Week 6 Research Paper
Page 1
Expert feedback
August 05, 2021
Hi,
I read your paper on Penetration testing. Below is a brief critique of the assignment.
Nice work,
Your Chegg Expert
Overall score: 3.5/5
Ideas and Content
4/5
Organization 3/5
Voice 3/5
Word Choice 4/5
Sentence Fluency 4/5
Grammar and spelling 3/5
Please note that the score provided above only represents the Expert’s judgment of your writing and in no
way makes any promises or assurances concerning your actual grade.
Page 2
Ideas and content
The ideas and details in your paper were clear and focused. The discussion was focused
on the “The limited awareness leads to the emergence of security holes that crackers
can utilize to access and disrupt the system stability by exploitation (Hasan et al.,
2017).” Also, the ideas presented by you in the paper are following the content of the
paper. Good work! However, make sure that the details provided by you in the paper
are supporting the main theme of the paper. Additionally, you could give an objective to
indicate what the main content is, to bring better clarity for the readers.
Organization
The paper is well-structured and organized. You could give a good start to the essay by
writing a good introductory paragraph that gives proper information about the subject
matter of the paper. However, the body paragraphs are not supporting the main aspect
of the paper. You could make sure that the body paragraphs are supporting the main
aspect of the paper by providing more information about “Penetration testing is a
gaining assurance method in an IT system security by attempting to breach all or some
of the security owned by that system, applying similar techniques and tools as an
adversary might…” Here, you could cite directly from resources to substantiate the
points. Furthermore, the concluding paragraph of the paper could support and reinstate
the main aspect and ideas of the paper.
Page 3
Voice
The essay builds satisfactory audience awareness about Penetration testing. Although,
the tone of the essay should be formal and informative to better suit the needs of the
paper. Furthermore, an analytical tone will help you put your point across to the
audience in a better manner.
Word Choice
The words used in the paper are in alignment with the topic and intent of the paper as
well as varied. An example of good word choice is ‘Vulnerability’, ‘assurance’,
‘reconnaissance’ etc. However, you could explain terms such as ‘Symantec asserts’.
Sentence Fluency
There is sufficient variety in sentence structure and length throughout the essay. The
ideas are written in a sequential manner and the reader is able to read them in a logical
manner. Apart from paragraphs, you could also ensure that each idea is connected to
the respective details and all the ideas are linked to the main topic of this paper. For this
purpose, you could use transitions such as “further/also/moreover”,
“however/but/yet/despite”, etc. This would allow the ideas to flow seamlessly between
paragraphs. For example, “The penetration testing scope is defined in this phase.
(Furthermore,) The test scale and scope are determined as per existing laws and
regulations, culture, security policies, industry requirements, and best practices.”
Page 4
Grammar and spelling
There is scope for improvement in grammar and spelling. You could construct simple
sentences to avoid syntax errors: “The second stage is reconnaissance . This stage is
where information is brought together.” You could avoid capitalization error. For
instance, “i(I)n instances where the software system is already hacked, and an
organization wants to ascertain.” Otherwise, your paper is rightly framed. Nice work!
For more results, you could run the Chegg Writing grammar checker:
https://www.chegg.com/writing/grammar-check/
Page 5
Next Steps
Fix what you agree with, ignore what you don't, and then resubmit to get another
expert check! The best way to improve your paper is to keep writing, revising,
and considering outside feedback.
Resubmit my paper
After you’ve got your paper reading just right, submit it for a Plagiarism and
Grammar check to add that final polish and catch any remaining issues!
