Skip to main content

Security Testing


Security testing is a process of testing any software authenticity that is it is done to check whether any software is secured from any unauthorized attack or not.
Precise testing solutions contains certified security software tester. We follow all rules provided by standard organization like Open Web Application security Project (OWASP) and Web Application Security Consortium (WASC).

Software Security Testing:

Software security testing deals with protection of data by Information System (IS) and maintains its function as deliberated. The six basic security concepts that need to be covered by security testing are:
Confidentiality, integrity, authenticity, authorization, availability and  non-repudiation.

Terms That Are Common in Security Testing

Vulnerability Scan:

This helps in determining known security issues using automated tools in order to match with known vulnerabilities. Tool automatically set risk level without manual interference by test vendor.

Vulnerability Assessment:

In order to identify security vulnerabilities, it uses vulnerabilities scanning and places the vulnerabilities according to their level under the test.

Security Assessment:  

It builds upon vulnerability assessment by adding manual verification to conform exposure but does not include exploitation of vulnerabilities to gain further access. This verification could be by making an authorized access to the system to confirm system settings and have an eye on logs, system responses, error messages codes etc. A security assessment looks in to the large area of the system under test but not the depth exposure as specific vulnerability does.

Penetration test:

This test is done by replicate a malicious party attack. This provides information about ability of an attacker to gain access to confidential information. This approach deals in attack detail in larger sense as compared to Security Assessment.

Vulnerability/Risk Management:

For planning and conducting Security Testing, this is the first step to be taken. This process identifies vulnerabilities inside the system or application. Vulnerability analysis helps in forecasting effectiveness of proposed countermeasures after they are put into use.
Security testing is important in today’s world which cannot be ignored by one .The various new tools are being invented day by day, one has to be careful in choosing them based on application or system nature.

TOOLS FOR SECURITY TESTING
1. Babel Enterprise.
2. BFB Tester - Brute Force Binary Tester
3. Brakeman
4. Cross
5. Flawfinder
6. Gendarme
7. HCE.
8. HCE - HTML Comment Extractor / Parser.
9. Knock Subdomain Scan.
10. Metasploit.
11. Nessus.
12. Nikto.
13. Nsiqcppstyle.
14. Oedipus.
15. OSSTMM - Open Source Security Testing Methodology     Manual.

Comments

Popular posts from this blog

In Regression Testing: Difference between Automation And Manual Testing

The difference between an Automation Testing & Manual-Testing is a pillar of the Software testing, because the whole-testing is based on the Automation Testing and Manual Testing. In the project you can do both Automation Testing & Manual Testing & you can also do both Automation testing and Manual Testing simultaneously. Difference between Automation and Manual Testing Automation Testing Manual Testing The automation testing is a continuous component of the manual testing. This testing is an initiate of the testing, without of this testing we cannot start the automation testing. This takes less of time. This takes a lot of time. In the automation testing, we always test by the running the scripts. In the manual testing testers’re allowed to do the random for find the Bugs. In automation testing, it is done on the different on same time. The manual testing would be executes sequentially. ...

Want to know about Mobile Application Testing? Came to right place

What is Mobile Application Testing ? Mobile Application Testing is a phenomenon of testing functionality, usability and consistency of application software designed for mobiles. It is done in two ways: Automated and Manually. When you buy a new mobile, various applications came pre-installed and some you install as per your need from mobile software distribution platforms such as Google Play, Nokia Store etc. In the recent years, mobile devices had shown a rapid growth rate .  Factors that give an open challenge to Mobile application Testing : 1. Mobile devices models : Different models have different hardware configurations, input methods (some are QWERTY, some are touch while others are normal). 2. Several different operating systems (OS) : Market  is full of availability of different operating  systems  (   Android , IOS, BREW, BREWMP, Symbian,   Windows Phone , and   BlackBerry   (RIM)).Each operating system is unique in ...

INTRODUCTION TO SELENIUM TESTING

If you are interesting in software testing and desperately want to work in software testing profile then this post is surely for you, as we know that selenium testing is an important aspect of  software testing so you should go through this at least once. WHAT IS SELENIUM TESTING? SELENIUM is a tool for authoring tests without learning test scripting language like selenium IDE. Selenium is not just a tool but actually it is a cluster of independent tools. And selenium testing is a testing which is performed by using selenium tool. WHY WE USE SELENIUM TESTING I f we talk about the functioning and scenario of today's IT industries or companies then it is known to everyone that there is a mass movement towards automation testing. Not only this but the cluster of manual testing scenario  has also raised a great demand to make to manual testing automated by using various tools such as selenium.  There are numerous benefits which a software tester gets if he/she impleme...