HomeProductsSupportServicesTrainingPartnersCompanyContact     


assuriaONLINE Customer and Partner resources Logon / register

     

Subscribe via RSS

RSS 2.0

 assuria bulletin                                                               

 

 
 Title:                         Assuria Auditor - AutoUpdate #76 - Assuria Information Reporter introduced

 Number:                   67          Date:   20th March 2008
 

Contents

 . PAGEREF _Toc193792088 \h 1

Introduction. PAGEREF _Toc193792089 \h 1

Retention of Crystal reports. PAGEREF _Toc193792090 \h 1

Assuria Auditor User Guide. PAGEREF _Toc193792091 \h 1

Transition. PAGEREF _Toc193792092 \h 2

Changing default reporting format. PAGEREF _Toc193792093 \h 2

Crystal reports. PAGEREF _Toc193792094 \h 2

Assuria Auditor Console changes. PAGEREF _Toc193792095 \h 3

Assuria Information Reporter PAGEREF _Toc193792096 \h 5

Assuria Auditor multi-session reports. PAGEREF _Toc193792097 \h 6

Administration Reports: PAGEREF _Toc193792098 \h 8

Executive Reports. PAGEREF _Toc193792099 \h 9

Line Manager and Technicians reports. PAGEREF _Toc193792100 \h 13

Session based reports. PAGEREF _Toc193792101 \h 14

Applicable platforms. PAGEREF _Toc193792102 \h 14

Textual Manifest PAGEREF _Toc193792103 \h 14

Agent updates. PAGEREF _Toc193792104 \h 14

Console update - Changed / added  files. PAGEREF _Toc193792105 \h 14

 

Introduction

Assuria Auditor AutoUpdate #76 is an enhancement update. This AutoUpdate adds the Assuria Information Reporter (AIR) to the Assuria Auditor console introducing new and improved functionality.

 

AIR is standards based using XML for data representation and XSLT style sheets to format output into HTML or PDF. AIR originally developed as part of Assuria Log Manager is to replace the use of Crystal reports within Assuria Auditor.  It is intended that Crystal Reports will be removed via the AutoUpdate process in approximately 3 months time. 

 

AIR is now common to both Assuria Auditor and Assuria Log Manager and will be a key component of future Assuria products. 

 

Retention of Crystal reports: Any users who would like the Crystal Reports functionality to be retained after that time please contact Assuria.

 

Assuria Auditor User Guide

The Assuria Auditor Users Guide has been updated to include the changes introduced at the AutoUpdate and the updated Users Guide is available for download from AssuriaOnline.

 

Transition to AIR

The transition to AIR requires no specific user action, the application of Assuria AutoUpdate #76 will add AIR to your system.

 

Changing default reporting format.

The default reporting format for multi-session reports can be changed by going to the Maintenance menu – Maintenance -> Options Reporting tab.

 

 

Crystal reports

At Assuria AutoUpdates #76 all of the Assuria Auditor multi-session reports currently produced via Crystal reports are replicated in AIR.  

 

In addition some new reports are added and include:

•        Agent AU Level

•        Agent Population by OS

•        Last Agent Communications

•        Most Recent Scan.

 

Further reports are planned in upcoming releases. 

 

Users are invited to submit requests for additional reports to info@assuria.com.

 

Assuria Auditor Console changes

The integration of AIR into the Assuria Auditor Console has enabled further enhancements to the user interface. 

 

The Console dashboard includes charts to show:

•        Agent AU Level

•        Agent Population by OS

•        Last Agent Communications

•        Most Recent Scan.

 

 

At this AutoUpdate Assuria has added the ability to print the data making up to the dashboard graphs. 

 

In addition Users can also view the data contributing to the graphical information by double clicking on any bar on the graph.

 

 

 

Assuria Information Reporter

Assuria Information Reporter brings new options to the multi-session reports, these include the ability to select risk levels to be reported.

 

 

The browse tab exposes the ‘View’, ‘Export’ and ‘Delete’ buttons.   ‘View’ allows previously generated reports to be viewed.

 

‘Export’ copies the report to another folder in the current format.

 

 

Assuria Auditor multi-session reports

 

Multi-session reports are designed to give an overview of the security of the enterprise’s information systems. Reports are produced from the results of a single scan or from multiple scans as required.

 

There are three groups of multi-session reports:

 

  • Executive reports assist with high level decisions about the status and direction of the information system’s security level.

 

  • Line Management reports help with decisions about applying high level plans.

 

  • Technician reports are tools for applying decisions to the information system.

 

 

Administration Reports:

Administration Reports assist the Assuria Auditor administrator to manage an installation with relevant information about the population of managed Assuria Auditor agents.

 

The existing Administration Report

 

·         Agent AU Level – Shows the current AU level as known by the Console of all configured agents.

 

is complemented by the addition of the reports below.

 

·         Agent Population by Operating System shows the agent population by operating system.

 

·         Last Agent Communications shows the date / time the Console last received communication from agents.

 

·         Most Recent Scan shows the date / time of the last recorded scan for the agent.

 

 

 

Executive Reports

Executive Reports assist with high level decisions about the status and direction of the each system and the installation’s security level. 

 

The available Executive reports are:

 

Latest State:

Graphical representation and analysis of the vulnerabilities detected for selected agents and/or classes during the last scan within (or for) each session.

 

Network Trends Analysis:

This report displays a month by month comparison of vulnerabilities. It displays the:

·         Percentage of checks for which vulnerabilities were found

·         Percentage of checks for which vulnerabilities were found, broken out into the three risk levels of High, Medium, and Low.

 

Network Vulnerability Assessment Summary

This report is useful for assessing the organization’s susceptibility to violation in relation to its policy and vulnerability conditions. It displays the:

·         Distribution of vulnerabilities by risk level

·         Percent of vulnerabilities by risk level

·         Percent of vulnerabilities per run.

Scan Differences:    

Information about vulnerabilities that are unique to a specific scan. You select a group of scans, then specify the ID of the scan you want to report on. Assuria Auditor compares the results of the selected scan to the results of the group and reports on any vulnerabilities that are unique to that scan.

 

Scans Summary sorted by Host:

Graphical representation, sorted by host, of the:

·         Percentage of High, Medium, and Low vulnerabilities found during the selected scans

·         Percentage of High, Medium, and Low checks that were run during the selected scans (the total, regardless of whether or not a vulnerability was detected).

 

Scans Summary sorted by Vulnerability:

This report is the same as the previous Scans Summary by Host report, except it is sorted by vulnerability.

 

Scorecard:    

A numerical representation of the vulnerabilities found, to allow a comparison of all agents in the system.  A simple vulnerability scoring system is used to create this report.

 

Vulnerable Agents: 

The Vulnerable Agents report shows the agent with the most vulnerabilities.  In graphical form it is useful to identify if a single or small number of servers are inconsistent with other similar systems.

 

 

Detail from the ‘Vulnerable agents’ report.

 

 

Line Manager and Technicians reports

Are designed to help with decisions about applying high level plans.

 

Host Assessment:  

Detailed information about each vulnerability found in the selected scans. For each host included in the report, vulnerability information is presented in decreasing risk level order. The detail section is preceded by a graphical summary of the vulnerabilities found, plus a tabulation of all checks made.

 

Vulnerability Assessment:

Descriptions of the vulnerabilities detected in selected scans. Vulnerabilities are presented in decreasing risk level order, with a list of each host affected. The detail section is preceded by a graphical summary of the vulnerabilities found, plus a tabulation of all checks used in the scans

 

Session based reports

Session based reporting is focused on reporting for a single scan or session.  These reports are produced by default and are typically in HTML format.  Assuria has enhanced the functionality in this are with Standard based reports and expanding HTML reports. See Assuria Bulletin 37 for more information.

 

Applicable platforms          

Assuria Auditor Console only.

 

Textual Manifest

The full manifest of new and changed files for this update can be viewed below

 

Agent updates

There are no agent updates in this AU.

 

Console update

    o Files updated

      - bin/tcl/config.tbc

      - bin/tcl/crystal.tbc

      - bin/tcl/db.tbc

      - bin/tcl/report.tbc

      - bin/tcl/treeutils.tbc

      - chelp/administrative_reports.html

      - chelp/Executive.html

      - chelp/Reports.html

 

    o New files

      - bin/jre1.6.0_03

      - bin/jre1.6.0_03/bin

      - bin/jre1.6.0_03/COPYRIGHT

      - bin/jre1.6.0_03/lib

      - bin/jre1.6.0_03/LICENSE

      - bin/jre1.6.0_03/PATCH.ERR

      - bin/jre1.6.0_03/README.txt

      - bin/jre1.6.0_03/THIRDPARTYLICENSEREADME.txt

      - bin/jre1.6.0_03/Welcome.html

      - bin/jre1.6.0_03/bin/awt.dll

      - bin/jre1.6.0_03/bin/axbridge.dll

      - bin/jre1.6.0_03/bin/client

      - bin/jre1.6.0_03/bin/cmm.dll

      - bin/jre1.6.0_03/bin/dcpr.dll

      - bin/jre1.6.0_03/bin/deploy.dll

      - bin/jre1.6.0_03/bin/dt_shmem.dll

      - bin/jre1.6.0_03/bin/dt_socket.dll

      - bin/jre1.6.0_03/bin/fontmanager.dll

      - bin/jre1.6.0_03/bin/hpi.dll

      - bin/jre1.6.0_03/bin/hprof.dll

      - bin/jre1.6.0_03/bin/instrument.dll

      - bin/jre1.6.0_03/bin/ioser12.dll

      - bin/jre1.6.0_03/bin/j2pcsc.dll

      - bin/jre1.6.0_03/bin/j2pkcs11.dll

      - bin/jre1.6.0_03/bin/jaas_nt.dll

      - bin/jre1.6.0_03/bin/java-rmi.exe

      - bin/jre1.6.0_03/bin/java.dll

      - bin/jre1.6.0_03/bin/java.exe

      - bin/jre1.6.0_03/bin/javacpl.cpl

      - bin/jre1.6.0_03/bin/javacpl.exe

      - bin/jre1.6.0_03/bin/javaw.exe

      - bin/jre1.6.0_03/bin/javaws.exe

      - bin/jre1.6.0_03/bin/java_crw_demo.dll

      - bin/jre1.6.0_03/bin/jawt.dll

      - bin/jre1.6.0_03/bin/JdbcOdbc.dll

      - bin/jre1.6.0_03/bin/jdwp.dll

      - bin/jre1.6.0_03/bin/jli.dll

      - bin/jre1.6.0_03/bin/jpeg.dll

      - bin/jre1.6.0_03/bin/jpicom.dll

      - bin/jre1.6.0_03/bin/jpiexp.dll

      - bin/jre1.6.0_03/bin/jpinscp.dll

      - bin/jre1.6.0_03/bin/jpioji.dll

      - bin/jre1.6.0_03/bin/jpishare.dll

      - bin/jre1.6.0_03/bin/jsound.dll

      - bin/jre1.6.0_03/bin/jsoundds.dll

      - bin/jre1.6.0_03/bin/jucheck.exe

      - bin/jre1.6.0_03/bin/jureg.exe

      - bin/jre1.6.0_03/bin/jusched.exe

      - bin/jre1.6.0_03/bin/keytool.exe

      - bin/jre1.6.0_03/bin/kinit.exe

      - bin/jre1.6.0_03/bin/klist.exe

      - bin/jre1.6.0_03/bin/ktab.exe

      - bin/jre1.6.0_03/bin/management.dll

      - bin/jre1.6.0_03/bin/msvcr71.dll

      - bin/jre1.6.0_03/bin/net.dll

      - bin/jre1.6.0_03/bin/nio.dll

      - bin/jre1.6.0_03/bin/npjava11.dll

      - bin/jre1.6.0_03/bin/npjava12.dll

      - bin/jre1.6.0_03/bin/npjava13.dll

      - bin/jre1.6.0_03/bin/npjava14.dll

      - bin/jre1.6.0_03/bin/npjava32.dll

      - bin/jre1.6.0_03/bin/npjpi160_03.dll

      - bin/jre1.6.0_03/bin/npoji610.dll

      - bin/jre1.6.0_03/bin/npt.dll

      - bin/jre1.6.0_03/bin/orbd.exe

      - bin/jre1.6.0_03/bin/pack200.exe

      - bin/jre1.6.0_03/bin/policytool.exe

      - bin/jre1.6.0_03/bin/regutils.dll

      - bin/jre1.6.0_03/bin/rmi.dll

      - bin/jre1.6.0_03/bin/rmid.exe

      - bin/jre1.6.0_03/bin/rmiregistry.exe

      - bin/jre1.6.0_03/bin/servertool.exe

      - bin/jre1.6.0_03/bin/splashscreen.dll

      - bin/jre1.6.0_03/bin/ssv.dll

      - bin/jre1.6.0_03/bin/sunmscapi.dll

      - bin/jre1.6.0_03/bin/tnameserv.exe

      - bin/jre1.6.0_03/bin/unpack.dll

