ArticleTrader.com
  

 Main Menu

  Home
  Member Login
  Forum
  Submit Article
  Membership
  RSS Feeds
  Contact Us
  About

 Services

  Article Distribution
  Link Building

 Tools

  ArticleMS
  Directory Tracker

 Categories

  Automotive
  Business
  Computers
  Entertainment
  Finance
  Food
  Health
  Home and Family
  Internet
  » Affiliate Programs
  » Blogging
  » Domains
  » Email
  » Forums
  » Online Business
  » PPC Advertising
  » RSS
  » Security
  » SEO
  » Site Promotion
  » Spam
  » Web Design
  » Web Hosting
  Legal
  Science
  Self Improvement
  Shopping
  Society
  Sports
  Technology
  Travel
  Writing

187 users online.



 
  » Category Sponsors
  Get Your Link Here - Limited Time Bargain at only $11/month!

Home » Internet » Security » The Penetration Tester: Keeping Computer Systems Safe

bsecure11
Article written by bsecure11

View Full Profile
Get Html Code
PDF | Print View | Post to your Site

The Penetration Tester: Keeping Computer Systems Safe

Submitted by bsecure11
Wed, 5 Nov 2008

Make Money With Your Site!
Sell Links off your
site at ReverseLinks.
Buy Permenant Links
Get Permanent Text Links
for cheap.
Nowadays, almost all kinds of information, including the sensitive and confidential ones, are stored in databases and made accessible via a computer system. In an ideal world, information stored and managed digitally should be safe and secure given the many ways to protect electronic data such as encryption, limited network access, firewalls, etc. However, cyber-criminals always find a way to work around these walls of protection. Thus, it's always important to have a penetration test and a penetration tester to oversee that.

A penetration test involves a simulated attack on a network or a system in a controlled environment to test its security. The penetration tester simulates the activities of a malicious user to determine the ways with which a real cyber criminal would be able to access the system. A big part of a penetration tester's job is finding all the vulnerabilities of the system, what's causing them, and how to resolve them. The job of a penetration tester is important especially when systems protecting sensitive data are involved.

A penetration tester can perform his tests in two ways—the black box or the white box. If a penetration tester uses black box, he is given no information about the system’s infrastructure beforehand. The penetration tester will need to determine that for himself before commencing his simulated attacks for analysis. The black box test is used when a system needs to be protected from actual attacks coming from hackers that have no knowledge of the system.

On the other hand, with the white box test, the penetration tester is given all the information he needs about the system’s infrastructure. From there, a penetration tester studies and determines how to attack the system from within. White box tests are needed for setting up much stricter security in the event of an inside job, or a mole getting into the heart of a system before leaking out confidential data.

Some penetration testers also perform gray box tests during which they are given incomplete information regarding a system’s design. This kind of test is helpful with determining what particular parts of the system, when disclosed, yields more vulnerabilities. Once the penetration tester determines what they are, he can recommend particular security measures.

Black back tests are inexpensive because it is fully automated—the work heavily relies on the penetration tester. White box tests cost more because of the labor involved in singling out specific parts of the system with each step of the testing. Either way, the client company is the one who determines what test is best for their system.

Does being a penetration tester sound interesting? If you are considering this as a career path, it’s best to get a certification before making the move. The International Council of E-Commerce Consultants (or EC-Council for short) provides a certification program called “Licensed Penetration Tester” for aspiring penetration testers. There are a few certification programs of this kind but EC-Council’s program is one of the most prestigious and widely recognized licensing programs in its field.

--

 

Bsecure is a Sydney based Network Security Services company that provides affordable assessment, consultation, design and implementation services in all areas of network and information security.


Source: ArticleTrader.com
Creative Commons License

Comments

No comments posted.

Add Comment

You do not have permission to comment. If you log in, you may be able to comment.

 Top Authors

 1 Stebee (3270)
 2 limalan88 (2920)
 3 alien82 (2756)
 4 kajuba (2508)
 5 sverdlow (1712)
 6 juliet (1691)
 7 jamiehanson (1690)
 8 MarkeD (1296)
 9 AnthonyF (1244)
 10 robertoms2003 (1212)
 11 articles (1205)
 12 artavia.seo (1148)
 13 spinxwebdesign (1113)
 14 gprather (1071)
 15 cj (1069)

 Distribution

Article Distribution

  
  Affiliate Program 2Checkout.com, Inc. is an authorized retailer of ArticleTrader.com

0.02s