Virus Scanner
Anti-Virus Messaging Firewall
- Protects your computing environment from one of the most common forms of virus exchange
- Prevents passing viruses to customers and partners
- Employs industry-leading virus detection software
- Detects viruses even in UUencoded or MIME-encoded attachments
- Sanitises messages found carrying a virus
- Alerts system management to virus detection
- Scans all or selected attachment types
- Operates selectively for different message destinations or users
The Route400 Virus Scanner is an optional component for the Route400
Message Server.
Its function is to prevent the passage of viruses that may be carried within a
message.
The Virus Scanner scans for the presence of viruses carried within messages and, if
detected, eradicates the virus-infected components of the message and alerts the
system manager.
The operation of the Virus Scanner requires no end-user involvement, operating
transparently to all client systems. This product complements the use of
client-based anti-virus software, to form a multi-layered defence against virus
attack.
The Virus Scanner can be combined with the Route400
Secure MTA Gateway
to form a powerful Messaging Firewall able to meet stringent security policy
requirements (see the backgrounder document entitled "The Messaging Firewall").
When used with other Route400 components, the Virus Scanner can analyse messages
passed between Internet Mail, X.400, cc:Mail, MS Mail, Lotus Notes and GroupWise.
The Virus Scanner operates together with the Route400
Document Converter.
Instead of converting documents attached to a message, the scanner submits
documents to a virus detection product.
In order to ensure the highest level of virus protection, the Virus Scanner comes
preconfigured to operate with the industry-leading anti-virus packages from either
Dr. Solomon or McAfee.
Alternative anti-virus products can be easily integrated.
Background
The type and form of computer viruses continues to grow, as does the cost of ensuring that your computing environment is kept free from infection.
An essential element in defending against the infiltration of virus material is applying a security policy that addresses how to:
- Stop virus infected material entering your computing environment
- Detect and eliminate viruses on infected systems
- Prevent the spread of virus infected material, both within your organisation and to those outside
Macro viruses (which infect macros attached to documents and spreadsheets) now represent an ever-increasing proportion of infections. Since documents are frequently exchanged, it is very easy for macro viruses to be spread unwittingly.
Given the dominant role of Messaging in document exchange, it is no surprise that this has now become one of the most common transport mechanisms for computer viruses. It is no longer an adequate response to this threat to rely solely on anti-virus software run on individual computers, experts agree that multi-layered defence is essential.
A primary defence is to firewall your messaging environment so that a virus-laden message can be stopped at the boundary of your organisation. This prevents viruses ever entering your computing environment. Equally, members of your organisation are prevented from passing a virus to customers and partners.
Overview
The Route400 Virus Scanner operates in conjunction with the Route400 Document Converter in order to scan for virus-laden messages.
If a virus is found or suspected then the suspect document is isolated and replaced with a textual attachment announcing the virus removal.
Additionally a message is sent to a configured user (usually the system manager) saying a virus has been found. The originator of the message can be similarly informed.
Features
Focuses protection where it is needed:
- Either all or selected types of attachment may be scanned
- Scanning may be performed selectively for different message destinations or users
Performs in-depth scanning:
- Forwarded messages, which may be nested to any depth, are completely scanned
- Scan of P772 (Military MHS) message content type is supported as an option
- Scan of UUencoded attachments is supported as an option (these may be converted to either File Transfer or Bilateral body parts)
- Scan of MIME encoded attachments (Base64) is supported as an option (these may be converted to either File Transfer or Bilateral body parts). Also handles partial MIME encoding (i.e. mime/partial)
Takes effective action upon virus detection:
- Alert message (with configurable content) may be sent to the originator and a selected user upon detecting a virus
- Isolation of virus-infected attachment
- Sanitise the message by replacing virus-infected attachments with a configurable textual announcement
Keeps track of scanning activity:
- Log files of virus scanning activity are maintained
- Virus infected attachments are isolated and retained in separate files for further analysis
- Log levels may be set to desired level of detail
Raises user confidence:
- In order to further reassure recipients as to the "cleanliness" of attachments, an option within the Document Converter may be used to insert a configurable attachment announcing that a messages has been scanned
System Requirements
The Virus Scanner is supported on the following platforms:
- SCO Unix
- Windows NT 4
- SPARC Solaris
Prerequisites:
- Route400 Message Server with Document Converter option
- Dr. Solomon’s Anti-Virus Toolkit
or
- McAfee's VirusScan
For information on integration with other industry-leading anti-virus packages, please contact NET-TEL.
|