Title
Two methodologies for physical penetration testing using social engineering
Abstract
Penetration tests on IT systems are sometimes coupled with physical penetration tests and social engineering. In physical penetration tests where social engineering is allowed, the penetration tester directly interacts with the employees. These interactions are usually based on deception and if not done properly can upset the employees, violate their privacy or damage their trust toward the organization and might lead to law suits and loss of productivity. We propose two methodologies for performing a physical penetration test where the goal is to gain an asset using social engineering. These methodologies aim to reduce the impact of the penetration test on the employees. The methodologies have been validated by a set of penetration tests performed over a period of two years.
Year
DOI
Venue
2010
10.1145/1920261.1920319
ACSAC
Keywords
Field
DocType
penetration test,penetration tester,it system,physical penetration testing,physical penetration test,law suit,social engineering,penetration testing,research ethics,methodology
Research ethics,Penetration (firestop),Physical security,Deception,Computer security,Computer science,Information technology,Social engineering (security),Penetration test
Conference
Citations 
PageRank 
References 
19
1.24
6
Authors
4
Name
Order
Citations
PageRank
Trajce Dimkov1736.27
André van Cleeff2606.47
Wolter Pieters322628.57
Pieter Hartel41159115.28