Home > Security Tips > Guest Commentary > Trend to ponder: Passive vulnerability assessment
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

GUEST COMMENTARY

Trend to ponder: Passive vulnerability assessment


Jim Reavis, Founder & President, Reavis Consulting Group
12.05.2003
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Passive vulnerability assessment is a fairly new concept, and it will be interesting to see if it takes hold. The idea behind passive vulnerability assessment is that rather than providing proactive probing of networks by generating test traffic, you are inferring the vulnerabilities by sniffing the normal network traffic. So while a traditional network scanner will send a "fingerprint" packet to identify a Web server operating system, passive vulnerability assessment finds the same information in the course of reading normal packets flowing between Web users and the Web server. What are the advantages to passive vulnerability assessment?

Non-intrusive. Network scanning is a necessary function, but can sometimes be downright scary. Testing for flaws can sometimes create unintended consequences, and any experienced pen tester can tell you war stories about locking up a host system or router while doing an assessment. With passive vulnerability assessment you do not add anything visible to a production network and do not have the associated liability.

No service window. Because you are not physically affecting the network, you have much more flexibility in scheduling tests and can run them virtually at all times.

Living VA. It is one thing to be aware of vulnerabilities on your network, it is another thing to put that knowledge in the context of how your network operates and how the traffic flows. Two hosts that look identical on a traditional VA report will look markedly different from the perspective of passive VA if one host receives 1,000 times the traffic of the other. The extra knowledge can only help in making the remediation decisions.

Does passive vulnerability assessment have disadvantages? One huge problem, it is not as accurate as traditional VA, nor can it ever be. It is simply impossible to count on production traffic uncovering all of the potential vulnerabilities lying dormant on a network. A fast moving worm like SQL Slammer, for example, exploited desktop SQL Servers that no one was aware of and that would not have showed up in a passive VA report. Attacks by definition are anomalous events and you may not be able to infer enough of your weaknesses by looking at normal network traffic.

My view is that passive vulnerability assessment and traditional active vulnerability assessment complement each other and will ultimately need to be provided as an integrated solution. VA companies should develop this capability or develop strategic alliances to integrate this functionality into their offerings. Security professionals should be wary of companies that try to position these two approaches against each other and try to make the case that only one or the other is needed. In the long run, the most accurate vulnerability assessment will give you a complete picture of all the network-attached devices and how that network operates as a living entity.

About the author
Jim Reavis is the editor of CSOinformer, a monthly research newsletter focused on emerging information security trends and a service of Reavis Consulting Group. An industry leader in information security research, Reavis Consulting Group provides research and analysis services to solution providers, investor groups and end users.


Also by Jim Reavis…

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Common Vulnerabilities and Prevention Tips
What's your infosec IQ?
IE update clears up spoofing issue
Countdown begins for Mydoom DDoS attacks
Microsoft to disable spoofing syntax in IE
IE flaw could fool users in illicit downloads
Mydoom variant targets security features, Microsoft
Hackers scanning for ports opened by Mydoom
Dangerous, familiar application vulnerabilities top list
Potent Mydoom worm flooding inboxes
Worm opens two backdoors, logs keystrokes

Network Assessment
Penetration testing
Ethical hacking: Ten crucial lessons
Vulnerability scanning with Nessus
Network security monitoring
Security Top 10 Update
Avoiding disaster

Guest Commentary
Google hacking exposes a world of security flaws
Eliminating the threat of spam email attacks
Outsourcing IT services: Is it worth the security risk?
How permanent is your storage solution?
Honeypots can strengthen reconnaissance and lower intrusion noise
Freedom of speech or lack of professional responsibility?
This year compliance, next year control
Senior security member explains his position on Abagnale
Computer Security Institute's leader responds to Abagnale flap
Spokesman or poster child?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts