McAfee MAP-3300-SWG Product Guide - Page 116

Anti-Virus Settings — Basic options, Scan archive files ZIP, ARJ

Page 116 highlights

Overview of Email features Email Policies Anti-Virus Settings - Basic options Use this page to specify basic options for anti-virus scanning. Email | Email Policies | Scanning Policies [Anti-Virus] -- Anti-Virus | Basic options Web | Web Policies | Scanning Policies [Anti-Virus] -- Anti-Virus | Basic options Table 84 Option definitions Option Enable anti-virus scanning Specify which files to scan Definition When selected, scans for viruses and other threats such as worms and spyware. The option is normally set to Yes. Select No only if you have anti-virus protection elsewhere in your network. • Scan all files - offers the highest security. However, scanning takes longer and might affect performance. • Default file types - scans only the most susceptible types of files. • Defined file types - scans only the types in the list. Scan archive files (ZIP, ARJ, RAR ...) Find unknown file viruses Find unknown macro viruses to Remove all macros from document files Enable McAfee Global Threat Intelligence file reputation with Sensitivity level When selected, scans this type of file. However, scanning takes longer and might affect performance. The contents of these files are harmful only when files inside are extracted, and can then by scanned by on-access scanners in individual computers in your network. When selected, does extra analysis to find any virus-like behavior. When selected, take actions against macros in documents. Macros inside documents are a popular target for virus writers. Enables McAfee Global Threat Intelligence file reputation on your appliance. McAfee Global Threat Intelligence file reputation complements the DAT-based signatures by providing the appliances access to millions of cloud-based signatures. This reduces the delay between McAfee detecting a new malware threat and its inclusion in DAT files, providing broader coverage. The sensitivity levels enable you to balance the risk of missing potentially harmful content (low settings) with the risk of false positive detections (high settings). For gateway appliances, the recommended sensitivity level is Medium. Attempt to clean If cleaning succeeds If cleaning fails Use the default alert And also If a file is zero bytes after cleaning Make deobfuscated content available to other scanners When selected, the infection inside the item is removed, if possible. When deselected, the entire item is removed. Provides several actions after cleaning succeeds. Provides several actions if the cleaning failed. When selected, issues the default alert upon detection. When deselected, allows you to click the link, then change the text of the alert. Provides several further actions. Provides an action against a file that is now empty. Zero-byte files cannot carry threats but you might prefer to remove the files if they confuse users. When selected, provides extra protection against unwanted content. The techniques that detect hidden viruses and malware are made available to content scanning. 116 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Anti-Virus Settings — Basic options
Use this page to specify basic options for anti-virus scanning.
Email
|
Email Policies
|
Scanning Policies [Anti-Virus] -- Anti-Virus
|
Basic options
Web
|
Web Policies
|
Scanning Policies [Anti-Virus] -- Anti-Virus
|
Basic options
Table 84
Option definitions
Option
Definition
Enable anti-virus scanning
When selected, scans for viruses and other threats such as worms and
spyware. The option is normally set to
Yes
. Select
No
only if you have
anti-virus protection elsewhere in your network.
Specify which files to scan
Scan all files
— offers the highest security. However, scanning takes longer
and might affect performance.
Default file types
— scans only the most susceptible types of files.
Defined file types
— scans only the types in the list.
Scan archive files (ZIP, ARJ,
RAR ...)
When selected, scans this type of file. However, scanning takes longer and
might affect performance. The contents of these files are harmful only
when files inside are extracted, and can then by scanned by on-access
scanners in individual computers in your network.
Find unknown file viruses
When selected, does extra analysis to find any virus-like behavior.
Find unknown macro viruses
to
Remove all macros from
document files
When selected, take actions against macros in documents. Macros inside
documents are a popular target for virus writers.
Enable McAfee Global Threat
Intelligence file reputation
with
Sensitivity level
Enables McAfee Global Threat Intelligence file reputation on your appliance.
McAfee Global Threat Intelligence file reputation complements the
DAT-based signatures by providing the appliances access to millions of
cloud-based signatures. This reduces the delay between McAfee detecting a
new malware threat and its inclusion in DAT files, providing broader coverage.
The sensitivity levels enable you to balance the risk of missing potentially
harmful content (low settings) with the risk of false positive detections
(high settings).
For gateway appliances, the recommended sensitivity level is Medium.
Attempt to clean
When selected, the infection inside the item is removed, if possible. When
deselected, the entire item is removed.
If cleaning succeeds
Provides several actions after cleaning succeeds.
If cleaning fails
Provides several actions if the cleaning failed.
Use the default alert
When selected, issues the default alert upon detection. When deselected,
allows you to click the link, then change the text of the alert.
And also
Provides several further actions.
If a file is zero bytes after
cleaning
Provides an action against a file that is now empty. Zero-byte files cannot
carry threats but you might prefer to remove the files if they confuse users.
Make deobfuscated content
available to other scanners
When selected, provides extra protection against unwanted content. The
techniques that detect hidden viruses and malware are made available to
content scanning.
Overview of Email features
Email Policies
116
McAfee Email and Web Security Appliances 5.6.0 Product Guide