RE: Why NOT to disable Real Time Antivirus on Servers

From: Zoran Marjanovic (Zoran.Marjanovic_at_registrarbih.gov.ba)
Date: 11/04/05

  • Next message: Gaddis, Jeremy L.: "Re: Sender Spoofing via SMTP"
    Date: Fri, 4 Nov 2005 14:01:32 +0100
    To: <security-basics@securityfocus.com>
    
    

     
    George,

    File level AV client on a dedicated exchange server will consume
    resources much needed for smooth messaging,
    especially if the number of e-mail clients is high and they are very
    active.
    If you are really sure that your network is completely covered with AV
    clients (file-level and e-mail client aware),
    the clients are updated regularly and you monitor it from your AV
    server, you patch your network regularly,
    have AV filter for mail (preferably not the same brand as file-level
    clients (I prefer GFIx4 engines), and it is ok to keep it on an smtp
    gateway),
    have a web filter on your internet gateway, and good app firewall, than
    you do not need file level av client on your exchange.
    If you do not have everything I listed, then your network is not well
    protected and you are open for viruses/worms.
    If you get one, it will possibly shut your network down and you won't
    really benefit of a healthy exchange at that time.
    No need to mention that exchange server should not be used for web
    browsing or running any client apps.
    There is an MS webcast transcript on their site that talk about your
    question. The Q/A part is the most interesting.

    Zoran

    On 2 Nov 2005 17:34:12 -0000, george.peek@gmx.net <george.peek@gmx.net>
    wrote:
    > Greetings,
    >
    > An Engineer and I are having an argument about keeping Real Time
    Antivirus disabled on servers.
    >
    > His point is keeping Real Time Antivirus Enabled on servers such as
    the Exchange Server takes a huge performance hit on the server.
    >
    > My argument is that keeping real time antivirus software disabled
    defeats the purpose of PREVENTING a server from being infected in the
    first place. Once it is infected, it is all too late already. The
    antivirus software is enabled on the workstations.
    >
    > He argues that since all of the workstations have the antivirus
    enabled, then there is no way for the virus to get in.
    >
    > Mine argument that a virus can still get in through other means. I
    need examples and case studies to refer to.
    >
    > I would like to find different case studies or scenarios where the
    real time antivirus was disabled on the servers, enabled on the PCs, and
    the company still got infected. Also, would like to find solutions to
    enabling real time scan and stream lining it so it does not affect the
    Exchange Server as bad.
    >
    > Would someone point me in the right direction or post potential case
    studies.
    >
    > Please post or email me.
    >
    > George.peek@gmx.net
    >
    > Thank You
    >

    --
    ME2  <http://www.santeriasys.net/>
    

  • Next message: Gaddis, Jeremy L.: "Re: Sender Spoofing via SMTP"

    Relevant Pages

    • Re: What doesnt lend itself to OO?
      ... >> proxy and instructs the server to constuct the real object. ... rather than client code. ... If 'clock' is instantiated in the server, ... > for the server interface at the OOA level. ...
      (comp.object)
    • This is going straight to the pool room
      ... or not the client has privilege to do what they're trying to do, ... The server environment is this: ... 3GL User action Routines that Tier3 will execute on your behalf during the ... Routine Name: USER_INIT ...
      (comp.os.vms)
    • Re: WM5, VPN via PPTP/MPPE, and direct connection to Exchange
      ... As for direction connection to your Exchange server, ... NOT synchronising with a client laptop. ... Is there any way of getting the VPN client in WM5 to use MPPE? ...
      (microsoft.public.pocketpc.phone_edition)
    • [Full-Disclosure] R: Full-Disclosure Digest, Vol 3, Issue 42
      ... Full-Disclosure Digest, Vol 3, Issue 42 ... SD Server 4.0.70 Directory Traversal Bug ... Arkeia Network Backup Client Remote Access ...
      (Full-Disclosure)
    • Re: What doesnt lend itself to OO?
      ... > rather than client code. ... no way to do that without also touching the object with clock semantics ... will not encapsulate both clock semantics and network semantics. ... The server can do whatever it wants ...
      (comp.object)