Friday, November 13, 2009

Get to know your network -- where ever it is

Skybox, Redseal, Cauldron are examples of Enterprise Risk Modeling (ERM) vendors. The tools filter noise, prioritize actions and put the attention on relevant exposures. Here is vulnerability reduction use-case:

Overlay the vulnerability results for a subnet or a set of host machines with a network scan. Then visualize the network topology instead of using VISIO diagrams. It is then easier to zoom in and group zones and classify hot-spots. You can track a SQL Injection vulnerability to inform remediation decisions such as applying a software patch. Cartography of the network is akin to a Google Map. You can spot quick wins such as an expansion of vulnerability scanning coverage. Another type of improvement can be to reduce or avoid false positives. You can look at a high vulnerability score’s and determine whether it will cascade into a worse problem. Finally visualization is a powerful way to present and communicate data in a meaningful way to the right audience. A picture speaks a thousand words.

What you can do with these tools, depend on what you feed it. You can automate firewall and network access compliance. You can inventory assets. You can grab vulnerability data.

    No comments:

    Post a Comment