Penetration Testing 2.0 - Corporate Tiger Team - Presentation Transcript
Penetration Testing 2.0:
Corporate Tiger Team
Tom Eston
Why are you here?
• Threats to your organization
• Why a Tiger Team?
• How can you do this?
• Real world scenario
• ...it’s one of the last talks of
the day!
Threats to your
organization
(Yes, Dan Kaminsky is a threat...)
No Tech Attacks
Social Engineering
“The clever manipulation
of the natural human
tendency to trust”
“Because there is
no patch for human
stupidity”
“Thief woos bank staff with chocolates...
then steals $28 million in diamonds”
64%
Dumpster Diving
Tailgating
This might be a
problem...
Shoulder Surfing
Buy his book!
Electronic Attacks
External Network
Attacks
• Web applications
• External servers
• Wireless
• DNS and BGP Internet
Routing
Help!
Their attacking our clients!
(aka: Internal Network Attacks)
Phishing
94%
Malfunction
• Software glitches
• Process breakdown
• Act of God/War/Terrorism
• Disruption
Presentation given at the 2008 Ohio Information Sec more
Presentation given at the 2008 Ohio Information Security Summit, October 2008. This was the first presentation I did using skills learned from "presentation zen" which I highly recommend you read!
Attackers are evolving...and so must your penetration testing program.
No longer can an organization only conduct a "traditional" penetration test against network hosts. Why bother attacking your external firewall? That could be too difficult and time consuming for an attacker. Attackers have evolved to using "no tech" hacking techniques. These techniques allow an attacker to gain access to networks and corporate facilities to steal confidential customer information for identity theft, trade secrets, and to potentially damage the reputation of a corporation. There will always be multiple ways to gain access to this type of information so the external firewall, internal network, applications, and the human element of security all cannot be ignored. Whether you are a large or small corporation, the next step in evolving your penetration testing program begins with testing all areas of security in an organization.
This presentation will begin with an overview of emerging threats to organizations in the form of no tech means (social engineering, dumpster diving, tailgating, etc...) and include more recent technology threats such as client side attacks using phishing. We will talk about what a Tiger Team is, what areas of security the Tiger Team will address (physical, technology, application, security awareness), testing methodology, team formation (if you have the ability to do this internally) and what qualifications should you look for in a third-party penetration testing firm. Finally, we will conclude with a real-world example of a Corporate Tiger Team assessment from start to finish which will demonstrate how each area of security is tested. less
0 comments
Post a comment