Telecom Security

Telecom and security are main focus of this blog, where I hope to share my experience, findings and ideas with you. Welcome.

Monday, February 27, 2006

Netclarity's VQS and FirewallBooster

Auditor is a vulnerability management product by Netclarity. It helps security administrators manage vulnerabilities based on its database which is synchonized with CVE remotely. VQS and Firewallbooster are highlights of this product.
/>VQS(Vulnerability Quarantine System) is a sort of clientless (agentless) vulnerability management tech. It uses technology-mapping to identify the OS and applications of the target of protection. If some vulnerabilities of higher priority are found with a host, then it can notify the firewalls (or routers, swithces) to filter out the corresponding networking communication related to those vulnerabilities or even the whole host. Netclarity calls it "Firewallbooster" technology. Although "Firewallbooster" is policy based, I am afraid it will scare the administrators away by high "false positive", especially for those mission critical back-end servers.

Compared with CA's eTrust Vulnerability Manager, Auditor doesn't provide any advantages to the customer, while it lackes auto inventory and built-in risk model.



Pasted from Telecom,Security and P2P.

0 Comments:

Post a Comment

<< Home