Έλεγχος ευπαθειών (vulnerability assessment) σε πληροφοριακά συστήματα οργανισμού ιδιωτικού τομέα με την χρήση του OpenVAS
View/ Open
Keywords
Vulnerability assessment ; OpenVAS ; Digital systems ; Private sectorAbstract
This paper focuses on the process of identifying and assessing vulnerabilities present in the information systems of a private sector organization, using the Open Vulnerability Assessment System (OpenVAS) tool. OpenVAS is one of the most widely used tools for vulnerability testing and is used in this paper for the analysis of information systems. In the paper the concepts of vulnerability management will be reviewed, especially the process of vulnerability assessment of information systems; the OpenVAS tool, its features, and how it is used to identify vulnerabilities will be briefly presented; and both the methodology of the process followed to test the organization's information systems (from preparation to execution of the tests) and the analysis of the results will be described. At the end, we will summarize the results of the vulnerability assessment, with an analysis of the main threats identified and their severity, and our conclusions on the security status of the organization's information systems with our recommendations for security improvement based on the results of the analysis.