Jump to main navigation Jump to main navigation Jump to main content Jump to footer content

Vulnerability scanning service

HITS IS operates a state-of-the-art vulnerability scanning service, which is operated at the LRZ by HITS IS employees. The service can be used to check systems in the publicly accessible networks of participating universities for vulnerabilities. HITS IS helps to plan the vulnerability scans, carry them out and sends reports on the identified vulnerabilities to the universities. With regular scan results, the universities can ensure the successful elimination of existing security deficiencies and check for newly emerging dangers.

The following software is currently used for the scans (subject to change):

  • Nessus Expert (Tenable)
  • Greenbone Enterprise and Community Edition
  • Nmap
  • shodan.io

Scope of Services and Service Specifics

  • Perform vulnerability scans
  • Generate reports (criticality assessment and scan results with instructions for action) within 2 weeks

 

Service Parameters

The scans are carried out by arrangement in defined time windows. Maintenance takes place in scheduled maintenance windows, these are currently Tue., 7:30 a.m. – 9:00 a.m. and Thurs., 7:30 a.m. – 9:00 a.m.

The HITS IS uses its own technical infrastructure at the LRZ for the scans and advises on the systems to be scanned, vulnerabilities, scan frequency and scan time. 

Scan Option 1:

  • Regular scans of publicly accessible systems
  • max. 1x per month

It takes 3 weeks from the order of the service until the service can be used by the customer.

Scan Option 2:

  • Execution of ad-hoc scans of publicly accessible systems
  • max. 2x per year per university

Requirements

  • Maintenance and disclosure of the IP address ranges to be checked (definition of exceptions, time windows for scans, etc.)
  • Notification to HITS IS in the event of changes to the university network infrastructure
  • Internal communication of planned scans and identified vulnerabilities within the university
  • Specifying a report recipient (preferably a function email address) for the generated report
  • Possibility of receiving encrypted e-mails (S/MIME, OpenPGP) by the report recipient and/or retrieval from a secure online storage
  • Assessment of vulnerabilities according to internal guidelines
  • Elimination of the vulnerabilities or active processing of the received report

 

User / Customers

This service is made available to the following categories of users.

 

User classNote
(1), (2)only for members of the Digital Network of Bavaria
(3), (4), (5), (6)not available for these customers

 

The service can be requested by CIO, CISO, ISB or data center management of the universities in the digital network via e-mail to informationssicherheit@remove-this.digitalverbund.bayern .