IL276308A

Selectively choosing between actual-attack and simulation/evaluation for validating a vulnerability of a network node during execution of a penetration testing campaign

Abstract

This record has no abstract on file.

IL276308A, drawing sheet 1
Sheet 1 of 32

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

28 claims: 17 independent, 11 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A method for penetration testing of a networked system by a penetration testing system using both active and passive validation methods during a single penetration testing campaign, the method for penetration testing comprising: a. determining a first target network node of the networked system to be the next network node to attempt to compromise during the single penetration testing campaign;b. determining a first vulnerability of network nodes to be used for compromising the first target network node;c. selecting a first validation method for validating the first vulnerability for the first target network node, a type of the first validation method being selected from the type group consisting of active validation and passive validation;d. validating the first vulnerability for the first target network node using the first validation method;e. determining a second target network node of the networked system to be the next network node to attempt to compromise during the single penetration testing campaign;f. determining a second vulnerability of network nodes to be used for compromising the second target network node;g. selecting a second validation method for validating the second vulnerability for the second target network node, a type of the second validation method being selected from the type group consisting of active validation and passive validation and being different from the type of the first validation method;h. validating the second vulnerability for the second target network node using the second validation method;and i. reporting at least one security vulnerability of the networked system determined to exist based on results of the executing of the single penetration testing campaign, wherein the reporting comprises performing at least one operation selected from the group consisting of: (A) causing a display device to display a report containing information about the at least one security vulnerability of the networked system, (B) storing the report containing information about the at least one security vulnerability of the networked system in a file and (C) electronically transmitting the report containing information about the at least one security vulnerability of the networked system, wherein all of steps a-i are performed by the penetration testing system, and all of steps a-h are performed during the single penetration testing campaign.
  2. 3
    The method of any one of claims 1-2 wherein:i. the selecting of the first validation method comprises: A. determining a first damage to the first target network node that can be caused by validating the first vulnerability for the first target network node by using active validation;and B. selecting the type of the first validation method to be a type of a validation method that is associated with the first damage;and ii. the selecting of the second validation method comprises: A. determining a second damage to the second target network node that can be caused by validating the second vulnerability for the second target network node by using active validation;and B. selecting the type of the second validation method to be a type of a validation method that is associated with the second damage.
  3. 5
    The method of any of claims 3-4, wherein the determining of the first damage includes determining a likelihood of the first damage occurring.
  4. 6
    The method of any one of claims 1 -2, wherein the selecting of the type of the first and second validation methods are performed such that the identity of the first vulnerability uniquely determines the type of the first validation method, and the identity of the second vulnerability uniquely determines the type of the second validation method.
  5. 7
    The method of any of claims 1-6, wherein steps a-i are performed in the order listed.
  6. 8
    The method of any of claims 1-2, wherein the penetration testing system is controlled by a user interface of a computing device, and the method for penetration testing of the networked system further comprises:j. receiving, by the penetration testing system and via the user interface of the computing device, one or more manually-entered inputs, the one or more manually-entered inputs explicitly defining at least one item selected from the group consisting of (i) a type of a validation method to be used for validating the first vulnerability, and (ii) a type of a validation method to be used for validating the second vulnerability.
  7. 9
    A penetration testing system for executing penetration testing of a networked system using both active and passive validation methods during a single penetration testing campaign, the penetration testing system comprising:a. a remote computing device comprising a computer memory and one or more processors, the remote computing device in networked communication with multiple network nodes of the networked system;b. a non-transitory computer-readable storage medium containing program instructions, wherein execution of the program instructions by the one or more processors of the remote computing device performs all of the following during the single penetration testing campaign: i. determine a first target network node of the networked system to be the next network node to attempt to compromise during the single penetration testing campaign;ii. determine a first vulnerability of network nodes to be used for compromising the first target network node;iii. select a first validation method for validating the first vulnerability for the first target network node, a type of the first validation method being selected from the type group consisting of active validation and passive validation;iv. cause a validation of the first vulnerability for the first target network node using the first validation method;v. determine a second target network node of the networked system to be the next network node to attempt to compromise during the single penetration testing campaign;vi. determine a second vulnerability of network nodes to be used for compromising the second target network node;vii. select a second validation method for validating the second vulnerability for the second target network node, a type of the second validation method being