{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,12]],"date-time":"2026-08-12T10:33:40Z","timestamp":1786530820805,"version":"build-2736575974"},"reference-count":25,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2014,11,28]],"date-time":"2014-11-28T00:00:00Z","timestamp":1417132800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2015,2]]},"DOI":"10.1007\/s11416-014-0231-x","type":"journal-article","created":{"date-parts":[[2014,12,2]],"date-time":"2014-12-02T17:47:08Z","timestamp":1417542428000},"page":"27-49","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":82,"title":["An overview of vulnerability assessment and penetration testing techniques"],"prefix":"10.1007","volume":"11","author":[{"given":"Sugandh","family":"Shah","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"B. M.","family":"Mehtre","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2014,11,28]]},"reference":[{"key":"231_CR1","unstructured":"Tiller, J.S.: CISO\u2019s Guide to Penetration Testing. CRC Press Publication, Boca Raton"},{"key":"231_CR2","unstructured":"The Canadian Institute of Chartered Accountants Information Technology Advisory Committee, Using an Ethical Hacking Technique to assess Information security Risk, Toronto. http:\/\/www.cica.ca\/research-and-guidance\/documents\/it-advisory-committee\/item12038.pdf . Accessed 03 Oct 2013"},{"key":"231_CR3","doi-asserted-by":"crossref","unstructured":"Xiong, P., Peyton, L.: A model driven penetration test framework for web applications. In: IEEE 8th Annual International Conference on Privacy, Security and Trust (2010)","DOI":"10.1109\/PST.2010.5593250"},{"key":"231_CR4","doi-asserted-by":"crossref","unstructured":"Liu, B., Shi, L., Cai, Z.: Software vulnerability discovery techniques: a survey. In: IEEE 4th International Conference on Multimedia Information Networking and Security (2012)","DOI":"10.1109\/MINES.2012.202"},{"key":"231_CR5","doi-asserted-by":"crossref","unstructured":"Duan, B., Zhang, Y., Gu, D.: An easy to deploy penetration testing platform. In: IEEE 9th International Conference for young Computer Scientists (2008)","DOI":"10.1109\/ICYCS.2008.335"},{"key":"231_CR6","unstructured":"Dr. Geer, D., Harthorne, J.: Penetration testing: a duet. In: IEEE Proceedings of 18th Annual Computer Security Application Conference, ACSAC\u201902 (2002)"},{"key":"231_CR7","doi-asserted-by":"crossref","unstructured":"Sparks, S., Embleton, S., Cunningham, R., Zou, C.: Automated vulnerability analysis: leveraging control flow for evolutionary input crafting. In: IEEE 23rd Annual Computer Security Applications Conference (2007)","DOI":"10.1109\/ACSAC.2007.27"},{"key":"231_CR8","unstructured":"Open Web Application Security Project. OWASP Top 10 Project. http:\/\/www.owasp.org\/index.php\/category:OWASP_Top_Ten_Project . Accessed 03 Oct 2013"},{"key":"231_CR9","doi-asserted-by":"crossref","unstructured":"Turpe, S., Eichler, J.: Testing production systems safely: common precautions in penetration testing. In: IEEE Academy Industrial Conference (2009)","DOI":"10.1109\/TAICPART.2009.17"},{"key":"231_CR10","doi-asserted-by":"crossref","unstructured":"Halfold, W., Choudhary, S., Orso, A.: Penetration testing with improved input vector identification. In: IEEE International Conference on Software Testing Verification and Validation (2009)","DOI":"10.1109\/ICST.2009.26"},{"key":"231_CR11","doi-asserted-by":"crossref","unstructured":"Austin, A., Williams, L.: One technique is not enough: a comparison of vulnerability discovery techniques. In: IEEE International Symposium on Empirical Software Engineering and Measurement (2011)","DOI":"10.1109\/ESEM.2011.18"},{"key":"231_CR12","unstructured":"The MITRE Corporation, Common Weakness Enumeration. http:\/\/www.cwe.mitre.org\/ . Accessed 03 Oct 2013"},{"key":"231_CR13","unstructured":"SANS Institute. SANS Top 25 Software Errors. http:\/\/www.sans.org\/top25-software-errors\/ . Accessed 03 Oct 2013"},{"key":"231_CR14","unstructured":"Institute for Security and Open Methodologies. Open Source Security Testing Methodology Manual. http:\/\/www.isecom.org\/mirror\/OSSTMM.3.pdf . Accessed 03 Oct 2013"},{"key":"231_CR15","unstructured":"Payment Card Industry Security Standards. Payment Card Industry Data Security Standard. http:\/\/www.pcisecuritystandards.org\/documents\/pci_dss_v2.pdf . Accessed 03 Oct 2013"},{"key":"231_CR16","unstructured":"Open Web Application Security Project. OWASP Testing Guide. http:\/\/www.owasp.org\/images\/5\/56\/OWASP_Testing_Guide_v3.pdf . Accessed 03 Oct 2013"},{"key":"231_CR17","unstructured":"International Organization for Standardization. IEC\/ISO 27001:2013. http:\/\/www.iso.org\/iso\/home\/store\/catalogue_ics\/catalogue_detail_ics.htm?csnumber=54534 . Accessed 03 Oct 2013"},{"key":"231_CR18","doi-asserted-by":"crossref","unstructured":"LanFang, W., HaiZhou, K.: A research of behavior based penetration testing model of the network. In: IEEE International Conference on Industrial Control and Electronics Engineering (2012)","DOI":"10.1109\/ICICEE.2012.444"},{"key":"231_CR19","unstructured":"iVolution Security Technologies. Benefits of Penetration Testing. http:\/\/www.ivolutionsecurity.com\/pen_testing\/benefits.php . Accessed 03 Oct 2013"},{"key":"231_CR20","doi-asserted-by":"crossref","unstructured":"Antunes, N., Vieira, M.: Benchmarking vulnerability detection tools for web services. In: IEEE International Conference on Web Services (2010)","DOI":"10.1109\/ICWS.2010.76"},{"key":"231_CR21","unstructured":"White Hat Statistics Report\u2019 2013. https:\/\/www.whitehatsec.com . Accessed 03 Oct 2013"},{"key":"231_CR22","unstructured":"Shah, S.: Vulnerability assessment and penetration testing (VAPT) techniques for cyber defence. IET-NCACNS\u2019 SGGS, Nanded (2013)"},{"key":"231_CR23","unstructured":"Shah, S., Mehtre, B.M.: A modern approach to cyber security analysis using vulnerability assessment and penetration testing. In: NCRTCST\u2019 2013, Hyderabad, India"},{"key":"231_CR24","unstructured":"Shah, S., Mehtre, B.M.: School of Computer and Information Sciences, University of Hyderabad, Hyderabad, India. In: 2013 IEEE International Conference on Computational Intelligence and Computing Research (ICCIC)"},{"key":"231_CR25","doi-asserted-by":"crossref","unstructured":"McDermott, J.P.: Attack net penetration testing. In: Proceedings of the 2000 Workshop on New Security Paradigms. ACM Press, New York (2001)","DOI":"10.1145\/366173.366183"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0231-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-014-0231-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-014-0231-x","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,18]],"date-time":"2019-08-18T02:33:24Z","timestamp":1566095604000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-014-0231-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,11,28]]},"references-count":25,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,2]]}},"alternative-id":["231"],"URL":"https:\/\/doi.org\/10.1007\/s11416-014-0231-x","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,11,28]]}}}