vulnerability scanner
Home > Software Quality Glossary > Definition - vulnerability scanner
EMAIL THIS
Glossary - powered by WhatIs.com
 BROWSE ALPHABETICALLY:    A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #    
Search for: in Full Target Search with Google

vulnerability scanner
A vulnerability scanner is a program that performs the diagnostic phase of a vulnerability analysis,also known as vulnerability assessment. Vulnerability analysis defines,identifies, and classifies the security holes (vulnerabilities) in acomputer, server, network, or communications infrastructure. Inaddition, vulnerability analysis can forecast the effectiveness ofproposed countermeasures, and evaluate how well they work after theyare put into use.

A vulnerability scanner relies on a database that contains allthe information required to check a system for security holes inservices and ports, anomalies in packet construction, and potentialpaths to exploitable programs or scripts. Then the scanner tries toexploit each vulnerability that is discovered. This process issometimes called ethical hacking.

An ideal vulnerability scanner has capabilities such as the following:

  • Maintenance of an up-to-date database of vulnerabilities.
  • Detection of genuine vulnerabilities without an excessive number of false positives.
  • Ability to conduct multiple scans simultaneously.
  • Ability to perform trend analyses and provide clear reports of the results.
  • Recommendations for countermeasures to eliminate discovered vulnerabilities.

If security holes are detected by a vulnerability scanner, a vulnerability disclosuremay be required. The person or organization that discovers thevulnerability, or a responsible industry body such as the ComputerEmergency Readiness Team (CERT), may make the disclosure, sometimesafter alerting the vendor and allowing them a certain amount of time toremedy or mitigate the problem.

Read more about it:
>>  Security Innovation explains how vulnerability scanners work, and compares several existing products.

Last updated on: Jul 04, 2006

WHITE PAPERS  
Implementing a "Smart IPS": IANS Working Knowledge Series™
Sourcefire

A New Affordable Event and Log Management Solution from OpenService to Help with Your Compliance Requirements (Press Release)
OpenService, Inc.

3 Key Components of a Risk-Based Security Plan
Foundstone, Inc.

Exchange Server Disaster Recovery: Planning for the Worst, Hoping for the Best
AppAssure Software

Building Bridges between IT Shops, Legal Teams and Security Staff
Symantec Corporation

>> More White Papers
  WHAT'S NEW
 1. Managing performance in the enterprise
 2. Software testing fundamentals
 3. Learning Guide: Debugging & unit testing
 4. .NET Application Security Learning Guide


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts