Defining Common Assessment Settings (Assessment Policy)
107
IBM Proventia Network Enterprise Scanner User Guide, Version 1.3
Use of OS information
Dynamically determine OS if SiteProtector information is
older than
x
(minutes)
The maximum age (in minutes) of usable OS information in
SiteProtector.
If the OS information for an asset is older than the time specified,
Enterprise Scanner reassesses OSID (operating system
identification) when it runs an assessment scan. (See page 171.)
Default:
120
For hosts whose identified OS is uncertain, do the following:
Run all checks (lowest performance)
If Enterprise Scanner is uncertain about the OS of the asset, it
runs all assessment checks.
Run all checks that apply to general OS (intermediate
performance)
If Enterprise Scanner is uncertain about the OS of the asset, it
runs checks for all versions of an operating system. (For example,
if Enterprise Scanner is uncertain about which version a Windows
operating system is, it runs all the checks for all versions of
Windows operating systems.)
Run only checks that apply to specific OS (best performance)
If Enterprise Scanner is uncertain about the OS of the asset, runs
only the checks that apply to the exact version of the operating
system.
Use of Application
Fingerprinting
Do not perform application fingerprinting
Does not try to specifically identify which applications are
communicating over which ports, and runs the checks as selected
in the Assessment policy. This option does not identify
applications communicating over non-standard ports. (Checks are
run against standard ports as defined in the Network Services
policy.)
Fingerprint applications and run checks that apply to
application protocol (e.g., http)
Identifies applications communicating over specific ports, and then
runs checks that apply to the protocol in use. This option identifies
applications communicating over non-standard ports.
Fingerprint applications and run checks that apply to specific
application (e.g., apache)
Identifies applications communicating over specific ports, and then
runs checks that apply only to the application identified. This
option identifies applications communicating over non-standard
ports.
Setting
Description
Summary of Contents for Proventia Network Enterprise
Page 1: ...IBM Internet Security Systems IBM Proventia Network Enterprise Scanner User Guide Version 1 3 ...
Page 8: ...8 Contents IBM Internet Security Systems ...
Page 14: ...Preface 14 IBM Internet Security Systems ...
Page 15: ...Part I Getting Started ...
Page 16: ......
Page 69: ...Part II Configuring Enterprise Vulnerability Protection ...
Page 70: ......
Page 80: ...Chapter 5 Introduction to Enterprise Scanner Policies 80 IBM Internet Security Systems ...
Page 120: ...Chapter 8 Defining Agent Policies 120 IBM Internet Security Systems ...
Page 121: ...Part III Scanning ...
Page 122: ......
Page 134: ...Chapter 9 Understanding Scanning Processes in SiteProtector 134 IBM Internet Security Systems ...
Page 150: ...Chapter 10 Monitoring Scans 150 IBM Internet Security Systems ...
Page 164: ...Chapter 11 Managing Scans 164 IBM Internet Security Systems ...
Page 165: ...Part IV Analysis Tracking and Remediation ...
Page 166: ......
Page 190: ...Chapter 13 Tracking and Remediation 190 IBM Internet Security Systems ...
Page 197: ...Part V Maintenance ...
Page 198: ......
Page 212: ...Chapter 16 Updating Enterprise Scanner 212 IBM Internet Security Systems ...
Page 218: ...Chapter 16 Updating Enterprise Scanner 218 IBM Internet Security Systems ...
Page 224: ...Chapter 16 Updating Enterprise Scanner 224 IBM Internet Security Systems ...
Page 252: ...Chapter 18 Enterprise Scanner Logs and Alerts 252 IBM Internet Security Systems ...
Page 258: ...Glossary 258 IBM Internet Security Systems ...
Page 268: ......