So I agree the false positives are a pain in networks with patched systems but this also seems to be standard behavior.
So I agree the false positives are a pain in networks with patched systems but this also seems to be standard behavior.
Our goal was to make something easy to run and deploy with similar results to something like openvas or Nessus.
I personally think accuracy issues are because security vendors don’t want to show that their expensive software found nothing, so they dial down the accuracy. This works using the same methods as a Nessus, banner grabbing and indexing issues.
We are going to keep working on this and look for ways to make it more accurate, but I’d say our results with this versus our expensive scanners was pretty much the same.
That might be a bit cynical, not sure I'd call openvas expensive.. I think it comes down to the fact that the damage of a single false negative can far outweigh the cost of the false positives. In the end, these scanners are mostly a tool to help document your security efforts, often for compliance reasons, making you think about and document the choices you make from a security perspective.
OpenVAS is free, but the big issue we've had with it is the complexity of setting it up and maintaining it. We are a security team, and would rather not spend our time managing servers, especially since we aren't the best people to do that at Cloudflare.
Shameless plug: I got it to work. Will be doing a talk about the experience at week's DC4420 meeting.
I've looked at it (openvas), got something working, but was never happy with it and ended up returning to a simpler/proven nmap base that I could manage better and add complexity if/when needed.
On the other hand.. I do have something that might be enough to get you going. The setup we built is open: https://github.com/smarkets/vuln-scanner - go have a look.
The glue code has comments on some of the stranger bugs I had to work around. So does the readme. If something isn't clear, feel free to ask.
One of my challanges was understanding the the zoo of tests OpenVAS would run and trying to reliably select which ones to apply. Did you, or anyone here, ever spot a way of outputting all the tests (nmap scripts etc.) that a particular run would trigger (but without actually running them)
I think there might be a way to choose categories to include/exclude but haven't had the time to actually investigate.
But they also required expensive functional scammer/scanner subscriptions. I see this basic tool plus some scraping of changelogs (included in suse and redhat binary rpms) for cve numbers should substantially reduce the false positives. For the price of another 50 lines of python.
Don't know what other distros or the BSDs have available.
The majority of time these reports are being produced to fulfill an auditing or FISMA requirement and not considered worth the risk to systems a functional scan could present.