Cisco Cisco Web Security Appliance S170 Guía Del Usuario
8-5
AsyncOS 9.2 for Cisco Web Security Appliances User Guide
Chapter 8 Configuring Security Services
Overview of Anti-Malware Scanning
•
Matching virus signature patterns
•
Heuristic analysis
Matching Virus Signature Patterns
McAfee uses virus definitions in its database with the scanning engine to detect particular viruses, types
of viruses, or other potentially unwanted software. It searches for virus signatures in files. When you
enable McAfee, the McAfee scanning engine uses this method to scan server response content.
of viruses, or other potentially unwanted software. It searches for virus signatures in files. When you
enable McAfee, the McAfee scanning engine uses this method to scan server response content.
Heuristic Analysis
Heuristic analysis is a technique that uses general rules, rather than specific rules, to detect new viruses
and malware. When the McAfee scanning engine uses heuristic analysis, it looks at the code of an object,
applies generic rules, and determines how likely the object is to be virus-like.
and malware. When the McAfee scanning engine uses heuristic analysis, it looks at the code of an object,
applies generic rules, and determines how likely the object is to be virus-like.
Using heuristic analysis increases the possibility of reporting false positives (clean content designated
as a virus) and might impact appliance performance.When you enable McAfee, you can choose whether
or not to also enable heuristic analysis when scanning objects.
as a virus) and might impact appliance performance.When you enable McAfee, you can choose whether
or not to also enable heuristic analysis when scanning objects.
McAfee Categories
Sophos Scanning
The Sophos scanning engine inspects objects downloaded from a web server in HTTP responses. After
inspecting the object, it passes a malware scanning verdict to the DVS engine so the DVS engine can
determine whether to monitor or block the request. You might want to enable the Sophos scanning engine
instead of the McAfee scanning engine if McAfee anti-malware software is installed.
inspecting the object, it passes a malware scanning verdict to the DVS engine so the DVS engine can
determine whether to monitor or block the request. You might want to enable the Sophos scanning engine
instead of the McAfee scanning engine if McAfee anti-malware software is installed.
McAfee Verdict
Malware Scanning Verdict Category
Known Virus
Virus
Trojan
Trojan Horse
Joke File
Adware
Test File
Virus
Wannabe
Virus
Killed
Virus
Commercial Application
Commercial System Monitor
Potentially Unwanted Object
Adware
Potentially Unwanted Software Package
Adware
Encrypted File
Encrypted File