Information security penetration testing is a technical tool and process to protect network security. The designed course is a tool and method commonly used in the infiltration test process through introduction, description and interaction and practice; learn about the weaknesses (vulnerabilities) and risks of mining organizations, networks, and systems. In turn, we know how to actually check the strength of the network security of the object under test, the current system environment and security status. It also helps to discover known and unknown vulnerabilities in the system. This course is designed to focus on information security related technical issues, with a focus on mining network and system security and vulnerability testing and verification. Twenty-two module courses are planned to learn and train qualified penetration test personnel for the Demonstration Course: 「Network Attack and Defense Technology-Information Security Penetration Testing Technology」.
丁諭祺,詹偉銘,張光宏,周國森,施君熹(2014)。以 WARGAME 型式建立資訊安全攻防演練平台。Communications of the CCISA,20(4),72-83。
Cyber Defense Exercise, https://cdx.nchc.org.tw/
Testbed@TWISC - Network Security Testbed web-site, http://testbed.ncku.edu.tw/
Laih, C. S.,Li, J. S.,Lin, M. J.,Chang, S. H.,Chen, L. D.,Tseng, S. H.,Chang, M.(2008).Development and Operation of Testbed@TWISC.The 3rd Joint Workshop on Information Security(JWIS 2008)
Sood, A.K.,Enbody, R.J(2013).Targeted Cyberattacks: A Superset of Advanced Persistent Threats.IEEE Security & Privacy,11(1),54-61.
林敬皇,盧建同,李忠憲,楊竹星(2012)。網路攻擊與防禦平台之研究與實作。CISC 2012,Taichung, Taiwan:
郭振忠,盧建同,林敬皇,李忠憲,楊竹星(2013)。基於測試平台之網路攻防演練活動設計與實作。NCS 2013,Taiwan: