C H A P T E R
9-1
User Guide for Cisco Security MARS Local Controller
78-17020-01
9
Configuring Vulnerability Assessment Devices
Revised: June 19, 2007
Vulnerability assessment (VA) devices provide MARS with valuable information about many of the
possible targets of attacks and threats. They provide information useful for accurately assessing false
positives. This information includes the operating system (OS) running on a host, the patch level of the
OS, the type of applications running on the host, as well as detailed logs about the activities occurring
on that host.
Note
When a vulnerability assessment device is deleted from the MARS web interface, its corresponding
vulnerabilities and open ports are not immediately removed from the MARS database. MARS continues
to use this event information for false positive analysis until a successful vulnerability assessment import
occurs. Upon completion of the new import, the historical event information associated with the deleted
device is removed from the database.
This chapter explains how to bootstrap and add the following VA devices to MARS:
•
Foundstone FoundScan 3.0, page 9-1
•
eEye REM 1.0, page 9-3
•
Qualys QualysGuard Devices, page 9-5
Foundstone FoundScan 3.0
To configure MARS to pull data from FoundScan, you must perform three tasks:
•
Configure Foundstone FoundScan to correlate the required data, ensuring that the data is current.
•
Add the Foundstone FoundScan server to MARS using the web interface.
•
Schedule the interval at which the Foundstone FoundScan server data is pulled by MARS.
This section contains the following topics:
•
Configure FoundScan to Generate Required Data, page 9-2
•
Add and Configure a FoundScan Device in MARS, page 9-2
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...