BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Call it Genius. Our Smart Groups Make Vulnerability Management Simple for Security Teams

Posted April 20, 2012    Morey Haber

eEye R&D has been hard at work on optimizing how our enterprise clients can manage and schedule assessments within Retina CS. These efforts will increase the efficiency of how our clients perform assessments across their IT infrastructure – be it their traditional server or desktop assets, or new technologies like mobile, virtual and cloud.

In a typical environment, regardless of vulnerability management tool, scan jobs are typically performed against a range of assets, address groups, or some other type of device collection or site location. If assessments are required across multiple groups, typically the user has to schedule multiple jobs or build containers that contain all of the corporate assets. Scanning these large groups can take a long time, be potentially too large for a single scan engine to process in one job, and produce a report (if it doesn’t time-out or crash first) that is tens of thousands of pages long. It is not common for a company with over 100,000 assets to truly scan all their devices. They just do not have the scanning infrastructure, manpower to schedule all the jobs, and personnel to handle the plethora of data. This is where eEye differs and excels in meeting enterprise vulnerability and threat management.

Retina CS employs called Smart Groups to build a collection of assets. These can be anything from address groups, to patterns contained in host-names, Active Directory queries, and even what software was detected on a host during previous scans. Smart Groups can also be built as parent objects referencing Child Groups. That is, the parent group can reference other Smart Groups and build a super set of all the data for role based access, alerting, and now job scheduling and reporting. If you’ve ever used the Smart Playlist function in iTunes, you’re already trained on how to build Smart Groups within Retina CS.

Consider an environment that has Smart Groups for locations or even business units. These are typically deployed as Smart Groups referencing the city, building, or business function. If you build a new group at the higher level that references all of these children by state, campus, or even business division then you have create a new logical parent. In Retina CS, you can now schedule a job at the parent level that will automatically be distributed to all children and honor key Smart Group settings like Scanner Locking or round robin scanner pooling for load balancing and rapid assessment of large IP ranges using multiple scanners simultaneously.

In terms of enterprise job scheduling, once the parent is built, it only takes 4 mouse clicks (yes, 4) in the Retina CS UI to perform and assess across the entire enterprise using distributed scan engines, scan pools, and fixed scanners that are dedicate to specific address spaces or locations! And, using Retina Insight, our unique Heat Maps can reduce the report into a few pages that can tell you which vulnerabilities are causing the highest risks and if mitigated, how your environment would change for the better!

No other solution is taking this approach to enterprise vulnerability management. eEye is the only vendor working to make  job scheduling, reporting, and threat intelligence simple for the IT security team, as well as for executives,  to understand the risks they face.

For more information on how Retina CS can help you today, please contact our sales team at sales@eeye.com. Our customer success engineers would love to show you how the next generation of Threat Management Solutions can solve problems with your enterprise scanning requirements.

Tags:
, , , , , ,

Additional articles

How To Implement The Australian Signals Directorate’s Top 4 Strategies

Posted October 20, 2014    Morey Haber

The Australian Signals Directorate (ASD), also known as the Defence Signals Directorate, has developed a list of strategies to mitigate targeted cyber intrusions. The recommended strategies were developed through ASD’s extensive experience in operational cyber security, including responding to serious security intrusions and performing vulnerability assessments and penetration testing for Australian government agencies. These recommendations…

Tags:
, , , ,
asp-mvc

Exploiting MS14-059 because sometimes XSS is fun, sometimes…

Posted October 17, 2014    BeyondTrust Research Team

This October, Microsoft has provided a security update for System.Web.Mvc.dll which addresses a ‘Security Feature Bypass’. The vulnerability itself is in ASP.NET MVC technology and given its wide adoption we thought we would take a closer look. Referring to the bulletin we can glean a few useful pieces of information: “A cross-site scripting (XSS) vulnerability exists…

Tags:
4bestpracticesaudits-blog

Four Best Practices for Passing Privileged Account Audits

Posted October 16, 2014    Chris Burd

Like most IT organizations, your team may periodically face the “dreaded” task of being audited. Your process for delegating privileged access to desktops, servers, and infrastructure devices is a massive target for the auditor’s microscope. An audit’s findings can have significant implications on technology and business strategy, so it’s critical to make sure you’re prepared…

Tags:
, , , ,