<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>2227-1899</journal-id>
<journal-title><![CDATA[Revista Cubana de Ciencias Informáticas]]></journal-title>
<abbrev-journal-title><![CDATA[Rev cuba cienc informat]]></abbrev-journal-title>
<issn>2227-1899</issn>
<publisher>
<publisher-name><![CDATA[Editorial Ediciones Futuro]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S2227-18992021000500225</article-id>
<title-group>
<article-title xml:lang="es"><![CDATA[Riesgos de Seguridad en Pruebas de Penetración Web]]></article-title>
<article-title xml:lang="en"><![CDATA[Security Risks in Web Penetration Testing]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[González Brito]]></surname>
<given-names><![CDATA[Henry Raúl]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Montesino Perurena]]></surname>
<given-names><![CDATA[Raydel]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Gainza Reyes]]></surname>
<given-names><![CDATA[Dainys]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Universidad de las Ciencias Informáticas. Subdirector del Centro de Telemática ]]></institution>
<addr-line><![CDATA[ La Habana]]></addr-line>
<country>Cuba</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Universidad de las Ciencias Informáticas  ]]></institution>
<addr-line><![CDATA[ La Habana]]></addr-line>
<country>Cuba</country>
</aff>
<aff id="Af3">
<institution><![CDATA[,Universidad de las Ciencias Informáticas Dirección de Educación de Posgrado ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Cuba</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>00</month>
<year>2021</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>00</month>
<year>2021</year>
</pub-date>
<volume>15</volume>
<numero>4</numero>
<fpage>225</fpage>
<lpage>243</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://scielo.sld.cu/scielo.php?script=sci_arttext&amp;pid=S2227-18992021000500225&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.sld.cu/scielo.php?script=sci_abstract&amp;pid=S2227-18992021000500225&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.sld.cu/scielo.php?script=sci_pdf&amp;pid=S2227-18992021000500225&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="es"><p><![CDATA[RESUMEN En el presente trabajo se realiza una sistematización de los principales riesgos de seguridad que pueden estar asociados a las pruebas de penetración en aplicaciones web. Para la realización del estudio se consultaron fuentes bibliográficas y reportes de un alto nivel científico y técnico. Se identificaron y describieron 31 riesgos clasificados en dos grupos: los asociados a daños directos a la confidencialidad, integridad y disponibilidad de la información de la aplicación web y aquellos relacionados con la realización de una prueba de penetración deficiente y cuyos resultados parciales también afectan de manera indirecta la seguridad web; estos últimos fueron dividido en cuanto a riesgos de alcance y tiempo, infraestructura tecnológica y personal. Para el tratamiento de los riesgos descritos, se brinda un conjunto de 14 recomendaciones bases para la conformación de una estrategia de mitigación en función de los escenarios de pruebas. Se particulariza también en los modos de aplicación de las herramientas automatizadas de evaluación de vulnerabilidades para limitar los daños en las aplicaciones web. Los resultados alcanzados tienen una alta pertinencia dada por la necesidad de los implicados en los procesos de pruebas de penetración de contar con una base de partida conceptual que favorezca el tratamiento de riesgos y contextualice mejor las decisiones tomadas en función de solucionar las vulnerabilidades de seguridad halladas a través de este tipo de evaluación de seguridad.]]></p></abstract>
<abstract abstract-type="short" xml:lang="en"><p><![CDATA[ABSTRACT This paper systematizes the main security risks that may be associated with penetration testing in web applications. Bibliographic sources and reports of a high scientific and technical level were consulted for the study. Thirty-one risks were identified and described, classified into two groups: those associated with direct damage to the confidentiality, integrity and availability of web application information and those related to the performance of a deficient penetration test and whose partial results also indirectly affect the security of web portals, the latter were divided into risks of scope and time, technological infrastructure and personnel. For the treatment of the described risks, a set of 14 basic recommendations is provided for the conformation of a mitigation strategy according to the existing test scenarios. It also focuses on how to apply automated vulnerability assessment tools to limit damage to web applications. The results achieved are highly relevant given the need for those involved in penetration testing processes to have a conceptual starting point that favors the treatment of risks and better contextualizes the decisions taken in order to solve the security vulnerabilities found through this type of security assessment.]]></p></abstract>
<kwd-group>
<kwd lng="es"><![CDATA[aplicaciones web]]></kwd>
<kwd lng="es"><![CDATA[mitigación de riesgos]]></kwd>
<kwd lng="es"><![CDATA[pruebas de penetración]]></kwd>
<kwd lng="es"><![CDATA[riesgos de seguridad]]></kwd>
<kwd lng="es"><![CDATA[seguridad web]]></kwd>
<kwd lng="en"><![CDATA[penetration testing]]></kwd>
<kwd lng="en"><![CDATA[risk mitigation]]></kwd>
<kwd lng="en"><![CDATA[security risks]]></kwd>
<kwd lng="en"><![CDATA[web applications]]></kwd>
<kwd lng="en"><![CDATA[web security]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alsmadi]]></surname>
<given-names><![CDATA[I]]></given-names>
</name>
</person-group>
<source><![CDATA[The NICE Cyber Security Framework: Cyber Security Intelligence and Analytics]]></source>
<year>2019</year>
<publisher-loc><![CDATA[Gewerbestrasse (Suiza) ]]></publisher-loc>
<publisher-name><![CDATA[Springer]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B2">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Antunes]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
<name>
<surname><![CDATA[Vieira]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Designing vulnerability testing tools for web services: approach, components, and tools.]]></article-title>
<source><![CDATA[International Journal of Information Security]]></source>
<year>2017</year>
<volume>16</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>435-57</page-range></nlm-citation>
</ref>
<ref id="B3">
<nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bari]]></surname>
<given-names><![CDATA[M. A]]></given-names>
</name>
<name>
<surname><![CDATA[Ahamad]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<source><![CDATA[Study of Ethical Hacking and Management of Associated Risks.]]></source>
<year>2021</year>
</nlm-citation>
</ref>
<ref id="B4">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Blackwell]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
</person-group>
<source><![CDATA[Towards a Penetration Testing Framework Using Attack Patterns.]]></source>
<year>2014</year>
<page-range>135-48</page-range><publisher-loc><![CDATA[Switzerland ]]></publisher-loc>
<publisher-name><![CDATA[Springer]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B5">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Dalalana Bertoglio]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Zorzo]]></surname>
<given-names><![CDATA[A. F]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Overview and open issues on penetration test.]]></article-title>
<source><![CDATA[Journal of the Brazilian Computer Society]]></source>
<year>2017</year>
<volume>23</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>1-16</page-range></nlm-citation>
</ref>
<ref id="B6">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[DeMarco]]></surname>
<given-names><![CDATA[J. V]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[An approach to minimizing legal and reputational risk in Red Team hacking exercises.]]></article-title>
<source><![CDATA[Computer Law and Security Review]]></source>
<year>2018</year>
<volume>34</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>908-11</page-range></nlm-citation>
</ref>
<ref id="B7">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[González Brito]]></surname>
<given-names><![CDATA[H. R]]></given-names>
</name>
<name>
<surname><![CDATA[Montesino Perurena]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Capacidades de las metodologías de pruebas de penetración para detectar vulnerabilidades frecuentes en aplicaciones web.]]></article-title>
<source><![CDATA[Revista Cubana de Ciencias Informáticas,]]></source>
<year>2018</year>
<volume>12</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>52-65</page-range></nlm-citation>
</ref>
<ref id="B8">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Hasan]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Meva]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Web Application Safety by Penetration Testing.]]></article-title>
<source><![CDATA[International Journal of Advanced Studies of Scientific Research]]></source>
<year>2018</year>
<volume>3</volume>
<numero>9</numero>
<issue>9</issue>
</nlm-citation>
</ref>
<ref id="B9">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Jansen]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Cusumano]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
<name>
<surname><![CDATA[Popp]]></surname>
<given-names><![CDATA[K. M]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Managing Software Platforms and Ecosystems]]></article-title>
<source><![CDATA[IEEE Software]]></source>
<year>2019</year>
<volume>36</volume>
<numero>3</numero>
<issue>3</issue>
<page-range>17-21</page-range></nlm-citation>
</ref>
<ref id="B10">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kao]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Wang]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Tsai]]></surname>
<given-names><![CDATA[F]]></given-names>
</name>
<name>
<surname><![CDATA[Chen]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
</person-group>
<source><![CDATA[Forensic analysis of network packets from penetration test toolkits]]></source>
<year>2018</year>
<page-range>363-8</page-range><publisher-loc><![CDATA[Nueva York, EE.UU ]]></publisher-loc>
<publisher-name><![CDATA[IEEE]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B11">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kettani]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Wainwright]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
</person-group>
<source><![CDATA[On the top threats to cyber systems.]]></source>
<year>2019</year>
<publisher-name><![CDATA[International Conference on Information and Computer Technologies, ICICT]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B12">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Knowles]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
<name>
<surname><![CDATA[Baron]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[McGarr]]></surname>
<given-names><![CDATA[T]]></given-names>
</name>
</person-group>
<source><![CDATA[The simulated security assessment ecosystem: Does penetration testing need standardisation?]]></source>
<year>2016</year>
<volume>62</volume>
<page-range>296-316</page-range><publisher-name><![CDATA[Computers &amp; Security]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B13">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kothia]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Swar]]></surname>
<given-names><![CDATA[B]]></given-names>
</name>
