[ Web Proxy ]
URL:
Viewing: https://brave.com/glossary/penetration-testing/ [Back]  [Original]

Penetration testing Meaning & Definition | Brave

Privacy glossary

Penetration testing

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

Published May 7, 2024

Table of Contents

What is penetration testing?

Penetration testing is a process that audits the security of a system or network by simulating a cyber-attack. The goal of penetration testing is to safely and legally identify potential points of vulnerability in a system so weaknesses can be addressed before they’re exploited by real attackers. Penetration testers often use the same tools and approaches that attackers use, and test all aspects of the system, including hardware, software, physical security, and staff training and activity.

Also called pen testing, this kind of audit can be applied to any aspect of a system or network that’s designed to be secure. Pen testing can look for exploitable vulnerabilities in hardware (like servers, routers, laptops, and mobile devices), networks, use of cloud computing and storage, software and Web app configurations (including Internet of Things interfaces), data interaction through APIs, and individuals’ credentials. Security awareness of employees can also be evaluated by testing both physical and virtual activities—things like how a phishing attempt is handled or if it’s possible to get past security and enter the physical building or a secure room.

Why is penetration testing important?

The goal of penetration testing is to find a system’s weaknesses to outside attacks, internal attempts to get beyond allowed access levels, or simple employee errors. “Real” attacks can lead to data breaches, ransomware, or general disruption of an organization’s business, so pen tests are meant to give an organization a better picture of unmitigated vulnerabilities, along with an idea of how to prioritize fixes. Without pen testing, an organization runs the risk of discovering a vulnerability only after it’s been exploited by an attacker.

While some pen testing is voluntary, an organization may be subject to regulations that require proof that sensitive data is secured. GDPR and HIPAA both contain requirements that any system containing sensitive data must be regularly tested and evaluated for adequate security. Pen testing is accepted as an excellent way to meet these requirements. PCI DSS, a global standard that applies to any organization that handles credit card data, specifically requires regular pen testing.

Tools used in penetration testing

Penetration testing is most effective when it’s thorough and comprehensive, which can be especially challenging when dealing with complex or large systems. To aid in the large scope of some pen testing situations, software packages are available to help with completing well-documented or repetitive tests. Software packages are often combined with a library of known exploits used in the past by attackers, and methods to test them. Notably, these packages are used by both testers to test a system and hackers to attack a system.

Some pen testing can be done by non-specialists, using a portion of these same software packages. More complex pen testing is usually done by independent third-party experts, who may use these tools as aids, but don’t generally rely on them exclusively. Independent pen testers are often a better choice over internal staff, since they aren’t influenced by inside knowledge or a false sense of confidence in the system.

Types of penetration testing

A pen test can be one of several scenarios, each distinguished by how much information the pen tester has initially about the system being tested:

The starting point knowledge base isn’t the only variable in a pen test scenario. Another variable is whether the internal security team is given notice that a pen testing event is occurring. Internal security may not be told in advance, resulting in real life testing of the security team’s responses to a security threat. In some situations, the pen tester and internal security may work together in a simulation, called Red Team vs. Blue Team. This allows for real time reactions and creates learning opportunities for the internal security team.

Stages of penetration testing

Comprehensive penetration testing can be quite involved, and require a certain level of organization in order to be effective. Typical steps of a pen test might look like this:

When is penetration testing done?

Systems are always evolving—new vulnerabilities can be introduced with new hardware, software updates, adding new users or altering the permissions of existing users, and more. New threats also surface when new vulnerabilities are discovered in existing code, or hackers develop new tools to attack systems. The value of pen testing is that it can identify vulnerabilities, and create a path to remediation, before a hacker finds them and causes much bigger problems.

In response to this always changing threat environment, pen testing should be done regularly, with the frequency based on an organization’s needs and budget. Some regulations require pen testing as often as quarterly. Pen testing is also helpful on an ad hoc basis whenever there’s a significant change in the cyber environment—internal or external. A small-scale pen test can be executed to focus on a particular new threat.

Does penetration testing protect me?

While penetration testing is conducted at an organizational level, it does protect the individual as well. Websites, apps, and databases of companies that do frequent pen testing are typically better protected against threats from hackers. This means your data and your online activity are also better protected. By choosing to use and support companies that run frequent pen tests (or are required to meet certain testing standards), and coupling that with other personal privacy steps like a VPN and a privacy browser like Brave, you can help to improve your safety online.

Ready for a better Internet?

Brave’s easy-to-use browser blocks ads by default, making the Web faster, safer, and less cluttered for people all over the world.

Get Brave
Google Play Store button [Google Play Store button]
Apple App Store button [Apple App Store button]
Get Brave

Web Proxy Viewer  |  New URL  |  Original Page