Uncategorised

The Evolution of Penetration Testing

The Evolution of Penetration Testing

The Evolution of Penetration Testing

Penetration Testing, or Pen Testing, is an essential component in any comprehensive network and application security strategy. Each security component is important, but there has been a tendency to see Pen Testing as an afterthought or as a box-ticking exercise for regulatory reasons. Indeed, organisations that gather credit card information need to comply with the PCI DSS[1] regulations, and these stipulate regular Pen Tests are required to maintain compliance. The recent introduction of GDPR[2] (General Data Protection Regulations) in the EU and the significant penalties associated with data loss have also driven many organisations to think more about the security of their IT systems. Both these regulatory frameworks have encouraged organisations to do Pen Tests, but there is widespread misunderstanding about what is required for a modern Pen Test that covers the current application delivery and network landscape.

Pen Tests are designed to highlight vulnerabilities in the IT systems that an organisation uses. However, the Pen Test should not be confused with automated vulnerability scans that merely check for known issues and deliver a simple report. Modern Pen Tests are multi-faceted, complex, and comprehensive mini-projects that greatly enhance application security and that will save costs in the medium to long term by helping to reduce malicious attacks and data breaches.

Traditional Pen Testing

Most IT professionals and business leaders who are not directly involved in the IT security field will have heard of Pen Testing, but they will have an incomplete picture of what it entails. Pen Testing has traditionally involved what we would now call a network Pen Test. This type of test targets the network infrastructure components of IT: firewalls, routers, load balancers, DNS systems, SNMP, SMTP, IPS systems, and SSL/TLS configuration.

Probing these for vulnerabilities involved someone outside the network trying to break in, and so this type of test is also known as an external network Pen Test. It tests the perimeter defences of the network to see if they can be breached. A few years ago this might have sufficed for Pen Testing, although that premise is open to debate. In the modern application and network world we inhabit this traditional network Pen Testing is not sufficient.

Modern Pen Testing

The application and network landscape have become much more layered and complicated over time. It doesn’t look like anything that traditional Pen Testing was designed to survey. Business systems and applications now comprise many more components, and as a result, present a larger surface area for attackers. Modern business applications can, and usually do, have the following elements underlying delivery:

  • Network infrastructure - the network that is used to deliver and secure systems and applications. Including wired, wireless, and mobile networks. Increasingly backed by software-defined network (SDN) infrastructure rather than physical firewalls, routers etc. This is the part of the modern application delivery network that most people think of in relation to Pen Testing.
  • Application servers - backend servers providing services for applications. Examples include databases, email, file, and authentication servers (Active Directory and other LDAP services).
  • Web Applications - the proliferation of web applications has been phenomenal. Most modern business applications are delivered via a web application or mobile application (see below). These web applications use a wide variety of technologies such as dotNET, ActiveX, Java, third-party code libraries and APIs (in many languages like JavaScript, Python, Ruby, and more). These web applications provide a very tempting target for attack, and it is vital that they are included in modern Pen Testing.
  • Mobile Applications - the world has gone mobile on Android and iOS. Almost everyone in business now has a smartphone running at least one business application. Even if it’s just the email app. There are also many purpose-built business apps deployed on mobile devices. These come in two types:
    • Wrappers for web apps - these are merely repackaged web apps that have all the issues outlined in the previous point.
    • Custom native mobile applications - these interact with business systems directly, which brings their own security issues related to code libraries and custom code that may have vulnerabilities.
  • Internet of Things (IoT) - Connected devices are everywhere. As with mobile devices, this increases the surface area for attacks on business networks. However, in the case the IoT devices the risk and threat increase is much more substantial.

It is vital that a modern Pen Testing strategy covers all the above components of an application delivery network, and that it also covers the non-technical aspects: the people using the systems. The social engineering aspects of a security breach are often underestimated or overlooked in Pen Testing. Techniques such as Phishing emails or other ways of tricking people into disclosing system information that would help attackers need to be part of any modern Pen Testing approach. It is also vital to address the fact that mobile devices can be lost, and that IoT devices may often be physically accessible to attackers.

Types of Modern Pen Testing

Modern Pen Testing can be grouped into three broad categories, along with a wider framework, known as Red Teaming, that is described later. The three groupings are:

  • White Box - This form of Pen Test is done with the testers having full access to all the information about the underlying IT systems and infrastructure. By full access, it means right up to full admin access to the network, and access to custom code if in use. This allows the testers to get right into the heart of the system from the inside and test for vulnerabilities. This provides for a very detailed examination and also tests the security between internal systems and if an attacker breaches the external protection.
  • Black Box - The opposite of White Box Pen Testing. In this, the testers start with no knowledge of the IT systems and then use the same techniques that an attacker would use to probe for vulnerabilities. This would include both technical and social engineering techniques to try to gain access to the systems. As a result, it also tests the people aspect of security.
  • Grey Box - When you blend white and black, you get grey. This form of Pen Testing is a hybrid of the two above. Testers start with limited knowledge of the IT systems and then use the usual techniques to try to discover more and gain access. This is often the closest to the real world scenario as most organisations have some publicly available information that attackers can use.

Red Teaming

Most modern and comprehensive Pen Tests use a form of Red Teaming. A Red Team is comprised of a group of testers with different skills, and as a group they probe and test all aspects of an organisations network and application security. It uses the various types of Pen Test, covering all the attack points listed in this article, as well as the social engineering and physical security of an organisation. This includes trying to get access to offices and data centres if the organisation has them and compromising data that way. An example is seeing unlocked PC screens on desks, or confidential papers sitting on desks if they get physical access to an office.

Conclusion

Pen Testing has evolved way beyond the external network infrastructure tests of the past. It is a vital part of the whole application and business system security solution. However, the goal of Pen Testing should be to increase the security of the systems and not just be a box ticking exercise for internal or external regulatory purposes. Doing that leads to complacency that protection is adequate.

Pen Testing requires experts who both know the current threat landscape, and who are dispassionate about the system your organisation has in place. Outpost 24 provide both this expertise and the impartial advice that IT professionals need, albeit helpfully and constructively.

[1] Payment Card Industry Data Security Standard https://www.pcisecuritystandards.org

[2] EU GPDR Information https://ec.europa.eu/info/law/law-topic/data-protection_en