McAfee MAP-3300-SWG Product Guide - Page 108

Special actions against packers and PUPs, Problems with alerts for mass mailers

Page 108 highlights

Overview of Email features Email Policies Programs that carry a virus often have distinctive features. They might attempt unprompted modification of files, invoke mail clients, or self-propagate. The scanner analyzes the program code to detect these kinds of computer instructions. It also searches for legitimate behavior, such as prompting the user before taking action, and thereby avoids raising false alarms. To avoid detection, some viruses are encrypted. Each computer instruction is a binary number, but the computer does not use all the possible numbers. By searching for unexpected numbers inside a program file, the scanner can detect an encrypted virus. Using these techniques, the scanner can detect known viruses, and many new viruses and variants. Special actions against packers and PUPs The appliance handles most detections according to the actions that you specify on the Basic Options tab. Email | Email Policies | Scanning Policies [Anti-Virus] Web | Web Policies | Scanning Policies [Anti-Virus] To specify that a scanner on the appliance handles some packers and PUPs differently, use the Custom Malware Options tab. Problems with alerts for mass mailers Normally, the appliance handles all potentially unwanted programs in the same way. However you can specify that certain types are handled differently. Email | Email Policies | Scanning Policies [Anti-Virus] Custom Malware options For example, you can configure the appliance to inform the sender, the recipient and an administrator with an alert message whenever a virus is detected in an email message. This feature is useful because it shows that the anti-virus detection is working correctly, but it can become a nuisance if a mass-mailer virus is encountered. Mass-mailer viruses (for example Melissa and Bubbleboy) propagate themselves rapidly using email. Numerous alerts are generated, and these can be as annoying as the surge of detected email messages that has been blocked. The appliance can handle any mass-mailer virus separately from other types of virus. You example, you can choose to discard the detected document immediately, and thereby suppress any alert messages that will otherwise be generated. 108 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Programs that carry a virus often have distinctive features. They might attempt unprompted
modification of files, invoke mail clients, or self-propagate. The scanner analyzes the program code to
detect these kinds of computer instructions. It also searches for legitimate behavior, such as
prompting the user before taking action, and thereby avoids raising false alarms.
To avoid detection, some viruses are encrypted. Each computer instruction is a binary number, but the
computer does not use all the possible numbers. By searching for unexpected numbers inside a
program file, the scanner can detect an encrypted virus.
Using these techniques, the scanner can detect known viruses, and many new viruses and variants.
Special actions against packers and PUPs
The appliance handles most detections according to the actions that you specify on the
Basic Options
tab.
Email
|
Email Policies
|
Scanning Policies [Anti-Virus]
Web
|
Web Policies
|
Scanning Policies [Anti-Virus]
To specify that a scanner on the appliance handles some packers and PUPs differently, use the
Custom
Malware Options
tab.
Problems with alerts for mass mailers
Normally, the appliance handles all potentially unwanted programs in the same way. However you can
specify that certain types are handled differently.
Email
|
Email Policies
|
Scanning Policies [Anti-Virus] Custom Malware options
For example, you can configure the appliance to inform the sender, the recipient and an administrator
with an alert message whenever a virus is detected in an email message. This feature is useful
because it shows that the anti-virus detection is working correctly, but it can become a nuisance if a
mass-mailer virus is encountered.
Mass-mailer viruses (for example Melissa and Bubbleboy) propagate themselves rapidly using email.
Numerous alerts are generated, and these can be as annoying as the surge of detected email
messages that has been blocked.
The appliance can handle any mass-mailer virus separately from other types of virus. You example,
you can choose to discard the detected document immediately, and thereby suppress any alert
messages that will otherwise be generated.
Overview of Email features
Email Policies
108
McAfee Email and Web Security Appliances 5.6.0 Product Guide