Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

MARS and vulnerability scanners

Our new MARS typically shows a large number of false positives. Is it worthwhile to invest into a vulnerability scanner, such as Foundstone, so MARS has a better idea on which systems are actually vulnerable?" I always thought MARS performed scanning on the fly using Nessus. Is this typically good enough to rely on?



Re: MARS and vulnerability scanners

The appliance centrally aggregates logs and events from a wide range of popular network devices (such as routers and switches), security devices and applications (such as firewalls, intrusion detection systems [IDSs], vulnerability scanners, and antivirus applications), hosts (such as Windows, Solaris, and Linux syslogs), applications (such as databases, Web servers, and authentication servers), and network traffic (such as Cisco NetFlow).For more info refer the following URL

Community Member

Re: MARS and vulnerability scanners

Firing events are classified automatically by MARS as system-confirmed false positives or unconfirmed false positives this is due to data reduction feature of MARS,more info on false positive can be found in the below link, U r corret MARS do have in built integrated NESSUS scanner,I have tested the VA scanning ability of the MARS the results were pretty satisfying it shoots one incident saying "Vulnerable host found" as soon as it finds one,if you are integrating any VA scanner with MARS it just acts as a catalyst to the existing VA scan capabilities of the MARS.

CreatePlease to create content