I use Nessus to periodically scan 4000+ systems then load the results into a database. The database also holds information about departmental responsibility for computer systems. I have established a network of security contacts in departments and a tool that allows departmental contacts to access the Nessus results relating only to systems for which they are responsible. They are able to, for example, select vulnerabilities with risk factor high or above for priority attention. The main problem I face is caused by the way plug-ins are, in my opinion, loosely classified by risk class and factor. I want my departmental contacts to feel enthusiastic towards using Nessus results and that would be helped greatly if the risk classification system of the plug-ins was more helpful. I don't want departmental contacts to get put off looking at the Nessus results because of having to investigate many incorrect "high risk vulnerabilities". In my opinion we should have these categories (plug-ins found to be in the wrong category should be moved):
i) plug-ins that show that a system has already been exploited (as reliably as is reasonably possible). ii) plug-ins that can definitely prove a vulnerability exists (as reliably as is reasonably possible). iii) plug-ins that show where a system has the potential for a vulnerability that needs to be investigated further. iv) plug-ins that provide supporting information that does not in itself indicate any action need or can be taken. I know that initial classification is difficult but with sufficient people providing feedback it would not take too long to get plug-ins classified as above. Those with a lot of systems to check out could then prioritise their investigations better. -- Carl Nelson Distributed Systems Support Section, Computer Centre, University of Leicester, Leicester, LE1 7RH, U.K. Tel: +44 (0)116 252 2060, Fax: +44 (0)116 252 5027 _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
