Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Snort and Nessus Signature |
|---|---|
| Date: | Wed, 21 Sep 2005 10:32:09 -0400 |
At 08:18 PM 9/19/2005, Michael Sierchio wrote:
[stuff deleted]
It would be nice[tm] not to have to perform an asset enumeration by hand -- this, in practice, isn't even possible. Desktop users install software all the time, either intentionally or... and hosts come and go on networks, as do services. So the idea of continuous scanning to perform the task is very appealing. That's one possible use of a vulnerability scanner.
Continuous scanning will help you find some things, but won't find:
- new client software - hosts protected by personal firewalls - off-port services (you want to do continuous scanning for all 65k ports?)
Most organizations also have portions of their network that are off limits to scanning. Over scanning switches, routers, IPSes, .etc can have impact to network performance and take out a number of devices.
This is the big reason we wrote NeVO at Tenable. NeVO gives the same type of data as Nessus, but does it through direct traffic analysis. All of Lightning's vuln/ids correlation (which it does for Cisco, TippingPoint, IntruSheild, ISS, Snort, Dragon, .etc) makes use of Nessus as well as NeVO data. It also makes use of any host-based results from your UNIX or Windows servers if you have credentials.
------------------------------------------------------------------------ Test Your IDS
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Auto-sensing for IPS devices, djmeier |
|---|---|
| Next by Date: | Re: Ossim, Adolfo . |
| Previous by Thread: | Re: Snort and Nessus Signature, Michael Sierchio |
| Next by Thread: | Re: Snort and Nessus Signature, Olaf Gellert |
| Indexes: | [Date] [Thread] [Top] [All Lists] |