본문 바로가기
  • Home

Design of a Security Vulnerability Analysis and Response Model Based on Automated Penetration Testing for SMEs -A Case Study Using Pentera Core

  • Journal of Internet of Things and Convergence
  • Abbr : JKIOTS
  • 2025, 11(2), pp.179~184
  • Publisher : The Korea Internet of Things Society
  • Research Area : Engineering > Computer Science > Internet Information Processing
  • Received : March 2, 2025
  • Accepted : April 15, 2025
  • Published : April 30, 2025

Keun-Ho Lee 1

1백석대학교 컴퓨터공학부

Accredited

ABSTRACT

Small and medium-sized enterprises(SMEs) often face challenges in conducting effective security assessments due to limitations in security personnel and budget. This study analyzes real-world security vulnerabilities in SMEs using an automated penetration testing solution, Pentera Core. By employing Black Box-based testing, threats such as credential theft, privilege escalation, and ransomware simulation were validated in real time. The results revealed that most organizations failed to comply with basic security practices, such as avoiding password reuse and applying critical patches. Based on these findings, a step-by-step response framework was designed, including risk-based prioritization and revalidation processes. Furthermore, the study proposes a practical security operation model through the adoption of Pentest as a Service(PTaaS). This approach not only enhances the cybersecurity posture of SMEs, but also offers scalability for future adoption in public and financial sectors

Citation status

* References for papers published after 2023 are currently being built.