      - bin/jre1.6.0_03/bin/unpack200.exe

      - bin/jre1.6.0_03/bin/verify.dll

      - bin/jre1.6.0_03/bin/w2k_lsa_auth.dll

      - bin/jre1.6.0_03/bin/wsdetect.dll

      - bin/jre1.6.0_03/bin/zip.dll

      - bin/jre1.6.0_03/bin/client/classes.jsa

      - bin/jre1.6.0_03/bin/client/jvm.dll

      - bin/jre1.6.0_03/bin/client/Xusage.txt

      - bin/jre1.6.0_03/lib/applet

      - bin/jre1.6.0_03/lib/calendars.properties

      - bin/jre1.6.0_03/lib/classlist

      - bin/jre1.6.0_03/lib/cmm

      - bin/jre1.6.0_03/lib/content-types.properties

      - bin/jre1.6.0_03/lib/deploy

      - bin/jre1.6.0_03/lib/deploy.jar

      - bin/jre1.6.0_03/lib/ext

      - bin/jre1.6.0_03/lib/flavormap.properties

      - bin/jre1.6.0_03/lib/fontconfig.98.bfc

      - bin/jre1.6.0_03/lib/fontconfig.98.properties.src

      - bin/jre1.6.0_03/lib/fontconfig.bfc

      - bin/jre1.6.0_03/lib/fontconfig.properties.src

      - bin/jre1.6.0_03/lib/fonts

      - bin/jre1.6.0_03/lib/i386

      - bin/jre1.6.0_03/lib/im

      - bin/jre1.6.0_03/lib/images

      - bin/jre1.6.0_03/lib/javaws.jar

      - bin/jre1.6.0_03/lib/jce.jar

      - bin/jre1.6.0_03/lib/jsse.jar

      - bin/jre1.6.0_03/lib/jvm.hprof.txt

      - bin/jre1.6.0_03/lib/logging.properties

      - bin/jre1.6.0_03/lib/management

      - bin/jre1.6.0_03/lib/management-agent.jar

      - bin/jre1.6.0_03/lib/meta-index

      - bin/jre1.6.0_03/lib/net.properties

      - bin/jre1.6.0_03/lib/plugin.jar

      - bin/jre1.6.0_03/lib/psfont.properties.ja

      - bin/jre1.6.0_03/lib/psfontj2d.properties

      - bin/jre1.6.0_03/lib/resources.jar

      - bin/jre1.6.0_03/lib/rt.jar

      - bin/jre1.6.0_03/lib/security

      - bin/jre1.6.0_03/lib/sound.properties

      - bin/jre1.6.0_03/lib/tzmappings

      - bin/jre1.6.0_03/lib/zi

      - bin/jre1.6.0_03/lib/cmm/CIEXYZ.pf

      - bin/jre1.6.0_03/lib/cmm/GRAY.pf

      - bin/jre1.6.0_03/lib/cmm/LINEAR_RGB.pf

      - bin/jre1.6.0_03/lib/cmm/sRGB.pf

      - bin/jre1.6.0_03/lib/deploy/ffjcext.zip

      - bin/jre1.6.0_03/lib/deploy/messages.properties

      - bin/jre1.6.0_03/lib/deploy/messages_de.properties

      - bin/jre1.6.0_03/lib/deploy/messages_es.properties

      - bin/jre1.6.0_03/lib/deploy/messages_fr.properties

      - bin/jre1.6.0_03/lib/deploy/messages_it.properties

      - bin/jre1.6.0_03/lib/deploy/messages_ja.properties

      - bin/jre1.6.0_03/lib/deploy/messages_ko.properties

      - bin/jre1.6.0_03/lib/deploy/messages_sv.properties

      - bin/jre1.6.0_03/lib/deploy/messages_zh_CN.properties

      - bin/jre1.6.0_03/lib/deploy/messages_zh_HK.properties

      - bin/jre1.6.0_03/lib/deploy/messages_zh_TW.properties

      - bin/jre1.6.0_03/lib/deploy/splash.jpg

      - bin/jre1.6.0_03/lib/ext/dnsns.jar

      - bin/jre1.6.0_03/lib/ext/meta-index

      - bin/jre1.6.0_03/lib/ext/sunjce_provider.jar

      - bin/jre1.6.0_03/lib/ext/sunmscapi.jar

      - bin/jre1.6.0_03/lib/ext/sunpkcs11.jar

      - bin/jre1.6.0_03/lib/fonts/LucidaSansRegular.ttf

      - bin/jre1.6.0_03/lib/i386/jvm.cfg

      - bin/jre1.6.0_03/lib/im/indicim.jar

      - bin/jre1.6.0_03/lib/im/thaiim.jar

      - bin/jre1.6.0_03/lib/images/cursors

      - bin/jre1.6.0_03/lib/images/cursors/cursors.properties

      - bin/jre1.6.0_03/lib/images/cursors/invalid32x32.gif

      - bin/jre1.6.0_03/lib/images/cursors/win32_CopyDrop32x32.gif

      - bin/jre1.6.0_03/lib/images/cursors/win32_CopyNoDrop32x32.gif

      - bin/jre1.6.0_03/lib/images/cursors/win32_LinkDrop32x32.gif

      - bin/jre1.6.0_03/lib/images/cursors/win32_LinkNoDrop32x32.gif

      - bin/jre1.6.0_03/lib/images/cursors/win32_MoveDrop32x32.gif

      - bin/jre1.6.0_03/lib/images/cursors/win32_MoveNoDrop32x32.gif

      - bin/jre1.6.0_03/lib/management/jmxremote.access

      - bin/jre1.6.0_03/lib/management/jmxremote.password.template

      - bin/jre1.6.0_03/lib/management/management.properties

      - bin/jre1.6.0_03/lib/management/snmp.acl.template

      - bin/jre1.6.0_03/lib/security/cacerts

      - bin/jre1.6.0_03/lib/security/java.policy

      - bin/jre1.6.0_03/lib/security/java.security

      - bin/jre1.6.0_03/lib/security/javaws.policy

      - bin/jre1.6.0_03/lib/security/local_policy.jar

      - bin/jre1.6.0_03/lib/security/US_export_policy.jar

      - bin/jre1.6.0_03/lib/zi/Africa

      - bin/jre1.6.0_03/lib/zi/America

      - bin/jre1.6.0_03/lib/zi/Antarctica

      - bin/jre1.6.0_03/lib/zi/Asia

      - bin/jre1.6.0_03/lib/zi/Atlantic

      - bin/jre1.6.0_03/lib/zi/Australia

      - bin/jre1.6.0_03/lib/zi/CET

      - bin/jre1.6.0_03/lib/zi/CST6CDT

      - bin/jre1.6.0_03/lib/zi/EET

      - bin/jre1.6.0_03/lib/zi/EST

      - bin/jre1.6.0_03/lib/zi/EST5EDT

      - bin/jre1.6.0_03/lib/zi/Etc

      - bin/jre1.6.0_03/lib/zi/Europe

      - bin/jre1.6.0_03/lib/zi/GMT

      - bin/jre1.6.0_03/lib/zi/HST

      - bin/jre1.6.0_03/lib/zi/Indian

      - bin/jre1.6.0_03/lib/zi/MET

      - bin/jre1.6.0_03/lib/zi/MST

      - bin/jre1.6.0_03/lib/zi/MST7MDT

      - bin/jre1.6.0_03/lib/zi/Pacific

      - bin/jre1.6.0_03/lib/zi/PST8PDT

      - bin/jre1.6.0_03/lib/zi/SystemV

      - bin/jre1.6.0_03/lib/zi/WET

      - bin/jre1.6.0_03/lib/zi/ZoneInfoMappings

      - bin/jre1.6.0_03/lib/zi/Africa/Abidjan

      - bin/jre1.6.0_03/lib/zi/Africa/Accra

      - bin/jre1.6.0_03/lib/zi/Africa/Addis_Ababa

      - bin/jre1.6.0_03/lib/zi/Africa/Algiers

      - bin/jre1.6.0_03/lib/zi/Africa/Asmara

      - bin/jre1.6.0_03/lib/zi/Africa/Bamako

      - bin/jre1.6.0_03/lib/zi/Africa/Bangui

      - bin/jre1.6.0_03/lib/zi/Africa/Banjul

      - bin/jre1.6.0_03/lib/zi/Africa/Bissau

      - bin/jre1.6.0_03/lib/zi/Africa/Blantyre

      - bin/jre1.6.0_03/lib/zi/Africa/Brazzaville

      - bin/jre1.6.0_03/lib/zi/Africa/Bujumbura

      - bin/jre1.6.0_03/lib/zi/Africa/Cairo

      - bin/jre1.6.0_03/lib/zi/Africa/Casablanca

      - bin/jre1.6.0_03/lib/zi/Africa/Ceuta

      - bin/jre1.6.0_03/lib/zi/Africa/Conakry

      - bin/jre1.6.0_03/lib/zi/Africa/Dakar

      - bin/jre1.6.0_03/lib/zi/Africa/Dar_es_Salaam

      - bin/jre1.6.0_03/lib/zi/Africa/Djibouti

      -