How we tested products that analyze networks passively from Sourcefire and Tenable.
We then installed Sourcefire’s Defense Center management system (a dedicated server) and Tenable’s Security Center management console (software on a different Linux-based server). Each management system was linked to the respective passive scanners over the LAN. We configured the Sourcefire IDS sensor to send events to its own Defense Center and to the Tenable Security Center. This let both management consoles see the same set of events at the same time.
Because we were running an early beta version of Sourcefire’s IDS sensor, we had a few false starts, as bugs were worked out of the IDS side. Once Sourcefire handed the reins over to us, however, we started using both systems for a total of six weeks.
Although both products support active scanning, we didn’t let either vendor run active scans on the network.
At the beginning, we took the results of each system and evaluated them for accuracy. Then we tried to tune each system in the way we’d expect a normal network manager to do. For example, we caught PVS making a number of false identifications on our mail servers, so we created a group of the mail servers and told PVS to ignore certain vulnerabilities on those systems. On the other hand, we didn’t go through and hand-edit each vulnerability. Instead, we focused on the highest-priority ones, assuming that most network managers would not have the time or inclination to look at lower priorities.
Although our network had only a few hundred systems on it, we tried to look at each product from the mind-set of a network manager with dozens of subnets and thousands of systems. For example, we assumed much of the detailed information we had about our small network would not be possible in a large network, simply because of the sheer number of systems.
At the end of our test, we revisited the vulnerability and network-device databases that each product had built and again evaluated them for accuracy.
Thanks to Avocent for the loan of an AMX5100 KVM and to VMware for the loan of GSX Server, both used to support this test.
Return to Sourcefire, Tenable tests




