
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 142
ToolsoftheTrade
Toperform an auditagainstthefirewallsystems,weneedthehelpofsomesoftware
tools.Thesetoolscanbeclassifiedintotwocategories:ScanningtoolsandStressTest
tools. Toensureaccurateresults,foreachtypeoftestweuseproductsof identical
naturefrom atleasttwodifferentvendors.Differentresultsetscanthenbe
consolidatedforfurtheranalysis.
Scanners:
n forthediscoveryofnetworkandsystem vulnerabilities
n suitableforbroadscanningatthenetworklevelagainstthefrontlineroutersand
firewalls
Retina(basedonNMAPtechnology)
RetinaisacommercialaudittoolbasedontheNMAPtechnology.
“Acknowledgedasthefastestvulnerabilityassessmentscanneronthemarkettoday,
Retinaisdesignedscananymachineonaninternet,intranet,orextranetnetworkin
ordertoidentifyexistingvulnerabilitiesandcheckadherenceofestablishedsecurity
policies.Retinaprovideshelponfixingidentifiedvulnerabilities,andproducesa
Thisisespeciallytrueforscanning.Differentscannersusedifferent
technologiesandtargetportlists,whichforsurewilldeliverdifferentresults.
Onemightarguethatsuchdisagreementinresultscanbeminimizedby
instructingthescannertoscanthrougheverysingleport.Suchstrategyis
technicallypossible,butisextremelytimeconsumingandisnotpracticalin
oursituation.
Comentários a estes Manuais