Re: SIM questions.



Ray,
You can enhance the capabilities of a SIM by feeding vulnerability
information to that SIM especially if you properly correlate IDS and
server logs with vulnerability information.

Eg:

Target is vulnerable on port 80
Attack Detect on Port 80
System log generated on port 80
Application Firewall Event on port 80

4 hits in one event instead of one event per hit. :)

Regards,
Adriel T. Desautels
Chief Technology Officer
Netragard, LLC.
Office : 617-934-0269
Mobile : 617-633-3821
http://www.linkedin.com/pub/1/118/a45

Join the Netragard, LLC. Linked In Group:
http://www.linkedin.com/e/gis/48683/0B98E1705142

---------------------------------------------------------------
Netragard, LLC - http://www.netragard.com - "We make IT Safe"
Penetration Testing, Vulnerability Assessments, Website Security

Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j
Three Things you must know : http://tinyurl.com/26pjsn


Ray Van Dolson wrote:
Hi all. Currently we make use of Nessus extensively for security
scanning. I'm evaluating Tenable's Security Center to make managing
these scans easier, but am curious how an SIM would fit into this.

Would something like Symantec's SIM *replace* Nessus' active scanning
capabilities? Complement it?

My impression is that the SIM is more of an information aggregator that
helps with your workflow vs actually doing the scanning -- and thus our
Nesuss scanners would still be necessary.

If any of you out there use Nessus + a SIM I'd be interested in hearing
how you've fit these pieces together.

Thanks,
Ray


Relevant Pages

  • Re: Tuning false positives (SIM and VM)
    ... SIMs do offer a lot of functionality beyond simply correlating Vulnerabilty information to IDS/IPS information. ... However, for customers who are using SIM solutions solely to correlate vulnerability and IDS/IPS data, we've simply integrated it into our Server software. ...
    (Focus-IDS)
  • RE: Tuning false positives (SIM and VM)
    ... Network Operations ... Subject: Re: Tuning false positives (SIM and VM) ... >I think you misunderstand what a SIM does with respect to vulnerability ... SIM products loaded with last year's vuln data, ...
    (Focus-IDS)
  • Re: Tuning false positives (SIM and VM)
    ... > 1) I can't even imaging letting my SIM scan the network in such an adhoc> manner. ... I think you misunderstand what a SIM does with respect to vulnerability ... SIM products loaded with last year's vuln data, ...
    (Focus-IDS)
  • Re: Porting a number while overseas
    ... >>> I'm porting a number to Virgin Mobile next week but I'm going to be in ... >>> Canada when it happens. ... i.e. is it going to port OK ... VM state that the SIM ...
    (uk.telecom.mobile)
  • Re: O2 liers...
    ... The way to do it is get a pay as you go sim tell 02 u want to cancel and ... port you number to ur new pay as u go sim, then wait a month and sign up for ... >>>like you made many calls anyway otherwise the real cost of the upgrade ...
    (uk.telecom.mobile)