Jul 2026· DMPedia Lecture Notes in Computer Science & Engineering· 1 citation· 1 references
TL;DR
This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.
Abstract
Cybersecurity has emerged as a key issue in contemporary computing environments due to an increasing dependence on digital systems and networked infrastructures. By discovering and exploiting vulnerabilities in a controlled and ethical manner, penetration testing has become an essential method for evaluating system security. Reducing cyber risks helps organisations assess their security posture, identify potential vulnerabilities, and implement appropriate defences. This review paper offers a comprehensive overview of the current literature on penetration testing, covering its methodologies, tools, frameworks, and applications across diverse areas, including network security, web application security, and enterprise systems. This study includes findings from various research projects, focusing on the efficacy of both manual and automated testing methodologies, including the application of structured frameworks, vulnerability scanning tools, and exploitation platforms. It also examines how standardised guidelines and methods can ensure that security assessments are systematic and reliable. The review goes into more detail on important topics, such as common attack methods (e.g., man-in-the-middle attacks, packet sniffing, SQL injection, cross-site scripting, and cross-site request forgery), and how to protect against them. It also points out how important automation and ongoing security assessment are becoming for making penetration testing more accurate and efficient. This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk. The paper concludes by highlighting the need for structured, thorough penetration testing and advocating further research into advanced, automated security testing to address new cyber threats.
It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.
S. Banu, H. Shanmatha, Mehdi Gheisari et al.· BOHR International Journal o...· 0 citations
Cloud is the essential component for modern computer systems, offering businesses flexible scalability and on-demand resources. However, as attackers use more complex techniques to compromise cloud networks, this technological advancement has ushered in a new era of cybersecurity challenges. Wide-ranging effects, such as data loss, financial penalties, reputational harm, and legal responsibilities, can result from such breaches. In response to these challenges, a strong security framework is essential to effectively protect cloud infrastructure. Recently, several artificial intelligence (AI) techniques have been developed for cyber threat detection. Hence, to get deeper insight into this, the survey aims to analyse the role of cyber threat detection techniques and provide an overview of their applications. To achieve this, around 28 research papers from the years 2023-2026 are reviewed based on their methods, algorithms, datasets, performance metrics, and achievements. Furthermore, this work reviews different types of threats affecting the availability, confidentiality, and integrity of cloud services and resources, and examines the applications, including intrusion detection in cloud and several types of cyber threat detection systems. The core insights formulated in this review provide a comparison of analytics as well as future directions.
Pradnya Patil, J. Bakal· 2026 7th International Confe...· 0 citations
Some operational and technical challenges that affect the adoption of effective cybersecurity prac-tices within e-government infrastructures are identified and the importance of scalable, cost-effective, and integrated monitoring infrastructures to manage cybersecurity proactively in developing countries are highlighted.
Lukumba Phiri, Steve Muwowo· International Journal of Ele...· 0 citations
The purpose of the work is to systematize modern threats to information security in corporate networks, analyze methods for their identification and neutralization, as well as identify promising areas for the development of security systems.
Maxim M. Panfilov, Rasul A. Vagapov· EKONOMIKA I UPRAVLENIE: PROB...· 0 citations
Computer-based testing (CBT) platforms have transformed education and certification by enabling scalable, efficient, and accessible examinations. However, these systems face significant cybersecurity risks, including unauthorized access, denial-of-service (DoS) attacks, and digital cheating, which threaten fairness and reliability. This study proposes a network-based security information system (NBSIS) designed specifically for CBT environments. The framework integrates layered defense, including pfSense firewalls (FW), Snort intrusion detection, Splunk security information and event management (SIEM), and artificial intelligence (AI)-powered analytics, into a unified architecture. A human-centered dashboard ensures usability for non-technical exam administrators, providing real-time alerts and intuitive controls. Validation through simulated attack scenarios demonstrated strong resilience, with high detection accuracy, reduced false positives, and rapid response times. Comparative analysis against intrusion detection system (IDS)-only and SIEM-only systems confirmed superior performance. The findings highlight NBSIS as a robust, scalable, and adaptive solution that safeguards exam integrity while remaining practical for diverse organizational contexts. This research contributes to computer science by advancing secure architecture, applying AI-driven anomaly detection, and integrating human-computer interaction principles into cybersecurity for education.
A novel Artificial Intelligence (AI)-enabled automated conceptual framework, AutoAIPenTest, is proposed that integrates machine learning, reinforcement learning, and large language models to perform intelligent, real-time security assessments in dynamic IoT ecosystems.