Auditing Tools: Scan the Scanner
There are a number of vulnerability assessment tools available on the block. The options you choose could determine what you end up with. If you like to work in a GUI environment then you may end up with a commercial product. If you like programming and command line then you may as well download open source products and tweak it to your objectives.Full scans can generate a lengthy report of 1000 pages or so. Analyzing that would be difficult. Manage the scans to suit your most immediate need. Also find out if the scanner gives updates to its ‘what to scan?’ database. Look up http://www.sans.org for more details on scans. Some products are given below.
Free
- MBSA- Microsoft Baseline Security Analyzer
- Nessus
- NMap
Comercial
- Preventsys
- Foundstone professional
- ‘eEye Retina’
- SAINT
- MBSA-Just checks the operating system to see if it has installed all the software patches and fixes all the bugs in system and application software like Windows operating systems, Internet Information Server (IIS), SQL Server, Exchange Server, Internet Explorer, Windows Media Player and Microsoft Office products. It also notifies weak and missing passwords and other insecurities. When new packs and patches are available it notifies the user.
- Nessus is open source and runs on Linux/Unix. There is also a Windows graphical front end (Win 32 GUI client) available. The advantage is that you can create your own plugins for tests. Also available is a host of third party tools that you may want to purchase for better functionality and reporting. One example is lighting from Tenable.
- Nmap is also a freeware and is adopted by many in the security community. It has flexibility and can powerful scanning ability. It has both command line and GUI versions and you could download the source as well as the documentation for use.
- Preventsys uses XML at its core and can also include a wireless module that analyzes wireless infrastructure. It has a strong centralized control point for vulnerability analysis and reporting.
- Foundstone professional deals with enterprise security systems and its security risk assessment product is a managed security solution. The product runs its scan from the McAfee scan centre.
- eEye Retina is a product for security risk assessment and project risk management and registry scans as well. Its scans can be conducted without administrative rights and incorporates up to date vulnerabilities.
- SAINT- Security Administrator’s Integrated Network Tool complies with government rules such as FISMA, GLBA, COPPA, etc…It has a GUI and is easy and fast.
- According to reviews, the management and the reporting of scan results was better in Foundstone and Retina. The Vulnerability detection was better in SAINT and Nessus.
Related Articles
Can You Find Out who is Intruding Your PC?Effective Tips: Prevent Network Attacks with Firewalls
Top Network Security Products
Hacking and Network Security
Effective Preventive solutions Network security includes the process of securing private and official data under authentic access control preventing system virus and hackers from attacking them.
Vulnerability Assessment
Intrusion Prevention
Firewall and Security
Network Security Solutions
Hacking Port Scanners
Tools and Standards
Network Tools
Network security includes the process of securing private and official data under authentic access control preventing system virus and hackers from attacking them.
![]()
Security Standard by IETF
Network Security Websites
Business Network policy
Network Security
Networking field take account of necessities and strategy that are followed by network administrators to monitor unauthorized access over computer network resources.
Computer Security Breach
Network Security and OS
Linux Network Security
Home Network Security
Wireless Network Security
Security systems over enterprise network cover wide-ranged strategies that help to guard the network beside possible threats on system hacks and cracks.
Spy BOT
Advantages of Honey Pots
Unified Threat Management
Information Security Policy
Denial Of Service
Haven´t found the article you are looking for, please suggest your article. We value all your suggestions and comments.
Suggest
Home
Sitemap
Privacy Policy
Contact Us
Disclaimer
Copyrights
©Copyright 2011 securingmynetwork.com All rights reserved. Read legal policy and privacy policy.
