Solved

vuln scanner performance

Posted on 2011-09-12
6
338 Views
Last Modified: 2012-05-12
Sorry to sound naive but networking and performance arent my area of expertese.
But what advantages are there running a corporate vuln scanner like nessus from a server as opposed to a workstation?
Can you please answer is management speak.
Plus any downsides of isntalling it on a server as opposed to an admins workstation.;
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 11

Expert Comment

by:slemmesmi
ID: 36524287
Dear pma111,

the only reasons for running a vulnerability scanner from a server I can think of off hand, are:

1. A server may/will most likely have higher performing hardware than a PC (e.g. in terms of multiple CPU's/cores, amount of RAM a server can be spec'ed with, disk array for eventual local database).

2. It may be the vulnerability scanner requires a locally installed/running database, based upon a specific database application/software (such as SQL Server), which requires a specific OS (such as Windows Server 2008).

P.S. Nessus is available for (a.o.) both Window PC and Server OS's so that itself doesn't require a "server".

Kind regards,
Soren
0
 
LVL 11

Accepted Solution

by:
slemmesmi earned 500 total points
ID: 36524328
Dear  pma111,

sorry submitted the above before also adding:

3. A "server" in IT perspective is seen as a computer running and delivering services or performing a certain set of services "all the time". In regards of Windows, a Windows PC OS is inherently not designed to function as such, whereas the Windows Server OS' are. Hence "server". Also (following the same track), the IT department will most likely apply a completely different set of maintenance procedures for a "server" than a "PC", e.g. manually installation of software updates (e.g. Microsoft Sercurity Updates) on a "server", rather than automatic installation of such (e.g. through WSUS) on a "PC". Also backup/restore/DRP is a topic for "servers" for sure managed differently than for a "PC".

4. If the vulnerability scanner is running a service which allows (IT security administrators) access to a "webpage" or similar, then it makes much more sense to have such on a server.

Kind regards,
Soren
0
 
LVL 4

Expert Comment

by:artsec
ID: 36533355
The only difference is the system resources. However, you can have a powerful workstation which is much cheaper than an actual server. In addition, you may have some difficulty to use Nessus on Windows server 2003 and 2008 due to the OS configuration and services.

In addition, you should not share a hardware (server) for the vulnerability scanning and other critical services. Further, the security engineers can write exploit codes or import them to the vulnerability scanners. This might be an issue when you have other services running on the same system in terms of information security governance.

I do recommend to use an isolate system with an up-link to the switch.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 11

Expert Comment

by:slemmesmi
ID: 36547817
Dear pma111 and artsec,

please beware that Nessus in the "Nessus 4.4 Installation Guide" pages 8 and 76(http://static.tenable.com/documentation/nessus_4.4_installation_guide.pdf) as well as on the FAQ "Is there a difference in running Nessus Windows on Windows Server (2003) versus Windows XP (Home & Pro)?" (http://www.nessus.org/products/nessus/nessus-faq#anchor56) state:

*quote BEGIN*
For increased performance and scan reliability, it is highly recommended that Nessus Windows be installed on a server product from the Microsoft Windows family such as Windows Server 2003.
Back to Windows Specific FAQ
*quote END*

Kind regards,
Soren
0
 
LVL 3

Author Comment

by:pma111
ID: 36548742
Can you have a portable liscence for nessus, and run it wherever you want.

Say if you were a pen test company and had 20 external clients each with their own network - how would they use that tool then, and how many liscences would they need.

The external customer may not be happy with them installing this tool on one of their corporate servers?

How does it work that way , ie a portable liscence?
0
 
LVL 11

Expert Comment

by:slemmesmi
ID: 36553589
Dear pma111,

Please post that as a new question, as it does not directly relate to the above about performance/server (or simply refer to the Nessus "Deployment options" http://www.nessus.org/products/nessus/deployment-options).

Kind regards,
Soren
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The next five years are sure to bring developments that are just astonishing, and we will continue to try to find the balance between connectivity and security. Here are five major technological developments from the last five years and some predict…
No single Antivirus application (despite claims by manufacturers) will catch or protect you from all Virus / Malware or Spyware threats. That doesn't stop you from further protecting yourself however - and this article is to show you how.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question