|
ESTec tests for all potential vulnerabilities. We then stress applications
in ways that the developers never expected. When an application
exists on multiple machines (typical of client/server architectures),
we test each, as well as the communications channels. We also try
to exploit 'features' of the applications to gain unauthorized access
to your network and computers.
Safety first: your senior management must agree to any test.
To protect affected assets, we work with you to define the scope
of the test and its cutoff points. Tests are run solely to prove
whether an intrusion is possible and what damage could occur. We
design them to prevent damage.
Penetration tests are directed at the organization, its Internet
interface, and applications. The goal is to test intrusion detection
and response mechanisms. A test succeeds if it is detected by the
intrusion detection mechanisms and properly responded to.
ESTec also trains your employees to perform basic intrusion studies
and vulnerability audits. Transferring skill sets and knowledge
we upgrade your company's staff while saving you time and expense.
|