Penetration Testing in System Security
DOI:
https://doi.org/10.65890/dmp-lncse.ICICCS26.196Keywords:
Penetration Testing, Vulnerability Assessment, Cybersecurity, Network Security, Metasploit, OWASP, NISTAbstract
Cybersecurity has emerged as a key issue in contemporary computing environments due to an increasing dependence on digital systems and networked infrastructures. By discovering and exploiting vulnerabilities in a controlled and ethical manner, penetration testing has become an essential method for evaluating system security. Reducing cyber risks helps organisations assess their security posture, identify potential vulnerabilities, and implement appropriate defences. This review paper offers a comprehensive overview of the current literature on penetration testing, covering its methodologies, tools, frameworks, and applications across diverse areas, including network security, web application security, and enterprise systems. This study includes findings from various research projects, focusing on the efficacy of both manual and automated testing methodologies, including the application of structured frameworks, vulnerability scanning tools, and exploitation platforms. It also examines how standardised guidelines and methods can ensure that security assessments are systematic and reliable. The review goes into more detail on important topics, such as common attack methods (e.g., man-in-the-middle attacks, packet sniffing, SQL injection, cross-site scripting, and cross-site request forgery), and how to protect against them. It also points out how important automation and ongoing security assessment are becoming for making penetration testing more accurate and efficient. This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk. The paper concludes by highlighting the need for structured, thorough penetration testing and advocating further research into advanced, automated security testing to address new cyber threats.
Downloads
Published
Conference Proceedings Volume
Section
License
Copyright (c) 2026 DMPedia Lecture Notes in Computer Science & Engineering

This work is licensed under a Creative Commons Attribution 4.0 International License.