Friday 17 February 2012

Evaluation of Nessus Version 5

Evaluating Nessus v5 by comparing it against the previous version in a head to head against a test web application, used the badstore.net vulnerable web application as the target for the comparison.

There is an improvement in the GUI and the way the results displayed in version 5 additional it has 5 categories of issues compared to the 3 categories in v4, there is now a critical, high, medium, low and info. Using Nessus version 4 I detected 81 issues across its 3 categories against the test application, with Nessus version 5 it detected 90 issues across its 5 categories.

Summary

A quick analysis shows version 5 better categorised the detected issues, this is helped by the 2 addition categories, in timing performance it seemed slightly slow than version 4, although I need to do the time tests under better test conditions.
In general version 5 seems to be an improvement and the client GUI is a definite improvement along with the additional categories. One point is that to get the best of the new client GUI in version when reviewing the issues, a large wide screen monitor is desirable.

I will post additional results if I get the time.

Screen shot of Nessus v4

Screen shot of Nessus v5

No comments:

Post a Comment