A penetration test is a traditional solution to evaluate and improve the robustness of an ICT system. This test is fully general, but some problems arise when deciding how to use its results to select the countermeasures against a successful penetration. These problems may explain the successful attacks against systems that successfully passed this test. We offer some theoretical explanations of the weaknesses of a penetration test and suggest some alternatives.

Avoiding the weaknesses of a penetration test

Fabrizio Baiardi
In corso di stampa

Abstract

A penetration test is a traditional solution to evaluate and improve the robustness of an ICT system. This test is fully general, but some problems arise when deciding how to use its results to select the countermeasures against a successful penetration. These problems may explain the successful attacks against systems that successfully passed this test. We offer some theoretical explanations of the weaknesses of a penetration test and suggest some alternatives.
In corso di stampa
Baiardi, Fabrizio
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11568/952097
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 9
  • ???jsp.display-item.citation.isi??? ND
social impact