Cisco Cisco Web Security Appliance S160 Guía Del Usuario
13-5
AsyncOS 9.1 for Cisco Web Security Appliances User Guide
Chapter 13 Configuring Security Services
Overview of Anti-Malware Scanning
Working with Multiple Malware Verdicts
The DVS engine might determine multiple malware verdicts for a single URL. Multiple verdicts can
come from one or both enabled scanning engines:
come from one or both enabled scanning engines:
•
Different verdicts from different scanning engines. When you enable both Webroot and either
Sophos or McAfee, each scanning engine might return different malware verdicts for the same
object. When a URL causes multiple verdicts from both enabled scanning engines, the appliance
performs the most restrictive action. For example, if one scanning engine returns a block verdict and
the other a monitor verdict, the DVS engine always blocks the request.
Sophos or McAfee, each scanning engine might return different malware verdicts for the same
object. When a URL causes multiple verdicts from both enabled scanning engines, the appliance
performs the most restrictive action. For example, if one scanning engine returns a block verdict and
the other a monitor verdict, the DVS engine always blocks the request.
•
Different verdicts from the same scanning engine. A scanning engine might return multiple
verdicts for a single object when the object contains multiple infections. When a URL causes
multiple verdicts from the same scanning engine, the appliance takes action according to the verdict
with the highest priority. The following text lists the possible malware scanning verdicts from the
highest to the lowest priority.
verdicts for a single object when the object contains multiple infections. When a URL causes
multiple verdicts from the same scanning engine, the appliance takes action according to the verdict
with the highest priority. The following text lists the possible malware scanning verdicts from the
highest to the lowest priority.
•
Virus
•
Trojan Downloader
•
Trojan Horse
•
Trojan Phisher
•
Hijacker
•
System monitor
•
Commercial System Monitor
•
Dialer
•
Worm
•
Browser Helper Object
•
Phishing URL
•
Adware
•
Encrypted file
•
Unscannable
•
Other Malware
Webroot Scanning
The Webroot scanning engine inspects objects to determine the malware scanning verdict to send to the
DVS engine. The Webroot scanning engine inspects the following objects:
DVS engine. The Webroot scanning engine inspects the following objects:
•
URL request. Webroot evaluates a URL request to determine if the URL is a malware suspect. If
Webroot suspects the response from this URL might contain malware, the appliance monitors or
blocks the request, depending on how the appliance is configured. If Webroot evaluation clears the
request, the appliance retrieves the URL and scans the server response.
Webroot suspects the response from this URL might contain malware, the appliance monitors or
blocks the request, depending on how the appliance is configured. If Webroot evaluation clears the
request, the appliance retrieves the URL and scans the server response.
•
Server response. When the appliance retrieves a URL, Webroot scans the server response content
and compares it to the Webroot signature database.
and compares it to the Webroot signature database.