Back to articles
Technology Insight

Automating Web Vulnerability Scanning: Deploying OpenVAS on a VPS for Continuous Security Monitoring

May 29, 2026

Introduction to Automated Vulnerability Management

In the contemporary digital ecosystem, web applications serve as the primary gateway for customer engagement, transactional operations, and proprietary data storage. Consequently, they have become prime targets for sophisticated cyber threats. While periodic manual penetration testing remains a critical component of a robust cybersecurity posture, it represents only a point-in-time assessment. Software environments are dynamic; new vulnerabilities, known as Common Vulnerabilities and Expositions (CVEs), are discovered daily, and continuous integration/continuous deployment (CI/CD) pipelines frequently introduce configuration drifts.

To bridge this security gap, modern enterprises must transition toward a proactive, continuous security model. Building an automated web vulnerability scanning system ensures that your infrastructure is evaluated consistently against the latest threat intelligence. By deploying OpenVAS (Open Vulnerability Assessment System)—now developed as the Greenbone Vulnerability Management (GVM) framework—on a dedicated Virtual Private Server (VPS), organizations can achieve enterprise-grade security orchestration without the prohibitive costs of proprietary SaaS alternatives.

Why OpenVAS and a Dedicated VPS?

Selecting the right framework and architecture is paramount for reliable security operations. OpenVAS stands out as the premier open-source vulnerability scanner, backed by a comprehensive, daily-updated feed of over 100,000 vulnerability tests. It excels not only at detecting unpatched web server components but also at identifying misconfigurations, weak cryptographic protocols, and open ports.

Hosting OpenVAS on an independent VPS offers distinct strategic advantages over local or shared hosting environments:

  • Consistent Network Peripherals: A dedicated VPS provides a stable, static IP address, which is essential for whitelisting the scanner in application firewalls and preventing false positives from intrusion detection systems.
  • Resource Isolation: Deep vulnerability scans are resource-intensive, requiring significant CPU cycles and memory overhead. Offloading this workload to a VPS ensures that production environments remain unaffected.
  • Asynchronous Scheduling: Operating 24/7 in the cloud allows the system to execute comprehensive scans during off-peak hours automatically, adhering to strict corporate compliance frameworks.

Prerequisites and System Requirements

Before initiating the deployment, ensure that your VPS instance adheres to the minimum technical baseline required to support the Greenbone architecture efficiently:

  • Operating System: Ubuntu 22.04 LTS or Debian 12 (clean installation recommended).
  • Hardware Specifications: A minimum of 4 vCPUs, 8 GB of RAM, and 50 GB of high-speed SSD storage (to accommodate the expansive PostgreSQL vulnerability database).
  • Network Configuration: Fully qualified domain name (FQDN) pointed to the VPS IP, and access to firewall configurations (UFW or security groups).

Step-by-Step Deployment of OpenVAS on a VPS

Step 1: System Optimization and Dependency Alignment

First, establish an SSH connection to your VPS and execute a comprehensive update of the system packages to ensure alignment with upstream repositories:

sudo apt update && sudo apt upgrade -y

Install the foundational dependencies required for compiling or extracting GVM containers, including common network utilities and build tools:

sudo apt install -y curl wget apt-transport-https gnupg2 software-properties-common

Step 2: Architecture Selection: Containerized Deployment

While compiling OpenVAS from source is an option, utilizing the official community containers via Docker is the industry standard for maintainability, security, and isolation. If Docker is not already present on your VPS, install it utilizing the official Docker convenience script:

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh

Once Docker and Docker Compose are initialized, create a dedicated directory structure for the Greenbone Community Containers:

mkdir -p /opt/gvm
cd /opt/gvm

Download the official Docker Compose configuration file provided by Greenbone. This file orchestrates the interconnected microservices, including the OpenVAS scanner, the Greenbone Vulnerability Management daemon (gvmd), the PostgreSQL database, and the Greenbone Security Assistant (GSA) web interface:

wget https://greenbone.github.io/docs/latest/_static/docker-compose-22.4.yml -O docker-compose.yml

Step 3: Orchestrating the Services

Launch the containers in detached mode. This initial initialization will automatically download the required container images and establish the network bridges:

sudo docker compose -f docker-compose.yml -p greenbone-community-containers up -d
Note: The initial container startup initiates a significant synchronization process. The system must download the latest Greenbone Community Feed, which includes thousands of Network Vulnerability Tests (NVTs), Scap data, and Cert data. This process can take anywhere from 30 minutes to several hours depending on your VPS network bandwidth and processing speed.

Monitor the synchronization progress by tailing the container logs:

sudo docker compose -f /opt/gvm/docker-compose.yml -p greenbone-community-containers logs -f gvmd

Configuring the Automated Security Scan Architecture

Once the logs indicate that the feed synchronization is complete, navigate to the web interface via your browser by accessing http://:9392. Log in using the default administrative credentials generated during the container setup (or verify them within the setup logs).

1. Define the Scan Target

To configure a scan, navigate to Configuration > Targets. Click the 'New Target' icon. Here, you must define the scope of your assessment:

  • Name: Input a descriptive identifier (e.g., "Production E-Commerce Web Server").
  • Hosts: Enter the domain name or public IP address of the website you wish to evaluate.
  • Port List: Select "All IANA assigned TCP and UDP" or opt for a specialized web scan profile mapping ports 80 and 443.

2. Construct the Scan Task

Navigate to Scans > Tasks and create a new task. Link this task directly to the Target profile created in the previous step. Under the Scan Config dropdown, select the depth of the scan. For regular web application environments, the "Full and Fast" configuration offers an optimized balance of speed and thoroughness, probing for known server vulnerabilities, outdated CMS versions, and SSL/TLS configuration deficiencies.

3. Automating Scans with Cron and Schedules

To transform this manual setup into a fully automated security pipeline, navigate to Configuration > Schedules. Define a periodic interval that aligns with your operational architecture. For standard enterprise websites, a weekly execution during weekend maintenance windows (e.g., Sunday at 02:00 UTC) is highly recommended. This mitigates any minor performance degradation risks for live users during the deep inspection phase.

Enterprise Best Practices for Cloud-Based Scanning

Operating a security scanner in a public cloud environment requires adherence to specific operational protocols to prevent self-inflicted disruptions:

  • Secure the Interface: Never leave the Greenbone Security Assistant web interface exposed on an unencrypted HTTP port. Implement a reverse proxy using Nginx or Caddy, and enforce strict TLS encryption with a Let's Encrypt certificate. Restrict access to the interface IP via firewall rules to corporate VPNs only.
  • ISP and Hosting Provider Notification: Some VPS providers classify automated vulnerability scanning as malicious behavior or a violation of Terms of Service. Always notify your hosting provider's abuse department or choose a provider that explicitly permits authorized security auditing on assets you legally own.
  • Alerting Integration: Configure SMTP alerts within OpenVAS to immediately dispatch PDF or XML scan reports to your Security Operations Center (SOC) or system engineering team upon task completion, specifically filtering for 'High' and 'Severe' threat logs.

Conclusion

Establishing an automated web vulnerability scanning system using OpenVAS on a dedicated VPS converts network security from a reactive, crisis-driven task into a structured, continuous operational workflow. By identifying vulnerabilities, expired certificates, and configuration errors before malicious actors can exploit them, organizations significantly minimize their attack surface. In an era where data integrity dictates business longevity, automated scanning is not an optional luxury—it is a core pillar of modern digital governance.

Automating Web Vulnerability Scanning: Deploying OpenVAS on a VPS for Continuous Security Monitoring | DPTCloud