Check Plagiarism and Grammar
Page 6
Your paper
Penetration Testing Name Institution Date Week 6 Research Paper Penetration testing is a simulated cyberattack against a computer or network that checks for exploitable vulnerabilities. Pen tests can involve attempting to breach application systems, APIs, servers, inputs, and code injection attacks to reveal vulnerabilities. In a well-written, highly- detailed research paper, discuss the following: 1. What is penetration testing 2. Testing Stages 3. Testing Methods 4. Testing, web applications and firewalls Your paper should meet the following requirements: 1. Be approximately 4-6 pages in length, not including the required cover page and reference page. (Remember, APA is double spaced) 2. Follow APA 7 guidelines. Your paper should include an introduction, a body with fully developed content, and a conclusion. 3. Support your answers with the readings from the course and at least two scholarly journal articles to support your positions, claims, and observations, in addition to your textbook. The UC Library is a great place to find resources. 4. Be clear and well-written, concise, and logical, using excellent grammar and style techniques. You are being graded in part on the quality of your writing. Penetration Testing
Page 7
Information technology development is a new security challenge for computer network systems and the contained information in them. Yet, the awareness level about the significance of network security systems remains very low. A survey carried out by Symantec asserts that the need to renew and in-place security system within an organization annually has an outcome that only 13 percent of respondents desire alterations to the security system to be vital from the comprehensive 3,300 institutions globally respondents (Satria et al., 2018). The limited awareness leads to the emergence of security holes that crackers can utilize to access and disrupt the system stability by exploitation (Hasan et al., 2017). Each year, cyber-attacks surge significantly, making it necessary to improve the existing system security annually. On that basis, a technique is required to periodically assess network and system security using penetration testing methods to check any vulnerabilities present on a system and on the network to foster security and minimize loss or theft of crucial data. The research paper discusses the penetration testing process, stages, methods, firewalls, and web applications. Penetration testing (PT) refers to an active technique for entering and evaluating digital assists security by generating, planning, and executing overall possible attacks capable of exploiting existing vulnerabilities (Ghanem & Chen, 2018). Also referred to as pen testing, penetration testing is a form of security testing applied to cover risks, threats, and vulnerabilities that an attacker is necessary to exploit in web applications, software, or networks applications (Chapple, Stewart & Gibson, 2018). The National Institute of Standards and Technology defines penetration testing as the cyber-attacks imitation security testing to identify network or system vulnerabilities before adversaries can take advantage of them. Penetration testing is a gaining assurance method in an IT system security by attempting to breach all or some of the security owned by that system, applying similar techniques and tools as an adversary might, according to the UK National Cyber Security Center (Penetration Testing, 2017). Penetration testing aims to locate and test the entire possible security vulnerabilities that exist in the software application. Vulnerability is defined as the risk that a hacker can gain or disrupt authorized access to the system or data it contains (Singh & Singh, 2017). Usually, vulnerabilities are accidentally introduced during the development and implementation phase of the software. Common vulnerabilities are software bugs, configuration errors, design errors, among others. Financial institutions like stock trading exchanges, banks, and investment banks want security to their data, and penetration testing is essential in ensuring security. Furthermore, in instances where the software system is already hacked, and the company wants to ascertain whether any threats are still existing in the system, penetration testing is necessary to avoid future attacks (Hasan et al., 2017). All in all, proactive penetration testing is a possible safeguard against hackers. There are various stages in penetration testing. Based on the requirements of the entity that needs the penetration test, a particular process is applied. According to Mamilla (2021), there exist eight stages in a penetration testing process. The initial stage is planning. The penetration testing scope is defined in this phase. The test scale and scope are determined as per existing laws and regulations, culture, security policies, industry requirements, and best practices. The
Page 8
stage is vital as it describes the whole test and guides the test to deliver. The second stage is reconnaissance. This stage is where information is brought together. A pen tester gathers complete information possible concerning the institution or the to-be-tested system, in the sense that the information can be relevant during the attack (Singh & Singh, 2017). The collection of the information is either deliberate or passive (Baloch, 2017). Deliberate gathering entails scanning ports to detect vulnerabilities, while passive gathering involves collecting available information from the public. The third stage is scanning. In this step, the pen tester utilizes scanning tools to scan in a target system for vulnerabilities. The stage entails scanning the target network for firewall detection, service running, firewall location, open ports, OS identification, and so on (Wang & D’Cruze, 2019). The fourth stage is gaining access. Exploiting the vulnerabilities found in scanning and applying the knowledge acquired from surveillance, a pen tester begins attacking the objective system to enter into the system. The fifth phase is maintaining access. After the pen tester gains access to the system, they apply different techniques to progress their system access. The sixth stage is covering tracks. This phase is accomplished by pen testers erasing the evidence that they accessed the system, thus covering their tracks. The seventh stage is analysis. All the acquired information is analyzed in this step, together with the discovered vulnerabilities, and suggests measures of remedy to counteract the noticed vulnerabilities (Mamilla, 2021). The final phase is reporting. The whole collected information in the previous stages is reported formally to the organization stakeholders in this stage. The report encompasses the discovered vulnerabilities, time spent, sensitive data accessed, and recommended remediation solutions. Consequently, penetration testing is executed via several methods. The first method is internal testing. In an internal test method, a pen tester who can access an application and its firewall imitate an attack by a hacker. A common kick-off scenario can be a worker whose credentials were stolen due to a phishing attack. The second method of penetration testing is external testing. This test targets the company assets seen on the internet, such as the company website, the web application, domain name servers, and email (Mamilla, 2021). The objective is to enter and extract valuable information. A third method is blind testing. In this method, the tester is handed only the enterprise identity that is being targeted. This move offers security personnel a real-time perception of the manner an actual application assault would occur. A fourth method is targeted testing. The security personnel and the tester in this scenario work in collaboration and keep one another appraised of their tactics. This move is a vital exercise of training that offers a security group real-time point-of-view hacker feedback (Wang & D’Cruze, 2019). The last method is double-blind testing. Security personnel possesses zero before- knowledge of the stimulated attack in this method. In the actual world, they will have no time to shore up their defenses before an attempted hacking. Penetration testing and web application, and firewalls are full security measures with mutual benefit. For numerous pen-testing kinds, excluding double-blind and blind tests, the tester is probable to utilize web application and firewalls date like logs to identify and exploit the weak spots of an application (Applebaum, Gaber & Ahmed, 2021). Web applications and firewalls, in
Page 9
turn, can from pen-testing data benefit. After completing a test, web application and firewalls configurations can be secured via updates against the test discovered weak spots. Finally, pen- testing meets compliance requirements for security auditing methods, including SOC 2, DSS, and PCI (Baloch, 2017). Specific standards, like PCI-DSS 6.6, can only be satisfied via a certified web application and firewall. However, doing that does not render pen-testing any less critical due to its benefits and ability to foster web application and firewall configurations. In conclusion, with the vast emergence of technology, security concerns have also drastically increased. Proactive penetration testing is the possible safeguard against hackers, detecting vulnerabilities in network security before utilizing them to enter it (Wang & D’Cruze, 2019). in instances where the software system is already hacked, and an organization wants to ascertain whether any threats are still existing in the system, penetration testing is necessary to avoid future attacks. Testers should behave like an actual hacker, test the system or application, and ascertain if a code is securely written. A penetration test will be fruitful when a well- implemented security policy is available. According to research, each system possesses a 20- 80% security risk (Satria et al., 2018). Based on these tests outcomes, it can be concluded that every system possesses a security vulnerability that is prone to attack and needs to be protected via penetration testing to avoid the actual attack. However, penetration testing methodology and policy should be available (Ghanem & Chen, 2018). Additionally, new penetration testing techniques need to be introduced. References Applebaum, S., Gaber, T., & Ahmed, A. (2021). Signature-based and Machine-Learning-based Web Application Firewalls: A Short Survey. Procedia Computer Science, 189, 359-367. Baloch, R. (2017). Ethical hacking and penetration testing guide. CRC Press. Chapple, M., Stewart, J. M., & Gibson, D. (2018). (ISC) 2 CISSP Certified Information Systems Security Professional Official Study Guide. John Wiley & Sons. Ghanem, M. C., & Chen, T. M. (2018, October). Reinforcement learning for intelligent penetration testing. In 2018 Second World Conference on Smart Trends in Systems, Security and Sustainability (WorldS4) (pp. 185-192). IEEE. Hasan, A. M., Meva, D. T., Roy, A. K., & Doshi, J. (2017, December). Perusal of web application security approach. In 2017 International Conference on Intelligent Communication and Computational Techniques (ICCT) (pp. 90-95). IEEE. Mamilla, S. R. (2021). A Study of Penetration Testing Processes and Tools. Penetration testing. (2017, August). Retrieved April 04, 2021, from https://www.ncsc.gov.uk/guidance/penetration-testing
Page 10
Satria, D., Alanda, A., Erianda, A., & Prayama, D. (2018). Network Security Assessment Using Internal Network Penetration Testing Methodology. JOIV: International Journal on Informatics Visualization, 2(4-2), 360-365. Singh, H., & Singh, J. (2017). Penetration Testing in Wireless Networks. International Journal of Advanced Research in Computer Science, 8(5). Wang, P., & D’Cruze, H. (2019). Cybersecurity certification: certified information systems security professional (CISSP). In 16th International Conference on Information Technology-New Generations (ITNG 2019) (pp. 69-75). Springer, Cham.