I use Nessus to periodically scan 4000+ systems then load the results into a database. 
The database also holds information about departmental responsibility for computer 
systems. I have established a network of security contacts in departments and a tool 
that allows departmental contacts to access the Nessus results relating only to 
systems for which they are responsible. They are able to, for example, select 
vulnerabilities with risk factor high or above for priority attention. The main 
problem I face is caused by the way plug-ins are, in my opinion, loosely classified by 
risk class and factor. I want my departmental contacts to feel enthusiastic towards 
using Nessus results and that would be helped greatly if the risk classification 
system of the plug-ins was more helpful. I don't want departmental contacts to get put 
off looking at the Nessus results because of having to investigate many incorrect 
"high risk vulnerabilities". In my opinion we should have these categories (plug-ins 
found to be in the wrong category should be moved):

i)   plug-ins that show that a system has already been exploited (as reliably as is 
reasonably possible).
ii)  plug-ins that can definitely prove a vulnerability exists (as reliably as is 
reasonably possible).
iii) plug-ins that show where a system has the potential for a vulnerability that 
needs to be investigated further.
iv)  plug-ins that provide supporting information that does not in itself indicate any 
action need or can be taken.

I know that initial classification is difficult but with sufficient people providing 
feedback it would not take too long to get plug-ins classified as above. Those with a 
lot of systems to check out could then prioritise their investigations better.

--
Carl Nelson
Distributed Systems Support Section, Computer Centre,
University of Leicester, Leicester, LE1 7RH, U.K.
Tel: +44 (0)116 252 2060, Fax: +44 (0)116 252 5027
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to