Vulnerability Assessment
Total Page:16
File Type:pdf, Size:1020Kb
Information Assurance Sixth Edition Tools Tools Report May 2, 2011 Vulnerability Assessment E Distribution Statement A X C E E C L I L V E R N E C S E Approved for public release; distribution is unlimited. I N N I IO NF OR MAT Form Approved REPORT DOCUMENTATION PAGE OMB No. 0704-0188 Public reporting burden for this collection of information is estimated to average 1 hour per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing this collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing this burden to Department of Defense, Washington Headquarters Services, Directorate for Information Operations and Reports (0704-0188), 1215 Jefferson Davis Highway, Suite 1204, Arlington, VA 22202-4302. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number. PLEASE DO NOT RETURN YOUR FORM TO THE ABOVE ADDRESS. 1. REPORT DATE (DD-MM-YYYY) 2. REPORT TYPE 3. DATES COVERED (From - To) 05-02-2011 Report 05-02-2011 4. TITLE AND SUBTITLE 5a. CONTRACT NUMBER SPO700-98-D-4002-0380 Information Assurance Tools Report – Vulnerability Assessment. Sixth Edition 5b. GRANT NUMBER 5c. PROGRAM ELEMENT NUMBER 6. AUTHOR(S) 5d. PROJECT NUMBER Revision by Karen Mercedes Goertzel, with contributions from Theodore Winograd 5e. TASK NUMBER N/A 5f. WORK UNIT NUMBER 7. PERFORMING ORGANIZATION NAME(S) AND ADDRESS(ES) 8. PERFORMING ORGANIZATION REPORT NUMBER ANDIATAC ADDRESS(ES) 13200 Woodland Park Road Herndon, VA 20171 9. SPONSORING / MONITORING AGENCY NAME(S) AND ADDRESS(ES) 10. SPONSOR/MONITOR’S ACRONYM(S) Defense Technical Information Center 8725 John J. Kingman Road, Suite 0944 Fort Belvoir, VA 22060-6218 11. SPONSOR/MONITOR’S REPORT NUMBER(S) 12. DISTRIBUTION / AVAILABILITY STATEMENT A/ Distribution Approved for public release; distribution is unlimited. 13. SUPPLEMENTARY NOTES IATAC is operated by Booz Allen Hamilton, 8283 Greensboro Drive, McLean, VA 22102 14. ABSTRACT This Information Assurance Technology Analysis Center (IATAC) report provides an index of automated vulnerability assessment tools. It summarizes pertinent information, providing users a brief description of available automated vulnerability assessment tools and contact information for each. IATAC does not endorse, recommend, or evaluate the effectiveness of any specific tool. The written descriptions are based solely on vendors’ claims and Security Content Automation Protocol (SCAP) Product Validation Report contents and are intended only to highlight the capabilities and features of each automated vulnerability assessment product. 15. SUBJECT TERMS IATAC Collection, Firewall 16. SECURITY CLASSIFICATION OF: 17. 18. NUMBER 19a. NAME OF RESPONSIBLE PERSON LIMITATION OF PAGES Tyler, Gene OF ABSTRACT a. REPORT b. ABSTRACT c. THIS PAGE None 142 19b. TELEPHONE NUMBER (include area UNCLASSIFIED UNCLASSIFIED UNCLASSIFIED code) 703-984-0775 Standard Form 298 (Rev. 8-98) Prescribed by ANSI Std. Z39.18 Table of Contents SECTION 1 u Introduction . 1 StillSecure® VAM 5.5 ................................39 1.1 Purpose ........................................2 Xacta® IA Manager .................................40 1.2 Report Organization .............................2 ZOHO® ManageEngine® Security Manager Plus 1.3 Scope .........................................3 Network Security Scanner component. .42 1.4 Assumptions ....................................5 Host Scanners Assuria Auditor and Auditor RA ......................43 SECTION 2 u Background . 6 Infiltration Systems Infiltrator for Home Users .........44 2.1 The Role of Vulnerability Assessment Microsoft® Attack Surface Analyzer ..................45 in ICT System Risk Management ..................6 NileSOFT Secuguard SSE ............................46 2.2 How Vulnerability Assessment Tools Work .........6 Numara® Vulnerability Manager. .47 2.3 Standards for Vulnerability Assessment Tools .......8 Proland Protector Plus Windows Vulnerability Scanner ...............................48 SECTION 3 u Vulnerability Analysis Tools . 10 SoftRun Inciter Vulnerability Manager ................49 Network Scanners ThreatGuard® Secutor ..............................50 Beyond Security® Automated Vulnerability Key Resources VAT .................................51 Detection System ...................................14 Database Scanners Black Falcon/Net Security Suite Falcon Application Security AppDetectivePro ................52 Vulnerability Analysis ...............................15 DBAPPSecurity MatriXay 3.6 .........................53 DragonSoft Vulnerability Management ................16 Fortinet FortiDB ....................................54 eEye® Retina® Network .............................17 Imperva® Scuba ....................................55 Fortinet® FortiScan 4.1.0 ............................18 McAfee Repscan and McAfee FuJian RongJi RJ-iTOP ..............................19 Vulnerability Manager for Databases .................56 GFI LANguard® 9.6 .................................20 NGSSecure NGS SQuirreL for DB2, GFI Sunbelt Network Security Inspector Suite 2.0 . .21 SQL Server, Oracle, Informix, Sybase ASE .............57 Global DataGuard® Unified Enterprise Security: Safety-Lab Shadow Database Scanner ...............58 Vulnerability Scanner Module .......................22 Web Application Scanners Greenbone Security Feed and Security Manager 1.4 ...23 Acunetix® Web Vulnerability Scanner .................59 Hangzhou DPtech Scanner1000 ......................24 Casaba Watcher 1.5.1 ..............................60 IBM® Proventia® Network Enterprise Scanner 2.3 ......25 Cenzic® Hailstorm® Enterprise Application Infiltration Systems Infiltrator 2009 ...................26 Risk Controller .....................................61 Inverse Path TPOL .................................27 Cenzic Hailstorm Professional ........................62 Lumension® Scan ...................................28 eEye Retina Web ...................................63 McAfee® Vulnerability Manager. .29 Grabber ...........................................64 nCircle® IP360 ......................................30 Hacktics® Seeker® ..................................65 netVigilance SecureScout® SecureScout HP WebInspect® ...................................66 Easybox 2.0 Scanner ................................31 IBM/Rational® AppScan® Standard, Enterprise, netVigilance SecureScout® (Enterprise Edition) ........32 and Express Editions ................................67 netVigilance SecureScout® (Windows Edition) .........33 Mavutina Netsparker® ..............................68 NGSSecure NGS Typhon III ..........................34 MAYFLOWER Chorizo! Intranet Edition ................69 NileSOFT Secuguard NSE ...........................35 MileSCAN ParosPro Desktop Edition 1.9.12 ............70 NSasoft Nsauditor .................................36 MileSCAN ParosPro Server Edition 1.5.0 ..............71 Safety-Lab Shadow Security Scanner .................37 nCircle WebApp360 .................................72 Security System Analyzer 2.0 Beta. .38 NGSSecure Domino Scan II .........................73 Vulnerability Assessment IA Tools Report – Sixth Edition i NGSSecure OraScan ...............................74 Websecurify ......................................112 Nikto2 2.1.4 ........................................75 Vulnerability Scan Consolidators NOSEC JSky 3.5.1 ...................................76 Atlantic Systems Group Information N-Stalker Web Application Security Assurance Application 3.0 ..........................114 Scanner 2009 ......................................77 Epok® CAULDRON .................................115 NT OBJECTives NTOSpider ..........................78 Prolific Solutions proVM Auditor ....................116 PortSwigger Burp Suite Professional Edition RedSeal® Vulnerability Advisor 4.2 ...................117 Burp Scanner Component ...........................79 Relational Security Rsam® Enterprise Subgraph Vega .....................................80 Governance, Risk, and Compliance: Syhunt Sandcat and Sandcat Pro .....................81 Threat & Vulnerability Management .................118 WATOBO 0.9.5. .82 Skybox® Risk Control ...............................119 Multilevel Scanners Belarc® BelManage: BelSecure Module ..............83 SECTION 4 u Vulnerability Analysis SaaS . 120 Critical Watch FusionVM® Enterprise and FusionVM MSSP ...............................84 SECTION 5 u Information Resources . 123 Imperva® SecureSphere® Discovery 5.1 Books ........................................123 and Assessment Server .............................85 5.2 Online Publications and Other Integrigy AppSentry ................................86 Web-Based Resources .........................123 Jump Network Jabil® Network Vulnerability 5.2.1 Resources on Vulnerability Assessment Assessment System ................................87 Methods and Technology .................124 NSFOCUS Remote Security Assessment System .......88 5.2.2 Source Selection and Open Vulnerability Assessment System 4 ..............89 Acquisition Resources ...................124 SAINT® Professional and SAINT® Enterprise ...........90 SecPoint The Penetrator ............................92 APPENDIX A u Acronyms, Abbreviations,