- 2
- 0
- 约2.17万字
- 约 41页
- 2017-12-07 发布于浙江
- 举报
Auditing Network Security
Review Methodologies
© 2005 Protiviti Inc. EOE
Assessment Methodologies
• Basic Network Review Phases
• OSSTMM (Open Source Security Testing
Methodology Manual)
–
• Specific review components
– Architecture
– Firewalls
– Routers/Switches
– Modems
– Wireless
– Servers
– Desktops
– VPNs
Review Methodologies 2
Basic Network Review Phases
• Network Reconnaissance
– Identify target networks
• System Service Identification
– Identify live systems
– Determine operating systems and services running
• Vulnerability Scanning
– Use automated tools to identify vulnerabilities and collect data
• Vulnerability Research and Verification
– Verify issues identified by automated scanning tools
– Identify new potential vulnerabilities within identified services or
applications
– Gain or elevate access
• Reporting
Review Methodologies 3
Example External Network Review
Example – Consumer Products Client – Heavystock Inc.
• Heavystock = Keep the store
shelves full
• External Penetration Review
Review Methodologies 4
Network Reconnaissance
• Gather public information
– Registered domains
– Registered networks
– Search engines Heavystock Inc.
– Corporate filings
SCANNING LAPTOP
• Identify target network
您可能关注的文档
- 论我国大众传播媒介的控制力量2.pdf
- 论我国大众传播媒介的控制力量-15.pdf
- 论信息效用及其实现过程.pdf
- 论注册会计师审计质量保持机制——兼论我国注册会计师审计质量保持机制的改进.pdf
- 落实科学发展观 强力推进计算机审计工作.pdf
- 论政府的媒介形象.pdf
- 铝及铝合金的非真空瞬间液相扩散连接研究-王学刚.pdf
- 略论国家审计中远程审计模式.pdf
- 媒介融合_概念_动因及利弊.pdf
- 马克思主义新闻实践观的比较研究.pdf
- 小区绿化施工协议书.docx
- 墙面施工协议书.docx
- 1 古诗二首(课件)--2025-2026学年统编版语文二年级下册.pptx
- (2026春新版)部编版八年级道德与法治下册《3.1《公民基本权利》PPT课件.pptx
- (2026春新版)部编版八年级道德与法治下册《4.3《依法履行义务》PPT课件.pptx
- (2026春新版)部编版八年级道德与法治下册《6.2《按劳分配为主体、多种分配方式并存》PPT课件.pptx
- (2026春新版)部编版八年级道德与法治下册《6.1《公有制为主体、多种所有制经济共同发展》PPT课件.pptx
- 初三教学管理交流发言稿.docx
- 小学生课外阅读总结.docx
- 餐饮门店夜经济运营的社会责任报告(夜间贡献)撰写流程试题库及答案.doc
原创力文档

文档评论(0)