10-12
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 10 Configuring Generic, Solaris, Linux, and Windows Application Hosts
Define Vulnerability Assessment Information
Step 2
Enter the new time interval in seconds. The default value is 300 seconds (five minutes).
Step 3
Click
Submit
.
Define Vulnerability Assessment Information
For each host that you define in MARS, you can specify information about that host that assists MARS
in assessing whether that host is vulnerable to the attacks that MARS detects. For example, you can
identify the operating system running on the host, even providing the latest or nearest patch level. When
an attack is detected that is targeted toward a specific operating system, then MARS can quickly
determine whether the host is running the operating system that is targeted.
For hosts that are defined as the base platform of a reporting device, you should define this information
as part of that device definition.
However, as MARS, it begins to add discovered hosts to the list of hosts under Management > IP
Management. You should periodically review these hosts to update their information if you do not have
a vulnerability assessment software device or service, such as Qualys QualysGuard, running on your
network.
To specify the vulnerability assessment information for a host, follow these steps:
Step 1
To select the desired host, do one of the following:
•
Select
Management > IP Management
, select the check box next to the desired host, and click
Edit
.
•
Select
Admin >
Security and Monitor Devices
, select the check box next to the desired host, and
click
Edit
.
Step 2
Click the
Vulnerability Assessment Info
tab.