05.08.2013 Views

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

Trend Micro InterScan Gateway Security Appliance M-Series ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Trend</strong> <strong>Micro</strong> <strong>InterScan</strong> <strong>Gateway</strong> <strong>Security</strong> <strong>Appliance</strong> M-<strong>Series</strong> Administrator’s Guide<br />

Best Practices<br />

Handling Compressed Files<br />

Compressed files provide a number of special security concerns. In short, compressed<br />

files can be password-protected or encrypted, they can harbor so-called "zip-of-death"<br />

threats, and they can contain within them numerous layers of compression.<br />

14-14<br />

To balance security and performance, <strong>Trend</strong> <strong>Micro</strong> recommends that you read the<br />

following before choosing compressed file settings:<br />

Block compressed files if...<br />

Decompressed file count exceeds:<br />

Set the number of files within a compressed archive at which <strong>InterScan</strong> <strong>Gateway</strong><br />

<strong>Security</strong> <strong>Appliance</strong> should stop extracting.<br />

For example, have <strong>InterScan</strong> <strong>Gateway</strong> <strong>Security</strong> <strong>Appliance</strong> abandon the extraction<br />

after 1,000 files.<br />

Whenever the limit is reached, the original archive, and any decompressed files, is<br />

deleted. In addition to benefiting overall scan efficiency, setting an upper limit for<br />

decompression can prevent "zip of death" attacks designed to crash vulnerable virus<br />

scanning programs.<br />

Size of a decompressed file exceeds:<br />

Set the maximum size that files being extracted from a compressed archive are<br />

allowed to reach.<br />

Once the limit is reached, the original archive, and any decompressed files, is<br />

deleted. As with Number of files, setting an upper size limit for decompression can<br />

help prevent the “zip of death” attack.<br />

Number of layers of compression exceeds:<br />

Set the maximum number of layers (compressed file within a compressed file) you<br />

want <strong>InterScan</strong> <strong>Gateway</strong> <strong>Security</strong> <strong>Appliance</strong> to scan down through. The system maximum<br />

is 20.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!