Question

how a scanner might be used to compile information about a network in conjunction with CVE...

how a scanner might be used to compile information about a network in conjunction with CVE information for identifying weak spots in network security.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Network scanning is a process used to recognize available TCP and UDP network services running on targeted systems, in finding filtering systems between user and targeted systems and in determining operating systems in use by analyzing their IP responses.

A Network scanner is a software tool that is used to scan the entire network for all possible security vulnerabilities ( Password strength, Open ports, Scripts , Operating system controls ) and threats, to diagnose and repair these security problems in networking environments. It scans, analyzes and evaluates the security strength of underlying network. Scanner is primarily used by network administrators to evaluate a network's security. . Scanner can scan any devices like Routers, Servers, Firewalls, Client computers. Most scanners after analysis provide reporting feature that reports - IT assets, Associated vulnerabilities, Prioritized threats, Percentage of risk vulnerability.

Common Vulnerabilities and Exposures(CVE) is a collection of known security threats. The collection is sponsored by the United States Department of Homeland Security(DHS), and here threats are divided in to two categories:

(i) Vulnerabilities: It is a mistake in software code that provides attacker with direct access to a network or system. Example-  allowing attacker to act as system administrator who has full rights on the code.

(ii) Exposures: It is a mistake in software code that provides attacker with indirect access to a network or system. Example- allowing attacker to secretly gather customer information that could be sold.

-----------------

  • By this, we say that scanner discovers security weak points (where vulnerabilities and threats present or may occur) on our network before intruders exploit them and allows us to automatically compile an inventory of networking devices on our network with the help of CVE information which is a dictionary of publicly disclosed cyber security vulnerabilities and exposures that is free to search, use, and incorporate in to products and services per the terms of use.
  • By using this CVE ,the Scanner identifies vulnerabilities associated with network services. It then compiles a list of discovered vulnerabilities and displays them in a grid like structure.
  • After this, it makes a HTML document file. It is a well-documented report. It gives a descriptive solution for vulnerability, which is(are) detected.
Add a comment
Know the answer?
Add Answer to:
how a scanner might be used to compile information about a network in conjunction with CVE...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT