|
|||||||||||
|
Re: Distributed Vulnerability Scanners
From: Michael Murray <mmurray(at)ncircle.com>
Date: Fri Mar 07 2003 - 14:30:27 EST -----BEGIN PGP SIGNED MESSAGE-----
Talisker, As far as distributed vulnerability scanners go, I have to throw in a couple of points. One person already mentioned nCircle (which is where I work): we're a totally distributed solution (multiple lightweight appliance-based scanners reporting to a central console that stores all the data for all of the appliances). As well, I'd say that our vulnerability coverage and accuracy is among the best out there. Of course, I may have a bit of a bias... ;) Note that I wouldn't put Nessus in the truly "distributed" model. In my experience, though it uses a client-server model, it really doesn't have a good way to control multiple scanner instances from a single point. (IIRC, Tenable's solution is an attempt to put some sort of way to do that on top of nessus). As well, I have heard that Foundstone's Foundscan product suffers from a similar limitation, but I haven't validated that firsthand. In all seriousness, and bias aside, due to the fact that you can truly distribute scanners throughout the network (regardless of where your data store and reporting interface is) I'd put nCircle's stuff at the top in terms of true distributed scanning... M
On Wednesday 05 March 2003 2:56 pm, Talisker wrote:
iD8DBQE+aPNTUsC8b1YJAp8RAgyLAJoCshqoOK7FX3a1lI3/O6uUPHeB8ACffy77
rZQahtmORPk8PrIqIlibZdQ=
Are your vulnerability scans producing just another report?
Manage the entire remediation process with StillSecure VAM's
Vulnerability Repair Workflow.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:33 EDT |
||||||||||
|
|||||||||||