1 Introduction¶
1.1 Vulnerability Management¶
In IT security, the combination of three elements influences the attack surface of an IT infrastructure:
Cyberattackers with sufficient experience, equipment and money to carry out an attack.
Access to the IT infrastructure.
Vulnerabilities in IT systems, caused by errors in applications and operating systems, or incorrect configurations.
If these three elements come together, a successful attack on the IT infrastructure is likely.
Since most vulnerabilities are known and can be fixed, the attack surface can be actively influenced using vulnerability management. Vulnerability management involves looking at the IT infrastructure from the outside – just as potential cyberattackers would. The goal is to find vulnerabilities that may exist in the IT infrastructure.
Vulnerability management identifies weaknesses in the IT infrastructure, assesses their risk potential, and recommends concrete measures for remediation. In this way, attacks can be prevented through targeted precautionary measures. This process – from identification and assessment to remediation and continuous monitoring – is carried out continuously.
Fig. 1.1 Process of vulnerability management¶
1.2 OPENVAS SCAN¶
OPENVAS SCAN is a vulnerability management appliance, available as physical and virtual models. It assists companies and agencies with automated and integrated vulnerability assessment and management.
1.2.1 Components and Field of Application¶
OPENVAS SCAN runs on Greenbone OS (GOS), which provides the operating environment for the appliance. The appliance includes the scan service and web interface and uses vulnerability information and vulnerability tests provided by the OPENVAS ENTERPRISE FEED. Physical appliance models additionally include dedicated hardware.
As new vulnerabilities are discovered every day, new vulnerability tests must be added continuously. Greenbone analyzes CVE [1] records and vendor security advisories and develops new vulnerability tests. The feed is updated daily to provide up-to-date vulnerability tests to reliably detect the newest vulnerabilities.
OPENVAS SCAN can be scaled for large enterprises, medium-sized and small companies, as well as for special use cases such as audits and training. With the included master-sensor and airgap technologies, the appliances can also be deployed in high-security sectors.
1.2.2 Types of Scans¶
The appliance can scan an IT infrastructure from different attack perspectives:
- External
The appliance can simulate an external attack to identify outdated or misconfigured firewalls.
- Demilitarized Zone (DMZ)
The appliance can identify vulnerabilities that may be exploited by cyberattackers who gain access to the DMZ.
- Internal
The appliance can also identify exploitable vulnerabilities in the internal network, for example those targeted by social engineering or computer worms. Due to the potential impact of such attacks, this perspective is particularly important for the security of any IT infrastructure.
DMZ and internal scans can be unauthenticated or authenticated. When performing an authenticated scan, the appliance uses credentials and can discover vulnerabilities in applications that are not running as services and may contain vulnerabilities (for example, web browsers, office applications or PDF viewers).
- Information about web application scanning
The vulnerability scanner of OPENVAS SCAN scans hosts specified by a domain name or an IP address. A website URL, however, contains additional components beyond a domain name or IP address. Since the appliance’s scanner does not process the other parts of a URL, it cannot automatically analyze and test the structure of a website. It is therefore not a Web Application Security Scanner (WASS) or an HTTP scanner.
However, if a host is scanned on which a web application is running, and if a known vulnerability exists and a corresponding vulnerability test is included in the feed, the appliance may still detect the vulnerability.
1.2.3 Vulnerability Classification and Remediation¶
The detected vulnerabilities are rated according to their severity using the Common Vulnerability Scoring System (CVSS). The severity can be used to determine which vulnerabilities to prioritize for remediation. The most important measures are those that protect the system against critical risks and eliminate the corresponding vulnerabilities.
Fundamentally, there are two options for addressing vulnerabilities:
Eliminating the vulnerability by updating the software, removing the vulnerable component or changing the configuration.
Implementing a rule in a firewall or in an intrusion prevention system (virtual patching).
Virtual patching is the apparent elimination of the vulnerability through a compensating control. The underlying vulnerability still exists and the cyberattackers can still exploit the vulnerability if the compensating control fails or if an alternative attack path is used.
An actual patch or update of the affected software is always preferred over virtual patching.
Footnotes