 28, 2015Start Time: 9 am US Pacific

12 noon US Eastern

5 pm London Time

#ISSAWebConf WebCONFERENCES

Jorge Orchilles

Vice President, South Florida ISSA

Network Security Testing—Are There Really Different Types of Testing?

Page 4: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

• John KindervagVice President & Principal Analyst, Forrrester

Research

• Eric RaistersCISSP, CSSLP

• Ira WinklerPresident, Secure Mentem, CISSP

• Donald ShinSr. Technical Business Development Manager, IXIA

Speaker Introduction

Title goes here 4WebCONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the Chat area of your screen.

You may need to click on the double arrows to open this function.

Network Testing—Are There Really Different Types of Testing?

Page 5: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Network Security Testing—

Are There Really Different Types of Testing?

+1 469.221.5372

[email protected]

@Kindervag

#ISSAWebConf

WebCONFERENCES

John KindervagVice President, Principal Analyst serving Security & Risk Professionals at Forrester Research

Materials omitted due to licensing and reproduction rights.

Page 6: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Network Testing—Are There Really Different Types of Testing?

Page 7: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Network Security Testing—

Are There Really Different Types of Testing?

[email protected]

#ISSAWebConf

WebCONFERENCES

Eric RaistersCISSP, CSSLP

Page 8: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Approach SUT as an attacker

Process (from SANS Ethical Hacking)

Planning

Scoping

Reconnaissance

Scanning

Exploitation

Documentation/Reporting

Pen Test Basics

Network Testing—Are There Really Different Types of Testing? 8

Page 9: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Approach SUT as an attacker

In-house developed apps/services

White-box testing

Deployed systems/purchased products

Includes virtual servers and cloud deployments

Pen Test Purpose

Network Testing—Are There Really Different Types of Testing? 9

Page 10: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

SUT object

Network – mis-configs, weak settings

Web apps/services – OWASP Top 10

Mobile apps/services – permissions, data leakage

Attack methods

Known vulnerability scans - automated

Exploitation proof - manual

Pen Test Types

Network Testing—Are There Really Different Types of Testing? 10

Page 11: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Kali Linux

Samurai Web Test Framework

Pwnie Express

Pen Test Toolkits

Network Testing—Are There Really Different Types of Testing? 11

Page 12: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Look for known vulnerabilities

Nessus (OpenVAS)

Nexpose

Core Impact

Burp Suite (free and commercial)

Zed Attack Proxy (OWASP)

Vulnerability Scan

Network Testing—Are There Really Different Types of Testing? 12

Page 13: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Prove a found vulnerability is exploitable

Metasploit (freed and commercial)

CANVAS

Network Exploits

Network Testing—Are There Really Different Types of Testing? 13

Page 14: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Burp Suite (free and commercial)

Zed Attack Proxy (OWASP)

Paros proxy

w3af

Netsparker

Web App Exploits

Network Testing—Are There Really Different Types of Testing? 14

Page 15: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Pwnie Express

zANTI

Hackcode

AndroRAT

Android Exploits

Network Testing—Are There Really Different Types of Testing? 15

Page 16: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Standard Linux pentest tools

iNalyser

iPhone Exploits

Network Testing—Are There Really Different Types of Testing? 16

Page 17: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Pen testing is important

Vulnerability scans are not enough

Exploit testing proves that a vulnerability is important enough to fix

Consider contracting experts

Consider a bug bounty program

If you don’t do it, the hackers will

Summary

Network Testing—Are There Really Different Types of Testing? 17

Page 18: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

sectools.org

n0where.net/directory

OWASP.prg

kali.org

Eric Raisters

[email protected]

Resources

Network Testing—Are There Really Different Types of Testing? 18

Page 19: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

19

Thank you!

Network Testing—Are There Really Different Types of Testing?

Page 20: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Eric RaistersCISSP, CSSLP

[email protected]

Question and Answer

Title goes here 20WebCONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the Chat area of your screen.

You may need to click on the double arrows to open this function.

Network Testing—Are There Really Different Types of Testing?

Page 21: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Eric RaistersCISSP, CSSLP

[email protected]

Thank You

Title goes here 21WebCONFERENCE:

#ISSAWebConf

Network Testing—Are There Really Different Types of Testing?

Page 22: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Network Security Testing—

Are There Really Different Types of Testing?

[email protected]

#ISSAWebConf

WebCONFERENCES

Ira WinklerPresident, Secure Mentem, CISSP

Page 23: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

23Network Testing—Are There Really Different Types of Testing?

Copyright Secure Mentem

Page 24: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

24Network Testing—Are There Really Different Types of Testing?

Page 25: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

25Network Testing—Are There Really Different Types of Testing?

Page 26: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

26Network Testing—Are There Really Different Types of Testing?

Copyright Secure Mentem

Page 27: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

27Network Testing—Are There Really Different Types of Testing?

Copyright Secure Mentem

Page 28: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

28Network Testing—Are There Really Different Types of Testing?

Copyright Secure Mentem

Page 29: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

29Network Testing—Are There Really Different Types of Testing?

Page 30: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

30Network Testing—Are There Really Different Types of Testing?

Copyright Secure Mentem

Page 31: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

31Network Testing—Are There Really Different Types of Testing?

Copyright Secure Mentem

Page 32: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

32Network Testing—Are There Really Different Types of Testing?

Page 33: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

33Network Testing—Are There Really Different Types of Testing?

Page 34: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

34Network Testing—Are There Really Different Types of Testing?

Page 35: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

35Network Testing—Are There Really Different Types of Testing?

Page 36: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

36Network Testing—Are There Really Different Types of Testing?

Page 37: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

37Network Testing—Are There Really Different Types of Testing?

Page 38: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

38Network Testing—Are There Really Different Types of Testing?

Thank You

Page 39: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Ira WinklerPresident, Secure Mentem, CISSP

[email protected]

@irawinkler

Question and Answer

Title goes here 39WebCONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the Chat area of your screen.

You may need to click on the double arrows to open this function.

Network Testing—Are There Really Different Types of Testing?

Page 40: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Ira WinklerPresident, Secure Mentem, CISSP

+1-443-603-02500

[email protected]

@irawinkler

Thank You

Title goes here 40WebCONFERENCE:

#ISSAWebConf

Network Testing—Are There Really Different Types of Testing?

Page 41: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Network Security Testing—

Are There Really Different Types of Testing?

www.ixiacom.com

#ISSAWebConf

WebCONFERENCES

Donald ShinSr. Technical Business Development Manager, IXIA

Page 42: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

42Network Testing—Are There Really Different Types of Testing?

Page 43: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

43Network Testing—Are There Really Different Types of Testing?

Page 44: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

44Network Testing—Are There Really Different Types of Testing?

Page 45: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

45Network Testing—Are There Really Different Types of Testing?

Page 46: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

46Network Testing—Are There Really Different Types of Testing?

Page 47: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

47Network Testing—Are There Really Different Types of Testing?

Page 48: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

48Network Testing—Are There Really Different Types of Testing?

Page 49: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

49Network Testing—Are There Really Different Types of Testing?

Page 50: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

50Network Testing—Are There Really Different Types of Testing?

Page 51: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

51Network Testing—Are There Really Different Types of Testing?

Page 52: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

52Network Testing—Are There Really Different Types of Testing?

Page 53: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

53Network Testing—Are There Really Different Types of Testing?

Page 54: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

54Network Testing—Are There Really Different Types of Testing?

Page 55: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

55Network Testing—Are There Really Different Types of Testing?

Page 56: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

56Network Testing—Are There Really Different Types of Testing?

Page 57: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

57Network Testing—Are There Really Different Types of Testing?

Page 58: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

58Network Testing—Are There Really Different Types of Testing?

Page 59: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

59Network Testing—Are There Really Different Types of Testing?

Page 60: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

60Network Testing—Are There Really Different Types of Testing?

Page 61: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

61Network Testing—Are There Really Different Types of Testing?

Page 62: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

62Network Testing—Are There Really Different Types of Testing?

Page 63: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Donald ShinSr. Technical Business Development Manager

IXIAwww.ixiacom.com

Question and Answer

Title goes here 63WebCONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the Chat area of your screen.

You may need to click on the double arrows to open this function.

Network Testing—Are There Really Different Types of Testing?

Page 64: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Donald Shin Sr. Technical Business Development Manager

IXIAwww.ixiacom.com

Thank You

Title goes here 64WebCONFERENCE:

#ISSAWebConf

Network Testing—Are There Really Different Types of Testing?

Page 65: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

• John KindervagVice President & Principal Analyst, Forrester

Research

• Eric RaistersCISSP, CSSLP

• Ira WinklerPresident, Secure Mentem, CISSP

• Donald ShinSr. Technical Business Development Manager, IXIA

Open Panel with Audience Q&A

Title goes here 65WebCONFERENCE:

#ISSAWebConf

To ask a question:

Type in your question in the Chat area of your screen.

You may need to click on the double arrows to open this function.

Network Testing—Are There Really Different Types of Testing?

Page 66: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

Thank you Citrix for donating

the Webcast service

Closing Remarks

Title goes here 66WebCONFERENCE:

#ISSAWebConf

Thank You

Network Testing—Are There Really Different Types of Testing?

Page 67: Network Security Testingc.ymcdn.com/sites/ · Network Security Testing ... Web App Exploits Network Testing—Are There Really Different Types of Testing? 14 ... Pen testing is important

• Within 24 hours of the conclusion of this webcast, you will receive a link via email to a post Web Conference quiz.

• After the successful completion of the quiz you will be given an opportunity to PRINT a certificate of attendance to use for the submission of CPE credits.

• On-Demand Viewers Quiz Link:http://www.surveygizmo.com/s3/2241426/ISSA-Web-Conference-July-28-2015-Network-Security-Testing-Are-There-Really-Different-Types-of-Testing

CPE Credit

Title goes here 67WebCONFERENCE:

#ISSAWebConf

Network Testing—Are There Really Different Types of Testing?