Jul 2026· DMPedia Lecture Notes in Computer Science & Engineering· 1 citation· 1 references
TL;DR
This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.
Abstract
Cybersecurity has emerged as a key issue in contemporary computing environments due to an increasing dependence on digital systems and networked infrastructures. By discovering and exploiting vulnerabilities in a controlled and ethical manner, penetration testing has become an essential method for evaluating system security. Reducing cyber risks helps organisations assess their security posture, identify potential vulnerabilities, and implement appropriate defences. This review paper offers a comprehensive overview of the current literature on penetration testing, covering its methodologies, tools, frameworks, and applications across diverse areas, including network security, web application security, and enterprise systems. This study includes findings from various research projects, focusing on the efficacy of both manual and automated testing methodologies, including the application of structured frameworks, vulnerability scanning tools, and exploitation platforms. It also examines how standardised guidelines and methods can ensure that security assessments are systematic and reliable. The review goes into more detail on important topics, such as common attack methods (e.g., man-in-the-middle attacks, packet sniffing, SQL injection, cross-site scripting, and cross-site request forgery), and how to protect against them. It also points out how important automation and ongoing security assessment are becoming for making penetration testing more accurate and efficient. This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk. The paper concludes by highlighting the need for structured, thorough penetration testing and advocating further research into advanced, automated security testing to address new cyber threats.
Web applications have become an integral part of everyday life, enabling services such as online banking, e-commerce, education, and communication. As their adoption continues to increase, so does the risk of cyberattacks targeting security weaknesses within these applications. Many of these vulnerabilities arise from insecure coding practices, improper configurations, and inadequate security controls. To address these challenges, the Open Web Application Security Project (OWASP) Top 10 serves as a widely accepted framework for identifying and mitigating common web application security risks. This study investigates web application vulnerabilities based on the OWASP Top 10 framework through a practical security assessment approach. Various security tools, including Burp Suite, OWASP ZAP, Threat Dragon, Hydra, Trivy, and Splunk, were utilized to perform threat modeling, vulnerability assessment, authentication testing, dependency analysis, and security monitoring. Testing was conducted in a controlled environment to evaluate the effectiveness of these tools in identifying security weaknesses. The assessment revealed several significant vulnerabilities, including Broken Access Control (IDOR), Cryptographic Failures, HTML Injection, Insecure Design, Identification and Authentication Failures, and Security Logging and Monitoring Failures. The findings demonstrate how these weaknesses can compromise application security and expose systems to potential attacks. Appropriate mitigation measures were also identified to reduce associated risks. The study concludes that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle. Adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.
S. Banu, H. Shanmatha, Mehdi Gheisari et al.· BOHR International Journal o...· 0 citations
E-government digital platforms are often attacked by sophisticated cybersecurity threats because of the sensitive nature of the information and services they provide. The analysis finds that these systems have vulnerabilities due to fragmented security architectures, not enough skilled personnel, limited budgets, and reactive security approaches, particularly within developing countries such as Zambia. This study reviews existing research on cybersecurity challenges affecting e-government systems, focusing on Gov-ernment-to-Business (G2B) digital platforms in developing countries. It also examines established cyber-security frameworks, including Defence-in-Depth (DiD), NIST CSF, ISO/IEC 27001, and the Zero Trust model. The study also reviews the role of Centralized Security Monitoring Platforms (CSMPs) integrated with Intrusion Detection and Prevention Platforms (IDPPs) in improving threat visibility, event correla-tion, and coordinated incident response. A lightweight validation approach is carried out using a virtual-ized environment, which relies on open-source platforms such as pfSense, Suricata, and Wazuh to show how the centralization of monitoring increases situational awareness and correlates events to show the relevance of the proposed solution within a resource-constrained environment. The study further identi-fied some operational and technical challenges that affect the adoption of effective cybersecurity prac-tices within e-government infrastructures and highlights the importance of scalable, cost-effective, and integrated monitoring infrastructures to manage cybersecurity proactively in developing countries.
Lukumba Phiri, Steve Muwowo· International Journal of Ele...· 0 citations
The article examines modern threats to information security faced by corporate networks, as well as analyzes methods and means of their neutralization. The relevance of the research is due to the rapid digital transformation of business, the transition to remote work formats, the active introduction of cloud technologies and the Internet of Things, which significantly expands the attack surface for intruders. According to analytical reports, the number of successful cyber-attacks on corporate networks increases by 15–20 percent annually, and the average damage from a single attack for a large company can reach several million dollars. The purpose of the work is to systematize modern threats to information security in corporate networks, analyze methods for their identification and neutralization, as well as identify promising areas for the development of security systems. The methodological base of the study includes an analysis of data on cyber-attacks in recent years, an overview of modern information security tools, as well as a summary of best practices in building information security systems.
Maxim M. Panfilov, Rasul A. Vagapov· EKONOMIKA I UPRAVLENIE: PROB...· 0 citations
Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and reliability. This study proposes a network-based security information system (NBSIS) designed specifically for CBT environments. The framework integrates layered defense, including pfSense firewalls (FW), Snort intrusion detection, Splunk security information and event management (SIEM), and artificial intelligence (AI)-powered analytics, into a unified architecture. A human-centered dashboard ensures usability for non-technical exam administrators, providing real-time alerts and intuitive controls. Validation through simulated attack scenarios demonstrated strong resilience, with high detection accuracy, reduced false positives, and rapid response times. Comparative analysis against intrusion detection system (IDS)-only and SIEM-only systems confirmed superior performance. The findings highlight NBSIS as a robust, scalable, and adaptive solution that safeguards exam integrity while remaining practical for diverse organizational contexts. This research contributes to computer science by advancing secure architecture, applying AI-driven anomaly detection, and integrating human-computer interaction principles into cybersecurity for education.
The rapid proliferation of the Internet of Things (IoT) has transformed industries by enabling seamless interconnectivity among devices, applications, and networks. However, this widespread adoption has also introduced significant security vulnerabilities, exposing IoT ecosystems to cyber threats such as unauthorized access, data breaches, and large-scale cyber-attacks. As IoT technology continues to evolve, mitigating these vulnerabilities remains a complex and pressing challenge. In this context, penetration testing, which is also known as pen testing, serves as a proactive security measure, enabling organizations to identify and address potential weaknesses before they can be exploited by malicious actors. Penetration testing for IoT systems is a specialized security assessment that addresses the unique vulnerabilities of interconnected devices, networks, and communication protocols, differing significantly from traditional computing and network penetration testing methodologies. In this regard, this study presents a review of penetration testing as a critical methodology for identifying, assessing, and mitigating security risks in IoT environments. We examine the key steps, tools, and methodologies specifically designed for IoT penetration testing, demonstrating their applicability across diverse infrastructures through a simple case study. Further, this study also proposes a novel Artificial Intelligence (AI)-enabled automated conceptual framework, AutoAIPenTest, that integrates machine learning, reinforcement learning, and large language models to perform intelligent, real-time security assessments in dynamic IoT ecosystems. Our findings highlight the critical role of proactive security measures, including structured penetration testing, secure development practices, and regulatory compliance, in strengthening the resilience of the IoT ecosystem. By discussing existing challenges and proposing effective security strategies, this study contributes to ongoing efforts to secure IoT domains and ensure that technological advancements do not come at the expense of cybersecurity.