selected from the type group consisting of active validation and passive validation and being different from the type of the first validation method;and viii. cause a validation of the second vulnerability for the second target network node using the second validation method;wherein the execution of the program instructions by the one or more processors of the remote computing device further performs: report at least one security vulnerability of the networked system determined to exist based on results of executing the single penetration testing campaign, wherein the reporting comprises performing at least one operation selected from the group consisting of: (A) causing a display device to display a report containing information about the at least one security vulnerability of the networked system, (B) storing the report containing information about the at least one security vulnerability of the networked system in a file and (C) electronically transmitting the report containing information about the at least one security vulnerability of the networked system.
  8. 10
    A method for penetration testing of a networked system by a penetration testing system using both active and passive validation methods, the method for penetration testing comprising:a. determining a first target network node of the networked system to be the next network node to attempt to compromise;b. determining a first vulnerability of network nodes to be used for compromising the first target network node;c. determining a first damage to the first target network node that can be caused by validating the first vulnerability for the first target network node by using active validation;d. selecting a first validation method for validating the first vulnerability for the first target network node, a type of the first validation method being: A. selected from the type group consisting of active validation and passive validation;and B. associated with the first damage;e. validating the first vulnerability for the first target network node using the first validation method;f. determining a second target network node of the networked system to be the next network node to attempt to compromise;g. determining a second vulnerability of network nodes to be used for compromising the second target network node;h. determining a second damage to the second target network node that can be caused by validating the second vulnerability for the second target network node by using active validation;i. selecting a second validation method for validating the second vulnerability for the second target network node, a type of the second validation method being: A. selected from the type group consisting of active validation and passive validation;B. associated with the second damage;and C. different from the type of the first validation method;j. validating the second vulnerability for the second target network node using the second validation method;and k. reporting at least one security vulnerability of the networked system determined to exist based on results of performing steps a-j , wherein the reporting comprises performing at least one operation selected from the group consisting of: (A) causing a display device to display a report containing information about the at least one security vulnerability of the networked system, (B) storing the report containing information about the at least one security vulnerability of the networked system in a file and (C) electronically transmitting the report containing information about the at least one security vulnerability of the networked system, wherein all of steps a-k are performed by the penetration testing system.
  9. 12
    The method of any of claims 10-11, wherein the determining of the first damage includes determining an extent of the first damage.
  10. 13
    The method of any of claims 10-11, wherein the determining of the first damage includes determining a likelihood of the first damage occurring.
  11. 14
    The method of any of claims 10-13, wherein steps a-k are performed in the order listed.
  12. 15
    The method of any of claims 10-14, wherein the penetration testing system is controlled by a user interface of a computing device, and the method for penetration testing of the networked system further comprises:j. receiving, by the penetration testing system and via the user interface of the computing device, one or more manually-entered inputs, the one or more manually-entered inputs explicitly defining at least one item selected from the group consisting of (i) a type of a validation method associated with the first damage, and (ii) a type of a validation method associated with the second damage.
  13. 16
    A penetration testing system for executing penetration testing of a networked system using both active and passive validation methods, the penetration testing system comprising:a. a remote computing device comprising a computer memory and one or more processors, the remote computing device in networked communication with multiple network nodes of the networked system;b. a non-transitory computer-readable storage medium containing program instructions, wherein execution of the program instructions by the one or more processors of the remote computing device performs all of the following: i. determine a first target network node of the networked system to be the next network node to attempt to compromise;ii. determine a first vulnerability of network nodes to be used for compromising the first target network node;iii. determine a first damage to the first target network node that can be caused by validating the first vulnerability for the first target network node by using active validation;iv. select a first validation method for validating the first vulnerability for the first target network node, a type of the first validation method being: A. selected from the type group consisting of active validation and passive validation;and B. associated with the first damage;v. cause a validation of the first vulnerability for the first target network node using the first validation method;vi. determine a second target network node of the networked system to be the next network node to attempt to compromise;vii. determine a second vulnerability of network nodes to be used for compromising the second target network node;viii. determine a second damage to the second target network node that can be caused by validating the second vulnerability for the second target network node by using active validation;ix. select a second validation method for validating the second vulnerability for the second target network node, a type