Vulnerability Management
Vulnerability
A flaw or weakness that allows a threat agent to skip safety.
Zero-Day Vulnerability (Zero Day)
A vulnerability that isn't always recognized to the software developer or dealer, but is
understood to an attacker
Resources to records about vulnerabilities
NIST National Vulnerability Database
MITRE CVE
FEEDLY
Twitter
CVSS (Common Vulnerability Scoring System)
A danger management approach to quantifying vulnerability information after which
considering the diploma of hazard to distinct types of structures or information.
Three.Zero
Generate a rating from 0-10 based on intrinsic traits of the vuln.
0 = none
zero.1=three.Nine = low
4.Zero-6.Nine = medium
7.0 - 8.9 -= excessive
nine.0+ = vital
CVE (Common Vulnerabilities and Exposures)
dictionary that provides a crucial repository of sec vuln's and issues
Each CVE # represents a specific vulnerability
Types of Vulnerability Scans
▪ Discovery scan
▪ Full test
▪ Stealth test
▪ Compliance test
▪Passive Scan
▪Active Scan
▪Credentialed Scan
, ▪Non-credentialed scan
▪Agent-Based Scan
▪Assessment Scan
Discovery Scan
A kind of vulnerability experiment this is basically meant to pick out the attack floor of a
target. A port experiment is a major part of a discovery scan.
AKA
to get an concept of what varieties of gadgets stay on a network and what types of
vulnerabilities is probably possible
Used to discover ability targets.
▪ Identity/information amassing early on
▪ Least intrusive test (like a ping sweep)
▪ Used to create a community map to reveal related devices inside the architecture
examples: nmap ping sweep
Full Scan
Full vulnerability scanning is the act of seeking out each possible vulnerability on a
community or laptop gadget the use of every device possible.
While acting complete vulnerability scanning, the safety researcher or IT administrator does
not care if everyone notices them acting these scans, and that they don't care if they draw
attention to themselves. By its nature, full vulnerability scanning may be very noisy because
you are poking and prodding at each feasible corner of the network.
Compliance Scan
A sort of vulnerability experiment that verifies a community adheres to certain coverage
necessities, as mandated by means of regulation, enterprise, or man or woman employer
For instance, PCI certification calls for that corporations meet sure standards together with
now not being vulnerable to certain vulnerabilities. Organizations can use vulnerability scans
to audit their protection to check for compliance.
▪ Used to pick out vulnerabilities that could affect compliance with rules or guidelines
▪ Commonly setup as a scanning template to your vulnerability scanner (PCI-DSS)
Stealth Scan
Vulnerability
A flaw or weakness that allows a threat agent to skip safety.
Zero-Day Vulnerability (Zero Day)
A vulnerability that isn't always recognized to the software developer or dealer, but is
understood to an attacker
Resources to records about vulnerabilities
NIST National Vulnerability Database
MITRE CVE
FEEDLY
CVSS (Common Vulnerability Scoring System)
A danger management approach to quantifying vulnerability information after which
considering the diploma of hazard to distinct types of structures or information.
Three.Zero
Generate a rating from 0-10 based on intrinsic traits of the vuln.
0 = none
zero.1=three.Nine = low
4.Zero-6.Nine = medium
7.0 - 8.9 -= excessive
nine.0+ = vital
CVE (Common Vulnerabilities and Exposures)
dictionary that provides a crucial repository of sec vuln's and issues
Each CVE # represents a specific vulnerability
Types of Vulnerability Scans
▪ Discovery scan
▪ Full test
▪ Stealth test
▪ Compliance test
▪Passive Scan
▪Active Scan
▪Credentialed Scan
, ▪Non-credentialed scan
▪Agent-Based Scan
▪Assessment Scan
Discovery Scan
A kind of vulnerability experiment this is basically meant to pick out the attack floor of a
target. A port experiment is a major part of a discovery scan.
AKA
to get an concept of what varieties of gadgets stay on a network and what types of
vulnerabilities is probably possible
Used to discover ability targets.
▪ Identity/information amassing early on
▪ Least intrusive test (like a ping sweep)
▪ Used to create a community map to reveal related devices inside the architecture
examples: nmap ping sweep
Full Scan
Full vulnerability scanning is the act of seeking out each possible vulnerability on a
community or laptop gadget the use of every device possible.
While acting complete vulnerability scanning, the safety researcher or IT administrator does
not care if everyone notices them acting these scans, and that they don't care if they draw
attention to themselves. By its nature, full vulnerability scanning may be very noisy because
you are poking and prodding at each feasible corner of the network.
Compliance Scan
A sort of vulnerability experiment that verifies a community adheres to certain coverage
necessities, as mandated by means of regulation, enterprise, or man or woman employer
For instance, PCI certification calls for that corporations meet sure standards together with
now not being vulnerable to certain vulnerabilities. Organizations can use vulnerability scans
to audit their protection to check for compliance.
▪ Used to pick out vulnerabilities that could affect compliance with rules or guidelines
▪ Commonly setup as a scanning template to your vulnerability scanner (PCI-DSS)
Stealth Scan