Vulnerability Scanning and Remediation
What is vulnerability scanning?
To help protect against computer viruses and other security threats, the campus scans computers that are attempting to connect to secure campus services, (i.e., those requiring Kerberos passwords for authentication). Access is denied to computers determined to be vulnerable or infected. When no vulnerability or infection is found, the computer is permitted to log on without interruption.
The campus also monitors traffic coming into and going out of the campus network by using an intrusion prevention system (IPS). In the event that the IPS detects malicious traffic – such as attempts to exploit vulnerabilities or commit identity theft – the IPS prevents the traffic from reaching its intended destination. Like all security measures, the IPS does not catch 100% of the malicious traffic, so you should continue to run your anti-virus program, install software patches, guard against identity theft and take other actions to protect your information and your computer.
What do I need to do if my computer is denied access when I try to authenticate?
Instructions for solving the problem and regaining access will be provided.
What happens if the IPS detects malicious traffic coming from or going to my computer?
If the IPS finds malicious traffic going to your computer, it will block the traffic. If the traffic is coming from your computer, you may find that you are suddenly unable to access certain web sites or applications that you were previously able to access. If this happens, call IT Express at 530-754-4357 for assistance.
What happens if the campus encounters a problem on my computer when I try to authenticate that cannot be fixed?
The campus may occasionally scan for critical problems for which no fix is yet available. In this case, you may be warned of the problem; however, access to the campus network will not be denied until a fix is available.
Will the campus scan my computer if I am attempting to connect to the campus network from off-campus?
No, the campus will not scan computers attempting to access the campus network from an off-campus location.
What is the self-scanning service?
This web-based service allows you to test your computer for selected viruses and vulnerabilities. To use this service, visit selfscan.ucdavis.edu and click "Test My Computer." Information for repairing any vulnerabilities and/or infections will be provided as needed when the scan is complete. When testing a computer from an off-campus location, you will be prompted for your campus login ID and Kerberos password.