Skip to main content
M. Veeraragaloo
February 2018
Outline
1. Design and validate assessment and test strategies
2. Conduct security control testing
a. Vulnerability assessment
b. Penetration testing
c. Log reviews
d. Synthetic transactions
e. Code review and testing (e.g., manual, dynamic, static,
fuzz)
f. Misuse case testing
g. Test coverage analysis
h. Interface testing (e.g., API, UI, physical)
Outline
3. Collect security process data (e.g., management and
operational controls)
a. Account management (e.g., escalation, revocation)
b. Management review
c. Key performance and risk indicators
d. Backup verification data
e. Training and awareness
f. Disaster recovery and business continuity
4. Analyze and report test outputs (e.g., automated,
manual)
5. Conduct or facilitate internal and third party audits
Design and Validate Assessment and Test Strategies
Building a Security Assessment and Testing Program
1. The cornerstone maintenance activity for an information
security team is their security assessment and testing
program.
2. This program includes tests, assessments, and audits that
regularly verify that an organization has adequate
security controls and that those security controls are
functioning properly and effectively safeguarding
information assets.
3. Three major components of a security assessment
program:
1. Security tests
2. Security assessments
3. Security audits
Design and Validate Assessment and Test Strategies
Building a Security Assessment and Testing Program
1. Security Testing
a. Security tests verify that a control is functioning properly.
b. These tests include automated scans, tool-assisted
penetration tests and manual attempts to undermine
security.
c. Security testing should take place on a regular schedule,
with attention paid to each of the key security controls
protecting an organization.
d. When scheduling security controls for review, information
security managers should consider the following factors:
i. Availability of security testing resources
ii. Criticality of the systems and applications protected by the tested
controls
Design and Validate Assessment and Test Strategies
Building a Security Assessment and Testing Program
1. Security Testing
i. Availability of security testing resources
ii. Criticality of the systems and applications protected by the tested controls
iii. Sensitivity of information contained on tested systems and applications
iv. Likelihood of a technical failure of the mechanism implementing the control
v. Likelihood of a mis-configuration of the control that would jeopardize security
vi. Risk that the system will come under attack
vii. Rate of change of the control configuration
viii. Other changes in the technical environment that may affect the control
performance
ix. Difficulty and time required to perform a control test
x. Impact of the test on normal business operations
e. After assessing each of these factors, security teams design and validate a
comprehensive assessment and testing strategy.
f. This strategy may include frequent automated tests supplemented by
infrequent manual tests
Design and Validate Assessment and Test Strategies
Building a Security Assessment and Testing Program
2. Security Assessment
a. Security assessments are comprehensive reviews of the security of a
system, application, or other tested environment.
b. During a security assessment, a trained information security professional
performs a risk assessment that identifies vulnerabilities in the tested
environment that may allow a compromise and makes recommendations
for remediation, as needed.
c. Security assessments normally include the use of security testing tools
but go beyond automated scanning and manual penetration tests.
d. They also include a thoughtful review of the threat environment, current
and future risks, and the value of the targeted environment.
e. The main work product of a security assessment is normally an
assessment report addressed to management that contains the results of
the assessment in nontechnical language and concludes with specific
recommendations for improving the security of the tested environment.
Design and Validate Assessment and Test Strategies
Building a Security Assessment and Testing Program
3. Security Audits
a. Security audits use many of the same techniques followed during
security assessments but must be performed by independent auditors.
b. Audits, on the other hand, are evaluations performed with the purpose
of demonstrating the effectiveness of controls to a third party.
c. The staff who design, implement, and monitor controls for an
organization have an inherent conflict of interest when evaluating the
effectiveness of those controls.
d. There are two main types of audits: internal audits and external audits.
e. Internal audits are performed by an organization’s internal audit staff
and are typically intended for internal audiences. The internal audit staff
performing these audits normally have a reporting line that is completely
independent of the functions they evaluate.
f. External audits are performed by an outside auditing firm. These audits
have a high degree of external validity because the auditors performing
the assessment theoretically have no conflict of interest with the
organization itself.
Conduct Security Control Testing
Performing Vulnerability Assessments
1. Vulnerability Scans
a. Vulnerability scans automatically probe systems, applications, and
networks, looking for weaknesses that may be exploited by an attacker.
b. The scanning tools used in these tests provide quick, point-and-click
tests that perform otherwise tedious tasks without requiring manual
intervention.
c. Most tools allow scheduled scanning on a recurring basis and provide
reports that show differences between scans performed on different days,
offering administrators a view into changes in their security risk
environment.
d. There are three main categories of vulnerability scans:
i. Network Discovery scans,
ii. Network Vulnerability Scans, and
iii. Web Application Vulnerability Scan.
Conduct Security Control Testing
Performing Vulnerability Assessments
1. Vulnerability Scans
a. Network Discovery Scanning
i. TCP SYN Scanning
1. Sends a single packet to each scanned port with the SYN flag set. This indicates a
request to open a new connection.
2. If the scanner receives a response that has the SYN and ACK flags set, this indicates
that the system is moving to the second phase in the three-way TCP handshake and
that the port is open. TCP SYN scanning is also known as “half-open” scanning.
ii. TCP Connect Scanning
1. Opens a full connection to the remote system on the specified port.
2. This scan type is used when the user running the scan does not have the
necessary permissions to run a half-open scan.
iii. TCP ACK Scanning
1. Sends a packet with the ACK flag set, indicating that it is part of an open connection.
iv. Xmas Scanning
1. Sends a packet with the FIN, PSH, and URG flags set.
2. A packet with so many flags set is said to be “lit up like a Christmas tree,” leading to the
scan’s name.
Conduct Security Control Testing
Performing Vulnerability Assessments
1. Vulnerability Scans
b. Network Vulnerability Scanning
i. Network vulnerability scans go deeper than discovery scans. They don’t stop
with detecting open ports but continue on to probe a targeted system or
network for the presence of known vulnerabilities.
ii. These tools contain databases of thousands of known vulnerabilities, along
with tests they can perform to identify whether a system is susceptible to each
vulnerability in the system’s database.
iii. By default, network vulnerability scanners run unauthenticated scans.
iv. They test the target systems without having passwords or other special
information that would grant the scanner special privileges.
v. This allows the scan to run from the perspective of an attacker but also limits
the ability of the scanner to fully evaluate possible vulnerabilities.
vi. One way to improve the accuracy of the scanning and reduce false positive and
false negative reports is to perform authenticated scans of systems.
Conduct Security Control Testing
Performing Vulnerability Assessments
1. Vulnerability Scans
c. Web Vulnerability Scanning
i. Web vulnerability scanners are special-purpose tools that scour web
applications for known vulnerabilities.
ii. Web vulnerability scans are an important component of an organization’s
security assessment and testing program. It’s a good practice to run scans in
the following circumstances:
1. Scan all applications when you begin performing web vulnerability
scanning for the first time. This will detect issues with legacy applications.
2. Scan any new application before moving it into a production environment
for the first time.
3. Scan any modified application before the code changes move into
production.
4. Scan all applications on a recurring basis. Limited resources may require
scheduling these scans based on the priority of the application. For
example, you may wish to scan web applications that interact with sensitive
information more often than those that do not.
Conduct Security Control Testing
Performing Vulnerability Assessments
2. Penetration Testing
a. The penetration test goes beyond vulnerability testing techniques because
it actually attempts to exploit systems.
b. Vulnerability scans merely probe for the presence of a vulnerability and do
not normally take offensive action against the targeted system.
c. When performing a penetration test, the security professional typically
targets a single system or set of systems and uses many different
techniques to gain access. The process may include the following:
i. Performing basic reconnaissance to determine system function (such as visiting websites
hosted on the system)
ii. Network discovery scans to identify open ports
iii. Network vulnerability scans to identify un-patched vulnerabilities
iv. Web application vulnerability scans to identify web application flaws
v. Use of exploit tools to automatically attempt to defeat the system security
vi. Manual probing and attack attempts
Conduct Security Control Testing
Performing Vulnerability Assessments
2. Penetration Testing
a. The tests are normally categorized into three groups:
i. White Box Penetration
1. Test Provides the attackers with detailed information about the systems they
target.
2. This bypasses many of the reconnaissance steps that normally precede attacks,
shortening the time of the attack and increasing the likelihood that it will find
security flaws.
ii. Gray Box Penetration
1. Test also known as partial knowledge tests, these are sometimes chosen to
balance the advantages and disadvantages of white and black box penetration
tests.
2. This is particularly common when black box results are desired but costs or
time constraints mean that some knowledge is needed to complete the testing.
iii. Black Box Penetration
1. Test Does not provide attackers with any information prior to the attack.
2. This simulates an external attacker trying to gain access to information about
the business and technical environment before engaging in an attack.
Conduct Security Control Testing
Testing Your Software
Software is a critical component in system security.
Characteristics common to many applications in use throughout the modern
enterprise:
1. Software applications often have privileged access to the operating
system, hardware, and other resources.
