• No results found

Edge-based Virus Scanning

N/A
N/A
Protected

Academic year: 2021

Share "Edge-based Virus Scanning"

Copied!
6
0
0

Loading.... (view fulltext now)

Full text

(1)

i Application Note: Edge-based Virus Scanning

Copyright  2002 ServGate Technologies, Inc.

APPLICATION NOTE

658 Gibraltar Court

Milpitas, CA 95035

Phone: 408-635-8400

Fax: 408-635-8470

www.servgate.com

Edge-based Virus

Scanning

(2)

Edge-based Virus Scanning

APPLICATION NOTE

All product names referenced herein are trademarks or registered trademarks of their Respective companies. ServGate Technologies, Inc. disclaims proprietary interest in the trademarks and brand names of others. As with all literature created and distributed by ServGate Technologies, Inc., we make every effort to ensure the information is truthful and factual, however, ServGate Technologies, Inc. will not be liable for any inaccuracies or accidental exclusions. ServGate Technologies, Inc. reserves the right to modify this and any document without prior notification. No part of this document may be reproduced or transmitted in any form or by any means, electronic or otherwise, for any purpose without express verbal or written consent by ServGate Technologies, Inc.

(3)

Application Note: Edge-based Virus Scanning Copyright  2002 ServGate Technologies, Inc.

iii

Table Of Contents

Objective……….. 1

Legacy Two-tier Virus Scanning……….. 2

Edge-based Virus Scanning in at Three-tier Model……..3

(4)

Edge-based Virus Scanning

Application Note

Objective

With the proliferation of viruses, worms, Trojans and blended threats like Nimda and Code Red at an all-time high, the need to protect the corporate network has never been higher. We have all read the studies: “…countless billions of dollars in lost productivity every year due to the devastating effects of viruses.”

Client and server-based virus scanning software provides adequate protection for simple networks, but the complexities of deployment, enforcement and in larger companies make this approach unpredictable and inadequate. By adding virus scanning at the network edge, viruses and worms can be stopped before they enter the network, offering an essential layer of protection against these increasingly sophisticated threats. ServGate Technologies has teamed with McAfee™ to integrate their award-winning virus-scanning engine into ServGate EdgeForce Security Gateways. The combined solution provides Firewall, VPN, Antivirus, Content Filtering and attack detection in a single, easily managed security appliance.

(5)

Application Note: Edge-based Virus Scanning Copyright  2002 ServGate Technologies, Inc.

2 Demilitarized Zone (DMZ) Mail Server FTP Server Web Server Client-based AntiVirus Server-based AntiVirus

Legacy Two-tier Virus Scanning

In a two-tiered anti-virus model, every client and server has independent virus scanning software installed on each machine. For email, the software typically scans all SMTP and/or POP3 traffic for infected files based on frequently updated virus definition files

obtained from the manufacturer of the virus scanning software. Additionally, FTP and HTML protocols may be scanned for viruses since the majority of threats lie in email attachments; POP3 and SMTP are typically the most important features of a virus-scanning package.

Two common threats in a typical network are viruses entering the network through the Firewall external (EXT) port destined for the mail, FTP or web server in the demilitarized zone (DMZ), and infected traffic originating from the client machines themselves (for

instance a dirty floppy disk, or an infected file downloaded form the Internet).

The client and server-based model offers reasonable protection for small networks, but there are significant risks associated with the model. It is difficult to manage hundreds or thousands of software packages at the individual client and server level.

• Even with modern mass-install and configuration utilities, it is very easy for individual users to modify the settings on the software, rendering them helpless against viruses.

• It is difficult to monitor and enforce each piece of virus scanning software to make sure it is compliant with the latest version of virus definitions form the manufacturer.

• There is risk in relying on a single manufacturer to stop all viruses, even with frequently updated virus definition files.

Many firewall vendors have placed 3rd party virus scanning logic on their appliances that ‘polices’ clients and servers in the network to ensure that they have the latest versions of virus definition files on individual machines. While this adds to the effectiveness of the overall security system, viruses and worms are left to enter the network where they are liable to wreak havoc with unprotected machines, or machines that do not have the most recent version of the anti-virus database.

(6)

Edge-based Virus-Scanning in a Three-tier Model

By adding virus scanning at the

network edge, a few good things happen. First, another complete layer of network security has been added to further protects the network. Viruses and worms are stopped before they enter the network. Second, by mixing vendors such that one

manufacturer of AV software is used at the client and server level, and another manufacturer at the edge-level, the virus scanning task has been ‘diversified’, further ensuring the network is protected in the case of a new outbreak.

A key component of edge-based virus scanning is file quarantine. It is important for the network manager to have the option to hold and inspect infected files before making the delete decision. Not only does this help in the troubleshooting and planning process, but provides significant aid to the forensic investigation process as well.

Security solutions that detect viruses are a must in today’s corporate network,

irrespective of network size. Small to Midsize Businesses and enterprises of all sizes are now considering a more comprehensive security solution based on a three-tier model. Why not stop viruses where they enter the network, at the network edge, then hedge the bet by adding anti-virus protection at the client and server level.

Demilitarized Zone (DMZ) Mail Server FTP Server Web Server

References

Related documents

The lift to drag ratio increases as the angle of attack increased on both wings, for rear wing the lift to drag ratio is reduced when compared to that of front wing due to

Op basis van het IMBP wordt de relatie gezocht tussen de intentie om het IW in het onderwijs te gebruiken en de houding, waargenomen sociale norm en eigen effectiviteit en de

• define good practice for archetype authorship • establish quality, governance and certification. processes for archetypes

No Post-Scriptum às Migalhas Filosófi cas, de 1846, há uma tese profundamente instigante sobre essa relação de Kierkegaard com a herança clássica e a herança cristã e, por

Network Firewalls Do Not Work For HTTP Firewall Port 80 HTTP Traffic Web Client Web Server Application Application Database Server...

46 In construing the statutory language narrowly, the court determined that the jury trial provision of the 1991 CRA places a necessary condition on awarding

In re- sponse to this trend, gas preconditioning upstream, or final step(s) for gas condi- tioning downstream of the gas-treating unit, are emerging as the best options to comply

Moreover, as a result of the strong correlation patterns among traits, I was able to generate much more precise estimates of plant functional type means (which can be used as