McAfee MAP-3300-SWG Product Guide - Page 107

Customized anti-virus settings, Detection of new and unknown viruses, Email, Email Policies

Page 107 highlights

Overview of Email features Email Policies Customized anti-virus settings Besides giving you the levels of scanning (such as default file types, which scans only the most susceptible files), the appliance also allows you to specify various options when scanning for viruses. Email | Email Policies | Scanning Policies [Anti-Virus] -- Anti-Virus | Basic options Web | Web Policies | Scanning Policies [Anti-Virus] -- Anti-Virus | Basic options Although more options can provide greater security, scanning will take longer. The scanning capabilities are: • Detect possible new viruses in programs and documents. Documents that carry a virus often have distinctive features such as a common technique for replicating themselves. Using heuristics, the scanner analyzes the document to detect these kinds of computer instructions. Program file heuristics scans program files and identifies potential new file viruses. Macro heuristics scans for macros in the attachments (such as those used by Microsoft Word, Microsoft Excel, and Microsoft Office) and identifies potential new macro viruses. • Scan inside archive files. By default, the scanner does not scan inside file archives such as .zip or .lzh files because any infected file inside them cannot become active until it has been extracted. • Scan default file types. Normally, the scanner examines only the default file types - it scans only those files that are susceptible to infection. For example, many popular text and graphic formats are not affected by viruses. Currently, the scanner examines over 100 file types by default, including .exe and .com. • Scan all files. This option ensures that every file is scanned. Some operating systems, such as Microsoft Windows, use the extension names of files to identify their type. For example, files with the extension .exe are programs. However, if an infected file is renamed with a harmless extension such as .txt, it can escape detection and the operating system can run the file as a program if it is renamed later. • Scan files according to file name extension. You can specify the types of files you want to scan according to their file name extensions. • Treat all macros as viruses. Macros inside documents are a popular target for virus writers. Therefore, for added security, consider scanning all files for macro viruses, and optionally removing any macros found, regardless of whether they are infected. • Scan compressed program files. This is used to scan compressed files such as those compressed using PKLITE. If you are scanning selected file extensions only, add the appropriate compressed file extensions to the list. Detection of new and unknown viruses An anti-virus scanner uses signatures and heuristic analysis to detect viruses. A virus signature is a binary pattern found in a virus-infected file. Using information in its anti-virus definition (DAT) files, the scanner searches for those patterns. Email | Email Policies | Scanning Policies [Anti-Virus] -- Anti-Virus | Basic options This approach cannot detect a new virus because its signature is not yet known. Therefore another technique, known as heuristic analysis, is employed. McAfee Email and Web Security Appliances 5.6.0 Product Guide 107

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Customized anti-virus settings
Besides giving you the levels of scanning (such as default file types, which scans only the most
susceptible files), the appliance also allows you to specify various options when scanning for viruses.
Email
|
Email Policies
|
Scanning Policies [Anti-Virus] -- Anti-Virus
|
Basic options
Web
|
Web Policies
|
Scanning Policies [Anti-Virus] -- Anti-Virus
|
Basic options
Although more options can provide greater security, scanning will take longer. The scanning
capabilities are:
Detect possible new viruses in programs and documents.
Documents that carry a virus often have distinctive features such as a common technique for
replicating themselves. Using heuristics, the scanner analyzes the document to detect these kinds
of computer instructions. Program file heuristics scans program files and identifies potential new
file viruses. Macro heuristics scans for macros in the attachments (such as those used by Microsoft
Word, Microsoft Excel, and Microsoft Office) and identifies potential new macro viruses.
Scan inside archive files.
By default, the scanner does not scan inside file archives such as .zip or .lzh files because any
infected file inside them cannot become active until it has been extracted.
Scan default file types.
Normally, the scanner examines only the default file types — it scans only those files that are
susceptible to infection. For example, many popular text and graphic formats are not affected by
viruses. Currently, the scanner examines over 100 file types by default, including .exe and .com.
Scan all files.
This option ensures that every file is scanned. Some operating systems, such as Microsoft
Windows, use the extension names of files to identify their type. For example, files with the
extension .exe are programs. However, if an infected file is renamed with a harmless extension
such as .txt, it can escape detection and the operating system can run the file as a program if it is
renamed later.
Scan files according to file name extension.
You can specify the types of files you want to scan according to their file name extensions.
Treat all macros as viruses.
Macros inside documents are a popular target for virus writers. Therefore, for added security,
consider scanning all files for macro viruses, and optionally removing any macros found, regardless
of whether they are infected.
Scan compressed program files.
This is used to scan compressed files such as those compressed using PKLITE. If you are scanning
selected file extensions only, add the appropriate compressed file extensions to the list.
Detection of new and unknown viruses
An anti-virus scanner uses signatures and heuristic analysis to detect viruses. A virus signature is a
binary pattern found in a virus-infected file. Using information in its anti-virus definition (DAT) files,
the scanner searches for those patterns.
Email
|
Email Policies
|
Scanning Policies [Anti-Virus] -- Anti-Virus
|
Basic options
This approach cannot detect a new virus because its signature is not yet known. Therefore another
technique, known as heuristic analysis, is employed.
Overview of Email features
Email Policies
McAfee Email and Web Security Appliances 5.6.0 Product Guide
107