欢迎来到天天文库
浏览记录
ID:7957850
大小:2.41 MB
页数:16页
时间:2018-03-03
《penetration testing and vulnerability assessment外语英文电子书》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、PenetrationTesting,VulnerabilityScanning,andSecurityAuditingJesperM.Johansson,Ph.D.,CISSPSecurityProgramManagerSecurityEngineeringMicrosoftCorporationjesperjo@microsoft.comAgenda©Theagesofsecurity©Whydoyouneedtothis?©TypeofSecurityAssessments¾VulnerabilityScanning¾P
2、enetrationTesting¾ITAudits©Conclusion1AssessingSecurityTheBronzeAgeTheBronzeAgeDefenseindepth:1000yearsago2AgesofSecurityInformationStoneAgeBronzeAgeAge©Nodecent©PrimitiveTools©Advanced,tools©Primitiveautomatedmethodologytools©Nomythology,noguidance©Littlesenseof©Co
3、mprehensivethebigpicturemethodology©Verylittle©Informationinformation©Widespreadspreadsslowlysharedexpertise©Awareness©Globallackofwidespread,but©Universalawarenessexpertiserareawareness©Survival©Thinkmentalityintegrated!WhyAssessSecurity?1.Yourmanagerasksthegoodque
4、stion:¾Isournetworksecure?¾Howdoyouknow?2.Organizationsonlymeasurewhatthecareaboutandonlycareaboutwhattheymeasure3.Yourorganizationisregulated4.Becauseyoumightbeyourowncustomer5.Becauseyoudonottrustanyone6.Soyoucansleepatnight3FundamentalTradeoffSecureUsableCheapYou
5、gettopickanytwo!AssessingSecurityTypeofSecurityTypeofSecurityAssessmentsAssessments43BasicTypesVulnerabilityScanningòFocusesonknownweaknessesòOfthethree,requirestheleastexpertiseòGenerallyeasytoautomatePenetrationTestingòFocusesonunknownweaknessesòRequiresadvancedte
6、chnicalexpertiseòCarriestremendouslegalburdenincertaincountries/organizationsITSecurityAuditsòFocusesonsecuritypoliciesandproceduresòOfthethree,requiresthemostexpertiseòWhendonerightisthemosteffectivetypeofassessmentVulnerabilityScanningLooksfor:©Thesamemistakesthat
7、everyoneelsemakes©Thekindofthingsthatgeteasilymissed¾Servicepacks,hotfixes,weakpasswords©Commonsettingsonsoftwareyouarenotfamiliarwith©Susceptibilitytoattack¾Knownweaknesseswithknownattacks(thinkDOSattacks)5VulnerabilityScanningToolsTorequireadminaccessornottorequir
8、eadminaccessthatisthequestion!KB824146Scan.exeforDCOMVulnerabilies(MS03-026andMS03-039)PitfallsofVulnerabilityScanning©Toolshavetheirprobl
此文档下载收益归作者所有