Locust is an easy-to-use, distributed, user load testing tool.
for load-testing web sites (or other systems) and figuring out how many concurrent users a system can handle.
to make your scenarios easy-to-read for everyone.
is a free Open Source tool for automated testing of web applications in a very effective way. Look at for a features' overview.
. Each time
GNU/Linux distribution aimed at digital forensics and penetration testing use.
after backtracking, a search algorithm. In March 2013 the BackTrack team later replaced it with a successor product, Kali Linux.
- Security Testing and Vendor Selection with BreakingPoint
Ixia-S-WP-Product-
Review_Ixia
enterprise traffic simulation tool that
helps networking teams ensure their equipment is prime-time ready
helps security teams simulate adversarial attacks
multifaceted tool that provides actionable data for network security testing and infrastructure validation.
BreakingPoint works by simulating traffic aimed at your network appliances and applications.
Because
BreakingPoint initiates the flow of traffic, security teams can measure network saturation and endpoint responsiveness under extreme load
Having the ability
to thoroughly test equipment during a proof-of-concept (
PoC) phase
Integration with a DevOps Continuous Integration (CI)/Continuous Deployment (CD) pipeline can
be handled via the REST API and tweaked via the scripting options built into the device.
The virtual appliance
consists of two OVA files: a virtual blade and a virtual controller.
We deployed the virtual appliance using
VMware ESXi and
proceeded to configure the virtual blades.
Analysts can use
BreakingPoint to test the networking capabilities and capacity of other enterprise appliances by simulating malware,
DDoS, application fuzzing and legitimate
packets.
We spent more than a month with
BreakingPoint, and as our familiarity with the tool increased, we identified three business objectives that use of the tool contributed to:
security assessments, technology/vendor selection and as an agent of change.
businesses
do not typically test for DoS during penetration testing.
We found that
BreakingPoint fits into the vulnerability management and penetration testing area as a complementary assessment too.
“Quick Test” options to explore fuzzing capabilities to test applications and the web application firewall’s (WAF) ability to detect and block malicious traffic.
We wanted to use the tool to send malicious payloads and verify that the target device/application successfully blocked the attacks.
From a security assessment perspective, another use case we wanted to test was leveraging
BreakingPoint to test device patch level or otherwise identify
vulnerable systems. At first blush, it didn’t seem that
BreakingPoint was the right tool for the job
in terms of running
vulnerability scans. Interestingly, however, we used
BreakingPoint to do exactly that, and this is how it works.
Initially setting up
BreakingPoint to identify whether a system is vulnerable to
Heartbleed, for example, is similar
to configuring the tool to tackle any other
type of test: Define the criteria to test for and the targets to test and save
them to easily run future tests. The results of testing provided in Figure 5 quickly showed that the target systems did not, in fact, “pass the test.”
At this point, we had done enough testing to develop a level of confidence that
BreakingPoint can help identify how well a WAF
is tuned and even identify
vulnerable assets not protected by the WAF.
In addition, we wanted to use this tool to perform application simulation for token randomization, brute force attacks,
dynamic file generation and other such attacks to assist with some components of web app pen testing.
we test web applications that are mature and in scope for the likes of PCI or
are otherwise required to
be tested and, conversely, applications
that are
pre-production or in various stages of the software development life cycle.
for new applications, or at least applications
that are not on well-defined networks, we needed
to manually define targets on a case-by-case basis.
This is relevant because it takes tuning the DevOps process to ensure a group of static networks and IPs for consistent testing with
BreakingPoint as
applications moved through the pipeline.
The “Strike List” was a good starting point, but with no matches for Open Web Application Security Project (OWASP) and a multitude of vulnerability-
specific exploit codes, the list was not ideal for session fuzzing, account brute forcing or logic attacks.
Regardless of OWASP not specifically being called out by name in the various strikes, several OWASP Top 10 vulnerability
categories are present and custom strike lists can
be crafted or uploaded.
One of the strong points of
BreakingPoint is that it allows the tester to synthesize real-world traffic and real-world conditions customized to the environment in which the devices will
be operating
.This concept is relevant in situations where a business has identified the need to purchase hardware and has one or more solutions in the
PoC phase actively
deployed on the network
.Most enterprises in a
PoC phase
don’t have the ability to failover a production load to an untested device.
From within the
BreakingPoint interface, we configured a test applicable to what the firewall would encounter in the live
environment and
simply turned up the data rate and configured the “Target Minimum Simultaneous Super Flows” to serve as the criteria to define pass/fail.
Specifically, we wanted to make sure that these database activity monitoring devices
are capable of handling the amount of throughput
currently being gathered in production.
As a rule of thumb, users should determine how much capacity
is needed and then test for at least one and half times that amount.
At this point, we knew by looking at
NetFlow
data and local packet capture information that we could expect a baseline of 300Mbps of raw SQL logs. Thus, we wanted to configure
BreakingPoint to test for this.
There are cases in which traffic is unique, such as proprietary protocols, and you can account for this by using
BreakingPoint’s “re-create” feature, which
essentially allows you to upload a
pcap with the exact traffic you want to simulate, as illustrated
.This complements the built-in options for
sending application- and protocol-specific traffic.
Let’s shift the discussion to measuring the performance impact of turning on SSL “HTTPS Everywhere” or only allowing TLS 1.2 for PCI standards on devices responsible for
the encryption overhead
.we found
BreakingPoint to be close to ideal as a solution to help us understand the performance impact of
enforcing TLS 1.2 across the network.
BreakingPoint can help as an agent of change as part of the DevOps process by verifying that infrastructure changes don’t degrade performance and validating that
new application implementations are ready for production.
there are two primary ways of interacting with
BreakingPoint that lend themselves to DevOps norms
.The first is a RESTful API, which is simple to use and
consists of about two dozen different
tasks that can
be implemented with POST and GET requests
utilizing JSON
.The second is the Enhanced Shell.
- The UI Automator testing framework provides a set of APIs to build UI tests that perform interactions on user apps and system apps. The UI Automator APIs allows you to perform operations such as opening the Settings menu or the app launcher in a test device
https://developer.android.com/training/testing/ui-automator
- Serenity is an Open Source project. Source code is hosted on GitHub, and the binaries are published to JCenter and the Maven Central Repository.
Serenity BDD helps you write better, more effective automated acceptance tests, and use these acceptance tests to produce world-class test reports and living documentation
http://www.thucydides.info/#/
- JUnit 5 is the next generation of JUnit. The goal is to create an up-to-date foundation for developer-side testing on the JVM. This includes focusing on Java 8 and above, as well as enabling many different styles of testing.
https://junit.org/junit5/
- Taurus improves experience of JMeter, Selenium and others.
Automation-friendly framework for Continuous Testing
Taurus tool is an Open Source test automation framework, providing simple YAML-based configuration format with DSL
https://gettaurus.org/
- The main goal for Karma is to bring a productive testing environment to developers. The environment being one where they don't have to set up loads of configurations, but rather a place where developers can just write the code and get instant feedback from their tests.
https://karma-runner.github.io/latest/index.html
- Robot Framework is a generic test automation framework for acceptance testing and acceptance test-driven development (ATDD). It has easy-to-use tabular test data syntax and it utilizes the keyword-driven testing approach.
http://robotframework.org/