Through Vulnerability Assessment (VA) and Penetration Test (PT) activities, we verify the logical and organizational security measures the customer has put in place, with the aim of preventing cybercrime and the disclosure of sensitive information.
Through Vulnerability Assessment (VA) and Penetration Test (PT) activities, we verify the logical and organizational security measures the customer has put in place, with the aim of preventing cybercrime and the disclosure of sensitive information. To achieve this, we need to:
  • ♦ identify IT security vulnerabilities in the corporate network and systems (especially systems deemed critical), including web servers;
  • ♦ verify that the behavioral policies and procedures in place, and the related training, are correct and complete, so as to prevent the security risks that arise from users’ carelessness or lack of awareness when using IT systems.
We take particular care to keep these activities as “transparent” as possible for users of the information system and to minimize any impact on the performance of the corporate network. External scans are preferably carried out at night. For more information, contact technical support or, if you are already a customer, open a ticket.

OBJECTIVES

The Vulnerability Assessment (VA) / Penetration Test (PT) service lets you verify how robust your network is through the following activities:
  • ♦ Network sniffing.
  • ♦ IP and port scanning.
  • ♦ ARP spoofing.
  • ♦ Access to the corporate network.
  • ♦ Attempts to steal or guess domain passwords.
  • ♦ Search for vulnerabilities at layers 2, 3 and 7 of the ISO/OSI stack.
  • ♦ Exploitation of any vulnerabilities found to gain control of systems/services.
  • ♦ Analysis, verification and interpretation of the results.

ACRONYMS AND ABBREVIATIONS

IVA = Internal Vulnerability Assessment EVA = External Vulnerability Assessment IPT = Internal Penetration Test EPT = External Penetration Test

METHODOLOGY

Our methodology measures corporate IT security through four macro steps:
  1. 1) Internal Vulnerability Assessment (Step 1).
This is the starting point for assessing the IT security of the internal network. It produces an index of the security status of the LAN (Local Area Network), which is then used to propose countermeasures and methodologies to raise the overall security level.
  1. 2) External Vulnerability Assessment (Step 2).
A Vulnerability Assessment conducted from outside against the information systems in the perimeter area. Although this phase can be carried out independently of the Internal Vulnerability Assessment, it is best performed after it, so that the overall results can be compared and the security findings can be more targeted.
  1. 3) Internal Penetration Test (Step 3).
A Penetration Test attempts to exploit the vulnerabilities that emerged from the previous analyses in order to breach the target systems. The Internal Penetration Test is performed from within the corporate network against internal and perimeter systems. The first two steps are prerequisites for this activity.
  1. 4) External Penetration Test (Step 4).
Similar to the previous step, but with the attack launched from outside the corporate perimeter. The flow chart in Figure 1 shows more clearly how these operational steps are interconnected. It is designed to analyze the security of the system and to apply suitable countermeasures by following clearly defined steps. Which tests are performed depends on the level of security you want to achieve. Analyzing the reports and applying best practices makes it easier to decide which security tests to select. Note: taken together, the steps described above form a security methodology that carries out the assessment process sequentially through a series of tests. The process is not meant to be atomic (running every test); as the flow chart below shows, it is a modular process for analyzing corporate security.

INTERNAL VULNERABILITY ASSESSMENT (IVA)

The robustness of the IT security measures will be verified from the inside (trusted network), by identifying which known vulnerabilities could be exploited by malicious users to carry out cyber attacks.

This involves running non-destructive “scans” of the systems, using tools designed to detect the status of standard operating systems and applications.

These are the same tools commonly used by malicious users and freely available on the Internet; on request, tools from well-known security software vendors can be used instead. Whether public open-source tools or commercial products are used makes no substantial difference to the results.

When analyzing the vulnerabilities and weaknesses of the infrastructure as a whole, the critical ones will be highlighted. A “critical” vulnerability is one that could cause serious and immediate damage, such as business disruption, loss of sensitive data, or loss of credibility, reputation or money. This allows immediate action to be taken to mitigate the problem.

At the end of the activity, the results will be summarized in a Vulnerability Assessment Report.

IVA TARGET

The Target is the set of elements covered by the Vulnerability Assessment. It varies according to the structural characteristics of the organization being analyzed and the type of VA being conducted. Based on initial considerations, the Target is the LAN (a connection to any LAN segment), regarded as a weak link in the network infrastructure. The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following devices within the LAN:
  1. ◊ Network devices.
  2. ◊ Security devices.
  3. ◊ Application servers.
  4. ◊ Storage servers.

IVA PHASES

The project is divided into the following phases:
  1. 1) Reconnaissance.
Gathering all information that may be useful for the VA. The technical information to be collected includes:
  • ◊ Network structure (reverse engineering to map the network topology).
  • ◊ Identification and classification of servers and network devices that are “critical” from a security architecture standpoint.
  • ◊ Identification of the operating systems in use (OS fingerprinting).
  • ◊ Research of public information on the applications in use.
  1. 2) Vulnerability Assessment.
Detection of vulnerabilities in the target systems. The tiger team carries out authorized attacks, using public or purpose-built tools, to find vulnerabilities in the target and gain access to its systems. The vulnerabilities identified are also used to pinpoint compromised (or compromisable) systems, which can serve in the following phases as a pivot (escalating point) for further scans or compromises.
  1. 3) Vulnerability classification.
Classification of the vulnerabilities found in the target systems. All identified vulnerabilities are ranked by priority, from most to least critical. This ranking supports decision-making on how to secure the IT infrastructure.
  1. 4) Reporting and countermeasure management.
Delivery of documentation on what was analyzed, with recommendations on any countermeasures to adopt.

IVA REPORT

The Internal Vulnerability Assessment report comprises all the documentation delivered at the end of the activity. Figure 2 outlines the first step described above, highlighting the reporting phase as the output of the IVA activity. The report will contain the following information:
  • ♦ List of vulnerabilities, if any, for each server / network device.
For each network element in the target, a list of security vulnerabilities and their descriptions will be provided.
  • ♦ Vulnerability classification.
The vulnerabilities identified will be grouped as follows:
  • ◊ High (Critical): vulnerabilities that pose, or may pose, a serious risk to the company.
  • ◊ Medium: medium-risk vulnerabilities, exploitable through few attack vectors or with limited impact on the company.
  • ◊ Low: vulnerabilities with little or no impact on business productivity.
A list of actions to eliminate or reduce the vulnerabilities affecting the system.
  • ♦ Best practices.
A set of recommended rules and behaviors to maintain a high, acceptable level of security. These may be provided as a list of actions, usually related to a specific activity, or as a methodological process in the form of a flow chart.

EXTERNAL VULNERABILITY ASSESSMENT (EVA)

EVA TARGET

Based on initial considerations, the Target is the set of perimeter network devices that physically separate the LAN from the Internet (the trusted and untrusted networks). The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following network devices:
  1. ♦ Security devices.
    1. ◊ Firewalls.
    2. ◊ VPN terminators.
    3. ◊ Access points / radio bridges.
  2. ♦ Application servers.

EVA PHASES

The project is divided into the following phases:
  1. 1) Reconnaissance.
Gathering all information that may be useful for the VA. The technical information to be collected includes:
  • ♦ Perimeter network structure (reverse engineering to map the network topology).
  • ♦ Identification and classification of servers and network devices that are “critical” from a security architecture standpoint.
  • ♦ Identification of the operating systems in use (OS fingerprinting).
  • ♦ Identification of remote access methods.
  • ♦ Research of public information on the company requesting the security test.
  • ♦ Research of public information on the applications in use.
  1. 2) Vulnerability Assessment.
Detection of vulnerabilities in the target systems. The tiger team carries out authorized attacks, using public or purpose-built tools, to find vulnerabilities in the target and gain access to its systems. The vulnerabilities identified are also used to pinpoint compromised (or compromisable) systems, which can serve in the following phases as a pivot (escalating point) for further scans or compromises.
  1. 3) Vulnerability classification.
Classification of the vulnerabilities found in the target systems. All identified vulnerabilities are ranked by priority, from most to least critical. This ranking supports decision-making on how to secure the IT infrastructure.
  1. 4) Reporting and countermeasure management.
Delivery of documentation on what was analyzed, with recommendations on any countermeasures to adopt.

