You are on page 1of 50

Tm hiu cch thc hot ng ca cc cng c qut l hng bo mt

Sinh vin thc hin 1. L Vn Sn 2. Khc Tm. 3. Nguyn Xun Minh 4. Nguyn Th Xun

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Tm hiu cch thc hot ng ca cc cng c qut l hng bo mt


Phn 1: Tng quan v cc cng c qut l hng bo mt Phn 2: Cch thc hot ng ca cc cng c qut l hng bo mt. Phn 3: Demo vi OpenVAS.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Tng quan v cc cng c qut l hng bo mt


1. Khi nim v l hng bo mt
L hng bo mt l nhng li phn mm, li trong c im k thut v thit k, nhng a s l li trong lp trnh. Cc nguyn nhn dn n l hng bo mt c th l:
Li phn mm Zero-Day Exploits n tn cng m thm Qu trnh khai thc

Cc l hng bo mt l im yu to ra s ngng tr dch v, thm quyn truy nhp tri php.. N tn ti trc tip trn cc dch v nh sendmail, ftp,web hay trn chnh cc h iu hnh nh winxp, win7

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Tng quan v cc cng c qut l hng bo mt


2. Cc cng c qut l hng bo mt
v c cc l hng bo mt th cn phi tm ra chng trc, tuy nhin iu ny l khng h d dng. C nhng l hng tn ti trng h thng my nm trc khi b pht hin. Vic s dng cc cng c qut l hng bo mt l cn thit. N c chc nng tm kim v pht hin ra cc li trn web,phn mm, h thng ng thi c th khc phc chng. C rt nhiu cng c ra i vi mc ch ny, trong y ta tm hiu v 3 cng c c nh gi cao l Nessus,Nmap,OpenVas.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Cch thc hot ng ca cc cng c qut l hng bo mt


Cc cng c

NESSUS Gii thit v Nessus Cc thnh phn Cc chnh sch trong Nessus Cch thc hot ng

Nmap Gii thiu v Nmap Cc u im ca Nmap Cc giai on ca Nmap S dng Nmap Mt s v d

OpenVAS Gii thiu v OpenVAS Kin trc ca OpenVAS Phng thc hot ng ca OpenVAS

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.1 Gii thiu v Nessus
L cng c qut l hng bo mt t xa, thc hin hn 1200 cuc kim tra trn mt my tnh no pht hin ra cc nguy c c th xy ra. Mc tiu ca n l pht hin cc l hng tim n trn cc h thng c kim tra chng hn nh:
Cc l hng cho php cracker c th kim sot hoc truy cp cc d liu nhy cm trn h thng t xa. Li cu hnh (v d nh m mail relay, mt cc bn v,) Cc mt khu mc nh, mt s mt khu chung, cc mt khu blank/absent (trng hay thiu) trn mt s ti khon h thng. T chi dch v i vi cc giao thc TCP/IP bng cch s dng cc gi d liu b c sai.
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 6

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.1 Gii thiu v Nessus
Nessus c mt c s d liu rt ln v l hng h thng c cp nht thng xuyn, giao din d s dng v kt qu c th c lu li di nhiu dng khc nhau nh biu , XML hay PDF ngi dng c th d dng tham kho.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.1 Gii thiu v Nessus
N khng hon ton l mt gii php bo mt, n l mt phn nh ca mt chin lc an ninh tt. Nessus khng tch cc ngn chn cc cuc tn cng, n ch l mt cng c kim tra my tnh ca bn tm cc l hng m tin tc c th khai thc. C th chy trn nn tng ca nhiu h iu hnh khc nhau nh UNIX, Linux, Mac OS X, Windows. Hin ti phin bn Nessus 5.0 chy trn giao din web, do c th d dng truy cp, s dng trn mi h iu hnh.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Cch thc hot ng ca cc cng c qut l hng bo mt

