Penetration Taxonomy: A Systematic Review on the Penetration Process, Framework, Standards, Tools, and Scoring Methods

被引:0
|
作者
Sarker, Kamal Uddin [1 ]
Yunus, Farizah [1 ]
Deraman, Aziz [1 ]
机构
[1] Univ Malaysia Terengganu, Informat, Kuala Terengganu 21030, Malaysia
关键词
vulnerability; cybersecurity; penetration testing; quality of service; sustainability; SECURITY; RISK;
D O I
10.3390/su151310471
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Cyber attackers are becoming smarter, and at the end of the day, many novel attacks are hosted in the cyber world. Security issues become more complex and critical when the number of services and subscribers increases due to advanced technologies. To ensure a secure environment, cyber professionals suggest reviewing the information security posture of the organization regularly via security experts, which is known as penetration testing. A pen tester executes a penetration test of an organization according to the frameworks and standardization guidelines. Security breaches of the system, loopholes in OS or applications, network vulnerabilities, and breaking data integration scopes are identified, and appropriate remediation is suggested by a pen tester team. The main aim of a penetration process is to fix the vulnerabilities prior to the attack in tangible and intangible resources. Firstly, this review work clarifies the penetration conception and is followed by the taxonomy of penetration domains, frameworks, standards, tools, and scoring methods. It performs a comparison study on the aforementioned items that develops guidelines for selecting an appropriate item set for the penetration process according to the demand of the organization. This paper ends with a constructive observation along with a discussion on recent penetration trends and the scope of future research.
引用
收藏
页数:26
相关论文
共 50 条
  • [41] A Review on Voltage Challenges and Remedial Methods with Excessive PV Penetration in Radial Distribution Feeder
    Arora, Swati
    Kaur, Sandeep
    Khanna, Rintu
    [J]. PROCEEDINGS OF 2019 5TH IEEE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMPUTING AND CONTROL (ISPCC 2K19), 2019, : 47 - 52
  • [42] A systematic review on task scheduling in Fog computing: Taxonomy, tools, challenges, and future directions
    Kaur, Navjeet
    Kumar, Ashok
    Kumar, Rajesh
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2021, 33 (21):
  • [43] Systematic review of mixed methods in the framework of educational innovation
    Ramirez-Montoya, Maria-Soledad
    Lugo-Ocando, Jairo
    [J]. COMUNICAR, 2020, 28 (65) : 9 - 20
  • [44] The goldmine of GWAS summary statistics: a systematic review of methods and tools
    Kontou, Panagiota I.
    Bagos, Pantelis G.
    [J]. BIODATA MINING, 2024, 17 (01):
  • [45] Measuring attitudes towards the dying process: A systematic review of tools
    Groebe, Bernadette
    Strupp, Julia
    Eisenmann, Yvonne
    Schmidt, Holger
    Schlomann, Anna
    Rietz, Christian
    Voltz, Raymond
    [J]. PALLIATIVE MEDICINE, 2018, 32 (04) : 815 - 837
  • [46] How to optimize the systematic review process using AI tools
    Fabiano, Nicholas
    Gupta, Arnav
    Bhambra, Nishaant
    Luu, Brandon
    Wong, Stanley
    Maaz, Muhammad
    Fiedorowicz, Jess G.
    Smith, Andrew L.
    Solmi, Marco
    [J]. JCPP ADVANCES, 2024, 4 (02):
  • [47] A framework for physics-driven in-process monitoring of penetration and interface width in laser overlap welding
    Ozkat, Erkan Caner
    Franciosa, Pasquale
    Ceglarek, Darek
    [J]. COMPLEX SYSTEMS ENGINEERING AND DEVELOPMENT, 2017, 60 : 44 - 49
  • [48] Why fexofenadine is considered as a truly non-sedating antihistamine with no brain penetration: a systematic review
    Ansotegui, Ignacio J.
    Bousquet, Jean
    Canonica, Giorgio Walter
    Demolys, Pascal
    Gomez, Rene Maximiliano
    Meltzer, Eli O.
    Murrieta-Aguttes, Margarita
    Naclerio, Robert M.
    Rosario Filho, Nelson
    Scadding, Glenis K.
    [J]. CURRENT MEDICAL RESEARCH AND OPINION, 2024, 40 (08) : 1297 - 1309
  • [49] Caval Penetration by Inferior Vena Cava Filters A Systematic Literature Review of Clinical Significance and Management
    Jia, Zhongzhi
    Wu, Alex
    Tam, Mathew
    Spain, James
    McKinney, J. Mark
    Wang, Weiping
    [J]. CIRCULATION, 2015, 132 (10) : 944 - 952
  • [50] Tissue Penetration of Antimicrobials in Intensive Care Unit Patients: A Systematic Review-Part I
    Finazzi, Stefano
    Luci, Giacomo
    Olivieri, Carlo
    Langer, Martin
    Mandelli, Giulia
    Corona, Alberto
    Viaggi, Bruno
    Di Paolo, Antonello
    [J]. ANTIBIOTICS-BASEL, 2022, 11 (09):