Vulnerability Management

Vulnerability DefenseFree Lesson

Advertisement

Vulnerability Management

Scanning, assessment, prioritization, remediation, and compliance tracking.

Overview

Vulnerability management identifies and fixes security weaknesses.

Lifecycle

Architecture Diagram
ā”Œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”
│ Discover    │ ← Asset inventory
ā”œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¤
│ Scan        │ ← Vulnerability scanning
ā”œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¤
│ Assess      │ ← Risk evaluation
ā”œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¤
│ Prioritize  │ ← Remediation order
ā”œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¤
│ Remediate   │ ← Fix vulnerabilities
ā”œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¤
│ Verify      │ ← Confirm fixes
ā”œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¤
│ Report      │ ← Documentation
ā””ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”˜

Scanning Tools

ToolTypeCost
NessusCommercial
∣∣OpenVAS∣OpenSource∣Free∣∣Qualys∣Cloud∣| | OpenVAS | Open Source | Free | | Qualys | Cloud |

| | Nexpose | Commercial | $$ | | Nikto | Web Scanner | Free |

Vulnerability Scoring (CVSS)

Architecture Diagram
CVSS Score Range:
0.0 - 3.9  → Low
4.0 - 6.9  → Medium
7.0 - 8.9  → High
9.0 - 10.0 → Critical

CVSS Vector:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  │     │     │     │     │   │   │   │
  │     │     │     │     │   │   │   └─ Availability
  │     │     │     │     │   │   └───── Integrity
  │     │     │     │     │   └───────── Confidentiality
  │     │     │     │     └───────────── User Interaction
  │     │     │     └─────────────────── Privileges Required
  │     │     └───────────────────────── Complexity
  │     └─────────────────────────────── Attack Vector
  └───────────────────────────────────── Version

Scanning Scripts

# Nmap vulnerability scan
nmap --script vuln target.com

# OpenVAS scan
omp -u admin -w password -X '<get_targets/>'

Remediation Priorities

PriorityCVSSSLA
P19.0-10.024 hours
P27.0-8.97 days
P34.0-6.930 days
P40.1-3.990 days

Practice

Set up OpenVAS and perform a vulnerability scan on a test network.

Advertisement

Need Expert Cybersecurity Help?

Get personalized security training or professional consulting.

Advertisement