0% ont trouvé ce document utile (0 vote)
75 vues13 pages

Tests d'intrusion avec Nessus

Le document décrit les tests d'intrusion dans les réseaux Internet à l'aide de l'outil Nessus. Il présente Nessus, la démarche des tests d'intrusion et les résultats d'audit réalisés avec différents scanners dont Nessus.

Transféré par

Taysir Automobiles
Copyright
© All Rights Reserved
Nous prenons très au sérieux les droits relatifs au contenu. Si vous pensez qu’il s’agit de votre contenu, signalez une atteinte au droit d’auteur ici.
Formats disponibles
Téléchargez aux formats PDF, TXT ou lisez en ligne sur Scribd
0% ont trouvé ce document utile (0 vote)
75 vues13 pages

Tests d'intrusion avec Nessus

Le document décrit les tests d'intrusion dans les réseaux Internet à l'aide de l'outil Nessus. Il présente Nessus, la démarche des tests d'intrusion et les résultats d'audit réalisés avec différents scanners dont Nessus.

Transféré par

Taysir Automobiles
Copyright
© All Rights Reserved
Nous prenons très au sérieux les droits relatifs au contenu. Si vous pensez qu’il s’agit de votre contenu, signalez une atteinte au droit d’auteur ici.
Formats disponibles
Téléchargez aux formats PDF, TXT ou lisez en ligne sur Scribd

CNAM Paris – Département informatique

Les tests d’intrusion dans les réseaux Internet,


l’outil Nessus

Examen probatoire
session de Mai 2004

Dongé Laurent
laurent_donge@[Link]

1 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Plan

„ Réseaux Internet
„ Tests d’intrusion
ª Démarche
ª Outils

„ Nessus
„ Tests d’audit réalisés
ª Scanners utilisés
ª Protocoles & Résultats

„ Conclusion

2 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Réseaux Internet
„ Réseaux Internet

„ Tests d’intrusion

¾ Démarche

¾ Outils

„ Nessus

„ Tests d’audit

réalisés

¾ Scanners utilisés

¾ Protocoles &

Résultats

„ Conclusion

3 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Tests d’intrusion
„ Réseaux Internet „ Définition :

„ Tests d’intrusion
une tentative autorisée de simuler les activités
de pirates afin d’évaluer les failles de sécurité
¾ Démarche présentées par un système d’information
¾ Outils
„ Stratégies :
„ Nessus ª test interne / test externe
„ Tests d’audit „ Méthodes :
réalisés ª test aveugle / double aveugle / ciblé
¾ Scanners utilisés „ Types :
¾ Protocoles & ª sécurité application Web
Résultats ª DoS
„ Conclusion ª War dialing
ª ingénierie sociale ...
4 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent
La démarche des Tests d’intrusion
„ Réseaux Internet

„ Tests d’intrusion

¾ Démarche
„ A. Phase préparatoire
¾ Outils

„ Nessus
„ B. Phase de réalisation
„ Tests d’audit réalisés

¾ Scanners utilisés

¾ Protocoles & „ C. Phase de restitution


Résultats

„ Conclusion

5 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Outils utilisés
„ Réseaux Internet

„ Tests d’intrusion

¾ Démarche

¾ Outils

„ Nessus

„ Tests d’audit

réalisés

¾ Scanners utilisés

¾ Protocoles &

Résultats

„ Conclusion

6 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Nessus (1/2)
„ Réseaux Internet
„ détection des services sur les différents
„ Tests d’intrusion
ports en analysant les protocoles
¾ Démarche

¾ Outils „ tests de vulnérabilités parmi 24


„ Nessus
familles sur les services détectés
„ Tests d’audit ª backdoors, CGI, CISCO, DoS , RPC,
SMTP …
réalisés

¾ Scanners utilisés
„ fournit :
¾ Protocoles & ª une liste des vulnérabilités classées
Résultats
ª des références CVE
„ Conclusion
ª des solutions

7 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Nessus (2/2)
„ Contexte
„ permet de réaliser des rapports
„ Tests d’intrusion

¾ Démarche – HTML, LaTeX …


¾ Outils

„ Nessus „ son architecture client/serveur


„ Tests d’audit

réalisés
ª test sous forme de plug-in (NASL)
¾ Scanners utilisés
ª bases d’information
¾ Protocoles &

Résultats
ª produits tiers : Nmap, Nitko, Hydra
„ Conclusion

8 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Tests d’audit réalisés (1/3)
Scanners utilisés sur un réseau Ethernet
„ Réseaux Internet
Scanners Nessus NeWT SAINT Internet
„ Tests d’intrusion
Scanner
¾ Démarche
Nature Open Commerciale
¾ Outils source

„ Nessus Plate-forme Linux Windows Linux Windows


possible Unix
„ Tests d’audit
Pate-forme Linux Windows Linux Windows
réalisés utilisée Fedora 2000 Fedora 2000
Core 1 B serveur Core 1 B serveur
¾ Scanners utilisés Facilité 4 5 5 3
d’installation
¾ Protocoles &

résultats

„ Conclusion
1: pas convaincant 2: passable 3: correct 4: bien 5: Excellent

9 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Tests d’audit réalisés (2/3)
„ Réseaux Internet „ Protocole des Tests
Tests d’intrusion
„
ªaudit sans attaques dangereuses
¾ Démarche

¾ Outils
ªaudit avec attaques dangereuses
„ Nessus ªaudit sans puis avec Nmap
„ Tests d’audit
„ Résultats
réalisés

¾ Scanners utilisés
ªNessus : détection complète,
¾ Protocoles &
temps d’analyse correct, évolutif,
résultats
ouvert
„ Conclusion ªPositionnement de Nessus

10 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Tests d’audit réalisés (3/3)
Tableau comparatif simplifié
„ Réseaux Internet

„ Tests d’intrusion
Nessus NeWT SAINT Internet
Scanner
¾ Démarche
Détection 4 4 3 4
¾ Outils

„ Nessus Temps 3 4 4 2
„ Tests d’audit
Rapport 3 3 4 2
réalisés

¾ Scanners utilisés
Appréciation 4 4 3 4
¾ Protocoles & générale
résultats
1: pas convaincant 2: passable 3: correct 4: bien 5: Excellent
„ Conclusion

11 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent


Conclusion
„ Réseaux Internet „ L’importance de référence
„ Tests d’intrusion
standardisée
¾ Démarche „ Les limites des scanners et des
¾ Outils tests d’intrusion
„ Nessus
„ la sécurisation nécessite des
„ Tests d’audit outils complémentaires
réalisés
„ les réseaux de taille importante
¾ Scanners utilisés demandent :
ª des architectures réparties plus
¾ Protocoles &

Résultats
robustes
„ Conclusion
ª la définition de stratégies
12 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent
Questions - Discussion

13 Test d’intrusion, l’outil Nessus - Mai 2004 Dongé Laurent

Common questions

Alimenté par l’IA

Using Nessus as a standalone security measure has notable limitations. Despite its robust detection capabilities, it might not cover all possible vulnerabilities, especially emerging threats, meaning it cannot replace other security tools entirely . Nessus can identify a wide range of vulnerabilities but lacks the contextual threat intelligence needed to assess the impact independently . Complementary tools, such as firewalls, intrusion detection systems, and additional vulnerability scanners, provide layered defenses, addressing issues like real-time threat detection and response, delivering comprehensive security solutions .

Integrating Nessus into an existing security infrastructure can present several challenges. These include compatibility issues with existing systems, especially if they are on different platforms . Organizations might also face difficulties in adapting workflows to incorporate the new tool, and there may be a learning curve associated with understanding the tool’s outputs and capabilities . Mitigating these challenges involves observing best practices, such as training IT staff on Nessus operations, ensuring infrastructure compatibility before full-scale deployment, and utilizing Nessus’s robust reporting to enhance existing workflows without major disruptions .

Nessus enhances vulnerability detection by identifying services on different ports through protocol analysis and testing vulnerabilities across 24 categories, including backdoors, CGI, CISCO, DoS, RPC, and SMTP . It classifies detected vulnerabilities and provides CVE references and solutions to address them, which aids in systematically handling network security issues . The tool's detailed reporting through various formats like HTML and LaTeX is part of its client-server architecture that uses plugins for tests, adding flexible, comprehensive scanning capabilities .

Intrusion testing employs various strategies and methods to evaluate the security of information systems. Strategies include internal and external testing, where internal testing simulates an attack from within the network and external testing simulates an outside attack . Methods incorporated include blind, double-blind, and targeted tests. A blind test provides the tester only the name of the target, simulating an attack by someone with limited information, while a double-blind test adds the element of surprise by not informing the security team in advance, testing their detection and response capabilities . A targeted test, however, is more collaborative, with both the tester and security team knowing about the test, often used to refine security measures .

Nessus reports can significantly aid organizations in improving their network security strategies. These reports provide a detailed list of vulnerabilities, classified by risk level, enabling prioritization in addressing the most critical issues first . The inclusion of CVE references in the reports helps in identifying known vulnerabilities and applying industry-standard resolutions quickly . Additionally, the flexible report formats, such as HTML and LaTeX, allow for easy sharing and analysis among different stakeholders, facilitating collaborative efforts in strategic planning and resource allocation to strengthen security measures .

Results from Nessus testing have a significant impact on decision-making processes related to network security enhancements. By providing detailed insights into existing vulnerabilities and their criticality levels, Nessus informs priorities in security planning and resource allocation . Decision-makers can use the structured vulnerability reports to define a clear remediation path, focusing efforts on the most impactful fixes to reduce risk levels effectively . Moreover, the integration of CVE references allows for alignment with best practice solutions, aiding in forming informed strategies to enhance security measures and monitor ongoing compliance .

The preparatory phase of intrusion testing involves crucial steps to ensure test effectiveness. It starts with defining the scope and objectives of the test, determining what assets are in scope, and identifying potential vulnerabilities and threats . Other critical considerations include selecting appropriate testing methods and tools, such as Nessus, and establishing pre-test baselines and compliance requirements . Additionally, permissions and legal considerations must be addressed to simulate attacks ethically and legally within the network .

Nessus stands out for its comprehensive detection capabilities, which are rated highly alongside NeWT and SAINT . Its scanning speed is rated as correct, which is competitive but not the fastest . The user appreciation and quality of reports generated are comparable across these tools, showing similar effectiveness in practical usage . However, Nessus's open-source nature and compatibility with various systems give it a cost-effective edge for many users . Nonetheless, all scanners have their limitations; for example, none fully guarantee protection against all the latest threats without complementary tools .

The use of standardized references like CVEs in Nessus reports enhances network security audits by providing a universally acknowledged framework for identifying and classifying vulnerabilities . This standardized approach ensures that the vulnerabilities identified are aligned with global security standards, promoting consistency and reliability in security assessments . It facilitates easier cross-referencing and validation against other security tools and databases, streamlining the process of applying fixes and updates . By leveraging these references, organizations can efficiently track vulnerabilities over time and benchmark their security posture against industry standards .

The comprehensive architecture of Nessus, based on a client-server model, supports its functionality by facilitating scalable and flexible scanning. The architecture incorporates NASL plug-ins for running specific tests, which makes it adaptable to various needs and updates . It integrates third-party products like Nmap, Nitko, and Hydra, enhancing its ability to detect and analyze vulnerabilities across different environments . The client-server structure allows multiple clients to run tests simultaneously from different points, increasing efficiency and coverage .

Vous aimerez peut-être aussi