Intorduction: Retina Network
Security Scanner
Product Benefits
Did you know that firewalls and intrusion
detection systems do not provide 100% protection against
hackers? These tools are reactive in nature: they only
protect you when someone is actually trying to hack
into your network. What you also need is a product that
proactively helps you secure your network.
- Retina was built to be non-intrusive. It does
not bring down your networks while you run your penetration
tests.
- Contrary to other scanners, in the Enterprise
License, there are no limitations on the IP's audited.
The licensing is easy and transparent.
- The autofix and autoupdate features are really
strong, and new vulnerabilities are added ASAP, not
once a month or six weeks like other tools. This is
something really crucial.
- Last but not least, the reporting is great.
It provides executive level summaries that are readable.
Moreover, you can install Retina on a laptop and audit
all your subnets. Try to get that done with
some of the other products!
Retina was designed by eEye Digital
Security to identify known and unknown vulnerabilities,
suggest fixes to identified vulnerabilities, and report
possible security holes within a network's internet,
intranet, and extranet environments.
The product's patented technology eclipses
the capabilities of the past generation of security
scanners and employs a unique artificial intelligence
engine that allows the product to think like a hacker
or network security analyst attempting to penetrate
your network.
Retina is a best-of-breed scanner supported
by powerful features that are attractive to the network
administrator and the security consultant alike. eEye
has committed to making Retina the most feature-rich
scanner available in the market today.
Features
Retina's key features include:
Latest Updates:
- Enhanced SQL auditing to detect servers vulnerable
to the Sapphire Worm.
- Enhanced Custom Policy management through
"Remove Audit From Current Policy" feature.
- Added "Email Audit Details" feature.
- Added ability to search audits database (Tools
| Audits Search...).
- Improved command line management of Retina
as a scanning engine.
- Scan ranges can be saved / loaded to a host
file (*.rti)
- Scan range files (*.rti) can be used in command
line mode.
- Added ability to scan non-sequential IP addresses.
- Added NetBIOS OS detection.
- If set to "Check Without Asking", the Auto-Updater
will now launch when using Retina command line
mode.
- Fixed false positives with Samba.
- Fixed CGI false positives (Compaq Insight
Manager, etc).
- Added user interface and error handling improvements
to the Auto-Update System
- ;Added command line options for launching Retina
scans
- Licensing mechanism now supports multi-byte
operating systems. This solves the problem when launching
on Japanese, Korean and Chinese operating systems
- Fixed bug where computers that contained a
dash ("-") in their name could not be scanned by entering
the machine name
- Fixed bug where scanning certain machines
would result in a database error when viewing a report
- Auto-Updater is now set by default to check
for new versions at startup
Unrivaled Ease of Use
Despite its powerful capabilities, Retina was designed
to be the easiest scanner to operate on the market.
The award-winning graphical user interface provides
easy control over all aspects of Retina's scanning and
reporting capabilities. Retina also features a number
of automatic features that facilitate such functions
as scheduling, repairing common system problems and
updating the application.
Remote Repair Capabilities
Retina's Auto-Fix function allows you to automatically
correct common system security issues such as registry
settings, file permissions and more. Because Auto-Fix
can function remotely across any size network, you have
the freedom and flexibility of operating from a single
location.
Frequent Updates for New Vulnerabilities
Unlike many commercial scanners that are updated once
a month or less, updates to Retina's vulnerability database
are available on a near-daily basis. Retina's Auto-Update
function provides easy Internet access for downloading
the latest vulnerability checks from eEye Digital Security,
a recognized digital security research powerhouse. Auto-Update
can be launched manually or set to run automatically
at the beginning of every Retina session.
Custom Audit Wizard
In addition to a comprehensive database of security
audits, Retina's Audit Wizard gives you the ability
to create new audits to check for security vulnerabilities
in custom applications or other configurations that
may be unique to your network. Audit Wizard simplifies
the process of building custom checks and getting them
integrated into Retina for use in your very next scan.
Advanced Scheduling Capabilities
Retina's scheduler function allows you to set the scanner
to run on a regular basis to periodically check for
vulnerabilities. And because Retina is non-intrusive
in its scanning operations, you can pre-schedule your
scans to be run without having to worry about unplanned
network downtime.
Non-Intrusive Scanning
Unlike most other security scanners on the market, eEye
has gone to great lengths to design Retina with intelligent
scanning techniques that are non-intrusive and do not
test by exploitation during normal scanning operation.
As a result, Retina can scan your network without overloading
its resources and without causing systems to crash.
This makes Retina especially powerful for remote scanning
services.
The Most Comprehensive and Up-to-Date
Vulnerabilities Database
Because eEye is a recognized digital security research
powerhouse, Retina incorporates the most comprehensive
and up-to-date vulnerabilities database. Along with
constantly monitoring security advisories, eEye frequently
has advanced knowledge of security issues due to discoveries
made by its own team of security experts. In fact, the
eEye research team has itself issued a number of advisories
regarding major security issues that its members have
personally detected. With Retina's Auto-Update feature,
this almost daily stream of vulnerability updates can
be automatically downloaded at the beginning of every
Retina session.
Ability to Uncover Unknown Vulnerabilities
In addition to scanning against the most complete database
of known vulnerabilities, Retina's unique, artificial
intelligence technology - called Common Hacker Attack
Methods or CHAM - delivers a capability beyond what
other security scanners can provide. With CHAM, Retina
is able to think like a hacker or network security analyst
attempting to penetrate your network. In this way, Retina
can actually detect previously unknown or hidden vulnerabilities,
giving you the knowledge you need to better secure your
networks.
Generates Highly Customized - and
Customizable - Reports
Rather than providing boilerplate text, Retina automatically
customizes the content of its network audit reports
to reflect the severity of the vulnerabilities discovered
and the level of security risk involved. You can further
customize these reports by rewriting specific content
and/or by incorporating your logo or other text in the
header and footer sections. Retina offers two different
reporting options: Technical Reports with intricate
details to satisfy IT personnel and Executive Reports
for high-level management summaries.
Breadth of Systems and Services
Audited
Retina runs on Windows NT/200 and XP platforms, but,
unlike other scanners, it is not limited to scanning
only Windows networks. In fact, Retina has the ability
to scan all types of operating systems for vulnerabilities,
including Unix-based operating systems (Solaris, Linux,
*BSD, etc.) as well as networked devices (such as routers
and firewalls) that run "home-grown" operating systems.
Retina includes vulnerability auditing modules for many
systems and services such as NetBIOS, HTTP, CGI and
WinCGI, FTP, DNS, DoS vulnerabilities, POP3, SMTP, LDAP,
TCP/IP, UDP, Registry, Services, Users and Accounts,
password vulnerabilities, publishing extensions, and
more. Retina also supports the auditing of wireless
networks.
Superior OS Detection
Retina is the first and only commercial scanner to license
and incorporate the Nmap (Network Mapper) Fingerprint
Database, an open-source utility for network exploration
and the most complete database of OS TCP/IP stack fingerprints
available. Nmap uses raw IP packets in novel ways to
determine which hosts are available on the network,
which services or ports they are offering, which operating
system they are running, what type of packet filters/firewalls
are in use, and dozens of other characteristics. Incorporating
Nmap allows Retina to perform remote operating system
detection for subsequently smarter scanning.
Smart Protocol Scanning
Unlike most other security scanners, Retina does not
make assumptions about typical protocols running behind
specific ports such as a web server running behind Port
80. Instead, the scanner actually analyzes the input/output
data on each port to determine which protocol and service
is actually running. In this way, Retina makes adjustments
for custom or unconventional machine setup.
Open Architecture for Advanced Customization
Retina is built with an open architecture that allows
you to develop vulnerability tests and auditing modules
tailored to your organization's own specific requirements.
You can also fine-tune the included audits, make custom
changes to the Retina interface and more. A documented
set of APIs is provided to simplify the process of building
custom scans in your preferred programming language
and integrating them into Retina. Retina also has a
Policies Wizard that walks you through the creation
of a custom scan.
High-Speed Scanning Ability
Retina is recognized as the fastest security scanner
on the market. It has the ability to scan every machine
on your network, all types of operating systems, networked
devices and third-party or custom applications in record
time. In fact, Retina is able to scan an entire Class
C network in about 15 minutes.
Highly Engineered Scanning Engine
Retina's scanning engine is engineered to be faster,
less intrusive, and produce better results than all
other scanners available. With each new feature update,
Retina is fine tuned to deliver more optimized scanning
for networks of all sizes and all levels of complexity.
Retina is considered to be the top
scanner in the market. Whenever Retina is compared head
to head, it has frequently won the comparison based
on the following factors:
1. Fastest scanner: Retina is
extremely fast. It can scan a class-c network in less
than 12 minutes
2. CHAM: Common hacking attack
methods is artificial intelligence that allows Retina
to go beyond scanning for a database
of known vulnerabilities. It actually simulates the
approach of hacker to break into a
system in order to uncover unknown vulnerabilities in
systems, and particularly custom software
and configurations.
3. NMAP: Retina is the first
and only scanner that incorporates the NMAP Fingerprint
Database (NMAP is a very popular shareware
scanning utility). This allows Retina to have superior
OS detection, particularly for remote
scans. eEye was actually the first company to port NMAP
to the NT platform.
4. Open architecture: Retina
incorporates a set of API's that allow the client to
build custom scans in his/her preferred
programming language and integrate them into Retina.
Retina also has a "wizard" that walks
the client through building a custom scan to simplify
the process of integration.
5. Custom and Smart reporting:
Retina generates comprehensive reports of the scans
it runs. Clients have full control
over customizing these reports, including the incorporation
of their own logos and text in the
header and footer. In addition, Retina incorporates
smart reporting whereby reports are automatically
generated to reflect the severity of the vulnerabilities
discovered.
6. Breadth of systems scanned:
Retina runs on the Windows NT/XP platform, but unlike
its peers, it is not limited to only
scanning Windows NT/XP networks for vulnerabilities.
In fact Retina has the ability to
scan all types of operating systems, including most
Unix operating systems (Solaris, Linux, *BSD
etc...) and networked devices (routers, firewalls etc...)
that run home grown operating systems.
For a technical consultant to call you
click here and they will do so at the time you specify. If you
are looking for a quotation or need help designing your
solution then click here.
If you require access to our SECURE online catalogue
then click here.
|