主要介绍了网络漏洞扫描系统的结构以及工作原理,并介绍了一种典型的网络漏洞扫描器——Nessus。重点讨论了Nessus的结构、具体扫描过程、服务器端的模块结构以及插件的下载过程等关键问题,并对各部分的代码给出了相应的分析描述。文章最后对网络漏洞扫描器的发展现状和评价标准进行了总结。
This paper discusses the frame and the working principles of the network vulnerability scanner system and introduces a typical network vulnerability scanner--Nessus, with the emphasis on its frame, the scanning process, the server module structure and the plugin download process. The description and analysis of the corresponding codes is given. The paper concludes with a review of the development of network vulnerability scanner and its evaluation criteria.