Giao din ng nhp ca Nessus 5


nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 9

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.2 Cc thnh phn ca Nessus
Nessus Engine: nhn, thc thi v tr li li cc yu cu qut ca ngi dng. Nessus Plugin: h thng file ca ngn ng kch bn NASL(Nessus Attrack Scripting Language), gm cc file nh ngha .inc v file kch bn .nasl. Nessus Server: thc hin nhn cc yu cu qut ca ngi dng, sau phn tch, tng hp, tr li kt qu cho Nessus client. Nessus Client: hin th kt qu qut li cho ngi dng thng qua trnh duyt web. Nessus Knowledge Base: C s d liu bit ca Nessus cho php cc plugin sau tn dng d liu kt qu ca Plugin trc .
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 10

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.3 Gii thiu v cc chnh sch trong Nessus.
Mt chnh sch ca Nessus bao gm cc cu hnh ty chn thc thi trong qu trnh kim tra li bo mt. Cc ty chn ny bao gm, nhng chng khng gii hn cc thng s kim sot cc kha cnh k thut qut nh thi gian tm ngng, s lng my ch, cc loi cng my qut... Nessus c mt s chnh sch mc nh c cung cp bi cng ty Tenable Network Security. H cung cp mt s cc chnh sch mu h tr bn trong vic to ra cc chnh sch ty chn cho cc n v hoc s dng qut cc ti nguyn ca bn.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

11

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.3 Gii thiu v cc chnh sch trong Nessus.

Mt s chnh sch mc nh ca Nessus External Network Scan Internal Network Scan Web App Tests Prepare for PCI DSS audits

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

12

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.1 Hot ng ca Nessus vi m hnh Client-Server
Nessus hot ng theo m hnh Client - Server. Nessus Server s cha thng tin v c s d liu, cp nht cc l hng mi, thng tin v username v password Nessus Client chng thc, thc hin qut li cc PC do Nessus Client yu cu.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

13

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.1 Hot ng ca Nessus vi m hnh Client-Server
Ban u, Server s tng hp tt c cc li bo mt hin c. Khi mt my tnh Client yu cu c kim tra cc li c tn ti trn my tnh ca mnh hay khng, u tin chng phi c kim tra xem c kt ni ti server hay khng, sau khi kim tra kt ni chng s c qut ty thuc vo cc mc yu cu khi qut. M hnh ny s da vo kt qu sau khi my Client yu cu kim tra, v da vo nhng li c xc nh c th a ra nhng nhng hng gii quyt mt cch nhanh nht.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

14

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.2 M hnh Nessus Plugin
Nessus hot ng da trn d liu t cc Plugin. Plugin l mt chng trnh cha cc d liu v l hng trong h thng. Plugin cha cc kch bn c vit bng NASL(Nessus Attrack Scripting Language). Cc kch bn l cc phng thc kim tra l hng trn h thng. NASL cho php cc nh phn tch an ninh nhanh chng to ra cc Plugin ring ca h. Nessus s dng hn 55.000 plugin khc nhau, bao gm c cc l hng cc b v t xa.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

15

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.2 M hnh Nessus Plugin

M hnh Nessus Plugin


nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

16

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.2 M hnh Nessus Plugin Cc my Client s gi yu cu n Nessus Plugin(c thit lp trong qu trnh cu hnh qut). Yu cu ny s nh danh Plugin m Client mun s dng. Sau khi nhn c yu cu t Client, Nessus Plugin s tin hnh qut h thng m Client yu cu theo kch bn c sn trong Plugin. Sau khi qu trnh qut hon tt th Nessus Plugin s gi kt qu ca qu trnh qut cho Client.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

17

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.3 M hnh Nessus Knowledge Base Knowledge Base l danh sch cc thng tin thu thp v mt my ch ang c th nghim. N cho php b sung, hoc th nghim chia s thng tin v h thng ch, cho php kim tra thng minh hn v s dng thn trng hn bng thng v kh nng x l. Knowledge Base cho php cc Plugin sau tn dng d liu ca Plugin trc . iu ny gip Nessus d dng m rng v tng tc thc thi.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

18

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.3 M hnh Nessus Knowledge Base
Gi s, ngi qun tr thc hin Scan ton b mt mng con v nhn c mt bo co kt qu. Mt vi ngy sau, anh ta pht hin ra rng cc my ch mi c thm vo mng con. Khi , nu tin hnh Scan vi tu chn " Only test hosts that have never been tested in the past " th my qut s ch kim tra cc my ch mi m n tm thy v lit k danh sch my ch mi cng nh cc l hng trong cc my ch mi .

