Subscribe by Email


Showing posts with label Sub Systems. Show all posts
Showing posts with label Sub Systems. Show all posts

Tuesday, May 1, 2012

How does penetration testing tool emphasize on data base security?


Data base is one of the critical elements of a web application and very much crucial for its proper functioning. All of the sensitive information regarding the functioning of the application as well as the user data is stored in the data base. 

This data is of very much use to the attacker. The attackers can steal this data and use it to their advantage. Therefore, it becomes absolutely necessary that the data base of an application must be provided with adequate security coverage.

Penetration testing is one of the ways to ensure the data base security. Most of us are familiar with what actually is the penetration testing. In this piece of writing we have discussed how the penetration testing tools emphasize up on the data base security. 

About Penetration Testing and Database Security


- Penetration testing is yet another testing methodology that has been adopted for testing the security of a computer network or system against the malicious attacks.
- It is quite a decent measure to evaluate the security level of the computer network by bombarding the network with false simulated attacks as malicious attacks from the outside as well as inside attackers.
Penetration testing is concerned with the security of the data base both from the aliens, foreigners or outside attackers who do not hold any authorized access to the computer system or network as well as the inside attackers who do have that access, but it is limited to a certain level. 
- The whole process of the penetration testing involves performing an active analysis using the penetration testing tools.
- This active analysis brings about an assessment of all the potential vulnerabilities of the whole data base system that are merely a consequence of the malfunctioning of the poor security level as well as configuration level of the application. 
- This active analysis is deemed to successful only if it has been carried out from the view point of a malicious attacker and is concerned about the active exploitation of the recognized vulnerabilities.
- The data base security depends up on the effectiveness of the testing which is in turn is affected by the effectiveness of the tools that are employed in the testing. 
- The tools indeed affect data base security, since the more effective are the tools, the more improvement will be there in the security mechanisms.

How Penetration Testing emphasize on Database Security?


- First step in the penetration testing of the data base is always the identification and recognition of the vulnerabilities and security leaks. 
- A number of penetration tests are then carried out on that particular application data base while simultaneously coupling the information with the active assessment of the risks and threats associated with the data base using the penetration testing tools.
- A whole lot of effective tools are designed to reduce the affect of these vulnerabilities.
- Penetration testing tools have been recognized as important component of the data base security audits.
- There are several other reasons why the penetration testing tools holds good for the data base security:
  1. They provide assistance in the assessment of the measure of the operational and business impacts of the attacks on the data base system.
  2. Successfully test the effectiveness of the security defenders in detecting and responding to the attacks.
  3. Provide the evidence in support of the investments that need to be made in the security field of the data base.



How does penetration testing tool emphasize on security subsystem?


Security is one of the important contributing factors in the success of a software system or application. The security level of the software system or application also influences the security of the users that use that system or application. The higher the security of a system is, the more secure it is for use. 

Since security plays a very important role in the computer world, there has to be some strategy or testing methodology that could judge or assess the security levels and mechanisms of the software systems and applications.
Do we have any such testing methodology? Yes of course we have! The penetration testing! 

About Penetration Testing and Security Sub Systems


- This software testing methodology has the answers to all our security related issues.
- The security mechanism of a software system or application is comprised of many sub mechanisms or sub systems which are commonly addressed as security sub systems. 
- These security subsystems are security components that make up the whole security model of the system.
- These sub systems ensure that the applications are not able to access the resources without being authorized and authenticated.
- Furthermore, they keep a track of the security policies and user accounts of the system. 
- There is a sub system called LSA which is responsible for maintaining all the information and details about the local security of the system. 
- The interactive user authentication services are provided by the security sub systems.
- The tokens containing the user information regarding security privileges are also generated by these sub systems. 
- The audit settings and policies are also managed by the security sub systems. 
- The following aspects are identified by the sub systems:
1.       Domain
2.       Who an access the system?
3.       Who has what privileges?
4.       Security auditing to be performed
5.       Memory quota

How Penetration Testing tool emphasize on Security Sub Systems?


So for having better security at the surface, it is important that the security at the sub systems level should not be over looked. All these matters make the security sub systems very essential. 
Therefore, it is required that to improve the overall quality of the security mechanisms, these sub systems should be tested. 

