Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 2002

Network Vulnerability Scanners


RSS
Subscribe to Windows IT Pro | See More Products / Software Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
SideBar    Nessus: An Open-Source Option

Put yourself on equal ground with potential intruders

Slowly but surely, organizations are paying more attention to the security of their networks. As complex as it is crucial, network security typically warrants the attention of a dedicated specialist. However, economic reality forces many companies to add network security to the responsibilities that busy network and systems administrators already shoulder. If you're in this situation, you might be wondering how to maintain security in an environment in which new threats evolve so quickly.

A useful tool that can substantially ease your burden is a network-based vulnerability scanner. This type of scanner uses the network to actively probe other devices and discover security holes. The scanner typically resides on one host, from which it launches probes, collects results, and compares the results with a database of vulnerability fingerprints. In this sense, a vulnerability scanner is similar in function to a virus scanner. A host-based vulnerability scanner's capabilities, however, are more sophisticated and the tool is more introspective, determining whether the host on which it resides complies with established security policy.

From a fairly crowded field of competitors, I looked at three products for scanning heterogeneous networks. These three products were Internet Security Systems' (ISS's) Internet Scanner 6.2, Network Associates' Distributed CyberCop Scanner 2.0 (a new release based on the older CyberCop Scanner 5.5), and Symantec's NetRecon 3.5.

Determining Value
The cost of most commercial vulnerability scanners is substantial. However, you must weigh the purchase price against the potential damage that a compromised network can cause. (You can also find some effective public-domain vulnerability scanners on the Web. For information about one such solution, see the sidebar "Nessus: An Open-Source Option," page 54.)

The first casualties of a successful attack are a company's data, uptime, and reputation. With those concerns in mind, consider the benefits of a vulnerability scanner:

  • A vulnerability scanner puts you on even footing with potential intruders. Tools that are functionally equivalent to those that intruders use reveal the same vulnerabilities that intruders recognize and exploit.
  • A vulnerability scanner answers the what, where, and how of your network's security vulnerabilities. You discover what the threat is, where it's located, and how you can fix it. (Answers to who and when are better suited to other tools, such as intrusion-detection utilities.) You also need to consider the tool's educational benefit. Good vulnerability scanners provide ample documentation about each vulnerability's nature, as well as links to Web sites that offer further information and fixes. You'll learn a great deal about security as you discover and repair system vulnerabilities. After you're familiar with the pattern of security vulnerabilities, you'll find yourself incorporating your security practices into other areas.
  • A vulnerability scanner can help you stay up-to-date on security threats and countermeasures. You'll quickly learn that the flow of new security information on the Web is overwhelming. (For a list of essential security Web sites, see Michael Otey, Top 10, "Security Resources on the Web," November 2001, InstantDoc ID 22556.) The available information increases almost exponentially with each additional network OS you support. To counter this trend, most vulnerability scanners provide a mechanism for regularly updating their vulnerability databases. If the scanner offers any level of automation, you'll be able to reduce the administrative burden of staying current with new security threats, as long as the vendor supplies timely, reliable updates.

Into the Lab
I used several networks and hosts to test the products. I approached the testing from the point of view of an average administrator and used testing criteria based on the value propositions I described earlier. I looked at how well each product discovered and enumerated the what and where of my networks' vulnerabilities and whether the product provided the how of fixing vulnerabilities. I also considered how easy each product was to set up, use, and maintain.

Each product's ease of installation and setup depended on its architecture. As Figure 1 shows, network-based vulnerability scanners generally comprise a scan engine, a vulnerability database, a results database, and an administrative console. Both Internet Scanner and NetRecon install these components on one host, and both products use the Microsoft Jet database engine and Microsoft Access databases to store scan results. This type of combined architecture gives you the advantage of an easy installation. I had NetRecon and Internet Scanner installed and running in minutes. However, such products can create administrative hurdles in large organizations that need to distribute the product across many networks yet maintain central control.

Network Associates has designed CyberCop's architecture for scalability and central administration. The core of CyberCop is a robust scan engine that you can distribute to hosts across your enterprise. For optimal scanning results, the company recommends placing a scan engine on each subnet. The database can use either Microsoft Data Engine (MSDE) or Microsoft SQL Server 7.0 and gives you the flexibility of single or multiple databases that can be centralized or distributed. MSDE is available on the CyberCop CD-ROM.

   Previous  [1]  2  3  4  Next 


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Microsoft Kills OneCare, Will Launch Free Security Solution

Microsoft on Tuesday announced that it would retire its $50-a-year security subscription product, Windows Live OneCare, and replace it with a free solution codenamed "Morro." Unlike OneCare, however, Morro will focus only on core anti-malware features and ...

The website is down because someone removed the X-Box

What happens when a manager mistakes a server for a games console. ...

Xbox 360 Overhaul Arrives with New UI, Avatars

Xbox 360 owners who logon to the system's Xbox Live system this morning will receive the most significant functional change yet to the console's user interface, or dashboard. Dubbed the New Xbox Experience, this new front-end features a completely new ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing