OS identification (OSID) certainty

Enterprise Scanner determines whether to run a check against a host based on the certainty of the OS information in SiteProtector and the setting in the Assessment policy that specifies what action to take if the OSID is uncertain.

What determines certainty?

The certainty with which a source provides a completely accurate OSID is based on the quality of the information available to the source. For example, OSID from an IBM Proventia Desktop agent is always considered certain because the agent has full access to information about the asset. OSID from an Enterprise Scanner scan is considered certain if the scanner had authenticated access but uncertain if it did not.

Sources of OSID

Information that identifies the operating system of an asset can come from different sources, such as agents or even directly from users. Each source has access to slightly different data, which makes some sources relatively more certain than others. SiteProtector receives OSID information in any of the following methods:

vEntered manually by a user

vImported from Active Directory

vReported by Proventia Desktop agent

vDiscovered by Enterprise Scanner

vDiscovered by Internet Scanner

Certainty of OSID sources

The following table describes the relative certainty of the sources of OSID data:

Table 23. Relative certainty of the sources of OSID data

Source of OSID Data

Relative Certainty

 

 

User

Certain

Active Directory

 

Desktop agent

 

 

 

Enterprise Scanner

Certain if obtained with authenticated access

 

Uncertain if not obtained with authenticated

 

access

 

 

Internet Scanner

Uncertain

 

 

Comparing Enterprise Scanner and Internet Scanner results

If you want to make a valid comparison of OSID results between Enterprise Scanner and Internet Scanner, you must make sure that you provide equivalent login access to both products.

104Enterprise Scanner: User Guide

Page 112
Image 112
IBM Partner Pavilion 2.3 manual OS identification Osid certainty, What determines certainty?, Sources of Osid