Cisco Cisco Web Security Appliance S170 사용자 가이드

다운로드
페이지 784
 
Chapter 19      Anti-Malware Services
Sophos Scanning
19-10
Cisco IronPort AsyncOS 7.0 for Web User Guide
OL-23079-01
For a list of malware scanning verdicts, see 
Sophos Scanning
The Sophos scanning engine inspects objects downloaded from a web server in 
HTTP responses. After inspecting the object, it passes a malware scanning verdict 
to the DVS engine so the DVS engine can determine whether to monitor or block 
the request. You might want to enable the Sophos scanning engine instead of the 
McAfee scanning engine if the client machines have McAfee anti-malware 
software installed.
For more information about how the DVS engine uses malware scanning verdicts 
to handle web traffic, see 
Configuring Anti-Malware Scanning
The DVS engine and Webroot, McAfee, and Sophos are enabled by default during 
system setup. Anytime after system setup, you can configure the anti-malware 
settings for the Web Security appliance. You configure the following 
anti-malware settings:
  •
Global anti-malware settings. Set object scanning parameters, specify 
global settings for URL matching, and control when to block the URL or 
allow processing to continue.
  •
Access Policy anti-malware settings. Enable monitoring or blocking for 
malware categories based on malware scanning verdicts.
To configure anti-malware settings:
Potentially Unwanted Software Package
Adware
Encrypted File
Encrypted File
Table 19-2
Appliance Categories for McAfee Verdicts (continued)
McAfee Verdict
Malware Scanning Verdict Category