02:10 PM
Connect Directly

Vulnerability Scanning Do's And Don'ts

Legacy hardware, software, traffic patterns among critical vulnerability scanner considerations

In vulnerability assessment scanning, preparation and planning can make the difference between an accurate and illuminating scan and a big IT headache. Failure to account for and accommodate legacy hardware and software, port management strategies, traffic patterns, and usage schedules can all contribute to a vulnerability scan that has the potential for causing as many problems as it identifies.

Yet the sheer variety of easy-to-install, point-and-click vulnerability scanners on both the commercial and free open-source markets that has helped make vulnerability scanning a near-ubiquitous tool for security-conscious businesses could itself contribute to a false sense of security and system safety when launching a scanner for the first time.

"Today's scanners are generally delivered with the best generic settings for most environments they'll be used in," says security consultant Chris Nickerson. Even so, a business isn't a generic commodity, he says.

That is why leading scanners include customization and tweaking tools, as well as plug-ins and add-ons that enable you to craft and tailor your vulnerability scan for your business' specific nature and operations. Tenable's Nessus, for instance, has more than 36,000 plug-ins.

That nature might well include legacy hardware and, in some industries (financial services, for example), lots of legacy hardware. Approaching big iron, a z/OS, or AS400 box, for instance, with a vulnerability scan calls for caution, lest the scan collide with the legacy machine's own approaches to port management and binding.

The consequences of such collisions can include connection hang-ups while waiting for responses, ports hanging up while waiting for connections, and, worst case, system crashes. In a post about new challenges that cloud computing brings to vulnerability assessment, security blogger Craig Balding offered this observation applicable to all vulnerability assessment tools: "If the scanning policy includes Denial of Service checks or the scanning engine is configured with 'aggressive' settings; e.g. connection entries in firewall state tables get exhausted. It's also possible for scans to tickle obscure bugs in the target -- or devices en route to the target."

The solution? Take it slow and take one (or a few) step at a time, particularly when launching vulnerability scans or a new scanner for the first time.

"Segment your risk," Nickerson advises. "Test and tune the scanner for the environment it will be used in and tackle the scan surgically, rather than a shotgun, all-at-once approach. If the default out-of-the-box scan tests 24 hosts at a time, try it with five hosts firsts. Break your hosts into manageable and actionable boxes before turning loose the hounds."

Steve Stasiukonis, founder and vice president of Secure Network Technologies, recommends setting up closed, test-bed environments if possible or practicable. "If you're aware of the potential harm an untested scan can create, you can easily see the benefit of running the scan first against a system that's not involved in business production," he says.

Likewise, critical business traffic and traffic patterns need to be factored into vulnerability scans because the scan itself will add to network traffic. The scan needs to be scheduled for minimal traffic impact, so don't launch a major scan of retail servers at the height of the holiday purchasing rush.

"Even without a full-on outage, poorly configured scans can still negatively impact performance or availability for other customers of shared infrastructure," Balding observed in his blog.

Understanding the nature of the business, the business' traffic patterns, and, crucially, communicating and coordinating with key business personnel are all keys to both an effective and nondisruptive vulnerability scan.

Scans and their effects are liable to set off alarms and key-person notifications. "Give some thought to what time your scans will be run and also to what time zone affected businesses operate in," Stasiukonis says. "Don't surprise someone on the West Coast with a 5 a.m. alert that you scheduled to run at 8 a.m. on the East Coast."

All of these considerations need to be factored in not only before launching a scan, but also before selecting the scanner you'll be launching.

The integration of vulnerability assessment scanning with penetration testing and other security tools will likely be accompanied by further refinements of interfaces, dashboards, and ease-of-use considerations.

And that is all for the good, so long as you bear in mind that the ease-of-use tools for major vulnerability include a wide array of customizations and add-ins.

"Use them," Nickerson says. "And use them before buying a scanning tool. Test the various scanners you're considering, and test them against the environment they'll be scanning. Make sure that the scanner you choose is the right tool for the environment you're choosing it for."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2014-10-24
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.4.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

Published: 2014-10-24 in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Published: 2014-10-24
WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.

Published: 2014-10-24
Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response with a large nonce2 length, then triggering the overflow with a mining.notify request.

Published: 2014-10-24
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) and (2), which allows local users to execute arbitrary Perl code by modifying these files.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.