Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

BYOD Auditing, Tenable Style

Note: Passive Vulnerability Scanner (PVS) is now Nessus Network Monitor. To learn more about this application and its latest capabilities, visit the Nessus Network Monitor web page.

The recent release of SecurityCenter 4.7 allows organizations to combine network monitoring and MDM auditing to discover and audit all mobile devices in use, regardless if they are being managed, only used for email, or are connected directly to the network.

Tenable accomplishes this with two different technologies – Nessus and the Passive Vulnerability Scanner.

Nessus supports discovery of mobile users, devices, and vulnerabilities through integration with Active Directory, Good for Enterprise, and Apple’s Profile Manager. SecurityCenter users can now leverage this information for reporting, dashboards, and analytics to identify risky mobile users and devices.

Below is a screen shot of mobile vulnerability data shown on a SecurityCenter dashboard:

SecurityCenter for Mobile Users

This dashboard shows a list of mobile vulnerabilities ranked by their criticality and prevalence, a pie chart of detected mobile device types, a list of mobile users (sanitized) ranked by number of vulnerabilities, and a list of mobile device types with the number of high and critical vulnerabilities associated with each. This is a tremendous amount of information pertaining to mobile devices that have accessed your network email through Active Directory authentication, or from your MDM.

SecurityCenter also supports mobile device vulnerabilities discovered by the Passive Vulnerability Scanner (PVS). These vulnerabilities are obtained from PVS deployments that are watching network traffic. PVS can identify all major mobile devices, as well as a wide variety of their vulnerabilities and popular applications like DropBox.

Below is a screen shot of passively detected mobile security issues:

PVS for Mobile

In this dashboard, the specific number of mobile device vulnerabilities currently active on the network is listed, as well as a seven-day trend of all mobile vulnerabilities observed by PVS.

Leveraging Nessus and PVS for mobile device discovery and auditing is significant for several use cases.

For organizations that allow their users to receive email on personal devices, Nessus audits of MDM and Active Directory installations easily identify security issues associated with these mobile devices. These vulnerabilities are often overlooked in the BYOD (Bring Your Own Device) discussion, because they aren’t “brought” to work or plugged into the network. They are personal devices that may or may not be managed, but they are on home and carrier 3G/4G networks. Traditional scanning, network access control, or sniffing won’t see these devices because they aren’t “on” the network.

For organizations that have mobile devices connected internally, passive discovery is an excellent continuous mechanism for discovery and internal monitoring. The larger a network is, the easier it is for an IT group to grant mobile devices access to wireless networks and areas not secured with network access control.

Leveraging active and passive network monitoring under the SecurityCenter platform ensures that you know how many mobile devices are on your network, and what risks they are bringing with them.

Each of these techniques can be combined into a single dashboard. Below is a screen shot of such a dashboard combining both passive network discovery of mobile security issues with audit results from an MDM.

Nessus for Mobile

In this particular dashboard, which has had the user names sanitized, it is interesting to note that PVS has discovered about 70 mobile devices, while direct Nessus auditing has found several hundred.

To learn more about Tenable’s approach to monitoring mobile risks to your network, please visit our Mobile Device Security page.

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training