Asset Discovery
Overview
Vulnerability Assessment begins with discovery - of network assets. Asset
Discovery provides an inventory of assets which you desire to be scanned. It involves addition of the resources present in your enterprise
(the servers, workstations, laptops, routers, switches and others) into the
ScanFi enterprise setup for vulnerability assessment. Asset Discovery
provides details such as IP Address, DNS Name, Operating System of all the
network resources that was discovered.
ScanFi provides you with a variety of ways to discover your enterprise
resources by either providing :
-
DNS Name or IP Address
- Select the 'Host[s]' radio button.
- In the text box, type the type the DNS/host names or IP addresses of the network
assets that you would like to discover.
- Multiple assets (can comprise of both Windows and Linux OS) can also be specified here by separating each
asset with a comma.
-
Select the 'Discovery Options'
you would prefer to use, based on your network configuration, for faster
discovery of network assets. By default , all options are selected for
better results.
- Click on 'Discover' button to begin discovery.
- You would see a discovery in progress cycle till all the host are
discovered.
- If ScanFi is not able to resolve any DNS Name, due to the host not being
in network or has been switched off, then it would suitably warn you,
stating "Could not resolve the hosts <host-name>".
[0R]
-
IP Range
- Select the 'IP Range' radio button.
- Enter the range of IP addresses of assets within a particular subnet
that you would like to discover (can comprise of both Windows and Linux OS).
- Select the 'Discovery Options' you would
prefer to use, based on your network configuration, for faster discovery of
network assets. By default , all options are selected for better results.
- Click on 'Discover' button to begin discovery.
- You would see a discovery in progress cycle till all the host are
discovered.
The link Show Discovered Assets : Latest
will list the most recently
discovered assets.
The link Show Discovered Assets : Complete
will list the entire list of assets that where
discovered using ScanFi.
You can delete the discovered assets using the 'Delete' link. Deleting an
asset will result in deletion of its scan result , provided the scanning for the
'to be deleted' asset has been already done.
ScanFi provides you with many options, which can be used to discover your
enterprise assets.
-
Discover host using :
- TCP Ping -
This option is useful in situations where ICMP ping has been disabled in
your enterprise. Refer 'Discovery
and Scan Preferences' section to configure TCP Ping based discovery.
- ICMP Ping -
ICMP Ping checks a remote host for availability. Local hosts should normally respond to ping requests within milliseconds. However, on a very congested network it may take
longer to receive an echo packet from the remote host . If this option has
been selected and ICMP ping has been disabled in your enterprise then
discovery will timeout and it will appear that the remote host is not reachable.
Refer 'Discovery
and Scan Preferences' section to configure ICMP Ping based discovery.
-
Identify Operating System :
- Using Nmap -
Nmap is a network port scanner and service detector offering stealth SYN scan, ping sweep, FTP bounce, UDP scan and operating system fingerprinting.
For effective port scanning and OS detection, you need to
separately install Nmap 3.55 or above. You can download the latest version of Nmap at
http://www.insecure.org/nmap/nmap_download.html
For Linux systems, after Nmap installation if you want ScanFi to use Nmap OS Detection, do any one of the following:
- Run the ScanFi server as super user
(or)
- Follow the below steps, after reading the Nmap man page,
available at
http://www.insecure.org/nmap/data/nmap_manpage.html
:
- Do a setuid to the nmap executable using the following steps
- Go to Super User mode
- Do chmod u+s /usr/bin/nmap
- Get out from Super User mode and start the ScanFi server
- Using SNMP -
SNMP based OS detection becomes effective only when the
'community' string set in ScanFi system match with the target machines.
Refer 'Discovery
and Scan Preferences' section for configuring SNMP Settings in ScanFi.
By default, ScanFi also uses some standard OS detection procedures such
as using Telnet and smbclient (for Linux).
After asset discovery is completed you can group the discovered assets based
on asset type (such as servers, workstations, laptops, routers, switches and
others) , operating systems (like windows, linux or cisco ios ...), or some
custom grouping based on your discretion.
Create New Asset Group
New asset groups can be created using any of the following options :
- Option 1
- Click on 'New Group' link
- In the 'Group Name' field enter a meaningful group name of your choice and Press OK.
A "New Asset Group created" message is displayed.
- Option 2
Adding assets to groups
Assets can be added to the groups using any of the following options :
- Option 1 - Adding assets to a New Group
- Select the list of discovered assets that you would like to add to a New
Group.
- Click on 'New Group' link
- In the 'Group Name' field enter a group name of your choice and Press OK.
A "Successfully added the Selected Addresses in the Group" message
will be displayed.
- Option 2 - Adding assets to an existing group
- Select the list of discovered assets that you would like to add to an
existing Group.
- Click on 'Add to Asset Group' link.
- Select from the list of existing groups. A "Successfully added the Selected
IPs to the Group" message
will be displayed.
- Option 3 - From Groups tab
The discovered assets can be scanned from the Asset Discovery page itself
using the 'Scan' link after selecting the desired IP Address /
DNS Name. You can also perform scans using any of the many provisions like : Quick
Scan, New
Scan, Schedule Scan .
Refer 'Scans' for more details.
Copyright © 2005, AdventNet Inc. All Rights Reserved.