2. Software applications routinely handle sensitive information,
including credit card numbers, Social Security Numbers, and
proprietary business information.
3. Many software applications rely on databases that also contain
sensitive information.
4. Software is the heart of the modern enterprise and performs
business-critical functions.
5. Software failures can disrupt businesses with very serious
consequences.
Conduct Security Control Testing
Testing Your Software
Software is a critical component in system security.
Characteristics common to many applications in use throughout the modern
enterprise:
1. Code Review and Testing
i. Code reviews and tests may discover security, performance, or reliability flaws in
applications before they go live and negatively impact business operations.
a. Code Review
i. Code review takes many different forms and varies in formality from organization to
organization.
ii. The most formal code review processes, known as Fagan inspections, follow a
rigorous review and testing process with six steps:
1. Planning
2. Overview
3. Preparation
4. Inspection
5. Rework
6. Follow-up
Conduct Security Control Testing
Testing Your Software
1. Code Review and Testing
a. Code Review
Conduct Security Control Testing
Testing Your Software
1. Code Review and Testing
a. Code Review
i. The Fagan inspection level of formality is normally found only in highly restrictive
environments where code flaws may have catastrophic impact.
ii. Most organizations use less rigorous processes using code peer review measures that
include the following:
1. Developers walking through their code in a meeting with one or more other team
members
2. A senior developer performing manual code review and signing off on all code before
moving to production
3. Use of automated review tools to detect common application flaws before moving to
production
iii. Each organization should adopt a code review process that suits its business
requirements and software development culture.
Conduct Security Control Testing
Testing Your Software
1. Code Review and Testing
b. Static Testing
i. Static testing evaluates the security of software without running
i g t by analyzing either the source code or the compiled
application.
ii. Static analysis usually involves the use of automated tools
designed to detect common software flaws, such as buffer
overflows.
iii. In mature development environments, application developers
are given access to static analysis tools and use them
throughout the design, build, and test process.
Conduct Security Control Testing
Testing Your Software
1. Code Review and Testing
b. Static Testing
i. Static testing evaluates the security of software without running
i g t by analyzing either the source code or the compiled
application.
ii. Static analysis usually involves the use of automated tools
designed to detect common software flaws, such as buffer
overflows.
iii. In mature development environments, application developers
are given access to static analysis tools and use them
throughout the design, build, and test process.
Conduct Security Control Testing
Testing Your Software
1. Code Review and Testing
c. Dynamic Testing
i. Dynamic testing evaluates the security of software in a runtime
environment and is often the only option for organizations deploying
applications written by someone else.
ii. In those cases, testers often do not have access to the underlying
source code.
iii. Dynamic testing may include the use of synthetic transactions to
verify system performance.
iv. These are scripted transactions with known expected results.
v. The testers run the synthetic transactions against the tested code and
then compare the output of the transactions to the expected state.
vi. Any deviations between the actual and expected results represent
possible flaws in the code and must be further investigated.
Conduct Security Control Testing
Testing Your Software
1. Code Review and Testing
c. Fuzz Testing
i. Fuzz testing is a specialized dynamic testing technique that provides many different
types of input to software to stress its limits and find previously undetected flaws.
ii. Fuzz testing software supplies invalid input to the software, either randomly
generated or specially crafted to trigger known software vulnerabilities.
iii. The fuzz tester then monitors the performance of the application, watching for
software crashes, buffer overflows, or other undesirable and/or unpredictable
outcomes. There are two main categories of fuzz testing:
1. Mutation (Dumb) Fuzzing
a. Takes previous input values from actual operation of the software and manipulates
(or mutates) it to create fuzzed input. It might alter the characters of the content,
append strings to the end of the content, or perform other data manipulation
techniques.
2. Generational (Intelligent) Fuzzing
a. Develops data models and creates new fuzzed input based on an understanding of
the types of data used by the program.
Conduct Security Control Testing
Testing Your Software
2. Interface Testing
a. Interface testing is an important part of the development of complex
software systems.
b. In many cases, multiple teams of developers work on different parts of a
complex application that must function together to meet business
objectives.
c. The handoffs between these separately developed modules use well-
defined interfaces so that the teams may work independently.
d. Interface testing assesses the performance of modules against the
interface specifications to ensure that they will work together properly
when all of the development efforts are complete.
e. Three types of interfaces should be tested during the software testing
process:
Conduct Security Control Testing
Testing Your Software
2. Interface Testing
a. Application Programming Interfaces (APIs)
i. Offer a standardized way for code modules to interact and may be
exposed to the outside world through web services. Developers must
test APIs to ensure that they enforce all security requirements.
b. User Interfaces (UIs)
i. Examples include graphic user interfaces (GUIs) and command-line
interfaces. UIs provide end users with the ability to interact with the
software. Interface tests should include reviews of all user interfaces to
verify that they function properly.
c. Physical Interfaces
i. Exist in some applications that manipulate machinery, logic
controllers, or other objects in the physical world. Software testers
should pay careful attention to physical interfaces because of the
potential consequences if they fail.
Conduct Security Control Testing
Testing Your Software
3. Misuse Case Testing
a. In some applications, there are clear examples of ways that
software users might attempt to misuse the application.
b. For example, users of banking software might try to manipulate
input strings to gain access to another user’s account.
c. They might also try to withdraw funds from an account that is
already overdrawn.
d. Software testers use a process known as misuse case testing or
abuse case testing to evaluate the vulnerability of their software to
these known risks.
e. In misuse case testing, testers first enumerate the known misuse
cases.
f. They then attempt to exploit those use cases with manual and/or
automated attack techniques.
Conduct Security Control Testing
Testing Your Software
4. Test Coverage Analysis
a. While testing is an important part of any software development process,
it is unfortunately impossible to completely test any piece of software.
b. There are simply too many ways that software might malfunction or
undergo attack.
c. Software testing professionals often conduct a test coverage analysis to
estimate the degree of testing conducted against the new software. The
test coverage is computed using the following formula:
d. Accurately computing test coverage requires enumerating the possible
use cases, which is an exceptionally difficult task.
e. Therefore, anyone using test coverage calculations should take care to
understand the process used to develop the input values when
interpreting the results.
Collect Security Process Data
Implementing Security Management Processes
1. These processes are a critical feedback loop in the
security assessment process because they provide
management oversight and have a deterrent effect
against the threat of insider attacks.
2. The security management reviews are:
a. Log Reviews
b. Account Management
c. Backup Verification
d. Key Performance
e. Risk Indicators
Collect Security Process Data
Implementing Security Management Processes
1. Log Reviews
a. Security incident and event management (SIEM) packages
play an important role in these processes, automating much
of the routine work of log review.
b. Information security managers should also periodically
conduct log reviews, particularly for sensitive functions, to
ensure that privileged users are not abusing their privileges.
c. If an information security team has access to eDiscovery
tools that allow searching through the contents of
individual user files, security managers should routinely
review the logs of actions taken by those administrative
users to ensure that their file access relates to legitimate
eDiscovery initiatives and does not violate user privacy.
Collect Security Process Data
Implementing Security Management Processes
2. Account Management
a. Account management reviews ensure that users only retain
authorized permissions and that unauthorized modifications do not
occur.
b. Account management reviews may be a function of information
security management personnel or internal auditors.
c. One way to perform account management is to conduct a full review
of all accounts.
d. This is typically done only for highly privileged accounts because of
the amount of time consumed.
e. The exact process may vary from organization to organization, but
here’s one example:
i. Managers ask system administrators to provide a list of users with privileged
access and the privileged access rights. They may monitor the administrator as
they retrieve this list to avoid tampering.
ii. Managers ask the privilege approval authority to provide a list of authorized
users and the privileges they should be assigned.
iii. The managers then compare the two lists to ensure that only authorized users
retain access to the system and that the access of each user does not exceed
their authorization.
Collect Security Process Data
Implementing Security Management Processes
3. Backup Verification
a. Managers should periodically inspect the results of
backups to ensure that the process functions
effectively and meets the organization’s data
protection needs.
b. This may involve reviewing logs, inspecting hash
values, or requesting an actual restore of a system or
file.
Collect Security Process Data
Implementing Security Management Processes
4. Key Performance and Risk Indicators
a. Security managers should also monitor key performance
and risk indicators on an ongoing basis. The exact metrics
they monitor will vary from organization to organization
but may include the following:
i. Number of open vulnerabilities
ii. Time to resolve vulnerabilities
iii. Number of compromised accounts
iv. Number of software flaws detected in preproduction scanning
v. Repeat audit findings
vi. User attempts to visit known malicious sites
b. Once an organization identifies the key security metrics it
wishes to track, managers may want to develop a dashboard
that clearly displays the values of these metrics over time
and display it where both managers and the security team
will regularly see it.
Analyze and Report Test Outputs
Conduct or Facilitate Internal and Third Party Audits
References
1. CISSP Study Guide – 7th Edition