EVA REPORT

The External Vulnerability Assessment report comprises all the documentation delivered at the end of the activity. Figure 3 outlines the second step described above, highlighting the reporting phase as the output of the EVA activity. The report will contain the following information:
  • ♦ List of vulnerabilities, if any, for each server / network device.
For each network element in the target, a list of security vulnerabilities and their descriptions will be provided.
  • ♦ Vulnerability classification.
The vulnerabilities identified will be grouped as follows:
  • ♦ High (Critical): vulnerabilities that pose, or may pose, a serious risk to the company.
  • ♦ Medium: medium-risk vulnerabilities, exploitable through few attack vectors or with limited impact on the company.
  • ♦ Low: vulnerabilities with little or no impact on business productivity.
A list of actions to eliminate or reduce the vulnerabilities affecting the system.
  • ♦ Best practices.
A set of recommended rules and behaviors to maintain a high, acceptable level of security. These may be provided as a list of actions, usually related to a specific activity, or as a methodological process in the form of a flow chart.

INTERNAL PENETRATION TEST (IPT)

IPT TARGET

Based on initial considerations, the Target is the LAN (a connection to any LAN segment), regarded as a weak link in the network infrastructure. The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following devices within the LAN:
  1. Network devices.
  2. Security devices.
  3. Application servers.
  4. Storage servers.

IPT PHASES

  1. Application server exploitation.
This phase builds on the information gathered during the IVA. Based on those earlier analyses, the tiger team selects or develops the appropriate set of attacks to compromise the application servers.
  1. Network penetration.
The tiger team uses attack techniques designed to evade network security systems.
  1. Privilege escalation.
The tiger team focuses on the compromised targets, which are also used as attack vectors.
  1. Reporting and countermeasure management.
Delivery of documentation on what was analyzed, with recommendations on any countermeasures to adopt.

IPT REPORT

The Internal Penetration Test report comprises all the documentation delivered at the end of the activity. Figure 4 outlines the third step described above, highlighting the reporting phase as the output of the IPT. The report will contain the following information:
  • Attack methods (exploits) used.
A description of the attack methods used and how they were applied in the target environment to breach the systems analyzed. A list of actions to eliminate or reduce the vulnerabilities affecting the system.
  • Best practices.
A set of recommended rules and behaviors to maintain a high, acceptable level of security. These may be provided as a list of actions, usually related to a specific activity, or as a methodological process in the form of a flow chart.

EXTERNAL PENETRATION TEST (EPT)

EPT TARGET

Based on initial considerations, the Target is the set of perimeter network devices that physically separate the LAN from the Internet (the trusted and untrusted networks). The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following network devices:
  1. Security devices.
    1. Firewalls.
    2. VPN terminators.
    3. Access points / radio bridges.
  2. Application servers.

EPT PHASES

  1. Application server exploitation.
This phase builds on the information gathered during the EVA. Based on those earlier analyses, the tiger team selects or develops the appropriate set of attacks to compromise the application servers.
  1. Network penetration.
The tiger team uses attack techniques designed to evade network security systems.
  1. Privilege escalation.
The tiger team focuses on the compromised targets, which are also used as attack vectors.
  1. Reporting and countermeasure management.
Delivery of documentation on what was analyzed, with recommendations on any countermeasures to adopt.

EPT REPORT

The External Penetration Test report comprises all the documentation delivered at the end of the activity. The report will contain the following information:
  • Attack methods (exploits) used.
A description of the attack methods used and how they were applied in the target environment to breach the systems analyzed. A list of actions to eliminate or reduce the vulnerabilities affecting the system.
  • Best practices.
A set of recommended rules and behaviors to maintain a high, acceptable level of security. These may be provided as a list of actions, usually related to a specific activity, or as a methodological process in the form of a flow chart.

Customers