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

19

Cch thc hot ng ca cc cng c qut l hng bo mt


1. Nessus
1.4 Cch thc hot ng 1.4.3 M hnh Nessus Knowledge Base
V d, chng ta thc hin qut kim tra li bo mt trn Server DomainName.com, qu trnh kim tra hon tt v khng thy mt li bo mt no c trn . Nhng lc ny Nessus Knowledge Base c to ra cho my ch ny li cho thy khong 2000 li. Ngi ta phi nh rng Nessus Knowledge Base cng ch c khong 1725 li c trusted. V nhng thng s c s dng cho nhng nghin cu sau ny m bo rng lin tc cp nht nhng li bo mt mi nht.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

20

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.1 Gii thiu v Nmap
Nmap ("Network Mapper" ) L mt tin ch m ngun m min ph cho thm d mng v kim ton an ninh Nmap cho php bn s dng cc packet IP th thc hin vic thm d trn cc host sn c trong 1 mng v cc dch v (cc cng ang m), phin bn h iu hnh ang chy, loi b lc, tng la s dng . N c thit k nhanh chng qut cc mng ln, nhng hot ng tt i vi host duy nht. Nmap c th s dng trn c Linux v Windows

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

21

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.2 u im ca Nmap
Linh hot : Hng chc h tr k thut tin tin lp bn cc mng vi cc b lc IP, tng la, router, v nhng tr ngi khc. iu ny bao gm nhiu c ch qut cng (c TCP v UDP), pht hin h iu hnh , pht hin phin bn, ping sweep, ... Mnh m : Nmap c s dng qut mng li rng ln ca hng trm ngn my tnh. D dng : Nmap cung cp mt tp hp phong ph cc tnh nng tin tin cho ngi dng, . Nhng chng trnh c sn cho nhng ngi khng mun bin dch Nmap t m ngun

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

22

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
Min ph : Nmap c sn ti v min ph, v cng i km vi m ngun y m bn c th chnh sa v phn phi li theo cc iu khon ca giy php . Hoan nghnh : Nmap ginh c nhiu gii thng, trong c "Sn phm An ton thng tin ca nm" do Tp ch Linux, Thng tin Th gii v Codetalker Digest. N c c trng trong hng trm bi bo tp ch, mt s b phim, hng chc cun sch, v mt lot truyn tranh. Ph bin : Hng ngn ngi ti Nmap mi ngy, v n c bao gm vi nhiu h iu hnh . N l mt trong mi chng trnh hng u (trong s 30.000) ti kho Freshmeat.Net
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

2.2 u im ca Nmap

23

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.3 Cc giai on ca Nmap Scan
Script pre-scanning (tp lnh trc khi qut) : Cc Nmap Scripting Engine (NSE) s dng mt tp hp cc tp lnh vi mc ch c bit bit c thm thng tin v h thng t xa Target enumeration (lit k mc tiu): Trong giai on ny, Nmap nghin cu specifiers host c cung cp bi ngi s dng, m c th l mt s kt hp ca host DNS names, IP addresses, k hiu mng CIDR, giai on ny khng th b qua v n l iu cn thit qut. Host discovery (ping scanning): Scan Network thng bt u bng cch pht hin cc mc tiu trn mng ang online v do c th iu tra su hn

