Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    FoundStone Refines Threat Assessment

    Written by

    Cameron Sturdevant
    Published September 22, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Foundstone Inc.s namesake Foundstone Enterprise 3.0.1 software packs enough punch for even the largest distributed networks, adding threat correlation to Windows host assessments that make shorter work of IT managers vulnerability assessment chores.

      EXECUTIVE SUMMARY
      Foundstone Enterprise 3.0.1

      Using Foundstones updated distributed vulnerability assessment tool, IT managers can now correlate new threats and use customized weighted scores to find security exposures and determine their severity. The initial costs are competitive, and ongoing maintenance is in line with what wed expect for distributed enterprise products.

      KEY PERFORMANCE INDICATORS

      USABILITY

      GOOD

      CAPABILITY

      EXCELLENT

      PERFORMANCE

      GOOD

      INTEROPERABILITY

      GOOD

      MANAGEABILITY

      EXCELLENT

      SCALABILITY

      GOOD

      SECURITY

      GOOD

      • PRO: New security exposures can be correlated to infrastructure without additional asset scans.
      • CON: Remediation procedures are sometimes too general to be of use for specific equipment.

      EVALUATION SHORT LIST
      • Internet Security Systems Inc.s Internet Scanner • The Nessus Projects Nessus • Qualys QualysGuard

      Like competitors such as Qualys Inc.s QualysGuard appliance (see review), it took Foundstone Enterprise 3.0.1 a significant amount of time to scan our test network for vulnerabilities. Although scan time is certainly a factor that IT managers should consider in vulnerability assessment tools, the quality of the scan should weigh far more heavily. In this regard, we believe Foundstone Enterprise, which is based on the companys Foundscan engine, is a top-notch competitor and should be placed on the short list of IT managers at midsize and large enterprises.

      Foundstone Enterprise 3.0.1 with threat correlation capabilities ships early next month and starts at $15,000, which includes the Foundstone FS1000 appliance. The Threat Correlation module is an additional 10 percent of the base software cost.

      Threat correlation is a clever value-add to Foundstone Enterprise, and we used the function to quickly assess systems in the test network. Foundstone takes in security advisories from many sources, including manufacturers such as Microsoft Corp. and Cisco Systems Inc., and creates a bulletin that is made available to Foundstone users. The bulletin explains the vulnerability and, most importantly, allows users to run a check of systems for the exposure.

      In tests, for example, Foundstone Enterprise Threat Correlation found multiple Windows 2000, XP and 2003 systems in our network that were susceptible to a buffer overrun. Microsoft Security Bulletin MS03-039 described the exposure and how to remediate it. Because Foundstone staff had pre-processed the security bulletin and created a threat correlation update to check our systems, it was a snap for us to run a check and identify which systems were at risk.

      There are two reasons why the threat correlation function is so appealing. First is that it made easy work of assessing our IT infrastructure for specific weaknesses without straining the network. We got results with little thought to the load that a full vulnerability scan would impose because the threat correlation bulletin runs against the Foundstone Enterprise database, and not against agents installed on the systems or other network infrastructure devices, such as routers and switches.

      The second reason we liked the threat correlation module is that it does away with most of the work involved in figuring out how to ferret out new weaknesses. Foundstone experts put the threat correlation bulletin together, so we were able to get the update from the Foundstone site and search our IT resources with hardly a second thought.

      All this takes time, however. Even a scan against our relatively small collection—about 25 devices including desktops, routers, switches and a variety of servers running Novell Inc., Red Hat Inc. and Sun Microsystems Inc. operating systems—often took between 3 and 10 minutes, depending on what we were looking for.

      That said, we are becoming less concerned with the length of time it takes a vulnerability assessment system tool to run a scan. We advise IT managers to look closely at the quality of the scan—the number of vulnerabilities found, some kind of ranking of the importance of the vulnerabilities and, increasingly, information about how to remediate the vulnerability.

      In this regard, we liked Foundstone Enterprises remediation center. The built-in ticket center is perfectly fine as a stand-alone break/fix tracking system.

      It can also be integrated with most popular trouble-ticket systems, although this will involve a little help from Foundstone professional services.

      Aside from the usual features, such as opening new tickets and tracking ticket status, we liked the remediation centers ability to ensure that items marked as fixed were easy to check. The “click to check” feature is great for quality control in the remediation process or just as a sanity check for security managers.

      We tested the feature by running a report that showed resolved trouble tickets. After opening an individual ticket, we clicked on the “verify” button, which checked the individual system.

      The ticket system worked reasonably well, but the information about vulnerabilities could stand some improvement.

      For example, the Foundscan vulnerability detection engine correctly identified an SNMP default community name on our WatchGuard Technologies Inc. Firebox V80 firewall appliance. Although the trouble ticket correctly identified the WatchGuard Firebox system in the header, all the remediation information was geared toward correcting the problem if it occurred in a Microsoft operating system.

      Next page: Scoring Points

      Scoring Points

      Clearly laid-out foundstone scores in the refined dashboard made identifying overall trends much easier than in previous versions. These scores can be configured by IT managers to more accurately reflect the importance of specific IT assets by assigning what Foundstone officials call a “criticality multiplier.”

      We think Foundstone has done something good here for IT managers, but the company has also opened the product up for a little mischief, too. During tests, it was possible to doctor the criticality multipliers to make our Foundstone score go down. (In this case, a lower number is better.)

      Fortunately for non-IT executives, Foundstone Enterprise keeps two sets of Foundstone scores: the default set and the customized set.

      In the interest of getting the most accurate assessment, its a good idea to ask for both sets of scores, reflecting a period of at least six months, when evaluating the health of the network.

      Its also a very good idea to base performance pay on the default Foundstone score. Even though a customized Foundstone score is susceptible to being doctored to reflect positively on IT staff, we still think this is a good addition to the product because it allows IT managers to ensure that really critical vulnerabilities get forced to the top of the fix-it list.

      Senior Analyst Cameron Sturdevant can be contacted at cameron_sturdevant@ziffdavis.com.

      Cameron Sturdevant
      Cameron Sturdevant
      Cameron Sturdevant is the executive editor of Enterprise Networking Planet. Prior to ENP, Cameron was technical analyst at PCWeek Labs, starting in 1997. Cameron finished up as the eWEEK Labs Technical Director in 2012. Before his extensive labs tenure Cameron paid his IT dues working in technical support and sales engineering at a software publishing firm . Cameron also spent two years with a database development firm, integrating applications with mainframe legacy programs. Cameron's areas of expertise include virtual and physical IT infrastructure, cloud computing, enterprise networking and mobility. In addition to reviews, Cameron has covered monolithic enterprise management systems throughout their lifecycles, providing the eWEEK reader with all-important history and context. Cameron takes special care in cultivating his IT manager contacts, to ensure that his analysis is grounded in real-world concern. Follow Cameron on Twitter at csturdevant, or reach him by email at cameron.sturdevant@quinstreet.com.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×