Title: Security Assessment Tools
1Security Assessment Tools
- Paula Kiernan
- Senior Consultant
- Ward Solutions
2Session Prerequisites
- Hands-on experience with Windows 2000 or Windows
Server 2003 - Working knowledge of networking, including basics
of security - Basic knowledge of network security-assessment
strategies
Level 200
3Session Overview
- Free Security Assessment Tools from Microsoft
- Alternative Assessment Methods
4Security Assessment Tools
- Free Security Assessment Tools from Microsoft
- Alternative Assessment Methods
5Free Security Assessment Tools
Free Security Assessment Tools from Microsoft
include
- MBSA
- Microsoft Update
- ExBPA
- MSRSAT
- Port Query
6MBSA
Microsoft Baseline Security Analyzer can examine
one or more computers for the following
- Missing Security Updates
- Missing Office Updates
- Vulnerabilities in Windows, IIS, SQL and
Exchange (depending on MBSA version) - Vulnerabilities in Internet Explorer
- Weak passwords, Auditing, Shares
- and much more
http//download.microsoft.com
7(No Transcript)
8(No Transcript)
9(No Transcript)
10Demonstration 1 Using the MBSA
- Analyze a computer using the MBSA
11Microsoft Update
- Main site for obtaining updates for
- Windows
- Office
- Internet Explorer
- All other Microsoft applications
- Will replace Windows and Office Update sites
http//update.microsoft.com/microsoftupdate/
12(No Transcript)
13Exchange Best Practices Analyzer
ExBPA can examine your Exchange servers to
Generate a list of issues, such as
misconfigurations or unsupported or
non-recommended options
ü
ü
Judge the general health of a system
ü
Help troubleshoot specific problems
http//download.microsoft.com
14Demonstration 2 Analyzing Configuration Settings
on Exchange Server 2003
- Analyze Exchange Server using the ExBPA Tool
15MSRSAT
Microsofts Security Risk Self-Assessment Tool
- Assess compliance with Microsoft Security Risk
Management Discipline guidelines
- Baseline for assessing security status of an
organization
- Obtain advice on areas requiring improvement that
may otherwise have been missed
16(No Transcript)
17Demonstration 3 Using the MSRSAT
18Port Query
Port Query can be used to
- Examine specified ports to determine their state
- LISTENING
- FILTERED
- NOT LISTENING
- PortqryUI.exe
- Portqry.exe
portqry -n microsoft.com -p tcp -e 25 portqry -n
169.254.0.11 -p tcp -o 143,110,25 -l portqry.txt
19Port Query UI
20Demonstration 4 Using the Port Query UI
- Analyze a computer using Port Query
21Other Free Security Assessment Tools
Other free software available from Microsoft
- Malicious Software Removal Tool
- Windows AntiSpyware (in Beta)
- Application Threat Modeling Tool
22Malicious Software Removal Tool
23Demonstration 5 Using the Malicious Software
Removal Tool
- Analyze a computer using MSRT
24Security Assessment Tools
- Free Security Assessment Tools from Microsoft
- Alternative Security Assessment Methods
25Alternative Security Assessment Methods
Other methods for assessing your network security
include
- Purchase advanced security assessment tools e.g.
NetIQs Vulnerability Manager - Have a professional Penetration Test carried out
by security experts
26Session Summary
Take advantage of the free security assessment
tools from Microsoft
ü
Check http//download.microsoft.com/ regularly
for new free tools
ü
Follow a Defense in Depth approach to security
and security assessments
ü
ü
Sign up for the Security Bulletin service from
Microsoft
Keep systems up-to-date on security updates and
service packs
ü
27Next Steps
- Find additional security training events
- http//www.microsoft.com/ireland/events/default.a
sp - Sign up for security communications
- http//www.microsoft.com/technet/security/signup/
default.mspx - Find additional e-learning clinics
- https//www.microsoftelearning.com/security/
- Find additional tools and downloads
- http//download.microsoft.com
28Questions and Answers Clinic
29Security Clinic Questions
- Patch Management
- Anti-Virus
- Firewalls and Perimeter Security
- Server Hardening
- Group Policy
- Security Assessment
- Policies and Procedures
30paula.kiernan_at_ward.iewww.ward.ie