Introduction
Security testing refers to the process that is used to evaluate if a system that encompasses of information technologies is able to shield the data from unlawful access and maintain the proper functionality of the system by being able to detect the error in the entire system and offering an appropriate solution to the problem. Security testing is also very vital in the information system technology since it enables in the entire process of trouble shooting the system to make sure that all the system functions appropriately without any failure. The failures that are detecting by the security testing method are usually detected are corrected in the best manner to make sure that the system is able to achieve its normal operating mode (Cyber security 2010).
In the current world the aspect of securing and operating the various web application which are vital for the human survival is a difficult and at the same time very challenging thus the need of experts who are normally able to test the security of the web application pages before they are implicated and used for the several functions. Basing on such facts it is vivid that any organization should formulate strategies that will enable it to make the web applications secure and able to withstand the various unsecure risks that are available on the network. A well established organization should include the vital security efforts that enable it from the threats from the access of unauthorized. The security efforts encompasses of accreditation, risk analysis, security architectures, certification and policy development.
These security efforts are very essential in the sense that it is able to assure the quality of the security testing in the organization (Wack, Tracy & Souppaya 123). Security testing is technical security measure that encompasses of the recovery testing, stress testing, deployment testing and performance testing. In general, security testing is a process that is used to make sure that the diverse feature that are implemented into a system during the designing process are able to function properly as intended by the designers.
This is made possible by various aspects such as penetration testing; function testing that makes sure that all the components of the system function appropriately and finally the verification of the different elements of the system. Security testing involves various functions that are supposed to be logically administered so as to ensure that the system acquires a successful security work form. This security taxonomy enables the management of a system to be able to identify the various methods that can be used in the process of enacting the security of a system in various diverse forms. The key six fundamental security concepts that usually makes up the security testing of a system encompasses of Network Scanning which encompasses searching through the system for viruses, Vulnerability Scanning, Password Cracking by the hackers to gain unauthorized access, Penetration Testing, War Driving and Virus Detection by the firewalls and the firewalls (Hope & Walther 122).
Security Testing and Security Audit
Security testing refers to the various techniques that are used to make sure that the network system of the organization is functioning appropriately as designed by the manufacturing. Security testing refers to reducing vulnerability in the system thus making it to function more efficiently than it used to perform in the past. While security audit refers to the process by which the system is changed to make sure that it also functions appropriately. The organization audit also enables management of the system to be able to identify the direction in which the organization is moving by identifying the profitable gains that are made (Wack, Tracy & Souppaya 117).
Network Scanning
Network scanning is whereby the system is tested so as to be able to identify the available hosts that are used to as to be able to activate the host so as to allow other devices such as the printer switches and routers to be connected in the system. Network scanning also involves the various techniques that are used to identify the viruses which are a threat to the normal functioning of the system. These viruses and the Trojans that might make the system to crush are the detected by the scanning tool that is installed in the system. The scanning also assists to protect the system from additional viruses into the system by informing the personnel the number of the viruses that are available in the system (Hope & Walther 176).
After the identification of the viruses and the Trojans in the system by the scanning device the network system is installed with appropriate tools that will enable the deletion of the viruses in the system so as to make it to resume it is usual operation ability that was initially reduced by the activation of the viruses into the system. The scanning devices also makes it very possible for the personnel to identify the vulnerability of the system thus makes the personal manager to be able to estimate the appropriate rate at which the system might be affected by the viruses thus make it not to function in an appropriate manner. Basing on such facts, it is important that the system is scanned frequently to enable the management personnel to know how far the system has been affected by the viruses. By scanning the system frequently, it makes the system to be more efficient especially in the transactions especially if the identified viruses are deleted from the network system.
Vulnerability Assessment
In the security testing taxonomy, vulnerability assessment is another essential aspect that is necessary for the proper functioning of the network system. The vulnerability assessment assists the personnel to vividly identify the various problems that are affecting the network system thus making it not to function properly. This is very vital since the system is affected by the normal functioning of both the internal and the external aspect that are in most cases introduced into the system by unauthorized access personnel.
After the vulnerabilities of the system are identified it is the duty of the personnel manager to ensure that they are deleted from the system to make sure that it does not break down by the improper functioning of the problems that affect the system. This makes the system to retain it is usual operating mode and enables the system to be installed by detecting risk tools that will be able to identify any more cases of vulnerabilities in the system hence making the system to improve in the nature in which the network is possible to make several transactions over to other systems (Wack, Tracy & Souppaya 145).
Password Cracking
The process of system testing also involves the various ways in which the system is installed with passwords that makes it even more secure from unauthorized access from the unauthorized personnel. The password is very essential since it prevents other people from accessing the network system without given permission from the management authorities. However, the password should be personal and private since the system can still be accessed by the hackers who have the ability to break thorough the passwords to be able to access the information that they might use to blackmail the organizations using the information that is obtained.
For this reasons, it is very essential for the passwords to be made stronger by making the password to encompass several digits and alphabetical letters that makes it vey difficult for the hackers to be able to crack through the codes. This makes the system more secure thus enabling it to function even more appropriately after undergoing thorough the process testing to ensure that it is functioning more efficiently. This also makes the information that is being transmitted over the network to be secured since it is not easily accessed by the unauthorized persons (Hope & Walther 162).
Virus Detection
Virus detection refers to the various ways that the system is able to search for the available viruses that are available in the system. This is done by troubleshooting the entire system using searching tools that will make it very simple to identify the viruses that are a threat to the normal functioning of the network system. The detected viruses that are found in the system can however be removed from the system to make it more efficient because more data bundles will be able to able to be transmitted over the network at a faster rate. The bandwidth of the network will also increase because the network will be free from the viruses which reduce the speed of the transaction (Pressman 135).
However, the viruses in the network system can be reduced or removed from the system by the use of the anti-viruses that might be installed in the system. This makes the system more defensive from the various viruses that might destroy it making it function in a less valuable to the users. The anti-viruses also make it possible for other infrastructures of the network such as the mails and the messages to be transmitted from the sender to the receipt without it being attacked by the viruses when still in the process of transmission.
Another was that might be very essential in the prevention of the viruses in the system is by the installation of the firewall in the system network to prevent the spread of the viruses from the server machine to the other servant machines. This is because the firewalls also detect the viruses at a very faster rate and informs the personnel management before the viruses are able to spread to other parts of the system. Firewalls are more preferred than the ant viruses in most of the system networks since they detect the viruses when still in the transmission lines. This is contrary to the anti-viruses which detect the viruses when they have already been invaded the system network thus very difficult to be omitted from the system (Pressman 166).
The viruses are a major threat to the system network thus should not be tolerated in the system at all since they lead to demolish of parts of the system making it very difficult for the system to function in an appropriate manner. For this reason, the system should be updated with the latest version of both the firewalls and the anti-viruses to make sure that the network system is kept away from the viruses as much as possible. The firewall and the anti-viruses should also be allowed to scan the system every time the network is resumed to prevent penetration of the viruses into the system.
War Driving
War driving is whereby the attackers who are the persons who expose the internet to the viruses so that the system of other people might be attacked with the viruses that will automatically lead to the destruction of the system. This is mostly likely practiced using the wireless network whereby the transmission of the data and the information is much faster since it is not through the cables and also making it very possible for the viruses to attack the network system since the data is not transmitted in cables making it very difficult for the viruses to be detected by protective devices such as the firewalls and the ant viruses (Graw 143). This can be prevented by the user of the network system reducing the interactions from foreign wireless networks that might increase the rates of the virus’s transmission of the viruses via the wireless transmission.
Penetration Testing
Penetration testing refers to the diverse ways that the hackers use to make it possible for the intrusion of another network using the high technology and unique methods that are acquired from getting used to various different network systems. This is the worst of all the means that the viruses might be introduced into the system since it is introduced manuals by the hackers who might install as much viruses as they are interested (Cyber security 2010).
Penetration testing also encompasses of the various means by which the organization is checked to ensure that there are no viruses or Trojans that have penetrated in to the system without the concern of the management of the organization. Therefore, if the viruses are detected to have penetrated into the system, appropriate measures should be taken on how they can be removed immediately from the system of the organization before it can be completely be destroyed by the viruses and the Trojans that usually makes the system to crush making it function in an usual manner. Penetration of the viruses into the system can be avoided by the installation of the firewall which detects and notifies the personnel before the system crushes (Takanen, Demott, & Miller 257).
Log Review
Log review refers to the various methods that are used to detect the numerous suspicious activities immediately they take place in the network system so as to be able to reduce the impact of the activity on the network as much as possible. When a suspicious activity is identified early by the security administrator of a system network, it helps to reduce the manner in which the system might get destroyed since the necessary actions will be taken to ensure that the activity is ejected from the system as fast as possible.
The identification of the suspicious activity in the system at an earlier state also assists the management administrator to be able to apply the necessary measures that will automatically assist in the prevention of the system from getting the harm of getting destroyed by the viruses. Log review can be enacted into the system by the system administrator being more careful with the components of the system thus being able to identify any slight change that might have taken place while he or she is away from the network system for various reasons such as bed rest (Cross 117).
War Dialing
War dialing is a method that is often used by the hackers to be able to retrieve the passwords of the computer machines that are found in a system so that they can retrieve the valuable information from the system. Although the entire process of war dialing might be the use of guess work, it is a very vital method that enables the hackers to get the valuable information from the network system thus it should be considered as a threat and be avoided as much as possible to avoid the system from being destroyed (Slezak 215). War dialing is usually done by the uses of a modem to scan automatically into a large areas system so that the hackers can be able to acquire the passwords of the computers by using the local area code that usually displays all the passwords of the computer users in a system.
Integrity Checkers
Integrity checkers are software that are installed into a network system for the main purposes of identifying Trojans and other backdoor intrusion that might have entered into the system without the concern of the system administrator. The most appropriate way to use the integrity checkers is by installing it to the main server which is mainly used by the personnel manager aft the system network. The integrity checkers also assist the system administrator to be able to identify the files that have been tempered by unauthorized persons into the system. However, although the integrity checker notifies the system administrator on the Trojans, it is very complicated to use thus most of the system security personnel prefer the use of the anti-viruses and firewalls since they are more users friendly (Graw 213).
Conclusion
In any given organization the security testing should be considered as the first option since the network system which the vital part of the organization might be attacked by viruses at any given moment. There are various ways that the viruses can be prevented from attacking the network system but the most important action that can be done to reduce the amount of the viruses in the system is by reducing the number of the intruders who are mostly the hackers who ate most time access the network with unauthorized permission. Anti-viruses and firewalls are the most common methods that are used to reduce viruses from invading the network system and are more efficient if the network is scanned frequently to make sure that it performance to it is best giving a hundred percentage performances (Pressman 159).
Work cited
Cyber security – michigan department of technology. (2010). Retrieved from http://www.michigan.gov/cybersecurity/0,1607,7-217-34415—,00.html,
Cross, Michael. Developer’s guide to web application security, New Jersey: Syngress, 2007
Graw, Gary. Software security: building security in, Addison-Wesley software security series, New York: Addison-Wesley, 2006
Hope, Paco & Walther, B. Web Security Testing Cookbook: Systematic Techniques to Find Problems Fast, Cookbook Series, Safari Books Online, New York: O’Reilly Media, Inc., 2008
Pressman, R.S. (2010). Software engineering. Crawfordsville,IN California: Mc Graw Hill .
Slezak, Dominik. Security Technology: International Conference, SecTech 2009, Held as Part of the Future Generation Information Technology Conference, FGIT 2009, Jeju Island, Korea, December 10-12, 2009. Proceedings, Volume 58 of Communications in Computer and Information Science, California: Springer, 2009
Takanen, Aris., Demott, Jared., Miller, Charles. Fuzzing for software security testing and quality assurance, Artech House information security and privacy series, London: Artech House
Wack., J, Tracy., M, & Souppaya, M. (2003). Guideline on network security testing. (800-42), Retrieved from http://csrc.nist.gov/publications/nistpubs/800-42/NIST-SP800-42.pdf
