Solved

vuln scanner performance

Posted on 2011-09-12
6
334 Views
Last Modified: 2012-05-12
Sorry to sound naive but networking and performance arent my area of expertese.
But what advantages are there running a corporate vuln scanner like nessus from a server as opposed to a workstation?
Can you please answer is management speak.
Plus any downsides of isntalling it on a server as opposed to an admins workstation.;
0
Comment
Question by:pma111
  • 4
6 Comments
 
LVL 11

Expert Comment

by:slemmesmi
ID: 36524287
Dear pma111,

the only reasons for running a vulnerability scanner from a server I can think of off hand, are:

1. A server may/will most likely have higher performing hardware than a PC (e.g. in terms of multiple CPU's/cores, amount of RAM a server can be spec'ed with, disk array for eventual local database).

2. It may be the vulnerability scanner requires a locally installed/running database, based upon a specific database application/software (such as SQL Server), which requires a specific OS (such as Windows Server 2008).

P.S. Nessus is available for (a.o.) both Window PC and Server OS's so that itself doesn't require a "server".

Kind regards,
Soren
0
 
LVL 11

Accepted Solution

by:
slemmesmi earned 500 total points
ID: 36524328
Dear  pma111,

sorry submitted the above before also adding:

3. A "server" in IT perspective is seen as a computer running and delivering services or performing a certain set of services "all the time". In regards of Windows, a Windows PC OS is inherently not designed to function as such, whereas the Windows Server OS' are. Hence "server". Also (following the same track), the IT department will most likely apply a completely different set of maintenance procedures for a "server" than a "PC", e.g. manually installation of software updates (e.g. Microsoft Sercurity Updates) on a "server", rather than automatic installation of such (e.g. through WSUS) on a "PC". Also backup/restore/DRP is a topic for "servers" for sure managed differently than for a "PC".

4. If the vulnerability scanner is running a service which allows (IT security administrators) access to a "webpage" or similar, then it makes much more sense to have such on a server.

Kind regards,
Soren
0
 
LVL 4

Expert Comment

by:artsec
ID: 36533355
The only difference is the system resources. However, you can have a powerful workstation which is much cheaper than an actual server. In addition, you may have some difficulty to use Nessus on Windows server 2003 and 2008 due to the OS configuration and services.

In addition, you should not share a hardware (server) for the vulnerability scanning and other critical services. Further, the security engineers can write exploit codes or import them to the vulnerability scanners. This might be an issue when you have other services running on the same system in terms of information security governance.

I do recommend to use an isolate system with an up-link to the switch.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 11

Expert Comment

by:slemmesmi
ID: 36547817
Dear pma111 and artsec,

please beware that Nessus in the "Nessus 4.4 Installation Guide" pages 8 and 76(http://static.tenable.com/documentation/nessus_4.4_installation_guide.pdf) as well as on the FAQ "Is there a difference in running Nessus Windows on Windows Server (2003) versus Windows XP (Home & Pro)?" (http://www.nessus.org/products/nessus/nessus-faq#anchor56) state:

*quote BEGIN*
For increased performance and scan reliability, it is highly recommended that Nessus Windows be installed on a server product from the Microsoft Windows family such as Windows Server 2003.
Back to Windows Specific FAQ
*quote END*

Kind regards,
Soren
0
 
LVL 3

Author Comment

by:pma111
ID: 36548742
Can you have a portable liscence for nessus, and run it wherever you want.

Say if you were a pen test company and had 20 external clients each with their own network - how would they use that tool then, and how many liscences would they need.

The external customer may not be happy with them installing this tool on one of their corporate servers?

How does it work that way , ie a portable liscence?
0
 
LVL 11

Expert Comment

by:slemmesmi
ID: 36553589
Dear pma111,

Please post that as a new question, as it does not directly relate to the above about performance/server (or simply refer to the Nessus "Deployment options" http://www.nessus.org/products/nessus/deployment-options).

Kind regards,
Soren
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Join & Write a Comment

If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now