Ir à oferta completa

PYTHON AND WRITING - ENHANCING PENTEST USING REACHABILITY ANALYSIS

Descrição da oferta de emprego

Risk-based Vulnerability Management II – Reachability Analysis and Blast Radius As a penetration tester, you have been tasked with analyzing and adapting a graph theory-based network reachability [3] analysis solution for prioritizing vulnerability remediation prioritization as part of your organization’s maturity model.
Description.
The solution uses in-degree centrality in graph theory to develop a reachability metric for vulnerability remediation prioritization.
The implementation uses the Networkx library to calculate the reachability of network-based vulnerabilities on IT assets, using sample data from firewall (management) solutions, vulnerability management solutions and DHCP servers, and trust values for different zones/subnets.
Additional details about the description [1] and implementation [2] of the solution have been provided.
The starting code in Python and the output have also been provided as part of the files.
Tasks.
Adapt the code to determine the ‘blast radius’ of an exploited vulnerability.
Take reachability from the same zone/subnet into account.
You can apply exploit chaining ([login to view URL]) or any other relevant methodology to address this task.
You are also permitted to generate additional appropriate sample data for your analysis.
Using an evidence- based scenario, discuss the integration of the reachability score and blast radius of an exploited vulnerability into risk-based vulnerability management Deliverables.
Updated Code, Example result (table or graph) of the reachability analysis that includes the blast radius, visited nodes, exploitable links and any other relevant output, and the discussion of streamlining reachability score and blast radius with existing vulnerability prioritization metrics.
This information should be appended to the pdf document.
Note.
This question requires the ability to understand and write code in Python, Basic TCP/IP knowledge, graph theory and relevant design of the IT network.
References 1.
Albert-Jan Talsma ().
Data-driven Vulnerability Management.
Graph Theory based Reachability Analysis (1/2).
[login to view URL]@[login to view URL] management-graph-theory-based-reachability-analysis-f2fe.
Albert-Jan Talsma ().
Data-driven Vulnerability Management.
Graph Theory based Reachability Analysis (2/2).
[login to view URL]@[login to view URL] management-graph-theory-based-reachability-analysis-e6a3de9c 3.
Khakpour, A.
.
and Liu, A.
., , June.
Quantifying and querying network reachability.
In IEEE 30th International Conference on Distributed Computing Systems (pp.
).
IEEE.
I require someone to verify my code and make changes if not correct and to complete the write up in 1 day.
Python Arquitetura de software Digital Networking ID do Projeto.
# Sobre o projeto 6 propostas Aberto para ofertas Projeto remoto Ativo em 12 minutos atrás
Ir à oferta completa

Detalhes da oferta

Empresa
  • Indeterminado
Localidade
  • Em todo Portugal
Endereço
  • Indeterminado - Indeterminado
Data de publicação
  • 12/10/2024
Data de expiração
  • 10/01/2025
Automation and Robotics Engineer
TECNICOAT, LDA

Excellent problem-solving and troubleshooting skills... strong communication and collaboration skills... stay abreast of industry trends and emerging technologies in automation and robotics... program, troubleshoot, and optimize robotic systems to meet performance and quality standards......

Position: Translator and Content Specialist (Portuguese)
DAC SERVICES AND SOLUTIONS LTD

Fluent in german and english... marketing materials:- translate brochures and other marketing materials from de>pt and en>pt... adapt surveys and questionnaires for portuguese-speaking audiences, ensuring cultural relevance and clarity... excellent attention to detail and strong organizational skills......

Junior Phyton NME and numpy developer
TEMPOSUSSURRANTE LTA

@confidentialnote: mne library of python will be used to explore, visualise and analysehuman neurophysiological data... this proposal definesdetailed features& functionality and development methodology... 5 mysql linux and windows json, rest, api... new remedies ltd (henceforth referred to as “company”......

Customer Support with French and English Insurance Company
Paco recrutiment

Operates in 54 countries offering property, personal and business insurance, as well as accident, supplementary health, reinsurance and life insurance... we are looking for french and english speaking employees for our team in lisbon to support our customers (inbound calls, emails and chat) project starts......

Contact Center Operator German and English (m\f)
Eurofirms

Customer orders related to customer reservations, orders and purchases... we act on a framework of transparency, responsibility and respect... our commitment and involvement, together with constant technological innovation, has allowed us to position ourselves as one of the leading national human resources......

French and english backoffice support for hotel hybrid work
Paco recrutiment

Przygotowywanie, utrzymywanie i przeglądanie plików handlowych, rapportów i cenników... do naszego zespołu w lizbonie poszukujemy pracowników mówiących po francusku i języku angielskim, którzy będą reagować na naszych klientów (czat w mediach społecznościowych, e-maile, a następnie rozmowy telefoniczne)......

French and English Backoffice Support for Hotel Hybrid work
Paco Recrutiment

Nasze oczekiwania: obywatelstwo ue lub zezwolenie na pobyt w portugalii mówisz ojczystym językiem francuskim mówisz po angielsku (b2) mieszkasz w lizbonie lub chcesz się tam przeprowadzić lubisz kontakt z ludźmi oferujemy: zatrudnienie na pełen etat oraz praca w modelu hybrydowym : od poniedziałku......

Customer Support German and English for Insurance Company
Paco Recrutiment

Do naszego zespołu w lizbonie poszukujemy pracowników mówiących po niemieckie i polskie, którzy będą wysyłać do naszych klientów (połączenie przychodzące, e-maile i czaty) twoje: zadanie odbieranie rozmów telefonicznych lub czatów od klientów, informacje dotyczące rodzaju ich polisy ubezpieczeniowej......

Costumer Support and sales representative
CCTalents

Estamos a recrutar para empresa, nossa cliente, assistende de apoio ao cliente ou vendedor, vagas para as duas funçõeslocal: costumer assistant: lisboa sales: teletrabalho regime: full-time oferecemos: salário acima da media bonus e comissões a combinar na entrevista ambiente de trabalho agradável......

Test Engineer (Automation) – Phyton
Newin

· analyse and verify best automated and manual test approaches and execute acceptance, integration and system testing... · execute performance testing and present results for validating and analysis to project teams... · apply, design and develop automated testing strategies and build automated testing......