About ScanFi


ScanFi Architecture

To understand how ScanFi keeps your network informed you need to know about the various components in ScanFi vulnerability assessment architecture. The three primary components of ScanFi are :


 

External Vulnerability Aggregator

The External Vulnerability Aggregator resides at the AdventNet site and draws vulnerability information from various security advisories - mainly advisories from the CVE and SecurityFocus websites, bulletins from the Microsoft website, and other vendor specific advisories, through Email and RSS Feeds.

 

Vulnerability and Windows patch information consolidation,  assessment for information authenticity and testing for functional correctness is also carried out by the ScanFi Enterprise Security Team. The final analysis and data are correlated to obtain a consolidated repository of vulnerability information - a vulnerability database,  which serves as a baseline for vulnerability assessment in the enterprise (customer site). The modified vulnerability database is then published to the Central Repository Server for further use. The whole process of information gathering, vulnerability assessment, patch analysis and publishing the latest vulnerability database occurs periodically.

Central Repository Server

The Central Repository Server is a highly secure comprehensive database of all thoroughly analyzed vulnerability and patch information, residing at the AdventNet site. Any update to the Central Repository Server is automatically recognized by the ScanFi server, situated at the customer site.

ScanFi Server

ScanFi Server is located at the enterprise (customer site) and subscribes to the Central Repository Server, to periodically download the vulnerability updates. It performs device discovery and assesses/scans the devices in the heterogeneous enterprise network and lists the open ports, vulnerabilities and  missing patches, and generates reports to effectively manage the vulnerability assessment process in your enterprise. All these actions can be initiated from a universally accessible, web-console in a few simple clicks.

How ScanFi works

Vulnerability Assessment using ScanFi can be broadly considered as a three step process.

Detect

ScanFi discovers all assets on a given network, and provides detailed information, including operating system, IP address, DNS Name, Mac Address and IF Descriptor , of the discovered asset. IT Administrators are provided with a variety of options to customize the discovery of enterprise resources., like using TCP ping or ICMP ping for host discovery, Nmap or SNMP for OS detection.

 

Once the network resources have been discovered scan is performed on open ports for identifying which services or applications are listening in these ports. On identifying the service, tests are run to identify the service specific vulnerabilities and Windows specific missing patches. When a scan is complete, vulnerabilities are displayed in a color-coded list that indicates the severity of each potential problem.

Report

Reports can be generated automatically from ScanFi web-console in HTML formats and exported to PDF formats and even can be e-mailed to any number of recipients in PDF formats. Customization is simple as ScanFi provides report customization templates, whereby report sections can be added, removed or re-ordered. The amount of technical detail can be adjusted, allowing reports to be tailored for any target audience.

 

Not only are ScanFi reports flexible, but they also provide the required vulnerability information efficiently in color-coded and graphical format. 

Remediate

Vulnerability reports contain information to quickly understand what the problem is and provide supporting evidence that the system is vulnerable. You can generate trouble tickets from the ScanFi generated vulnerability notification mails provided you have a Helpdesk system, like ManageEngine ServiceDesk Plus,  in your enterprise which recognizes notification mails generated by ScanFi and converts them to trouble tickets. URL links to vendor advisories and downloadable patches make remediation straightforward.


Copyright © 2005, AdventNet Inc. All Rights Reserved.