Vulnerablility Scanners, Differences Between Passive and Active Vulnerablity

Submitted by: Submitted by

Views: 10

Words: 675

Pages: 3

Category: Science and Technology

Date Submitted: 02/17/2016 07:24 PM

Report This Essay

There are two approaches to network vulnerability scanning, active and passive. The active approach encompasses everything an organization does to foil system breaches, while the passive (or monitoring) approach entails all the ways the organization oversees system security. When making buying decisions for your organization, it's a mistake to think that you have to choose between the two types of protection.

The passive approach allows security personnel to monitor which operating systems are in use; what is being sent to, from and within the system; which services are available; and where parts of the system may be vulnerable to security threats. The active approach, on the other hand, offers much information about system and application vulnerabilities.

Active scanning tools are used where constant vigilance is required. They have a specific area of focus that the product is programmed to monitor. (And they are sometimes configured to prevent particular situations as well, such as the use of USB key chains on a network.) Their core monitoring functionality is generally very rigid and can't be easily customized or extended.

When an organization uses the passive approach in scanning its LAN, the information obtained will normally include data pertaining to the hosts in the network -- which ports are open, which software versions are being maintained and which services are running.

There is a huge potential with passive analysis because it allows you to assess the vulnerability of your software without interfering with the client or server. This technology facilitates IT asset management, since it allows an IT manager to instantly get a list of which users are running vulnerable copies of certain software programs.

When combined with passive vulnerability scanning, an active scan can help provide a more complete picture of the software load-out on client-side systems, as well as on servers. In short, the two types of scanners complement each other....