Vulnerability scan reports are not always accurate, and validating results means distinguishing between true positives, false positives, true negatives, and false negatives. Understanding these four states is essential for ensuring scan findings reflect actual network conditions.
Vulnerability Scan Validation
There are times when I've pulled a report and it's flagged an issue, something that's really critical or a high importance, and then when I do a rescan it goes away. So we want to do some sort of validation to see what exactly the issue is and if it's a true issue.
When we do a vulnerability scan on a network, we're going to be discovering vulnerabilities, and then we get a report as a result. But not always are those reports accurate. Hopefully they are most of the time, but there are times when I've come up with problems that don't actually exist on the network.
Whenever something is being reported or alerting on, then we have four states that can happen here. It could either be true or false, and it could be positive or negative, generating four different states.
The true positive and the true negative means that this is an accurate report. The false positive or false negative just means that it's not accurate on a report. A positive means that it's been reported or found. A negative means that it's not reported or it's not found. In the case with a vulnerability report, if there is a vulnerability reported then it's found. If it is not reporting anything, then that just means that that vulnerability was not found.
Here's another way to look at that. This is what shows up on the report: positive means it shows up on the report, negative means it does not show up on the report. And this is if it's accurate or not, so this is the accuracy. Obviously what we want is we want it to be accurate, which is true right here, so this is the response that we want. If it is showing up in the report, then we want it to be true. If it doesn't show up on the report, then we want it to be true that the vulnerability doesn't exist.
The reason why we validate things is because if something does show up on the report, which is a positive, we want to make sure that it's accurate, which is a true positive. We want to make sure whatever shows up on the report is going to be a true positive, so we would analyze each one of those vulnerabilities and make sure that it's a true positive. If not, then we would call that a false positive, and so we want to eliminate these false positives and want to make sure that we're only getting true positives.
Some systems require some sort of tuning. That is, if we're getting false information, then we may need to step in and do some tuning. For instance, if we got a false negative, that means the negative, it didn't show up on the report, but it should have, because it actually is a vulnerability. So what we need to do is find out why it didn't show up on the report. Same thing if we have a false positive. Sometimes we can get desensitized to this and start ignoring things, so this would be something that we need to dig into and find out why did we get a false positive.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →