Re: Nessus scripts and Moore's Law

Erik Stephens <[email protected]> Fri, 12 Nov 2004 09:50:24 -0700
Newsgroups gmane.comp.security.nessus.devel
Message-ID <[email protected]>
On Nov 12, 2004, at 4:25 AM, Pavel Kankovsky wrote:

> On Thu, 11 Nov 2004, Michel Arboi wrote:
>
>> Over optimizing might be dangerous too: if the web server banner is
>> not in the KB because of a network glitch, the plugin should try to
>> grab it again (that's what get_http_banner does)
>
> This is silly. Rather than ending with a completely and obviously bogus
> report (no information about the service), you end with a partially 
> bogus
> report (some plugins got the banner, some plugin did not). The latter 
> is
> worse IMHO.

I agree.  I'd much rather have something obviously inaccurate than 
something that is inaccurate but appears accurate on the surface.

On a side note, port scanning is the most sensitive and time consuming 
for us.  With optimize tests enabled, many of the tests will not run.  
Plus, the tests seem to run very quickly in comparison.  Kudos to the 
nessus devel team for keeping them that way. :-)


>> That would be good. The issue today is not really speed, but CPU 
>> usage.
>> If you are testing 3 hosts in parallel, you don't care about such a 
>> VM.
>> However, if you intend to scan your class B, you want a high level of
>> optimization, which can be achieved if each process has a very little
>> CPU footprint.
>
> As far as I can tell, Nessus has always been more memory (*) and 
> network
> bandwith hungry than CPU hungry. I had to reduce parallelism in order 
> to
> prevent thrashing and network congestion on several occasions but I 
> don't
> recall I have ever had to reduce it because CPU was overloaded. YMMV.

Another point of reference, our experience has been that network 
bandwidth is the critical resource.  Second would be memory, then cpu a 
distant third.  However, most of our assessments have been done over 
the Internet where we obviously don't have as much bandwidth to play 
with.


Best regards,
Erik Stephens                                      www.edgeos.com
                         Managed Vulnerability Assessment Services

_______________________________________________
Nessus-devel mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus-devel