Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Remote Desktop Detection

by Michael Willison
August 1, 2014

Tenable SecurityCenter Continuous View (CV) with Nessus, PVS, and LCE provides information on Remote Desktop vulnerabilities, exploits, events, and network traffic flow. Microsoft developed its own graphical remote control technology called Remote Desktop Connection, which uses Remote Desktop Protocol (RDP) to help with some of the limitation and security issues with Virtual Network Connection (VNC), and to replace Microsoft Terminal Service. RDP allows for access to a remote computer to access files and applications. RDP is known to have a variety of exploitable security flaws and vectors of attack. Man-in-the-middle attacks, memory harvesting attacks used to capture passwords in memory, and the Win32/Filecoder.NAH Trojan used to encrypt files and extort users are just a few examples of these flaws. 

The Remote Desktop Detection dashboard has six components that report on RDP vulnerabilities, exploits, and RDP traffic flow. By understanding the vulnerabilities and their severities, SecurityCenter CV users can better assess risk prioritize mitigations to discovered vulnerabilities.  Furthermore, knowing which vulnerabilities are exploitable helps security professionals to resolve threats before attacks occur. Understanding the normal network traffic flow and the direction of RDP communications allows for anomaly analysis and increases the likelihood breach detection.  This dashboard provides the tools to monitor RDP vulnerabilities and their associated risks. 

The dashboard and its components are available in the SecurityCenter Feed, a comprehensive collection of dashboards, reports, assurance report cards and assets. The dashboard can be easily located in the SecurityCenter Feed under the category Discovery & Detection.

The dashboard requirements are:

  • SecurityCenter 4.8.1
  • LCE 4.2.2 
  • Nessus 5.2.7
  • PVS 4.0.2

Listed below are the included components:

  • Remote Detection - Vulnerabilities by IP  Address: By understanding the vulnerabilities and their severities, SecurityCenter CV users can better assess risk and prioritize mitigations to discovered vulnerabilities. This component provides a table of the top 20 vulnerable Remote Desktop systems. The table is sorted by vulnerability weight score. The columns displayed are IP Address, OS, Score, and vulnerability severity (info, low, medium, high, and critical). The severity columns will have a total vulnerability count in each severity cell.  
  • Remote Desktop Detection - Directional Event: Understanding the normal network traffic flow and the direction of Remote Desktop (RDP) communications allows for anomaly analysis and increases the likelihood of breach detection.  This component provides a table of RDP network traffic directional flow by nine event types. The event types used are: Intrusion, Login, Logout, Failed Login, Connection, Continuous, Networks, Errors, and System. SecurityCenter Continuous View defines network traffic flow as internal, inbound and outbound. The Total Event Types column displays a count of all of the respective events, while the remaining three columns show the percentage of events according to directional flow.
  • Remote Desktop Detection - Normalized Events: Analyzing both the normalized event and the trending of these events will help SecurityCenter CV users understand Remote Desktop (RDP) activity on the network and detect anomalies. This component displays normalized events from SecurityCenter CV over the past seven days. The fields displayed are: normalized events names, total events, and a trend graph for events collected over the past 7 days.
  • Remote Desktop Detection - Vulnerability with Exploits by Severities: By detecting exploitable Remote Desktop vulnerabilities, SecurityCenter CV can mitigate exploits before a compromise can occur.  This component displays the top exploitable Remote Desktop (RDP) vulnerabilities for both servers and clients. The table columns are: vulnerability name, family, severity, and total vulnerabilities, which are sorted by severity level.
  • Remote Desktop Detection -Total Number of Events per Day over 7 Days: This event-by-day component is useful for understanding the total amount of Remote Desktop (RDP) events being seen each day over a period seven-day period of time. By viewing the total amount of RDP events each day, an IT team can quickly recognize when anomalies are happening in the network. This component displays the total number of RDP events per day over a seven-day period. Any substantial increase or decrease in RDP events indicates a change in the normal RDP activity.
  • Remote Desktop  Detection - Network Traffic Directional Event Trending: Monitoring for inbound and outbound Remote Desktop (RDP) traffic will vary based on network configuration.  Network administrators should review network traffic trends to determine if traffic is following normal usage patterns. This component displays a RDP network traffic directional event trending flow over 25 days. The traffic flow is represented using the directional filters of internal, inbound, and outbound.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training