Ballista

Evaluation Halted: Aug 4th, 1997
This evaluation was done on a copy with very limited functionality . The report is not complete until a fully functional copy of Ballista can be obtained.


Name

Ballista

Release Information

Product of Secure Networks Inc (SNI)
Version 1.2
Evaluation copies available for download at http://www.secnet.com

Support

Email : Ballista-questions@secnet.com
Ph : 403-262-9211
(I must say that the quality of support provided could be better. They have not even bothered to send me a fully functional copy of their product inspite of two reminders)

Functionality

The Ballista Security Auditing System is a network security auditing tool on the lines of the ISS Scanner. It performs evaluations of intranets, web servers, firewalls and routers.

Requirements

Supported for the following Unix flavours

Documentation

The User Manual which is available at ftp://ftp.secnet.com/pub/ballista/manuals/userguide-html.tar.gz

Installing Ballista

  1. Change your Desktop Environment to Openview
  2. Log in as root or use sudo
  3. cp Ballista_Demo_Solaris.2.5.tar to your local directory
  4. Unpack the archive in that directory
  5. Change the working directory to ballista
  6. Run the script ./xinterface (motif interface) or ./interface (textual interface)

Problems Faced

  1. Ballista can be installed only using OpenWindows. It does not work with the default Common Desktop Enviroment. The developers are working on this.

Starting S3

  1. Log in as root
  2. Change working directory to ballista
  3. Run the script ./xinterface (motif interface) or ./interface (textual interface)

Problems Faced

  1. Cannot run the tool without the license key. This key is machine specific and has to be present in the ballista directory and saved as license.key. It can be ordered from SecNet.

Configuring S3

Key in the following values while configuring ballista

  1. Click on "Create New Configuration" button
  2. DNS domain name : barnum.cs.purdue.edu
  3. Host's IP address :  < do a nslookup on the host >
  4. Network Interface :  The default value provided is usually correct.
  5. NIS Domain Name : cs.purdue.edu
  6. Gateway: 
  7. Web Browser : /usr/local/www/netscape

Evaluation Details

The Good News :

    The Bad News :

    1. Poor customer service and techhnical Support
    2. User Interface could be better
    3. The evaluation copy does not generate a proper scan

    Features

    The features can be classified into :

    Conclusion

    I have not seen a working copy of the complete Ballista tool. The evaluation copy did not perform a scan on the local host at all.

    Recommendation

    Discussion.


    This review was written by Jai Sundar Balasubramaniyan <balasujs@cs.purdue.edu> during the summer of 1997. The opinions expressed are for purposes of critical review, and do not represent any official recommendation or endorsement by COAST or Purdue University.