|
Dr.Web Server Security Suite Functions |
|
This Manual describes aspects of configuring components of Dr.Web Server Security Suite designed for GNU/Linux and FreeBSD. The Manual is intended for a person responsible for anti-virus protection and configuration of networks (hereinafter referred to as "Administrator"). Dr.Web Server Security Suite is designed to protect servers running on OSes of GNU/Linux family and FreeBSD from viruses and other types of malicious software, and to prevent distribution of threats designed for different platforms. Main features of Dr.Web Server Security Suite: 1.Detection and neutralization of threats. Scans for malicious programs of all possible types (various viruses, including those that infect mail files and boot records, trojans, mail worms, and so on) and unwanted software (adware, joke programs and dialers). Threat detection methods: •signature analysis—a scan method allowing to detect known threats registered in virus databases; •heuristic analysis—a set of scan methods allowing to detect threats that are not known yet; •Dr.Web Cloud service, which collects up-to-date information about recent threats and sends it to various products of Doctor Web. Note that the heuristic analyzer may raise false-positive detections of legitimate software. Thus, objects that contain threats detected by the analyzer are considered “suspicious”. It is recommended that you choose to quarantine such files and send them for analysis to the Doctor Web anti-virus laboratory. Scanning the file system at user request can be performed in two modes: full scan (scanning all file system objects) and custom scan (scanning selected objects—directories or files that satisfy specified criteria). Moreover, the user can start a separate scan of volume boot records and executables that spawned currently active processes. In the latter case, if a malicious executable is detected, it is neutralized and all processes spawned by this file are forced to terminate. 2.Monitoring access to files: •File system in the OS. File events and attempts to run executables are monitored. This feature allows to detect and neutralize malware instantly at attempt of infecting the file system of the server. •Samba shared directories. Read and write operations of local and remote users of the file server are monitored. This feature allows to detect and neutralize malware instantly at an attempt of copying it to the file storage, which prevents its further distribution over the network. •Novell Storage Services volumes. Write operations of the NSS file storage users are monitored. This feature allows to detect and neutralize malware instantly at an attempt of copying it to the NSS storage, which prevents its further distribution over the network.
3.Reliable isolation of malicious or suspicious objects in special storage known as quarantine to prevent any damage to the system. When quarantined, the objects are renamed according to specific rules and, if necessary, such objects can be restored to their original location only on user demand. |