Re: families

Bob Gerdes <[email protected]>
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>

On Wed, 14 Apr 2004, Erik wrote:

> On Wed, 14 Apr 2004, Michel Arboi wrote:
>
> > I know that this subject has been debated for a long time and that we
> > could not reach a compromise. MHO, the current family sets sucks, mostly
> > because it mixes several things:
> > [snip]
>
> What about removing the restriction for a plugin to belong to only one
> "family"?  Instead of a 'family' field, how about something like a
> 'keywords' or 'families' field (can't think of a good field name to
> represent what I'm trying to say)?  I think exceptions could be handled
> more elegantly then.  Just a thought.   I wasn't around the last time
> this was debated :)

   One dilemma that we face is to be able to identify plugins by their
scanning effects (DOS, disruptive, banner, etc.) to aid the scanning
process; then identify plugins by service being tested (ssh, ftp,
backdoors, etc.) to aid both scan choices and remediation processes; and
then identify remediation effort (patch via windowsupdate, other patching,
configuration, and so on) to help understand policy efforts and
remediation efforts.  The first draft of this has helped at negotiating
vulnerabilities at each stage of the effort.

> Best regards,
> Erik Stephens                                 www.edgeos.com
>                    Managed Vulnerability Assessment Services
> _______________________________________________
> Nessus-devel mailing list
> [email protected]
> http://mail.nessus.org/mailman/listinfo/nessus-devel
>
_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.