Penetration testing as a means of increasing the level of information systems cyber protection
DOI:
https://doi.org/10.34121/1028-9763-2025-2-24-29Keywords:
cybersecurity, information systems, penetration testing, types, variations, artificial intelligenceAbstract
Penetration testing is one of the primary methods for assessing the cybersecurity level of information systems and a means of improving it. The security evaluation of a system or network is conducted by partially simulating the actions of external attackers attempting to infiltrate it, as well as internal malicious actors. This process is based on an active analysis of the system to identify any potential vulnerabilities that may arise due to improper system configuration, known and unknown hardware and software defects, or delays in procedural or technical countermeasures. Such analysis is conducted from the perspective of a potential attacker and must include the active exploitation of system vulnerabilities, at least during the portion of testing performed by an expert. Typically, a penetration test reveals a certain set of vulnerabilities within the tested system. The gathered information is compiled into a standardized report presented to the system owner. A crucial part of this report is the analysis, which combines this information with a detailed assessment of the potential impact on the organization and outlines the scope of technical and procedural countermeasures to mitigate risks. The primary advantage of penetration testing is the early identification of risks, since it helps to detect weaknesses before they can be exploited by malicious actors. Additionally, regular testing enables organizations to enhance their reputation by demonstrating responsibility in cybersecurity and cyber defense. Overall, penetration testing is becoming increasingly mandatory across various regions and industries, as it helps organizations comply with standards such as ISO 27001, SOC 2, PCI DSS, and others. Today, the development of penetration testing aligns with trends toward further automation, the use of cloud-based tools, artificial intelligence in vulnerability analysis, and the growing role of tests incorporating social engineering techniques. Penetration testing will continue to expand and develop both methodologically and instrumentally.
References
1. Рenetration Testing History. Retrieved. URL: https://christianespinosa.com/blog/penetration-testinghistory/ (дата звернення: 12.12.2024).
2. Вacudio A., Yuan X., Chu B., Jones M. An Overview of Penetration Testing. International Journal of Network Security & Its Applications. 2011. Vol. 3. P. 19–38. DOI: https://doi.org/10.5121/ijnsa.2011.3602 (дата звернення: 16.12.2024).
3. Тести на проникнення. Retrieved on 12.12.2024. URL: https://uk.wikipedia.org/wiki/%D0%A2%D0%B5%D1%81%D1%82_%D0%BD%D0%B0_%D0%BF%D1%80%D0%BE%D0%BD%D0%B8%D0%BA%D0%BD%D0%B5%D0%BD%D0%BD%D1%8F (дата звернення: 12.12.2024). ISSN 1028-9763. Математичні машини і системи. 2025. № 2 29
4. Alhamed M., Rahman M. A Systematic Literature Review on Penetration Testing in Networks: Future Research Directions. Applied Sciences. 2022. Vol. 13 (12). P. 6986. URL: https://doi.org/10.3390/app13126986 (дата звернення: 22.12.2024).
5. Ferdous R., Suchi U. Evaluating Penetration Testing and Methodologies. 2024. URL: https://www.researchgate.net/publication/382617676_Evaluating_Penetration_Testing_and_Methodologis (дата звернення: 22.12.2024).
6. Software Testing — White Box Penetration Testing. 2024. URL: https://www.geeksforgeeks.org/ software-testing-white-box-penetration-testing/ (дата звернення: 02.01.2025).
7. Altulaihan E., Alismail A., Frikha M. A Survey on Web Application Penetration Testing. Electronics. 2023. Vol. 12 (5). P. 1229. URL: https://doi.org/10.3390/electronics12051229 (дата звернення:02.01.2025).
8. Makadia H., Kotadia J. Mobile Security and Penetration Testing. International Journal of Advanced Research in Science, Communication and Technology. 2021. Vol. 12, Issue 1. P. 455–460. DOI: https://doi.org/10.48175/IJARSCT-2215.
9. Network Penetration Testing. 2024. URL: https://www.blackduck.com/glossary/what-is-networkpenetration-testing.html (дата звернення: 04.01.2025).
10. Соціальна інженерія: що це та як уберегтися від шахрайства. 2024. URL: https://www.zen.com/uk/blog/personal-finance-uk/social-engineering-how-to-protect-yourself-from-fraud/ (дата звернення: 02.01.2025).
11. Physical pen testing methods and tools. 2023. URL: https://www.techtarget.com/searchsecurity/tip/Physical-pen-testing-methods-and-tools (дата звернення: 08.01.2025)

