You can't know that all services are running apt installed code, or if they are whether they were restarted already, and the dependencies don't encode what each binary loads at runtime. So scanning processes is the correct thing to do.
Most solutions in engineering involve a trade-off. Clearly this solution trades simplicity for complexity and multiple CVEs. An OS could utilise a known static configuration as described by its packaging system, for a much simpler solution. It could disallow running services any other way.