Educause Security Discussion mailing list archives

Re: Checking for AV software on students' machines


From: Craig Blaha <blaha () TCNJ EDU>
Date: Wed, 9 Jun 2004 13:30:22 -0400

I'd be interested in this as well, especially related to whether the
personal firewall delivered with MS will block this scan. We're deciding
whether or not to build an automated DMZ system, but if the latest
versions of windows are delivered with the firewall on, it seems that
will limit the useful life of this type of scan process.

Thanks,
Craig Blaha

Mike Wiseman wrote:

I'd be interested to hear the details of your patch version checking system. Our group is
in the process of combining NetReg (www.netreg.org) and Nessus for this purpose. In
regards to your quest to obtain more information from an unmanaged end station, I too am
looking for this next step and have begun to look at adapting open-source software
installer packages. The intention is for the end user to download/run this application
which would gather pertinent data and send it to the admin host.

Mike Wiseman
Manager - Computer Security Administration
Computing and Networking Services
University of Toronto



Now that we have found a way to check students' machines for missing
patches before they are allowed on the network, we are looking to expand
to checking for the presence of updated anti-virus software. This
requires access to the students' machines, so we are looking at using a
web page with a .NET component to perform the check. A few questions:

1) Is anyone else doing something like this currently?
2) How have you implemented this (web page w/ ActiveX/.Net, downloadable
program...)?
3) What do you look for to determine if AV software is present (registry
entries, services, running processes...)?
4) How successful has it been?
5) Pitfalls?




**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.



--

   *Craig Blaha*
   /Associate Director
   Information Policy, Security and Web Development/
   The College of New Jersey
   PO Box 7718
   Ewing, NJ 08628
   www.tcnj.edu

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.

Current thread: