What is a vulnerability scanner?
A scanner is a computer application that profiles systems as it maps the targeted network. The current application can scan for the SANS/FBI Top Twenty vulnerabilities which classifies these into general operating systems like Windows or Unix. The SANS/FBI Top Twenty list is valuable because the majority of successful attacks on computer systems via the Internet can be traced to exploitation of security flaws on this list. These few software vulnerabilities account for the majority of successful attacks, simply because attackers are opportunistic – taking the easiest and most convenient route. They exploit the best-known flaws with the most effective and widely available attack tools. They count on organizations not fixing the problems, and they often attack indiscriminately, scanning the Internet for any vulnerable systems. What does a scan do? In an effort to improve the security of University systems to protect against computer intrusions and compromises, it is important to understa