Home > Security Channel Tips > Network Security > Using Microsoft Baseline Security Analyzer to detect security holes
Security Channel Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY

Using Microsoft Baseline Security Analyzer to detect security holes


Brien M. Posey
11.12.2007
Rating: --- (out of 5)


Security Channel Update
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


As a reseller of computer hardware and software, you may occasionally have customers ask you to verify that their networks are secure. While verifying the security of an entire network is a huge undertaking, it is relatively easy to perform a check to make sure that servers and workstations have the latest security patches and adhere to Microsoft's security best practices. The tool of choice for doing so is the Microsoft Baseline Security Analyzer (MBSA).

You can download Microsoft Baseline Security Analyzer versions 2.0.1 and 2.1, currently in beta testing, from Microsoft. For the purposes of this article, I demonstrate version 2.1, because it is the only version of MBSA that is fully compatible with Windows Vista.

More from Brien Posey
Check out Brien Posey's firewall troubleshooting tip series.

Downloading and installing MBSA version 2.1 is easy. The download is only 1.3 MB in size (at least for the current beta of the X86 version). Once the download completes, the installation process consists of little more than accepting the end-user license agreement and verifying the installation path.

When you finish installing Microsoft Baseline Security Analyzer, a shortcut to it will appear on the Start | All Programs menu. When you launch MBSA for the first time, you will be given the choice of either scanning a computer or scanning multiple computers, as shown in Figure A. Assuming that your purpose in running MBSA is to validate the security of a particular configuration, you will want to choose the option to scan a computer.


Figure A: You can use the "Scan a Computer" option to validate a single computer's security configuration.

Click Next and you will be prompted to enter either the name or the IP address of the computer that you want to run the scan against. As you can see in Figure B, the local computer is selected by default. If you need to run a scan against a remote Windows Vista machine, then you must download version 3.0 of the Windows Update Agent (WUA 3.0).


Figure B: You must specify either the name or the IP address of the computer that you want to scan.

As you can see in the figure above, MBSA allows you to customize the name of the report that it produces and choose the types of tests that it runs. It's worth taking a moment to go through the lists of tests, because the defaults aren't always appropriate for every system.

Once you have decided which tests to run, click the "Start Scan" button. MBSA will take a few minutes to download security updates from Microsoft and then begin the scan.


Figure C: This is the resulting report after the completed scan.

When the scan completes, the resulting report will look something like the one that's shown in Figure C. I wrote this article on my laptop in a hotel room, and the hotel's firewall prevents the MBSA from downloading the updated security settings, but the rest of what you see in the figure should be fairly accurate.

MBSA allows you to sort the report so that the most pressing issues are listed first. This makes it less likely that you will overlook an important issue that's buried deep within the list of results.

About the author
Brien M. Posey, MCSE, is a Microsoft Most Valuable Professional for his work with Windows 2000 Server and IIS. Brien has served as CIO for a nationwide chain of hospitals and was once in charge of IT security for Fort Knox. As a freelance technical writer he has written for Microsoft, CNET, ZDNet, TechTarget, MSD2D, Relevant Technologies and other technology companies. You can visit Brien's personal Web site at www.brienposey.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurityChannel.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network Security
How to help customers choose a network access control product
Offering SaaS for securing mobile devices
How to perform a network security audit for customers
Cracks in WPA? How to continue protecting Wi-Fi networks
Host-based IDS/IPS Partner Program Directory
Network security algorithms introduction
Searching for multiple strings in packet payloads
Approximate string matching
Detecting worms
IP traceback via logging

Network intrusion detection and prevention defenses
SIEM services help customers with security monitoring
Implementing IDS/IPS technologies: Managing politics and accountability
Juniper launches mid-level security appliances
Must-haves for wireless network security: WLAN switches, intrusion detection and more
Host-based IDS/IPS Partner Program Directory
Understanding Snort's Unified2 output
Network security algorithms introduction
Searching for multiple strings in packet payloads
Approximate string matching
Detecting worms

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts