Jump to content

With regard to antivirus/antimalware on my web filter...  

27 members have voted

  1. 1. With regard to antivirus/antimalware on my web filter...

    • I use SmoothWall and have AV turned on
      11
    • I use Smoothwall and don't use AV because... (please post)
      3
    • I use "Brand X" filter and have AV turned on
      6
    • I use "Brand X" filter and have AV turned off
      2
    • I use "Brand X" filter, they don't do AV, but I'd like it
      2
    • AV on my web filter? Pah, waste of time! (Post why!)
      3


Recommended Posts

Posted (edited)

Hello my educationally minded friends!

 

I'm looking for a bit of feedback, if you don't mind.

 

Gateway antivirus - particularly AV of incoming web traffic. Interested to know your thoughts in general, preferably here, in-thread, but if you have specific in-depth thinkings, I would love to hear them by PM, email or phone.

 

Is it worth having?

Does your current vendor provide it?

What does/should it cost?

What are the issues you find?

What do you think of these "new generation" behavioural AV engines?

 

Also on the menu: AV for outgoing HTTP. AV for SMTP. AV for IM. AV for FTP. Any ramblings on those subjects also deemed extremely valuable :)

Edited by tom_newton
Posted (edited)
Ive ran clamAV on my "smoothy then endian" box for 4-5 years now, just doing http AVing. Its great for what it is but you've got to balence performance against the added security it provides. Viruses dont tend to be embedded in websites so much no more, or not the ones i visit. They tend more to be trogens, and as such can get past the AV due to the large file size on the host app - striking a balence between silly processing time on large files against just passing the file unchecked. Edited by Guest
Posted

Viruses are less of a problem these days. It's websites containing Spyware, Malware and Rootkits which are more problematic, but you're just as well to block these sites altogether.

 

I believe scanning all incoming traffic with AV Software will inevitably slow down browsing as can web filtering. Workstations should be running AV software anyway as that can catch viruses through the internet and removable media, such as USB sticks.

Posted (edited)

I have it enabled on SW because I like defense in depth. However, the frequency of false positives for "broken executable" detections needs reducing (yeah, a clamav problem). We recently had an issue where an automated update process pulled about 600GB of traffic over a weekend because SW was flagging a 2MB patch as broken when it was perfectly fine and the app kept retrying. Nagios started paging me mid-weekend because the wierdness threshold was tripped.

 

I'd also like much better detection of fake av - it's slipping through SW and hitting desktop av a bit too often for my liking.

Edited by pete
Posted
I'd also like much better detection of fake av

 

This is my point exactly. Malware or fake AV as you phrase it is a lot more of a nuisance. Even Edugeek themselves were experiencing problems recently through one of their ad campaigns (it appears).

We're professionals, we can tell the differences between real and fake, but the not so experienced user can very easily be fooled they're infected.

Posted
Just had a look on our SWG-708 and it says 'Web anti-virus engine' : Stopped. I don't think it's ever been enabled. That wasn't a decision we made so it's either not included in this version or it's turned off by default.
Posted
@pete, @Michael - would you consider a worthy addition to your security arsenal gateway AV which detected more malware, fakeav etc. and did not pick up "broken executable" - what I am saying really, is, if SmoothWall offered a top quality AV/AM engine on HTTP traffic - would that be considered beneficial?
Posted
if SmoothWall offered a top quality AV/AM engine on HTTP traffic - would that be considered beneficial?

 

Yes I'd say that would be more beneficial.

Posted
Thanks to those who have replied/voted so far. Very interesting. Personally, I think gateway av/anti-malware is an important component - so I will be using your feedback to directly influence development. Would welcome any particular tales of AV woe/entertainment still :)
Posted
, if SmoothWall offered a top quality AV/AM engine on HTTP traffic - would that be considered beneficial?

 

Yes.

 

(my message is too short)

Posted

We are using UTM-1000 (firewall only) + 2 x NG08 (content filter) and do not run the clamAV on our smoothwall systems. The reason for this is performance as we can have a 1000 users browsing the internet at any given time.

 

Eric

Posted
@ezzauk - if we could improve performance though (the AV we are looking at outpaces Clam significantly, and the new filtering engine uses less RAM and CPU) would you consider it?
Posted

On a similar subject I was reading the other day that Kaspersky have patented hardware anti-virus

 

I suppose at the rate viruses are being created a hardware type solution will be required, but then again processors these days can handle more than most people realise.

 

To be honest however a good free alternative is to run in limited rights mode as much as possible and this will stop pretty much all viruses, malware and spyware in their tracks.

Posted

Not convinced by most "dedicated hardware". The "thing you are doing" needs to be either really unsuited to regular CPUs or really really common.

Take Graphics - not that suitable for a normal CPU, and there are LOADS of gamers, 3d folk etc want fast gfx. Perfect for going "off cpu".

 

OTOH, most AV applications are local and small scale, and regular CPUs are "not bad" at AV stuff. These folks Sensory Networks: Solutions for High-Performance Network Security used to do a hardware Clam-accelerator among other things. Now its all software libraries. Dedicated ASICs cost too much.

Posted
On a similar subject I was reading the other day that Kaspersky have patented hardware anti-virus

 

I suppose at the rate viruses are being created a hardware type solution will be required, but then again processors these days can handle more than most people realise.

 

To be honest however a good free alternative is to run in limited rights mode as much as possible and this will stop pretty much all viruses, malware and spyware in their tracks.

 

 

 

Hardware AV, what a load of rubbish how can you patent that. I'm pretty sure it will be a device running an 'minimal' OS with an AV app, hmmmm that sounds familiar to me (a small PC anyone?) just the hardware is specialised.

Posted

I think the patent is because there's a physical device between the data cable and the hard disk itself (that's how I understood it). I'm by no means an expert in AV technology, but clearly Kaspersky are going to do something with it.

Patents can cost a small fortune if a lot of research is required to determine whether a patent is valid.

 

To be fair most hardware devices have a basic OS of some kind, but there will still need to be a database of information (software) which is updated regularly. I can imagine this sort of technology may interest businesses but I just couldn't imagine the likes of PC World selling it to customers.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...