john_dix
Editor in Chief

Security requires net knowledge

Opinion
Mar 17, 20033 mins

How would you like to be able to close the books on a security audit just like you do a financial audit? That’s the goal of newcomer Preventsys, a San Diego start-up that is just coming out of beta testing with a network auditing and policy assurance tool designed to help companies get a better handle on security.

How would you like to be able to close the books on a security audit just like you do a financial audit? That’s the goal of newcomer Preventsys, a San Diego start-up that is just coming out of beta testing with a network auditing and policy assurance tool designed to help companies get a better handle on security.

Today, of course, a security audit is a largely manual process involving specialists poring over security policies and then spot-checking the network for compliance. Besides being slow and expensive, sampling means the results can be spotty.

While we’ll have to wait to see if Preventsys can make audits faster and less expensive, it does seem to sidestep the sampling problem. Instead of spot-checks, the company’s AudIT Server scans an organization’s entire address space looking for what talks to what, and available services. A 5,000-node network can take a couple of hours to size up, says company co-founder and CTO John Williams.

The AudIT Server includes a harness to integrate popular vulnerability scanners that are used to beat on specific types of resources, looking for known vulnerabilities. Some scanners come with the box, such as the open source Nessus tool that scans for 2,800 vulnerabilities, while Preventsys is developing still others, including one for 802.11 wireless Ethernet networks.

Information harvested by the scanners is correlated and normalized into XML and put in a relational database, and customers can then map policies to it. Policies are developed using the Preventsys Policy Lab and can take into account everything from best practices to government regulations, and specific beliefs about what makes a network sound, Williams says.

For example, a company might want to outlaw FTP on the desktop, or only sanction use of a certain instant-messaging client. Once coded into policy, network scans will turn up exceptions and report them through the Preventsys Management Server.

Williams says the goal is to identify problems before they occur. In the case of the SQL Slammer worm, his tool should have revealed SQL servers exposed to the Internet, and servers not upgraded to prevent this kind of attack.

With the frequency of attacks increasing, potential damage escalating and regulations getting stiffer, it seems inevitable that we’ll have to turn to tools such as those from Preventsys and competitors such as Securify, if only so we can sleep at night.

Targeted at large companies, the Preventsys software costs about $350,000 for a 5,000-node network.