<name>
<surname><![CDATA[Jaafar]]></surname>
<given-names><![CDATA[F]]></given-names>
</name>
</person-group>
<source><![CDATA[Knowledge Extraction and Integration for Information Gathering in Penetration Testing.]]></source>
<year>2019</year>
<publisher-name><![CDATA[IEEE 19th International Conference on Software Quality, Reliability and Security Companion]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B14">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kumar]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Tlhagadikgora]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
</person-group>
<source><![CDATA[Internal Network Penetration Testing Using Free/Open Source Tools: Network and System Administration Approach]]></source>
<year>2019</year>
<publisher-name><![CDATA[Singapore]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B15">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Laidlaw]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
<name>
<surname><![CDATA[Shoemaker]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Software assurance: the things a manager needs to know]]></article-title>
<source><![CDATA[EDPACS]]></source>
<year>2020</year>
<volume>61</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>1-8</page-range></nlm-citation>
</ref>
<ref id="B16">
<nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Manaseer]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[K.Al Hwaitat]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Jabri]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<source><![CDATA[Distributed Detection and prevention of Web Threats in Heterogeneous Environment]]></source>
<year>2018</year>
</nlm-citation>
</ref>
<ref id="B17">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mansfield-Devine]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Open source software: determining the real risk posed by vulnerabilities]]></article-title>
<source><![CDATA[Network Security]]></source>
<year>2017</year>
<volume>2017</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>7-12</page-range></nlm-citation>
</ref>
<ref id="B18">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mansfield-Devine]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Friendly fire: how penetration testing can reduce your risk]]></article-title>
<source><![CDATA[Network Security]]></source>
<year>2018</year>
<volume>2018</volume>
<numero>6</numero>
<issue>6</issue>
<page-range>16-9</page-range></nlm-citation>
</ref>
<ref id="B19">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Miaoui]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Boudriga]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Enterprise security investment through time when facing different types of vulnerabilities.]]></article-title>
<source><![CDATA[Information Systems Frontiers]]></source>
<year>2019</year>
<volume>21</volume>
<numero>2</numero>
<issue>2</issue>
<page-range>261-300</page-range></nlm-citation>
</ref>
<ref id="B20">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Murthy]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
<name>
<surname><![CDATA[Shilpa]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<source><![CDATA[Vulnerability Coverage Criteria for Security Testing of Web Applications]]></source>
<year>2018</year>
<publisher-name><![CDATA[Paper presented at the 2018 International Conference on Advances in Computing, Communications and Informatics (ICACCI)]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B21">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Negi]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Kumar]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
<name>
<surname><![CDATA[Ghosh]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Shukla]]></surname>
<given-names><![CDATA[S. K]]></given-names>
</name>
<name>
<surname><![CDATA[Gahlot]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<source><![CDATA[Vulnerability Assessment and Mitigation for Industrial Critical Infrastructures with Cyber Physical Test Bed.]]></source>
<year>2019</year>
<page-range>145-52</page-range><publisher-loc><![CDATA[Nueva York, EE.UU: IEEE ]]></publisher-loc>
<publisher-name><![CDATA[IEEE International Conference on Industrial Cyber Physical Systems (ICPS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B22">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Nieles]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
<name>
<surname><![CDATA[Dempsey]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
<name>
<surname><![CDATA[Pillitteri]]></surname>
<given-names><![CDATA[V]]></given-names>
</name>
</person-group>
<source><![CDATA[An introduction to information security.]]></source>
<year>2017</year>
<publisher-loc><![CDATA[EE.UU ]]></publisher-loc>
<publisher-name><![CDATA[Project Management Institute]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B23">
<nlm-citation citation-type="">
<collab>PTES</collab>
<source><![CDATA[The Penetration Testing Execution Standard Documentation]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B24">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Rahalkar]]></surname>
<given-names><![CDATA[S. A]]></given-names>
</name>
</person-group>
<source><![CDATA[Certified Ethical Hacker (CEH) Foundation Guide.]]></source>
<year>2016</year>
<publisher-loc><![CDATA[Pune (India ]]></publisher-loc>
<publisher-name><![CDATA[Springer]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B25">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Saha]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Das]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Kumar]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Biswas]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Saha]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<source><![CDATA[Ethical Hacking: Redefining Security in Information System]]></source>
<year>2020</year>
<publisher-name><![CDATA[Singapore]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B26">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Shah]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
<name>
<surname><![CDATA[Ahmed]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Saeed]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
<name>
<surname><![CDATA[Junaid]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
<name>
<surname><![CDATA[Khan]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Ata Ur]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<source><![CDATA[Penetration testing active reconnaissance phase - Optimized port scanning with nmap tool.]]></source>
<year>2019</year>
<page-range>pp. 1-6</page-range><publisher-loc><![CDATA[Nueva York, EE.UU: IEEE ]]></publisher-loc>
<publisher-name><![CDATA[2019 2nd International Conference on Computing, Mathematics and Engineering Technologies, iCoMET 2019]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B27">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Shon]]></surname>
<given-names><![CDATA[M. D]]></given-names>
</name>
</person-group>
<source><![CDATA[Information Security Analysis as Data Fusion]]></source>
<year>2019</year>
<publisher-name><![CDATA[Paper presented at the 2019 22th International Conference on Information Fusion (FUSION)]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B28">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Sina]]></surname>
<given-names><![CDATA[B. J]]></given-names>
</name>
</person-group>
<source><![CDATA[Identifying the Efficacy of Various Penetration Testing Practices.]]></source>
<year>2019</year>
<publisher-name><![CDATA[Utica College]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B29">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Stallings]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
<name>
<surname><![CDATA[Brown]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<source><![CDATA[Computer Security: Principles and Practice]]></source>
<year>2018</year>
<publisher-loc><![CDATA[New York (EE.UU) ]]></publisher-loc>
<publisher-name><![CDATA[Pearson]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B30">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Such]]></surname>
<given-names><![CDATA[J. M]]></given-names>
</name>
<name>
<surname><![CDATA[Gouglidis]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Knowles]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
<name>
<surname><![CDATA[Misra]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
<name>
<surname><![CDATA[Rashid]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Information assurance techniques: Perceived cost effectiveness.]]></article-title>
<source><![CDATA[Computers &amp; Security]]></source>
<year>2016</year>
<volume>60</volume>
<page-range>117-33</page-range></nlm-citation>
</ref>
<ref id="B31">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Thakre]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Bojewar]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
</person-group>
<source><![CDATA[Studying the Effectiveness of Various Tools in Detecting the Protecting Mechanisms Implemented in Web-Applications.]]></source>
<year>2018</year>
<page-range>1316-21</page-range><publisher-name><![CDATA[2018 International Conference on Inventive Research in Computing Applications (ICIRCA]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B32">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Türpe]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Eichler]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
</person-group>
<source><![CDATA[Testing Production Systems Safely: Common Precautions in Penetration Testing.]]></source>
<year>2009</year>
<publisher-name><![CDATA[Practice and Research Techniques]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B33">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Work]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
</person-group>
<source><![CDATA[In wolf's clothing: Complications of threat emulation in contemporary cyber intelligence practice]]></source>
<year>2019</year>
<publisher-name><![CDATA[International Conference on Cyber Security and Protection of Digital Services (Cyber Security)]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B34">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Wu]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Sun]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Huang]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Jia]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
<name>
<surname><![CDATA[Liu]]></surname>
<given-names><![CDATA[L]]></given-names>
</name>
</person-group>
<source><![CDATA[Session-Based Webshell Detection Using Machine Learning in Web Logs]]></source>
<year>2019</year>
<publisher-name><![CDATA[Security and Communication Networks]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B35">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Yin]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
<name>
<surname><![CDATA[Lv]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Zhang]]></surname>
<given-names><![CDATA[F]]></given-names>
</name>
<name>
<surname><![CDATA[Tian]]></surname>
<given-names><![CDATA[Z]]></given-names>
</name>
<name>
<surname><![CDATA[Cui]]></surname>
<given-names><![CDATA[X]]></given-names>
</name>
</person-group>
<source><![CDATA[Study on Advanced Botnet Based on Publicly Available Resources.]]></source>
<year>2018</year>
<publisher-loc><![CDATA[Lille, France ]]></publisher-loc>
<publisher-name><![CDATA[Paper presented at the 20th International Conference, ICICS 2018]]></publisher-name>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
