Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: "Real-time" Vulnerability Assessment |
|---|---|
| Date: | Mon, 30 Aug 2004 08:20:45 -0400 |
Just wanted some feedback from experienced VA experts on this list. What do people think of agent-based real-time VA using nessus? Is anyone aware of any activity regarding the above? Do you think real-time VA is viable?
regards, Samir Kelekar
Hi Samir,
I'm sure there are plenty of different opinions on this topic, but the three that I share are this:
- If you can run an agent on a system, such as nessusd, then you have some sort of credentials which allows you to do this. Given the choice between a network scan and a host level assessment (Nessus can do both) I would choose the host level assessment.
- Since you said 'real-time' along with 'agent-based' I'd like to point out Tenable's passive vulnerability scanner named NeVO. It sniff's network traffic and gives you a list of hosts, ports, who's communication to who and a list of vulnerabilities in a Nessus .nsr style report. Our research folks at Tenable write the plugins for Nessus and as we do this, we make sure to write plugins for NeVO.
- When other folks say 'real-time', in almost all cases, this corresponds to continuous network scanning. Usually folks who do this are scanning for new/missing open ports, new/missing systems or new vulnerabilities. Our Lightning Console can do this, but we really don't recommend for people to continuously port scan or ping sweep their networks and feel that NeVO is a more accurate way to find open ports. Typically, for scans that occur on a daily or weekly basis, we've seen people minimize network impact by only scanning ports less than 1024. This would miss Sasser and many other backdoors and trojans.
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | "Real-time" Vulnerability Assessment, Samir Kelekar |
|---|---|
| Next by Date: | Re: "Real-time" Vulnerability Assessment, Russell Fulton |
| Previous by Thread: | "Real-time" Vulnerability Assessment, Samir Kelekar |
| Next by Thread: | Re: "Real-time" Vulnerability Assessment, Russell Fulton |
| Indexes: | [Date] [Thread] [Top] [All Lists] |