Q
Problem solve Get help with specific problems with your technologies, process and projects.

Should black-box, white-box testing be used together?

Learn why black-box, white-box testing should be used together when searching for Web application code vulnerabilities.

Should black-box testing and white-box testing be used together? What does black box testing look for that white-box testing doesn't?
Yes, it is ideal that black-box and white-box testing be used together. Using both types of testing will identify more vulnerabilities than one method alone, but many times both are not done because of limited resources.

Black-box testing takes an outsider view of the system, and white-box testing takes an internal view of the sy...

stem.

Black-box testers attempt to affect an application but have no prior knowledge of the system and do not depend on access to source code or knowledge of the system's architecture. Black-box testing looks for vulnerabilities that can be used to gain unauthorized access, denial-of-service, or many other types of attacks. A black-box test can be seen like an external penetration test where the goal is to get access to sensitive data or protected resources.

White-box testers, however, have or are given internal knowledge, potentially access to internal documentation and source code, and other internal resources. While black-box testing attempts to look at vulnerabilities from an attacker's point of view, white-box testing attempts to see threats from a quality assurance perspective. White-box testing validates the code, security functionality, or identifies exploitable vulnerabilities. This can be done with source code analysis tools or manual analysis.

White-box testing might be more acceptable to some organizations because many times black-box testing is performed at the edges of ethical boundaries of the security industry. All black-box testing should be performed by ethical testers that are appropriately engaged with the client and will maintain the confidentially of the results.

Sometimes, though, reformed criminals are recruited to perform black-box testing because they can think like a criminal when trying to find the bugs to exploit for illegitimate access. This is seen as allowing criminals to profit from their crimes, and represents a moral gray area in the information security world.

More details on white- and black-box testing (including gray-box testing) can be found at the Build Security In project by the U.S. Department of Homeland Security and Cigital Inc.

This was last published in May 2010

Dig Deeper on Application attacks (buffer overflows, cross-site scripting)

PRO+

Content

Find more PRO+ content and other member only offers, here.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

-ADS BY GOOGLE

SearchCloudSecurity

SearchNetworking

SearchCIO

SearchEnterpriseDesktop

SearchCloudComputing

ComputerWeekly.com

  • CIO Trends #6: Nordics

    In this e-guide, read how the High North and Baltic Sea collaboration is about to undergo a serious and redefining makeover to ...

  • CIO Trends #6: Middle East

    In this e-guide we look at the role of information technology as the Arabian Gulf commits billions of dollars to building more ...

  • CIO Trends #6: Benelux

    In this e-guide, read about the Netherlands' coalition government's four year plan which includes the term 'cyber' no fewer than ...

Close