Penetration Taxonomy: A Systematic Review on the Penetration Process, Framework, Standards, Tools, and Scoring Methods

被引:0
|
作者
Sarker, Kamal Uddin [1 ]
Yunus, Farizah [1 ]
Deraman, Aziz [1 ]
机构
[1] Univ Malaysia Terengganu, Informat, Kuala Terengganu 21030, Malaysia
关键词
vulnerability; cybersecurity; penetration testing; quality of service; sustainability; SECURITY; RISK;
D O I
10.3390/su151310471
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Cyber attackers are becoming smarter, and at the end of the day, many novel attacks are hosted in the cyber world. Security issues become more complex and critical when the number of services and subscribers increases due to advanced technologies. To ensure a secure environment, cyber professionals suggest reviewing the information security posture of the organization regularly via security experts, which is known as penetration testing. A pen tester executes a penetration test of an organization according to the frameworks and standardization guidelines. Security breaches of the system, loopholes in OS or applications, network vulnerabilities, and breaking data integration scopes are identified, and appropriate remediation is suggested by a pen tester team. The main aim of a penetration process is to fix the vulnerabilities prior to the attack in tangible and intangible resources. Firstly, this review work clarifies the penetration conception and is followed by the taxonomy of penetration domains, frameworks, standards, tools, and scoring methods. It performs a comparison study on the aforementioned items that develops guidelines for selecting an appropriate item set for the penetration process according to the demand of the organization. This paper ends with a constructive observation along with a discussion on recent penetration trends and the scope of future research.
引用
收藏
页数:26
相关论文
共 50 条
  • [1] The standards process: tools and methods for standards tracking and implementation
    Sloane, A
    [J]. COMPUTER STANDARDS & INTERFACES, 2000, 22 (01) : 5 - 12
  • [2] Data Science Methods and Tools for Industry 4.0: A Systematic Literature Review and Taxonomy
    Arruda, Helder Moreira
    Bavaresco, Rodrigo Simon
    Kunst, Rafael
    Bugs, Elvis Fernandes
    Pesenti, Giovani Cheuiche
    Barbosa, Jorge Luis Victoria
    [J]. SENSORS, 2023, 23 (11)
  • [3] Penetration of Vancomycin into the Cerebrospinal Fluid: A Systematic Review
    Jessica E. Beach
    Jerrold Perrott
    Ricky D. Turgeon
    Mary H. H. Ensom
    [J]. Clinical Pharmacokinetics, 2017, 56 : 1479 - 1490
  • [4] Penetration of Vancomycin into the Cerebrospinal Fluid: A Systematic Review
    Beach, Jessica E.
    Perrott, Jerrold
    Turgeon, Ricky D.
    Ensom, Mary H. H.
    [J]. CLINICAL PHARMACOKINETICS, 2017, 56 (12) : 1479 - 1490
  • [5] Methods for evaluating penetration of drug into the skin: A review
    Supe, Shibani
    Takudage, Pooja
    [J]. SKIN RESEARCH AND TECHNOLOGY, 2021, 27 (03) : 299 - 308
  • [6] Modernizing the systematic review process to inform comparative effectiveness: tools and methods
    Wallace, Byron C.
    Dahabreh, Issa J.
    Schmid, Christopher H.
    Lau, Joseph
    Trikalinos, Thomas A.
    [J]. JOURNAL OF COMPARATIVE EFFECTIVENESS RESEARCH, 2013, 2 (03) : 273 - 282
  • [7] Taxonomy of Performance Testing Tools: a Systematic Literature Review
    Costa, Victor
    Girardon, Gustavo
    Bernardino, Maicon
    Machado, Rodrigo
    Legramante, Guilherme
    Neto, Anibal
    Basso, Fabio Paulo
    Rodrigues, Elder de Macedo
    [J]. PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1997 - 2004
  • [8] Systematic review of methods of scoring inhaler technique
    De Vos, Ruth
    Hicks, Alexander
    Lomax, Mitch
    Mackenzie, Heather
    Fox, Lauren
    Brown, Thomas P.
    Chauhan, Anoop J.
    [J]. EUROPEAN RESPIRATORY JOURNAL, 2023, 62
  • [9] A systematic review of methods of scoring inhaler technique
    De Vos, Ruth
    Hicks, Alexander
    Lomax, Mitch
    Mackenzie, Heather
    Fox, Lauren
    Brown, Thomas P.
    Chauhan, A. J.
    [J]. RESPIRATORY MEDICINE, 2023, 219
  • [10] Penetration for Cooperative Learning in Engineering Education: A Systematic Literature Review
    Baligar, Preethi
    Joshi, Gopalkrishna
    Shettar, Ashok
    Kandakatla, Rohit
    [J]. PROCEEDINGS OF THE 2022 IEEE GLOBAL ENGINEERING EDUCATION CONFERENCE (EDUCON 2022), 2022, : 610 - 619