渗透测试小组成功的行业标准的检验

M. Ducoste, Rachel Bleiman, T. Nguyen, Aunshul Rege
{"title":"渗透测试小组成功的行业标准的检验","authors":"M. Ducoste, Rachel Bleiman, T. Nguyen, Aunshul Rege","doi":"10.1109/ISEC52395.2021.9764146","DOIUrl":null,"url":null,"abstract":"Penetration testing groups can be used as an ethical proxy to study cybercrime groups, as both parties share the common goal of identifying and exploiting weaknesses in their targets’ systems. Pentesters often use existing industry standards to guide their performance and practices, but little research has investigated how these standards operate in simulated cybersecurity exercises. Using the experiences of college students in the 2018 and 2019 National Collegiate Penetration Testing Competition (CPTC), a simulation of a professional real-world penetration test, this study seeks to further examine pentesting metrics. Metrics from industry standards of pentesting practices are compared to the metrics identified by the CPTC participants, revealed through semi-structured group interviews. Industry metrics include standards, such as methods, information gathering, attack generation, quantity of findings, quality of findings, and reporting of findings. Other additional metrics identified by the CPTC participants include skills of the team, the environment, expectations, and the relationships among group members. This study uses a qualitative methodological approach to examine the metrics of success identified by pentesters as they reflect on their decisions, actions, and performance.","PeriodicalId":329844,"journal":{"name":"2021 IEEE Integrated STEM Education Conference (ISEC)","volume":"58 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-03-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"An Examination of Industry Standards of Success within Penetration Testing Groups\",\"authors\":\"M. Ducoste, Rachel Bleiman, T. Nguyen, Aunshul Rege\",\"doi\":\"10.1109/ISEC52395.2021.9764146\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Penetration testing groups can be used as an ethical proxy to study cybercrime groups, as both parties share the common goal of identifying and exploiting weaknesses in their targets’ systems. Pentesters often use existing industry standards to guide their performance and practices, but little research has investigated how these standards operate in simulated cybersecurity exercises. Using the experiences of college students in the 2018 and 2019 National Collegiate Penetration Testing Competition (CPTC), a simulation of a professional real-world penetration test, this study seeks to further examine pentesting metrics. Metrics from industry standards of pentesting practices are compared to the metrics identified by the CPTC participants, revealed through semi-structured group interviews. Industry metrics include standards, such as methods, information gathering, attack generation, quantity of findings, quality of findings, and reporting of findings. Other additional metrics identified by the CPTC participants include skills of the team, the environment, expectations, and the relationships among group members. This study uses a qualitative methodological approach to examine the metrics of success identified by pentesters as they reflect on their decisions, actions, and performance.\",\"PeriodicalId\":329844,\"journal\":{\"name\":\"2021 IEEE Integrated STEM Education Conference (ISEC)\",\"volume\":\"58 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-03-13\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE Integrated STEM Education Conference (ISEC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ISEC52395.2021.9764146\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE Integrated STEM Education Conference (ISEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISEC52395.2021.9764146","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

渗透测试组织可以作为研究网络犯罪组织的道德代理,因为双方都有一个共同的目标,即识别和利用目标系统中的弱点。渗透测试者经常使用现有的行业标准来指导他们的表现和实践,但很少有研究调查这些标准如何在模拟网络安全演习中运作。利用大学生在2018年和2019年全国大学生渗透测试竞赛(CPTC)中的经验,本研究旨在进一步检验渗透测试指标。CPTC是一项模拟专业真实世界渗透测试的竞赛。来自渗透测试实践的行业标准的指标与CPTC参与者确定的指标进行比较,这些指标是通过半结构化的小组访谈揭示的。行业量度包括标准,例如方法、信息收集、攻击生成、发现的数量、发现的质量和发现的报告。CPTC参与者确定的其他附加指标包括团队技能、环境、期望和团队成员之间的关系。本研究使用一种定性的方法来检查渗透测试人员在反思他们的决策、行动和表现时确定的成功度量。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
An Examination of Industry Standards of Success within Penetration Testing Groups
Penetration testing groups can be used as an ethical proxy to study cybercrime groups, as both parties share the common goal of identifying and exploiting weaknesses in their targets’ systems. Pentesters often use existing industry standards to guide their performance and practices, but little research has investigated how these standards operate in simulated cybersecurity exercises. Using the experiences of college students in the 2018 and 2019 National Collegiate Penetration Testing Competition (CPTC), a simulation of a professional real-world penetration test, this study seeks to further examine pentesting metrics. Metrics from industry standards of pentesting practices are compared to the metrics identified by the CPTC participants, revealed through semi-structured group interviews. Industry metrics include standards, such as methods, information gathering, attack generation, quantity of findings, quality of findings, and reporting of findings. Other additional metrics identified by the CPTC participants include skills of the team, the environment, expectations, and the relationships among group members. This study uses a qualitative methodological approach to examine the metrics of success identified by pentesters as they reflect on their decisions, actions, and performance.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信