Vulnerability Reports
Once a scan is completed, analyzing the data can be quite a task. Depending
upon the audience, there is often too much or too little data. The reporting
framework in ScanFi has been designed to provide the flexibility necessary to
satisfy all parties. Various levels of technical detail are supported, allowing
reports to be tailored for audiences ranging from upper management to system
administrators.
Reports can be generated automatically from ScanFi web-console in HTML
formats and exported to PDF formats or even e-mailed to any number of recipients
in PDF formats. Customization is simple as ScanFi provides report customization
templates, whereby report sections can be added, removed or re-ordered. The
amount of technical detail can be adjusted, allowing reports to be tailored for
any target audience.
Not only are ScanFi reports flexible, but they also provide the needed
information efficiently in color-coded and graphical format. Vulnerability
reports contain information to quickly understand what the problem is and
provide supporting evidence that the system is vulnerable. URL links to vendor
advisories and downloadable patches make remediation straightforward.
Some of the System Reports
templates
included, by default, in ScanFi are :
- Executive Report - Provides a high-level summary of scan
results in rich graphical formats. Used by the IT Managers to know the
exposure level of the enterprise network to
threats.
- Remediation Report - Provides a comprehensive report on
the vulnerabilities with links to solutions for fixing the problem. Used by
the System Administrators to prioritize vulnerability resolution.
ScanFi provides report customization templates that can be used to generate new custom reports
or even modify existing reports.
To Generate :
- System Reports
- Click on either Remediation Report link or Executive Report
link, available in the System Reports
section of the
Reports page, which will take you to a page listing of All
Scans performed in ScanFi.
- Select the scan (Scan Name) for which you would like to generate
report and click the
Generate link.
- Custom Reports
- Click on New Template link present in the right side of the Reports
page.
- Provide a Report Title of your choice and select the various
options, spread across the two tab sections - General and Filters,
which you would like to see in your custom reports.
- Do a Save Template and this new custom template created by you
will be saved under Custom Reports section of the Reports
page.
- Now to generate a report based on the custom template created by you click
on the Report Title, in
the Custom Reports section, which will take you a page listing
of All
Scans performed in ScanFi.
- Select the scan (Scan Name) for which you would like to generate
report and click the
Generate link.
To Modify :
- System Reports
- If you would like to select or de-select any of the options available in
the report customization template, click on the Edit Template link
available for the standard reports and do the necessary changes to the
template and save the template.
- If you would like to change the layout of the report , you can do so by clicking
on the Customize Layout link available for the standard reports,
which will take you to the Table Layout Customization view, where you
can rearrange the existing view components using drag-and-drop and can also
drag-and-drop any other view components from the SIDEBAR .
Note : You cannot delete the System Reports
- Custom Reports
- If you would like to select or de-select any of the options available in
the report customization template, click on the Edit link available
alongside each of the custom report created by you and do the necessary changes to
the template and save the template.
- If you would like to change the layout of the report , you can do so by clicking
on the Customize link available alongside each of the custom report
created
by you, which will take you to the Table Layout Customization view,
where you can rearrange the existing view components using drag-and-drop and
can also drag-and-drop any other view components from the SIDEBAR .
You can delete the Custom Reports by clicking on the Delete link available
alongside each of the custom report created
by you .
Report Mail Settings
For you to automatically receive vulnerability reports immediately after a
scan is completed, you need to configure the ScanFi Report Mail Settings
page (Reports >>Report Mail Settings).
- The various options provided for mailing the report, after a scan has been
completed, are:
- For scheduled scans - select this option if you want the recipient
to automatically receive vulnerability reports for scans scheduled in
ScanFi.
- For all scans [including scheduled scans] - select this option if
you want the recipient to automatically receive vulnerability
reports for all scans performed in ScanFi.
- No, Don't E-mail any reports - select this option if you do not
want the recipient to automatically receive any vulnerability
report.
- Choose the report type : listing, gives you a list of report
templates, both System and Custom report templates, to
select from. This ensures that the report that is automatically generated
and mailed to the recipient, on scan completion, adheres to the report
type or template that has been selected by you.
- Recipient E-Mail ID : provide the e-mail ID's
to which the reports have to be sent (separate multiple e-mail ID's with commas).
Once the report mail settings have been configured, do a Save
Settings. You will receive the message "Report Mail Settings Saved
Successfully" in the web-client.
ScanFi also provides you with many Predefined Views like :
- Top Hosts by Vulnerability Count - Lists the vulnerability count
for the hosts that were recently scanned .
- Top Hosts by High Vulnerability
Count - Lists the recently scanned hosts with HIGH
risk vulnerability count.
- Hosts frequently scanned - List of hosts that are frequently
scanned.
- Hosts not so frequently scanned - List of hosts that are not
frequently scanned.
- Hosts running HTTP - Lists the recently scanned hosts that have
HTTP Service running and their corresponding ports.
- Hosts running SMTP - Lists the recently scanned hosts that have SMTP
Service running and their corresponding ports.
- Top Hosts with Open Ports - Lists the recently scanned hosts that
have the most number of open ports.
- Top Hosts with Missing Patches - Lists the recently scanned hosts
that have the most number of missing patches.
The Knowledge Base section in the Reports page, contains a complete list of the vulnerabilities and patches information.
This list gets updated regularly with latest information available in the Central
Repository Server depending on your vulnerability
updates cycle.
- Vulnerability Knowledge Base : contains a list of vulnerabilities
that will be scanned for, during a Vulnerability Scan. You can
search
the vulnerability knowledge base , based on Risk, Service, Description or
CVEID .
- Patches Knowledge Base : contains a list of patches that
will be scanned for, during a Vulnerability Scan. You can
search
the patches knowledge base , based on Severity, Title, Bulletin or
Patch To Install .
Copyright © 2005, AdventNet Inc. All Rights Reserved.