of the second validation method being: A. selected from the type group consisting of active validation and passive validation;B. associated with the second damage;and C. different from the type of the first validation method;x. cause a validation of the second vulnerability for the second target network node using the second validation method;and xi. report at least one security vulnerability of the networked system determined to exist based on results of performing operations b(i)-b(x), wherein the reporting comprises performing at least one operation selected from the group consisting of: (A) causing a display device to display a report containing information about the at least one security vulnerability of the networked system, (B) storing the report containing information about the at least one security vulnerability of the networked system in a file and (C) electronically transmitting the report containing information about the at least one security vulnerability of the networked system.
  14. 17
    A method for subjecting a single networked system to first and second penetration testing campaigns such that (i) both penetration testing campaigns are performed by a single penetration testing system; (ii) the first penetration testing campaign employs only active validation for validating vulnerabilities of network nodes of the single networked system; and (iii) the second penetration testing campaign employs only passive validation for validating vulnerabilities of network nodes of the single networked system, the method comprising:a. executing the first penetration testing campaign by the single penetration testing system, the executing of the first penetration testing campaign comprising performing one or more validation operations for validating vulnerabilities for network nodes of the single networked system, wherein the methods of validation used for all validation operations included in the first penetration testing campaign are active validation methods;b. executing the second penetration testing campaign by the single penetration testing system, the executing of the second penetration testing campaign comprising performing one or more validation operations for validating vulnerabilities for network nodes of the single networked system, wherein the methods of validation used for all validation operations included in the second penetration testing campaign are passive validation methods, and c. reporting, by the single penetration testing system, at least one security vulnerability of the single networked system determined to exist based on at least one member selected from the group consisting of (1) results of the executing of the first penetration testing campaign, and (2) results of the executing of the second penetration testing campaign, wherein the reporting comprises performing at least one operation selected from the group consisting of (i) causing a display device to display a report containing information about the at least one security vulnerability of the single networked system, (ii) storing the report containing information about the at least one security vulnerability of the single networked system in a file, and (iii) electronically transmitting the report containing information about the at least one security vulnerability of the single networked system.
  15. 22
    The method of any of claims 17-21, wherein the first penetration testing campaign is based on a first scenario template, the second penetration testing campaign is based on a second scenario template, and the second scenario template is different from the first scenario template.
  16. 26
    The method of any of claims 17-21 wherein the first penetration testing campaign and the second penetration testing campaign are both based on a common scenario template.
  17. 28
    A penetration testing system for subjecting a networked system to first and second penetration testing campaigns such that (i) both penetration testing campaigns are performed by the penetration testing system; (ii) the first penetration testing campaign employs only active validation for validating vulnerabilities of network nodes of the networked system; and (iii) the second penetration testing campaign employs only passive validation for validating vulnerabilities of network nodes of the networked system, the penetration testing system comprising:a. a remote computing device comprising a computer memory and one or more processors, the remote computing device in networked communication with multiple network nodes of the networked system;b. a non-transitory computer-readable storage medium containing program instructions, wherein execution of the program instructions by the one or more processors of the remote computing device performs all of the following during the first and second penetration testing campaigns: i. execute the first penetration testing campaign by the remote computing device , the executing of the first penetration testing campaign comprising causing one or more validation operations for validating vulnerabilities for network nodes of the networked system, wherein the methods of validation used for all validation operations included in the first penetration testing campaign are active validation methods;and ii. execute the second penetration testing campaign by the remote computing device, the executing of the second penetration testing campaign comprising causing one or more validation operations for validating vulnerabilities for network nodes of the networked system, wherein the methods of validation used for all validation operations included in the second penetration testing campaign are passive validation methods;wherein the execution of the program instructions by the one or more processors of the remote computing device further performs: report at least one security vulnerability of the networked system determined to exist based on at least one member selected from the group consisting of (1) results of the executing of the first penetration testing campaign, and (2) results of the executing of the second penetration testing campaign, wherein the reporting comprises performing at least one operation selected from the group consisting 5 of (i) causing a display device to display a report containing information about the at least one security vulnerability of the networked system, (ii) storing the report containing information about the at least one security vulnerability of the networked system in a file, and (iii) electronically transmitting the report containing information about the at least one security vulnerability of the 10 networked system.