Donate to A.R.T.

Advertisement

powered_by.png, 1 kB

Home arrow News arrow Atomic-Bleeding arrow New Project: Endstate
New Project: Endstate Print E-mail
Written by scott   
Wednesday, 03 May 2006
Not a whole lot of R&D on the previous projects... wheres the fun in that? Although I have been getting a veritable tsunami of PHP interest lately (more than every other project combined). And thats just from PSA users. I've started on a new project, focusing on analysis of security data. This has nothing to do with PSA, so unless youre also doing security work, this probably wont interest you :)
Endstate is a presentation layer of that data, it doesn't do anything with it beyond that. However, it uses the totality of the data to weed out false positives in other areas, a very very common problem with vulnerability scanners. At this stage its creating graphs, charts, and a rudimentary final report. In addition, the stubs are in place to eventually do delta comparisons from one assessment to another, so you can see the change over time in the overall security posture of a network.

Additional features coming soon will be the ability to see graphically the effect of applying specific fixes to the network, and how this will effect the overall security posture of the network. Generation of remediation plans, and possibly even an electronic security policy generation system based off of data collected in the analysis phase.

No code released at this time, but here are some screenshots of Endstate

Comments

Only registered users can write comments.
Please login or register.

Powered by AkoComment 2.0.3!

 
< Prev   Next >
© 2008 atomicrocketturtle.com :: digital turtlist
Joomla! is Free Software released under the GNU/GPL License.
sheta@atomicrocketturtle.com
Fight Spam! Click Here!