Home > Networking All-in-One Guides > Network management > Network monitoring > Monitoring tools > Essential security testing tools for SMBs
All-in-One Guides: Network management:
EMAIL THIS
 START   OVERVIEW   NETWORK ANALYSIS   NETWORK MONITORING   
Network monitoring


Monitoring tools
<< PREVIOUS | NEXT >>: Network visibility thwarts crime, identifies...
 TIPS & NEWSLETTERS TOPICS 


Essential security testing tools for SMBs


Kevin Beaver, CISSP
07.13.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip originally appeared on SearchSMB.com. For more IT articles and tips specific to small and midsized businesses, visit SearchSMB.com.

Security testing -- vulnerability assessments, penetration tests and higher-level audits -- requires the proper tools. There's a wide variety of tools that perform dozens of different tasks, making it difficult to determine what you need to get a good view of your overall network security.

I've found several types of essential security testing tools that cover all areas of network security. I'm partial to commercial products because of their ease of use, reporting features and overall professional look and feel, but there are some good freeware and open source options as well. It all depends on your taste and budget.

General network scanning: A ping sweeper and port scanner tool will help you browse your network and find which hosts are active so you'll know what to probe. Mission Viejo, Calif.-based Foundstone Inc.'s SuperScan version 3 is great for getting things kicked off. SuperScan version 4 offers even more options for enumerating Windows systems that can prove to be very fruitful for scanning your own systems. Foundstone's SiteDigger is another neat tool for performing advanced Google queries. SiteDigger allows you to to dig up stuff you may not know has been publicized.

File scanning: A file-scanning utility can be something as basic as the DOS "find" command or the Search function built into Windows Explorer. Files containing private, confidential and other sensitive information are commonly stored on local hard drives and network shares that not everyone needs access to. This is a big vulnerability, especially when it concerns information that's regulated under the Health Insurance Portability and Accountability Act or the Gramm-Leach-Bliley Act.

A great tool for searching local and network drives is Effective File Search. It's blazingly fast (compared with standard Windows programs) and has a lot of interesting text search capabilities. Download this tool and search your network for dob, ssn, license, etc. and I guarantee you'll find some unprotected files in the wrong places.

Operating system scanning: Once you've identified systems with potential vulnerabilities you can dig deeper, looking for specific OS vulnerabilities: Share and file permissions, missing patches and weak security policy settings. A great starter tool that has received significant improvements over the years is GFI Software Ltd.'s LANguard Network Security Scanner. This is especially good if you have a lot of systems and pricing is an issue. My all-time favorite is QualysGuard by Qualys Inc. -- an extremely powerful and comprehensive tool that's a great fit for critical systems. If you're really price-conscious, many people rave about Nessus, which has recently become much more powerful and easier to use.

Password cracking: This is yet another hot issue, especially in light of all the emerging privacy and security regulations. My clients and I are often very surprised at how vulnerable most users' network passwords are. Plain old trial and error guessing or password cracking is still very common. A basic tool that can check for some common password weaknesses in Windows is Microsoft's Microsoft Baseline Security Analyzer. However, if you want to do some hard-core cracking you should look into Elcomsoft Co.'s Proactive Password Auditor, Cain and Abel, or the "no password left uncracked" RainbowCrack.

Web application scanning: These tools are essential for finding common flaws in Web applications. Some even scan back-end databases. They aren't flawless, as manual testing is still often required, but such tools can save you a lot of time and effort. A formidable tool to get started with is N-Stalker, along with my favorite, WebInspect, by SPI Dynamics inc. A reasonably priced tool for scanning back-end databases (you know, where the "money" is) is Application Security Inc.'s AppDetective line of products.

Network analysis: A network analyzer (a.k.a. sniffer) will dig up rogue systems, employees doing things they shouldn't be doing, protocols that don't belong, hack attacks in action, data leakage, and more. They're great for looking at both wired and wireless networks. TamoSoft's CommView products are great for getting started and are very reasonably priced. EtherPeek SE is an extremely powerful wired network analyzer that practically anyone can use. For wireless testing, outside of NetStumbler, check out the bootable Auditor collection of powerful Linux-based utilities and AirMagnet Inc.'s Laptop Analyzer -- all tools that can make your security testing much, much easier.


Kevin Beaver is founder and information security advisor with Atlanta-based Principle Logic LLC. He has more than 17 years of experience in IT and specializes in performing information security assessments. Kevin has authored five information security-related books including Hacking For Dummies (Wiley), the brand new Hacking Wireless Networks For Dummies, and The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach). He can be reached at kbeaver @ principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Network visibility thwarts crime, identifies...
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Monitoring tools
What good network monitoring tools are there to run on Windows servers?
BackTrack: The gotta-have, free, network security tool you've never heard of
Network visibility thwarts crime, identifies unwanted traffic
Network security toolbox
Reducing false positives in network monitoring
Network monitoring with Nagios, part one

Network Security Best Practices and Products
3Com acquisition confirms HP-Cisco battle for China
Enterprises demand next-generation firewalls with IPS, app visibility
Preventing hacker attacks with network behavior analysis IPS
Is there a way to trace my stolen laptop computer?
Integrating NAC with network security tools
Should organizations separate technical from administrative security?
What network equipment is needed to secure a small business LAN?
Ethical hacking and countermeasures: Network penetration testing intro
Are you on a domain name system (DNS) blacklist database?
Rogue access points: Preventing, detecting and handling best practices

Network Security Monitoring and Analysis
Application-specific network intrusion detection systems emerge
Anomaly-based intrusion protection configuration and installation
How can I calculate perimeter firewall throughput?
How do I find the application on my network that's dropping packets?
Integrating NAC with network security tools
Where can I find a sample security audit report? How can I run my own?
The firewall remains the network traffic cop, but its role is changing
Troubleshooting VLANs: How to monitor 802.1q tagged traffic
Poor data-loss prevention practices almost cost Intel a billion
How can I block my competitor's IP address range from my website?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anti-replay protocol  (SearchNetworking.com)
dynamic packet filter  (SearchNetworking.com)
HELLO packet  (SearchNetworking.com)
packet filtering  (SearchNetworking.com)
rule base  (SearchNetworking.com)
stateful inspection  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts