Cisco Cisco Web Security Appliance S360 用户指南
8-4
AsyncOS 9.2 for Cisco Web Security Appliances User Guide
Chapter 8 Configuring Security Services
Overview of Anti-Malware Scanning
•
Different verdicts from different scanning engines. When you enable both Webroot and either
Sophos or McAfee, each scanning engine might return different malware verdicts for the same
object. When a URL causes multiple verdicts from both enabled scanning engines, the appliance
performs the most restrictive action. For example, if one scanning engine returns a block verdict and
the other a monitor verdict, the DVS engine always blocks the request.
Sophos or McAfee, each scanning engine might return different malware verdicts for the same
object. When a URL causes multiple verdicts from both enabled scanning engines, the appliance
performs the most restrictive action. For example, if one scanning engine returns a block verdict and
the other a monitor verdict, the DVS engine always blocks the request.
•
Different verdicts from the same scanning engine. A scanning engine might return multiple
verdicts for a single object when the object contains multiple infections. When a URL causes
multiple verdicts from the same scanning engine, the appliance takes action according to the verdict
with the highest priority. The following text lists the possible malware scanning verdicts from the
highest to the lowest priority.
verdicts for a single object when the object contains multiple infections. When a URL causes
multiple verdicts from the same scanning engine, the appliance takes action according to the verdict
with the highest priority. The following text lists the possible malware scanning verdicts from the
highest to the lowest priority.
•
Virus
•
Trojan Downloader
•
Trojan Horse
•
Trojan Phisher
•
Hijacker
•
System monitor
•
Commercial System Monitor
•
Dialer
•
Worm
•
Browser Helper Object
•
Phishing URL
•
Adware
•
Encrypted file
•
Unscannable
•
Other Malware
Webroot Scanning
The Webroot scanning engine inspects objects to determine the malware scanning verdict to send to the
DVS engine. The Webroot scanning engine inspects the following objects:
DVS engine. The Webroot scanning engine inspects the following objects:
•
URL request. Webroot evaluates a URL request to determine if the URL is a malware suspect. If
Webroot suspects the response from this URL might contain malware, the appliance monitors or
blocks the request, depending on how the appliance is configured. If Webroot evaluation clears the
request, the appliance retrieves the URL and scans the server response.
Webroot suspects the response from this URL might contain malware, the appliance monitors or
blocks the request, depending on how the appliance is configured. If Webroot evaluation clears the
request, the appliance retrieves the URL and scans the server response.
•
Server response. When the appliance retrieves a URL, Webroot scans the server response content
and compares it to the Webroot signature database.
and compares it to the Webroot signature database.
McAfee Scanning
The McAfee scanning engine inspects objects downloaded from a web server in HTTP responses. After
inspecting the object, it passes a malware scanning verdict to the DVS engine so the DVS engine can
determine whether to monitor or block the request.
inspecting the object, it passes a malware scanning verdict to the DVS engine so the DVS engine can
determine whether to monitor or block the request.
The McAfee scanning engine uses the following methods to determine the malware scanning verdict: