Re: families
Bob Gerdes <[email protected]>
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 14 Apr 2004, Erik wrote: > On Wed, 14 Apr 2004, Michel Arboi wrote: > > > I know that this subject has been debated for a long time and that we > > could not reach a compromise. MHO, the current family sets sucks, mostly > > because it mixes several things: > > [snip] > > What about removing the restriction for a plugin to belong to only one > "family"? Instead of a 'family' field, how about something like a > 'keywords' or 'families' field (can't think of a good field name to > represent what I'm trying to say)? I think exceptions could be handled > more elegantly then. Just a thought. I wasn't around the last time > this was debated :) One dilemma that we face is to be able to identify plugins by their scanning effects (DOS, disruptive, banner, etc.) to aid the scanning process; then identify plugins by service being tested (ssh, ftp, backdoors, etc.) to aid both scan choices and remediation processes; and then identify remediation effort (patch via windowsupdate, other patching, configuration, and so on) to help understand policy efforts and remediation efforts. The first draft of this has helped at negotiating vulnerabilities at each stage of the effort. > Best regards, > Erik Stephens www.edgeos.com > Managed Vulnerability Assessment Services > _______________________________________________ > Nessus-devel mailing list > [email protected] > http://mail.nessus.org/mailman/listinfo/nessus-devel > _______________________________________________ Nessus-devel mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus-devel