Host-based security assessment tool that
addresses many different aspects of internal enterprise security.
HostCHECK is designed to offset the increase in internal computer crime
from current or former employees, vulnerabilities that exist within the
operating system, as well as unintentional security breaches. The tool is part
of DMW's family of adaptive e-business solutions that help companies leverage
the power of advanced networks in order to conduct business and deliver service
online in a secure environment.
HostCHECK was designed to give
companies the option of performing security assessments on a regular basis
without relying on a third party. Most importantly, HostCHECK was developed
with e-business in mind.
DMW's vulnerability database exposes close to 2000 vulnerabilities.
ersion 2.0 features six tools
and six utilities to assess and maintain security in the network. Together
these tools and utilities determine the weaknesses of each system, giving the
users the ability to evaluate, assess, improve, correct, manage, and maintain
security.
- Evaluate -- The Configuration Check module automatically
detects
system characteristics, allowing HostCHECK to correctly configure itself on
the installed platform. It identifies files considered
critical to their security configuration of the computer or files that, if
tampered with, can be used for penetration purposes.
- Assess -- Several modules perform a thorough security assessment
on the host system. These include Directory Check, Integrity Check, Network
Check and User Check. DMW's CrackIT is another
assessment module capable of cracking passwords locally and remotely with the
goal of helping organizations improve the
integrity of file access passwords. Directory Check, which searches files for
insecure permissions, is extremely fast,
checking the security of up to 30,000 files in 60 seconds.
- Correct and Improve -- The AutoCorrect feature is designed so
that when HostCHECK detects a problem, it displays a screen prompt that
identifies the vulnerability, suggests a correction
and provides the rational and impact of that correction. This feature provides
the host with an immediate improvement in
security. In addition, HostCHECK includes the MarkIT utility, allowing users
to mark security critical files, and RemoveIT, a
secure file wipe program.
- Manage Configuration -- The User Manager provides administrators
with a standard interface that can be run across multiple Unix platforms and
allows them to manage account and group structures
uniformly. This eliminates the creation of new security vulnerabilities when
new accounts are created, thus greatly
improving system administration and reducing security weaknesses.