blog




  • Essay / Nessus: The Vulnerability Scanner - 630

    In Greek mythology, Nessus was a centaur who was killed by Hercules for attempting to kidnap his beautiful wife. As Nessus lay dying, he convinced Hercules' wife to take his poisoned garment to prevent Hercules from leaving her. It was not long before Hercules' wife presented Hercules with the garment of Nessus, poisoning him so that he would die in torment. Today, Nessus is a popular vulnerability scanner that detects security flaws. It was introduced as an open source project over 13 years ago and later evolved into a commercial product now managed by Tenable Network Security. It is known as one of the best and most used vulnerability scanners in the world, due to its rich feature set and profound benefits. If UMUC is looking for a robust and inexpensive vulnerability scanner solution, Nessus 5.2.1 is definitely the way to go. Since its release in 1998, the Nessus vulnerability scanner has offered a free version for individual users; However, the professional version provides vendor support and access to the latest updates. The professional version also offers compliance checks (PCI, NIST or CIS) and virtualization support. The annual professional license fee is around $1,500, which is very affordable compared to other commercial vulnerability scanners. If UMUC plans to perform vulnerability assessments regularly, it makes sense to go with the professional version, because the free version is seven days behind the professional version and does not include advanced features that could be used to search for policy violations and sensitive data, such as social security numbers. Nessus is an effective and comprehensive vulnerability scanner that provides fewer false positives than many other tools currently available middle of paper......linking compliant security tools. Additionally, Nessus is supported on Windows, Linux/UNIX, and Mac OS X. This helps make it a great all-around tool to use in a mixed client environment. User rights can be set to lock down the types of scans they can perform. If users are more familiar and comfortable with Windows, then they can use the Windows client to run scans. There are no big differences between each specific version, but network scanning performance is much better on Linux/UNIX based systems. With such powerful and comprehensive tools available like Nessus, it's hard to justify spending thousands or tens of thousands of dollars. dollars to implement a vulnerability scanning product. If UMUC is looking for a robust and inexpensive vulnerability scanning solution, Nessus 5.2.1 deserves to be on the shortlist of products to test and consider..