Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  What are the advantages of DAS vs Vulnerability scaner

    Posted 06-27-2021 09:03
    Dear 
          I know that DAS can scan and find DB Vulnerability,but i don't know what are the advantages of DAS vs scaner like tenable or rapid7 DB scan.
          Which friend has compared the difference between DAS and scaner, what are the adventages of imperva DAS?

    #DatabaseActivityMonitoring

    ------------------------------
    jeff gao
    security Engineer
    Shanghai�SHNetworks Technology Co.,Ltd.
    Shanghai
    ------------------------------


  • 2.  RE: What are the advantages of DAS vs Vulnerability scaner

    Posted 06-28-2021 10:05
    Hi Jeff,

    Most vulnerability scanners will look for missing patches.  In addition to that, DAS will also look for vulnerabilities in the DB configuration itself and map it to existing standards (CIS and DISA).  

    Examples of things that vulnerability scanners might miss:  password complexity requirements, tables that have public permissions, guest users enabled, tables with permissions directly applied instead of groups.

    Jim

    ------------------------------
    Jim Burtoft
    SE
    State College PA
    ------------------------------