CAaNES security assessments are based on proven and patent pending methodologies and are the most comprehensive in the industry. Our experts use proprietary tools and redundant benchmark assessment methodologies to ensure cross validation, uniformity of process and consistency of results.
Our assessments are divided into three major categories; internal, external and remote assessment. We cover the operations, processes and technologies associated with directly defending against interruption, interception, modification, and fabrication to an enterprise’s network, information systems and operations.
To ensure a complete security posture assessment our process includes analysis and review of policies, information systems, network peripherals, information security devices (firewalls, intrusion prevention and detection systems), remote access services, wireless access points, printers, back-up systems, log management systems, voice over IP systems, disaster recovery techniques and physical security.
The figure below illustrates our assessment and penetration testing process.
IPT automates common hacker attack technique (CHAT) for performing penetration testing through a multistage process.
IPT provides real-time testing capabilities against core information assurance building blocks (Network, Client, and Application). IPT’s attack modules consist of payloads that belong to one or more of the four major attack taxonomies (interruption, interception, modification, and fabrication). Testing is divided into three major categories internal, external and remote testing.
replicates actions of an attacker with an adversarial intent to gain unauthorized access to portions of enterprise’s network i.e., any device that has a network address or is accessible to any other device from the perspective of a trusted user and adversary from inside, remote and outside.
replicates actions of an attacker with an adversarial intent to gain unauthorized access using persuasion and/or deception to gain access to, or information about, information systems.
replicates actions of an attacker to gain unauthorized access and/or gain greater level of access to web applications, e-commerce, ERP, and databases. Main goal of this test is to gain unauthorized access through privilege escalation using SQL injection, code injection, remote file inclusion, and cross site scripting
EVENT tool uses a correlation engine to correlate consolidated reports from all the scanners used to Dshield’s top 10 reports (targets, source attack ports, and destination attack ports) to determine the intent of the attack (targeted or global trend).
About Dshield: Source [http://en.wikipedia.org/wiki/Dshield] Dshield is a community-based collaborative firewall log correlation system. It receives logs from volunteers’ worldwide and uses them to analyze attack trends. Analysis provided by DShield has been used in the early detection of several worms, like "Ramen", Code Red, "Leaves", "SQL Snake" and more. DShield data is regularly used by researchers to analyze attack patterns.
The goal of the DShield project is to allow access to its correlated information to the public to raise awareness and provide accurate and current snapshots of internet attacks. Several data feeds are provided to users to either include in their own web sites or to use as an aide to analyze events.
