home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Security
R E V I E W  
VA Scanners Pinpoint Your Weak Spots

  June 26, 2003
  By Kevin Novak


>> continued from previous page

SAINT 4.3
TOC Issue TOC
Printer Print full article
Printer Print this page
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
Wants & Needs
arrow
Foundstone Enterprise and FoundScan Engine 2.6
arrow
Qualys QualysGuard Intranet Scanner
arrow
Harris Corp. STAT Scanner Professional Edition 5
arrow
eEye Digital Security Retina Network Security Scanner
arrow
Vigilante.com SecureScan NX 2.6.50
arrow
SAINT 4.3
arrow
nCircle Network Security IP360 Vulnerability Management System 5.3
arrow
Other Products Reviewed
arrow
How We Tested
arrow
Web Links
arrow
Report Card

SAINT proved a formidable opponent but unfortunately, like every other scanner, it sails in some areas, sinks in others. SAINT's vulnerability coverage was above average, and its price is right, but we felt the product could be improved on the management and reporting fronts.

Although SAINT takes a bit more know-how than do the products from Foundstone, Qualys and nCircle, it runs over a standard Linux distribution and has the easiest install script we've seen over a Linux command shell. We highly recommend the Express plug-in (www.saintcorporation.com/products/saint_express.html); without it, performing updates is a tedious process. We hope SAINT will build Express into the standard product in the future.

The most annoying problem was with adding IP addresses. You'd think this should be a simple task, but not so: To enter address ranges from multiple subnets, you must pull from a text file. If any address fails, the entire scan fails, but not necessarily right away. On several occasions we had to wait for half an hour before SAINT bombed on one address that we'd entered incorrectly. SAINT would benefit from a more intuitive interface for programming multiple addresses and address blocks.

Although SAINT doesn't offer much in the way of exportable reports, it does provide some well-designed prebuilt reports and lets you create your own. SAINT's reports make extensive use of hyperlinks--letting us jump from an address to an explanation of that entire system and so on; unfortunately, we soon found ourselves lost in the jumps. We believe that a dynamic reporting interface would prove much more efficient than simple hyperlinks. SAINT is a good solution for small-to-midsize organizations, but it doesn't have the aggregation capabilities needed for larger enterprises.


SAINT 4.3, 10 hosts: $639; Class C: $2,495; 500 hosts: $5,195; auditing licenses: $395 to $9,495, SAINT Corp., (800) 596-2006, (301) 656-0521. www.saintcorporation.com


start top  Vigilante.com SecureScan NX 2.6.50 nCircle Network Security IP360 Vulnerability Management System 5.3 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights