Re: Medium Scale Scanning Best Practices

From: John Malconian (malcat_private)
Date: Thu Jan 17 2002 - 19:20:15 PST

  • Next message: Troy Davis: "Re: Medium Scale Scanning Best Practices"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <3c441d87.7262.0at_private>
    
    If a commercial product is a viable option for
    you,
    you may want to check out a product called
    IP360 from nCircle.  IP360 consists of dedicated
    scanning devices that continuously scan your
    networks for vulnerabilities at regular intervals
    and report back to a web-based central console. 
    IP360 is kind of a two for one
    deal.  Information specific to vulnerabilities
    detected on your network devices is also sent to
    IP360's dedicated intrusion detection sensors that
    only report attacks against the specific
    vulnerabilities detected by the scanner. The
    premise for this model is essentially a reduction
    in false positives.
    
    I've been the testing the product in a lab
    environment, and
    from what I've seen so far, it seems pretty
    solid.  
    
    good luck,
    
    John
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Fri Jan 18 2002 - 08:39:26 PST