Careers  |  Legal  |  Search  | 

VA | Penetration Testing

Penetration testing is a starting point for confirming that network attacks are occurring, being prevented or that network security needs improvements. In a penetration test, our network security professionals attempt unauthorized access to your systems and outline how intruders could capture and/or corrupt data or disrupt network availability. We then recommend potential solutions to remedy identified risks. This process generates a substantial amount of information that we can use to help develop a more comprehensive risk assessment. 

 

By developing a comprehensive picture of your organization's network security status, our Risk Management professional has the foundation for recommending network security solutions that meet your business needs. Our assessments focus on understanding how your network technology is used to enable your business strategy and the risks can be addressed through effective network security. We then work with you to conduct an inventory of network-centric components and prioritize these based on the defined business risks. Our professionals then perform comprehensive assessments of the security policies, configuration, deployment and monitoring processes for selected components. 

Depending on your business risks, effective network security may require 24-hour oversight of inappropriate or suspicious activity and intrusions throughout the enterprise network. This level of monitoring may prevent potential security breaches or intercept them before they wreck havoc in your organization. Pre-defined responses to threats, according to your unique business risk strategy and documentation, creates an audit trail for effective prosecution and regulatory compliance. 

Some of the tools we use to assist us include: 

NESSUS Scanner - a comprehensive network vulnerability assessment tool.  Nessus is used to probe systems and report vulnerabilities that might create an exposure. 

AppDetective - a  comprehensive database-specific tool for identifying database vulnerabilities and for monitoring database security. 

MegaPing - a commercial tool that provides network information. 

TonLoc | SandStorm - a tool for assessing phone number networks. 


WebInspect - an automated scanning tool that provides a comprehensive assessment of web service vulnerabilities.  In addition to assessing internally developed applications this tool incorporates "Threat Agents" for several commercial application platforms. 

AirMagnet - a commercial wireless network analyzer and security tool. 

Ethereal - a network sniffer and protocol analyzer. 

 

For a list of additional tools click here

If you would like to obtain more information regarding our  Vulnerability Assessment or Penetration Testing services please contact us.

   Print   |   Email