Security Database https://www.security-database.com/toolswatch/ <p>Security-Database help your corporation foresee and avoid any security risks that may impact your IT infrastructure and business applications.</p> en SPIP - www.spip.net Working on Common Vulnerability Scoring System v3 integration https://www.security-database.com/toolswatch/Working-on-Common-Vulnerability.html https://www.security-database.com/toolswatch/Working-on-Common-Vulnerability.html 2016-07-31T23:00:00Z text/html en Security Database Team SD Papers Documentations vDNA Update <p>While working on Common Vulnerability Scoring System v3 implementation, we have to make choices. <br class='autobr' /> Some of them are easy, other tricky. As we already say, CVSSv3 and CVSSv2 can be affected to the same alert, and we must keep CVSSv2 for SCAP needs, and simply because some alerts does not have CVSSv3 (old alerts). <br class='autobr' /> We must propagate the right score (and only one per alert). We cannot deal with 2 scores like the NVD, our alerts are linked (see crosslinks demo) <br class='autobr' /> Alerts CVSS scoring priority (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a>, <a href="https://www.security-database.com/toolswatch/+-vDNA-+.html" rel="tag">vDNA</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a> CPE Deprecated Dictionary integration https://www.security-database.com/toolswatch/Handle-of-the-CPE-Deprecated.html https://www.security-database.com/toolswatch/Handle-of-the-CPE-Deprecated.html 2016-06-28T20:38:43Z text/html en Security Database Team SD News Update vDNA Documentations <p>This update is one of our biggest 'technical' updates. We will now fully handle the CPE Deprecated Dictionary made by NVD. Thousand lines of codes, tests, checks, re checks and more. Again, our data quality, but also our alerts, will be greater. <br class='autobr' /> But what is "Deprecated CPE Dictionary." <br class='autobr' /> It means that when a CPE is no more valid, we handle it automatically. We made the change in our database, for alerts, but also on your vDNA Monitoring pool. And, of course, we mail you when it impacts your (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-News-.html" rel="directory">SD News</a> / <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a>, <a href="https://www.security-database.com/toolswatch/+-vDNA-+.html" rel="tag">vDNA</a>, <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a> And Prev? What does that mean? https://www.security-database.com/toolswatch/And-Prev-What-does-that-mean.html https://www.security-database.com/toolswatch/And-Prev-What-does-that-mean.html 2016-03-14T14:13:58Z text/html en Security Database Team SD Papers Documentations Update <p>Some of our data providers use these small typo to explain that a vulnerability affects multiple products and specially “previous version” of a product. <br class='autobr' /> For products like google chrome, we can understand that manually reference 3,000 chrome versions could be hard work. Nevertheless, data integrity is critical! For you, and our alerting system, it's a big miss. So we have worked hard to find an automated way to tag all versions of a product impacted by a vulnerability. It's starting today. <br class='autobr' /> We (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a> CVSS v3 and Updates https://www.security-database.com/toolswatch/CVSS-v3-and-Updates.html https://www.security-database.com/toolswatch/CVSS-v3-and-Updates.html 2015-07-06T12:30:59Z text/html en Security Database Team SD Papers Documentations Update vDNA <p>It's been a year without posting, but not without work. Attentive user has found that we have put into production some changes, like CVSSv3, CPE search, and add some API. We also have added the possibility to change your monitoring email (Business and enterprise). And yes, we also have corrected some bugs ;) Let's now talk about them. <br class='autobr' /> Common Vulnerability Scoring System v3 As you already may know, the Common Vulnerability Scoring System v3, also know as CVSS v3 is now available on First.org. (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a>, <a href="https://www.security-database.com/toolswatch/+-vDNA-+.html" rel="tag">vDNA</a> Code improvement and security, from good to great! https://www.security-database.com/toolswatch/Code-improvement-and-security-from.html https://www.security-database.com/toolswatch/Code-improvement-and-security-from.html 2014-07-28T09:02:02Z text/html en Security Database Team SD Papers Update <p>After the last big update, we have decided to go into maintenance mode and made some code cleanup and rework. Minor change for you, but big update for us. <br class='autobr' /> First of all, we have rewritten our Session Management. It's really interesting that "Session Encryption" does not use a "standard" nor PHP a session option that encrypt into memory... <br class='autobr' /> So we start to work on our own side. But, what encryption mechanism and what PHP module? <br class='autobr' /> Some sites help us with an interesting benchmark between Mcrypt (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a> Customize your monitored Products by adding an Environmental CVSS vector https://www.security-database.com/toolswatch/Customize-your-monitored-Products.html https://www.security-database.com/toolswatch/Customize-your-monitored-Products.html 2014-06-18T13:09:45Z text/html en Security Database Team SD Papers vDNA Documentations Update <p>Yes, it's done! Now, you an customize your monitored products and add, for each one, a CVSS Environmental Vector! But, wait! What is an Environmental Vector and what it can do for you? Simple, lower or higher the score of an Alert, based on YOUR Environment! <br class='autobr' /> The basis Starting with the base, here is the definition of the CVSS Scoring system: <br class='autobr' /> “CVSS is composed of three metric groups: Base, Temporal, and Environmental, each consisting of a set of metrics. These metric groups are described as (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-vDNA-+.html" rel="tag">vDNA</a>, <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a> 58.000+ Nessus files integration and vDNA API update https://www.security-database.com/toolswatch/58-000-Nessus-files-integration.html https://www.security-database.com/toolswatch/58-000-Nessus-files-integration.html 2014-02-17T18:48:06Z text/html en Security Database Team SD Papers Documentations vDNA Update <p>Our Team have integrated 61.240 NASL files, 58.288 Nessus exploits (without marked deprecated or empty) with 190.370+ cpes and 149.850+ "Security-database" References into our database. Integration is done automatically each day, without human interaction like usual. And off course, we have added them to each alert, alert History, CPE, Dashboard, API... <br class='autobr' /> Like the last update, we have integrated Nessus Exploits into our database. Of course, we now display exploits information in each alerts (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a>, <a href="https://www.security-database.com/toolswatch/+-vDNA-+.html" rel="tag">vDNA</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a> vDNA update and Snort Rules integration https://www.security-database.com/toolswatch/vDNA-update-and-Snort-Rules.html https://www.security-database.com/toolswatch/vDNA-update-and-Snort-Rules.html 2014-01-20T08:00:00Z text/html en Security Database Team SD Papers Documentations vDNA Update <p>Happy new year 2014! Our Team have integrated 30.000+ Snort Rules into our database and have improved our vDNA API. Integration is done automatically each day, without human interaction like usual Of course, we have added them to each alert, alert History, CPE, Dashboard, API... <br class='autobr' /> Like our the last update, we have integrated Snort Rules into our database. Of course, we now display Rules information in each alerts and each CPE (Product or Version). At this time, 34 049 Snort Rules. As we (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a>, <a href="https://www.security-database.com/toolswatch/+-vDNA-+.html" rel="tag">vDNA</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a> vDNA Crosslinks as Christmas gift https://www.security-database.com/toolswatch/vDNA-Crosslinks-as-Christmas-gift.html https://www.security-database.com/toolswatch/vDNA-Crosslinks-as-Christmas-gift.html 2013-12-18T08:21:07Z text/html en Security Database Team SD Papers vDNA Update Data Mining <p>vDNA Crosslinks allows you to gather +80.000 Security Alerts data from Security-Database and export it as JSON format. Exports provide related Alert information. By that we mean, all alerts linked to the first one at specified depth. <br class='autobr' /> We are proud to bring you our latest creation, vDNA Crosslinks. What alerts are linked to each other ? What is the vulnerability scoring propagation? We offer this information as JSON format and have built a demo website to play with, and perhaps, give you (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-vDNA-+.html" rel="tag">vDNA</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a>, <a href="https://www.security-database.com/toolswatch/+-Data-Mining-+.html" rel="tag">Data Mining</a> CVE syntax is changing https://www.security-database.com/toolswatch/CVE-syntax-is-changing.html https://www.security-database.com/toolswatch/CVE-syntax-is-changing.html 2013-12-14T15:30:36Z text/html en Security Database Team SD Papers Documentations Update <p>CVE syntax is changing on January 1, 2014. Be prepared, modify and test your code. This modification is not a big deal, the last 4 fixed digits became arbitrary digits with a minimum of 4 and without a maximum. <br class='autobr' /> "The new syntax for CVE Identifiers (CVE-IDs), which was determined in a recent vote by the CVE Editorial Board, will take effect on January 1, 2014. This announcement is being made now so that users will have enough time to change their processes and software to handle the new ID (...)</p> - <a href="https://www.security-database.com/toolswatch/-SD-Papers-.html" rel="directory">SD Papers</a> / <a href="https://www.security-database.com/toolswatch/+-Documentations-+.html" rel="tag">Documentations</a>, <a href="https://www.security-database.com/toolswatch/+-Update-+.html" rel="tag">Update</a>