Cisco Cisco Web Security Appliance S360 Guia Do Utilizador

Página de 286
8-4
AsyncOS 9.2 for Cisco Web Security Appliances User Guide
 
Chapter 8      Configuring Security Services
  Overview of Anti-Malware Scanning
Different verdicts from different scanning engines. When you enable both Webroot and either 
Sophos or McAfee, each scanning engine might return different malware verdicts for the same 
object. When a URL causes multiple verdicts from both enabled scanning engines, the appliance 
performs the most restrictive action. For example, if one scanning engine returns a block verdict and 
the other a monitor verdict, the DVS engine always blocks the request. 
Different verdicts from the same scanning engine. A scanning engine might return multiple 
verdicts for a single object when the object contains multiple infections. When a URL causes 
multiple verdicts from the same scanning engine, the appliance takes action according to the verdict 
with the highest priority. The following text lists the possible malware scanning verdicts from the 
highest to the lowest priority.
Virus
Trojan Downloader
Trojan Horse
Trojan Phisher
Hijacker
System monitor
Commercial System Monitor
Dialer
Worm
Browser Helper Object
Phishing URL
Adware
Encrypted file
Unscannable
Other Malware
Webroot Scanning
The Webroot scanning engine inspects objects to determine the malware scanning verdict to send to the 
DVS engine. The Webroot scanning engine inspects the following objects:
URL request. Webroot evaluates a URL request to determine if the URL is a malware suspect. If 
Webroot suspects the response from this URL might contain malware, the appliance monitors or 
blocks the request, depending on how the appliance is configured. If Webroot evaluation clears the 
request, the appliance retrieves the URL and scans the server response.
Server response. When the appliance retrieves a URL, Webroot scans the server response content 
and compares it to the Webroot signature database. 
McAfee Scanning
The McAfee scanning engine inspects objects downloaded from a web server in HTTP responses. After 
inspecting the object, it passes a malware scanning verdict to the DVS engine so the DVS engine can 
determine whether to monitor or block the request.
The McAfee scanning engine uses the following methods to determine the malware scanning verdict: