Uppsats

External Threat Assessment and Internal Network Security Evaluation : A Penetration Test and Vulnerability Analysis of IVA’s Internal Infrastructure Against External Threats

Kandidat-uppsats

KTH/Skolan för elektroteknik och datavetenskap (EECS)

Publicerad: 2025

Språk: Engelska

Sammanfattning

This thesis explores the field of cyber security with a focus on external threat assessment and internal network resilience. As digital systems become more central to the daily operations of public and private institutions, understanding how exposed infrastructure can be exploited by external actors is increasingly important. The project addresses the lack of prior structured evaluation of the Royal Swedish Academy of Engineering Sciences’ (IVA) external network surface. As an independent academic institution with a strong public presence, IVA hosts several publicly accessible systems that could pose significant risk if misconfigured or vulnerable. Such assessments are rarely conducted in similar organizations due to resource limitations and operational sensitivities, making this project both novel and suitably challenging for a Bachelor’s thesis. The assessment followed an established penetration testing framework to systematically identify, evaluate, and analyze external exposure points. Manual testing methods were used in combination with standard reconnaissance and scanning tools to map infrastructure, detect vulnerabilities, and understand system behavior without disrupting operations. The DREAD model—assessing Damage, Reproducibility, Exploitability, Affected users, and Discoverability—was applied to qualitatively assess risk and prioritize findings. The results revealed that IVA’s systems are generally well-maintained and resistant to known public vulnerabilities. However, the project identified areas for improvement in external system exposure, security configuration, and overall security posture. These conclusions provide IVA with concrete recommendations to further enhance its security posture, reduce future risk and lay the foundation for further testing. Key takeaways include the importance of minimizing externally exposed services, improving clarity around system configurations, and adopting consistent security hardening practices. However, as this assessment focused solely on externally accessible systems, a comprehensive internal security evaluation is necessary to gain a full understanding of IVA’s overall security posture and uncover risks that may not be visible from the outside. It is also recommended that routine security checks and structured reporting processes be established to maintain visibility over time, track changes, and support continuous improvement. Together, these findings highlight the value of ongoing, layered security assessments as part of a proactive defense strategy.

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.