Vulnerability databases: does size matter?
The information in this article applies to:
- GFI LANguard 9.0
- GFI LANguard Network Security Scanner 5
- GFI LANguard Network Security Scanner 6
- GFI LANguard Network Security Scanner 7
- GFI LANguard Network Security Scanner 8
Article ID: KBID002207
Query keywords:
Many competitors use the 'size' of their vulnerability database to justify their higher price. In truth, the number of vulnerability checks is almost irrelevant. What counts is the kind and quality of checks performed.
It's very easy to create a large database of vulnerabilities. Such databases include vulnerabilities in old OS and software versions, old software that is no longer used, and so on. However, this slows down the scanning process and provides you with useless information and unnecessary false positives.
What is important is that you look at the product's scanning capabilities and the quality of the checks performed! For example:
- Are missing patches identified correctly?
- Is important Windows information enumerated?
- Are Linux machines correctly identified and scanned?