home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Security
R E V I E W  
VA Scanners Pinpoint Your Weak Spots

  June 26, 2003
  By Kevin Novak


>> continued from previous page

Harris Corp. STAT Scanner Professional Edition 5
TOC Issue TOC
Printer Print full article
Printer Print this page
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Wants & Needs
arrow
Foundstone Enterprise and FoundScan Engine 2.6
arrow
Qualys QualysGuard Intranet Scanner
arrow
Harris Corp. STAT Scanner Professional Edition 5
arrow
eEye Digital Security Retina Network Security Scanner
arrow
Vigilante.com SecureScan NX 2.6.50
arrow
SAINT 4.3
arrow
nCircle Network Security IP360 Vulnerability Management System 5.3
arrow
Other Products Reviewed
arrow
How We Tested
arrow
Web Links
arrow
Report Card

Harris is on to something with STAT Scanner--it not only scans a very wide array of vulnerabilities but also incorporates policy/registry checking and remediation. This product lets an administrator set registry, log and user policies that can be manually or automatically updated upon detection.

One area that sets STAT Scanner apart from peers is its noninvasive nature. This product doesn't offer a "safe scan," because it doesn't need it. However, this design is both an asset and a liability. Because there are no unsafe scans available, the risk of target meltdown is almost completely mitigated (we still recommend caution because we did encounter a few application issues); however, this product does require authentication for each and every target, and failure to provide such authentication will result in a tremendous number of false positives and false negatives.

We attempted scanning without any authentication parameters on several hosts; the system simply indicated that the open port might be a Trojan. This could be a serious problem for large organizations, particularly those with varied administrative realms. This limitation hinders the ability to scan a large number of nonsimilar networks without a great deal of intervention and departmental cooperation. Although administrators can create authentication groups and assign those groups usernames and passwords, we still see this as crippling.

Finally, STAT was incapable of assessing our NetWare servers. Although STAT will attempt to assess other system types, it is best-suited for Microsoft and Unix environments.


When it comes to reporting, STAT Scanner offers the widest array of export options we've seen. Out of the box, STAT Scanner results can be exported to .MDB format, with all database tables and even a couple of query tables preformatted for Microsoft Access. There are also several reports to choose from, each of which can be exported into various formats, such as CSV, Excel, Word, Lotus and HTML.

Harris offers STAT Analyzer to complement STAT Scanner. STAT Analyzer uses Ipswich's What'sUpGold for system monitoring and inventory; can execute and control Nessus Vulnerability Scanner and Harris' STAT Scanner; and can import test results from ISS' Internet Security Scanner. The result is a complete report of aggregated data from multiple scanners, likely producing a larger percentage of detected vulnerabilities than any one system alone.

STAT Scanner Professional Edition 5, as tested with a 50-node license and a one-year maintenance license, $1,995. Harris Corp., (888) 725-7828, (321) 727-9100. www.stat.harris.com


start top  Qualys QualysGuard Intranet Scanner eEye Digital Security Retina Network Security Scanner 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights