Re: antivirus software

From:
Date: 09/06/02


Date: Fri, 6 Sep 2002 14:20:31 +0100

Liam Cunningham <liam@consumercontact.com> wrote in message
news:doNd9.58610$C8.159302@nnrp1.uunet.ca...
> Amavis acts as a gateway between a mail transport and an virus scanner

Most of the major virus scanners scanners are available on Linux, and some
on commercial unixes including Kaspersky, McAfee, Sophos, Trend.

There is also at least one open-source scanner - Clam - which hangs out at
http://clamav.elektrapro.com/

Note that most anti-virus programs operate in the same way - attempting to
match patterns in a file against a database of fingerprints (typically a
highly optimized FSM). Sometimes it's worth thinking about the problem in a
different way - e.g. there is a lot of mileage in blocking executable
attachments in Emails (Amavis, mimedefang, renattach et al.). Another useful
tool for virus control is file based IDS - (e.g. tripwire or L5) which can
spot modifications to files. Although it is possible to spot / identify
macros within Microsoft files, they keep moving the goal posts by redefining
file formats.

...or stop using applications / operating systems which are susceptible, of
course ;).

Colin



Relevant Pages

  • Re: [Full-Disclosure] Re: January 15 is Personal Firewall Day, help the cause
    ... You may not be running a virus scanner, ... are not stupid enough to ignore the need for chkrootkit and some file ... RUN on any Linux system. ... Nothing more happened and nothing more can happen unless the worm ...
    (Full-Disclosure)
  • Re: What is Dazuko?
    ... >> Dazuko can run several daemons in one real time scan. ... Its possible to scan every Linux file, which already runs or will start ... but only with AntiVir virus scanner and you have to run AVGuard. ... > it does not make sense to scan a Linux machine for Windows virusses. ...
    (alt.os.linux.suse)
  • Re: Security for the desktop user
    ... If the bean counter doesn't have sufficient clue for this to satisfy them, ... Whilst I'd agree with you on the subject of viable viruses for Linux its ... It makes more sense to run the virus scanner on the system which is affected by ... Any machine connected to the University network ...
    (uk.comp.os.linux)
  • Re: [SLE] Virus Scanner
    ... > other mail server, that my computer send viruses on Saturday, ... > possible spam. ... > Our office mail server use f-prot as virus scanner and clamuko ... Linux virus they dont exist out there and attempts at illicit ...
    (SuSE)
  • Re: What are the best virus scanners 4 linux?
    ... i think he wanted a recommendation from other peoples experience, ... > Not much use for spending manhours for making a virus scanner for linux. ... > returns over 9,000 hits, change to best virus scanner ...
    (alt.linux)

Quantcast