An Easy To Deploy Penetration Testing Platform

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    An Easy To Deploy Penetration Testing Platform - Presentation Transcript

    1. An Easy-to-deploy Penetration Testing Platform Bing Duan, Yinqian Zhang, Dawu Gu Department of Information Security Engineering Shanghai Jiao Tong University Presenter:Bo-Chun Peng Advisor: Yu-Lun Huang 20090401
    2. Outline Introduction  Principle of PT design  Architecture of PT design  Distributed testing client- SolarSword  A real test case study  Conclusion  Reference 
    3. Introduction PT models have two categories  Flaw hypothesis model  Attack tree model 
    4. Introduction(cont.) Flaw hypothesis model  Vulnerabilities are relatively more fixed and obvious.  Attack tree model  Lacking background info on security leaks.  Top-down tree structure to represent the attack behavior. 
    5. Introduction(cont.) Setbacks of the former platforms  Manual processes  Time cousuming,error-prone  Testing platforms’ security  Testing systems are difficult to deploy 
    6. Principles of PT platform design Automatic  Pt tools, attacking modes & strategies.  Minimize manual errors.  Quick deployment  Single point can’t cover all of network.  Immune  Probably be attached or injected by malicious codes 
    7. Architecture of design Control center  Administrative interface.  Template and scripts for the testing clients.  Automatic analysis and decision making of the strategy.  Distributed testing clients  LiveDVD system: SolarSword  Equipped with various security tools  Download the testing scripts and upload the testing  results
    8. Flow chart of design The info gathering phase  The vulnerability  exploitation phase. Report generation phase 
    9. Distributed testing client-SolarSword Base on the Opensolaris operating system.  Read only- immune to virus and rootkit attack.  Not need any installation- flexible and easy to deploy  Equiped with a lot of PT weapons 
    10. Distributed testing client-SolarSword 1. Scanners & Analyzers  1) Vulnerability scanner  2) Application scanner & analyzer  3) Web vulnerability scanner  4) Port scanner  2. Packet Craft  3. Vulnerability Exploit  4. Traffic Monitoring Tools  5. Password Crack Tools  6. Bruteforce Tools  7. Spoof Tools  8. Footprinting Tools  9. Others 
    11. A real test case study The Ethernet is in 192.168.0.0/24 network segment.  The selected host is an AMD Sempron 3400+  machine with 1G RAM.
    12. A real test case study (cont.) Insert the LiveDVD into the random machine.  Download the testing scripts with default template  from the control center.
    13. A real test case study (cont.) Information gathering phase Vulnerability exploitation phase
    14. A real test case study (cont.) Microsoft IIS web server 5.1  DOS attack  CUP usage of 192.168.0.105  when it is attacked.
    15. Conclusion Advantages  Distributed , easy to deploy  Automatic  Immune  Drawbacks  Control center is needed  Log in control center. 
    16. Reference An Easy-to-Deploy Penetration Testing Platform  Bing Duan; Yinqian Zhang; Dawu Gu; Young Computer Scientists, 2008. ICYCS 2008. The 9th International Conference for 18-21 Nov. 2008 Page(s):2314 - 2318 Digital Object Identifier 10.1109/ICYCS.2008.335 SCHNEIER, B., Attack Trees, Dr. Dobbs Journal, December1999.  www.solarsword.org 
    SlideShare Zeitgeist 2009

    + ponpon7ponpon7 Nominate

    custom

    179 views, 0 favs, 0 embeds more stats

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 179
      • 179 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 3
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories