Correlating Vulnerability Scans with Network Path Analysis to Find and Remediate the Biggest Risks to Your Network and Avoid Wasting Time on the Little Ones

8/22/2017 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 8/22/2017 4:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 8/22/2017 5:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 8/22/2017 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 8/22/2017 6:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 8/22/2017 6:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 8/22/2017 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 8/22/2017 7:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 8/22/2017 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 8/22/2017 8:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 8/22/2017 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 8/22/2017 9:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 8/22/2017 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 8/22/2017 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 8/22/2017 10:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 8/22/2017 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 8/22/2017 11:00:00 AM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 8/22/2017 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 8/22/2017 10:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 8/22/2017 11:00:00 AM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 8/22/2017 11:00:00 AM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 8/22/2017 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 8/22/2017 12:00:00 PM
Cuba Standard Time-(UTC-05:00) Havana 8/22/2017 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 8/22/2017 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 8/22/2017 12:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 8/22/2017 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 8/22/2017 12:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 8/22/2017 12:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 8/22/2017 12:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 8/22/2017 1:00:00 PM
Turks And Caicos Standard Time-(UTC-04:00) Turks and Caicos 8/22/2017 12:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 8/22/2017 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 8/22/2017 1:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 8/22/2017 1:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 8/22/2017 1:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 8/22/2017 1:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 8/22/2017 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 8/22/2017 1:00:00 PM
Magallanes Standard Time-(UTC-03:00) Punta Arenas 8/22/2017 1:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 8/22/2017 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 8/22/2017 1:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 8/22/2017 2:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 8/22/2017 3:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 8/22/2017 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 8/22/2017 3:00:00 PM
UTC-(UTC) Coordinated Universal Time 8/22/2017 4:00:00 PM
Morocco Standard Time-(UTC+00:00) Casablanca 8/22/2017 5:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 8/22/2017 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 8/22/2017 4:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 8/22/2017 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 8/22/2017 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 8/22/2017 6:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 8/22/2017 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 8/22/2017 5:00:00 PM
Namibia Standard Time-(UTC+01:00) Windhoek 8/22/2017 5:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 8/22/2017 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 8/22/2017 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 8/22/2017 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 8/22/2017 6:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 8/22/2017 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 8/22/2017 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 8/22/2017 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 8/22/2017 6:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 8/22/2017 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 8/22/2017 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 8/22/2017 6:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 8/22/2017 6:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 8/22/2017 7:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 8/22/2017 7:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 8/22/2017 7:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 8/22/2017 7:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg, Volgograd 8/22/2017 7:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 8/22/2017 7:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 8/22/2017 8:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 8/22/2017 8:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 8/22/2017 8:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 8/22/2017 8:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 8/22/2017 8:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 8/22/2017 8:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 8/22/2017 8:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 8/22/2017 8:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 8/22/2017 8:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 8/22/2017 8:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 8/22/2017 9:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 8/22/2017 9:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 8/22/2017 9:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 8/22/2017 9:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 8/22/2017 9:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 8/22/2017 9:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 8/22/2017 10:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 8/22/2017 10:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 8/22/2017 10:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 8/22/2017 10:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 8/22/2017 11:00:00 PM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 8/22/2017 11:00:00 PM
W. Mongolia Standard Time-(UTC+07:00) Hovd 8/22/2017 11:00:00 PM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 8/22/2017 11:00:00 PM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 8/22/2017 11:00:00 PM
Tomsk Standard Time-(UTC+07:00) Tomsk 8/22/2017 11:00:00 PM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 8/23/2017 12:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 8/23/2017 12:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 8/23/2017 12:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 8/23/2017 12:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 8/23/2017 12:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 8/23/2017 12:00:00 AM
North Korea Standard Time-(UTC+08:30) Pyongyang 8/23/2017 12:30:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 8/23/2017 12:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 8/23/2017 1:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 8/23/2017 1:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 8/23/2017 1:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 8/23/2017 1:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 8/23/2017 1:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 8/23/2017 1:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 8/23/2017 2:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 8/23/2017 2:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 8/23/2017 2:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 8/23/2017 2:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 8/23/2017 2:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 8/23/2017 2:30:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 8/23/2017 3:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 8/23/2017 3:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 8/23/2017 3:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 8/23/2017 3:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 8/23/2017 3:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 8/23/2017 3:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 8/23/2017 4:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 8/23/2017 4:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 8/23/2017 4:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 8/23/2017 4:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 8/23/2017 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 8/23/2017 4:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 8/23/2017 5:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 8/23/2017 5:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 8/23/2017 5:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 8/23/2017 6:00:00 AM

Webinar Registration

Vulnerability scanning has its place but I’ve often found that it produces a mountain of data with little guidance for prioritizing updates other than a relative high/medium/low risk rating of the exploit itself and of the device’s value.


Many of the vulnerabilities reported are mitigated by other compensating controls that the scanner is not aware of. The most frequent compensating control is network restrictions.


For instance, a given high value server, like a Hyper-V server, may be vulnerable to a Remote Desktop Protocol Exploit and is dutifully reported by your vulnerability scanner. But that Hyper-V system happens to be on a highly isolated network segment where RDP connections are only admitted from a trusted jump box. 

some_text

So, to get an accurate picture of vulnerability analysis you need to consider network-based controls.


And that’s not just from the point of view of reducing the relative priority of reported vulnerabilities because of compensating controls. While network restrictions may be effective they are also complicated, subject to change and managed by a network team while servers are managed by their own team. A typical organization has many firewalls if you count routers, managed switches and everything else with a network access control list. It's not at all unusual to have tens of thousands, even more than a hundred thousand, rules if you combine all your network devices.


So, taking into account network access when analyzing vulnerabilities can also push up the relative risk of a given vulnerability. Taking the earlier example a step further, what if over the course of time that jump box is replaced with a privilege session management appliance on a different IP address? The ACL is never updated to remove the exception allowing the jumpbox to RDP into the Hyper-V host segment and that IP address is re-used for some other device such as maybe a Linux server for “playing around with” by IT admins.

some_text

Now that vulnerability on the Hyper-V servers becomes a much bigger risk.

In this real training for free event, I will explore how to correlate vulnerability scans with network access path data to discover your biggest risks while helping de-prioritize those vulnerabilities that present the least risk when taking into account the current state of your routed network.


My sponsor, FireMon, are the experts on analyzing firewall rules to optimize network traffic and security and Matt Dean, VP of Product, will join me to share what they’ve learned about correlating vulnerability scans with network path analysis and will briefly show you how FireMon can even visually lay vulnerability data on top of route intelligence to help you see the risks.


Please join me for this real training for free event.

First Name:   
Last Name:   
Work Email:  
Phone:  
Job Title:  
Organization:  
Country:    
City:  
State:  
Zip/Postal Code:  
Industry:  
Company Size:
 

Your information will be shared with the sponsor.


 

 

Additional Resources