- The penetration testing tools emphasize upon the security sub systems in the same way as they emphasize the network security.
- Penetration testing was first adopted for the testing of the security of a computer network or system against the malicious attacks.
- For providing a way to evaluate the security level of the computer network by bombarding the network with false simulated attacks as malicious attacks from the outside as well as inside attackers. 
- The whole process of the penetration testing is driven by an active analysis which involves an assessment of all the potential vulnerabilities of the security sub systems that are merely a consequence of its poor security level as well as configuration level. 
- Apart from this, the flaws form both the hardware as well as software components contribute to these vulnerabilities rather than only operational weaknesses. 
- The security at the sub system level depends up on the effectiveness of the testing. 
- And the testing in turn is affected by the effectiveness of the tools that have been employed in the testing. 
- The tools indeed affect the sub systems’ security, since if the tools are reliable and efficient in finding vulnerabilities, obviously there will be more improvement in the security mechanisms. 
- A whole lot of effective tools are designed to reduce the affect of these vulnerabilities.




Monday, December 19, 2011

What are the characteristics of system integration testing?

In the context of software development and engineering, system integration can be defined as the juxta posing of all the software and the hardware components of the software system and ensuring that the subsystems and assemblages cooperate and work together as one software system or application.

- System integration is the process of linking of different computing systems, sub systems and software applications together functionally and physically so that as to make up the whole software system a well coordinating one.

- This whole process is carried out by the system integrator. It brings together the discrete parts of the software system or application by employing a variety of techniques.

Some of the techniques have been mentioned below:
1. Computer networking
2. Enterprise application integration
3. Business process management
4. Manual programming


- A system itself is an aggregation or collection of subsystems cooperating so that the system is able to deliver the high speed and quality performance.
- System integration also considers already existing and disparate subsystems or assemblages.
- The process of system integration involves joining the subsystems together through their interactive interfaces.
- The system integration is all about knowing how to glue two sub system interfaces together without affecting their functionality.
- System integration is also about making the system more valuable and rendering it capabilities that the system needs to achieve its aim and the desired behavior.

This whole process is called system integration testing or “SIT” as its abbreviation. Now this process can be defined as a process that implements the co existence of a software system with other software systems.

- In system integration testing it is always assumed that the individual sub systems have already tested through integration testing and have passed the tests at all the previous levels.
- System integration testing seeks to test the specified interactions of these sub systems with the other sub systems.
- Usually a pre system integration testing is carried before carrying out the major system integration testing.
- Special test cases are designed for system integration testing.
- Data driven method is the most commonly used method for system integration testing.
- The specialty of this method is that this methodology can be carried out with minimum requirements of the software system testing tools.
- It imports and exports data and then examines the behavior and function of each and every data field within every layer of integrated software system.

There are 3 main routes for data flow in system integration testing:
- Data state within the integration layer
Integration layer here means a middle ware or a web service. This layer acts an a media for the transfer of data and involves the following steps:
(a) cross checking of data properties.
(b) execution of unit tests and
(c) investigation of middle ware and server logs.

- Data state within the data base layer: This combination involves checking of data, checking of data properties, checking for data validations and constraints, checking stored procedures and investigation of server logs for the purpose of trouble shooting.

This is all done according to the specifications of the documentation.

- Data state within the application layer:
This combination involves marking of fields, creation of data map, and checking of data properties.

Apart from the above mentioned three combinations, there are several other combinations that can be carried out based on the availability of time for system integration testing. System integration is performed at the time of integration of two systems. Like for example, it carried out at the time of integrating bank accounting system with some inventory management system.


Wednesday, April 13, 2011

What is Software Architecture ? What are subsystems and interfaces?

Software architecture defines a set of decisions about the organization. It includes:
- how to select structural elements.
- how to select their interfaces.
- how to select the behavior.
- how to select the composition of these structural and behavioral elements into larger subsystems.
- architectural style that guides this organization.
A software architecture is a description of the sub-systems and components of a software system and the relationships between them.
Software architecture is layered structure of software components and the manner in which these components interact.
A software architecture is modeled using package diagram of UML. A package is a model element that can contain other elements.
A subsystem is a combination of package and class. The advantages of defining subsystem are:
- Development of smaller units is possible.
- Re-usability increases.
- Handling complexity is managed properly.
- Maintainability eases.
- Supports portability.

An interface is a set of operations.
- Allows the separation of the declaration of behavior from the realization of the behavior.
- Serves as a contract to help in the independent development of the components by the development team, and ensures that the components can work together.
- There are two styles of communication subsystems use: client-server and peer-to-peer communication.


Facebook activity