Black Box Vs. White Box
Penetration tests can be conducted in several ways. The most common difference is the amount of knowledge of the implementation details of the system being tested that are available to the testers. Black box testing assumes no prior knowledge of the infrastructure to be tested. The testers must first determine the location and extent of the systems before commencing their analysis. At the other end of the spectrum, white box testing provides the testers with complete knowledge of the infrastructure to be tested, often including network diagrams, source code, and IP addressing information. There are also several variations in between, often known as grey box tests. Penetration tests can also be described as "full disclosure" (white box), "partial disclosure" (grey box), or "blind" (black box) tests based on the amount of information provided to the testing party.
The relative merits of these approaches are debated. Black box testing simulates an attack from someone who is unfamiliar with the system. White box testing simulates what might happen during an "inside job" or after a "leak" of sensitive information, where the attacker has access to source code, network layouts, and possibly even some passwords.
The services offered by penetration testing firms span a similar range, from a simple scan of an organization's IP address space for open ports and identification banners to a full audit of source code for an application.
Read more about this topic: Penetration Test
Famous quotes containing the words black, box and/or white:
“The confirmation of Clarence Thomas, one of the most conservative voices to be added to the [Supreme] Court in recent memory, carries a sobering message for the African- American community.... As he begins to make his mark upon the lives of African Americans, we must acknowledge that his successful nomination is due in no small measure to the support he received from black Americans.”
—Kimberly Crenshaw (b. 1959)
“Franceska: I was happy in the life I built up for myself. I put a fine high wall of music around me and nothing could touch me. I was safe and secure. And then you had to come along and knock it all down and I hate you for that.
Maxwell: On the contrary, you love me.”
—Muriel Box (b. 1905)
“Stands the Spring! heralded by its bright-clothed
Trumpeters, of bough and bush and branch;
Pale Winter draws away his white hands, loathed,
And creeps, a leper, to the cave of time.”
—Philip Larkin (19221986)