Network Scanning Cookbook
eBook - ePub

Network Scanning Cookbook

Practical network security using Nmap and Nessus 7

  1. 304 pages
  2. English
  3. ePUB (mobile friendly)
  4. Available on iOS & Android
eBook - ePub

Network Scanning Cookbook

Practical network security using Nmap and Nessus 7

About this book

Discover network vulnerabilities and threats to design effective network security strategies

Key Features

  • Plunge into scanning techniques using the most popular tools
  • Effective vulnerability assessment techniques to safeguard network infrastructure
  • Explore the Nmap Scripting Engine (NSE) and the features used for port and vulnerability scanning

Book Description

Network scanning is a discipline of network security that identifies active hosts on networks and determining whether there are any vulnerabilities that could be exploited. Nessus and Nmap are among the top tools that enable you to scan your network for vulnerabilities and open ports, which can be used as back doors into a network.

Network Scanning Cookbook contains recipes for configuring these tools in your infrastructure that get you started with scanning ports, services, and devices in your network. As you progress through the chapters, you will learn how to carry out various key scanning tasks, such as firewall detection, OS detection, and access management, and will look at problems related to vulnerability scanning and exploitation in the network. The book also contains recipes for assessing remote services and the security risks that they bring to a network infrastructure.

By the end of the book, you will be familiar with industry-grade tools for network scanning, and techniques for vulnerability scanning and network protection.

What you will learn

  • Install and configure Nmap and Nessus in your network infrastructure
  • Perform host discovery to identify network devices
  • Explore best practices for vulnerability scanning and risk assessment
  • Understand network enumeration with Nessus and Nmap
  • Carry out configuration audit using Nessus for various platforms
  • Write custom Nessus and Nmap scripts on your own

Who this book is for

If you're a network engineer or information security professional wanting to protect your networks and perform advanced scanning and remediation for your network infrastructure, this book is for you.

Tools to learn more effectively

Saving Books

Saving Books

Keyword Search

Keyword Search

Annotating Text

Annotating Text

Listen to it instead

Listen to it instead

Information

Configuration Audits

In this chapter, we will cover the following:
  • Introducing compliance scans
  • Selecting a compliance scan policy
  • Introducing configuration audits
  • Performing an operating system audit
  • Performing a database audit
  • Performing a web application scan

Introducing compliance scans

In this chapter, we will be going through various recipes on the significance of Nessus for performing various audits, such as a credentialed scan, and performing policy compliance audits, such as an operating system audit, a database audit, and an application audit. This is a crucial part of a white box assessment for network security, as this allows an internal administrator or auditor to understand the security posture of the systems in the organization.

Selecting a compliance scan policy

An entire compliance scan or audit is different from a typical vulnerability scan; it is completely dependent on the plugins and the Nessus audit file. We have already covered the basics on how to download and update the plugins in Chapter 2, Understanding Network Scanning Tools. We will now uncover further details about plugins and the Nessus audit file. In this recipe, we will look how to select the correct baseline policy from the set of policies that come preloaded in Nessus, in order to perform a configuration audit for a Linux host.

Plugins

Each plugin consists of syntax to check for a specific vulnerability for a version or multiple versions of the software, services, and operating systems. A group of plugins for a similar operating system/service/software are grouped as a plugin family, shown as follows:
These plugin families expand into different plugins that each perform a specific check. A user cannot manually add a plugin; they can only download or update new or missing plugins only when they are made available by Tenable. Each plugin has a set of parameters to help a user understand the plugin. These parameters are discussed in greater detail in the following section.

Synopsis

This section consists of brief information about the vulnerability and acts as a title for the vulnerability.

Description

This section provides deeper insight into the vulnerability of the exact component and version (if available) affected, along with details about the vulnerability. This allows the user to understand which part of the service or software is vulnerable, and the vulnerability as a whole.

Solution

This section provides the user with details of remediation, such as configuration changes or code changes that are to be performed, or a link to an article by Tenable or any other trusted source on how to mitigate the vulnerability.

Plugin information

This section consists of parameters that differentiate the plugin from other plugins. Parameters include the ID, version, type, publication date, and modified date. These parameters act as metadata for the plugin.

Risk information

This section provides information about the severity of the vulnerability, alongside Common Vulnerability Scoring System (CVSS) data, which is one of the globally accepted standards for scoring vulnerabilities. The severity ratings vary from Critical to Informational; the CVSS score is on a scale of 1-10.

Vulnerability information

This section provides details about the platform for which the plugin is applicable, using the Common Platform Enumeration (CPE) index, which is currently maintained by the National Vulnerability Database (NVD). Further, it also provides information about the exploitability of the vulnerability, using parameters such as exploit available and exploit ease. It also consists of the publication date of the plugin.

Reference information

This section consists of information about reference IDs assigned to the vuln...

Table of contents

  1. Title Page
  2. Copyright and Credits
  3. Packt Upsell
  4. Foreword
  5. Contributors
  6. Preface
  7. Introduction to Network Vulnerability Scanning
  8. Understanding Network Scanning Tools
  9. Port Scanning
  10. Vulnerability Scanning
  11. Configuration Audits
  12. Report Analysis and Confirmation
  13. Understanding the Customization and Optimization of Nessus and Nmap
  14. Network Scanning for IoT, SCADA/ICS
  15. Other Books You May Enjoy

Frequently asked questions

Yes, you can cancel anytime from the Subscription tab in your account settings on the Perlego website. Your subscription will stay active until the end of your current billing period. Learn how to cancel your subscription
No, books cannot be downloaded as external files, such as PDFs, for use outside of Perlego. However, you can download books within the Perlego app for offline reading on mobile or tablet. Learn how to download books offline
Perlego offers two plans: Essential and Complete
  • Essential is ideal for learners and professionals who enjoy exploring a wide range of subjects. Access the Essential Library with 800,000+ trusted titles and best-sellers across business, personal growth, and the humanities. Includes unlimited reading time and Standard Read Aloud voice.
  • Complete: Perfect for advanced learners and researchers needing full, unrestricted access. Unlock 1.4M+ books across hundreds of subjects, including academic and specialized titles. The Complete Plan also includes advanced features like Premium Read Aloud and Research Assistant.
Both plans are available with monthly, semester, or annual billing cycles.
We are an online textbook subscription service, where you can get access to an entire online library for less than the price of a single book per month. With over 1 million books across 990+ topics, we’ve got you covered! Learn about our mission
Look out for the read-aloud symbol on your next book to see if you can listen to it. The read-aloud tool reads text aloud for you, highlighting the text as it is being read. You can pause it, speed it up and slow it down. Learn more about Read Aloud
Yes! You can use the Perlego app on both iOS and Android devices to read anytime, anywhere — even offline. Perfect for commutes or when you’re on the go.
Please note we cannot support devices running on iOS 13 and Android 7 or earlier. Learn more about using the app
Yes, you can access Network Scanning Cookbook by Sairam Jetty in PDF and/or ePUB format, as well as other popular books in Ciencia de la computación & Redes de computadoras. We have over one million books available in our catalogue for you to explore.