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

24

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.3 Cc giai on ca Nmap Scan
Reverse-DNS resolution (phn gii ngc DNS): Khi Nmap xc nh host qut, n s tra tn Reverse-DNS ca tt c cc host tm thy ang online bng cch qut ping, Bc ny c th b b qua vi ty chn -n (khng c phn gii) Port scanning (Qut cng): Probes (cc u d) c gi i v nhng phn hi vi nhng cc u d c s dng phn loi cng t xa vi cc trng thi nh open, closed, filtered. Qut cng c tin hnh mc nh, c th b qua vi ty chn sn Versisdwerdfron detection (pht hin phin bn): Nu c cng c tm thy l open, Nmap c th xc nh nhng phn mm server g ang chy trn h thng t xa. OS detection (pht hin h iu hnh): Nu c yu cu vi ty chn o, Nmap tin hnh d h iu hnh
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 25

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.3 Cc giai on ca Nmap Scan
Traceroute: Nmap cha mt thc hin traceroute ti u ha, kch hot bi ty chn traceroute, n c th tm ra nh tuyn mng ti nhiu host tng ng Script scanning (Tp lnh qut): Hu ht Nmap Scripting Engine (NSE) chy trong giai on ny ch khng phi l giai on prescanning v giai on postscan Output (u ra): Cui cng, Nmap thu thp tt c cc thng tin ly c v a n ln mn hnh hoc vo mt tp tin. Script post-scanning (Tp lnh post-scanning): Sau khi Nmap hon thnh scanning, tp lnh giai on ny c th x l kt qu v cung cp bo co tng kt, thng k
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

26

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.3 Hng dn s dng Nmap
Cu trc lnh ca nmap : nmap [Scan Type(s)] {host mc tiu} [Options] nmap :tn chng trnh. Scan Type(s) : loi qut , c th kt hp nhiu loi qut trong mt ln qut Mt s Scan Type: -sT connect Scan l phng thc qut TCP ng tin cy, h thng gi hm connect() kt ni n cng ang m trn 1 my -sS SYN Scan : thng c gi l k thut qut 1 na (Haft Open Scan) v n khng to ra kt ni TCP y
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 27

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.3 Hng dn s dng Nmap

Mt s Scan Type: -sF -sX -sN FIN Scan , Xmas Tree Scan , Null Scan li th ca kiu qut ny l c th scan xuyn qua Firewall v b lc Packet m t b cn tr , ngn cn -sP Ping scanning k thut ny c dng trong trng hp bn ch mun bit c bao nhiu host hin ang online trn mt Network no . -sU UDP Scan K thut ny c s dng xc nh xem Port UDP no ang open trn host.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

28

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.3 Hng dn s dng Nmap

Mt s Scan Type: -sA ACK Scan: K thut ny c s dng thu thp cc thng tin v h thng t bn ngoi Firewall. c bit n c th xc nh xem cc Firewall c phi l mt Firewall theo ng ngha hay ch l mt b lc Packet SYN t bn ngoi. -sW Windows scan: K thut tng t nh ACK scan. Ch c iu bn d pht hin c cc port open vi b lc c ch nh dng cho cc OS

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

29

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.3 Hng dn s dng Nmap
Mt s Option - O s dng bit h iu hnh chy trn my ch, v d nh ta dng Nmap s dng phng thc scan l XMAS Scan v on bit h iu hnh ca: www.gocthuthuat.net ta dng cu lnh: nmap sX o www.gocthuthuat.net - P Gii port s dng scan - F Ch nhng port trong danh sch scan ca Nmap - V S dng Scan hai ln nhm tng tin cy v hiu qu ca phng thc scan no ta s dng. - P0 khng s dng ping Scan nhm mc ch gim thiu cc qu trnh qut ngn chn scan trn cc trang web hay my ch.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

30

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.4 Mt s v d
Qut Port (Scan Port) Mc ch: Xem port no ang Open, t chng ta c th bit c Target ang run nhng Service g Code: nmap sT www.target.com Nu thch kn o, c th s dng ty chn Scan SYN Code: nmap sS www.target.com o info.txt Ty chn o filname lu kt qu ra mt file cho php ta c li

sau
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 31

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.4 Mt s v d

Qut Port (Scan Port) Sau khi scan ta thy:


Starting nmap V 2.53 by Fyodor (fyodor@dhp.com, www.insecure.com/nmap) Interesting ports on (IP cua target.com). Port State Protocol Service 21 open TCP FTP 23 open TCP Telnet 25 open TCP SMTP 80 open TCP HTTP ...

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

32

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.4 Mt s v d Qut Ping
Mc ch: Qut phn lp D ca mt h thng mng no t cho ta bit trong phn lp hin ang c bao nhiu host ang online. Lnh sau s Ping cc host ang Open Port 80: Code: nmap sP PT80 202.162.48.0/24

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

33

Cch thc hot ng ca cc cng c qut l hng bo mt


2. Nmap
2.4 Mt s v d
Qut Ping Sau khi scan ta thy:
TCP probe ports is 80 Starting nmap V 2.53 by Fyodor (fyodor@dhp.com, www.insecure.com/nmap) Host (202.162.48.0) appears to be up Host (202.162.48.1) appears to be up Host (202.162.48.2) appears to be up

...
Host (202.162.48.x) appears to be up Nmap run completed --- 256 IP addreses (x hosts up) scanned in x seconds.
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

34

Cch thc hot ng ca cc cng c qut l hng bo mt


3. OpenVAS 3.1 Gii thiu v OpenVAS
OpenVAS ( Open Vulnerrability System) l mt framework cho mt s dch v v cc cng c, n mang n mt chc nng qut ton din v mnh m N cha mt ngun cp d liu vi nhng nh gi l hng mng v cch khc phc., c cp nht hng ngy. c tham gia bi nhiu ngi trn th gii. y l mt cng c hon ton min ph.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

35

Cch thc hot ng ca cc cng c qut l hng bo mt


3. OpenVAS 3.1.2 OpenVAS project
y l mt nhm pht trin OpenVAS bao gm nhiu ngi n t nhiu ni khc nhau nh cc t chc, cc nhn, doanh nghip, ngi dng Tt c cc sn phm OpenVAS u l nhng phn mm min ph theo giy php GNU GPL. OpenVAS xut pht t mt d n ca Nessus nhng tr thnh mt sn phm c quyn v c nhng bc pht trin ring ca mnh.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

36

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.1.3 OpenVAS software
openVAS software bao gm hai thnh phn chnh l openVAS client v OpenVAS server. a. OpenVAS server y l thnh phn ct li ca OpenVAS. N cha cc chc nng c s dng qut mt lng ln cc my ch tc cao, cng vic qut s lun c bt ngun t cc my ch OpenVAS-server ang chy. b. OpenVAS client OpenVAS-Client c chc nng kim sot OpenVAS Server, s l cc kt qu qut v hin th chng cho ngi dng.
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 37

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.2 Kin trc ca OpenVAS

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

38

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.2.1 OpenVAS Scanner
L mt my qut thc hin kim tra cc l hng bo mt, n c cp nht hng ngy thng qua ngun cp d liu. Cc tnh nng : Qut ng thi nhiu my ch cng mt lc. H tr OpenVAS Transfer Protocol. H tr SSL cho OTP. h tr WMI(ty chn)- mt cng c qun l cc h thng my ch v my bn trong mi trng doanh nghip.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

39

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.2.2 OpenVAS Manager
Hp nht cc chc nng kim tra bo mt ring l thnh mt h thng qun l bao gm y cc tnh nng. Qun l cc trung tm iu khin d liu SQL ni b, ni tt c cc kt qu qut v cu hnh c lu tr. Tnh nng:
OpenVAS Manager Protocol Cu hnh qut v a ra cc kt qu qut da vo c s d liu SQL. H tr SSL cho OMP. Qun l nhiu my qut ng thi thc hin nhiu nhim v. H tr tnh nng qut theo lch trnh, t ng linh hot theo trng thi ca mt nhim v qut.
40

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.2.3 OpenVAS Adminitrator
Hot ng nh mt cng c dng lnh. Qun l ngi dng v qun l ngun cp d liu. Tnh nng tng quan:
OpenVAS Adminitrator Protocol H tr SSL cho giao thc OAP. H tr tt c cc lnh cng nh thng s dng lnh.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

41

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.3 Phng thc hot ng ca OpenVAS
3.3.1 Tng quan v NVT a. Gii thiu v NVT
Duy tr mt ngun cp cho vic kim tra v nh gi cc l hng bo mt ca mng l NVT. n nm 2012 n c hn 25.000 NVTs. Cc tp tin OpenVAS NVT Feed c k bi OpenVASL Transfer Integrity

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

42

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.3 Phng thc hot ng ca OpenVAS
3.3.1 Tng quan v NVT
b. Quy trnh to NVT nh gi cc l hng bo mt. La chn cc bo mt ti u a vo NVT Thc hin NVT. Nu khng t tiu chun th bn giao li cho nhm pht trin Pht hnh v phn phi.

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

43

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.3 Phng thc hot ng ca OpenVAS
3.3.1 Tng quan v NVT c. Cu hnh NVT lm vic mt NVT FEED v gi c bn cp nht mi nht ca NVT th ta cn phi cu hnh chng trong mi trng lm vic. Ch k th thch hp khi cu hnh my ch OpenVAS Scanner. Sau khi cc iu kin ban u th cu hnh:
Kim tra cu hnh bng lnh:openvas-nvt-sync Chy lnh ng b ha : # openvas-nvt-sync Nu mun update chy lnh : openvas-update
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

44

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.3 Phng thc hot ng ca OpenVAS
3.3.2 Cc giao thc chnh trong OpenVAS

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

45

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.3 Phng thc hot ng ca OpenVAS
3.3.2 Cc giao thc chnh trong OpenVAS
OpenVAS Transfer Protocol
Cc client v m-un my ch trong OpenVAS c ci t thng qua OpenVAS Transfer Protocol (OTP). Phin bn trc ca OpenVAS s dng Nessus Transport Protocol (NTP) c tha k t Nessus, nhng gii quyt thiu st ca NTP v to iu kin thun li cho vic ci tin trong cc m-un OpenVAS s dng giao thc mi. Hin nay OpenVAS dng phin bn 3.2.5. C nhng thay i khc bit gia hai phin bn NTP 2.1 vi OpenVAS 1.0 Nhng ngi trc tng c kinh nghim khi lm vic vi NTP th s d dng hn trong qu trnh lm vic vi OpenVAS.
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 46

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.3 Phng thc hot ng ca OpenVAS
3.3.2 Cc giao thc chnh trong OpenVAS OpenVAS Manager Protocol y l mt giao thc kh mi cho php giao tip gia client v cc ng dng my ch. Cho php qun l c quyn pha my ch, d liu ngi dng nh cc nhim v, bo co Khi chuyn i gia cc giao thc n kh thch hp dch giao thc OMP thnh OTP. N cn c th rii khi OpenVAS qun tr (openvasd) m khng b thay i.
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 47

Cch thc hot ng ca cc cng c qut l hng bo mt


3 OpenVAS
3.3 Phng thc hot ng ca OpenVAS
OpenVAS Adminnitrator Protocol
L mt giao thc mi cho php client kim sot cc thit lp ca mt my ch OpenVAS. Cu hnh ca mt my ch hin nay i hi ngi qun tr my ch truy cp vo my ch thng qua cc shell v thc thi cc lnh shell hoc sa i cc tp tin cu hnh bng tay. iu ny c th dn n vic sai khc my ch. OAP ra i gii quyt vn . Mc ch khi xy dng:
cho php phn tch c php d dng v nhanh chng ca giao thc trong khi vn gip ngi dng d tin hnh cc mc ch g li v pht trin. Tr thnh mt giao thc thng nht trnh s chm tr khng cn thit trong qu trnh giao tip. Cho php tch hp d dng vo cc giao thc khc v cc phng tin truyn thng.
nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt. 48

Cch thc hot ng ca cc cng c qut l hng bo mt

Demo vi OpenVAS

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

49

nhom9-tm hiu cch thc hot ng ca cc cng c qut l hng bo mt.

50

You might also like